Instruction
During this assignment, students will identify the laws or regulations an organization must adhere to and map to specific controls within a framework to communicate and implement throughout the organization.
Access the "Company Profiles," located within the Course Materials.
Select a fictitious company to use for the duration of this course and create an associated abbreviation (e.g., Across the States Bank (ASB), Lopes Manufacturing (LM), or Pike's Peak Health Care (PPHC)).
For the company selected, research online or use Chapter 2 of the textbook and identify at a minimum two laws or regulations that include a set of standards the organization must implement to achieve compliance (i.e., PCI DSS, HIPAA-HITECH, ISO/IEC 27001:2013, or NISPOM 5220.22).
Use the "NIST 800-53 Framework - Appendix F,” the two identified laws, and the “Developing Enterprise Framework Template," to map the various standards to the controls within the framework. Refer to the “Developing Enterprise Framework Example.”
Map a minimum of two NIST controls per law or regulation. NIST 800-53 controls may duplicate across standards as shown in the Developing Enterprise Framework Example (see SC-13).
Complete at least 25 mappings.
In the "Notes" column, briefly explain the purpose that all three are trying to achieve. For example, the first row in the example is establishing a policy on risk assessment and the identification and management of threats and vulnerabilities.
Research and create a security program framework outline for your fictitious company which aligns to the mission and vision of the company. Your outline should include a table of contents; topics that your company would need to address the many issues revolving around its business.
In 750 words or less explain your security framework outline and how it is specific to your company. Explain why you determined to include your specific topics and how they will help to secure your companies interests long term. Include at least 2 references outside of required reading.
APA style is not required, but solid academic writing is expected.
Refer to the "ITT-430 Developing Enterprise Framework for a Security Program Scoring Guide," prior to beginning the assignment to become familiar with the expectations for successful completion.