Letter: What does FISMA scorecard actually assess?

A reader questions the reason for having the Federal Information Security Management Act scorecard if doesn't assess what its supposed to.

Regarding "Justice IG finds IT security vulnerabilities"

If the Federal Information Security Management Act scorecard doesn't assess actual security of the information technology environment, then what does it really assess?

There should be a recommendation to the Office of Management and Budget and the National Institute of Standards and Technology to align the FISMA scorecard with true measures of information technology security.

Anonymous

What do you think? Paste a comment in the box below (registration required), or send your comment to letters@fcw.com (subject line: Blog comment) and we'll post it.