• Embed Doc
  • Readcast
  • Collections
  • CommentGo Back
Download
 
Risk Management Guide forInformation Technology Systems
Recommendations of the National Institute of Standards and Technology
Gary Stoneburner, Alice Goguen, and Alexis Feringa
 
Special Publication 800-30
 
SP 800-30Page ii
 
C O M P U T E R S E C U R I T Y
Computer Security DivisionInformation Technology Laboratory National Institute of Standards and TechnologyGaithersburg, MD 20899-8930
1
Booz Allen Hamilton Inc.3190 Fairview Park DriveFalls Church, VA 22042
July 2002
U.S. DEPARTMENT OF COMMERCE
 
 Donald L. Evans, Secretary
TECHNOLOGY ADMINISTRATION
Phillip J. Bond, Under Secretary for Technology
NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY
 Arden L. Bement, Jr., Director 
 
NIST Special Publication 800-30
Risk Management Guide forInformation Technology Systems
 
 Recommendations of theNational Institute of Standards and Technology
Gary Stoneburner, Alice Goguen
1
, andAlexis Feringa
1
 
 
SP 800-30Page iii
 Reports on Computer Systems Technology
The Information Technology Laboratory (ITL) at the National Institute of Standards and Technologypromotes the U.S. economy and public welfare by providing technical leadership for the nation’smeasurement and standards infrastructure. ITL develops tests, test methods, reference data, proof-of-concept implementations, and technical analyses to advance the development and productive use of information technology. ITL’s responsibilities include the development of technical, physical,administrative, and management standards and guidelines for the cost-effective security and privacy of sensitive unclassified information in federal computer systems. The Special Publication 800-seriesreports on ITL’s research, guidance, and outreach efforts in computer security, and its collaborativeactivities with industry, government, and academic organizations.
National Institute of Standards and Technology Special Publication 800-30Natl. Inst. Stand. Technol. Spec. Publ. 800-30, 54 pages (July 2002)CODEN: NSPUE2
 
Certain commercial entities, equipment, or materials may be identified in this document in order to describe anexperimental procedure or concept adequately. Such identification is not intended to imply recommendation or endorsement by the National Institute of Standards and Technology, nor is it intended to imply that the entities,materials, or equipment are necessarily the best available for the purpose.
of 00

Leave a Comment

You must be to leave a comment.
Submit
Characters: ...
You must be to leave a comment.
Submit
Characters: ...