Risk Management Framework for Information Systems and Organizations : NIST
Risk Management Framework for Information Systems and Organizations A System Life Cycle Approach for Security and Privacy by U.S. Department of Commerce Wilbur L. Ross, Jr., Secretary National Institute of Standards and Technology Walter Copan, NIST Director and Under Secretary of Commerce for Standards and Technology INTRODUCTION THE NEED TO MANAGE SECURITY AND PRIVACY RISK Organizations depend on information systems to carry out their missions and business functions. The success of the missions and business functions depends on protecting the confidentiality, integrity, availability of information processed, stored, and transmitted by those systems and the privacy of individuals. The threats to information systems include equipment failure, environmental disruptions, human or machine errors, and purposeful attacks that are often sophisticated, disciplined, well-organized, and well-funded. When successful, attacks on information systems can result in seriou...