1989 Computer Security and Privacy Plans (CSSP) review project:

Dennis M Gilbert · 1990

The goal of the Computer Security Act of 1987 (Public Law 100-235) (the Act) is to prompt federal agencies to take measures to improve the security and privacy of sensitive information in federal computer systems.The Act requires federal agencies to prepare and submit for review security plans for unclassified computer systems that contain sensitive information.The Act provides that the plans be submitted to the National Institute of Standards and Technology (NIST) and the National Security Agency (NSA) for review and comment.This report describes the Computer Security and Privacy Plan (CSPP) review effort that was conducted in response to the Act by a joint team from NIST and NSA in 1989.The report also discusses future directions for implementing the Act.iiiThe Computer Security Act of 1987 (the Act) has further increased our growing awareness that information and information resources are integral to the functioning of government -and that their protection is fundamental, not peripheral to, the government serving the public trust.We applaud and support the efforts undertaken under the Act and welcome the opportunity to further serve in this area.We would like to acknowledge, congratulate, and thank the many individuals and agencies that took the time and effort to seriously examine their computer security programs and plans.We are proud of the vital role that our organizations play in supporting the Act's goals.We look forward to continued cooperation between our organizations in carrying out the spirit of the Computer Security Act to better serve the federal community and, ultimately, the public.

Read the paper · More papers on PaperTik