TAILIEUCHUNG - security assessment case studies for implementing the nsa iam phần 6

Bạn đang cung cấp chuyên môn để hướng dẫn quá trình ra quyết định của họ. Bạn nên hiểu rằng nếu định nghĩa của bạn thay đổi, bạn sẽ cần phải xem xét lại OICM để xem nếu có các xếp hạng đã thay đổi dựa trên các định nghĩa mới. | Understanding the Technical Assessment Plan Chapter 6 201 Modifying the Nine NSA-Defined Areas One way to customize the TAP is through changes in the composition of the TAP. By default you may not remove sections and still be within the IAM guidelines. The components discussed are considered by NSA to be minimum requirements for any plan to be used in an assessment. If a conflict arises and a section cannot be completed the reasons or events leading to these issues need to be clearly documented. The section will remain but the information detailed will be in regard to the lack of completion not the actual topic itself. Adding sections is entirely up to the customer. Several items may be added as requested or as part of an overall independent business practice. Just a few that can be used to add value to the document are these Executive summaries Summaries can go a long way toward providing descriptions and instructions on how to read and understand the plan. They can also be used to summarize the methodology or provide background into the purpose or goal of this particular assessment. Version history information This can be very useful when dealing with very fluid engagements where change is the standard. In the example in the appendices you ll notice that a version control page was combined with approval authority to demonstrate acceptance and understanding of each change on one simple page. Level of Detail The level of detail is a very important aspect of the IAM TAP. It can depend on many things such as the level of involvement the customer organization wants to have with the assessment process. A hands-on approach may dictate requirements for a very detailed plan as well as increase the chances for multiple revisions down the road. What is included as detail should be based on interactions with the customer. This should be worked out early on in the pre-assessment site visit and an introduction to a sample TAP during initial meetings would not be

Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.