<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: fisma]]></title>
    <link>http://securityratty.com/tag/fisma</link>
    <description></description>
    <pubDate>Tue, 17 Jun 2008 11:04:44 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[A Few More Words on DLP and Compliance]]></title>
      <link>http://securityratty.com/article/16543edb37f97e4484ed9be5f504d9c6</link>
      <guid>http://securityratty.com/article/16543edb37f97e4484ed9be5f504d9c6</guid>
      <description><![CDATA[Today I was thinking about DLP again :-) (yes, I know that &quot;content monitoring and protection&quot; - CMF - is a better description) Specifically, I was thinking about DLP and compliance. At first, it was...]]></description>
      <content:encoded><![CDATA[<p>Today I was thinking about DLP again :-) (yes, I know that &quot;content monitoring and protection&quot; - <a href="http://securosis.com">CMF</a> - is a better description) Specifically, I was thinking about DLP and compliance. At first, it was truly amazing to me that DLP vendors &quot;under-utilize&quot; compliance in their messaging. In other words, they don't push the &quot;C-word&quot; as strongly as many other security companies. Compliance dog doesn't snarl at you from their front pages and it doesn't bite you in you ass when you read the whitepapers, etc. Sure, it is mentioned there, but, seemingly, as an after-thought.</p>  <p>For example, Reconnex that was recently absorbed by McAfee, touts &quot;information protection&quot; before compliance. Similarly, my friends from <a href="http://www.nextiernetworks.com">nexTier</a> only mention &quot;compliance&quot; on <a href="http://www.nextiernetworks.com/solutions.html">a few pages</a>. Even newly unveiled DLP resource&#160; (<a href="http://www.dlpindepth.org/">DLP In-Depth portal</a>) only contains a little bit&#160; of information on how DLP solutions help with various compliance projects. People tout &quot;data protection&quot;, &quot; data security&quot;, &quot;data governance&quot; (aka &quot;we know big words - bigger than you&quot;) or even &quot;data risk management&quot; (aka &quot;we are confused about what we sell&quot;)</p>  <p>I decide to explore this curious phenomenon. </p>  <p>Initially, I thought that it was <a href="http://chuvakin.blogspot.com/2008/05/reverse-compliance-or-as-proof-of.html">reverse compliance</a> at work? People not wanting to know what content packs up and leaves their network. Then I thought that maybe DLP vendors just aren't &quot;the bandwagon jumping kind&quot; (yeah, right!) Then I thought that they are &quot;beyond compliance&quot; already :-)</p>  <p>But you know what? I actually think that it is something different, much more sinister. It is the ominous <a href="http://chuvakin.blogspot.com/2008/04/rsa-impressions-2-compliance.html">checklist mentality</a> (<a href="http://chuvakin.blogspot.com/2007/02/so-is-security-art.html">here</a> too)!&#160; You know, DLP is newer than&#160; most regulations (PCI DSS, HIPAA, FISMA, etc) and - what a shock! - the documentation for these mandates just doesn't mention DLP (or CMF) by name. Sure, they talk about data protection (e.g. PCI DSS Requirements 3 and 4), but mostly in terms of encryption, access control, <a href="http://www.loglogic.com">logging</a> (of course!).</p>  <p>Also, PCI DSS directly and explicitly says &quot;get a firewall&quot;, &quot;deploy <a href="http://www.loglogic.com">log management</a>&quot;, &quot;get scanned&quot;, &quot;install and update AV&quot; - but where is DLP? Ain't there...</p>  <p>Yes, Virginia, folks who &quot;go by the book&quot; and just &quot;do the minimum&quot; are missing out on the chance to procure DLP while their compliance budgets are still flowing. To me that means that many still don't get the <em>&quot;compliance+&quot; model</em> - <strong>buy for compliance -&gt; use for security, operations, having fun, etc. </strong>Think what <a href="http://www.nextiernetworks.com">a good DLP solution</a>&#160; will do for you in discovering regulated data across the entire organization, blocking those pesky email with SSNs, PHI (hi, HIPAA) and CCs (hi, PCI) as well as solving plenty of other problems ...</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=PKkyjK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=PKkyjK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=xsv29K"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=xsv29K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=cyhlHK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=cyhlHK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/366024281" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 10:51:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dlp">dlp</category>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/dlp in-depth portal">dlp in-depth portal</category>
      <category domain="http://securityratty.com/tag/procure dlp">procure dlp</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data governance">data governance</category>
      <category domain="http://securityratty.com/tag/pci dss requirements">pci dss requirements</category>
      <category domain="http://securityratty.com/tag/mention dlp">mention dlp</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/366024281/few-more-words-on-dlp-and-compliance.html">A Few More Words on DLP and Compliance</source>
    </item>
    <item>
      <title><![CDATA[Even More Logging Questions - Answered]]></title>
      <link>http://securityratty.com/article/42419cabc2c6779620c8b8bb44fe54c9</link>
      <guid>http://securityratty.com/article/42419cabc2c6779620c8b8bb44fe54c9</guid>
      <description><![CDATA[I did this fun webcast on logging for accountability ( here ) and people asked a lot of good questions. Here are some of the answers for them and all my blog readers

Q1: How do you handle variety of...]]></description>
      <content:encoded><![CDATA[<p>I did <a href="http://isc2.brighttalk.com/node/403">this fun webcast</a> on logging for accountability (<a href="http://isc2.brighttalk.com/node/403">here</a>) and people asked a lot of good questions. Here are some of the answers for them and all my blog readers.</p>  <p>&#160;</p>  <p>Q1: How do you handle variety of log sources? There are so many, almost beyond my capability. </p>  <p>A1: Sorry to ponder the meaning of &quot;is&quot; here, but what is meant by &quot;handle&quot;? It is really not that hard to collect logs from a large number of diverse sources (as long as the logs can be delivered via syslog or exist as files and can be collected). Now, there will certainly be challenges&#160; when the volume of logs gets large, but if by &quot;handle&quot; you mean &quot;collect + store&quot;, it is really not that hard, given <a href="http://www.loglogic.com">the right tools.</a> Now, if &quot;handle&quot; means &quot;make sense of what all those logs are trying to tell you,&quot; it is a different story altogether.</p>  <p>&#160;</p>  <p>Q2: You talked about the importance of logging; however for an intermediate or novice admin what are the starting steps .. what are the minimal logs they should start at once?</p>  <p>A2: Answered in <a href="http://chuvakin.blogspot.com/2008/07/log-management-day-1.html">&quot;Log Management - Day 1&quot;</a> If you want a simple list of things to &quot;enable today,&quot;&#160; I cannot really answer it since I know neither your needs, nor your environment. In other words, this is the &quot;what is the meaning of life question?