Skip Ribbon Commands
Skip to main content

Title

6.4.4 Prepare Security Categorization Report

Predecessors

 

Priority

(2) Normal

Status

Not Started

% Complete

 

Assigned To

 

Description

The fourth step of the security categorization process is the preparation of the security categorization
report.
Security practitioners should summarize in a report the results of the injury assessment for reporting
purposes and to serve as input to two downstream activities (the IT security function definition process
and the departmental security control profile development process). For each business process and related
information, the security categorization report should include:
• A short description;
• A description of the expected injuries to threat compromise;
• The levels of expected injury as they relate to confidentiality, integrity, and availability; and
• The rational for attributing the levels of injury.
 
 

Start Date

 

Due Date

 

Project

ITSG 33 Departmental Security Control Profiles

Milestone

6.4 Security Categorization Process Description

Cost

$0.00

Cost in Days

0.00

Process

 

VisioFlow

 

Attachments

Content Type: Task
Created at 11/25/2013 8:58 PM by System Account
Last modified at 11/25/2013 8:58 PM by System Account