Continuous Monitoring-slp

profilejimmylb1234
SLP2.docx

The following example demonstrates how to apply the continuous monitoring technical reference model to a risk management domain. Please read the following article and identify a few key lessons learned from it in relation to what principles and methods you have learned in the Case Assignment.

NIST (2018). The Technical Specification for the Security Content Automation Protocol (SCAP)

Practicing continuous monitoring fundamentals, processes, etc., to one's own experiences offers an opportunity to apply what you've learned to the real world. Select an information system security domain of your organization or industry and apply what you learned from the case readings and SLP examples. You can choose to assess comprehensively, or you can focus on two or three major perspectives and go much more in depth. You can choose the same security domain in the previous SLP assignment in this course or start with a new one.

SLP Assignment Expectations

Write a 3 to 5 page paper titled:

"Continuous Monitoring for ______ (your chosen information system security domain in your chosen organization/industry): Challenges and Solutions"

Address the following issues:

· Special requirements of continuous monitoring in your chosen information system security domain in your chosen organization/industry if there are any.

· Two perspectives of continuous monitoring that you select for an in-depth discussion.

· One or two major lessons learned from the example that you will apply in your own continuous monitoring issue here.

· Key challenges and solutions of continuous monitoring

Background Readings:

Chapple, M., Stewart, J. M., and Gibson, D. (2018) Certified information systems professional study guide, 8th edition, Sybex Chapters 1-4. ISBN: 9781119475934. Books 24/7 version. Available in the Trident Online Library.

Gregory, P. H. (2018). CISM certified information security manager all-in-one exam guide. McGraw-Hill/Osborne, Chapter 5. ISBN: 9781260027037. Books 24/7 version. Available in the Trident Online Library.

NIST (2011). Information Security -- Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations.  National Institute of Standards and Technology Special Publication  800-137.

Oniha, A., Weaver, G., Arnold, C. and Shreck, T. (2017). Information security continuous monitoring. Journal of Cyber Security and Information Systems. 5(1). https://www.csiac.org/journal-article/information-security-continuous-monitoring-iscm/

Snedaker, S. and Rima, C. (2014, 2nd ed. Syngress Publishing, ISBN:9780124105263. Chapters 6-8. Books 24/7 version. Available in the Trident Online Library.