Search FCW


Subscribe Now!
Table of Contents
Business
BPM
CXOs
Columns
Columnists
Defense
E-Government
Elections 2008
Enterprise Architecture
Funding
Homeland Security
Health IT
IPv6
LOB
Management
Procurement
Privacy
Policy
Program Management
State and Local
Security
Technology
Telework
Workforce

More Topics
resourcecenter
Home
Letters to the Editor
Current Issue/Download
Print/Online Archives
Editorial Calendar
researchstore
resourcecenter
Sprint Communications for Continuity Operations
Oracle Resource Center
GSA: Your Customer Service Agency
Government Leadership Survey
Green Solutions Guide
Report: Information Sharing
DISA IT Strategy & Vision
Emergency Preparedness Report
Report: Green Computing
PEO EIS Guidebook
Content Library

More >>



Latest News
ADVERTISEMENT





 

ODNI tests Justice security control application

By Mary Mosquera
Published on October 24, 2007

Comment

Click here to comment on this article


Related story links

NIST prepares due diligence standards for cybersecurity

Time to move beyond FISMA, experts say

Security LOB cleared for takeoff

For more defense coverage, visit Defense Systems.

www.defensesystems.com


Newsletters

You might also be interested in these FCW newsletters:

Daily
Defense
Security

To learn more, click here.


The Office of the Director of National Intelligence is testing a Justice Department application that automates many of the tasks of certifying and accrediting information systems, said Dennis Heretick, Justice’s chief information security officer.

The test joins two efforts that aim to help agencies improve their information technology security by revitalizing the certification and accreditation (C&A) process to comply with the Federal Information Security Management Act. The efforts are part of a move toward a unified federal approach to certification and accreditation.

ODNI and the Defense Department are working to converge common security standards for C&A across the national security community, an initiative that Dale Meyerrose, ODNI’s chief information officer, and DOD CIO John Grimes initiated last year, said Sharon Ehlers, ODNI’s lead for the C&A effort. At the same time, Ron Ross, a senior computer scientist at the National Institute of Standards and Technology, has produced a common framework for risk management.

“Once national security agrees on standards later this year, we will work with Ron Ross to converge them as one group of federal standards under NIST,” Ehlers said Oct. 23 at the Federal Information Assurance Conference in College Park, Md. Ehlers said she anticipates the national security standards convergence to be completed by the end of fiscal 2008.

The goal of federal security standards is not only to simplify reporting for FISMA compliance but to encourage information sharing, Heretick said. Justice is a shared service center under the Information Systems Security Line of Business consolidation initiative with 15 departments and agencies planning to migrate to its FISMA services.

ODNI is testing Justice’s control authoring tool that lets agencies conduct risk management and assess security controls electronically instead of checking against a static paper checklist, said Ken Gandola, a Northrop Grumman contractor who provides IT security support. Other agencies use this application, but the intelligence community is only testing it. The control application makes use of data stored in Justice’s Cyber Security Assessment and Management database of security requirements, controls, systems inventory and security categories.



upcoming event

Enterprise Architecture 2008 - Washington, DC
September 9 - September 10, 2008

Occupational Health & Safety Executive Summit - Arlington, VA
October 6 - October 7, 2008


 

head
fcw
issue
First Name State
Last Name Zip
Title Email