You are an IT auditor trainee at an auditing firm. Cooper & Kumar, a large, publicly traded financial investment firm, is a client. Cooper & Kumar has 25 sites across the region, 2,000 staff members, and thousands of clients. You recently assessed the company’s overall security policy and related documents. One area that was lacking was a description of security controls that apply to data connections from outside the internal network, such as when clients access their investment accounts. Nina, your manager, suggests that you consult the latest versions of NIST SP 800-53 and NIST SP 800-53A as your primary resources to identify relevant controls and assessment objectives. For this assignment: Conduct research on applicable security controls and assessment objectives as described in NIST SP 800-53 and NIST SP 800-53a. For example, consider remote access, session termination, and transmission confidentiality and integrity. Draft a memo to your manager regarding three different security controls that are applicable to the scenario, as well as related assessment objectives as stated in NIST SP 800-53a Cite your research properly.

Database System Concepts
7th Edition
ISBN:9780078022159
Author:Abraham Silberschatz Professor, Henry F. Korth, S. Sudarshan
Publisher:Abraham Silberschatz Professor, Henry F. Korth, S. Sudarshan
Chapter1: Introduction
Section: Chapter Questions
Problem 1PE
icon
Related questions
Question

You are an IT auditor trainee at an auditing firm. Cooper & Kumar, a large, publicly traded financial investment firm, is a client. Cooper & Kumar has 25 sites across the region, 2,000 staff members, and thousands of clients.

You recently assessed the company’s overall security policy and related documents. One area that was lacking was a description of security controls that apply to data connections from outside the internal network, such as when clients access their investment accounts. Nina, your manager, suggests that you consult the latest versions of NIST SP 800-53 and NIST SP 800-53A as your primary resources to identify relevant controls and assessment objectives.

For this assignment:

Conduct research on applicable security controls and assessment objectives as described in NIST SP 800-53 and NIST SP 800-53a. For example, consider remote access, session termination, and transmission confidentiality and integrity.

Draft a memo to your manager regarding three different security controls that are applicable to the scenario, as well as related assessment objectives as stated in NIST SP 800-53a

Cite your research properly. 

 

Expert Solution
trending now

Trending now

This is a popular solution!

steps

Step by step

Solved in 3 steps

Blurred answer
Knowledge Booster
Maintenance
Learn more about
Need a deep-dive on the concept behind this application? Look no further. Learn more about this topic, computer-science and related others by exploring similar questions and additional content below.
Similar questions
  • SEE MORE QUESTIONS
Recommended textbooks for you
Database System Concepts
Database System Concepts
Computer Science
ISBN:
9780078022159
Author:
Abraham Silberschatz Professor, Henry F. Korth, S. Sudarshan
Publisher:
McGraw-Hill Education
Starting Out with Python (4th Edition)
Starting Out with Python (4th Edition)
Computer Science
ISBN:
9780134444321
Author:
Tony Gaddis
Publisher:
PEARSON
Digital Fundamentals (11th Edition)
Digital Fundamentals (11th Edition)
Computer Science
ISBN:
9780132737968
Author:
Thomas L. Floyd
Publisher:
PEARSON
C How to Program (8th Edition)
C How to Program (8th Edition)
Computer Science
ISBN:
9780133976892
Author:
Paul J. Deitel, Harvey Deitel
Publisher:
PEARSON
Database Systems: Design, Implementation, & Manag…
Database Systems: Design, Implementation, & Manag…
Computer Science
ISBN:
9781337627900
Author:
Carlos Coronel, Steven Morris
Publisher:
Cengage Learning
Programmable Logic Controllers
Programmable Logic Controllers
Computer Science
ISBN:
9780073373843
Author:
Frank D. Petruzella
Publisher:
McGraw-Hill Education