Continuous Monitoring 2 Flashcards
DoD Policy
- 16 insider threat program
- 06 CI awareness and reporting
- 01 cybersecurity
- 01 Risk management framework (consistent with principles established in NIST
CNSSI 1253 security categorization and control/selection for national security systems
NIST
National institute of standards and technology
NIST SP
800-37 guide for applying RMF to federal info systems
800-137 ISCM for fed info systems and orgs
800-128 Guide for security focused configuration management of info systems
800-53 security and privacy controls for fed info systems and orgs
NISPOM
Detailed industrial security policy for contracts
DoD 5220.22
RMF overview
Risk: Possibility that threat will adversely impact info systems exploiting vulnerability
Risk assessment: analyzing threats, defining impact, ID countermeasures
Strategic risk tiers
Communication loop
ISCM
Maintaining ongoing awareness of IS
Tiers 1/2 develop policies and procedures
ISCM strategy developed tiers 1/2
System specific policy and procedure of implementation tier 3. Strategy based on government guidance
Na
SecCM Controlling Configuration Changes
Access restrictions for change employed