Automation support for security control assessments:
Kelley L. Dempsey, Nedim Goren, Paul W. Eavy, George Moore · 2018
The National Institute of Standards and Technology (NIST) and the Department of Homeland Security (DHS) have collaborated to produce this report which describes a process that automates the test assessment method described in NIST Special Publication (SP) 800-53A for the security controls catalogued in SP 800-53.The process is consistent with the Risk Management Framework as described in SP 800-37 and the Information Security Continuous Monitoring (ISCM) guidance in SP 800-137.The multi-volume NIST Interagency Report 8011 (NISTIR 8011) has been developed to provide information on automation support for ongoing assessment.NISTIR 8011 describes how ISCM facilitates automated ongoing assessment to provide near real-time security-related information to organizational officials on the security posture of individual systems and the organization as a whole.NISTIR 8011 Volume 1 includes a description of ISCM Security Capabilities-groups of security controls working together to achieve a common purpose.The subsequent NISTIR 8011 volumes are capability-specific volumes.Each volume focuses on one specific ISCM information security capability in order to (a) add tangible detail to the more general overview given in NISTIR 8011 Volume 1; and (b) provide a template for the transition to detailed, standards-based automated assessments.This publication, Volume 3 of NISTIR 8011, addresses the information security capability known as Software Asset Management (SWAM).The focus of the SWAM capability is to manage risk created by unmanaged or unauthorized software that are on a managed network.When software is unmanaged or unauthorized, they are vulnerable because the software files may be forgotten or unidentified.Moreover, when vulnerabilities are discovered on such software, responsibility to respond to the consequent risk is not assigned.As a result, the presence of unmanaged and unauthorized software means that devices are targets that attackers can use as a persistent platform from which to attack components on the network.A well-designed SWAM program helps to:• prevent compromised software from being installed or staying deployed on the network;• prevent attackers from gaining a foothold;• prevent attacks from becoming persistent; and• restore required and authorized software as needed.Automated ongoing assessment helps verify that software asset management is working by applying defect checks to test the effectiveness of the SWAM capability and the security controls that support the SWAM capability.This volume outlines detailed step-by-step processes to meet the needs of a specific assessment target network and apply the results to the assessment of all authorization boundaries on that network.A process is also provided to implement the assessment (diagnosis) and response.Automated testing related to the controls for SWAM, as outlined herein, is consistent with other NIST guidance.1 Derived from the Control Allocation Tables (CAT) in this volume.With respect to security controls selected in the SP 800-53 Low-Medium-High baselines that support the SWAM capability, 75 of 81 determination statements (92.6%) can be fully or partially automated.