NIST Template
The NIST SP 800-53 and FIPS 200 are policies whose intent is to ensure that all information systems apply suitable security controls and requirements. Through evaluation of risk, the policies allow agencies to authenticate their first security control choices and ascertain if extra controls are required to safeguard corporate processes, as well as corporate reputation, mission, image, and functions as well as organizational assets, other agencies, the nation, or individuals (Howard, 2016). The resultant security controls set up a level of security suitable for a particular agency. These policies have been implemented well through collaboration between themselves and other policies. For instance, for an organization to conform to the federal standards, it has to ascertain the type of security aligning to its information system in reference to FIPS Publication 199 (Howard, 2016). Next, it should use the security category outlined in FIPS 200 to obtain the information system impact level, and then appropriately apply customized security controls as delineated in SP 800-53.
NIST template
Document Number | Document Name | Date | NIST Guidance |
NIST Special Publication 800-53 Revision 4 | Security and Privacy Controls for Federal Information Systems and Organizations | 4/30/2013 | It provides guidelines concerning state-of-the-practice security controls and control enhancements addressing areas such as application security, supply chain security, cloud and mobile computing, trustworthiness, insider threat, assurance, application security, advanced persistent threat, and insider threat. |
NIST Special Publication 800-53A Revision 4 | Assessing Security and Privacy Controls in Federal Information Systems and Organizations Building: Effective Assessment Plans | 12/4/2014 | It offers guidelines for building efficient security evaluation procedures and plans for evaluating the efficacy of security controls applied in federal information systems and organizations. |
FIPS PUB 200 | FEDERAL INFORMATION PROCESSING STANDARDS PUBLICATION (Minimum Security Requirements for Federal Information and Information Systems) | 3/9/2006 | It constitutes a set of minimum security requirements for all information systems and federal information. |
References
Howard, P. D. (2016). FISMA principles and best practices: Beyond compliance. CRC press.
U.S. Department of Commerce. (2014). Assessing Security and Privacy Controls in Federal Information Systems and Organizations Building Effective Assessment Plans. Retrieved from https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf
U.S. DEPARTMENT OF COMMERCE. (2006). Minimum Security Requirements for Federal Information and Information Systems. Retrieved from https://csrc.nist.gov/csrc/media/publications/fips/200/final/documents/fips-200-final-march.pdf
U.S. Department of Commerce. (2013). Security and Privacy Controls for Federal Information Systems and Organizations. Retrieved from https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf