<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-6447776621493920602.post8425642276851638179..comments</id><updated>2011-11-04T11:53:03.111-07:00</updated><category term='Membership Benefits'/><category term='COBIT'/><category term='Cyber Crime'/><category term='Risk Management'/><category term='IT Governance'/><category term='Certification'/><category term='Miscellany'/><category term='Cloud Computing'/><category term='Contingency Planning'/><category term='CGEIT'/><category term='Information Warfare'/><category term='Information Security'/><category term='Business Intelligence'/><category term='CRISC'/><category term='CPE'/><category term='CISM'/><category term='Continuous Audit'/><category term='Career Opportunities'/><category term='CISA'/><category term='Learning'/><category term='Compliance'/><category term='IT Audit'/><category term='Privacy'/><category term='Virtualization'/><category term='Law'/><category term='E-Discovery'/><title type='text'>Comments on ISACA Sacramento Web Log: FISMA Compliance: Metrics or Management?</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.isaca-sacramento.org/feeds/8425642276851638179/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6447776621493920602/8425642276851638179/comments/default'/><link rel='alternate' type='text/html' href='http://blog.isaca-sacramento.org/2008/06/fisma-compliance-metrics-or-management.html'/><author><name>ISACA-SAC Blog Master</name><uri>http://www.blogger.com/profile/07672995893033955927</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>7</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6447776621493920602.post-4405343245548183412</id><published>2011-04-20T05:25:17.066-07:00</published><updated>2011-04-20T05:25:17.066-07:00</updated><title type='text'>I totally agree that COBIT is the best answer to t...</title><content type='html'>I totally agree that COBIT is the best answer to the management requirement of IT industry. But can it work without affecting the efficiency?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6447776621493920602/8425642276851638179/comments/default/4405343245548183412'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6447776621493920602/8425642276851638179/comments/default/4405343245548183412'/><link rel='alternate' type='text/html' href='http://blog.isaca-sacramento.org/2008/06/fisma-compliance-metrics-or-management.html?showComment=1303302317066#c4405343245548183412' title=''/><author><name>USB Encryption</name><uri>http://www.lok-it.net/encrypted-flash-drive/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.isaca-sacramento.org/2008/06/fisma-compliance-metrics-or-management.html' ref='tag:blogger.com,1999:blog-6447776621493920602.post-8425642276851638179' source='http://www.blogger.com/feeds/6447776621493920602/posts/default/8425642276851638179' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1966997094'/></entry><entry><id>tag:blogger.com,1999:blog-6447776621493920602.post-241614108377487163</id><published>2011-02-09T09:21:52.897-08:00</published><updated>2011-02-09T09:21:52.897-08:00</updated><title type='text'>@Encrypted Flash Guy

So... is Federal management ...</title><content type='html'>@Encrypted Flash Guy&lt;br /&gt;&lt;br /&gt;So... is Federal management incapable? Personally, I think that the govt&amp;#39;s efficiency issues originate at a higher level than agency management. The most talented managers executing against the most relevant metrics won&amp;#39;t correct systemic policy and organizational shortcomings that lead to complacency, malignant redundancy, and fiefdom-building. Goals, carrots, and sticks are all misguided, and root causes are difficult at best, impossible at worst, to correct.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6447776621493920602/8425642276851638179/comments/default/241614108377487163'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6447776621493920602/8425642276851638179/comments/default/241614108377487163'/><link rel='alternate' type='text/html' href='http://blog.isaca-sacramento.org/2008/06/fisma-compliance-metrics-or-management.html?showComment=1297272112897#c241614108377487163' title=''/><author><name>Aud Man Out</name><uri>http://www.blogger.com/profile/03695859295572986136</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.isaca-sacramento.org/2008/06/fisma-compliance-metrics-or-management.html' ref='tag:blogger.com,1999:blog-6447776621493920602.post-8425642276851638179' source='http://www.blogger.com/feeds/6447776621493920602/posts/default/8425642276851638179' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-554029919'/></entry><entry><id>tag:blogger.com,1999:blog-6447776621493920602.post-8296952614493824836</id><published>2011-02-08T03:39:52.695-08:00</published><updated>2011-02-08T03:39:52.695-08:00</updated><title type='text'>FISMA has allocated precise tasks to the groups Na...</title><content type='html'>FISMA has allocated precise tasks to the groups National Institute of Standards and Technology (NIST) and Office of the Management and Budget (OMB). Metrics are a sine qua non situation of a capable management; in fact management cannot be based just leading perception, it has to be underpinned by figures. A Strategy-Focused association aligns its every day actions and communicates that approach during the enterprise.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6447776621493920602/8425642276851638179/comments/default/8296952614493824836'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6447776621493920602/8425642276851638179/comments/default/8296952614493824836'/><link rel='alternate' type='text/html' href='http://blog.isaca-sacramento.org/2008/06/fisma-compliance-metrics-or-management.html?showComment=1297165192695#c8296952614493824836' title=''/><author><name>J (Encrypted Flash Drive Guy)</name><uri>http://www.lok-it.net/encrypted-flash-drive/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.isaca-sacramento.org/2008/06/fisma-compliance-metrics-or-management.html' ref='tag:blogger.com,1999:blog-6447776621493920602.post-8425642276851638179' source='http://www.blogger.com/feeds/6447776621493920602/posts/default/8425642276851638179' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1370399350'/></entry><entry><id>tag:blogger.com,1999:blog-6447776621493920602.post-2784184610422558205</id><published>2008-07-14T04:00:00.000-07:00</published><updated>2008-07-14T04:00:00.000-07:00</updated><title type='text'>Hello all, I would also like to give my opinion on...</title><content type='html'>Hello all, I would also like to give my opinion on Risk and Compliance.&lt;BR/&gt;IT governance, risk and compliance (IT GRC) is about striking an appropriate balance between business reward and risk. The maturity of IT GRC practices for managing reward and risk has a direct impact on the organization. IT GRC encompasses the practices for delivering: Greater business value from IT strategy, investment and alignment, Significantly reduced business and financial risk from the use of IT, and Conformance with policies of the organization and its external legal and regulatory compliance mandates. IT GRC energizes the entire organization to imagine what it can achieve, establishes methods for achieving their objectives, and demonstrates the practices that are proven to work for minimizing business and financial risk. Fundamentally, IT GRC is about striking an appropriate balance between business reward and risk, enabling an organization to more effectively anticipate and manage business risk while more effectively delivering value for the organization. IT governance, risk, compliance, IT GRC, White paper, compliance survey report, 2008 compliance report. &lt;BR/&gt;You can also get more information from http://www.compliancehome.com/symantec/</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6447776621493920602/8425642276851638179/comments/default/2784184610422558205'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6447776621493920602/8425642276851638179/comments/default/2784184610422558205'/><link rel='alternate' type='text/html' href='http://blog.isaca-sacramento.org/2008/06/fisma-compliance-metrics-or-management.html?showComment=1216033200000#c2784184610422558205' title=''/><author><name>jacksmith</name><uri>http://www.blogger.com/profile/15617558583873270467</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.isaca-sacramento.org/2008/06/fisma-compliance-metrics-or-management.html' ref='tag:blogger.com,1999:blog-6447776621493920602.post-8425642276851638179' source='http://www.blogger.com/feeds/6447776621493920602/posts/default/8425642276851638179' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-625273212'/></entry><entry><id>tag:blogger.com,1999:blog-6447776621493920602.post-1048623865535369539</id><published>2008-06-19T17:48:00.000-07:00</published><updated>2008-06-19T17:48:00.000-07:00</updated><title type='text'>rybolov,&lt;br&gt;&lt;br&gt;Very humorous sarcasm! That &lt;i&gt;was...</title><content type='html'>rybolov,&lt;BR/&gt;&lt;BR/&gt;Very humorous sarcasm! That &lt;I&gt;was&lt;/I&gt; sarcasm, right? Seriously, I’m so excited about your ideas that I’m going to link back to you.&lt;BR/&gt;&lt;BR/&gt;Yes, &lt;A HREF="http://csrc.nist.gov/groups/SMA/fisma/framework.html" REL="nofollow"&gt;NIST Risk Management Framework&lt;/A&gt; closely resembles—and in some cases borrows from—COBIT. It’s less structured and much more comprehensive, given all the Special Publications that comprise it. COBIT attempts to specify &lt;I&gt;what&lt;/I&gt; you should do to achieve high-performing IT-driven operations. As I view it, the NIST framework attempts to tell you both &lt;I&gt;what&lt;/I&gt; you should do and, in verbose detail, &lt;I&gt;how&lt;/I&gt; you should do it.&lt;BR/&gt;&lt;BR/&gt;When your smart friends figure out how to dismantle the barriers to quality and performance management in government, please include me in the celebration. I’ve been working on that problem most of my adult life.&lt;BR/&gt;&lt;BR/&gt;I work in a large State government, so I can empathize with your plight. Sounds like the Fed faces conditions very similar to ours. I’m not sure that I can agree, though, that there are not enough skillfull/clueful people to meet demand. I find that a great many skillful—and clueful—people are chewed up and spit out by institutions that were purposefully designed not to change, evolve, or die. The theory of evolution &lt;I&gt;does not&lt;/I&gt; hold true for government. Of course, DC is a very different place from Sacramento. Heck, LA is a very different place from Sacramento. California’s difficulty, I think, is:&lt;BR/&gt;&lt;BR/&gt;1. Our constitution gives broad powers to individual agencies to manage as they see fit.&lt;BR/&gt;&lt;BR/&gt;2. Influencers at the Executive level have two levers to shape the will of agencies: policy, i.e. administrative regulations, and law.&lt;BR/&gt;&lt;BR/&gt;But...&lt;BR/&gt;&lt;BR/&gt;3. Administrative regulation is largely ignored, with no ramifications befalling those in positions to know better.&lt;BR/&gt;&lt;BR/&gt;4. Politics makes law impossible to effect.&lt;BR/&gt;&lt;BR/&gt;A few years ago, the Governor commissioned a task force to find ways to improve operations. The group identified over 200 vectors in the problem space. But in short order, cold hard reality befell the naïve Governor’s best laid plans.  Between a Legislature and public employees’ union bent on stonewalling all attempts to mandate change, and the utter inability of the Administration to apply pressure on agencies that had been ordained as kingdoms in the State Constitution, the initiative quietly died with only a handful of its recommendations realized.&lt;BR/&gt;&lt;BR/&gt;Incidentally, I’ve been told that the Canadian government has been successful—you define success—at implementing the COBIT framework. I would sure like to visit Ottawa to see what everyone’s talking about.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6447776621493920602/8425642276851638179/comments/default/1048623865535369539'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6447776621493920602/8425642276851638179/comments/default/1048623865535369539'/><link rel='alternate' type='text/html' href='http://blog.isaca-sacramento.org/2008/06/fisma-compliance-metrics-or-management.html?showComment=1213922880000#c1048623865535369539' title=''/><author><name>M.P. Schmidt</name><uri>http://www.blogger.com/profile/03695859295572986136</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.isaca-sacramento.org/2008/06/fisma-compliance-metrics-or-management.html' ref='tag:blogger.com,1999:blog-6447776621493920602.post-8425642276851638179' source='http://www.blogger.com/feeds/6447776621493920602/posts/default/8425642276851638179' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-554029919'/></entry><entry><id>tag:blogger.com,1999:blog-6447776621493920602.post-2160436955242134573</id><published>2008-06-18T05:51:00.000-07:00</published><updated>2008-06-18T05:51:00.000-07:00</updated><title type='text'>Cavalcade of Risk #54 is up, and your post is in i...</title><content type='html'>Cavalcade of Risk #54 is up, and your post is in it:&lt;BR/&gt;&lt;BR/&gt;http://www.bargaineering.com/articles/cavalcade-of-risk-54.html</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6447776621493920602/8425642276851638179/comments/default/2160436955242134573'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6447776621493920602/8425642276851638179/comments/default/2160436955242134573'/><link rel='alternate' type='text/html' href='http://blog.isaca-sacramento.org/2008/06/fisma-compliance-metrics-or-management.html?showComment=1213793460000#c2160436955242134573' title=''/><author><name>Henry Stern, LUTCF, CBC</name><uri>http://www.blogger.com/profile/03043774760749462290</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.isaca-sacramento.org/2008/06/fisma-compliance-metrics-or-management.html' ref='tag:blogger.com,1999:blog-6447776621493920602.post-8425642276851638179' source='http://www.blogger.com/feeds/6447776621493920602/posts/default/8425642276851638179' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-17008122'/></entry><entry><id>tag:blogger.com,1999:blog-6447776621493920602.post-7489439061030665813</id><published>2008-06-16T06:54:00.000-07:00</published><updated>2008-06-16T06:54:00.000-07:00</updated><title type='text'>Yes, the government's metrics are broken right now...</title><content type='html'>Yes, the government's metrics are broken right now.  Some really smart people that I know are working on changing that, but it's slow because the culture of Government is to resist change.&lt;BR/&gt;&lt;BR/&gt;I agree with you that PCI is the road to go down.  In fact, I wrote a tongue-in-cheek rebuttal on my blog at &lt;A HREF="http://www.guerilla-ciso.com/archives/363" REL="nofollow"&gt;FISMA: Better if PCI. WTF?&lt;/A&gt;&lt;BR/&gt;&lt;BR/&gt;While COBIT makes some sense, the problem is that government is driven by a different set of laws and standards that the private sector.  Looking through your description of COBIT, it's exactly what NIST has created in their Risk Management Framework.&lt;BR/&gt;&lt;BR/&gt;The biggest problem that we have in the Government is one of scale:&lt;BR/&gt;1. We do not have information security models above the enterprise level.&lt;BR/&gt;2. We do not have enough skillfull/clueful people in the DC area to keep up with the demand.&lt;BR/&gt;&lt;BR/&gt;No matter what the framework you use, you still will get the same results because it's not about the framework, it's about the people.&lt;BR/&gt;&lt;BR/&gt;Have a look at the presentation I put together on &lt;A HREF="http://www.guerilla-ciso.com/archives/408" REL="nofollow"&gt;security and the Government&lt;/A&gt;, I go through some of this.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6447776621493920602/8425642276851638179/comments/default/7489439061030665813'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6447776621493920602/8425642276851638179/comments/default/7489439061030665813'/><link rel='alternate' type='text/html' href='http://blog.isaca-sacramento.org/2008/06/fisma-compliance-metrics-or-management.html?showComment=1213624440000#c7489439061030665813' title=''/><author><name>rybolov</name><uri>http://www.blogger.com/profile/09022232218670789122</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.isaca-sacramento.org/2008/06/fisma-compliance-metrics-or-management.html' ref='tag:blogger.com,1999:blog-6447776621493920602.post-8425642276851638179' source='http://www.blogger.com/feeds/6447776621493920602/posts/default/8425642276851638179' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1142562883'/></entry></feed>
