Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST SP 800-18 Rev. 1

Guide for Developing Security Plans for Federal Information Systems

Date Published: February 2006

Supersedes: SP 800-18 (12/01/1998)

Planning Note (03/17/2023): Send inquiries about this publication to


Marianne Swanson (NIST), Joan Hash (NIST), Pauline Bowen (NIST)



Authorize processing; computer security; general support system; major application; management controls; operational controls; rules of behavior; security plan; technical controls
Control Families

Assessment, Authorization and Monitoring; Planning


Download URL

Supplemental Material:
None available

Document History:
02/24/06: SP 800-18 Rev. 1 (Final)