NIST SP800-53A rev1.pdf NIST SP800-53A rev1.pdf评分: INTRODUCTION THE NEED TO ASSESS SECURITY CONTROL EFFECTIVENESS IN INFORMATION SYSTEMS T T oday’s information systems9 are complex assemblages of technology (i.e., hardware, software, and firmware), processes, and people, working together ...
为此, NISTNIST又开发又开发NIST SP 800-53ANIST SP 800-53A联邦信息系统中安全控制评联邦信息系统中安全控制评 价指南价指南,其中针对,其中针对FIPS SP 800-53FIPS SP 800-53中的安全控制,给出了中的安全控制,给出了 安全控制评估中可应用的评估规程,并以这些评价规程为基安全控制评估中可应用的 13、评估...
SP 800-53/53A – Security Controls Catalog and Assessment Procedures • SP 800-60 – Mapping Information Types to Security Categories • SP 800-128 – Security-focused Configuration Management • SP 800-137 – Information Security Continuous Monitoring • Many others for operational and ...
NIST SP800-53A rev1.pdf INTRODUCTION THE NEED TO ASSESS SECURITY CONTROL EFFECTIVENESS IN INFORMATION SYSTEMS T T oday’s information systems9 are complex assemblages of technology (i.e., hardware, software, and firmware), processes, and people, working together to provide organizations with the ...
NISTpublishedSpecial Publication (SP) 800-53A Revision 5assessment procedures in multiple data formats, so agencies can process them using automated tools and free upcybersecurityassessors for more challenging work. Updatedprivacyandsupply chainrisk managementcontrols came out in September for agencies to...
本节提供了符合NIST SP 800-37和NIST SP 800-53A的安全评估计划模板。有关文档元素的描述,请参见本NISTIR第1卷第6节。第1卷的第9节专门介绍如何将模板和文档与NIST SP 800-37和NIST SP 800-53A中定义的评估任务和工作产品关联。 要对安全评估计划进行调整使其满足组织的需求并实现自动化监控,可采取图6所示...
·针对SP800-30、SP800-39、SP800-53、SP800-53A、SP800-137、和CNSS 1253号指令等文件中所述的安全控制有效性、信息系统及其运行环境中的任何潜在或实际变更,制定相应策略; ·根据SP800-30、SP800-53和CNSS 1253号指令等文件,审查并批准安全计划。
The assessment of SA-12 and SA-19 controls was conducted using NIST SP 800-53A Rev. 4 assessment procedures.Microsoft’s supply chain processes are implemented at a programmatic level and applicable across the board for all Azure systems. Based on the 3PAO's review of the SA-12 and SA-...
以下安全控制/控制项不属于NIST SP 800-53基线,因此在关键字搜索后没有进一步分析: 项目管理(PM)系列,因为PM控制不适用于单个系统 通过VUL关键字(如附录B中所述)选择、但不属于任何NIST SP 800-53基线的控制/控制项 隐私控制 本附录中提供了与上述各项标准匹配的控制/控制项,供想要自行开发自动化测试的组织使用...
按照NIST SP800-53A设计评估时,哪项评估部分包括策略和程序? 17 2022-10 如何最大程度地确保所有Windows台式机都具有相同的日志设置? 16 2022-10 请问什么系统本身不支持syslog? 12 2022-10 组织应使用所示的哪项技术,来确保日志可在整个基础设施执行时间排序?