What federal codes and standards are the CS2SAT based on?
The CS2SAT requirements were derived from widely accepted standards such as: • NERC CIP-002 through CIP-009: North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) (http://www.nerc.com/), Effective June 1, 2006. • NIST SP 800-53: National Institute of Standards and Technology (NIST), Special Publication (SP) 800-53, Recommended Security Controls for Federal Information Systems, Revisions 0, 1, and 2. • NIST SPP-ICS: National Institute of Standards and Technology, System Protection Profile – Industrial Control Systems, Version 1.0, April 2004. • NIST SPP-CIPCS: National Institute of Standards and Technology, System Protection Profile – Critical Infrastructure Process Control Systems, Version 1.07, June 2005 (DRAFT). • ISO/IEC 15408 (The Common Criteria): International Organization of Standards/ International Electrotechnical Commission, Versions 2.1 to 3.0. • DODI 8500.2: US Department of Defense (DOD) Instruction Number 8500.2, “Information Assu