The National Security Agency last week announced the first companies to undergo an appraisal of their information security practices in a program aimed at helping government and commercial organizations improve their systems security. According to the Infosec Assessment Training and Rating . . . . The National Security Agency last week announced the first companies to undergo an appraisal of their information security practices in a program aimed at helping government and commercial organizations improve their systems security. According to the Infosec Assessment Training and Rating Program, organizations that need to assess their vulnerability can call on companies that are qualified to perform such assessments within NSA-defined guidelines and standards, according to NSA. This marks the first time civilian agencies have been able to access security assessment companies that have undergone this type of government evaluation and it enables customers to judge whether a provider is capable of meeting its requirements. Many agencies are using the General Services Administration's Safeguard contract, which offers more than 25 vendors who perform such cybersecurity assessments, but GSA does not provide any standard evaluation of the vendors' capabilities. The link for this article located at FCW is no longer available. . The FBI launched an initiative aimed at businesses to evaluate their data protection measures to enhance cybersecurity strategies.. InfoSec Rating,Cybersecurity Assessment,National Security Agency,Vulnerability Evaluation,Security Standards. . LinuxSecurity.com Team
The National Institute of Standards and Technology on Sept. 10 released the final version of a step-by-step guide for agencies to measure the effectiveness of their information security programs and plans. The special publication, "Security Self-Assessment Guide for Information Technology Systems," . . . . The National Institute of Standards and Technology on Sept. 10 released the final version of a step-by-step guide for agencies to measure the effectiveness of their information security programs and plans. The special publication, "Security Self-Assessment Guide for Information Technology Systems," is a how-to guide that complements the CIO Council's Federal IT Security Assessment Framework. The council developed the framework to help agencies determine where, within six levels of effectiveness, their security programs fall and what areas can be improved. The NIST guide provides a questionnaire on security in three areas: management controls, operational controls and technical controls. Within those areas, there are subquestions on 17 topics. One focuses on all the steps necessary to ensure that an agency is providing adequate reviews of its security controls, including asking whether independent reviews are performed whenever key changes are made. The link for this article located at FCW.com is no longer available. . The NIST's conclusive manual assists organizations in evaluating cybersecurity efficiency by means of comprehensive surveys.. NIST Security Guide, Information Security Assessment, Effective Security Practices. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.