Where to turn for help


Besides the Office of Management and Budget guidance, there are other sourcesof information about the requirements of the Government Information SecurityReform Act.

* The act itself. It's available on the CIO Council Web site (www.cio.gov/docs/NDAA2001.htm),separate from the fiscal 2001 Defense Authorization Act.

* The National Institute of Standards and Technology draft special publication,"Self-Assessment Guide for Information Technology Systems." Available atthe Computer Security Resource Center's Web site (csrc.nist.gov). A finalversion will be available soon but won't differ much from the draft.

* The CIO Council's Information Technology Security Assessment Framework.Also available on the council's site, the framework is what the NIST specialpublication builds on.

* The CIO Council's report "Securing Electronic Government." This publication,also on the council's Web site, takes a more program-oriented view at whatsecurity is necessary for different systems and services

Featured

  • FCW Perspectives
    tech process (pkproject/Shutterstock.com)

    Understanding the obstacles to automation

    As RPA moves from buzzword to practical applications, agency leaders say it’s forcing broader discussions about business operations

  • Federal 100 Awards
    Federal 100 logo

    Fed 100 nominations are now open

    Help us identify this year's outstanding individuals in federal IT.

Stay Connected

FCW INSIDER

Sign up for our newsletter.

I agree to this site's Privacy Policy.