DECEMBER 2022ENTERPRISE SECURITY| | 9security assessments; (v) configuration management; (vi) contingency planning; (vii) identification and authentication; (viii) incident response; (ix) maintenance; (x) media protection; (xi) physical and environmental protection; (xii) planning; (xiii) personnel security; (xiv) risk assessment; (xv) systems and services acquisition; (xvi) system and communications protection; and (xvii) system and information integrity. The seventeen areas represent a broad-based, balanced information security program that addresses the management, operational, and technical aspects of protecting federal information and information systems. Policies and procedures play an important role in the effective implementation of enterprise-wide information security programs within the federal government and the success of the resulting security measures employed to protect federal information and information systems. Thus, organizations must develop and promulgate formal, documented policies and procedures governing the minimum-security requirements set forth in this standard and must ensure their effective implementation."This means organizations will be required to prioritize the introduction of more robust protection measures into production applications while also leveraging their applications teams to upgrade to the latest versions to take advantage of more recent software security utilities. Oftentimes, this creates integration challenges for legacy systems, which may need to be upgraded or replaced. In some cases, this could take multiple years, which creates greater expense for organizations and resource conflicts for IT teams that are already stretched thin.To help mitigate these challenges, it's helpful to ensure the following control mechanisms are in place:· System Inventory: Maintenance of an up-to-date inventory of all systems and their integrations in use.· Risk Categorization: Categorization of risk and security requirements for each infrastructure component.· System Security Plan: A comprehensive security plan and related processes which are updated regularly.· Security Controls: Series of enforced security controls to remain compliant with industry best practices.· Risk Assessments: Periodic three-tiered risk assessment, performed by a third party, using the Risk Management Framework (RMF).· Certification and Accreditation: Annual security reviews to identify and mitigate any existing vulnerabilities within the IT infrastructure. For organizations to remain secure,the CIO and CISO must work together to implement controls, maintain current patch levels, and monitor systems to ensure that vulnerabilities are prevented, detected and mitigated as quickly as possible.The cost and level of effort for implementing these security controls is not a small task. Because of cost and resource constraints with existing IT resources, organizations are oftentimes forced to rely on external consultants who possess extensive experience with compliance standards such FISMA, GDPR, ISO 27001, and CMMC to help assess current environments and security controls. The growing scope of information security and compliance has even necessitated the introduction of new roles to monitor and control the proliferation of personally identifiable information (PII) that could be associated with, or could reasonably be linked, directly or indirectly, with an individual or household. Individuals whose data is encompassed by this definition may include, but are not limited to, customers, potential customers, and employees of an organization. These data privacy officers ensure that all PII collected or processed on behalf is handled in accordance with guidelines, meaning it cannot be sold, rented, leased, disclosed, disseminated, made available, transferred, or otherwise communicate orally, in writing, or by electronic or other means to another business or third party for monetary or other valuable consideration. Data privacy officers also ensure that PII is not used for any purpose other than the specific purpose for which it was collected, which means working closely with IT personnel to ensure proper controls are in place for data mapping and data loss prevention. In summary, the IT security and IT infrastructure teams must work in tandem to ensure the following five elements:1. Alignment with Industry Best Practices2. Prevention of Data Loss3. Awareness of Cyber Security Best Practices Across the Enterprise4. Regularly Updated Policies and Procedures5. Optimized Risk PostureOf course, there is no guarantee that security incidents will never occur, but the likelihood is greatly reduced when the CIO and CISO work closely together to formulate and execute strategic goals that are mutually beneficial. ESORGANIZATIONS MUST DEVELOP AND PROMULGATE FORMAL, DOCUMENTED POLICIES AND PROCEDURES GOVERNING THE MINIMUM-SECURITY REQUIREMENTS SET FORTH IN THIS STANDARD AND MUST ENSURE THEIR EFFECTIVE IMPLEMENTATION
<
Page 8 |
Page 10 >