<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=Industry%3AProject_Review%2FNIST_SP_800-37r1_FPD_Appendix_A</id>
		<title>Industry:Project Review/NIST SP 800-37r1 FPD Appendix A - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=Industry%3AProject_Review%2FNIST_SP_800-37r1_FPD_Appendix_A"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Industry:Project_Review/NIST_SP_800-37r1_FPD_Appendix_A&amp;action=history"/>
		<updated>2026-05-07T13:23:42Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Industry:Project_Review/NIST_SP_800-37r1_FPD_Appendix_A&amp;diff=74685&amp;oldid=prev</id>
		<title>Dan Philpott: Created page with '{| align=&quot;right&quot; | __TOC__ |}  &lt;big&gt;APPENDIX A&lt;/big&gt;  &lt;big&gt;'''REFERENCES'''&lt;/big&gt;  LAWS, POLICIES, DIRECTIVES, INSTRUCTIONS, STANDARDS, AND GUIDELINES   {{GIC-NISTSP80037r1FPDRef…'</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Industry:Project_Review/NIST_SP_800-37r1_FPD_Appendix_A&amp;diff=74685&amp;oldid=prev"/>
				<updated>2009-12-04T05:10:28Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;#039;{| align=&amp;quot;right&amp;quot; | __TOC__ |}  &amp;lt;big&amp;gt;APPENDIX A&amp;lt;/big&amp;gt;  &amp;lt;big&amp;gt;&amp;#039;&amp;#039;&amp;#039;REFERENCES&amp;#039;&amp;#039;&amp;#039;&amp;lt;/big&amp;gt;  LAWS, POLICIES, DIRECTIVES, INSTRUCTIONS, STANDARDS, AND GUIDELINES   {{GIC-NISTSP80037r1FPDRef…&amp;#039;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{| align=&amp;quot;right&amp;quot;&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;big&amp;gt;APPENDIX A&amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;big&amp;gt;'''REFERENCES'''&amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
LAWS, POLICIES, DIRECTIVES, INSTRUCTIONS, STANDARDS, AND GUIDELINES&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{GIC-NISTSP80037r1FPDReferenceHeaders&lt;br /&gt;
| Text=LEGISLATION&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
1. [http://fismapedia.org/index.php?title=Doc:E-Government_Act E-Government Act] [includes FISMA] ([http://fismapedia.org/index.php?title=Doc:P.L._107-347 P.L. 107-347]), December 2002.&lt;br /&gt;
&lt;br /&gt;
2. [http://fismapedia.org/index.php?title=Doc:Federal_Information_Security_Management_Act Federal Information Security Management Act] ([http://fismapedia.org/index.php?title=Doc:P.L._107-347 P.L. 107-347], Title III), December 2002.&lt;br /&gt;
&lt;br /&gt;
3. [http://fismapedia.org/index.php?title=Doc:Paperwork_Reduction_Act Paperwork Reduction Act] ([http://fismapedia.org/index.php?title=Doc:P.L._104-13 P.L. 104-13]), May 1995.&lt;br /&gt;
&lt;br /&gt;
{{GIC-NISTSP80037r1FPDReferenceHeaders&lt;br /&gt;
| Text=POLICIES, DIRECTIVES, INSTRUCTIONS&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
1. Committee on [http://fismapedia.org/index.php?title=Term:National_Security_Systems National Security Systems] ([http://fismapedia.org/index.php?title=AnA:CNSS CNSS]) Instruction 4009, National [http://fismapedia.org/index.php?title=Term:Information_Assurance Information Assurance] Glossary, June 2006.&lt;br /&gt;
&lt;br /&gt;
2. Committee on [http://fismapedia.org/index.php?title=Term:National_Security_Systems National Security Systems] ([http://fismapedia.org/index.php?title=AnA:CNSS CNSS]) Instruction 1253, [http://fismapedia.org/index.php?title=Term:Security_Categorization Security Categorization] and Control Selection for [http://fismapedia.org/index.php?title=Term:National_Security_Systems National Security Systems], October 2009.&lt;br /&gt;
&lt;br /&gt;
3. [http://fismapedia.org/index.php?title=Office_of_Management_and_Budget Office of Management and Budget], [http://fismapedia.org/index.php?title=Doc:Circular_A-130 Circular A-130], Appendix III, Transmittal Memorandum #4, Management of Federal [http://fismapedia.org/index.php?title=Term:Information_Resources Information Resources], November 2000.&lt;br /&gt;
&lt;br /&gt;
4. [http://fismapedia.org/index.php?title=Doc:Office_of_Management_and_Budget_Memorandum_M-02-01 Office of Management and Budget Memorandum M-02-01], Guidance for Preparing and Submitting Security [http://fismapedia.org/index.php?title=Term:Plans_of_Action_and_Milestones Plans of Action and Milestones], October 2001.&lt;br /&gt;
&lt;br /&gt;
{{GIC-NISTSP80037r1FPDReferenceHeaders&lt;br /&gt;
| Text=STANDARDS&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
1. [http://fismapedia.org/index.php?title=National_Institute_of_Standards_and_Technology National Institute of Standards and Technology] [http://fismapedia.org/index.php?title=Doc:Federal_Information_Processing_Standards_Publication_199 Federal Information Processing Standards Publication 199], Standards for [http://fismapedia.org/index.php?title=Term:Security_Categorization Security Categorization] of Federal Information and Information Systems, February 2004.&lt;br /&gt;
&lt;br /&gt;
2. [http://fismapedia.org/index.php?title=National_Institute_of_Standards_and_Technology National Institute of Standards and Technology] [http://fismapedia.org/index.php?title=Doc:Federal_Information_Processing_Standards_Publication_200 Federal Information Processing Standards Publication 200], Minimum [http://fismapedia.org/index.php?title=Term:Security_Requirements Security Requirements] for Federal Information and Information Systems, March 2006.&lt;br /&gt;
&lt;br /&gt;
{{GIC-NISTSP80037r1FPDReferenceHeaders&lt;br /&gt;
| Text=GUIDELINES&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
1. [http://fismapedia.org/index.php?title=National_Institute_of_Standards_and_Technology National Institute of Standards and Technology] [http://fismapedia.org/index.php?title=Doc:Special_Publication_800-18 Special Publication 800-18], Revision 1, Guide for Developing Security Plans for Federal Information Systems, February 2006.&lt;br /&gt;
&lt;br /&gt;
2. [http://fismapedia.org/index.php?title=National_Institute_of_Standards_and_Technology National Institute of Standards and Technology] [http://fismapedia.org/index.php?title=Doc:Special_Publication_800-27 Special Publication 800-27], Revision A, Engineering Principles for Information Technology Security (A Baseline for Achieving Security), June 2004.&lt;br /&gt;
&lt;br /&gt;
3. [http://fismapedia.org/index.php?title=National_Institute_of_Standards_and_Technology National Institute of Standards and Technology] [http://fismapedia.org/index.php?title=Doc:Special_Publication_800-30 Special Publication 800-30], [http://fismapedia.org/index.php?title=Term:Risk_Management Risk Management] Guide for Information Technology Systems, July 2002.&lt;br /&gt;
&lt;br /&gt;
4. [http://fismapedia.org/index.php?title=National_Institute_of_Standards_and_Technology National Institute of Standards and Technology] [http://fismapedia.org/index.php?title=Doc:Special_Publication_800-39 Special Publication 800-39] (Second Public Draft), Managing Risk from Information Systems: An Organizational Perspective, April 2008.&lt;br /&gt;
&lt;br /&gt;
5. [http://fismapedia.org/index.php?title=National_Institute_of_Standards_and_Technology National Institute of Standards and Technology] [http://fismapedia.org/index.php?title=Doc:Special_Publication_800-53 Special Publication 800-53], Revision 3, Recommended [http://fismapedia.org/index.php?title=Term:Security_Controls Security Controls] for Federal Information Systems and Organizations, August 2009.&lt;br /&gt;
&lt;br /&gt;
6. [http://fismapedia.org/index.php?title=National_Institute_of_Standards_and_Technology National Institute of Standards and Technology] [http://fismapedia.org/index.php?title=Doc:Special_Publication_800-53A Special Publication 800-53A], Guide for Assessing the [http://fismapedia.org/index.php?title=Term:Security_Controls Security Controls] in Federal Information Systems: Building Effective [http://fismapedia.org/index.php?title=Term:Security_Assessment Security Assessment] Plans, July 2008.&lt;br /&gt;
&lt;br /&gt;
7. [http://fismapedia.org/index.php?title=National_Institute_of_Standards_and_Technology National Institute of Standards and Technology] [http://fismapedia.org/index.php?title=Doc:Special_Publication_800-59 Special Publication 800-59], Guideline for Identifying an Information System as a [http://fismapedia.org/index.php?title=Term:National_Security_System National Security System], August 2003.&lt;br /&gt;
&lt;br /&gt;
8. [http://fismapedia.org/index.php?title=National_Institute_of_Standards_and_Technology National Institute of Standards and Technology] [http://fismapedia.org/index.php?title=Doc:Special_Publication_800-60 Special Publication 800-60], Revision 1, Guide for Mapping Types of Information and Information Systems to Security Categories, August 2008.&lt;br /&gt;
&lt;br /&gt;
9. [http://fismapedia.org/index.php?title=National_Institute_of_Standards_and_Technology National Institute of Standards and Technology] [http://fismapedia.org/index.php?title=Doc:Special_Publication_800-70 Special Publication 800-70], Revision 1, National Checklist Program for IT Products--Guidelines for Checklist Users and Developers, September 2009.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Sources ==&lt;br /&gt;
&lt;br /&gt;
* [http://csrc.nist.gov/publications/drafts/800-37-Rev1/SP800-37-rev1-FPD.pdf NIST SP 800-37 Rev. 1 DRAFT Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach]&lt;br /&gt;
&lt;br /&gt;
[[Category:GIC-NISTSP80037r1FPDFPD]]&lt;/div&gt;</summary>
		<author><name>Dan Philpott</name></author>	</entry>

	</feed>