US Department of State Jay Coplon

21
US Department of State Jay Coplon

description

US Department of State Jay Coplon. My Commitment. You will get a sense for how we do C&A You will find value in being here All of your questions will be answered. Key Points. Quantitative Metrics Toolkits, Tools and Templates Continuous Monitoring Questions and Answers. - PowerPoint PPT Presentation

Transcript of US Department of State Jay Coplon

Page 1: US Department of State Jay Coplon

US Department of State

Jay Coplon

Page 2: US Department of State Jay Coplon

My Commitment

• You will get a sense for how we do C&A• You will find value in being here• All of your questions will be answered

Page 3: US Department of State Jay Coplon

Key Points

• Quantitative Metrics• Toolkits, Tools and Templates• Continuous Monitoring• Questions and Answers

Page 4: US Department of State Jay Coplon

Decision Memo Authorization to Operate• When the Control Limits have not been exceeded.

Page 5: US Department of State Jay Coplon

Decision Memo Authorization to Operate• When the Control Limits have been exceeded.

Page 6: US Department of State Jay Coplon

Risk Score in iPost

Page 7: US Department of State Jay Coplon

Fully Reporting in iPost

System Owner will maintain a high level of hosts fully reporting (to iPost) within the accreditation boundary. Fully means current reporting on hardware, software, patch, vulnerability, and compliance

Page 8: US Department of State Jay Coplon

Low or No Medium Traditional Risk

The System Owner will maintain a level or state of low or no Medium business risk as determined by traditional C&A.

Page 9: US Department of State Jay Coplon

Notification of Change Metrics

• Exceeding the Specification Limits• Exceeding the Control Limits

Page 10: US Department of State Jay Coplon

C&A – How we communicate with our customers.

• SharePoint Website Policy, Procedure, Standard

• Document Center Organized by categories

• Alert Notifications Page and/or Document

• WorkshopsTools

Page 11: US Department of State Jay Coplon

SharePoint

Page 12: US Department of State Jay Coplon

SharePoint

Page 13: US Department of State Jay Coplon
Page 14: US Department of State Jay Coplon
Page 15: US Department of State Jay Coplon

Get Ready Get Set STOP!• Exceed any specification limit• Readiness to Start C&A Checklist

Page 16: US Department of State Jay Coplon

FIPS 199 and OMB M-04-04

• Categorize your System• Determine the Assurance Level

Page 17: US Department of State Jay Coplon

Control Selection Tool

• Identify which controls have been implemented• How each control has been implemented• C&A and Annual Security Control Assessments• Manage controls over the systems lifecycle

Page 18: US Department of State Jay Coplon

POA&M Tester Database Tool

• Linked to the system FIPS 199 categorization • Import Open Findings from previous assessments• Finding and Recommended remediation• Failed Controls are identified• Standardizes the risk is calculated for each finding• Risk Scoping

Page 19: US Department of State Jay Coplon

iPost Continuous Monitoring

Page 20: US Department of State Jay Coplon

IPost Continuous Monitoring

Page 21: US Department of State Jay Coplon

Questions and Answers