learn unix and linux commands

FISMA – Is Something Missing?


 
Thread Tools Search this Thread
# 1  
Old 05-30-2008
FISMA – Is Something Missing?

Since its inception into law, the Federal Information Security Management Act of 2002 (FISMA) has faced many challenges, both through establishing itself in the federal landscape, and developing the necessary framework for applying the principles into practice. Although FISMA has been in existence for 5-years, many would say that security has only shown limited improvement, while others would stand by its success.
Those familiar with FISMA have experienced the uncertainty of the initial implementations, and identified with some key improvements brought about through the increased visibility of security. FISMA has now made security a mandated priority, whereas, prior to its enactment security was only given limited attention. The work performed by the National Institute of Standards and Technology (NIST) has been instrumental in taking a legislative mandate, and through multiple attempts, refine processes and practices that have taken shape across the federal government. However, there is still a great deal of work to be done to provide the assurance needed for federal agencies and contractors hosting federal information and information systems to sustain a measurable security posture that can be monitored more effectively and efficiently.
I would not consider FISMA in itself to be a failure, but instead believe the major weaknesses that exist are tied to the lack of a baseline set of measurements that can be used to show measurable improvements. According to the Office of Management and Budget (OMB) 2009 IT Budget Summaries, IT security spending could see an effective increase of at least 10.3 percent from the actual 2008 budget, which would mean agencies need to have better parameters for demonstrating where failures exist when a D or F rating is given on the Computer Security Report Card.
IT security is not an exact science because not all environmental characteristics that affect security can be completely relieved of risk. Management of the risk requires proven measurements to demonsrate security can be adequately managed, if properly planned and implemented. This could also help to provide assurance to senior leaders within these federal government, that if funding was properly allocated to support IT security requirements, there is some direct relationship to meeting security goals. Without a platform to capture these performance measurements, security will only be an increasing spiral of cost with no tie-back to a return-on-investment.


More...
Login or Register to Ask a Question

Previous Thread | Next Thread

7 More Discussions You Might Find Interesting

1. Red Hat

Yum - resolving missing dependencies that are not missing

I am trying to install VirtualBox on RHEL 5 but I need the 32 bit version for 32 bit Windows. When I run yum I get the following: sudo yum localinstall /auto/spvtg-it/spvss-migration/Software/VirtualBox-4.3-4.3.2_90405_el6-1.i686.rpm Loaded plugins: fastestmirror Setting up Local Package... (13 Replies)
Discussion started by: gw1500se
13 Replies

2. SuSE

How to resolve missing missing dependencies with opensuse 11.3 and 12.3?

Hello, This is a programming question as well as a suse question, so let me know if you think I should post this in programming. I have an application that I compiled under opensuse 12.2 using g77-3.3/g++3.3. The program compiles and runs just fine. I gave the application to a colleague who... (2 Replies)
Discussion started by: LMHmedchem
2 Replies

3. Shell Programming and Scripting

[: missing `]'

Hi, I am getting this error while running the following code. i=`awk '{print $2}' test1.txt` j=`awk '{print $4}' test1.txt` k=`awk '{print $6}' test1.txt` if ; then echo "Up." else echo "down" fi rm -f test.txt test1.txt error is this: line 12: ' Please suggest. (2 Replies)
Discussion started by: arijitsaha
2 Replies

4. Shell Programming and Scripting

Error : [: missing `]'

Hi, I am attempting to test the input value for an integer. And if the value is not an integer, the intent is to complain about it and exit. Only if I can get past the syntax error, life will be full. # test input to be a number +$'; ] && { echo "Invalid input; Enter an integer..."; exit 2; }... (7 Replies)
Discussion started by: IETF
7 Replies

5. Linux

missing in script

Hi , I am trying to make this change work in my script but its not working.The idea is to grep for "CREATE VIEW" and then change view name from orig to VW_orig. but the problem comes when there is no schema prefix to the view name . the code I am using is #!/bin/ksh... (5 Replies)
Discussion started by: capri_drm
5 Replies

6. UNIX for Dummies Questions & Answers

missing scrollbar

Hi, My tcsh window doesn't have a scrollbar, so I don't get a lot of history! Can you help to get scrollbar? Thanks (3 Replies)
Discussion started by: parisa_3456
3 Replies

7. Shell Programming and Scripting

what am I missing?

I have the following portion of a script Check() { echo "\n\nChecking that all constraints are Enabled" echo "..." sleep 2 CHECK_COUNT='sqlplus -s $1 <<-EOSQL4 set feed off pause off pages 0 head off; set linesize 150 echo off; select count(*) from user_constraints where... (4 Replies)
Discussion started by: Zelp
4 Replies
Login or Register to Ask a Question