OIG: NASA's National Security Systems

NASA OIG: Final Memorandum on the Audit of the Reporting of NASA's National Security Systems (IG-09-024, August 28, 2009)

"We found that NASA did not comply with FISMA requirements for the reporting of national security systems for FYs 2007 and 2008 because NASA had not clearly assigned this responsibility to a specific NASA office. Further, NASA had not formally designated an entity with appropriate resources to complete the annual independent evaluations of its national security systems required by FISMA. We notified the Agency about this issue in February 2009, and NASA immediately assigned the responsibility to the Office of the Chief Information Officer (OCIO). In response to our draft report, NASA assigned the Office of Protective Services (OPS) to work with the OCIO to gather and compile the required information to report to OMB and stated that a formal agreement with an independent entity was being developed. We consider management's proposed actions to be responsive and will close the related recommendation after verifying that the Agency has established a formal agreement with an entity with the appropriate resources to conduct the annual independent evaluation of NASA's national security systems."


Advertise Here

1 Comment

| Leave a comment
user-pic

Nothing in my life has made me lose respect for "metrics" quicker than the FISMA C&A reporting stuff. I'm not going to dispute that proper documentation and accountability are critical for IT security - but right now we're:

* Gathering metrics verbatim from broken patch management tools with false positives and insisting that we live by those results
* Assigning favored vendors with virtually no operational experiense the task of "auditing" our compliance
* Providing HQ and OMB level visibility into every single documentation task, no matter how small a system or problem
* Holding individual sysadmins responsible for "POAM Items" that live at Headquarters and demanding documentation of when they'll be remediating HQ's mistakes.

The list could go on a while!

There's a lot more that goes into properly securing computer systems than headquarters demanding that you boil it all down into whether you're "Red, Yellow or Green" this month and it's very frustrating to have the "metrics" take center stage over actual security.

Leave a comment




calendar

Events
Launches
Your Event

Monthly Archives

Mortgage Lead

Play online bingo at the top bingo sites.

Interested in Space Travel, try the next best thing, name your own star.

Online Bingo

Hier finden Sie die neuesten Casino Bonus Codes von fuhrenden Gaming-Sites.

Forex like a Pro with a leading forex broker.

About this Entry

This page contains a single entry by Keith Cowing published on August 29, 2009 10:40 PM.

Steve Cook Departure Update was the previous entry in this blog.

Astronauts On NASA Stability is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.



- Find brilliant bingo sites and start to win

-

- Trade Forex like a Pro

- Die besten Seiten fur online roulette spielen, Spielstrategien und Tipps.