|
NIST SP 800-53A SI-05 .01(iv)
|
Question: Do the system and information integrity policy and the procedures addressing security alerts and advisories specify that the organization maintain contact with special interest groups (e.g., information security forums) that: (a) facilitate sharing of security-related information (e.g., threats, vulnerabilities, and latest security technologies), (b) provide access to advice from security professionals, and (c) improve knowledge of security best practices ? |