首页> 外文期刊>EDPACS: The EDP audit, control and security newsletter >NEW NIST REVISIONS - WHAT DO THEY MEAN FOR REGULATORY COMPLIANCE?
【24h】

NEW NIST REVISIONS - WHAT DO THEY MEAN FOR REGULATORY COMPLIANCE?

机译:新的NIST修订 - 他们对监管合规是什么意思?

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Regardless of the industry, there are several commonalities that transcend data privacy and security. Confidentiality, integrity and availability of the data should form the foundation of any risk analysis that assesses technical, administrative and physical safeguards. In the United States, the National Institute for Standards and Technology ("NIST") publishes a variety of special publications to assist the United States Government and private persons in their legal and regulatory compliance efforts. Recently, NIST promulgated new publications - NIST-SP-800-53, rev. 5 and NISTIR 8228. These two publications are of particular importance for two reasons. First, SP800-53 addresses a broad spectrum of privacy and security controls. Second, NISTIR 8228 applies IoT, which is quickly expanding and evolving into a collection of various technologies that interact with the physical world. In essence, IoT is the intersection between information technology and operational technology. The impetus behind this article is to provide a synopsis of these two recent NIST standards, assess their application to a variety of laws in the healthcare, finance and government procurement and conclude with a round-up of why NIST should be the first place to turn. The take-aways for readers should be the following: to appreciate the importance of data privacy and security compliance; to utilize a risk analysis, which is based on NIST standards to address the gaps in the requisite technical, administrative and physical safeguards; and to provide a sampling of legal scenarios where NIST applies.
机译:无论行业如何,有几种常见的常见性超越数据隐私和安全性。数据的保密性,完整性和可用性应成为评估技术,行政和实际保障的任何风险分析的基础。在美国,国家标准与技术研究所(“NIST”)出版了各种特殊出版物,以协助美国政府和私人的法律和监管合规努力。最近,NIST颁布了新的出版物 - NIST-SP-800-53,Rev。 5和Nistir 8228.这两个出版物的原因特别重要。首先,SP800-53解决了广泛的隐私和安全控制。其次,Nistir 8228应用IoT,这很快扩展和发展成为与物理世界互动的各种技术的集合。实质上,物联网是信息技术与运营技术的交叉路口。本文背后的推动力是提供这两个最近的NIST标准的概要,评估其在医疗保健,财务和政府采购中的各种法律上的申请,并结束了为什么NIST应该是第一个转向的地方。读者的旅行应该如下:理解数据隐私和安全合规性的重要性;利用风险分析,基于NIST标准来解决必要的技术,行政和实际保障中的差距;并提供NIST适用的法律场景的采样。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号