National Institute for Standards and Technology Special Publication 800-53 Revision 1
- Describes security control selection and specification of the structural components of security controls and how the controls are organized into families
- Defines minimum or baseline security controls to be implemented to create an effective information security program
- Clarifies the use of common security controls in support of information security programs
- Defines appropriate security controls for use in external environments
- Provides guidelines for assurance in the effectiveness of security controls
- Presents guidelines for the commitment to maintaining the currency of individual security controls and control baselines
- Describes the process of selecting and specifying security controls for an information system and defining the organization´s overall approach to managing risk
- Categorizes the information system in accordance with FIPS 199
- Outlines the process for selection of the initial set of baseline security controls supplemented by the tailored security control baseline based upon risk assessment results
- Provides guidelines on updating the controls as part of a continuous and comprehensive monitoring process
The National Institute of Standards and Technology Special Publication (NIST SP) 800-53 Revision 1 provides guidelines for securing information systems within the federal government by selecting and specifying security controls. These guidelines are applicable to all parts of an information system that process, store, or transmit federal information. These guidelines provided in NIST Special Publication 800-53 Rev. 1 are appropriate to all federal information systems, except systems designated as national security systems as defined in 44 U.S.C., Section 3542. NIST 800-53 Rev. 1 is intended to provide guidance to federal agencies in achieving a FIPS 200 titled, Minimum Security Requirements for Federal Information and Information Systems, baseline. Any organization that comprises part of the critical infrastructure of the nation is encouraged to use the guidelines of NIST Special Publication 800-53 Rev. 1 where appropriate.
|