|
|
libcats.org
Security Assessment: Case Studies for Implementing the NSA IAMSean ThurstonIn 1998, the National Security Agency (NSA) Information Assurance Methodology (IAM) was developed to meet the demand for information security (INFOSEC) assessments-a demand that was increasing due to Presidential Decision Directive 63 (PDD-63) while at the same time NSA was downsizing. NSA sought a way to maximize its resources to assist as many customers as possible and so they created a list of organizations that could perform the same service as the NSA. NSA quickly realized that this system would not only provide valuable information to consumers-it would also provide a vehicle for standardization of INFOSEC assessments. * Define What Composes an Assessment * Learn about the NSA's three-phases: Assessment, Evaluation, and Red teaming * Understand Industry Concerns for the Assessment SiteReview the items that affect your client: Health Insurance Portability and Accounting Act of 1996 (HIPAA), Sarbanes-Oxley, Financial Management and Accountability (FMA) Act, Family Education Rights and Privacy Act (FERPA), and others.Create the Organizational Information Criticality Matrix (OICM)Create the OICM, which provides a basis for everything else in the methodology and clarifies the intentions and goals of the assessment process for the customer.Handle Documentation Identification and CollectionWork with the client to gather and define documents such as policy, guidelines, plans, SOPs, user documentation and see what happens when no documentation exists.Understand the Technical Assessment Plan (TAP)Use the TAP to define all dates and scheduling, personnel involvement, understood boundaries, deliverables, priority concerns, and priority constraints.Review the 18 NSA INFOSEC Baseline Classes and CategoriesUse these 18 categories to address the customer's security posture and determine what questions should be asked during the interview process.Create a Recommendation Road MapProvide the customer with a road map to the best way to address or implement the corrective measures for negative findings.Understand the FindingsAssess the overall risk to a customer by looking at the threats, vulnerabilities, and asset value and analyze both negative and positive findings to create a true picture of the customer's security posture.Register for Your 1 Year UpgradeThe Syngress Solutions upgrade plan protects you from content obsolescence and provides monthly mailings, whitepapers, and more!
Скачать книгу бесплатно (pdf, 4.96 Mb)
Читать «Security Assessment: Case Studies for Implementing the NSA IAM» EPUB | FB2 | MOBI | TXT | RTF
* Конвертация файла может нарушить форматирование оригинала. По-возможности скачивайте файл в оригинальном формате.
Популярные книги за неделю:
Система упражнений по развитию способностей человека (Практическое пособие)Автор: Петров Аркадий НаумовичКатегория: Путь к себе
Размер книги: 818 Kb
Сотворение мира (3-х томник)Автор: Петров Аркадий НаумовичКатегория: Путь к себе
Размер книги: 817 Kb
Introduction to Functional Programming (Prentice Hall International Series in Computing Science)Автор: Richard Bird, Автор: Philip WadlerКатегория: Математика, Прикладная математика
Размер книги: 4.73 Mb
The Clean Coder: A Code of Conduct for Professional Programmers (Robert C. Martin Series)Автор: Robert C. Martin
Размер книги: 6.06 Mb
Только что пользователи скачали эти книги:
Theorie des groupes, groupe des rotations et de PoincareАвтор: Delamotte B.Категория: Mathematics, Symmetry and groups
Размер книги: 406 Kb
ActionScript 3.0 Design Patterns: Object-Oriented Programming TechАвтор: William Sanders, Автор: Chandima Cumaranatunge
Размер книги: 3.96 Mb
Quantum Theory of Magnetism - Magnetic Properties of MaterialsАвтор: Robert M. White
Размер книги: 8.09 Mb
The Forest Landscape Restoration Handbook (Earthscan Forestry Library)Автор: Jennifer Rietbergen-McCracken, Автор: Stewart Maginnis, Автор: Alastair SarreКатегория: Геология
Размер книги: 3.45 Mb
The Messiah: A Comparative Study of the Enochic Son of Man and the Pauline Kyrios (Jewish & Christian Text)Автор: James A. Waddell
Размер книги: 997 Kb
The Influence of Islamic Philosophy and Ethics on The Development of Medicine During the Islamic RenaissanceАвтор: GhazalКатегория: The Influence of Islamic Philosophy and Ethics on The Development of Medicine During the Islamic Renaissance, Alhassanain Network, http:, alhassanain.org, english, ?com=book&id=919
Размер книги: 105 Kb
|
|
|