The Case for Flexible NIST Security Standards.
The article discusses the role of the U.S. National Institute of Standards and Technology (NIST) in issuing information system security standards (ISS). The Computer Security Act of 1987 and the Federal Information Security Act of 2002 (FISMA) established the NIST's authority to issue computer secur...
| Publicado en: | Computer (00189162) Vol. 40; no. 6; pp. 19 - 27 |
|---|---|
| Autores principales: | , |
| Formato: | Artículo |
| Publicado: |
IEEE
Jun2007
|
| Materias: | |
| Acceso en línea: | Ver este registro en EBSCOhost |
| fields | @attributes: recordID: 1 pdfLink: plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=25514833&site=ehost-live header: @attributes: shortDbName: hlh uiTerm: 25514833 longDbName: Humanities International Complete uiTag: AN controlInfo: bkinfo: jinfo: jid: 00189162 PUT jtl: Computer (00189162) issn: 00189162 maglogo: N pubinfo: dt: Jun2007 vid: 40 iid: 6 pid: 13605 pub: IEEE artinfo: ui: 25514833 10.1109/MC.2007.223 ppf: 19 ppct: 8 formats: tig: atl: The Case for Flexible NIST Security Standards. aug: au: Keblawi, Feisal Sullivan, Dick affil: Member, IEEE Computer Society Air Traffic Control Association Certified Information System Security Professional su: National Institute of Standards & Technology (U.S.) Computer security standards Computer security laws Computer network security Internet protocols Risk management in business GOSIP (Computer network standard) Legacy systems Government policy sug: subj: National Institute of Standards & Technology (U.S.) Computer security standards Computer security laws Computer network security Internet protocols Risk management in business GOSIP (Computer network standard) Legacy systems Government policy ab: The article discusses the role of the U.S. National Institute of Standards and Technology (NIST) in issuing information system security standards (ISS). The Computer Security Act of 1987 and the Federal Information Security Act of 2002 (FISMA) established the NIST's authority to issue computer security standards. The authors suggest security control standards issued for federal agencies regulate agency options rather than technology and that flexible security controls are required. The Government Open Systems Interconnection Profile (GOSIP) standard issued by NIST was later replaced by Internet protocols. The authors suggest NIST standards should focus on risk management to prioritize concerns and should address the limitations of commercial products and agencies with legacy systems. pubtype: Academic Journal doctype: Article src: R language: English refInfo: copyright: @attributes: flag: Y dt: @attributes: year: 2007 holdings: @attributes: islocal: N |
|---|