• DocumentCode
    2348761
  • Title

    Information system security compliance to FISMA standard: A quantitative measure

  • Author

    Hulitt, Elaine ; Vaughn, Rayford B., Jr.

  • Author_Institution
    U.S. Army Eng. Res. & Dev. Center, Vicksburg, MS
  • fYear
    2008
  • fDate
    20-22 Oct. 2008
  • Firstpage
    799
  • Lastpage
    806
  • Abstract
    To ensure that safeguards are implemented to protect against a majority of known threats, industry leaders are requiring information processing systems to comply with security standards. The National Institute of Standards and Technology Federal Information Risk Management Framework (RMF) and the associated suite of guidance documents describe the minimum security requirements (controls) for non-national-security federal information systems mandated by the Federal Information Security Management Act (FISMA), enacted into law on December 17, 2002, as Title III of the E-Government Act of 2002. The subjective compliance assessment approach described in the RMF guidance, though thorough and repeatable, lacks the clarity of a standard quantitative metric to describe for an information system the level of compliance with the FISMA-required standard. Given subjective RMF assessment data, this article suggests the use of Pathfinder networks to generate a quantitative metric suitable to measure, manage, and track the status of information system compliance with FISMA.
  • Keywords
    government data processing; information systems; risk management; security of data; software standards; FISMA standard; Federal Information Security Management Act; Pathfinder networks; information processing systems; information system security compliance; technology federal information risk management framework; Electrical equipment industry; Information processing; Information security; Information systems; Management information systems; Measurement standards; NIST; National security; Protection; Risk management;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Science and Information Technology, 2008. IMCSIT 2008. International Multiconference on
  • Conference_Location
    Wisia
  • Print_ISBN
    978-83-60810-14-9
  • Type

    conf

  • DOI
    10.1109/IMCSIT.2008.4747334
  • Filename
    4747334