Where can I find detailed information on planning/documenting/implementing information technology (IT) security in a Federal agency?
A. NIST has developed several guidance documents. NIST Special Publication 800-12, “An Introduction to Computer Security: The NIST Handbook” offers guidance on all areas of a Federal security IT program. NIST Special Publication 800-14, “Generally Accepted Principles and Practices for Securing Information Technology Systems” (.pdf format) contains what should be done in securing IT resources. Additionally, the Program Management section in the FASP area contains examples of agency security program plans and handbooks.
Related Questions
- How does a Federal funding agency insure that an agency is engaged in relocation planning and providing the advisory services described in this section? How does an agency demonstrate compliance?
- Where can I find detailed information on planning/documenting/implementing information technology (IT) security in a Federal agency?
- Does ISO have any interaction with the Federal Emergency Management Agency or the Department of Homeland Security?