Wednesday, May 02, 2007

Federal Information Systems - Information Assurance Reference

I wanted to take this opportunity to post a quick "cheat sheet" on the various resources needed for the certification and accreditation (C&A) of federal information systems, as well as some other related resources. A number of federal C&A things are changing. For example, rather than using the NIST 800-26 self assessment questions, C&A will be done by making assessments against the NIST 800-53 controls. Some organizations use NIST 800-53, and some use 800-53, Rev 1. Here is a quick list of the publications and regulations that apply to federal systems. Enjoy.

National Institute of Standards and Technology (NIST):

SP 800-100
Information Security Handbook: A Guide for Managers

SP 800-12
An Introduction to Computer Security: The NIST Handbook

SP 800-14
Generally Accepted Principles and Practices for Securing Information Technology Systems

SP 800-18
Guide for Developing Security Plans for Federal Information Systems

SP 800-23
Guidline to Federal Organizations on Security Assurance and Acquisition/Use of Tested/Evaluated Products

SP 800-26
Security Self Assessment Guide for Information Technology Systems

SP 800-27
Engineering Principles for Information Technology Security (A Baseline for Achieving Security)

SP 800-30
Risk Management Guide for Information Technology Systems

SP 800-31
Intrusion Detection Systems (IDS)

SP 800-34
Contingency Planning Guide for Information Technology Systems

SP 800-36
Guide to Selecting Information Technology Security Products

SP 800-37
Guide for Security Certification and Accreditation

SP 800-42
Guideline on Network Security Testing

SP 800-47
Security Guide for Interconnecting Information Technology Systems

SP 800-51
Use of the Common Vulnerabilities and Exposures (CVE) Vulnerability Naming Scheme

SP 800-53
Recommended Security Controls for Federal Information Systems

SP 800-53 Rev 1
Recommended Security Controls for Federal Information Systems, Revision 1

SP 800-53A (DRAFT)
Guide for Assessing the Security Controls in Federal Information Systems

SP 800-55
Security Metrics Guide for Information Technology

SP 800-56
Recommendation on Key Establishment Schemes

SP 800-57
Recommendation on Key management

SP 800-60
Guide or Mapping Types of Information Systems to Security Categories

SP 800-61
Computer Security Incident Handling

SP 800-64
Security Considerations in the Information System Development Lifecycle

SP 800-70
Security Configuration Program Checklists Program For IT Products - Guidance For Checklists Users and Developers

-------------------------------------------------------------


Federal Information Processing Standards (FIPS):

FIPS 140-2
Security Requirements for Cryptographic Modules

FIPS 199
Standards for Security Categorization of Federal Information and Information Systems

FIPS 200
Minimum Security Requirements for Federal Information Systems

-------------------------------------------------------------


Office of Management and Budget (OMB):

OMB Circular A-123
Management's Responsibility for Internal Controls

OMB Circular A-130
Management of Federal Information Resources

OMB Circular A-130, Appendix III
Security of Federal Automated Information Resources

-------------------------------------------------------------


Laws and Regulations:

FISMA
Federal Information Security Management Act of 2002

-------------------------------------------------------------


Other Publications and Usefull Information Assurance References:

CNSS
Committee on National Security Systems

Common Criteria
Common Criteria for Information Technology Security Evaluation

Common Criteria - An Introduction
Brochure: An Introduction to the Common Criteria Project

DIACAP
DoD InformationAssurance Certification and Accreditation (will replace DITSCAP)

DITSCAP
DoD Information Technology Security Certification and Accreditation Process

GAO-05-231
Emerging Cybersecurity Issues Threaten Federal Information Systems

Mitre
Common Vulnerabilities and Exposures

NIACAP
National Information Assurance Certification and Accreditation Process

NIAP
National Information Assurance Partnership

NIATS
National Information Assurance Training Standard for System Administrators

NIST and SDLC
Brochure: NIST and the Systems Development Lifecycle (SDLC)

US-CERT
United States Computer Emergency Readiness Team

-------------------------------------------------------------


Topic Reference:

Security Certification and Accreditation
SP 800-37
NIACAP
DITSCAP
DIACAP

Security Categorization (C-I-A, High, Moderate, Low)
FIPS 199
SP 800-60

No comments: