When are Plan of Action and Milestones POAMs done in the RMF process

Поділитися
Вставка
  • Опубліковано 7 лис 2024

КОМЕНТАРІ • 12

  • @ConvoCourses
    @ConvoCourses  4 роки тому +1

    Check out free courses @ convocourses.com

  • @dennywood3469
    @dennywood3469 2 роки тому +1

    Class act. Thank you for offering to help our veterans!

  • @uche2564
    @uche2564 3 роки тому +3

    JUst want to say man your page has been a big help, greatly appreciated

    • @ConvoCourses
      @ConvoCourses  3 роки тому

      thank you so much :) Glad to hear it!

  • @Youcanthandlethetruth99
    @Youcanthandlethetruth99 Рік тому +1

    Where would the security control assessor find the recommended remediation fix for failed controls to support the POAM without running a scan?

    • @ConvoCourses
      @ConvoCourses  Рік тому

      SCA can find the remediation fixes or "expected results" in several places:
      - Vulnerability scan results usually have the solutions to the finding (nessus calls in plugin Output or solution)
      - For operational issues, the expected result is what the organization states in the policy (frequency of scan, backups schedule, audit log reviews)
      - For policy and procedures, every industry has a certain standard and requirement of documents. 1 example is governments FISMA states that all organization should have a security policy and they should address every control.
      A great resource for expected results is NIST 800-53A

  • @Teesamp86
    @Teesamp86 Рік тому

    If there are immediate fix to findings do you still have to create a POAM?

  • @OshunBabyKhalimaCrazy
    @OshunBabyKhalimaCrazy 3 роки тому +1

    Where can i find that control list?

    • @TooLazyToFail
      @TooLazyToFail 3 роки тому +1

      Little late I know, but what you're looking for is NIST SP 800-53.

  • @medianetwork7972
    @medianetwork7972 4 роки тому +1

    ☝️👍

  • @marandamarkwood6639
    @marandamarkwood6639 4 роки тому +1

    Huh