REG NASA-LLIS-5099-2012 Lessons Learned - Information Technology (IT) Security Requirements Levied On Federal Agencies Do Not Align With Systems Engineering and Integration (SE&I) .pdf

上传人:dealItalian200 文档编号:1019481 上传时间:2019-03-21 格式:PDF 页数:2 大小:58.59KB
下载 相关 举报
REG NASA-LLIS-5099-2012 Lessons Learned - Information Technology (IT) Security Requirements Levied On Federal Agencies Do Not Align With Systems Engineering and Integration (SE&I) .pdf_第1页
第1页 / 共2页
REG NASA-LLIS-5099-2012 Lessons Learned - Information Technology (IT) Security Requirements Levied On Federal Agencies Do Not Align With Systems Engineering and Integration (SE&I) .pdf_第2页
第2页 / 共2页
亲,该文档总共2页,全部预览完了,如果喜欢就下载吧!
资源描述

1、Public Lessons Learned Entry: 5099 Lesson Info: Lesson Number: 5099 Submitting Organization: KSC Submitted by: Jenni Palmer Subject: Information Technology (IT) Security Requirements Levied On Federal Agencies Do Not Align With Systems Engineering and Integration (SE&I) Requirements Management Proce

2、sses Abstract: Federally mandated IT security requirements when implemented through the Constellation Program requirements process failed to capture scope and intent of higher level requirements. Description of Driving Event: The Constellation Program identified the need to tailor security controls

3、for implementation in Orion/Ares flight communication systems. The resulting requirements, based on NIST 800-53 controls, were inserted in Program level requirements document and levied on system designers through the Constellation Architecture Requirements Document. This resulted in designers addre

4、ssing only the allocated requirements rather than assessing the applicability of the entire standard. Lesson(s) Learned: Placing a subset of NIST 800-53 controls into the SE&I requirements management process created the appearance that the NIST 800-53 controls not referenced were not applicable to s

5、ystem designers. The current SE&I requirements management structure is not structured to accommodate the requirement of system designers to address NIST 800-53 controls. Recommendation(s): Program specific requirements relating to IT security should be limited to the definition of interfaces between

6、 systems. Decisions regarding applicability and implementation of specific NIST 800-53 controls should be made at the lowest level possible so the intent of controls are met in the most cost efficient manner. Evidence of Recurrence Control Effectiveness: N/A Documents Related to Lesson: NPR 2810.1 S

7、ecurity of Information Technology NIST 800-53 Recommended Security Controls for Federal Information Systems and Organizations Mission Directorate(s): Exploration Systems Additional Key Phrase(s): Additional Categories. Additional Categories.Information Technology/Systems Additional Info: Provided by IHSNot for ResaleNo reproduction or networking permitted without license from IHS-,-,-Project: constellation Approval Info: Approval Date: 2012-04-05 Approval Name: mbell Approval Organization: HQ Provided by IHSNot for ResaleNo reproduction or networking permitted without license from IHS-,-,-

展开阅读全文
相关资源
猜你喜欢
  • NF U47-102-2008 Animal health analysis methods - Isolation and identification of any salmonella serotype or of specified salmonella serotypes among mammals 《动物健康分析方法 所有血清型沙门菌或规定的哺乳.pdf NF U47-102-2008 Animal health analysis methods - Isolation and identification of any salmonella serotype or of specified salmonella serotypes among mammals 《动物健康分析方法 所有血清型沙门菌或规定的哺乳.pdf
  • NF U47-103-2003 Animal health analysis methods - Isolation and identification of mycobacterium avium subsp paraturberculosis on the basis of samplings (faeces or organs) taker from.pdf NF U47-103-2003 Animal health analysis methods - Isolation and identification of mycobacterium avium subsp paraturberculosis on the basis of samplings (faeces or organs) taker from.pdf
  • NF U47-105-2004 Animal health analysis methods - Isolation and identification of Brucella spp  except B ovis and B canis 《动物健康分析方法 不包括B ovis和B canis的布鲁菌spp 的隔离和识别》.pdf NF U47-105-2004 Animal health analysis methods - Isolation and identification of Brucella spp except B ovis and B canis 《动物健康分析方法 不包括B ovis和B canis的布鲁菌spp 的隔离和识别》.pdf
  • NF U47-106-2004 Animal health analysis methods - In-vitro determination of the susceptibility of bacterial to antimicrobial agents using the agar dilution method 《动物健康分析方法 使用琼脂稀释法体.pdf NF U47-106-2004 Animal health analysis methods - In-vitro determination of the susceptibility of bacterial to antimicrobial agents using the agar dilution method 《动物健康分析方法 使用琼脂稀释法体.pdf
  • NF U47-109-2004 Animal health analysis methods - Isolation and identification of Brucella ovis 《动物健康分析方法 绵羊布鲁氏杆菌的隔离和识别》.pdf NF U47-109-2004 Animal health analysis methods - Isolation and identification of Brucella ovis 《动物健康分析方法 绵羊布鲁氏杆菌的隔离和识别》.pdf
  • NF U47-300-2002 Animal health analysis method - Terminology 《动物健康分析方法 术语》.pdf NF U47-300-2002 Animal health analysis method - Terminology 《动物健康分析方法 术语》.pdf
  • NF U47-301-2001 Animal health analyse methods - Presentation file for control of biological reagents used in the animal health sector 《动物健康分析方法 动物保健部门用的生物反应试剂控制的表示文档》.pdf NF U47-301-2001 Animal health analyse methods - Presentation file for control of biological reagents used in the animal health sector 《动物健康分析方法 动物保健部门用的生物反应试剂控制的表示文档》.pdf
  • NF U47-302-2002 Animal health analysis methods - Reagent control protocol for the detection of antibodies against the bovine enzootic leucosis virus by the ELISA method in serums (.pdf NF U47-302-2002 Animal health analysis methods - Reagent control protocol for the detection of antibodies against the bovine enzootic leucosis virus by the ELISA method in serums (.pdf
  • NF U47-304-2004 Animal health analysis methods - Control protocol of reagents Control protocol of reagents for the detection of antibodies directed against brucellosis by the Rose he s.pdf NF U47-304-2004 Animal health analysis methods - Control protocol of reagents Control protocol of reagents for the detection of antibodies directed against brucellosis by the Rose he s.pdf
  • 相关搜索

    当前位置:首页 > 标准规范 > 国际标准 > 其他

    copyright@ 2008-2019 麦多课文库(www.mydoc123.com)网站版权所有
    备案/许可证编号:苏ICP备17064731号-1