课程: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

免费学习该课程!

今天就开通帐号,24,600 门业界名师课程任您挑!

Control management

Control management

- [Narrator] In addition to conducting regular audits and assessments, organizations should perform routine management of their own controls. Every security program should include control testing procedures, a process for managing exceptions to controls, the building of control remediation plans, and the use of compensating controls. Control testing should take place on a regular basis, while periodic audits and assessments do evaluate the effectiveness of security controls. These usually occur relatively and frequently. Organizations should supplement these more formal tests with routine and automated monitoring of security controls. For example, an automated review process might routinely check to see if new ports are opened on a firewall in an unexpected manner. You'll also find that there is an exception to every rule in the world of security. You should have a defined process in place to help team members understand how they can request an exception to a security control, and who…

内容