Question
Managing Security Architecture with Broad Considerations Containers and container security is of increasing importance as they provide a method to isolate applications. Technologies will come and go, the ability to apply general concepts to specific technologies is critical. The “Trustworthiness Model” in NIST SP800-53r5 is clearly applicable to container environments for example. However, in viewing NIST SP800-53r5, the only control listed explicitly in regard to “containers'' is on container encryption. After reviewing NIST SP 800-190 (https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-190.pdf ) and NIST SP 800-53 rev. 5 Appendix C, (https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf ) what other controls are applicable to container environments? For this part of the assignment, select 4 separate controls from 4 separate control families and detail the control implementation options when containers are used for applications. Each control and its possible implementation sets should be briefly described and may include the range of security possible for implementation as different environments may select different implementations based on risk tolerance and policy requirements. Control Description Applicability to containers Implementation options (Control Number/Name) 2. 3. 4. 1. 2. 3. 4. 1. 2. 3. 4. 1. 2. 3. 4. The principles and Key Concepts described in section 3.1 Principles Supporting Platform Resiliency of NIST SP 800-193 provide the high-level information on controls that can be measured and managed according to a security control framework. Considering the root/chain of trust (Section 3.3), describe how the controls to ensure a system is protected, recoverable, and resilient can be managed. Automation is possible and techniques are available such as using standards for the TPM measurements from the Trusted Computing Group. How do these map into NIST SP 800-53 controls? When providing the answer, combine the sets of information into a single response. Control descriptions from NIST SP 800-193 are mapped to NIST SP 800-53r5 controls and not separate responses. Type NIST 800-53 control Description of control implementation Protected Recoverable Resilient NIST’s Cyber Security Control Framework is intended for use to map between security programs of organizations and as a way to progress a security program articulating risk management practices. Describe the evolution of a security program in context of the concept of Tiers from partial to adaptive including moving toward and embracing continuous audit cycles before reaching the stage of adaptable. Response may be bulleted and should be limited to 200 words total.