Now ISC2 Blogs have an Opinion on FISMA

Posted June 2nd, 2008 by

The fun part of this time of the year:  the FISMA Report Armchair Quarterbacks.  Hey, even I fit in there somewhere because right now I’m nowhere near being in a decision-making role for the Government.

Well, today it’s the ISC2 blog talking about FISMA.

So why is it that nobody addresses the huge pink and chartreuse elephant in the room?  The problem is not the metrics, as flawed as they might be.  The problem is not identifying a security baseline, even though that makes sense to have.  The problem is not demonstrating Return on Security Investment (as flawed as  the concept is, and no, I don’t want to debate whether it’s a valid concept, even though we all know it’s not) even though good CISOs try to do that as internal marketing to their management.

This is the primary problem for the Government when it comes to security:  due to the scale of the Federal Government, we do not have enough skilled security people to go around.  Almost all of our governance models are designed around this flaw:

  • Catalog of controls to standardize
  • Checklists so that less-skilled assessors can
  • Varying degrees of automation
  • Prioritization of security practitioners’ time

This is why I’m adding “Fast Food Franchises” to the list of models that large-scale security can draw from.  =)  More to come on this topic once I sort out the ideas.

McDonald's Checklist

McDonald’s Checklist photo by myuibe



Similar Posts:

Posted in FISMA, Rants | 6 Comments »
Tags:

6 Responses

  1.  mini-me Says:

    Can I get fries with that?

  2.  rybolov Says:

    How about a vulnerability management shake and a side order of risk slaw?

  3.  mini-me Says:

    I was thinking of a compliance side salad with a dash of eDiscovery?

  4.  shrdlu Says:

    Make mine a Caesar cipher, with the bacon bit turned on.

  5.  rybolov Says:

    Just don’t forget the magic FISMA sprinkles. =)

  6.  Vlad the Impaler Says:

    I can has a CyberShake!

Leave a Comment

Please note: Comment moderation is enabled and may delay your comment. There is no need to resubmit your comment.


Visitor Geolocationing Widget: