• Skip to main content
  • Skip to primary sidebar

ConvoCourses

Cyber Security Compliance and IT Jobs

  • Cyber Security Training
  • about me.
  • Information Assurance Jobs

risk assessment reports

January 21, 2014 by Bruce Brown 1 Comment

Risk Assessment Reports (RAR) also known as the Security Assessment Report (SAR) is an essential part of the DIARMF Authorization Package.  This document can be done at anytime after the system is implemented (DIARMF Process step 3) but must be done during DIARMF step 4, Assess for the risk identification of the system.  The Authorization Package consists of the following (but is not limited to):

authorization package
authorization package
  • System Security Plan (SSP) – “Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.”  — NIST SP 800-18.  This document provides over all system characterization and control analysis for the system.  More on Security Plan  – NIST SP 800-18, Guide for Developing Security Plans for Federal Information Systems
  • Plan of Action and Milestone (POA&M pronounced PO’AM) – “A document that identifies tasks needing to be accomplished. It details resources required to accomplish the elements of the plan, any milestones in meeting the tasks, and scheduled completion dates for the milestones.” — NIST SP 800-18.  After the DIARMF Assessment the POA&M is accomplished to address the residual risks that could not be properly mitigated.
  • Risk Assessment Report / Security Assessment Report (RAR/SAR) – “The process of identifying risks to agency operations (including mission, functions, image, or reputation), agency assets, or individuals by determining the probability of occurrence, the resulting impact, and additional security controls that would mitigate this impact.”  — NIST SP 800-18.  Form more see NIST SP 800-30, Guide for Conducting Risk Assessments.
  • Artifacts – Supporting documents that provide evidence that certain security feature and/or programs exist.

NIST SP 800-30, guide on risk assessment, breaks down what should be in a risk assessment report / security assessment report in appendix K, RISK ASSESSMENT REPORTS ESSENTIAL ELEMENTS OF INFORMATION

The  risk assessment report / security assessment report results provide decision makers (system owners & authorization officers) with some idea of the risks that will be imposed upon the organization, asset, individuals in the organization, associates of the organization and in some cases the Nation.  

The  risk assessment report / security assessment report is broken into three parts:

  1.  Executive Summary (audience Managers)  – the executive summary gives a brief high-level view of the overall risk assessment.  It lists the dates of the risk assessment, summarized the purpose and scope and gives a quick idea of the finding.
  2. Body of the Report (audience Security Practitioners) – fills out the details of the findings.  In addition to detailing the who, what, when, where and how of the risk assessment, it goes int specific information technology issues.  Since it is mentions specific IP addresses and associated vulnerabilities, it must be considered confidential.  The RAR/SAR may describe how vulnerabilities can be exploited and what was done to fix the weakness to limit the risk.
  3. Supporting Appendices – may include actual raw network vulnerability scans.  References & glossary.

    risk assessment report
    risk assessment report

Template of Risk Assessment Report/Security Assessment: Risk assessment report_Example

Filed Under: risk management Tagged With: authorization package, nist risk management framework, risk, risk assessment reports, risk management, sar, security assessment report, ssp, system security plan

Reader Interactions

Trackbacks

  1. risk evaluation says:
    January 21, 2014 at 2:39 am

    […] risk evaluation from a system security perspective is known as a risk assessment (or security assessment).  The process of the risk evaluation is detailed in NIST SP 800-30, Guide for Risk Assessments and […]

    Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Social connect:

Primary Sidebar

search


This book is an overview of how the NIST SP 800-37 risk management framework works from the perspective of an information system security officer (ISSO).

also available on Amazon!

View Book

NIST RMF 800-37 templates
Free 800-37 templates

The NIST 800 Template download contains a .doc file template and xls templates for POAMs, Federal, State, cloud based and a legacy template as well as resources where you can find more on NIST 800-37 documents for your use.

View Book

Learn to Make 6 Figures in CyberSecurity

Cyber Security How to make up to 6 Figures
6 figures in Cyber Security

This course explains how I have been able to consistently make 6 figures doing cyber security. There is a method that I have used during my development in cyber security. I am presenting that method to you.

View Course

Teleworking - IT Remote Work
Teleworking – IT Remote Work

Teleworking is something I have been doing for the last 5 years. This is how I did it.

Find Teleworking IT Jobs

View Course

RMF ISSO Foundations Training
RMF ISSO Foundations Training

RMF ISSO Foundations

I was an Information System Security Officer (ISSO) doing Risk Management Framework (NIST SP 800-37) for over a decade. I am a Cybersecurity veteran and I can explain (in plain English) what you DO in the Risk Management Framework process as an ISSO.

View Course

NIST SP 800-37 Presentation
NIST SP 800-37 Presentation

View Course

login

  • Register
  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Recent Posts

  • RMF / security compliance beginner reading list NIST 800-37 NIST 800-53 and NIST 800-12
  • IT to cybersecurity jobs
  • Access Control Family: What is NIST Access Control (part1)
  • RMF Security Controls when the operating system changes
  • Cybersecurity Convocourses: Control Correlation Identifier (CCI), CIS and STIGS

Meta

  • Register
  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Recent Comments

  • http://Www.Finance.Ipt.Pw/ on SRG/STIG Applicability Guide and Collection Tool Update
  • Elsa7 on ConvoCourses podcast: Cyber Security day to day activity
  • Tony on STIG Update – DISA has released the Microsoft SQL Server 2016 STIG Version 1
  • horloge on SCAP Compliance Checker SCC)
  • 218 Information assurance Success Criteria – ITSECURITYSURVIVAL.COM on Information Assurance Vulnerability Alert

Tags

8140 8570 ArcSight c&a CISSP convocourses cyber cybersecurity cyber security DIACAP DIARMF diarmf - implement disa DISA STIG dodd 8140 dodd 8140 cyberspace workforce HBSS IA implement implementation info assurance information assurance information security ISSO it jobs it jobs in usa job jobs Linux mcafee network nist nist risk management framework nist risk management framework 800-37 podcast risk risk assessment risk management risk management framework rmf security STIG stigs unix windows

Copyright © 2022 · Author Pro on Genesis Framework · WordPress · Log in

Posting....