SP 800-65. Integrating IT Security into the Capital Planning and Investment Control Process

  • Authors:
  • Joan Hash;Nadya Bartol;Holly Rollins;Will Robinson;John Abeles;Steve Batdorff

  • Affiliations:
  • National Institute of Standards and Technology;-;-;-;-;-

  • Venue:
  • SP 800-65. Integrating IT Security into the Capital Planning and Investment Control Process
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

Traditionally, information technology (IT) security and capital planning and investment control (CPIC) processes have been performed independently by security and capital planning practitioners. However, the Federal Information Security Management Act (FISMA) of 2002 and other existing federal regulations charge agencies with integrating the two activities. In addition, with increased competition for limited federal budgets and resources, agencies must ensure that available funding is applied towards the agencies' highest priority IT security investments. Applying funding towards high-priority security investments supports the objective of maintaining appropriate security controls, both at the enterprise-wide and system level, commensurate with levels of risk and data sensitivity. This special publication introduces common criteria against which agencies can prioritize security activities to ensure that corrective actions identified in the annual FISMA reporting process are incorporated into the capital planning process to deliver maximum security in a cost-effective manner.