AbstractManagement areas of considerationManagement controlsInformation security resourcesMeasures of performance (SP 800-55)Measures of performanceFederal enterprise architectureSystem and services acquisition (SA)Security services life cycleInformation security and external partiesCA – security assessment and authorizationPL – planning family and family plansRA – risk assessment familyCritical success factors to information security managementOperational areas of considerationOperational security controls key conceptsPhysical securityPersonnel securitySystem integrityTechnical areas of considerationAccess controlIdentification and authentication