Preview

Iscm Strategic Plan

Good Essays
Open Document
Open Document
1276 Words
Grammar
Grammar
Plagiarism
Plagiarism
Writing
Writing
Score
Score
Iscm Strategic Plan
The objectives of the DOC ISCM Strategic Plan include the following:
• Help drive the U.S. Government continuous monitoring vision through strategic milestones that can be progressively and methodically achieved;
• Delineate roles and responsibilities for the successful realization of continuous monitoring throughout the Department;
• Communicate the projected timeframes, outcomes, end–states, and benefits of continuous monitoring;
• Ensure balance and alignment of technical and non–technical processes, both of which are fundamental for the successful operationalization of continuous monitoring;
• Promote a common language for prioritizing continuous monitoring implementation stages; a systematic structure to guide, track, and measure
…show more content…
are often requested by organization officials such as the Risk Executive, CIO, CISO, and AO as well as by external Federal entities such as DHS and OMB, because they provide a holistic view of the security posture of the organization and measure the effectiveness of the program. The ISCM Program team will define metrics and security controls that align with their information security goals and identify improvements to the security posture of the systems. Metrics and controls should include security-related information from security status monitoring and security status assessments and support risk-based decision making. Moreover, the measurement and reporting schedule will need to be adjusted accordingly as the program matures and as additional requirements are identified. Current ECMO metrics as outlined in the table below will serve as a starting point. The ISCM integrated project team will continue to develop relevant and measurable metrics that support reporting through an executive level CDM dashboard. Additional information on security controls can be found in Appendix B. The dashboard will summarize security metrics and reporting while continuously providing trend analysis for the organization, and give management the ability to see the progress or regression of a given system within the cybersecurity continuous monitoring …show more content…
To the extent possible, organizations should identify, report, and remediate vulnerabilities in a coordinated, organization-wide manner using automated vulnerability and patch management tools and technologies. Vulnerability scanners are commonly used in organizations to identify known vulnerabilities on hosts and networks and on commonly used operating systems and applications. These scanning tools can proactively identify vulnerabilities, provide a fast and easy way to measure exposure, identify out-of-date software versions, validate compliance with an organizational security policy, and generate alerts and reports about identified

You May Also Find These Documents Helpful

  • Powerful Essays

    IS3110 U5L1

    • 912 Words
    • 4 Pages

    One of the most important first steps to risk management and implementing a security strategy is to identify all resources and hosts within the IT infrastructure. Once you identify the workstations and servers, you now must then find the threats and vulnerabilities found on these workstations and servers. Servers that support mission critical applications require security operations and management procedures to ensure C-I-A throughout. Servers that house customer privacy data or intellectual property require additional security controls to ensure the C-I-A of that data. This lab requires the students to identify threats and vulnerabilities found within the Workstation, LAN, and Systems/Applications Domains.…

    • 912 Words
    • 4 Pages
    Powerful Essays
  • Good Essays

    Strategic Plan Part I

    • 646 Words
    • 3 Pages

    Vantage West Credit Union has become a full-service financial institution, offering a wide array of personal and business accounts, ranging from savings and checking accounts, to loans, mortgages, merchant services, and consumer credit cards. The mission statement is “People helping people achieve their financial goals...our #1 priority.” Vantage West serves its members through its branches, online banking system and call center.…

    • 646 Words
    • 3 Pages
    Good Essays
  • Satisfactory Essays

    NT2580

    • 526 Words
    • 5 Pages

    Common security countermeasures typically found in an IT infrastructure  Risk assessment approach to securing an IT infrastructure  Risk mitigation strategies to shrink the information security gap NT2580 Introduction to Information Security © ITT Educational Services, Inc. All rights reserved. Page 3 EXPLORE: CONCEPTS NT2580…

