A Matter of Compliance Texas

These days, "compliance" is a hot topic, and nowhere more so than within the federal government. Although the term "compliance" means something different to every agency, and to the various stakeholders within it, the intent of multiple regulations across industries has a core purpose: to ensure the security, the availability, and ultimately the integrity of government information. The sheer number of regulations and the varying levels of policy and technical guidance are a challenge. Agencies are best served by recognizing that the key to success is applying sound management techniques and good governance to their organizations. Compliance will be a by-product of these actions, however, for agencies navigating the road to compliance, it is important to make a distinction between IT compliance and regulatory compliance. In this article, we will discuss a strategic path that can help an agency deal with IT compliance and, in keeping with the notion of sound management and a go ...

Local Companies

Birch Communications
214-618-1487
1624 Marble Falls Drive
Frisco, TX
Bracken and Associates
(972) 484-9887
4019 Candlenut Ln
Dallas, TX
J F Smith Group
(817) 563-5374
4275 Little Rd
Arlington, TX
Bumble Bee Pools
(281) 395-2040
Katy, TX
M R I Dallas-Irving
(972) 550-1111
1425 Greenway Dr
Irving, TX
Peg Peterson & Associates
(281) 398-5852
Katy, TX
Fergson Enterprises
(210) 467-0016
4427 Factory Hill St
San Antonio, TX
Affinity Sports Marketing
(817) 749-0383
1205 S White Chapel Blvd Ste 110
Southlake, TX
Global Project Consultants Inc
(281) 759-1650
14800 Saint Marys Ln Ste 250
Houston, TX
Risktec Solutions
(281) 333-5080
1110 Nasa Pkwy
Houston, TX


A Matter of Compliance



By Stacey McDaniel

These days, "compliance" is a hot topic, and nowhere more so than within the federal government. Although the term "compliance" means something different to every agency, and to the various stakeholders within it, the intent of multiple regulations across industries has a core purpose: to ensure the security, the availability, and ultimately the integrity of government information. The sheer number of regulations and the varying levels of policy and technical guidance are a challenge. Agencies are best served by recognizing that the key to success is applying sound management techniques and good governance to their organizations. Compliance will be a by-product of these actions, however, for agencies navigating the road to compliance, it is important to make a distinction between IT compliance and regulatory compliance. In this article, we will discuss a strategic path that can help an agency deal with IT compliance and, in keeping with the notion of sound management and a good governance regulatory compliance as well.

Regulatory compliance
These are policies that are externally mandated. For example, the Federal Information Security Management Act of 2002 (FISMA) is mandated by Congress and enforced by the Office of Management and Budget (OMB). Here are more policies that many federal agencies must comply with that require some degree of IT contribution:

  • Clinger-Cohen Act of 1996
  • Computer Fraud and Abuse Act of 1986
    Electronic Communications Privacy Act of 1986 Executive Order 13011, "Federal Information Technology," 61 FR 37657
  • Paper Work Reduction Act of 1995
  • Privacy Act of 1974
  • Homeland Security Presidential Directive 7 (HSPD-7) "Critical Infrastructure Identification, Prioritization, and Protection"
  • OMB Circular A123, Management Accountability and Control, June 21, 1995 

Most of these external regulations lack detailed guidance on how to actually achieve compliance. For example, FISMA regulations instruct agencies to meet certain IT security standards, but provide little instruction on how to achieve compliance. This is where various frameworks come into play. Frameworks such as ISO-17799, ITIL and Special Publication (SP) 800-53 Recommended Security Controls for Federal Information Systems help by providing specific instructions for agencies trying to achieve regulatory compliance.

Internal IT compliance
In addition to all of the externally mandated regulations, agencies should not lose sight of the importance of establishing and maintaining internal IT policies that designate exactly how their IT infrastructure should function. On the policy side, this can include having internal documents governing privacy, email use, password management, and more. Internal controls should also be in place to regulate things like access control, incident management and recovery, and storage solutions.
 
A strategic approach
One of the major goals of external regulations is to assure that organizations demonstrate "due care" in providing appropriate IT controls that assure the security and privacy of information assets and protect them from damage or misuse. As we have mentioned, external regulations are often vague, and must be aligned with internal IT polices and industry best practices in order to achieve due care and satisfy auditors that compliance requirements have been met.
 
Working towards complying with any regulation, whether it is external or internal, requires an ongoing pattern of determining policies, identifying changes needed, and making the changes. Here are some strategic steps your agency can take:

1. Determine which IT policies you want to adhere to (these will likely be policies that will also help you meet external regulations, such as FISMA).

2. Inventory all IT assets, including hardware and software. This will help you identify everything you have, so you can determine what needs to be done to protect it.

3. Assign a level of risk that indicates how mission critical each system is so you can apply appropriate levels of security. This can be as simple as "high," "medium," and "low," with "high" indicating a mission critical system (deserving of maximum security levels), and "low" meaning that, should it go down, it would be inconvenient but would pose no major disruption (minimum security).

4. Determine the current compliance status of your systems.

5. Turn to industry best practices for recommendations (which set of best practices you choose will depend upon the regulations you are trying to comply with). Commonly used best practices come from the following sources:

    • Center for Internet Security (CIS) configuration benchmarks, Level 1 or Level 2
    • Sun Microsystems best practices
    • National Institute of Standards and Technology (NIST) is now just completing all of its guidelines
    • IT Infrastructure Library (ITIL(r)) an exceptionally well-known international approach to managing IT services

6. Upon creation of your policies, make sure the policies are communicated to employees.

7. Determine compliance status across the agency. For example, to determine compliance with a password policy, run a query of all workstations to look for those not in compliance.

8. Certification and Accreditation (C&A) -- The OMB defines requirements for certifying and accrediting the security of information systems for processing sensitive information. All security controls in place for operational systems must be reviewed, then certified and accredited every three years. C&A is a slow, manual process, but is required of every agency.

9. Quarterly FISMA status reports must be filed with the OMB.

10. If a system or machine is discovered to be non-compliant, a Plan of Action Milestone (POAM) should be developed. This involves identifying the machine, reporting the problem, noting what needs to be done, and when it will be fixed.

11. Perform a gap analysis. With regards to benchmarks you have set for your agency, determine where your systems currently are, and where they need to be.

Behind in security
Each year, Congress releases a report card that reveals the grades given to each of the 24 Federal agencies with regards to the agency's computer security status. The latest report card was released in March 2006, and the results were not good. For the second year in a row, the federal government as a whole earned a D+, and eight agencies received failing marks. Considering all of the regulations designed to improve security within the government, why has there been no marked improvement? Here are a couple of possible reasons:

  • Shortage of funds: Many agencies are finding that budget cuts have left them without excess dollars to spend on IT security and compliance, yet they must attend effectively to both. In some cases, large proportions of an agency's security funds are being to used pay for things like hiring independent contractors to write FISMA-required reports as part of the C&A process. Such expenditures leave little money for implementing actual security measures.
  • Overwhelming: While it is difficult to manage compliance with any one policy, it is overwhelming to manage compliance with ALL policies. Achieving effective, simultaneous compliance with numerous policies can be intimidating, and the process can be tedious. The time and manpower necessary for understanding requirements, collecting and analyzing data, and delivering meaningful, timely reports are at a premium.
    In many cases, this work is all done manually, and any time a change in the policy is made, the agency must manually modify its systems and processes to comply with the new version.

Conclusion
Federal agencies face all kinds of compliance issues. A shortage of manpower and funds, coupled with the sheer number of regulations, has left many agencies struggling with IT security. The good news is that most regulations are focused on the same desired result -- securing the IT environment. This means it is important for an agency to start by building a strong foundation, built on good internal IT controls and policies. Only then will an agency find success with external regulatory compliance.

Stacey McDaniel has been writing about high-tech issues for more than six years.

Featured Local Company

Birch Communications

214-618-1487
1624 Marble Falls Drive
Frisco, TX
www.Birch.com

Regional Articles
- A Matter of Compliance Abilene TX
- A Matter of Compliance Alamo TX
- A Matter of Compliance Alice TX
- A Matter of Compliance Allen TX
- A Matter of Compliance Alvarado TX
- A Matter of Compliance Alvin TX
- A Matter of Compliance Amarillo TX
- A Matter of Compliance Angleton TX
- A Matter of Compliance Arlington TX
- A Matter of Compliance Athens TX
- A Matter of Compliance Austin TX
- A Matter of Compliance Azle TX
- A Matter of Compliance Bastrop TX
- A Matter of Compliance Bay City TX
- A Matter of Compliance Baytown TX
- A Matter of Compliance Beaumont TX
- A Matter of Compliance Bedford TX
- A Matter of Compliance Beeville TX
- A Matter of Compliance Bellaire TX
- A Matter of Compliance Belton TX
- A Matter of Compliance Big Spring TX
- A Matter of Compliance Boerne TX
- A Matter of Compliance Borger TX
- A Matter of Compliance Brenham TX
- A Matter of Compliance Brownsville TX
- A Matter of Compliance Brownwood TX
- A Matter of Compliance Bryan TX
- A Matter of Compliance Burleson TX
- A Matter of Compliance Canyon TX
- A Matter of Compliance Carrollton TX
- A Matter of Compliance Cedar Hill TX
- A Matter of Compliance Cedar Park TX
- A Matter of Compliance Channelview TX
- A Matter of Compliance Cleburne TX
- A Matter of Compliance Cleveland TX
- A Matter of Compliance Clute TX
- A Matter of Compliance College Station TX
- A Matter of Compliance Colleyville TX
- A Matter of Compliance Conroe TX
- A Matter of Compliance Converse TX
- A Matter of Compliance Coppell TX
- A Matter of Compliance Copperas Cove TX
- A Matter of Compliance Corpus Christi TX
- A Matter of Compliance Corsicana TX
- A Matter of Compliance Crosby TX
- A Matter of Compliance Crp Christi TX
- A Matter of Compliance Cypress TX
- A Matter of Compliance Dallas TX
- A Matter of Compliance Dayton TX
- A Matter of Compliance Deer Park TX
- A Matter of Compliance Del Rio TX
- A Matter of Compliance Del Valle TX
- A Matter of Compliance Denison TX
- A Matter of Compliance Denton TX
- A Matter of Compliance Desoto TX
- A Matter of Compliance Dickinson TX
- A Matter of Compliance Donna TX
- A Matter of Compliance Dumas TX
- A Matter of Compliance Duncanville TX
- A Matter of Compliance Eagle Pass TX
- A Matter of Compliance Edinburg TX
- A Matter of Compliance El Campo TX
- A Matter of Compliance El Paso TX
- A Matter of Compliance Elgin TX
- A Matter of Compliance Ennis TX
- A Matter of Compliance Euless TX
- A Matter of Compliance Floresville TX
- A Matter of Compliance Flower Mound TX
- A Matter of Compliance Fort Worth TX
- A Matter of Compliance Fredericksburg TX
- A Matter of Compliance Freeport TX
- A Matter of Compliance Friendswood TX
- A Matter of Compliance Frisco TX
- A Matter of Compliance Gainesville TX
- A Matter of Compliance Galveston TX
- A Matter of Compliance Garland TX
- A Matter of Compliance Gatesville TX
- A Matter of Compliance Georgetown TX
- A Matter of Compliance Gilmer TX
- A Matter of Compliance Granbury TX
- A Matter of Compliance Grand Prairie TX
- A Matter of Compliance Grapevine TX
- A Matter of Compliance Greenville TX
- A Matter of Compliance Groves TX
- A Matter of Compliance Haltom City TX
- A Matter of Compliance Harker Heights TX
- A Matter of Compliance Harlingen TX
- A Matter of Compliance Henderson TX
- A Matter of Compliance Hereford TX
- A Matter of Compliance Houston TX
- A Matter of Compliance Humble TX
- A Matter of Compliance Huntsville TX
- A Matter of Compliance Hurst TX
- A Matter of Compliance Irving TX
- A Matter of Compliance Jacksonville TX
- A Matter of Compliance Jasper TX
- A Matter of Compliance Joshua TX
- A Matter of Compliance Katy TX
- A Matter of Compliance Kaufman TX
- A Matter of Compliance Keller TX
- A Matter of Compliance Kerrville TX
- A Matter of Compliance Kilgore TX
- A Matter of Compliance Killeen TX
- A Matter of Compliance Kingsville TX
- A Matter of Compliance Kyle TX
- A Matter of Compliance La Porte TX
- A Matter of Compliance Lake Jackson TX
- A Matter of Compliance Lancaster TX
- A Matter of Compliance Laredo TX
- A Matter of Compliance League City TX
- A Matter of Compliance Leander TX
- A Matter of Compliance Levelland TX
- A Matter of Compliance Lewisville TX
- A Matter of Compliance Livingston TX
- A Matter of Compliance Lockhart TX
- A Matter of Compliance Longview TX
- A Matter of Compliance Lubbock TX
- A Matter of Compliance Lufkin TX
- A Matter of Compliance Lumberton TX
- A Matter of Compliance Mabank TX
- A Matter of Compliance Magnolia TX
- A Matter of Compliance Mansfield TX
- A Matter of Compliance Marble Falls TX
- A Matter of Compliance Marshall TX
- A Matter of Compliance Mc Kinney TX
- A Matter of Compliance Mcallen TX
- A Matter of Compliance Mercedes TX
- A Matter of Compliance Mesquite TX
- A Matter of Compliance Midland TX
- A Matter of Compliance Midlothian TX
- A Matter of Compliance Mineral Wells TX
- A Matter of Compliance Mission TX
- A Matter of Compliance Missouri City TX
- A Matter of Compliance Montgomery TX
- A Matter of Compliance Mount Pleasant TX
- A Matter of Compliance Nacogdoches TX
- A Matter of Compliance Navasota TX
- A Matter of Compliance Nederland TX
- A Matter of Compliance New Braunfels TX
- A Matter of Compliance New Caney TX
- A Matter of Compliance North Richland Hills TX
- A Matter of Compliance Odessa TX
- A Matter of Compliance Orange TX
- A Matter of Compliance Palestine TX
- A Matter of Compliance Pampa TX
- A Matter of Compliance Paris TX
- A Matter of Compliance Pasadena TX
- A Matter of Compliance Pearland TX
- A Matter of Compliance Pflugerville TX
- A Matter of Compliance Pharr TX
- A Matter of Compliance Plainview TX
- A Matter of Compliance Plano TX
- A Matter of Compliance Port Arthur TX
- A Matter of Compliance Port Lavaca TX
- A Matter of Compliance Porter TX
- A Matter of Compliance Portland TX
- A Matter of Compliance Red Oak TX
- A Matter of Compliance Richardson TX
- A Matter of Compliance Richmond TX
- A Matter of Compliance Rio Grande City TX
- A Matter of Compliance Roanoke TX
- A Matter of Compliance Robstown TX
- A Matter of Compliance Rockport TX
- A Matter of Compliance Rockwall TX
- A Matter of Compliance Roma TX
- A Matter of Compliance Rosenberg TX
- A Matter of Compliance Rosharon TX
- A Matter of Compliance Round Rock TX
- A Matter of Compliance Rowlett TX
- A Matter of Compliance San Angelo TX
- A Matter of Compliance San Antonio TX
- A Matter of Compliance San Benito TX
- A Matter of Compliance San Juan TX
- A Matter of Compliance San Marcos TX
- A Matter of Compliance Santa Fe TX
- A Matter of Compliance Schertz TX
- A Matter of Compliance Seabrook TX
- A Matter of Compliance Seagoville TX
- A Matter of Compliance Seguin TX
- A Matter of Compliance Sherman TX
- A Matter of Compliance Silsbee TX
- A Matter of Compliance South Houston TX
- A Matter of Compliance Southlake TX
- A Matter of Compliance Spring TX
- A Matter of Compliance Springtown TX
- A Matter of Compliance Stafford TX
- A Matter of Compliance Stephenville TX
- A Matter of Compliance Sugar Land TX
- A Matter of Compliance Sulphur Springs TX
- A Matter of Compliance Taylor TX
- A Matter of Compliance Temple TX
- A Matter of Compliance Terrell TX
- A Matter of Compliance Texarkana TX
- A Matter of Compliance Texas City TX
- A Matter of Compliance The Colony TX
- A Matter of Compliance Tomball TX
- A Matter of Compliance Tyler TX
- A Matter of Compliance Universal City TX
- A Matter of Compliance Uvalde TX
- A Matter of Compliance Victoria TX
- A Matter of Compliance Vidor TX
- A Matter of Compliance Waco TX
- A Matter of Compliance Waxahachie TX
- A Matter of Compliance Weatherford TX
- A Matter of Compliance Webster TX
- A Matter of Compliance Weslaco TX
- A Matter of Compliance Wharton TX
- A Matter of Compliance Wichita Falls TX
- A Matter of Compliance Willis TX
- A Matter of Compliance Woodway TX
- A Matter of Compliance Wylie TX
Related Local Events
Avnet Partner Solutions 2008 Partnership Sales Meeting
Dates: 8/23/2008 - 8/26/2008
Location: Marriott Rivercenter
San Antonio TX
View Details

37th Turbomachinery Symposium
Dates: 9/8/2008 - 9/11/2008
Location: George R. Brown Convention Center
Houston TX
View Details

Vocational Technical Education Consortium of States 2008 Technical Coordinator In-Service Meeting
Dates: 9/17/2008 - 9/19/2008
Location: The St. Anthony - A Wyndham Historic Hotel
San Antonio TX
View Details

American Water Works Assn DSS 08 - Distribution Systems Symposium & Exposition
Dates: 9/21/2008 - 9/24/2008
Location: TBD
Austin TX
View Details

AWWA's DSS: The Distribution & Plant Operations Conference and Exposition!
Dates: 9/21/2008 - 9/24/2008
Location: TBD
Austin TX
View Details
Rate Article
     
Articles Insider

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Entertainment Home Electronics Software
Business Services Family Home Services Technology
Career Fashion Internet Telecommunications
Cars Financial Services Legal Trade Shows
Computer Hardware Franchise Miscellaneous Travel
Construction Health Nightlife Weddings
Education Holidays Online Database World History
Educational Content Home Appliances Real Estate Resources