-
Book Overview & Buying
-
Table Of Contents
Executive's Cybersecurity Program Handbook
By :
We take risks every day. Whether they are human, environmental, or technical, they are risks that we evaluate constantly. When evaluating the risks to an IT resource, the same challenges apply. You must have a structured way to evaluate and respond to risks once they have been identified. In this chapter, you have learned to evaluate these risks using the NIST RMF and apply risk management in various stages from categorizing to monitoring.
As mentioned, once risks are identified, they should be published in a risk register and remediated using the steps defined in a POA&M. An SSP captures all the system components, establishes the scope, identifies the parties involved, and is the document that should be signed off by an executive before a system goes into production. Remember, identified risks and remediation steps should never be deleted from these documents. Once a risk is closed out, it should be marked closed in the status column and never be deleted.
Over the...