Information Assurance: Managing Organizational IT Security Risks

Provide an understanding of how the organization can monitor and assess its compliance with its established IA policy. There are a variety of automated and nonautomated techniques and approaches that are available to an organization. A proper combination of these techniques and approaches needs to be developed and operated to sufficiently manage an organization's IA posture and maintain an acceptable level of risk.
As discussed in Chapter 6 ("Layer 1: IA Policies"), IA policies are the first layer of any organization's Defense in Depth strategy. IA policies essentially define the bounds of acceptable behavior and actions that are needed to achieve the IA needs of the organization. These policies are intended to control and influence the behavior and actions of people, automated systems, people's interactions with automated systems, and the interactions between automated systems. Therefore, there must be means of monitoring and assessing the extent to which the IA policies are being achieved. The intent of an organization's IA policy compliance oversight function is to provide a means of detecting, reporting, and correcting noncompliance with the IA policies.
The implementation of the compliance oversight can be performed both internally within the organization and by external parties.
First, the implementation of the oversight can be performed by the IA staff within the organization or by employees who have been designated to support the IA staff.
Second, an organization's internal audit staff can perform compliance oversight...