Posts Tagged ‘ fisma ’

Weekly Rewind – CISSP Value, Monthly Continuous Monitoring, Mobile Average Practices, & More

September 24, 2011
By
Weekly Rewind – CISSP Value, Monthly Continuous Monitoring, Mobile Average Practices, & More

Here’s another addition of the Weekly Rewind, where we post out a quick summary of all our stories as well as the industry articles you seemed to like the most from the past week. If you missed anything or happened to be offline, we hope you find this post useful as a quick reference....
Read more »

Tags: , , , , , , , , , , , , ,
Posted in Infosec Blogs/Podcasts, News | 1 Comment »

Will New Monthly “Continuous” Monitoring FISMA Requirements Work?

September 21, 2011
By
Will New Monthly “Continuous” Monitoring FISMA Requirements Work?

According to GovInfoSecurity as well as several other publications, starting next month federal agencies will be required to implement continuous monitoring as part of their obligations under FISMA. At a minimum “continuous” is defined as monthly. All of their reported data needs to be fed into the CyberScope system. Oh and for training and...
Read more »

Tags: , , , ,
Posted in News | 5 Comments »

Feds and Amazon Web Services

August 26, 2011
By
Feds and Amazon Web Services

Yesterday, I posted my thoughts on Amazon’s new GovCloud announcement. Although it offers a huge step in the right direction, there is still a lot of ground work that needs to be done in most cases. Someone that’s a bit more read in this whole area is local blogger Chris “@cyberhiker” Burton. You may...
Read more »

Tags: , , , , , , , , ,
Posted in Infosec Blogs/Podcasts, News | 2 Comments »

Thoughts on Amazon’s GovCloud

August 25, 2011
By
Thoughts on Amazon’s GovCloud

If you haven’t heard by now, Amazon recently announced a new self-contained cloud region specifically customized for U.S. government customers. Think of it as their normal set of services (e.g., EC2, S3, etc.) but set up in their own special area only accessible to U.S. persons. They aren’t the first cloud provider to claim...
Read more »

Tags: , , , , , , ,
Posted in News | 2 Comments »

Are New NIST Privacy Controls Necessary?

July 21, 2011
By
Are New NIST Privacy Controls Necessary?

In case you missed the announcement on Tuesday, National Institute of Standards and Technology (NIST) has released a draft of new privacy controls to be included in the next update of Special Publication (SP) 800-53. Currently referred to as SP 800-53 Appendix J, the update provides the first steps to standardizing what privacy means...
Read more »

Tags: , , , , ,
Posted in News | 3 Comments »

Clouds, FISMA, and the Lawyers

April 28, 2011
By
Clouds, FISMA, and the Lawyers

Mike “@rybolov” Smith just posted his thoughts on the recent Microsoft/Google FISMA “certification” story from last week. Thought some of you might find this interesting. Personally, I think Google misrepresented their new email service. Even though it is based on an existing service that has an Authority to Operate (ATO), that does not mean...
Read more »

Tags: , , , ,
Posted in Infosec Blogs/Podcasts | No Comments »

Reinventing FedRAMP

February 15, 2011
By
Reinventing FedRAMP

For those that haven’t heard GSA has been quickly pushing the Federal Risk and Authorization Management Program (FedRAMP) out the door with the goal of accrediting common cloud-based solutions that agencies can develop on top of. In this post from The Guerilla CISO, Mike “@rybolov” Smith takes on FedRAMP discussing the pros, cons, and...
Read more »

Tags: , , , , ,
Posted in Infosec Blogs/Podcasts | 1 Comment »

Old Saint NIST: Ho Ho Hold on, what’s this?

December 14, 2009
By

Every once in a while an opportunity presents itself to affect some real change in federal information security practice.  Now is such a time.  A slew of new NIST documents are being released between now and April.  These are the core NIST documents that describe how to satisfy FISMA. They include NIST SPs 800-30 Revision...
Read more »

Tags: , , , , , , ,
Posted in Infosec Blogs/Podcasts | 1 Comment »

Reminder: ISACA – NCA Chapter Infosec Meetup Event is Tomorrow, 05-12

May 11, 2009
By

Just a quick reminder that the ISACA – National Capital Area (NCA) Chapter infosec meetup event is tomorrow, May 12th. For more information about the ISACA – National Capital Area (NCA) Chapter, see its description in our Infosec Meetups section. View our Calendar for a list of similar infosec events in and around the NoVA area. See our original...
Read more »

Tags: , , , , , , , ,
Posted in NoVA Meetups | No Comments »

ISACA – NCA Chapter Infosec Meetup Event – Tuesday, 05-12: Security Management

May 8, 2009
By

This week’s ISACA – National Capital Area (NCA) Chapter meetup will cover trends, perspectives, and practices in Federal Information Security Management. According to the ISACA – NCA Chapter website, “hether you are directly impacted by the Federal Information Security Management Act (FISMA) or otherwise responsible for designing, managing, or auditing information system controls, this event is...
Read more »

Tags: , , , , , , , ,
Posted in NoVA Meetups | No Comments »

Search

Current Poll

Should We Change Our Name to NovaInfosec.com?

  • Yes, change the name to NovaInfosec.com. (91%, 10 Votes)
  • No, keep it the way it's always been at NovaInfosecPortal.com. (9%, 1 Votes)

Total Voters: 11

Loading ... Loading ...