Question: Assignment Content As the team leader for Phoenix Security Services SureMarket account, you completed your SOX assessment of compliance. Now your company is being retained
Assignment Content
As the team leader for Phoenix Security Services SureMarket account, you completed your SOX assessment of compliance. Now your company is being retained to monitor the status of SureMarkets security posture, including maintaining compliance with the SarbanesOxley SOX act using the NIST RMF as described in NIST SP :
Step : Categorize Information Systems
Step : Select Security Controls
Step : Implement Security Controls
Step : Assess Security Controls
Step : Authorize Information System
Step : Monitor Security Controls
Review the security controls implemented and assessed during Steps and
Your next task as team leader is to complete Step of the NIST RMF process by requiring various methods of monitoring, including security metrics and vulnerability management.
Security metrics are used to gain a holistic view of the effectiveness of the overall security program, while vulnerability management constantly monitors for any new vulnerabilities and applies mitigation actions in order to reduce the risks of those newly identified vulnerabilities. In some cases, the process will start over with Step of the NIST RMF process.
Part A: Metrics Plan
To prepare a metrics plan for the SureMarket information security department, create a to page Microsoft Word document that includes the following:
Describe the security strategy for measuring the effectiveness of the implemented security controls and risk mitigation put into place during Step of the NIST RMF process. Include the following for each of the vulnerabilities with respect to the SureMarket IT systems:
How to measure mitigated risk
How to identify new vulnerabilities
How to measure SOX compliance
Describe the tools that you would use to measure and track trends, including key performance indicators and thresholds.
Illustrate how you would present metrics to senior leadership, including the requirement for reauthorization.
Part B: Vulnerability Management Plan
To prepare a vulnerability management plan for the SureMarket information security department, create a to page Microsoft Word document that includes the following:
Describe the strategy for continuously monitoring the SureMarket network and IT systems for new vulnerabilities. Include the methods and frequency for conducting the following:
Vulnerability scanning
Penetration testing
Describe a decision tree for mitigating newly identified vulnerabilities.
Format your citations according to APA guidelines.
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
