Stephen D. Gantz
Daniel R. Philpott
Copyright
Acquiring Editor: Chris Katsaropolous
Editorial Project Manager: Ben Rearick
Project Manager: Priya Kumaraguruparan
Designer: Matthew Limbert
Syngress is an imprint of Elsevier
225 Wyman Street, Waltham, MA 02451, USA
Copyright 2013 Elsevier, Inc. All rights reserved.
No part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopying, recording, or any information storage and retrieval system, without permission in writing from the publisher. Details on how to seek permission, further information about the Publishers permissions policies and our arrangements with organizations such as the Copyright Clearance Center and the Copyright Licensing Agency, can be found at our website: www.elsevier.com/permissions.
This book and the individual contributions contained in it are protected under copyright by the Publisher (other than as may be noted herein).
Notices
Knowledge and best practice in this fi eld are constantly changing. As new research and experience broaden our understanding, changes in research methods or professional practices, may become necessary. Practitioners and researchers must always rely on their own experience and knowledge in evaluating and using any information or methods described herein. In using such information or methods they should be mindful of their own safety and the safety of others, including parties for whom they have a professional responsibility.
To the fullest extent of the law, neither the Publisher nor the authors, contributors, or editors, assume any liability for any injury and/or damage to persons or property as a matter of products liability, negligence or otherwise, or from any use or operation of any methods, products, instructions, or ideas contained in the material herein.
Library of Congress Cataloging-in-Publication Data
FISMA and the risk management framework : the new practice of federal cyber security / edited by Stephen. Gantz, Daniel R. Philpott1st ed.
p. cm.
Includes bibliographical references and index.
ISBN: 978-1-59749-641-4
1. Computer securityUnited States. 2. Computer securityLaw and legislationUnited States. 3. Information technologySecurity measuresUnited States. 4. Electronic government informationSecurity measuresUnited States. 5. Administrative agenciesInformation resources managementSecurity measuresUnited States. 6. Computer networksSecurity measuresUnited States. 7. United States. Federal Information Security Management Act of 2002. I. Gantz, Stephen D. II. Philpott, Daniel R.
QA76.9.A25F57 2013
005.8dc23
2012039363
British Library Cataloguing-in-Publication Data
A catalogue record for this book is available from the British Library.
Printed in the United States of America
13 14 15 10 9 8 7 6 5 4 3 2 1
For information on all Syngress publications visit our website at www.syngress.com
Dedication
This book is dedicated to my father, David A. Gantz, a gentleman and a scholar.
Trademarks
International Council of Electronic Commerce Consultants EC-Council Certified Security Analyst (ECSA)
International Information Systems Security Certification Consortium Certified Accreditation Professional (CAP)
ISACA Certified Information Systems Auditor (CISA)
Microsoft Word and Excel
SANS Institute Global Information Assurance Certification (GIAC)
SANS Institute GIAC Systems and Network Auditor (GSNA)
SecureInfo Risk Management Services (RMS)
Symantec Enterprise Security Manager
Telos Xacta IA Manager
Trusted Integration Trusted Agent FISMA
Acknowledgements
I would like to thank Dan Philpott for conceiving and proposing the book project and for his tireless efforts working to stay abreast of activity and publications coming out of FISMA implementation and other federal security initiatives. I am grateful for the expert support from the Syngress/Elsevier team throughout the long process of bringing this project to fruition, including Angelina Ward, Matt Cater, Steve Elliot, Chris Katsaropoulos, and Meagan White. Thanks also go to Darren Windham for his constructive feedback and technical edits on the book.
I owe a professional debt of gratitude to many of the career civil servants with whom I have worked over the years, particularly including former HHS Deputy CIO John Teeter, HHS Chief Enterprise Architect Mary Forbes, and former HHS and VA CISO Jaren Doherty. I also sincerely appreciate the leadership of Ron Ross and the dedicated team of government and contractor personnel at NIST working on the FISMA Implementation Project and the Joint Task Force Transformation Initiative.
Many friends and co-workers listened attentively and provided a sounding board for ideas incorporated into the book. These patient individuals include colleagues Jim Chen, Davis Foster, Vicki Bowen, Marco Demartin, Tom Howe, and Erik Rolf. This project would not have been possible without the support of my wife Rene, my son Henry, and my daughters Claire and Gillian. I appreciate their indulgence throughout the writing process.
About the Author
Stephen Gantz (CISSP-ISSAP, CEH, CGEIT, CRISC, CIPP/G, C|CISO) is an information security and IT consultant with over 20 years of experience in security and privacy management, enterprise architecture, systems development and integration, and strategic planning. He currently holds an executive position with a health information technology services firm primarily serving federal and state government customers. He is also an Associate Professor of Information Assurance in the Graduate School at University of Maryland University College. He maintains a security-focused website and blog at http://www.securityarchitecture.com.
Steves security and privacy expertise spans program management, security architecture, policy development and enforcement, risk assessment, and regulatory compliance with major legislation such as FISMA, HIPAA, and the Privacy Act. His industry experience includes health, financial services, higher education, consumer products, and manufacturing, but since 2000 his work has focused on security and other information resources management functions in federal government agencies. His prior work history includes completing projects for government clients including the Departments of Defense, Labor, and Health and Human Services, Office of Management and Budget, Federal Deposit Insurance Corporation, U.S. Postal Service, and U.S. Senate.
Steve holds a masters degree in public policy from the Kennedy School of Government at Harvard University, and also earned his bachelors degree from Harvard. He is nearing completion of the Doctor of Management program at UMUC, where his dissertation focuses on trust and distrust in networks and inter-organizational relationships. Steve currently resides in Arlington, Virginia with his wife Rene and children Henry, Claire, and Gillian.