SP 800-100. Information Security Handbook: A Guide for Managers

SP 800-100. Information Security Handbook: A Guide for Managers
复制标题

SP 800-100。

DOI:
--
复制
发表时间:
2006
期刊:
影响因子:
--
通讯作者:
Mark Wilson
Mark Wilson
中科院分区:
--
文献类型:
--
作者:
P. Bowen;Joan Hash;Mark Wilson

文献摘要

被引文献

相似文献

本《信息安全手册》提供了信息安全计划要素的广泛概述,以帮助管理人员了解如何建立和实施信息安全计划。通常,组织希望该计划负起全面责任,以确保选择和实施适当的安全控制措施,并证明满足其声明的安全要求的有效性。本文件中的专题是根据与信息安全有关的法律和法规选定的,其中包括1996年的《克林格-科恩法》、2002年的《联邦信息安全管理法》和管理和预算局的A-130号通告。本手册中的材料可作为特定主题的一般信息参考,也可用于制定信息安全计划的决策过程。国家标准与技术研究所(NIST)机构间报告(IR)7298,关键信息安全术语词汇表,提供了本文档中使用的基本安全术语的摘要词汇表。在阅读本手册时,请考虑到该指南并不是针对特定机构的。各机构应根据其安全态势和业务要求定制本指南。
This Information Security Handbook provides a broad overview of information security program elements to assist managers in understanding how to establish and implement an information security program. Typically, the organization looks to the program for overall responsibility to ensure the selection and implementation of appropriate security controls and to demonstrate the effectiveness of satisfying their stated security requirements. The topics within this document were selected based on the laws and regulations relevant to information security, including the Clinger-Cohen Act of 1996, the Federal Information Security Management Act (FISMA) of 2002, and Office of Management and Budget (OMB) Circular A-130. The material in this handbook can be referenced for general information on a particular topic or can be used in the decision making process for developing an information security program. National Institute of Standards and Technology (NIST) Interagency Report (IR) 7298, Glossary of Key Information Security Terms, provides a summary glossary for the basic security terms used throughout this document. While reading this handbook, please consider that the guidance is not specific to a particular agency. Agencies should tailor this guidance according to their security posture and business requirements.