Study Reveals Software Quality Concerns

Points to Significant FISMA Disconnect Is the Cure Worse Than the Disease?

Article Tools

  • Bookmark

Significant FISMA Disconnect Is the Cure Worse Than the Disease?

Intelligent Decisions, Inc., a systems integrator in the Washington, D.C., metropolitan area, announced the results of its first annual Federal Chief Information Security Officer (CISO) Study. Across the board, Federal CISOs ranked patch management as their number-one security concern pointing directly to significant issues with commercial software quality. The study highlights cyber attack preparedness, Federal Information Security Management Act (FISMA) compliance, and network compromise among major concerns that keep CISOs up at night.

The Intelligent Decisions Federal CISO Study, based on telephone interviews with 25 of the total population of 117 Federal agency CISOs, is based on the first empirical survey of these executives. The goal of the Study is to examine the role of the Federal CISO and to understand their daily duties, budget, and management responsibilities. The study outlines current and future IT security priorities, trends, concerns, as well as attitudes toward commercial security vendors.

The study reveals a class divide among Federal CISOs those who control less than $500,000 and those who control more than $10 million in annual information technology (IT) spending. The security have nots are loaded down with administrative tasks and challenged to get to strategic security management functions. This class of CISOs devotes 45 percent of its time to FISMA compliance reporting an administrative task and just 22 percent of its time to the high-value security management functions architecture development, inventory control, and vendor collaboration that FISMA is supposed to encourage. The security haves spend 27 percent of their time on FISMA compliance reporting. This class devotes almost 50 percent of its time to high-value security management functions.

It is clearly time for private industry to get serious about software quality, said Harry Martin, president, Intelligent Decisions. CISOs rank product quality and past performance as the two most important criteria for evaluating vendors and solution providers. The weight of mechanical FISMA compliance reporting is clearly an issue for smaller agencies. Sixty-three percent of Federal CISOs at small agencies are calling industry to develop a real-time FISMA compliance tool. It would be logical to develop such an offering as a managed service to reduce the financial and administrative burden on these smaller agencies.

Other key study findings:

CISOs who control less than $500,000 annually:

Spend 45 percent of their time on FISMA compliance reporting, 13 percent on troubleshooting, nine percent on network monitoring, nine percent on collaborating with vendor/contractor partners, eight percent on system administration, six percent on architecture development, and six percent on inventory control

Consider the top three most important products/services to their agency to be network security/firewalls, intrusion detection/prevention systems, and authentication/PKI/encryption devices

Supervise 2.6 dedicated IT staff on average

Have served 3.2 years in their position on average

CISOs surveyed who control more than $10 million:

Spend 27 percent of their time on FISMA compliance reporting, 18 percent on collaborating with vendor/contractor partners, 18 percent on troubleshooting, 15 percent on architecture development, 12 percent on inventory control, nine percent on network monitoring, and zero percent on system administration

Consider the top three most important products/services to their agency to be authentication/PKI/encryption devices, biometrics for user log-on authentication, and security information management tools

Supervise 16.7 dedicated IT staff on average

Have served three years in their position on average

For study results, visit: http://www.govpro.com/ASP/ViewArticle.asp?strArticleId=104188

About Intelligent Decisions

Intelligent Decisions (ID) is a certified small, minority-owned business and a provider of comprehensive IT solutions. For more than 15 years, ID has solved clients most challenging IT problems by leveraging its core areas of expertise in data lifecycle management; cyber and physical security; network operations; product solutions; contract manufacturing; and specialized security services supporting the Intelligence community.

To support federal procurement requirements, ID manages a robust GSA Schedule, Government Wide Acquisition Contracts (GWACs) including SEWP III, ECS III and ADMC-1 and a significant number of agency Blanket Purchase Agreements (BPAs). For more information about ID, visit http:// www.intelligent.net or call toll-free 800-929-8331.

Want to use this article? Click here for options!
© 2008 Penton Media Inc.

Commenting terms of use blog comments powered by Disqus

Online Resources

Free Webinar: Secrets for Maximizing Your Contract Management Process

Learn duringIBM and Info Trends' LIVE Webinar October 28, 2pm ET. Contracts are a critical source of information to an ever-larger number of employees and business processes, but how do you make them work better for you? Join our featured speakers as they explain six key ways to improve your contract process. Register Now.

More Webinars

eNews

Maryland County Aims to Juice Up Energy Efficiency in its Buildings

Prince George's County in Maryland has inked a deal with Pepco Energy Services that could provide more than $4 million in energy savings for county facilities over the 14-year life of the project... Read Now.

More Articles

  • Webinars
  • News
  • Videos
  • eNews
  • eCards
  • Jobs
  • RSS

Featured Products

Facilities

Single-stage compressor

The 7500 S-energy Series with Energy Efficiency System (EES) heat recovery is Sullair's most energy-efficient single-stage compressor...

Fleets

Thinking locally

Beginning in 2003, strategic sourcing became a well-traveled buzzword in government procurement circles, winding its way through state capitals across...

Green

Hybrid system produces high-gloss barrier for concrete

Bellatrix water-based hybrid system provides dual actions of penetrating and topical protection for previously densified concrete. When used in conjunction...

Grounds

Remote connectivity for mulcher

Remote connectivity is available on Model FTX440 crawler mulchers. Systems information can be viewed from almost anywhere...

Parks & Rec

Riding mower

The Z Master Z595-D zero-turn riding mower offers landscape contractors a proven high-torque diesel engine with added horsepower for tackling tough mowing conditions...

Public Safety

ADA-compliant handrail system

Kee Access safety components are used to build handrails that meet ADA requirements. ...

Public Works

Drywall screwdrivers durable silent-clutch design reduces noise

Model BFS450 18-volt LXT lithium-ion cordless drywall screwdriver delivers 4,000 rpm. Durable silent-clutch design in forward mode reduces driver noise....

Technology

Tunable laser system

Opolette HR integrated tunable laser system incorporate a diode-pumped, true-solid-state (DPSS) laser as the pump source. ...

Video Gallery

Check out Government TV

Tune in daily to see company video programs, product demonstrations, reports from industry trade shows and interviews with newsmakers

Featured Video:

More Videos

What You're Saying