DocumentCode :
158673
Title :
MAVEN information security governance, risk management, and compliance (GRC): Lessons learned
Author :
Takamura, Eduardo ; Gomez-Rosa, Carlos ; Mangum, Kevin ; Wasiak, Fran
Author_Institution :
NASA/Goddard Space Flight Center, Greenbelt, MD, USA
fYear :
2014
fDate :
1-8 March 2014
Firstpage :
1
Lastpage :
12
Abstract :
As the first interplanetary mission managed by the NASA Goddard Space Flight Center, the Mars Atmosphere and Volatile EvolutioN (MAVEN) had three IT security goals for its ground system: COMPLIANCE, (IT) RISK REDUCTION, and COST REDUCTION. In a multi-organizational environment in which government, industry and academia work together in support of the ground system and mission operations, information security governance, risk management, and compliance (GRC) becomes a challenge as each component of the ground system has and follows its own set of IT security requirements. These requirements are not necessarily the same or even similar to each other´s, making the auditing of the ground system security a challenging feat. A combination of standards-based information security management based on the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF), due diligence by the Mission´s leadership, and effective collaboration among all elements of the ground system enabled MAVEN to successfully meet NASA´s requirements for IT security, and therefore meet Federal Information Security Management Act (FISMA) mandate on the Agency. Throughout the implementation of GRC on MAVEN during the early stages of the mission development, the Project faced many challenges some of which have been identified in this paper. The purpose of this paper is to document these challenges, and provide a brief analysis of the lessons MAVEN learned. The historical information documented herein, derived from an internal pre-launch lessons learned analysis, can be used by current and future missions and organizations implementing and auditing GRC.
Keywords :
risk management; satellite ground stations; security of data; FISMA; Federal Information Security Management Act; GRC; IT security goals; MAVEN information security; NASA Goddard Space Flight Center; NIST risk management framework; National Institute of Standards and Technology; RMF; cost reduction; governance risk management and compliance; ground system security; mars atmosphere and volatile evolution; multiorganizational environment; risk reduction; Information security; NASA; NIST; Risk management; FISMA; GRC; IT security; compliance; cyber security; governance; information security; information security management; regulations; risk; risk management;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Aerospace Conference, 2014 IEEE
Conference_Location :
Big Sky, MT
Print_ISBN :
978-1-4799-5582-4
Type :
conf
DOI :
10.1109/AERO.2014.6836516
Filename :
6836516
Link To Document :
بازگشت