Network Planning and Requirements

profiletwinkletoes
Commentary-IFSM3706381TelecommunicationsinInformationSystems2205.pdf

6/9/2020 Commentary - IFSM 370 6381 Telecommunications in Information Systems (2205)

https://learn.umgc.edu/d2l/le/content/535355/fullscreen/18702385/View 1/12

Module 3: Business Requirements and Risk Management

Topics

1. Needs Analysis and Business Requirements 2. Risk Assessment 3. Risk Management 4. Security

1. Needs Analysis and Business Requirements

A telecommunications requirements analysis involves a systematic evaluation of needs derived from a company's business goals and strategy. The expected outcomes of this analysis are a clear definition of core business needs and a compilation of measurable, testable telecommunications requirements. While there are several methods of categorizing items in a requirements analysis, one simple way involves the classification of functional and nonfunctional system requirements.

Functional requirements are necessary to make the system or component work, while nonfunctional requirements can determine how well the system or component works.

For example, a small software development firm, Mark's Discount Software, plans to acquire office space in a new, fast-growing suburb. Mark's Discount Software wants to make its software products available to a global marketplace, so they are pretty sure they have to be "online," but they also need a way to experiment, test, distribute, and store software before it is ready for Internet distribution. (They may or may not require an internal network—that is part of the requirements analysis.)

The company's development of the software's core features is defined by the functional requirements. The specific type of Internet access, the security protections, the type of web server, and even the company's internal local area network for distributing the information are defined by nonfunctional requirements. Remember, the core software development business can still function without the network, even if the company's software programmers develop the software code on specific computers and distribute physical media to customers by FedEx. The software code would still function.

Important nonfunctional requirements could greatly increase Mark's Discount Software's internal and external software distribution if it had a high-speed data network offered via a telecommunications provider. To sort through the decisions, Mark's Discount Software may choose to hire a consultant to help them translate its business needs into specific telecommunications requirements, or it may contact a local service provider, such as Verizon Business Services, to initiate the process of defining external and internal telecommunications needs. Either choice will set the company on the right path; maintaining separate problem space and solution space is important.

For our discussion of telecommunications, information systems, and infrastructure, the associated requirements are viewed as nonfunctional, derived requirements that must support the functional, business goals of the corporation. Nonfunctional telecommunications requirements are part of the system architecture (think of the architecture of a building), while specific functional requirements drive system design (think of building blueprints).

6/9/2020 Commentary - IFSM 370 6381 Telecommunications in Information Systems (2205)

https://learn.umgc.edu/d2l/le/content/535355/fullscreen/18702385/View 2/12

Therefore, it is important to remember the following:

Business requirements determine telecommunications and network requirements, not vice versa. The clarity of functional and nonfunctional requirements is critical to success analysis. The problem/need/requirement should be separate from the solution. Customers define what needs to be done, and providers determine how it should be accomplished. Business guidance and stakeholder involvement are important keys to successful definition and alignment of strategic goals and opportunities.

Figure 3.1 Separation of Problem Space and Solution Space

Think About It…

A customer may struggle with response time on his computer. To solve the problem, he might self-identify a need for a faster computer or a faster network connection, while the real culprit may be a distant web server limited by high traffic volume, a bottleneck of a proxy server, a limitation on the corporate firewall, or any other remote elements outside of the customer's control.

6/9/2020 Commentary - IFSM 370 6381 Telecommunications in Information Systems (2205)

https://learn.umgc.edu/d2l/le/content/535355/fullscreen/18702385/View 3/12

A faster computer or connection will not make a difference in this customer's network experience, so it is important to understand or uncover the real requirement in order to meet and manage the customer's expectation.

In maintaining separate problem and solution spaces, customers can focus on what they need for their business specialties, while IT professionals can determine how to efficiently and effectively provide solutions. Future collaboration among stakeholders can result in a perspective that accounts for greater adherence to business goals, regulatory constraints, and environmental concerns, but only after the business requirement is clearly understood.

Try this Module 3. Knowledge Check 1 - Please go to My Tools -> Self Assessments -> to complete this self assessment.

2. Risk Assessment

As part of a design or engineering tradeoff, potential telecommunications solutions must factor risk into the overall analysis. For our discussion, IT risk is defined as the probability that a threat agent will act on a vulnerability to cause harm to a business asset.

A risk assessment will assign quantitative or qualitative values to various factors in a given scenario, and as the Committee on National Security Systems (CNSS) National Information Assurance (IA) Glossary defines it, a risk assessment is simply "[t]he process of identifying, prioritizing, and estimating risks (p. 61).

While there is a level of risk in most activities, the assessment allows stakeholders to evaluate potential liability and take proactive measures to minimize their exposure. A risk/reward tradeoff ensures that these factors are analyzed in support of the proposed business solution.

In some cases, a business impact analysis (BIA), which measures a company's ability to sustain business operations under adverse conditions, is conducted prior to the risk assessment. A BIA focused on telecommunications would allow the company to quickly evaluate items such as critical computer networking dataflow, single points of communication failure, or communication requirements for off-site storage. For example, an online business should assign considerable resources to ensure protected, high-availability access to its web server since that is the primary source of communication with customers and the primary method of content distribution.

A BIA allows an evaluator to capture the critical dependence for business operations and permits him or her to recommend a proportionate allocation of resources for assurance of operations. Ultimately, the selection of specific telecommunications solutions will depend on business needs and a variety of factors in the risk assessment.

Figure 3.2 shows the risk assessment process defined in National Institute of Standards and Technology Special Publication 800- 30 (NIST, 2002, p. 9). The more important aspects of the process for this course are the primary risk components: threat, vulnerabilities, and impact.

Figure 3.2 Risk Assessment Methodology Flowchart

6/9/2020 Commentary - IFSM 370 6381 Telecommunications in Information Systems (2205)

https://learn.umgc.edu/d2l/le/content/535355/fullscreen/18702385/View 4/12

Source: National Institute of Standards and Technology. Risk Assessment Methodology Flowchart. NIST SP 800-30.

A review of the steps in figure 3.2 will show the importance of performing a brief risk assessment. Even if the risk assessment is informal, there should be consideration of the major steps involved in this process.

6/9/2020 Commentary - IFSM 370 6381 Telecommunications in Information Systems (2205)

https://learn.umgc.edu/d2l/le/content/535355/fullscreen/18702385/View 5/12

Once the assessment of risk is complete, a strategy of direction and disposition must be conducted to determine the best response. It is important to identify risk before you decide your response strategies. In a classic set of definitions, risk disposition or risk response can be accomplished via four methods:

Table 3.1 Disposition of Risk

1. Avoid the risk. (Since there is usually some risk in everything, totally avoiding risk usually means avoiding the opportunity.)

2. Accept the risk. (If the risk is low enough and there are no feasible options, a stakeholder may have to accept the situation as is, realizing that the risk could occur and harm to the system could result.)

3. Transfer the risk. (Think of an insurance policy to transfer liability.)

4. Mitigate/reduce and manage the risk. (Apply security controls and safeguards, and manage them to meet goals and expectations. This means that the risk is identified, and actions are planned and taken to minimize the occurrence of the risk and harm to the system.)

Much of the work in this course and in many operational environments will require the professional to reduce risk through the implementation of security safeguards in the network. Remember that if you decide to ignore, accept, or transfer the risk, there is no need to "mitigate/reduce and manage the risk" through a risk management process, as described in the next section. You have decided to handle your risk in a different way, so there is no need to implement option 4. However, if you choose to reduce and manage the risk, continued management of these security controls will help ensure the effectiveness of your solution as hardware, software, processes, and information are modified over their life cycles.

Try this Module 3. Knowledge Check 2 - Please go to My Tools -> Self Assessments -> to complete this self assessment.

3. Risk Management

NIST Special Publication 800-30 defines risk management as "the process that allows IT managers to balance the operational and economic costs of protective measures and achieve gains in mission capability by protecting the IT systems and data that support

6/9/2020 Commentary - IFSM 370 6381 Telecommunications in Information Systems (2205)

https://learn.umgc.edu/d2l/le/content/535355/fullscreen/18702385/View 6/12

their organizations" (NIST, 2002, p. 4). Many telecommunications professionals who make, buy, or resell a telecommunications service must also assess, mitigate, and manage the associated risk of their solution.

As discussed earlier, IT risk is characterized as the potential of threat agents to take advantage of vulnerabilities and the impact they could have on a business environment. Practically speaking, a level of risk exists in any complex telecommunications environment, and this assessed risk aligns the mitigation response with the value of the protected information, the cost of the security controls, and the importance of the operational mission.

The higher the possibility that a threat will occur and the greater the impact if it does occur, the more willing the professional should be to take action, spend time and effort, and provide funding to mitigate the risk. For threats that are less likely to occur or will have less impact, less time, effort, and funding might be necessary.

NIST Special Publication 800-30 offers this Sample Safeguard Implementation Plan Summary Table (NIST, 2002, p. C-1):

Table 3.2(a) Sample Safeguard Implementation Plan Summary Table

Risk Risk Level

Recommended Controls

Impact Selected Planned Controls

Required Resources

Responsible Personnel

Start/End Date

Comments

Unauthorized users can telnet to XYZ server and browse sensitive company files with the guestID.

High Disallow inbound telnet Disallow "world" access to sensitive company files Disable the guestID or assign difficult-to- guess password to the guest ID

High Disallow inbound telnet Disallow "world" access to sensitive company files Disabled the guest ID

10 hours to reconfigure and test the system

John Doe, XYZ server system administrator; Jim Smith, company firewall administrator

9-1-2001 to 9-2- 2001

Perform periodic system security review and testing to ensure adequate security is provided for the XYZ server

Source: Adapted from National Institute of Standards and Technology. Sample Safeguard Implementation Plan Summary Table. NIST SP 800-30.

A table like this can be used to assess a variety of risks. For example, we can enter our own data to describe a threat posed to a server by severe weather:

Table 3.2(b) Sample Safeguard Implementation Plan Summary Table

Risk Risk Level

Recommended Controls

Impact Selected Planned Controls

Required Resources

Responsible Personnel

Start/End Date

Comments

XYZ server is located in a data center in the Midwest that is subject to severe weather

Med Install computer in a special hardened facility that is less susceptible to damage

Use the network to send nightly backups to another hardened facility

Med Send nightly backups to another facility

40 hours to establish process, connections for an existing backup facility

John Doe, XYZ system administrator

9-1-2010 to 9-6- 2010

Building/lease costs are too expensive for hardened facilities in this part of the country, so nightly backups are the planned control for this effort.

Adapted from template provided in NIST SP 800-30, Sample Safeguard Implementation Plan Summary Table.

Information security risks in telecommunications can be reduced by the following types of security safeguards:

Encrypt communications channels carrying sensitive or proprietary data. Filter and limit data through corporate firewalls and proxy servers. Increase system availability through the provision of multiple points of presence (POPs) or diversity of routing and switching.

6/9/2020 Commentary - IFSM 370 6381 Telecommunications in Information Systems (2205)

https://learn.umgc.edu/d2l/le/content/535355/fullscreen/18702385/View 7/12

Establish a business continuity plan (BCP) to counter an extended outage for continuity of operations (COOP). Develop a disaster recovery plan (DRP) to handle a more devastating and extended set of circumstances.

Think About It…

Amazon provides a suite of cloud-based web services—for example, Amazon Web Services (AWS)' Simple Storage Service (S3) and Elastic Compute Cloud (EC2)— that can host or support a company's Internet activities in a controlled, scalable, virtual environment. A business's internal IT tasks of processing, data storage, archiving, internal networking, testing and evaluation, provisioning, managing, monitoring, and so forth, become the responsibility of Amazon.

