Introduction:
The National Institute of Standards and Technology (NIST) replaced the former NIST Special Publication 800-37, Guide for the Security Certification and Accreditation of Federal Information Systems with NIST Special Publication 800-37 Revision 1, Guide for Applying Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach. The NIST document changed from a certification and accreditation framework to a risk management framework because information security management systems should be regularly reviewed, updated, and maintained. It makes more sense to follow a security life cycle approach (continuous monitoring) versus a single one-time static certification/accreditation approach.
For this task, you will be using NIST Special Publication 800-37 Revision 1, Guide for Applying Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach and the attached “Healthy Body Wellness Center Risk Assessment” case study.
You have been hired to apply the NIST’s risk management framework to the Healthy Body Wellness Center’s information systems. You know that the organization has recently had a risk assessment completed that includes recommendations for implementing security controls and mitigating risks. In your new role, a team of people will be assigned to help you with the task. The first job you are tasked with is creating a to-do list for the specific tasks outlined in each of the six steps in the risk management framework (RMF).
Task:
- Discuss key elements that need to be addressed as part of the risk management framework by completing the attached “RMF To-Do List.”
- Create a white paper that compares the ISO 27002, COBIT, NIST, and ITIL frameworks by doing the following:
- Discuss how each framework is most commonly used.
- Analyze the purpose of each framework design.
- Evaluate the strengths of each framework.
- Evaluate the weaknesses of each framework.
- Discuss the certification and accreditation process for the frameworks.
- Discuss when you would choose to use each framework (e.g., ISO 27002 versus COBIT, NIST, or ITIL).
- When you use sources, include all in-text citations and references in APA format.
Note: When bulleted points are present in the task prompt, the level of detail or support called for in the rubric refers to those bulleted points.
Note: For definitions of terms commonly used in the rubric, see the Rubric Terms web link included in the Evaluation Procedures section.
Note: When using sources to support ideas and elements in a paper or project, the submission MUST include APA formatted in-text citations with a corresponding reference list for any direct quotes or paraphrasing. It is not necessary to list sources that were consulted if they have not been quoted or paraphrased in the text of the paper or project.
Note: No more than a combined total of 30% of a submission can be directly quoted or closely paraphrased from sources, even if cited correctly. For tips on using APA style, please refer to the APA Handout web link included in the General Instructions section.
Do you want your assignment written by the best essay experts? Order now, for an amazing discount.
You May Also Like This:
- Implementing Risk Management
- Security and Risk Management
- Principle of Risk Management and Insurance
- NR531-11100 Week 3: Describe the nursing care delivery model used at your current or previous employer. Would you utilize this model at SLMC? Discuss current interprofessional collaboration and how you would encourage collaborative efforts. Does the model support the person-centred nursing framework by McCormack and McCance (2017)? Explain your rationale for choosing to use or not use the person-centred nursing framework.
- Auditing (Management Fraud and Audit Risk)
- Risk Management on a Satellite Development Project
- Self-Assessment of Modifiable Risk Factors
- Project Management Paper
- Risk Register
- Management of Project Risk, Quality and Safety
- Business Risk Analysis of GPT Group and preparation of an audit strategy
- Ranking and treating risk
- Organizational Risk Management
- Risk Management
- Population At Risk(Pregnant Women at Risk In Maryland)
- Communicating Risk
- Why a failure in technology is a risk in business?
- DERIVATIVES AND RISK MANAGEMENT
- Project Management for Construction
- risk attitudes that people display.
- supply chain inventory, people, technology, and risk
- ontological and epistemological framework
- the implications of Liquidity Risk
- Project Management Plan PMP
- Porter’s analytical framework
- Change Management
- Analyzing the framework of a strategic plan
- Emergency Management Airport Assessment part #2
- Managing Risk
- Occupational Health Management Program Proposal