首页> 外文会议>International Multiconference on Computer Science and Information Technology >Information System Security Compliance to FISMA Standard: A Quantitative Measure
【24h】

Information System Security Compliance to FISMA Standard: A Quantitative Measure

机译:信息系统安全符合FISMA标准:定量措施

获取原文

摘要

To ensure that safeguards are implemented to protect against a majority of known threats, industry leaders are requiring information processing systems to comply with security standards. The National Institute of Standards and Technology Federal Information Risk Management Framework (RMF) and the associated suite of guidance documents describe the minimum security requirements (controls) for non-national-security federal information systems mandated by the Federal Information Security Management Act (FISMA), enacted into law on December 17, 2002, as Title III of the E-Government Act of 2002. The subjective compliance assessment approach described in the RMF guidance, though thorough and repeatable, lacks the clarity of a standard quantitative metric to describe for an information system the level of compliance with the FISMA-required standard. Given subjective RMF assessment data, this article suggests the use of Pathfinder networks to generate a quantitative metric suitable to measure, manage, and track the status of information system compliance with FISMA.
机译:为确保实施保护以防止大多数已知威胁,行业领导者要求信息处理系统遵守安全标准。国家标准与技术联邦信息风险管理框架(RMF)和相关指导文件的相关套件描述了联邦信息安全管理法(FISMA)规定的非全国安全联邦信息系统的最低安全要求(控制) ,2002年12月17日颁布了法律,作为2002年电子政务法案的III。在RMF指导中描述的主观合规性评估方法虽然彻底和可重复,但缺乏标准定量指标的清晰度来描述信息系统遵守FISMA所需标准的水平。给定主观RMF评估数据,本文建议使用Pathfinder网络来生成适合测量,管理和跟踪与Fisma信息系统遵守情况的地位的定量度量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号