Risk Management and the Cybersecurity of the U.S. Government

B. Lampson
Abstract:Risk management is a fundamental principle of cybersecurity. It is the basis of the NIST Framework for Improving Critical Infrastructure Cybersecurity. Agencies of the U.S. Government certify the operational security of their information systems against the requirements of the FISMA Risk Management Framework (RMF). The alternative to risk management would presumably be a quest for total security – both unaffordable and unachievable.
Law,Political Science,Computer Science
What problem does this paper attempt to address?