0% found this document useful (0 votes)
25 views15 pages

Federal IT Compliance Guide

Every federal IT pro is familiar with cybersecurity, its importance, and its challenges.

Uploaded by

norcavata
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
25 views15 pages

Federal IT Compliance Guide

Every federal IT pro is familiar with cybersecurity, its importance, and its challenges.

Uploaded by

norcavata
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

WHITE PAPER

The Ultimate Guide to


Federal IT Compliance

page 1
GOVERNMENT WHITE PAPER: THE ULTIMATE GUIDE TO FEDERAL IT COMPLIANCE

Leveraging SolarWinds to Solve


Your Security Challenge
Every federal IT pro is familiar with cybersecurity, its importance, and its challenges.
That said, an ultimate understanding can be gained by taking a historic perspective,
and bringing that forward: knowing how—and by whom—cybersecurity rules and
regulations were created, then connecting that information to today’s solutions.
This perspective can help provide a broader understanding of one of the federal
IT pros greatest challenges.

THE COMPLIANCE CHALLENGE


Federal Guidelines
Today’s security standards for computing systems owned or operated by and for the US Government
have been set by two principle overarching entities: the US Congress and the National Institutes of
Standards and Technology (NIST).

In 1996, Congress directed NIST to develop and issue best practices and other guidance for secure
operation of US Government systems; in response, NIST developed the Federal Information Processing
Standards Publications (FIPS PUB) standards. The most relevant publications, “Standards for Security
Categorization of Federal Information and Information Systems” (FIPS PUB 199) and “Minimum
Security Requirements for Federal Information and Information Systems” (FIPS PUB 200) require
federal agencies to categorize the security levels of their information systems based on the types of
information the systems will process and/or store.

Agencies must categorize their information systems as low-, moderate-, or high-impact for each of
three primary information security objectives: confidentiality, integrity, and availability (CIA). The overall
impact categorization of a system is usually equal to the highest impact assigned to any of the three
objectives. In other words, a system categorized as “low-moderate-low” based on the CIA security
objectives will carry an overall impact categorization of “moderate”. Each system will need this defined
categorization before one can begin the process of selecting security controls, as the controls are
dependent on the categorization (higher-impact systems will have more stringent security controls).

Six years later, Congress further strengthened requirements for US Government systems by
enacting the Federal Information Security Management Act (FISMA) of 2002. FISMA has since been
implemented across the Federal Government through a variety of named processes and procedures,
guided by NIST standards and agency-specific guidance. FISMA requires Federal agencies to
safeguard systems based on the impact categorization (FIPS 199) such that residual information
security risk is mitigated to an acceptable level.

page 2
GOVERNMENT WHITE PAPER: THE ULTIMATE GUIDE TO FEDERAL IT COMPLIANCE

The principal guidance documents that support FISMA implementation again come from NIST:
Special Publications 800-53, and 800-37. NIST SP 800-53 outlines the method for selecting baseline
security controls for the chosen system based on its impact categorization; 800-37 outlines a FISMA-
compliance process called the Risk Management Framework, or RMF, and the six high-level tasks
required to ensure a system meets federal IT compliance standards.

The fifth iteration (Revision 5) of NIST 800-53 is nearing completion; the current release (Revision 4)
has provided the required guidance for federal agencies for the past five years.

New requirements for contractors: 800-171


In 2015, NIST published an additional type of guidance—NIST SP 800-171—to help protect Controlled
Unclassified Information (CUI).

Unlike previous NIST guidance, which was focused primarily on ensuring government systems are
FISMA compliant, 800-171 requires security compliance initiatives on the part of the government
contractors who process, store, and use government-provided CUI in non-government systems. In
other words, security compliance requirements now extend beyond federal agencies’ systems to
include federal contractors’ systems.

What comprises CUI? For starters, it encompasses common and expected privacy information like PII
and other data that identifies government personnel. CUI may also comprise government acquisition
information, including quantity and pricing data inherent to acquisitions processes.

The government initially required 800-171 compliance for DoD contracts and contractors; that
requirement is now expanding and includes civilian agency contractors who generate, store, and
process CUI. In other words, all contractors must be aware of this relatively new requirement. Of
particular note is the potential cost of meeting the requirement, which will have to be factored into
bidding strategies and overall corporate expenses.

Security Controls and STIGs


The federal IT security pro is required to implement a particular set of security controls based on the
impact categorization of a given system. A high-impact system can have more than 1,700 possible
security controls and sub-controls, also called “enhancements”, that are necessary to secure—or
harden—that system. Since each control can be its own set of tasks based on the variables of the
system and its components, the government has created further guidance and tools for ensuring
these controls are chosen and implemented correctly.

The DoD, through the Defense Information Systems Agency (DISA) Field Security Operations (FSO),
has created hundreds of highly detailed guides for a wealth of systems components including
operating systems, application servers, database servers, switches, firewalls, and other common
computing system components. These guides are known as the Security Technical Implementation
Guides, or “STIGs” for short.

page 3
GOVERNMENT WHITE PAPER: THE ULTIMATE GUIDE TO FEDERAL IT COMPLIANCE

How do agencies use STIGs? Let’s take a common system component as an example: a STIG for
a Cisco® router will not only mandate using passwords to restrict router access, but also provide
iOS® configuration instructions for how to properly configure password authentication. Government
and industry have developed automated and manual tools for testing STIG compliance for each
system component to ensure the component is hardened such that it maintains a baseline security
configuration that meets the requirements of the chosen impact level.

Additional Guidance
The government’s Executive Branch also offers guidance, in several different forms.

First, in September 2018 the White House issued the National Cyber Strategy, a relatively high-level
memorandum that takes a four-pillar approach to protecting the nation’s data. The objective of each
of these pillars, according to the White House, is:

»» Pillar 1: Manage cybersecurity risks to increase the security and resilience of the Nation’s
information and information systems.

»» Pillar 2: Preserve United States influence in the technological ecosystem and the development
of cyberspace as an open engine of economic growth, innovation, and efficiency.

»» Pillar 3: Identify, counter, disrupt, degrade, and deter behavior in cyberspace that is
destabilizing and contrary to national interests, while preserving United States overmatch in
and through cyberspace.

»» Pillar 4: Preserve the long-term openness, interoperability, security, and reliability of the
Internet, which supports and is reinforced by United States interests.

The Executive Branch also issues executive orders. These memorandums require specific additional
security efforts such as encryption standards for data-at-rest and data-in-transit, as well as identity
management requirements through the issuance of smart cards to US Government personnel and
their contractor partners.

The memorandums further define the types of collected and stored information that require additional
security safeguards, such as Personally Identifiable Information (PII). Office of Management and
Budget (OMB) Memorandum M-07-1616 defines PII as information sufficient to identify an individual
alone, or when combined with other identifying information. PII is protected by The Privacy Act of
1974. Another form of such protected information is Electronic Protected Health Information (ePHI),
information that is protected under the Health Insurance Portability and Accountability Act of 1996
(HIPAA).

Cybersecurity is clearly complex, and is guided by an equally complex series of concepts, processes,
guidelines, and requirements. That said, every effort is of critical importance. Consider the current
threat landscape comprising bad actors, data breaches, insider threats, poorly configured software,
and system components that require the regular application of vendor security patches to ensure that
a baseline security configuration is maintained.

page 4
GOVERNMENT WHITE PAPER: THE ULTIMATE GUIDE TO FEDERAL IT COMPLIANCE

Now let’s add the inevitable staffing shortages that come from lengthy hiring and acquisition
processes, competition from the private sector, and all the skills and certifications that are required
to qualify for security work in the US Government. Securing an agency against cybersecurity threats
is a difficult situation that only grows more challenging by the day.

Despite the complexity of the challenge, there are absolutely best-practice solutions and basic steps
Federal IT pros can implement to help secure systems and data within a timeline that supports agency
IT initiatives.

CYBERSECURITY BEST PRACTICES: RMF AND BEYOND


RMF Compliance
FISMA requires each federal agency to implement information security safeguards, audit these
safeguards annually, and report the results to the Office of Management and Budget (OMB). The
OMB, in turn, prepares an annual compliance report for Congress. This concerted effort taken together
strengthens the cybersecurity of US Government systems and data, and dramatically reduces risk.

RMF has traditionally mapped out six steps toward compliance and risk reduction:

»» Step 1: Categorize Risk. Meet this need by applying the standards outlined in FIPS 199 and 200.
The end result should be an impact categorization of low, moderate, or high.

»» Step 2: Select Security Controls. Choose a set of security controls from NIST SP 800-53 based
on the categorization chosen in step 1.

»» Step 3: Implement Security Controls. Begin the process of applying controls to a given system.
Some controls may be met by policies and management decisions, others by technical efforts.
Automated tools can dramatically speed up these processes.

»» Step 4: Assess Security Controls. Begin to test that the security controls chosen have been applied
correctly. Automated tools really shine here, especially for those controls with a technical test
mechanism.

»» Step 5: Authorize Information System. Now that controls have been implemented and validated,
it’s time to get approval for the system to operate.

»» Step 6: Monitor Security Controls. A key differentiator of the Risk Management Framework over
previous security compliance processes is the notion of continuously monitoring the system and
its controls to ensure the system remains secure across the system life cycle.

The newest revision (NIST SP 800-37 Revision 2) of RMF also includes a “Prepare” step that
organizations should take before beginning the six-step process outlined above. At a high level, this
new step focuses on assigning risk management roles, developing a risk-management strategy, and
conducting enterprise-level risk assessments. The goal is to encourage more effective communication
between executives and operational staff; identify common controls and tailored control baselines;
reduce complexity of the infrastructure; and increase emphasis on the protection of high-value assets.

page 5
GOVERNMENT WHITE PAPER: THE ULTIMATE GUIDE TO FEDERAL IT COMPLIANCE

CATEGORIZE

MONITOR SELECT

PREPARE

AUTHORIZE IMPLEMENT

ASSESS

Source- NIST Publication RMF 2.0 Risk Management Framework

According to NIST: “Without adequate risk management preparation at the organizational and system
levels, security and privacy activities can become too costly, demand too many skilled security and
privacy professionals, and produce ineffective solutions.”

Released in December 2018, RMF 2.0 includes Prepare as the first step, followed by the “Categorize
Step” and continuing through seven steps all together.

FISMA compliance efforts for government systems must adhere strictly to all RMF steps in order to
minimize risk to government systems, data, and the business processes that rely on secure computing.
And, yes, RMF provides a framework that combines IT security and risk management to enable a
more dynamic approach to managing agency risk.

That said, successfully reducing risk goes beyond RMF and FISMA compliance.

Beyond RMF
First and foremost, ensure good cyber hygiene. Make sure all systems are up to date on all hardware
and software updates and patches. New malware is introduced every day; ensuring all systems are
up to date should be the agency baseline.

page 6
GOVERNMENT WHITE PAPER: THE ULTIMATE GUIDE TO FEDERAL IT COMPLIANCE

In addition to standard cyber hygiene, there are also several fundamental steps every federal IT pro
should take to help ensure a strong security foundation.

1. Create an information security framework. This should encompass a series of


well-documented policies, guidelines, processes, and procedures about how
best to implement and manage ongoing security within your agency. There
are several established security frameworks, but the US government most
closely follows the guidelines set forth in NIST SP 800-53 to comply with the
FIPS 200 requirements.

2. Develop a consistent training program. Train the team to understand how


to recognize potential vulnerabilities quickly, and how to find the gems of
important information within a sea of security-related alerts and alarms. Train
developers on secure coding methodologies. And, train end uses on things
like creating strong passwords, identifying phishing emails and other social-
engineering attacks, and what information can and cannot leave the confines
of the agency.

3. Monitor and maintain IT systems. Day to day security monitoring and


maintenance is the key to successful day to day risk and vulnerability
mitigation. Having a strong backup system in place is part of this maintenance.
If a breach occurs and data is compromised, a good backup system will
ensure minimal data and productivity loss.

Next, even with a solid program for cyber hygiene and a solid security foundation, there are additional
things the federal IT pro can do to help reduce agency risk, particularly in light of unique challenges
that come with federal security.

»» Complexity: Agency environments can be quite large and quite complex. Tools that can help
determine the perimeter of your network boundary, and account for all devices communicating
on that network, are invaluable.

»» Change: Federal environments change over time. Tools that can capture an existing environment
and its baseline configuration settings and then capture changes over time, allow analysts
and architects the ability to find and resolve performance issues and vulnerabilities related to
misconfiguration in that environment based on real, quantifiable evidence.

»» Too much information: System components generate vast quantities of data in the form of logs.
A SIEM tool can help your team wade through these details and find anomalies that may indicate
device misconfiguration, improper data or location access, privilege escalation, indicators of
compromise, and more. The use of a SIEM can provide actionable insight and additionally meet
access management and other security controls under RMF.

page 7
GOVERNMENT WHITE PAPER: THE ULTIMATE GUIDE TO FEDERAL IT COMPLIANCE

Finally, there is an organization called the Center for Internet Security (CIS) that can provide even
further assistance. Specifically, CIS provides a comprehensive security framework called The CIS
Critical Security Controls (CSC) for Effective Cyber Defense that provides agencies with a set of clearly
defined controls to reduce the risk of cyberattack and improve IT security posture. The framework
consists of 20 controls. That said, according to CIS, implementation of the first five controls provides
effective defense against 85 percent of the most common cyberattacks.

Those first five controls are:

1. Inventory of Authorized and Unauthorized Devices

2. Inventory of Authorized and Unauthorized Software

3. Secure Configurations for Hardware and Software on


Mobile Devices, Laptops, Workstations, and Servers

4. Continuous Vulnerability Assessment and Remediation

5. Controlled Use of Administrative Privileges

CIS provides guidance on how to implement the controls and which tools to use to reduce the burden
on security teams.

Auditing and Automation


Security audits are a core component of ongoing security best-practices and are part of agency FISMA
requirements. The goal of the audit is to ensure compliance requirements are being met.

So, what should federal IT security pros expect for the audit process?

First, expect the audit to take place on-site. The auditor will need a place to work as well as one or more
sets of temporary credentials in order to access the target system or network as well as associated
documentation.

For the vast majority of the audit, the auditor will perform a range of verifications to ensure compliance
requirements are being met. For example, the auditor likely will verify that:

»» a security categorization has been chosen for the target system (per FIPS 199 and 200) and that
the security categorization is accurate

»» security controls have been selected for the system that align with the chosen security
categorization (low/moderate/high) impact level and controls detailed in NIST SP 800-53,
Appendix D, for the corresponding impact level (low/moderate/high)

»» security controls have been accurately selected and implemented

page 8
GOVERNMENT WHITE PAPER: THE ULTIMATE GUIDE TO FEDERAL IT COMPLIANCE

Auditors may choose to create one or more vulnerability and risk reports as outputs for their testing
efforts. Based on this report, identified vulnerabilities may require a mitigation tracking document
(e.g. a Plan of Actions and Milestones, or POA&M) that identifies the severity of each vulnerability
and the responsible parties for ensuing the vulnerability is addressed, a timeline for addressing the
vulnerability, and the level of effort for the mitigation activities.

Based on this, what should the federal IT security pro do to prepare? Here are a few tips:

»» Ensure all necessary personnel are available on the audit date(s) during core testing activities,
and be sure all personnel contact information is accurate and up to date

»» Ensure all system function and security documentation exists, is up to date, and is available on
the audit date

»» Validate that an accurate security categorization has been chosen for each application in the
environment

»» Validate that security controls have been selected and implemented based on that categorization
level

»» Verify the security control validation schedule for those systems

»» Verify how and when system and data backups occur and that at least one regular backup is
maintained offline (on a device unattached to the network and/or on an external backup resource)

»» Verify the system patch schedule with technical personnel, obtain current patch status, and
quantify all known patches that have yet to be applied

Meeting compliance requirements—particularly in advance of an audit—can be incredibly time


consuming. Automation can go a long way toward meeting these requirements while saving valuable
federal IT personnel time.

