The Field Report
There are 18,000 banking institutions in the U.S., and somebody has to blog about their breaches, concerns and security successes.
Comments (0)
Read All Posts (16)
While reforming FISMA sounds like a good idea, placing additional administrative burden on security resources that clearly have work to do seems like a step in the wrong direction.
With IT security resources so heavily invested in policy, audits and compliance reporting, where is the room for real innovation and |
One of the problems is that legislators and regulators have looked to FISMA and the myriad of other mandates to keep systems resilient and secure against emerging security threats. This is not a sustainable approach - the "audit and compliance" exercise is simply not suitable for dealing with state-sponsored, agile and anonymous groups of attackers with nothing but time on their hands and a high-speed Internet connection. The FISMA effort is just one example of a heavyweight process that emphasizes reporting and audit at the expense of making some real substantive progress.
The federal government collectively needs to adopt a forward-leaning, anticipatory mindset, to meet - head-on - an adversary that is very comfortable in an offensive information environment. We need to spend less time talking and reporting about security and more time building security into our culture and technology. With IT security resources so heavily invested in policy, audits and compliance reporting, where is the room for real innovation and progress?
While the damage caused by this incident is being debated, it's important to underscore that these attacks had the potential to be much worse. Sure, the lights are still on, the networks are still up and order has been maintained. But what about next time?
Eric M. Fiterman is a former FBI special agent and founder of Methodvue, a consultancy that provides cybersecurity and computer forensics services to the federal government and private businesses.
Other blogs from Fiterman:
NIST SP 800-34 Rev. 1: Contingency Planning Guide for Federal Information Systems..Next Topic
DoJ: Report to Congress on Implementation of Section 1001 of the USA PATRIOT Act..Next Topic
NIST Guide to Security for WiMAX Technologies (Draft)..Next Topic
NIST SP 800-41 Revision 1: Guidelines on Firewalls and Firewall Policy..Next Topic
OMB Memorandum: New Reporting Instructions for FISMA..Next Topic
NIST IR 709: Cryptographic Key Management Workshop Summary (Draft)..Next Topic