NIST Special Publication 800-39, Managing Information Security Risk: Organization, Mission, and Information System View
Author | : nist |
Publisher | : |
Total Pages | : 98 |
Release | : 2013-12-29 |
ISBN-10 | : 1494836343 |
ISBN-13 | : 9781494836344 |
Rating | : 4/5 (344 Downloads) |
Download or read book NIST Special Publication 800-39, Managing Information Security Risk: Organization, Mission, and Information System View written by nist and published by . This book was released on 2013-12-29 with total page 98 pages. Available in PDF, EPUB and Kindle. Book excerpt: The purpose of Special Publication 800-39 is to provideguidance for an integrated, organization-wide program for managing information security risk to organizational operations (i.e., mission, functions, image, and reputation), organizational assets, individuals, otherorganizations, and the Nation resulting from the operation and use of federal information systems. Special Publication 800-39 provides a structured, yet flexible approach for managing information security riskthat is intentionally broad-based, with the specific details of assessing, responding to, and monitoring risk on an ongoing basis provided by other supporting NIST security standards and guidelines. The guidance providedin this publication is not intended to replace or subsume other risk-related activities, programs, processes, or approaches that organizations have implemented or intend to implement addressing areas of risk management covered by other legislation, directives, policies, programmatic initiatives, or mission/business requirements. Rather, the information security riskmanagement guidance described herein is complementary to and can be used as part of a more comprehensive Enterprise Risk Management (ERM) program.