New publication fundamentally changes federal information security risk management

Mar 02, 2011 By Evelyn Brown

The National Institute of Standards and Technology (NIST) has published the final version of a special publication that can help organizations to more effectively integrate information security risk planning into their mission-critical functions and overall goals.

Managing Risk: Organization, Mission, and Information System View (NIST Special Publication 800-39) provides the groundwork for a three-tiered, approach that "fundamentally changes how we manage information security risk at the federal level," says Ron Ross, NIST Fellow and one of the principal authors of the publication.

For decades, organizations have managed risk at the information system level that resulted in a very narrow perspective that constrained risk-based decisions by senior management, Ross explains. SP 800-39 calls for a holistic approach in which senior leaders determine what needs to be protected based on the organization's core missions and business functions. For example, managers of a power plant tied to the distribution grid need to ensure that its computer security keeps hackers from interfering with the plant's power generation or getting into the power grid to wreak greater havoc.

The publication is the fourth in the series of risk management and information security guidelines being developed by the Joint Task Force Transformation Initiative, a joint partnership among the Department of Defense, Intelligence Community, NIST and the Committee on National Security Systems.

The multi-tiered risk management approach described in SP 800-39 progresses from organization to missions to . The goal is to ensure that strategic considerations drive investment and operational decisions with regard to managing risk to organizational operations (including mission, function, image and reputation), organizational assets, individuals, other organizations (collaborating or partnering with federal agencies and contractors) and the nation.

This type of risk-based, decision making is critical as organizations address advanced persistent threats of sophisticated cyber attacks that have the potential to degrade or debilitate information systems supporting the federal government's critical applications and operations.

"SP 800-39 is about building more secure information systems which will ultimately allow senior leaders and executives to better understand the mission and business risk brought into their enterprises by the ever-increasing use of, and dependence on, information technology and network connectivity," Ross says.

Explore further: Pakistan adopts Chinese rival GPS satellite system

More information: SP 800-39, Managing Information Security Risk: Organization, Mission, and Information System View, has been developed in support of the Federal Information Security Management Act (FISMA). It can be downloaded from csrc.nist.gov/publications/nistpubs/800-39/SP800-39-final.pdf

add to favorites email to friend print save as pdf

Related Stories

Wake-up call: Draft security pub looks at cell phones, PDAs

Jul 10, 2008

In recent years cell phones and PDAs—"Personal Digital Assistants"—have exploded in power, performance and features. They now often boast expanded memory, cameras, Global Positioning System receivers and the ability to ...

New publication offers security tips for WiMAX networks

Oct 07, 2009

Government agencies and other organizations planning to use WiMAX -- Worldwide Interoperability for Microwave Access—networks can get technical advice on improving the security of their systems from a draft computer security ...

Recommended for you

Pakistan adopts Chinese rival GPS satellite system

18 minutes ago

Pakistan is set to become the fifth Asian country to use China's domestic satellite navigation system which was launched as a rival to the US global positioning system, a report said Saturday.

British children's on-screen reading overtakes books

May 16, 2013

For the first time, British children are reading more on computers and other electronic devices than they are reading books, magazines, newspapers and comics, according to a study of nearly 35,000 youngsters ...

Exploring the artsy side of 3-D printing

May 16, 2013

Three-D printing technology is a game changer in the arts and crafts world. "It really takes the lid off of what's possible," says Andrej Suskavcevic, president and CEO of the Craft and Hobby Association, ...

IT industry ignores silver surfers at its peril

May 14, 2013

Hardware and software vendors are foolish to ignore the needs of the growing population of older computer and information technology users, the so-called "silver surfers". US researchers offer convincing evidence in a monograph ...

User comments : 0

More news stories

Morocco to harness the wind in energy hunt

Morocco is ploughing ahead with a programme to boost wind energy production, particularly in the southern Tarfaya region, where Africa's largest wind farm is set to open in 2014.

Yahoo Japan suspects 22 million IDs stolen

Yahoo Japan Corp. has said it suspects up to 22 million user IDs may have been stolen during an unauthorised attempt to access the administrative system of its Yahoo! Japan portal.

New case of SARS-like virus in Saudi: ministry

A new case of the deadly coronavirus has been detected in Saudi Arabia where 15 people have already died after contracting it, the health ministry announced on Saturday on its Internet website.

Galaxy's Ring of Fire

Johnny Cash may have preferred this galaxy's burning ring of fire to the one he sang about falling into in his popular song. The "starburst ring" seen at center in red and yellow hues is not the product of ...