Automating continuous monitoring is the first and likely most helpful aspect of compliance automation.
In fact, automation is a core intent of continuous monitoring as this approach can dramatically
streamline security processes.

These are many aspects of continuous monitoring that can be automated through the use of tools
designed specifically for this task. For example, the federal IT security pro can automate attack-surface
discovery by regularly scanning for open ports, protocols used, and services available from multiple
network locations inside and outside the network. Automated scans can ensure patches are applied
in a timely manner and that security controls continue to be implemented.

Federal IT security pros can also automate log aggregation and other event details in a SIEM, which
provides actionable business intelligence on current security status. Automation tools can also provide
incident response support and evidence of Indicators of Compromise (IoCs).

page 9
GOVERNMENT WHITE PAPER: THE ULTIMATE GUIDE TO FEDERAL IT COMPLIANCE

Reporting is a critical part of compliance, and is also something that can be automated. When scans
are run, for example, many tools automatically provide output in a report format that ties directly to
security control validation. These automated reports can provide information on missing patches,
non-permitted ports, which protocols or services are available at any network location, and more.
Some directly address security controls in NIST 800-53 and other compliance requirements.

All sounds, good, right? But there are still a large amount of security controls to choose, implement,
and validate successful implementation. And then there’s the accompanying documentation. So let’s
look at the SolarWinds tools that can help reduce the federal IT pro’s risk exposure and enhance the
path toward FISMA and RMF compliance.

SolarWinds Compliance Solutions


Solar Winds has several products that are designed to facilitate security control implementation,
management, and oversight. For example,

»» RMF Step 3, Implement controls: Several SolarWinds products, including Network Configuration
Manager (NCM), and Patch Manager, can be used to help satisfy controls or to help implement
and manage implementation of controls.

»» RMF Step 4, Assess controls are working correctly: SolarWinds’ security product portfolio,
including NCM, and SolarWinds Security Event Manger (SEM), formerly Log & Event Manager
(LEM), can be used to help make sure controls have been implemented correctly.

»» RMF Step 6, Monitor: Several SolarWinds products including LEM, Network Performance Monitor
(NPM), and NCM, can be used to help make sure that controls are working as expected, bypasses
aren’t attempted, and produce reports that can be used to prove controls have been correctly
implemented.

page 10
GOVERNMENT WHITE PAPER: THE ULTIMATE GUIDE TO FEDERAL IT COMPLIANCE

NCM and SEM


Let’s start by examining two of the most critical tools SolarWinds offers for helping federal IT pros
meet FISMA and RMF compliance demands.

»» SolarWinds Security Event Manger (SEM), formerly Log & Event Manager (LEM): SIEM tools can make
it easier to use event logs for security, compliance, and troubleshooting and simplify many aspects of
FISMA compliance. SEM comes bundled with hundreds of built-in reports, many of which are designed
to directly support FISMA compliance efforts. These reports rapidly address the Assess/Monitor
activities by helping look for exceptions to controls, unexpected changes or activity, or attempts to
bypass controls. In addition, SEM includes dozens of correlation rules categorized for a verity of
compliance initiatives, including FISMA. SEM additionally supports file integrity monitoring, USB device
monitoring, automated threat remediation, advance search, and forensic analysis. The tool improves
operational security at the same time it streamlines RMF tasks.

»» Network Configuration Manager (NCM): NCM includes templates designed to help meet NIST
and DISA STIG requirements for network components. These templates can identify services
exposed on network devices, identify where and how remote access is enabled on these devices,
identify the management protocols used by these devices, and identify key access control lists
(ACLs) that should be present to ensure compliance with the relevant security controls. NCM then
helps close known vulnerabilities on devices and keeps updated on Cisco devices by accessing
the National Vulnerability Database (NVD). The tool supports initial and ongoing network security
requirements that dovetail with RMF.

