SlideShare uma empresa Scribd logo
1 de 10
Near Real-Time Risk Management Continuous Monitoring, Configuration Managementand SCAP ACT/IAC Information Security and Privacy SIG 501 School Street SW Suite 800 Washington, DC 20024 202-567-2777  www.tantustech.com Daniel Philpott, CISSP, CAP Federal Information Security Architect Tantus Technologies March 22, 2010
Continuous Monitoring “The objective of the continuous monitoring program is to determine if the set of deployed security controls continue to be effective over time in light of the inevitable changes that occur.” 				- NIST SP 800-37 Revision 1, Appendix G “Continuous monitoring of security controls using automated support tools facilitates near real-time risk management …” - NIST SP 800-37 Revision 1, Appendix G 2
Monitoring: High Level Overview Strategy Organizations, information system owners and common control providers should develop a strategy to plan how continuous monitoring can effectively be established in their environment to support near real-time risk management. Program Functions Track changes to the system and its environment of operation; Conduct security impact analyses; Take remediation actions; Reassess security controls; Record and report the security status of the system; and Determine risk and decide whether the risk is acceptable. 3
Monitoring: What? What do we monitor? Primary Focus: Security Controls Hardware Software Firmware Secondary Focus: Operational Environment Threat space/environment Mission and business Policy and law Changes 4
Monitoring: Which? Which Security Controls do we monitor? Decisions belong to Information System Owner and Common Control Providers Authorizing Official or AODR approves decisions How Many Security Controls Consider the categorization of the system and importance to organizational mission Consider recent risk assessments and threat environment Selecting Security Controls Volatility – How often will the control change? Effectiveness – Does the control have a known weakness? Impact – How important is the control in relation to threats? 5
Monitoring: How? How do we monitor? Methods of monitoring vary by class of Security Control: Technical Controls – Best monitored by automated mechanisms, configuration management and SCAP Operational Controls – Interviews with knowledgeable staff Management Controls – Reviews of pertinent documentation and interviews with knowledgeable staff Automation can be applied anywhere: Create automated mechanisms to monitor for document changes Configuration Management processes offer a rich source of operational and management change information 6
Monitoring: Configuration Management What is Configuration Management? A collection of activities focused on establishing and maintaining the integrity of products and systems, through control of the processes for initializing, changing, and monitoring the configurations of those products and systems. How does it work with Continuous Monitoring? Anticipated changes to security controls are tracked by it Assessment of anticipated control changes occur within it Remediation of control weaknesses are enacted through it Records of control changes are maintained in it NIST SP 800-128 Guide for Security Configuration Management of Information Systems (Draft) 7
Monitoring: SCAP Security Content Automation Protocol (SCAP) Six specifications and associated content which enable: Documentation of configuration standards for software and operating systems Validation of software and operating system configurations against the standard Scanning for vulnerabilities and patch levels Discovery of known insecure configuration settings Asset management Best known use: Federal Desktop Core Configuration NIST SP 800-126 Technical Specification for the Security Content Automation Protocol (SCAP) v1.0 8
Resources NIST SP 800-37 Revision 1: http://csrc.nist.gov/publications/nistpubs/800-37-rev1/sp800-37-rev1-final.pdf  NIST SP 800-128 (Configuration Management Draft): http://csrc.nist.gov/publications/drafts/800-128/draft_sp800-128-ipd.pdf NIST SP 800-126 (SCAP): http://csrc.nist.gov/publications/nistpubs/800-126/sp800-126.pdf 9
10 Contacts Buck Keswani Chief Executive Officer Tel 202-567-2720 Cell 703-582-7664 bkeswani@tantustech.com    Peter Rath Information Assurance Program Director Cell 703 624-2796 prath@tantustech.com Daniel Philpott Federal Information Security Architect Cell 301-825-5722 dphilpott@tantustech.com www.tantustech.com  

Mais conteúdo relacionado

Mais procurados

Guide for Applying The Risk Management Framework to Federal Information Systems
Guide for Applying The Risk Management Framework to Federal Information SystemsGuide for Applying The Risk Management Framework to Federal Information Systems
Guide for Applying The Risk Management Framework to Federal Information Systems
Guillermo Remache
 

Mais procurados (20)

NIST 800-37 Certification & Accreditation Process
NIST 800-37 Certification & Accreditation ProcessNIST 800-37 Certification & Accreditation Process
NIST 800-37 Certification & Accreditation Process
 
Developing a Continuous Monitoring Action Plan
Developing a Continuous Monitoring Action PlanDeveloping a Continuous Monitoring Action Plan
Developing a Continuous Monitoring Action Plan
 
Understanding the Risk Management Framework & (ISC)2 CAP Module 3: Roles
Understanding the Risk Management Framework & (ISC)2 CAP Module 3: RolesUnderstanding the Risk Management Framework & (ISC)2 CAP Module 3: Roles
Understanding the Risk Management Framework & (ISC)2 CAP Module 3: Roles
 
Continuous Monitoring: Getting Past Complexity & Reducing Risk
Continuous Monitoring: Getting Past Complexity & Reducing RiskContinuous Monitoring: Getting Past Complexity & Reducing Risk
Continuous Monitoring: Getting Past Complexity & Reducing Risk
 
Achieving Continuous Monitoring with Security Automation
Achieving Continuous Monitoring with Security AutomationAchieving Continuous Monitoring with Security Automation
Achieving Continuous Monitoring with Security Automation
 
Understanding the Risk Management Framework & (ISC)2 CAP Module 6: Categorize
Understanding the Risk Management Framework & (ISC)2 CAP Module 6: CategorizeUnderstanding the Risk Management Framework & (ISC)2 CAP Module 6: Categorize
Understanding the Risk Management Framework & (ISC)2 CAP Module 6: Categorize
 
INFOSECFORCE Risk Management Framework Transition Plan
INFOSECFORCE Risk Management Framework Transition PlanINFOSECFORCE Risk Management Framework Transition Plan
INFOSECFORCE Risk Management Framework Transition Plan
 
"Backoff" Malware: How to Know If You're Infected
"Backoff" Malware: How to Know If You're Infected"Backoff" Malware: How to Know If You're Infected
"Backoff" Malware: How to Know If You're Infected
 
Introduction to NIST’s Risk Management Framework (RMF)
Introduction to NIST’s Risk Management Framework (RMF)Introduction to NIST’s Risk Management Framework (RMF)
Introduction to NIST’s Risk Management Framework (RMF)
 
Auditing information System
Auditing information SystemAuditing information System
Auditing information System
 
Security auditing architecture
Security auditing architectureSecurity auditing architecture
Security auditing architecture
 
Guide for Applying The Risk Management Framework to Federal Information Systems
Guide for Applying The Risk Management Framework to Federal Information SystemsGuide for Applying The Risk Management Framework to Federal Information Systems
Guide for Applying The Risk Management Framework to Federal Information Systems
 
SuprTEK Continuous Monitoring
SuprTEK Continuous MonitoringSuprTEK Continuous Monitoring
SuprTEK Continuous Monitoring
 
General and Application Control - Security and Control Issues in Informatio...
General and Application Control - Security  and Control Issues in  Informatio...General and Application Control - Security  and Control Issues in  Informatio...
General and Application Control - Security and Control Issues in Informatio...
 
IS audit checklist
IS audit checklistIS audit checklist
IS audit checklist
 
Hipaa checklist - information security
Hipaa checklist - information securityHipaa checklist - information security
Hipaa checklist - information security
 
Securitymetrics
SecuritymetricsSecuritymetrics
Securitymetrics
 
Security and Control Issues in information Systems
Security and Control Issues in information SystemsSecurity and Control Issues in information Systems
Security and Control Issues in information Systems
 
Scope of work IT DD
Scope of work IT DDScope of work IT DD
Scope of work IT DD
 
System Security Plans 101
System Security Plans 101System Security Plans 101
System Security Plans 101
 

Destaque

Cloud security - Auditing and Compliance
Cloud security - Auditing and ComplianceCloud security - Auditing and Compliance
Cloud security - Auditing and Compliance
Josh Tullo
 
Dave Presentation In Vn
Dave Presentation In VnDave Presentation In Vn
Dave Presentation In Vn
Hung Pham Thai
 
Nicole's Technology Experience
Nicole's Technology ExperienceNicole's Technology Experience
Nicole's Technology Experience
hales4
 
Chinh Sach Cua Cong Ty
Chinh Sach Cua Cong TyChinh Sach Cua Cong Ty
Chinh Sach Cua Cong Ty
Hung Pham Thai
 
Technology In The Classroom
Technology In The ClassroomTechnology In The Classroom
Technology In The Classroom
hales4
 
Beatles -the_complete_songbook
Beatles  -the_complete_songbookBeatles  -the_complete_songbook
Beatles -the_complete_songbook
Hung Pham Thai
 

Destaque (20)

DojoSec FISMA Presentation
DojoSec FISMA PresentationDojoSec FISMA Presentation
DojoSec FISMA Presentation
 
Cloud security - Auditing and Compliance
Cloud security - Auditing and ComplianceCloud security - Auditing and Compliance
Cloud security - Auditing and Compliance
 
Managing System Security
Managing System SecurityManaging System Security
Managing System Security
 
Implementing FISMA Moderate Applications on AWS
Implementing FISMA Moderate Applications on AWSImplementing FISMA Moderate Applications on AWS
Implementing FISMA Moderate Applications on AWS
 
FedRAMP High & AWS GovCloud (US): FISMA High Requirements
FedRAMP High & AWS GovCloud (US): FISMA High RequirementsFedRAMP High & AWS GovCloud (US): FISMA High Requirements
FedRAMP High & AWS GovCloud (US): FISMA High Requirements
 
Form
FormForm
Form
 
Dave Presentation In Vn
Dave Presentation In VnDave Presentation In Vn
Dave Presentation In Vn
 
Nicole's Technology Experience
Nicole's Technology ExperienceNicole's Technology Experience
Nicole's Technology Experience
 
THU HOẠCH
THU HOẠCHTHU HOẠCH
THU HOẠCH
 
Symptoms of a Billing and Payment Problem
Symptoms of a Billing and Payment ProblemSymptoms of a Billing and Payment Problem
Symptoms of a Billing and Payment Problem
 
Lunch-time, Life-time - ATD Course Project
Lunch-time, Life-time - ATD Course Project Lunch-time, Life-time - ATD Course Project
Lunch-time, Life-time - ATD Course Project
 
Money (viet nam)
Money (viet nam)Money (viet nam)
Money (viet nam)
 
Chinh Sach Cua Cong Ty
Chinh Sach Cua Cong TyChinh Sach Cua Cong Ty
Chinh Sach Cua Cong Ty
 
Calendasexy Viet Nam
Calendasexy Viet NamCalendasexy Viet Nam
Calendasexy Viet Nam
 
Mr
MrMr
Mr
 
Access vba 052009
Access vba 052009Access vba 052009
Access vba 052009
 
Technology In The Classroom
Technology In The ClassroomTechnology In The Classroom
Technology In The Classroom
 
Bvtv
BvtvBvtv
Bvtv
 
Beatles -the_complete_songbook
Beatles  -the_complete_songbookBeatles  -the_complete_songbook
Beatles -the_complete_songbook
 
Business Intelligence Jumpstart
Business Intelligence JumpstartBusiness Intelligence Jumpstart
Business Intelligence Jumpstart
 

Semelhante a FISMA NextGen - Continuous Monitoring, Near Real-Time Risk Management

L4 RMF Phase 3 Select.pptx
L4 RMF Phase 3 Select.pptxL4 RMF Phase 3 Select.pptx
L4 RMF Phase 3 Select.pptx
StevenTharp2
 
L8 RMF Phase 7 Monitor.pptx
L8 RMF Phase 7 Monitor.pptxL8 RMF Phase 7 Monitor.pptx
L8 RMF Phase 7 Monitor.pptx
StevenTharp2
 
Information Security Identity and Access Management Administration 07072016
Information Security   Identity and Access Management Administration 07072016Information Security   Identity and Access Management Administration 07072016
Information Security Identity and Access Management Administration 07072016
Leon Blum
 
· Processed on 09-Dec-2014 901 PM CST · ID 488406360 · Word .docx
· Processed on 09-Dec-2014 901 PM CST · ID 488406360 · Word .docx· Processed on 09-Dec-2014 901 PM CST · ID 488406360 · Word .docx
· Processed on 09-Dec-2014 901 PM CST · ID 488406360 · Word .docx
LynellBull52
 
Continual Monitoring
Continual MonitoringContinual Monitoring
Continual Monitoring
Tripwire
 
CIS_Controls_v7.1_Implementation_Groups.pdf
CIS_Controls_v7.1_Implementation_Groups.pdfCIS_Controls_v7.1_Implementation_Groups.pdf
CIS_Controls_v7.1_Implementation_Groups.pdf
NesterWare
 

Semelhante a FISMA NextGen - Continuous Monitoring, Near Real-Time Risk Management (20)

L4 RMF Phase 3 Select.pptx
L4 RMF Phase 3 Select.pptxL4 RMF Phase 3 Select.pptx
L4 RMF Phase 3 Select.pptx
 
L8 RMF Phase 7 Monitor.pptx
L8 RMF Phase 7 Monitor.pptxL8 RMF Phase 7 Monitor.pptx
L8 RMF Phase 7 Monitor.pptx
 
Information Security Identity and Access Management Administration 07072016
Information Security   Identity and Access Management Administration 07072016Information Security   Identity and Access Management Administration 07072016
Information Security Identity and Access Management Administration 07072016
 
Logging, monitoring and auditing
Logging, monitoring and auditingLogging, monitoring and auditing
Logging, monitoring and auditing
 
Chapter005
Chapter005Chapter005
Chapter005
 
· Processed on 09-Dec-2014 901 PM CST · ID 488406360 · Word .docx
· Processed on 09-Dec-2014 901 PM CST · ID 488406360 · Word .docx· Processed on 09-Dec-2014 901 PM CST · ID 488406360 · Word .docx
· Processed on 09-Dec-2014 901 PM CST · ID 488406360 · Word .docx
 
International Journal of Engineering Research and Development (IJERD)
International Journal of Engineering Research and Development (IJERD)International Journal of Engineering Research and Development (IJERD)
International Journal of Engineering Research and Development (IJERD)
 
IIA GAM CS 8-5: Audit and Control of Continuous Monitoring Programs and Artif...
IIA GAM CS 8-5: Audit and Control of Continuous Monitoring Programs and Artif...IIA GAM CS 8-5: Audit and Control of Continuous Monitoring Programs and Artif...
IIA GAM CS 8-5: Audit and Control of Continuous Monitoring Programs and Artif...
 
CS 8-5_Audit and Control of Continuous Monitoring Programs and Artificial Int...
CS 8-5_Audit and Control of Continuous Monitoring Programs and Artificial Int...CS 8-5_Audit and Control of Continuous Monitoring Programs and Artificial Int...
CS 8-5_Audit and Control of Continuous Monitoring Programs and Artificial Int...
 
5757912.ppt
5757912.ppt5757912.ppt
5757912.ppt
 
Continual Monitoring
Continual MonitoringContinual Monitoring
Continual Monitoring
 
Information security as an ongoing effort
Information security as an ongoing effortInformation security as an ongoing effort
Information security as an ongoing effort
 
Pillars of Effective Software Maintenance and Support Stability, Security, an...
Pillars of Effective Software Maintenance and Support Stability, Security, an...Pillars of Effective Software Maintenance and Support Stability, Security, an...
Pillars of Effective Software Maintenance and Support Stability, Security, an...
 
Ch10 Conducting Audits
Ch10 Conducting AuditsCh10 Conducting Audits
Ch10 Conducting Audits
 
CIS_Controls_v7.1_Implementation_Groups.pdf
CIS_Controls_v7.1_Implementation_Groups.pdfCIS_Controls_v7.1_Implementation_Groups.pdf
CIS_Controls_v7.1_Implementation_Groups.pdf
 
Ignyte assurance platform NIST RMF datasheet.
Ignyte assurance platform NIST RMF datasheet.Ignyte assurance platform NIST RMF datasheet.
Ignyte assurance platform NIST RMF datasheet.
 
Information system implementation, change management and control
Information system implementation, change management and controlInformation system implementation, change management and control
Information system implementation, change management and control
 
27001.pptx
27001.pptx27001.pptx
27001.pptx
 
The information security audit
The information security auditThe information security audit
The information security audit
 
Unit Iii
Unit IiiUnit Iii
Unit Iii
 

Último

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Último (20)

Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
A Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusA Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source Milvus
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 

FISMA NextGen - Continuous Monitoring, Near Real-Time Risk Management

  • 1. Near Real-Time Risk Management Continuous Monitoring, Configuration Managementand SCAP ACT/IAC Information Security and Privacy SIG 501 School Street SW Suite 800 Washington, DC 20024 202-567-2777 www.tantustech.com Daniel Philpott, CISSP, CAP Federal Information Security Architect Tantus Technologies March 22, 2010
  • 2. Continuous Monitoring “The objective of the continuous monitoring program is to determine if the set of deployed security controls continue to be effective over time in light of the inevitable changes that occur.” - NIST SP 800-37 Revision 1, Appendix G “Continuous monitoring of security controls using automated support tools facilitates near real-time risk management …” - NIST SP 800-37 Revision 1, Appendix G 2
  • 3. Monitoring: High Level Overview Strategy Organizations, information system owners and common control providers should develop a strategy to plan how continuous monitoring can effectively be established in their environment to support near real-time risk management. Program Functions Track changes to the system and its environment of operation; Conduct security impact analyses; Take remediation actions; Reassess security controls; Record and report the security status of the system; and Determine risk and decide whether the risk is acceptable. 3
  • 4. Monitoring: What? What do we monitor? Primary Focus: Security Controls Hardware Software Firmware Secondary Focus: Operational Environment Threat space/environment Mission and business Policy and law Changes 4
  • 5. Monitoring: Which? Which Security Controls do we monitor? Decisions belong to Information System Owner and Common Control Providers Authorizing Official or AODR approves decisions How Many Security Controls Consider the categorization of the system and importance to organizational mission Consider recent risk assessments and threat environment Selecting Security Controls Volatility – How often will the control change? Effectiveness – Does the control have a known weakness? Impact – How important is the control in relation to threats? 5
  • 6. Monitoring: How? How do we monitor? Methods of monitoring vary by class of Security Control: Technical Controls – Best monitored by automated mechanisms, configuration management and SCAP Operational Controls – Interviews with knowledgeable staff Management Controls – Reviews of pertinent documentation and interviews with knowledgeable staff Automation can be applied anywhere: Create automated mechanisms to monitor for document changes Configuration Management processes offer a rich source of operational and management change information 6
  • 7. Monitoring: Configuration Management What is Configuration Management? A collection of activities focused on establishing and maintaining the integrity of products and systems, through control of the processes for initializing, changing, and monitoring the configurations of those products and systems. How does it work with Continuous Monitoring? Anticipated changes to security controls are tracked by it Assessment of anticipated control changes occur within it Remediation of control weaknesses are enacted through it Records of control changes are maintained in it NIST SP 800-128 Guide for Security Configuration Management of Information Systems (Draft) 7
  • 8. Monitoring: SCAP Security Content Automation Protocol (SCAP) Six specifications and associated content which enable: Documentation of configuration standards for software and operating systems Validation of software and operating system configurations against the standard Scanning for vulnerabilities and patch levels Discovery of known insecure configuration settings Asset management Best known use: Federal Desktop Core Configuration NIST SP 800-126 Technical Specification for the Security Content Automation Protocol (SCAP) v1.0 8
  • 9. Resources NIST SP 800-37 Revision 1: http://csrc.nist.gov/publications/nistpubs/800-37-rev1/sp800-37-rev1-final.pdf NIST SP 800-128 (Configuration Management Draft): http://csrc.nist.gov/publications/drafts/800-128/draft_sp800-128-ipd.pdf NIST SP 800-126 (SCAP): http://csrc.nist.gov/publications/nistpubs/800-126/sp800-126.pdf 9
  • 10. 10 Contacts Buck Keswani Chief Executive Officer Tel 202-567-2720 Cell 703-582-7664 bkeswani@tantustech.com    Peter Rath Information Assurance Program Director Cell 703 624-2796 prath@tantustech.com Daniel Philpott Federal Information Security Architect Cell 301-825-5722 dphilpott@tantustech.com www.tantustech.com  

Notas do Editor

  1. Security Controls discussed in Monitoring tend to indicate Technical controls are intendedGoal of monitoring is to identify changes in or to the information system which affect risk
  2. Decisions the ISO and CCP make are: Which controls are monitored and how frequently they are monitoredInformation System Monitoring – The information system owner and common control provider determine what to monitor and how frequently in collaboration with AO, CIO, CISO and Risk Executive (Function)
  3. Best case: Staff changes are recorded as system changesStaff changes can be discovered by monitoring who is filing, reviewing and approving changesChanges in change management processes can indicate policy changes
  4. Configuration Management (CM) comprises a collection of activities focused on establishing and maintaining the integrity of products and systems, through control of the processes for initializing, changing, and monitoring the configurations of those products and systems.