170k views
5 votes
What is the NIST 800-39?

A. Managing Information Security Risk: Organization, Mission, and Information System View
B. Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach
C. Recommended Security Controls for Federal Information Systems and Organizations
D. Guide for Assessing the Security Controls in Federal Information Systems and Organizations: Building Effective Security Assessment Plans.

User Evoskuil
by
7.1k points

1 Answer

2 votes

Final answer:

NIST 800-39 is a guideline entitled 'Managing Information Security Risk: Organization, Mission, and Information System View', focusing on managing security risks at different organization levels.

Step-by-step explanation:

The NIST 800-39 is titled 'Managing Information Security Risk: Organization, Mission, and Information System View'.

This publication provides guidelines on how to manage information security risk at three tiers within an organization: the organization level, mission/business process level, and the information system level.

It is part of the NIST Special Publication 800-series that reports on the Information Technology Laboratory's research, guidelines, and outreach efforts in information system security and its collaborative activities with industry, government, and academic organizations.

The NIST 800-39 is a guide for applying the Risk Management Framework (RMF) to federal information systems. It provides a security life cycle approach to managing information security risk in an organization. The guide helps organizations identify and assess risks, develop and implement security controls, and monitor the effectiveness of those controls.

User Imran Ahmed
by
7.3k points