13.07.2015 Views

Information Systems Security Manager (ISSM) - Marine Corps ...

Information Systems Security Manager (ISSM) - Marine Corps ...

Information Systems Security Manager (ISSM) - Marine Corps ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

NAVSO P-5239-04SEPTEMBER 1995This document establishes the IRM Standards and Guidelines Program and authorizes thedevelopment and distribution of publications. The IRM Program is the primary meansthrough which technical direction is exercised. The program is designed to facilitate the rapidpublication of standards and guidelines covering all aspects of the management of informationresources, including INFOSEC.Executive Office/Congress and National BranchExecutive Order 12 958, Classified National <strong>Security</strong> <strong>Information</strong>, 17 April 1995.This document established a system for classifying, declassifying, and safeguarding nationalsecurity information. It identifies classification authorities and describes their generalresponsibilities for the origination and handling of classified information.National <strong>Security</strong> Decision 42 , National Policy for the <strong>Security</strong> of National <strong>Security</strong>Telecommunications and <strong>Information</strong> <strong>Systems</strong>, Executive Office of the President, July 1990.This document establishes initial objectives, policies, and an organizational structure to guidethe conduct of activities to secure national security systems from exploitation; establishes amechanism for policy development and dissemination; and assigns responsibilities forimplementation.National Telecommunications and <strong>Information</strong> <strong>Systems</strong> <strong>Security</strong> Policy No. 200 ,National Policy on Controlled Access Protection, National Telecommunications and<strong>Information</strong> <strong>Systems</strong> <strong>Security</strong> Committee, July 1987.This document, under the authority of NSDD 145, National Telecommunications and<strong>Information</strong> <strong>Systems</strong> <strong>Security</strong> Policy (NTISSP) No. 200 , defines the minimum level ofprotection for ISs processing classified or sensitive unclassified information. It prescribes theC2 class criteria of DOD 5200.28-STD as the minimum level of protection for such systems,with additional protection required if warranted by a system risk assessment.Public Law 100-235 , Computer <strong>Security</strong> Act of 1987, 8 January 1988.This document redefines the role of the National Institute of Standards and Technology(formerly the National Bureau of Standards) and establishes a new Computer System <strong>Security</strong>and Privacy Advisory Board. It requires each federal agency to provide for mandatoryperiodic training in computer security awareness and accepted computer security practices;identify each federal computer system and system under development that contains sensitiveinformation; establish a plan for security and privacy of such systems.Joint StaffChairman of the Joint Chiefs of Staff Instruction CJCSI 6510.01 , Joint and CombinedCommunications <strong>Security</strong>, 1 September 1993.A-4

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!