|
+Authorize Technology Assets, Applications and/or Services (TAAS) |
Authorize Technology Assets, Applications and/or Services (TAAS)DescriptionMechanisms exist to compel data and/or process owners to obtain authorization for the production use of each Technology Asset, Application and/or Service (TAAS) under their control.Possible Solutions & ConsiderationsMicro-Small Business (<10 staff) / BLS Firm Size Classes 1-2∙ SCF Security, Compliance & Resilience Management System (SCRMS)Small Business (10-49 staff) / BLS Firm Size Classes 3-4∙ SCF Security, Compliance & Resilience Management System (SCRMS)Medium Business (50-249 staff) / BLS Firm Size Classes 5-6∙ SCF Security, Compliance & Resilience Management System (SCRMS)Large Business (250-999 staff) / BLS Firm Size Classes 7-8∙ SCF Security, Compliance & Resilience Management System (SCRMS)Enterprise (> 1,000 staff) / BLS Firm Size Class 9∙ SCF Security, Compliance & Resilience Management System (SCRMS)SCR-CMMLevel 0 Not PerformedPractices are non-existent, based on the inability to demonstrate an implemented and operational capability. A reasonable person would conclude the control is not being performed.Level 1 Performed InformallySCR-CMM Level 1 criteria definitions are not available for this control:▪ A reasonable person would conclude this control requires a structured process. ▪ At this level of maturity, the "ad hoc" nature of performing a capability informally would indicate the intent of the control is not met due to a lack of consistency and formality. Level 2 Planned TrackedSCR-CMM Level 2 criteria definitions are not available for this control:▪ A reasonable person would conclude a well-defined and standardized process is required. ▪ At this level of maturity, the “requirements-driven” nature of performing the control is focused on a localized and/or regionalized implementation, not uniform and consistent across the organization. ▪ Requirements are narrowly scoped for applicability and are primarily derived from compliance obligations (e.g., laws, regulations and contracts). Level 3 Well DefinedCybersecurity & Data Protection Governance (GOV) capabilities are standardized across the entity for applicability to People, Processes, Technologies, Data and/or Facilities (PPTDF) to ensure consistency for Technology Assets, Applications, Services and/or Data (TAASD). Capability criteria associated with this control reasonably expect the following criteria to exist:▪ Policies and standards associated with GOV domain capabilities are formally documented and centrally-managed by the entity's Governance, Risk & Compliance (GRC) team, or similar function. ▪ Standardized Operating Procedures (SOP) associated with GOV domain capabilities are well-documented and kept current by process owners. ▪ The entity's GRC team, or similar function, is appropriately staffed and supported to implement and maintain GOV domain capabilities to address Minimum Compliance Requirements (MCR) (e.g., applicable statutory, regulatory and/or contractual requirements) and Discretionary Security Requirements (DSR) (e.g., entity-required controls). ▪ Technology is leveraged to enhance the efficiency and accuracy of governance, risk management and compliance operations (e.g., GRC platform). ▪ An implemented and operational capability exists to compel data and/or process owners to obtain authorization for the production use of each Technology Asset, Application and/or Service (TAAS) under their control. Level 4 Quantitatively ControlledUtilize SCR-CMM Level 3 criteria definitions:▪ There are no defined Level 4 criteria, since it is reasonable to assume a quantitatively-controlled process is not necessary to operationalize this control. ▪ While it may be possible to develop “metrics-driven” capabilities for this control, the criteria would be organization-specific to define. Level 5 Continuously ImprovingUtilize SCR-CMM Level 3 or Level 4 (if available) criteria definitions:▪ There are no defined Level 5 criteria, since it is reasonable to assume a continuously-improving process is not necessary to operationalize this control. ▪ Level 5 capabilities should be considered “world-class” where the control builds on Level 4 capabilities, but are continuously improving through Artificial Intelligence (AI) and/or Machine Learning (ML) technologies. ▪ While it may be possible to develop responsive capabilities for this control through the use of AI and/or ML technologies, the criteria would be organization-specific to define. 1. Übersicht
1.1 Referenzen1.2 Identifizierte Anforderungen1.3 Related Regulations2. Identifizierte Anforderungen
3. Related Regulations
Linked Issues
|