Security guidelines need a makeover

Say what you mean! If my experience can be extrapolated to the larger community of security professionals, then I would say the connotations of words and lack of clear thinking are large impediments to attacking security issues.

What is risk? What is risk management? Is it different from secure systems management? What are the elements of risk? What is security? What is assurance?

These are a few questions that arise from a comparative reading of the Defense Information Technology Security Certification and Accreditation Process, Defense Information Assurance Certification and Accreditation Process, Director of Central Intelligence Directive 6/3 and National Institute of Standards and Technology Special Publication 800-37.

It seems likely that the first three of those documents would be as useful as the NIST document if the authors were clearer thinkers and better writers. Fundamental policy and procedure documents need careful, thoughtful and skilled authors so that the users of those documents have clear directions.

Anonymous
SAIC

Featured

  • Cybersecurity

    DHS floats 'collective defense' model for cybersecurity

    Homeland Security Secretary Kirstjen Nielsen wants her department to have a more direct role in defending the private sector and critical infrastructure entities from cyberthreats.

  • Defense
    Defense Secretary James Mattis testifies at an April 12 hearing of the House Armed Services Committee.

    Mattis: Cloud deal not tailored for Amazon

    On Capitol Hill, Defense Secretary Jim Mattis sought to quell "rumors" that the Pentagon's planned single-award cloud acquisition was designed with Amazon Web Services in mind.

  • Census
    shutterstock image

    2020 Census to include citizenship question

    The Department of Commerce is breaking with recent practice and restoring a question about respondent citizenship last used in 1950, despite being urged not to by former Census directors and outside experts.

Stay Connected

FCW Update

Sign up for our newsletter.

I agree to this site's Privacy Policy.