<A HREF="http://as.cmpnet.com/event.ng/Type=click&FlightID=130099&AdID=209259&TargetID=2556&Segments=91,115,350,2549,2690,2943,3108,3448,8877,9991,100 60,13943,13985,14402,14497,14750&Targets=39,315,302,2164,2556,2625,2878,6529,10068,10537,10640&Values=34,46,51,63,77,87,91,102,140,203,222,227,279, 382,442,657,940,1311,1716,1767,1785,1925,1970,2299,2310,2327,2352,2678,2767,2862,2878,2942,3890,3904,4080,6236,6293,6325,6352,6389,6391,6392,6393,6 422,6440,6541,6567,6580&RawValues=&Redirect=http://www.apc.com/promo/get.cfm?keycode=e896w" target="_top"><IMG SRC="http://i.cmpnet.com/ads/graphics/as5/kls/apc/ee_LEAD_a.gif" WIDTH=728 HEIGHT=90 BORDER=0></A>
home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek 

Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers

Regulatory Resource   Threat Intelligence      Resilient IT      Boardroom Strategies      
Regulatory Resource / Sectors

NIST Publications Offer FISMA Compliance Guidance

By Stacey McDaniel

The federal government has become increasingly reliant on technology and the Internet for its operations; as a result, maintaining a secure cyberspace has become essential to our homeland and national security. Recognizing this, the government has taken some important steps to address the need for stronger information security practices within the government and its associated organizations. Two examples can be seen in the Federal Information Security Management Act (FISMA) security requirements, and the increased number of National Institute of Standards and Technology (NIST) publications addressing best security practices.

FISMA sets requirements

FISMA requires every federal agency, as well as any organization whose information systems possess or make use of federal information, to develop, document, and implement an agency-wide risk-based information security program. Additionally, FISMA requires periodic testing and evaluation of the effectiveness of the information security policies, procedures, and practices that are in place. While FISMA lays out the required elements of the security program, it doesn't set any security benchmarks, or provide much in the way of guidance on how to achieve these requirements. That's where NIST comes in.

NIST provides guidance

NIST is a non-regulatory federal agency within the U.S. Commerce Department's Technology Administration. For more than two decades, it has produced a number of publications that provide computer security guidance for federal agencies. NIST has always taken the evolving nature of technology and new vulnerabilities into account to provide timely advice, and now FISMA has called upon it to step up and establish some important standards and practices for government security.

Official publications

FISMA has tasked NIST with developing a series of official publications relating to information system security standards and guidelines that provide the following:

  • Standards to be used by federal agencies to categorize all information and information systems collected or maintained by, or on behalf of, each agency based on the objectives of providing appropriate levels of information security according to a range of risk levels;

  • Guidelines for the types of information and information systems to be included in each category; and

  • Minimum information security requirements (i.e., management, operational, and technical controls), for information and information systems in each category.

Publications to address FISMA

"Security Considerations in the Information Systems Development Life Cycle" was the first set of NIST guidelines mandated under FISMA. This publication outlines ways to link different types of federal information and systems, and then assign levels to the risks each faces. It also defines three security areas for information and systems (confidentiality, integrity, and availability), and then identifies three levels of potential impact on organizations or individuals if any of those security areas are compromised.

Another publication developed in accordance with FISMA is "Standards for the Security Categorization of Federal Information and Information Systems." It sets security categorization standards; standards and guidelines for the specification, selection, and testing of security controls for information systems; and guidelines for the certification review and accreditation of information systems.

In January 2004, NIST published "Computer Security Incident Handling Guide." This guide is intended to help both established and newly formed incident response teams respond effectively and efficiently to a variety of incidents. More specifically, it discusses organizing a computer security incident response capability, establishing incident response policies and procedures, structuring an incident response team, and handling incidents -- from initial preparation through the post-incident "lessons learned" phase. And, as the title suggests, it discusses handling a variety of incidents, such as denial of service, unauthorized access, malicious code, and inappropriate usage. Readers will also find the guide has such helpful resources as security checklists and FAQs. Many computer security experts have lauded NIST's Incident Handling Guide as a comprehensive "must read" document for every information security professional, whether in the public or private sector.

