文件名称:
Is “Agile Cybersecurity” Possible?
开发工具:
文件大小: 3mb
下载次数: 0
上传时间: 2019-03-02
详细说明:Is “Agile Cybersecurity”Possible? - Strategic and Tactical Solutions
to Realizing AgilityCopyright 2018, by Syber Risk LLC
All rights reserved. No parts of this book may be reproduced or utilized in any form or by any means
electronic or mechanical, including photocopying, recording or by any information storage and
retrieval system, without permission in writing from the Publisher/Author. Inquiries should be
addressed to Syber risk, LLC, 6528 Seventh Street Nw, Washington, District of Columbia, 20012 or
syber.risk.llc(gmail.com
DEDICATION
This book is dedicated to the cyber-security men and women that protect and
defend the information Systems of this great Nation
LEGAL STUFF
ANY REGISTERED R NAMED SYSTEM HARDWARE OR SOFTWARE COMPONENT
IDENTIFIED IS ONLY MEANT FOR EDUCATIONAL PURPOSES AND DOES NOT CONSTRUE
ANY PROMOTION OF THE PRODUCT. READERS SHOULD EXERCISE THEIR DUE
DILIGENCE AND CONDUCT PROPER MARKET RESEARCH TO IDENTIFY THEIR NEEDED
PRODUCTS IN ACCORDANCE WITH THEIR COMPANY OR AGENCY POLICIES AND
STANDARDS
LIMIT OF LIABILITY DISCLAIMER OF WARRANTY: THE PUBLISHER AND THE AUTHOR
MAKE NO REPRESENTATIONS OR WARRANTIES WITH RESPECT TO THE ACCURACY OR
COMPLETENESS OF THE CONTENTS OF THIS WORK AND SPECIFICALLY DISCLAIM ALL
WARRANTIES. INCLUDING WITHOUT LIMITATION WARRANTIES OF FITNESS FOR A
PARTICULAR PURPOSE. NO WARRANTY MAY BE CREATED OR EXTENDED BY SALES
OR PROMOTIONAL MATERIALS. THE ADVICE AND STRATEGIES CONTAINED HEREIN
MAY NOT BE SUITABLE FOR EVERY SITUATION. THIS WORK IS SOLD WITH THE
UNDERSTANDING THAT THE PUBLISHER IS NOT ENGAGED IN RENDERING LEGAL
ACCOUNTING, OR OTHER PROFESSIONAL SERVICES. IF PROFESSIONAL ASSISTANCE IS
REQUIRED, THE SERVICES OF A COMPETENT PROFESSIONAL PERSON SHOULD BE
SOUGHT, NEITHER THE PUBLISHER NOR THE AUTHOR SHALL BE LIABLE FOR
DAMAGES ARISING HEREFROM. THE FACT THAT AN ORGANIZATION OR WEBSITE IS
REFERRED TO IN THIS WORK AS A CITATION AND/ORA POTENTIAL SOURCE OF
FURTHER INFORMATION DOES NOT MEAN THAT THE AUTHOR OR THE PUBLISHER
ENDORSES THE INFORMATION THE ORGANIZATION OR WEBSITE MAY PROVIDE OR
RECOMMENDATIONS IT MAY MAKE FURTHER. READERS SHOULD BE AWARE THAT
INTERNET WEBSITES LISTED IN THIS WORK MAY HAVE CHANGED OR DISAPPEARED
BETWEEN WHEN THIS WORK WAS WRITTEN AND WHEN IT IS READ
Is"“ Agile Cybersecurity” Possible:
Table of contents
Is agile cybersecurity? possible?
nist 800-53 is too cumbersome
The Risk Management Framework(RMF Failure
Risk versus threat
A Return to the past: A hybrid solution
The Nature of Continuous Monitoring
The National Cybersecurity Framework (NCF
NCF Agility
A Need for Third-Party Assessment
The Subjectivity of Compliance
National Institute of Standards and Technology(NIsT800-171
Where is 800-171 Going?
Consequences of Non-compliance
The Likely Course: FAR Clause 52.204-21
Proof of a companys cybersecurity posture
The Risk Assessment(RA
The ra defined
The ra workflow
The RA and agility
Specialized IT Systems(SPITS)
Constrained number of controls
SPITS Categorization
Conclusion
Appendix A--Relevant Terms
Appendix B-Continuous MonitoringA More Detailed Discussion
Defining Continuous Monitoring
Continuous Monitoring-First Generation
End-Points
Security Tools
Security Controls
Security Information and Event Management (SIEM Solutions
Next Generations
Endnotes for "Continuous Monitoring: A More Detailed Discussion
Appendix C-Plan of Action Milestones(POAM)
Appendix D--Sample Risk Assessment(RA) Analysis Report
Appendix E--Ten Success Recommendations
Appendix F-Special Information Technology Systems(SPITS)
Baseline controls
APPENDIX G-NIST 800-171 Compliance Checklist
Access Control(AC)
Awareness Training(AT)
Audit Accountability (AU)
Configuration Management (CM
Identification Authentication (IA)
Incident Response (R
Maintenance MA)
Media Protection( MP
Personnel Security(Ps)
Physical Security (PP)
Risk Assessments(RA)
Security Assessments( A)
System Communications Protection SC)
System Information Integrity(SD
About the author
Other Supplements by the author
Is"Agile Cybersecurity"Possible?
(系统自动生成,下载前可以参看下载内容)
下载文件列表
相关说明
- 本站资源为会员上传分享交流与学习,如有侵犯您的权益,请联系我们删除.
- 本站是交换下载平台,提供交流渠道,下载内容来自于网络,除下载问题外,其它问题请自行百度。
- 本站已设置防盗链,请勿用迅雷、QQ旋风等多线程下载软件下载资源,下载后用WinRAR最新版进行解压.
- 如果您发现内容无法下载,请稍后再次尝试;或者到消费记录里找到下载记录反馈给我们.
- 下载后发现下载的内容跟说明不相乎,请到消费记录里找到下载记录反馈给我们,经确认后退回积分.
- 如下载前有疑问,可以通过点击"提供者"的名字,查看对方的联系方式,联系对方咨询.