Transcription of Threat-Based Risk Profiling Methodology - FedRAMP
{{id}} {{{paragraph}}}
Threat-Based RiskProfilin g MethodologyDeveloped by: GSA FedRAMP PMOV ersion Risk Profiling Methodology White PaperDOCUMENT REVISION HISTORYDateVersionPage(s)DescriptionAuth or02 PublicationFedRAMP PMO02 to Methodology : Scoredcontrols against the MITREATT&CK threat frameworkFedRAMP Risk Profiling Methodology White PaperTABLE OF CONTENTSA cknowledgements1 Organizational Affiliations1 General Services Administration (GSA)1 Executive Scoring Methodology4 Potential Outcomes of the Threat-Based Methodology5 Threat based Risk Profiling Methodology5 Phase 1: Threat Analysis ( , Security Controls Scoring)6 Phase 2: Security Controls Assessment6 Phase 3: Risk Profiling7 Applications of Threat based Risk Profiling8 Conclusion9 Appendix A: Security Controls Scoring10 Step 1. Control Item Scoring10 Step 2. Security Control Prioritization11 Appendix B: Security Controls Assessment12 Appendix C: Risk Profiling ( , Capability Maturity Levels)12 Appendix D: Risk Profiling Methodology White PaperAcknowledgementsThis publication was developed by the Federal Risk and Authorization Management Program ( FedRAMP )with representatives from the Department of Homeland Security (DHS) Cybersecurity Infrastructure SecurityAgency (CISA) in an ongoing effort to produ
Threat-Based Risk Profiling Methodology White Paper With a threat-based approach, cybersecurity authorizations can be achieved faster, use fewer resources, and be more secure by focusing on the current threat landscape. f e d r a m p . g o v p a g e 3
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document:
{{id}} {{{paragraph}}}