What is your e-mail address?

My e-mail address is:

Do you have a password?

Forgot your password? Click here
close

OMB proposes new FISMA performance metrics

OMB wants feedback on potential metrics

The Office of Management and Budget has detailed possible new metrics for agencies to use in the annual computer security reporting they do to comply with the Federal Information Security Management Act.

The proposed metrics “represent a new approach, which focuses on improving security, not just compliance,” according to a statement posted on the National Institute of Standards and Technology’s Web site. Requirements for FISMA compliance have been often criticized for being too focused on paperwork.

OMB asked that comments on the potential metrics be sent to OMB-Metrics@nist.gov by Jan. 4, 2010.

In the OMB’s report to Congress on agencies’ FISMA implementation during fiscal 2008, OMB said it would review the security metrics agencies use to report their compliance with FISMA and it may develop new metrics to improve the assurance of information security.

“These metrics should encourage agencies to take concrete steps to improve their security posture by implementing monitoring tools, strengthening areas such as identity and configuration management, and reporting on four new categories: remote access management, identity and access management, data level controls, real-time security awareness and management,” the statement, posted Dec. 8, said.

About the Author

Ben Bain is a reporter for Federal Computer Week.

Reader comments

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Your Name:(optional)
Your Email:(optional)
Your Location:(optional)
Comment:
Please type the letters/numbers you see above

Editorial Webcasts

  • Desktop Virtualization: Better Management with Smaller Budgets Register Now

    This webcast will explore the benefits of desktop virtualization, and how the innovative technology can help agencies lower the cost of their IT infrastructure, improve end-user performance, while enabling a mobile workforce. A government expert will share real-life case studies of leveraging desktop virtualization solutions to enable secure telework policies, organization-wide IT infrastructure standards and extend the life of current hardware assets - Register Now!! Read more

Federal Computer Week eNewsletters

  • Subscribe to Newsletters Subscribe

    Federal Computer Week's eNewsletters deliver the latest policy and management news to your inbox.