Welcome to cissp CISSP training Certified Information Systems Security Professional
Search
Nickname Password Security Code Security Code Type Security Code  

Best training in the world

FITSI the certification program for the federal workforce

Rated #1 Training

Best hacking and penetration testing  magazine in the world

Surveys

Where do you find the best price for books?

Amazon.Com
Bookpool.Com
The ISC2 webstore
CISSPS.COM
Cheapbooks.com
Ecampus.com
Other (Please leave a comment with name of site)



Results
Polls

Votes 1758

Who's Online

There are currently, 46 guest(s) and 5 member(s) that are online.

You are Anonymous user. You can register for free by clicking here

FISMA compliance made easier with OpenFISMA
Posted on Tuesday, 28 October 2008 @ 20:30:12 EDT
Contributed by boss | Topic: Law & Legalities

FISMA compliance made easier with OpenFISMA
Scott Sidel, Contributor
10.27.2008

Managing security in a large corporation can be daunting, which is why the U.S. government has made a concerted effort to standardize best security practices. The Federal Information Security Management Act (FISMA) not only mandates the processes for information systems used by federal agencies and by contractors working with the government, but also provides an excellent security baseline for any large organization.

From an information security perspective, the first step in implementing FISMA guidelines involves gaining an understanding of the processes FISMA mandates, Then, practitioners typically rely on NIST publications, which guide security personnel through the baseline security requirements, detailing the more specific technical and operational controls needed to meet those requirements. Managing the compliance process can quickly become a challenge, however, because working with multiple parties on a broad range of controls overwhelms the typical spreadsheet and manual tracking process.

OpenFISMA can help: it automates the compliance process by using a platform-independent OSS Web application framework (Apache, MySQL, PHP) to manage the workflow. OpenFISMA also guides requirements-gathering activities, such as verifying compliance with requirements, security assessments and vulnerability remediation.

To better understand how OpenFISMA can improve security, one example is the processes associated with a plan of actions and milestones (POA&M), which are the activities used for tracking and fixing security vulnerabilities. OpenFISMA provides a Web-based centralized repository to manage and track vulnerability reporting and remediation activities. Users log in to their role-based accounts to work through or oversee the compliance processes. Typical users would be the security officer (CSO or CISO), technical operations staff and the independent verifiers.

OpenFISMA's business rules provide guidance for the submission of remediation evidence and sign-off for the work performed. The user controls protect the integrity of the audit information from unauthorized access, modification and deletion. Timestamps support the ability to audit and account for each of the steps, and a reporting engine helps track performance against stated completion goals.

Learn how penetration testing can aid compliance efforts

Find out about open-source IDS audit tools

When using OpenFISMA, information about security weaknesses can be entered manually or ingested from automated sources by using popular vulnerability assessment scanners that output their results in XML, CSV or XLS formats. A known vulnerability then follows one of three typical paths: a) the finding is remediated, b) the finding is demonstrated to be a false positive, or c) the risk is accepted. A risk level can be assigned to help prioritize the level of threat to the organization and the mitigation strategy can be reviewed and approved by independent third parties. After the work to remediate the weakness is done, evidence for the remediation can be analyzed by third-party verifiers. Finally, assuming the remediation is accepted, the verifiers would close out the weakness.

Implementing government standards for security can be a huge task, but OpenFISMA provides structure and automation to help manage the process.

About the author:
Scott Sidel is an ISSO with Lockheed Martin.
For more recommendations from the author, check out Scott Sidel's Downloads


Login

Nickname

Password

Security Code:
Security Code
Type Security Code

Don't have an account yet? You can create one. As a registered user you have some advantages like theme manager, comments configuration and post comments with your name.

Related Links

· More about Law & Legalities
· News by boss


Most read story about Law & Legalities:
California sets fines for spyware

Article Rating

Average Score: 5
Votes: 2

Average Score

Please take a second and vote for this article:

Excellent
Very Good
Good
Regular
Bad

Options


Re: FISMA compliance made easier with OpenFISMA (Score: 1)
by al7orya on Friday, 30 October 2009 @ 05:26:48 EDT
(User Info | Send a Message)

<a href=" http://www.al7orya.com/book/indexcat-21.html/">طبيخ</a [www.al7orya.com]>
<a href=" http://www.al7orya.com/book/indexcat-21.html/">كتب [www.al7orya.com] وصفات اكل شهية</a>
<a href=" http://www.al7orya.com/book/indexcat-21.html/">أكل [www.al7orya.com] وحلويات وكتب للمطبخ</a>
<a href=" http://www.al7orya.com/book/indexcat-22.html/">كتب [www.al7orya.com] وابحاث ودراسات حول اليهودية و النصرانية</a>
<a href=" http://www.al7orya.com/book/indexcat-22.html/">دراسات [www.al7orya.com] حول اليهودية </a>
<a href=" http://www.al7orya.com/book/indexcat-22.html/ [www.al7orya.com]"> النصرانية</a>
<a href=" http://www.al7orya.com/book/indexcat-23.html/">كتب [www.al7orya.com] زراعية وتربية دواجن وطيور ومشاريع</a>
<a href=" http://www.al7orya.com/book/indexcat-23.html/">تربية [www.al7orya.com] دواجن وطيور</a>
<a href=" http://www.al7orya.com/book/indexcat-23.html/">كتب [www.al7orya.com] زراعية</a>
<a href=" http://www.al7orya.com/vb/t19552.html#post100282/">حصريا [www.al7orya.com] 1000 صورة وفريم للفوتوشوب لتواقيع وشهادات التقدير صور png</a>
<a href=" http://www.al7orya.com/dl/add-site.html/">اضف [www.al7orya.com] موقعك</a>
<a href=" http://www.al7orya.com/dl/add-site.html/">اضافة [www.al7orya.com] موقعك</a>
<a href=" http://www.al7orya.com/dl/add-site.html/">موقعك</a [www.al7orya.com]&g

Read the rest of this comment...




Re: FISMA compliance made easier with OpenFISMA (Score: 1)
by al7orya on Friday, 30 October 2009 @ 05:27:44 EDT
(User Info | Send a Message)

<a href=" http://www.al7orya.com/vb/f90.html/">الطفل [www.al7orya.com] المسلم </a>
<a href=" http://www.al7orya.com/vb/f90.html/">الطفل [www.al7orya.com] الفلسطيني </a>
<a href=" http://www.al7orya.com/vb/f90.html/">مواضيع [www.al7orya.com] عن الطفولة </a>
<a href=" http://www.al7orya.com/vb/f90.html/">اناشيد [www.al7orya.com] الاطفال </a>
<a href=" http://www.al7orya.com/vb/f90.html/">الاطفال [www.al7orya.com] </a>
<a href=" http://www.al7orya.com/vb/f90.html/">الطفل [www.al7orya.com] العربي</a>
<a href=" http://www.al7orya.com/vb/f59.html/">قصص</a [www.al7orya.com]>
<a href=" http://www.al7orya.com/vb/f59.html/">قصص [www.al7orya.com] وروايات</a>
<a href=" http://www.al7orya.com/dl/">دليل [www.al7orya.com] مواقع </a>
<a href=" http://www.al7orya.com/dl/">دليل [www.al7orya.com] مواقع </a>
<a href=" http://www.al7orya.com/dl/">دليل [www.al7orya.com] مواقع </a>
<a href=" http://www.al7orya.com/dl/">دليل [www.al7orya.com] مواقع </a>
<a href=" http://www.al7orya.com/dl/">دليل [www.al7orya.com] مواقع </a>
<a href=" http://www.al7orya.com/dl/">دليل [www.al7orya.com] مواقع </a>
<a href=" http://www.al7orya.com/dl/">دليل [www.al7orya.com] مواقع </a>
<a href=" http://www.al7orya.com/vb/f71.html/">رجلا [www.al7orya.com] صنعوا التاريخ</a>
<a href=" http://www.al7orya.com/vb/f71.html/">رجال [www.al7orya.com] علما&#15

Read the rest of this comment...




Re: FISMA compliance made easier with OpenFISMA (Score: 1)
by al7orya on Friday, 30 October 2009 @ 05:28:53 EDT
(User Info | Send a Message)

<a href=" http://www.al7orya.com/dl/section-36.html/">دليل [www.al7orya.com] مواقع نسائية</a>
<a href=" http://www.al7orya.com/dl/section-36.html/">مواقع [www.al7orya.com] نسائية</a>
<a href=" http://www.al7orya.com/dl/section-37.html/">دليل [www.al7orya.com] الأطفال</a>
<a href=" http://www.al7orya.com/dl/section-37.html/">مواقع [www.al7orya.com] اطفال</a>
<a href=" http://www.al7orya.com/dl/section-38.html/">اناشيد</a [www.al7orya.com]>
<a href=" http://www.al7orya.com/dl/section-38.html/">دليل [www.al7orya.com] مواقع الاناشيد</a>
<a href=" http://www.al7orya.com/dl/section-40.html/">ترفيه [www.al7orya.com] وتهنئة</a>
<a href=" http://www.al7orya.com/dl/section-40.html/">بطاقات [www.al7orya.com] تهنئة</a>
<a href=" http://www.al7orya.com/dl/section-39.html/">دليل [www.al7orya.com] المأكولات والطبيخ</a>
<a href=" http://www.al7orya.com/dl/section-39.html/">مواقع [www.al7orya.com] طعام وحلويات</a>
<a href=" http://www.al7orya.com/dl/section-42.html/">العاب [www.al7orya.com] </a>
<a href=" http://www.al7orya.com/dl/section-42.html/">دليل [www.al7orya.com] مواقع الالعاب</a>
<a href=" http://www.al7orya.com/dl/section-41.html/">مواقع [www.al7orya.com] نكت وضحك</a>
<a href=" http://www.al7orya.com/dl/section-41.html/">دليل [www.al7orya.com] مواقع الترفيه</a>
<a href=" http://www.al7orya.com/dl/sec

Read the rest of this comment...




