Ensayo

Páginas: 64 (15916 palabras) Publicado: 13 de febrero de 2013
Special Publication 800-30

Risk Management Guide for
Information Technology Systems
Recommendations of the National Institute of
Standards and Technology
Gary Stoneburner, Alice Goguen, and Alexis Feringa


NIST Special Publication 800-30

Risk Management Guide for
Information Technology Systems
Recommendations of the
National Institute of Standards and Technology
GaryStoneburner, Alice Goguen1, and
Alexis Feringa1

COMPUTER

S E C U R I T Y


Computer Security Division
Information Technology Laboratory
National Institute of Standards and Technology
Gaithersburg, MD 20899-8930
1

Booz Allen Hamilton Inc.
3190 Fairview Park Drive
Falls Church, VA 22042

July 2002

U.S. DEPARTMENT OF COMMERCE
Donald L. Evans, Secretary
TECHNOLOGYADMINISTRATION
Phillip J. Bond, Under Secretary for Technology
NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY
Arden L. Bement, Jr., Director

SP 800-30

Page ii

Reports on Computer Systems Technology
The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology
promotes the U.S. economy and public welfare by providing technical leadership forthe nation’s
measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof-ofconcept implementations, and technical analyses to advance the development and productive use of
information technology. ITL’s responsibilities include the development of technical, physical,
administrative, and management standards and guidelines for the cost-effectivesecurity and privacy of
sensitive unclassified information in federal computer systems. The Special Publication 800-series
reports on ITL’s research, guidance, and outreach efforts in computer security, and its collaborative
activities with industry, government, and academic organizations.

National Institute of Standards and Technology Special Publication 800-30

Natl. Inst. Stand.Technol. Spec. Publ. 800-30, 54 pages (July 2002)

CODEN: NSPUE2


Certain commercial entities, equipment, or materials may be identified in this document in order to describe an
experimental procedure or concept adequately. Such identification is not intended to imply recommendation or
endorsement by the National Institute of Standards and Technology, nor is it intended to implythat the entities,
materials, or equipment are necessarily the best available for the purpose.

SP 800-30

Page iii

Acknowledgements

The authors, Gary Stoneburner, from NIST and Alice Goguen and Alexis Feringa from Booz
Allen Hamilton wish to express their thanks to their colleagues at both organizations who
reviewed drafts of this document. In particular, Timothy Grance,Marianne Swanson, and Joan
Hash from NIST and Debra L. Banning, Jeffrey Confer, Randall K. Ewell, and Waseem
Mamlouk from Booz Allen provided valuable insights that contributed substantially to the
technical content of this document. Moreover, we gratefully acknowledge and appreciate the
many comments from the public and private sectors whose thoughtful and constructive
comments improvedthe quality and utility of this publication.

SP 800-30

Page iv

TABLE OF CONTENTS


1.

INTRODUCTION..............................................................................................................................................1

1.1
1.2
1.3
1.4
1.5
1.6

2.

RISK MANAGEMENT OVERVIEW.............................................................................................................4

2.1
2.2
2.3

3.

STEP 1: SYSTEM CHARACTERIZATION ......................................................................................................10

System-Related Information................................................................................................................10

Information-Gathering Techniques...
Leer documento completo

Regístrate para leer el documento completo.

Estos documentos también te pueden resultar útiles

  • Ensayo de el Ensayo
  • ensayo de ensayo
  • Ensayo Del Ensayo
  • Ensayo de un ensayo
  • Ensayemos un ensayo
  • ensayo del ensayo
  • Ensayo del ensayo
  • Ensayo del ensayo

Conviértase en miembro formal de Buenas Tareas

INSCRÍBETE - ES GRATIS