﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>I-Assure Forums / Information Assurance / Security Testing  / Assigning DIACAP Severity Codes and risk assessments / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>I-Assure Forums</description><link>http://www.i-assure.com/forums/</link><webMaster>forums@i-assure.com</webMaster><lastBuildDate>Thu, 09 Sep 2010 12:40:43 GMT</lastBuildDate><ttl>20</ttl><item><title>Assigning DIACAP Severity Codes and risk assessments</title><link>http://www.i-assure.com/forums/Topic927-7-1.aspx</link><description>Good evening,&lt;P&gt;In my current position, I routinely see 'risk assessment' reports that consist of no more than DISA Gold Disk findings assigned to an DoDD 8500.2 IA control. I've been assurred by the 'experts' who conducted an ST&amp;amp;E that the report does not contain false positives.  When asked, "how do you know it doesn't contain false positives," I was promptly told "it doesn't!"  &lt;/P&gt;&lt;P&gt;In my opinion, a report with nothing more than cut and paste from a DISA Gold report isn't all that useful and could contain false positives.  Isn't some level of analysis is needed to ensure what makes your final report is an actual finding? &lt;/P&gt;&lt;P&gt;My question:  How in the heck can you assess a severity code I to an IA control based on DISA Gold/STIG/checklist findings that may or may not be true?  Essentially, where is the analysis????&lt;/P&gt;&lt;P&gt;If I were a Cert Authority (CA), I wouldn't make a recommendation to my DAA based data that hasn't been analyzed.  It seems that some organizations rely solely on DISA gold/SRR/Checklist and if it's a STIG CAT I, by god, it's going to make the IA Control a CAT I.  Grrrr ... very frustrating!  I've seen several STIG PDIs that make reference to the wrong IA control.&lt;/P&gt;&lt;P&gt;Sorry to vent, but the IA business really sucks at times! </description><pubDate>Mon, 15 Feb 2010 21:36:02 GMT</pubDate><dc:creator>07caddy</dc:creator></item></channel></rss>