Six Critical Elements to Ensure Pain-Free FISMA Compliance

Michael Rasmussen, Corporate Integrity; Jeff Hughes & Steve Antone, Lumension
Federal CISOs note compliance as one of their top three priorities with significant time spent on addressing compliance issues. This is exacerbated by the complexity of today’s IT environment, including physical and virtual environments, multiple operating systems and applications supported, and the mobility of data and users. A FISMA compliance approach that relies on a manual and labor-intensive process can produce mountains of paper and electronic documents that become quite burdensome to manage and ultimately don’t ensure a secure network. It’s no surprise then, that in a recent ISC2 survey, while FISMA is generally viewed as having had a positive effect, two in five CISOs believe it has become misdirected or is a time-wasting exercise.

In this Lumension webcast you will learn:
•About FISMA and its requirements
•The six critical elements necessary to reduce the burden of FISMA compliance processes, improve security and optimize resources
•How to apply these critical elements to achieve economical FISMA compliance
Jan 21 2010
60 mins
Six Critical Elements to Ensure Pain-Free FISMA Compliance
More from this community:

Health IT

Webinars and videos

  • Live and recorded (302)
  • Upcoming (14)
  • Date
  • Rating
  • Views
  • Ever feel like you spend more time converting security information from one format to another, than actually connecting the dots hidden within it? The Collective Intelligence Framework (CIF) is a data processor for pulling in and normalizing out all these threat intel sources into a single combined dataset.

    Learn how to...
    Get CIF up and running
    Connect intelligence sources to CIF
    Leverage CIF with your existing security controls
    Host: Conrad Constantine, Community Manager, AlienVault
    Guest: Todd Leetham, Visiting Scientist, RSA I The Security Division of EMC
    Event Date: Tuesday, May 21, 2013 at 11am PDT
  • This webinar provides an introductory overview of NHS Finance in England, to gain as awareness and basic understanding of how NHS finance works. You will learn about the distinction between capital and revenue and different finance regimes operated in the NHS. It will also include information on where the money is spent and International comparisons.
  • How to keep your head (and your job) when the worse case scenario happens.

    Due to the increasing frequency of security breaches, defining an action plan is critical for every security practitioner. Getting breached doesn’t determine whether or not you’ve got a good security program in place – but how you respond to one does.

    Join security expert Conrad Constantine of AlienVault, for an in-depth discussion on things you and your team should do today to prepare for information security breaches. You’ll get practical, lessons learned advice on:

    -The inevitability of security breaches
    -Preparing to survive security breaches
    -Threat identification and containment
    -Handling the aftermath so it’s not worse than the breach itself
  • The data center is changing in an era of applications and automation, but how do you get there? OST, an expert in crafting automation for large-scale public clouds and developing new provisioning models for enterprise technology and in-application development, has experience in bringing data centers into the 21st century.

    Register for this webinar to learn:
    •How to develop core disciplines of application development and automation in the IT department
    •How to provide business-responsive services without compromising quality
    •How to prepare your data center for the future
  • Attend this webinar to discover:

    ·Insight from BRIC healthcare leaders as they share field experiences and best practices gathered through hundreds of successful cases
    ·Common obstacles international companies must overcome in these regions
    ·How to exploit the hidden potential of BRIC countries
    ·Tactics to adjust strategy to successfully penetrate BRIC markets
    ·The top 10 technologies and products expected to drive growth in these regions
  • Give Your Users the Bling Without the Sting
    – a BYOD Strategy for Healthcare IT and Beyond.

    Users in every industry are voyaging more and more to using their own consumer devices. This is the birth of BYO. This is never more true than in Healthcare and Healthcare IT faces some of the greatest challenges in supporting their clinical users in a Bring You Own world. But using advanced technologies from RES Software and Flexera Software you can support your clinicians as they move across a multitude of devices throughout their day, as they roam across the hospital and access their critical healthcare applications and data in a variety of methods.

    Learn from the experts in the trenches from VDX how to successfully support the new age of mobility across the care cycle, and get IT out of the basement and into the boardroom, where IT belongs.
  • Advances in the understanding of the behavior and function of biological systems are dependent on the study of cells and tissues. An essential tool in this research is the use of in vitro cell culture. Many variables contribute to providing a physiological environment for the cell in the laboratory, a few examples include cell source, isolation techniques, growth conditions such as matrix proteins and soluble factors, and cell age. Basic laboratory practices are sometimes overlooked as a source of discrepancy in data; however the application of fastidious and reproducible technique can reduce cell culture as a source of data variation. As specialized techniques have been developed to modulate cells and tissues in vitro, the importance of reproducible data has become paramount. In this presentation, we will identify and discuss basic principles of in vitro mammalian cell culture that influence the quality of experimental results.
  • Do you want to know how ‘best-of-breed’ enterprises prioritize their IT risk? Join Richard Mason, Vice President & Chief Security Officer at Honeywell, whose team is responsible for global security, during a roundtable discussion with Pat Clawson, Chairman & CEO of Lumension and Roger Grimes, Security Columnist & Author. Uncover strategies beyond traditional antivirus signatures and learn a more holistic approach to effective risk management. Find out ‘how’ and ‘why’ you can make security a prioritized function within your organization.

