Now ISC2 Blogs have an Opinion on FISMA
Posted June 2nd, 2008 by rybolovThe fun part of this time of the year: the FISMA Report Armchair Quarterbacks. Hey, even I fit in there somewhere because right now I’m nowhere near being in a decision-making role for the Government.
Well, today it’s the ISC2 blog talking about FISMA.
So why is it that nobody addresses the huge pink and chartreuse elephant in the room? The problem is not the metrics, as flawed as they might be. The problem is not identifying a security baseline, even though that makes sense to have. The problem is not demonstrating Return on Security Investment (as flawed as the concept is, and no, I don’t want to debate whether it’s a valid concept, even though we all know it’s not) even though good CISOs try to do that as internal marketing to their management.
This is the primary problem for the Government when it comes to security: due to the scale of the Federal Government, we do not have enough skilled security people to go around. Almost all of our governance models are designed around this flaw:
- Catalog of controls to standardize
- Checklists so that less-skilled assessors can
- Varying degrees of automation
- Prioritization of security practitioners’ time
This is why I’m adding “Fast Food Franchises” to the list of models that large-scale security can draw from. =) More to come on this topic once I sort out the ideas.
McDonald’s Checklist photo by myuibe
Similar Posts:
Posted in FISMA, Rants | 6 Comments »
Tags: blog • compliance • fisma • gettingtogreen • government • infosec • management • scalability • security
June 2nd, 2008 at 2:05 pm
Can I get fries with that?
June 2nd, 2008 at 3:25 pm
How about a vulnerability management shake and a side order of risk slaw?
June 2nd, 2008 at 4:59 pm
I was thinking of a compliance side salad with a dash of eDiscovery?
June 2nd, 2008 at 6:53 pm
Make mine a Caesar cipher, with the bacon bit turned on.
June 3rd, 2008 at 9:13 am
Just don’t forget the magic FISMA sprinkles. =)
June 3rd, 2008 at 11:57 pm
I can has a CyberShake!