Tag: RMF

  • POAM (an overview) Part 1

    Check out the courses at: https://securitycompliance.thinkific.com

    Here is the POAM template I was looking at:
    https://www.fedramp.gov/developing-a-plan-of-actions-milestones/
    https://www.fedramp.gov/assets/resources/templates/FedRAMP-POAM-Template.xlsm

    PM-4 PLAN OF ACTION AND MILESTONES PROCESS
    The organization:
    a. Implements a process for ensuring that plans of action and milestones for the security program and associated organizational information systems:

    1. Are developed and maintained;
    2. Document the remedial information security actions to adequately respond to risk to organizational operations and assets, individuals, other organizations, and the Nation; and
    3. Are reported in accordance with OMB FISMA reporting requirements.

    b. Reviews plans of action and milestones for consistency with the organizational risk management strategy and organization-wide priorities for risk response actions.

  • NIST SP 800-53, Revision 5 Security Controls for Information Systems and Organizations – 1 overview

    NIST SP 800-53, Revision 5 Security Controls for Information Systems and Organizations – 1 overview

    To download the slide go to:
    https://securitycompliance.thinkific.com

    NIST Special Publication 800-53, Revision 5
    Security and Privacy Controls
    Final Public Draft: October 2018
    Final Publication: December 2018
    Source: https://csrc.nist.gov/projects/risk-m…

    NIST Special Publication 800-53A, Revision 5
    Assessment Procedures for Security and Privacy Controls
    Initial Public Draft: March 2019
    Final Public Draft: June 2019
    Final Publication: September 2019

    There are 6 major objectives for this update—
    -Making the security and privacy controls more outcome-based by changing the structure of the controls;

    -Fully integrating the privacy controls into the security control catalog creating a consolidated and unified set of controls for information systems and organizations

    -Separating the control selection process from the actual controls: systems engineers, software developers, enterprise architects; and mission/business owners

    -Promoting integration with different risk management and cybersecurity approaches and lexicons, including the Cybersecurity Framework

    -Clarifying the relationship between security and privacy to improve the selection of controls necessary to address the full scope of security and privacy risks
    https://www.youtube.com/watch?v=hWWILCZbDho

  • NIST 800 37 Revision 2 – RMF for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy

    Download the presentation in this Video & Learn more here:

    http://securitycompliance.thinktific.com

    This is an overview of NIST 800-37 Revision 2. I discuss the changes, the sources and Cybersecurity Framework.

    NIST Special Publication 800-37, Revision 2
    Risk Management Framework for Security and Privacy
    Initial Public Draft: May 2018
    Final Public Draft: July 2018
    Final Publication: October 2018

    NIST 37-800 Rev 2:
    http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r1.pdf

    Executive Order:
    https://www.whitehouse.gov/presidential-actions/presidential-executive-order-strengthening-cybersecurity-federal-networks-critical-infrastructure/

    OMB:
    https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2017/M-17-25.pdf

    Cybersecurity Framework:
    https://www.nist.gov/sites/default/files/documents/cyberframework/cybersecurity-framework-021214.pdf

    NIST SP 800-53 (Revision 5):
    https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/draft

    Source of Changes:
    President’s Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure
    Office of Management and Budget Memorandum M-17-25 – next-generation Risk Management Framework (RMF) for systems and organizations
    NIST SP 800-53 Revision 5 Coordination

  • diacap to diarmf: manage information security risk

    Risk Management Framework is implemented throughout an organization.

    NIST 800-39, Manage Information Security Risk, describes how to implement risk within t three layers (or tiers) of of an organization:

    Tier 1: Organization level
    Tier 2: Mission/Business Process level
    Tier 3: Information System level

    diarmf risk management of information security

    Tier 1: Organization Level risk management
    Tier one addresses security from the organizations perspective. The activities include the implementation of the first component of risk management, risk framing. Risk framing provides context of all the risk activities within an organization, which affects the risk activities of tier 1 & 2. The output of risk framing is Risk Management Strategy. In tier 1 the organization establishes and implements governance structure that are in compliance with laws, regulations and policies. Tier 1 activities include establishment of the Risk Executive Function, establishment of the risk management strategy and determination of the risk tolerance.

    Tier 2: Mission/Business Process Level risk management

    Tier 2 risk management activities include: 1) defining the mission/business processes to support the organization. 2) Prioritize the mission/business process with respect to the long term goals of the organization. 3) Define the type of information needed to successfully execute the mission/business processes, criticality/sensitivity of the information and the information flows both internal and external of the information.

    Having a risk-aware process is an important part of tier 2. To be risk-aware senior leaders/executives need to know: 1) types of threat sources and threat events that could have an adverse affect the ability of the organizations 2) the potential adverse impacts on the organizational operations and assets, individuals, the Nation if confidentiality, integrity, availability is compromised 3) the organization�s resilience to such an attack that can be achieved with a given mission/business process

    Tier 3: Information System risk management

    From the information system perspective, tier 3 addresses the following tasks:
    1) Categorization of the information system
    2) Allocating the organizational security control
    3) Selection, implementation, assessment, authorization, and ongoing

    Chapter 3 focuses on the step to have a comprehensive risk management program. The tasks discussed include:
    Risk Framing
    Risk Assessing
    Risk Response
    Risk Monitoring

     

    For more information go to: http://elamb.org/training-certification800-39-manage-information-security-risks/

     

  • diacap to diarmf: C&A vs RMF

    DIACAP is transitioning from a Certification and Accreditation to a Risk Management Framework.  Most of the new Risk Manager Framework is in the NIST Special Publication 800-37.  The old NIST SP 800-37 was also based on Certification and Accreditation.  After FISMA 2002, it adjusted to a Risk Management Framework in NIST SP 800-37 Rev 1, Guide for Applying the Risk Management Framework to Federal Information Systems.

    diacap-to-diarmf-ca-vs-rmf
    diacap-to-diarmf-ca-vs-rmf

    NIST SP 800-37 to SP 800-37 rev 1 transformed from a Certification and Accreditation (C&A) process into the six-step Risk Management Framework (RMF).  The changes included:

    1. Revised process emphasizes
    2. Building information security capabilities into federal information systems through the application of state-of-the-practice management, operational, and technical security controls
    3. Maintaining awareness of the security state of information systems on an ongoing basis though enhanced monitoring processes
    4. Providing essential information to senior leaders to facilitate decisions regarding the acceptance of risk to organizational operations and assets, individuals, other organizations, and the Nation arising from the operation and use of information systems
  • Approved System

    Information Assurance is based on obtaining a high level of confidence on information’s confidentiality, integrity, and availability.  Some organizations that deal with “critical information”.  Critical information included things like banking transactions, classified data, information that is evidence in an ongoing investigation.  Companies, unions and government that handle this kind of information usually have a lot of exposure because they are handling public data, share holder data, employee data and are doing a lot of translation across the un-trusted networks such as the Internet.  With critical information and high exposure these organizations MUST have “approved processes” for vetting, testing and validating “approved software” and “approved systems”.

    For example, in the Department of Defense there are many lists that have approved software.  These lists are per command within larger organizations.  One over arching process/list is the Common Criteria:

    Common Criteria is an international standard for validating technical security built in to security feature of information systems.  The international standard is known as ISO/IEC 15408.

    This standard is used by many large organizations all over the world that serve the public:

    www.commoncriteriaportal.org

    www.commoncriteria.com

    Each organization has there own specific security needs so most of the time they have many levels of application approval and process:

    NSA / DOD / US Gov - www.niap-ccevs.org - National Information Assurance Partnership (NIAP) uses Common Criteria Evaluation and Validation Scheme (CCEVS) to ensure that only approved Information Assurance (IA)  and IA-Enabled Information Technology (IT) products are used

    Canadian Trusted Computer Product Evaluation Criteria
    UK – www.cesg.gov.uk/servicecatalogue/ccitsec‎

    Commercial organizations that want their products used by organization processing and storing critical information must submit to common criteria as well:

    Apple – https://ssl.apple.com/support/security/commoncriteria/‎

    Microsoft – www.microsoft.com/en-us/sqlserver/common-criteria.aspx‎

    xeroxCommon Criteria

    Citrix – www.citrix.com/support/security-compliance/common-criteria.html‎

    CiscoCisco Common Criteria 
    Emc – EMC – Common Criteria

    Organizational units also have their own criteria for approved applications and systems:

    US ArmyArmy Chess

    US Air ForceAF E/APL – Certified Air Force Evaluated Approved Product List