MONITORING AND OVERSIGHT
InfoScreen establishes specifications for monitoring, oversight,
and compliance activities.
- Periodically test/measure the state of controls to determine if controls are operating as intended
- Have new vulnerabilities appeared or have control processes deteriorated
- Vulnerability scanning techniques
- Penetration testing techniques
- Patch-level assessment
- Platform configuration assessment
- Access privilege/entitlement analysis
- Intrusion detection; in-house or managed services
- Internal or external audit
- Status reporting to management, including management guidance regarding required information security program improvements.
|