Other NIST guidelines released in 2004 include "Recommendation for Electronic Authentication," "Engineering Principles for Information Technology Security (A Baseline for Achieving Security),"and "Mapping Types of Information and Information Systems to Security Categories."

As the world's largest consumer of information technology, the federal government has finally made securing that technology an important issue. The NIST publications will play a critical role as federal agencies determine the level of security needed for their information systems in order to be FISMA-compliant. NIST breaks down the security standards and required measures into understandable and manageable terms -- it is up to IT managers in the government to consult these important publications as they work on building an effective security program.

Stacey McDaniel has been writing about high-tech issues for more than six years.

 

IT Strategy Center is a daily editorial resource offering innovative insights and strategies for building an integrated, secure and resilient IT infrastructure.

Articles by Topic
Sectors
Law
Tactics
Related Content
Fast Fact

"Maintaining a secure cyberspace has become essential to our homeland and national security."

Sponsor Tools
Podcast Audio Content

CIO Strategy Center is now available in audio format.

This week's feature topic is:


Risks of Wireless Email
Playtime: 8 min 23 sec



Download | Subscribe



Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR

RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.





Internet Evolution









<A HREF="http://as.cmpnet.com/event.ng/Type=click&FlightID=132180&AdID=212017&TargetID=347&Segments=92,118,335,351,3108,3448,8879,10297,13986,14405,14 496&Targets=40,347,2625,2878,6527,10071,10470&Values=34,46,51,63,77,87,90,102,140,205,222,227,279,382,442,657,940,1431,1716,1767,1785,1925,1945,197 0,2256,2299,2310,2313,2327,2352,2678,2862,2878,3712,3714,3890,3904,4079,6236,6293,6325,6352,6389,6393,6422,6440,6489,6541,6567&RawValues=&Redirect= http://www.informationagenda.techweb.com/?cid=webtile_ms_bi" target="_top"><IMG SRC="http://i.cmpnet.com/ads/graphics/as5/gml/IBM/Leveraging_infoagenda/tile.gif" WIDTH=125 HEIGHT=125 BORDER=0></A>

What's Hot at NWC
Editor's Picks
Network Computing Reports
 


Advertisement
<A HREF="http://as.cmpnet.com/event.ng/Type=click&FlightID=130106&AdID=209266&TargetID=294&Segments=94,117,334,353,2567,2692,3108,3448,4080,10296,1398 8,14467,14495&Targets=322,294,298,2625,2878,3348,10067,10535,10641&Values=34,46,51,63,77,87,90,102,140,206,222,227,279,382,442,657,940,1431,1716,17 67,1785,1925,1945,1970,2256,2299,2310,2313,2327,2352,2678,2862,2878,3712,3714,3890,3904,4079,6236,6293,6325,6352,6389,6393,6422,6440,6489,6541,6567 &RawValues=&Redirect=http://www.apc.com/promo/get.cfm?keycode=e897w" target="_top"><IMG SRC="http://i.cmpnet.com/ads/graphics/as5/kls/apc/ee_SKY_c.gif" WIDTH=160 HEIGHT=600 BORDER=0></A>


Microsite of the Week

< Advertisement >

Powerful Information at Your Fingertips

 










<A HREF="http://as.cmpnet.com/event.ng/Type=click&FlightID=130079&AdID=209235&TargetID=42&Segments=93,116,352,2689,3108,3448,8547,9985,13942,13987,144 93&Targets=42,321,2625,2878,10069,10556&Values=34,46,51,63,77,87,91,102,140,204,222,227,279,442,657,1311,1716,1767,1785,1798,1925,1970,2299,2310,23 13,2327,2352,2678,2767,2862,2878,2942,3712,3714,3890,3904,4079,6236,6293,6325,6356,6359,6389,6391,6392,6393,6422,6440,6541,6567,6580,6643&RawValues =&Redirect=http://www.apc.com/promo/get.cfm?keycode=e901w" target="_top"><IMG SRC="http://i.cmpnet.com/ads/graphics/as5/kls/apc/isx_LEAD_a.gif" WIDTH=728 HEIGHT=90 BORDER=0></A>

InformationWeek Business Technology 

Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo JitterPlug Into The Cloud
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business 

ExpoSoftware ConferenceCSI - Computer Security Institute
Black 

HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight 

Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower 

Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space


Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights