SlideShare a Scribd company logo
1 of 15
2012 nCircle Federal Security and
                                                Compliance Trends Survey

                                                      Preliminary Results
                                             DGI Cyber Conference – May 31, 2012
                                       Keren Cummins, Director of Federal Markets, nCircle

© 2012 nCircle. All rights reserved.
Respondent Profile To Date
                What part of the US                                           Are you an employee or a
              Government do you work                                                contractor?
                       for?
                       Intelligen
                        ce, 5.7%



                           Military, 1
                             4.3%
                                                                                                        Employee,
                                                                                                          47.1%
                                                                                           Contractor
                                                                                            , 52.9%
                                              Civilian, 8
                                                0.0%




2   © 2012 nCircle. All rights reserved.                    nCircle Company Confidential
© 2012 nCircle. All rights reserved.
© 2012 nCircle. All rights reserved.
© 2012 nCircle. All rights reserved.
© 2012 nCircle. All rights reserved.
© 2012 nCircle. All rights reserved.
© 2012 nCircle. All rights reserved.
© 2012 nCircle. All rights reserved.
© 2012 nCircle. All rights reserved.
© 2012 nCircle. All rights reserved.
© 2012 nCircle. All rights reserved.
© 2012 nCircle. All rights reserved.
© 2012 nCircle. All rights reserved.
© 2012 nCircle. All rights reserved.

More Related Content

Similar to 2012 nCircle Federal Security and Compliance Trends Survey

Why Your 5-Year-Old is More Digital Than Most CMOs - Sean Miller, R/GA and J...
Why Your 5-Year-Old is More Digital Than Most CMOs -  Sean Miller, R/GA and J...Why Your 5-Year-Old is More Digital Than Most CMOs -  Sean Miller, R/GA and J...
Why Your 5-Year-Old is More Digital Than Most CMOs - Sean Miller, R/GA and J...R/GA
 
X-as-a-Service: Impact on the Global Sourcing Market
X-as-a-Service: Impact on the Global Sourcing MarketX-as-a-Service: Impact on the Global Sourcing Market
X-as-a-Service: Impact on the Global Sourcing MarketStanton Jones
 
Intelligence Report (AU) - February 2013
Intelligence Report (AU) - February 2013Intelligence Report (AU) - February 2013
Intelligence Report (AU) - February 2013Computershare
 
Mon1545 powerof cloud-dougclark-ibm
Mon1545 powerof cloud-dougclark-ibmMon1545 powerof cloud-dougclark-ibm
Mon1545 powerof cloud-dougclark-ibmeurocloud
 
Transform your Insurance Processes with BPM and Decision Management
Transform your Insurance Processes with BPM and Decision ManagementTransform your Insurance Processes with BPM and Decision Management
Transform your Insurance Processes with BPM and Decision ManagementIBM WebSphereIndia
 
Energy Risk Magazines ETRM Software Rankings 2013
Energy Risk Magazines ETRM Software Rankings 2013Energy Risk Magazines ETRM Software Rankings 2013
Energy Risk Magazines ETRM Software Rankings 2013Allegro Development
 
Future of the it department 17 may 2012 mt
Future of the it department 17 may 2012 mtFuture of the it department 17 may 2012 mt
Future of the it department 17 may 2012 mtIBM
 
MassTLC marketing analytics summit, Constant Contact
MassTLC marketing analytics summit, Constant ContactMassTLC marketing analytics summit, Constant Contact
MassTLC marketing analytics summit, Constant ContactMassTLC
 
How Agile is Your Business? New Research on Agility Trends
How Agile is Your Business? New Research on Agility TrendsHow Agile is Your Business? New Research on Agility Trends
How Agile is Your Business? New Research on Agility TrendsSteelwedge
 
KLAS Performance Insight Overview
KLAS Performance Insight OverviewKLAS Performance Insight Overview
KLAS Performance Insight OverviewChase Titensor
 
SolarWinds UK and Germany SME Survey Results - Time and Budget
SolarWinds UK and Germany SME Survey Results - Time and BudgetSolarWinds UK and Germany SME Survey Results - Time and Budget
SolarWinds UK and Germany SME Survey Results - Time and BudgetSolarWinds
 
Oracle Advance Controls
Oracle Advance ControlsOracle Advance Controls
Oracle Advance ControlsZeeshan Khan
 
Webinar Deck: Market Vista - Key Market Development in Q3 2012
Webinar Deck: Market Vista - Key Market Development in Q3 2012Webinar Deck: Market Vista - Key Market Development in Q3 2012
Webinar Deck: Market Vista - Key Market Development in Q3 2012Everest Group
 
Delivering the PCC Vision
Delivering the  PCC VisionDelivering the  PCC Vision
Delivering the PCC Visionpam_alliantist
 
Keefe, Bruyette & Woods, Inc. Large Cap Bank Conference
	Keefe, Bruyette & Woods, Inc. Large Cap Bank Conference	Keefe, Bruyette & Woods, Inc. Large Cap Bank Conference
Keefe, Bruyette & Woods, Inc. Large Cap Bank ConferenceQuarterlyEarningsReports3
 
LRN ethics and compliance survey preliminary findings
LRN ethics and compliance survey preliminary findingsLRN ethics and compliance survey preliminary findings
LRN ethics and compliance survey preliminary findingsMark Harrison
 

Similar to 2012 nCircle Federal Security and Compliance Trends Survey (18)

Why Your 5-Year-Old is More Digital Than Most CMOs - Sean Miller, R/GA and J...
Why Your 5-Year-Old is More Digital Than Most CMOs -  Sean Miller, R/GA and J...Why Your 5-Year-Old is More Digital Than Most CMOs -  Sean Miller, R/GA and J...
Why Your 5-Year-Old is More Digital Than Most CMOs - Sean Miller, R/GA and J...
 
X-as-a-Service: Impact on the Global Sourcing Market
X-as-a-Service: Impact on the Global Sourcing MarketX-as-a-Service: Impact on the Global Sourcing Market
X-as-a-Service: Impact on the Global Sourcing Market
 
Intelligence Report (AU) - February 2013
Intelligence Report (AU) - February 2013Intelligence Report (AU) - February 2013
Intelligence Report (AU) - February 2013
 
Mon1545 powerof cloud-dougclark-ibm
Mon1545 powerof cloud-dougclark-ibmMon1545 powerof cloud-dougclark-ibm
Mon1545 powerof cloud-dougclark-ibm
 
Transform your Insurance Processes with BPM and Decision Management
Transform your Insurance Processes with BPM and Decision ManagementTransform your Insurance Processes with BPM and Decision Management
Transform your Insurance Processes with BPM and Decision Management
 
Energy Risk Magazines ETRM Software Rankings 2013
Energy Risk Magazines ETRM Software Rankings 2013Energy Risk Magazines ETRM Software Rankings 2013
Energy Risk Magazines ETRM Software Rankings 2013
 
Future of the it department 17 may 2012 mt
Future of the it department 17 may 2012 mtFuture of the it department 17 may 2012 mt
Future of the it department 17 may 2012 mt
 
MassTLC marketing analytics summit, Constant Contact
MassTLC marketing analytics summit, Constant ContactMassTLC marketing analytics summit, Constant Contact
MassTLC marketing analytics summit, Constant Contact
 
How Agile is Your Business? New Research on Agility Trends
How Agile is Your Business? New Research on Agility TrendsHow Agile is Your Business? New Research on Agility Trends
How Agile is Your Business? New Research on Agility Trends
 
US Market Study
US Market StudyUS Market Study
US Market Study
 
Agility in S&OP
Agility in S&OPAgility in S&OP
Agility in S&OP
 
KLAS Performance Insight Overview
KLAS Performance Insight OverviewKLAS Performance Insight Overview
KLAS Performance Insight Overview
 
