NIST published Generally Accepted Principles and Practices for Securing Information Technology Systems (Special Pub 800-14) in September 1996. Its eight principles are listed below: Computer Security Supports the Mission of the Organization and Cost-Effective Security Is an Integral Element of Sound Management. It is Constrained by Societal Factors. It requires a Comprehensive and Integrated Approach. It should be Periodically Reassessed. It must be cost-effective. It also requires a comprehensive and integrated approach.”]

