The Experts below are selected from a list of 21 Experts worldwide ranked by ideXlab platform

Laura P Taylor - One of the best experts on this subject based on the ideXlab platform.

  • Addressing FISMA Findings
    FISMA Compliance Handbook, 2020
    Co-Authors: Laura P Taylor
    Abstract:

    Understanding how to resolve the Reported vulnerabilities is the final step in the FISMA compliance process. The weaknesses noted in the Security Assessment Report need to be identified and described in a document known as the Plan of Action & Milestones (POA&M). The POA&M represents the ISSO’s to-do list and typically needs to be approved by the evaluation team that evaluated the system before they send in the recommendation for authorization. If the POA&M is well articulated, the system owner will likely obtain an Authority to Operate.

  • developing the Security Assessment Report
    FISMA Compliance Handbook (Second Edition), 2013
    Co-Authors: Laura P Taylor
    Abstract:

    The Security Assessment Report is the document written by independent assessors after they have finished performing Security testing on the system. Vulnerabilities are Reported in this Report taking into consideration likelihood, impact, and threats. Security assessors need to include enough information about vulnerabilities so that ISSOs and System Owners can understand where and what the weaknesses are. With the Security Assessment Report in hand, the system owner and ISSO are armed with all the right information to formulate decisions.

Vincent Scotti - One of the best experts on this subject based on the ideXlab platform.

  • The Feasibility Study The Feasibility of Wearables in an Enterprise Environment And Their Impact on IT Security
    Florida Institute of Technology, 2015
    Co-Authors: Vincent Scotti
    Abstract:

    This paper is intended to explore the usability and feasibility of wearables in an enterprise environment and their impact on IT Security. In this day and age, with the advent of the Internet of Things, we must explore all the new technology emerging from the minds of the new inventors. This means exploring the use of wearables in regards to their benefits, limitations, and the new challenges they pose to securing computer networks in the Federal environment. We will explore the design of the wearables, the interfaces needed to connect them, and what it will take to connect personal devices in the Federal enterprise network environment. We will provide an overview of the wearable design, concerns of ensuring the confidentiality, integrity, and availability of information and the challenges faced by those doing so. We will also review the implications and limitations of the policies governing wearable technology and the physical efforts to enforce them. Nomenclature Android Wear = Google IOS Interface connecting Smartphones with wearables AO = Authorizing Official API = Application Programming Interface Apps = Applications ATO = Authorization To Operate Attacker = A person or system trying to gain unauthorized access to a system BYOD = Bring Your Own Device C&A = Certification & Accreditation DaR = Data at Rest DiT = Data in Transit ECDH = Elliptic Curve Diffie-Hellman FIPS = Federal Information Processing Standards Compromise = An event for which an attacker has tried or succeeded in gaining access to the system FISMA = Federal Information Security Management Act of 2002 HOST = Any computer that has full two-way access to other computers on the Internet. Incident = A violation of computer Security, acceptable use, or standard computer Security policies IoT = Internet of Things IOS = mobile operating system created and developed by Apple, presently powers many of the company's mobile devices LED = Light Emitting Diode Legacy = often implies that the system is out of date or in need of replacement MDMS = Mobile Device Management System NIST = National Institute of Standards and Technology Organization = An entity of any size, complexity, or positioning within an Institutional structure PEnE = Policy Enforcement Engine Piconet = A small Bluetooth network created on an ad hoc basis that includes two or more devices. PII = Personal Identifying Information PIN = Personal Identifying Number RISK = A measure of the extent to which an entity is threatened by a potential circumstance or event RMF = Risk Management Framework RoT = Root of Trust RTI = Root of Trust for Integrity RTM = Root of Trust for Measurement RTR = Root of Trust for Reporting RTS = Root of Trust for Storage RTV = Root of Trust for Verification Safeguards = Protective measures prescribed to meet the Security requirements for an Information System SAR = Security Assessment Report SDLC = System Development Life Cycle Smart = Having advanced circuitry, wireless connectivity and independent processing capability Smartwatch = A wearable device which connects to Smartphone using Android Wear IOS Interface SP = Special Publications SSP = System Security Plan Threat = Any circumstance or event with the potential to adversely impact organizational operations Vulnerability = A weakness in a computer system which allows an attacker to reduce a system's information assurance Wearable = Being worn for an extended period of time, with the user experience significantly enhanced as a result Wearable = Includes Smartwatches, Smartbands, Smartglasses, Smart jewelry, and Smart earbuds Technology LG G Smartwatch Feasibility Study

Djenana Campara - One of the best experts on this subject based on the ideXlab platform.

  • establishing and maintaining trust for an airborne network search and rescue enterprise Security Assessment Report
    2014
    Co-Authors: Djenana Campara
    Abstract:

    Abstract : This Report was developed under a SBIR contract for topic AF103-165. This Report describes the results a Security Assessment conducted on the Search and Rescue (SAR) enterprise. The purpose of the Security Assessment is to identify the operational risks to the SAR enterprise. In particular, those resulting from cyber attacks, identify the corresponding vulnerabilities, assess the criticality of the components, and recommend mitigations. SAR case study is a comprehensive illustration to the Department of Defense Architecture Framework (DoDAF) published as part of the international standard UML Profile for DoDAF and MoDAF (UPDM) by the Object Management Group (OMG). For the purposes of this Assessment, the SAR is defined by International Aeronautical and Maritime Search and Rescue Manual (IAMSAR) and Canadian National Search and Rescue Manual. The Security Assessment described herein was one part of an overall project to develop a generic methodology and technology framework for computing a trustworthiness index (TI). A TI is a measure of confidence that risk is low in a claim about a system component supporting mission objectives

Leighton Johnson - One of the best experts on this subject based on the ideXlab platform.

  • Chapter 13 – Reporting
    Security Controls Evaluation Testing and Assessment Handbook, 2016
    Co-Authors: Leighton Johnson
    Abstract:

    The various types of Assessment Reports are defined and reviewed. The Security Assessment Report and the Risk Assessment Report are the primary outputs from any Assessment in the RMF process and each is defined and discussed, and sample templates are provided.

James Broad - One of the best experts on this subject based on the ideXlab platform.