Date Published: February 2005 
                    
                            
                
                
                Author(s)
                
                    
                            Ron Ross (NIST),                             Stuart Katzke (NIST),                             L. Johnson (NIST),                             Marianne Swanson (NIST),                             Gary Stoneburner (APL),                             George Rogers,                             Annabelle Lee (NIST)                    
                
                
                
                
                Announcement
                [Original publication, from 2/28/2005]
                    
                
            
                
                The purpose of this publication is to provide guidelines for selecting and specifying security controls for information systems supporting the executive agencies of the federal government. The guidelines have been developed to help achieve more secure information systems within the federal government by: (i) facilitating a more consistent, comparable, and repeatable approach for selecting and specifying security controls for information systems; (ii) providing a recommendation for minimum security controls for information systems categorized in accordance with Federal Information Processing Standards (FIPS) 199, Standards for Security Categorization of Federal Information and Information Systems; (iii) promoting a dynamic, extensible catalog of security controls for information systems to meet the demands of changing requirements and technologies; and (iv) creating a foundation for the development of assessment methods and procedures for determining security control effectiveness. The guidelines provided in this special publication are applicable to all federal information systems other than those systems designated as national security systems as defined in 44 U.S.C., Section 3542. The guidelines have been broadly developed from a technical perspective to complement similar guidelines for national security systems. This publication is intended to provide guidance to federal agencies until the publication of FIPS 200, Minimum Security Controls for Federal Information Systems
                
                        
                            The purpose of this publication is to provide guidelines for selecting and specifying security controls for information systems supporting the executive agencies of the federal government. The guidelines have been developed to help achieve more secure information systems within the federal...
                            
See full abstract
                        
                            The purpose of this publication is to provide guidelines for selecting and specifying security controls for information systems supporting the executive agencies of the federal government. The guidelines have been developed to help achieve more secure information systems within the federal government by: (i) facilitating a more consistent, comparable, and repeatable approach for selecting and specifying security controls for information systems; (ii) providing a recommendation for minimum security controls for information systems categorized in accordance with Federal Information Processing Standards (FIPS) 199, Standards for Security Categorization of Federal Information and Information Systems; (iii) promoting a dynamic, extensible catalog of security controls for information systems to meet the demands of changing requirements and technologies; and (iv) creating a foundation for the development of assessment methods and procedures for determining security control effectiveness. The guidelines provided in this special publication are applicable to all federal information systems other than those systems designated as national security systems as defined in 44 U.S.C., Section 3542. The guidelines have been broadly developed from a technical perspective to complement similar guidelines for national security systems. This publication is intended to provide guidance to federal agencies until the publication of FIPS 200, Minimum Security Controls for Federal Information Systems
                            Hide full abstract
                         
                    Keywords
                    
                            accreditation;                             assurance requirements;                             common security controls;                             information technology;                             operational controls;                             organizational responsibilities;                             risk assessment;                             security controls;                             technical controls                    
             
                    
            Control Families
            
                    None selected