NIST readies guidance on IT security assessments

The National Institute of Standards and Technology has finished the third and possibly final draft of its revised guidelines for assessing the adequacy of IT security. Special Publication 800-53A, Guide for Assessing the Security Controls in Federal Information Systems, will be released for comment June 4.

NIST is charged under the Federal Information Security Management Act with developing standards and guidance for implementing IT security programs. SP 800-53 is part of a series of documents developed for selecting the proper level and types of IT security controls. The core of the series is Federal Information Processing Standard 200, which establishes minimum security requirements under FISMA. Once those requirements have been established, agencies select the appropriate set of controls from NIST SP 800-53, Recommended Security Controls for Federal Information Systems. SP 800-53A is an addendum that sets out the framework for conducting mandatory assessments of security controls required under FISMA.

Comments on previously released drafts have resulted in significant changes in the third draft version, according to NIST. Changes are expected to include a greater emphasis on two-factor authentication, trust relationships to assure adequate security controls at IT vendors and greater restrictions on remote access to sensitive data.

Comments on the current version will be accepted by the Computer Security Division of NIST's IT Laboratory through July 31. Comments can be e-mailed to [email protected] All of the FISMA-related security standards and guidelines can be found at

Final publication of SP 800-53A is expected early next year. NIST will decide on whether additional public drafts are needed based on comments received on the present draft.

About the Author

William Jackson is a Maryland-based freelance writer.


  • Records management: Look beyond the NARA mandates

    Pandemic tests electronic records management

    Between the rush enable more virtual collaboration, stalled digitization of archived records and managing records that reside in datasets, records management executives are sorting through new challenges.

  • boy learning at home (Travelpixs/

    Tucson’s community wireless bridges the digital divide

    The city built cell sites at government-owned facilities such as fire departments and libraries that were already connected to Tucson’s existing fiber backbone.

Stay Connected