Date Published: April 2018
Comments Due: May 4, 2018 (public comment period is CLOSED)
Email Questions to: sec-cert@nist.gov
This is the initial public draft release of NIST Internal Report (NISTIR) 8011 Volume 3, Automation Support for Security Control Assessments: Software Asset Management. This NISTIR represents a joint effort between NIST and the Department of Homeland Security to provide an operational approach for automating security control assessments in order to facilitate information security continuous monitoring (ISCM), ongoing assessment, and ongoing security authorizations in a way that is consistent with the NIST Risk Management Framework overall and the guidance in NIST SPs 800-53 and 800-53A in particular.
NISTIR 8011 will ultimately consist of 13 volumes. Volumes 1 and 2 were published in 2017. Volume 3 provides details specific to the software asset management security capability. The remaining 10 ISCM security capability volumes will provide details specific to each capability but will be organized in a very similar way to Volumes 2 and 3.
Assessment, Authorization and Monitoring; Risk Assessment
Publication:
Draft NISTIR 8011 Vol. 3 (pdf)
Supplemental Material:
None available
Other Parts of this Publication:
IR 8011 Vol. 1
IR 8011 Vol. 2
Related NIST Publications:
Document History:
04/05/18: IR 8011 Vol. 3 (Draft)
12/06/18: IR 8011 Vol. 3 (Final)
asset management, assurance, continuous monitoring, controls assessment, risk assessment, security automation, security controls, system authorization, testing & validation
Technologies Laws and RegulationsE-Government Act, Federal Information Security Modernization Act, OMB Circular A-130