Carry out a security self-assessment of an organization using the NIST Special Publication 800-26 as a guide. This may be your current or previous employer or your own organization. You must seek permission from the individual responsible for the information security of that organization.
The SP 800-26 document is a self-assessment guide to assess the IT system of an organization. This document is no longer available from NIST but it is available in the Management of Information Security (Michael Whitman) text book appendix Use primary areas uch as Management controls, Operational controls, Technical controls, etc., as a guide to assess a system. I am only looking for 4-5 page report.
Document is in draft form. Those of you who are working or are experienced in Federal IT Systems may use this publication as an alternative to SP 800-26.
Basically you have a choice of using SP 800-26 or 53A.
Report
prepare a report based on the self-assessment of an organization. It should be 4-5 pages long, 12 point character size, single line spacing, and 1" margins (left, right, top, and bottom). It is recommended that you do not use the actual name of the organization in the report; use a title, such as "ABC Inc." Your report should include a brief description of the organization, nature of the business, analysis of the
results, and recommendations for improvement in the form of an action plan.