Nothing easy about security

Information security experts offer no easy answers for agencies trying to improve their security grades.

The maze of requirements imposed by the Federal Information Security Management Act (FISMA) of 2002 has created confusion about interpretation, said Les Cashwell, a security analyst and chief executive officer of Cashwell & Associates, a consulting company. "It's not perfect legislation, but at least it's something," Cashwell said, speaking today in Arlington, Va., at a seminar sponsored by e-Security Inc.

With tongue in cheek, Cashwell offered a graphic depiction of FISMA as a beast with long, sharp teeth and many eyes. Besides doing good, Cashwell said, FISMA created "a lot of bureaucracy and paperwork." Deciding how much detailed security information to report to senior managers is "a huge challenge," he said.

Addressing agency officials who wanted to know how to improve their FISMA grades, security analysts at the seminar urged federal managers to adopt a consistent approach to certifying and accrediting their information systems as required under FISMA. A consistent approach has proved difficult for many federal agencies struggling with how large or small to define a "system," Cashwell said.

Analyst Michael Rasmussen, director of research at Forrester Research Inc., said FISMA and other security requirements may soon create a need for organizations to hire chief operational risk officers. Some organizations already have hired officers to coordinate the physical, legal, personnel, information and information-systems dimensions of security, Rasmussen said. It is a practice, he predicted, that would be common in five years.

Rasmussen advised agencies to focus on creating "good enough" security to meet FISMA requirements. "We don't need to build a Fort Knox," he said.

Featured

  • Defense
    Ryan D. McCarthy being sworn in as Army Secretary Oct. 10, 2019. (Photo credit: Sgt. Dana Clarke/U.S. Army)

    Army wants to spend nearly $1B on cloud, data by 2025

    Army Secretary Ryan McCarthy said lack of funding or a potential delay in the JEDI cloud bid "strikes to the heart of our concern."

  • Congress
    Rep. Jim Langevin (D-R.I.) at the Hack the Capitol conference Sept. 20, 2018

    Jim Langevin's view from the Hill

    As chairman of of the Intelligence and Emerging Threats and Capabilities subcommittee of the House Armed Services Committe and a member of the House Homeland Security Committee, Rhode Island Democrat Jim Langevin is one of the most influential voices on cybersecurity in Congress.

Stay Connected

FCW INSIDER

Sign up for our newsletter.

I agree to this site's Privacy Policy.