&quot; :-)</p>  <p>&#160;</p>  <p>Q3: What regulations, rules or guidance exist regarding sharing or visibility of logs to users?</p>  <p>A3: PCI DSS says in Requirement 10.5:&#160; &quot;Secure audit trails so they cannot be altered.    <br /><em>10.5.1 Limit viewing of audit trails to those with a job-related need      <br /></em>10.5.2 Protect audit trail files from unauthorized modifications     <br />10.5.3 Promptly back-up audit trail files to a centralized log server or media that is difficult to     <br />alter&quot; </p>  <p>NIST guidance for FISMA also says something similar (for example, look in <a href="http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf">NIST 800-92 doc</a>). Overall, <a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">log protection and security</a> are mentioned in many other regulations as well. </p>  <p>&#160;</p>  <p>Q4: Privileged groups membership monitoring in AD one of the most important from my point of view. However I did not find effective way to monitor/report on changes in those groups. Any recommendations?</p>  <p>A4: This is indeed a tricky one which might take more space to answer than I have here; it might also take you 'beyond logs.' One good source of information is <a href="http://www.ultimatewindowssecurity.com/encyclopedia.aspx">Randy Smith's site</a> and, specifically, his webinar on 'Active Directory &quot;Logging Gap&quot;' (<a href="http://www.ultimatewindowssecurity.com/aaad/">here somewhere</a>) - which covers how to audit things of that sort when then native logging is not sufficient.</p>  <p>&#160;</p>  <p>Q5: How I can learn what exactly I need to log?</p>  <p>A5: OMG, this is a $1,000,000 question :-) Let me answer &quot;how can I learn&quot; part and not the &quot;what exactly I need to log part,&quot;&#160; (also see discussion on &quot;<a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">MUST-DO Logging for PCI?</a>&quot;) as it is actually answerable. To learn what you need to log, first ask &quot;Why?&quot; (and then see <a href="http://chuvakin.blogspot.com/2008/07/log-management-day-1.html">this</a>) - basically establish what you want to accomplish with logs, catalogue your systems, figure how to tweak the logging knobs - and then do it!</p>  <p>&#160;</p>  <p>Q6: How granular should logging be? What is your recommendation for enterprise servers like domain servers and Windows servers?</p>  <p>A6: Again, too long to answer here in details (it will become a subject of a longer blog post later), but some pointers follow: <a href="http://www.ultimatewindowssecurity.com/blog/blog_commento.asp?blog_id=23&amp;month=05&amp;year=2007&amp;giorno=&amp;archivio=OK">here for Windows</a> (MS site also have a few recommendations on audit policies)</p>  <p>&#160; </p>  <p>Q7: What is &quot;more control&quot; and what is &quot;less control&quot; that you <a href="http://isc2.brighttalk.com/node/403">mention in the webcast</a>? Can you give an example?</p>  <p>A7: OK, I did say that &quot;sometimes when you implement more controls, you actually have less control.&quot; What do I mean? If you buy a firewall (a network security control) and then - over time, of course - configure it with 7800 rules (!) that are supposed to give you control over who can and cannot access your network, you will not gain control over your environment. You will actually be less in control of who is touching your network, compared to, say, having only 20 rules.</p>  <p>&#160;</p>  <p>Q8: What about mandated NIST controls for government systems? Auditing is a specific control for Moderate and High risk systems. What list of events do you recommend for auditing?</p>  <p>A8: This is too long to answer here, but <a href="http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf ">NIST 800-92 Guide</a> is a really good source of such info (&quot;<a href="http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf">Guide to Computer Security Log Management [PDF]</a>&quot;) Also, see my presentation on <a href="http://www.slideshare.net/anton_chuvakin/nist-80092-log-management-guide-in-the-real-world/">NIST 800-92 Guide in the Real World</a>.</p>  <p>&#160;</p>  <p>Q9: The issue that many organizations get stuck on, is the monitoring process, and defining what exceptions to monitor for? Is there guidance / framework for this? How much of it is system specific and how much is applicable generally to all systems?</p>  <p>A9: I outlined some general ideas <a href="http://www.slideshare.net/anton_chuvakin/what-every-organization-should-log-and-monitor">back in 2004 via this presentation</a>&#160;<em>(note to self - update that to be more 2008-relevant);</em> it is mostly general, but also has pointers to specific system. Keep in mind that it is focused on security, not operational monitoring (which is often no less important - in fact, often <a href="http://rationalsecurity.typepad.com/blog/2008/02/omg-availabilit.html">MORE important</a>)</p>  <p>&#160;</p>  <p>Enjoy! Sorry for being brief with some of the answers - I am woefully late with this even as they are...</p>  <p><strong>Other questions that I answered in the past:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/05/more-log-management-questions-answered.html">More Log Management Questions - Answered!</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/some-burning-logging-questions-answered.html">Some Burning Logging Questions - Answered!</a> </li> </ul>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=juyDeK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=juyDeK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=o5WeXK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=o5WeXK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=mnNGqK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=mnNGqK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/357664119" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 07:43:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/log server">log server</category>
      <category domain="http://securityratty.com/tag/log">log</category>
      <category domain="http://securityratty.com/tag/log sources">log sources</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/control">control</category>
      <category domain="http://securityratty.com/tag/questions">questions</category>
      <category domain="http://securityratty.com/tag/specific control">specific control</category>
      <category domain="http://securityratty.com/tag/network security control">network security control</category>
      <category domain="http://securityratty.com/tag/log protection">log protection</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/357664119/even-more-logging-questions-answered.html">Even More Logging Questions - Answered</source>
    </item>
    <item>
      <title><![CDATA[Government Sent Home with a C on FISMA Report Card]]></title>
      <link>http://securityratty.com/article/529e18cdf61d27f345cad3dbd55b1041</link>
      <guid>http://securityratty.com/article/529e18cdf61d27f345cad3dbd55b1041</guid>
      <description><![CDATA[Too bad there is no Kaplan Test Prep equivalent for FISMA
For the third year in a row, the governments overall FISMA grade improved. But dont get too excited; the grade only improved from a C- to a C...]]></description>
      <content:encoded><![CDATA[<p>Too bad there is no Kaplan Test Prep equivalent for FISMA.
