Managing Enterprise Security Risk with NIST Standards
Ron Ross · Computer · 2007
Federal agencies and private-sector organizations are increasingly concerned with the risks that today's sophisticated cyberthreats pose to critical enterprise missions and business functions. Federal Information Security Management Act (FISMA) established sweeping information security (IS) requirements for the federal government and contractors, and it made the National Institute of Standards and Technology (NIST) responsible for developing IS standards and guidelines to allow for compliance. NIST faced the challenging task of establishing mandatory minimum IS standards and guidelines for the federal government and supporting contractors, while ensuring flexible implementation based on diverse missions and business functions.