Question

In: Computer Science

During system/ asset classification, should we think about risk first or categorizing? What process should be...

During system/ asset classification, should we think about risk first or categorizing? What process should be followed to categorize the systems?

Solutions

Expert Solution

I would suggest to identify first the risk before categorizing since it allows you to create a comprehensive understanding that can be leveraged to influence stakeholders and create better project decisions.  Good risk identification creates good project communication and good communication creates good decisions. It is the foundation of good risk management and no fancy tool or spreadsheet will overcome poor risk identification.

In order to determine the system security category, the information owner/information

system owner collects relevant documentation specific to the information system such as the system description and architecture. In addition, the information owner/information system owner also collects any available guidance documentation issued by the organization. The information owner/information system owner establishes working relationships with others within the organization who are also impacted by the categorization decision such as the information security program office, the enterprise architecture group, information sharing partner .

Prior to categorizing an information system, the information owner/information system

owner collects available documentation on the information system. While the details of a new information system may not be known, sufficient information should be available to begin to identify the types of information that will be processed, stored, or transmitted by the system such as system description, concept of operations, typically documented in the initial system security plan.


Related Solutions

In system/ asset classification, what would be the actual risk associated with compromise of different system...
In system/ asset classification, what would be the actual risk associated with compromise of different system types? Would you allocate protection/detection resources differently based on categorization?
2.1) Aged care risk classification system
2.1) Aged care risk classification system
Do you think that gender should be taken into consideration in the hiring process? What about...
Do you think that gender should be taken into consideration in the hiring process? What about when assessing a company’s risk appetite?
What information does the operating system need to store about a running process? (Think of 4...
What information does the operating system need to store about a running process? (Think of 4 or 5 different things.)
1-risk and portfolio How we decrease the risk in a portfolio? What actions should we follow?...
1-risk and portfolio How we decrease the risk in a portfolio? What actions should we follow? 2-investor and stock markets What is the biggest fear for an investor? In your opinion, what is it that should bother the investor the most?
This is a discussion question for global technology. You should think about the SYSTEM of technology....
This is a discussion question for global technology. You should think about the SYSTEM of technology. how is it created, maintained, implemented? are there issues of power? Is there anything problematic about a society that is based solely on services? Are there any issues related to not having, or losing, the knowledge or capacity to produce goods; i.e. manufacturing? Issues of stability? Negotiating with partners? Do they lose, or give up, any power? Please provide a thourough, contemplative response, at...
1. Do you think the US should continue to use the first-past-the-post electoral system or should...
1. Do you think the US should continue to use the first-past-the-post electoral system or should we use a different system, such as a rank choice voting system? Explain your answer.
When most of us think of Amazon, we think about what we, as consumers, can buy...
When most of us think of Amazon, we think about what we, as consumers, can buy there— currently, just about anything. But Amazon is much more than just a company that supplies consumers with books, household products, clothing, and so forth. Describe Amazon's business-to business (B2B) transactions.
Agents of socialization teach us ways that we should act and think about ourselves, but they...
Agents of socialization teach us ways that we should act and think about ourselves, but they also teach us how we should think about and act toward others. What kinds of messages did you receive from different agents of socialization about gender? What did you learn about boys and girls and from where did you learn these messages? What about race? What kinds of messages did you receive about white people? Black people? Asian? Hispanic?
Do you think we should be worried about the size of the federal debt? Why or...
Do you think we should be worried about the size of the federal debt? Why or why not?
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT