<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: omb]]></title>
    <link>http://securityratty.com/tag/omb</link>
    <description></description>
    <pubDate>Tue, 26 Feb 2008 07:44:08 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[No, FISMA Doesnt Require That, Silly Product Pushers]]></title>
      <link>http://securityratty.com/article/e7338459ca02abf727eaf2b68ac02e51</link>
      <guid>http://securityratty.com/article/e7338459ca02abf727eaf2b68ac02e51</guid>
      <description><![CDATA[Post #9678291 on why people dont understand what FISMA really is : Secure64 DNSSEC Press Releases
FISMA Act encourages U.S. government agencies to configure their DNS servers to the DNSSEC security...]]></description>
      <content:encoded><![CDATA[<p>Post #9678291 on <a href="http://www.guerilla-ciso.com/archives/150" target="_blank">why people don&#8217;t understand what FISMA really is</a>:  <a href="http://www.domaininformer.com/news/press/310708DNSSEC.html" target="_blank">Secure64 DNSSEC Press Releases</a>.</p>
<p style="padding-left: 30px;"><em>&#8220;FISMA Act encourages U.S. government agencies to configure their DNS servers to the DNSSEC security specifications set by the National Institute of Standards and Technology, and it has been reported that the federal government<span id="bwanpa5">’</span>s Office of Management and Budget (OMB) plans to begin enforcing DNSSEC requirements through an auditing process, setting the standard for DNS best practices.&#8221;</em></p>
<p>Yep, if you stamp FISMA on it, people will buy it, maybe in your PR department&#8217;s wettest and wildest dreams.  Guys, it&#8217;s been 6 years, that kind of marketing doesn&#8217;t work nowadays, mostly because we spent ourselves into oblivion buying junkware similar to yours and now we&#8217;re all jaded.</p>
<p>Now don&#8217;t get me wrong, DNSSEC is a good thing, especially this month.  But there is something I need to address:  FISMA requires good security management with a dozen or so key indicators, not a solution down to the technical level.  Allusions to OMB are just FUD, FUD, and more FUD because unless it&#8217;s in a memo to agency heads, it&#8217;s all posturing&#8211;something everybody in this town knows how to do very well.  OMB would rather stay out of mandating DNSSEC and maybe give a &#8220;due date&#8221; once NIST has a final standard.</p>
<p>My one word of wisdom for today:  anybody who tries to sell a product and <a href="http://www.guerilla-ciso.com/archives/216" target="_blank">uses FISMA as the &#8220;compelling event&#8221; has no clue what they&#8217;re talking about</a>.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Del.icio.us" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to digg" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to reddit" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers&amp;url=http://www.guerilla-ciso.com/archives/440&amp;version=0.7" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Feed Me Links" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/440" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Technorati" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/440&amp;t=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Yahoo My Web" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Stumble Upon" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Google Bookmarks" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/440" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Squidoo" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/440" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Bloglines" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=2mnw8J"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=2mnw8J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=HAXdPj"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=HAXdPj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/351599310" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 31 Jul 2008 10:36:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fisma">fisma</category>
      <category domain="http://securityratty.com/tag/fisma requires">fisma requires</category>
      <category domain="http://securityratty.com/tag/fisma act encourages">fisma act encourages</category>
      <category domain="http://securityratty.com/tag/stamp fisma">stamp fisma</category>
      <category domain="http://securityratty.com/tag/dnssec">dnssec</category>
      <category domain="http://securityratty.com/tag/dnssec requirements">dnssec requirements</category>
      <category domain="http://securityratty.com/tag/dns">dns</category>
      <category domain="http://securityratty.com/tag/standard">standard</category>
      <category domain="http://securityratty.com/tag/dns servers">dns servers</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/351599310/440">No, FISMA Doesnt Require That, Silly Product Pushers</source>
    </item>
    <item>
      <title><![CDATA[Links List 7.25.08]]></title>
      <link>http://securityratty.com/article/630a1fc26c11310563527f51eaebf464</link>
      <guid>http://securityratty.com/article/630a1fc26c11310563527f51eaebf464</guid>
      <description><![CDATA[The Wall Street Journal reports that the military is taking Tech Lessons . It seems that over the last few years, the DISA CIO has been visiting different tech companies to learn about cutting-edge...]]></description>
      <content:encoded><![CDATA[<p>The Wall Street Journal reports that the military is taking “<a href="http://blogs.wsj.com/biztech/2008/07/24/the-military-takes-tech-lessons/?mod=djemTECH" target="_blank">Tech Lessons</a>”. It seems that over the last few years, the DISA CIO has been visiting different tech companies to learn about cutting-edge technologies that might be able to help soldiers in the battlefield. CIO Garing identified social networks and mashups as great technologies for smaller projects with potentially more immediate impact than the traditional years-long IT projects of the past. He should check out NAPA and the Collaboration Project [link to Dan Munz Q&amp;A] which highlights just how government agencies and orgs are already doing what he’s talking about.
