Background
After the authorizing official (AO) has reviewed all security documentation, all high-level security findings have been mitigated, and the Plan Of Action and Milestones are viable, the AO will issue an Authorization To Operate (ATO) for the system. This could be anywhere from a few months, to a few years, to (rarely) indefinite. Even though the system has gone through full scrutiny and accreditation, security of the system is not over. Having a consistently updated continuous monitoring strategy will help maintain the security health of the system, and make re-accreditation of the system easier the second time around.
Deliverables
Submit an APA-formatted paper, 1250 words minimum (at least 5 pages), that includes all deliverables listed below.
Reminder: Assume you are using your home computer for work, connecting to the company network through a Virtual Private Network (VPN).
Create a Continuous Monitoring strategy. At a minimum, this strategy should address :
a) Frequency and depth of reviewing security audit logs.
b) Frequency and depth of vulnerability scans.
c) Frequency and depth of personnel background investigations.
d) Frequency of account review and removing access for inactive/terminated users.
e) Frequency and depth of reviewing physical security controls.
f) Frequency of reviewing and updating open items in the POA&M.
g) Frequency and responsible parties for updating security baseline documentation.
h) Frequency for reviewing all security controls and re-accreditation of the system.
APA Requirements
Standard APA formatting is required. This includes in-text citations, references page, title page, section headings, running head, etc.
Last Completed Projects
| topic title | academic level | Writer | delivered |
|---|
