<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: gao]]></title>
    <link>http://securityratty.com/tag/gao</link>
    <description></description>
    <pubDate>Sun, 13 Apr 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[HP layoffs, Wall Street blues, Palin's hack]]></title>
      <link>http://securityratty.com/article/f48704a9269ad525e8c97cf198d3ace5</link>
      <guid>http://securityratty.com/article/f48704a9269ad525e8c97cf198d3ace5</guid>
      <description><![CDATA[The week got off to a rough start with the collapse of Lehman Brothers sending shudders through global financial markets and raising questions about whether there will be a ripple effect on the IT...]]></description>
      <content:encoded><![CDATA[The week got off to a rough start with the collapse of Lehman Brothers sending shudders through global financial markets and raising questions about whether there will be a ripple effect on the IT industry. After the market closed Monday, Hewlett-Packard added to the dismal mood by announcing it will lay off 24,600 employees as it integrates Electronic Data Systems into the HP fold. Republican vice presidential candidate Sarah Palin was the victim of an apparent hacking attack on the Yahoo account she uses for official business as governor of Alaska, and in other government-related IT news, a GAO report says the U.S. does a lousy job of following its regulations regarding electronic-waste shipment and disposal.]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/electronic data systems">electronic data systems</category>
      <category domain="http://securityratty.com/tag/republican vice presidential">republican vice presidential</category>
      <category domain="http://securityratty.com/tag/global financial markets">global financial markets</category>
      <category domain="http://securityratty.com/tag/lousy job">lousy job</category>
      <category domain="http://securityratty.com/tag/yahoo account">yahoo account</category>
      <category domain="http://securityratty.com/tag/gao report">gao report</category>
      <category domain="http://securityratty.com/tag/lehman brothers">lehman brothers</category>
      <category domain="http://securityratty.com/tag/rough start">rough start</category>
      <category domain="http://securityratty.com/tag/dismal mood">dismal mood</category>
      <source url="http://www.networkworld.com/news/2008/091908-hp-layoffs-wall-street-blues.html?fsrc=rss-security">HP layoffs, Wall Street blues, Palin's hack</source>
    </item>
    <item>
      <title><![CDATA[Fear not, no wait, you should fear.]]></title>
      <link>http://securityratty.com/article/62970ace259302e46fc33f22f86e9c5e</link>
      <guid>http://securityratty.com/article/62970ace259302e46fc33f22f86e9c5e</guid>
      <description><![CDATA[Ever get the feeling that the bow of the ship is slipping under the waves


clipped from www.msnbc.msn.com

U.S. Cybersecurity Is Weak, GAO Says



Five years after the Homeland Security Dept. took...]]></description>
      <content:encoded><![CDATA[<div > Ever get the feeling that the bow of the ship is slipping under the waves? </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/3EFCAA8A-BF2C-497A-8513-A48D6844A0AD/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/ad915f0a-26dc-4cc3-8945-0ed58ccf8ec1/3EFCAA8A-BF2C-497A-8513-A48D6844A0AD/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.msnbc.msn.com/id/26738121/" href="http://www.msnbc.msn.com/id/26738121/" style="font-size: 11px;">www.msnbc.msn.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.msnbc.msn.com/id/26738121/ -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">
U.S. Cybersecurity Is Weak, GAO Says
</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.msnbc.msn.com/id/26738121/ --><P class="textBodyBlack"><SPAN id="byLine"></SPAN><br />
Five years after the Homeland Security Dept. took charge of the team as a critical safeguard against threats to national security, US-CERT &#8220;still does not exhibit aspects of the attributes essential to having a truly national capability,&#8221; according to the draft report.<br />
</P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.msnbc.msn.com/id/26738121/ --><P class="textBodyBlack"><SPAN id="byLine"></SPAN><br />
Vulnerable to Foreign Adversaries</P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.msnbc.msn.com/id/26738121/ --><P class="textBodyBlack"><SPAN id="byLine"></SPAN><br />
Goals Not Being Met</P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.msnbc.msn.com/id/26738121/ --><P class="textBodyBlack"><SPAN id="byLine"></SPAN><br />
Actions Are Inadequate</P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.msnbc.msn.com/id/26738121/ --><P class="textBodyBlack"><SPAN id="byLine"></SPAN><br />
Weak Warning Capabilities</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/3EFCAA8A-BF2C-497A-8513-A48D6844A0AD/blog/" title="blog or email this clip"><img src="http://content6.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_180908012351"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=180908012351&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=180908012351&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=180908012351&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_180908012351" /></a></P>]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 09:23:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/homeland security dept">homeland security dept</category>
      <category domain="http://securityratty.com/tag/exhibit aspects">exhibit aspects</category>
      <category domain="http://securityratty.com/tag/critical safeguard">critical safeguard</category>
      <category domain="http://securityratty.com/tag/attributes essential">attributes essential</category>
      <category domain="http://securityratty.com/tag/national capability">national capability</category>
      <category domain="http://securityratty.com/tag/draft report">draft report</category>
      <category domain="http://securityratty.com/tag/weak">weak</category>
      <category domain="http://securityratty.com/tag/national security">national security</category>
      <category domain="http://securityratty.com/tag/foreign adversaries">foreign adversaries</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=623">Fear not, no wait, you should fear.</source>
    </item>
    <item>
      <title><![CDATA[Civilians Ask Whats With All the Privacy Act Kerfluffle?]]></title>
      <link>http://securityratty.com/article/d5daa36201f5ba38464b919d3abcc3dc</link>
      <guid>http://securityratty.com/article/d5daa36201f5ba38464b919d3abcc3dc</guid>
      <description><![CDATA[And by kerfluffle, I mean these articles
GAOPrivacy Report
Technology Liberation Front
Center for Democracy and Technology
And how about an analysis of the Privacy Act from DOJ for background reasons...]]></description>
      <content:encoded><![CDATA[<p>And by &#8220;kerfluffle&#8221;, I mean these articles:</p>
<ul>
<li><a href="http://www.gao.gov/new.items/d08536.pdf" target="_blank">GAO Privacy Report</a></li>
<li><a href="http://techliberation.com/2008/06/20/gao-issues-report-on-privacy/" target="_blank">Technology Liberation Front</a></li>
<li><a href="http://www.cdt.org/publications/policyposts/2008/10" target="_blank">Center for Democracy and Technology</a></li>
<li>And how about an <a href="http://www.usdoj.gov/oip/04_7_1.html" target="_blank">analysis of the Privacy Act </a>from DOJ for background reasons?</li>
</ul>
<p>Well, let&#8217;s talk about how privacy and the Government works with Uncle Rybolov (please hold the references to Old Weird Uncle Harold until we&#8217;re through with today&#8217;s lesson please).</p>
<p>We have a law, the Privacy Act of 1974.  Think about it, what significant privacy-wrenching activities happened just a couple of years prior?  Can we say &#8220;<a href="http://en.wikipedia.org/wiki/Watergate_scandal" target="_blank">Watergate Scandal</a>&#8220;?  Can we say &#8220;<a href="http://en.wikipedia.org/wiki/Church_Committee" target="_blank">Church Committee</a>&#8220;?  Suffice it to say, the early 1970s was an era filled with privacy issues and is where most of our privacy policy and law comes from.  Remember this for later:  this was the 1970&#8217;s!</p>
<p>Each of the various sections of the Privacy Act deals with a particular data type.  For instance, Title 13 refers to data collected by the Census Bureau when they&#8217;ll go count everybody in 2010.</p>
<p>The Privacy Act talks about the stuff that everybody in the Government needs to know about:  how you&#8217;re going to jail if you disclose this information to a third party.  For those of you who have ever been in the military or had to fill out a government form that required your social security number, the light in the back of your head should be going off right now because they all have the warnings about disclosure.</p>
<p style="text-align: center;"><em><img src="http://farm3.static.flickr.com/2095/2054565713_1d20d5f90a.jpg?v=0" alt="Huts and Chairs Need Privacy Too" width="376" height="500" /></em></p>
<p style="text-align: center;"><em>Remember to respect the privacy of the beach huts and chairs photo by </em><a href="http://www.flickr.com/photos/joeshlabotnik/" target="_blank"><em>Joe Shlabotnik</em></a></p>
<p>When it comes to IT security, the Privacy Act works like this:</p>
<ul>
<li>You realize a need to collect PII on individuals.</li>
<li>You do a privacy impact assessment to determine if you can legally collect this data and what the implications of collecting the data are.</li>
<li>You build rules about what you can do normally with the data once you have collected it.  This is called the &#8220;routine use&#8221;.</li>
<li>You write a report on how, why, and about whom you&#8217;re collecting this information.  This is known as the &#8220;System of Record Notice&#8221;.</li>
<li>You file this report with the Federal Register to notify the public.</li>
<li>This IT system becomes the authoritative source of that information.</li>
</ul>
<p>IE, no secret dossiers on the public.  We&#8217;ll suspend our disbelief in FISA for a minute, this conversation is about non-intelligence data collection.</p>
<p>Now the problem with all this is that if you stop and think about it, I was 1 year old when the Privacy Act was signed.  Our technology for information sharing has gone above and beyond that.  We can exchange data much much much more quickly than the Privacy Act originally intended.  As a result, we have PII everywhere.  Most of the PII is needed to provide services to the citizens, except that it&#8217;s a royal PITA to protect it all, and that&#8217;s the lesson of the past 2 years in Government data breaches.</p>
<p>Problems with the Privacy Act:</p>
<ul>
<li>The SORN is hard to read and is not easy to find.</li>
<li>Privacy Act data given to contractors or &#8220;business partners&#8221; (aka, state and local government or NGOs) does not have the same amount of oversight as it does in the Government.</li>
<li>Data given to the Government by a third-party is not susceptible to the Privacy Act because the Government did not collect it.  Wow, lots of room for abuse&#8211;waterboarding-esque abuse.</li>
<li>Privacy Act procedures were written for mainframes.  Mainframes have been replaced with clusters of servers.  It&#8217;s easy to add a new server to this setup.  Yes, this <strong>is</strong> a feature.</li>
<li>If you build a new system with the same data types and routine uses as an already existing SORN, you can &#8220;piggyback&#8221; on that existing SORN.</li>
<li>It&#8217;s very easy to use the data in a way that isn&#8217;t on your &#8220;routine use&#8221; statement, thus breaking the entire privacy system.</li>
</ul>
<p>Obviously, at this point, you should have gotten the hint that maybe we need to revise the Privacy Act.  I think GAO and OMB would agree with you here.</p>
<p>So, what alternatives do we have to the existing system?</p>
<ul>
<li>Make blanket data types and do a PIA and SORN on them regardless of where that data lies.</li>
<li>Bend the Paperwork Reduction act and OMB guidance so that we don&#8217;t collect as much information.</li>
<li>Make the Privacy Act more specific on what should be in SORN, PIA, and routine use statements.</li>
</ul>
<p>To be honest, it seems like most of this is already in place, it just needs to get tuned a little bit so we&#8217;re doing the right things.  Once again, the scale of the Government&#8217;s IT infrastructure is keeping us from doing the right thing:    there isn&#8217;t enough time in the day to do PIAs on a per-server basis or to keep track of every little bit of data.  You have to automate our privacy efforts in some fashion.</p>
<p>And this is why, dear readers, I think the Government needs DLP solutions more than the private sector does.  Too bad the DLP vendors are stuck on credit cards and social security numbers.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/424&amp;title=Civilians+Ask+%26%238220%3BWhat%26%238217%3Bs+With+All+the+Privacy+Act+Kerfluffle%3F%26%238221%3B" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Del.icio.us" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/424&amp;title=Civilians+Ask+%26%238220%3BWhat%26%238217%3Bs+With+All+the+Privacy+Act+Kerfluffle%3F%26%238221%3B" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to digg" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/424&amp;title=Civilians+Ask+%26%238220%3BWhat%26%238217%3Bs+With+All+the+Privacy+Act+Kerfluffle%3F%26%238221%3B" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to reddit" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Civilians+Ask+%26%238220%3BWhat%26%238217%3Bs+With+All+the+Privacy+Act+Kerfluffle%3F%26%238221%3B&amp;url=http://www.guerilla-ciso.com/archives/424&amp;version=0.7" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Feed Me Links" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/424" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Technorati" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/424&amp;t=Civilians+Ask+%26%238220%3BWhat%26%238217%3Bs+With+All+the+Privacy+Act+Kerfluffle%3F%26%238221%3B" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Yahoo My Web" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/424&amp;title=Civilians+Ask+%26%238220%3BWhat%26%238217%3Bs+With+All+the+Privacy+Act+Kerfluffle%3F%26%238221%3B" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Stumble Upon" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/424&amp;title=Civilians+Ask+%26%238220%3BWhat%26%238217%3Bs+With+All+the+Privacy+Act+Kerfluffle%3F%26%238221%3B" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Google Bookmarks" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/424" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Squidoo" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/424" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Bloglines" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=iZflJI"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=iZflJI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=SHBmQi"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=SHBmQi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/320829287" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 17:51:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/privacy act">privacy act</category>
      <category domain="http://securityratty.com/tag/privacy act procedures">privacy act procedures</category>
      <category domain="http://securityratty.com/tag/privacy act deals">privacy act deals</category>
      <category domain="http://securityratty.com/tag/privacy act data">privacy act data</category>
      <category domain="http://securityratty.com/tag/privacy">privacy</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data lies">data lies</category>
      <category domain="http://securityratty.com/tag/privacy act talks">privacy act talks</category>
      <category domain="http://securityratty.com/tag/privacy policy">privacy policy</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/320829287/424">Civilians Ask Whats With All the Privacy Act Kerfluffle?</source>
    </item>
    <item>
      <title><![CDATA[Government Akountability Office]]></title>
      <link>http://securityratty.com/article/0a1ec52c05ba59ac581bb4ba24c838d2</link>
      <guid>http://securityratty.com/article/0a1ec52c05ba59ac581bb4ba24c838d2</guid>
      <description><![CDATA[Ah yes, my favorite subject to bash: compliance. Better comply or GAO will report you


Bookmark...]]></description>
      <content:encoded><![CDATA[<p> Ah yes, my favorite subject to bash: compliance.  Better comply or GAO will report you. =)</p>
<p> <a href="http://mine.icanhascheezburger.com/view.aspx?ciid=1143269"></a></p>
<p style="text-align: center;"><img src="http://images.icanhascheezburger.com/completestore/2008/5/14/akountabilityof128552889792476786.jpg" alt="funny pictures" /></p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/393&amp;title=Government+Akountability+Office" title="Add 'Government Akountability Office' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'Government Akountability Office' to Del.icio.us" alt="Add 'Government Akountability Office' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/393&amp;title=Government+Akountability+Office" title="Add 'Government Akountability Office' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'Government Akountability Office' to digg" alt="Add 'Government Akountability Office' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/393&amp;title=Government+Akountability+Office" title="Add 'Government Akountability Office' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'Government Akountability Office' to reddit" alt="Add 'Government Akountability Office' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Government+Akountability+Office&amp;url=http://www.guerilla-ciso.com/archives/393&amp;version=0.7" title="Add 'Government Akountability Office' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'Government Akountability Office' to Feed Me Links" alt="Add 'Government Akountability Office' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/393" title="Add 'Government Akountability Office' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'Government Akountability Office' to Technorati" alt="Add 'Government Akountability Office' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/393&amp;t=Government+Akountability+Office" title="Add 'Government Akountability Office' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'Government Akountability Office' to Yahoo My Web" alt="Add 'Government Akountability Office' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/393&amp;title=Government+Akountability+Office" title="Add 'Government Akountability Office' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'Government Akountability Office' to Stumble Upon" alt="Add 'Government Akountability Office' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/393&amp;title=Government+Akountability+Office" title="Add 'Government Akountability Office' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'Government Akountability Office' to Google Bookmarks" alt="Add 'Government Akountability Office' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/393" title="Add 'Government Akountability Office' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'Government Akountability Office' to Squidoo" alt="Add 'Government Akountability Office' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/393" title="Add 'Government Akountability Office' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'Government Akountability Office' to Bloglines" alt="Add 'Government Akountability Office' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=if5DsI"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=if5DsI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=xEWDHi"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=xEWDHi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/305562505" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 05 Jun 2008 09:39:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/favorite subject">favorite subject</category>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/report">report</category>
      <category domain="http://securityratty.com/tag/bash">bash</category>
      <category domain="http://securityratty.com/tag/bookmark">bookmark</category>
      <category domain="http://securityratty.com/tag/gao">gao</category>
      <category domain="http://securityratty.com/tag/comply">comply</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/305562505/393">Government Akountability Office</source>
    </item>
    <item>
      <title><![CDATA[GAO: FDIC Needs Stronger Security Controls]]></title>
      <link>http://securityratty.com/article/e682669dbda7f8acb24261c30ff5859e</link>
      <guid>http://securityratty.com/article/e682669dbda7f8acb24261c30ff5859e</guid>
      <description><![CDATA[Meh, they only handle the insurance for your money. No biggie right
From FCW
A key reason for the latest weaknesses the auditors found is that the FDIC did not always fully implement critical...]]></description>
      <content:encoded><![CDATA[<p>Meh, they only handle the insurance for your money. No biggie right?</p>
<p>From FCW:</p>
<blockquote><p>A key reason for the latest weaknesses the auditors found is that the FDIC did not always fully implement critical information security program activities, GAO said.</p>
<p>For example, multiple FDIC users shared the same login ID and password, had unrestricted access to application source code and used a password that was not adequately encrypted. The FDIC also did not fully test configuration controls, GAO reported,</p>
<p>Until the FDIC fully performs key information security program activities, GAO said there is an increased risk that it may not be able to maintain sufficient control over its financial systems and information.</p></blockquote>
<p>Yeah, see that&#8217;s bad m&#8217;kay.</p>
<p><center><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2008/06/mackey.png" alt="Mr. Mackey" title="mackey" width="296" height="361" /></center></p>
<p><a href="http://www.fcw.com/online/news/152725-1.html">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=6VknoS"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=6VknoS" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=fjVNYI"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=fjVNYI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=7P55Ki"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=7P55Ki" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=LD4mwi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=LD4mwi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=u1iaGi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=u1iaGi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=htdtBi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=htdtBi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/304997498" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 04 Jun 2008 23:09:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fdic">fdic</category>
      <category domain="http://securityratty.com/tag/multiple fdic users">multiple fdic users</category>
      <category domain="http://securityratty.com/tag/gao">gao</category>
      <category domain="http://securityratty.com/tag/maintain sufficient control">maintain sufficient control</category>
      <category domain="http://securityratty.com/tag/test configuration controls">test configuration controls</category>
      <category domain="http://securityratty.com/tag/application source code">application source code</category>
      <category domain="http://securityratty.com/tag/financial systems">financial systems</category>
      <category domain="http://securityratty.com/tag/article link">article link</category>
      <category domain="http://securityratty.com/tag/password">password</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/304997498/">GAO: FDIC Needs Stronger Security Controls</source>
