Posts

Showing posts matching the search for fisma

FISMA Redux

Image
Late last year I mentioned I planned to read and review FISMA Certification & Accreditation Handbook by Laura Taylor. You know if I read a book on Cisco MARS on one leg of my last trip, I probably read a different book on the return leg. FISMA was that book. These comments are going to apply most directly to FISMA itself, based on what I learned reading Ms. Taylor's book. I'll save comments on the book itself for a later date. Last year I wrote FISMA is a joke. . I was wrong, and I've decided to revise my opinion. Based on my understanding of FISMA as presented in this book, FISMA is a jobs program for so-called security companies without the technical skills to operationally defend systems. This doesn't mean that if you happen to conduct FISMA work, you're definitelTy without technical skills. I guarantee my friends at ClearNet Security are solid guys, just based on their ability to detect the C&A project they joined was worthless. Anyway, I gu...

FISMA Dogfights

Image
My favorite show on The History Channel is Dogfights . Although I wore the US Air Force uniform for 11 years I was not a pilot. I did get "incentive" rides in T-37, F-16D, and F-15E jets as a USAFA cadet. Those experiences made me appreciate the rigor of being a fighter pilot. After watching Dogfights and learning from pilots who fought MiGs over North Vietnam, one on six, I have a new appreciation for their line of work. All that matters in a dogfight is winning, which means shooting down your opponent or making him exit the fight. A draw happens when both adversaries decide to fight another day. If you lose a dogfight you die or end up as a prisoner of war. If you're lucky you survive ejection and somehow escape capture. Winning a dogfight is not all about pilot skill vs pilot skill. Many of the dogfights I watched involved American pilots who learned enemy tactics and intentions from earlier combat. Some of the pilots also knew the capabilities of enemy aircr...

Why DIARMF, "Continuous Monitoring," and other FISMA-isms Fail

Image
I've posted about twenty FISMA stories over the years on this blog, but I haven't said anything for the last year and a half. After reading Goodbye DIACAP, Hello DIARMF by Len Marzigliano, however, I thought it time to reiterate why the newly "improved" FISMA is still a colossal failure. First, a disclaimer: it's easy to be a cynic and a curmudgeon when the government and security are involved. However, I think it is important for me to discuss this subject because it represents an incredible divergence between security people. On one side of the divide we have "input-centric," " control-compliant ," "we-can-prevent-the-threat" folks, and on the other side we have "output-centric," "field-assessed," "prevention eventually fails" folks. FISMA fans are the former and I am the latter. So what's the problem with FISMA? In his article Len expertly discusses the new DoD Information Assurance Risk...

Thoughts on New OMB FISMA Memo

Image
I read the new OMB memorandum M-10-15 , "FY 2010 Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Management." This InformationWeek article pretty well summarizes the memo, but I'd like to share a few thoughts. Long-time blog readers should know I've been writing about FISMA for five years, calling it a "joke," a "a jobs program for so-called security companies without the technical skills to operationally defend systems," and other kind words. Any departure from the previous implementation is a welcome change. However, it's critical to remember that control monitoring is not threat monitoring . Let's take a look at the OMB letter to see if we can see what is really changing for FISMA implementation. For FY 2010, FISMA reporting for agencies through CyberScope, due November 15, 2010, will follow a three-tiered approach: 1. Data feeds directly from security management tools 2. Government-wi...

FISMA 2006 Scores

Image
There are FISMA scores for 2006, along with 2005, 2004 , and 2003 -- some of which I discussed previously. What I wrote earlier still stands: Notice that these grades do not reflect the effectiveness of any of these security measurements. An agency could be completely 0wn3d (compromised in manager-speak) and it could still receive high scores. I imagine it is difficult to grade effectiveness until a common set of security metrics is developed, including ways to count and assess incidents. I still believe FISMA is a joke and a jobs program for so-called security companies without the technical skills to operationally defend systems. The only benefit I've seen from FISMA is that low-scoring agencies are being embarrassed into doing more certification and accreditation. C&A is a waste of time and money. However, if security staff can redirect some of that time and money into technical security work that really makes a difference, then FISMA is indirectly helping agencies w...