Re: FISMA compliance made easier with OpenFISMA (Score: 1)
by al7orya on Friday, 30 October 2009 @ 05:29:40 EDT
(User Info | Send a Message)

<a href=" http://www.al7orya.com/radio/">اذاعة [www.al7orya.com] عشاق الحور</a>
<a href=" http://www.al7orya.com/radio/">اذاعة [www.al7orya.com] اسلامية بث مباشر</a>
<a href=" http://www.al7orya.com/radio/">اذاعة [www.al7orya.com] من الاقصى والقدس</a>
<a href=" http://www.al7orya.com/radio/">اذاعات [www.al7orya.com] فلسطينية اسلامية</a>
<a href=" http://www.al7orya.com/group/">قروب [www.al7orya.com] ملتقيات عشاق الحور</a>
<a href=" http://www.al7orya.com/group/">قروب [www.al7orya.com] ملتقيات عشاق الحور</a>
<a href=" http://www.al7orya.com/group/">قروب [www.al7orya.com] ملتقيات عشاق الحور</a>
<a href=" http://www.al7orya.com/book/indexcat-17.html/">بحوث [www.al7orya.com] إسلامية</a>
<a href=" http://www.al7orya.com/book/indexcat-17.html/">بحوث [www.al7orya.com] إسلامية</a>
<a href=" http://www.al7orya.com/book/indexcat-18.html/">أبحاث [www.al7orya.com] اجتماعية وعائلية</a>
<a href=" http://www.al7orya.com/book/indexcat-18.html/">أبحاث [www.al7orya.com] اجتماعية وعائلية</a>
<a href=" http://www.al7orya.com/book/indexcat-19.html/">ابحاث [www.al7orya.com] جغرافية وبيئية</a>
<a href=" http://www.al7orya.com/book/indexcat-19.html/">ابحاث [www.al7orya.com] جغرافية وبيئية</a>
<a href="Read the rest of this comment...




Re: FISMA compliance made easier with OpenFISMA (Score: 1)
by al7orya on Friday, 30 October 2009 @ 05:30:28 EDT
(User Info | Send a Message)


<a href=" http://www.al7orya.com/dl/section-2.html/">القرآن [www.al7orya.com] الكريم </a>
<a href=" http://www.al7orya.com/dl/section-3.html/">الحديث [www.al7orya.com] الشريف </a>
<a href=" http://www.al7orya.com/dl/section-4.html/">العلماء [www.al7orya.com] والدعاة </a>
<a href=" http://www.al7orya.com/dl/section-5.html/">الفرق [www.al7orya.com] والمذاهب والأديان </a>
<a href=" http://www.al7orya.com/dl/section-6.html/">المجلات [www.al7orya.com] والتسجيلات الإسلاميه </a>
<a href=" http://www.al7orya.com/dl/section-7.html/">الكتب [www.al7orya.com] الإسلامية </a>
<a href=" http://www.al7orya.com/dl/section-8.html/">الفتاوى [www.al7orya.com] </a>
<a href=" http://www.al7orya.com/dl/section-9.html/">الصوتيات [www.al7orya.com] الإسلامية </a>
<a href=" http://www.al7orya.com/dl/section-74.html/">مواقع [www.al7orya.com] البرامج </a>
<a href=" http://www.al7orya.com/dl/section-21.html/">مواقع [www.al7orya.com] كمبيوتر عامة </a>
<a href=" http://www.al7orya.com/dl/section-22.html/">اخبار [www.al7orya.com] ومجلات الكمبيوتر </a>
<a href=" http://www.al7orya.com/dl/section-23.html/">البرامج [www.al7orya.com] وانظمة التشغيل </a>
<a href=" http://www.al7orya.com/dl/section-24.html/">الرسم [www.al7orya.com] والتصميم - الجراف&#16

Read the rest of this comment...




uggs outlet (Score: 1)
by uggsmall123 on Saturday, 26 June 2010 @ 00:07:30 EDT
(User Info | Send a Message)

Uggsmall is Uggs outlet [www.uggsmall.com] which offer 100% authentic cheap ugg boots [www.uggsmall.com].The hot selling Uggs on sale [www.uggsmall.com] Shoes for your selection. Have a try on the Uggs Australia [www.uggsmall.com]




All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2007 by CCCure.Org, and the site maintainers Clement Dupuis and Nathalie Lambert. Reuse is strictly prohibited without written permission of CCCure.Org or it's maintainers.

This web site is not associated directly or indirectly with ISC2, the SANS Institute, ISACA, or other certification authority. The GCFW, CISSP, SSCP, ISSEP, ISSMP, CISA, and CISM are all the property of their respecful owners. The content of this site is provided to you freely due to the generosity of our sponsors.


  • Career
  • Magazines
  • Conferences
  • Study Books
  • Certifications
  • Training
  • Tutorials
  • Quizzes
  • Forums

  • Page Generation: 1.99 Seconds