Security Assertions, Criteria, and Metrics Developed for the IRS
May 2001
Paul Bicknell, The MITRE Corporation
ABSTRACT
The Federal Information Technology Security Assessment Framework has been adopted by the Internal Revenue Service to provide a basis for conducting an evaluation of its cyber security program. The criteria contained in the framework have been expanded into security assertions, performance goals and metrics, and establish quantifiable security assessment targets. The goals and metrics are granular to the tasking level and allow for organization budget and tracking efforts.

Additional Search Keywords
security metrics, security assessments, Federal Information Technology Security Assessment Framework, FITSAF
|