Plan of Action and Milestones POAMs
A POAM is a plan that describes specific measures to be taken to correct deficiencies found during a security control assessment. The POAM should identify: An organizational strategy for developing…
Free resources for programming help
A POAM is a plan that describes specific measures to be taken to correct deficiencies found during a security control assessment. The POAM should identify: An organizational strategy for developing…
Any information security policy and Site Security Plan (SSP) should contain a section known as “Rules of Behavior” that establishes appropriate use and behavior of system users and the consequences…
Each of the seventeen families of security controls found in 800-53 contain a first control that requires the development of policy and procedures for that specific family of controls. Here…
KEY NIST DOCS:800-50
The security planning process eventually produces a Site Security Plan, known as the “Security Plan” or SSP. The security plan provides an overview of the security requirements of the system…
We want to trust that the measures we take to protect our information systems are working. But we need concrete reasons to hold that trust. We need proof that our…
It is a mantra of quality improvement methodology that you can’t manage what you don’t measure. Security metrics are the measurements that allow management of information security. As function and…
Tailoring security controls involves adapting the generic baseline sets of security controls to better fit a specific operating environment. Here is a list of tailoring activities: Once tailoring changes have…
The NIST Risk Management Framework (RMF) is a six step process as follows: The second step begins with selecting a baseline of controls. This is done automatically, according to the…
After the baseline of security controls have gone through the tailoring process of: scoping guidance, compensating controls and organizationally defined parameters, it is possible that additional controls or enhancements may…