Security Controls In-Depth – 3 Days

The 3-day Security Authorization Process Security Controls In-Depth course builds on and strengthens the students Security Authorization Process Essentials knowledge base. The blend of lecture and hands-on exercises is continued to provide the student with highly detailed information concerning: security control selection and specification, the activities necessary to translate the security controls identified in the security plan into an effective implementation, and the process of assessing the security controls in organizational information systems.

In the spirit of continuing the rapid convergence, NIST, ODNI, DOD, and CNSS initiated an interagency working group in March 2008 to develop a common security authorization process for federal information systems. The new security authorization process changes the traditional focus from the stove-pipe, organization-centric, static-based approaches to C&A and provides the capability to more effectively manage information system-related security risks in highly dynamic environments of complex and sophisticated cyber threats, ever increasing system vulnerabilities, and rapidly changing missions. The process, designed to be tightly integrated into enterprise architectures and ongoing system development life cycle processes, promotes the concept of near real-time risk management, capitalizes on current and previous investments in technology including automated support tools, and takes advantage of over three decades of lessons learned in previous C&A approaches.

The ultimate objective is to be able to provide the right information to senior leaders so they can explicitly manage the security risks to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation arising from the operation and use of information systems.  We at SecureInfo refer to this as the Federal Information System Security Authorization Process or Security Authorization Process which is essentially a new and more efficient way of performing the NIST 800-37 process.

**We recommend attending the Security Authorization Process Essentials 3-Day course before taking this course.**

Duration
3 days

Course Topics:
Security Authorization Process Security Controls In-Depth :

  • Selecting and Specifying the Security Controls
    • Fundamental Concepts
      • Structural components of security controls
      • Minimum (baseline) security controls
      • Common security controls
      • Assurance in the effectiveness of security controls
      • Commitment to maintain currency
    • The Process
      • The organization’s overall approach to managing risk
      • FIPS 199 - categorizing the system
      • Selecting and tailoring the initial set of controls
      • Supplementing the tailored security control baseline
      • Updating the controls
  • Implementing the Security Controls
    • The “Easy” security controls
    • The “Tough” security controls
      • Using the NIST Checklist Program
      • Pre-defined checklist operational environments
      • Threat discussions
      • Baseline technical security practices
      • Selecting the “best” checklists for the environment
      • Tailoring and Implementing Checklists
      • Developing Checklists
  • Assessing the Security Controls
    • Fundamental Concepts
      • Integrating assessments into the SDLC
      • An organization-wide strategy for conducting assessments
      • Developing effective assurance cases
      • Format and content of assessment procedures
      • Extended assessment procedures
    • The Process
      • Organizational activities to prepare for an assessment
      • Assessor activities to prepare for security control assessments
      • Developing the Security Assessment Plan (SAP)
      • Conducting and Analyzing the security control assessments
      • Reporting assessment results – the SAR
      • Organizational post-assessment report analysis
      • Organizational follow-on activities

Cost of Course: $1500

Laptop Required
Laptops are required for this course, as each student will be asked to create documentation and participate in practical exercises that guide the students learning from Security Authorization Process essentials, fundamental concepts, and Security Authorization Phases to the details of selecting, specifying, implementing, and assessing the security controls. The laptop must have a Web browser, Adobe Acrobat Reader, Excel, and Word. Resource Kits are provided via Thumb Drives for students attending the course, for in-class work, as well as supplemental materials.

Who Should Attend?
This 3 day course is intended to serve a diverse group of information system and information security professionals in and supporting the federal government including:

  • Individuals with information system development and integration responsibilities (e.g., program managers, information technology product developers, information system developers, systems integrators)
  • Individuals with information system and security management and oversight responsibilities (e.g., authorizing officials, chief information officers, senior agency information security officers, information system managers, information security managers)
  • Individuals with information system and security control assessment and monitoring responsibilities (e.g., system evaluators, assessors/assessment teams, independent verification and validation assessors, auditors, Inspectors General, or information system owners)
  • Individuals with information security implementation and operational responsibilities (e.g., information system owners, common control providers, information owners/stewards, mission/business owners, information system security engineers/officers).

Register Now

Questions about our corporate training may be directed to training@secureinfo.com, or call 888.677.9351.

Ask about our mobile training capability--it saves you money!