Standards body drafts guide on preventing data breaches

The National Institute for Standards and Technology has released a draft of its new guide to better protect federal agencies from data breaches.

The 387-page guide is designed to help agency technical teams evaluate whether the security controls they have actually work as intended to protect information systems from being compromised.

It is designed as a companion to an earlier publication on minimum security controls for federal information systems. That guide, according to lead author Ron Ross, defines the different security controls required by the federal government -- including encryption, identification and authentication of users, access control to systems, personnel security and physical security.

The latest publication lists the different security measures and explains how to test them. For example, for continuity of operation requirements, the report outlines how to determine if an agency really has developed a plan, if people understand it and if it has been distributed to the right people within the organization.

The 2002 Federal Information Security Management Act instructs NIST to prepare minimum computer-security requirements for all systems other than those connected to national security, which have separate rules.

"The assessment requirements presented in this latest draft are intended to make compliance with FISMA easier, more efficient, and ultimately to produce better computer and information security for the federal government," said Ross, who is the FISMA implementation project leader at NIST.

Ross said the report is the last in a series since 2003 and is designed o make security procedures more cost-effective and easier to implement. NIST is asking for comments through the end of next month. The guidelines could help federal agencies, which received a grade of C-minus for FISMA compliance for 2006.

Sen. Norm Coleman, R-Minn., has introduced legislation that would amend FISMA rules to broaden the definition of sensitive personal data and direct the White House Office of Management and Budget to establish policies that agencies should follow after data breaches.

In addition to names, Social Security numbers, birth dates and places, mother's maiden names, and biometric records, the bill would include education, criminal, medical and employment history. The measure, S. 1558, also would give agency chief information officers more power to enforce compliance with security rules.

"In the wake of data breaches at the Departments of Veterans Affairs, Commerce, Agriculture, the [Transportation Security Administration] and IRS, we must ensure that federal agencies are taking the necessary preventative security measures to protect our citizens' personal information," Coleman said. "In addition to establishing a new protocol, this legislation will also create a system for notifying victims in the event of a security breach."

The Senate bill is designed as a companion to a House bill, H.R. 2124. Unlike broader data-protection measures drafted or being drafted by other committees, the bills would apply to just personal data stored by the federal government.

Stay up-to-date with federal news alerts and analysis — Sign up for GovExec's email newsletters.
Close [ x ] More from GovExec

Thank you for subscribing to newsletters from
We think these reports might interest you:

  • Going Agile:Revolutionizing Federal Digital Services Delivery

    Here’s one indication that times have changed: Harriet Tubman is going to be the next face of the twenty dollar bill. Another sign of change? The way in which the federal government arrived at that decision.

  • Cyber Risk Report: Cybercrime Trends from 2016

    In our first half 2016 cyber trends report, SurfWatch Labs threat intelligence analysts noted one key theme – the interconnected nature of cybercrime – and the second half of the year saw organizations continuing to struggle with that reality. The number of potential cyber threats, the pool of already compromised information, and the ease of finding increasingly sophisticated cybercriminal tools continued to snowball throughout the year.

  • Featured Content from RSA Conference: Dissed by NIST

    Learn more about the latest draft of the U.S. National Institute of Standards and Technology guidance document on authentication and lifecycle management.

  • GBC Issue Brief: The Future of 9-1-1

    A Look Into the Next Generation of Emergency Services

  • GBC Survey Report: Securing the Perimeters

    A candid survey on cybersecurity in state and local governments

  • The New IP: Moving Government Agencies Toward the Network of The Future

    Federal IT managers are looking to modernize legacy network infrastructures that are taxed by growing demands from mobile devices, video, vast amounts of data, and more. This issue brief discusses the federal government network landscape, as well as market, financial force drivers for network modernization.

  • eBook: State & Local Cybersecurity

    CenturyLink is committed to helping state and local governments meet their cybersecurity challenges. Towards that end, CenturyLink commissioned a study from the Government Business Council that looked at the perceptions, attitudes and experiences of state and local leaders around the cybersecurity issue. The results were surprising in a number of ways. Learn more about their findings and the ways in which state and local governments can combat cybersecurity threats with this eBook.


When you download a report, your information may be shared with the underwriters of that document.