Tuesday, June 3, 2008

Extracting my foot from my mouth

Apparently I spoke a little too soon.

There IS a forum for federal security managers to attend on a regular basis. Here is the link:

http://csrc.nist.gov/groups/SMA/forum/index.html

I have not attended, I simply found it while looking for something else. If you can attest to its content or organizational qualities, I (among others) would find it of interest.

Monday, June 2, 2008

FISMA is about Risk Management

I feel inclined to talk about something that the Guerrilla CISO discussed earlier.

I found this post at ISC2 annoying in that it is the same in a long line of "look at all these problems with FISMA" writings. We get it, its new (relatively, for the government) and there are problems.

But just like all the other posts, no solutions are offered. I don't have all the answers either, but now, I will be more aware of when I am spewing and when I am trying to be helpful.

So, let's go there. The reporting and measurement of system risks is nebulous, at best. Specific training for Accrediting Authorities (AA) and their delegates would be the first thing to do. The topics would look something like:
  • Introduction to Risk Management
    • What is Risk?
    • How do I know my risks?
  • How to conduct a Risk Assessment
    • What are threats?
    • What are vulnerabilities?
    • Determining likelihood
    • Determining impact
    • Generate Risk
  • Risk Management (MEAT, I just made up this acronym)
    • Mitigation (Compensating or additional controls)
    • Elimination (Remediate underlying vulnerabilities)
    • Acceptance (Justification for Operational Necessity)
    • Transfer (Delegate up or down, buy insurance)
  • Balancing Success and Usability with Security and Assurance
    • Or How not to add too many countermeasures and controls to make the system costly to run.
  • Measurement and Reporting of Residual Risk
I find that second last one to be the general issue and the root of many of breaches. Either the system has no budget so the AA has to except risks they may or may not be comfortable with. Or the system has too much budget and the Security Architect goes overboard. Lastly, not all risks are discovered at the time of accreditation and no new risk assessments are conducted.

So once all that is done, it must be uniformly applied (directly to the forehead, haha). More simply quarterly or semi-annual summits/counsels/conferences with the AAs with case studies, panels and open forums to discuss emerging threats, emerging countermeasures, what risks should be accepted, etc. Keeping it as simple and high level as possible, given that some of the AAs have little to no IT background.

This may already be happening and I am not aware of it. Please let me know if it is or isn't or anything you would want to see as possible solutions. It would be up to NIST or OMB to institute something like this, since FISMA gives them that authority. Or I accept Cash, Check, Wire Transfer, Money Orders and Google Checkout.

Sunday, June 1, 2008

Guitar Gods

Eric Clapton - Layla




Welcome to my feeble attempt at maintaining content.

Thursday, May 29, 2008

FISMA Report Card

I know that I am late on this one, but I have been busy. Just for a brief moment let's consider the point of these report cards and from where they come.

My personal feeling is that the report card means nothing and says even less. They apply an arbitrary metric to an ambiguous reporting mechanism. Any agency could have the best, most secure systems. If they don't report on it correctly, they can still fail. This also means that if the people performing the reporting are not trained correctly they can fail. Lastly, those who know how to report can pass without necessarily having secure systems.

Someone told me recently that the intent of this is to: a) make Congress feel good about doing something productive and b) inspire agency competition for success.

Sorry I am so negative on this, but again there is an "end of project requirements mismatch discovery". OMB, NIST and others recognize that good information systems security comes from well written policy and superior risk management. When others will tell try to sell IDPS, firewalls and log management platforms as solutions to your FISMA problems.

This report card reinforces an over simplified view of how easy/hard it is to secure an enterprise.

Friday, May 9, 2008

A New Draft of the Same Thing with Thoughts on Outsourcing

The 800-123 Guide to General Server Security came out this week, and really who needed this. I am sure this would have been helpful in 1995, when people had just started putting servers on the Internet. But who is seriously going to sit down with this and say "I hadn't thought of that!"

What I think we need now in the age of government *sourcing is some NIST guidance around Cloud, Managed and Virtualized systems.

My personal belief is that vendors are trying to get management/operation of government systems out of the government's hands so that there isn't as much bureaucracy.

Here is the thing, it is still the government's data. The system still must be certified.

To the Honorable Karen Evans: Please issue a memo stating unequivocally that: outsourced, managed, clouded virtualized, SaaS, shared whatevers need controls implemented to the same level that they would be if the government had built it themselves.

Quoteth the FISMA 3544(a)(1):
"(A) providing information security protections commensurate with the risk and magnitude of the harm resulting from unauthorized access, use, disclosure, disruption, modification, or destruction of—
"(i) information collected or maintained by or on behalf of the agency; and
"(ii) information systems used or operated by an agency or by a contractor of an agency or other organization on behalf of an agency;
So for those of you out there who keep saying "Chris, it isn't in the agency's physical boundary". Stop it. You know who you are.

More on this later (I keep saying this, but will it ever happen?).