Risk Assessment & Incident Response Paper
NASA Cybersecurity Audit Review
Agenda
Overview
Summary of findings
High Risk Review
Recommendations
Recommended COTS products
References
Information Security and Risk Management
Overview/Mission
Information Security and Risk Management
Summary of findings
Information Security and Risk Management
High Risk Review - Authentication
Information Security and Risk Management
Recommendations
Information Security and Risk Management
Recommended COTS products
Information Security and Risk Management
Recommended Controls Description
SA - System and Service Acquisition Control Family
SA-5: Information System Documentation
CM - Configuration Management Control Family
CM-1: Configuration Management P&P’s
CM-6: Configuration Settings
CM-8: Information System Component Inventory
CM-10: Software Usage Restrictions
CM-11: User Installed Software
PL- Planning Control Family
PL-1: Security Planning and Procedures
PL-2: System Security Plan
MP - Media Protection Control Family:
MP-5(3): Media Protection - Custodians
PM - Program Management Control Family
PM-5: Information System Inventory
RA - Risk Assessment Control family
RA-5(5): Vulnerability Scanning - Privileged access
IA - Identification and Authentication control family
IA-5: Authenticator Management
Information Security and Risk Management
References
NIST SP 800-53 (rev 4) [nvd.nist.gov]
CWE-287: Improper Authentication [cwe.mitre.org]
CVE-2009-3421 [cve.mitre.org]
Authentication [msdn.microsoft.com]
NASA [nasa.gov/content/nasa-history-overview]
Information Security and Risk Management