Managing Enterprise Security Risk with NIST Standards

Ron Ross · Computer · 2007

Federal agencies and private-sector organizations are increasingly concerned with the risks that today's sophisticated cyberthreats pose to critical enterprise missions and business functions. Federal Information Security Management Act (FISMA) established sweeping information security (IS) requirements for the federal government and contractors, and it made the National Institute of Standards and Technology (NIST) responsible for developing IS standards and guidelines to allow for compliance. NIST faced the challenging task of establishing mandatory minimum IS standards and guidelines for the federal government and supporting contractors, while ensuring flexible implementation based on diverse missions and business functions.

Read the paper · More papers on PaperTik