<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mods="http://www.loc.gov/mods/v3" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee1c1bb3430">
    <name type="corporate">
         <namePart>United States Government Publishing Office</namePart>
         <role>
              <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
              <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
        </role>
         <role>
              <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
              <roleTerm authority="marcrelator" type="code">dst</roleTerm>
        </role>
    </name>
    <name type="corporate">
         <namePart>United States</namePart>
         <namePart>Commerce Department</namePart>
         <namePart>National Institute of Standards and Technology (NIST)</namePart>
         <role>
              <roleTerm authority="marcrelator" type="text">author</roleTerm>
              <roleTerm authority="marcrelator" type="code">aut</roleTerm>
        </role>
         <description>Government Organization</description>
    </name>
    <name type="personal">
         <namePart>Joint Task Force.</namePart>
         <role>
              <roleTerm authority="marcrelator" type="text">author</roleTerm>
              <roleTerm authority="marcrelator" type="code">aut</roleTerm>
        </role>
    </name>
    <typeOfResource>text</typeOfResource>
    <genre authority="marcgt">government publication</genre>
    <language>
         <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
    </language>
    <extension>
         <collectionCode>GOVPUB</collectionCode>
         <category>Executive Agency Publications</category>
         <branch>executive</branch>
         <dateIngested>2023-10-27</dateIngested>
    </extension>
    <originInfo>
         <publisher>Commerce Department</publisher>
         <dateIssued encoding="w3cdtf">2022-01-25</dateIssued>
         <issuance>monographic</issuance>
         <edition>New version</edition>
    </originInfo>
    <physicalDescription>
         <note type="source content type">deposited</note>
         <digitalOrigin>born digital</digitalOrigin>
         <extent>733 digital object pages</extent>
    </physicalDescription>
    <classification authority="sudocs">C 13.</classification>
    <identifier type="uri">https://www.govinfo.gov/app/details/GOVPUB-C13-50108754418a2f7a74f636e2f8ea96ed</identifier>
    <identifier type="local">P0b002ee1c1bb3430</identifier>
    <relatedItem type="series">
         <titleInfo>
              <title>NIST Special Publications</title>
        </titleInfo>
    </relatedItem>
    <identifier type="ILS system id">on1389890229</identifier>
    <identifier type="oclc">(OCoLC)1389890229</identifier>
    <recordInfo>
         <recordContentSource authority="marcorg">DGPO</recordContentSource>
         <recordCreationDate encoding="w3cdtf">2023-10-27</recordCreationDate>
         <recordChangeDate encoding="w3cdtf">2026-06-27</recordChangeDate>
         <recordIdentifier source="DGPO">GOVPUB-C13-50108754418a2f7a74f636e2f8ea96ed</recordIdentifier>
         <recordOrigin>machine generated</recordOrigin>
         <languageOfCataloging>
              <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
        </languageOfCataloging>
    </recordInfo>
    <accessCondition type="GPO scope determination">fdlp</accessCondition>
    <extension>
         <docClass>C13</docClass>
         <accessId>GOVPUB-C13-50108754418a2f7a74f636e2f8ea96ed</accessId>
         <uniqueId>50108754418a2f7a74f636e2f8ea96ed</uniqueId>
         <ACCode>GOVPUB</ACCode>
         <fedPubName>NIST Special Publications</fedPubName>
         <field name="Note">NOTE: THE “DATE ISSUED” ABOVE MAY DEFAULT TO JANUARY 1ST OF A GIVEN YEAR. TO THE VIEW THE MOST ACCURATE DATE OF ISSUE, REVIEW THE TITLE PAGE OF THE PUBLICATION.</field>
         <description>This series includes proceedings of conferences sponsored by NIST, NIST annual reports, and other special publications appropriate to this grouping such as wall charts, pocket cards, and bibliographies.</description>
         <agency abbrev="NIST">National Institute of Standards and Technology</agency>
         <resultsLineTwoText>Commerce Department. National Institute of Standards and Technology. 2022</resultsLineTwoText>
         <dateIssued>2022-01-25</dateIssued>
    </extension>
    <location>
         <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GOVPUB-C13-50108754418a2f7a74f636e2f8ea96ed</url>
         <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GOVPUB-C13-50108754418a2f7a74f636e2f8ea96ed/pdf/GOVPUB-C13-50108754418a2f7a74f636e2f8ea96ed.pdf</url>
    </location>
    <titleInfo>
         <title>Assessing Security and Privacy Controls in Information Systems and Organizations</title>
    </titleInfo>
    <subject>
         <topic>Assessment</topic>
