NIST Updates Federal Cybersecurity Guidelines
National Institute for Standards and Technology simplified security assessment and control procedures to focus on near-real-time risk management.The National Institute for Standards and Technology (NIST) on Wednesday released an updated set of guidelines that organizations can use to develop their security assessment plans, as well as their associated procedures for security controls.
The 399-page set of guidelines is officially dubbed NIST Special Publication 800-53A, Revision 1, Guide for Assessing the Security Controls in Federal Information Systems and Organizations Building Effective Security Assessment Plans. The guidelines are designed to complement Special Publication 800-53, Recommended Security Controls for Federal Information Systems and Organizations.
More Government Insights
Webcasts
- Single Source of Truth for Managing Critical Assets Application Consolidation across Public Sector Organizations
- Reliable Information for Actionable Insights
White Papers
More >>Reports
More >>According to NIST, 800-53A include procedures "for both national security and non-national security systems," which are aimed at all parts of the development lifecycle, including development, implementation, and operation.
Revisions include numerous simplifications, such as eliminating the extended assessment procedure, simplifying much of the nomenclature, and removing various designations in the assessment procedures catalog.
"These simplifications will provide organizations with greater flexibility in selecting appropriate assessment methods, such as those supporting information system developments, initial and ongoing security authorizations, and continuous monitoring," according to NIST.
These revisions "are part of a larger strategic initiative to focus on enterprise-wide, near-real-time risk management," according to a statement from Ron Ross, who leads the FISMA Implementation Project, which was established in 2003, as required by Congressional legislation, to develop security guidelines and standards.
"Achieving the objective of near-real-time risk management means that organizations must have the flexibility to tailor their assessment activities based on where the information system is in its lifecycle, from initial development to continuous monitoring in operational environments," he said.
NIST said the revised 800-53A guide remains consistent with the Federal Information Security Management Act (FISMA), which sets guidelines and security standards for government agencies, as well as contractors. FISMA can also assess their compliance through audits.
From NASA to the CIA, CIOs are coming up with innovative approaches to long-standing challenges. Download the latest all-digital issue of InformationWeek Government for that story and more. (Free registration required.)
Related Reading
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
Subscribe to RSSResource Links
Related Webcasts
- Single Source of Truth for Managing Critical Assets Application Consolidation across Public Sector Organizations
- Reliable Information for Actionable Insights
- The view is better up here: breaking through barriers to Cloud
- Supporting an Enterprise-wide Data Archive and Retention Strategy
- High-Frequency Trading: The Good, The Bad and The Ugly
This Week's Issue
Free Print Subscription
SubscribeCurrent Healthcare Issue
- InformationWeek Healthcare CIO 25: Our second annual honor roll of the health IT leaders driving healthcare's transformation.
- EHR Unreadiness: Only a small percentage of physicians planning to apply for Meaningful Use funds have e-health record systems capable of achieving most of the requirements. .
- And much more!
- Read the Current Issue
Related Whitepapers
- Advanced Case Management: Making its Mark on Key Government Sectors
- Unleashing Cloud Performance
- The Creating value in the Public Sector: intelligent project selection in the US federal government
- Improve Business Performance in a Project-Intensive World
- Defining and Planning Continuous Monitoring for NIST Requirements
Featured Whitepaper
In this white paper, Tripwire discusses strategies for defending cyber threats that include monitoring security status of systems throughout the enterprise, detecting threats to sensitive data, and responding to threats in real-time.
Learn More












