The 3-day Security Authorization Process Security Controls In-Depth course builds on and strengthens the students Security Authorization Process Essentials knowledge base. The blend of lecture and hands-on exercises is continued to provide the student with highly detailed information concerning: security control selection and specification, the activities necessary to translate the security controls identified in the security plan into an effective implementation, and the process of assessing the security controls in organizational information systems.
In the spirit of continuing the rapid convergence, NIST, ODNI, DOD, and CNSS initiated an interagency working group in March 2008 to develop a common security authorization process for federal information systems. The new security authorization process changes the traditional focus from the stove-pipe, organization-centric, static-based approaches to C&A and provides the capability to more effectively manage information system-related security risks in highly dynamic environments of complex and sophisticated cyber threats, ever increasing system vulnerabilities, and rapidly changing missions. The process, designed to be tightly integrated into enterprise architectures and ongoing system development life cycle processes, promotes the concept of near real-time risk management, capitalizes on current and previous investments in technology including automated support tools, and takes advantage of over three decades of lessons learned in previous C&A approaches.
The ultimate objective is to be able to provide the right information to senior leaders so they can explicitly manage the security risks to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation arising from the operation and use of information systems. We at SecureInfo refer to this as the Federal Information System Security Authorization Process or Security Authorization Process which is essentially a new and more efficient way of performing the NIST 800-37 process.
**We recommend attending the Security Authorization Process Essentials 3-Day course before taking this course.**
Duration
3 days
Course Topics:
Security Authorization Process Security Controls In-Depth :
Cost of Course: $1500
Laptop Required
Laptops are required for this course, as each student will be asked to create documentation and participate in practical exercises that guide the students learning from Security Authorization Process essentials, fundamental concepts, and Security Authorization Phases to the details of selecting, specifying, implementing, and assessing the security controls. The laptop must have a Web browser, Adobe Acrobat Reader, Excel, and Word. Resource Kits are provided via Thumb Drives for students attending the course, for in-class work, as well as supplemental materials.
Who Should Attend?
This 3 day course is intended to serve a diverse group of information system and information security professionals in and supporting the federal government including:
Questions about our corporate training may be directed to training@secureinfo.com, or call 888.677.9351.
Ask about our mobile training capability--it saves you money!
Schedule:
View Upcoming Courses
Prices:
For Corporate Pricing, Please Call 703.918.4856
GSA Contract Pricing
GSA Contract:
GS-35F-0330J
Schedule 70, SIN 132.50: IT Equipment, Software, & Services
Schedule 70, SIN 132.51: Classroom Training