NIST Site Search
Search NIST.GOV
Custom Search
[Official NIST.GOV TIME]
Product Research

Advertise on this site
NIST SP 800-37 Guide for the Security Certification and Accreditation of Federal Information Systems
on Saturday 21 January 2006 print the content item {PDF=create pdf file of the content item^plugin:content.41}
in NIST.gov Publications > Special Publications - SP 800 series

Federal Information Security Management Act (FISMA), requires each federal agency to develop, document, and implement an agency-wide information security program to provide information security for the information and information systems that support the operations and assets of the agency. Security Certification and Accreditation is a big part of the FISMA process.

Download NIST Special Publication 800-37.

Please use the NIST.org Forum to ask questions or discuss this document. Members can use the comment link below for short comments about this publication.

(The below SP 800-37 description is from NIST.gov, edited)

Description of NIST Special Publication 800-37:

NIST Special Publication 800-37 provides guidelines for the security certification and accreditation of Information Technology (IT) systems supporting the executive branch agencies of the federal government. The guidelines have been developed to help achieve more secure information systems within the federal government by:

  • Enabling more consistent, comparable, and repeatable assessments of security controls in federal information systems;
  • Promoting a better understanding of agency-related mission risks resulting from the operation of information systems; and
  • Creating more complete, reliable, and trustworthy information for authorizing officials—to facilitate more informed security accreditation decisions.


Security certification and accreditation are important activities that support a risk management process and are an integral part of an agency’s information security program. Security accreditation is the official management decision given by a senior agency official to authorize operation of an information system and to explicitly accept the risk to agency operations, agency assets, or individuals based on the implementation of an agreed-upon set of security controls. Required by OMB Circular A-130, Appendix III, security accreditation provides a form of quality control and challenges managers and technical staffs at all levels to implement the most effective security controls possible in an information system, given mission requirements, technical constraints, operational constraints, and cost/schedule constraints. By accrediting an information system, an agency official accepts responsibility for the security of the system and is fully accountable for any adverse impacts to the agency if a breach of security occurs. Thus, responsibility and accountability are core principles that characterize security accreditation.

Security accreditation is the official management decision given by a senior agency official to authorize operation of an information system and to explicitly accept the risk to agency operations, agency assets, or individuals based on the implementation of an agreed-upon set of security controls.

The SP 800-37 document was created by the National Institute of Standards and Technology and is public domain (not subject to copyright).




NIST Special Publication # 800-37


Translate to: {GOOGLETRANS}
Google Ads




Headlines

»CVE-2013-7463
The aescrypt gem 1.0.0 for Ruby does not randomize the CBC IV for use with the AESCrypt.encrypt and ...
»CVE-2014-9907 (imagemagick)
coders/dds.c in ImageMagick allows remote attackers to cause a denial of service via a crafted DDS f ...
»CVE-2015-8285
The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service.
»CVE-2015-8957
Buffer overflow in ImageMagick before 6.9.0-4 Beta allows remote attackers to cause a denial of serv ...
»CVE-2015-8958
coders/sun.c in ImageMagick before 6.9.0-4 Beta allows remote attackers to cause a denial of service ...
»CVE-2015-8959
coders/dds.c in ImageMagick before 6.9.0-4 Beta allows remote attackers to cause a denial of service ...
»CVE-2016-0720
Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.
»CVE-2016-0721
Session fixation vulnerability in pcsd in pcs before 0.9.157.
»CVE-2016-0833
Android allows users to cause a denial of service.
»CVE-2016-10091
Multiple stack-based buffer overflows in unrtf 0.21.9 allow remote attackers to cause a denial-of-se ...
»CVE-2016-10345
In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-mod ...
»CVE-2016-1148
Akerun - Smart Lock Robot App for iOS before 1.2.4 does not verify SSL certificates.
»CVE-2016-1161
Cross-site request forgery (CSRF) vulnerability in ManageEngine Password Manager Pro before 8.5 (Bui ...
»CVE-2016-1184
Tokyo Star bank App for Android before 1.4 and Tokyo Star bank App for iOS before 1.4 do not validat ...
»CVE-2016-1186
Kintone mobile for Android 1.0.0 through 1.0.5 does not verify SSL server certificates.


Date published: 2017-04-23T10:00:01Z
Details

»Drupal Releases Security Updates
Original release date: April 19, 2017 Drupal has released an advisory to address a vulnerabil ...
»Cisco Releases Security Updates
Original release date: April 19, 2017 Cisco has released updates to address several high-impa ...
»Mozilla Releases Security Updates
Original release date: April 19, 2017 Mozilla has released security updates to address a vuln ...
»Google Releases Security Updates for Chrome
Original release date: April 19, 2017 Google has released Chrome version 58.0.3029.81 for Win ...
»VMware Releases Security Updates
Original release date: April 18, 2017 VMware has released security updates to address vulnera ...
»Oracle Releases Security Bulletin
Original release date: April 18, 2017 Oracle has released its Critical Patch Update for April ...
»Microsoft Addresses Shadow Brokers Exploits
Original release date: April 15, 2017 | Last revised: April 17, 2017 The Microsoft Security R ...
»VMware Releases Security Updates
Original release date: April 14, 2017 VMware has released security updates to address a vulne ...
»ISC Releases Security Updates for BIND
Original release date: April 12, 2017 The Internet Systems Consortium (ISC) has released upda ...
»Apache Software Foundation Releases Security Updates
Original release date: April 12, 2017 | Last revised: April 18, 2017 The Apache Foundation ha ...


Date published: not known
Details




Date published: not known
Details
Main Menu
· Home
Current Security News
 
US-CERT Current Activity

» Drupal Releases Security Updates
[19 Apr 2017 06:17pm]

» Cisco Releases Security Updates
[19 Apr 2017 06:14pm]

» Mozilla Releases Security Updates
[19 Apr 2017 06:04pm]

» Google Releases Security Updates for Chrome
[19 Apr 2017 06:02pm]

» VMware Releases Security Updates
[18 Apr 2017 02:34pm]

» Oracle Releases Security Bulletin
[18 Apr 2017 02:30pm]

» Microsoft Addresses Shadow Brokers Exploits
[15 Apr 2017 07:09pm]

» VMware Releases Security Updates
[14 Apr 2017 04:13pm]

» ISC Releases Security Updates for BIND
[12 Apr 2017 08:19pm]

» Apache Software Foundation Releases Security Updates
[12 Apr 2017 12:11pm]

***
US-CERT Alerts

» TA17-075A: HTTPS Interception Weakens TLS Security
[16 Mar 2017 06:40am]

» TA16-336A: Avalanche (crimeware-as-a-service infrastructure)
[30 Nov 2016 10:00pm]

» TA16-288A: Heightened DDoS Threat Posed by Mirai and Other Botnets
[14 Oct 2016 05:59pm]

» TA16-250A: The Increasing Threat to Network Infrastructure Devices and Recommended Mitigations
[06 Sep 2016 04:29pm]

» TA16-187A: Symantec and Norton Security Products Contain Critical Vulnerabilities
[05 Jul 2016 08:50am]

» TA16-144A: WPAD Name Collision Vulnerability
[23 May 2016 05:38am]

» TA16-132A: Exploitation of SAP Business Applications
[11 May 2016 05:31am]

» TA16-105A: Apple Ends Support for QuickTime for Windows; New Vulnerabilities Announced
[14 Apr 2016 01:48pm]

» TA16-091A: Ransomware and Recent Variants
[31 Mar 2016 04:00pm]

» TA15-337A: Dorkbot
[03 Dec 2015 04:40pm]

***
Computerworld Security

» There's now a tool to test for NSA spyware
[22 Apr 2017 05:43am]

» Hackers use old Stuxnet-related bug to carry out attacks
[20 Apr 2017 02:57pm]

» Developer lifts Windows 7's update blockade with unsanctioned patch
[20 Apr 2017 02:28pm]

» DHS's ICS-CERT warns of BrickerBot: IoT malware that will brick vulnerable devices
[19 Apr 2017 09:21am]

» Experts contend Microsoft canceled Feb. updates to patch NSA exploits
[18 Apr 2017 02:06pm]

» How one personal cyber insurance policy stacks up
[18 Apr 2017 05:00am]

» IDG Contributor Network: Most of the Windows zero-day exploits have already been patched
[17 Apr 2017 01:46pm]

» Microsoft confirms it's patched most of the NSA's Windows exploits
[17 Apr 2017 01:05pm]

» 1,175 hotels listed in payment card breach of Holiday Inn parent company
[17 Apr 2017 11:11am]

» Profiling 10 types of hackers
[17 Apr 2017 05:00am]

» An introduction to six types of VPN software
[15 Apr 2017 04:44pm]

» Honesty is not the best privacy policy
[15 Apr 2017 05:00am]

» Microsoft begins denying updates to some Windows 7 users
[14 Apr 2017 01:56pm]

» Quantum computing advances toward the enterprise
[14 Apr 2017 01:19pm]

» IDG Contributor Network: Massive change to a moderate Patch Tuesday
[14 Apr 2017 10:02am]

***
Microsoft Security Advisories

» 3123479 - SHA-1 Hashing Algorithm for Microsoft Root Certificate Program - Version: 2.0
[14 Mar 2017 11:00am]

» 4010983 - Vulnerability in ASP.NET Core MVC 1.1.0 Could Allow Denial of Service - Version: 1.0
[27 Jan 2017 11:00am]

» 3214296 - Vulnerabilities in Identity Model Extensions Token Signing Verification Could Allow Elevation of Privilege - Version: 1.0
[10 Jan 2017 11:00am]

» 3181759 - Vulnerabilities in ASP.NET Core View Components Could Allow Elevation of Privilege - Version: 1.0
[13 Sep 2016 11:00am]

» 3174644 - Updated Support for Diffie-Hellman Key Exchange - Version: 1.0
[13 Sep 2016 11:00am]

» 3179528 - Update for Kernel Mode Blacklist - Version: 1.0
[09 Aug 2016 11:00am]

» 2880823 - Deprecation of SHA-1 Hashing Algorithm for Microsoft Root Certificate Program - Version: 2.0
[18 May 2016 11:00am]

» 3155527 - Update to Cipher Suites for FalseStart - Version: 1.0
[10 May 2016 11:00am]

» 3152550 - Update to Improve Wireless Mouse Input Filtering - Version: 1.1
[22 Apr 2016 11:00am]

» 3137909 - Vulnerabilities in ASP.NET Templates Could Allow Tampering - Version: 1.1
[10 Feb 2016 11:00am]

» 2871997 - Update to Improve Credentials Protection and Management - Version: 5.0
[09 Feb 2016 11:00am]

» 3109853 - Update to Improve TLS Session Resumption Interoperability - Version: 1.0
[12 Jan 2016 11:00am]

» 3118753 - Updates for ActiveX Kill Bits 3118753 - Version: 1.0
[12 Jan 2016 11:00am]

» 2755801 - Update for Vulnerabilities in Adobe Flash Player in Internet Explorer and Microsoft Edge - Version: 53.0
[05 Jan 2016 11:00am]

» 3057154 - Update to Harden Use of DES Encryption - Version: 1.1
[08 Dec 2015 11:00am]

***
WIRED

» Security News This Week: A Coachella Smartphone Thief Forgot About ‘Find My iPhone’
[22 Apr 2017 06:00am]

» Want to Stop Facebook Violence? You Won’t Like the Choices
[22 Apr 2017 05:00am]

» Encrypted Chat Took Over. Let’s Encrypt Calls, Too
[21 Apr 2017 07:00am]

» The US Charging Julian Assange Could Put Press Freedom on Trial
[20 Apr 2017 09:13pm]

» A New Way to Securely Send Information to WIRED
[20 Apr 2017 10:00am]

» North Korea’s Failed Missile Launch Eases Experts’ Worst-Case Scenario Fears
[19 Apr 2017 09:37am]

» Facebook Offers a Better Way to Get Back Into Your Locked-Out Apps
[18 Apr 2017 11:45am]

» Sneaky Exploit Allows Phishing Attacks From Sites That Look Secure
[18 Apr 2017 05:00am]

» Courts Are Using AI to Sentence Criminals. That Must Stop Now
[17 Apr 2017 05:00am]

» Security News This Week: Nasty Microsoft Word ‘Booby Trap’ Loaded PCs With Malware
[15 Apr 2017 08:00am]

***
Network World Security

» There's now a tool to test for NSA spyware
[21 Apr 2017 06:47pm]

» Phishing attacks using internationalized domains are hard to block
[21 Apr 2017 11:11am]

» DARPA opens massive “Colosseum” to develop radical wireless applications
[21 Apr 2017 10:24am]

» Forget signatures for malware detection. SparkCognition says AI is 99% effective  
[21 Apr 2017 09:43am]

» Fight firewall sprawl with AlgoSec, Tufin, Skybox suites
[10 Apr 2017 04:32am]

» Review: Canary Flex security camera lives up to its name
[24 Mar 2017 07:01am]

» Smackdown: Office 365 vs. G Suite management
[16 Mar 2017 07:01am]

» Zix wins 5-vendor email encryption shootout
[13 Mar 2017 04:00am]

» Review: vArmour flips security on its head
[06 Mar 2017 03:50am]

» 5 open source security tools too good to ignore
[21 Feb 2017 07:12am]

» Review: Samsung SmartCam PT network camera
[15 Feb 2017 07:00am]

» Review: Arlo Pro cameras offer true flexibility for home security
[09 Feb 2017 07:01am]

» Face-off: Oracle vs. CA for identity management
[26 Jan 2017 10:30am]

» Phishing attacks using internationalized domains are hard to block
[21 Apr 2017 11:11am]

» DARPA opens massive “Colosseum” to develop radical wireless applications
[21 Apr 2017 10:24am]

***


More IT Security
News Feeds
More Sponsors

Advertise on this site
RSS Feeds
Our news can be syndicated by using these rss feeds.
rss1.0
rss2.0
rdf

NIST.org is in no way connected to the U.S. government site NIST.gov

This site is © John Herron, CISSP. All Rights Reserved.

Please visit daily to stay up to date on all your IT Security compliance issues.

http://www.nist.org -
Hosted by BlueHost. We've never had a better hosting company.
{THEMEDISCLAIMER}