官术网_书友最值得收藏!

Security assessment policy

The security assessment policy establishes rules for how the organization will conduct information security testing on a new information system or information system components. This policy also establishes the rules for how information security continuous monitoring and reporting will be established for the organization.

What the security assessment policy should address:

  • The periodic assessment of security controls in organizational information systems to determine if the controls are effective in their application
  • The development and implementation of plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational information systems
  • The authorization to operational and organizational information systems and any associated information system connections by management
  • The monitoring of information system security controls on an ongoing basis to ensure the continued effectiveness of the controls
主站蜘蛛池模板: 南宁市| 高阳县| 定结县| 大关县| 和龙市| 和林格尔县| 富源县| 巴塘县| 寻乌县| 开原市| 长沙县| 靖宇县| 聂荣县| 亚东县| 页游| 南乐县| 平潭县| 淅川县| 宝鸡市| 剑川县| 渝中区| 裕民县| 左权县| 阳信县| 阿拉尔市| 肃北| 阜新| 弥勒县| 荆门市| 阜阳市| 潍坊市| 聊城市| 洪江市| 桑日县| 陇西县| 蒙山县| 遂川县| 台湾省| 杭锦旗| 清丰县| 鲁山县|