Security Assessment: Case Studies for Implementing the NSA IAM

Course

Distance

£ 47 + VAT

Description

  • Type

    Course

  • Methodology

    Distance Learning

This book shows how to do a complete security assessment based on the National Security Agency's (NSA) INFOSEC Assessment Methodology (IAM).

Questions & Answers

Add your question

Our advisors and other users will be able to reply to you

Who would you like to address this question to?

Fill in your details to get a reply

We will only publish your name and question

Emagister S.L. (data controller) will process your data to carry out promotional activities (via email and/or phone), publish reviews, or manage incidents. You can learn about your rights and manage your preferences in the privacy policy.

Reviews

Course programme

Description
This book shows how to do a complete security assessment based on the National Security Agency's (NSA) INFOSEC Assessment Methodology (IAM).

Program

The National Security Agency's INFOSEC Assessment Methodology (IAM) provides guidelines for performing an analysis of how information is handled within an organization: looking at the systems that store, transfer, and process information. It also analyzes the impact to an organization if there is a loss of integrity, confidentiality, or availability.

This book shows how to do a complete security assessment based on the NSA's guidelines . This book also focuses on providing a detailed organizational information technology security assessment using case studies. The Methodology used for the assessment is based on the National Security Agency's (NSA) INFOSEC Assessment Methodology (IAM).

Examples will be given dealing with issues related to military organizations, medical issues, critical infrastructure (power generation etc). The book is intended to provide an educational and entertaining analysis of an organization, showing the steps of the assessment and the challenges faced during an assessment. It also provides examples, sample templates, and sample deliverables that readers can take with them to help them be better prepared and make the methodology easier to implement.

Overview of the Book:
  • Define What Composes an Assessment
    Learn about the NSA's three-phases: Assessment, Evaluation, and Red teaming
  • Understand Industry Concerns for the Assessment Site
    Review the items that affect your client: including US legislation such as the Health Insurance Portability and Accounting Act of 1996 (HIPAA), Sarbanes-Oxley, Financial Management and Accountability (FMA) Act, Family Education Rights and Privacy Act (FERPA), and others.
  • Create the Organizational Information Criticality Matrix (OICM)
    Create the OICM, which provides a basis for everything else in the methodology and clarifies the intentions and goals of the assessment process for the customer.
  • Handle Documentation Identification and Collection
    Work with the client to gather and define documents such as policy, guidelines, plans, SOPs, user documentation and see what happens when no documentation exists.
  • Understand the Technical Assessment Plan (TAP)
    Use the TAP to define all dates and scheduling, personnel involvement, understood boundaries, deliverables, priority concerns, and priority constraints.
  • Review the 18 NSA INFOSEC Baseline Classes and Categories
    Use these 18 categories to address the customer's security posture and determine what questions should be asked during the interview process.
  • Create a Recommendation Road Map
    Provide the customer with a road map to the best way to address or implement the corrective measures for negative findings.
  • Understand the Findings
    Assess the overall risk to a customer by looking at the threats, vulnerabilities, and asset value and analyze both negative and positive findings to create a true picture of the customer's security posture.
Authors: Russ Rogers, Greg Miles, Ed Fuller, Ted Dykstra
Publisher: Syngress Press
Format: Soft Cover
ISBN 10: 1932266968
ISBN 13: 9781932266962
Pages: 448
Published Date: Jan 2004
Availability: Ex Stock

Order today for immediate despatch!

Security Assessment: Case Studies for Implementing the NSA IAM

£ 47 + VAT