Documentation and Reporting Flashcards
Documents to Maintain Includes:
- Gap Assessment Report
- Vulnerability Assessment Report
- Risk Assessment Report
- Zone & Conduit diagrams
Vulnerability Assessment Report
- Scope of the assessment
- “As found” System Architecture
- Assessment details
- Prioritized summary of findings
- Detailed findings
Vulnerability Assessment Report
- Scope of the assessment
- “As found” System Architecture
- Assessment details
- Prioritized summary of findings
- Detailed findings
Cybersecurity Risk Assessment Report
- Risk profile
- Scope of the risk assessment
- Assessment details
- Detailed findings
- Prioritezed recomendations
Cybersecurity Requirements Specifications
A Cybersecurity Requirements Specification (CRS) documents general security requirements based upon company policy and standards, relevant regulations and the outcome of the high-level risk assessment as well as any mandatory security functions of the SuC.
Definition of zones and conduits, access control requirements, and security level targets should all be included in which document?
Cybersecurity Requirements Specification (CRS)
In a CRS, which requirements can be grouped?
Access control
The desired level of security for a particular system is known as a Target Security Level (SL-T). Which document includes SL-Ts?
CRS
True of False?
A CRS is a living document that may change over time
True
True of False?
Without documentation, there is nothing to verify, audit or prove.
True