Federated identity primer
Book information
Description
FrontMatter......Page 1 Copyright......Page 3 dedication......Page 4 Acknowledgements......Page 5 Trademarks......Page 6 About the Author......Page 7 Introduction......Page 8 Purpose and Rationale......Page 10 Key Audience......Page 12 Implementation Responsibilities......Page 13 FISMA Progress to Date......Page 14 FISMA Provisions......Page 15 Standards and Guidelines for Federal Information Systems......Page 16 System Certification and Accreditation......Page 18 Strengths and Shortcomings of FISMA......Page 19 Structure and Content......Page 20 Chapter 2: Federal Information Security Fundamentals......Page 21 Chapter 6: Risk Management Framework Planning and Initiation......Page 22 Chapter 11: Security Assessment Report......Page 23 Chapter 15: Contingency Planning......Page 24 Relevant Source Material......Page 25 References......Page 26 2 Federal Information Security Fundamentals......Page 29 Information Security in the Federal Government......Page 31 Brief History of Information Security......Page 32 Civilian, Defense, and Intelligence Sector Practices......Page 34 Information Classification and Security Categorization......Page 35 Security Controls......Page 37 Certification and Accreditation Process......Page 38 Legislative History of Information Security Management......Page 39 Certification and Accreditation......Page 40 FIPS 102......Page 41 DITSCAP......Page 42 NIACAP......Page 43 NIST Special Publication 800-37......Page 45 DIACAP......Page 46 NIST Risk Management Framework......Page 47 Joint Task Force Transformation Initiative......Page 48 Organizational Responsibilities......Page 49 National Institute of Standards and Technology (NIST)......Page 50 Department of Homeland Security (DHS)......Page 51 Congress......Page 52 Relevant Source Material......Page 53 References......Page 54 3 Thinking About Risk......Page 59 Key Concepts......Page 60 Certainty, Uncertainty, and Probability......Page 61 Assurance......Page 62 Types of Risk......Page 63 Budgetary Risk......Page 65 Political Risk......Page 66 Reputation Risk......Page 67 Supply Chain Risk......Page 68 Organizational Risk......Page 69 Risk Tolerance......Page 70 Risk Executive......Page 71 Trust, Assurance, and Security......Page 72 Assurance and Confidence......Page 73 Trust Models......Page 74 Risk Associated with Information Systems......Page 76 Risk Management Framework......Page 77 Risk Assessment......Page 78 Other Risk Management Frameworks Used in Government Organizations......Page 79 Summary......Page 81 References......Page 82 4 Thinking About Systems......Page 85 Defining Systems in Different Contexts......Page 86 Information Systems in FISMA and the RMF......Page 87 Information System Types......Page 88 Security Categorization......Page 89 National Security Systems......Page 90 Information Security Management......Page 91 Capital Planning and Investment Control......Page 92 Enterprise Architecture......Page 93 System Development Life Cycle......Page 94 Information Privacy......Page 96 Establishing Information System Boundaries......Page 97 Subsystems......Page 98 System Interconnections......Page 101 Maintaining System Inventories......Page 103 Relevant Source Material......Page 104 References......Page 105 5 Success Factors......Page 110 Prerequisites for Organizational Risk Management......Page 111 Justifying Information Security......Page 112 Head of Agency......Page 114 Chief Information Officer......Page 115 Managing the Information Security Program......Page 116 Compliance and Reporting......Page 119 Information Security Program Evaluation......Page 120 Governance......Page 121 Planning......Page 122 Communication......Page 123 Flexibility......Page 124 Measuring Security Effectiveness......Page 125 Security Measurement Types......Page 127 Security Measurement Process......Page 128 References......Page 131 6 Risk Management Framework Planning and Initiation......Page 135 Planning......Page 136 Planning the RMF Project......Page 138 Aligning to the SDLC......Page 139 Planning the RMF Timeline......Page 140 Prerequisites for RMF Initiation......Page 141 Inputs to Information System Categorization......Page 142 Inputs to Security Control Selection......Page 143 Organizational Policies, Procedures, Templates, and Guidance......Page 144 Identifying Responsible Personnel......Page 146 Establishing a Project Plan......Page 147 Roles and Responsibilities......Page 148 Getting the Project Underway......Page 149 Summary......Page 152 References......Page 153 7 Risk Management Framework Steps 1 & 2......Page 156 Standards and Guidance......Page 157 Step 1: Categorize Information System......Page 160 Security Categorization......Page 161 Identifying Information Types......Page 163 Categorizing Information Types......Page 164 Personally Identifiable Information (PII)......Page 165 Categorizing Information Systems......Page 166 Information System Description......Page 169 Information System Registration......Page 170 Step 2: Select Security Controls......Page 171 Common Control Identification......Page 177 Common and Hybrid Control Candidates......Page 178 Security Control Descriptions......Page 179 Tailoring Baseline Controls......Page 180 Monitoring Strategy......Page 183 Relevant Source Material......Page 184 References......Page 185 8 Risk Management Framework Steps 3 & 4......Page 190 Working with Security Control Baselines......Page 191 Assurance Requirements......Page 192 Sources of Guidance on Security Controls......Page 193 Management Controls......Page 197 Technical Controls......Page 198 Step 3: Implement Security Controls......Page 199 Security Engineering and Control Implementation......Page 201 Secure Development, Implementation, and Configuration......Page 202 Commercially Available Security Tools......Page 203 Security Control Documentation......Page 204 Step 4: Assess Security Controls......Page 205 Security Control Assessment Components......Page 207 Assessment Preparation......Page 208 Scoping the Assessment......Page 209 Assessor Qualifications......Page 212 Security Assessment Plan......Page 213 Security Control Assessment......Page 214 Security Assessment Report......Page 215 Remediation Actions......Page 216 Relevant Source Material......Page 217 References......Page 218 9 Risk Management Framework Steps 5 & 6......Page 222 Preparing for System Authorization......Page 223 Step 5: Authorize Information System......Page 225 Plan of Action and Milestones......Page 226 Determining Actions to Include in the POA&M......Page 227 POA&M Content......Page 228 Security Authorization Package......Page 229 Risk Determination......Page 231 Risk Acceptance......Page 232 Step 6: Monitor Security Controls......Page 233 Information System and Environment Changes......Page 236 Ongoing Security Control Assessments......Page 237 Ongoing Remediation Actions......Page 238 Key Updates......Page 239 Security Status Reporting......Page 240 Information System Removal and Decommissioning......Page 241 Relevant Source Material......Page 242 References......Page 243 10 System Security Plan......Page 247 System Security Plan Scope......Page 248 Defining the System Boundary......Page 249 The Role of the SSP within the RMF......Page 251 Structure and Content of the System Security Plan......Page 253 System Security Plan Format......Page 254 System Identification......Page 255 System Categorization......Page 256 Operational Status......Page 257 System Type......Page 258 System Environment......Page 259 Laws, Regulations, and Policies......Page 260 Security Control Selection......Page 261 Security Control Listing......Page 264 Completion and Approval Dates......Page 265 SSP Linkage to Other Key Artifacts......Page 266 Developing the System Security Plan......Page 268 Rules of Behavior......Page 269 Managing System Security Using the SSP......Page 270 Summary......Page 271 References......Page 272 11 Security Assessment Report......Page 276 Security Control Assessors and Supporting Roles......Page 277 Assessor Independence......Page 280 Assessment Resources and Assessor Skills......Page 281 Assessment Timing and Frequency......Page 282 Assessing New Systems Prior to Authorization......Page 283 Assessing (and Reassessing) Operational Systems......Page 284 Scope and Level of Detail......Page 285 Security Control Baselines......Page 287 Controls, Enhancements, and Objectives......Page 288 Report Contents......Page 289 Assessment Methods and Objects......Page 291 Penetration Testing......Page 292 Assessment Determinations......Page 294 Recommendations and Responses......Page 295 Assessment Cases......Page 296 The Security Assessment Report in Context......Page 297 The Purpose and Role of the Security Assessment Report......Page 299 Security Test and Evaluation......Page 300 Relevant Source Material......Page 301 References......Page 302 12 Plan of Action and Milestones......Page 306 Regulatory Background......Page 308 Agency-Level POA&M......Page 309 System-Level POA&M Information......Page 310 Creating POA&M Items......Page 314 Planning for Remediation......Page 317 Weaknesses and Deficiencies......Page 318 Risk Assessments......Page 319 Risk Responses......Page 320 Sources of Weaknesses......Page 321 Timing and Frequency......Page 323 Maintaining and Monitoring the Plan of Action and Milestones......Page 324 Relevant Source Material......Page 325 Summary......Page 326 References......Page 327 Risk Management......Page 330 Threats......Page 333 Likelihood......Page 334 Risk......Page 335 Organizational Perspective......Page 336 Risk Executive......Page 337 Risk Management Strategy......Page 338 Investment Strategy......Page 339 Mission and Business Perspective......Page 340 Enterprise Architecture......Page 341 Information Security Architecture......Page 342 Information System Perspective......Page 343 Trust and Trustworthiness......Page 344 Risk Assumptions......Page 345 Risk Tolerance......Page 347 Assess......Page 348 Threat and Vulnerability Identification......Page 349 Respond......Page 350 Risk Response Identification......Page 351 Risk Response Implementation......Page 352 Risk Monitoring......Page 353 Information System Risk Assessments......Page 354 Risk Models......Page 356 Assessment Methods......Page 357 Prepare......Page 358 Maintain......Page 360 Summary......Page 361 References......Page 362 14 Continuous Monitoring......Page 367 The Role of Continuous Monitoring in the Risk Management Framework......Page 369 Monitoring Strategy......Page 373 Selecting Security Controls for Continuous Monitoring......Page 374 Roles and Responsibilities......Page 375 Continuous Monitoring Process......Page 377 Define ISCM Strategy......Page 380 Establish ISCM Program......Page 381 Performance Metrics......Page 382 Monitoring Frequency......Page 383 ISCM Architecture......Page 384 Analyze Data and Report Findings......Page 385 Respond to Findings......Page 386 Review and Update ISCM Program and Strategy......Page 387 Manual vs. Automated Monitoring......Page 388 Data Gathering......Page 389 Event Management......Page 390 Malware Detection......Page 391 Configuration Management......Page 392 Information Management......Page 393 Aggregation and Analysis......Page 394 Relevant Source Material......Page 395 References......Page 396 Introduction to Contingency Planning......Page 402 Contingency Planning Drivers......Page 403 Contingency Planning Controls......Page 405 Contingency Training......Page 406 Alternate Storage Site......Page 407 Alternate Processing Site......Page 408 Information System Backup......Page 409 Contingency Planning and Continuity of Operations......Page 410 Federal Requirements for Continuity of Operations Planning......Page 411 Distinguishing Contingency Planning from Continuity of Operations Planning......Page 412 Contingency Planning Components and Processes......Page 413 Business Continuity Plan......Page 414 Incident Response Plan......Page 415 Develop Contingency Planning Policy......Page 416 Conduct Business Impact Analysis......Page 417 Identify Preventive Controls......Page 418 Create Contingency Strategies......Page 419 Conduct Plan Testing, Training, and Exercises......Page 421 Testing......Page 422 Developing the Information System Contingency Plan......Page 423 ISCP Introduction and Supporting Information......Page 424 Concept of Operations......Page 425 Activation and Notification......Page 426 Recovery......Page 427 Reconstitution......Page 429 Appendices and Supplemental Information......Page 430 System Development and Engineering......Page 431 Technical Contingency Planning Considerations......Page 432 Client/Server Systems......Page 433 Telecommunications Systems......Page 434 Cloud Computing......Page 435 Relevant Source Material......Page 436 References......Page 437 16 Privacy......Page 443 Privacy Requirements for Federal Agencies Under FISMA and the E-Government Act......Page 444 Privacy Provisions in the E-Government Act of 2002......Page 445 Privacy Protections on Agency Web Sites......Page 447 Reporting on Privacy Practices......Page 448 Privacy and Minimum Security Controls......Page 449 Privacy in FISMA Reporting......Page 450 Federal Agency Requirements Under the Privacy Act......Page 453 Fair Information Practices......Page 454 Restrictions on Collection, Use, and Disclosure......Page 456 Access, Review, and Correction of Records by Individuals......Page 457 Information Management......Page 458 Privacy Impact Assessments......Page 459 Applicability of Privacy Impact Assessments......Page 460 Conducting Privacy Impact Assessments......Page 461 Documenting and Publishing PIA Results......Page 462 Updates to Privacy Impact Assessments for Third-Party Sources......Page 463 Protecting Personally Identifiable Information (PII)......Page 464 Notification Requirements for Breaches of Personally Identifiable Information......Page 466 Privacy Requirements Potentially Applicable to Agencies......Page 468 Health Information Portability and Accountability Act of 1996......Page 470 Financial Services Modernization Act of 1999......Page 471 US Code, Title 38 §5701, §5726, and §7332......Page 472 Relevant Source Material......Page 473 References......Page 474 Network Security......Page 479 US-CERT......Page 480 Comprehensive National Cybersecurity Initiative......Page 481 EINSTEIN......Page 482 Cloud Computing......Page 483 FedRAMP......Page 484 Application Security......Page 485 Federal Information Processing Standards......Page 486 Secure Configuration Checklists......Page 487 Identity and Access Management......Page 488 Personal Identity Verification......Page 489 Electronic Authentication......Page 491 Federal PKI......Page 494 Other Federal Security Management Requirements......Page 495 OMB Memoranda......Page 496 Federal Enterprise Architecture......Page 497 Relevant Source Material......Page 499 References......Page 500 A References......Page 505 Acronyms and Abbreviations......Page 519 Glossary......Page 524 C......Page 543 E......Page 545 F......Page 546 I......Page 547 K......Page 549 N......Page 550 P......Page 551 R......Page 553 S......Page 554 T......Page 557 X......Page 558
Similar books
Физика металлов: Учебное пособие
2013 · PDF
Nanotechnology: Read and Discuss: Учебное пособие
2012 · PDF
Физика металлов: Учебное пособие
2013 · PDF
Материаловедение: Учебное пособие
2017 · ZIP
Наноструктурные стали: Учебное пособие
2014 · ZIP
Физическое металловедение: Практикум
2019 · ZIP