WITAT `96 Session Notes Session Title: Operational Assurance Description: Product and system assurance is only one ingredient involved in gaining confidence in an operation. Operational assurance depends not only on the information technology, but also on the people, environment, and processes involved. Even if information technology was 100% free of flaws, people would have to install, configure, and use it correctly for the system to be secure. This working group provided recommendations for improvement to operational assurance. Scope: This working group addresses those additional assurance required when a system is operating and the three areas in which this assurance is addressed: Certification and Accreditation (C&A) Inspector General (IG) Inspections and Security Audits Information System Security Officer (ISSO) Oversight Approach: The system analysis working group listed 9 objectives for the operational assurance methods. Each of the methods was evaluated against each of these objectives. Where appropriate, recommendations were made for each of the operational assurance methods to more fully meet the objective. The result is a set of recommendations for each of the methods to more fully meet the objectives listed below. Operational Assurance Objectives A Assure continuity of security posture throughout system lifecycle. B Collect and react to exploitation feedback. C Ensure complete analysis of enterprise including the environment, the processes, and the personnel. D Ensure continuity of protection objectives across physical and electronic implementation of the enterprise (i.e., across the policies, procedures, personnel, environment, and AIS implementations). E Determine and counter degraded assurance due to changes in the knowledge base and experience of system administration, operations, and system users. F Measure and promote an institutionalization and ownership of security practices. G Reflect actual assurance not just a "snap-shot." H Collect the data necessary to, detect, react, correct, and prosecute violations to security policy. I Ensure that the residual risk is well-understood in the context of the mission (or business) objectives. Recommendations Certification and Accreditation (C&A) A Complete the process of examining the difference between technical risk and total mission risk. A Examine the European method of performing Accreditations for improvements. A Regulate accountability for operating at risk to those who make decisions to operate. A Inspect for the degree of institutionalization of security practices. B Validate the process by which the ISSO functions to collect and react to exploitation feedback. C Clearly describe the security perimeter. C Document allocation of security requirements to enterprise components (e.g., people, process, environment). C Review the implementation of the security requirements. D Ensure continuity of protection objectives across physical and electronic implementation of the enterprise (i.e., across the policies, procedures, personnel, environment, and AIS implementations). E Determine and document personnel knowledge and experience requirements/ assumptions. F Indicate those accountable for breaches in security ad degraded mode of operations. H Ensure that residual risk is well-understood by accreditation authority. Inspector General (IG) Inspections and Security Audits A Simplify security administration through tool awareness and improvement . A Inspect for the degree of institutionalization of security practices. B Check the execution of exploitation feedback reaction to documented process. C Address the requirements for periodic review of security posture. (Policy compliance review). D Audit the information handling and protection across the physical / AIS boundary. E Determine personnel knowledge and experience. F Indicate those accountable for breaches in security ad degraded mode of operations. G Conduct random inspections to gain better insight into institutionalization of security practices. H (Private sector) Ensure that the link between financial readiness and mission readiness is well-understood. Information System Security Officer (ISSO) Oversight A The ISSO must promote the institutionalization of security practices. B The ISSO is responsible for detecting, reporting, and reacting to exploitation feedback. E Determine personnel knowledge and experience. E Ensure adequate knowledge and experience. F Inform those accountable for breaches in security ad degraded mode of operations. F Demonstrate a willingness to be accountable and to hold those responsible accountable. F Include rationale for security practices and dangers to mission in security awareness training. G Promote an institutionalization of security practices. G Centralize security administration. G Build and promote the ISSO career path.