[go: up one dir, main page]
More Web Proxy on the site http://driver.im/ skip to main content
Skip header Section
Automation Support for Security Control Assessments Vol 1: NISTIR 8011 Volume 1 OverviewJune 2017
Publisher:
  • CreateSpace Independent Publishing Platform
  • 7290 Investment Drive # B
  • North Charleston
  • SC
  • United States
ISBN:978-1-5484-0027-9
Published:23 June 2017
Pages:
100
Reflects downloads up to 09 Mar 2025Bibliometrics
Skip Abstract Section
Abstract

NISTIR 8011 Volume 1 - Overview Released JUNE 2017 This volume introduces concepts to support automated assessment of most of the security controls in NIST Special Publication (SP) 800-53. Referencing SP 800-53A, the controls are divided into more granular parts (determination statements) to be assessed. The parts of the control assessed by each determination statement are called control items. The control items are then grouped into the appropriate security capabilities. As suggested by SP 800-53 Revision 4, security capabilities are groups of controls that support a common purpose. For effective automated assessment, testable defect checks are defined that bridge the determination statements to the broader security capabilities to be achieved and to the SP 800-53 security control items themselves. The defect checks correspond to security sub-capabilitiescalled sub-capabilities because each is part of a larger capability. Capabilities and sub-capabilities are both designed with the purpose of addressing a series of attack steps. Automated assessments (in the form of defect checks) are performed using the test assessment method defined in SP 800-53A by comparing a desired and actual state (or behavior). Why buy a book you can download for free? First you gotta find it and make sure its the latest version (not always easy). Then you gotta print it using a network printer you share with 100 other people and its outta paper and the toner is low (take out the toner cartridge, shake it, then put it back). If its just 10 pages, no problem, but if its a 250-page book, you will need to punch 3 holes in all those pages and put it in a 3-ring binder. Takes at least an hour. An engineer thats paid $75 an hour has to do this himself (who has assistants anymore?). If you are paid more than $10 an hour and use an ink jet printer, buying this book will save you money. Its much more cost-effective to just order the latest version from Amazon.com This book is published by 4th Watch Books and includes copyright material. We publish compact, tightly-bound, full-size books (8 by 11 inches), with glossy covers. 4th Watch Books is a Service Disabled Veteran-Owned Small Business (SDVOSB), and is not affiliated with the National Institute of Standards and Technology. For more titles published by 4th Watch Books, please visit: cybah.webplus.net A full copy of all the pertinent cybersecurity standards is available on DVD-ROM in the CyberSecurity Standards Library disc which is available at Amazon.com. NIST SP 500-299 NIST Cloud Computing Security Reference Architecture NIST SP 500-291 NIST Cloud Computing Standards Roadmap Version 2 NIST SP 500-293 US Government Cloud Computing Technology Roadmap Volume 1 & 2 NIST SP 500-293 US Government Cloud Computing Technology Roadmap Volume 3 DRAFT

Contributors
Please enable JavaScript to view thecomments powered by Disqus.

Recommendations

Skip Bibliometrics Section