科技报告详细信息
An Analysis of Department of Defense Instruction 8500.2 'Information Assurance (IA) Implementation.'
Campbell, Philip LaRoche
关键词: IMPLEMENTATION;    US DOD;    INFORMATION;    INFORMATION SYSTEMS;   
DOI  :  10.2172/1034875
RP-ID  :  SAND2012-0110
PID  :  OSTI ID: 1034875
Others  :  TRN: US201205%%14
学科分类:社会科学、人文和艺术(综合)
美国|英语
来源: SciTech Connect
PDF
【 摘 要 】

The Department of Defense (DoD) provides its standard for information assurance in its Instruction 8500.2, dated February 6, 2003. This Instruction lists 157 'IA Controls' for nine 'baseline IA levels.' Aside from distinguishing IA Controls that call for elevated levels of 'robustness' and grouping the IA Controls into eight 'subject areas' 8500.2 does not examine the nature of this set of controls, determining, for example, which controls do not vary in robustness, how this set of controls compares with other such sets, or even which controls are required for all nine baseline IA levels. This report analyzes (1) the IA Controls, (2) the subject areas, and (3) the Baseline IA levels. For example, this report notes that there are only 109 core IA Controls (which this report refers to as 'ICGs'), that 43 of these core IA Controls apply without variation to all nine baseline IA levels and that an additional 31 apply with variations. This report maps the IA Controls of 8500.2 to the controls in NIST 800-53 and ITGI's CoBIT. The result of this analysis and mapping, as shown in this report, serves as a companion to 8500.2. (An electronic spreadsheet accompanies this report.)

【 预 览 】
附件列表
Files Size Format View
RO201704190004488LZ 3527KB PDF download
  文献评价指标  
  下载次数:0次 浏览次数:10次