Proposed FY 2010 FISMA Performance Metrics

OMB has released a draft set of performance metrics for FISMA 2010 reporting. The metrics are focused on several key areas:

  • Real time system, hardware, software, connection, and training inventory and configuration management. OMB is looking to see how well agencies can discovery authorized and unauthorized hardware, software, and connections in the agencies enterprise.
  • How well the agency's has Integrated Security into the System Develop Lifecycle (SDLC)
  • How well Incident Management is integrated into the agency's Security Operation Center and Network Operation Center
  • Does the agency's use appropriate Identity & Access Management (IdAM) mechanisms to access sensitive agency information
  • Has the agency integrated Data Leakage Prevention (DLP) technologies and procedures into the agency's environment
  • Does the agency provide real to near real time enterprise-wise cybersecurity situational awareness

It appears that OMB is continuing to drive agencies to real time automated cybersecurity solutions

AttachmentSize
draft-omb-fy2010-security-metrics.pdf106.02 KB