         <topic>Assessment plan</topic>
         <topic>Assurance</topic>
         <topic>Control assessment</topic>
         <topic>FISMA</topic>
         <topic>Open Security Controls Assessment Language (OSCAL)</topic>
         <topic>Privacy controls</topic>
         <topic>Privacy requirements</topic>
         <topic>Risk Management Framework</topic>
         <topic>Security controls</topic>
         <topic>Security requirements</topic>
         <name type="personal">
              <namePart>United States. Federal Information Security Management Act of 2002</namePart>
        </name>
    </subject>
    <name type="corporate">
         <namePart>Joint Task Force</namePart>
         <role>
              <roleTerm authority="marcrelator" type="text">creator</roleTerm>
        </role>
    </name>
    <name type="personal">
         <namePart>Joint Task Force.</namePart>
    </name>
    <name type="corporate">
         <namePart>National Institute of Standards and Technology (U.S.)</namePart>
         <namePart>Information Technology Laboratory</namePart>
    </name>
    <originInfo>
         <place>
              <placeTerm authority="marccountry" type="code">mdu</placeTerm>
        </place>
         <publisher>U.S. Dept. of Commerce, National Institute of Standards and Technology</publisher>
         <dateIssued>2022-01-25.</dateIssued>
         <edition>New version</edition>
         <issuance>monographic</issuance>
    </originInfo>
    <physicalDescription>
         <extent>1 online resource (733 pages) : illustrations (color)</extent>
    </physicalDescription>
    <typeOfResource>text</typeOfResource>
    <genre authority="marcgt">technical report</genre>
    <language>
         <languageTerm authority="iso639-2b" type="code">eng</languageTerm>
    </language>
    <abstract>This publication provides a methodology and set of procedures for conducting assessments of security and privacy controls employed within systems and organizations within an effective risk management framework. The assessment procedures, executed at various phases of the system development life cycle, are consistent with the security and privacy controls in NIST Special Publication 800-53, Revision 5. The procedures are customizable and can be easily tailored to provide organizations with the needed flexibility to conduct security and privacy control assessments that support organizational risk management processes and are aligned with the stated risk tolerance of the organization. Information on building effective security and privacy assessment plans is also provided with guidance on analyzing assessment results.</abstract>
    <note type="statement of responsibility">Joint Task Force.</note>
    <note>January 2022.</note>
    <note>Title from PDF title page (viewed January 4, 2023).</note>
    <note type="bibliography">Includes bibliographical references.</note>
    <note type="venue">Approved by the NIST Editorial Review Board on 2022-01-20</note>
    <note type="system details">Mode of access: World Wide Web.</note>
    <note type="system details">Systems requirements: Adobe Acrobat PDF reader.</note>
    <subject authority="lcsh">
         <name type="corporate">
              <namePart>United States. Federal Information Security Management Act of 2002</namePart>
        </name>
    </subject>
    <subject>
         <topic>Assessment</topic>
    </subject>
    <subject>
         <topic>Assessment plan</topic>
    </subject>
    <subject>
         <topic>Assurance</topic>
    </subject>
    <subject>
         <topic>Control assessment</topic>
    </subject>
    <subject>
         <topic>FISMA</topic>
    </subject>
    <subject>
         <topic>Privacy controls</topic>
    </subject>
    <subject>
         <topic>Open Security Controls Assessment Language (OSCAL)</topic>
    </subject>
    <subject>
         <topic>Privacy requirements</topic>
    </subject>
    <subject>
         <topic>Risk Management Framework</topic>
    </subject>
    <subject>
         <topic>Security controls</topic>
    </subject>
    <subject>
         <topic>Security requirements</topic>
    </subject>
    <relatedItem type="series">
         <titleInfo>
              <title>NIST special publication; NIST special pub; NIST SP; 800-53Ar5</title>
        </titleInfo>
    </relatedItem>
    <location>
         <url displayLabel="electronic resource" usage="primary display">https://doi.org/10.6028/NIST.SP.800-53Ar5</url>
    </location>
    <titleInfo type="alternative">
         <title>Assessing security and privacy controls in information systems and organizations</title>
    </titleInfo>
    <extension>
         <searchTitle>
              <title>Assessing security and privacy controls in information systems and organizations</title>
        </searchTitle>
    </extension>
</mods>