Policy and Procedure
Each of the seventeen families of security controls found in 800-53 contain a first control that requires the development of policy and procedures for that specific family of controls. Here…
Free resources for programming help
Each of the seventeen families of security controls found in 800-53 contain a first control that requires the development of policy and procedures for that specific family of controls. Here…
KEY NIST DOCS:800-50
The security planning process eventually produces a Site Security Plan, known as the “Security Plan” or SSP. The security plan provides an overview of the security requirements of the system…
We want to trust that the measures we take to protect our information systems are working. But we need concrete reasons to hold that trust. We need proof that our…
It is a mantra of quality improvement methodology that you can’t manage what you don’t measure. Security metrics are the measurements that allow management of information security. As function and…
Tailoring security controls involves adapting the generic baseline sets of security controls to better fit a specific operating environment. Here is a list of tailoring activities: Once tailoring changes have…
The NIST Risk Management Framework (RMF) is a six step process as follows: The second step begins with selecting a baseline of controls. This is done automatically, according to the…
After the baseline of security controls have gone through the tailoring process of: scoping guidance, compensating controls and organizationally defined parameters, it is possible that additional controls or enhancements may…
Categorization is the process of selecting an Impact Level according to FIPS 199, which is a public law and must be adhered to. FIPS 199 sets three impact levels of…
Risk assessment is the process of analyzing threats to an information system and known vulnerabilities to determine the likelihood and impact of some anticipated loss. This risk analysis can then…