The Program Review for Information Security Assistance (PRISMA) project was last updated in 2007; NIST Interagency Report (IR) 7358 and the corresponding PRISMA tool continue to serve as useful resources for high-level guidance and as a general framework, but may not be fully consistent with changes to requirements, standards and guidelines for securing systems.
Option one of a PRISMA review focuses on the strategic aspects of the overall information security program. The review identifies the level of maturity of the information security program and the agency's ability to comply with existing requirements in eight areas focus areas:
Security and Privacy: assurance, program management