NIST Requests Comments on Final Public Draft of Federal Cybersecurity Plan | Practical Law

NIST Requests Comments on Final Public Draft of Federal Cybersecurity Plan | Practical Law

The National Institute of Standards and Technology is requesting comments on the final public draft of Security and Privacy Controls for Federal Information Systems and Organizations. This document is the culmination of a two-year initiative to update the NIST's guidance for the selection and specification of security controls for federal information systems and organizations.

NIST Requests Comments on Final Public Draft of Federal Cybersecurity Plan

Practical Law Legal Update 3-524-0423 (Approx. 3 pages)

NIST Requests Comments on Final Public Draft of Federal Cybersecurity Plan

by PLC Intellectual Property & Technology
Published on 07 Feb 2013USA (National/Federal)
The National Institute of Standards and Technology is requesting comments on the final public draft of Security and Privacy Controls for Federal Information Systems and Organizations. This document is the culmination of a two-year initiative to update the NIST's guidance for the selection and specification of security controls for federal information systems and organizations.
The National Institute of Standards and Technology is requesting comments on Security and Privacy Controls for Federal Information Systems and Organizations, Special Publication (SP)800-53, Revision 4. This document provides a catalog of security and privacy controls for federal information systems and organizations and a process for selecting controls to protect organizational operations, organizational assets and individuals from a diverse set of security and privacy threats. For more background on this document, see Legal Update, National Institute of Standards and Technology Proposes Revised Guidelines for Mobile Device Security.
(SP)800-53, Revision 4 incorporates a number of major proposed changes, including:
  • Clarification of security control language.
  • Updated security control baselines.
  • New privacy controls and implementation guidance based on the internationally recognized Fair Information Practice Principles.
Comments must be sent to [email protected] by March 1, 2013.