AIR FORCE FIPS PUB 200-2006 Minimum Security Requirements for Federal Information and Information Systems《联邦信息和信息系统的在最低安全要求》.pdf
《AIR FORCE FIPS PUB 200-2006 Minimum Security Requirements for Federal Information and Information Systems《联邦信息和信息系统的在最低安全要求》.pdf》由会员分享,可在线阅读,更多相关《AIR FORCE FIPS PUB 200-2006 Minimum Security Requirements for Federal Information and Information Systems《联邦信息和信息系统的在最低安全要求》.pdf(17页珍藏版)》请在麦多课文档分享上搜索。
1、FIPS PUB 200 _ FEDERAL INFORMATION PROCESSING STANDARDS PUBLICATION Minimum Security Requirements for Federal Information and Information Systems _ Computer Security Division Information Technology Laboratory National Institute of Standards and Technology Gaithersburg, MD 20899-8930 March 2006 U.S.
2、DEPARTMENT OF COMMERCE Carlos M. Gutierrez, Secretary NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY William Jeffrey, DirectorProvided by IHSNot for ResaleNo reproduction or networking permitted without license from IHS-,-,-FIPS Publication 200 Minimum Security Requirements for Federal Information a
3、nd Information Systems _ FOREWORD The Federal Information Processing Standards (FIPS) Publication Series of the National Institute of Standards and Technology (NIST) is the official series of publications relating to standards and guidelines adopted and promulgated under the provisions of the Federa
4、l Information Security Management Act (FISMA) of 2002. Comments concerning FIPS publications are welcomed and should be addressed to the Director, Information Technology Laboratory, National Institute of Standards and Technology, 100 Bureau Drive, Stop 8900, Gaithersburg, MD 20899-8900. - CITA M. FU
5、RLANI, ACTING DIRECTOR INFORMATION TECHNOLOGY LABORATORY ii Provided by IHSNot for ResaleNo reproduction or networking permitted without license from IHS-,-,-FIPS Publication 200 Minimum Security Requirements for Federal Information and Information Systems _ AUTHORITY Federal Information Processing
6、Standards Publications (FIPS PUBS) are issued by the National Institute of Standards and Technology after approval by the Secretary of Commerce pursuant to Section 5131 of the Information Technology Management Reform Act of 1996 (Public Law 104-106) and the Federal Information Security Management Ac
7、t of 2002 (Public Law 107-347). iii Provided by IHSNot for ResaleNo reproduction or networking permitted without license from IHS-,-,-FIPS Publication 200 Minimum Security Requirements for Federal Information and Information Systems _ Federal Information Processing Standards 200March 9, 2006 Announc
8、ing the Standard for Minimum Security Requirements for Federal Information and Information Systems Federal Information Processing Standards Publications (FIPS PUBS) are issued by the National Institute of Standards and Technology (NIST) after approval by the Secretary of Commerce pursuant to the Fed
9、eral Information Security Management Act (FISMA) of 2002. 1. Name of Standard. FIPS Publication 200: Minimum Security Requirements for Federal Information and Information Systems. 2. Category of Standard. Information Security. 3. Explanation. The E-Government Act (P.L. 107-347), passed by the one hu
10、ndred and seventh Congress and signed into law by the President in December 2002, recognized the importance of information security to the economic and national security interests of the United States. Title III of the E-Government Act, entitled the Federal Information Security Management Act (FISMA
11、), emphasizes the need for each federal agency to develop, document, and implement an enterprise-wide program to provide information security for the information and information systems that support the operations and assets of the agency including those provided or managed by another agency, contra
12、ctor, or other source. FISMA directed the promulgation of federal standards for: (i) the security categorization of federal information and information systems based on the objectives of providing appropriate levels of information security according to a range of risk levels; and (ii) minimum securi
13、ty requirements for information and information systems in each such category. This standard addresses the specification of minimum security requirements for federal information and information systems. 4. Approving Authority. Secretary of Commerce. 5. Maintenance Agency. Department of Commerce, NIS
14、T, Information Technology Laboratory. 6. Applicability. This standard is applicable to: (i) all information within the federal government other than that information that has been determined pursuant to Executive Order 12958, as amended by Executive Order 13292, or any predecessor order, or by the A
15、tomic Energy Act of 1954, as amended, to require protection against unauthorized disclosure and is marked to indicate its classified status; and (ii) all federal information systems other than those information systems designated as national security systems as defined in 44 United States Code Secti
16、on 3542(b)(2). The standard has been broadly developed from a technical perspective to complement similar standards for national security systems. In addition to the agencies of the federal government, state, local, and tribal governments, and private sector organizations that compose the critical i
17、nfrastructure of the United States are encouraged to consider the use of this standard, as appropriate. iv Provided by IHSNot for ResaleNo reproduction or networking permitted without license from IHS-,-,-FIPS Publication 200 Minimum Security Requirements for Federal Information and Information Syst
18、ems _ 7. Specifications. FIPS Publication 200, Minimum Security Requirements for Federal Information and Information Systems. 8. Implementations. This standard specifies minimum security requirements for federal information and information systems in seventeen security-related areas. Federal agencie
19、s must meet the minimum security requirements as defined herein through the use of the security controls in accordance with NIST Special Publication 800-53, Recommended Security Controls for Federal Information Systems, as amended. 9. Effective Date. This standard is effective immediately. Federal a
20、gencies must be in compliance with this standard not later than one year from its effective date. 10. Qualifications. The application of the security controls defined in NIST Special Publication 800-53 required by this standard represents the current state-of-the-practice safeguards and countermeasu
21、res for information systems. The security controls will be reviewed by NIST at least annually and, if necessary, revised and extended to reflect: (i) the experience gained from using the controls; (ii) the changing security requirements within federal agencies; and (iii) the new security technologie
22、s that may be available. The minimum security controls defined in the low, moderate, and high security control baselines are also expected to change over time as well, as the level of security and due diligence for mitigating risks within federal agencies increases. The proposed additions, deletions
23、, or modifications to the catalog of security controls and the proposed changes to the security control baselines in NIST Special Publication 800-53 will go through a rigorous, public review process to obtain government and private sector feedback and to build consensus for the changes. Federal agen
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
5000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- AIRFORCEFIPSPUB2002006MINIMUMSECURITYREQUIREMENTSFORFEDERALINFORMATIONANDINFORMATIONSYSTEMS 联邦 信息 信息系统

链接地址:http://www.mydoc123.com/p-427397.html