Question

In: Computer Science

1. Explain the difference between a General Support System, Major Application, and a Minor Application and...

1. Explain the difference between a General Support System, Major Application, and a Minor Application and explain how you determine the accreditation boundary?

2. Explain each of the three different ways to assess a security control and give an example of how each one is used.

3. Explain the 4 phases of assessing security controls.  

Please I need an answer to this..... Thanks!!!

Solutions

Expert Solution

1. General Support System:- It is an interconnected set of information resources under the same direct management control that shares common functionality. It normally includes hardware, software, information, data, applications, communications, and people.A GSS can be, for example, a LAN including smart terminals that supports a branch office, an agency-wide backbone, a communications network, a departmental data processing center including its operating system and utilities, a tactical radio network, or a shared information processing service organization.

Major Application:- A major application is expected under FIPS 199 to have an impact level of moderate or high, as these are more critical systems. Major applications are systems that perform a clearly specified function, for which there are readily identifiable threats.

Minor Application:-Applications which are not deemed major are minor applications. Minor applications inherit most of their security controls from the GSS, or occasionally, the MA if they are part of one. Minor applications can have an impact rating of low or moderate, but if a minor application resides on a system that does not have adequate boundary protection, the minor application must implement the minimum security requirements required by the system.

2.The thee different ways to assess a security control are as follows:-

i) Management security is the overall design of your controls. Sometimes referred to as administrative controls, these provide the guidance, rules, and procedures for implementing a security environment.

ii) Operational Security is the effectiveness of your controls. Sometimes referred to as technical controls, these include access controls, authentication, and security topologies applied to networks, systems, and applications.

iii) Physical security is the protection of personnel, data, hardware, etc., from physical threats that could harm, damage, or disrupt business operations or impact the confidentiality, integrity, or availability of systems and/or data.

3. The 4 phases of assessing a security control arae as follows:-

i) Identify:- It is the process of identifying your digital assets.

ii) Protection:- It includes a variety of processes, from implementing security policies to installing sophisticated software that provides advanced data risk management capabilities.

iii) Implementation:- It includes the adoption of formal policies and data security controls.

iv) Risk Montioring:- Adopting an information risk management framework is critical to providing a secure environment for your technical assets.


Related Solutions

Explain the key difference between a web service application and a general client/server application
Explain the key difference between a web service application and a general client/server application
Road engineering: Explain with diagrams, the concept of the major and minor drainage system approach.
Road engineering: Explain with diagrams, the concept of the major and minor drainage system approach.
1). What is the difference between system and application software ? Give a real life example.
1). What is the difference between system and application software ? Give a real life example.
Discuss the difference between the financial reporting system and general ledger system.
Discuss the difference between the financial reporting system and general ledger system. 
What is the difference between an information system and acomputer application?What is the purpose...
What is the difference between an information system and a computer application?What is the purpose of systems analysis? Why is it important?What is the difference between systems analysis and systems design?What is a project?What is the purpose of the system development life cycle (SDLC)?What are the six core processes of the SDLC?What is meant by Agile development and iterative development?What is the purpose of a System Vision Document?What is the difference between a system and a subsystem?What is the purpose...
What is the major difference between a periodic and perpetual inventory system
What is the major difference between a periodic and perpetual inventory system
1. Explain the difference between General Unemployment rate and the Share of Unemployed persons. 2. What...
1. Explain the difference between General Unemployment rate and the Share of Unemployed persons. 2. What is the difference between CPI and Deflator? example 3.Describe how exchange rate changes affect the country's export and import.
in laws and public affairs, what are the major difference between the British legal system and...
in laws and public affairs, what are the major difference between the British legal system and that of the united states?
Hi, i want 5 (report) conclusions for each topic 1-The application of Bernoulli’s equation 2-Major&Minor Losses...
Hi, i want 5 (report) conclusions for each topic 1-The application of Bernoulli’s equation 2-Major&Minor Losses in Pipes
Explain the major difference between traditional sampling and dollar unit sampling.
Explain the major difference between traditional sampling and dollar unit sampling.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT