Archive - Balancing Security and ComplianceSubscribe Information Assurance RevolutionTransitioning from DITSCAP to DIACAP will provide CIOs an enterprise view of DoD systems and a better method for meeting FISMA requirements. But will this new process achieve greater systems security for DoD? Federal IT Security Mandates: Help or Hindrance?CIOs interviewed in annual survey question whether the burdens of compliance outweigh the return on their IT investments. Grading On a CurveDavid Raikow of GovernmentVAR reports that security assessments are complex and tricky -- and trying to boil them down to widely applicable standards, benchmarks, and certifications is even trickier. FISMA: Paperwork Or Actual SecurityOf the many blogs discussing federal security compliance, few can compare -- statistically speaking -- to the content presented by this blogger. Federal Security Leaders Speak Out on Top Issues
In this radio interview, Ron Ross, FISMA Implementation Project Leader, National Institute for Standards and Technology, says that while attacks on government systems persist, defenses are improving by the day. Latest in Cybersecurity AwarenessFISMA's cybersecurity awareness training requirements are prompting agencies to develop new tools such as the Department of Defense's CyberCIEGE, a highly interactive commercial-quality video game. |
Featured ContentData Security: Preparing for the Age of the ZettabyteIn dealing with the explosion of the digital universe, organizations need to spearhead the development of organization-wide policies for information governance: information security, information retention, data access, and compliance. How to Prepare for a FISMA Audit![]() So what lessons have been learned in six years of FISMA Audits that are critical to business CIOs and CISOs? Evaluate publicly available data on FISMA assessments. > Evaluate ISO, ITIL and COBIT Triple Play Fosters Optimal SecurityOne industry analyst group examines how the profile of an organization that uses multiple IT frameworks differs from that of an organization that implements just one set of process controls, or none at all. 2008 GAO Report to CongressThis GAO testimony summarizes agency progress, effectiveness, and opportunities to strengthen federal security. > Read Full Report Events |