请输入您要查询的百科知识:

 

词条 National Industrial Security Program
释义

  1. NISP Operating Manual (DoD 5220.22-M)

     Data sanitization 

  2. References

  3. External links

The National Industrial Security Program, or NISP, is the nominal authority (in the United States) for managing the needs of private industry to access classified information.{{fact|date=April 2016}}

The NISP was established in 1993 by Executive Order 12829.[1] The National Security Council nominally sets policy for the NISP, while the Director of the Information Security Oversight Office is nominally the authority for implementation. Under the ISOO, the Secretary of Defense is nominally the Executive Agent, but the NISP recognizes four different Cognizant Security Agencies, all of which have equal authority: the Department of Defense, the Department of Energy, the Central Intelligence Agency, and the Nuclear Regulatory Commission.[2]

NISP Operating Manual (DoD 5220.22-M)

A major component of the NISP is the NISP Operating Manual, also called NISPOM, or DoD 5220.22-M. The NISPOM establishes the standard procedures and requirements for all government contractors, with regards to classified information. {{As of|2017}}, the current NISPOM edition is dated 28 Feb 2006. Chapters and selected sections of this edition are:[3]

  • Chapter 1 – General Provisions and Requirements
  • Chapter 2 – Security Clearances
    • Section 1 – Facility Clearances
    • Section 2 – Personnel Security Clearances
    • Section 3 – Foreign Ownership, Control, or Influence (FOCI)
  • Chapter 3 – Security Training and Briefings
  • Chapter 4 – Classification and Marking
  • Chapter 5 – Safeguarding Classified Information
  • Chapter 6 – Visits and Meetings
  • Chapter 7 – Subcontracting
  • Chapter 8 – Information System Security
  • Chapter 9 – Special Requirements
    • Section 1 – RD and FRD
    • Section 2 – DoD Critical Nuclear Weapon Design Information (CNWDI)
    • Section 3 – Intelligence Information
    • Section 4 – Communication Security (COMSEC)
  • Chapter 10 – International Security Requirements
  • Chapter 11 – Miscellaneous Information
    • Section 1 – TEMPEST
    • Section 2 – Defense Technical Information Center (DTIC)
    • Section 3 – Independent Research and Development (IR&D) Efforts
  • Appendices

Data sanitization

DoD 5220.22-M is sometimes cited as a standard for sanitization to counter data remanence. The NISPOM actually covers the entire field of government–industrial security, of which data sanitization is a very small part (about two paragraphs in a 141-page document).[4] Furthermore, the NISPOM does not actually specify any particular method. Standards for sanitization are left up to the Cognizant Security Authority. The Defense Security Service provides a Clearing and Sanitization Matrix (C&SM) which does specify methods.[5] As of the June 2007 edition of the DSS C&SM, overwriting is no longer acceptable for sanitization of magnetic media; only degaussing or physical destruction is acceptable.[6]

References

1. ^{{cite web|url=http://www.fas.org/irp/offdocs/eo12829.htm|title=Executive Order 12829|work=FAS website|accessdate=2007-04-01}}
2. ^{{cite web | url=http://www.dss.mil/isec/nispbrochure.pdf| title=NISP Brochure | publisher=DSS| format=PDF | archiveurl=https://web.archive.org/web/20060420050102/http://www.dss.mil/isec/nispbrochure.pdf | archivedate=2006-04-20 | accessdate=2007-04-01 }} (59 KB)
3. ^{{cite web|url=http://www.dss.mil/isp/fac_clear/download_nispom.html|title=Download NISPOM|publisher=DSS|accessdate=2010-11-10}}
4. ^{{cite web|url = http://www.dss.mil/documents/odaa/nispom2006-5220.pdf#page=75|title = National Industrial Security Program Operating Manual (NISPOM)|accessdate = 2013-03-07|author = DoD|publisher = DSS|date = 2006-02-28|pages = 8–3-1|format = PDF|authorlink = United States Department of Defense}} (1.92 MB)
5. ^{{cite web|url=http://www.oregon.gov/DAS/OP/docs/policy/state/107-009-005_Exhibit_B.pdf| title=DSS Clearing & Sanitization Matrix|publisher=DSS| format=PDF|date=2007-06-28|accessdate=2011-04-26}} (98 KB)
6. ^NIST (2014-12-18). Unrelated to NISP or NISPOM, National Institute of Standards and Technology (NIST) Computer Security Division Released Special Publication 800-88 Revision 1, Guidelines for Media Sanitization, 18 December 2014. Retrieved from http://csrc.nist.gov/news_events/news_archive/news_archive_2014.html#dec18.

External links

  • [https://www.archives.gov/isoo/policy-documents/eo-12829.html EO-12829 overview ("National Industrial Security Program")]
  • [https://www.archives.gov/isoo/policy-documents/eo-12829.pdf EO-12829 PDF]
  • NIST News Archive 2014-12-18
{{Data Erasure}}

7 : Establishments by United States executive order|United States intelligence agencies|United States Department of Defense agencies|Classified documents|Data security|United States government secrecy|Data erasure

随便看

 

开放百科全书收录14589846条英语、德语、日语等多语种百科知识,基本涵盖了大多数领域的百科知识,是一部内容自由、开放的电子版国际百科全书。

 

Copyright © 2023 OENC.NET All Rights Reserved
京ICP备2021023879号 更新时间:2024/11/10 18:22:29