Security guidelines need a makeover

Say what you mean! If my experience can be extrapolated to the larger community of security professionals, then I would say the connotations of words and lack of clear thinking are large impediments to attacking security issues.

What is risk? What is risk management? Is it different from secure systems management? What are the elements of risk? What is security? What is assurance?

These are a few questions that arise from a comparative reading of the Defense Information Technology Security Certification and Accreditation Process, Defense Information Assurance Certification and Accreditation Process, Director of Central Intelligence Directive 6/3 and National Institute of Standards and Technology Special Publication 800-37.

It seems likely that the first three of those documents would be as useful as the NIST document if the authors were clearer thinkers and better writers. Fundamental policy and procedure documents need careful, thoughtful and skilled authors so that the users of those documents have clear directions.

Anonymous
SAIC

Featured

  • Cybersecurity
    Shutterstock photo id 669226093 By Gorodenkoff

    The disinformation game

    The federal government is poised to bring new tools and strategies to bear in the fight against foreign-backed online disinformation campaigns, but how and when they choose to act could have ramifications on the U.S. political ecosystem.

  • FCW PERSPECTIVES
    sensor network (agsandrew/Shutterstock.com)

    Are agencies really ready for EIS?

    The telecom contract has the potential to reinvent IT infrastructure, but finding the bandwidth to take full advantage could prove difficult.

  • People
    Dave Powner, GAO

    Dave Powner audits the state of federal IT

    The GAO director of information technology issues is leaving government after 16 years. On his way out the door, Dave Powner details how far govtech has come in the past two decades and flags the most critical issues he sees facing federal IT leaders.

Stay Connected

FCW Update

Sign up for our newsletter.

I agree to this site's Privacy Policy.