文档介绍:NIST Special Publication 800-55 Security Metrics Guide for
Information Technology Systems
Marianne Swanson, Nadya Bartol, John Sabato, Joan
Hash, and Laurie Graffo
C O M P U T E R S E C U R I T Y
Computer Security Division
Information Technology Laboratory
National Institute of Standards and Technology
Gaithersburg, MD 20899-8933
July 2003 INITIAL PUBLIC DRAFT
. Department merce
Donald L. Evans, Secretary
Technology Administration
Phillip J. Bond, Under Secretary merce for Technology
National Institute of Standards and Technology
Arden L. Bement, Jr., Director
i
Reports puter Systems Technology
The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology
(NIST) promotes the . economy and public welfare by providing technical leadership for the Nation’s
measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof of
concept implementations, and technical analyses to advance the development and productive use of
information technology. ITL’s responsibilities include the development of management, administrative,
technical, and physical standards and guidelines for the cost-effective security and privacy of sensitive
unclassified information in puter systems. This Special Publication 800-series reports on ITL’s
research, guidelines, and outreach efforts puter security, and its collaborative activities with
industry, government, and anizations.
. GOVERNMENT PRINTING OFFICE
WASHINGTON: 2003
For sale by the Superintendent of Documents, . Government Printing Office
: — Phone: (202) 512-1800 — Fax: (202) 512-2250
Mail: Stop SSOP, Washington, DC 20402-0001
ii
Authority
This document has been developed by NIST in furtherance of its statutory responsibilities under puter
Security Act of 1987 and