Challenges in Certification and Accreditation

Ken Buszta · IT Professional · 2008

As the threat of malicious activity through the Internet increased, the US government began reviewing protection requirements for national and international security systems. Legislation resulting from this review included the Federal Information Security Management Act (FISMA), the Paperwork Reduction Act of 1995, and the Information Technology Management Reform Act of 1996 (also known as the Clinger-Cohen Act). This legislation sought to foster trust between the government and the public through significant security improvements in these systems. To this end, it the government established a peer-review process we've come to know as certification and accreditation, or C&A.

Read the paper · More papers on PaperTik