Security Control Assessment (SCA) Process Overview

Sdílet
Vložit
  • čas přidán 13. 07. 2024
  • In this video we looked at how to prepare for a Security Control Assessment (SCA). What we need to do before, during and after the Assessment.
    Security Assessment Plan (SAP): - This document clearly defines the process, procedures, and methodologies for testing Information System Security Controls.
    Security Assessment Reports (SAR): - This documents is used to document all the results of the testings and assessments conducted. It also clearly defines the process, procedures and methodologies utilized for testing and assessing the security controls of an Information System.
    FedRAMP Documents and Templates
    www.fedramp.gov/documents-tem...
    Computer Security Resource Center
    csrc.nist.gov/publications
    The free way to help the channel grow is by subscribing using the link below:
    czcams.com/users/KamilSec?su...
    ************Patreon & Channel Support******************
    www.patreon.com/kamilSec?fan_...
    *******Order your KamilSec (KS) Designs Merch:*********
    kamilsec.creator-spring.com/
    **************************************************************
    CashApp: $Kamilzak
    Zelle: kaamilzak@gmail.com
    Paypal: paypal.me/MZakari
    Thank You!!!
    *************************************************************
    *I ALSO CONDUCT INDIVIDUALIZED RESUME AND INTERVIEW PREP SESSION*
    Connect with me on Social Media:
    Twitter: / kamilzak_1​
    Instagram: @Kamilzak1

Komentáře • 86

  • @lawrencemichael6002
    @lawrencemichael6002 Před rokem +4

    Kamil, you are just a generous genius. Bless your heart in the good work you continue to do and life you touch globally. Thank you champ.

    • @KamilSec
      @KamilSec  Před rokem

      Thank you, I appreciate that!!!

  • @poshtecconsults8
    @poshtecconsults8 Před 2 lety +6

    A great teachable moment. Thank you Prof.

    • @KamilSec
      @KamilSec  Před 2 lety

      You are very welcome, Portia.

  • @germainkone9029
    @germainkone9029 Před rokem +4

    So thankful. Anytime that I am lost a little bit I come over here and I walked out so satisfied . Thanks again 🙏

    • @KamilSec
      @KamilSec  Před rokem

      You are so welcome

    • @germainkone9029
      @germainkone9029 Před rokem

      @@KamilSec Please tell me what how far in details and how many minutes should I go with Tell me about yourself question ! After watching so many videos with no clear answer , here I am again seeking for some tips. Thanks again in advance. 🙏

  • @Risklearner
    @Risklearner Před 5 měsíci +2

    Thank you for the video. So helpful to understand the SCA process.

  • @leviteshouse7213
    @leviteshouse7213 Před 2 lety +4

    Great job as usual Prof👍

  • @realchanger8220
    @realchanger8220 Před rokem +2

    Very very helpful. Thank you

  • @elvistuffour1731
    @elvistuffour1731 Před 2 lety +2

    Great content, Legend!

  • @Fidelisinspire
    @Fidelisinspire Před 2 měsíci +2

    Excellent content and presentation. I'm using this to prepare for an upcoming SCA interview. Thank you so much brother!

  • @Nsorkwame
    @Nsorkwame Před 2 lety +4

    Thanks sir, very informative as usual 👌🏼

    • @KamilSec
      @KamilSec  Před 2 lety +1

      You're welcome Kwame, thanks!

  • @user-vb8nc5cf5q
    @user-vb8nc5cf5q Před 4 měsíci +2

    Thank you for such a great presentation. Very informative and helpful. 👍

  • @sjames916
    @sjames916 Před rokem +2

    Gold! Kamil laying out the blueprint to get into security compliance.

  • @XX2LFEUSNVET
    @XX2LFEUSNVET Před 2 lety +2

    Appreciate it learned more here than on my project team, like they're trying to sabatosh me on purpose.

    • @KamilSec
      @KamilSec  Před 2 lety

      I am glad it was helpful!

  • @ALLISONFolks
    @ALLISONFolks Před rokem +2

    amazing content sir, extremely helpful. Thank you

  • @adedolaadediran4712
    @adedolaadediran4712 Před 2 lety +2

    such great information.Thanks Kamilsec. Am a new subscriber

    • @KamilSec
      @KamilSec  Před 2 lety

      You're very welcome Adedola, and thanks for being a subscriber on the channel!

  • @princenanafosu8161
    @princenanafosu8161 Před rokem +2

    Good job .thanks👍

  • @iyamahsylva7316
    @iyamahsylva7316 Před rokem +2

    Good training and program

  • @AdeleClarice
    @AdeleClarice Před 2 lety +2

    Thank you for the video.. very helpful.

    • @KamilSec
      @KamilSec  Před 2 lety

      You're very welcome! Glad it was helpful!

    • @AdeleClarice
      @AdeleClarice Před 2 lety

      @@KamilSec do you have some form of training? I just got a job as a SCA... I need some more help.

  • @FM-zp2hl
    @FM-zp2hl Před 2 lety +2

    Amazing content

  • @algbla6042
    @algbla6042 Před 2 lety +4

    Great presentation on preparation for control assessment. Definitely learned a lot from this.

    • @KamilSec
      @KamilSec  Před 2 lety

      Awesome, I am glad to hear that Alhaji, Thanks!