page 11
GOVERNMENT WHITE PAPER: THE ULTIMATE GUIDE TO FEDERAL IT COMPLIANCE

Other SolarWinds tools that can help with navigating and implementing 800-53, in addition to NCM
and SEM, are:

»» User Device Tracker (UDT) to detect device usage in classified environments

»» Patch Manager to help implement and manage controls

»» Network Performance Monitor (NPM) to ensure controls are working as expected

»» NetFlow Traffic Analyzer (NTA) to help monitor communications

»» Server & Application Monitor (SAM) for enterprise-wide continuous monitoring

»» Storage Resource Monitor (SRM) to help detect denial of service (DoS) and resource/performance
issues

»» Database Performance Analyzer (DPA) to identify large queries or unexpected database activity

Next, let’s look at SolarWinds Access Rights Manager (ARM) and SolarWinds Server Configuration
Monitor (SCM), two SolarWinds’ products that can automate monitoring and reporting of common
system components and configuration settings over time:

»» Access Rights Manager: This tool monitors user and system account access for common access
control components such as Active Directory® and Microsoft® Exchange™. The tool additionally
supports auditing of Windows® File Shares a we well as User provisioning, management, and
permissions analysis. Lastly, the tool can generate custom reports useful to support compliance
reporting and RMF activities.

»» Server Configuration Monitor: This tool monitors system and application changes, server
configuration settings and changes for online and offline systems, and an asset inventory for
your environment. The tool additionally permits the comparison of configuration changes over
time and informs how these changes may have impacted performance. This kind of real-time
and historical detail is invaluable when implementing RMF.

Other tools, produced by SolarWinds, competitors, and the open source community can swiftly
automate the implementation of other controls by detecting when a restricted port or protocol is in
use, whether a critical patch has been applied to close a security flaw, and the like. The shared goal is
to allow federal IT personnel to rapidly assess the current security posture of a system, identify flaws,
and mitigate those flaws in order to maintain the security posture for a given system in a manner
commensurate with the risk categorization identified.

page 12
GOVERNMENT WHITE PAPER: THE ULTIMATE GUIDE TO FEDERAL IT COMPLIANCE

SolarWinds Security Products Overview


Identity Protect Detect Respond Recover

Patch Manager Patch Manager


Windows ® and third-party patching, asset inventory, and reporting Patch compromised systems

Security Event Manager


SIEM tool for threat detection, incident response, and compliance reporting

Access Rights Manager


Manage and audit user access rights across your infrastructure

Server Configuration Server Configuration Server Configuration


Monitor Monitor Monitor
HW and SW asset inventory Detect unauthorized changes View previous configurations

Network Configuration Manager


Automates management of network configurations and helps ensure compliance and backup status

User Device Tracker


Detect and locate rogue users and devices on your network

User Device Tracker


Find suspicious network activity

Serv-U MFT
Secure file transfer and sharing

Backup Backup
Easy web-based backups Restore data and systems

Threat Monitor
SaaS-based threat detection, incident repsonse, and compliance reporting

Enhancing Compliance and Reducing Risk with SolarWinds


IT security threats posed by careless or untrained agency insiders and foreign governments are at
an all-time high, according to the 2019 SolarWinds Federal Cybersecurity Survey Report. That said,
58 percent of survey respondents said that improved strategy and processes to apply security best
practices is the primary reason reasons that insider threats have improved or remained in control.

Sources of Federal Security Threats - Trend


All sources of security threats have increased since 2014. Six of the eight threat sources are at am all time high.

2014 2015 2016 2017 2018

Careless/untrained insiders 42% 53% 48% 54% 56%

Foreign governments 34% 38% 48% 48% 52%

General hacking community 47% 46% 46% 38% 48%

Hacktivists 26% 30% 38% 34% 31%

Malicious insiders 17% 23% 22% 29% 36%

Terrorists 21% 18% 24% 20% 25%

For-profit crime 11% 14% 18% 17% 15%

Industrial spies 6% 10% 16% 12% 19%

Note: Multiple responses allowed N=200 = top three sources = statistically significant difference from 2017

page 13
GOVERNMENT WHITE PAPER: THE ULTIMATE GUIDE TO FEDERAL IT COMPLIANCE

The survey uncovered even more evidence that training and good cyber hygiene all help contribute
to a more secure environment. Survey respondents cited the following reasons that insider threats
have improved or remained in control within their agency environments:

