NASA implements policy to suspend C&A in favor of continuous monitoring

Taking the latest information security guidance from OMB to heart, NASA Deputy CIO for Information Security Jerry Davis issued a directive this week to all NASA ISSOs, system owners, authorizing officials, and IT manager and operators…

Federal agencies have a window of opportunity to move on continuous monitoring

The call now seems to coming from all sides that federal government agencies need to fully embrace risk-based approaches to information security and move towards continuous monitoring and enterprise situational awareness. OMB, in coordination with the…

House appetite growing for cybersecurity, FISMA reform

No sooner did the Federal Information Security Amendment (FISA) Act (H.R. 4900) clear the House Oversight and Government Reform Committee’s Subcommittee on Government Management, Organization and Procurement, another cybersecurity bill was introduced and referred to the…

Key government security initiatives making slower than anticipated progress

The Government Accountability Office released two reports, completed in March and released publicly on Monday, that highlight slower-than-expected progress being made on key government-wide information security initiatives. The first report focuses on the Federal Desktop Core…

Federal information security focus shifting to next-generation FISMA, continuous monitoring

While we have seen perennial efforts in Congress to revise or replace the Federal Information Security Management Act (FISMA) and shift government agencies’ security focus off compliance efforts and reporting mountains of paperwork on their information…

New proposed FISMA metrics suggest key technology recommendations

Earlier this month, the National Institute of Standards and Technology issued a request for comments on a draft set of proposed security metrics that OMB is considering using for agencies’ annual reporting as required under the…

Revised SP800-37 not ideal, but an improvement

NIST has released for public comment a revision to its Special Publication 800-37, “Guide for Applying the Risk Management Framework to Federal Information Systems.” This document was formerly the “Guide for the Security Certification and Accreditation…