opencontrol / discuss

a place to have conversations about OpenControl projects
https://github.com/opencontrol/discuss/issues
Other
16 stars 0 forks source link

introductions to security compliance? #57

Open afeld opened 5 years ago

afeld commented 5 years ago

@pburkholder posed a good question:

For FISMA and ATO overviews...any other talks you would recommend in addition to https://youtu.be/-Nc4GXPxpQg?

That video could use an update, but was (as it says) everything I knew at the time. In terms of documentation, I then put what I knew into Before You Ship.

Anyone else know of good introductory materials? Assuming an audience of tech but not government experience, I guess?

cc @brittag @wslack

pburkholder commented 5 years ago

@afeld Did you ever get answers to your questions:

That said, this video pretty concise and easy to follow but

brasky commented 5 years ago

Everything from 5:00 (The "what" section) to 26:00 (The section where FedRAMP LI SaaS, now FedRAMP Tailored is mentioned) is good information for anyone who wants to know learn about compliance.

Some of your questions have pretty long explanations, and with the NIST website down for the shutdown it's hard to cite all the exact laws.

Q: What is stopping the AO to say yes to everything? A: Before 2011 (that memorandum) agencies could choose their own controls, but even worse they could manage their own assessments which you can imagine how effective that is. Basically nothing was stopping them. Now there is (slightly) more oversight, see next question.

Q: Does FedRAMP have government authority? A: FedRAMP does have some authority, but only really through proxy of the OMB. FedRAMP is a program not an agency, which is why FedRAMP can't issue an ATO, only a P-ATO (provisional), which is really more of a thumbs up than a rubber stamp except that the OMB and JAB says it's legit, plus the JAB is made up of CIOs from GSA, DoD, and DHS, which if they give you approval most other agencies will just trust.

The chain of command in a nutshell (without going back too far) goes something like:

And now we're here today (basically)! Sorry for the wall of text but I haven't actually ever had to type this out so it was kind of fun. In terms of talks, there really is next to no content out there... There's fedramp.gov/training ...

pburkholder commented 5 years ago

@brasky That's helpful context. Coincidentally, Aidan's talk was posted 27 July 2016, and A-130 was updated the next day: https://www.federalregister.gov/documents/2016/07/28/2016-17872/revision-of-omb-circular-no-a-130-managing-information-as-a-strategic-resource.

brasky commented 5 years ago

This reddit thread just popped up about how to better understand NIST and there was a good comment with a few videos about 800-171 that could be useful.

For anyone diving into the world of Federal government cybersecurity frameworks and compliance, these videos might be helpful. None of this is strictly 800-53, but the 800-171 stuff is pretty useful to understand as well.

4 hours https://youtu.be/6mdVTPk6jlE

8.5 hours https://youtu.be/qk5J4gFysLU

I've found a lot of good resources with webinars like via Brighttalk as well. Might as well start with the free stuff first if you want a starter.

Also, here is a link to a really informative FAQ that NIST published in April of 2018. It’s about 50 pages. The new stuff is highlighted in yellow.

[http://www.berenzweiglaw.com/wp-content/uploads/2018/05/Revision-to-Cyber-DFARS-FAQs-7012-etc.-April-2-2018-37165xC5166.pdf]

wslack commented 5 years ago

@Jkrzy might have ideas?

afeld commented 5 years ago

Launched a new site for this - see #70.

its-a-lisa commented 4 years ago

suggest closing this based on the new site existing