|
Key Components of the FISMA Reporting Solution:
| | |
The ASSERT System
EPA has achieved great success with FISMA reporting using our Automated System Security Evaluation and Remediation Tracking (ASSERT) system. ASSERT provides federal managers with the type of reports and information needed to help agencies protect their critical cyber infrastructure and promote protection of privacy information. It helps agencies better understand and assess their security risks, monitor corrective actions and provide standardized and automated FISMA reports. Most importantly, ASSERT provides agency senior managers the information they need, from an enterprise perspective, to make timely and informed decisions regarding the level of security implemented on their information resources.
ASSERT is revolutionary because it builds the concept of "risk assessment" into the traditional system life cycle. It helps system owners and management officials better understand the risks systems face, the security controls necessary to address these risks, how systems interconnect, and current information on the status of any remediation activities being undertaken to strengthen the security on the information system.
Back to Top
Features of ASSERT
This innovative software provides a central, accessible repository of critical security data associated with an agency's major information systems. Allows view of security status and reports for the entire agency, organization or an individual system by providing:
- Automated system categorization
- Automated assessments
- Plans of Action and Milestones (POAMs) for remediation
- OMB data for Quarterly and Annual FISMA reports
- Secure Web-based application and centralized database
- Tailored customization for agency-specific terminology, reference tables, logo and colors
- User-centered design for easy navigation
- Scalable solution for agencies of all sizes
Back to Top
Customized Support Services
Because each agency will have unique requirements we are offering ASSERT partners customized support. We will work closely with our new partners to develop a plan for a highly customized implementation of ASSERT to meet their needs, budget and agency size. A menu of services includes such items as:
- Basic use of ASSERT
- Hosting the application at EPA's National Computer Center or at their own federal facility
- Membership in the ASSERT Consortium
- Support of agency-specific data entry
- Help desk support
- User training sessions
- FISMA-related consulting for business process improvements
- Support for completing the OMB Quarterly and Annual FISMA reports.
Back to Top
Current federal agencies using our FISMA Reporting Solution, including
ASSERT:
- Environmental Protection Agency (EPA)
- Export-Import Bank (EXIM)
- General Services Administration (GSA)
- Housing and Urban Development (HUD)
- National Aeronautics and Space Administration (NASA)
- Nuclear Regulatory Commission (NRC)
- Pension Benefit Guaranty Corporation (PBGC)
- Social Security Administration (SSA)
Back to Top
Customer Testimonials
"Since 2004 SSA has used the ASSERT tool. It has met all our
expectations and more as the Inspector General and their contractor have
also given it a 'thumbs up.' The team at EPA is excellent to deal with
and they go out of their way to assist ASSERT users. We at SSA highly
recommend the tool."
Information Technology Specialist
Office of the Chief Information Officer
Social Security Administration
Back to Top
Background and Philosophy
EPA has been designated by the Department of Homeland Security and
the Office of Management and Budget as a Shared Service Center for
Federal Information Security Management Act (FISMA) reporting. This
Shared Service Center will save the public's tax dollars by
encouraging effective sharing and reuse of solutions for FISMA
reporting - allowing agencies to dedicate their limited resources to
critical, mission-specific issues. More information about OMB's
Presidential Initiatives on Information System Security is
available.
EPA strongly believes that continuous improvement and a
customer-focused approach are fundamental components of our
successful system. Dedicated attention to system improvements ensures
alignment with federal business practices as required by FISMA, OMB
and the National Institute of Standards and Technology (NIST).
Contact us for more information about our ASSERT system for FISMA
reporting
Sign up for our ASSERT system for FISMA reporting
More information about OMB's Presidential Initiatives on Information System Security is available.
Back to Top