SP800-30
SP800-30 (NIST)
Product identity card
General information
Basic information to identify the product
Method or tool name : Risk Management Guide for Information Technology systems
Vendor name : National Institute for Standards and Technology (NIST)
Country of origin : United States
Level of reference of the product
Details about the type of initiator of the product
National Standardization body : NIST (USA)
Identification
Specify the phases this method supports and a short description
R.A. Method phases supported
-
Risk identification : Detailed with samples
-
Risk analysis : Detailed in check-list and with samples
-
Risk evaluation : None
R.M. Method phases supported
-
Risk assessment: Very detailed with inventory and template
-
Risk treatment : Detailed with flowchart and with mathematical aspect
-
Risk acceptance : Include in a chapter on risk mitigation
Brief description of the product
-
This product is one of the Special Publication 800-series reports. It gives very detailed guidance and identification of what should be considered within a Risk Management and Risk Assessment in computer security. There are some detailed checklists, graphics (including flowchart) and mathematical formulas, as well as references that are mainly based on US regulatory issues.
Lifecycle
Date of the first edition, date and number of actual version
Date of first release : 2002
Date and identification of the last version : 2002
Useful links
Link for further information
Official web site : http://www.csrc.nist.gov
User group web site : N/A
Relevant web site : N/A
Languages
List the available languages that the tool supports
Availability in European languages : English
Price
Specify the price for the method
-
Free
Scope
Target organisations
Defines the most appropriate type of organisations the product aims at
-
Government, agencies
-
Large companies
-
SME
-
Commercial CIEs
-
Non commercial CIEs
Specific sector : N/A
Geographical spread
Information concerning the spread of this tool
Used in EU member states : N/A
Used in non-EU member states : USA
Level of detail
Specify the target kind of users
-
Operational
-
Technical
License and certification scheme
Specify the licensing and certification schemes available for this method
Recognized licensing scheme : No
Existing certification scheme : No
Users viewpoint
Skills needed
Specify the level of skills needed to use and maintain the solution
-
To introduce : Standard
-
To use : Standard
-
To maintain : Standard
Consultancy support
Specify the kind of support available
Consultancy : Open market
Regulatory compliance
There is a given compliance of the product with international regulations
-
N/A
Compliance to IT standards
There is a compliance with a national or international standard
-
N/A
Trial before purchase
Details regarding the evaluation period (if any) before purchase of the product.
Availability : No
Maturity level of the Information system
The product gives a means of measurement for the maturity of the information system security
It is possible to measure the I.S.S. maturity level : No
Tools supporting the method
List of tools that support the product
Non commercial tools
-
N/A
Commercial tools
-
N/A
Technical integration of available tools
Particular supporting tools (see C-7) can be integrated with other tools
Tools can be integrated with other tools : No
Organisation processes integration
The method provides interfaces to existing processes within the organisation
Method provides interfaces to other organisational processes : N/A
Flexible knowledge databases
It is possible to adapt a knowledge database specific to the activity domain of the company.
Method allows use of sector adapted databases : N/A