FITSP-M. Lab Activity Guide

Size: px
Start display at page:

Download "FITSP-M. Lab Activity Guide"

Transcription

1 These lab exercises will walk you through the steps of the Risk Management Framework (RMF), with an activity for each step. FITSP-M Lab Activity Guide

2 Table of Contents Introduction... 3 Documentation... 3 Lab Activity 1: Searching for Guidance... 4 Lab Activity 2: Categorizing Information Systems... 5 Information System: HGA LAN, Washington, DC... 5 Information System: Public Access Directory... 5 Lab Activity 3: Selecting Security Controls Selection... 6 Lab Activity 4: Security Control Implementation... 7 Integrating Security Control Technologies... 7 Common Configuration Enumeration... 8 Defining Security Control Monitoring Strategy... 8 Lab Activity 5: Update the HGA LAN SSP... 9 Lab Activity 6: Building an Assessment Case... 9 Table of Figues Table 1 - Documents to Support Lab Activities... 3 Table 2 - Documenting System Categorization... 5 Table 3 - Selecting Security Controls from Catalog... 6 Table 4 - Security Control Implementation... 7 Table 5 - Baseline Configuration from USGCB... 8 Table 6 - Monitoring Strategy... 8 Table 7 - Building an Assessment Case... 10

3 Introduction These lab exercises will walk you through the steps of the Risk Management Framework (RMF), for the Hypothetical Government Agency (HGA), from the Risk Management Scenario reading assignment. You will apply abbreviated steps of the RMF process outlined in the NIST SP r1. You will start with the categorization of information and information systems using the NIST r1. Then, mitigation of risk will be addressed through the selection and implementation of appropriate security controls listed in the NIST Finally, you will build an assessment case for one of security controls using guidance from the NIST Ar1. Documentation You may document this information in any application you feel comfortable, preferably MS Office Excel, or Word. Most of this information is suitable for table format. There is an Excel workbook that you may use as an example/template called LabActivityWorkingData.xlsx. Please use this as your primary output working document. You will eventually move only the relevant data to the system security plan. There is a staggering amount of information detailed in the NIST information and security control catalogs. Information can be organized and used as input tools during this process, as well. There are several documents that will help you navigate through this information, so that you can find what you re looking for, and store it in such a way as to promote reusability. The following documents, templates and examples are at your disposal to make these activities less time consuming: Document Name Document Type Description Table 1 - Documents to Support Lab Activities Mapping_NICE.accdb Input Access database that lists all controls. USGCB-Windows-Settings.xls Input Excel worksheet that documents all of the mandated configuration settings for multiple Windows OS platforms LabActivityWorkingData.xlsx Output Excel worksheet that provides a template with examples of how to organize your data, as you go through the lab activities HGA System Security Plan.docx Output Word document that provides examples and placeholders for information that you will add to the plan, as you complete the lab activities.

4 Lab Activity 1: Searching for Guidance Using Internet search engines, find the following information: 1. So far, DHS has issued two FISMs (Federal Information Security Memorandums) for FY2011. Find those FISMs and answer the following: a. The subject for FISM is b. The Department of Homeland Security issues Federal Information Security Memoranda to inform federal departments and agencies of their responsibilities, required actions, and effective dates to achieve [hint: FISM footnote] c. The subject of FISM is 2. Continuous monitoring is the next stage in the evolution of FISMA compliance. On the NIST website (csrc.nist.gov) you can find a wealth of information relating to the technical aspects of FISMA compliance. Go to the Drafts section, and open the latest document regarding Continuous Monitoring. a. What is the document number? b. Referencing the Applying the Continuous Monitoring Technical Reference Model to the Asset, Configuration, and Vulnerability Management Domains Table of Contents, what is this draft document s Relationship to Existing Standards and Specifications Please list the other 3 document numbers relating to CM: i. ii. iii. 3. Do a search for OMB Memorandum. Navigate to the White House Memorandum (current year). This is one of the key areas for dissemination of information relating to all OMB policies, including information security and systems security. a. The OBM memorandums are organized by b. There is a memo from 2011 that clarifies Chief Information Officer Authorities (and responsibilities); Agency CIOs will be held accountable for lowering operational costs, terminating and turning around troubled projects, and delivering meaningful functionality at a faster rate while enhancing the security of information systems. What are the four areas of responsibilities? i. ii. iii. iv. 4. Every year, the OMB releases updated reporting instructions for FISMA. a. The memo number for 2011 is. b. The first page of this memo emphasizes Cybersecurity Responsibilities and Activities of the Executive Office of the President and the Department of Homeland Security (DHS), " What is on the 2 nd page of this memo? And what is the significance of that second page?! c. The most significant portion of this memo is the Frequently Asked Questions, which tend to be a slight variation of the FAQs from the previous year. Please make note of the following questions, and their corresponding answers They represent a considerable shift in compliance: #9, #10, #28.

5 Lab Activity 2: Categorizing Information Systems We are going to create artifacts that we will use to build a system security plan for one of our information systems; the HGA LAN, in Washington, DC. Your first artifact will document the system category, which will list the following: 1. The name of the information system 2. The information types discovered (this information will be given) 3. The provisional impact level for each information type 4. Any justification for modifying the impact level of the information or information system 5. The High Water Mark, or impact rating for each of your information systems Information System: HGA LAN, Washington, DC HGA s locally hosted LAN server contains a mix of management, and mission-specific information, such as draft regulations, internal correspondence and a variety of other business documents, memos and reports. Currently, remote, wireless, and mobile device access is not available. The cost per fiscal year to operate the LAN is $1.2 million per year. The following information types have been discovered on the HGA LAN system: Workplace Policy Development & Management Training and Employment Worker Safety Health Care Administration Public Resources, Facility and Infrastructure Management Information Infrastructure Management International Development and Humanitarian Aid You will find these information types and their associated impact levels in the NIST SP Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories. Information System: Public Access Directory Information System Category: Low Table 2 - Documenting System Categorization Information Type Confidentiality Integrity Availability General Information Low Low Low 1. Name Low Low Low 2. Address Low Low Low 3. Phone Low Low Low Personal Identifiable Information Moderate Moderate Moderate High Water Mark Moderate Adjusted Impact Level Low Down Scope Justification PII information processed, stored, and transmitted on this system can be found in the public domain.

6 Lab Activity 3: Selecting Security Controls Selection The SP rev 3, Recommended Security Controls for Federal Information Systems and Organizations, is a catalog of security controls that define the baseline security configurations for low, moderate and high systems. In this exercise, you will select all of the relevant, Priority 1 controls, from the Access Control (AC) family. Document them in a table (Task 2-2). Indicate, in the CCC column, if the control would be a good Common Control candidate. (Task 2-1) The example below shows all of the relevant, Priority 1 & 2 controls, from the System and Information Integrity (SI) family, applicable to the Public Access Directory system with a low impact categorization. You can find all of these controls in the Mapping_NICE.accdb file NO CNTL_NAME Common CNTL_DESCRIPTION SI-1 System And Information Integrity Policy & Procedures SI-2 SI-3 SI-5 Flaw Remediation Malicious Code Protection Security Alerts, Advisories, And Directives Yes (Task 2-1) Table 3 - Selecting Security Controls from Catalog Develops, disseminates, and reviews/updates [Assignment: organization-defined frequency]: a. A formal, documented system and information integrity policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance Develops, disseminates, and reviews/updates [Assignment: organization-defined frequency]: b. Formal, documented procedures to facilitate the implementation of the system and information integrity policy and associated system and information integrity controls a. Identifies, reports, and corrects information system flaws b. Tests software updates related to flaw remediation for effectiveness and potential side effects on organizational information systems before installation c. Incorporates flaw remediation into all configuration management process a. Employs malicious code protection mechanisms at information system entry and exit points and at workstations, servers, or mobile computing devices on the network to detect and eradicate malicious code: - Transported by electronic mail, electronic mail attachments, web accesses, removable media, or other common means; or - Inserted through the exploitation of information system vulnerabilities b. Updates malicious code protection mechanisms (including signature definitions) whenever new releases are available in accordance with organizational configuration management policy and procedures c. Configures malicious code protection mechanisms to: - Perform periodic scans of the information system [Assignment: organization-defined frequency] and real-time scans of files from external sources as the files are downloaded, opened, or executed in accordance with organizational security policy; and - [Selection (one or more): block malicious code; quarantine malicious code; send alert to administrator; [Assignment: organization-defined action]] in response to malicious code detection d. Addresses the receipt of false positives during malicious code detection and eradication and the resulting potential impact on the availability of the information system a. Receives information system security alerts, advisories, and directives from designated external organizations on an ongoing basis b. Generates internal security alerts, advisories, and directives as deemed necessary c. Disseminates security alerts, advisories, and directives to [Assignment: organizationdefined list of personnel (identified by name and/or by role)]

7 Lab Activity 4: Security Control Implementation You will now select one of the Security Controls from the previous exercise, and document how you plan to implement (Task 3-1) and monitor (Task 2-3) the security control. The security control will typically be implemented by integrating another technology, such as installing antivirus software, or by modifying the configuration of existing technologies, such as configuring and deploying Windows Group Policies Objects (GPOs). Integrating Security Control Technologies Security control technologies, targeted for deployment, within the information system, are allocated to specific system components, responsible for providing a particular security capability. For example, to satisfy SI-3 security control, I have implemented SEP11 anti-virus software for my client workstations, and ScanMail antivirus for my Exchange servers. You should consider the use of information technology products that have been tested, evaluated, or validated by approved, independent, third-party assessment facilities. Table 4 - Security Control Implementation NO SI-3 SI-3 CNTL NAME Malicious Code Protection Malicious Code Protection CC Provider CNTL_Implementation Platforms Monitoring Strategy Systems Anti-Virus signature file Integrity age detection is provided Division by SMS. Systems Integrity Division Symnantec Endpoint Protection v.11 - The AntiVirus Program provides anti-virus software support to Domestic Bureaus, Consular and Executive Offices, IRM Systems Managers, Overseas Posts and Tenant Organizations Department-wide. Fortinet FortiMail, FortiGate, Micro ScanMail. To protect the network backbone infrastructure, i.e., gateways and Windows Exchange Servers from penetration by hostile hacker software tools, the Department implemented network "on the fly" anti-virus software support. The contract with the Symantec Corporation for Symantec Endpoint Protection (SEP) supports the following operating system platforms: Windows File and Exchange Servers, and client workstations, Current Operating Systems (Windows NT, 2000, XP, 2003, Vista),Macintosh, HomeUse: Windows 2003, 2008, XP, Vista, Windows 7, and Macintosh (Apple) OS. Implemented network anti-virus software support using: Fortinet FortiMail - SMTP, Spam, Phishing,Fortinet FortiGate - SMTP, FTP and HTTP Scanning, Trend Micro ScanMail for Microsoft Exchange Servers - SMTP, Spam, Content Filtering. The date on the signature file is compared to the current date. There is no score until a grace period of 6 days has elapsed. Beginning on day 7, a score of 6.0 is assigned for each day since the last update of the signature file. In particular, on day 7 the score is 42.0.

8 Common Configuration Enumeration For configuration settings, you must ensure that mandatory configuration settings are established and implemented on information technology products, in accordance with federal and organizational policies (e.g., Federal Desktop Core Configuration (FDCC), or the US Government Configuration Baseline (USGCB)). The example below shows passwordrelated settings mandated by the USGCB. You can find USGCB Windows setting in the USGCB-Windows-Settings.xls file. NO Implementation USGCB Setting Impact Rationale IA-5 Minimum password length IA-5 AC-3 CM-6 CM-7 SC-5 IA-5 AC- 11 Password must meet complexity requirement Maximum password age Account lockout threshold 12 characters To make brute force password guessing attacks more difficult. Enabled To make brute force password guessing attacks more difficult. 60 days A user's account is at greater risk of compromise through brute force attacks when the same password is used for an extended period of 5 invalid logon attempts time. To render infeasible password guessing attacks. Table 5 - Baseline Configuration from USGCB Requiring long passwords increases the risk that users will write down their passwords in order to remember them. It is recommended that agencies provide users advice on password creating using ideas such as passphrases. Requiring complex passwords increases the risk that users will write down their passwords in order to remember them. Users will have to specify a new password every 60 days. Configuring this to a lower number of days may actually lower security because it increases the risk that users will write down their passwords in order to be able to remember them. Locked-out accounts will continue to be locked out until they are reset by an administrator or until the 15 minute account lockout duration expires. Its probable that this setting will increase help desk calls. Defining Security Control Monitoring Strategy Table 6 - Monitoring Strategy NO Implementation USGCB Setting AC-3 CM-6 CM-7 SC-5 IA-5 Maximum password age Monitoring Strategy 60 days AD Users monitors the age of user account passwords (PWs). DoS policy requires all passwords be changed every 60 days. This includes service accounts. The date the password was changed is compared to the current date. There is no score for 60 days. Beginning on day 61, a score of 1.0 is assigned for each day since the last password change. However, under any of the following conditions, the score remains 0.0: The user account is disabled The user account requires two-factor authentication for login If ipost cannot determine the date of the last password reset, e.g., if the user account has restrictive permissions, then a flat score of 200 is assigned. Finally, if the account is set to never expire, an additional 5 points are added to whatever score was calculated above.

