NASA appoints new information security chief
- 15 January, 2011 04:50
- Comments 1
NASA this week appointed Valarie Burks as its deputy CIO for Information Technology Security.
Burks replaces Jerry Davis, who left NASA last July to take over as the security chief at the Department of Veterans Affairs. NASA describes Burks as experienced in IT infrastructure development and management.
Burks was previously the associate CIO for cyber and privacy policy and oversight at the U.S. Department of Agriculture and was responsible for managing the department's governance, risk, crisis management and compliance functions. Burks is credited with developing and implementing a center of excellence for information security at the USDA.
Burks previously handled IT management functions at the White House Office of Management and Budget, Department of Commerce and the Government Accountability Office.
Burks' appointment to her new role is likely to be closely watched by security analysts.
Davis is credited with creating at NASA an operations-oriented information security, rather than one that focuses purely on maintaining compliance with the Federal Information Security Act (FISMA) standard.
Alan Paller, director of research at the SANS Institute, an organization that provides security training and certification services for many government organizations, said that NASA CIO Linda Cureton's is looking to Burks to continue that strategy.
"Cureton is just the second (federal CIO) to move an operations person who is also a good leader, into the top role," in information security, Paller said. The only other federal CIO to adopt such an approach is Roger Baker at the VA, he added.
"[Some] federal CIOs have awakened to the fact that their CISOs are compliance rather than operations people," Paller said. "They were getting reports instead of secure systems."
Some federal CISOs have proved somewhat inept at managing and improving security because of their focus on compliance management, he said. "All they [can] do is wave FISMA around and say 'you have to do this or that,'" Paller said.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- Setting a strategy for secure mobile printing
- HP Imaging and Printing Services
- Pathways Advanced ICT Leadership Development Program Brochure and Course Outline 2012
- Six tips for choosing a unified threat management (UTM) solution
- CommVault Extends its Data Protection and Information Management Strategy with Simpana 9
-
NBN build gaining momentum daily: Quigley
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Monday Grok: Will Siri crack the walls of GOOG?
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Closing the print security gap - The market landscape for print security
Today, many organisations continue to rely on printing to support business processes, particularly in the public sector, finance industry and legal profession. Whilst MFPs and printers have improved business productivity, they pose the same security risk as any networked device if left unprotected. With reported data breaches on the rise and growing industry and regulatory requirements around information security, businesses may suffer financial and reputational damage if they ignore the risks of unsecured printing. Read more. -
Five Things You Need to Know About Your Users Before You Deploy Business Intelligence
In our years of experience working with companies of all types and sizes to design and deploy business intelligence systems, we’ve learned that there are five key things you need to know about your users before you roll out related technologies to them. In this paper, we will discuss these five things, as well as their implications. -
Seven SOA Practices to Unlock Business Value
The fact is that companies are increasingly using SOA to gain competitive business advantage. Distilled down to seven essential SOA practices, the following list enables IT professionals to tightly align SOA investments with their organization’s business priorities. Using these practices can help with driving competitive advantage and adding measurable business value...and that’s a sure way for IT pros to win recognition and ongoing support within their companies.
-
The Essential Guide to User Interface Design, Third Edition
-
Teach Yourself Visually Macromedia Dreamweaver 8
-
Java Programming
-
Information Technology for Management
-
ASP.NET Professional Secrets
-
Photoshop Cs4 for Nature Photographers
-
Effective Project Management
-
Yahoo! Sitebuilder for Dummies
-
Software Test Automation From Components to Systems








Comments
Jugs
Compliance based management is bare bones - the OMB, Dept. of Commerce and GAO rarely follow their own advice. FISMA standards are based on original governmental needs as the need for security increases the standards must be improved. As someone who worked in Project Control and Oversight once said "If it's not a controled project than it's an oversight."
Post new comment