Explain how the orange book is the precursor

Assignment Help Management Information Sys
Reference no: EM131310548 , Length: 4

System Security Certification and Accreditation (CS662 -1604B -01)

Official (ISC)2 Guide to the CAP CBK 2 Howard Taylor & Francis 9781439820766

Individual Project

Deliverable Length: 3-4 Pages, Microsoft Word document

Description:

Throughout this course, you will be working on several aspects of System Security Certification and Accreditation through the following scenario and you will produce a

case study report. Each week, you will complete a part of the report. The final report is due at the end of the course. Additional information and the deliverables for each Individual Project will be provided in the assignment description for the project. This is the course's Key Assignment that you will make contributions to each week.

Scenario

You have just been hired as the security manager of Medical Credentials Company (MCC), reporting to the Chief Information Officer (CIO). MCC is a kind of clearinghouse for doctors, hospitals, and group practices. It stores and distributes information on its clients, including sensitive information on previous malpractice lawsuits or disciplinary action. MCC is converting from an in-house database to a distributed database, which can be queried by telecommuting employees and clients. This change requires a high level of security. It is your responsibility to provide your engineers with the security requirements and at the same time convince senior management that the system being developed is robust and secure enough to protect the this sensitive information. After careful examination of the database requirements and security requirements, you decide that compliance with the current accreditation/authorization process (NIST 800-37 RMF) would sufficiently protect the database from intrusion and tampering.

Project Background

After your initial meeting with the CIO, she is close to agreeing that the database system needs to comply with an accreditation/authorization process. She needs to understand that the Orange Book is the precursor to current methodologies. She understands the general ideas behind the process, but needs you to explain the NIST 800-37 (RMF) process: the different roles and how the process works in six steps.

Assignment Description

Your first task in this project is to review the provided scenario and create the shell for the case study. This case study will be used as the basis for each of the assignments throughout the course. As you proceed through each project phase, you will add content to each section of the final document to gradually complete the final project delivery.

The project deliverables for week 1 are as follows:

?Case Study Report Shell (document detailed below)

?Title page: Should include course name and number, project name, student name, and date

?Table of contents: Auto-generated, in a separate page and should be updated in each phase

?Section headings (Create each heading on a new page with TBD as content except for sections listed under "New content" below.)

?Case Study Outline

?Assurance and the Orange Book

?The DITSCAP Process

?Appendix Development

?The Common Criteria system

?The EAL ratings in the Common Criteria New content (needs to be filled in for phase 1)

?Case Study Outline: Material can be taken from the provided scenario

?Assurance and the Orange Book:

?Explain how the Orange Book is the precursor to current accreditation and authorization methodologies.

?Explain the NIST 800-37 (RMF) process: it's 6 steps and the roles involved in each step.

Reference no: EM131310548

Questions Cloud

Determine time required to raise initially ozone free water : Determine the time required to raise the initially ozone-free water in the pond to a concentration level of 0.15 mol/m3.
How many bacteria will be present after ten minutes : The bacteria Escherichia Coli are commonly found in the human intestines. How many bacteria will be present after 10 minutes? 20 minutes? 30 minutes? 40 minutes? And 60 minutes?
Calculate the density of the exhaust gas : calculate the density of the exhaust gas. How would your solution to this problem change if the engine were attached to the wing of an airplane flying through still air at a velocity of 900 km/h?
Determine the kla for oxygen for new dispenser : Determine the KLa for oxygen for this new dispenser when it is operated 3.2 m below the liquid surface with the air flow rate of 7:08 × 10-3 m3/s.
Explain how the orange book is the precursor : Explain how the Orange Book is the precursor to current accreditation and authorization methodologies. Your first task in this project is to review the provided scenario and create the shell for the case study. This case study will be used as the b..
Discuss the performance of the stock over the last year : Discuss the performance of the stock over the last year and offer your thoughts being specific about why the stock has done well or not.
Determine the location of the maximum acceleration : determine the acceleration, noting the local and convective components; and
Find time that is necessary to raise dissolved oxygen level : Find the time that is necessary to raise the dissolved oxygen level in the wastewater from 8 × 10-2to 2 × 10-1 mmol/L if the temperature of the water is 283 K and the depth of the water above the spargers is 3.2 m.
Determine the user interface which is the most efficient : From the first e-Activity, examine two (2) of the most common reasons that some users are avoiding Windows 8. Determine whether Microsoft has taken any steps to address these user concerns and, provide at least one (1) example if they have taken a..

Reviews

Write a Review

Management Information Sys Questions & Answers

  Characteristics of a general computer system

General computer system security - How do the characteristics of a general computer system

  Explain a software selection process

Software Selection Process - Explain a software selection process for an organization. Describe the evaluation criteria that you would use.

  Project management risk managementrisk management is a

project management risk managementrisk management is a critical aspect of project management. the supply chain

  Design was repeated on two different occasions

Each of the combinations in the design was repeated on two different occasions. The factors studied and the measured response rates are summarized in the following table.

  What are major types of is in organizations

What are the major types of IS in organizations, and how do they help serve the various needs of an organization?

  Important information about hardware and software

Important information about Hardware and Software - Is there away that you could elaborate on the expenditure control of accounting, pertaining to the question?

  Discuss about the solid waste management

In order for engineering in solid waste management to maintain professional autonomy, the public has to trust engineers.However, should the public completely trust and rely on engineers to make the best decisions for the community, or should the pub..

  Compare the two categories of algorithms

Lossless and lossy are the two (2) universally known categories of compression algorithms. Compare the two (2) categories of algorithms, and determine the major advantages and disadvantages of each. Provide one (1) example of a type of data for wh..

  Is the digital divide a major issue within the united

is the digital divide a major issue within the united states or across the globe? if so what are the solutions and the

  Basic technology underlying health care information systems

Analyze the basic technology underlying health care information systems. Argue that the need for technological innovation and / or modification is most pressing. Support the argument with examples

  Price of products after implementing new technologyas

price of products after implementing new technologyas manager of online instructional services ois you receive exciting

  How does an erp system give management control

How does an ERP system like SAP simplify looking up customer numbers, setting a delivery date, and charging a unique price to a given customer? Include a discussion of master data. What is document flow? Why is it important for auditors of a compan..

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd