Davis backs FISMA

The Federal Information Security Management Act of 2002 has the right ideas, but the devil is in the details, said the chairman of the House Government Reform Committee said this week.

Speaking Jan. 27 at a Potomac Forum ICG Government Conference, Rep. Tom Davis (R-Va.) said Congress and the administration are trying to balance seemingly competing interests: expanding electronic government services and protecting government information systems from misuse or attacks.

FISMA requires agencies to apply risk management techniques to make their computer information systems more secure. Since the law went into effect, many agency officials say they have found risk management to be an unfamiliar discipline and often difficult to apply.

Noting that intruders are continuously looking for vulnerabilities, Davis underscored the importance of complying with FISMA requirements. "We're getting a lot of probes and penetrations into our systems from outside," he said.

Despite criticism and confusion among government employees about the new law, FISMA is good policy, Davis said. The difficulty comes from putting it into practice, he said.

Davis said he appreciates the complaints of federal executives who say they had many too many mandates to juggle, even before FISMA.

Echoing Davis, Anthony McDonald, a senior information technology specialist at the U.S. Geological Survey, remarked that on occasion some managers within USGS have responded to staff members' FISMA efforts with pointed questions of their own, such as: What's the mission of our agency? Is it to do security?

Another challenging aspect of FISMA, Davis said, is that few people on Capitol Hill even know what it is. "On a good day, 10 congressmen could tell you," he said.

A member of Davis's staff said that educating Congress about the need to appropriate money to pay for FISMA activities would be a top priority this year.

In coming months, the House Committee on Government Reform, which Davis chairs, will work to bring contracting procedures in line with FISMA requirements. "You have a lot of things to do when you're overseeing a contract," Davis said. Ensuring that contract items are FISMA-compliant "has got to be something that is second nature," he said.

Featured

  • Defense
    Soldiers from the Old Guard test the second iteration of the Integrated Visual Augmentation System (IVAS) capability set during an exercise at Fort Belvoir, VA in Fall 2019. Photo by Courtney Bacon

    IVAS and the future of defense acquisition

    The Army’s Integrated Visual Augmentation System has been in the works for years, but the potentially multibillion deal could mark a paradigm shift in how the Defense Department buys and leverages technology.

  • Cybersecurity
    Deputy Secretary of Homeland Security Alejandro Mayorkas  (U.S. Coast Guard photo by Petty Officer 3rd Class Lora Ratliff)

    Mayorkas announces cyber 'sprints' on ransomware, ICS, workforce

    The Homeland Security secretary announced a series of focused efforts to address issues around ransomware, critical infrastructure and the agency's workforce that will all be launched in the coming weeks.

Stay Connected