DocumentCode :
3392920
Title :
The new FISMA standards and guidelines changing the dynamic of information security for the federal government
Author :
Ross, Ron ; Katzke, Stuart ; Toth, Patricia
Author_Institution :
Div. of Comput. Security, Nat. Inst. of Stand. & Technol., Gaithersburg, MD
fYear :
2005
fDate :
17-20 Oct. 2005
Firstpage :
864
Abstract :
The Federal Information Security Management Act (FISMA) of 2002 places significant requirements on federal agencies for the protection of information and information systems; and places significant requirements on the National Institute of Standards and Technology (NIST) to assist federal agencies to comply with FISMA. In response to this important legislation, NIST is leading the development of key information system security standards and guidelines as part of its FISMA Implementation Project (http://csrc.nist.gov/sec-cert/index.html). This high-priority project includes the development of security categorization standards; standards and guidelines for the specification, selection, and testing of security controls for information systems; guidelines for the certification review and accreditation of information systems; and guidelines for the continuous monitoring of controls to ensure they continue to operate as intended. This paper includes a discussion of NIST´s FISMA risk management framework (RMF) and the suite of related standards and guidelines being developed by NlST to help federal agencies comply with FISMA requirements (i.e., the FISMA suite of documents). In addition, the paper discusses how agency systems will benefit from applying the FISMA RMF and why the FISMA RMF and the related suite of standards and guidelines should be of interest to other government sectors (e.g., DoD) and to the commercial sector
Keywords :
government data processing; government policies; information management; risk management; security of data; standards; FISMA standards; Federal Information Security Management Act of 2002; NIST; National Institute of Standards and Technology; continuous monitoring; federal agencies; federal government; information security; information system security standards; information systems; risk management framework; security categorization standards; security controls; Control systems; Guidelines; Information management; Information security; Management information systems; NIST; Protection; Standards development; Technology management; US Government;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Military Communications Conference, 2005. MILCOM 2005. IEEE
Conference_Location :
Atlantic City, NJ
Print_ISBN :
0-7803-9393-7
Type :
conf
DOI :
10.1109/MILCOM.2005.1605789
Filename :
1605789
Link To Document :
بازگشت