Considerations for a Federal Security Compliance and Risk Management Program

Compliance with the Federal Information Security Management Act (FISMA) can be challenging due to the broad scope of technical standards specified by NIST. The security framework in SP 800-53 includes 17 areas of security covering 205 technical and program management controls. Mapping these to IT operations of a large federal agency, implementation, and ongoing management is a huge process. To help, PacketViper has mapped 20 critical SANS controls for effective cyber defense. These specific recommendations are viewed effectively in blocking currently known high-priority attacks, as well as those attack types expected in the near future.

See below how PacketViper offers solutions to help federal agencies and contractors be compliant.

Limitation and Control of Network Ports, Protocols and Switches

NIST Special Publication 800-53 r4 Controls: AT-1,2,3,4 – SA-11,16 – PM-13,14,16

Allow remote access only to legitimate users and services. Apply host-based firewalls and port-filtering and scanning tools to block traffic that is not explicitly allowed. Properly configure web servers, mail servers, file and print services, and domain name system (DNS) servers to limit remote access. Disable automatic installation of unnecessary software components. Move servers inside the firewall unless remote access is required for business purposes

Limitation and control of network ports is primarily accomplished with the discovery of traffic flowing through the perimeter environment.  This is achieved by using tools such as:

  • Home Screen dashboard widgets
  • Summary and scheduling reporting
  • Searchable log filterings with linked IP context
  • Advanced Analytics
  • Web and Mail Analyzers
  •  Virtual Minefield sensors

Risk Management

 

PacketViper can regularly generate reports and sensor data including time, network ports, protocols, countries, companies, and associated networks found.  A record of each discovery is kept within PacketViper for a period of time designated by the customer or forwarded to 3rd party logging system (example: Splunk, LogRythm, etc.)

PacketViper can correlate connection traffic against any country, company, network, and IP using time criteria within our Advanced Analytics module. PacketViper can ingest converted network captures from sources, such as PCAP, to correlate the captured data within Advanced Analytics module. Virtual Minefield Zones and Sensors can detect unusual or unauthorized network activity including, but are not limited, the following:

  • Critical Host Volume
  • Scans and probes
  • Time schedule Violations
  • Port Activity Rates
  • Unusual Port Activity
  • Unusual Network Volume
  • Geographical Region, Company, or Network
  • Direction

Risk Management Correlation

Use PacketViper dashboards to view, in real time, live traffic with time stamp source and destination country, company, and IP.  Each view is hyperlinked to our patented NetCheck which provides the full IP context of data capable of geographically isolating any part of the traffic by IP, company, or country.  

Boundary Defense

NIST Special Publication 800-53 r4 Controls: AC-4,17,20  – CA-3,7,9 – CM-2 – SA-9 – SC-4, 7 – SI-4

Control the flow of traffic through network borders and police content by looking for attacks and evidence of compromised machines. Establish multi-layered boundary defenses by relying on firewalls, proxies, demilitarized zone (DMZ) perimeter networks and other network-based tools. Filter inbound and outbound traffic, including traffic through business partner networks (“extranets”).

Deny communications with or limit the data flow to known malicious IP addresses (blacklists), or limit access only to trusted sites (whitelists). Tests can be periodically carried out by sending packets from bogon source IP addresses (un-routable or otherwise unused IP addresses) into the network to verify they are not transmitted through network perimeters. Lists of bogon addresses are publicly available on the Internet from various sources and indicate a series of IP addresses that should not be used for legitimate traffic traversing the Internet. To control the flow of traffic through network borders, and to police content by looking for attacks and evidence of compromised machines, boundary defenses should be multi-layered—relying on firewalls, proxies, and DMZ perimeter networks as well as network based IPS and IDS. It is also critical to filter both inbound and outbound traffic.

PacketViper can granularly control, regulate, and identify traffic geographically by rate, direction and time. You can also identify by country, company, network and IP.  By filtering the key aspects identified, port and protocol filters will significantly reduce the activity and unwanted traffic through the security perimeter.  This method reduces traffic congestion and the amount of loads which in return provides better visibility to enhance current security postures.

Risk Management Map

 

PacketViper can specifically control boundaries of internal, external, and cross connected networks. This can be done geographically by rate, time, company, network or IP for any connected devices.

Risk Management Controls

 

PacketViper can analyze, alert, and filter traffic destined or received from dump servers, command and control machines or bots. Our Virtual Minefields can gather intelligence while detecting newly infected bots, proxy attempts, probes/scans and flooding.

Deception Dashboard

About FISMA

FISMA is part of the E-Government Act of 2002. Its provisions fall into three major categories: assessment, enforcement, and compliance.

Assessment pertains to determining the adequacy of the security of federal assets.

Enforcement requires that key information security provisions be implemented and managed.

Compliance establishes provisions for the management of each agency’s information security program and the accountability of each agency for compliance and reporting.

FISMA directs the National Institute of Standards and Technologies (NIST) to create and manage technical standards for compliance. Key standards include NIST Special Publication (SP) 800-53 and Federal Information Processing Standards (FIPS) 199 and 200. Audits for FISMA compliance are managed by the Office of Management and Budget (OMB).

Why FISMA Matters to Your Organization

Threats to federal systems and critical cyber infrastructures come from sovereign states, terrorists, criminals, lone hackers, and mistakes committed by staff and contractors. A successful exploit would be disastrous if it were to stop or stall vital functions of government or critical services.

If a federal agency fails to comply with FISMA, it may be sanctioned via a budget cut. Contractors that exchange data with federal information systems must also comply with FISMA or risk termination from a contract. Non-compliance may preclude contractors from bidding on future federal contracts.

From Our Blog

  • Vendor Risk Monitoring 360:  It’s Continuous and it’s inside

    continuous vendor risk managmentIs your organization looking for a way to protect against a vendor-related breach? Do you want to enforce policies around how your vendors behave on your network? Read this blog to learn how.

  • How to Detect and Prevent Ruthless Cryptojacking

    cryptojackersThis blog takes a look at crypto mining from a networking perspective. Fundamentally, crypto mining is a very long-lived TCP connection between a client and a server. The ports and protocol can vary, and the TCP communication can be encrypted. Discover how to prevent the worm from completing its crypto mining task.

  • Build a Business Case for Deception Technology

    NCSAM 2019Three unique use cases build a business case for deception technology as we mark the start of National Cyber Security Awareness Month (NCSAM).

  • NIST gets down with Deception

    A lot of CISOs look to the National Institute of Standards and Technology (NIST) and ISO for third-party validation of appropriate security controls and security program approaches. In this blog, read how NIST recommends Deception for protecting critical programs and high-value assets.

  • Deception Gets Screen Time at Gartner Security Risk and Management Summit 2019

    Don Gray recaps the Gartner® Security and Risk Management Summit 2019 commenting on three key points: deception prominently referenced in the keynote presentation, 7 imperatives of CARTA, and DevSecOps.

  • What is Internal and External Cyber Deception Technology?

    Internal and external cyber deception technology together is not your traditional approach to deception, nor to security in general. Since the days of honeypots, cybersecurity experts have utilized deception as a way to protect the network interior. Threat detection at the network perimeter, on the other hand, has seemingly been the role of firewalls. Read More...

  • Deception at the cyber “front line”

    Cyber Deception Front LineWhatever you call the front, the ability to stop the enemy where you first face them is vital. A paired approach of deception both externally and internally represents a tremendous opportunity to reduce attack vectors and strengthen overall cyber defense.

  • Announcing PacketViper at RSAC Early Stage Expo

    RSAC Early Stage ExpoBe our guest at RSAC 2019. Register with our special code to gain entrance to the RSAC Expo arena. Visit the large halls at the Moscone but also come visit us at the Early Stage Expo in the Marriott just down the street from the conference.