Download presentation
Presentation is loading. Please wait.
Published byRobert Phelps Modified over 8 years ago
1
New Paradigms for Capital Planning in IT Security Sandy Washington Federal Railroad Administration July 22, 2008
2
Topics Federal Railroad Administration’s (FRA) IT Governance Integrating Continuous Monitoring into IT Security Governance
3
FRA’s IT Governance Cycle Cycle/Quarters 1 & 2: Program Reviews ▫Review Content: cost, schedule, performance and risk ▫Information Sources: Investment Review Template, PM Notebook ▫Decisions: “Continue As-Is”, “Continue With Modifications”, “Discontinue” Cycle/Quarter 3: Portfolio Review ▫Review Content: portfolio “mix”, total spending, new budget year requirements, mid- year requirements, Ex300 95% Solution ▫Information Sources: Spending Matrix, OMB Exhibit 53, new investments ▫Decisions: “Continue Portfolio As-Is”, “Continue Portfolio With Modifications” Cycle/Quarter 4: Process Review ▫Review Content: CPIC and EA processes, communication channels, review template ▫Information Sources: FRA Integrated EA & CPIC Handbook, PM Handbook, Investment Review Template ▫Decisions: “Continue Process As-Is”, “Continue Process With Modifications” 3 Q1 Program Review Q2 Program Review Q3 Portfolio Review Q4 Process Review PM Notebook Investment Review Template IT Spending Matrix FRA IT Governance Documents
4
FRA IT Governance Relationships 4
5
Continuous Monitoring ▫The continuous monitoring of security controls can be achieved through security reviews, self-assessments, security testing and evaluation, or audits. 1 ▫Continuous Monitoring requires tight inventory control and a well documented baseline IT configuration/ enterprise architecture. Initiation Phase Security Certification Phase Security Accreditation Phase Continuous Monitoring Phase 1 NIST Special Publication 800-37, Guide for the Security Certification and Accreditation of Federal Information Systems, May 2004.
6
Integration Configuration Control Board (CCB) Implement and enforce the FRA’s Configuration Control Board to include: ▫Continuous monitoring status reporting and documentation of all software and hardware. Expand documentation changes to the organization’s information systems and supporting infrastructure beyond the operational information system. Identify all Configuration Items.
7
FRA Accomplishments & Next Steps Accomplishments ▫Security team formed a close relationship with the enterprise architecture team and leveraged segment architecture development. ▫Provided continuous monitoring training to system owners. Next Steps ▫Update FRA’s CCB Charter. ▫Identify changes to working group processes. ▫Realign security funding.
8
Contact Information Sandy Washington Federal Railroad Administration Office of Information Technology (202) 493-1309 Sandy.washington@dot.gov
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.