Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
News
SHARE
NIST Security Recommendations... in English

by eSecurity Planet Staff

Excerpt:

As part of the continuous monitoring documents, NIST SP 800-137 states that the following are “essential to organization-wide continuous monitoring”:

  1. Ongoing assessment of security controls – Read this as, “Test the stuff you already bought and figure out if it is working.”
  2. Configuration management, change control and a corresponding security impact analyses – In other words, “If you make a change, like standing up a new app, what is the overall effect? Are you more secure or less secure now?”
  3. Security status reporting - When doing this, you need to consider the metrics and reports you are using. Do they reflect the real risks your organization is facing?

Source: eSecurity Planet

Read the full article

Related Content