9 Note: This implementation shows a cross section of controls from four different control families: Access Control (AC), Configuration Management (CM), System and Communications Protection (SC), and Identification and Authentication (IA). Monitoring whether each individual control (900) is in place and operating as intended could be very costly. Many argue that is not sufficient to understand the effectiveness of the entire security program. Lab Activity 5: Update the HGA LAN SSP Open the HGA System Security Plan.docx and select a category in Section 2, then cut and paste your security controls implementation table under section 13, and your Monitoring Strategy under section 14. Choose today s date for questions 15. Save the document as {GroupName} HGA SSP.docx. Lab Activity 6: Building an Assessment Case An assessment case represents a worked example of an assessment procedure, identifying the specific actions that an assessor might carry out during the assessment of a security control or control enhancement in an information system. There is one assessment case per control, covering all assessment objectives from the assessment procedure in Appendix F for that control (both base control and all enhancements). The assessment case provides an example by experienced assessors of a potential set of specific assessor action steps to accomplish the assessment that were developed with consideration for the list of potential assessment methods and objects, and incorporating the level of coverage and depth to be applied and the specific purpose to be achieved by each assessor action. This additional level of detail in the assessment cases provides assessors with more prescriptive assessment information. Yet, while being more prescriptive, the assessment cases are not intended to restrict assessor flexibility provided as part of the design principles in Special Publication A. The assessor remains responsible for making the specified determinations and for providing adequate rationale for the determinations made. Please build an assessment case for AC-7.1 Unsuccessful Login Attempts, using the assessment case template and example worksheets from LabActivityWorkingData.xlsx workbook. The following is an example of the specific evidence gathering actions that build the assurance case for AC [Use the USGCB as guidance for verifying configuration of specific settings, relating to control AC-7]

10 Table 7 - Building an Assessment Case Action Step AC AC AC AC AC Potential Assessor Evidence Gathering Actions Examine information system access control policy and procedures, physical and environmental protection policy and procedures, security plan, or other relevant documents; reviewing for the automated mechanisms and configuration settings to be employed to defines the time period of user inactivity after which the information system initiates a session lock; Examine System Configuration Guide, describing the current configuration settings for an agreed-upon specific sample of automated mechanisms identified AC-11.1; reviewing for indication that the mechanisms are configured as identified in AC11.1. Examine GPO Screen Saver Setting User Configuration\Administrative Templates\Control Panel\Personalization is enabled, and set to time out after 900 seconds. Test, by observing the information system, to see if initiates a session lock after 15 minutes of inactivity. Test the information system, by observing the system for 30 minutes, to see if it retains the session lock until the user reestablishes access using established identification and authentication procedures. Legend AA: Alphanumeric characters representing security control family in Special Publication N: Numeric character representing the security control number within the family of controls. n: Number of determination statements in the assessment object. m: Number of action steps associated with a specific determination statement.

Security Control Standard

Security Control Standard Department of the Interior Security Control Standard Security Assessment and Authorization January 2012 Version: 1.2 Signature Approval Page Designated Official Bernard J. Mazer, Department of the Interior,

More information

How To Audit The Mint'S Information Technology

How To Audit The Mint'S Information Technology Audit Report OIG-05-040 INFORMATION TECHNOLOGY: Mint s Computer Security Incident Response Capability Needs Improvement July 13, 2005 Office of Inspector General Department of the Treasury Contents Audit

More information

Security Control Standard

Security Control Standard Department of the Interior Security Control Standard Risk Assessment January 2012 Version: 1.2 Signature Approval Page Designated Official Bernard J. Mazer, Department of the Interior, Chief Information

More information

Independent Evaluation of NRC s Implementation of the Federal Information Security Modernization Act of 2014 for Fiscal Year 2015

Independent Evaluation of NRC s Implementation of the Federal Information Security Modernization Act of 2014 for Fiscal Year 2015 Independent Evaluation of NRC s Implementation of the Federal Information Security Modernization Act of 2014 for Fiscal Year 2015 OIG-16-A-03 November 12, 2015 All publicly available OIG reports (including

More information

POSTAL REGULATORY COMMISSION

POSTAL REGULATORY COMMISSION POSTAL REGULATORY COMMISSION OFFICE OF INSPECTOR GENERAL FINAL REPORT INFORMATION SECURITY MANAGEMENT AND ACCESS CONTROL POLICIES Audit Report December 17, 2010 Table of Contents INTRODUCTION... 1 Background...1

More information

U.S. ELECTION ASSISTANCE COMMISSION OFFICE OF INSPECTOR GENERAL

U.S. ELECTION ASSISTANCE COMMISSION OFFICE OF INSPECTOR GENERAL U.S. ELECTION ASSISTANCE COMMISSION OFFICE OF INSPECTOR GENERAL FINAL REPORT: U.S. Election Assistance Commission Compliance with the Requirements of the Federal Information Security Management Act Fiscal

More information

SMITHSONIAN INSTITUTION

SMITHSONIAN INSTITUTION SMITHSONIAN INSTITUTION FEDERAL INFORMATION SECURITY MANAGEMENT ACT (FISMA) 2012 INDEPENDENT EVALUATION REPORT TABLE OF CONTENTS PURPOSE 1 BACKGROUND 1 OBJECTIVES, SCOPE, AND METHODOLOGY 2 SUMMARY OF RESULTS

More information

CONTINUOUS MONITORING

CONTINUOUS MONITORING CONTINUOUS MONITORING Monitoring Strategy Part 2 of 3 ABSTRACT This white paper is Part 2 in a three-part series of white papers on the sometimes daunting subject of continuous monitoring (CM) and how

More information

FISMA / NIST 800-53 REVISION 3 COMPLIANCE

FISMA / NIST 800-53 REVISION 3 COMPLIANCE Mandated by the Federal Information Security Management Act (FISMA) of 2002, the National Institute of Standards and Technology (NIST) created special publication 800-53 to provide guidelines on security

More information

Office of Inspector General Audit Report

Office of Inspector General Audit Report Office of Inspector General Audit Report USMMA SECURITY CONTROLS WERE NOT SUFFICIENT TO PROTECT SENSITIVE DATA FROM UNAUTHORIZED ACCESS Maritime Administration Report Number: FI-2012-138 Date Issued: May

More information

Health Insurance Portability and Accountability Act Enterprise Compliance Auditing & Reporting ECAR for HIPAA Technical Product Overview Whitepaper

Health Insurance Portability and Accountability Act Enterprise Compliance Auditing & Reporting ECAR for HIPAA Technical Product Overview Whitepaper Regulatory Compliance Solutions for Microsoft Windows IT Security Controls Supporting DHS HIPAA Final Security Rules Health Insurance Portability and Accountability Act Enterprise Compliance Auditing &

More information

GFI White Paper PCI-DSS compliance and GFI Software products

GFI White Paper PCI-DSS compliance and GFI Software products White Paper PCI-DSS compliance and Software products The Payment Card Industry Data Standard () compliance is a set of specific security standards developed by the payment brands* to help promote the adoption

More information

Office of Inspector General

Office of Inspector General DEPARTMENT OF HOMELAND SECURITY Office of Inspector General Security Weaknesses Increase Risks to Critical United States Secret Service Database (Redacted) Notice: The Department of Homeland Security,

More information

U.S. Department of Energy Office of Inspector General Office of Audits and Inspections

U.S. Department of Energy Office of Inspector General Office of Audits and Inspections U.S. Department of Energy Office of Inspector General Office of Audits and Inspections Audit Report The Department's Configuration Management of Non-Financial Systems OAS-M-12-02 February 2012 Department

More information

Security Control Standards Catalog

Security Control Standards Catalog Security Control Standards Catalog Version 1.2 Texas Department of Information Resources April 3, 2015 Contents About the Security Control Standards Catalog... 1 Document Life Cycle... 1 Revision History...

More information

CTR System Report - 2008 FISMA

CTR System Report - 2008 FISMA CTR System Report - 2008 FISMA February 27, 2009 TABLE of CONTENTS BACKGROUND AND OBJECTIVES... 5 BACKGROUND... 5 OBJECTIVES... 6 Classes and Families of Security Controls... 6 Control Classes... 7 Control

More information

How To Improve Nasa'S Security

How To Improve Nasa'S Security DECEMBER 5, 2011 AUDIT REPORT OFFICE OF AUDITS NASA FACES SIGNIFICANT CHALLENGES IN TRANSITIONING TO A CONTINUOUS MONITORING APPROACH FOR ITS INFORMATION TECHNOLOGY SYSTEMS OFFICE OF INSPECTOR GENERAL

More information

Final Audit Report -- CAUTION --

Final Audit Report -- CAUTION -- U.S. OFFICE OF PERSONNEL MANAGEMENT OFFICE OF THE INSPECTOR GENERAL OFFICE OF AUDITS Final Audit Report Audit of the Information Technology Security Controls of the U.S. Office of Personnel Management

More information

LockoutGuard v1.2 Documentation

LockoutGuard v1.2 Documentation LockoutGuard v1.2 Documentation (The following graphics are screen shots from Microsoft ISA Server and Threat Management Gateway which are the property of Microsoft Corp. and are included here for instructive

More information

Security Control Standard

Security Control Standard Department of the Interior Security Control Standard Maintenance January 2012 Version: 1.2 Signature Approval Page Designated Official Bernard J. Mazer, Department of the Interior, Chief Information Officer

More information

Enterprise Cybersecurity Best Practices Part Number MAN-00363 Revision 006

Enterprise Cybersecurity Best Practices Part Number MAN-00363 Revision 006 Enterprise Cybersecurity Best Practices Part Number MAN-00363 Revision 006 April 2013 Hologic and the Hologic Logo are trademarks or registered trademarks of Hologic, Inc. Microsoft, Active Directory,

More information

NATIONAL CREDIT UNION ADMINISTRATION OFFICE OF INSPECTOR GENERAL

NATIONAL CREDIT UNION ADMINISTRATION OFFICE OF INSPECTOR GENERAL NATIONAL CREDIT UNION ADMINISTRATION OFFICE OF INSPECTOR GENERAL INDEPENDENT EVALUATION OF THE NATIONAL CREDIT UNION ADMINISTRATION S COMPLIANCE WITH THE FEDERAL INFORMATION SECURITY MANAGEMENT ACT (FISMA)

More information

Telemedicine HIPAA/HITECH Privacy and Security

Telemedicine HIPAA/HITECH Privacy and Security Telemedicine HIPAA/HITECH Privacy and Security 1 Access Control Role Based Access The organization shall provide secure rolebased account management. Privileges granted utilizing the principle of least

More information

Security Language for IT Acquisition Efforts CIO-IT Security-09-48

Security Language for IT Acquisition Efforts CIO-IT Security-09-48 Security Language for IT Acquisition Efforts CIO-IT Security-09-48 Office of the Senior Agency Information Security Officer VERSION HISTORY/CHANGE RECORD Change Number Person Posting Change Change Reason

More information

Information Security for Managers

Information Security for Managers Fiscal Year 2015 Information Security for Managers Introduction Information Security Overview Enterprise Performance Life Cycle Enterprise Performance Life Cycle and the Risk Management Framework Categorize

More information

U.S. Census Bureau. FY 2009 FISMA Assessment of the Field Data Collection Automation System (CEN22)

U.S. Census Bureau. FY 2009 FISMA Assessment of the Field Data Collection Automation System (CEN22) U.S. DEPARTMENT OF COMMERCE Office of Inspector General U.S. Census Bureau FY 2009 FISMA Assessment of the Field Data Collection Automation System (CEN22) Final Report No. OAE-19728 November 2009 Office

More information

United States Patent and Trademark Office

United States Patent and Trademark Office U.S. DEPARTMENT OF COMMERCE Office of Inspector General United States Patent and Trademark Office FY 2009 FISMA Assessment of the Patent Cooperation Treaty Search Recordation System (PTOC-018-00) Final

More information

FedRAMP Standard Contract Language

FedRAMP Standard Contract Language FedRAMP Standard Contract Language FedRAMP has developed a security contract clause template to assist federal agencies in procuring cloud-based services. This template should be reviewed by a Federal

More information

U.S. ELECTION ASSISTANCE COMMISSION OFFICE OF INSPECTOR GENERAL

U.S. ELECTION ASSISTANCE COMMISSION OFFICE OF INSPECTOR GENERAL U.S. ELECTION ASSISTANCE COMMISSION OFFICE OF INSPECTOR GENERAL FINAL REPORT: U.S. ELECTION ASSISTANCE COMMISSION EVALUATION OF COMPLIANCE WITH THE REQUIREMENTS OF THE FEDERAL INFORMATION SECURITY MANAGEMENT

More information

EVALUATION REPORT. Weaknesses Identified During the FY 2014 Federal Information Security Management Act Review. March 13, 2015 REPORT NUMBER 15-07

EVALUATION REPORT. Weaknesses Identified During the FY 2014 Federal Information Security Management Act Review. March 13, 2015 REPORT NUMBER 15-07 EVALUATION REPORT Weaknesses Identified During the FY 2014 Federal Information Security Management Act Review March 13, 2015 REPORT NUMBER 15-07 EXECUTIVE SUMMARY Weaknesses Identified During the FY 2014

More information

TSA audit - How Well Does It Measure Network Security?

TSA audit - How Well Does It Measure Network Security? DEPARTMENT OF HOMELAND SECURITY Office of Inspector General Improved Security Required For Transportation Security Administration Networks (Redacted) Notice: The Department of Homeland Security, Office

More information

Continuous Monitoring

Continuous Monitoring Continuous Monitoring The Evolution of FISMA Compliance Tina Kuligowski Tina.Kuligowski@Securible.com Overview Evolution of FISMA Compliance NIST Standards & Guidelines (SP 800-37r1, 800-53) OMB Memorandums

More information

Office of Inspector General

Office of Inspector General DEPARTMENT OF HOMELAND SECURITY Office of Inspector General Improved Security Required for DHS Networks (Redacted) Notice: The Department of Homeland Security, Office of Inspector General, has redacted

More information

U.S. Department of Energy Office of Inspector General Office of Audits & Inspections

U.S. Department of Energy Office of Inspector General Office of Audits & Inspections U.S. Department of Energy Office of Inspector General Office of Audits & Inspections Audit Report Management of Western Area Power Administration's Cyber Security Program DOE/IG-0873 October 2012 Department

More information

Audit Report. The Social Security Administration s Compliance with the Federal Information Security Management Act of 2002 for Fiscal Year 2013

Audit Report. The Social Security Administration s Compliance with the Federal Information Security Management Act of 2002 for Fiscal Year 2013 Audit Report The Social Security Administration s Compliance with the Federal Information Security Management Act of 2002 for Fiscal Year 2013 A-14-13-13086 November 2013 MEMORANDUM Date: November 26,

More information

HIGH-RISK SECURITY VULNERABILITIES IDENTIFIED DURING REVIEWS OF INFORMATION TECHNOLOGY GENERAL CONTROLS

HIGH-RISK SECURITY VULNERABILITIES IDENTIFIED DURING REVIEWS OF INFORMATION TECHNOLOGY GENERAL CONTROLS Department of Health and Human Services OFFICE OF INSPECTOR GENERAL HIGH-RISK SECURITY VULNERABILITIES IDENTIFIED DURING REVIEWS OF INFORMATION TECHNOLOGY GENERAL CONTROLS AT STATE MEDICAID AGENCIES Inquiries

More information

Audit of the Department of State Information Security Program

Audit of the Department of State Information Security Program UNITED STATES DEPARTMENT OF STATE AND THE BROADCASTING BOARD OF GOVERNORS OFFICE OF INSPECTOR GENERAL AUD-IT-15-17 Office of Audits October 2014 Audit of the Department of State Information Security Program

More information

Belarc Advisor Security Benchmark Summary

Belarc Advisor Security Benchmark Summary Page 1 of 5 The license associated with the Belarc Advisor product allows for free personal use only. Use on multiple computers in a corporate, educational, military or government installation is prohibited.

More information

September 2005 Report No. 05-031. FDIC s Information Technology Configuration Management Controls Over Operating System Software

September 2005 Report No. 05-031. FDIC s Information Technology Configuration Management Controls Over Operating System Software September 2005 Report No. 05-031 FDIC s Information Technology Configuration Management Controls Over Operating System Software Report No. 05-031 September 2005 FDIC s Information Technology Configuration

More information

Review of the SEC s Systems Certification and Accreditation Process

Review of the SEC s Systems Certification and Accreditation Process Review of the SEC s Systems Certification and Accreditation Process March 27, 2013 Page i Should you have any questions regarding this report, please do not hesitate to contact me. We appreciate the courtesy

More information

UCI FISMA Core Program Procedures & Processes Frequently Asked Questions (FAQs)

UCI FISMA Core Program Procedures & Processes Frequently Asked Questions (FAQs) Health Affairs Information Systems University of California, Irvine UCI FISMA Core Program Procedures & Processes Frequently Asked Questions (FAQs) April 11, 2012 Version 1.1 HAIS Coordination Copy The

More information

Evaluation Report. Office of Inspector General

Evaluation Report. Office of Inspector General Evaluation Report OIG-08-035 INFORMATION TECHNOLOGY: Network Security at the Office of the Comptroller of the Currency Needs Improvement June 03, 2008 Office of Inspector General Department of the Treasury

More information

U.S. Department of Energy Office of Inspector General Office of Audits and Inspections

U.S. Department of Energy Office of Inspector General Office of Audits and Inspections U.S. Department of Energy Office of Inspector General Office of Audits and Inspections Audit Report Management of Los Alamos National Laboratory's Cyber Security Program DOE/IG-0880 February 2013 Department

More information

FY15 Quarter 1 Chief Information Officer Federal Information Security Management Act Reporting Metrics V1.0

FY15 Quarter 1 Chief Information Officer Federal Information Security Management Act Reporting Metrics V1.0 FY15 Quarter 1 Chief Information Officer Federal Information Security Management Act Reporting Metrics V1.0 Prepared by: US Department of Homeland Security Office of Cybersecurity and Communications Federal

More information

Deep Security Vulnerability Protection Summary

Deep Security Vulnerability Protection Summary Deep Security Vulnerability Protection Summary Trend Micro, Incorporated This documents outlines the process behind rules creation and answers common questions about vulnerability coverage for Deep Security

More information

Compliance series Guide to meeting requirements of USGCB

Compliance series Guide to meeting requirements of USGCB Compliance series Guide to meeting requirements of USGCB avecto.com Contents Introduction to USGCB 2 > From FDCC to USGCB 3 > USGCB settings and standard user accounts 3 > Application compatibility 4 >

More information

Final Audit Report. Report No. 4A-CI-OO-12-014

Final Audit Report. Report No. 4A-CI-OO-12-014 U.S. OFFICE OF PERSONNEL MANAGEMENT OFFICE OF THE INSPECTOR GENERAL OFFICE OF AUDITS Final Audit Report Subject: AUDIT OF THE INFORMATION TECHNOLOGY SECURITY CONTROLS OF THE U.S. OFFICE OF PERSONNEL MANAGEMENT'S

More information

Desktop Security. Overview and Technology Guidance. Michael Ramsey Network Specialist, NC DPI

Desktop Security. Overview and Technology Guidance. Michael Ramsey Network Specialist, NC DPI Desktop Security Overview and Technology Guidance Michael Ramsey Network Specialist, NC DPI Desktop Security Best practices for both the technical type and the typical user Defensive Layering Top Vulnerabilities

More information

U.S. OFFICE OF PERSONNEL MANAGEMENT OFFICE OF THE INSPECTOR GENERAL OFFICE OF AUDITS. Final Audit Report

U.S. OFFICE OF PERSONNEL MANAGEMENT OFFICE OF THE INSPECTOR GENERAL OFFICE OF AUDITS. Final Audit Report U.S. OFFICE OF PERSONNEL MANAGEMENT OFFICE OF THE INSPECTOR GENERAL OFFICE OF AUDITS Final Audit Report Audit of the Information Technology Security Controls of the U.S. Office of Personnel Management

More information

PRIVACY IMPACT ASSESSMENT

PRIVACY IMPACT ASSESSMENT Name of System/Application: LAN/WAN PRIVACY IMPACT ASSESSMENT U. S. Small Business Administration LAN/WAN FY 2011 Program Office: Office of the Chief Information Officer A. CONTACT INFORMATION 1) Who is

More information

Microsoft Baseline Security Analyzer (MBSA)

Microsoft Baseline Security Analyzer (MBSA) Microsoft Baseline Security Analyzer Microsoft Baseline Security Analyzer (MBSA) is a software tool released by Microsoft to determine security state by assessing missing security updates and lesssecure

More information

Security and Privacy Controls for Federal Information Systems and Organizations

Security and Privacy Controls for Federal Information Systems and Organizations NIST Special Publication 800-53 Revision 4 Security and Privacy Controls for Federal Information Systems JOINT TASK FORCE TRANSFORMATION INITIATIVE This document contains excerpts from NIST Special Publication

More information

Evaluation of DHS' Information Security Program for Fiscal Year 2014

Evaluation of DHS' Information Security Program for Fiscal Year 2014 Evaluation of DHS' Information Security Program for Fiscal Year 2014 December 12, 2014 HIGHLIGHTS Evaluation of DHS Information Security Program for Fiscal Year 2014 December 12, 2014 Why We Did This We

More information

Sample CDC Certification and Accreditation Checklist For an Application That Is Considered a Moderate Threat

Sample CDC Certification and Accreditation Checklist For an Application That Is Considered a Moderate Threat Sample CDC Certification and Accreditation Checklist For an Application That Is Considered a Moderate Threat Centers for Disease and Prevention National Center for Chronic Disease Prevention and Health

More information

User Management Guide

User Management Guide AlienVault Unified Security Management (USM) 4.x-5.x User Management Guide USM v4.x-5.x User Management Guide, rev 1 Copyright 2015 AlienVault, Inc. All rights reserved. The AlienVault Logo, AlienVault,

More information

Privacy Impact Assessment (PIA) for the. Certification & Accreditation (C&A) Web (SBU)

Privacy Impact Assessment (PIA) for the. Certification & Accreditation (C&A) Web (SBU) Privacy Impact Assessment (PIA) for the Cyber Security Assessment and Management (CSAM) Certification & Accreditation (C&A) Web (SBU) Department of Justice Information Technology Security Staff (ITSS)

More information

NIST 800-53A: Guide for Assessing the Security Controls in Federal Information Systems. Samuel R. Ashmore Margarita Castillo Barry Gavrich

NIST 800-53A: Guide for Assessing the Security Controls in Federal Information Systems. Samuel R. Ashmore Margarita Castillo Barry Gavrich NIST 800-53A: Guide for Assessing the Security Controls in Federal Information Systems Samuel R. Ashmore Margarita Castillo Barry Gavrich CS589 Information & Risk Management New Mexico Tech Spring 2007

More information

NARA s Information Security Program. OIG Audit Report No. 15-01. October 27, 2014

NARA s Information Security Program. OIG Audit Report No. 15-01. October 27, 2014 NARA s Information Security Program OIG Audit Report No. 15-01 October 27, 2014 Table of Contents Executive Summary... 3 Background... 4 Objectives, Scope, Methodology... 7 Audit Results... 8 Appendix

More information

Requirements For Computer Security

Requirements For Computer Security Requirements For Computer Security FTA/IRS Safeguards Symposium & FTA/IRS Computer Security Conference April 2, 2008 St. Louis 1 Agenda Security Framework Safeguards IT Security Review Process Preparing

More information

Today s Topics. Protect - Detect - Respond A Security-First Strategy. HCCA Compliance Institute April 27, 2009. Concepts.

Today s Topics. Protect - Detect - Respond A Security-First Strategy. HCCA Compliance Institute April 27, 2009. Concepts. Protect - Detect - Respond A Security-First Strategy HCCA Compliance Institute April 27, 2009 1 Today s Topics Concepts Case Study Sound Security Strategy 2 1 Security = Culture!! Security is a BUSINESS

More information

Report of Evaluation OFFICE OF INSPECTOR GENERAL. OIG 2014 Evaluation of the Farm Credit OIG 2014 Administration s. Management Act.

Report of Evaluation OFFICE OF INSPECTOR GENERAL. OIG 2014 Evaluation of the Farm Credit OIG 2014 Administration s. Management Act. OFFICE OF INSPECTOR GENERAL Report of Evaluation OIG 2014 Evaluation of the Farm Credit OIG 2014 Administration s Evaluation of the Farm Compliance Credit Administration s with the Federal Information

More information

Office of Inspector General

Office of Inspector General DEPARTMENT OF HOMELAND SECURITY Office of Inspector General Improved Security Required for U.S. Coast Guard Networks (Redacted) Notice: The Department of Homeland Security, Office of Inspector General,

More information

Security Controls Assessment for Federal Information Systems

Security Controls Assessment for Federal Information Systems Security Controls Assessment for Federal Information Systems Census Software Process Improvement Program September 11, 2008 Kevin Stine Computer Security Division National Institute of Standards and Technology

More information

Fiscal Year 2014 Federal Information Security Management Act Report: Status of EPA s Computer Security Program

Fiscal Year 2014 Federal Information Security Management Act Report: Status of EPA s Computer Security Program U.S. ENVIRONMENTAL PROTECTION AGENCY OFFICE OF INSPECTOR GENERAL Information Technology Fiscal Year 2014 Federal Information Security Management Act Report: Status of EPA s Computer Security Program Report.

