Review the Red Clay Renovations company profile, the project #3 description, and the weekly readings before responding to this question.
Prepare a one page briefing statement (3 to 5 paragraphs) for the company’s Corporate Board. This statement should answer the question: “Why is a separate System Security Plan (SSP) required for each field office?” (Or, put another way “Why doesn’t one size fits all work for SSP’s?”)
Do not assume that all members of the board are familiar with the purpose and contents of an SSP. Nor, will they be familiar with enterprise architectures and the details of the IT infrastructure for the field office.
Provide specific information about “the company” in your briefing statement. (Customize your briefing for THIS company.)
Provide in-text citations and references for 3 or more authoritative sources. Put the reference list at the end of your posting.
http://dx.doi.org/10.6028/NIST.SP.800-100
Pay special attention to the following chapters:
2. Information Security Governance
6. Interconnecting Systems (section 6.1)
8. Security Planning (all sections!)
https://doi.org/10.6028/NIST.SP.800-39
This resource provides guidance for identifying (“framing”), assessing, responding to, and monitoring risks associated with information systems.
http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf
See Appendix A for additional information about completing the System Security Plan.
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf
http://www.verizonenterprise.com/terms/us/products/internet/sla/
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-12r1.pdf

WhatsApp us