Overview:Monitor information system security controls on an ongoing basis to ensure the continued effectiveness of the controls. Action Items:3.12.3[a]Determine if: security controls are monitored on an ongoing basis to ensure the continued... Read More
Security Assessment
Overview:Periodically assess the security controls in organizational information systems to determine if the controls are effective in their application. Action Items:3.12.1[a]Determine if: the frequency of security control assessments is defined. 3... Read More
Overview:Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational information systems. Action Items:3.12.2[a]Determine if: deficiencies and vulnerabilities to be addressed by the... Read More
Overview:Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems. Action... Read More