GCN Home > 05/22/06 issue
FISMA from the inside out
Roundtable focuses on the details of improving security
By Brad Grimes, GCN Staff
Back in March, it happened again. The House Government Reform Committee issued its annual security report card per the Federal Information Security Management Act. And for the fifth straight year, the government as a whole earned the kind of mark that might get a school-age kid grounded [GCN.com, Quickfind 583].

But lost in the consternation over feds cumulative D+ is the fact that some agencies actually pulled up that average. What are the Agency for International Development, Environmental Protection Agency, Labor Department, Office of Personnel Management and Social Security Administrationall A+ recipientsdoing right in securing their systems?

In late April, federal officials convened at GCNs offices in Washington to discuss the role of FISMA and what agencies need to do to improve their grades.

Around the table were Karen Evans, administrator of e-government and IT for the Office of Management and Budget; Glen Schlarman, OMBs chief of the information policy and technology branch; Victoria Proctor, a professional staff member for the House Government Reform Committee; Ron Ross, a senior computer scientist and information security researcher at the National Institute of Standards and Technologys FISMA implementation project; and Phil Heneghan, chief information security officer at AID.

Offering industrys perspective were Terri Allen, a senior vice president at Cloakware Corp. of Vienna, Va., and Dave Steidle, director of product management at netForensics Inc. of Edison, N.J.

The discussion was wide-ranging, but frequently came back to management issues. In short, participants agreed, for security (and FISMA grades) to improve, business leaders within each agencynot technologistsmust understand whats at stake and drive security efforts.

As Evans put it, The real motivating factor is not ending up on the front page of the Washington Post.

Ultimately, there may be better days ahead for FISMA. As Ross pointed out, NIST has only just finished all the guidance mandated by the act.

More news on related topics: IT Security, FISMA, Management, IT Management