Real time risk monitoring from the Feds
Federal Security Goes Realtime

White House Cybersecurity Coordinator Howard Schmidt.
The US Federal government is shaping up to require agencies to file real time reports on their information security to a central website under a new set of continious reporting requirements outlined here. This new initiative will build upon the 2002 FISMA legislation but will bring more automation to the collection of compliance and risk information and with a central point of real time collection. The memo requires that agencies will file this information through a structred data feed on at least a monthly basis.
This is an interesting development for regulations, compliance and risk management in general. One of the greatest challanges facing the audit orientated approach to risk and compliance is the fact that it is always historic. Gaining real time situational awareness on the levels of compliance and identifying risk in realtime requires an automated process that can gather information directly from all entities subject to the compliance standard. Only then can you begin to understand the effect compliance is having on risk.
Recent Blogs
- Visa TIP comes the US August 16, 2011
- PCI DSS V2.0 Risk Assessment June 28, 2011
- PCI SSC issues mobile payment app guidance June 24, 2011
- Compliant in the Cloud? Sounds like a reality now! March 9, 2011
- Visa Europe - Understanding PCI DSS Merchant Training Workshop November 25, 2010
- SC Magazine - Most Influential 2010 October 22, 2010
- PCI DSS Merchant Training Nottingham UK June 29, 2010
- Clouds in the sky May 19, 2010
- PCI SSC Releases ISA Details May 8, 2010
- Visa PCI Merchant Training Zagreb April 29, 2010
