National Institute of Standards and Tech Elizabeth Chew Marianne Swanson
This document is a guide to assist in the development, selection, and implementation of measures to be used at the information system and program levels. These measures indicate the effectiveness of security controls applied to information systems and supporting information security programs. Such measures are used to facilitate decision making, improve performance and increase accountability through the collection, analysis, and reporting of relevant performance-related data-providing a way to tie the implementation, efficiency, and effectiveness of information system and program security...
This document is a guide to assist in the development, selection, and implementation of measures to be used at the information system and program leve...
U. S. Department of Commerce Marianne Swanson Joan Hash
The purpose of the system security plan is to provide an overview of the security requirements of the system and describe the controls in place or planned for meeting those requirements. The system security plan also delineates responsibilities and expected behavior of all individuals who access the system. The system security plan should be viewed as documentation of the structured process of planning adequate, cost-effective security protection for a system. It should reflect input from various managers with responsibilities concerning the system, including information owners, the system...
The purpose of the system security plan is to provide an overview of the security requirements of the system and describe the controls in place or pla...