<p>Just what I was waiting for, <a href="http://news.cnet.com/8301-13505_3-9996318-16.html" target="_blank">open source takes on cloud computing</a>. <img src='http://blog.sciencelogic.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />
<p>We had a very interesting call this week with analyst firm, <a href="http://www.the451group.com/report_view/report_view.php?entity_id=54199" target="_blank">The 451 Group</a>, about the cloud and who is really doing what in this space now. Trying to separate the hype from reality, just like everyone else.
<p><a href="http://vmblog.com/archive/2008/07/23/forbes-interviews-vmware-ceo-paul-maritz-after-financial-analyst-call.aspx" target="_blank">After a disappointing (to analysts and the street) financial analyst call on Tuesday, VMware&#8217;s stock reached an all time low, almost back to the IPO stage</a>. In a follow-up interview, Forbes asked the new CEO what he thinks about the stock price, the analysts saying VMware doesn&#8217;t have a solid or innovative growth plan for the future, and whether <a href="http://vmware.com/" target="_blank">VMware</a> should be <a href="http://www.forbes.com/2008/07/22/vmware-maritz-qa-tech-intel-cx_wt_0722techvmware.html" target="_blank">part of EMC or not</a> (their backhand way of bringing up the whole Diane Greene thing…he didn’t fall for it).&nbsp;
<p>Wait for it…wait for it…we have been waiting for it. VMware announced plans to <a href="http://www.eweek.com/c/a/Infrastructure/VMwares-ESXi-Hypervisor-for-Free/?kc=EWKNLNAV07242008STR1" target="_blank">launch a free version of its ESXI hypervisor</a> starting July 28. I have to question the timing on this one. <a href="http://redmondmag.com/news/rss.asp?editorialsid=10067" target="_blank">Why didn’t they do this before Hyper-v came out</a> and try to at least undercut the Microsoft announcement? VMware is and should be the leader in this space but they act like they’re playing from behind. And to Wall Street, perception counts for a lot.
<p>Surprisingly, there hasn’t been a lot of coverage after the June 2008 OMB mandate on IPv6 readiness. But one interesting follow-up, <a href="http://www.networkworld.com/news/2008/072108-ipv6nat.html" target="_blank">a feature is set to be added to IPv6 which the upgrade was supposed to eliminate</a>. One of the <a href="http://www.circleid.com/posts/nat_just_say_no/">design goals</a> for IPv6 was that it would rid the Internet of network address translation (NAT), gateways that match increasingly scarce public IPv4 addresses with private IPv4 addresses used inside corporations, government agencies and other organizations.&nbsp; NAT adds complexity and cost, but due to the length of time it’s taken to migrate from IPv4 to IPv6, engineers may create special NAT devices to translate between IPv4-only and IPv6-only hosts and hopefully nudge along the transition to IPv6. IEEE is all set to meet on this topic later this month.</p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Links+List+7.25.08&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Flinks-list-72508%2F07%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Fri, 25 Jul 2008 08:28:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ipv6-only hosts">ipv6-only hosts</category>
      <category domain="http://securityratty.com/tag/ipv6">ipv6</category>
      <category domain="http://securityratty.com/tag/ipv6 readiness">ipv6 readiness</category>
      <category domain="http://securityratty.com/tag/nat">nat</category>
      <category domain="http://securityratty.com/tag/special nat devices">special nat devices</category>
      <category domain="http://securityratty.com/tag/financial analyst call">financial analyst call</category>
      <category domain="http://securityratty.com/tag/government agencies">government agencies</category>
      <category domain="http://securityratty.com/tag/ipv4 addresses">ipv4 addresses</category>
      <category domain="http://securityratty.com/tag/ipv4">ipv4</category>
      <source url="http://blog.sciencelogic.com/links-list-72508/07/2008">Links List 7.25.08</source>
    </item>
    <item>
      <title><![CDATA[FISMA Reporting Guidance for 2008]]></title>
      <link>http://securityratty.com/article/fcf546cc4af6858f0a8c433f0c7dd524</link>
      <guid>http://securityratty.com/article/fcf546cc4af6858f0a8c433f0c7dd524</guid>
      <description><![CDATA[Its out. Check it out in the OMB Memo. Ill most likely have something pithy to say when I look at it a little bit more, but it looks like its mostly the same as last year
Anyway, you can get it here,...]]></description>
      <content:encoded><![CDATA[<p>It&#8217;s out.  Check it out in the OMB Memo.  I&#8217;ll most likely have something pithy to say when I look at it a little bit more, but it looks like it&#8217;s mostly the same as last year.</p>
