From the course: Implementing the NIST Risk Management Framework

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Examples of monitoring

Examples of monitoring

From the course: Implementing the NIST Risk Management Framework

Start my 1-month free trial

Examples of monitoring

- [Instructor] What are some typical ways organizations continually monitor their environment? The most efficient and least expensive method is to inject security throughout the project management and system development lifecycle. As a security consultant, I do this by introducing security and privacy requirements at the beginning of the project in the planning and analysis phase. I monitor any new projects and work with project managers to build security into whatever is being developed. Next, during the design and implementation phases, I conduct security testing to ensure risks are known and that the end product will meet all control requirements. Once the system is in production, I take part in change control meetings to assess how the change may impact security or privacy controls. Whenever possible, the security function should formally approve any changes prior to implementation. With security a part of the change…

Contents