The UNIX and Linux Forums  


Go Back   The UNIX and Linux Forums > Special Forums > Security > IT Security RSS
.
google unix.com



More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Delimiters missing Indalecio Shell Programming and Scripting 2 02-23-2007 04:28 AM
missing CDE frankkahle SUN Solaris 5 05-25-2006 06:35 PM
what am I missing? Zelp Shell Programming and Scripting 4 06-13-2005 06:32 PM
/tmp is missing ???? BAM UNIX for Dummies Questions & Answers 1 11-05-2002 02:50 PM
/dev/fb* missing heinb UNIX for Dummies Questions & Answers 5 02-12-2002 05:22 AM

 
English Japanese Spanish French German Portuguese Italian Dutch Swedish Russian Norwegian Hungarian Hebrew Danish Bulgarian Greek Powered by Powered by Google
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Prev Previous Post   Next Post Next
  #1 (permalink)  
Old 05-30-2008
iBot's Avatar
iBot iBot is offline
Forum Robot Girl
  
 

Join Date: Sep 2000
Posts: 22,260
FISMA – Is Something Missing?

Since its inception into law, the Federal Information Security Management Act of 2002 (FISMA) has faced many challenges, both through establishing itself in the federal landscape, and developing the necessary framework for applying the principles into practice. Although FISMA has been in existence for 5-years, many would say that security has only shown limited improvement, while others would stand by its success.
Those familiar with FISMA have experienced the uncertainty of the initial implementations, and identified with some key improvements brought about through the increased visibility of security. FISMA has now made security a mandated priority, whereas, prior to its enactment security was only given limited attention. The work performed by the National Institute of Standards and Technology (NIST) has been instrumental in taking a legislative mandate, and through multiple attempts, refine processes and practices that have taken shape across the federal government. However, there is still a great deal of work to be done to provide the assurance needed for federal agencies and contractors hosting federal information and information systems to sustain a measurable security posture that can be monitored more effectively and efficiently.
I would not consider FISMA in itself to be a failure, but instead believe the major weaknesses that exist are tied to the lack of a baseline set of measurements that can be used to show measurable improvements. According to the Office of Management and Budget (OMB) 2009 IT Budget Summaries, IT security spending could see an effective increase of at least 10.3 percent from the actual 2008 budget, which would mean agencies need to have better parameters for demonstrating where failures exist when a D or F rating is given on the Computer Security Report Card.
IT security is not an exact science because not all environmental characteristics that affect security can be completely relieved of risk. Management of the risk requires proven measurements to demonsrate security can be adequately managed, if properly planned and implemented. This could also help to provide assurance to senior leaders within these federal government, that if funding was properly allocated to support IT security requirements, there is some direct relationship to meeting security goals. Without a platform to capture these performance measurements, security will only be an increasing spiral of cost with no tie-back to a return-on-investment.


More...
 

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 06:17 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited. Language Translations Powered by .
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2009. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0