NIST invites public comments on the new draft guidelines for three months. The agency will hold an open, public workshop in March 2004 to share comments and discuss possible revisions to the draft.
The document is available at the NIST Web site.
Security controls are the management, operational and technical safeguards, and countermeasures prescribed for a computer system that, taken together, adequately protect the confidentiality, integrity and availability of a system and its information. Management safeguards range from risk assessment to security planning. Operational safeguards include factors such as personnel security and basic maintenance of hardware and software. Technical safeguards include items such as audit trails and communications protection.
NIST SP 800-53 provides a method for categorizing security risk levels based on another recent NIST document, the draft FIPS Publication 199, Standards for Security Categorization of Federal Information and Information Systems, also available at the Web address above.