<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Handbook AS-805 Archives -</title>
	<atom:link href="https://zymitry.com/tag/handbook-as-805/feed/" rel="self" type="application/rss+xml" />
	<link>https://zymitry.com/tag/handbook-as-805/</link>
	<description>Tech &#38; Other Stuff</description>
	<lastBuildDate>Thu, 05 Jun 2025 22:53:56 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://i0.wp.com/zymitry.com/wp-content/uploads/2016/11/favicon.png?fit=32%2C32&#038;ssl=1</url>
	<title>Handbook AS-805 Archives -</title>
	<link>https://zymitry.com/tag/handbook-as-805/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">120106411</site>	<item>
		<title>Information Security Publication Comparison</title>
		<link>https://zymitry.com/information-security-publication/</link>
					<comments>https://zymitry.com/information-security-publication/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Sat, 26 Nov 2016 04:18:17 +0000</pubDate>
				<category><![CDATA[Information Security Compliance]]></category>
		<category><![CDATA[comparison]]></category>
		<category><![CDATA[Handbook AS-805]]></category>
		<category><![CDATA[ISO27002]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[publication]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://zymitry.com/?p=297</guid>

					<description><![CDATA[<p>Information Security Publication Comparison: Chart comparing major sections of the USPS Handbook AS-805 - Information Security to NIST Special Publications; 800-12, 800-14, 800-18, 800-26, and 800-30.</p>
<p>The post <a href="https://zymitry.com/information-security-publication/">Information Security Publication Comparison</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<h1>Information Security Publication Comparison</h1>
<p>&nbsp;</p>
<p><strong>Information Security Publication Comparison</strong></p>
<h4>Chart comparing major sections of the USPS Handbook AS-805 &#8211; Information Security to NIST Special Publications; 800-12, 800-14, 800-18, 800-26, and 800-30.</h4>
<table style="height: 1437px;" width="911">
<tbody>
<tr>
<td width="319"><strong>Handbook AS-805 &#8211; Information Security (USPS, 2015)</strong></td>
<td width="319"><strong>NIST Special Publications</strong></td>
</tr>
<tr>
<td width="319">Introduction: Corporate Information Security</td>
<td width="319">Generally Accepted System Security Principles (NIST SP 800-14)</td>
</tr>
<tr>
<td width="319">Security Roles and Responsibilities</td>
<td width="319">System Security Plan Responsibilities <a href="https://web.archive.org/web/20250529010625/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf" target="_blank" rel="noopener noreferrer">(NIST SP 800-18)</a>,  (NIST SP 800-14)</td>
</tr>
<tr>
<td width="319">Information Designation and Control</td>
<td width="319">Generally Accepted System Security Principles (NIST SP 800-14)</td>
</tr>
<tr>
<td width="319">Security Risk Management</td>
<td width="319">Guide for Conducting Risk Assessments. <a href="https://web.archive.org/web/20250525195835/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf" target="_blank" rel="noopener noreferrer">(NIST SP 800-30) </a>(NIST SP 800-14)</td>
</tr>
<tr>
<td width="319">Acceptable Use</td>
<td width="319">Generally Accepted System Security Principles (NIST SP 800-14)</td>
</tr>
<tr>
<td width="319">Personnel Security</td>
<td width="319">Generally Accepted System Security Principles (NIST SP 800-14)</td>
</tr>
<tr>
<td width="319">Physical and Environmental Security</td>
<td width="319">3.10 Physical and Environmental Security (NIST SP 800-14), Physical and Environmental Security (NIST SP 800-12),</td>
</tr>
<tr>
<td width="319">Development and Operations Security</td>
<td width="319">1.5 Major Applications, General Support Systems, and Minor Applications <a href="https://web.archive.org/web/20250529010625/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf" target="_blank" rel="noopener noreferrer">(NIST SP 800-18)</a>, 3.9 Security Considerations in Computer Support and Operations (NIST SP 800-14)</td>
</tr>
<tr>
<td width="319">Information Security Services</td>
<td width="319">3.14 Minimum Security Controls <a href="https://web.archive.org/web/20250529010625/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf" target="_blank" rel="noopener noreferrer">(NIST SP 800-18)</a></td>
</tr>
<tr>
<td width="319">Hardware and Software Security</td>
<td width="319">Several chapters (NIST SP 800-14)</td>
</tr>
<tr>
<td width="319">Network Security</td>
<td width="319">2.3 General Support Systems <a href="https://web.archive.org/web/20250529010625/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf" target="_blank" rel="noopener noreferrer">(NIST SP 800-18)</a> Management Control (NIST SP 800-12)</td>
</tr>
<tr>
<td width="319">Business Continuity Management</td>
<td width="319">3.6 Preparing for Contingencies and Disasters (NIST SP 800-14),</td>
</tr>
<tr>
<td width="319">Security Incident Management</td>
<td width="319">12.0 Computer Security Incident Handling (NIST SP 800-12), 3.7 Computer Security Incident Handling (NIST SP 800-14)</td>
</tr>
<tr>
<td width="319">Security Compliance and Monitoring</td>
<td width="319">3.16 Ongoing System Security Plan Maintenance <a href="https://web.archive.org/web/20250529010625/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf" target="_blank" rel="noopener noreferrer">(NIST SP 800-18)</a></td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<h4>Chart comparing the ISO/IEC 27002 with NIST Publications</h4>
<table style="height: 1740px;" width="917">
<tbody>
<tr>
<td width="235"><strong>ISO27002 </strong><a href="https://web.archive.org/web/20220702104124/https://www.praxiom.com/iso-27002.htm" target="_blank" rel="noopener noreferrer">(Praxiom web, 2013)</a></td>
<td width="83"><strong>NIST 800-12</strong></td>
<td width="79"><strong>NIST 800-14</strong></td>
<td width="78"><a href="https://web.archive.org/web/20250529010625/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf" target="_blank" rel="noopener noreferrer"><strong>NIST 800-18</strong></a></td>
<td width="90"><strong>NIST 800-26</strong></td>
<td width="96"><a href="https://web.archive.org/web/20250525195835/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf" target="_blank" rel="noopener noreferrer"><strong>NIST 800-30</strong></a></td>
</tr>
<tr>
<td width="235">Security Policy Management</td>
<td width="83">Covered. NIST is more of an overview</td>
<td width="79">Covers many aspects such as security program management.</td>
<td width="78">Covered. Both cover same aspects.</td>
<td width="90">Not directly covered. Program management briefly covered.</td>
<td width="96">Not covered</td>
</tr>
<tr>
<td width="235">Corporate Security Management</td>
<td width="83">Covered. NIST is more of an overview</td>
<td width="79">Covered in depth.</td>
<td width="78">Covers duties and responsibilities.</td>
<td width="90">Not covered</td>
<td width="96">Not covered</td>
</tr>
<tr>
<td width="235">Personal Security Management</td>
<td width="83">Covers personnel/user issues</td>
<td width="79">Both cover same aspects</td>
<td width="78">Not covered</td>
<td width="90">Covered only as a checklist item</td>
<td width="96">Not covered</td>
</tr>
<tr>
<td width="235">Organizational Asset Management</td>
<td width="83">Covered</td>
<td width="79">Not covered</td>
<td width="78">Not Covered</td>
<td width="90">Covered</td>
<td width="96">Not Covered</td>
</tr>
<tr>
<td width="235">Information Access Management</td>
<td width="83">Covered Chapter 17</td>
<td width="79">Covered Chapter 3</td>
<td width="78">Not covered</td>
<td width="90">Not covered</td>
<td width="96">Not covered</td>
</tr>
<tr>
<td width="235">Cryptography Policy Management</td>
<td width="83">Covered Chapter 19</td>
<td width="79">Covered briefly Chapter 3.14</td>
<td width="78">Not covered</td>
<td width="90">Not covered</td>
<td width="96">Not covered</td>
</tr>
<tr>
<td width="235">Physical Security Management</td>
<td width="83">Covered Chapter 15</td>
<td width="79">Covered Chapter 3.10</td>
<td width="78">Not covered</td>
<td width="90">Not covered</td>
<td width="96">Not Covered</td>
</tr>
<tr>
<td width="235">Operational Security Management</td>
<td width="83">Covered</td>
<td width="79">Covered. ISO 27002 offers more detail</td>
<td width="78">Covered</td>
<td width="90">Covered</td>
<td width="96">Covered</td>
</tr>
<tr>
<td width="235">Network Security Management</td>
<td width="83">Covered only as a control</td>
<td width="79">Covered only as a system</td>
<td width="78">Not covered</td>
<td width="90">Not covered</td>
<td width="96">Not covered</td>
</tr>
<tr>
<td width="235">System Security Management</td>
<td width="83">Not covered</td>
<td width="79">Not covered</td>
<td width="78">Covered Chapter 2.3</td>
<td width="90">Covered Chapter 3.1.2</td>
<td width="96">Not covered</td>
</tr>
<tr>
<td width="235">Supplier Relationship Management</td>
<td width="83">Covered as overview Chapter 10</td>
<td width="79">Not covered</td>
<td width="78">Not covered</td>
<td width="90">Not covered</td>
<td width="96">Not covered</td>
</tr>
<tr>
<td width="235">Security Incident Management</td>
<td width="83">Covered in detail 11 &amp; 12</p>
<p>&nbsp;</td>
<td width="79">Covered Chapter 3.7</td>
<td width="78">Not covered</td>
<td width="90">Not covered</td>
<td width="96">Covers threat events and response</td>
</tr>
<tr>
<td width="235">Security Continuity Management</td>
<td width="83">Not covered</td>
<td width="79">Covers security reassessment</td>
<td width="78">Covered Chapter 3.16</td>
<td width="90">Covered Chapter 4.3.1</td>
<td width="96">Covers assessment cycle</td>
</tr>
<tr>
<td width="235">Security Compliance Management</td>
<td width="83">Covered Chapter 6</td>
<td width="79">Covers as part of policy</td>
<td width="78">Covered Chapter 3.12</td>
<td width="90">Covers compliance reviews</td>
<td width="96">Covered</td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<h4>References</h4>
<p><a href="https://web.archive.org/web/20250525195835/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf" target="_blank" rel="noopener noreferrer">http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf</a></p>
<p><a href="https://web.archive.org/web/20220702104124/https://www.praxiom.com/iso-27002.htm" target="_blank" rel="noopener noreferrer">http://www.praxiom.com/iso-27002.htm</a></p>
<p><a href="https://csrc.nist.gov/publications/detail/sp/800-12/archive/1995-10-02" target="_blank" rel="noopener">https://csrc.nist.gov/publications/detail/sp/800-12/archive/1995-10-02</a></p>
<p><a href="http://csrc.nist.gov/publications/nistpubs/800-14/800-14.pdf" target="_blank" rel="noopener noreferrer nofollow">Click to access 800-14.pdf</a></p>
<p><a href="https://web.archive.org/web/20250529010625/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf" target="_blank" rel="noopener noreferrer">http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf</a></p>
<p>https://about.usps.com/handbooks/as805/welcome.htm</p>
<h4>Additional Articles</h4>
<p><a href="https://zymitry.com/byod-policies-practices/" target="_blank" rel="noopener">Bring Your Own Device (BYOD) Policies and Practices</a></p>
<p><a href="https://zymitry.com/governance-cloud-systems/" target="_blank" rel="noopener">The Governance of Cloud-Based Systems</a></p>
<p><a href="https://zymitry.com/cloud-computing-saas-paas-iaas/" target="_blank" rel="noopener">Cloud Computing Models -SaaS, PaaS, IaaS</a></p>
<p><a href="https://zymitry.com/artificial-intelligence-implications-exploration/" target="_blank" rel="noopener">Exploring the Implications of Artificial Intelligence</a></p>
<p><a href="https://zymitry.com/artificial-intelligence-texas-higher-ed/" target="_blank" rel="noopener">Artificial Intelligence in Texas Higher Education: Ethical Considerations, Privacy, and Security</a></p>
<p><a href="http://zymitry.com/zymitry-disclaimer/" target="_blank" rel="noopener noreferrer">Disclaimer</a></p>
<p><a href="https://zymitry.com/terms-conditions-use/" target="_blank" rel="noopener">Terms and Conditions of Use</a></p>
<p>&nbsp;</p>
<p>The post <a href="https://zymitry.com/information-security-publication/">Information Security Publication Comparison</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/information-security-publication/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">297</post-id>	</item>
	</channel>
</rss>
