"Continuous monitoring," a phrase coined under the federal government's FISMA guidelines, refers to the shift from paper reports on federal agency's cybersecurity posture to an online reporting system. Earlier this month, FISMA reporting requirements were increased from annual to monthly (PDF) as part of the effort to force agencies into more automated, online security monitoring and reporting.
"The move to monthly reporting was [former federal CIO] Vivek Kundra's effort to make it impossible to do security reporting as a bureaucratic exercise," says Mike Lloyd, chief scientist at RedSeal Systems, which makes security monitoring tools. "If you're doing it monthly, you can't do it with people pushing paper. He was trying to make reporting difficult enough to force agencies to move to automation."
Reports issued this month suggest that such a kick in the pants is sorely needed among federal agencies, which have been slow to implement continuous monitoring guidelines and the federal Cyberscope tools, which are designed to help automate the monitoring and reporting processes.
A study published this month by InformationWeek indicates that nearly half of federal IT pros are unaware of continuous monitoring requirements.
In another report issued this month, the Government Accountability Office (GAO) identified weaknesses in 17 of 24 agencies’ fiscal year 2010 efforts for continuous monitoring (PDF).
And in a third report (PDF) issued last week, the government watchdog Center for Regulatory Effectivenes (CRE) recognizes the lack of compliance with continuous monitoring requirements and outlines a set of best practices for implementing them, as exemplified by initiatives at NASA.
Of the three reports, the GAO study offers the most specifics on the deployment of continuous monitoring technology. In its investigation of 24 agencies, the GAO reported that two have not established a continuous monitoring program at all, and 15 of the agencies that have initiated a program had weaknesses in their implementations.
"These weaknesses included, for example, that continuous monitoring procedures were not fully developed or consistently implemented at 11 agencies," the report states. "In another example, 10 inspectors general cited weaknesses in ongoing assessments of selected security controls. Inspectors general at nine agencies reported that information, such as status reports covering continuous monitoring results, was not provided to key officials."
The GAO report not only cites issues with reporting security posture, but also with agencies' ability to take action based on their findings: "For example, 18 of 24 inspectors general reported that their agency had weaknesses in its configuration management programs, and 16 indicated their agency’s patch management processes for mitigating software flaws were not fully developed."
This issue is at the heart of the continuous monitoring problem, says Bruce Levinson, editor of FISMA Focus and author of the CRE's report on continuous monitoring.
"The agencies have to have a plan for the use of continuous monitoring data," Levinson says. "The question is not just how to collect the data, but how to use it to make better decisions about security. If agencies are not doing that, then this whole thing needs to be rethought."
Joe Gottlieb, CEO of security information and event monitoring vendor Sensage, agrees. "The data collection is important, but if agencies hope to truly improve security, they will have to be more proactive in how they analyze it," he says. "It's the analysis of the data that will help them find that user who's collecting unusual amounts of information and might be an insider threat."
So why aren't agencies moving more quickly toward continuous monitoring? Some experts say one big problem is federal contractors that have built big businesses supporting the paper process -- and are dragging their feet because they don't want to give up those businesses.
"Many of the agency heads have been part of the paper compliance process for a long time, and they resist the change," Levinson says. "On the contractor side, there has been a big pushback from those who have a vested interest in keeping the process the way it was."
"Federal contractors have been making big money doing policy review, and they don't want to give it up," says Tom Kellermann, CTO of AirPatrol, a mobile security vendor that does much of its business with the federal government. "But automation is clearly the answer long-term."
Have a comment on this story? Please click "Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
Security Via HIPAA Compliance
IT organizations in the healthcare industry can make tremendous progress on security initiatives using the HIPAA Security Rule for leverage. Here are some insights on how compliance initiatives can be the catalyst you need to build out your organization's IT security program.
Security via SOX Compliance
The effort to achieve and maintain compliance with Sarbanes-Oxley requirements remains one of the primary drivers behind many IT security initiatives. In this report, we share 10 best practices to meet SOX security-related requirements and help ensure you'll pass your next compliance audit.
Security via PCI Compliance? Yes, If You Play Your Cards Right
By teaming up with peers on the compliance side, doing appropriate scoping and preparation, and paying attention to
emerging standards, security practitioners can leverage PCI compliance activities to improve the security game of the
company as a whole.
Other reports from the Compliance Tech Center:
| Sponsored by: |
IT Operations Strategies: Manage Applications, Servers and Enterprise Infrastructure
Cut the time and effort of troubleshooting and reporting. ArcSight Logger provides better visibility into IT data to help manage applications, servers and enterprise infrastructure.
Log Management Facilitates IT Operations
Governments and businesses are increasingly vulnerable to cyber-attacks by hackers, malware and malicious insiders. Learn how logs can be used for forensic analysis of cyber-security incidents. Get the key requirements for a universal log management solution and discover how ArcSight Logger delivers on those requirements.
Cost-effectively Automate PCI Audits
Get turnkey and automated PCI compliance. ArcSight PCI Logger is an all-in-one log collection, storage and analysis solution for cost-effective automation of PCI audits and proactive protection of cardholder data.
Priority Health Combats Major Security Issues
Priority Health's ArcSight ESM deployment immediately addressed its most serious security issues. Data from firewalls, syslogs, IDS and Web servers was integrated into a single console -- providing much-needed visibility across the organization.
Case Study: Fiserv Tackles Compliance Challenges
ArcSight Logger makes it possible for Fiserv to quickly sift through terabytes of log data and isolate log events needed for compliance.
MORE NEWSFEED >>>