Importance of continuous monitoring of information systems

Assignment Help Management Information Sys
Reference no: EM131455815

Module- Case: CONTINUOUS MONITORING

Assignment Overview

Continuous monitoring is a critical part of risk management process. "Continuous monitoring is ongoing observance with intent to provide warning. A continuous monitoring capability is the ongoing observance and analysis of the operational states of systems to provide decision support regarding situational awareness and deviations from expectations." -Source: Keith Willett (MITRE) in support of the NSA.

"Information Security Continuous Monitoring (ISCM) is defined as maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions." -NIST.

Organizations should establish, implement, and maintain ISCM. ISCM should be a recursive process as its monitoring strategy is continually refined so that ISCM is a robust system. Tiered organization-wide ISCM framework and dynamic ISCM processes are proposed by the National Institute of Standards and Technology. Please scan through the important framework and processes in the following article. Its Appendix D "Technologies for Enabling ISCM" provides some technical and managerial details and examples.

NIST (2011). Information Security -- Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations. National Institute of Standards and Technology Special Publication 800-137.

Additional reference models are also provided and extended to go more in depth both technically and managerially. Please investigate the CAESARS model below and its extension.

DHS (2011). Continuous Asset Evaluation, Situational Awareness, and Risk Scoring Reference Architecture Report (CAESARS). Department of Homeland Security.

Mell, P. (2011) Presentation: An Enterprise Continuous Monitoring Technical Reference Model. Jointly developed by the U.S. National Security Agency, the U.S. Department of Homeland Security, and the National Institute of Standards and Technology.

Assignment Expectations

After reading the above articles, please write a 3- to 5-page paper titled:

"Information Security Continuous Monitoring-Challenges and Solutions"

Please address the following issues in your paper:

1. The importance of continuous monitoring of information systems
2. The technical and managerial challenges of continuous monitoring
3. The technical and managerial solutions to continuous monitoring, including framework, processes, etc.

Reference no: EM131455815

Questions Cloud

Industry news related to the company : Research the industry news related to the company (Kohl's). For example, Apple's price has peaked in 2012 and is steadily declining in 2013.
Discuss about the cohesive evidence-based proposal : Combine all elements completed in previous weeks into one cohesive evidence-based proposal and share the proposal with a leader in your organization.
Find probability of proportion as the sample size increased : Assume that the population proportion is .55. Compute the standard error of the proportion. sp. for sample sizes of 100. 200. 500. and 1000.
What is the new market value : Suppose interest rates rise and pulls the preferred stock yield up to 9% What is the new market value?
Importance of continuous monitoring of information systems : Explain The importance of continuous monitoring of information systems. The technical and managerial challenges of continuous monitoring.
Deposit is made on the day you depart : If your first deposit is made 1 year from today and the final deposit is made on the day you depart? Please Show calculations
What is the fund required rate of return : If the market required rate of return is 14% and the risk-free rate is 6%, what is the fund's required rate of return?
What is the advantage of a larger sample size : The population proportion is .30. What is the probability that a sample proportion will be within ±.04 of the population proportion for each of the following.
Reflective writing proforma : Use the sociological imagination (SI) template to reflect on your feelings, thoughts and behaviours in response to knowledge, experiences

Reviews

Write a Review

Management Information Sys Questions & Answers

  Analyze case study - the cliptomania web storeshow the

analyze case study - the cliptomania web storeshow the strategic issues faced by the company in launching and

  Implement and require extensive organizational change

They cannot provide value if they are implemented atop flawed processes or if firms do not know how to use these systems to measure performance improvements. Employees require training to prepare for new procedures and roles.

  Technology for strategic business processesthe journal

technology for strategic business processesthe journal article is business process integration feasible? provides a

  Define edischargedefine edischarge and its impact on

define edischargedefine edischarge and its impact on patient care management by conducting a costs benefit analysis and

  Discussing current and emerging technologydevelop and

discussing current and emerging technologydevelop and submit an organizational technology plan paper. provide a summary

  Importance of quality management

Quality Management help - Show the importance of quality management and measurement within the global context and Construct control charts to compare global operational processes of the chosen organizations

  Write memo related to technology and computer science

Description - Any Topic with one page (memo) I rather to be one page memo related to technology and computer science or something close to that

  Describe one way that a good project manager

Given today's tough economic client and the trends you see in business and government, which of these four causes do you think are the most significant? Describe one way that a good project manager can help overcome that most significant factor.

  Define processing information systems applications

The use of an enterprise service provider for processing information systems applications such as a payroll, human resources, or sales order taking.

  Why supply chain management is important

Provide at least three reasons why supply chain management is an important part of the value delivery network.

  Crack hash values in order to recover the original word

Given 5 different hash values. Crack those hash values in order to recover the original word that was used to produce those hashes in the first place.

  How do paper plate systems improve efficiency

How do "paper plate" systems improve efficiency?What is state? What is irreproducible state?What are the benefits of moving variations to the end of the process?What are the benefits of IaC?What is idempotency? Why are most CM systems idempotent?

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd