Managing the Security of Information Exchanges

An organization often has mission and business-based needs to exchange (share) information with one or more other internal or external organizations via various information exchange channels; however, it is recognized that the information being exchanged also requires the same or similar level of protection as it moves from one organization to another (protection commensurate with risk).

This publication focuses managing the protection of the information being exchanged or accessed before, during, and after the exchange rather than on any particular type of technology-based connection or information access or exchange method and thus provides guidance on identifying information exchanges, considerations for protecting exchanged information, and the agreement(s) needed to help manage protection of the exchanged information. Organizations are expected to tailor the guidance to meet specific organizational needs and requirements regarding the information exchange.

An organization often has mission and business-based needs to exchange (share) information with one or more other internal or external organizations via various information exchange channels; however, it is recognized that the information being exchanged also requires the same or similar level of. See full abstract

An organization often has mission and business-based needs to exchange (share) information with one or more other internal or external organizations via various information exchange channels; however, it is recognized that the information being exchanged also requires the same or similar level of protection as it moves from one organization to another (protection commensurate with risk).

This publication focuses managing the protection of the information being exchanged or accessed before, during, and after the exchange rather than on any particular type of technology-based connection or information access or exchange method and thus provides guidance on identifying information exchanges, considerations for protecting exchanged information, and the agreement(s) needed to help manage protection of the exchanged information. Organizations are expected to tailor the guidance to meet specific organizational needs and requirements regarding the information exchange.

Keywords

agreements ; connection ; information exchange ; information exchange agreement ; interconnection ; interconnection security agreement ; memoranda of agreement ; memoranda of understanding ; nondisclosure agreement ; protection requirements ; risk management ; service level agreement ; user agreement

Control Families

Assessment, Authorization and Monitoring ; Planning ; Risk Assessment ; System and Communications Protection

Documentation

Supplemental Material:
None available

Document History:
01/26/21: SP 800-47 Rev. 1 (Draft)
07/20/21: SP 800-47 Rev. 1 (Final)

Topics

Security and Privacy

Laws and Regulations