11.01.2017 Views

A Technical History of the SEI

ihQTwP

ihQTwP

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

People who work in small organizations liked <strong>the</strong> OCTAVE approach but needed a streamlined<br />

method to accommodate <strong>the</strong>ir staff size, schedules, and budgets. In response, <strong>the</strong> <strong>SEI</strong> developed<br />

OCTAVE-S [Alberts 2005]. 47 While remaining consistent with OCTAVE principles, OCTAVE-S<br />

provides organizations <strong>of</strong> fewer than 100 people with an efficient, inexpensive approach to identifying<br />

and managing information security risks. Both OCTAVE and OCTAVE-S are supported<br />

with guidance, worksheets, and questionnaires. The <strong>SEI</strong> developed ano<strong>the</strong>r alternative, OCTAVE<br />

Allegro [Caralli 2007], in response to OCTAVE users<br />

who were looking for a more information-centric<br />

method that could be institutionalized at <strong>the</strong> operational<br />

unit level. Allegro helps businesses identify <strong>the</strong>ir information<br />

assets and determine how those assets are at risk<br />

by putting <strong>the</strong>m in <strong>the</strong> context <strong>of</strong> “containers”—places<br />

where information is stored, transmitted, or processed.<br />

While Allegro can be used in a collaborative workshop<br />

style like <strong>the</strong> original OCTAVE methods, it is also well<br />

suited for individuals who want to perform a risk assessment<br />

without extensive organizational involvement or<br />

expertise. Allegro developers reduced <strong>the</strong> amount <strong>of</strong> risk<br />

analysis and IT knowledge needed, and simplified instructions<br />

and worksheets.<br />

The Consequence: Enterprise Risk<br />

Management and Security Improvement<br />

Organizations using <strong>the</strong> OCTAVE product suite have<br />

control over <strong>the</strong>ir information security activities [Shantamurthy<br />

2011]. Managers can develop a protection<br />

strategy that is appropriate for <strong>the</strong>ir particular organizations’<br />

mission and priorities, a strategy that addresses<br />

policy, management, administrative, and technological<br />

aspects, among o<strong>the</strong>rs. As a result <strong>of</strong> <strong>SEI</strong> evaluations,<br />

government and commercial organizations have a<br />

The View from O<strong>the</strong>rs<br />

Conducting a security risk analysis<br />

has long been a requirement <strong>of</strong> <strong>the</strong><br />

HIPAA Security Rule and is also<br />

necessary to achieve Stage 1 and<br />

Stage 2 Meaningful Use regarding<br />

<strong>the</strong> use <strong>of</strong> electronic health records<br />

(“EHR") systems. OCTAVE<br />

Allegro provides us with a useful<br />

framework for assessing risks to<br />

ePHI, including EHR’s, while at<br />

<strong>the</strong> same time providing <strong>the</strong> evidentiary<br />

requirements necessary<br />

for regulatory compliance. Our<br />

clients need something that is easy<br />

to deploy, repeatable, underpinned<br />

by good practice and OCTAVE<br />

provides this.<br />

– Greg Porter, Founder,<br />

Principal Consultant,<br />

Allegheny Digital<br />

clearer view <strong>of</strong> <strong>the</strong>ir information security risk and control over <strong>the</strong>ir security posture. They manage<br />

<strong>the</strong>ir risk through improvement efforts and periodic assessments, which <strong>the</strong>y schedule and<br />

perform at <strong>the</strong>ir own discretion. Many organizations establish a multidisciplinary team that can<br />

perform <strong>the</strong> follow-up assessments and act as a focal point for <strong>the</strong> improvement efforts. Important<br />

organizational and individuals’ information are protected. As a result, <strong>the</strong> organizations improve<br />

not only <strong>the</strong>ir own risk pr<strong>of</strong>ile but also that <strong>of</strong> <strong>the</strong> sectors to which <strong>the</strong>y belong—thus contributing<br />

to national security.<br />

One example <strong>of</strong> information protection and security improvement is <strong>the</strong> use <strong>of</strong> <strong>the</strong> OCTAVE<br />

method and OCTAVE Allegro by various agencies <strong>of</strong> <strong>the</strong> county government <strong>of</strong> Clark County,<br />

Nevada. Clark County adopted <strong>the</strong> OCTAVE method as a way to comply with <strong>the</strong> federal HIPAA<br />

47 The development <strong>of</strong> OCTAVE-S was sponsored by <strong>the</strong> <strong>SEI</strong> Technology Insertion, Demonstration,<br />

and Evaluation (TIDE) program, created to help small manufacturing enterprises adopt state-<strong>of</strong>-<strong>the</strong>practice<br />

technologies.<br />

CMU/<strong>SEI</strong>-2016-SR-027 | SOFTWARE ENGINEERING INSTITUTE | CARNEGIE MELLON UNIVERSITY 189<br />

Distribution Statement A: Approved for Public Release; Distribution is Unlimited.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!