From the course: Cloud Security Operations by Pearson
Unlock this course with a free trial
Join today to access over 25,200 courses taught by industry experts.
Specialized compliance requirements
From the course: Cloud Security Operations by Pearson
Specialized compliance requirements
In this lesson, we're going to look at a couple of highly regulated industries, starting with NERC-CIP. So to reinforce the cyber resilience of the United States, the government created the North American Electric Reliability Corporation, or NERC, framework that's directed at protecting a portion of the U.S. utility infrastructure. The NERC Critical Infrastructure Protection CIP standards relate explicitly to the cybersecurity characteristics of the bulk electric system and its proficient and dependable supply. CIP is directed at the pre-planning and groundwork inside enterprises and agencies to address threats to the effective and timely operations of national and regional critical infrastructure. NERC's CIP has 10 key areas, 1. Identification and Categorization, 2. Security Controls, 3. Background Checks and Training, 4. Electronic Security, 5. Physical Security, 6. System Security, 7. management, 8 recovery plans, 9 configuration and vulnerabilities, and 10 information protection…
Contents
-
-
-
-
-
-
(Locked)
Audit controls, reports, and their impact1m 59s
-
(Locked)
Gap analysis and internal InfoSec management systems2m 41s
-
(Locked)
Policies and stakeholder involvement4m 21s
-
(Locked)
Specialized compliance requirements2m 55s
-
(Locked)
The impact of distributed IT3m 33s
-
(Locked)
Business agreement requirements2m 56s
-
(Locked)
Supply chain management1m 28s
-
(Locked)
-