FISMA compliance handbook
Moulder, Patricia

 

  • FISMA compliance handbook
  • 紀錄類型: 書目-語言資料,印刷品 : 單行本
    作者: TaylorLaura P.,
    其他作者: MoulderPatricia,
    出版地: Waltham, MA
    出版者: Syngress;
    出版年: c2013
    版本: 2nd ed.
    面頁冊數: xx, 359 p.ill. : 24 cm.;
    標題: Computer security - Law and legislation - United States -
    標題: Data protection - Law and legislation - United States -
    標題: Electronic government information - Security measures - United States -
    附註: Includes bibliographical references and index
    摘要註: "FISMA, also known as Title III of the E-Government Act (Public Law107-347), requires that all systems and applications that reside on U.S. government networks undergo a formal security assessment before being put into production. System authorization is the ultimate output of a FISMA compliance project, and a system or application cannot be authorized unless it meets specific security control requirements. However, keep in mind that no system can be completely secure - unless it is powered off and locked in a vault. Of course then it is not very useable. Determining the security controls for the system is a balancing act between making the system useable and making the system secure. These two endeavors are often at odds with each other. In order to find the balance, security experts analyze the probability and impact of potential vulnerabilities being exploited (or not) and then make risk-based decisions based on the analysis. Clearly the goal of FISMA is to force federal agencies to put into production secure systems and applications. Once put into production, FISMA requires that system owners analyze risk periodically on the production system in order to find vulnerabilities, and fix them, before they are exploited by adversaries"--Provided by publisher
    ISBN: 978-0-12-405871-2
    內容註: FISMA compliance overview FISMA trickles into the private sector FISMA compliance methodologies Understanding the FISMA compliance process Establishing a FISMA compliance program Getting started on your FISMA project Preparing the hardware and software inventory Catagorizing data sensitivity Addressing security awareness and training Addressing rules of behavior Developing an incident repsonse plan Conducting a privacy impact assessment Preparing the business impact analysis Developing the contingency plan Developing a configuration management plan Preparing the system security plan Peforming the business risk assessment Getting ready for security testing Submitting the security package Independent assessor audit guide Developing the security assessment report Addressing FISMA findings FedRAMP : FISMA for the cloud
館藏地:  出版年:  卷號: 
館藏

期刊年代月份卷期操作說明(Help)
  • 1 筆 • 頁數 1 •
  • 1 筆 • 頁數 1 •
評論
建立或儲存個人書籤
書目轉出
取書館別
 
 
變更密碼
登入