As a staff member supporting the ciso you have been asked


Project: System Security Plan

Company Background & Operating Environment -

The assigned case study and attachments to this assignment provide information about "the company."

  • Use the Baltimore field office as the target for the System Security Plan.
  • Use Verizon FiOS as the Internet Services Provider.

Policy Issue & Plan of Action -

A recent risk assessment highlighted the need to formalize the security measures required to protect information, information systems, and the information infrastructures for the company's field offices. This requirement has been incorporated into the company's risk management plan and the company's CISO has been tasked with developing, documenting, and implementing the required security measures. The IT Governance board also has a role to play since it must review and approve all changes which affect IT systems under its purview.

The CISO has proposed a plan of action which includes developing system security plans using guidance from NIST SP-800-18 Guide for Developing Security Plans for Federal Information Systems. The IT Governance board, after reviewing the CISO's proposed plan of action,voted and accepted this recommendation. In its discussions prior to the vote, the CISO explained why the best practices information for security plans from NIST SP 800-18 was suitable for the company's use. The board also accepted the CISO's recommendation for creating a single System Security Plan for a General Support Systemsince, in the CISO's professional judgement, this type of plan wouldbest meet the"formalization" requirement from the company's recently adopted risk management strategy.

Your Task Assignment -

As a staff member supporting the CISO, you have been asked to research and then draft the required system security plan for a General Support System. In your research so far, you have learned that:

  • A general support system is defined as "an interconnected set of information resources under the same direct management control that shares common functionality." (See NIST SP 800-18)
  • The Field Office manager is the designated system owner for the IT support systems in his or her field office.
  • The system boundaries for the field office General Support System have already been documented in the company's enterprise architecture (see the case study).
  • The security controls required for the field office IT systems have been documented in a security controls baseline (see the controls baseline attached to this assignment).

Research:

1. Review the information provided in the case study and in this assignment, especially the information about the field offices and the IT systems and networks used in their day to day business affairs.

2. Review NIST's guidance for developing a System Security Plan for a general support IT System.  This information is presented in NIST SP 800-18.

3. Review the definitions for IT Security control families as documented in Federal Information Processing Standard (FIPS) 200: Minimum Security Requirements for Federal Information and Information Systems(see section 3).

4. Review the definitions for individual controls as listed in Appendix F Security Control Catalog in NIST SP 800-53 Security and Privacy Controls for Federal Information Systems and Organizations.

Attachment:- Assignment Files.rar

Request for Solution File

Ask an Expert for Answer!!
Computer Network Security: As a staff member supporting the ciso you have been asked
Reference No:- TGS02464906

Expected delivery within 24 Hours