<p>For the third year in a row, the government’s overall FISMA grade improved. But don’t get too excited; the grade only <a href="http://republicans.oversight.house.gov/media/PDFs/Reports/FY2007FISMAReportCard.pdf" target="_blank">improved from a C- to a C</a> this year. (And D+ in 2005).
<p>But there’s a lot to hide in an “average grade”. Turns out that the reality is a split between <a href="http://www.fcw.com/online/news/152595-1.html">overachievers and underachievers</a>.
<p>The agencies/departments with a grade of A-, A or A+:
<ul>
<li>Department of Justice</li>
<li>US AID</li>
<li>EPA</li>
<li>NSF</li>
<li>SSA</li>
<li>HUD</li>
<li>OPM (I would hope so)</li>
</ul>
<p>And, sadly the ones that got an F:
<ul>
<li>Department of the Interior</li>
<li>Department of Treasury</li>
<li>Nuclear Regulatory Commission</li>
<li>Department of Veterans Affairs</li>
<li>Department of Agriculture</li>
</ul>
<p>FISMA (Federal Information Security Management Act) became a federal law back in 2002 as part of the E-Government Act. Six years later, there has been improvement, but there’s still clearly a long way to go.
<p>So what’s the disconnect? Speaking from a vendor perspective, we’ve had first-hand experience with the lack of actionable, concrete guidelines around FISMA – for processes, monitoring and check-list assessment items. We even contacted NIST directly to get more guidance on how their very broad guidelines should be translated to actual features and reporting in something like our monitoring solution. The end goal, after all, is to help our government customers not only meet the FISMA requirements but also to be seen/assessed as meeting those requirements. As we do for other compliance/governance requirements like Sarbanes-Oxley, the more that EM7 can automate and report on, the better.
<p>But that leads to the second issue here. How accurate is the FISMA scorecard? <a href="http://www.scmagazineus.com/Government-vertical-Is-FISMA-working/article/58396/" target="_blank">SC Magazine</a> writes, “Many have seen organizations get an A when they believe they should have received an F, and vice versa” and some experts “blame this on the lack of a standardized evaluation, as well as censorship among auditors.” There’s talk about language ambiguities and opinions that the scorecard is not “one size fits all” – <a href="http://www.compliancehome.com/news/FISMA/10477.html" target="_blank">that small agencies face different IT security challenges than the big guys</a>.
<p>So what’s right about FISMA? We can point to a heightened awareness about the importance of security and the “security picture” in each federal agency. Certainly, from our own <a href="http://www.sciencelogic.com/pdf/FOSE_SurveyComparison.pdf" target="_blank">survey at FOSE</a>, we saw the difference just from last year to this one:
<ul>
<li>91% surveyed said FISMA was important (up from 66% last year)</li>
<li>Over 50% had solutions installed to help with FISMA (up from only 14% last year)</li>
</ul>
<p>Based on these numbers, we’re not surprised to see the FISMA average grade go up, but we expected it to be even higher. So what will it take to get the government on the honor roll? From <a href="http://republicans.oversight.house.gov/news/PRArticle.aspx?NewsID=362" target="_blank">Rep. Tom Davis</a>, “We need to seriously consider incentives for agency success and funding penalties and personnel reforms for agencies that don’t measure up…We need a bill with teeth, and we need agencies to understand the goal is to keep information safe, not to check a statutory box.”</p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Government+Sent+Home+with+a+%26ldquo%3BC%26rdquo%3B+on+FISMA+Report+Card&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fgovernment-sent-home-with-a-c-on-fisma-report-card%2F08%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 09:43:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fisma average grade">fisma average grade</category>
      <category domain="http://securityratty.com/tag/average grade">average grade</category>
      <category domain="http://securityratty.com/tag/fisma">fisma</category>
      <category domain="http://securityratty.com/tag/grade">grade</category>
      <category domain="http://securityratty.com/tag/fisma grade">fisma grade</category>
      <category domain="http://securityratty.com/tag/scorecard">scorecard</category>
      <category domain="http://securityratty.com/tag/fisma scorecard">fisma scorecard</category>
      <category domain="http://securityratty.com/tag/fisma requirements">fisma requirements</category>
      <category domain="http://securityratty.com/tag/requirements">requirements</category>
      <source url="http://blog.sciencelogic.com/government-sent-home-with-a-c-on-fisma-report-card/08/2008">Government Sent Home with a C on FISMA Report Card</source>
    </item>
    <item>
      <title><![CDATA[No, FISMA Doesnt Require That, Silly Product Pushers]]></title>
      <link>http://securityratty.com/article/e7338459ca02abf727eaf2b68ac02e51</link>
      <guid>http://securityratty.com/article/e7338459ca02abf727eaf2b68ac02e51</guid>
      <description><![CDATA[Post #9678291 on why people dont understand what FISMA really is : Secure64 DNSSEC Press Releases
FISMA Act encourages U.S. government agencies to configure their DNS servers to the DNSSEC security...]]></description>
      <content:encoded><![CDATA[<p>Post #9678291 on <a href="http://www.guerilla-ciso.com/archives/150" target="_blank">why people don&#8217;t understand what FISMA really is</a>:  <a href="http://www.domaininformer.com/news/press/310708DNSSEC.html" target="_blank">Secure64 DNSSEC Press Releases</a>.</p>
<p style="padding-left: 30px;"><em>&#8220;FISMA Act encourages U.S. government agencies to configure their DNS servers to the DNSSEC security specifications set by the National Institute of Standards and Technology, and it has been reported that the federal government<span id="bwanpa5">’</span>s Office of Management and Budget (OMB) plans to begin enforcing DNSSEC requirements through an auditing process, setting the standard for DNS best practices.&#8221;</em></p>
<p>Yep, if you stamp FISMA on it, people will buy it, maybe in your PR department&#8217;s wettest and wildest dreams.  Guys, it&#8217;s been 6 years, that kind of marketing doesn&#8217;t work nowadays, mostly because we spent ourselves into oblivion buying junkware similar to yours and now we&#8217;re all jaded.</p>
<p>Now don&#8217;t get me wrong, DNSSEC is a good thing, especially this month.  But there is something I need to address:  FISMA requires good security management with a dozen or so key indicators, not a solution down to the technical level.  Allusions to OMB are just FUD, FUD, and more FUD because unless it&#8217;s in a memo to agency heads, it&#8217;s all posturing&#8211;something everybody in this town knows how to do very well.  OMB would rather stay out of mandating DNSSEC and maybe give a &#8220;due date&#8221; once NIST has a final standard.</p>
<p>My one word of wisdom for today:  anybody who tries to sell a product and <a href="http://www.guerilla-ciso.com/archives/216" target="_blank">uses FISMA as the &#8220;compelling event&#8221; has no clue what they&#8217;re talking about</a>.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Del.icio.us" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to digg" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to reddit" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers&amp;url=http://www.guerilla-ciso.com/archives/440&amp;version=0.7" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Feed Me Links" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/440" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Technorati" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/440&amp;t=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Yahoo My Web" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Stumble Upon" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Google Bookmarks" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/440" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Squidoo" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/440" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Bloglines" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=2mnw8J"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=2mnw8J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=HAXdPj"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=HAXdPj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/351599310" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 31 Jul 2008 10:36:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fisma">fisma</category>
      <category domain="http://securityratty.com/tag/fisma requires">fisma requires</category>
      <category domain="http://securityratty.com/tag/fisma act encourages">fisma act encourages</category>
      <category domain="http://securityratty.com/tag/stamp fisma">stamp fisma</category>
      <category domain="http://securityratty.com/tag/dnssec">dnssec</category>
      <category domain="http://securityratty.com/tag/dnssec requirements">dnssec requirements</category>
      <category domain="http://securityratty.com/tag/dns">dns</category>
      <category domain="http://securityratty.com/tag/standard">standard</category>
      <category domain="http://securityratty.com/tag/dns servers">dns servers</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/351599310/440">No, FISMA Doesnt Require That, Silly Product Pushers</source>
    </item>
    <item>
      <title><![CDATA[On Government Employees, Culture, and Survivability]]></title>
      <link>http://securityratty.com/article/5480412299d0a4f28970697b7dbced94</link>
      <guid>http://securityratty.com/article/5480412299d0a4f28970697b7dbced94</guid>
      <description><![CDATA[A couple of months before I was activated and went to Afghanistan, I got a briefing from a Special Forces NCO who had done multiple tours in the desert. One thing he said still sticks in my mind...]]></description>
      <content:encoded><![CDATA[<p>A couple of months before I was activated and went to Afghanistan, I got a briefing from a Special Forces NCO who had done multiple tours in the desert.  One thing he said still sticks in my mind (obviously paraphrased):</p>
<blockquote><p>&#8220;The Afghanis, they live in mud huts, they don&#8217;t have electricity, they are stick-people weighing 85 lbs, and to say that we could bomb them into the stone age would be an advancement in their technology level.  But never underestimate these people, they&#8217;re survivors.  They&#8217;ve survived 35 years of warfare, starting with the Soviets, then they fought a civil war before we arrived on the scene.  Never underestimate their ability to survive, and have respect for them because of who they are.&#8221;</p></blockquote>
<p>Today, I feel the same way about government employees, even more so because it&#8217;s an election year:  they&#8217;re survivors.</p>
<p>Now time for what I see is the &#8220;real&#8221; reason why the government is doing badly (if that&#8217;s what you believe&#8211;opinions differ) at security: it&#8217;s all an issue of culture. I have a friend who converted a year ago to a GS-scale employee and took a class on what motivates government employees. Some of these are obvious:</p>
<ul>
<li>Pride at making a difference</li>
<li>Helping people</li>
<li>Supporting a cause</li>
<li>Gaining unique experience on a global-class scope</li>
<li>Job stability</li>
<li>Retirement benefits</li>
</ul>
<p>And one thing is noticeably absent: better pay and personal recognition.  Hey, sounds like me in the army.</p>
<p style="text-align: center;"><em><img src="http://farm2.static.flickr.com/1348/1470902823_4a5145322e.jpg?v=0" alt="The Companion Family Plan to Survival at Home" width="362" height="500" /></em></p>
<p style="text-align: center;"><em>The Companion Family Plan for Survival at Home photo by <a href="http://www.flickr.com/photos/jikan/" target="_blank">Uh &#8230; Bob</a>.</em></p>
<p>Now I&#8217;m not trying to stereotype, but you need to know the organizational behavior pieces to understand how government security works. And in this case, the typical government employee is about as survival-aware as their Afghani counterpart.</p>
<p>Best advice I ever heard from a public policy wonk: the key to survival in this town is to influence everything you can get your hands on and never have your name actually written on anything.</p>
<p>In other words, don&#8217;t criticize, be nice to everybody even though you think they are a jerk, and avoid saying anything at all because you never know when it will be contrary to the political scene.  The Government culture is a silent culture. That&#8217;s why every day amazing things happen to promote security in the Government and you&#8217;ll never hear about it on the outside.</p>
<p>One of the reasons that I started blogging was to counter the naysayers who say that FISMA is failing and that the Government would succeed if they would just buy their product for technical policy compliance or end-to-end encryption.  Sadly, the true heroes in Government, the people who just do their job every day and try to survive a hostile political environment, are giving credit to the critics because of their silence.</p>
<p>Which brings me to my point:</p>
<p>Yes, my name is Rybolov and I&#8217;m a heretic, but this is the secret to security in the Government:  it&#8217;s cultural at all layers of the personnel stack.  Security (and innovation, now that I think about it) needs a culture of openness where it&#8217;s allowable to make mistakes and/or criticize.  Doesn&#8217;t sound like any government&#8211;local, state, or federal&#8211;that I&#8217;ve ever seen.  However, if you fix the culture, you fix the security.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Del.icio.us" alt="Add 'On Government Employees, Culture, and Survivability' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to digg" alt="Add 'On Government Employees, Culture, and Survivability' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to reddit" alt="Add 'On Government Employees, Culture, and Survivability' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=On+Government+Employees%2C+Culture%2C+and+Survivability&amp;url=http://www.guerilla-ciso.com/archives/298&amp;version=0.7" title="Add 'On Government Employees, Culture, and Survivability' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Feed Me Links" alt="Add 'On Government Employees, Culture, and Survivability' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/298" title="Add 'On Government Employees, Culture, and Survivability' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Technorati" alt="Add 'On Government Employees, Culture, and Survivability' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/298&amp;t=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Yahoo My Web" alt="Add 'On Government Employees, Culture, and Survivability' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Stumble Upon" alt="Add 'On Government Employees, Culture, and Survivability' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Google Bookmarks" alt="Add 'On Government Employees, Culture, and Survivability' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/298" title="Add 'On Government Employees, Culture, and Survivability' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Squidoo" alt="Add 'On Government Employees, Culture, and Survivability' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/298" title="Add 'On Government Employees, Culture, and Survivability' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Bloglines" alt="Add 'On Government Employees, Culture, and Survivability' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=KQw1LJ"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=KQw1LJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=8UDDwj"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=8UDDwj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/341552257" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 09:46:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/government employees">government employees</category>
