Managing Metrics and Improvement

Information

Measuring control effectiveness is an integral process to each ISMS. Metrics provide visibility into how well controls are protecting the environment. Risk management often depends on qualitative and quantitative metrics.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Measuring control effectiveness is an integral process to each ISMS. Metrics provide visibility into how well controls are protecting the environment. Risk management often depends on qualitative and quantitative metrics.

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: ACCESS CONTROL, AWARENESS AND TRAINING, AUDIT AND ACCOUNTABILITY, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, IDENTIFICATION AND AUTHENTICATION, INCIDENT RESPONSE, MAINTENANCE, MEDIA PROTECTION, PHYSICAL AND ENVIRONMENTAL PROTECTION, PLANNING, PROGRAM MANAGEMENT, PERSONNEL SECURITY, RISK ASSESSMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AC-1, 800-53|AT-1, 800-53|AU-1, 800-53|CA-1, 800-53|CM-1, 800-53|CP-1, 800-53|CP-2, 800-53|IA-1, 800-53|IA-5, 800-53|IR-1, 800-53|MA-1, 800-53|MP-1, 800-53|PE-1, 800-53|PL-1, 800-53|PM-1, 800-53|PS-1, 800-53|RA-1, 800-53|RA-2, 800-53|RA-3, 800-53|SA-1, 800-53|SC-1, 800-53|SI-1

Plugin: amazon_aws

Control ID: 040cb9d4d69afd2a6a51967060a9e62f0cfb31303c1e91c57b0ccd25bbbe2aaf