»» End-user security awareness training (47%)

»» Network access control (45%)

»» Patching (43%)

»» IT configuration management and reporting (41%)

»» Identity and access monitoring tools (39%)

»» IT asset management and reporting (31%)

Compliance played an even greater role. According to the survey, 60% of respondents cited “NIST
Framework for Improving Critical Infrastructure Cybersecurity” as a contributing factor in managing
risk as part of the agency’s overall security posture; 55% cited FISMA as a contributing factor; and
52% cited DISA STIGs.

SolarWinds can help federal agencies with all of these, whether basic cyber hygiene or compliance
requirements. SolarWinds has the tools, expertise, and experience-based knowledge of the federal
space to help any agency enhance its security posture, reduce risk, and more effectively protect
agency data—and in turn, the agency mission.

page 14
GOVERNMENT WHITE PAPER: THE ULTIMATE GUIDE TO FEDERAL IT COMPLIANCE

ABOUT SOLARWINDS
SolarWinds (NYSE: SWI) provides powerful and affordable IT management software to customers
worldwide from Fortune 500 enterprises to governments including nearly every U.S. civilian
agency, DoD branch, and intelligence agency, as well as a large number of state and local
government, education, National Health Service, European Parliament, and NATO customers. In all
market areas, the SolarWinds approach is consistent—focusing exclusively on IT Pros and striving
to eliminate the complexity that they have been forced to accept from traditional enterprise
software vendors. SolarWinds delivers on this commitment with unexpected simplicity through
products that are easy to find, buy, use and maintain while providing the power to address any IT
management problem on any scale. Each solution is rooted in the company’s deep connection
®
to their user base, which interacts in an online community, THWACK , to solve problems, share
technology and best practices, and directly participate in the product development process.

SolarWinds provides IT management and monitoring solutions to numerous common public


sector IT challenges including continuous monitoring, cybersecurity, network operations,
compliance, IT consolidation, data center operations, cloud computing, mobile workforce
and devices, DevOps, and scaling to the enterprise. SolarWinds software is available through
numerous channel partners and systems integrators worldwide as well as the U.S. General
Services Administration (GSA®) Schedule, United Nations Global Marketplace (UNGM), Crown
Commercial Service (CCS), and United Nations Atlas.

CONTACT US
PHONE EMAIL
877.946.3751 Federal: federalsales@[Link]
+353 21 233 0110 State and Local: governmentsales@[Link]
Education: educationsales@[Link]
WEB [Link]/government National Government: nationalgovtsales@[Link]

© 2019 SolarWinds Worldwide, LLC. All rights reserved.

The SolarWinds, SolarWinds & Design, Orion, and THWACK trademarks are the exclusive property of SolarWinds Worldwide, LLC or its
affiliates, are registered with the U.S. Patent and Trademark Office, and may be registered or pending registration in other countries. All
other SolarWinds trademarks, service marks, and logos may be common law marks or are registered or pending registration. All other
trademarks mentioned herein are used for identification purposes only and are trademarks of (and may be registered trademarks) of
their respective companies.

Common questions

Powered by AI

Federal IT security threats have evolved with increasing risks from careless insiders, foreign governments, and for-profit crime. The 2019 SolarWinds Federal Cybersecurity Survey Report highlights the heightened threats, with a noted increase in vulnerabilities posed by untrained insiders. To mitigate these risks, agencies are improving security strategies by adopting enhanced cybersecurity practices like end-user security awareness training, network access control, and resilient IT configuration management. Additionally, leveraging the NIST Framework for Improving Critical Infrastructure Cybersecurity and FISMA compliance are cited as measures that help manage risk and maintain a robust security posture .

