You are here

NIST: Managing Risk from Information Systems, An Organizational Perspective

Il Computer Security Resourcer center (CSRC) del NIST ha pubblicato la bozza iniziale della Special Publication 800-39, "Managing Risk from Information Systems: An Organizational Perspective" (pdf, 558 K, 60 pp) . La pubblicazione fornisce le linee guida per la gestione di rischi informatici prendendo in considerazione aspetti relativi alle operaizoni, gli assetti organizzativi, le responsabilità delle organizzazioni e dei singoli. Obiettivo del documento è facilitare l'integrazione dei sistemi informativi  con la mission aziendale e i processi di business. Eventuali commenti possono essere inviati (in lingua inglese) entro il 14 dicembre 2007 a sec-cert[at]nist.gov

Indice del documento

  1. Chapter one introduction
    • 1.1 purpose and applicability
    • 1.2 target audience
    • 1.3 relationship to other information security publications
    • 1.4 organization of this special publication
  2. Chapter two the fundamentals
    • 2.1 organization-wide perspective
    • 2.2 risk-based protection strategies
    • 2.3 trustworthiness of information systems
    • 2.4 establishing trust relationships among organizations
    • 2.5 strategic planning considerations
  3. Chapter three the process
    • 3.1 risk management framework
    • 3.2 security categorization
    • 3.3 security control selection
    • 3.4 security control supplementation
    • 3.5 security control documentation
    • 3.6 security control implementation
    • 3.7 security control assessment
    • 3.8 information system authorization
    • 3.9 continuous monitoring
  4. Appendix a references
  5. Appendix b glossary
  6. Appendix c acronyms
  7. Appendix d managing risks within life cycle processes
  8. Appendix e risk management approaches

Articoli collegati

Link

  • Computer Security Resourcer center (CSRC)
  • National Institute of Standards and Technology (NIST)
  • DRAFT SP 800-39, Managing Risk from Information Systems: An Organizational Perspective (annuncio) e pdf (558 K, 60 pp)
AG-Vocabolario: