A Matter of Compliance Pennsylvania

These days, "compliance" is a hot topic, and nowhere more so than within the federal government. Although the term "compliance" means something different to every agency, and to the various stakeholders within it, the intent of multiple regulations across industries has a core purpose: to ensure the security, the availability, and ultimately the integrity of government information. The sheer number of regulations and the varying levels of policy and technical guidance are a challenge. Agencies are best served by recognizing that the key to success is applying sound management techniques and good governance to their organizations. Compliance will be a by-product of these actions, however, for agencies navigating the road to compliance, it is important to make a distinction between IT compliance and regulatory compliance. In this article, we will discuss a strategic path that can help an agency deal with IT compliance and, in keeping with the notion of sound management and a go ...

Local Companies

Win Knows.com
(717) 813-5159
876 Jay St
Lebanon, PA
Action International Business Coaching
(570) 524-3547
23 N Derr Dr
Lewisburg, PA
Blue Mountain Pediatrics
(570) 402-8900
RR 209
Brodheadsville, PA
Strategies For Growth
(610) 399-9717
309 Baywood Rd
West Chester, PA
Craighead Associates
(570) 646-7761
Pocono Pines, PA
Emerald Strategies Inc
(717) 234-4441
205 State St
Harrisburg, PA
Consulting Group Matrix
(610) 644-8074
51 W Central Ave
Paoli, PA
B Tm Associates Inc
(610) 279-6920
2500 Dekalb Pike
Norristown, PA
Laundry Logic Inc
(610) 828-0110
4110 Butler Pike
Plymouth, PA
Science & Technology Research Inc
(610) 970-9727
1685 Fernbrook Ln
Pottstown, PA

A Matter of Compliance



By Stacey McDaniel

These days, "compliance" is a hot topic, and nowhere more so than within the federal government. Although the term "compliance" means something different to every agency, and to the various stakeholders within it, the intent of multiple regulations across industries has a core purpose: to ensure the security, the availability, and ultimately the integrity of government information. The sheer number of regulations and the varying levels of policy and technical guidance are a challenge. Agencies are best served by recognizing that the key to success is applying sound management techniques and good governance to their organizations. Compliance will be a by-product of these actions, however, for agencies navigating the road to compliance, it is important to make a distinction between IT compliance and regulatory compliance. In this article, we will discuss a strategic path that can help an agency deal with IT compliance and, in keeping with the notion of sound management and a good governance regulatory compliance as well.

Regulatory compliance
These are policies that are externally mandated. For example, the Federal Information Security Management Act of 2002 (FISMA) is mandated by Congress and enforced by the Office of Management and Budget (OMB). Here are more policies that many federal agencies must comply with that require some degree of IT contribution:

  • Clinger-Cohen Act of 1996
  • Computer Fraud and Abuse Act of 1986
    Electronic Communications Privacy Act of 1986 Executive Order 13011, "Federal Information Technology," 61 FR 37657
  • Paper Work Reduction Act of 1995
  • Privacy Act of 1974
  • Homeland Security Presidential Directive 7 (HSPD-7) "Critical Infrastructure Identification, Prioritization, and Protection"
  • OMB Circular A123, Management Accountability and Control, June 21, 1995 

Most of these external regulations lack detailed guidance on how to actually achieve compliance. For example, FISMA regulations instruct agencies to meet certain IT security standards, but provide little instruction on how to achieve compliance. This is where various frameworks come into play. Frameworks such as ISO-17799, ITIL and Special Publication (SP) 800-53 Recommended Security Controls for Federal Information Systems help by providing specific instructions for agencies trying to achieve regulatory compliance.

Internal IT compliance
In addition to all of the externally mandated regulations, agencies should not lose sight of the importance of establishing and maintaining internal IT policies that designate exactly how their IT infrastructure should function. On the policy side, this can include having internal documents governing privacy, email use, password management, and more. Internal controls should also be in place to regulate things like access control, incident management and recovery, and storage solutions.
 
A strategic approach
One of the major goals of external regulations is to assure that organizations demonstrate "due care" in providing appropriate IT controls that assure the security and privacy of information assets and protect them from damage or misuse. As we have mentioned, external regulations are often vague, and must be aligned with internal IT polices and industry best practices in order to achieve due care and satisfy auditors that compliance requirements have been met.
 
Working towards complying with any regulation, whether it is external or internal, requires an ongoing pattern of determining policies, identifying changes needed, and making the changes. Here are some strategic steps your agency can take:

1. Determine which IT policies you want to adhere to (these will likely be policies that will also help you meet external regulations, such as FISMA).

2. Inventory all IT assets, including hardware and software. This will help you identify everything you have, so you can determine what needs to be done to protect it.

3. Assign a level of risk that indicates how mission critical each system is so you can apply appropriate levels of security. This can be as simple as "high," "medium," and "low," with "high" indicating a mission critical system (deserving of maximum security levels), and "low" meaning that, should it go down, it would be inconvenient but would pose no major disruption (minimum security).

4. Determine the current compliance status of your systems.

5. Turn to industry best practices for recommendations (which set of best practices you choose will depend upon the regulations you are trying to comply with). Commonly used best practices come from the following sources:

    • Center for Internet Security (CIS) configuration benchmarks, Level 1 or Level 2
    • Sun Microsystems best practices
    • National Institute of Standards and Technology (NIST) is now just completing all of its guidelines
    • IT Infrastructure Library (ITIL(r)) an exceptionally well-known international approach to managing IT services

6. Upon creation of your policies, make sure the policies are communicated to employees.

7. Determine compliance status across the agency. For example, to determine compliance with a password policy, run a query of all workstations to look for those not in compliance.

8. Certification and Accreditation (C&A) -- The OMB defines requirements for certifying and accrediting the security of information systems for processing sensitive information. All security controls in place for operational systems must be reviewed, then certified and accredited every three years. C&A is a slow, manual process, but is required of every agency.

9. Quarterly FISMA status reports must be filed with the OMB.

10. If a system or machine is discovered to be non-compliant, a Plan of Action Milestone (POAM) should be developed. This involves identifying the machine, reporting the problem, noting what needs to be done, and when it will be fixed.

11. Perform a gap analysis. With regards to benchmarks you have set for your agency, determine where your systems currently are, and where they need to be.

Behind in security
Each year, Congress releases a report card that reveals the grades given to each of the 24 Federal agencies with regards to the agency's computer security status. The latest report card was released in March 2006, and the results were not good. For the second year in a row, the federal government as a whole earned a D+, and eight agencies received failing marks. Considering all of the regulations designed to improve security within the government, why has there been no marked improvement? Here are a couple of possible reasons:

  • Shortage of funds: Many agencies are finding that budget cuts have left them without excess dollars to spend on IT security and compliance, yet they must attend effectively to both. In some cases, large proportions of an agency's security funds are being to used pay for things like hiring independent contractors to write FISMA-required reports as part of the C&A process. Such expenditures leave little money for implementing actual security measures.
  • Overwhelming: While it is difficult to manage compliance with any one policy, it is overwhelming to manage compliance with ALL policies. Achieving effective, simultaneous compliance with numerous policies can be intimidating, and the process can be tedious. The time and manpower necessary for understanding requirements, collecting and analyzing data, and delivering meaningful, timely reports are at a premium.
    In many cases, this work is all done manually, and any time a change in the policy is made, the agency must manually modify its systems and processes to comply with the new version.

Conclusion
Federal agencies face all kinds of compliance issues. A shortage of manpower and funds, coupled with the sheer number of regulations, has left many agencies struggling with IT security. The good news is that most regulations are focused on the same desired result -- securing the IT environment. This means it is important for an agency to start by building a strong foundation, built on good internal IT controls and policies. Only then will an agency find success with external regulatory compliance.

Stacey McDaniel has been writing about high-tech issues for more than six years.

Featured Local Company

Win Knows.com

Let us offer you our assistance in Information and Technology

7178135159
876 Jay St
Lebanon, PA
http://www.winknows.com/shop/start

About US: Our Custom PC's and Laptops are hand built with only the best components on the market. Our attention to detail and custom wiring will make you look twice. With a combination of lighting, cooling and a touch of personality, your PC will be a work of art and performance.
Don't put off your emergency planning until after the
disaster happens. Careful preparation now can save
you precious time whenever an IT outage strikes.
Having systems,
processes, and policies in place can lessen the overall
impact and keep your valuable data safe.


