New CyberScope is another step in the right direction on federal security

This month the federal government launched a new online FISMA reporting application, CyberScope, based on the Justice Department’s Cyber Security Assessment and Management (CSAM) system, which was already offering FISMA reporting services to other agencies through…

Security issues at NASA highlight challenges in control effectiveness

A report released this month by GAO on what it views as deficiencies in the information security program and security control effectiveness at the National Aeronautics and Space Administration (NASA) serves to highlight once again the…

Initial observations on Revision 3 of SP800-53

NIST last week released the final version of Revision 3 of its Special Publication 800-53, “Recommended Security Controls for Federal Information Systems and Organizations.” This update has a number of really interesting characteristics, beyond the simple…

No point in asking private entities to comply with FISMA

In what has become a consistent theme out of the Office of the National Coordinator for Health IT, it seems the idea is still under consideration to try to require private-sector organizations to comply with the…

FISMA still being touted as best security for health information exchange

Coming out of the recent CONNECT User Training Seminar held this week in Washington, DC is a reiteration of the opinion previous expressed by federal stakeholders working on the Nationwide Health Information Network (NHIN) that non-federal…

NIST finalizing standard government-wide security controls

After more than two years of collaboration among civilian, defense, and intelligence agencies, the National Institute of Standards and Technology’s Information Technology Laboratory has released the final public draft of revision 3 of its Special Publication…

FISMA provides insufficient foundation for trust

There seems to be an inordinate amount of attention on FISMA in the ongoing debate about how to establish a sufficient trust framework among public and private sector participants in health information exchange. Federal government security…