From: GCN
By William Jackson
The National Institute of Standards and Technology has released the final draft of its updated catalog of IT security controls, expanded to address new threats and with the flexibility to let agencies tailor controls to their needs. NIST expects to publish the finished product in April.
Special Publication 800-53, Security and Privacy Controls for Federal information Systems and Organizations, is a foundational document underlying federal cybersecurity regulation. Agencies are required under the Federal Information Security Management Act to apply appropriate controls detailed in the document to their IT systems, based on the level of assurance needed for each system.
Originally published in 2005, SP 800-53 was last updated in 2009 as part of what NIST called a historic collaboration with the military and intelligence communities to produce a set of governmentwide IT security controls. The latest update, Revision 4, is the most comprehensive to date and reflects changes in the IT and security landscapes over the past two years.
“The changes are substantial,” said Ron Ross, the FISMA implementation lead at NIST. “The fundamental underpinnings haven’t changed,” but the catalog of security controls has grown from more than 600 to more than 850 controls, and there is a new emphasis on the underlying trustworthiness of systems and on privacy controls.
Leave a Reply