Evaluate the weaknesses of each framework

Assignment Help Management Information Sys
Reference no: EM13761231

The National Institute of Standards and Technology (NIST) replaced the former NIST Special Publication 800-37, Guide for the Security Certification and Accreditation of Federal Information Systems with NIST Special Publication 800-37 Revision 1, Guide for Applying Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach. The NIST document changed from a certification and accreditation framework to a risk management framework because information security management systems should be regularly reviewed, updated, and maintained. It makes more sense to follow a security life cycle approach (continuous monitoring) versus a single one-time static certification/accreditation approach.

For this task, you will be using NIST Special Publication 800-37 Revision 1, Guide for Applying Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach and the attached "Healthy Body Wellness Center Risk Assessment" case study.

You have been hired to apply the NIST's risk management framework to the Healthy Body Wellness Center's information systems. You know that the organization has recently had a risk assessment completed that includes recommendations for implementing security controls and mitigating risks. In your new role, a team of people will be assigned to help you with the task. The first job you are tasked with is creating a to-do list for the specific tasks outlined in each of the six steps in the risk management framework (RMF).

Task:

A. Discuss key elements that need to be addressed as part of the risk management framework by completing the attached "RMF To-Do List."

B. Create a white paper that compares the ISO 27002, COBIT, NIST, and ITIL frameworks by doing the following:

1. Discuss how each framework is most commonly used.

2. Analyze the purpose of each framework design.

3. Evaluate the strengths of each framework.

4. Evaluate the weaknesses of each framework.

5. Discuss the certification and accreditation process for the frameworks.

6. Discuss when you would choose to use each framework (e.g., ISO 27002 versus COBIT, NIST, or ITIL).

C. When you use sources, include all in-text citations and references in APA format.

Reference no: EM13761231

Questions Cloud

Describe some of the purposes for doing a data mining : Describe some of the purposes for doing a data mining? Provide some advantages of Data mining with relevant examples
Design a knowledge application system : Design a knowledge application system to support your business needs. Describe the type of system and the foundation technologies that you would use to develop such system. What are some of the intelligent technologies that enable those systems?
What are the key elements of luluemons strategies : What are the key elements of luluemon's strategies? what features of luluemon's strategy stand out as being different from that of other makers of sports apparel (e.g. Nike and Under Armour)?
Market for performance-based yoga and fitness apparel : How strong are the competitive forces confronting lululemon in the market for performance-based yoga and fitness apparel? Use a five-forces analysis to support your answer? What does your strategic group map of the performance sports apparel industry..
Evaluate the weaknesses of each framework : Discuss how each framework is most commonly used. Analyze the purpose of each framework design. Evaluate the strengths of each framework. Evaluate the weaknesses of each framework
Significant challenges associated with facial reconstruction : The bones of the face, or skull as it is sometimes referred to, are there for the purpose of protecting and supporting the entrance to the digestive system and the respiratory system.
Remainder of the outstanding bonds : The remainder of the outstanding bonds is reacquired by exercising the bonds' call feature. In the final analysis, how much was the gain or loss experienced by Hurst in reacquiring its 8% bonds? (Assume the firm used straight-line amortization.) S..
Computer-based training : Computer-based training is more widely used today by both organizations and educational institutions. Discuss the differences between CBT and eLearning in both environments.
Explain marketing communications : Answer the following questions: Explain Marketing Communications in your own words.

Reviews

Write a Review

Management Information Sys Questions & Answers

  Impact the future of hci

Here are some up and coming technologies that could impact the future of HCI

  Describe the rationale for utilizing probability concepts

Describe the rationale for utilizing probability concepts. Is there more than one type of probability? If so, describe the different types of probability

  Iso 9000 standardsusing the iso website and other web

iso 9000 standardsusing the iso website and other web resources identify a situation where iso 9000 standards have been

  Determine the balanced scorecard categories

Determine the balanced scorecard categories that you believe would be appropriate for the honor society.

  Information mobilization and deployment

Information networks as "enterprise glue": information mobilization and deployment - To what degree should organizations depend on the analysis of large databases and other IT resources to formulate basic strategy?

  Impact of technology on gms competitivenessexplain if you

impact of technology on gms competitivenessexplain if you would support mr. szygendas comment regarding how technology

  Step-by-step answer to information systemsfinancial

step-by-step answer to information systemsfinancial information systems can serve many functions in a business.how

  The stages of technology development in technology

the stages of technology development in technology industrydescribe the stages of technology development in technology

  Explain rate of returns - what is the new value for ke

Rate of Returns - What is the new value for Ke and What does this tell you about investors' feelings toward risk based on the new ERP?

  Problem related to insurance policies

Eve's Apples opened business on January 1, 2009, and paid for two insurance policies effective that date. The liability policy was $36,000 for eighteen-months, and the crop damage policy was $12,000 for a two-year term.

  Purchase of a new computer

Purchase of a new computer - Assume you are considering the purchase of a new computer. Use the Internet to access the Web site of the manufacturer of the computer you are considering.

  Provide some detailed information on the following- how

provide some detailed information on the following- how does a business stay ahead of technological advances?- what are

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd