Big Data. Big Decisions
InformationWeek
Special Coverage Series


10 Steps To Ace A FISMA Audit

Anyone working with a federal agency will face one of these sooner or later. The best way to sail through is to know what auditors are looking for.

The Federal Information Security Management Act, known as FISMA, is typically thought to apply only to government organizations. However, contractors and vendors that provide services to, manage systems on behalf of, or maintain close relationships with a government agency may be held to similar standards.

That can be a problem because FISMA regulations are confusing at best and more commonly just plain overwhelming. Not surprisingly, a cottage industry has sprung up of expensive contractors who promise FISMA help.

Here's what they don't want you to know: Staying on the right side of FISMA auditors is a matter of common sense and solid security best practices. You're probably already doing much of what's required if you're complying with other security requirements, like PCI for payment accounts data security.

What follows are 10 commonsense steps you can take to prepare for a FISMA audit. While basic FISMA compliance won't always meet every government organization's security requirements--for example, you may be required to implement stricter data control requirements or a more involved change control process--you will have a sturdy base to build on.

1. Don't let details overwhelm you.

FISMA's Original Purpose
Provide a comprehensive framework for ensuring the effectiveness of information security controls that support federal operations and assets.
Establish effective government-wide management and oversight of related information security risks, including coordination of civilian information security efforts.
Provide for development and maintenance of minimum controls required to protect federal information and information systems.
Virtual Iron could go head-to-head with VMware in the data center, but it's building its base from below with an easy-to-administer product at a very aggressive price.
Acknowledge that commercially developed information security products offer advanced,dynamic, robust, and effective information security.
Recognize that agencies should be able to select specific hardware and software from among commercial products.
When FISMA was drafted eight years ago, its six tenets were nothing less than groundbreaking (see box, right). Where information security had long been an afterthought in most government agencies, it was brought to the forefront and made a requirement.

While these items are broad, their intent can be distilled: Agencies and their contractors need to build frameworks to address information security and risk management within their organizations. An accountable party must be tasked with information security, so that it won't fall by the wayside. And the government recognized, possibly for the first time, that the private sector has many benefits to offer in terms of protecting public information assets.

FISMA provides a bare-minimum starting point for organizations to build and take responsibility for their information security programs.

2. Protect the data.

Throughout FISMA, there's an emphasis on protecting information rather than systems. Systems and system security are important, of course, but in most cases, it's the data on these systems that has the most value.

Look at the data that's critical to your organization and the agency you work with. Work outward to the systems, segments, and people around that data. This will not only better align you with FISMA, it will give you a more cost-effective, risk-based security program.

3. Accept that some risk is OK.

A 100% clean assessment checklist means the organization being assessed either lied or the assessor missed something, because there is always something to be found. Even the government accepts this as part of FISMA, stating that agencies must implement policies and procedures to "cost-effectively reduce risks to an acceptable level."

There it is in black and white--the U.S. government telling you to be cost prudent, take a risk-based approach, and accept risk when necessary.

What's acceptable will vary from auditor to auditor. Use common sense, and when in doubt, do some research to understand how best-practices frameworks handle the risk. Typically, if you can provide reasonable thought behind a decision and show compensating controls in other areas, auditors will be open to discussing the situation.

4. Appoint someone to own data security.

FISMA requires organizations to appoint someone responsible for information security, with accountability ultimately rolling up to the CIO. Outside the government, many organizations have adopted other management paths for information security. Don't get hung up on the "letter of the law" here: The CIO doesn't need to be the person responsible. What must be in place, though, is a person who has ultimate oversight over information security matters, policies, and risk management and who's free from conflicts that may arise from other responsibilities.

That said, don't go too far down the ladder, either. A single, lowly system or network administrator responsible for security as part of a greater duty set isn't going to pass muster.

5. Implement a written plan and a budget.

Don't make security part of the miscellaneous bucket, where you force admins to rob Peter to pay Paul. This indicates to auditors a lack of planning and foresight. Set a budget, even if it's a small one to start, to show your clients and assessors that you're serious about security.

6. Embrace reporting.

Like many IT pros, I dislike reports. But the fact is, reports can actually save time and very often reduce misunderstandings. Keep in mind that assessors want their reports, and FISMA requires annual reporting for government agencies.

Automation is key here, so invest in software that will save time and money in the long run. Spend the time needed to automate as many reports as you can. Pretty is not key.

Implementing technologies to provide better insight, refine reporting metrics, and reduce workload will go a long way with auditors while increasing the effectiveness of your security program. For example, a security information and event management system such as ArcSight or OSSIM can be invaluable in helping to correlate information from which metrics can be derived and reports built.

