- The Future of Information System Authorization

Patrick D. Howard · Auerbach Publications eBooks · 2012

With the passage of the Federal Information Security Management Act (FISMA) and other federal legislation that mandated implementation of security controls to protect government information, compliance has become a primary business requirement for federal agencies that have generally accepted these mandated requirements. Likewise, private rms that have contractual relationships with the federal government are also meeting these security-related compliance requirements. Because of this compliance focus, the continued reliance on system authorization is certain, and with its gradual recognition as an effective means for managing security risk, its future at least for the next decade is ensured. The body of guidance that has been developed by the National Institute of Standards and Technology (NIST) has provided a solid foundation for a practical and simplied approach to system authorization, and NIST’s commitment to system authorization gives reason to believe that it will stand the test of time.

Read the paper · More papers on PaperTik