From National Institute of Standards and Technology | May 18, 2009
This Information Security Handbook provides a broad overview of information security
program elements to assist managers in understanding how to establish and implement an
information security program. Typically, the organization looks to the program for
overall responsibility to ensure the selection and implementation of appropriate
security controls and to demonstrate the effectiveness of satisfying their stated
security requirements.
The topics within this document were selected based on the laws and regulations
relevant to information security, including the Clinger-Cohen Act of 1996, the Federal
Information Security Management Act (FISMA) of 2002, and Office of Management and
Budget (OMB) Circular A-130. The material in this handbook can be referenced for
general information on a particular topic or can be used in the decision-making process
for developing an information security program. While reading this handbook, please
consider that the guidance is not specific to a particular agency. Agencies should
tailor this guidance according to their security posture and business requirements.
The attached Zip file includes:
- Intro Page.doc
- Cover Sheet and Terms.pdf
- Information Security Handbooks – A Guide for Managers.pdf