Answer should be original, and similarity (plagiarism) not more than 10% this is very important otherwise I will be in trouble.
Answer should be a clear explanation and should be clear understanding (500 words).
Answer should be references on Harvard style (Not use Wikipedia) should be Academic Articles or books.
When use citation from any reference please keep it between "citation" (Author,Year),please citation should be not more than 5%
As reference you can use the following book:
Security Engineering: A Guide to Building Dependable Distributed Systems (2nd Edition)
Author: Anderson, R.
ISBN: ISBN-10: 0470068523 ISBN-13: 978-0470068526
Publisher: John Wiley & Sons
Book available from below link:
http://www.cl.cam.ac.uk/~rja14/book.html
Assignment is:
Make yourself familiar with the concept of security controls. How it can be used for organization/system security evaluation and risk assessment?
Useful links:
The Standard of Good Practice for Information Securityhttps://www.isfsecuritystandard.com/SOGP07/index.htm
SP 800-110 DRAFT Information System Security Reference Data Modelhttp://www.csrc.nist.gov/publications/drafts/sp800-110/Draft-SP800-110.pdf Security Controls for Federal Information systems.
Recommendedhttp://www.csrc.nist.gov/publications/nistpubs/800-53/SP800-53.pdf