Information technology security audit guidebook for NIST SP 800-171 / Mark A. Russo
Material type:
- 9781726674904
- QA 76.9.A93 .R87 2020

Item type | Current library | Home library | Collection | Call number | Copy number | Status | Date due | Barcode | |
---|---|---|---|---|---|---|---|---|---|
![]() |
National University - Manila | LRC - Annex II General Circulation | Accountancy | GC QA 76.9.A93 .R87 2020 (Browse shelf(Opens below)) | c.1 | Available | NULIB000018417 |
Browsing LRC - Annex II shelves, Shelving location: General Circulation, Collection: Accountancy Close shelf browser (Hides shelf browser)
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
||
GC HG 4028.V3 .V35 2015 Valuation workbook : step-by-step exercises and tests to help you master valuation / | GC HJ 9733 .R43 2013 Accounting for governmental and nonprofit entities / | GC K 1005.3 .A94 2013 International business law : text, cases, and readings / | GC QA 76.9.A93 .R87 2020 Information technology security audit guidebook for NIST SP 800-171 / | GC TS 155 .H45 2008 Operations Management / | GC TS 155 .M37 1996 c.2 Fundamentals of production/operations management / |
For NIST 800-171 Security Auditors -- Elements of good Audit practice -- Current NIST 800+171 Contract direction and development -- Why pursue an expansion of NIST-based cybersecurity standards? -- People-Process-Technology PPT Model -- More about artifacts and POAMs -- All things considered -- How to use this book -- ACCESS CONTROL -- AWARENESS & TRAINING (AT) -- AUDIT AND ACCOUNTABILITY (AU) -- CONFIGURATION MANAGEMENT (CM) -- IDENTIFICATION AND AUTHENTICATION (IA) -- INCIDENT RESPONSE (IR) -- MAINTENANCE (MA) -- MEDIA PROTECTION (MP) -- PERSONNEL SECURITY (PS) -- PHYSICAL PROTECTION (PP) -- RISK ASSESSMENT (RA) -- SECURITY ASSESSMENT (SA) -- SYSTEM AND COMMUNICATIONS PROTECTION (SC) -- SYSTEM AND INFORMATION INTEGRITY (SI) -- CONSCLUSION.
This book is designed to walk the auditor through each of the 110 controls with a thorough understanding of whether a control is met or not. There is no "partial credit." While the process is subjective, the assessor must make a reasonable determination that the system owner understands and can demonstrate his company or agency's compliance with NIST 800-171. We include a compliance checklist designed to build out a record of the audit. This has been one of our most sought books on the evolving state of NIST 800-171.
There are no comments on this title.