Shows & Panels
- The 2014 Big Picture on Cyber Security
- AFCEA Answers
- Ask the CIO
- Connected Government
- Consolidating Mission-critical Systems
- Constituent Servicing
- The Data Privacy Imperative: Safeguarding Sensitive Data
- Eliminating the Pitfalls: Steps to Virtualization in Government
- Federal Executive Forum
- Federal Tech Talk
- Government Cloud Brokerage: Who, What, When, Where, Why?
- Government Mobility
- The Intersection: Where Technology Meets Transformation
- Maximizing ROI Through Data Center Consolidation
- Mobile Device Management
- The Modern Federal Threat Landscape
- Moving to the Cloud. What's the best approach for me
- Navigating Tough Choices in Government Cloud Computing
- Satellite Communications: Acquiring SATCOM in Tight Times
- Transformative Technology: Desktop Virtualization in Government
- Understanding the Intersection of Customer Service and Security in the Cloud
Shows & Panels
Search Tags: risk management
Testimony obtained by FederalNewsRadio says IT security measurements focus too much on compliance and not on risk. GAO surveyed 24 agencies and found few have moved beyond just fulfilling FISMA requirements.
Tags: technology , Greg Wilshusen , Vivek Kundra , John Streufert , GAO , OMB , State Department , Senate Homeland Security and Governmental Affairs , NIST , Tom Davis , Deloitte , cybersecurity , FISMA ,
Updated 800-53 publication expected by July 31
The National Institute of Standards and Technology's (NIST) recent release of Special Publication 800-37, Revision 1 Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach is an important change in the direction of how federal agencies achieve information security and manage information system-related security risks. It shifts the focus away from a point in time Certification and Accreditation (C&A) approach to compliance towards continually assessing risk and security authorization. As a result, the federal information security community is sending a message to the broader federal community and creating an important discussion: the cyber threat is real and must be addressed in the context of its potential impact on an organization. Cyber security is not as simple as a "check the box" requirement. The paradigm shift away from point in time security and towards obtaining situational awareness of the organization's risk posture must be as pervasive in the federal government as the cyber threats are against us.
Regarding the impact on agency security procedures, the publication is clear on the focus of its new framework, stating:
The revised process emphasizes: (i) building information security capabilities into federal information systems through the application of state-of-the-practice management, operational, and technical security controls; (ii) maintaining awareness of the security state of information systems on an ongoing basis through enhanced monitoring processes; and (iii) providing essential information to senior leaders to facilitate decisions regarding the acceptance of risk to organizational operations and assets, individuals, other organizations, and the Nation arising from the operation and use of information systems.
This new Risk Management Framework builds much needed flexibility into the overall federal information security lifecycle to address the increasing nature and scope of threats in real-time, providing a number of key advantages that include:
- Continually evaluating the organization's risk posture and maintaining situational awareness of its cyber security posture
- Understanding the state and maturity of an agency's cyber security program
- Evaluating cyber security programs at key vulnerability points: people, processes, and technology
- Maintaining a focus on the security program lifecycle
- Addressing the key functions (governance, risk, management, compliance, operations) of a security program
Perhaps most importantly, agency security programs will be better positioned to evolve and mature - an absolute necessity for staying ahead of the growing and dynamic threat to our Nation's cyber security.
Lawmakers question TSA, NPPD on 2010 budget proposals. Rep. Jackson-Lee says NPPD may need to be reorganized.
Tags: mngt , technology , Phil Reitinger , Gail Rossides , Rep. Sheila Jackson-Lee , Rep. Dan Lungren , Rand Beers , DHS , TSA , National Protection and Programs Directorate , House Homeland Security Committee , Registered Traveler , Secure Flight , cybersecurity ,