    • 526 Words
    • 5 Pages
    Satisfactory Essays
  • Better Essays

    The review results were positive with a suggestion for an improvement. The team found that RedSeal product provides the intelligence necessary to improve defenses, maintain continuous compliance and mitigate real-world risks by identifying the available paths of access and exposed vulnerabilities present across a network (Stephenson, 2012). The RedSeal solution is either a hardware appliance or software product and is architected for a fast and efficient means of implementing the system (Stephenson, 2012). The design will provide the most secure, scalable, and dependable deployment possible (Stephenson, 2012). Continuous monitoring focuses on correlating IT, network, and vulnerability feeds (Stephenson, 2012). The system identifies risk associated with the business’s security effectiveness as opposed to policy and compliance driven tools (Stephenson, 2012). RedSeal provides a large library of supported vendor products, allowing security and vulnerability data to be quickly and easily imported into the system. The system automatically builds network maps and correlates the map data with configuration and vulnerability data, which creates a threat reference library. RedSeal finds and eliminates gaps in businesses security controls and prioritizes the impact of those gaps. RedSeal is not an assessment or audit tool, but it does correlate risk to various controls for compliance regulations, creating reports that show gaps in deployed configurations/controls (Stephenson, 2012). The team would have liked to have seen more integration with governance, risk, and compliance solutions (Stephenson, 2012). The product only provided a piece of the risk picture. The piece is important, and one that a number of assessment and audit driven tools do not deliver and could leverage (Stephenson,…

    • 1317 Words
    • 6 Pages
    Better Essays
  • Powerful Essays

    Rounding encourages responsibility and accountability, which increases the staff member’s skill set, and level of care. An increased quality of care leads to fewer readmissions, decreases the length of stay, and provides a safe caring environment. Purposeful rounding provides more patient contact, and a greater understanding of needs for both, the care staff and the patient. Practice changes are not easily made, but through perseverance and dedication any process can become hardwired.…

    • 1176 Words
    • 5 Pages
    Powerful Essays
  • Powerful Essays

    Jacobs, Alex, et al. 2010, “Three approaches to monitoring: feedback systems, participatory monitoring and evaluation and logical frameworks.”…

    • 5638 Words
    • 23 Pages
    Powerful Essays
  • Good Essays

    Healthy People2020

    • 602 Words
    • 3 Pages

    Targeted health improvement includes universal methods as well as monitoring. Some of the tools that we use at my hospital are based on the "always" model. Our always model consists of the healthcare team promise to the patient for safe patient care, promise of loyalty and dignity to all patients that come to our hospital. Our goals consist of assessing the patient, planning, interventions, follow ups, and outcomes. Our plans are measurable and the healthcare team is involved with other departments such as social services and case management. It is important to follow these models in our profession to provide safe care.…

    • 602 Words
    • 3 Pages
    Good Essays
  • Satisfactory Essays

    References: Goldratt, E., & Cox, J. (2004). The goal: a process of ongoing improvement (3rd ed). Great Barrington, MA: North River Press.…

    • 282 Words
    • 2 Pages
    Satisfactory Essays
  • Satisfactory Essays

    yfug

    • 282 Words
    • 2 Pages

    Monitor and correct performance issues as the system yields results. Make sure to identify problems with the scorecard and measurement processes---and correct these as needed.…

    • 282 Words
    • 2 Pages
    Satisfactory Essays
  • Good Essays

    High quality inputs with constant monitoring and controls equals high quality outputs. By having a sound action plan, the necessary processes for a smooth running project can be developed. This involves agreeing on expectations, budgets, suppliers and skilled staff with appropriate training to name a few.…

    • 2039 Words
    • 9 Pages
    Good Essays
  • Good Essays

    - Monitored to make sure you obtain the desired results. (Systems Analysis and Design, 5).…

    • 640 Words
    • 3 Pages
    Good Essays
  • Good Essays

    This ongoing process gives the manager the ability to gather information that measures performance, compare that progress to established standards, and then decide of addition steps or changes need to be made to insure compliance with the established standards. This process of continued process improvement, and supervising the results is paramount to achieving goals.…

    • 577 Words
    • 2 Pages
    Good Essays
  • Powerful Essays

    In fact, monitoring and evaluation are invaluable internal management tools. If you don’t assess how well you are doing against targets and indicators, you may go on using resources to no useful end, without changing the situation you have identified as a problem at all. Monitoring and evaluation enable you to make that assessment.…

    • 24944 Words
    • 100 Pages
    Powerful Essays
  • Good Essays

    Financial Management Notes

    • 1499 Words
    • 6 Pages

    Monitoring and review to ensure that the mission is on target and that performance indicators are being met…

    • 1499 Words
    • 6 Pages
    Good Essays
  • Better Essays

    Foreign Studies

    • 2426 Words
    • 8 Pages

    What is a monitoring system? What is the purpose of a monitoring system? What are the different structures orientations and/or classifications of a monitoring system? What factors should be considered in designing in a monitoring system for trainings? The subsequent discussions will answer these questions leading to a thorough understanding on the subject.…

    • 2426 Words
    • 8 Pages
    Better Essays