About Us

InformationWeek Analytics' experienced analysts arm business technology decision-makers with real-world perspective based on a combination of qualitative and quantitative research, business and technology assessment and planning tools, and technology adoption best practices gleaned from experience.

Read More >>

Briefs

Informed CIO: Cyber Security

Informed CIO: Cyber Security

Integrity Check: 5 Steps to Data-Centric Cyber Security

Change is the only constant. This is particularly true in the cat-and-mouse world of information security. With a constant flow of zero-day attacks and malevolent—albeit not always innovative—thinking on how to best exploit hardened systems, data defenders need to be ever vigilant. Certainly, public- and private-sector CIOs are constantly bombarded with new silver-bullet applications, appliances and techniques aimed at providing enhanced protective controls. But even the most sophisticated tool is of limited value if we don’t understand a key tenet: Sensitive data can still be vulnerable even when placed within a well-protected infrastructure.

It’s the age-old problem of having strong, solid exterior walls and limited additional inside defenses. The analog in the information technology realm is that of very strong perimeter defenses (firewalls, IPS, hardened border routers) at interconnection points, but only limited supplemental controls at the “trusted” core of the enterprise. Although it’s an archaic assumption that firewalls alone constitute an adequate defense, in our practice, we still see the occasional IT group that subscribes to this approach’s effectiveness. More progressive organizations, often with significant investments in information assurance technologies, may be better protected, but even they can be lulled into a false sense of security when their systems are surrounded by sophisticated network appliances, intimidating physical security controls and exhaustively documented security policies.

In our recent InformationWeek Analytics Government IT Priorities survey of federal technology decision-makers, cyber security was the No. 1 IT initiative within respondents’ organizations in terms of importance and current leadership focus (ahead of data records management and DR planning). For most of these shops, cyber security means dealing with the Federal Certification and Accreditation (C&A) process required by FISMA. This mandated approach is highly proscriptive: There are 17 separate control families with which to comply, each bringing its own specific directives. Although some of these can be deferred by using common controls for the organization (for example, information security policy or incident handling) others cannot be—and rightly so.

The upside to FISMA and the ensuing NIST documentation is that agencies have a consistent and broadly applicable standard for how information security should be applied to systems that are deemed to warrant a given classification level. The downside is that the true goal of adequately securing sensitive information and preserving core mission processing sometimes gets lost in a maze of requirements. By proposing a highly data-centric approach, we’ll help agency CIOs and CISOs refocus their security programs back to the essential precept of protecting information.

Table of Contents

    3 Author's Bio
    4 Executive Summary
    6 Render Unto the Common Controls...
    6 Figure 1: IT Priorities
    7 Figure 2: Decline in Government Reliance on Contractors?
    8 Figure 3: Federal Initiative Success
    11 Figure 4: Current and Planned Encryption Use
    13 Look for the Seal
    14 Figure 5: Defining User Roles and Responsibilities
    16 Figure 6: Identity Authentication
    17 Figure 7: DLP Product Capabilities
    19 Think Outside the FISMA Box
    10 Steps to Data-Centric Cyber Security:
    9 1 | Master controls are out. Think data-centric instead.
    10 2 | Embrace data encryption.
    14 3 | Implement strong authentication controls.
    16 4 | Use data loss prevention to “watch the watchers.”
    18 5 | Layer on data integrity controls.

About the Author

Research: Affordable Conformance With Multiple Regulations

Richard Dreger is president of WaveGard, a vendor-neutral security consulting firm. Rick has significant, broad-based technology experience with extensive skills in the information assurance, security and wireless networking fields. He has consulted for a wide breadth of clients in both the public and private sectors, and his professional background includes over 15 years of experience in Fortune 100 companies as well as smaller technology consulting firms.

Rick has complemented his hands-on consulting experience by leading courses such as the CWNP wireless curriculum and the (ISC)2 CISSP review. In addition to being one of the 11 founding members of the Certified Wireless Network Experts (CWNE) roundtable, he is also coauthor of the Certified Wireless Security Professional (CWSP) v2 study guide and numerous InformationWeek articles. Rick obtained his BSE from Duke University and his Masters from Villanova University.

Become a Member Close

Benefits of becoming a member of InformationWeek Analytics

  • Basic
  • Requires registration only, download, rate and comment on all briefs and sponsored reports.

  • Premium
  • Special inaugural rate: $99 per month (normally $199). Download and rate on all content; access all research reports

  • Corporate
  • Yearly rates for multiple user access.


Membership Signup Already a member? Login

Related Reports

Cybersecurity Balancing Act

Cybersecurity Balancing Act

Government IT pros face growing threatsand compliance requirements

Continue Reading >>

Research: Government IT Priorities

Research: Government IT Priorities

Agency tech chiefs are under the gun to meet challenges in cyber security, green IT, business intelligence, the IPv6 transition and other initiatives. We analyzed our poll of more than 300 government technology professionals and developed recommendations to help federal IT pros, and the consultants and vendors that support them, advance the new administration's goals.

Continue Reading >>

Informed CIO: 7 Key Issues for Government Backups

Informed CIO: 7 Key Issues for Government Backups

Managing and protecting huge amounts of data is a hot-button issue for many federal agencies. In this InformationWeek Analytics Informed CIO report,we discuss a strategy for being effective stewards of public information.

Continue Reading >>

Research: Government 2.0

Research: Government 2.0

The much-anticipated Open Government Directive will come at a time when federal CIOs already face unprecedented resource, technology and process challenges. Two things are clear: A new type of chief is needed to bring about significant evolution in public-sector IT delivery, and this is a journey, not a destination. Here's our guide.

Continue Reading >>

Strategy: Efficient Data Centers

Strategy: Efficient Data Centers

Strategy Session: Energy-Efficient Government Data Centers

Continue Reading >>