Premium Content

Access "Viewpoint: FIPS concepts applicable beyond governments"

Published: 22 Oct 2012

Follow Government's Lead Dave Shackleford ("Shine Those Skills," November 2007) states CISOs need to be more concerned with risk management, and not so much with technical details. I agree; however, I would like to point out that risk management is at the heart of the certification and accreditation process used by the government to control which systems are allowed into operation. The process is described by the DoD's "Information Assurance Certification and Accreditation Process Interim Guidance," and by FIPS 200: "Minimum Security Requirements for Federal Information and Information Systems" and NIST Special Publication 800-53, "Recommended Security Controls for Federal Information Systems," for other government agencies. In both cases, the processes include a number of steps to determine and mitigate the risks to the system, ending up with a determination that the risks have been adequately identified and can be mitigated (certification) and an acceptance of the residual risks by a responsibility party (accreditation). Although these processes are aimed ... Access >>>

Access TechTarget
Premium Content for Free.

By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

What's Inside

Features

More Premium Content Accessible For Free