    </item>
    <item>
      <title><![CDATA[FISMA Report Card News, Formulas, and 3 Myths]]></title>
      <link>http://securityratty.com/article/b5be8b7e91c58d0ef038594276f66108</link>
      <guid>http://securityratty.com/article/b5be8b7e91c58d0ef038594276f66108</guid>
      <description><![CDATA[Ever watch a marathon on TV? Theres the usual formula for how we lay out the day
History of the marathon and Pheidippides
Discussion of the race length and how it was changes so that the Queen could...]]></description>
      <content:encoded><![CDATA[<p>Ever watch a marathon on TV?  There&#8217;s the usual formula for how we lay out the day:</p>
<ul>
<li>History of the marathon and <a title="Pheidippides" href="http://en.wikipedia.org/wiki/Pheidippides" target="_blank">Pheidippides</a></li>
<li>Discussion of the race length and how it was changes so that the Queen could watch the finish</li>
<li>World records and what our chances are for making one today</li>
<li>Graphics of the race course showing the key hills and the &#8220;sprint to the finish&#8221;</li>
<li>Talk about the womens&#8217; marathon including Joan Benoit and Kathrine Switzer</li>
<li>Description of energy depletion and &#8220;The Wall&#8221;</li>
<li>Stats as the leaders hit the finsh line</li>
<li>Shots of &#8220;back-of-the-pack&#8221; runners and the race against yourself</li>
</ul>
<p>Well, I now present to you the formula for FISMA Report Cards:</p>
<ul>
<li>Paragraph about how agencies are failing to secure their data, the report card says so</li>
<li>History and trending of the report card</li>
<li>Discussion on changing FISMA</li>
<li>Quote from Karen Evans</li>
<li>Quote from Alan Paller about how FISMA is a failure and checklist-driven security</li>
<li>Wondering when the government will get their act together</li>
</ul>
<p>Have a read of <a href="http://blogs.zdnet.com/security/?p=1185" target="_blank">Dancho&#8217;s response </a>to the FISMA Report Card.  Pretty typical writing formula that you&#8217;ll see from journalists.  I won&#8217;t even comment on the &#8220;FISMA compliance&#8221; title.  Oh wait, I just did.  =)</p>
<p>Some myths about FISMA in particular that I need to dispell right now:</p>
<ol>
<li><strong>FISMA is a report card:</strong>  It&#8217;s a law, the grades are just an awareness campaign.  In fact, the whole series of NIST Special Publications are just implementation techniques&#8211;they are <em>guidance </em>after all.  Usually the media and bloggers talk about what FISMA measures and um, well, it doesn&#8217;t measure anything, it just requires that agencies have security programs based on a short list of criteria such as security planning, contingency planning, and security testing.  It just goes back to the adage that <a href="http://www.guerilla-ciso.com/archives/150" target="_blank">nobody really knows what FISMA is</a>.</li>
<li><strong>FISMA needs to be changed:</strong>  As a law, FISMA is <em>exactly</em> where it needs to be.  Yes, Congress does have talks about modifying FISMA, but not much has come of it because what they eventually discover after much debate and sword-waving is that FISMA is the way to write the law about security, the problem is with the execution at all levels&#8211;OMB, GAO, and the agencies&#8211;and typically across organizational boundaries and competing master agendas.</li>
<li><strong>There is a viable alternative framework:</strong>  Dancho points out <a href="http://www.ignet.gov/pande/audit/fismaframework0906.pdf" target="_blank">this framework</a> in his post which is really an auditors&#8217; plugin to the existing NIST Framework for FISMA.  Thing is, nobody has a viable alternative framework because it&#8217;s still going to be the same people with the same training executing in the same environment.</li>
</ol>
<p style="text-align: center;"><em><img src="http://farm1.static.flickr.com/47/181917366_70c6423250.jpg?v=0" alt="Urban Myth: Cellular Phones Cause Gas Fires" width="500" height="375" /></em></p>
<p style="text-align: center;"><em>Urban Cell-Phone Fire Myth photo by </em><a href="http://www.flickr.com/photos/bike/" target="_blank"><em>richardmasoner</em></a><em>.  This myth is <a href="http://www.snopes.com/autos/hazards/gasvapor.asp" target="_blank">dispelled at snopes.com</a>.</em></p>
<p>Way back last year I wrote a blog post about <a href="http://www.guerilla-ciso.com/archives/96" target="_blank">indicator species and how we&#8217;re expecting the metrics to go up based on our continual measuring of them</a>.  Every couple of months I go back and review it to see if it&#8217;s still relevant.  And the answer this week is &#8220;yes&#8221;.</p>
<p>Now I&#8217;ve been thinking and talking probably too much about FISMA and the grades over the past couple of years, so occassionally I come to conclusions .  According to Mr Vlad the Impaler, the report card is a bad idea, but I&#8217;m slowly beginning to see the wisdom of it:  it&#8217;s an opportunity to have a debate and to raise some awareness of Government security outside of those of us who do it.  The only other time that we have a public debate about security is after a serious data breach, and that&#8217;s not a happy time.</p>
<p>I just wish the media would stop with the story line that FISMA is failing because the grades provide recursive evidence of it.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/404&amp;title=FISMA+Report+Card+News%2C+Formulas%2C+and+3+Myths" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Del.icio.us" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/404&amp;title=FISMA+Report+Card+News%2C+Formulas%2C+and+3+Myths" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to digg" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/404&amp;title=FISMA+Report+Card+News%2C+Formulas%2C+and+3+Myths" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to reddit" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=FISMA+Report+Card+News%2C+Formulas%2C+and+3+Myths&amp;url=http://www.guerilla-ciso.com/archives/404&amp;version=0.7" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Feed Me Links" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/404" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Technorati" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/404&amp;t=FISMA+Report+Card+News%2C+Formulas%2C+and+3+Myths" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Yahoo My Web" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/404&amp;title=FISMA+Report+Card+News%2C+Formulas%2C+and+3+Myths" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Stumble Upon" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/404&amp;title=FISMA+Report+Card+News%2C+Formulas%2C+and+3+Myths" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Google Bookmarks" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/404" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Squidoo" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/404" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Bloglines" alt="Add 'FISMA Report Card News, Formulas, and 3 Myths' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=CeAzjI"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=CeAzjI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=ZGK9zi"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=ZGK9zi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/299192207" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 27 May 2008 12:36:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/report card">report card</category>
      <category domain="http://securityratty.com/tag/fisma report card">fisma report card</category>
      <category domain="http://securityratty.com/tag/fisma">fisma</category>
      <category domain="http://securityratty.com/tag/fisma measures">fisma measures</category>
      <category domain="http://securityratty.com/tag/fisma compliance title">fisma compliance title</category>
      <category domain="http://securityratty.com/tag/fisma report cards">fisma report cards</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security programs based">security programs based</category>
      <category domain="http://securityratty.com/tag/framework">framework</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/299192207/404">FISMA Report Card News, Formulas, and 3 Myths</source>
    </item>
    <item>
      <title><![CDATA[FISMA Report Cards IssuedResponse is Rote by Now]]></title>
      <link>http://securityratty.com/article/c4fec28ddd80fa55d26b93033e54c7fc</link>
      <guid>http://securityratty.com/article/c4fec28ddd80fa55d26b93033e54c7fc</guid>
      <description><![CDATA[Yay, FISMA report card for 2007 has been issued. You can go check it out here . I cant believe it, but DHS scored a B against all odds
And of course, by now the response to the report card is all...]]></description>
      <content:encoded><![CDATA[<p>Yay, FISMA report card for 2007 has been issued.  You can go <a href="http://republicans.oversight.house.gov/media/PDFs/Reports/FY2007FISMAReportCard.pdf" target="_blank">check it out here</a>.  I can&#8217;t believe it, but DHS scored a &#8220;B&#8221; against all odds. =)</p>
<p>And of course, by now the response to the report card is all rote&#8211;everybody wonders what the letters really mean:</p>
<ul>
<li><a href="http://www.scmagazineus.com/Federal-agencies-FISMA-grade-up-slightly/article/110375/" target="_blank">SC Magazine</a></li>
<li><a href="http://news.idg.no/cw/art.cfm?id=08F0A29C-17A4-0F78-3113197D5C06A6C5" target="_blank">IDG</a></li>
<li><a href="http://www.itbusinessedge.com/blogs/hdw/?p=2238" target="_blank">IT Business Edge</a></li>
<li><a href="http://federaltimes.com/index.php?S=3539078" target="_blank">Federal Times</a></li>
<li><a href="http://blog.washingtonpost.com/securityfix/2008/05/govt_earns_grade_of_c_for_comp.html?nav=rss_blog" target="_blank">Washington Post</a></li>
<li><a href="http://www.securityfocus.com/brief/741" target="_blank">Security Focus</a></li>
</ul>
<p>Yeah, yeah, I guess it just goes to prove what we say about the classified world: the people who know don&#8217;t talk and the people who talk don&#8217;t know.  In this case, everybody attacks the metric because, well, it&#8217;s a bad metric&#8211;what action are we supposed to take because of what the results are?  It&#8217;s also pretty much ignored by this point anyway except for the witty sound bites from some of my &#8220;favorite people&#8221;, so it&#8217;s nothing to get all hot and bothered about.  The GAO and OMB reports that <a href="http://www.guerilla-ciso.com/archives/348" target="_blank">I&#8217;ve covered in much detail </a>are much better and have a pretty decent level of analysis.</p>
<p>But fer chrissakes, the report card is issued by Congress, how much detail do you think it will ever contain?  =)</p>
<p>My rapidly expanding queue of pet peeves about this time of the year:</p>
<ul>
<li><strong>People who think that FISMA is just a report card and that we should re-examine how we measure security:</strong>  the grades are not even required by the law, it&#8217;s just technique and we can change that easily enough.</li>
<li><strong>People who criticize but do not offer an alternative:</strong>  even if you had an alternative plan, the environment for execution still involves the same IT assets and the same front-line employees.</li>
<li><strong>People who don&#8217;t understand enterprise-wide security much less a federation of semi-independent enterprises:</strong> it&#8217;s the nature of government-wide security metrics that they&#8217;ll be indicators which can be faked.</li>
<li><strong>Sound bites from people who have never implemented any aspect of FISMA:</strong>  come on, SANS and Gartner?  GAO and the Cyber Security Industry Alliance are a little bit better but taken out of context.</li>
<li><strong>Nobody ever asks me for a quote on FISMA numminess:</strong>  I&#8217;ll be pouting for the rest of the week, TYVM.  =)</li>
</ul>
<p>Not that I&#8217;m the world&#8217;s best expert at fact-checking, but something caught my eye in the report:  it&#8217;s issued by Tom Davis and the url is from the <a href="http://republicans.oversight.house.gov/" target="_blank">Minority Office</a> for the <a href="http://oversight.house.gov/" target="_blank">House Committee on Oversight and Government Reform</a>.  Tom Davis is the representative from Northern Virginia and is the sponsor for FISMA back when it was signed.  Until the last election, he was the chairman of the House Committee on Oversight and Government Reform.  The committee is now chaired by <a href="http://oversight.house.gov/about/chairmanwaxman.asp" target="_blank">Henry Waxman</a>. </p>
<p>Time for a new concept in your vocabulary:  LGOPP (OK, actually it&#8217;s <a href="http://pagentsprogress.com/?p=555" target="_blank">LGOP</a>, but I added an extra &#8220;P&#8221; for comedy purposes).  Imagine June 6th, 1944, paratroopers scattered all over the French countryside.  What happens is you pick up the people around you, the senior person becomes the leader, and you carry out the mission.</p>
<p style="text-align: center;"><img src="http://farm1.static.flickr.com/115/299334216_8f9593d01f.jpg?v=0" alt="Paratrooper Stained Glass Window" width="257" height="500" /></p>
<p style="text-align: center;"><em>Photo of Paratrooper Stained Glass in Sainte Mère Église by</em><a href="http://www.flickr.com/photos/nelsonminar/" target="_blank"><em> Nelson Minar</em></a></p>
<p>Hence the true meaning of LGOPP: Little Groups of P*ssed-off Paratroopers.  An equivalent phrase is &#8220;isolated pockets of brilliance&#8221;.</p>
<p>In the words of somebody I went off to war with: <em> &#8220;LGOPPS are the spirit of the infantry:  a handfull of 18- and 19-year-olds with fully automatic weapons who can barely remember what their mission is running around the woods raising hell&#8221;</em>.</p>
<p>Now, I know you guys, you&#8217;re wondering what this has to do with security?  Well, this is relevant because it&#8217;s an election year.  What that means is that instead of being bothered with all this security stuff, Congress is involved in playing &#8220;gotcha&#8221; with the Executive branch.  After the election, it&#8217;s rearranging deck chairs on the Titanic and all of the leadership will change.</p>
<p>Instead of any national-level security agendas and strategizing, we&#8217;ll have to be content with security LGOPPs fighting the fight wherever they end up gaining enough critical mass.</p>
