NIST SP 800-60

E700394

NIST SP 800-60 is a U.S. National Institute of Standards and Technology guideline that provides a methodology for mapping federal information and information systems to security impact levels to support risk management and FISMA compliance.

All labels observed (1)

Label Occurrences
NIST SP 800-60 canonical 3

How this entity was disambiguated

Statements (46)

Predicate Object
instanceOf NIST Special Publication
U.S. federal government standard
information security guideline
appliesTo federal information
federal information systems
author National Institute of Standards and Technology
basedOn Federal Information Processing Standards Publication 199
countryOfOrigin United States
defines methodology for mapping information systems to security impact levels
methodology for mapping information to security impact levels
focusesOn information security
risk management
security categorization
governs mapping of management and support information types
mapping of mission-based information types
hasPart Volume I
Volume II
language English
objective facilitate selection of appropriate security controls
support consistent security categorization of federal information
support consistent security categorization of federal information systems
partOfSeries NIST Special Publication 800 series
linked to: NIST SP 800 series
publisher National Institute of Standards and Technology
relatedTo FIPS 199
FIPS 200
NIST SP 800-37
NIST SP 800-53
scope civilian federal agencies
supports Federal Information Security Management Act compliance
Federal Information Security Modernization Act compliance
federal information system risk management
targetAudience federal agencies
information security program managers
information system owners
risk managers
usedFor classifying information types
determining security impact levels
supporting system authorization decisions
usesConcept availability impact level
confidentiality impact level
high impact
integrity impact level
low impact
moderate impact
Volume I Guide for Mapping Types of Information and Information Systems to Security Categories
Volume II Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories

How these facts were elicited

Referenced by (3)

Full triples — surface form annotated when it differs from this entity's canonical label.

NIST SP 800 series includes NIST SP 800-60
NIST SP 800-171 relatedTo NIST SP 800-60
FedRAMP High impact level basedOn NIST SP 800-60