go to NIST home page go to CSRC home page go to Focus Areas page go to Publications page go to Advisories page go to Events page go to Site Map page go to ITL home page CSRC home page link
header image with links

  ROSI Home page
 
  June 30, 2003
  IT Security Capital Investment
  Planning Workshop

 
  June 4, 2003
  IT Security Capital Investment
  Planning Workshop

 
  Submit ROSI Ideas

 

  CSRC Pages

  -  CSRC Homepage
  -  ICAT Vulnerability Database
  -  Vulnerability/Threat Advisories
  -  Site Map
  -  Virus Information

  Search CSRC

  Search:  


  Search Vulnerability
      Archive
     Enter vendor, software, or keyword
   
   
Return on Security Investment (ROSI) image
IT Security Capital Investment Planning
Second IT Security Capital Investment Planning (CPIC) Workshop: June 30, 2003

POSTED July 23, 2003:
Click here to go to page that contains links to view/download the workshop presentations, notes, and handouts. Available in .pdf format.


Workshop Description
 
Focus
 

Workshop Description
This workshop will focus on effectively integrating security into the capital planning process. It will also provide participants with information on how to best develop a comprehensive business case in support of IT security acquisitions and investments.

The seminar is designed to support those with key roles in the IT security planning process and personnel responsible for investment development and approval requests. This includes:

  • IT Managers and security professionals
  • Security Program Managers
  • Investment Review Board (IRB) participants

Federal government contractors will be permitted to register for this workshop. In addition to formally registering, contractors should have their agency contacts email Elaine Frye [elaine.frye@nist.gov] indicating that the contractor is attending at their request.

Objectives of the course are:

  • Identify why the IT Governance process is important in making sound IT Security investment decisions
  • Explain how current security requirements relate to and support IT capital planning.
  • Identify relevant OMB and other guidance that applies to governing Federal Government IT Security investment decisions.
  • Identify security roles and responsibilities in the IT capital planning process
  • Identify steps required to complete a sound business case in support of IT Security investments

Preliminary Agenda

8:30AM Registration
 
9:00AM Introduction
 
9:10AM FY03 FISMA Reporting Instructions and Plans of Action and Milestones Guidance
 
10:30AM Break
 
10:45AM Requirements Overview
 
11:05AM Security Investment Life cycle Planning
 
11:30PM Lunch
 
1:00PM Questions from Morning Session
1:10PM Security Investment Life cycle Planning
 
2:10PM Questions from Afternoon Session
2:20PM Breakout Session 
 
3:00PM Break
 
3:15PM Out brief of Breakout Session
 
4:00PM Wrap Up

Focus
There are no special prerequisites beyond the expectation that those attending have a role in the IT security capital planning process. Suggested attendees are noted above.

Technical Information
Joan Hash
NIST
Telephone: 975-3357
Fax: (301) 975-4007
Email:    joan.hash at nist.gov
     (note: substitute the "at" with "@" in e-mail link)
 

 :

Last updated: October 25, 2005
Page created: June 6, 2003

Disclaimer Notice & Privacy Statement / Security Notice
Send comments or suggestions to webmaster-csrc@nist.rip
NIST is an Agency of the U.S. Commerce Department's
Technology Administration