<p>And in the case of this year&#8217;s FISMA report card, the LGOPP that is Tom Davis&#8217;s staffers issued the report while the rest of the committee was busy worrying about elections.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/400&amp;title=FISMA+Report+Cards+Issued%26%238211%3BResponse+is+Rote+by+Now" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Del.icio.us" alt="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/400&amp;title=FISMA+Report+Cards+Issued%26%238211%3BResponse+is+Rote+by+Now" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to digg" alt="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/400&amp;title=FISMA+Report+Cards+Issued%26%238211%3BResponse+is+Rote+by+Now" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to reddit" alt="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=FISMA+Report+Cards+Issued%26%238211%3BResponse+is+Rote+by+Now&amp;url=http://www.guerilla-ciso.com/archives/400&amp;version=0.7" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Feed Me Links" alt="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/400" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Technorati" alt="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/400&amp;t=FISMA+Report+Cards+Issued%26%238211%3BResponse+is+Rote+by+Now" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Yahoo My Web" alt="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/400&amp;title=FISMA+Report+Cards+Issued%26%238211%3BResponse+is+Rote+by+Now" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Stumble Upon" alt="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/400&amp;title=FISMA+Report+Cards+Issued%26%238211%3BResponse+is+Rote+by+Now" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Google Bookmarks" alt="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/400" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Squidoo" alt="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/400" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Bloglines" alt="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=cUasoI"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=cUasoI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=3r3Ssi"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=3r3Ssi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/295120811" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 21 May 2008 11:36:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/report">report</category>
      <category domain="http://securityratty.com/tag/fisma">fisma</category>
      <category domain="http://securityratty.com/tag/fisma report card">fisma report card</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/measure security">measure security</category>
      <category domain="http://securityratty.com/tag/enterprise-wide security">enterprise-wide security</category>
      <category domain="http://securityratty.com/tag/report card">report card</category>
      <category domain="http://securityratty.com/tag/security stuff">security stuff</category>
      <category domain="http://securityratty.com/tag/security lgopps">security lgopps</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/295120811/400">FISMA Report Cards IssuedResponse is Rote by Now</source>
    </item>
    <item>
      <title><![CDATA[Security Briefing: May 21st]]></title>
      <link>http://securityratty.com/article/ed10bfdf0672ac7e03278777c04940ea</link>
      <guid>http://securityratty.com/article/ed10bfdf0672ac7e03278777c04940ea</guid>
      <description><![CDATA[Yesterday was the first day on the job with my new day job company. Let me tell you, it was a welcome experience. Very welcome
Click here to subscribe to Liquidmatrix Security Digest
And now, the...]]></description>
      <content:encoded><![CDATA[<p><center><img src='http://www.liquidmatrix.org/blog/wp-content/uploads/2007/09/newspapera.jpg' alt='newspapera.jpg' /></center></p>
<p>Yesterday was the first day on the job with my new day job company. Let me tell you, it was a welcome experience. <i>Very</i> welcome. </p>
<p>Click here to <a href="http://feeds.feedburner.com/Liquidmatrix">subscribe to Liquidmatrix Security Digest!</a></p>
<p>And now, the news&#8230;</p>
<ol>
<li><a href="http://www.theregister.co.uk/2008/05/21/china_sql_injection_attack/">Mass SQL injection hits English language websites</a></li>
<li><a href="http://news.bbc.co.uk/1/hi/technology/7410885.stm">Criticism for &#8216;UK database&#8217; plan</a></li>
<li><a href="http://www.pcworld.com/businesscenter/article/146123/mauritius_gets_computer_emergency_response_team.html">Mauritius Gets Computer Emergency Response Team</a></li>
<li><a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/05/20/AR2008052002354.html?hpid=moreheadlines">TVA Power Plants Vulnerable to Cyber Attacks, GAO Finds</a></li>
<li><a href="http://www.itbusinessnet.com/articles/viewarticle.jsp?id=398785">Microsoft Expands Security Information Sharing Program to CERTs</a></li>
<li><a href="http://www.vindy.com/news/2008/may/21/congress-challenges-computer-security-plan/">Congress challenges computer security plan</a></li>
<li><a href="http://news.idg.no/pcw/art.cfm?id=077DF6E3-17A4-0F78-31BB6473E6AB9CB0">Reader favorites: 10 great free network tools</a></li>
<li><a href="http://www.siliconrepublic.com/news/news.nv?storyid=single11062">False sense of security</a></li>
</ol>
<p> Tags: <a href="http://technorati.com/tag/News" rel="tag">News</a>, <a href="http://technorati.com/tag/Daily+Links" rel="tag"> Daily Links</a>, <a href="http://technorati.com/tag/Security+Blog" rel="tag"> Security Blog</a>, <a href="http://technorati.com/tag/Information+Security" rel="tag"> Information Security</a>, <a href="http://technorati.com/tag/Security+News" rel="tag"> Security News</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=yj2OnS"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=yj2OnS" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=jgeQQH"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=jgeQQH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=YBkRBh"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=YBkRBh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=xYJyxh"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=xYJyxh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=hMz79h"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=hMz79h" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=6iqCjh"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=6iqCjh" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/294964776" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 21 May 2008 07:12:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/security news">security news</category>
      <category domain="http://securityratty.com/tag/liquidmatrix security">liquidmatrix security</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/day job company">day job company</category>
      <category domain="http://securityratty.com/tag/job">job</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <category domain="http://securityratty.com/tag/security blog">security blog</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/294964776/">Security Briefing: May 21st</source>
    </item>
    <item>
      <title><![CDATA[$160 Billion Robotic Army Network Passes First Big Test. Kinda.]]></title>
      <link>http://securityratty.com/article/6bb6208ef347d0e269a0e843e5740d09</link>
      <guid>http://securityratty.com/article/6bb6208ef347d0e269a0e843e5740d09</guid>
      <description><![CDATA[A van full of insurgents speeds through the desert. They do not notice a series of networked ground sensors that have begun tracking their every move
Hovering somewhere overhead, a tiny robot points...]]></description>
      <content:encoded><![CDATA[<p>A van full of insurgents speeds through the desert. They do not notice a series of networked ground sensors that have begun tracking their every move.</p>

