There are five methodologies that agencies use as a basis to carry out FISMA compliance. The five methodologies are all slightly different, though the concepts among them are largely the same. Here's ...
The new NIST guidance for managing information security risk is called the capstone of the agency's work on FISMA implementation. The National Institute of Standards and Technology has released the ...
Federal agencies made progress in using risk management to enhance computer security in fiscal 2005, the Office of Management and Budget concluded last week. But some information security experts say ...