08.11.2012 Views

Evaluation of Department of State Information Security Program ...

Evaluation of Department of State Information Security Program ...

Evaluation of Department of State Information Security Program ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

UNCLASSIFIED<br />

Appendix D. Systems With Outdated <strong>Security</strong> Baseline Controls<br />

In the evaluation, we assessed a sample <strong>of</strong> 30 systems (see Appendix I) to determine<br />

whether the systems were in compliance with National Institute <strong>of</strong> Standards and Technology<br />

(NIST) Special Publication (SP) 800-53 Revision 3, Recommended <strong>Security</strong> Controls for<br />

<strong>Information</strong> Systems (August 2009) (last updated May 1, 2010). NIST SP 800-53 Revision 3<br />

provides guidelines for selecting and specifying security controls (management, operational, and<br />

technical) for information systems supporting the executive agencies <strong>of</strong> the Federal Government<br />

to meet the requirements <strong>of</strong> FIPS 200, Minimum <strong>Security</strong> Requirements for Federal <strong>Information</strong><br />

and <strong>Information</strong> Systems.<br />

Table 1 lists the systems for which security controls have not been updated to comply<br />

with NIST SP 800-53 Revision 3. 1<br />

Table 1. Systems With Outdated <strong>Security</strong> Baseline Controls<br />

Sample # Bureau Name Package Type FIPS Compliance<br />

Name No. Categorization (Y/N)<br />

1 A ILMS 830 UNCL M N<br />

2 CA IVAMS 97 UNCL M N<br />

3 CA FEP 344 UNCL M N<br />

4 CA PLOTS 346 UNCL M N<br />

5 CA CLASS 558 UNCL H N<br />

6 CA MIS 724 UNCL M N<br />

7 CA OPSS 898 UNCL M N<br />

8 CA PLMS 4547 UNCL M N<br />

9 DS CMS 424 UNCL M N<br />

10 DS SIMAS 798 UNCL M N<br />

11 DS IDMS 1000 UNCL M N<br />

12 EUR EXTRANE<br />

T<br />

1140 UNCL L N<br />

1<br />

OMB Memorandum M-11-33 FY 2011 FAQs states that agencies are expected to be in compliance with NIST<br />

standards and guidelines within one year <strong>of</strong> the publication date unless otherwise directed by OMB.<br />

48<br />

UNCLASSIFIED

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!