ad-assurance - RE: [AD-Assurance] Applying FISMA to 800-63
Subject: Meeting the InCommon Assurance profile criteria using Active Directory
List archive
- From: "Capehart,Jeffrey D" <>
- To: "" <>
- Subject: RE: [AD-Assurance] Applying FISMA to 800-63
- Date: Thu, 25 Apr 2013 18:09:34 +0000
- Accept-language: en-US
- Authentication-results: sfpop-ironport05.merit.edu; dkim=neutral (message not signed) header.i=none
David, Excerpting directly from SP-800-63-1 in the Purpose/Introduction, my interpretation of the guidance at step 4 is that completing an SP-800-53 assessment (FISMA)
is acceptable for validating that the required controls for the appropriate assurance level have been met. OMB guidance outlines a 5 step process by which agencies should meet their e-authentication assurance requirements: 1.
Conduct a risk assessment of the government system
2.
Map identified risks to the appropriate assurance level [OMB M-04-04]
3.
Select technology based on e-authentication technical guidance
4.
Validate that the implemented system has met the required assurance level
– As some implementations may create or compound particular risks, agencies should conduct a final validation to confirm that the system achieves the required assurance level for the user-to-agency process. NIST SP
800-53A [SP 800-53A] provides guidelines for the assessment of the implemented system during the validation process. Validation should be performed as part of a security
authorization* process as described in NIST SP 800-37, Revision 1 [SP 800-37].
5.
Periodically reassess the information system to determine technology refresh requirements
This is just a small piece from SP-800-37. *Security
authorization is the official management decision given by a senior organizational official to authorize operation of an information system and to explicitly accept the risk to organizational operations and assets, individuals, other organizations, and
the Nation based on the implementation of an agreed-upon set of security controls. Supplemental Guidance:
The
security authorization package contains: (i) the security plan; (ii) the security assessment report; and (iii) the plan of action and milestones. The information in these key documents is used by authorizing officials to make risk-based authorization
decisions. For information systems inheriting common controls for specific security capabilities, the security authorization package for the common controls or a reference to such documentation is also included in the authorization package. When security controls
are provided to an organization by an external provider (e.g., through contracts, interagency agreements, lines of business arrangements, licensing agreements, and/or supply chain arrangements), the organization ensures that the information needed for authorizing
officials to make risk-based decisions, is made available by the provider. Additional information can be included in the security authorization package at the request of the authorizing official carrying out the authorization action. The contents of the security authorization
package are protected appropriately in accordance with federal and organizational policies. Organizations are strongly encouraged to use automated support tools in preparing and managing the content of the security authorization package… Jeff Capehart, CISA From: [mailto:]
On Behalf Of David Walker Jeffrey,
|
- [AD-Assurance] Applying FISMA to 800-63, Capehart,Jeffrey D, 04/24/2013
- Re: [AD-Assurance] Applying FISMA to 800-63, David Walker, 04/25/2013
- RE: [AD-Assurance] Applying FISMA to 800-63, Brian Arkills, 04/25/2013
- Re: [AD-Assurance] Applying FISMA to 800-63, David Walker, 04/25/2013
- RE: [AD-Assurance] Applying FISMA to 800-63, Eric Goodman, 04/26/2013
- Re: [AD-Assurance] Applying FISMA to 800-63, David Walker, 04/25/2013
- RE: [AD-Assurance] Applying FISMA to 800-63, Capehart,Jeffrey D, 04/25/2013
- Re: [AD-Assurance] Applying FISMA to 800-63, David Walker, 04/25/2013
- RE: [AD-Assurance] Applying FISMA to 800-63, Capehart,Jeffrey D, 04/25/2013
- Re: [AD-Assurance] Applying FISMA to 800-63, Ann West, 04/29/2013
- RE: [AD-Assurance] Applying FISMA to 800-63, Rank, Mark, 04/29/2013
- RE: [AD-Assurance] Applying FISMA to 800-63, Eric Goodman, 04/29/2013
- RE: [AD-Assurance] Applying FISMA to 800-63, Rank, Mark, 04/30/2013
- Re: [AD-Assurance] Applying FISMA to 800-63, Ann West, 04/30/2013
- RE: [AD-Assurance] Applying FISMA to 800-63, Eric Goodman, 04/30/2013
- Re: [AD-Assurance] Applying FISMA to 800-63, David Walker, 04/30/2013
- RE: [AD-Assurance] Applying FISMA to 800-63, Capehart,Jeffrey D, 04/30/2013
- RE: [AD-Assurance] Applying FISMA to 800-63, Rank, Mark, 04/29/2013
- Re: [AD-Assurance] Applying FISMA to 800-63, Ann West, 04/29/2013
- RE: [AD-Assurance] Applying FISMA to 800-63, Capehart,Jeffrey D, 04/25/2013
- Re: [AD-Assurance] Applying FISMA to 800-63, David Walker, 04/25/2013
- RE: [AD-Assurance] Applying FISMA to 800-63, Brian Arkills, 04/25/2013
- Re: [AD-Assurance] Applying FISMA to 800-63, David Walker, 04/25/2013
Archive powered by MHonArc 2.6.16.