Standards body drafts guide on preventing data breaches

The National Institute for Standards and Technology has released a draft of its new guide to better protect federal agencies from data breaches.

The 387-page guide is designed to help agency technical teams evaluate whether the security controls they have actually work as intended to protect information systems from being compromised.

It is designed as a companion to an earlier publication on minimum security controls for federal information systems. That guide, according to lead author Ron Ross, defines the different security controls required by the federal government -- including encryption, identification and authentication of users, access control to systems, personnel security and physical security.

The latest publication lists the different security measures and explains how to test them. For example, for continuity of operation requirements, the report outlines how to determine if an agency really has developed a plan, if people understand it and if it has been distributed to the right people within the organization.

The 2002 Federal Information Security Management Act instructs NIST to prepare minimum computer-security requirements for all systems other than those connected to national security, which have separate rules.

"The assessment requirements presented in this latest draft are intended to make compliance with FISMA easier, more efficient, and ultimately to produce better computer and information security for the federal government," said Ross, who is the FISMA implementation project leader at NIST.

Ross said the report is the last in a series since 2003 and is designed o make security procedures more cost-effective and easier to implement. NIST is asking for comments through the end of next month. The guidelines could help federal agencies, which received a grade of C-minus for FISMA compliance for 2006.

Sen. Norm Coleman, R-Minn., has introduced legislation that would amend FISMA rules to broaden the definition of sensitive personal data and direct the White House Office of Management and Budget to establish policies that agencies should follow after data breaches.

In addition to names, Social Security numbers, birth dates and places, mother's maiden names, and biometric records, the bill would include education, criminal, medical and employment history. The measure, S. 1558, also would give agency chief information officers more power to enforce compliance with security rules.

"In the wake of data breaches at the Departments of Veterans Affairs, Commerce, Agriculture, the [Transportation Security Administration] and IRS, we must ensure that federal agencies are taking the necessary preventative security measures to protect our citizens' personal information," Coleman said. "In addition to establishing a new protocol, this legislation will also create a system for notifying victims in the event of a security breach."

The Senate bill is designed as a companion to a House bill, H.R. 2124. Unlike broader data-protection measures drafted or being drafted by other committees, the bills would apply to just personal data stored by the federal government.

Stay up-to-date with federal news alerts and analysis — Sign up for GovExec's email newsletters.
Close [ x ] More from GovExec

Thank you for subscribing to newsletters from
We think these reports might interest you:

  • Forecasting Cloud's Future

    Conversations with Federal, State, and Local Technology Leaders on Cloud-Driven Digital Transformation

  • The Big Data Campaign Trail

    With everyone so focused on security following recent breaches at federal, state and local government and education institutions, there has been little emphasis on the need for better operations. This report breaks down some of the biggest operational challenges in IT management and provides insight into how agencies and leaders can successfully solve some of the biggest lingering government IT issues.

  • Communicating Innovation in Federal Government

    Federal Government spending on ‘obsolete technology’ continues to increase. Supporting the twin pillars of improved digital service delivery for citizens on the one hand, and the increasingly optimized and flexible working practices for federal employees on the other, are neither easy nor inexpensive tasks. This whitepaper explores how federal agencies can leverage the value of existing agency technology assets while offering IT leaders the ability to implement the kind of employee productivity, citizen service improvements and security demanded by federal oversight.

  • IT Transformation Trends: Flash Storage as a Strategic IT Asset

    MIT Technology Review: Flash Storage As a Strategic IT Asset For the first time in decades, IT leaders now consider all-flash storage as a strategic IT asset. IT has become a new operating model that enables self-service with high performance, density and resiliency. It also offers the self-service agility of the public cloud combined with the security, performance, and cost-effectiveness of a private cloud. Download this MIT Technology Review paper to learn more about how all-flash storage is transforming the data center.

  • Ongoing Efforts in Veterans Health Care Modernization

    This report discusses the current state of veterans health care


When you download a report, your information may be shared with the underwriters of that document.