Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations
Ronald S. Ross, Kelley L. Dempsey, Patrick Viscuso, Mark A. Riddle, Gary Guissanie · 2015
This publication has been developed by NIST to further its statutory responsibilities under the Federal Information Security Modernization Act (FISMA) of 2014, 44 U.S.C. § 3541 et seq., Public Law (P.L.) 113-283.NIST is responsible for developing information security standards and guidelines, including minimum requirements for federal information systems, but such standards and guidelines shall not apply to national security systems without the express approval of appropriate federal officials exercising policy authority over such systems.This guideline is consistent