You are here

NIST: Draft SP 800-60 – Categorizzare secondo la sicurezza le informazioni ed i sistemi informativi

Il Computer Security Resourcer center (CSRC) del NIST ha pubblicato le bozze iniziali della Special Publication SP 800-60 Revision 1, Volume I "Guide for Mapping Types of Information and Information Systems to Security Categories" (pdf, 1.5 M, 52 pp o pdz zip, 826 K)  e del Volume II "Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories" (pdf, 8.5 M, 304 pp o pdz zip, 4 M)
Il volume I contiene le line guida di base per mappare sia le informazioni sia i sistemi informativi rispetto alle categorie di sicurezza. Il volume II contiene la categorizzazione di sicurezza proposta. Commenti ai contenuti dei due volumi possono essere inviati fino al 10 dicembre 2007 nelle modalità indicate nei documenti stessi.

Indice del volume I

  • EXECUTIVE SUMMARY
  • 1.0 INTRODUCTION
    • 1.1 Authority
    • 1.2 Purpose and Scope
    • 1.3 Applicability & Audience
    • 1.4 Publication Structure
  • 2.0 PUBLICATION OVERVIEW
    • 2.1 Value to Agency Missions, Security Programs and IT Management
    • 2.2 Role in the System Development Lifecycle
    • 2.3 Role in the Certification and Accreditation Process
    • 2.4 Role in the NIST Risk Management Framework
  • 3.0 SECURITY CATEGORIZATION OF INFORMATION AND INFORMATION SYSTEMS
    • 3.1 Security Categories and Objectives (Contents from FIPS 199)
      • 3.1.1 Security Categories
      • 3.1.2 Security Objectives and Types of Potential Losses
      • 3.1.2.1 Confidentiality
      • 3.1.2.2 Integrity
      • 3.1.2.3 Availability
    • 3.2 Impact Assessment (Contents from FIPS 199)
      • 3.2.1 Levels of Impact
      • 3.2.2 Establishment of Security Categories for Information Types
  • 4.0 ASSIGNMENT OF IMPACT LEVELS AND SECURITY CATEGORIZATION
    • 4.1 Step 1: Identify Information Types
      • 4.1.1 Identification of Mission-based Information Types
      • 4.1.2 Identification of Management and Support Information
      • 4.1.2.1 Services Delivery Support Information
      • 4.1.2.2 Government Resource Management Information
      • 4.1.2.3 Legislative and Executive Information Mandates
    • 4.2 Step 2: Select Provisional Impact Level
      • 4.2.1 FIPS 199 Security Categorization Criteria
      • 4.2.2 Examples of FIPS 199-Based Selection of Impact Levels
      • 4.2.3 Common Factors for Selection of Impact Levels
      • 4.2.3.1 Confidentiality Factors
      • 4.2.3.2 Integrity Factors
      • 4.2.3.3 Availability Factors
    • 4.3 Step 3: Review Provisional Impact Levels and Adjust/Finalize Information Impact Levels
    • 4.4 Step 4: Assign System Security Category
      • 4.4.1 FIPS 199 Process for System Categorization
      • 4.4.2 Guidelines for System Categorization
      • 4.4.2.1 Aggregation
      • 4.4.2.2 Critical System Functionality
      • 4.4.2.3 Extenuating Circumstances
      • 4.4.2.4 Other System Factors
    • 4.5 Documenting the Security Categorization Process
    • 4.6 Additional Considerations for Categorized Information Systems
      • 4.6.1 Large Supporting and Interconnecting Systems
      • 4.6.2 Additional Uses of Categorization Information
  • APPENDIX A: GLOSSARY OF TERMS
  • APPENDIX B: REFERENCES

Articoli collegati

Link

  • Computer Security Resourcer center (CSRC)
  • National Institute of Standards and Technology (NIST)
  • DRAFT SP 800-60 Revision 1, Volume I "Guide for Mapping Types of Information and Information Systems to Security Categories" (pdf, 1.5 M, 52 pp o pdz zip, 826 K)  e Volume II "Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories" (pdf, 8.5 M, 304 pp o pdz zip, 4 M)