Sorry, you need to enable JavaScript to visit this website.
Home > Who We Serve > Improving Visibility and Performance of Critical Cybersecurity Program Through Automated Reporting
Improving Visibility and Performance of Critical Cybersecurity Program Through Automated Reporting

Improving Visibility and Performance of Critical Cybersecurity Program Through Automated Reporting

CLIENT STORY

The Cryptographic Module Validation Program (CMVP) is a joint effort between the United States and Canada. In the United States, a large federal agency responsible for commerce oversees the program through a component agency that advances measurement science, standards, and technology. The goal of the CMVP is twofold: (1) promote the use of validated cryptographic modules and (2) provide federal agencies with a security metric to use in procuring equipment containing validated cryptographic modules.

PROBLEM

Cryptographic and Security Testing Laboratories (CSTLs), which are independent laboratories located worldwide, perform the validation testing of cryptographic modules. Currently, almost 600 laboratories, located in the United States, Canada, Mexico, and many other nations, hold the necessary National Voluntary Laboratory Accreditation Program (NVLAP) certification needed to participate in the program. Verification testing involves ensuring modules meet a set of testable cryptographic and security requirements, including Federal Information Processing Standards (FIPS) 140-1 and 140-2.

Each CSTL submission must be reviewed and validated by CMVP. While all CMVP submission data was available within an application that users and managers could manually query, no summary status and metric information was readily available to them.

SOLUTION

Electrosoft, recognizing the need for timely and accurate program information, undertook the task of automating and modernizing the process on behalf of the U.S. agency. In so doing, leaders and module Points of Contact (PoCs) could readily view desired metrics and status information at a glance without manually querying the application.

Electrosoft created a set of individualized daily reports for each PoC and used the Report Builder subscription service to email reports to each PoC. In this way, PoCs had a daily snapshot of overall submission metrics, their assigned modules, and the current workflow status of each item. The leadership team received an analogous report containing composite information for all PoCs as well as weekly summary reports. In addition, Electrosoft developed and customized a daily report for the CMVP program manager to facilitate tracking and managing the CMVP submission workload.

RESULTS/BENEFITS

Implementing daily and weekly automated status updates for the CMVP program has significantly improved program visibility for users, program managers, PoCs, and other leaders. This proactive transparency has reduced the risk of issues and bottlenecks remaining undetected, enabling faster issue resolution and keeping the program on track. Furthermore, these automated updates have freed up valuable time for PoCs and leaders, eliminating the need for individual status inquiries and allowing them to focus on critical program activities.

Top