<p>Hovering somewhere overhead, a tiny robot points its camera at the van and takes note of its color scheme and markings. An even bigger drone, thousands of feet above its hovering kin, maintains a God’s-eye vigil on the whole hunt.</p>

<p>Everything these robots see is radioed to monitors thousands of miles away -- and into the targeting systems of a B-52 bomber winging, silent and nearly invisible, several miles overhead.</p>

<p>This scenario, played out at a remote Nevada facility last week, was the first major test of the Army’s $160-billion, 20-year plan to build a high-tech family of networked robots and hybrid-electric armored vehicles. The “Future Combat Systems” program, co-managed by Boeing and consultants SAIC, aims to equip roughly a third of the Army with 14 new vehicle types that are connected constantly to a vast communications net.</p>

<p>The theory behind the FCS is that dispersed, intelligent robotic systems plugged into a universal communications network can help small numbers of U.S. troops riding in new vehicles to control huge swaths of terrain. Any ship, airplane or tank fitted with the FCS network devices will be able to see everything the others see.</p>

<p>The SkyNet-like network and dynamic coordination “is the most important thing,” Brigadier General James Terry says. </p>

<p>This is “a big deal for joint fires,” Army spokesman Paul Mehney told Wired.com. </p>

<p>“Joint fires” is mil-speak for getting all the military services to share info and coordinate their attacks. That kind of teamwork is a big factor in the U.S. military’s combat prowess. And if FCS works out as planned, the five U.S. military branches will team up better than ever.</p>

<p>Did the test work? Kinda.</p>

<p>The robots spotted the van; their targeting data bounced to a nearby unit of specially-equipped Humvees, then across the network to an Air Force intelligence cell in Langley, Virginia, then back to the B-52 -- all in just seconds. The bomber simulated dropping a guided bomb to “destroy” the van. </p>

<p>The Nevada test proved it was possible, according to Mehney. </p>

<p>But one critic says the test essentially was rigged -- that the conditions were too easy.</p>

<p>“There is ‘works’ and then there is ‘works,’” John Pike, an analyst with Globalsecurity,org, told Wired.com. </p>

<p>“A considerable fraction of the FCS network hardware does not currently exist,” Pike said. And the integration of that hardware that does exist has been touch-and-go.</p>

<p>In February, when testers “flipped the switch” for the first time on the network radios, there was a collective sigh of relief that the radios even worked -- this according to one FCS insider who spoke on background.</p>

