ABSTRACT

With the passage of FISMA and other federal legislation that mandates implementation of security controls, compliance has become a primary business requirement for federal agencies and private companies that have contractual relationships with the federal government. With an increased emphasis on compliance, it appears that the future of certification and accreditation is secure. The body of guidance that has been developed by the National Institute of Standards and Technology and the promise of continued refinement of that guidance have provided a strong foundation for a practical and simplified approach to certification and accreditation that should to be able to withstand the test of time.