(ISC)² Twitter Updates

  • (ISC)² Twitter Updates

    About the
    (ISC)² Blog

    • (ISC)² believes in the importance of open dialogue and collaboration, between both (ISC)², its certified members and members of business and society.

      (ISC)² established this blog to provide a voice to its certified members, who have significant knowledge and valuable insights to share that can benefit the information security industry, the people in it and the public at large.

      The postings on this site are the author's own and don't necessarily represent
      (ISC)²'s positions, strategies or opinions. (ISC)² does not control, monitor, or endorse any links provided in this blog and makes no warranty or statement regarding the content on any linked website.

      Those who post comments to blogs should ensure their comments are focused on the topic at hand. (ISC)² reserves the right to remove any post or comment from this site.

      Should you find objectionable content in this blog, please notify us as soon as possible at blog@isc2.org.

      Please click here for FAQs.

      Please click here for the Blog guidelines.

    Enter your email address:

    Delivered by FeedBurner

    « On the Internet, No-one Knows you're a Hog... | Main | The Top Ten Cybersecurity Threats for 2008 Revisited »

    30 May 2008

    TrackBack

    TrackBack URL for this entry:
    http://www.typepad.com/services/trackback/6a00e54f109b67883400e552a525108834

    Listed below are links to weblogs that reference FISMA – Is Something Missing?:

    Comments

    As far as I am concerned, there are several problems with how FISMA has been implemented. There is needs to be more standardization on what is truly required. Right now, the C&A is very cumbersome. It is more of a measurement of compliance to policy rather than the true status of a system's security. In addition, there is a lot of duplication of effort in the documentation required.

    We need to streamline the C & A processes. Currently, it takes several months and hundreds of thousands of dollars to accredit a system. After is it all done, the information in the documentation may already be outdated.

    "IT security is not an exact science because not all environmental characteristics that affect security can be completely relieved of risk."

    I will start by saying that there is no silver bullet in IT Security, who believes that there is a total risk mitigation for IT does not understand risk management and theconcept of integrating IT in the business model (IT Governance)

    "Management of the risk requires proven measurements to demonsrate security can be adequately managed, if properly planned and implemented. "
    Not sure what is the meaning of this statement but I can say that the management of ANYTHING requires using metrics. Metrics do not prove that a security implementation can be managed...

    The comments to this entry are closed.

    The (ISC)² bloggers

    • Tipton W. Hord Tipton, CISSP-ISSEP, CAP, (ISC)² Executive Director
      Schmidt Prof. Howard A. Schmidt, CISSP, CISM (Hon.)
      Sarah E. Bohne, Director of Communications & Member Services

    Recent Contributors

    Past Contributors