    Join this expert panel webcast to learn how to:
    1)Understand your business audiences and evaluate their risk tolerance
    2)Leverage reputation management services that are appropriate for your organization
    3)Utilize realistic change management to secure prioritized data depositories
  • Sit down with AlienVault and open source pioneer, Luca Deri. Learn more about his work on DPI and the changes he’s making to the Linux Kernal to be able to catch-up with companies like Palo Alto Networks and more.
  • The first webinar in the series will focus on the concept of value in healthcare whilst delivering value for money. Against an environment of constrained finances and the extensive reforms underway, this is a significant challenge for the NHS, however improving productivity and quality is key with trusts needing to dliver more ambitious cost improvement plans and at the same time drive efficiencies through radical service reconfiguration. Alongside system change and financial challenge, the NHS must continue to deliver high-quality and value services to patients.

    This session will cover:

    •What we mean by value in healthcare
    •Why it is important to consider value in healthcare and how this requires a different approach
    •Reference to Michael Porters four key elements for delivering value in healthcare
    •Understanding the importance of the role of clinicians on delivering value
    •Experience in practical examples from the speakers
  • Channel
  • Channel profile
Up Down
  • BYOD & Mobile Security: How to Respond to the Security Risks Jun 4 2013 4:00 pm UTC 60 mins
    Bring Your Own Device (BYOD) is a popular topic in 2013. The trouble is that IT is trying to understand the security risks and prepare strategies to either adopt employee-owned mobile devices or decide against it for security and data control reasons.

    The 160,000 member Information Security Community on LinkedIn conducted the survey “BYOD & Mobile Security 2013” to shed some light on the drivers for BYOD, how companies will benefit from BYOD, and how they respond to the security risks associated with this trend. With 1,600 responses, some interesting insights and patterns into BYOD were uncovered.

    Participate in this interactive webcast to learn:

    •Current Mobile Security Threats
    •Top Trends & Drivers in BYOD & Mobile Security
    •Necessary Features to Minimize these Security Risks
    •Live, Interactive Q&A
  • 3 Executive Strategies to Prioritize Your IT Risk Recorded: May 8 2013 60 mins
    Do you want to know how ‘best-of-breed’ enterprises prioritize their IT risk? Join Richard Mason, Vice President & Chief Security Officer at Honeywell, whose team is responsible for global security, during a roundtable discussion with Pat Clawson, Chairman & CEO of Lumension and Roger Grimes, Security Columnist & Author. Uncover strategies beyond traditional antivirus signatures and learn a more holistic approach to effective risk management. Find out ‘how’ and ‘why’ you can make security a prioritized function within your organization.

    Join this expert panel webcast to learn how to:
    1)Understand your business audiences and evaluate their risk tolerance
    2)Leverage reputation management services that are appropriate for your organization
    3)Utilize realistic change management to secure prioritized data depositories
  • Understanding the Ins & Outs of Java Vulnerabilities and What to do About It Recorded: Mar 13 2013 61 mins
    Many organizations are jumping on the “Death to Java” bandwagon, ranting about turning off Java to eliminate risk. However, it is important to put the issue in the proper context. The reality is that a Java vulnerability is not the end game for a cyber criminal, it is merely a delivery mechanism in the quest to install and execute bigger malware.

    There is no “one size fits all” recommendation for eliminating Java risks. But, you do want to eliminate as much exploitable surface area as reasonably possible on your critical endpoints. This should be the philosophy engrained in every organization’s security culture. If you’re not having this conversation about Java - and quite frankly all of the third-party applications in your environment - you are missing the mark and not calculating your risk. Join Paul Henry and Russ Ernst as they bring us up to speed on the Java vulnerabilities and how to limit your exposure without going overboard.
  • Defending Your Corporate Endpoints: How to Go Beyond Anti-Virus Recorded: Jan 30 2013 1 min
    Businesses large and small continue to struggle with malware. As a result, 50% of endpoint operating costs are directly attributable to malware alone[1]. Traditional approaches to malware protection, like standalone antivirus, are proving themselves unfit for the task. Something has to give.

    In this roundtable discussion, independent information security expert Kevin Beaver and Lumension Security’s Chris Merritt will talk about what can be done differently, including:

    • How to get a better grasp of the weaknesses in endpoint security that continue to get overlooked,
    • Examining whether or not anti-virus as we’ve known it is effective, and
    • A comparison between a proactive versus reactive approach to fighting the malware fight.

    [1] Ponemon Institute, 2011 State of Endpoint Risk, December 2010
  • 2013 Data Protection Maturity Trends. How Do You Compare? Recorded: Jan 22 2013 61 mins
    In 2012 we found out that the BYOD environment and consumerization of the workplace had turned traditional notions of corporate IT upside down. The 2013 Data Protection Maturity Report will highlight how organizations have managed this trend over the last year and what steps are being taken in 2013 to further enhance data security. Find out how IT teams are developing a holistic model that encompasses policy, education, technology and enforcement.

    During this webcast we look at each of data protection trends, helping you define your organization’s best practice guide to address the top concerns. We will also be showing you how you can gauge the maturity of your security systems, allowing you to plug any holes before your valuable data starts to leak through them.
  • Greatest IT Security Risks of 2013: Annual State of the Endpoint Report Recorded: Dec 5 2012 59 mins
    What are IT pros most concerned about heading into 2013? The annual State of the Endpoint Report sponsored by Lumension and conducted by Ponemon Institute reveals APTs and mobile devices pose the biggest security threat to organizations in the coming year. Unfortunately, respondents also demonstrated a disconnect between their identified risk and planned security spend as well as a significant need for improved internal collaboration.

    Join Larry Ponemon of the Ponemon Institute and Paul Zimski of Lumension for a webcast that will reveal statistics on growing insecurity, IT’s perceived areas of greatest risk for 2013 as well as tactical suggestions for how to improve your endpoint security. Specifically, you will learn:

    •IT perspective on today’s Top 3 risks;
    •Disconnect between perceived risk and corresponding strategies to combat those threats;
    •Tips and tricks on how to best communicate today’s threats and subsequent needed responses up the management chain
  • SENSATIONAL HEADLINES OR REAL THREATS? What New Attacks Mean For You? Recorded: Oct 22 2012 59 mins
    Well-organized, highly sophisticated cyber attacks continue to make headlines, hitting major U.S. banks and global companies like Adobe to name a few. In support of October as National Cyber Security Awareness Month, Lumension CEO Pat Clawson, Prolexic CEO Scott Hammack, security industry expert and author, Richard Stiennon and industry analyst and webcast moderator Eric Ogren will share their unique insight into these recent news-making attacks and what they mean for enterprises everywhere.

    In this webcast, you will learn:
    •The latest, seemingly extraordinary attacks;
    •How these attacks could escalate to the point where they matter to you and;
    •What you should be doing to secure against them.
  • Developing Best Practices to Device Control & Encryption: Technical Webcast Recorded: Aug 28 2012 74 mins
    The proliferation of USB flash drives and other removable storage devices has increased the porosity of the network perimeter. This has resulted in sensitive corporate and customer data leaking through the corporate firewall, exposing the organization to data loss, data theft and malware propagation. Understanding the powerful data protection tools available to your organization can help you mitigate these risks, while still enabling the flexible and managed use of these productivity devices.

    Join this webcast to learn the practical steps to guide you in the deployment of device control and encryption technology as we dive into a technical discussion of what the critical items to address, including:

    •Laying the Groundwork for Data Security
    •Preparing for Technical Enforcement
    •Enforcing Your Data Protection Policies
    •Managing Your Secure Environment
  • How to Guard Healthcare Information with Device Control and Data Encryption Recorded: Aug 7 2012 61 mins
    The need to protect digitized health information is a top priority in the healthcare industry. HIPAA and the HITECH Act put pressure on your organization to maintain the privacy and security of patient data, with the potential legal liability for non-compliance. So how does your healthcare organization meet or exceed industry best practices in guarding healthcare information?

    Join this webcast as Eric Ogren, President of The Ogren Group, and Chris Merritt, Solution Marketing Director at Lumension come together to take you through:

    • What PHI breaches are currently documented by the US Department of Health and Human Resources (HHS) and why these breaches are occurring
    • How a healthcare organization can mitigate costs with encryption technologies
    • What to look for in device control and full disc encryption solutions
  • Welcome to the Age of Weaponized Malware. What Does it Mean to Your Enterprise? Recorded: Jun 26 2012 61 mins
    The U.S. has not denied their role in the use of weaponized malware and already, other countries are jumping on board. India recently announced they are empowering government agencies to carry out similar such actions.

    State sponsored malware attacks are officially out of the shadows and mainstream for organizations and end users alike. In fact, Google recently announced an alert service for gmail users for “state sponsored attacks”. How exactly did we get to this point and what are the factors and threats that you need to be aware of?

    Join this complimentary webcast during this roundtable discussion by IT security industry experts as they answer the following questions:
    *How did we get to this point?
    *Why should the enterprise care?
    *What should the enterprise do?

    Walk away from this webcast with the knowledge and approach to help defend your enterprise against weaponized malware.
  • How Mature is Your Data Protection? 3 Steps to Effective Data Security. Recorded: May 22 2012 64 mins
    Make no mistake, consumerization of the workplace is one genie that is not about to go back into the bottle.

    With the BYOD movement overwhelming IT, and the convergence between personal devices and the corporate networks set to increase, the ability to restrict-and-ban the network is doomed to failure. Worse, they may be counterproductive to the business. Instead, IT teams must look at security in a different way, developing a holistic model that encompasses policy, education, technology and enforcement.

    During this webcast we look at each of these aspects, helping you define your organization’s best practice guide. We will also be showing you how you can gauge the maturity of your security systems, allowing you to plug any holes before your valuable data starts to leak through them.
  • E is for Endpoint II: How to Implement the Vital Layers on Your Endpoints Recorded: May 9 2012 60 mins
    IT security professionals rank third-party application vulnerabilities as the greatest security risk of 2012. And yet malware continues to exploit these – and other – vulnerabilities to breach our defenses. Clearly there’s a disconnect between knowing the problem and solving it. Yet it does not have to be this way, if we intelligently apply adequate protections against the exploitation of these vulnerabilities.

    Join this webcast, led by expert IT security panelists, to learn:

    •What are the vital layers of your endpoint defense.
    •How to thwart exploitation of your endpoint OS, configuration and 3rd-party application vulnerabilities.
    •How to prevent unknown applications from executing on your systems.
  • Developing Best Practices to Patch Management: An In-Depth Technical Webcast Recorded: Apr 25 2012 91 mins
    In today’s complex networking environment using patch and vulnerability management as the principal component of your risk mitigation strategy, and taking prudent measures to establish a best practices approach, can help reduce costs and risks in the long term.

    Patch and vulnerability management continues to be the first and last line of defense against existing and newest exploits. With the sophistication and sheer volume of exploits targeting major applications and operating systems, the speed of assessment and deployment of security patches across your complex IT infrastructure is key to mitigating risks and remediating vulnerabilities. Join this webcast to learn the recommended steps to cure your patch management headache as we dive into a technical discussion of what the critical items to address:

    •To Lay the Ground Work for Patch and Remediation
    •A Week before Patch Tuesday
    •On Patch Tuesday
    •After Patch Tuesday
  • E is for Endpoint: 6 Security Strategies for Highly Effective IT Pros Recorded: Feb 22 2012 59 mins
    We all like the idea of a silver bullet—a single, simple solution to a complex problem. But there’s no silver bullet when it comes to information security. Though some IT professionals have clung to the vain hope that antivirus (AV) alone would do the trick, others have come around to the need for a layered, defense-in-depth approach to endpoint security. But today’s endpoints demand even more. Endpoint security now requires a new way of thinking that goes beyond just battling threats to actually enabling operational improvement.

    Join this webcast, led by expert IT security panelists as you learn:
    •The most common attack vectors in today’s IT environment
    •Six steps to help you think different about endpoint security
    •Secrets to an effective defense-in-depth approach
  • Greatest IT Security Risks in 2012: Annual State of the Endpoint Report Recorded: Jan 17 2012 55 mins
    While malware attacks continue to be a significant risk and operational cost driver, IT security teams today are more concerned about the new threats brought on by personal mobile devices in the workplace, virtualization technologies and cloud computing, according to the 2012 State of the Endpoint survey sponsored by Lumension and conducted by Ponemon Institute. And while reliance on these productivity tools are expected by other business leaders, inadequate collaboration and lacking resources for security create a perfect storm for hackers.

    Join this webcast as we reveal statistics on growing insecurity, perceived areas of greatest risk for IT in 2012, and interestingly, a significant disconnect between risk and planned security strategies. In addition, we will examine the evolving IT risk environment and recommendations to more effectively and cost-efficiently secure your endpoints. Learn about:

    * How organizations are creating a perfect storm for hackers
    * The Top 3 new threats to the workplace
    * Perceived risks and corresponding strategies to combat the evolving endpoint environment
  • How to Reduce Endpoint Complexity and Costs Recorded: Nov 8 2011 61 mins
    Ensuring the security of organizational endpoints is tough, especially when you have limited resources and budget. It’s not just about what security technologies to deploy, but how can you more efficiently manage your environment.

    Join Roger Grimes and Chris Merritt for the second part of our SMB Security Webcast Series as they discuss key recommendations for improving endpoint security while also:

    • Improving Uptime, without additional management burden
    • Reducing Complexity, by limiting the number of security agents and consoles to manage
    • Reducing Overall Costs, by getting more from limited IT security resources and budget
  • How to Improve Endpoint Security on a SMB Budget Recorded: Sep 27 2011 63 mins
    Today’s cybercriminals are targeting small-to-midsize organizations more frequently. With limited staff and resources, SMBs face the challenge of increasing IT security issues and more sophisticated threats with a limited arsenal. Recent research shows that:
    •60 percent of users are running unpatched versions of Adobe*
    •36 percent of SMBs rely on free antivirus**
    •13 percent of SMBs have no security at all**

    Learn practical recommendations for improving security, including how to:

    •Deter cybercriminals by taking care of the IT security basics
    •Prioritize what security technologies to implement
    •Better educate users to limit user errors
    •Implement processes that improve security without impacting overall productivity
  • Reorganizing Federal IT to Address Today’s Threats Recorded: Aug 11 2011 59 mins
    New reports show U.S. government servers are faced with 1.8 billion cyber attacks every month. A quick look at these numbers and it is painfully obvious that status quo security measures are not keeping pace with today’s threats. Congress has taken a step by introducing the Cyber Security Public Awareness Act of 2011, but more evolution of our cyber defenses needs to occur.

    In this webcast, Richard Stiennon analyst with IT Harvest and author of Surviving Cyber War, and Paul Zimski, VP of solution strategy with Lumension, will examine:
    • Today’s threats targeting government IT systems
    • How federal IT departments can be reorganized to improve security and operations
    • What key endpoint security capabilities should be implemented
  • How to Enable Local Admin Access Without the Risk Recorded: Jun 16 2011 59 mins
    In today’s Windows environment, end users are accustomed to having local administrator privileges which allow them to download a variety of applications and potentially misconfigure their PCs. While standard wisdom may be to simply solve the problem by revoking local administrator rights on users’ systems, the reality is that this may not be an option at all organizations. And removing local admin rights doesn’t address applications such as Google Chrome or browser plug-ins for which admin access isn’t required.
    Fortunately, there’s hope for IT administrators seeking to gain control over the Windows environment while still offering local admin rights to the user base – through application whitelisting. With application whitelisting, IT can gain power over what types of applications their users install and limit their access to under-the-hood controls that determine how well config¬ured the machine remains.

    In this webcast, we’ll examine:
    • Why revoking local admin rights won’t solve the problem of unwanted and malicious applications
    • How to promote productivity through local admin access while achieving control over configuration changes
    • Additional benefits of application whitelisting, including the prevention of zero-day attacks
  • Why Patch Management is Still the Best First Line of Defense Recorded: Apr 13 2011 35 mins
    Vulnerabilities are on the rise - especially from third party, non-Microsoft applications, which have four times more vulnerabilities than Microsoft applications. And cybercriminals have taken notice, exploiting these vulnerabilities at a faster rate than ever before. Today more than 2 million malware signatures are identified each month and traditional anti-virus defenses simply can’t keep up. Even the major anti-virus vendors have concluded that stand-alone anti-virus no longer provides an effective defense and that additional layers of security technology are needed to address the rising volume and sophistication of threats.

    In this webcast, security and forensics analyst Paul Henry will examine:

    • Why you can’t forget about older vulnerabilities
    • How to reduce exposure from both OS and 3rd party application vulnerabilities
    • The challenges with reliance upon “free” patching tools and native updaters
    • Why you should consider patch management as the core of an effective depth-in-defense endpoint security approach
Tips to Endpoint Management, Security and Compliance Challenges
This channel provides live and on-demand webcasts on a range of Endpoint Management and Security topics, including: identifying the latest trends and best practices for minimizing insider risks, reducing your threat exposure, managing Web 2.0 threats, reducing your cost of compliance and taking control of your endpoints, from both an operational and security perspective.

Embed in website or blog

Successfully added emails: 0
Remove all
  • Title: Six Critical Elements to Ensure Pain-Free FISMA Compliance
  • Live at: Jan 21 2010 6:00 pm
  • Presented by: Michael Rasmussen, Corporate Integrity; Jeff Hughes & Steve Antone, Lumension
  • From:
Your email has been sent.
or close
You must be logged in to email this