Computer Security Division 2009 annual report

2010

The Security Management and Assurance (SMA) Group provides leadership, expertise, outreach, validation, standards and guidelines in order to assist the federal IT community in protecting its information and information systems, which allows our federal custom ers to use these critical assets in accomplishing their missions. OverviewInformation security is an integral element of sound management.Information and information systems are critical assets that support the mission of an organization.Protecting them can be as important as protecting other organizational resources, such as money, physi cal assets, or employees.However, including security considerations in the management of information and computers does not com pletely eliminate the possibility that these assets will be harmed.Ultimately, responsibility for the success of an organization lies with its senior management.They establish the organization's computer security program and its overall program goals, objec tives, and priorities in order to support the mission of the organiza tion.They are also responsible for ensuring that required resources are applied to the program.Collaboration with a number of entities is critical for success.Feder ally, we collaborate with the U.S. Office of Management and Bud get (OMB), the U.S. Government Accountability Office (GAO), the National Security Agency (NSA), the Chief Information Officers (CIO) Council, and all Executive Branch agencies.We also work closely with a number of information technology organizations and stan dards bodies, as well as public and private organizations.Interna tionally we work jointly with the governments of our allies to include Canada, Japan and several European and Asian countries to stan dardize and validate the correct implementation of cryptography.Major initiatives in this area include: • The Federal Information Security Management Act (FISMA) Implementation project; • The Cryptographic Module Validation Program; • The Cryptographic Algorithm Validation Program; • Extended outreach initiatives to federal and nonfederal agencies, state and local governments and international organizations; • Information security training, awareness and education; • Outreach to small and medium business; • Standards development; and • Producing and updating NIST Special Publications (SP) on se curity management topics.Key to the success of this area is our ability to interact with a broad constituency -federal and nonfederal--in order to ensure that our program is consistent with national objectives related to or im pacted by information security.

Read the paper · More papers on PaperTik