Operations and Maintenance
Goal: Sustain security and privacy posture throughout operations.
- Maintain a schedule for vulnerability scanning, patch management, and configuration reviews.
- Conduct periodic privacy and security control reviews and update PIAs as needed.
- Ensure change management enforces security reviews and testing before changes are applied.
- Continue training for administrators and users; run phishing and awareness programs.
- Keep data retention schedules and securely sanitize or delete data when no longer required.
- Keep an incident response plan current and conduct tabletop exercises regularly.
No Comments