U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

FIPS 200

Minimum Security Requirements for Federal Information and Information Systems

Date Published: March 2006

Supersedes: SP 800-26 (11/01/2001)

Planning Note (3/17/2023): Send inquiries about this publication to sec-cert@nist.gov.

Author(s)

National Institute of Standards and Technology

Abstract

Keywords

risk-assessment; security controls; security requirements
Control Families

Access Control; Audit and Accountability; Awareness and Training; Assessment, Authorization and Monitoring; Configuration Management; Contingency Planning; Identification and Authentication; Incident Response; Maintenance; Media Protection; Personnel Security; Physical and Environmental Protection; Planning; Risk Assessment; System and Communications Protection; System and Information Integrity; System and Services Acquisition

Documentation

Publication:
FIPS 200 (DOI)
Local Download

Supplemental Material:
None available

Related NIST Publications:
FIPS 199

Document History:
03/01/06: FIPS 200 (Final)