Categorization and Baseline Selection
Categorization is the process of selecting an Impact Level according to FIPS 199, which is a public law and must be adhered to. FIPS 199 sets three impact levels of…
Free resources for programming help
Categorization is the process of selecting an Impact Level according to FIPS 199, which is a public law and must be adhered to. FIPS 199 sets three impact levels of…
Synthesizing Intelligence We are constantly getting better at designing software tools to help us navigate an ever growing ocean of information and negotiate methods of applying it wisely. We ask…
Risk assessment is the process of analyzing threats to an information system and known vulnerabilities to determine the likelihood and impact of some anticipated loss. This risk analysis can then…
The SDLC framework is a multi-step outline that describes the life cycle of an information system. The five phases of the SDLC are: Security that is integrated into this life…
Situational awareness is one of the most difficult things to get right in doing cloud security, and hand in hand with that goes inventory awareness. To understand why, take a…
A previous article here on general Security Metrics outlined some key security controls for measurement: NOTE: each of these security controls may have several or even many metrics that can…
Connecting your information system to a cloud is an interconnection. NIST guidance on handling the security of interconnections is documented in 800-47 Rev. 1 “Managing the Security of Information Exchanges”.…
Cloud computing is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications and services) that can be…
Cloud computing may not deliver the cost savings that everybody seems to expect. The general computing community seems to take it for granted that the driving reason for moving to…
FEDRAMP (FEDeral Risk and Authorization Management Program) offers baselines of 800-53 security controls that have been tailored for cloud environments. But they do not offer a HIGH impact baseline. Presumably,…