New NIST publication provides guidance for computer security risk assessments

Sep 19, 2012

The National Institute of Standards and Technology has released a final version of its risk assessment guidelines that can provide senior leaders and executives with the information they need to understand and make decisions about their organization's current information security risks and information technology infrastructures.

" are an important tool for managers," explains Ron Ross, NIST fellow and one of the authors of Guide for Conducting Risk Assessments. "With the increasing breadth and depth of on and the U.S. , risk assessments provide important information to guide and inform the selection of appropriate defensive measures so organizations can respond effectively to cyber-related risks."

Information technology risks include risk to the organization's operations (including, for example, missions and reputation), its critical assets such as data and physical property, and individuals who are part of or served by the organization. In some cases, these risks extend to the nation as a whole. Risk assessments are part of an organization's total risk management process.

In March 2011, NIST released Managing Information Security Risk: Organization, Missions and Information System View (NIST Special Publication 800-39), which describes the process for managing information for federal agencies and contractors. That process includes framing risk, assessing risk, responding to risk and monitoring risk over time.

The new publication, Guide for Conducting Risk Assessments, focuses exclusively on risk assessment—the second step in the information security risk management process. The guidance covers the four elements of a classic risk assessment: threats, vulnerabilities, impact to missions and business operations, and the likelihood of threat exploitation of vulnerabilities in information systems and their to cause harm or adverse consequences.

"As the size and complexity of our collective IT infrastructure grows, we cannot protect everything we own or manage to the highest degree," says Ross. "Risk assessments show us where we are most at risk. It provides a way to decide where managers should focus their attention."

The risk assessment guidance is designed to meet the needs of a variety of organizations, large and small, including financial institutions, health care providers, software developers, manufacturing companies, military planners and operators, and law enforcement groups.

The Guide for Conducting Risk Assessments (SP 800-30, Revision 1) completes the original series of five key computer security documents envisioned by the Joint Task Force—a partnership of NIST, the Department of Defense, the Office of the Director of National Intelligence and the Committee on National Security Systems—to create a unified framework for the federal government. SP 800-39 is also in this series.

The guide is available at www.nist.gov/manuscript-publication-search.cfm?pub_id=912091 .

Explore further: Tablets thrust Thai classrooms into digital era

add to favorites email to friend print save as pdf

Related Stories

Recommended for you

US spy chief: Plot against Wall Street foiled

3 hours ago

The U.S. foiled a plot to bomb the New York Stock Exchange because of the sweeping surveillance programs at the heart of a debate over national security and personal privacy, officials said Tuesday at a rare ...

Tablets thrust Thai classrooms into digital era

15 hours ago

In a rural classroom in the Thai highlands, hill tribe children energetically slide their fingertips over tablet computer screens practicing everything from English to mathematics and music.

Research examines how technology can break down barriers

Jun 17, 2013

A small, pilot study is examining how mobile technology might support deaf and hard-of-hearing college students when an interpreter can't physically be present at the time the services are requested. The University of Cincinnati ...

Hands-free texting still distracting for drivers (Update)

Jun 12, 2013

Using voice commands to send text messages and emails from behind the wheel, which is marketed as a safer alternative for drivers, actually is more distracting and dangerous than simply talking on a cellphone, ...

Smartphones, drones, to save lives in Malawi

Jun 11, 2013

A mobile phone equipped to measure heart rate, body temperature and breathing, with a digital medical manual for health care staff. Unmanned drones that can drop medicine and collect blood samples in remote areas. Researchers ...

User comments : 0

More news stories

3D printing tiny batteries

(Phys.org) —3D printing can now be used to print lithium-ion microbatteries the size of a grain of sand. The printed microbatteries could supply electricity to tiny devices in fields from medicine to communications, ...

Origins of 'The Hoff' crab revealed (w/ Video)

The history of a new type of crab, nicknamed 'The Hoff' because of its hairy chest, which lives around hydrothermal vents deep beneath the Southern Ocean and Indian Ocean, has been revealed for the first ...