Date Published: August 2008 
            
            
            
            
            
            
            
			
			
            
            
            
            
            
            Supersedes: SP  800-60 Ver. 2.0 (June 2004)
            
            
			
            
            Author(s)
            Kevin Stine (NIST), Richard Kissel (NIST), William Barker (NIST), Jim Fahlsing (SAIC), Jessica Gulick (SAIC)
            
            
            
            
            
                
                
                    Title III of the E-Government Act, titled the Federal Information Security Management Act (FISMA) of 2002, tasked NIST to develop (1) standards to be used by all Federal agencies to categorize information and information systems collected or maintained by or on behalf of each agency based on the objectives of providing appropriate levels of information security according to a range of risk levels; and (2) guidelines recommending the types of information and information systems to be included in each such category. Special Publication 800-60 was issued in response to the second of these tasks. The revision to Volume I contains the basic guidelines for mapping types of information and information systems to security categories. The appendices contained in Volume I include security categorization recommendations and rationale for mission-based and management and support information types.
                 
                
                    
                    
                        Title III of the E-Government Act, titled the Federal Information Security Management Act (FISMA) of 2002, tasked NIST to develop (1) standards to be used by all Federal agencies to categorize information and information systems collected or maintained by or on behalf of each agency based on the...
                        
See full abstract
                    
                        Title III of the E-Government Act, titled the Federal Information Security Management Act (FISMA) of 2002, tasked NIST to develop (1) standards to be used by all Federal agencies to categorize information and information systems collected or maintained by or on behalf of each agency based on the objectives of providing appropriate levels of information security according to a range of risk levels; and (2) guidelines recommending the types of information and information systems to be included in each such category. Special Publication 800-60 was issued in response to the second of these tasks. The revision to Volume I contains the basic guidelines for mapping types of information and information systems to security categories. The appendices contained in Volume I include security categorization recommendations and rationale for mission-based and management and support information types.
                        Hide full abstract
                     
                    
                 
                Keywords
 computer security; cyber security; FISMA; categorization; information type; security category
            
 
            
            Control Families
            
                
                
                    Program Management; 
                
                    Risk Assessment;