New publication fundamentally changes federal information security risk management

Posted In: Information Tech

By EurekAlert

Wednesday, March 2, 2011


newsvine diigo google
slashdot
Share
Loading...

The National Institute of Standards and Technology (NIST) has published the final version of a special publication that can help organizations to more effectively integrate information security risk planning into their mission-critical functions and overall goals.

Managing Information Security Risk: Organization, Mission, and Information System View (NIST Special Publication 800-39) provides the groundwork for a three-tiered, risk-management approach that "fundamentally changes how we manage information security risk at the federal level," says Ron Ross, NIST Fellow and one of the principal authors of the publication.

For decades, organizations have managed risk at the information system level that resulted in a very narrow perspective that constrained risk-based decisions by senior management, Ross explains. SP 800-39 calls for a holistic approach in which senior leaders determine what needs to be protected based on the organization's core missions and business functions. For example, managers of a power plant tied to the distribution grid need to ensure that its computer security keeps hackers from interfering with the plant's power generation or getting into the power grid to wreak greater havoc.

The publication is the fourth in the series of risk management and information security guidelines being developed by the Joint Task Force Transformation Initiative, a joint partnership among the Department of Defense, Intelligence Community, NIST and the Committee on National Security Systems.

The multi-tiered risk management approach described in SP 800-39 progresses from organization to missions to information systems. The goal is to ensure that strategic considerations drive investment and operational decisions with regard to managing risk to organizational operations (including mission, function, image and reputation), organizational assets, individuals, other organizations (collaborating or partnering with federal agencies and contractors) and the nation.

This type of risk-based, decision making is critical as organizations address advanced persistent threats of sophisticated cyber attacks that have the potential to degrade or debilitate information systems supporting the federal government's critical applications and operations.

"SP 800-39 is about building more secure information systems which will ultimately allow senior leaders and executives to better understand the mission and business risk brought into their enterprises by the ever-increasing use of, and dependence on, information technology and network connectivity," Ross says.

SOURCE

0 Comments

blog comments powered by Disqus

New To Market

more

JEOL to launch world's smallest solid-state NMR probe
JEOL to launch world's smallest solid-state NMR probe

According to JEOL Resonance, a new benchmark for resolution and benchmark will be set with its introduction next week of a new 0.75-mm solid state nuclear magnetic resonance (NMR) probe. The probe is capable of high resolution sample analysis by spinning the sample at 110 kHz, the world's fastest spinning speed for NMR.

Energy Harvesting Subsystems for Wireless Sensors

Nextreme Thermal Solutions has developed two new energy harvesting subsystems for the plumbing and HVAC industries. The subsystems are the latest additions to Nextreme's Thermobility energy harvesting platform that uses thin-film thermoelectric technology to convert available thermal energy into electric power for a variety of autonomous self-powered applications.

Tools & Technology

more

Microscope System with LED Illumination
Microscope System with LED Illumination

Leica Microsystems has introduced the Leica DM4000 B LED, a microscope system with LED illumination suited for biomedical applications.

Liquid Handler

Gilson Inc. has introduced the GX-241 liquid handler, a compact liquid handler suited for application and laboratories where bench space is at a premium.

Advertisement

Advertisement

Top Stories and Headlines
EVERY DAY!

FREE Email Newsletter