ACS Directive Handbook OCIO-01 Handbook for Information ...

All such risk assessments shall be conducted in accordance with NIST SP 800-30, Risk Management Guide for Information Technology Systems, and Department’s Information Assurance Risk Assessment Guide. All risk assessments must be documented and have signed acknowledgement of receipt by the system security officer and the Principal Officer. ................
................