Standards body drafts guide on preventing data breaches

The National Institute for Standards and Technology has released a draft of its new guide to better protect federal agencies from data breaches.

The 387-page guide is designed to help agency technical teams evaluate whether the security controls they have actually work as intended to protect information systems from being compromised.

It is designed as a companion to an earlier publication on minimum security controls for federal information systems. That guide, according to lead author Ron Ross, defines the different security controls required by the federal government -- including encryption, identification and authentication of users, access control to systems, personnel security and physical security.

The latest publication lists the different security measures and explains how to test them. For example, for continuity of operation requirements, the report outlines how to determine if an agency really has developed a plan, if people understand it and if it has been distributed to the right people within the organization.

The 2002 Federal Information Security Management Act instructs NIST to prepare minimum computer-security requirements for all systems other than those connected to national security, which have separate rules.

"The assessment requirements presented in this latest draft are intended to make compliance with FISMA easier, more efficient, and ultimately to produce better computer and information security for the federal government," said Ross, who is the FISMA implementation project leader at NIST.

Ross said the report is the last in a series since 2003 and is designed o make security procedures more cost-effective and easier to implement. NIST is asking for comments through the end of next month. The guidelines could help federal agencies, which received a grade of C-minus for FISMA compliance for 2006.

Sen. Norm Coleman, R-Minn., has introduced legislation that would amend FISMA rules to broaden the definition of sensitive personal data and direct the White House Office of Management and Budget to establish policies that agencies should follow after data breaches.

In addition to names, Social Security numbers, birth dates and places, mother's maiden names, and biometric records, the bill would include education, criminal, medical and employment history. The measure, S. 1558, also would give agency chief information officers more power to enforce compliance with security rules.

"In the wake of data breaches at the Departments of Veterans Affairs, Commerce, Agriculture, the [Transportation Security Administration] and IRS, we must ensure that federal agencies are taking the necessary preventative security measures to protect our citizens' personal information," Coleman said. "In addition to establishing a new protocol, this legislation will also create a system for notifying victims in the event of a security breach."

The Senate bill is designed as a companion to a House bill, H.R. 2124. Unlike broader data-protection measures drafted or being drafted by other committees, the bills would apply to just personal data stored by the federal government.

Stay up-to-date with federal news alerts and analysis — Sign up for GovExec's email newsletters.
Close [ x ] More from GovExec

Thank you for subscribing to newsletters from
We think these reports might interest you:

  • Sponsored by G Suite

    Cross-Agency Teamwork, Anytime and Anywhere

    Dan McCrae, director of IT service delivery division, National Oceanic and Atmospheric Administration (NOAA)

  • Data-Centric Security vs. Database-Level Security

    Database-level encryption had its origins in the 1990s and early 2000s in response to very basic risks which largely revolved around the theft of servers, backup tapes and other physical-layer assets. As noted in Verizon’s 2014, Data Breach Investigations Report (DBIR)1, threats today are far more advanced and dangerous.

  • Federal IT Applications: Assessing Government's Core Drivers

    In order to better understand the current state of external and internal-facing agency workplace applications, Government Business Council (GBC) and Riverbed undertook an in-depth research study of federal employees. Overall, survey findings indicate that federal IT applications still face a gamut of challenges with regard to quality, reliability, and performance management.

  • PIV- I And Multifactor Authentication: The Best Defense for Federal Government Contractors

    This white paper explores NIST SP 800-171 and why compliance is critical to federal government contractors, especially those that work with the Department of Defense, as well as how leveraging PIV-I credentialing with multifactor authentication can be used as a defense against cyberattacks

  • Toward A More Innovative Government

    This research study aims to understand how state and local leaders regard their agency’s innovation efforts and what they are doing to overcome the challenges they face in successfully implementing these efforts.

  • From Volume to Value: UK’s NHS Digital Provides U.S. Healthcare Agencies A Roadmap For Value-Based Payment Models

    The U.S. healthcare industry is rapidly moving away from traditional fee-for-service models and towards value-based purchasing that reimburses physicians for quality of care in place of frequency of care.

  • GBC Flash Poll: Is Your Agency Safe?

    Federal leaders weigh in on the state of information security


When you download a report, your information may be shared with the underwriters of that document.