Commentary
Senate Committee Approves Updated FISMA Bill
The Senate Homeland Security and Government Affairs Committee just approved S.3474, which will update the Federal Information Security Management Act (FISMA), in the hope of lifting federal security efforts beyond what many have deemed a paperwork shuffle that does little to boost security.The Senate Homeland Security and Government Affairs Committee just approved S.3474, which will update the Federal Information Security Management Act (FISMA), in the hope of lifting federal security efforts beyond what many have deemed a paperwork shuffle that does little to boost security.The Federal Information Security Management Act of 2008 could be the biggest overhaul to the act, which aims to strengthen federal security, since its 2002 inception.
Here are some highlights I gleaned from the bill:
More Security Insights
White Papers
- Mobile BI: Actionable Intelligence for the Agile Enterprise
- How To Regain IT Control In An Increasingly Mobile World - by BlackBerry
Reports
More >>Webcasts
- Outsourcing Security: What Every Potential Cloud Security Customer Should Know
- Maximize ROI with Database Consolidation onto Private Clouds
Audits: The current round of "evaluations" will be replaced by more, presumably, stringent audits.
CISOs: Each federal agency will need to designate a Chief Information Security Officer who will report directly to the Chief Information Officer. These CISOs will, according to the bill in its current form, not only be charged with providing security, but have the authority to do so. From the bill:
The Chief Information Security Officer of an agency shall be responsible for and have the authority to assure that any information system connected to the network (directly or indirectly) that does not comply with security policies and standards, or has been compromised, is denied access and use of the agency network until the information system meets or exceeds accepted security policies and standards.
Establish a CISO Council: The council members will exchange their real-world experiences and work together to promote the development and use of standard performance measures for the agencies.
Costing: The bill also requires agencies to develop cost estimates and bi-annual implementation progress reports to Congress,
Because the bill must now pass the Senate, there's little sense in discussing the minutia until it's passed in its final form. So far, adding accountability, designating CISOs, and giving them a reasonable amount of authority looks like a good step forward to me.
Related Reading
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. | |
|
|
T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting! |
Subscribe to RSSResource Links
This Week's Issue
Technology Whitepapers
- Creating the Enterprise-Class Tablet Environment - by Yankee Group
- How To Regain IT Control In An Increasingly Mobile World - by BlackBerry
- The BlackBerry PlayBook tablet's Good Bones - by BlackBerry
- Red Alert: Why Tablet Security Matters - by BlackBerry
- New Visual and Wizard-Driven Paradigms for Exploring Data and Developing Analytic Workflows
Featured Resource
This is your portal to all the news, product information, technical data, and other information related to the topic of computer user authentication and certification. Visit us to find out how to ensure that computer users are who they say they are.
Learn More












