How to Get CDM Right – Gov Leaders Offer Valuable Insights

As agencies get ready to roll out the DHS’ Continuous Diagnostics and Mitigation (CDM) Program, feedback from early implementations got audiences excited and reassured at the 2015 Symantec Government Symposium in Washington, D.C.

During a panel session, CDM and Risk Management, government and industry leaders weighed in on the challenges, successes and what’s next on the road to full CDM implementation and long-term risk management security. You can listen to their insights here (Session E-2), but by way of a recap, below are a few highlights:

“Continuous” is at the Heart of CDM

The concept of “Continuously” is less about continually gathering data, but about continuously assessing risk said Tony Sager, Chief Technologist at the Center for Internet Security.

The days when we thought we could get security perfect upfront have long disappeared.” As new threats continue to emerge, risk postures change.

So what is worth doing upfront? It’s worth putting in place the machinery to manage change and that’s one of the conceptual underpinnings of the program.”

Department of Energy Leads the CDM Adoption Charge

One early adopter of this new paradigm and the “machinery” that enables it is the Department of Energy.

During the session, the DOE’s Chief Information Security Officer, Rod Turk, shared his insights on successes so far and what challenges the agency has faced.

One of the biggest challenges for the DOE was the integration of the risk process with the program. “You need to have a good sense of what your risk management program is and how your individual controls play into that process,” said Turk.

Despite these challenges, DOE is already reaping the rewards CDM’s “singularity of tools” affords. The ability to obtain a real-time view of networks, vulnerabilities and breaches and roll that information up to an enterprise level so that the Department has a better understanding of what’s going on has been a significant benefit.

Learn More

To learn more about how CDM is working, upcoming changes to reporting requirements, and more listen to the on-demand podcast.

Watch-Webinar-CTA