Find White Papers
Home
About Us
List Your Papers
    
> Tripwire > Automating FISMA Compliance with Tripwire

Automating FISMA Compliance with Tripwire

White Paper Published By: Tripwire

Learn how Tripwire can help you deploy a comprehensive configuration assessment and control solution that: a) reduces the time and resources required to verify compliance and prepare for audits; and b) maintains continuous compliance by allowing IT to immediately identify any exceptions and trigger remediation of configurations that do not conform to policy.



Tags : 
tripwire, automate, fisma, compliance, configuration, assessment, solution, audit

Tripwire
Published:  Jun 30, 2009
Type:  White Paper
Length:  17 pages

Automating FISMA
Compliance with Tripwire
white paper
Configuration Control for Virtual and Physical InfrastructuresContents
Contents 3 Introduction 3 Challenges 4 Meeting FISMA Requirements 5 Ensuring Compliance with Tripwire Configuration Control Solutions 6 Evidence of Effectiveness
2 | WHITE PAPER | Automating FISMA Compliance with TripwireIntroduction
Since the enactment of the Federal Information Security concept of unambiguous personal accountability for agency Management Act (FISMA) in 2002, federal agencies have residual risk.been required to develop, document and implement agency-wide information security programs to protect the Challengesconfidentiality, integrity and availability of the data and systems that support government operations and assets. While NIST is the doorway to information on what is Foundations, educational institutions, and other organiza- required by FISMA, generating, collecting, understand-tions that have system connections with a federal agency, ing and reporting FISMA results each year remains tedious as well as private contractors worldwide and state, regional, and time-consuming-often requiring complicated, manual local or tribal agencies that store, process or transmit data processes. With no streamlined way to integrate all of the from a federal agency, must comply with FISMA as well. data coming in from various sources and solutions, agencies FISMA is codified in a number of standards and guidance use various methods to collect the required security data, documents produced by the National Institute of Standards including databases, spreadsheets and other documents. and Technology (NIST). Included among them are FIPS- Audit preparation time is equally time-consuming and 199, the Standards for Security Categorization of Federal expensive. Demonstrating FISMA compliance requires enor-Information and Information Systems. FIPS-199 defines the mous effort, budget and IT resources, all of which take away requirements to be used by federal agencies in categorizing from an agency's primary work. The Office of Budget and information and information systems in order to provide Management (OMB) reported agencies spent approximately appropriate levels of information security for a range of $5.5 billion in fiscal year 2006 to meet FISMA requirements. risk levels. The standard establishes three levels of protec- It is predicted that to maintain compliance with FISMA, tion requirements-low, moderate, and high-for each of agencies will require upwards of $27.9 billion between 2008 the security objectives of confidentiality, integrity, and and 2012. The challenge of setting appropriate priorities availability. and allocating scarce funds to compliance activities will Implemented in March 2006, FIPS-200, Minimum Security continue to be faced by department heads throughout the Requirements for Federal Information and Information federal government. Systems, took an important next step. FIPS-200 requires Unfortunately, so far, according to the 2007 Federal agencies to use the FIPS-199 standards for system catego- Computer Security Report Card, many agencies are still rization, and then select an appropriate set of security receiving failing grades. What's more, a passing grade is no controls from Special Publication (SP) 800-53, Recommended guarantee your agency's data is secure. FISMA can't mandate Security Controls for Federal Information Systems. This a secure IT system, Instead it intends to achieve that state document provides federal agencies with a foundation for by requiring adherence to a common process for assessing, understanding security controls and their use within an testing and managing IT security. In these early years of information security program. FISMA's adoption, what's really being graded is the quality NIST SP800-53 is designed to help federal agencies more of compliance efforts, which is only indirectly linked to the easily comply with FISMA by removing any debate over quality of security practices.which controls must be implemented and to what level of Meanwhile, software vulnerabilities increase every year. operational assurance. Together, the FISMA requirements According to IBM Internet Security Systems, software vul-and NIST technical guidance documents are emerging as a nerabilities increased 45.9% in 2004, 12.8% in 2005 and world-class framework for achieving and maintainin... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search