<p>Last week’s desert test comes at a critical time for Future Combat Systems. Mounting criticism from the GAO plus the growing cost of fixing and upgrading the Army’s current war-weary vehicle fleet -- $120 billion over 10 years, according to the GAO -– has put the squeeze on the futuristic program. “It is not yet clear if or when the Army and [its contractors] can develop, build, and demonstrate the … network,” the Government Accountability Office reported in March.</p>

<p>One powerful congressman, nominally a supporter of FCS, has proposed injecting extra money into the program in order to rescue some of its technologies before canceling the rest.</p>

<p>Rep. John Murtha (D-PA), chair of the defense appropriations subcommittee, promised an extra $20 billion this year for FCS, provided the Army could use the money to wrap up the program quickly. “We need to accelerate FCS if we ever want to see anything accomplished,” Matt Mazonkey, a Murtha staffer, told Wired.com. </p>

<p>The Army is still preparing its response to Murtha’s query, Mehney said. Regardless, the service’s position on FCS has never wavered. The Army says that FCS is on-budget, on-schedule, and with continued funding will deliver on its promises to connect the ground service to itself and to all the other military branches.</p>

<p>And to ensure smooth progress despite a combined $900 million budget cut last year, the Army this month asked Congress to “re-appropriate” $250 million of other Army funds into FCS coffers. </p><br style="clear: both;"/>
      <a href="http://www.pheedo.com/click.phdo?s=60fb2ddae35439be877b98960768dcc2"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=60fb2ddae35439be877b98960768dcc2"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=60fb2ddae35439be877b98960768dcc2" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=EouXcG"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=EouXcG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=f0GkJg"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=f0GkJg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=KpPnsg"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=KpPnsg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=glEASG"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=glEASG" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=X7WHYG"><img src="http://feeds.wired.com/~f/wired/politics/security?i=X7WHYG" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=rpxZig"><img src="http://feeds.wired.com/~f/wired/politics/security?i=rpxZig" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=TyYySg"><img src="http://feeds.wired.com/~f/wired/politics/security?i=TyYySg" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Zjk1YG"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Zjk1YG" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/281164411" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/281164412" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 30 Apr 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fcs network devices">fcs network devices</category>
      <category domain="http://securityratty.com/tag/fcs">fcs</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/fcs network hardware">fcs network hardware</category>
      <category domain="http://securityratty.com/tag/test">test</category>
      <category domain="http://securityratty.com/tag/radios">radios</category>
      <category domain="http://securityratty.com/tag/network radios">network radios</category>
      <category domain="http://securityratty.com/tag/army">army</category>
      <category domain="http://securityratty.com/tag/fcs coffers">fcs coffers</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/281164412/robots_army">$160 Billion Robotic Army Network Passes First Big Test. Kinda.</source>
    </item>
    <item>
      <title><![CDATA[GAO: Stolen U.S. military gear sold on eBay, Craigslist]]></title>
      <link>http://securityratty.com/article/b7ea14613dc269c8c162594ff3be8393</link>
      <guid>http://securityratty.com/article/b7ea14613dc269c8c162594ff3be8393</guid>
      <description><![CDATA[Stolen and sensitive U.S. military equipment, including body armor, night vision goggles and gear to protect against nuclear or biochemical warfare, are being sold on Craigslist and eBay Inc., a GAO...]]></description>
      <content:encoded><![CDATA[Stolen and sensitive U.S. military equipment, including body armor, night vision goggles and gear to protect against nuclear or biochemical warfare, are being sold on Craigslist and eBay Inc., a GAO report says.
			
			<div style="margin-top:20" />
			<table border="1" BORDERCOLOR="#0033CC" cellspacing="0" cellpadding="2">
				<tr valign="top" align="left">
					<td>
						<table border="0" cellspacing="3" cellpadding="2" width="100%">
			
			
		  
		<tr> 
		<tr>
      <td width="*">
				<font face="Arial,Helvetica,Geneva,Sans-serif,sans-serif" size="-1">
				<p>	
			
			<a href="http://rsslinks.industrybrains.com/click?sid=93&scid=10069&rqctid=589&lid=477408&cid=134557&pr=2&tstamp=20080415000000&url=http://clk.atdmt.com/CNT/go/ndstrwir0090000141cnt/direct/01/" target=_blank><strong>Understanding VPN Technology Choices</strong></a></p>
				<td align="right">
					<font face="Arial,Helvetica,Geneva,Sans-serif,sans-serif" COLOR="#0033CC" size="-1"><p>Advertisement</p></font>
				</td>
				</tr>
				<tr><td colspan="2"><font face="Arial,Helvetica,Geneva,Sans-serif,sans-serif" size="-1"><p>Knowing the VPN options can help a manager work more effectively with available technologies.
			
				</p>
				</font>
		 	</td>
     </tr>
		 
		 
			
						</table>
					</td>
				</tr>
			</table>
			<div style="margin-top:20" />
			
			]]></content:encoded>
      <pubDate>Sun, 13 Apr 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vpn technology choices">vpn technology choices</category>
      <category domain="http://securityratty.com/tag/night vision goggles">night vision goggles</category>
      <category domain="http://securityratty.com/tag/ebay">ebay</category>
      <category domain="http://securityratty.com/tag/military equipment">military equipment</category>
      <category domain="http://securityratty.com/tag/craigslist">craigslist</category>
      <category domain="http://securityratty.com/tag/body armor">body armor</category>
      <category domain="http://securityratty.com/tag/vpn options">vpn options</category>
      <category domain="http://securityratty.com/tag/gao report">gao report</category>
      <category domain="http://securityratty.com/tag/biochemical warfare">biochemical warfare</category>
      <source url="http://www.networkworld.com/news/2008/041408-gao-stolen-us-military-gear.html?fsrc=rss-security">GAO: Stolen U.S. military gear sold on eBay, Craigslist</source>
    </item>
  </channel>
</rss>