      <category domain="http://securityratty.com/tag/government security">government security</category>
      <category domain="http://securityratty.com/tag/culture">culture</category>
      <category domain="http://securityratty.com/tag/government culture">government culture</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/typical government employee">typical government employee</category>
      <category domain="http://securityratty.com/tag/promote security">promote security</category>
      <category domain="http://securityratty.com/tag/silent culture">silent culture</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/341552257/298">On Government Employees, Culture, and Survivability</source>
    </item>
    <item>
      <title><![CDATA[FISMA Reporting Guidance for 2008]]></title>
      <link>http://securityratty.com/article/fcf546cc4af6858f0a8c433f0c7dd524</link>
      <guid>http://securityratty.com/article/fcf546cc4af6858f0a8c433f0c7dd524</guid>
      <description><![CDATA[Its out. Check it out in the OMB Memo. Ill most likely have something pithy to say when I look at it a little bit more, but it looks like its mostly the same as last year
Anyway, you can get it here,...]]></description>
      <content:encoded><![CDATA[<p>It&#8217;s out.  Check it out in the OMB Memo.  I&#8217;ll most likely have something pithy to say when I look at it a little bit more, but it looks like it&#8217;s mostly the same as last year.</p>
<p>Anyway, <a href="http://www.whitehouse.gov/omb/memoranda/fy2008/m08-21.pdf" target="_blank">you can get it here, it&#8217;s OMB Memo 08-21</a>.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/437&amp;title=FISMA+Reporting+Guidance+for+2008" title="Add 'FISMA Reporting Guidance for 2008' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'FISMA Reporting Guidance for 2008' to Del.icio.us" alt="Add 'FISMA Reporting Guidance for 2008' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/437&amp;title=FISMA+Reporting+Guidance+for+2008" title="Add 'FISMA Reporting Guidance for 2008' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'FISMA Reporting Guidance for 2008' to digg" alt="Add 'FISMA Reporting Guidance for 2008' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/437&amp;title=FISMA+Reporting+Guidance+for+2008" title="Add 'FISMA Reporting Guidance for 2008' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'FISMA Reporting Guidance for 2008' to reddit" alt="Add 'FISMA Reporting Guidance for 2008' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=FISMA+Reporting+Guidance+for+2008&amp;url=http://www.guerilla-ciso.com/archives/437&amp;version=0.7" title="Add 'FISMA Reporting Guidance for 2008' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'FISMA Reporting Guidance for 2008' to Feed Me Links" alt="Add 'FISMA Reporting Guidance for 2008' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/437" title="Add 'FISMA Reporting Guidance for 2008' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'FISMA Reporting Guidance for 2008' to Technorati" alt="Add 'FISMA Reporting Guidance for 2008' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/437&amp;t=FISMA+Reporting+Guidance+for+2008" title="Add 'FISMA Reporting Guidance for 2008' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'FISMA Reporting Guidance for 2008' to Yahoo My Web" alt="Add 'FISMA Reporting Guidance for 2008' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/437&amp;title=FISMA+Reporting+Guidance+for+2008" title="Add 'FISMA Reporting Guidance for 2008' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'FISMA Reporting Guidance for 2008' to Stumble Upon" alt="Add 'FISMA Reporting Guidance for 2008' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/437&amp;title=FISMA+Reporting+Guidance+for+2008" title="Add 'FISMA Reporting Guidance for 2008' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'FISMA Reporting Guidance for 2008' to Google Bookmarks" alt="Add 'FISMA Reporting Guidance for 2008' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/437" title="Add 'FISMA Reporting Guidance for 2008' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'FISMA Reporting Guidance for 2008' to Squidoo" alt="Add 'FISMA Reporting Guidance for 2008' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/437" title="Add 'FISMA Reporting Guidance for 2008' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'FISMA Reporting Guidance for 2008' to Bloglines" alt="Add 'FISMA Reporting Guidance for 2008' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=vvElhJ"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=vvElhJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=2AYEVj"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=2AYEVj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/339069843" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 11:02:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/omb memo">omb memo</category>
      <category domain="http://securityratty.com/tag/check">check</category>
      <category domain="http://securityratty.com/tag/bookmark">bookmark</category>
      <category domain="http://securityratty.com/tag/bit">bit</category>
      <category domain="http://securityratty.com/tag/pithy">pithy</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/339069843/437">FISMA Reporting Guidance for 2008</source>
    </item>
    <item>
      <title><![CDATA[William Jackson on FISMA: It Works, Maybe]]></title>
      <link>http://securityratty.com/article/23ddad0ab4920cf875a8ac91773447fd</link>
      <guid>http://securityratty.com/article/23ddad0ab4920cf875a8ac91773447fd</guid>
      <description><![CDATA[Article from William Jackson in Government Computer News: Security policies remain a burden to federal IT managers, but they are producing results
First off, GCN, come into the modern Web 2.0 era by...]]></description>
      <content:encoded><![CDATA[<p>Article from William Jackson in Government Computer News:  <a href="http://www.gcn.com/online/vol1_no1/46559-1.html?topic=&amp;CMP=OTC-RSS&amp;page=1" target="_blank">Security policies remain a burden to federal IT managers, but they are producing results</a>.</p>
<p>First off, GCN, come into the modern Web 2.0 era by letting people comment on your articles or at least allow trackbacks.  Having said that, let&#8217;s look at some of Mr Jackson&#8217;s points:</p>
<ul>
<li><strong>NIST Special Publications:</strong> They&#8217;re good.  They&#8217;re free.  The only problem is that they&#8217;re burying us in them.  And oh yeah, <a href="http://csrc.nist.gov/news_events/index.html#june30" target="_blank">SP 800-53A is finally final</a>.</li>
<li><strong>Security and Vendors/Contractors:</strong>  It&#8217;s much harder than you might think.  If there&#8217;s interest, I&#8217;ll put out some presentations on it in my &#8220;copious amounts of free time&#8221;.  In the meantime, check out <a href="http://www.guerilla-ciso.com/archives/category/outsourcing-and-managed-service-providers" target="_blank">what I&#8217;ve said so far about outsourcing</a>.</li>