More information

GAO INFORMATION SECURITY. State Has Taken Steps to Implement a Continuous Monitoring Application, but Key Challenges Remain

GAO INFORMATION SECURITY. State Has Taken Steps to Implement a Continuous Monitoring Application, but Key Challenges Remain GAO United States Government Accountability Office Report to Congressional Requesters July 2011 INFORMATION SECURITY State Has Taken Steps to Implement a Continuous Monitoring Application, but Key Challenges

More information

How To Set Up Safetica Insight 9 (Safetica) For A Safetrica Management Service (Sms) For An Ipad Or Ipad (Smb) (Sbc) (For A Safetaica) (

How To Set Up Safetica Insight 9 (Safetica) For A Safetrica Management Service (Sms) For An Ipad Or Ipad (Smb) (Sbc) (For A Safetaica) ( SAFETICA INSIGHT INSTALLATION MANUAL SAFETICA INSIGHT INSTALLATION MANUAL for Safetica Insight version 6.1.2 Author: Safetica Technologies s.r.o. Safetica Insight was developed by Safetica Technologies

More information

AHS Flaw Remediation Standard

AHS Flaw Remediation Standard AGENCY OF HUMAN SERVICES AHS Flaw Remediation Standard Jack Green 10/14/2013 The purpose of this procedure is to facilitate the implementation of the Vermont Health Connect s security control requirements

More information

74% 96 Action Items. Compliance

74% 96 Action Items. Compliance Compliance Report PCI DSS 2.0 Generated by Check Point Compliance Blade, on July 02, 2013 11:12 AM 1 74% Compliance 96 Action Items Upcoming 0 items About PCI DSS 2.0 PCI-DSS is a legal obligation mandated

More information

VA Office of Inspector General

VA Office of Inspector General VA Office of Inspector General OFFICE OF AUDITS & EVALUATIONS Department of Veterans Affairs Federal Information Security Management Act Audit for Fiscal Year 2013 May 29, 2014 13-01391-72 ACRONYMS AND

More information

Windows Remote Access

Windows Remote Access Windows Remote Access A newsletter for IT Professionals Education Sector Updates Issue 1 I. Background of Remote Desktop for Windows Remote Desktop Protocol (RDP) is a proprietary protocol developed by

More information

Deriving Software Security Measures from Information Security Standards of Practice

Deriving Software Security Measures from Information Security Standards of Practice Deriving Software Measures from Standards of Practice Julia Allen Christopher Alberts Robert Stoddard February 2012 2012 Carnegie Mellon University Copyright 2012 Carnegie Mellon University. This material

More information

Penetration Testing Report Client: Business Solutions June 15 th 2015

Penetration Testing Report Client: Business Solutions June 15 th 2015 Penetration Testing Report Client: Business Solutions June 15 th 2015 Acumen Innovations 80 S.W 8 th St Suite 2000 Miami, FL 33130 United States of America Tel: 1-888-995-7803 Email: info@acumen-innovations.com

More information

Vulnerability Scanning Requirements and Process Clarification Comment Disposition and FAQ 11/27/2014

Vulnerability Scanning Requirements and Process Clarification Comment Disposition and FAQ 11/27/2014 Vulnerability Scanning Requirements and Process Clarification Disposition and FAQ 11/27/2014 Table of Contents 1. Vulnerability Scanning Requirements and Process Clarification Disposition... 3 2. Vulnerability

More information

COORDINATION DRAFT. FISCAM to NIST Special Publication 800-53 Revision 4. Title / Description (Critical Element)

COORDINATION DRAFT. FISCAM to NIST Special Publication 800-53 Revision 4. Title / Description (Critical Element) FISCAM FISCAM 3.1 Security (SM) Critical Element SM-1: Establish a SM-1.1.1 The security management program is adequately An agency/entitywide security management program has been developed, An agency/entitywide

More information

U.S. Department of Energy Office of Inspector General Office of Audits and Inspections. Evaluation Report

U.S. Department of Energy Office of Inspector General Office of Audits and Inspections. Evaluation Report U.S. Department of Energy Office of Inspector General Office of Audits and Inspections Evaluation Report The Department's Unclassified Cyber Security Program 2011 DOE/IG-0856 October 2011 Department of

More information

NETWORK AND CERTIFICATE SYSTEM SECURITY REQUIREMENTS

NETWORK AND CERTIFICATE SYSTEM SECURITY REQUIREMENTS NETWORK AND CERTIFICATE SYSTEM SECURITY REQUIREMENTS Scope and Applicability: These Network and Certificate System Security Requirements (Requirements) apply to all publicly trusted Certification Authorities

More information

SECURITY CATEGORIZATION AND CONTROL SELECTION FOR NATIONAL SECURITY SYSTEMS

SECURITY CATEGORIZATION AND CONTROL SELECTION FOR NATIONAL SECURITY SYSTEMS 1 CNSSI No. 1253 15 March 2012 SECURITY CATEGORIZATION AND CONTROL SELECTION FOR NATIONAL SECURITY SYSTEMS Version 2 THIS DOCUMENT PRESCRIBES MINIMUM STANDARDS YOUR DEPARTMENT OR AGENCY MAY REQUIRE FURTHER

More information

2014 Audit of the Board s Information Security Program

2014 Audit of the Board s Information Security Program O FFICE OF I NSPECTOR GENERAL Audit Report 2014-IT-B-019 2014 Audit of the Board s Information Security Program November 14, 2014 B OARD OF G OVERNORS OF THE F EDERAL R ESERVE S YSTEM C ONSUMER FINANCIAL

More information

U.S. Department of Energy Office of Inspector General Office of Audits & Inspections. Evaluation Report

U.S. Department of Energy Office of Inspector General Office of Audits & Inspections. Evaluation Report U.S. Department of Energy Office of Inspector General Office of Audits & Inspections Evaluation Report The Department's Unclassified Cyber Security Program - 2012 DOE/IG-0877 November 2012 MEMORANDUM FOR

More information

United States Department of Agriculture. Office of Inspector General

United States Department of Agriculture. Office of Inspector General United States Department of Agriculture Office of Inspector General U.S. Department of Agriculture, Office of the Chief Information Officer, Fiscal Year 2013 Federal Information Security Management Act

More information

Estate Agents Authority

Estate Agents Authority INFORMATION SECURITY AND PRIVACY PROTECTION POLICY AND GUIDELINES FOR ESTATE AGENTS Estate Agents Authority The contents of this document remain the property of, and may not be reproduced in whole or in

More information

E-Mail Secure Gateway (EMSG)

