SP 800-27 (REV. A), NIST SPECIAL PUBLICATION: ENGINEERING PRINCIPLES FOR INFORMATION TECHNOLOGY SECURITY (A BASELINE FOR ACHIEVING SECURITY) (JUN 2004)
SP 800-27 (REV. A), NIST SPECIAL PUBLICATION: ENGINEERING PRINCIPLES FOR INFORMATION TECHNOLOGY SECURITY (A BASELINE FOR ACHIEVING SECURITY) (JUN 2004)., The purpose of the Engineering Principles for Information Technology (IT) Security (EP-ITS)
is to present a list of system-level security
principles to be considered in the design,
development, and operation of an information system.
Ideally, the principles presented here would be used from the onset of a program—at the
beginning of, or during the initiation phase—and then employed throughout the system’s lifecycle.
However, these principles are also helpful in affirming and confirming the security
posture of already deployed information systems. The principles are short and concise and can
be used by organizations to develop their system life-cycle policies.