<li><strong>Documentation and Paperwork:</strong>  Sadly, this is a fact of life for the Government.  The primary problem is the layers of oversight that the system owner and ISSO have.  When you are as heavily audited as the executive branch is, you tend to avoid risks and overdocument.  My personal theory is that the reason is insistence on compliance instead of risk management.</li>
<li><strong>Revising FISMA:</strong>  I&#8217;ve said it time and time again, the law is good and doesn&#8217;t need to be changed, the execution is the part that needs work.</li>
</ul>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/428&amp;title=William+Jackson+on+FISMA%3A+It+Works%2C+Maybe" title="Add 'William Jackson on FISMA: It Works, Maybe' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'William Jackson on FISMA: It Works, Maybe' to Del.icio.us" alt="Add 'William Jackson on FISMA: It Works, Maybe' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/428&amp;title=William+Jackson+on+FISMA%3A+It+Works%2C+Maybe" title="Add 'William Jackson on FISMA: It Works, Maybe' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'William Jackson on FISMA: It Works, Maybe' to digg" alt="Add 'William Jackson on FISMA: It Works, Maybe' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/428&amp;title=William+Jackson+on+FISMA%3A+It+Works%2C+Maybe" title="Add 'William Jackson on FISMA: It Works, Maybe' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'William Jackson on FISMA: It Works, Maybe' to reddit" alt="Add 'William Jackson on FISMA: It Works, Maybe' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=William+Jackson+on+FISMA%3A+It+Works%2C+Maybe&amp;url=http://www.guerilla-ciso.com/archives/428&amp;version=0.7" title="Add 'William Jackson on FISMA: It Works, Maybe' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'William Jackson on FISMA: It Works, Maybe' to Feed Me Links" alt="Add 'William Jackson on FISMA: It Works, Maybe' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/428" title="Add 'William Jackson on FISMA: It Works, Maybe' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'William Jackson on FISMA: It Works, Maybe' to Technorati" alt="Add 'William Jackson on FISMA: It Works, Maybe' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/428&amp;t=William+Jackson+on+FISMA%3A+It+Works%2C+Maybe" title="Add 'William Jackson on FISMA: It Works, Maybe' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'William Jackson on FISMA: It Works, Maybe' to Yahoo My Web" alt="Add 'William Jackson on FISMA: It Works, Maybe' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/428&amp;title=William+Jackson+on+FISMA%3A+It+Works%2C+Maybe" title="Add 'William Jackson on FISMA: It Works, Maybe' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'William Jackson on FISMA: It Works, Maybe' to Stumble Upon" alt="Add 'William Jackson on FISMA: It Works, Maybe' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/428&amp;title=William+Jackson+on+FISMA%3A+It+Works%2C+Maybe" title="Add 'William Jackson on FISMA: It Works, Maybe' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'William Jackson on FISMA: It Works, Maybe' to Google Bookmarks" alt="Add 'William Jackson on FISMA: It Works, Maybe' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/428" title="Add 'William Jackson on FISMA: It Works, Maybe' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'William Jackson on FISMA: It Works, Maybe' to Squidoo" alt="Add 'William Jackson on FISMA: It Works, Maybe' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/428" title="Add 'William Jackson on FISMA: It Works, Maybe' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'William Jackson on FISMA: It Works, Maybe' to Bloglines" alt="Add 'William Jackson on FISMA: It Works, Maybe' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=jf9oiI"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=jf9oiI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=Jk49Ti"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=Jk49Ti" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/323523622" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 30 Jun 2008 17:03:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/free time">free time</category>
      <category domain="http://securityratty.com/tag/free">free</category>
      <category domain="http://securityratty.com/tag/security policies remain">security policies remain</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/william jackson">william jackson</category>
      <category domain="http://securityratty.com/tag/government computer news">government computer news</category>
      <category domain="http://securityratty.com/tag/nist special publications">nist special publications</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/323523622/428">William Jackson on FISMA: It Works, Maybe</source>
    </item>
    <item>
      <title><![CDATA[Needed: Agency CSOs]]></title>
      <link>http://securityratty.com/article/88e84c9df459b2e05803d8591fc27913</link>
      <guid>http://securityratty.com/article/88e84c9df459b2e05803d8591fc27913</guid>
      <description><![CDATA[Check out this article by Andy Boots on the Tech Insiders blog
It brings up an interesting point: Agencies do not typically have a CSO-level manager. According to FISMA, each agency has to have a CISO...]]></description>
      <content:encoded><![CDATA[<p>Check out <a href="http://techinsider.nextgov.com/2008/06/real_security_leaders_ignore_mission_security_at_their_organizations_peril.php" target="_blank">this article by Andy Boots </a>on the Tech Insiders blog.</p>
<p>It brings up an interesting point:  Agencies do not typically have a CSO-level manager.  According to FISMA, each agency has to have a CISO whose primary responsibility is information security.</p>
<p>But typically these CISOs do not have any authority over physical security or personnel security:  in reality, they work for the CIO and only have scope over what the CIO manages:  data centers, networks, servers, desktops, applications, and databases.</p>
<p>Except for one thing:  we&#8217;re giving today&#8217;s Government CISO a catalog of controls that contain physical and personnel security.  The &#8220;party line&#8221; that I&#8217;ve gotten from NIST is that the CISOs need to work through the CIO to effect change with the areas that are out of their control.  I personally think it&#8217;s a bunch of bull and that we&#8217;ve given CISOs all of the responsibility and none of the authority that they need to get the job done.  In my world, I call that a &#8220;scapegoat&#8221;.</p>
<p>To be honest, I think we&#8217;re doing a disservice to our CISOs, but the only way to fix it is to either move our existing CISOs out of the CIOs staff and make them true CxOs or write a law creating an agency CSO position just like Clinger-Cohen created the CIO and FISMA created the CISO.