10.10.2014 Views

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

2.2.1.5 Establish Appropriate Security Baseline Requirements<br />

As a rule, the NIST 800-53 Moderate Baseline is to be applied to all<br />

State systems. Agencies may, at their discretion, determine that the<br />

High Baseline is appropriate for given systems depending on system<br />

and/or agency requirements:<br />

• Review the system to determine if the Moderate Baseline is<br />

not applicable based on system and/or agency requirements.<br />

2.3. Maintain Records<br />

Agencies should capture documentation appropriate to all assessment and planning<br />

processes:<br />

• Document and retain copies <strong>of</strong> the outcome <strong>of</strong> all Risk Assessments.<br />

• Document and retain copies <strong>of</strong> all Security Plans.<br />

5

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!