HomelandSecurity #484 Public Law 107296 107th
Posted on October 28th, 2009 by admin
http://www.govtrack.us/congress/bill.xpd?bill=h107-5005 in complying with agency policies and procedures designed to reduce these risks; (5) periodic testing and evaluation of the effectiveness of information security policies, procedures, and practices, to be performed with a frequency depending on risk, but no less than annually, of which such testing— (A) shall include testing of management, operational, and technical controls of every information system identified in the inventory required under section 3505(c); and (B) may include testing relied on in a evaluation under section 3535; (6) a process for planning, implementing, evaluating, and documenting remedial action to address any deficiencies in the information security policies, procedures, and practices of the agency; (7) procedures for detecting, reporting, and responding to security
Duration : 0:0:59
[youtube 6es6K_YIslg]