From the course: Implementing the NIST Risk Management Framework

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Applying NIST security controls

Applying NIST security controls

From the course: Implementing the NIST Risk Management Framework

Start my 1-month free trial

Applying NIST security controls

- [Instructor] In the control implementation step, you apply the security and privacy controls you have listed in your plans. You also need to document the specific details of the control implementation in your baseline configuration report. When implementing the controls, you should follow industry best practices such as the Center for Internet Security Benchmarks, NIST guidelines, Vendor documentation, and any other applicable standards based on your organization's operations. During control implementation, you establish and apply any mandatory configuration settings in accordance with applicable industry standards and your organization's policies. For example, you would configure password policies on all systems based on NIST and industry directives. Some systems may inherit common controls from a service provider. Using the previous example, your system or application may use a common source like federated…

Contents