Page 43 - CISSO_Prep_ Guide
P. 43
system (Low. Moderate or High), SP800-53 lists what security
controls would be recommended.
NIST SP800-100 Information Security Handbook: A Guide
for Managers
NIST SP800-100 outlines the primary areas of concern for
Managers. These include:
- Information Security Governance
- Systems Development Life Cycle
- Awareness and Training
- Capital Planning and Investment Control
- Interconnecting Systems
- Performance Measures
- Security Planning
- Information Technology Contingency Planning
- Risk Management
- Certification, Accreditation and Security Assessments
- Security Services and Product Acquisition
- Incident Response
- Configuration Management
Summary of Frameworks
Each of these frameworks can be a valuable tool in the hands of
the security professional. Just like a recipe to a chef, these
frameworks can help ensure that nothing is overlooked or missed
in the creation of the security plan. It also provides that the
program will be authoritative, balanced, complete, and justifiable.
It must be remembered that the use of a framework is not a
guarantee that the security program will be ideal or successful.