NIST is coming out with new standards, updates to existing guidelines and new guidelines at a much faster rate than in previous years. Threats continue to morph, audit requirements continue to become more stringent, and CyberScope questions and audit recommendations from the previous year are being addressed while the agency awaits the 'late' arrival of new CyberScope questions for the existing year (even 5 to 6 months into the Fiscal Year).
As the new guidance from NIST is released, many organizations do not have time to review the extensive documents and come up with a strategy to apply the guidance to their particular environments. In addition, many government agencies are so large and decentralized that many key security and agency staff do not get the message on the new standards and guidance. They are too busy with their day-to-day jobs to spend time understanding what the new information means to them.
In response to these issues, Treadstone 71 created the FISMA Focused Role Based Training. For example, our training covers all aspects of how to apply the risk management framework (RMF) as defined in NIST Special Publication 800- 37Rev1. We cover the six steps (Figure 1), roles and responsibilities, as well as how to apply the into your systems/software development lifecycle. We provide training on security program assessments as outlined in 800-100; in-depth information on how to apply and build an enterprise integrated risk management program through all three defined Tiers (800-39); the new risk management process as defined in 800-30Rev1; and the most difficult that seems to be giving many organizations trouble - defining, applying and integrating continuous monitoring through all three Tiers and control types (managerial, technical and operational) so a cohesive approach is applied. We even provide training on how best to interface with the office of inspector general (OIG) and other auditors. Treadstone 71 believes this interface and relationship should be not only amicable but also symbiotic in nature.
Contract Treadstone 71 to find out how we can help you educate your staff, integrated the new guidelines while getting ready for the next OIG audit.