1. Computing

SANS Publishes Consensus Guidelines for FISMA

From Al Lukaszewski, About.com GuideFebruary 24, 2009

It is an open secret that the US government is perhaps the largest software customer in the country. If you or your company deal with any government agency, you will be aware of FISMA (Federal Information Security Management Act of 2002). Seeking to bolster the criteria of FISMA, several federal agencies and private companies have released the Consensus Audit Guidelines (CAG). There they list 20 criteria for cybersecurity that need to be implemented in your organisation in order to be FISMA compliant. The list runs as follows:
  1. Inventory of authorized and unauthorized hardware.
  2. Inventory of authorized and unauthorized software; enforcement of white lists of authorized software.
  3. Secure configurations for hardware and software on laptops, workstations, and servers.
  4. Secure configurations of network devices such as firewalls, routers, and switches.
  5. Boundary Defense
  6. Maintenance, Monitoring and Analysis of Complete Audit Logs
  7. Application Software Security
  8. Controlled Use of Administrative Privileges
  9. Controlled Access Based On Need to Know
  10. Continuous Vulnerability Testing and Remediation
  11. Dormant Account Monitoring and Control
  12. Anti-Malware Defenses
  13. Limitation and Control of Ports, Protocols and Services
  14. Wireless Device Control
  15. Data Leakage Protection
  16. Secure Network Engineering
  17. Red Team Exercises
  18. Incident Response Capability
  19. Data Recovery Capability
  20. Security Skills Assessment and Appropriate Training To Fill Gaps
Obviously, not all of these relate to the security of web applications themselves. Rather, they apply not only to the software being implementated but also to the environment in which it is developed. Application security is additional, and you can find more about it at the following pages:
Comments
Comments are closed for this post.
Leave a Comment

Line and paragraph breaks are automatic. Some HTML allowed: <a href="" title="">, <b>, <i>, <strike>
Top Related Searches consensus guidelines

©2013 About.com. All rights reserved.