官术网_书友最值得收藏!

Security assessment policy

The security assessment policy establishes rules for how the organization will conduct information security testing on a new information system or information system components. This policy also establishes the rules for how information security continuous monitoring and reporting will be established for the organization.

What the security assessment policy should address:

  • The periodic assessment of security controls in organizational information systems to determine if the controls are effective in their application
  • The development and implementation of plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational information systems
  • The authorization to operational and organizational information systems and any associated information system connections by management
  • The monitoring of information system security controls on an ongoing basis to ensure the continued effectiveness of the controls
主站蜘蛛池模板: 沁水县| 佛学| 合江县| 辰溪县| 连山| 昌图县| 白城市| 富阳市| 溆浦县| 旌德县| 高邑县| 昔阳县| 青河县| 桐梓县| 台山市| 太谷县| 彩票| 阿克苏市| 和顺县| 得荣县| 浦城县| 隆子县| 香格里拉县| 饶平县| 南靖县| 皋兰县| 福州市| 资阳市| 大安市| 维西| 柘荣县| 阳山县| 丰台区| 卓资县| 淮滨县| 红河县| 昆明市| 平度市| 定边县| 洛隆县| 米林县|