User guide

Chapter 7. Federal Standards and Regulations
110
7.3. National Industrial Security Program Operating Manual
(NISPOM)
The NISPOM (also called DoD 5220.22-M), as a component of the National Industrial Security
Program (NISP), establishes a series of procedures and requirements for all government contractors
with regard to classified information. The current NISPOM is dated February 28, 2006. The NISPOM
document can be downloaded from the following URL: https://www.dss.mil/GW/ShowBinary/DSS/isp/
fac_clear/download_nispom.html.
7.4. Payment Card Industry Data Security Standard (PCI
DSS)
From https://www.pcisecuritystandards.org/about/index.shtml: The PCI Security Standards Council
is an open global forum, launched in 2006, that is responsible for the development, management,
education, and awareness of the PCI Security Standards, including the Data Security Standard (DSS).
You can download the PCI DSS standard from https://www.pcisecuritystandards.org/
security_standards/pci_dss.shtml.
7.5. Security Technical Implementation Guide
A Security Technical Implementation Guide or STIG is a methodology for standardized secure
installation and maintenance of computer software and hardware.
Refer to the following URL for a list of available guides: http://iase.disa.mil/stigs/stig/index.html.