IHS Inc. The Source for Critical Information and Insight
Electronics |  Change  

Go
 
 

Cybersecurity Guidance Promotes Unified Information Security Framework

August 6, 2009 // Published as a news service by IHS

  
Document Management Tools
IHS Standards Expert is an online service providing access to documents from top standards bodies, including ASTM, ISO, ANSI, IEC, DIN, BSI and 100s more.

Features include customized collections, flexible search options, watch lists, advanced navigation and alerts.

To learn more, and for a free quote, please complete the form below.
IHS Standards Expert
First Name:

Last Name:

Email Address:
In a step toward creating a unified information security framework for the U.S. federal government, the National Institute of Standards and Technology (NIST) released NIST Special Publication 800-53 - Recommended Security Controls for Federal Information Systems and Organizations.

According to NIST, information systems at U.S. government civilian agencies have operated under different security controls than military and intelligence information systems.

The unified framework, said NIST, will result in the defense, intelligence and civil communities using a common strategy to protect critical federal information systems and associated infrastructure.

The NIST recommendations were developed based on several guiding principles, including conformance to the minimum security controls for information systems outlined in Federal Information Processing Standards (FIPS) 199 - Standards for Security Categorization of Federal Information and Information Systems.

According to the recommendations, an effective information security program should include:

  • Periodic assessments of risk, including the magnitude of harm that could result from the unauthorized access, use, disclosure, disruption, modification or destruction of information and information systems that support the operations and assets of the organization.
  • Policies and procedures based on risk assessments that cost-effectively reduce information security risks to an acceptable level and address information security throughout the life cycle of each organizational information system.
  • Plans for providing adequate information security for networks, facilities, information systems or groups of information systems, as appropriate.
  • Security awareness training to inform personnel (including contractors and other users) of the information security risks associated with their activities and their responsibilities in complying with organizational policies and procedures designed to reduce these risks.
  • Periodic testing and evaluation (no less than annually) of the effectiveness of information security policies, procedures, practices and security controls to be performed with a frequency depending on risk.
  • A process for planning, implementing, evaluating and documenting remedial actions to address deficiencies in the information security policies, procedures and practices of the organization.
  • Procedures for detecting, reporting and responding to security incidents.
  • Plans and procedures for continuity of operations for information systems that support the operations and assets of the organization.

"This final publication represents a solidification of the partnership between the (U.S.) Department of Defense, the intelligence community and NIST and their efforts to bring common security solutions to the federal government and its support contractors," said Ron Ross of NIST's computer security division.

"The aim is to provide greater protection for federal information systems against cyber attacks."

The recommendations may be found on NIST's Computer Security Resource Center web page.

Source: National Institute of Standards and Technology (NIST).


ELECTRONICS & TELECOM SECURITY NEWS
October 30, 2009
EC Steps Up Legal Action Over Privacy, Personal Data Protection in U.K.
The European Commission (EC) announced on Oct. 29 it moved to the second phase of an infringement proceeding against the United Kingdom over ... more
October 20, 2009
NIST Publishes WiMAX Security Guide
The National Institute of Standards and Technology (NIST) published a draft computer security guide - Special Publication 800-127, Guide to Security ... more
August 31, 2009
IEEE-SA Forms Security Group to Address Computer Security Threats
The Institute of Electrical and Electronics Engineers Standards Association (IEEE-SA) formed the Industry Connections Security Group (ICSG) to ... more
August 6, 2009
Cybersecurity Guidance Promotes Unified Information Security Framework
In a step toward creating a unified information security framework for the U.S. federal government, the National Institute of Standards and Technology ... more
June 4, 2009
ISO/IEC 27000:2009 Addresses Information Security Management Systems
The International Organization for Standardization (ISO) issued ISO/International Electrotechnical Commission (IEC) 27000:2009 - Information ... more
Show All..