Recommended security controls for federal information systems and organizations
Robert S. Ross, S Katzke, L A Johnson, M Swanson, Gary Stoneburner, George Oliver Rogers · 2006
The answers to these questions are not given in isolation but rather in the context of an effective information security program for the organization that identifies, controls, and mitigates risks to its information and information systems.6 The security controls defined in Special Publication 800-53 and recommended for use by organizations in protecting their information systems should be employed in conjunction with and as part of a well-defined and documented information security program.An effective information security program should include:• Periodic assessments of risk, including the magnitude of harm that could result from the unauthorized access, use, disclosure, disruption, modification, or destruction of information and information systems that support the operations and assets of the organization;• Policies and procedures that are based on risk assessments, cost-effectively reduce information security risks to an acceptable level and address information security throughout the life cycle of each organizational information system; 3 An information system is a discrete set of information resources organized expressly for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.Information systems also include specialized systems such as industrial/process controls systems, telephone switching/private branch exchange (PBX) systems, and environmental control systems.4 Organizational operations include mission, functions, image, and reputation.5 Security control effectiveness addresses the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the information system in its operational environment.6 The E-Government Act (P.L. 107-347), passed by the one hundred and seventh Congress and signed into law by the President in December 2002, recognized the importance of information security to the economic and national security interests of the United States.Title III of the E-Government Act, entitled the Federal Information Security Management Act (FISMA), emphasizes the need for organizations to develop, document, and implement an organization-wide program to provide security for the information systems that support its operations and assets. PAGE 1Special Publication 800-53, Revision 1systems, or groups of information systems, as appropriate;• Security awareness training to inform personnel (including contractors and other users of information systems that support the operations and assets of the organization) of the information security risks associated with their activities and their responsibilities in complying with organizational policies and procedures designed to reduce these risks;• Periodic testing and evaluation of the effectiveness of information security policies, procedures, practices, and security controls to be performed with a frequency depending on risk, but no less than annually;• A process for planning, implementing, evaluating, and documenting remedial actions to address any deficiencies in the information security policies, procedures, and practices of the organization;• Procedures for detecting, reporting, and responding to security incidents; and• Plans and procedures for continuity of operations for information systems that support the operations and assets of the organization.It is of paramount importance that responsible officials within the organization understand the risks and other factors that could adversely affect organizational operations, organizational assets, or individuals.Moreover, these officials must understand the current status of their security programs and the security controls planned or in place to protect their information systems in order to make informed judgments and investments that appropriately mitigate risks to an acceptable level.The ultimate objective is to conduct the day-to-day operations of the organization and to accomplish the organization's stated mission(s) with what the Office of Management and Budget (OMB) Circular A-130 defines as adequate security, or security commensurate with risk, including the magnitude of harm to individuals, the organization, or its assets resulting from the unauthorized access, use, disclosure, disruption, modification, or destruction of information.determining security control effectiveness.The guidelines provided in this special publication are applicable to all federal information systems 8 other than those systems designated as national security systems as defined in 44 U.S.C., Section 3542.9 The guidelines have been broadly developed from a technical perspec to complement similar guidelines for national security systems.This publication is intended to provide guidance to federal agencies implementing FIPS 200, Minimum Security Requirements for Federal Information and Information Systems.In addition to the agencies of the federal government, state, local, and tribal governments, and private sector organizations that compose the critical infrastructure of the United States, are encouraged to use these guidelines, as appropriate.tive TARGET AUDIENCEThis publication is intended to serve a diverse federal audience of information system and information security professionals including: (i) individuals with information system and information security management and oversight responsibilities (e.g., chief information officers, senior agency information security officers, and authorizing officials); (ii) individuals with information system development responsibilities (e.g., program and project managers, mission/application owners, system designers, system and application programmers); (iii) individuals with information security implementation and operational responsibilities (e.g., information system owners, information owners, information system administrators, information system security officers,); and (iv) individuals with information system and information security assessment and monitoring responsibilities (e.g., auditors, inspectors general, evaluators, and certification agents).Commercial companies producing information technology products and systems, creating information security-related technologies, and providing information security services can also benefit from the information in this publication. RELATIONSHIP TO OTHER SECURITY CONTROL PUBLICATIONSTo create the most technically sound and broadly applicable set of security controls for information systems, a variety of sources were considered during the development of this special publication.The sources included security controls from the defense, audit, financial, healthcare, and intelligence communities as well as controls defined by national and international standards organizations.10 The objective of NIST Special Publication 800-53 is to provide a set of security 8 A federal information system is an information system used or operated by an executive agency, by a contractor of an executive agency, or by another organization on behalf of an executive agency.9 NIST Special Publication 800-59 provides guidance on identifying an information system as a national security system.10 Security controls from the audit, defense, healthcare, intelligence, and standards communities are contained in the following publications: (i) Government Accountability Office, Federal Information System Controls Audit Manual; (ii) Department of Defense Instruction 8500.2,Information Assurance Implementation; (iii) Department of Health and Human Services Centers for Medicare and Medicaid Services, Core Security Requirements; (iv) Director of Central Intelligence Directive 6/3 Manual, Protecting Sensitive Compartmented Information within Information Systems; (v) NIST Special Publication 800-26, Security Self-Assessment Guide for Information Technology Systems; and (vi) International Organization for Standardization/International Electrotechnical Commission 17799:2005, Code of Practice for Information Security Management.