7. Note that monitoring is mandatory.

FISMA requires continuous monitoring of certain controls, such as system changes, configuration management, ongoing assessments of security controls, and reporting activities. Monitoring can be costly and overwhelming, so look at what tools you already have and determine if they can be used to meet this requirement. For example, are you logging activity already? Is someone looking at reports periodically, and does the tool support automated alerts? Great--pass security logs through this process. If not, look to automate as much as possible without breaking the bank, such as with the open source OSSIM tool. Also go with a system that can benefit the organization in ways other than just security, such as Splunk for log management.

8. Test controls and be able to prove you did so.

FISMA requires that organizations evaluate the controls they have in place regularly, at least annually. Many companies stumble with this. Testing needs to be thought out. Spend time planning this step to meet these goals:

  • Thoroughly evaluate the controls;
  • Retain evidence of evaluation and findings; and
  • Implement a process to remediate findings.

Keep proper documentation, plan this step before beginning the evaluation, and assign someone ownership of the remediation project--it will make the process much smoother. And to avoid stumbling in this area, employ an audit-tracking system.

9. Follow the leader.

Investigate the controls stressed by the agency that will be assessing your program, and follow its lead. If you have yet to win a contract, search Google for information security policies and requirements for providers at the agency you want to work with. If you can't find anything online, call the office of the CIO and ask for guidance.

10. Still confused? Time for outside help.

Don't be afraid to ask your assessors or clients for recommendations on security products and services. If this isn't possible, bring in a consultant familiar with FISMA to evaluate your plans. A few hours of consulting fees may save you a lot of hassle and cost during the remediation process.

We worked with one information security manager whose company was undergoing a review by a federal agency. He read everything he could and talked to colleagues, but in the end what paid off most was attending an event where federal security practitioners were available for questions. There, he met someone willing to provide pointers and insight into specific control areas free of charge.

When all is said and done, FISMA compliance isn't much different from other standards. Bottom line: Look at a FISMA audit as an impetus to implement better security, provide value to your customers, and do the right thing by those whose data you hold.

Adam Ely is director of security for TiVo.

Write to us at iweekletters@techweb.com.



Related Reading


More Insights




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.

Follow InformationWeek

By The Numbers

What Are Your Primary Concerns About Using Big Data Software?

Base: 417 respondents at organizations using or planning to deploy data analytics, BI or statistical analysis software
Data: InformationWeek 2013 Analytics, Business Intelligence and Information Management Survey of 541 business technology professionals, October 2012

What Do You Think?

What's your attitude about SQL analysis on top of Hadoop?
We want fast, standard SQL analysis capabilities on Hadoop ASAP
Hadoop is for unstructured data; SQL is for relational databases
We'll give SQL on Hadoop a try, but relational DBs will remain the mainstay
Given strong SQL support on Hadoop, we'd nix the data warehouse
We're not interested in Hadoop
No opinion



Related Content

From Our Sponsor

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Business leaders often need a visual snapshot of data to quickly grasp and use it. This paper identifies five challenges in presenting data and how visual analytics can resolve them. Solutions are suggested to overcome the challenges of: speed, data clarity, data quality, displaying meaningful results, and dealing with outliers.

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Today's competitive advantage requires a deeper understanding of your business, your market and your customers. As an IT executive, you can drive that knowledge transformation. In this white paper, learn how to make decisions as a strategic business leader and three steps to begin an analytics initiative within your enterprise.

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

High-performance data visualization turns sophisticated analyses into meaningful graphics, leading to faster and smarter decision making. In this white paper, learn how visual analytics can transform big data, with additional features such as real-time functionality, mobile compatibility, robust applications for technical groups and accessibility for nontechnical users.

Big Data: Lessons from the Leaders

Big Data: Lessons from the Leaders

Financial performance, competitive advantage, operational efficiency, strategic decision making - every business goal can extract value from big data, and the time for doubt or inaction has long passed. In this Economist Intelligence Unit report, in-depth interviews with data pioneers reveal the link between the effective use of big data and the bottom line among other results.

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Which came first, the data or the decision? This white paper makes the case for having a decision in mind, then tailoring big data's volume, variety and velocity to achieve business results such as overcoming customer dissatisfaction or creating well-informed strategies in real time.

Informationweek Reports

Research: The Big Data Management Challenge

Research: The Big Data Management Challenge

The challenge of big data is real, but most organizations don't differentiate 'big data' from traditional data, and nearly 90% of respondents to our survey use conventional databases as the primary means of handling data. We'll help you understand what constitutes big data (it's not just size) and the numerous management challenges it poses.