  • @benjaminacquaye6444
    @benjaminacquaye6444 Před 5 měsíci +2

    🙏

  • @annetish1205
    @annetish1205 Před 2 lety +3

    Awesome- God bless u

  • @sidalpha2000
    @sidalpha2000 Před rokem +2

    good info

  • @estheranddemiyaforsang6171

    Awesome video Sir! Can you share the artifact list, please?

  • @cgao5599
    @cgao5599 Před rokem +2

    Share a complete ATO package video.

  • @lachampagnia
    @lachampagnia Před 2 lety +3

    Hello. Do you offer interview prep classes?

  • @juddybest1612
    @juddybest1612 Před rokem +3

    The best teaching. Thanks a lot. Question: What skills or qualities are expect by an Organization from a newly hired SCA who has no prior practical/ field knowledge of the job? For instance, one who just graduated from the college.

    • @KamilSec
      @KamilSec  Před rokem

      Usually, they prefer to hire candidates with at least few years of experience.

  • @RodThePRConsult
    @RodThePRConsult Před 2 lety +5

    Awesome presentation... Thank you.. I have a question, how often should Security Assessment Report be updated?

    • @KamilSec
      @KamilSec  Před 2 lety +3

      New SARs are only created after every Security Control Assessment (SCA). SAR are updated when/if after the SCA and a finding was disputed, and the assessors agree, then they will update the SAR. Hope that makes sense.

  • @abdulzar1050
    @abdulzar1050 Před 2 lety +2

    Thanks a lot for this presentation. It a has vicarious feel to it. Can you do on risk assessment?

    • @KamilSec
      @KamilSec  Před 2 lety

      I am sure I have something on Risk Assessment on the channel as well.

    • @abdulzar1050
      @abdulzar1050 Před 2 lety

      @@KamilSec thanks

  • @farahatiqah9988
    @farahatiqah9988 Před 2 lety +2

    Great presentation! Is there any sources or guidance from NIST on artifacts request list? For eg if Access Control Family is being assessed, what are the list of artifacts should be requested? Thanks!

    • @KamilSec
      @KamilSec  Před 2 lety +1

      Unfortunately no. This has to be developed by the assessment team members.

  • @maxwellaburam4911
    @maxwellaburam4911 Před 2 lety +2

    Great Video.
    Do you have a video on how to develop a test plan for assessing security controls./Control Correlation I identifier (CCI)?

    • @KamilSec
      @KamilSec  Před 2 lety +2

      Not yet, will do that soon.

    • @CFH298
      @CFH298 Před 2 lety

      This was would be an awesome video. Thanks!

  • @jesl3nt64
    @jesl3nt64 Před 2 lety +2

    I have a question what are some of the monitoring tools afther Accessment is done

    • @KamilSec
      @KamilSec  Před 2 lety

      Well depending on the agency, SIEM tools like Splunk, QRadar as well as Vulnerability scanning tools like Nessus, WebInspect, DBProtect, NexPose etc. can be used to assist in the Continuous Monitoring.

  • @atohambe5775
    @atohambe5775 Před 2 lety +2

    Hi Kamilsec. I will like to join your class for training.
    When is the next cissp class?

    • @KamilSec
      @KamilSec  Před 2 lety

      Not conducting training currently.

  • @AlmondHealthcareServicesLLC

    great video's, do you have training classes?

  • @uche2564
    @uche2564 Před rokem +2

    What are some common problems you would run into during an assessment ?

    • @KamilSec
      @KamilSec  Před rokem +1

      1. Clients not providing artifacts/evidence on time
      2. Clients deliberately providing wrong artifacts/evidence
      3. Clients refusing to accept findings and so on....

    • @uche2564
      @uche2564 Před rokem

      @@KamilSec Thankyou! One last question. As an assessor, what are your options or next steps if a client refuses to accept the findings

  • @cricriy1400
    @cricriy1400 Před 2 lety +2

    Is this work a team work or a self work?

    • @KamilSec
      @KamilSec  Před 2 lety

      Yea, the SCA is a team work

  • @joycefynn8496
    @joycefynn8496 Před 2 lety +2

    Well done prof! How can I contact you please?

  • @tanveerahmed9494
    @tanveerahmed9494 Před 7 měsíci +2

    Hi, can u pls share the artifact request list

    • @KamilSec
      @KamilSec  Před 6 měsíci

      There is a link to my Patreon page in the video description where you can find all documents I used in my videos.

  • @jackybandoh7335
    @jackybandoh7335 Před 2 lety +2

    Quick question
    What’s the difference between security assessment and risk assessment?

    • @KamilSec
      @KamilSec  Před 2 lety +3

      I will say Security Assessment can be a subset of Risk Assessment. Because in Risk Assessment, every aspect of the business or the organization such as financial, marketing, competitive advantages etc. of the business will be evaluated and reviewed, where as Security Assessment can be just limited to security operation.

    • @jackybandoh7335
      @jackybandoh7335 Před 2 lety

      Thanks

  • @maryniang7683
    @maryniang7683 Před rokem +2

    How can you be reached?

  • @dinayenbelirta4213
    @dinayenbelirta4213 Před 2 lety +2

    Great one,Can you be my Mentor sir

  • @ITSS.MEEEEEEE
    @ITSS.MEEEEEEE Před 2 lety +3

    Hi uncle

    • @KamilSec
      @KamilSec  Před 2 lety +1

      Hi Zee Zee, How are you? I hope you are reading your books.

    • @ITSS.MEEEEEEE
      @ITSS.MEEEEEEE Před 2 lety +2

      I think so