E-Mail Secure Gateway (EMSG) for the E-Mail Secure Gateway (EMSG) DHS/MGMT/PIA-006 March 22, 2012 Contact Point David Jones MGMT/OCIO/ITSO/ESDO DHS HQ (202) 447-0167 Reviewing Official Mary Ellen Callahan Chief Privacy Officer Department

More information

Audit of the Board s Information Security Program

Audit of the Board s Information Security Program Board of Governors of the Federal Reserve System Audit of the Board s Information Security Program Office of Inspector General November 2011 November 14, 2011 Board of Governors of the Federal Reserve

More information

Overview. FedRAMP CONOPS

Overview. FedRAMP CONOPS Concept of Operations (CONOPS) Version 1.0 February 7, 2012 Overview Cloud computing technology allows the Federal Government to address demand from citizens for better, faster services and to save resources,

More information

Windows Operating Systems. Basic Security

Windows Operating Systems. Basic Security Windows Operating Systems Basic Security Objectives Explain Windows Operating System (OS) common configurations Recognize OS related threats Apply major steps in securing the OS Windows Operating System

More information

DIVISION OF INFORMATION SECURITY (DIS)

DIVISION OF INFORMATION SECURITY (DIS) DIVISION OF INFORMATION SECURITY (DIS) Information Security Policy Information Systems Acquisitions, Development, and Maintenance v1.0 October 15, 2013 Revision History Update this table every time a new

More information

NETWRIX IDENTITY MANAGEMENT SUITE

NETWRIX IDENTITY MANAGEMENT SUITE NETWRIX IDENTITY MANAGEMENT SUITE FEATURES AND REQUIREMENTS Product Version: 3.3 February 2013. Legal Notice The information in this publication is furnished for information use only, and does not constitute

More information

Promoting Application Security within Federal Government. AppSec DC November 13, 2009. The OWASP Foundation http://www.owasp.org

Promoting Application Security within Federal Government. AppSec DC November 13, 2009. The OWASP Foundation http://www.owasp.org Promoting Application Security within Federal Government AppSec DC November 13, 2009 Dr. Sarbari Gupta, CISSP, CISA Founder/President Electrosoft sarbari@electrosoft-inc.com 703-437-9451 ext 12 The Foundation

More information

AHS Vulnerability Scanning Standard

AHS Vulnerability Scanning Standard AGENCY OF HUMAN SERVICES AHS Vulnerability Scanning Standard Jack Green 10/17/2013 The purpose of this procedure is to facilitate the implementation of the Vermont Health Connect s security control requirements

More information

DIVISION OF INFORMATION SECURITY (DIS) Information Security Policy Threat and Vulnerability Management V1.0 April 21, 2014

DIVISION OF INFORMATION SECURITY (DIS) Information Security Policy Threat and Vulnerability Management V1.0 April 21, 2014 DIVISION OF INFORMATION SECURITY (DIS) Information Security Policy Threat and Vulnerability Management V1.0 April 21, 2014 Revision History Update this table every time a new edition of the document is

More information

Fortinet Solutions for Compliance Requirements

Fortinet Solutions for Compliance Requirements s for Compliance Requirements Sarbanes Oxley (SOX / SARBOX) Section / Reference Technical Control Requirement SOX references ISO 17799 for Firewall FortiGate implementation specifics IDS / IPS Centralized

More information

On-Site Computer Solutions values these technologies as part of an overall security plan:

On-Site Computer Solutions values these technologies as part of an overall security plan: Network Security Best Practices On-Site Computer Solutions Brian McMurtry Version 1.2 Revised June 23, 2008 In a business world where data privacy, integrity, and security are paramount, the small and

More information

Continuous Monitoring Strategy & Guide

Continuous Monitoring Strategy & Guide Version 1.1 July 27, 2012 Executive Summary The OMB memorandum M-10-15, issued on April 21, 2010, changed from static point in time security authorization processes to Ongoing Assessment and Authorization

More information

2012 FISMA Executive Summary Report

2012 FISMA Executive Summary Report 2012 FISMA Executive Summary Report March 29, 2013 UNITED STATES SECURITIES AND EXCHANGE COMMISSION WASHINGTON, D.C. 20549 OI'!'ICEOI' lnstfl! C1'0R GENERAt MEMORANDUM March 29,2013 To: Jeff Heslop, Chief

More information

HHS Information System Security Controls Catalog V 1.0

HHS Information System Security Controls Catalog V 1.0 Information System Security s Catalog V 1.0 Table of Contents DOCUMENT HISTORY... 3 1. Purpose... 4 2. Security s Scope... 4 3. Security s Compliance... 4 4. Security s Catalog Ownership... 4 5. Security

More information

Risk Management Framework (RMF): The Future of DoD Cyber Security is Here

Risk Management Framework (RMF): The Future of DoD Cyber Security is Here Risk Management Framework (RMF): The Future of DoD Cyber Security is Here Authors: Rebecca Onuskanich William Peterson 3300 N Fairfax Drive, Suite 308 Arlington, VA 22201 Phone: 571-481-9300 Fax: 202-315-3003

More information

INTERNATIONAL TRADE ADMINISTRATION Improvements Are Needed to Strengthen ITA s Information Technology Security Program

INTERNATIONAL TRADE ADMINISTRATION Improvements Are Needed to Strengthen ITA s Information Technology Security Program INTERNATIONAL TRADE ADMINISTRATION Improvements Are Needed to Strengthen ITA s Information Technology Security Program FINAL REPORT NO. OIG-12-037-A SEPTEMBER 27, 2012 U.S. Department of Commerce Office

More information

Promoting Application Security within Federal Government. AppSec DC November 13, 2009. The OWASP Foundation http://www.owasp.org

Promoting Application Security within Federal Government. AppSec DC November 13, 2009. The OWASP Foundation http://www.owasp.org Promoting Application Security within Federal Government AppSec DC November 13, 2009 Dr. Sarbari Gupta, CISSP, CISA Founder/President Electrosoft sarbari@electrosoft-inc.com 703-437-9451 ext 12 The Foundation

More information

Department of Homeland Security

Department of Homeland Security Evaluation of DHS Information Security Program for Fiscal Year 2013 OIG-14-09 November 2013 Washington, DC 20528 / www.oig.dhs.gov November 21, 2013 MEMORANDUM FOR: FROM: SUBJECT: Jeffrey Eisensmith Chief

More information

Security Self-Assessment Tool

Security Self-Assessment Tool Security Self-Assessment Tool State Agencies Receiving FPLS Information, 7/15/2015 Contents Overview... 2 Access Control (AC)... 3 Awareness and Training (AT)... 8 Audit and Accountability (AU)... 10 Security

More information