Current federal IT compliance standards are rooted in historical legislative actions and guidance development. In 1996, the US Congress directed the National Institute of Standards and Technology (NIST) to develop best practices for secure operations of government systems, leading to the creation of the Federal Information Processing Standards Publications, specifically FIPS PUB 199 and 200. These documents require federal agencies to categorize information systems based on confidentiality, integrity, and availability, influencing the selection of security controls. The Federal Information Security Management Act (FISMA) of 2002 further enforced these requirements by mandating agencies adhere to NIST's guidance, including the SP 800-53 and SP 800-37 for security control selection and risk management, respectively .

The National Cyber Strategy contributes to federal cybersecurity efforts by providing a high-level directive that aligns strategic goals with specific tactical compliance frameworks like FISMA and RMF. It promotes a unified approach to defending cyberspace, safeguarding critical infrastructure, and strengthening the federal IT environment. While FISMA and RMF detail specific procedures for risk management and compliance, the National Cyber Strategy provides a broader policy background that supports and enhances the effectiveness of such frameworks through its focus on national security, economic security, and resilience .

The Risk Management Framework (RMF) ensures that federal agencies meet IT compliance standards by guiding them through a structured process of categorizing risk, selecting security controls, implementing and assessing these controls, authorizing the system, and continuously monitoring security controls. RMF 2.0 introduced the 'Prepare' step to improve risk management by encouraging assignment of roles, risk management strategy development, and enterprise-level risk assessments before proceeding with the standard six-step RMF process. This advance helps streamline communication between executives and operational staff, thus reducing complexity and focusing on protecting high-value assets .

Security Technical Implementation Guides (STIGs) are vital in federal IT compliance as they provide detailed guidance on the configuration of security controls for specific system components. For instance, a STIG for a Cisco router mandates the use of passwords for control access and provides IOS configuration instructions for proper password authentication. These guides help ensure systems maintain a baseline security configuration aligned with their designated impact level, and both manual and automated tools can assess compliance with STIG requirements .

SolarWinds tools aid federal agencies in achieving IT compliance by offering solutions for network performance monitoring, security control implementation, and configuration management. Tools like Patch Manager and Network Configuration Manager (NCM) automate patching and configuration tasks that align with NIST 800-53 security controls. The Access Rights Manager helps oversee user access rights management, which supports RMF activities by ensuring compliance and facilitating reporting. These tools provide comprehensive monitoring and management capabilities that enhance compliance efforts .

Executive guidance from the White House plays a pivotal role in shaping federal IT and cybersecurity policies by setting national priorities and frameworks within which compliance standards like FISMA and RMF operate. The White House's issuance of the National Cyber Strategy, for example, establishes a comprehensive policy approach that underscores the significance of cybersecurity as a governmental and national security priority. This high-level guidance aligns disparate compliance efforts by federal entities and fosters a coherent national framework, driving agencies toward improved cyber defenses and robust risk management capabilities .

Continuous monitoring is a critical component of the RMF process that distinguishes it from previous security compliance frameworks. This step ensures that systems remain secure throughout their lifecycle by constantly assessing the effectiveness of implemented security controls. Continuous monitoring allows for the timely detection and mitigation of vulnerabilities, thereby significantly reducing risks associated with evolving cybersecurity threats. This proactive approach helps maintain robust security postures in accordance with the defined impact categorization of systems .

NIST SP 800-171 establishes compliance requirements for government contractors handling Controlled Unclassified Information (CUI) on non-government systems, extending beyond the scope of federal agencies' FISMA compliance. Initially focused on DoD contracts, these requirements now apply to civilian agency contractors. The SP 800-171 provides guidance on safeguarding data such as PII and acquisition information. Its implementation can increase the cost of compliance, affecting contractors' bidding strategies and overall expenses, thus necessitating awareness and strategic adjustment among contractors .

The 'Authorization' step in the RMF is crucial for enhancing the security posture of federal information systems as it involves formally accepting the risks presented by a system and granting permission to operate. This step necessitates a thorough review of implemented security controls and their effectiveness, ensuring that any remaining risks are deemed acceptable. By requiring a documented approval before a system goes live, the Authorization step acts as a checkpoint, reinforcing accountability and ensuring a system is securely configured before operational deployment .

You might also like