Amazon's processes, economies of scale, and efficiency of operation allow it to offer much lower costs than its competitors for these resizable, virtual hosting services. While the type of service must be tailored to ensure regulatory and legal compliance for a specific country and industry, these services can be handled by the cloud service. In using this service, a company can hand over the bulk of its operations to Amazon, but this automatically makes Amazon a part of the business impact analysis and risk assessment. Since the cloud service is now the primary source of a company's operations, any Internet business relying extensively on the Amazon cloud must factor alternative methods of support and operation in the risk assessment in case Amazon fails.

On April 21, 2011, Amazon Web Services suffered an unplanned outage that left popular social media companies like Reddit, Quora, and Foursquare without complete business service for several days. A postmortem of the Amazon event showed that a network configuration error was the trigger for the outage (Amazon, 2011).

This risk occurrence shows that companies must plan for failure in the development of the business impact analysis or risk assessment. They must have workable plans of recovery. Companies need to understand how major components, services, and processes impact business operations, and they must implement automatic switchover (in the event of a failure to the cloud), employ alternate providers, and periodically test backup plans to ensure higher availability.

Figure 3.3 Risk Management Framework

Source: National Institute of Standards and Technology. Risk Management Framework. NIST SP 800-37.

NIST Special Publication 800-37 provides guidance for applying risk management to IT systems in a structured framework by documenting the many elements required to make a risk management decision (NIST, 2010, p. 8). The six major steps of this NIST framework, as shown in figure 3.3, contain lower levels of detail, but it is important to understand how the results of the risk assessment—along with architecture and organizational inputs—trigger the initial phases of this risk management framework.

Here are some important points:

6/9/2020 Commentary - IFSM 370 6381 Telecommunications in Information Systems (2205)

https://learn.umgc.edu/d2l/le/content/535355/fullscreen/18702385/View 8/12

All external exploits, and many internal exploits, use the network to transfer illicit code, transport malware, and invoke illegal instructions and related functions. A risk assessment must be performed. The risk assessment is based on the business goals, needs, and requirements of the company; it leads to a separate solution space for identifying and implementing economically balanced security safeguards. In many situations, the disposition of risk will be accomplished through mitigation; this involves selecting, implementing, and assessing specific security controls (see figure 3.3 and table 3.1). The authorization (or permission) to operate an information or telecommunications system is a critical management decision in the risk management framework. The continuous monitoring task ensures that timely hardware, software, or process updates are appropriately made in the product/system life cycle.

Try this Module 3. Knowledge Check 3 - Please go to My Tools -> Self Assessments -> to complete this self assessment.

4. Security

Security safeguards in the enterprise protect telecommunications channels, minimize successful hacker attacks, and create infrastructures to enhance enterprise-level security. More specifically, the safeguards protect information during transit, storage, or processing (traditional IT) by keeping the information private, unaltered, and accessible for authorized users. The information security services of confidentiality (privacy), integrity (lack of alteration) and availability (accessibility) ensure that information is secure at the customer's level of expectation for telecommunications, information systems, or supporting infrastructure.

Communications Security

Any business should ensure that sensitive and proprietary data remain private. From evaluating the results of a risk assessment to applying the risk management framework, specific communications security controls are identified and implemented to reduce the network risk to a reasonable and acceptable level.

Communications security protects wired/cable and wireless (radio) channels in a variety of telecommunications environments, information types, and data formats. Much of the information traversing the telecommunications landscape is supported by the packet-based Internet Protocol (IP) data network, but other data formats and transport mechanisms exist. Mobile cellular networks, wireless local networks, and traditional landline networks are separate telecommunications infrastructures that use various standards and formats at the lower end of the OSI reference model to group, organize, and transport IP data to various end-user devices. Formats and standards at the higher end of the OSI model ensure that data are prepared for network applications and the end user. The common use of the IP packet in the network layer allows standard techniques for securing sensitive, private information across multiple platforms, systems, and infrastructures.

The confidentiality of IP communications is usually provided through a process of encryption that makes the data unreadable. This scrambling of data occurs in wireless LAN transmissions, secure Internet connections, e-commerce, some private e-mail transmissions, and other areas where privacy is extremely important. If you want to keep data from snooping eyes, you encrypt it.

For example, in a telecommunications and networking environment, a company's personnel file or payroll data could be transported through multiple networks (e.g., from the payroll processor's network through the Internet to Company B's network), so the information is virtually and physically out of the originator's control. A skilled hacker could capture the data at multiple points of transit and read the contents without the sender or receiver having knowledge of the interception. Therefore, to make it more difficult for would-be hackers, network encryption scrambles the data so only the sender and intended recipients can easily read the information.

Technical Dive

Systems Security

While communications security supports data in transit, there are equally important features and security controls for servers and end-user computing devices. Since these devices are the access points for the network, they are also important to the security of the network.

Information systems in a networked environment require a variety of security features to ensure that an authorized user has appropriate access to the set of protected data required for the user to perform a task. These security controls are growing in importance as more consumers access the Internet from a growing array of devices such as smartphones, tablets, gaming platforms, and nontraditional devices (e.g., kitchen appliances). As with communications security, encryption is also important for

6/9/2020 Commentary - IFSM 370 6381 Telecommunications in Information Systems (2205)

https://learn.umgc.edu/d2l/le/content/535355/fullscreen/18702385/View 9/12

stored, sensitive data, especially as laptops and other mobile devices contain a growing amount of personal privileged information and business secrets that criminals may acquire and transmit to other users in support of a broader attack. Limiting access to servers and end-user devices through authentication services (e.g., username/password) helps preserve overall system security and the integration of communications security.

For instance, botnets are groups of compromised systems that can be used by a hacker not only to commit crimes, but also to limit the availability of target systems via distributed denial of service (DDoS) attacks. System authentication can be provided via multiple mechanisms, such as passwords or biometrics using preferred multifactor variables defined by

something the user uniquely knows something the user uniquely has something the user inherently and uniquely is

Ensuring high information system availability has distinct security concerns that are difficult to achieve for system or communications security components when they are handled independently. The integration of communications security, information systems, and underlying infrastructure is critical to the success or failure of cybersecurity initiatives. The importance of business needs, risk assessment, and security controls culminates in the integration of infrastructure services.

Think About It…

Providing total system security is a difficult task for any company serving a largely anonymous global community. Without an accurate and trustworthy verification system for entities, hiding in anonymity or masquerading through identity theft becomes easy for those willing to engage in system abuse/misuse or criminal activity. While Internet companies desire clients to use a particular product or service in an intended way, it is difficult to fully restrict user access when software and firmware features are involved.

For instance, the Sony PlayStation Network attack and breach initiated between April 17 and April 19, 2011, forced a outage of this service for one month, denying access to online gaming and delivery of digital content (e.g., movies, chat, and social networking) for approximately 77 million registered accounts (Galnate, J., Kharif, O., & Alpeyev, P., 2011). The irony of this situation is the alleged use of Amazon's cloud service, Elastic, to perpetrate the attack. This hack illustrates the dilemma faced by businesses and service organizations as they attempt to balance terms of use, potential service misuse, and potential liability for both legitimate and illegal use.

A significant portion of Sony's technical response had to involve a holistic review of the integrated action of servers, communications, infrastructure services, and policies used to provide PlayStation Network service. Since the user accounts and end systems are part of the integrated activities, both firmware and authentication/passwords are end-user activities likely to help secure the integrated network.

Infrastructure Security

Infrastructure is often taken for granted; we don't think about it until it's not working. A clogged pipe or a frayed electrical wire in your home may not be seen, but you will find out about it when water backs up in the sink or a lamp doesn't work.

For consumers, infrastructure just works, but there is a lot of activity behind the scenes that keeps that infrastructure working safely and securely. The telecommunications security infrastructure for a business can comprise corporate firewalls, intrusion protection services (IPS), public key infrastructures (PKI), antivirus software, etc.—items designed to identify and negate malicious network traffic. Through the use of common infrastructure services, a large business can define a stronger and more centralized security posture. From this perspective, potential risks and threats can be easily categorized, current status can be more easily monitored, and attacks or other security incidents can receive a more holistic response instead of a fragmented one.

