Minimum Security Requirements
Meeting minimum security requirements at every level demands consistent enforcement of policies, controls, and protections across systems, applications, data, and organizational processes.
3 slides · 1 min read · Domain 1
To provide appropriate levels of security, a fundamental understanding of the desired outcomes is necessary. Security professionals achieve this by gathering a set of minimum-security requirements to use as a goal.
The minimum set of requirements should be created for every level of granularity in an operation.
This includes the organization (where the minimum-security requirements are referred to as the baseline), the overall!! environment, each network included in the environment, each system in each network, and even each component. Moreover, this practice is not limited to IT and data activity, but it should also be included in project management and process functions.
Some hints for effectively gathering minimum security requirements:
- Involve stakeholders in the development, acquisition, and planning processes as soon as possible (close to the start of the endeavor).
- Ensure that requirements are specific, realistic, and measurable.
- Record and document all elements of the discussion and outcome.
- Ensure they are clear and agreed upon by all sides.
- Develop a baseline that captures the technical components of the minimumsecurity requirements. These baselines simplify ongoing governance of the environment.
If possible, create diagrams, models, and prototypes to solidify mutual understanding of the requirements before commencing full-scale development and production.
