08.05.2016 Views

FY2017 PROPOSED BUDGET

FY2017%20Proposed%20Budget

FY2017%20Proposed%20Budget

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Washington Metropolitan Area Transit Authority<br />

Proposed <strong>FY2017</strong> Budget<br />

Chapter 3<br />

their own IT environment for vulnerabilities and increases awareness and minimize our risk<br />

profile. Automated scan schedules for systems have been initiated which evaluate vulnerabilities<br />

as well as patching on a monthly and quarterly basis, as defined for each type of system. CIS<br />

benchmarks have been created for WMATA databases and continue to be the benchmarks for all<br />

system types throughout the WMATA’s Vulnerability Management Program.<br />

WMATA completed another successful PCI DSS project that lead to receiving another year of<br />

compliance. MITS successfully implemented new, repeatable processes, for collecting artifacts<br />

and answering the call of compliance which has reduced time to completion. Additionally, MITS<br />

submitted a complete process package to help the authority in achieving our ISO-9000<br />

certification. The package is to be used as a template for how to execute a complete process.<br />

The Risk and Compliance department continues to execute and offer support with various audits<br />

to include the FTA, FMO and OIG. Currently MITS is involved with answering the call to<br />

complete the OIG audit on Oracle Databases. MITS created standardized processes for database<br />

security configurations and procedures for database scanning. MITS has also executed an outreach<br />

effort to our counterparts to make them aware of the standardization and assist with efforts to<br />

classify their data. In the past 12 months we have established a process of performing risk<br />

assessment for IT projects and compliance review which includes documented procedures and<br />

forms for performing various risk assessments.<br />

Supported multiple WMATA Bus & Rail projects for initial risk assessment to include Metro<br />

Network extension to Van Buren office, extension of WMATA network to Dulles trailer, and Bus<br />

Traffic Signal Prioritization.<br />

III-80

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!