We put the fun in federally funded.
New motto for the Policy, Assurance, and Risk Management function of LBL.
Labels: fisma
Office of the Liaison Policy Blog for Information Technology Policy issues at LBL including FISMA, Clinger-Cohen, Enterprise Architecture, University of California IT Policy, Security, Cybersecurity, and more. Disclaimer: Some components of this blog may not represent the official position of the University or the CIO and they most certainly do not represent the position of the DOE.
New motto for the Policy, Assurance, and Risk Management function of LBL.
Labels: fisma
Basically every law before FISMA rationally makes a distinction between National Labs and Feds. FISMA does too, it's just that everyone behaves as if it's not true.
Labels: agency, clinger cohen, fisma, pra
I'm in DC for the NSF Large Facilities Security conference. Excellent keynotes this morning (if a little depressing) and an enjoyable roundtable going on now. More on these a bit later, but in the meantime, here is the entirety of the NSF regulation on cyber security:
Labels: doe nsf, fisma, laboratories
Steve Lau and my talk at Internet2, NIST It By That Much, is looking more perceptive by the day. The Department of Energy Office of the CIO has released hundreds of page of new draft policy which, in my opinion, misunderstands NIST in precisely the way we described: it fails to recognize that the NIST documents create a baseline of controls from which you as the system owner are supposed to tailor your set of controls, NIST 800-53 is a baseline, not a set of minimum security standards for all systems.
Labels: ca, doe, federal policy, fisma
The OIG has a draft out of their Audit of the Department's websites. Unfortunately, the cover letter asks that the draft not be shared. However, our response to the draft report can be shared (or in this case summarized).
Interesting article in Science this week reporting on a study in JAMA on the impact of the HIPAA Privacy Rule on Epidemiological researchers:
Labels: cyber security policy, fisma, hipaa
The DOE through its DAA, the Manager of the BSO, has granted all five lbl enclaves new Authorities to Operate good for three years. This was the penultimate step in what was basically a two year long process throughout the Office of Science, led by SC SIME Mike Robertson, to not only improve cyber security throughout the DOE Office of Science, but to improve it in a way that truly takes advantage of the unique risks, capabilities, and missions of the various Office of Science sites, while still maximizing the similarities of the approach to documentation and risk-assessment.
Labels: ATO, ca, certification, fisma
Certification and Accreditation process is proceeding apace. The external auditors are completing their assessment and our documentation is nearly done.
Labels: ca, certification, compliance, fisma, is-3, ucop
The auditors we hired to perform our external Security Test and Evaluation for our C&A were onsite last week for the second phase of their testing. Things seem good and we await their final report.
Labels: fisma