SolarWinds UK and Germany SME Survey Results - Time and Budget
SolarWinds UK and Germany SME Survey Results - Time and BudgetSolarWinds UK and Germany SME Survey Results - Time and Budget
SolarWinds UK and Germany SME Survey Results - Time and Budget
 
Oracle Advance Controls
Oracle Advance ControlsOracle Advance Controls
Oracle Advance Controls
 
Webinar Deck: Market Vista - Key Market Development in Q3 2012
Webinar Deck: Market Vista - Key Market Development in Q3 2012Webinar Deck: Market Vista - Key Market Development in Q3 2012
Webinar Deck: Market Vista - Key Market Development in Q3 2012
 
Delivering the PCC Vision
Delivering the  PCC VisionDelivering the  PCC Vision
Delivering the PCC Vision
 
Keefe, Bruyette & Woods, Inc. Large Cap Bank Conference
	Keefe, Bruyette & Woods, Inc. Large Cap Bank Conference	Keefe, Bruyette & Woods, Inc. Large Cap Bank Conference
Keefe, Bruyette & Woods, Inc. Large Cap Bank Conference
 
LRN ethics and compliance survey preliminary findings
LRN ethics and compliance survey preliminary findingsLRN ethics and compliance survey preliminary findings
LRN ethics and compliance survey preliminary findings
 

Recently uploaded

Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfpollardmorgan
 
Market Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 EditionMarket Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 EditionMintel Group
 
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607dollysharma2066
 
8447779800, Low rate Call girls in Rohini Delhi NCR
8447779800, Low rate Call girls in Rohini Delhi NCR8447779800, Low rate Call girls in Rohini Delhi NCR
8447779800, Low rate Call girls in Rohini Delhi NCRashishs7044
 
Innovation Conference 5th March 2024.pdf
Innovation Conference 5th March 2024.pdfInnovation Conference 5th March 2024.pdf
Innovation Conference 5th March 2024.pdfrichard876048
 
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCRashishs7044
 
Digital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdfDigital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdfJos Voskuil
 
Call Us 📲8800102216📞 Call Girls In DLF City Gurgaon
Call Us 📲8800102216📞 Call Girls In DLF City GurgaonCall Us 📲8800102216📞 Call Girls In DLF City Gurgaon
Call Us 📲8800102216📞 Call Girls In DLF City Gurgaoncallgirls2057
 
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCRashishs7044
 
Case study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailCase study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailAriel592675
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckHajeJanKamps
 
Global Scenario On Sustainable and Resilient Coconut Industry by Dr. Jelfina...
Global Scenario On Sustainable  and Resilient Coconut Industry by Dr. Jelfina...Global Scenario On Sustainable  and Resilient Coconut Industry by Dr. Jelfina...
Global Scenario On Sustainable and Resilient Coconut Industry by Dr. Jelfina...ictsugar
 
Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.Anamaria Contreras
 
Annual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesAnnual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesKeppelCorporation
 
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdfKhaled Al Awadi
 
International Business Environments and Operations 16th Global Edition test b...
International Business Environments and Operations 16th Global Edition test b...International Business Environments and Operations 16th Global Edition test b...
International Business Environments and Operations 16th Global Edition test b...ssuserf63bd7
 
2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis UsageNeil Kimberley
 

Recently uploaded (20)

Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
 
Market Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 EditionMarket Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 Edition
 
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
 
Corporate Profile 47Billion Information Technology
Corporate Profile 47Billion Information TechnologyCorporate Profile 47Billion Information Technology
Corporate Profile 47Billion Information Technology
 
No-1 Call Girls In Goa 93193 VIP 73153 Escort service In North Goa Panaji, Ca...
No-1 Call Girls In Goa 93193 VIP 73153 Escort service In North Goa Panaji, Ca...No-1 Call Girls In Goa 93193 VIP 73153 Escort service In North Goa Panaji, Ca...
No-1 Call Girls In Goa 93193 VIP 73153 Escort service In North Goa Panaji, Ca...
 
Call Us ➥9319373153▻Call Girls In North Goa
Call Us ➥9319373153▻Call Girls In North GoaCall Us ➥9319373153▻Call Girls In North Goa
Call Us ➥9319373153▻Call Girls In North Goa
 
8447779800, Low rate Call girls in Rohini Delhi NCR
8447779800, Low rate Call girls in Rohini Delhi NCR8447779800, Low rate Call girls in Rohini Delhi NCR
8447779800, Low rate Call girls in Rohini Delhi NCR
 
Innovation Conference 5th March 2024.pdf
Innovation Conference 5th March 2024.pdfInnovation Conference 5th March 2024.pdf
Innovation Conference 5th March 2024.pdf
 
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
 
Digital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdfDigital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdf
 
Call Us 📲8800102216📞 Call Girls In DLF City Gurgaon
Call Us 📲8800102216📞 Call Girls In DLF City GurgaonCall Us 📲8800102216📞 Call Girls In DLF City Gurgaon
Call Us 📲8800102216📞 Call Girls In DLF City Gurgaon
 
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
 
Case study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailCase study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detail
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
 
Global Scenario On Sustainable and Resilient Coconut Industry by Dr. Jelfina...
Global Scenario On Sustainable  and Resilient Coconut Industry by Dr. Jelfina...Global Scenario On Sustainable  and Resilient Coconut Industry by Dr. Jelfina...
Global Scenario On Sustainable and Resilient Coconut Industry by Dr. Jelfina...
 
Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.
 
Annual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesAnnual General Meeting Presentation Slides
Annual General Meeting Presentation Slides
 
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
 
International Business Environments and Operations 16th Global Edition test b...
International Business Environments and Operations 16th Global Edition test b...International Business Environments and Operations 16th Global Edition test b...
International Business Environments and Operations 16th Global Edition test b...
 
2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage
 

2012 nCircle Federal Security and Compliance Trends Survey

Editor's Notes

  1. Good morning and thank you for being here today. My name is Keren Cummins and I am the Director of Federal Markets for nCircle. For those of you who do not know us, nCircle provides information risk and security performance management solutions to both public and private sector enterprise organizations and currently supports over 20 US federal agencies. I am here today to share with you the preliminary results of our annual Security and Compliance Trends Survey and to encourage you to complete the survey you received at the registration table this morning. It should take you just a few minutes and for those interested in being considered for a free iPad 2 drawing, you can submit the completed survey at the nCircle table.
  2. So what is the nCircle Security and Compliance Trends Survey? Each year, the nCircle Security Trends Survey provides insight intothe challenges and concerns of information security professionals through a comprehensive study. This year for the first time, the survey dives into the unique cyber security hurdles and issues faced by the U.S. federal government. The survey is being conducted from April 28 through June 4, and we will be announcing the full results mid-June. In the meantime, in talking with the DGI team, I thought it would be interesting to share just a few of the preliminary results since the data we have received thus far is very timely and relevant to the topics being addressed here at the conference throughout the day. Then, I am going to step aside and turn the floor over to my respected colleague and nCircle CTO, Tim Keanini – TK.So who has responded to the survey thus far? Over 70 participants from the US federal government have completed the survey with the greatest percentage (80%) from civilian agencies.The respondents to date are almost an equal mix of contractors vs. government employees (+/-6%),
  3. With representation spanning the very small to very large agencies. All identify themselves in large part as “security” professionals with almost 20% holding a Senior Management position.
  4. When asked their biggest concern for 2012, meeting compliance requirements leads out with almost 32% identifying it as their top concern. Next in the lead is mobile devices and cloud.
  5. While cloud migration appears to be moving at a slow pace, with the vast majority of agency respondents indicating that one-third or less of their infrastructure has been migrated to the cloud,over 30% of those who are using cloud are already migrating moderate impact data, speaking to a growing level of confidence in both the technology and policies that can enable higher risk use of the cloud.
  6. This is an interesting snapshot of FedRAMP’s progress….Only a very small percentage of respondents acknowledge a role for FedRAMP’s baseline security controls in advancing their migration to the cloud. Perhaps security is not an issue for the remainder, but it seems more likely that FedRAMP still has some work to do to communicate the benefits of their security guidance. Thus far it does not appear to be resonating and/or building confidence among agency heads, enough to significantly advance their move to the cloud.
  7. Mobile security is a topic of increasing concern, and on a more encouraging note, it appears that a significant majority of agencies do indeed have a mobile device security policy in place, and that they enforce it.Concerns about various types of mobile devices span the gamut, although Android and iPhone represent the greatest concerns.
  8. However, when asked about their plans for monitoring such devices, almost twice as many folks do not have a strategy for monitoring the variety of mobile devices being introduced into the government space, as those who do.
  9. REMOVE?Yeah, not sure what to say about this one
  10. Moving into the area of Oversight and Legislation, we are seeing limited confidence coming from inside government that the current proposed cyber legislation offers much improvement for the private sector’s security posture.
  11. With respect to agency compliance,when asked specifically if CyberScope is helping to ease the burden of FISMA on government agencies, an overwhelming majority said “no”.
  12. Perhaps the benefit of CyberScope is simply yet-to-be-realized given the fact that at least a third of agencies report not having yet participated in a CyberStat Review session. Clearly, however, if CyberScope is going to make significant progress in achieving its goal to reduce network risk, agencies are going to need to walk away from the reporting process with a clear path for improvement.
  13. Moving more deeply into the continuous monitoring aspect of security, there are no surprises here – limited budgets are the greatest challenge for the implementation of continuous monitoring programs. A recent CBO report estimated that agency implementations of continuous monitoring would cost 2% of the overall cost of FISMA – or $710M over 5 years. The question I’d like to have asked survey respondents is, “Is that high or is that low?”For those agencies that are aggressively implementing continuous monitoring and risk scoring (CMRS) as a foundation for ongoing risk reduction, 2% seems rather low,given that the full value of a risk scoring program requires changes in business process and workflow,changes that support effective, prioritized response to identified risks. This certainly doestake both time and money. In my opinion, ultimately, For those organizations that are committed to using the program for risk identification, prioritization and remediation, Continuous monitoring will represent a considerably larger percentage of their overall FISMA costs – but I also believe it will help drive their overall FISMA costs down. But, I didn’t get to ask that question…
  14. I actually talk about the value of continuous monitoring and the associated metrics at great length in the nCircle Federal Outlook blog. While I can’t run a survey there I would encourage you to take a look at my recent posts on effective measuring. Would love to get comments. My premise is, ‘When you measure the measurement, and not the result -- sometimes you just get the act of measurement – and no results.’  I think this chart supports that theory.  Despite the fact that the stated purpose of continuous monitoring is to manage and reduce risk, only a quarter of respondents have found continuous monitoring, as currently implemented and measured in their agencies, to have had a favorable impact on risk. 
  15. Finally, over the last year the threat environment has changed dramatically. While the term “hacktivism” has been around since 1996, most of the public probably heard it for the first time in the last 12-18 months. Today the threat environment includes three distinct categories of attackers, and our community perceives that all three types of attackers are targeting federal agencies and their data. Based on our preliminary survey results, advanced persistent threats (APT) poses a greater risk in public vs. private sectors. So why is that?I’m going to ask my colleague Tim Keanini, universally known as TK, to answer that question. In his presentation, TK will discuss the differences in motivation and intent for each of the three different types of attackers and discuss how federal security teams can use OODA loop principles to create and refine practical cyber security defenses for all three threat categories.Without further ado, TK….