[CWA14167-1]
Security Requirements for Trustworthy Systems Managing Certificates for Electronic Signatures Part 1: System Security Requirements, CEN Workshop Agreement, CWA 14167-1, June 2003
[FIP186-2]
NIST FIPS PUB 186-2 “Digital Signature Standard (DSS),” with Change Notice 1, October 2001.
[FIPS-140-2]
National Institute of Standards and Technology, FIPS 140-2, Security Requirements for
Cryptographic Modules, January 24, 2007
[Mitre]
Mitre, 2009 CWE/SANS Top 25 Most Dangerous Programming Errors, http://cwe.mitre.org/
top25/, January 2009.
[RFC 4301]
Kent & Seo, Security Architecture for IP, RFC 4301, December 2005
[RFC3851]
Ramsdell, S/MIME 3.1 Message Specification, RFC 3851, July 2004
[RFC4346]
Dierks & Rescorla, The TLS Protocol, RFC4301, April 2006
[RSA]
RSA Laboratories, “PKCS#1 v2.1: RSA Cryptography Standard,” June 2002.
[SFTP]
Galbraith & Saarenmaa, SSH File Transfer Protocol, draft-ietf-secsh-filexfer, June 2005
[SHA]
NIST FIPS PUB 180-2, “Secure Hash Standard,” National Institute of Standards and Technology,
U.S. Department of Commerce., August 2001.
[SP800-67]
NIST SP 800-67 “Recommendation for the Triple Data Encryption Algorithm (TDEA) Block Cipher,”
May 2004.
[ISO11770-1]
Information technology – Security Techniques, Key Management, ISO/IEC 11770-1:2006(E) Part
1: Key Management-Framework, International Organisation for Standardisation & International
Electrotechnical Commission, 2006
[RFC4408]
M. Wong, W. Schlitt, on Sender Policy Framework (SPF) for Authorizing Use of Domains in E-Mail,
Version 1, Internet Engineering Task Force (IETF), RFC 4408, April 2006
Defined terms are specified in the Information Assurance Framework, [IAP-NAT-IAFW]. The following defined terms
are used in this document: Agency, State Agency, Personal Information, Hot/Warm/Cold Sites, Q-CERT,
MOTC, National Classification Markings.
17
NATIONAL INFORMATION ASSURANCE MANUAL