Tech Blog
FISMA: The GCN Roundtable
A couple weeks ago, GCN convened a roundtable of government officials in our Washington headquarters to talk about what a lot of folks have been talking about lately: the Federal Information Security Management Act. Specifically, theyve been talking about what it means that the U.S. government seems to score so poorly on the FISMA report card, issued annually by the House Government Reform Committee.
We werent so interested in re-hashing the strengths or weaknesses of the act itself (although with a staffer from Congressman Tom Davis committee at the table, we spent a little time on the legislation). What we really wanted to get at was how agencies could improve their security in general, and thereby boost their high-profile FISMA grades.
Around the table were Karen Evans, administrator of e-government and IT for the Office of Management and Budget; Glen Schlarman, chief of the information policy and technology branch at OMB; Victoria Proctor, of the House Government Reform Committee; Ron Ross, from the FISMA implementation project at NIST; and Phil Heneghan, chief information security officer at the Agency for International Development (recipient of two straight A+ grades on the FISMA report card).
We also invited a couple executives from the security industry to get their perspectives: Terri Allen, a senior VP at Vienna, Va.-based Cloakware; and Dave Steidle, director of product management at Edison, N.J.-based netForensics Inc.
The conversation was lively and wide-ranging. Look for an in-depth article about the roundtable in the May 22 issue of Government Computer News. For now, heres a sampling of what we discussed:
Ron Ross, on criticisms leveled at FISMA: The legislation is broad, its sweeping, it is changing the culture across the entire federal government, and I think we dont have a lot of patience sometimes. Were only three years in, and were just now completing the standards and guidelines.
Karen Evans, on whether FISMA compliance is more about security tools or policies: A fool with a tool is still a fool. Its not about the tools. Its really about understanding what youre managing.
Phil Heneghan, on how USAID handles remote laptop users: We scan every box every three days. People found out that when they plugged it in, theyd get scanned and wed send grades to the mission directors. After one month of that, mission directors now enforce the rule of no laptop gets plugged in until after the sys admin people have patched it.
Victoria Proctor, on why some agencies score well and others dont: To a large extent, an agency like the Social Security Administration and the Labor Department have done quite well [with FISMA] because they deal with information on a regular basis. They know that if any information gets into the wrong hand, they failed in their mission.
What you wont read in the May 22 article is Terri Allens take on future security issues. Frankly, we just dont have the room for all the good points our panelists made. Allen was a senior VP at GTSI Corp. before joining Cloakware, so she has experience in the federal space.
We think that identity management from an user perspective is good, Allen said. Were focusing on an area of unmet need, which is the unattended server farms out there. In many cases youve got hard-coded passwords and not many people managing that piece of business. So were talking to customers about unattended server farms and unattended applications and making sure were securing those applications with a trusted solution.
Bottom line: FISMA is about managing risk and putting in place disciplined processes so an agency can adapt to a changing security landscape. We hope you come away from the conversation with something that helps improve your agencys security posture.
Posted by Brad Grimes
| Post a Comment
If you are currently registered, click here to login and post your comment. If you are new to GCN, click here to register and post your comment. |




