NIST Updates Federal Cybersecurity Guidelines

National Institute for Standards and Technology simplified security assessment and control procedures to focus on near-real-time risk management.

The National Institute for Standards and Technology (NIST) on Wednesday released an updated set of guidelines that organizations can use to develop their security assessment plans, as well as their associated procedures for security controls.

The 399-page set of guidelines is officially dubbed NIST Special Publication 800-53A, Revision 1, Guide for Assessing the Security Controls in Federal Information Systems and Organizations Building Effective Security Assessment Plans. The guidelines are designed to complement Special Publication 800-53, Recommended Security Controls for Federal Information Systems and Organizations.


More Government Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

According to NIST, 800-53A include procedures "for both national security and non-national security systems," which are aimed at all parts of the development lifecycle, including development, implementation, and operation.

Revisions include numerous simplifications, such as eliminating the extended assessment procedure, simplifying much of the nomenclature, and removing various designations in the assessment procedures catalog.

"These simplifications will provide organizations with greater flexibility in selecting appropriate assessment methods, such as those supporting information system developments, initial and ongoing security authorizations, and continuous monitoring," according to NIST.

These revisions "are part of a larger strategic initiative to focus on enterprise-wide, near-real-time risk management," according to a statement from Ron Ross, who leads the FISMA Implementation Project, which was established in 2003, as required by Congressional legislation, to develop security guidelines and standards.

"Achieving the objective of near-real-time risk management means that organizations must have the flexibility to tailor their assessment activities based on where the information system is in its lifecycle, from initial development to continuous monitoring in operational environments," he said.

NIST said the revised 800-53A guide remains consistent with the Federal Information Security Management Act (FISMA), which sets guidelines and security standards for government agencies, as well as contractors. FISMA can also assess their compliance through audits.

From NASA to the CIA, CIOs are coming up with innovative approaches to long-standing challenges. Download the latest all-digital issue of InformationWeek Government for that story and more. (Free registration required.)

Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS

Resource Links