Trade secrets
On the point of “where” we find things, valid security portals meet every resource information criteria, with one providing particular advantage to audit. They explain their current legal mandates and current best strategies for implementation of specific published standards. For example, “OMB Circular A-130: Management of Federal Information Resources[78]," OMB Circular A-119, Federal Participation in the Development and Use of Voluntary Consensus Standards and in Conformity Assessment Activities[79], The Cyber Security Research and Development Act[80], enforce, among other things, National Institute of Standards and Technology (NIST)[81] authority to perform oversight, research and development, management and distribution of security standards and various benchmarking tools. Security Technical Implementation Guides (STIGS)[82], found at DISA Checklists / Implementation Guides, exemplify a regulated and monitored security source. Equal in rank, and including duplication in some areas of information, is the Center for Internet Security (CIS). CIS checklists[83] are categorized by use, as applied to various industry requirements. U.S. Commerce Department's Technology Administration funding and guidance to NIST is a part of our United States Law, and plays a leading role in our “National Strategy to Secure Cyberspace[84].” The works produced by NIST, under U.S. Commerce Department's Technology administration’s authority, is “critical” and essential to our practice. It’s at the top of my list.
You can’t make me download!
It took several days just to review publication dates, document contents, organizations and authors. In spite of Mount Must Read™, I resisted impulses to save and print. The titles remained in their native homes, while records only stored hyperlinks, along with background details and high level metadata regarding criticality, use and contents. The most notable reference was a very short document simply listing titles used to evaluated best security practices by the House of Representatives committee known as the CISWG[85]. United States Cyber Security Reference List[86] highlights a standards review process resulting in improvements to the way we define, prevent, regulate, and criminally penalize cyber crimes. CISWG Human and Eagle efforts continue to impact law, standards, and technology as an industry[87]. Under the Directive of the Cyber Security Enhancement Act, Report To The Congress: Increased Penalties For Cyber Security Offenses (As Required By Section 225(C) of The Homeland Security Act of 2002, Public Law 107-296), provides excellent summary of laws designed to manage international and national cyber risk, explaining the nature of data privacy rulings and the need for greater controls, in a manner I found unsurpassed[88].
GAO, is that you?
Beware of our Government Accountability office, GAO. Pack a lunch before you launch, as you may become glued to the monitor for the next several days. Auditors and IT professionals will feel compelled to read the “Yellow Book” series, but my advice is to go straight for the Federal Information and Communications Audit Management Guide (FISCAM)[89]. Skip the search for Cliff Notes. You simply have to put on high boots and march through these pages one at a time. Having a mental picture of FISCAM’s framework will alter all future thinking in terms of what is available to us in the world of audit.
A mental hierarchy will evolve. With visibility, you gain confidence in the knowledge that two reams of unread white papers are, by virtue, obsolete better practices. This is a reminder that federally mandated standards (FIPS) should be exclusively viewed at the Computer Security Resource Center’s (CSRC's) Computer Security Division (CSD) web site, which is the only place that holds responsibility for their distribution and content[90]. Similarly, keep COBIT® standards linked to the ISACA web site and check back often for new release and updates. There are thousands of sites posting rogue copies of out of date standards. As IT professionals, this is a habit we all should break.
If this is your first exposure to the words FIPS and NIST, excellent presentations by Marianne Swanson and Dr. Ron Ross can help to quickly fill in what you missed[91]. As indicated in their presentations, they collectively manage projects, publications, and training for the Computer Security Division of the Information Technology Laboratory at NIST. In draft, NIST SP 800 53-a, identifies Dr. Ross as government appointed FISMA Implementation Project Leader. Most recently, Dr. Ross made publicly available, Building More Secure Information Systems[92], A Strategy for Effectively Applying the Provisions of FISMA.
Regarding recovery
I knew I’d completely lost my mind. Anyone with impulse to wrap their head in tin foil in order to conceal thoughts from a stack of reading material, (even if the stack has glaring eyes, and a pitching arm), is minimally experiencing “a cry for help.” I made many calls, left messages, demanding information about my anesthesia and the array of federally regulated recovery aids. NFL nurses kept me from reaching the surgeon, since apparently paranoid delusional panic is completely normal. The nurses kept saying, “You just had surgery. These things take time. You’re in recovery for crying out loud. Go back to bed.”
Even the score
I realized I had to find a way to slip Must Read™ all of my remaining drugs. After all, I’m in recovery, so he needs the pills more than I.
The Ruse: An entire bottle of sleeping pills ground to fine powder and sprinkled between the pages of bogus publication, tucked deep within his stack, under pretext of adding fresh reading. While Must Read™ surrendered to a deeply delusional power nap, I snatched away redundant copies of web enabled resources. 47 inches shorter, Must Read™ eventually woke, oblivious to any change.
The diet starts today: All right today... first thing in the morning… I mean it this time
After consuming twenty five pounds of regulation and Halloween candy, the previous night’s reading fall began to melt. I’d gained a range of tools, saved $75.00 in ink, and noticed common evolutionary patterns in the list of significant mandates.
Returning to the Compliance Farm™ Theory of Evolution[93], the details aligned to framework quite nicely. Eagles report observed faults, which spawn wolf teams to analyze risk impact. Wolves define details of the problems, breeding theories, tools, and best practice. These discoveries influence ideals, and Humans form committees to amend our laws. This leads to regulation requiring supporting standards. The standards evolve increasingly efficient methods to mitigate the exact same observation that started the cycle in the first place, a fault, a perceived weakness affecting the survival of the pack.
These factors further strengthen the quest to conquer Must Read™:
Duplications exist across organization and lists because most webmasters apply unique names to identical content. Focus on the diamond domains like www.crcs.nist or www.gpo.gov.
Laws are introduced, amended, enacted and codified, each version having its own short title. With the help of LOC (our Library of Congress) and institutions like Cornell, Duke and Harvard Law, legal lists normalize by 80%, if you simply check the history on any law or act.
Favorite discovery: Among the Humans (i.e., authors, organization leaders, committee chairs), were names I actually know. If you take part in the ISACA list services, you may be posting with them on a regular basis. Members of ISACA, CMU, Perdue and IIA had cross pollinated years ago. Reference after reference demonstrate the same sets of names, executive board members, professors, engineers, directors, corporate owners (large and small), and security professionals; essentially a list of people that look and feel a lot like “us.”
A good diet can make anyone strong. I told Mount Must Read™ (MMR™., since we’ve become more familiar) to “Back off! I don’t have to pick a winner. The frameworks don’t compete.” Mount Must Read™ only shrugged in submission. We both knew the “building in isolation” hypothesis wasn’t working.
“Is it possible” I asked aloud, “that the proliferation of laws and standards is just our need to improve on existing ideas? All I need to solve this problem is to start finding document nutrition labels and checking for expiration dates.”
Did I have him now? Was this the blow that would take him down?
“Expired Ideas? Blah ha, ha, ha! You’re killing me!” Mount Must Read™ exploded in earth quaking laughter.
“Laws have Sundown dates. Drugs have "use by" dates. Even car parts have warranty and recall dates. Why shouldn't standards have "applicable by" dates? Stop laughing at me!”
Birth records, death certificates and standards euthanasia
It seemed reasonable to me, a rule that let a standard it has outlived its usefulness. We could establish a committee to determine recommendations for putting various standards down. On second thought, I was beginning to see Mount Must Read’s™ point. We are not a culture that likes to throw things out, never mind recognize when it’s time to gracefully step-down. The solution had to be data driven and non-emotional.
First attempts at gathering a baseline inventory of registered standards, relied on non-member area publications at ISO\IETF hosted sites. Unfortunately, the number of technical committees alone spans hundreds of web locations, and the 2004 year end report by ISO lists more than a thousand standards in active use. FFIEC, ANSI, NIST, and NISO had more generic lists, but still failed to establish an altitude to consistently represent domains, framework concepts, categories, or classes. Listing everything would be too much information and instantly obsolete. There must be a Standard for the Classification of Standards. How can organizations like ANSI and ISO exist without it?
Long time user of the ISO’s 9000 and 17799 series, I can’t tell where the standards end and my own thinking begins. With bias, I’ll suggest that published ISO/IEC Directives make the best model for a framework to create or manage standards. A review of recent Supplement Procedures specific to ISO[94], located at the ISO TC Portal, reveals that ISO committees, by design, will not approve the scope of a Technical Committee (TC), unless thorough review, which verifies the standard to be unique and not in conflict with a known charter or activity by any other registered standards body. ISO is without question the highest ranking standards organization world wide. Templates for the development of a standard alone can make other efforts and products appear trivial, (although I’m not saying that they are). To consider a means for evaluation and comparison of standards should begin with consideration for the values expressed in a world report published December 2004, stating the criteria for the adoption of any ISO standard. They should:
- respond effectively to global regulatory requirements, market needs and scientific/technical developments;
- not distort markets nor have adverse effects on fair competition;
- not stifle innovation or technological development;
- not give preference to the requirements of specific countries or regions; and
- be performance-based rather than design-prescriptive[95].
ISO provides templates for the development of standards. The models found here should be part of the collective consideration establishing the bar for the quality of standards produced by any organization. There is a published standard for the Conformity Assessment: Code of Good Practice: ISO/IEC Guide 60:2004, describing “[…] all elements of conformity assessment, including normative documents, bodies, systems, schemes, and results. It is intended for use by individuals and bodies who wish to provide, promote or use ethical and reliable conformity assessment services. ISO/IEC Guide 60:2004 is designed to facilitate trade at the international, regional, national and sub-national level(s)[96]." This guide establishes a clear target for the implication of a standard to promote safe trade through a process of clear measurement.
If it makes sense, it exists
I wondered if I could just buy the data. ANSI pointed to the following sources:
- NSSN / Standards Mall
- Homeland Security Standards Database
- The Hydrogen Codes and Standards portal
- Standards Information
- Standards Developing Organizations
- National Standards Bodies
- Other Organizations/Topics of Interest
A trip to the Standards Mall
Do you see it? There is a Standards Mall. For a fee of only $99.00, anyone can obtain a database of coordinates, locations and access to an untold number of standards. Actually, the number is over a quarter million.
The NSSN: A National Resource for Global Standards includes contributions by 600 developers and is grouped into six categories:
- Approved Industry Standards
- Approved International Standards
- Approved S. Government Standards
- Industry Standards Under Development
- International Standards Under Development
- S. Government Standards Under Development
With updates ranging from weekly to monthly, this number is no doubt already greatly increasing. Standards Tracking and Automated Reporting (STAR) Services are described this way:
In today's world of change, the best laid business plans can be swept away almost without warning. Speed has become the name of the game and instant information provides the competitive edge.
Users require immediate access to data organized in a meaningful format. The NSSN's Standards Tracking and Automated Reporting (STAR) Service […] keeps you informed by tracking critical updates in the standards arena. Current status reports on more than 270,000 standards under development, revision and maintenance are as close as your desktop and as easy as sitting back and reading your e-mail.
Available only by subscription via NSSN, STAR identifies new project proposals and automatically tracks changes in status of a development project or standard under maintenance[97].
Each change of document status is compared to a directory of user-established profiles - profiles broad enough to span an entire industry or focused enough to track updates to a single standard. Users impacted by an update receive an e-mail summary and a URL link to a personal web page cataloguing details of the modification.
After 30 or 40 links, it was clear I had too many choices and no compelling hierarchy for gathering a baseline of standards. I left the mall hungry for one high level list.
NISO, the National Information Standards Organization[98], for example, provides a comprehensive overview of TC international standards, commentary regarding how standards are created, as well as current U.S. (Technical Committee), JTC (joint) and WG (Working Group) involvement with ISO[99]. The U.S. involvement in technical standards is vast. U.S. TAG to ISO TC 46 on Information and Documentation provides information regarding naming classifications, libraries and works across all organizations involved in creation and management of standards; and is organized in the following five categories.
- SC 4 Technical Interoperability
- SC 8 Quality - Statistics and Performance Evaluation
- SC 9 Identification and Description
- SC 11 Archives/Records Management
- WG 2 Coding of Country Names and Related Entities
Attempting any single Joint Technical Committee's list of standards is a mistake. There are hundreds of subcommittees, each managing hundreds of standards, and their own lists. Clearly, this issue is important to all of our nations, as ISO has a committee dedicated to nothing more than a means to simply classify the standards. ISO 5963:1985 aims to provide a catalogue of standards, with scope including “Documentation - Methods for examining documents, determining their subjects, and selecting indexing terms.”
Updates to drafts and release occur with all the regularity of an atomic clock. In 2004, ISO[100] reported 1,247 publications in use by a member body, which can only be counted by number of countries and member associations[101]. It is clear that if any group has in its possession a true need for an ontology governing the comparative record of all known standards, it will be found in the coordinated efforts of ISO, IEC, ANSI and NIST. This core group is regulated by a variety of local, industry, national and international laws. Bound by MOU (Methods of Understanding) and in accordance with The Agreement on technical cooperation between ISO and CEN[102], Public Law 104-113[103], and the WTO- Final Act of the Uruguay Round, this core group is recognized by the principle of US National Conformity Assessment[104] to the extent that their implementation may be assessed by conformity assessment bodies, such as CASCO.
To speak for the workings of even one technical area requires a long period of involvement. To speak with authority to any single standard, one would at least need to be a contributing member of the Information Technology Task Force (ITTF)[105]. I find it hard to believe anyone knows every consideration ever made within every area of ISO, IEC, ANSI and NIST aligned committees.
Given the choice to build a list or get the list from ISO, the choice is fairly obvious. ISO wins.
I’m not suggesting we can’t perform an information audit unless we use standards as created by ISO. If I try to isolate and extract all ISO influence in my own thinking, I’m left with a big empty space in my head.
At best, I have evolved to the professional ranks of dog-squirrel. Part squirrel and part rescue dog, I don’t pick up the principals of ISO based in pure wolf instinct. I sniff at everything new and then bury it in the yard, I store nuts for winter, and I need a good master to tell me what to do. I’m pretty loyal to ISO.
In the event you are not familiar with ISO, I suggest a warm up using the two documents I mentioned before. Start with the GTAG Information Control Guidance, because it is easy to understand, and provides thoughtful insight in the way we conduct our practice. Then read Aligning COBIT®, ITIL® and ISO 17799 for Business Benefit, because exposure begins with the advantage of ISO standards in an audit context[106].
Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics