国防部信息技术安全认证和认证过程(DITSCAP)(1997年12月30日)

ID:40826

大小:0.44 MB

页数:136页

时间:2023-03-14

金币:20

上传者:战必胜
Department of Defense
INSTRUCTION
NUMBER 5200.40
December 30, 1997
ASD(C3I)
SUBJECT: DoD Information Technology Security Certification and Accreditation
Process (DITSCAP)
References: (a) DoD Directive 5200.28, “Security Requirements for Automated
Information Systems (AISs),” March 21, 1988
(b) Public Law 100-235, “Computer Security Act of 1987,” January 8,
1988
(c) Office of Management and Budget Circular No. A-130, “Management
of Federal Information Resources,” February 8, 1996
(d) Director of Central Intelligence 1/16, “Security Policy on Intelligence
Information in Automated Systems and Networks,” March 14, 1988
(e) through (m), see enclosure E1.
1. PURPOSE
This Instruction:
1.1. Implements policy, assigns responsibilities, and prescribes procedures under
reference (a) for Certification and Accreditation (C&A) of information technology
(IT), including automated information systems, networks, and sites in the Department
of Defense.
1.2. Creates the DoD IT Security Certification and Accreditation Process
(DITSCAP) for security C&A of unclassified and classified IT to implement references
(a) through (d).
1.3. Stresses the importance of a life-cycle management approach to the C&A and
reaccreditation of DoD IT.
1
Downloaded from http://www.everyspec.com
资源描述:

当前文档最多预览五页,下载文档查看全文

此文档下载收益归作者所有

当前文档最多预览五页,下载文档查看全文
温馨提示:
1. 部分包含数学公式或PPT动画的文件,查看预览时可能会显示错乱或异常,文件下载后无此问题,请放心下载。
2. 本文档由用户上传,版权归属用户,天天文库负责整理代发布。如果您对本文档版权有争议请及时联系客服。
3. 下载前请仔细阅读文档内容,确认文档内容符合您的需求后进行下载,若出现内容与标题不符可向本站投诉处理。
4. 下载文档时可能由于网络波动等原因无法下载或下载错误,付费完成后未能成功下载的用户请联系客服处理。
关闭