Agencies to follow new IT security standards
ONDI and DOD this week announced the seven areas of certification and accreditation for information technology systems that they will standardize.
The Office of the National Director of National Intelligence (ONDI) and the Defense Department this week announced the seven areas of certification and accreditation for information technology systems that they will standardize.
The next step is a group of small implementation teams that will begin developing the how the agencies will use these new policies, said Dale Meyerrose, ODNI's chief information officer and associate director of national intelligence. He was speaking at the FOSE trade show last week in Washington. D.C.
Meyerrose announced four of the seven areas during his speech at FOSE, and today ODNI and DOD made public the other three areas.
DOD and ODNI will:
- Define a common set of trust levels so both departments share information and connect systems more easily.
- Adopt reciprocity agreements to reduce systems development and approval time.
- Define common security controls using the National Institute of Standards and Technology's Special Publication 800-53 as a starting point.
- Agree to common definitions and an understanding of security terms, starting with the Committee on National Security Systems 4009 glossary as a baseline.
- Implement a senior risk executive function to base an enterprise view of all factors, including mission, IT, budget and security.
- Operate IT security within the enterprise operational environments, enabling situational awareness and command and control.
- Institute a common process to incorporate security engineering within life cycle processes.
Jason Miller is assistant managing editor of Government Computer Newsan 1105 Government Information Group publication
NEXT STORY: Networx shocker