The Case for Flexible NIST Security Standards.

The article discusses the role of the U.S. National Institute of Standards and Technology (NIST) in issuing information system security standards (ISS). The Computer Security Act of 1987 and the Federal Information Security Act of 2002 (FISMA) established the NIST's authority to issue computer secur...

Descripción completa

Detalles Bibliográficos
Publicado en:Computer (00189162) Vol. 40; no. 6; pp. 19 - 27
Autores principales: Keblawi, Feisal, Sullivan, Dick
Formato: Artículo
Publicado: IEEE Jun2007
Materias:
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=25514833&site=ehost-live
header:
  @attributes:
    shortDbName: hlh
    uiTerm: 25514833
    longDbName: Humanities International Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    jinfo:
      jid:
        00189162
        PUT
      jtl: Computer (00189162)
      issn: 00189162
      maglogo: N
    pubinfo:
      dt: Jun2007
      vid: 40
      iid: 6
      pid: 13605
      pub: IEEE
    artinfo:
      ui:
        25514833
        10.1109/MC.2007.223
      ppf: 19
      ppct: 8
      formats:
      tig:
        atl: The Case for Flexible NIST Security Standards.
      aug:
        au:
          Keblawi, Feisal
          Sullivan, Dick
        affil:
          Member, IEEE Computer Society
          Air Traffic Control Association
          Certified Information System Security Professional
      su:
        National Institute of Standards & Technology (U.S.)
        Computer security standards
        Computer security laws
        Computer network security
        Internet protocols
        Risk management in business
        GOSIP (Computer network standard)
        Legacy systems
        Government policy
      sug:
        subj:
          National Institute of Standards & Technology (U.S.)
          Computer security standards
          Computer security laws
          Computer network security
          Internet protocols
          Risk management in business
          GOSIP (Computer network standard)
          Legacy systems
          Government policy
      ab: The article discusses the role of the U.S. National Institute of Standards and Technology (NIST) in issuing information system security standards (ISS). The Computer Security Act of 1987 and the Federal Information Security Act of 2002 (FISMA) established the NIST's authority to issue computer security standards. The authors suggest security control standards issued for federal agencies regulate agency options rather than technology and that flexible security controls are required. The Government Open Systems Interconnection Profile (GOSIP) standard issued by NIST was later replaced by Internet protocols. The authors suggest NIST standards should focus on risk management to prioritize concerns and should address the limitations of commercial products and agencies with legacy systems.
      pubtype: Academic Journal
      doctype: Article
      src: R
    language: English
    refInfo:
    copyright:
      @attributes:
        flag: Y
      dt:
        @attributes:
          year: 2007
    holdings:
      @attributes:
        islocal: N