Tag: authorization

  • DIACAP to DIARMF: Assessment Authorization

    DIACAP to DIARMF: Assessment Authorization

    With the move from certification and accreditation (C&A) to risk management framework, comes a few new terms.  “C&A” will be replaced with assessment and authorization.  Even though “information assurance (IA) controls” will be call “security controls”, the definition and work is still the same, but the hope is that its done continuously and more cost-effective.

     

    Certification (NIST Assessment) – Comprehensive evaluation of an information system assessment of IA Controls/Security Controls to determine the extent to which the controls are implemented correctly and operating as intended. That means when evaluated, they produce the desired outcome.  An assessment is about gathering information to providing the factual basis for an authorizing official (Designated Accrediting Authority) to render a security accreditation decision

    Accreditation (NIST Authorization) – Security accreditation is the official management decision to operate (DAA – Formal approval of the system). Authorization is given by a senior agency official (upper-management/higher head quarters/combat commander). The official should have the authority to oversee the budget and business operations of the information system explicitly accept the risk to operations, assets, individuals. They accept responsibility for the security of the system and are fully accountable for the security of the system.

    “The official management decision given by a senior organization“The official management decision given by a senior organizational official to authorize operation of an information system and to explicitly accept the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security controls.”

    – NIST SP 800-37 rev 1

    March 14, 2014, UPDATE RMF – DoD IT:

    DIARMF will be known as Risk Management Framework for DoD IT.

     

  • ISC2 CAP Domain Changes

    Got this message today on CAP domain changes.. Not much changed:

    On September 1, 2013, (ISC)²® will implement certain domain-related changes for the Certified Authorization Professional (CAP®) credential exam.  These will be the new domains you will need to select when submitting CPE credits for your CAP certification.

    These domain changes are being implemented based on the outcome of the Job Task Analysis (JTA) completed in late 2012. The JTA provides the essential foundation for all of (ISC)²’s credential exams. Under general circumstances, changes due to a new JTA study are incremental, so addition or deletion of Domains does not occur normally.

    isc2-cap-domain-changes
    courtesy of gabfirethemes

    Current CAP Domains:

    1.      Understand the Security Authorization of Information Systems

    2.      Categorize Information Systems

    3.      Establish the Security Control Baseline

    4.      Apply Security Controls

    5.      Assess Security Controls

    6.      Authorize Information System

    7.      Monitor Security Controls

    Effective September 1, 2013 CAP Domains:

    1.      Risk Management Framework (RMF)

    2.      Categorization of Information Systems

    3.      Selection of Security Controls

    4.      Security Control Implementation

    5.      Security Control Assessment

    6.      Information System Authorization

    7.      Monitoring of Security Controls