首页> 外文会议>Computer Science and Information Technology, 2008 International Multiconference on >Information system security compliance to FISMA standard: A quantitative measure
【24h】

Information system security compliance to FISMA standard: A quantitative measure

机译:符合FISMA标准的信息系统安全性:一种量化措施

获取原文

摘要

To ensure that safeguards are implemented to protect against a majority of known threats, industry leaders are requiring information processing systems to comply with security standards. The National Institute of Standards and Technology Federal Information Risk Management Framework (RMF) and the associated suite of guidance documents describe the minimum security requirements (controls) for non-national-security federal information systems mandated by the Federal Information Security Management Act (FISMA), enacted into law on December 17, 2002, as Title III of the E-Government Act of 2002. The subjective compliance assessment approach described in the RMF guidance, though thorough and repeatable, lacks the clarity of a standard quantitative metric to describe for an information system the level of compliance with the FISMA-required standard. Given subjective RMF assessment data, this article suggests the use of Pathfinder networks to generate a quantitative metric suitable to measure, manage, and track the status of information system compliance with FISMA.
机译:为了确保实施保护措施以抵御大多数已知威胁,行业领导者要求信息处理系统符合安全标准。美国国家标准技术研究院联邦信息风险管理框架(RMF)和相关的指导文件套件描述了《联邦信息安全管理法》(FISMA)规定的非国家安全性联邦信息系统的最低安全要求(控制措施) ,于2002年12月17日作为2002年《电子政务法案》的标题III颁布。RMF指南中描述的主观合规性评估方法虽然详尽且可重复,但缺乏描述标准量化指标的清晰性。信息系统符合FISMA要求的标准的级别。给定主观RMF评估数据,本文建议使用Pathfinder网络来生成定量度量,该度量适用于测量,管理和跟踪信息系统符合FISMA的状态。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号