At the U.S. federal level, the National Institute of Standards and Technology (NIST) has
specified guidelines for implementing the Federal Information Security Management Act
(FISMA). This act aims to provide the standards shown in Figure 3.1.
The “Federal Information Security Management Framework Recommended by NIST” [2]
sidebar describes the risk management framework as specified in FISMA. The activities
specified in this framework are paramount in implementing an IT security management plan.
Although specified for the federal government, this framework can be used as a guideline by
any organization.