preview

Information Security Standards For An Organization

Better Essays

Information Security Standards for an Organization 1. Introduction. In 1958 the National Aeronautics and Space Act established as the civilian agency that would control the United States space and aeronautical activities. From the beginning of the agency it has been on the cutting edge of technology from rockets to computer control centers and communication that would reach outside of our world. With the growing number of computers that were being used throughout the government and the amount of information that was being exchanged electronically, congress realized the importance for the federal government to have security management of the network. Congress enacted the Federal Information Security Management Act of 2002 (FISMA) to …show more content…

2. Standards “FISMA defines a framework for managing information security that must be followed for all information systems used or operated by a U.S. federal government agency in the executive or legislative branches, or by a contractor or other organization on behalf of a federal agency in those branches. (FISMA, 2002)” This is enforces the use of NIST standards and guidelines in order to meet the requirements that are established in the FISMA. FISMA has also advocated that security be bases upon periodic assessments of the risks that could have a potential to result in harm to the organization and come from the “unauthorized access, use, disclosure, disruption, modification, or destruction of information and information systems that support the operations and assets of the agency” ("44 U.S. Code § 3542 - Definitions"). Furthermore, FISMA provides and organization the flexibility regarding the application of security controls. ISO/IEC 27002 standard aligned with ISO/IEC 9001 (the Quality Management System) aims to meet the needs of non-Government agencies. An organizations management system needs to meet a basic best-practices management system. The organization is required to have an appropriately defined risk management process and assessment

Get Access