DocumentCode
158673
Title
MAVEN information security governance, risk management, and compliance (GRC): Lessons learned
Author
Takamura, Eduardo ; Gomez-Rosa, Carlos ; Mangum, Kevin ; Wasiak, Fran
Author_Institution
NASA/Goddard Space Flight Center, Greenbelt, MD, USA
fYear
2014
fDate
1-8 March 2014
Firstpage
1
Lastpage
12
Abstract
As the first interplanetary mission managed by the NASA Goddard Space Flight Center, the Mars Atmosphere and Volatile EvolutioN (MAVEN) had three IT security goals for its ground system: COMPLIANCE, (IT) RISK REDUCTION, and COST REDUCTION. In a multi-organizational environment in which government, industry and academia work together in support of the ground system and mission operations, information security governance, risk management, and compliance (GRC) becomes a challenge as each component of the ground system has and follows its own set of IT security requirements. These requirements are not necessarily the same or even similar to each other´s, making the auditing of the ground system security a challenging feat. A combination of standards-based information security management based on the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF), due diligence by the Mission´s leadership, and effective collaboration among all elements of the ground system enabled MAVEN to successfully meet NASA´s requirements for IT security, and therefore meet Federal Information Security Management Act (FISMA) mandate on the Agency. Throughout the implementation of GRC on MAVEN during the early stages of the mission development, the Project faced many challenges some of which have been identified in this paper. The purpose of this paper is to document these challenges, and provide a brief analysis of the lessons MAVEN learned. The historical information documented herein, derived from an internal pre-launch lessons learned analysis, can be used by current and future missions and organizations implementing and auditing GRC.
Keywords
risk management; satellite ground stations; security of data; FISMA; Federal Information Security Management Act; GRC; IT security goals; MAVEN information security; NASA Goddard Space Flight Center; NIST risk management framework; National Institute of Standards and Technology; RMF; cost reduction; governance risk management and compliance; ground system security; mars atmosphere and volatile evolution; multiorganizational environment; risk reduction; Information security; NASA; NIST; Risk management; FISMA; GRC; IT security; compliance; cyber security; governance; information security; information security management; regulations; risk; risk management;
fLanguage
English
Publisher
ieee
Conference_Titel
Aerospace Conference, 2014 IEEE
Conference_Location
Big Sky, MT
Print_ISBN
978-1-4799-5582-4
Type
conf
DOI
10.1109/AERO.2014.6836516
Filename
6836516
Link To Document