FISMA Is a Joke

Image
Thanks to SANS Newsbites I read the article FISMA Fizzles . I've written about FISMA before . The new article points me to a potential wise man who understands that FISMA is a joke: ex-Energy Department CIO Bruce Brody. This comment cut straight to the problem with FISMA: OMB's FISMA implementation basically boils security down to paperwork exercises, and score card pressure ensures it stays that way. But that's not how cybersecurity works; it requires real-time monitoring , updating and patching, Brody says, which isn't necessarily reducible to a paper trail. (emphasis added) Did I read "real-time monitoring"? Wow. Mr. Brody "gets it." Consider the alternative point of view: FISMA has its defenders. An agency fully compliant with FISMA is a secure agency, says Scott Charbo, Homeland Security Department CIO. The law and cybersecurity are "the same thing in my mind," he says. I see. Reading the DHS' grade history shows they ha...

Reviews of FISMA and Wireshark Posted

Image
Yes, you are reading that title correctly. After four months of inactivity I managed to read and review two new books. The first is FISMA by Laura Taylor. From my four star review : I am no fan of the FISMA law. I've posted several stories on my blog explaining why I think FISMA is a waste of taxpayer money. Laura Taylor's FISMA Certification and Accreditation Handbook, however, is a good book if you are unfortunate enough to be tasked with performing FISMA work. The second is Wireshark & Ethereal Network Protocol Analyzer Toolkit by Angela Orebaugh. From my four star review : Despite the new title, Wireshark & Ethereal Protocol Analyzer Toolkit (WEPAT) is a second edition of Ethereal Packet Sniffing (EPS). I reviewed that book almost three years ago, in May 2004. WEPAT has replaced all of the earlier screen captures with Wireshark replacements. Unfortunately, WEPAT is largely a repeat of EPS, really only featuring a new wireless chapter. If you own EPS, you don...

When FISMA Bites

After reading State Department to face hearing on '06 security breach I realized when FISMA might actually matter: combine repeated poor FISMA scores (say three F's and one D+) with publicly reported security breaches , and now Congress is investigating the State Department: In a letter sent to Secretary of State Condoleeza Rice on April 6, committee Chairman Bennie Thompson asked the department to provide specific information regarding how quickly department security specialists detected the attack, whether the department knows how long the attackers had access to the network and what other systems may have been compromised during the attack. The three-page letter also asks the department to provide evidence that it completely eliminated any malicious software the attackers may have planted, as well as documentation of all of the communications between State and the Department of Homeland Security regarding the incident. I'm going to keep an eye on the Subcommittee on E...

2004 US Government Security Report Card

Image
This is the US House Committee on Government Reform 2004 report card for US Federal government security. I wrote about the report for CY 2003 at the end of 2003 . The big news for this year's report card are the huge swings made by some agencies. Justice and Interior improved from F's to B- and C+, respectively, while State marginally moved out of the failing category by progressing from F to D+. Others regressed, some substantially; the NSF dropped from an A- to C+, Commerce from C- to F, and the VA from C to F. Overall, 7 out of 24 agencies received F's, balanced by 7 with B's or better. The "Report Grading Elements" ( http://reform.house.gov/UploadedFiles/2004%20FISMA%20Report%20Grading%20Element.pdf">.pdf ) used the following major categories to grade agencies: 1. The percentage of the agency's programs and systems reviewed, including contractor operations or facilities in FY04 by CIOs and IGs. 2. The degree to which agency program offi...

Initial Thoughts on Digital Security Hearing

Image
Several news outlets are reporting on the hearing I mentioned in my post When FISMA Bites . There following excerpts appear in Lawmakers decry continued vulnerability of federal computers : The network intrusions at State and Commerce follow years of documented failure to comply with the Federal Information Security Management Act (FISMA), which requires agencies to maintain a complete inventory of network devices and systems. Government and industry officials at the hearing acknowledged a disconnect between FISMA's intent and effecting improved network security. "The current system that provides letter grades seems to have no connection to actual security," said Rep. Zoe Lofgren, D-Calif. (emphasis added) WOW -- does Zoe Lofgren read my blog? Some lawmakers are considering whether the Department of Homeland Security should be given primary responsibility for overseeing federal network security, but officials at DHS and elsewhere suggested that wouldn't be the bes...

Consensus Audit Guidelines Are Still Controls

Image
Blog readers know that I think FISMA Is a Joke , FISMA Is a Jobs Program , and if you fought FISMA Dogfights you would always die in a burning pile of aerial debris. Now we have the Consensus Audit Guidelines (CAG) published by SANS . You can ask two questions: 1) is this what we need? and 2) is it at least a step in the right direction? Answering the first question is easy. You can look at the graphic I posted to see that CAG is largely another set of controls. In other words, this is more control-compliant "security," not field-assessed security. Wait, you might ask, doesn't the CAG say this? What makes this document effective is that it reflects knowledge of actual attacks and defines controls that would have stopped those attacks from being successful. To construct the document, we have called upon the people who have first-hand knowledge about how the attacks are being carried out. That excerpt means that CAG defines defensive activities that are believed to b...

Two Prereviews

Two publishers were kind enough to send new books last week. I plan to read and review both early next year. The first is Apress' Beginning C, 4th Ed by Ivor Horton. What, learn C? I don't expect or plan to become any C wizard by reading this and a few other books. Rather, I'd like to be able to understand code I come across, or perhaps make small modifications to otherwise useful programs. Any original programming I plan for 2007, I expect to use Python. Second is Syngress' FISMA Certification & Accreditation Handbook by Laura Taylor. Talk about moving from something useful (C) to something not (FISMA). Still, this seems like the only book on the subject, and FISMA is always a big discussion item at my local beltway bandit ISSA meetings. I hope this book will let me better understand the FISMA racket and why it's a waste of money. Of course, the book will not use those terms, but I will report what I find when I review it early next year.

Thoughts on Latest SANS Whitepaper

I read about the new SANS paper IT Security Industry Changes: Trouble on the Horizon (September 2006) (.pdf) in this NewsBites issue. Here are some excerpts and my reactions. Over the past six months, SANS Technology Institute's Stephen Northcutt has been gathering data and stories from security managers in more than 100 US organizations searching for patterns in job changes of security managers and the consultants who support them. The research was triggered by multiple emails from security managers who were facing reorganizations. His conclusions, albeit preliminary, paint a worrisome picture of job prospects for ill-equipped security managers, but also offer promise of some opportunities for success and advancement. That's an interesting project. Let's read more. [S]enior executives began to feel more comfortable voicing their frustration that they were wasting money paying for hugely expensive people and compliance reports that probably were not needed and that ofte...

FISMA 2007 Scores

Image
The great annual exercise of control-compliant security , the US Federal government 2007 FISMA report card , has been published. Since I've been reporting on this farce since 2003, I don't see a reason to stop doing so now. If you're the sort of sports fan who judges the success of your American football team by the height of the players, their 40-yard dash time, their undergraduate school, and other input metrics, you'll love this report card. If you've got any shred of sanity you'll realize only the scoreboard matters, but unfortunately we don't have a report card on that. Thanks to Brian Krebs for blogging this news item.

Soft Skills: The End is Nigh

I read the following in the latest SANS NewsBites : The lead story contains an important notification by Major General Lord of broad-based US federal IT security failure. As senior officials discover how bad federal security really is, they have begun looking for solutions (some are also looking for scapegoats.) The first and most important change they will make is to begin cutting budgets for policy and report writers, and transfer budget and responsibility to operational technical security projects and professionals who can actually protect their systems. The transformation has already begun. If you have soft skills (policy writing, security awareness, risk assessment, C&A report writing, etc.) and want to have great, long-term job prospects in security, it makes sense to move quickly to add hands-on technical skills so you can lead the teams of people who will be needed to turn the tide against the attackers. The "lead story" refers to this post . Alan Paller continues...

NoVA Sec Meeting 1930 Thu 31 Jan 08

Image
I was determined to start 2008 right by having a NoVA Sec meeting in January. Thursday night is our last chance, but thanks to last-minute coordination with Dowless and Associates we have a meeting location. The next NoVA Sec meeting will take place 1930 Thursday 31 January 2008 at Dowless and Associates: 13873 Park Center Rd. Suite 450 Herndon, VA 20171 Devin will speak and demo his One Laptop Per Child (OLPC) box. Our host is requesting a list of names of attendees, so please RSVP via email (taosecurity at gmail dot com) by end of day Wednesday 30 January 2008. Thank you. Remember, there are no dues and no requirements for membership. We do leave certifications, FISMA, the certification and accreditation (C&A) process, and related items in the parking lot. Note: I am only cross-posting this one NoVA Sec announcement because it has been a while since we held a NoVA Sec meeting. I will post future announcements only on the NoVA Sec blog and mailing list .

Feds Plan to Reduce, Then Monitor

Image
According to OMB directs agencies to close off most Internet links , by June 2008 the Federal government plans to reduce the number of Internet connections it maintains, and then monitor them more closely: The Office of Management and Budget's Trusted Internet Connections (TIC) initiative likely is to be the last publicized program in the Bush administration's stepped-up focus on cybersecurity, some experts say. More importantly, the new initiative requires agencies to implement real-time gateway monitoring , which has been a deficit in federal network protection. The TIC initiative mandates that officials develop plans for limiting the number of Internet connections into their departments and agencies. OMB officials want to reduce the number of gateways from the more than 1,000 to about 50, said Karen Evans, OMB's administrator for e-government and information technology. (emphasis added) This sounds promising. The story continues: The initiative also asks chief informat...

What Should the Feds Do

Recently I discussed Federal digital security in Initial Thoughts on Digital Security Hearing . Some might think it's easy for me to critique the Feds but difficult to propose solutions. I thought I would try offering a few ideas, should I be called to testify on proposed remedies. For a long-term approach, I recommend the steps offered in Security Operations Fundamentals . Those are operational steps to be implemented on a site-by-site basis, and completing all of them across the Federal government would probably take a decade. In the short term (over the next 12 months) I recommend the following. These ideas are based on the plan the Air Force implemented over fifteen years ago, partially documented in Network Security Monitoring History along with more recent initiatives. Identify all Federal networks and points of connectivity to the Internet. This step should already be underway, along with the next one, as part of OMB IPv6 initiative . The Feds must recognize the s...

FCW on Comprehensive National Cybersecurity Initiative

Image
Brian Robinson's FCW article Unlocking the national cybersecurity initiative caught my attention. I found these excerpts interesting, although my late 2007 article Feds Plan to Reduce, Then Monitor discussed the same issues. The cybersecurity initiative launched by the Bush administration earlier this year remains largely cloaked in secrecy, but it’s already clear that it could have a major and far-reaching effect on government IT operations in the future. Everything from mandated security measures and standard desktop configurations across government to a recast Federal Information Security Management Act (FISMA) could influence the way agencies buy and manage their IT. Overseeing all of this will be a central office run by the Homeland Security Department, the first time that the government’s efforts in cybersecurity will run through a single office tasked with coordinating the work of separate federal cybersecurity organizations... [First was the] creation of a National Cybe...

Human Weapon

Image
In FISMA Dogfights I mentioned my favorite show on the History Channel is Dogfights . A very close second, if not an equal, is the new series Human Weapon . I don't recall another regular television series devoted exclusively to martial arts. If you wonder why I bother posting about a martial arts show, see my post Fight to Your Strengths . On a related subject, based on other stories in the security blogosphere, I expect to see a martial arts rumble at the next Black Hat in 2008. I better get my shoulder fixed and start training again.