Infosec Guru Ron Ross on NIST's Revolutionary Guidance

Published: Feb. 25, 2010, 1:58 p.m.

b'NIST senior computer scientist Ron Ross heads a National Institute of Standards and Technology-Defense Department team that created the just-released information security guidance for federal agencies: Special Publication 800-37, Revision 1, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach. \\n\\n

In an interview with GovInfoSecurity.com, Ross discusses the:\\n\\n

Importance of the new guidance that provides for real-time monitoring of IT systems.
\\n
Challenges federal agencies face in adopting NIST IT security guidance.
\\n
State of cybersecurity in the federal government.
\\n\\n

Ross was interviewed by GovInfoSecurity.com\'s Eric Chabrow.\\n\\n

The highly regarded NIST senior computer scientist and information security researcher serves as the institute\'s FISMA implementation project leader. He also supports the State Department in the international outreach program for information security and critical infrastructure protection. Ross previously served as the director of the National Information Assurance Partnership, a joint activity of NIST and the National Security Agency. \\n\\n

A graduate of the United States Military Academy at West Point, Ross served in a variety of leadership and technical positions during his 20-year career in the Army. While assigned to the National Security Agency, he received the Scientific Achievement Award for his work on an interagency national security project and was awarded the Defense Superior Service Medal upon his departure from the agency. He\'s a two-time recipient of the Federal 100 award for his leadership and technical contributions to critical information security projects affecting the federal government. During his military career, Ross served as a White House aide and as a senior technical advisor to the Department of the Army. \\n\\n

Ross is a graduate of the Program Management School at the Defense Systems Management College and holds a master and Ph.D. in computer science from the United States Naval Postgraduate School.'