Page 43 - CISSO_Prep_ Guide
P. 43

system (Low. Moderate or High), SP800-53 lists what security
            controls would be recommended.



            NIST SP800-100 Information Security Handbook: A Guide
            for Managers

            NIST SP800-100 outlines the primary areas of concern for
            Managers. These include:
            - Information Security Governance
            - Systems Development Life Cycle
            - Awareness and Training
            - Capital Planning and Investment Control
            - Interconnecting Systems
            - Performance Measures
            - Security Planning
            - Information Technology Contingency Planning
            - Risk Management
            - Certification, Accreditation and Security Assessments
            - Security Services and Product Acquisition
            - Incident Response
            - Configuration Management



            Summary of Frameworks
            Each of these frameworks can be a valuable tool in the hands of
            the  security  professional.  Just  like  a  recipe  to  a  chef,  these
            frameworks can help ensure that nothing is overlooked or missed
            in  the  creation  of  the  security  plan.  It  also  provides  that  the
            program will be authoritative, balanced, complete, and justifiable.
            It  must  be  remembered  that  the  use  of  a  framework  is  not  a
            guarantee that the security program will be ideal or successful.
   38   39   40   41   42   43   44   45   46   47   48