-
FISMA Compliance RMF STEP 1-3 44
-
Lecture1.1
-
Lecture1.2
-
Quiz1.1
-
Lecture1.3
-
Quiz1.2
-
Lecture1.4
-
Quiz1.3
-
Lecture1.5
-
Quiz1.4
-
Lecture1.6
-
Quiz1.5
-
Lecture1.7
-
Quiz1.6
-
Lecture1.8
-
Quiz1.7
-
Lecture1.9
-
Quiz1.8
-
Lecture1.10
-
Quiz1.9
-
Lecture1.11
-
Quiz1.10
-
Lecture1.12
-
Quiz1.11
-
Lecture1.13
-
Quiz1.12
-
Lecture1.14
-
Quiz1.13
-
Lecture1.15
-
Quiz1.14
-
Lecture1.16
-
Quiz1.15
-
Lecture1.17
-
Lecture1.18
-
Quiz1.16
-
Lecture1.19
-
Quiz1.17
-
Lecture1.20
-
Quiz1.18
-
Lecture1.21
-
Quiz1.19
-
Lecture1.22
-
Quiz1.20
-
Lecture1.23
-
Quiz1.21
-
-
FISMA Compliance RMF STEPS 4-5 25
-
Lecture2.1
-
Quiz2.1
-
Lecture2.2
-
Quiz2.2
-
Lecture2.3
-
Quiz2.3
-
Lecture2.4
-
Quiz2.4
-
Lecture2.5
-
Quiz2.5
-
Lecture2.6
-
Quiz2.6
-
Lecture2.7
-
Quiz2.7
-
Lecture2.8
-
Quiz2.8
-
Lecture2.9
-
Quiz2.9
-
Lecture2.10
-
Quiz2.10
-
Lecture2.11
-
Quiz2.11
-
Lecture2.12
-
Quiz2.12
-
Lecture2.13
-
This content is protected, please login and enroll course to view this content!
6 Comments
I can’t place/see the listed information types. could it be listed so I can use it in my ssp
thanks
Hi,
the SSP that you’re drafting should be an SSP of your home network. so you shouldn’t need the DOP information type. You will need to create your own information types. Examples of information typed that you can use is listed in the NIST 800-60.
okay, thanks
hello Paul,
I would rather if I had a list of the information types though, this gives me a better scenario of a work base, using my home network would give me too much freedom (if that makes sense)
Also I noticed in your SSP you used only the information titles, those this mean we can’t pin to an actual type say for example: Help Desk service (just trying to understand things better)
thanks
hello Paul,
I would rather if I had a list of the information types though, this gives me a better scenario of a work base, using my home network would give me too much freedom (if that makes sense)
Also I noticed in your SSP you used only the information titles, those this mean we can’t pin to an actual type say for example: Help Desk service (just trying to understand things better)
thanks
Hi,
What do you mean by having a list of the information types? its all listed on nist 800-60v2r1. below is a link to the referenced document. the list is on page 2, 3 and 103 (for classified systems).
Are you suggesting i tell you what your information types are? you are the system owner so you should be able to creatively come up with your own information types.
As for me not using the NIST recommended information types in the example in the video, you;re right, i should have. to make things more clear. But in my defense, NIST 800-60 is a recommendation not a requirement 🙂 I’ll improve this part when i revise the video.
thanks!
https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-60v2r1.pdf