0% found this document useful (0 votes)
93 views2 pages

NIST SP 800-12 Overview and Guidance

The NIST documents provide guidance on designing security frameworks and implementing security best practices. Specifically: 1. NIST SP 800-12 is a reference guide for routine security management. 2. NIST SP 800-14 details security best practices and principles to direct development of a comprehensive security blueprint. 3. NIST SP 800-18 Rev. 1 provides methods for assessing, designing, and implementing controls and serves as a useful guide for developing security plans.

Uploaded by

Anusha K
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
93 views2 pages

NIST SP 800-12 Overview and Guidance

The NIST documents provide guidance on designing security frameworks and implementing security best practices. Specifically: 1. NIST SP 800-12 is a reference guide for routine security management. 2. NIST SP 800-14 details security best practices and principles to direct development of a comprehensive security blueprint. 3. NIST SP 800-18 Rev. 1 provides methods for assessing, designing, and implementing controls and serves as a useful guide for developing security plans.

Uploaded by

Anusha K
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

NIST Security Models

Other approaches are described in the many documents available from the Computer Security
Resource Center of the National Institute for Standards and Technology. Because the NIST
documents are publicly available at no charge and have been available for some time, they have
been broadly reviewed by government and industry professionals and are among the references
cited by the federal government when it decided not to select the ISO/IEC 17799 standards. The
following documents can assist in the design of a security framework:
1. SP 800-12: An Introduction to Computer Security: The NIST Handbook
2. SP 800-14: Generally Accepted Security Principles and Practices for Securing
Information Technology Systems.
3. SP 800-18 Rev. 1: Guide for developing Security Plans for Federal Information Systems.
4. SP 800-26: Security Self-Assessment Guide for Information Technology Systems.
5. SP 800-30: Risk Management Guide for Information Technology Systems.
Many of these documents have been referenced as sources of the management of security.
NIST Special Publication SP 800-12
SP 800-12, An Introduction to Computer Security: The NIST Handbook, is an excellent
reference and guide for the security manager or administrator in the routine management of
information security. It provides little guidance, however on design and implementation of new
security systems, and therefore should be used only as a precursor to understanding an
information security blueprint.
NIST Special Publication 800-14
Generally Accepted Principles and Practices for Securing Information Technology
Systems provides best practices and security principles that can direct that security team in the
development of a security blueprint. In addition to detailing security best practices across the
spectrum of security areas, it provides the philosophical principles that the security team should
integrate into the entire information security process.
The document can guide the development of the security framework and should be combined
with other NIST publications providing the necessary structure to the entire security process.
The scope of NIST SP 800-14 is broad. It is important to consider each of the security principles
it presents and therefore the following sections examine some of the more significant points in
detail.
1. Security supports the Mission of the Organization: Failure to develop an information
security system based on the organization’s mission, vision and culture guarantees the
failure of the information security program.
2. Security is an Integral Element of Sound management: Effective management includes
planning, organizing, leading and controlling. Security enhances management functions
by providing input during the planning process for organizational initiatives. Information
security controls support sound management via enforcement of both managerial and
security policies.
3. Security should be Cost Effective: The costs of information security should be considered
part of the cost doing business much like the cost of computers, networks and voice
communication systems. These are profit generating areas of the organization and may
not lead to competitive advantages. Information security should justify its own cots. The
use of security measures that do not justify their cost must have a strong business
justification.
4. Security Responsibilities and Accountability should be made explicit: Policy documents
should clearly identify the security responsibilities of users, administrators, and mangers.
To be legally binding, the policies must be documented, disseminated, read, understood,
and agreed to by all involved members of the organization. Organizations should provide
information about relevant laws in issue-specific security policies.
5. Security Requires a Comprehensive and Integrated Approach: Security personal alone
cannot effectively implement security. The three communities of interest should
participate in the process of developing a comprehensive information security program.
6. Security is constrained by Societal Factors: There are a number of factors that influence
the implementation and maintenance of security. Legal demands, shareholders
requirements. Even business practices affect the implementation of security controls and
safeguards. For example, security professionals generally prefer to isolate information
assets from the Internet, which is the leading avenue of threats to the assets, but the
business requirements of the organization may preclude this control measure.
NIST Special Publication 800-18 Rev. 1
The Guide for Developing Security Plans for Federal Information Systems can be used as
the foundation for a comprehensive security blueprint and framework. This publication provides
detailed methods for assessing, designing and implementing controls and plans for applications
of varying size. SP 800-18 Rev 1 can serve as a useful guide to the activities and as an aid in the
planning process. It also includes the templates for major application security plans.

You might also like