From: BankInfoSecurity
House Panel OK’s Federal Information Security Amendments Act
By Eric Chabrow
House panel approved and sent to the entire House of Representatives legislation to reform the Federal Information Security Management Act, the 11-year-old law that governs IT security in the federal government.
The bipartisan Federal Information Security Amendments Act of 2013 unanimously passed the House Oversight and Government Reform Committee by a voice vote on March 20. The measure would require federal agencies to continuously monitor their IT systems for cyberthreats and implement regular threat assessments. The legislation, if enacted, would usurp the current FISMA law that heavily relies on a check-list approach to IT security that many people in government contend doesn’t truly show how secure agencies’ IT systems are.
Each agency would be required to designate an official to be chief information security officer under provisions of the bill. An agency’s chief information officer could serve simultaneously as CISO; however, the bill would require that information security be the CISO’s main focus.
CISO’s Responsibilities
According to the bill, the CISO’s responsibilities would include:
- Overseeing the establishment and maintenance of a security operation that through automated and continuous monitoring can detect, contain and mitigate incidents that impair information security and agency information systems;
- Developing, maintaining and overseeing an agencywide information security program;
- Developing, maintaining and overseeing information security policies, procedures and control techniques to address all applicable requirements;
- Training and overseeing personnel with significant responsibilities for information security;
- Assisting senior agency officials on cybersecurity matters;
- Ensuring the agency has a sufficient number of trained and security-cleared personnel to assist in complying with federal cybersecurity law and procedures;
- Reporting at least annually to agency executives the effectiveness of the agency information security program; information derived from automated and continuous monitoring, including threat assessments; and progress on actions to remediate threats.
Leave a Reply