Archive for category Information Assurance
Security Guidance for Critical Areas of Focus in Cloud Computing
Posted by Shahid N. Shah in Cloud Computing, Information Assurance on May 7th, 2009
The Cloud Security Alliance was recently formed to “promote the use of best practices for providing security assurance within Cloud Computing, and provide education on the uses of Cloud Computing to help secure all other forms of computing.” Their first publication is out and is worth reviewing.
Managing FISMA compliance with OpenFISMA tool
Posted by Shahid N. Shah in Government 2.0, Information Assurance, Tools on May 4th, 2009
As architects working on federal projects we spend a ton of time on security practices and FISMA compliance. Implementing FISMA guidelines involves lots of manual tracking of dozens of steps and checks across various groups. I was pleased to run across OpenFISMA recently because it helps automate some of the manual steps in FISMA compliance by using a LAMP-based application to manage the process. OpenFISMA also guides requirements-gathering activities, such as verifying compliance with requirements, security assessments and vulnerability remediation. Here’s the description of the tool from their website:
The OpenFISMA project is an open source application designed to reduce the complexity and automate the regulatory requirements of the Federal Information Security Management Act (FISMA) and the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF).
OpenFISMA contains many of the NIST SP 800-53 security controls required for a FIPS-199 "high" impact information system. This helps you get your OpenFISMA instance authorized to operate quickly. The built-in controls include system use notification, rules of behavior, electronic privacy policy (p3p), and many, many more.
OpenFISMA also contains a catalog of all NIST SP 800-53 Rev. 2 controls built-in. Findings in OpenFISMA can be matched against these security controls to provide supplemental information for remediation and planning. The catalog includes descriptions of the controls, scoping, and supplemental guidance.

Recent Comments