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/423&amp;title=Needed%3A+Agency+CSOs" title="Add 'Needed: Agency CSOs' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'Needed: Agency CSOs' to Del.icio.us" alt="Add 'Needed: Agency CSOs' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/423&amp;title=Needed%3A+Agency+CSOs" title="Add 'Needed: Agency CSOs' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'Needed: Agency CSOs' to digg" alt="Add 'Needed: Agency CSOs' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/423&amp;title=Needed%3A+Agency+CSOs" title="Add 'Needed: Agency CSOs' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'Needed: Agency CSOs' to reddit" alt="Add 'Needed: Agency CSOs' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Needed%3A+Agency+CSOs&amp;url=http://www.guerilla-ciso.com/archives/423&amp;version=0.7" title="Add 'Needed: Agency CSOs' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'Needed: Agency CSOs' to Feed Me Links" alt="Add 'Needed: Agency CSOs' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/423" title="Add 'Needed: Agency CSOs' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'Needed: Agency CSOs' to Technorati" alt="Add 'Needed: Agency CSOs' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/423&amp;t=Needed%3A+Agency+CSOs" title="Add 'Needed: Agency CSOs' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'Needed: Agency CSOs' to Yahoo My Web" alt="Add 'Needed: Agency CSOs' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/423&amp;title=Needed%3A+Agency+CSOs" title="Add 'Needed: Agency CSOs' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'Needed: Agency CSOs' to Stumble Upon" alt="Add 'Needed: Agency CSOs' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/423&amp;title=Needed%3A+Agency+CSOs" title="Add 'Needed: Agency CSOs' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'Needed: Agency CSOs' to Google Bookmarks" alt="Add 'Needed: Agency CSOs' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/423" title="Add 'Needed: Agency CSOs' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'Needed: Agency CSOs' to Squidoo" alt="Add 'Needed: Agency CSOs' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/423" title="Add 'Needed: Agency CSOs' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'Needed: Agency CSOs' to Bloglines" alt="Add 'Needed: Agency CSOs' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=JxUDlI"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=JxUDlI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=QEC3li"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=QEC3li" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/320498593" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 08:49:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/agency">agency</category>
      <category domain="http://securityratty.com/tag/todays government ciso">todays government ciso</category>
      <category domain="http://securityratty.com/tag/cio">cio</category>
      <category domain="http://securityratty.com/tag/ciso">ciso</category>
      <category domain="http://securityratty.com/tag/cio manages">cio manages</category>
      <category domain="http://securityratty.com/tag/cisos">cisos</category>
      <category domain="http://securityratty.com/tag/agency cso position">agency cso position</category>
      <category domain="http://securityratty.com/tag/personnel security">personnel security</category>
      <category domain="http://securityratty.com/tag/responsibility">responsibility</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/320498593/423">Needed: Agency CSOs</source>
    </item>
    <item>
      <title><![CDATA[NISTS FISMA Pase IIWho Certifies Those who Certify the Certifiers?]]></title>
      <link>http://securityratty.com/article/271d22495a76ce6a3ee6919616e42509</link>
      <guid>http://securityratty.com/article/271d22495a76ce6a3ee6919616e42509</guid>
      <description><![CDATA[Check out this slideshow and this workshop paper from 2006 on some ideas that NIST and a fairly large advisory panel have put together about certification of C&amp;A service providers. Ive heard about...]]></description>
      <content:encoded><![CDATA[<p>Check <a href="http://csrc.nist.gov/groups/SMA/fisma/documents/PPT/FISMA-Phase-II.pdf" target="_blank">out this slideshow</a> and this <a href="http://csrc.nist.gov/groups/SMA/fisma/documents/Workshop-April26-2006/NIST-FISMA-PhaseII-Workshop-Notes.pdf" target="_blank">workshop paper </a>from 2006 on some ideas that NIST and a fairly large advisory panel have put together about certification of C&amp;A service providers.  I&#8217;ve heard about this for several years now, and it&#8217;s been fairly much on a hiatus since 2006, but it&#8217;s starting to get some eartime lately.</p>
<p>The interesting thing to me is the big question of certifying companies v/s individuals.  I think the endgame will involve doing both because you certify companies for methodology and you certify people for skills.</p>
<p>This is the problem with certification and accreditation services as I see it today:</p>
<ul>
<li><strong>Security staffing shortage means lower priority:</strong>  If you are an agency CISO and have 2 skilled people, where are you going to put them?  Odds are, architecture, engineering, or some other high-payoff activity, meaning that C&amp;A services are candidates for entry-level security staff.</li>
<li><strong>Centralized v/s project-specific funding:</strong>  Some agencies have a &#8220;stable&#8221; of C&amp;A staff, if it&#8217;s done wrong, you end up with standardization and complete compliance but not real risk management.  The opposite of this is where all the C&amp;A activities are done on a per-project basis and huge repetition of effort ensues.  Basic management technique is to blend the 2 approaches.</li>
<li><strong>Crossover of personnel from &#8220;risk-avoidance&#8221; cultures:</strong>  Taking people from compliance-centric roles such as legal and accounting and putting them into a risk-based culture is a sure recipe for failure, overspending, and frustration.</li>
<li><strong>Accreditation is somewhat broken:</strong>  Not a new concept&#8211;teaching business owners about IT security risk is always hard to do, even more so when they have to sign off on the risk.</li>
<li><strong>C&amp;A services are a commodity market:</strong>  I <a href="http://www.guerilla-ciso.com/archives/412">covered this last week</a>.  This is pivotal, remember it for later.</li>
<li><strong>Misinformation abounds:</strong>  Because the NIST Risk Management Framework evolves so rapidly, what&#8217;s valid today is not the same that will be valid in 2 years.</li>
</ul>
<p>So what we&#8217;re looking at with this blog post is how would a program to certify the C&amp;A service providers look like.  NIST has 3 viable options:</p>
<ul>
<li><strong>Use Existing Certs:</strong> Require basic certification levels for role descriptions.  DoD 8570.1M follows this approach.  Individual-level certification would be CAP, CISSP, CG.*, CISA, etc.  The company-level certification would be something like ITIL or CMMI.</li>
<li><strong>Second-Party Credentialing:</strong>  The industry creates a new certification program to satisfy NIST&#8217;s need without any input from NIST.  Part of this has already happened with some of the certifications like CAP.</li>
<li><strong>NIST-Sponsored Certification:</strong>  NIST becomes the &#8220;owner&#8221; of the certification and commissions organizations to test each other.</li>
</ul>
<p>Now just like DoD 8570.1M, I&#8217;m torn on this issue.  On one hand, it means that you&#8217;ll get a higher caliber of person performing services because they have to meet some kind of minimum standard.  On the other hand, introducing scarcity means that there will be even less people available to do the job.  But the big problem that I have is that if you introduce higher requirements on commodity services, you&#8217;re squeezing the market severely:  costs as a customer go up for basic services, vendors get even less of a margin on services, more charlatans show up because you&#8217;ve tipped over into higher-priced boutique services, and mayhem ensues.</p>
<p>Guys, I&#8217;m not really a rocket scientist on this, but really after all this effort, it seems to me that the #1 problem that the Government has is a lack of skilled people.  Yes, certifying people is a good thing because it helps weed out the dirtballs with a very rough sieve, but I get the feeling that maybe what we should be doing instead is trying to create more people with the skills we need.  Alas, that&#8217;s a future blog post&#8230;.</p>
<p>However, the last thing that I want to see happen is a meta-game of what&#8217;s going on with certifications right now&#8211;who certifies those who certify?  I think it&#8217;s a vicious cycle of cross-certification that will end up with the entire Government security industry becoming one huge self-licking ice cream cone.  =)</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/419&amp;title=NIST%26%238217%3BS+FISMA+Pase+II%26%238211%3BWho+Certifies+Those+who+Certify+the+Certifiers%3F" title="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Del.icio.us" alt="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/419&amp;title=NIST%26%238217%3BS+FISMA+Pase+II%26%238211%3BWho+Certifies+Those+who+Certify+the+Certifiers%3F" title="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to digg" alt="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/419&amp;title=NIST%26%238217%3BS+FISMA+Pase+II%26%238211%3BWho+Certifies+Those+who+Certify+the+Certifiers%3F" title="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to reddit" alt="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=NIST%26%238217%3BS+FISMA+Pase+II%26%238211%3BWho+Certifies+Those+who+Certify+the+Certifiers%3F&amp;url=http://www.guerilla-ciso.com/archives/419&amp;version=0.7" title="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Feed Me Links" alt="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/419" title="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Technorati" alt="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/419&amp;t=NIST%26%238217%3BS+FISMA+Pase+II%26%238211%3BWho+Certifies+Those+who+Certify+the+Certifiers%3F" title="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Yahoo My Web" alt="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/419&amp;title=NIST%26%238217%3BS+FISMA+Pase+II%26%238211%3BWho+Certifies+Those+who+Certify+the+Certifiers%3F" title="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Stumble Upon" alt="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/419&amp;title=NIST%26%238217%3BS+FISMA+Pase+II%26%238211%3BWho+Certifies+Those+who+Certify+the+Certifiers%3F" title="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Google Bookmarks" alt="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/419" title="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Squidoo" alt="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/419" title="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Bloglines" alt="Add 'NIST&#8217;S FISMA Pase II&#8211;Who Certifies Those who Certify the Certifiers?' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=CAHm0I"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=CAHm0I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=PZTRxi"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=PZTRxi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/314090909" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 17 Jun 2008 17:22:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/boutique services">boutique services</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk-avoidance cultures">risk-avoidance cultures</category>
      <category domain="http://securityratty.com/tag/accreditation services">accreditation services</category>
      <category domain="http://securityratty.com/tag/company-level certification">company-level certification</category>
      <category domain="http://securityratty.com/tag/security risk">security risk</category>
      <category domain="http://securityratty.com/tag/certification">certification</category>
      <category domain="http://securityratty.com/tag/certification program">certification program</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/314090909/419">NISTS FISMA Pase IIWho Certifies Those who Certify the Certifiers?</source>
    </item>
    <item>
      <title><![CDATA[Its All Friggin Magic, Mkay?]]></title>
      <link>http://securityratty.com/article/22c7dc12b338751ca5fdfce977683aff</link>
      <guid>http://securityratty.com/article/22c7dc12b338751ca5fdfce977683aff</guid>
      <description><![CDATA[OK, whoever named this product should be shot: Ashampoo Magical Security
However, as much as I love sprinkling on the Magic FISMA Fairy Dust , Magical Security is craziness
I wont go into too much...]]></description>
      <content:encoded><![CDATA[<p>OK, whoever named this product should be shot:  <a href="http://www.ashampoo-security.com/product.php?idstring=0704&amp;session_langid=2" target="_blank">Ashampoo Magical Security</a>.</p>
<p>However, as much as I love sprinkling on the <a href="http://www.guerilla-ciso.com/archives/216" target="_blank">Magic FISMA Fairy Dust</a>, &#8220;Magical Security&#8221; is craziness.</p>
<p>I won&#8217;t go into too much detail on hackers, shampoo, washing, and <a href="http://en.wikipedia.org/wiki/South_Pacific_(musical)" target="_blank">South Pacific</a>.  I have a feeling I&#8217;ll get plenty of comments to that effect.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/417&amp;title=It%26%238217%3Bs+All+Friggin%26%238217%3B+Magic%2C+Mkay%3F" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Del.icio.us" alt="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/417&amp;title=It%26%238217%3Bs+All+Friggin%26%238217%3B+Magic%2C+Mkay%3F" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to digg" alt="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/417&amp;title=It%26%238217%3Bs+All+Friggin%26%238217%3B+Magic%2C+Mkay%3F" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to reddit" alt="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=It%26%238217%3Bs+All+Friggin%26%238217%3B+Magic%2C+Mkay%3F&amp;url=http://www.guerilla-ciso.com/archives/417&amp;version=0.7" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Feed Me Links" alt="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/417" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Technorati" alt="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/417&amp;t=It%26%238217%3Bs+All+Friggin%26%238217%3B+Magic%2C+Mkay%3F" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Yahoo My Web" alt="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/417&amp;title=It%26%238217%3Bs+All+Friggin%26%238217%3B+Magic%2C+Mkay%3F" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Stumble Upon" alt="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/417&amp;title=It%26%238217%3Bs+All+Friggin%26%238217%3B+Magic%2C+Mkay%3F" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Google Bookmarks" alt="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/417" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Squidoo" alt="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/417" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Bloglines" alt="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=Z8DYhI"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=Z8DYhI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=Geooyi"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=Geooyi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/313852981" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 17 Jun 2008 11:04:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ashampoo magical security">ashampoo magical security</category>
      <category domain="http://securityratty.com/tag/magical security">magical security</category>
      <category domain="http://securityratty.com/tag/south pacific">south pacific</category>
      <category domain="http://securityratty.com/tag/plenty">plenty</category>
      <category domain="http://securityratty.com/tag/effect">effect</category>
      <category domain="http://securityratty.com/tag/craziness">craziness</category>
      <category domain="http://securityratty.com/tag/comments">comments</category>
      <category domain="http://securityratty.com/tag/shampoo">shampoo</category>
      <category domain="http://securityratty.com/tag/detail">detail</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/313852981/417">Its All Friggin Magic, Mkay?</source>
    </item>
  </channel>
</rss>
