Security and Privacy Controls for Federal Information Systems and Organizations

Security and Privacy Controls for Federal Information Systems and Organizations
复制标题

DOI:
10.6028/nist.sp.800-53r4
复制
发表时间:
2013-04
期刊:
--
影响因子:
--
通讯作者:
J. Initiative
J. Initiative
中科院分区:
其他
文献类型:
--
作者:
J. Initiative

文献摘要

被引文献

相似文献

本出版物提供了联邦信息系统和组织的安全和隐私控制目录,以及选择控制措施的过程,以保护组织运营(包括使命、职能、形象和声誉)、组织资产、个人、其他组织和国家免受各种威胁,包括恶意网络攻击、自然灾害、结构故障和人为错误。这些控制是可定制的,并作为管理信息安全和隐私风险的组织范围流程的一部分实施。这些控制措施满足了联邦政府和关键基础设施的各种安全和隐私要求,这些要求源自立法、行政命令、政策、指令、法规、标准和/或使命/业务需求。该出版物还介绍了如何开发专门的控制或覆盖,为特定类型的任务/业务功能,技术或操作环境量身定制。最后,安全控制目录从功能角度(提供的安全功能和机制的强度)和保证角度(对所实现的安全功能的信心度量)来解决安全问题。同时处理安全功能和安全保证问题,可确保信息技术产品和利用健全的系统和安全工程原则从这些产品建立的信息系统足够值得信赖。
This publication provides a catalog of security and privacy controls for federal information systems and organizations and a process for selecting controls to protect organizational operations (including mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation from a diverse set of threats including hostile cyber attacks, natural disasters, structural failures, and human errors. The controls are customizable and implemented as part of an organization-wide process that manages information security and privacy risk. The controls address a diverse set of security and privacy requirements across the federal government and critical infrastructure, derived from legislation, Executive Orders, policies, directives, regulations, standards, and/or mission/business needs. The publication also describes how to develop specialized sets of controls, or overlays, tailored for specific types of missions/business functions, technologies, or environments of operation. Finally, the catalog of security controls addresses security from both a functionality perspective (the strength of security functions and mechanisms provided) and an assurance perspective (the measures of confidence in the implemented security capability). Addressing both security functionality and security assurance ensures that information technology products and the information systems built from those products using sound systems and security engineering principles are sufficiently trustworthy.