Featured Research

from universities, journals, and other organizations

New publication fundamentally changes federal information security risk management

Date:
March 2, 2011
Source:
National Institute of Standards and Technology (NIST)
Summary:
NIST has published the final version of a special publication that can help guide organizations in more effectively integrating information security risk planning into their mission-critical functions and overall goals.

The National Institute of Standards and Technology (NIST) has published the final version of a special publication that can help organizations to more effectively integrate information security risk planning into their mission-critical functions and overall goals.

Managing Information Security Risk: Organization, Mission, and Information System View (NIST Special Publication 800-39) provides the groundwork for a three-tiered, risk-management approach that "fundamentally changes how we manage information security risk at the federal level," says Ron Ross, NIST Fellow and one of the principal authors of the publication.

For decades, organizations have managed risk at the information system level that resulted in a very narrow perspective that constrained risk-based decisions by senior management, Ross explains. SP 800-39 calls for a holistic approach in which senior leaders determine what needs to be protected based on the organization's core missions and business functions. For example, managers of a power plant tied to the distribution grid need to ensure that its computer security keeps hackers from interfering with the plant's power generation or getting into the power grid to wreak greater havoc.

The publication is the fourth in the series of risk management and information security guidelines being developed by the Joint Task Force Transformation Initiative, a joint partnership among the Department of Defense, Intelligence Community, NIST and the Committee on National Security Systems.

The multi-tiered risk management approach described in SP 800-39 progresses from organization to missions to information systems. The goal is to ensure that strategic considerations drive investment and operational decisions with regard to managing risk to organizational operations (including mission, function, image and reputation), organizational assets, individuals, other organizations (collaborating or partnering with federal agencies and contractors) and the nation.

This type of risk-based, decision making is critical as organizations address advanced persistent threats of sophisticated cyber attacks that have the potential to degrade or debilitate information systems supporting the federal government's critical applications and operations.

"SP 800-39 is about building more secure information systems which will ultimately allow senior leaders and executives to better understand the mission and business risk brought into their enterprises by the ever-increasing use of, and dependence on, information technology and network connectivity," Ross says.

SP 800-39, Managing Information Security Risk: Organization, Mission, and Information System View, has been developed in support of the Federal Information Security Management Act (FISMA). It can be downloaded from http://csrc.nist.gov/publications/nistpubs/800-39/SP800-39-final.pdf.


Story Source:

The above story is based on materials provided by National Institute of Standards and Technology (NIST). Note: Materials may be edited for content and length.


Cite This Page:

National Institute of Standards and Technology (NIST). "New publication fundamentally changes federal information security risk management." ScienceDaily. ScienceDaily, 2 March 2011. <www.sciencedaily.com/releases/2011/03/110302131940.htm>.
National Institute of Standards and Technology (NIST). (2011, March 2). New publication fundamentally changes federal information security risk management. ScienceDaily. Retrieved September 30, 2014 from www.sciencedaily.com/releases/2011/03/110302131940.htm
National Institute of Standards and Technology (NIST). "New publication fundamentally changes federal information security risk management." ScienceDaily. www.sciencedaily.com/releases/2011/03/110302131940.htm (accessed September 30, 2014).

Share This



More Computers & Math News

Tuesday, September 30, 2014

Featured Research

from universities, journals, and other organizations


Featured Videos

from AP, Reuters, AFP, and other news services

Apple Releases 'Shellshock' Fix Despite Few Affected Users

Apple Releases 'Shellshock' Fix Despite Few Affected Users

Newsy (Sep. 29, 2014) Apple released a security fix for the "Shellshock" vulnerability Monday, though it says only "advanced UNIX users" of OS X need it. Video provided by Newsy
Powered by NewsLook.com
Do Video Games Trump Brain Training For Cognitive Boosts?

Do Video Games Trump Brain Training For Cognitive Boosts?

Newsy (Sep. 29, 2014) More and more studies are showing positive benefits to playing video games, but the jury is still out on brain training programs. Video provided by Newsy
Powered by NewsLook.com
New Facebook Ad Platform Goes Where You Go On The Web

New Facebook Ad Platform Goes Where You Go On The Web

Newsy (Sep. 29, 2014) Called Atlas, the platform allows advertisers to place ads based on Facebook info on sites outside of Facebook. Video provided by Newsy
Powered by NewsLook.com
Google Tightens Requirements For Android Manufacturers

Google Tightens Requirements For Android Manufacturers

Newsy (Sep. 27, 2014) Phonemakers who want to use Google’s software in their devices will have to stick to more stringent requirements. Video provided by Newsy
Powered by NewsLook.com

Search ScienceDaily

Number of stories in archives: 140,361

Find with keyword(s):
Enter a keyword or phrase to search ScienceDaily for related topics and research stories.

Save/Print:
Share:

Breaking News:

Strange & Offbeat Stories


Space & Time

Matter & Energy

Computers & Math

In Other News

... from NewsDaily.com

Science News

Health News

Environment News

Technology News



Save/Print:
Share:

Free Subscriptions


Get the latest science news with ScienceDaily's free email newsletters, updated daily and weekly. Or view hourly updated newsfeeds in your RSS reader:

Get Social & Mobile


Keep up to date with the latest news from ScienceDaily via social networks and mobile apps:

Have Feedback?


Tell us what you think of ScienceDaily -- we welcome both positive and negative comments. Have any problems using the site? Questions?
Mobile: iPhone Android Web
Follow: Facebook Twitter Google+
Subscribe: RSS Feeds Email Newsletters
Latest Headlines Health & Medicine Mind & Brain Space & Time Matter & Energy Computers & Math Plants & Animals Earth & Climate Fossils & Ruins