Archive for security plan
You are browsing the archives of security plan.
You are browsing the archives of security plan.
Each of the seventeen families of security controls found in 800-53 contain a first control that requires the development of policy and procedures for that specific family of controls. Here is an example from the PL family: 800-53 security control PL-1 SECURITY PLANNING POLICY AND PROCEDURES Control: The organization develops, disseminates, and periodically reviews/updates: (i) [...]
Any information security policy and Site Security Plan (SSP) should contain a section known as “Rules of Behavior” that establishes appropriate use and behavior of system users and the consequences of non-compliance. From 800-100, Appendix B, FAQs: Q – What are “Rules of Behavior”? A – The rules should state the consequences of inconsistent behavior [...]
Plan of Action and Milestones A POAM is a plan that describes specific measures to be taken to correct deficiences found during a security control assessment. The POAM should identify: The tasks needed to correct the deficiency The resources required to make the plan work Milestones in completing the tasks Scheduled completion dates for the [...]
Federal agencies are required by law to report incidents to the US Computer Readiness Team (CERT) office in DHS and must have a formal incident response capability. INCIDENT RESPONSE METHODOLOGY Prepare – accumulate knowledge, resources, tools, team members and training needed to handle incident reponse. Provide feedback into other processes (patch management…) that may help [...]
Policy Identify statutory or regulatory requirements Create a policy statement Get the policy statement approved Publish the policy statement Key elements of policy Roles and responsibilities Scope Resources required Training required Testing and exercises schedule Maintenance schedule Backup and storage schedule Business Impact Assessment (BIA) The BIA is a critical piece of the CP that [...]
AC-18 WIRELESS RESTRICTIONS (NIST SP 800-53) The organization: (i) establishes usage restrictions and implementation guidance for wireless technologies; and (ii) authorizes, monitors, controls wireless access to the information system. NIST Special Publications 800-48 and 800-97 provide guidance on wireless network security. NIST Special Publication 800-94 provides guidance on wireless intrusion detection and prevention. Overview of [...]
Defining the security requirements, including risk assessment and security controls. Security planning involves documenting these requirements and preventative controls.
(…more)