Win Knows High SPEED DSL
Win Knows.com Your Information and Technology Solution

Related Articles
- Add Your Voice to the Compliance Team Pennsylvania
Thousands of large public companies were able to comply with Sarbanes-Oxley requirements in their annual reports recently thanks to the efforts of their information technology teams. But while IT is acknowledged as playing a crucial role in regulatory compliance, CIOs often find themselves without a seat at the table because ownership of the data originated in another department.
- Managing Compliance Risks Pennsylvania
- Managing IT Security Compliance Pennsylvania
- Oil and Gas: Stepping Up to Security Compliance Pennsylvania
- NERC CIP: Don't Be a Compliance "Laggard" Pennsylvania
- Sarbanes-Oxley Compliance: Round Two Pennsylvania
- Sustainable IT Compliance Pennsylvania
- Making Compliance Part of the "IT DNA" Pennsylvania
- Critical Challenges for Corporate Compliance Pennsylvania
- IT Compliance Pennsylvania
Regional Articles
- A Matter of Compliance Aliquippa PA
- A Matter of Compliance Allentown PA
- A Matter of Compliance Allison Park PA
- A Matter of Compliance Altoona PA
- A Matter of Compliance Ambler PA
- A Matter of Compliance Apollo PA
- A Matter of Compliance Aston PA
- A Matter of Compliance Beaver Falls PA
- A Matter of Compliance Beaver PA
- A Matter of Compliance Belle Vernon PA
- A Matter of Compliance Bellefonte PA
- A Matter of Compliance Bensalem PA
- A Matter of Compliance Berwick PA
- A Matter of Compliance Bethel Park PA
- A Matter of Compliance Bethlehem PA
- A Matter of Compliance Birdsboro PA
- A Matter of Compliance Bloomsburg PA
- A Matter of Compliance Blue Bell PA
- A Matter of Compliance Boyertown PA
- A Matter of Compliance Bridgeville PA
- A Matter of Compliance Broomall PA
- A Matter of Compliance Bryn Mawr PA
- A Matter of Compliance Butler PA
- A Matter of Compliance Camp Hill PA
- A Matter of Compliance Canonsburg PA
- A Matter of Compliance Carlisle PA
- A Matter of Compliance Carnegie PA
- A Matter of Compliance Chalfont PA
- A Matter of Compliance Chambersburg PA
- A Matter of Compliance Chester PA
- A Matter of Compliance Clairton PA
- A Matter of Compliance Clarks Summit PA
- A Matter of Compliance Clifton Heights PA
- A Matter of Compliance Coatesville PA
- A Matter of Compliance Collegeville PA
- A Matter of Compliance Connellsville PA
- A Matter of Compliance Conshohocken PA
- A Matter of Compliance Coraopolis PA
- A Matter of Compliance Cranberry Twp PA
- A Matter of Compliance Darby PA
- A Matter of Compliance Dillsburg PA
- A Matter of Compliance Downingtown PA
- A Matter of Compliance Doylestown PA
- A Matter of Compliance Drexel Hill PA
- A Matter of Compliance Du Bois PA
- A Matter of Compliance East Stroudsburg PA
- A Matter of Compliance Easton PA
- A Matter of Compliance Elizabethtown PA
- A Matter of Compliance Elkins Park PA
- A Matter of Compliance Ellwood City PA
- A Matter of Compliance Emmaus PA
- A Matter of Compliance Ephrata PA
- A Matter of Compliance Erie PA
- A Matter of Compliance Exton PA
- A Matter of Compliance Feasterville Trevose PA
- A Matter of Compliance Gettysburg PA
- A Matter of Compliance Gibsonia PA
- A Matter of Compliance Glenshaw PA
- A Matter of Compliance Glenside PA
- A Matter of Compliance Greensburg PA
- A Matter of Compliance Hanover PA
- A Matter of Compliance Harleysville PA
- A Matter of Compliance Harrisburg PA
- A Matter of Compliance Hatboro PA
- A Matter of Compliance Hatfield PA
- A Matter of Compliance Havertown PA
- A Matter of Compliance Hazleton PA
- A Matter of Compliance Hershey PA
- A Matter of Compliance Hollidaysburg PA
- A Matter of Compliance Hummelstown PA
- A Matter of Compliance Huntingdon PA
- A Matter of Compliance Huntingdon Valley PA
- A Matter of Compliance Indiana PA
- A Matter of Compliance Irwin PA
- A Matter of Compliance Jeannette PA
- A Matter of Compliance Jenkintown PA
- A Matter of Compliance Johnstown PA
- A Matter of Compliance Kennett Square PA
- A Matter of Compliance King Of Prussia PA
- A Matter of Compliance Kingston PA
- A Matter of Compliance Kittanning PA
- A Matter of Compliance Kutztown PA
- A Matter of Compliance Lancaster PA
- A Matter of Compliance Langhorne PA
- A Matter of Compliance Lansdale PA
- A Matter of Compliance Lansdowne PA
- A Matter of Compliance Latrobe PA
- A Matter of Compliance Lebanon PA
- A Matter of Compliance Lehighton PA
- A Matter of Compliance Levittown PA
- A Matter of Compliance Lewistown PA
- A Matter of Compliance Lititz PA
- A Matter of Compliance Lock Haven PA
- A Matter of Compliance Manheim PA
- A Matter of Compliance Marcus Hook PA
- A Matter of Compliance Mc Kees Rocks PA
- A Matter of Compliance Mckeesport PA
- A Matter of Compliance Meadville PA
- A Matter of Compliance Mechanicsburg PA
- A Matter of Compliance Media PA
- A Matter of Compliance Monroeville PA
- A Matter of Compliance Morrisville PA
- A Matter of Compliance Nazareth PA
- A Matter of Compliance New Castle PA
- A Matter of Compliance New Cumberland PA
- A Matter of Compliance New Kensington PA
- A Matter of Compliance Newtown PA
- A Matter of Compliance Newtown Square PA
- A Matter of Compliance Norristown PA
- A Matter of Compliance North Wales PA
- A Matter of Compliance Oil City PA
- A Matter of Compliance Palmyra PA
- A Matter of Compliance Perkasie PA
- A Matter of Compliance Philadelphia PA
- A Matter of Compliance Phoenixville PA
- A Matter of Compliance Pittsburgh PA
- A Matter of Compliance Pittston PA
- A Matter of Compliance Pottstown PA
- A Matter of Compliance Pottsville PA
- A Matter of Compliance Punxsutawney PA
- A Matter of Compliance Quakertown PA
- A Matter of Compliance Reading PA
- A Matter of Compliance Red Lion PA
- A Matter of Compliance Royersford PA
- A Matter of Compliance Scranton PA
- A Matter of Compliance Selinsgrove PA
- A Matter of Compliance Sewickley PA
- A Matter of Compliance Shippensburg PA
- A Matter of Compliance Southampton PA
- A Matter of Compliance State College PA
- A Matter of Compliance Stroudsburg PA
- A Matter of Compliance Telford PA
- A Matter of Compliance Uniontown PA
- A Matter of Compliance Upper Darby PA
- A Matter of Compliance Verona PA
- A Matter of Compliance Warminster PA
- A Matter of Compliance Washington PA
- A Matter of Compliance Wayne PA
- A Matter of Compliance Waynesboro PA
- A Matter of Compliance Waynesburg PA
- A Matter of Compliance West Chester PA
- A Matter of Compliance West Mifflin PA
- A Matter of Compliance Wexford PA
- A Matter of Compliance Whitehall PA
- A Matter of Compliance Wilkes Barre PA
- A Matter of Compliance Williamsport PA
- A Matter of Compliance Willow Grove PA
- A Matter of Compliance York PA
Related Local Events
SecureGOV Council Symposium
Dates: 12/7/2008 - 12/9/2008
Location: Hershey Lodge and Convention Center
Hershey PA
View Details

FILTRATION 2008
Dates: 12/9/2008 - 12/11/2008
Location: Pennsylvania Convention Center
Philadelphia PA
View Details

Association of Science-Technology Centers - ASTC 2008 Annual Conference
Dates: 10/18/2008 - 10/21/2008
Location: Franklin Institute Science Museum
Philadelphia PA
View Details

IBM Internet Security Systems Breakfast Seminar
Dates: 9/9/2008 - 9/9/2008
Location: Marriot Pittsburgh Airport
Coraopolis PA
View Details

Cable-Tec Expo 2008
Dates: 6/25/2008 - 6/27/2008
Location: Pennsylvania Convention Center
Philadelphia PA
View Details
Rate Article
     
Articles Insider

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Software
Business Services Fashion Internet Technology
Career Financial Services Legal Telecommunications
Cars Franchise Miscellaneous Trade Shows
Computer Hardware Health Nightlife Travel
Construction Holidays Online Database Weddings
Education Home Appliances Pets World History
Entertainment Home Electronics Real Estate Resources