Security Metrics
It is a mantra of quality improvement methodology that you can’t manage what you don’t measure. Security metrics are the measurements that allow management of information security. As function and…
Free resources for programming help
It is a mantra of quality improvement methodology that you can’t manage what you don’t measure. Security metrics are the measurements that allow management of information security. As function and…
Tailoring security controls involves adapting the generic baseline sets of security controls to better fit a specific operating environment. Here is a list of tailoring activities: Once tailoring changes have…
The NIST Risk Management Framework (RMF) is a six step process as follows: The second step begins with selecting a baseline of controls. This is done automatically, according to the…
After the baseline of security controls have gone through the tailoring process of: scoping guidance, compensating controls and organizationally defined parameters, it is possible that additional controls or enhancements may…
Categorization is the process of selecting an Impact Level according to FIPS 199, which is a public law and must be adhered to. FIPS 199 sets three impact levels of…
Synthesizing Intelligence We are constantly getting better at designing software tools to help us navigate an ever growing ocean of information and negotiate methods of applying it wisely. We ask…
Risk assessment is the process of analyzing threats to an information system and known vulnerabilities to determine the likelihood and impact of some anticipated loss. This risk analysis can then…
The SDLC framework is a multi-step outline that describes the life cycle of an information system. The five phases of the SDLC are: Security that is integrated into this life…
Situational awareness is one of the most difficult things to get right in doing cloud security, and hand in hand with that goes inventory awareness. To understand why, take a…
A previous article here on general Security Metrics outlined some key security controls for measurement: NOTE: each of these security controls may have several or even many metrics that can…