Editor's note: Improving FISMA

CISOs are looking for ways to complement the FISMA regime with a program that emphasizes continuous monitoring

What is it about our human psyche that makes procedure a substitute for a solution? You see it in legal circles, where justice and public safety often take a back seat to following the book, as if it’s the book that deters a criminal act. Since the 2001 terrorist attacks, we’ve seen it applied to information security, to the extent that merely documenting your agency’s prior safety record is tantamount to declaring victory over the bad guys who never sleep.

The Federal Information Security Management Act was a federal response to a real problem — the fact that agencies and their computer systems are under constant threat from cyber terrorists. But for many a chief information security officer — the person appointed to oversee an agency’s threat response — FISMA guidelines often seem like a never-ending stream of paperwork designed to document what didn’t happen last year. More hours are spent compiling certification and accreditation reports than are devoted to finding and deterring malicious acts.

Now some CISOs are looking for ways to complement the FISMA regime with a program that emphasizes continuous monitoring. As contributing writer John Moore reports in our cover story, some agencies are adopting a strategy that depends, in part, on a package of 20 security practices, named the Consensus Audit Guidelines or the 20 critical security controls.

CAG states that enterprises should focus on a few key controls that block the most common types of known attacks, and those controls should be monitored around the clock.

It’s a notion that has critics, to be sure. But CAG has found favor with the Office of Management and Budget, and it is being practiced in key venues such as the State Department, which must guard locations that span the globe. What’s more, it has the ring of real problem-solving and the smell of true vigilance.

 

About the Author

David Rapp is editor-in-chief of Federal Computer Week and VP of content for 1105 Government Information Group.

FCW in Print

In the latest issue: Looking back on three decades of big stories in federal IT.

Featured

  • FCW @ 30 GPS

    FCW @ 30

    Since 1996, FCW has covered it all -- the major contracts, the disruptive technologies, the picayune scandals and the many, many people who make federal IT function. Here's a look back at six of the most significant stories.

  • Shutterstock image.

    A 'minibus' appropriations package could be in the cards

    A short-term funding bill is expected by Sept. 30 to keep the federal government operating through early December, but after that the options get more complicated.

  • Defense Secretary Ash Carter speaks at the TechCrunch Disrupt conference in San Francisco

    DOD launches new tech hub in Austin

    The DOD is opening a new Defense Innovation Unit Experimental office in Austin, Texas, while Congress debates legislation that could defund DIUx.

  • Shutterstock image.

    Merged IT modernization bill punts on funding

    A House panel approved a new IT modernization bill that appears poised to pass, but key funding questions are left for appropriators.

  • General Frost

    Army wants cyber capability everywhere

    The Army's cyber director said cyber, electronic warfare and information operations must be integrated into warfighters' doctrine and training.

  • Rising Star 2013

    Meet the 2016 Rising Stars

    FCW honors 30 early-career leaders in federal IT.

Reader comments

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Please type the letters/numbers you see above

More from 1105 Public Sector Media Group