IT SECURITY REGULATORY OVERVIEW
Federal Government agencies and the cleared contractor base face a unique series of challenges in the cybersecurity arena. With advanced targeted attacks from all quarters, these entities are tasked with following a series of standards and risk-based guidelines for securing their IT infrastructures and systems against external threats with the twin goals of data security and privacy. These regulations are born of necessity and the guidelines go a long way towards covering effective risk management of critical infrastructure, but stop short of providing implementation recommendations.
The Federal Information Security Management Act of 2002 (FISMA) and its subsequent updates drive the efforts to keep security systems current. FISMA requires the “development and maintenance of minimum controls required to protect Federal information and information systems” and “a mechanism for improved oversight of Federal agency information security programs.” The law gives authority to the National Institute of Standards and Technology (NIST) to set the control standards, and many states also base their own regulations on these models.
Global standards such as ISO/IEC 27000 series from the International Organization for Standardization, the European Data Protection Directive (EDPD), and others provide additional impetus for Federal organizations and their worldwide counterparts to continuously improve their information defenses across the board.

Federal IT directors, Chief Information Security Officers and other high-level actors are challenged with practical implementation decisions that must mitigate risk across the FISMA/NIST families of risk classification. These decisions are weighed against a threat landscape that has increased by 75% from FY10 to FY11 alone. (1) Implementation of IT security policies must be made in accordance with existing infrastructure capabilities and without adding significant workload to already overburdened IT staff.
Malicious software (malware) is among the fastest growing and rapidly evolving security challenges facing the Federal sector, expanding more quickly than most organizations can respond to it, and nearly impossible to defend against entirely.
By providing actionable intelligence from our Malware Analyzer G2 and a feedback cycle to our Network Protection, Network Threat Discovery enables continuous monitoring, analysis, and remediation capabilities. Quickly converting unknown samples into identified malware with clearly understood behavior successfully prevents future attacks. This helps to reduce the organization’s threat cross-section and improve its overall defensive posture, exceeding compliance and moving closer to true data security.

