GSA / GSA/modernization

Mandate for security automation

Open
#10 0 comments 0 reactions 0 assignees View on GitHub
Public comment
Dominant language
CSS
Stars
59
Forks
8
PR merge metrics
No merged PRs in 30d

Description

Although many standards are mentioned as part of the directives, there is no mandate for agencies, programs, or suppliers to implement security automation. The directives and committee mission should mandate, not recommend, that data center, cloud and application infrastructure should possess native capability to "automatically assess its security configuration status against standard security benchmarks defined in NIST SCAP machine operable formats, and further that the System shall provide operators an automated means to set configuration options to comply with defined benchmarks as required by security and risk management governance and policy for the target program(s)."

This approach will encourage and allow technology suppliers to make the required investments in System management software to help Federal agencies harden their systems and sustain secure configurations for the life cycle of those Systems and their associated mission(s).

There are suppliers in the market ready to make these investments with the correct signals from government to justify these investments for offer to Federal programs.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.