The Case for Flexible NIST Security Standards.

The article discusses the role of the U.S. National Institute of Standards and Technology (NIST) in issuing information system security standards (ISS). The Computer Security Act of 1987 and the Federal Information Security Act of 2002 (FISMA) established the NIST's authority to issue computer secur...

Descripción completa

Detalles Bibliográficos
Publicado en:Computer (00189162) Vol. 40; no. 6; pp. 19 - 27
Autores principales: Keblawi, Feisal, Sullivan, Dick
Formato: Artículo
Publicado: IEEE Jun2007
Materias:
Acceso en línea:Ver este registro en EBSCOhost
Descripción
Sumario:The article discusses the role of the U.S. National Institute of Standards and Technology (NIST) in issuing information system security standards (ISS). The Computer Security Act of 1987 and the Federal Information Security Act of 2002 (FISMA) established the NIST's authority to issue computer security standards. The authors suggest security control standards issued for federal agencies regulate agency options rather than technology and that flexible security controls are required. The Government Open Systems Interconnection Profile (GOSIP) standard issued by NIST was later replaced by Internet protocols. The authors suggest NIST standards should focus on risk management to prioritize concerns and should address the limitations of commercial products and agencies with legacy systems.