Home / Blogs

Federal Cybersecurity Best Practices: FISMA Continuous Monitoring

Studies have found only limited, insufficient agency adherence with FISMA's (Federal Information Security Management Act) continuous monitoring mandates. One survey found almost half of federal IT professionals were unaware of continuous monitoring requirements. A recent GAO report found that two-thirds of agencies "did not adequately monitor networks" to protect them "from intentional or unintentional harm."

To provide senior and staff level cybersecurity professionals with practical guidance in effectively implementing Information Security Continuous Monitoring (ISCM), the Center for Regulatory Effectiveness has released a Best Practices case study of agency compliance with FISMA's continuous monitoring requirements.

Based on NIST FISMA guidance and technical reference documents, CRE developed a set of five continuous monitoring principles. The study documents and explains how a federal agency thwarted an Advance Persistent Threat by adhering to the principles. The study also explains the crucial role of OMB and agency IT leadership in successfully driving agency adoption of continuous monitoring.

The five ISCM Best Practices, in brief, are:

  • Principle 1: Aggregate Diverse Data.
  • Principle 2: Analyze Multi-Source Data.
  • Principle 3: Create Real-Time Data Queries.
  • Principle 4: Transform Data Into Actionable Intelligence.
  • Principle 5: Maintain Real-Time Actionable Awareness.

The complete study is available, without cost, on CRE's FISMA Focus Interactive Public Docket (www.TheCRE.com/fisma) available here.

By Bruce Levinson, SVP, Regulatory Intervention - Center for Regulatory Effectiveness

Related topics: Cloud Computing, Policy & Regulation, Security

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

A Look at Traffic Management for External "Cloud" Load Balancing

Dyn Research: Where Do Companies Host Their Websites?

Hope is Not a Strategy: Neustar Releases 2012 Annual DDoS Attack and Impact Survey

How Neustar Technology Can Help Mitigate DDoS Attacks

Reducing the Risks of BYOD with Nominum's Security Solution

Neustar Launches Enterprise Professional Services Offerings

Nominum Releases New Security Intelligence Application

Mitigating DDoS Attacks: A Global Challenge

New Nixu NameSurfer 7.3 Series Powers the Software-Defined Data Centre

Our New Initiatives To Combat Botnets

Recent Trends and Options to Mitigate DDoS Attacks (Webcast)

PIR Survey Reveals That Most Americans Are Uninformed About DDoS Attacks

Nixu Integrates with Nominum N2 Platform in Hybrid Cloud Environments

Comments by DCA TRUST on ICANN Multi-Stakeholder Model and DCA's Contribution to ICANN Africa

SPECIAL: Updates from the ICANN Meetings in Toronto

What's in a Name Server?

New Nixu Solution Slashes Cloud Application Delivery Times from Weeks to Milliseconds

Recommendations Made to Improve Protections at Second-Level in New gTLDs

MarkMonitor Releases Q2 2012 Fraud Intelligence Report

Neustar Launches Web Performance Management Solution, Features Real-Time Intelligent Alerting

Sponsored Topics

Neustar

DNS

Sponsored by
Neustar
dotMobi

Mobile

Sponsored by
dotMobi
Afilias

DNS Security

Sponsored by
Afilias
Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines