The UNIX and Linux Forums  


Go Back   The UNIX and Linux Forums > Special Forums > Security > IT Security RSS
.
google unix.com



More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
TextCite: Publication Quotation Manager 1.3 (Default branch) iBot Software Releases - RSS News 0 05-08-2008 07:10 PM
TextCite: Publication Quotation Manager 1.0.3 (Default branch) iBot Software Releases - RSS News 0 01-26-2008 10:20 PM
RefDB Publication List 1.1 (Default branch) iBot Software Releases - RSS News 0 12-27-2007 03:40 AM
Patrick Townsend & Associates Achieves NIST Certification of Its ... - Business Wire iBot UNIX and Linux RSS News 0 06-18-2007 01:30 PM

 
English Japanese Spanish French German Portuguese Italian Dutch Swedish Russian Norwegian Hungarian Hebrew Danish Bulgarian Greek Powered by Powered by Google
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Prev Previous Post   Next Post Next
  #1 (permalink)  
Old 02-07-2009
iBot's Avatar
iBot iBot is offline
Forum Robot Girl
  
 

Join Date: Sep 2000
Posts: 22,251
NIST Special Publication (SP) 800-53 Rev. 3 (Initial Public Draft)

On February 5, 2009, NIST released a major revision to NIST SP 800-53.  This is the third revision of the original document widely known among the federal government as the abbreviated 800-53, includes significant changes to the various control baselines ("Low", "Moderate", and "High") used as a basis for assessing the effectiveness of the security of federal information systems.  The changes also reflect adding additional controls that have not been assigned to a control baseline, but may be assigned in the final release or added in future updates:
  • AC-21 (User-Based Collaboration and Information Sharing)
  • CM-9 (Configuration Management Plan)
  • SC-25 (Thin Nodes)
  • SC-26 (Honeypots)
  • SC-27 (Operating System-Independent Applications)
  • SC-29 (Hoterogeneity)
  • SC-30 (Abstraction Techniques)
  • SC-31 (Covert Channel Analysis)
In the summary of changes in the draft of NIST SP 800-53 Rev. 3, NIST noted changes, however some significant significant changes that are important to highlight, include:
  • Consolidation of the steps in the Risk Management Framework (RMF) from 8 to 6 based on changes in NIST SP 800-37 Rev. 1 (Draft) and the new NIST SP 800-39 (Second Public Draft)
  • Many of the security controls were rescoped to either consolidate related controls, or expanded to require additional security requirements (specifically “Moderate” and “High” control baselines
  • A new section was added that focused on Information Security Programs (PM Controls), requiring System Security Plans (SSPs) for Security Programs and also tied in organizational Common Controls
  • Mapping of NIST SP 800-53 Security Controls to the ISO/IEC 270001, (Information technology-Security techniques-Information security management system-Requirements)



More...
 

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 12:59 PM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited. Language Translations Powered by .
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2009. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0