As a provider (or consumer) of infrastructure services, some points for you to consider are:

Which information systems compose the enterprise infrastructure? Have protections been applied to protect all information systems and the network infrastructure? What level of compliance, audit, or regulatory concern is required for the business, operating environment, or location? What are the roles and responsibilities of people accessing restricted data (e.g., payroll, human resources, trade secrets, etc.)? How are the systems, network, and infrastructure monitored and managed? Are there defined rules for configuration/change management of any network-enabled devices?

Figure 3.4 Implementation of Security Controls (System, Infrastructure, and Network)

in the Risk Management Framework

6/9/2020 Commentary - IFSM 370 6381 Telecommunications in Information Systems (2205)

https://learn.umgc.edu/d2l/le/content/535355/fullscreen/18702385/View 10/12

Source: National Institute of Standards and Technology. Risk Executive Function. NIST SP 800-37.

Figure 3.4 illustrates the complete set of security activities centered on the risk management framework and the associated approvals (e.g., authorization decisions) to operate those systems securely (NIST, 2010, p. 17). The basic premise behind the diagram is that security controls must be designed at the outset; risk must be assessed and mitigated; security controls (network, system, and infrastructure) must be implemented, assessed, and verified; and finally, all aspects must be continuously managed to provide a complete solution. The security controls depicted in this diagram provide confidentiality, integrity, and availability functions, and are directly applied to networks, information systems, and infrastructure. The major consideration in this diagram is the holistic integration of multiple types of security controls and a structured approach to ensure that all controls are continuously monitored in the risk management framework.

This must be designed and implemented in a cost-effective manner, and security controls must be balanced against the operational mission and assets they are protecting. Security controls should not be developed and implemented independently of the business's scope and needs; controls should be balanced against the value of the assets they are protecting. While it is bad business to protect data worth one dollar with a million-dollar firewall, it is equally bad to protect a million dollars' worth of data with a one-dollar firewall. In the context of this module, figure 3.4 illustrates:

1. System controls that are specific to certain computers. 2. Common (e.g., infrastructure security) controls that are inherited by the organization at a corporate level. 3. Network controls are either hybrid controls (i.e., they affect multiple components, such as the HR department firewall), or

they are common controls that affect all systems.

A company's internal IT infrastructure requires significant resources for development, implementation, operation, management, and maintenance throughout its life cycle. Many large companies have their own staff, equipment, networks, backup facilities, etc., to support business operations via highly reliable and secure network infrastructure services. However, some companies are selecting another solution to the business problem of infrastructure services by choosing cloud services. (Note: Companies still need to perform a risk assessment and possess a risk management plan for services outside their immediate control.)

Cloud services can be described as one of several ways to subscribe to an IT service and pay only for what is required. For instance, people regularly subscribe to specific content via really simple syndication (RSS) feeds or through a publisher's range of magazines; it is the consumer's choice, not the publisher's, what the customer receives. Similarly, the flexibility and low cost of cloud services are very appealing to a wide range of companies. Categories of cloud services such as software as a service

6/9/2020 Commentary - IFSM 370 6381 Telecommunications in Information Systems (2205)

https://learn.umgc.edu/d2l/le/content/535355/fullscreen/18702385/View 11/12

(SaaS), platform as a service (PaaS), and infrastructure as a service (IaaS) are clearly poised to provide economic benefits, quality of service, and security features to companies of various sizes.

Companies with sensitive data are still faced with a difficult choice of whether to maintain their current internal infrastructures, or to use some cloud services. There are still regulatory and compliance concerns for international data, especially when there are restrictions on physical storage locations. There are also internal security concerns associated with the accidental mixing of data or potential leakage of corporate secrets. There could be legal liability issues, too, if the leakage of data causes harm to consumers, as in the case of credit card numbers being exposed. A thorough analysis of business needs and requirements should be conducted prior to using the public cloud, and multiple elements must be accounted for in the final analysis and choice.

Try this Module 3. Knowledge Check 4 - Please go to My Tools -> Self Assessments -> to complete this self assessment.

Module Summary

The following ideas and concepts were covered in this module:

Business needs drive the focus of the company and the supporting IT requirements (functional and nonfunctional). Risk is the probability of a threat agent taking advantage of vulnerabilities and the resulting impact (harm) to the system. Risk is an important concept that must be factored into IT solutions and decisions. Risk management involves identifying and assessing risk in specific environments. Risk can be handled by

accepting the risk ignoring the risk transferring the risk mitigating the risk via security controls

Security controls may be applied to information systems, networks, and/or infrastructure, but the best method involves a holistic security approach. Many security controls for telecommunications, information systems, and infrastructure are designed to protect the information's

confidentiality integrity availability

A holistic approach to information security examines the interdependent and integrated relationship of computer networking, information systems, and security infrastructure. Furthermore, it examines how these factors are affected by the needs of the business in a risk-managed environment. The cost of providing this entire set of functions is driving many businesses to use cloud services.

References

Amazon. (2011). Summary of the Amazon EC2 and Amazon RDS Service Disruption in the US East Region. Retrieved June 17, 2011, from http://aws.amazon.com/message/65648/

Committee on National Security Systems. (2010). Committee on National Security Systems national information assurance (IA) glossary. Retrieved June 17, 2011, from http://www.cnss.gov/Assets/pdf/cnssi_4009.pdf

Galnate, J., Kharif, O., & Alpeyev, P. (2011). Sony network breach shows Amazon cloud's appeal for hackers. Bloomberg. Retrieved June 17, 2011, from http://www.bloomberg.com/news/2011-05-15/sony-attack-shows-amazon-s-cloud-service-lures- hackers-at-pennies-an-hour.html

National Institute of Standards and Technology. (2002). Special Publication 800-30: Risk management guide for information technology systems. Gaithersburg, MD: Department of Commerce, NIST. Retrieved June 17, 2011, from http://csrc.nist.gov/publications/nistpubs/800-30/sp800-30.pdf

National Institute of Standards and Technology. (2010). Special Publication 800-37: Guide for applying the risk management framework to federal information systems: A security life cycle approach. Gaithersburg, MD: Department of Commerce, NIST. Retrieved June 17, 2011, from http://csrc.nist.gov/publications/nistpubs/800-37-rev1/sp800-37-rev1-final.pdf

Image Credits

National Institute of Standards and Technology. (2010). Risk executive function. Special Publication 800-37: Guide for applying the risk management framework to federal information systems: A security life cycle approach. p. 17. Gaithersburg, MD: Department of Commerce, NIST. Retrieved June 17, 2011, from http://csrc.nist.gov/publications/nistpubs/800-37-rev1/sp800- 37-rev1-final.pdf

6/9/2020 Commentary - IFSM 370 6381 Telecommunications in Information Systems (2205)

https://learn.umgc.edu/d2l/le/content/535355/fullscreen/18702385/View 12/12

National Institute of Standards and Technology. (2010). Risk management framework. Special Publication 800-37: Guide for applying the risk management framework to federal information systems: A security life cycle approach. p. 8. Gaithersburg, MD: Department of Commerce, NIST. Retrieved June 17, 2011, from http://csrc.nist.gov/publications/nistpubs/800-37-rev1/sp800- 37-rev1-final.pdf

National Institute of Standards and Technology. (2002). Risk assessment methodology flowchart. Special Publication 800-30: Risk management guide for information technology systems. p. 9. Gaithersburg, MD: Department of Commerce, NIST. Retrieved June 17, 2011, from http://csrc.nist.gov/publications/nistpubs/800-30/sp800-30.pdf

National Institute of Standards and Technology. (2002). Sample safeguard implementation plan summary table. Special Publication 800-30: Risk management guide for information technology systems. p. C-1. Gaithersburg, MD: Department of Commerce, NIST. Retrieved June 17, 2011, from http://csrc.nist.gov/publications/nistpubs/800-30/sp800-30.pdf

Return to top of page

Report broken links or any other problems on this page.

Copyright © by University of Maryland University College.