What federal codes and standards is CSET based on?
CSET requirements were derived from widely accepted standards such as: • NIST SP 800-53: National Institute of Standards and Technology (NIST), Special Publication (SP) 800-53, Recommended Security Controls for Federal Information Systems, Revisions 0, 1, 2, and 3 Final Public Draft, June 2009. • NIST SP 800-82: National Institute of Standards and Technology, Special Publication 800-82, Guide to Industrial Control Systems (ICS) Security, Final Public Draft, September 2008. • NIST SPP-CIPCS: National Institute of Standards and Technology, System Protection Profile – Critical Infrastructure Process Control Systems, Version 1.07, June 2005 (DRAFT). –> • ISO/IEC 15408 (The Common Criteria): International Organization of Standards/ International Electrotechnical Commission, Version 3.1, September 2007. • DODI 8500.2: US Department of Defense (DoD) Instruction Number 8500.2, “Information Assurance (IA) Implementation,” February 6, 2003. • NERC CIP-002 through CIP-009: North American Electri