<p>Anyway, <a href="http://www.whitehouse.gov/omb/memoranda/fy2008/m08-21.pdf" target="_blank">you can get it here, it&#8217;s OMB Memo 08-21</a>.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/437&amp;title=FISMA+Reporting+Guidance+for+2008" title="Add 'FISMA Reporting Guidance for 2008' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'FISMA Reporting Guidance for 2008' to Del.icio.us" alt="Add 'FISMA Reporting Guidance for 2008' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/437&amp;title=FISMA+Reporting+Guidance+for+2008" title="Add 'FISMA Reporting Guidance for 2008' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'FISMA Reporting Guidance for 2008' to digg" alt="Add 'FISMA Reporting Guidance for 2008' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/437&amp;title=FISMA+Reporting+Guidance+for+2008" title="Add 'FISMA Reporting Guidance for 2008' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'FISMA Reporting Guidance for 2008' to reddit" alt="Add 'FISMA Reporting Guidance for 2008' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=FISMA+Reporting+Guidance+for+2008&amp;url=http://www.guerilla-ciso.com/archives/437&amp;version=0.7" title="Add 'FISMA Reporting Guidance for 2008' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'FISMA Reporting Guidance for 2008' to Feed Me Links" alt="Add 'FISMA Reporting Guidance for 2008' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/437" title="Add 'FISMA Reporting Guidance for 2008' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'FISMA Reporting Guidance for 2008' to Technorati" alt="Add 'FISMA Reporting Guidance for 2008' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/437&amp;t=FISMA+Reporting+Guidance+for+2008" title="Add 'FISMA Reporting Guidance for 2008' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'FISMA Reporting Guidance for 2008' to Yahoo My Web" alt="Add 'FISMA Reporting Guidance for 2008' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/437&amp;title=FISMA+Reporting+Guidance+for+2008" title="Add 'FISMA Reporting Guidance for 2008' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'FISMA Reporting Guidance for 2008' to Stumble Upon" alt="Add 'FISMA Reporting Guidance for 2008' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/437&amp;title=FISMA+Reporting+Guidance+for+2008" title="Add 'FISMA Reporting Guidance for 2008' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'FISMA Reporting Guidance for 2008' to Google Bookmarks" alt="Add 'FISMA Reporting Guidance for 2008' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/437" title="Add 'FISMA Reporting Guidance for 2008' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'FISMA Reporting Guidance for 2008' to Squidoo" alt="Add 'FISMA Reporting Guidance for 2008' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/437" title="Add 'FISMA Reporting Guidance for 2008' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'FISMA Reporting Guidance for 2008' to Bloglines" alt="Add 'FISMA Reporting Guidance for 2008' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=vvElhJ"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=vvElhJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=2AYEVj"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=2AYEVj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/339069843" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 11:02:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/omb memo">omb memo</category>
      <category domain="http://securityratty.com/tag/check">check</category>
      <category domain="http://securityratty.com/tag/bookmark">bookmark</category>
      <category domain="http://securityratty.com/tag/bit">bit</category>
      <category domain="http://securityratty.com/tag/pithy">pithy</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/339069843/437">FISMA Reporting Guidance for 2008</source>
    </item>
    <item>
      <title><![CDATA[Times Up IPv6 OMB Mandate]]></title>
      <link>http://securityratty.com/article/cc832c2648fa421babda1922e9cba906</link>
      <guid>http://securityratty.com/article/cc832c2648fa421babda1922e9cba906</guid>
      <description><![CDATA[Three years ago, the OMB set a June 2008 deadline by which all agencies infrastructure (network backbones) must be using IPv6 and agency networks must interface with this infrastructure
Agencies are...]]></description>
      <content:encoded><![CDATA[<p>Three years ago, the OMB set a June 2008 deadline “by which all agencies’ infrastructure (network backbones) <a href="http://www.whitehouse.gov/omb/memoranda/fy2005/m05-22.pdf" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.whitehouse.gov');" target="_blank">must be using IPv6 and agency networks must interface with this infrastructure</a>.”
<p>Agencies are supposed to demonstrate that they can:
<ul>
<li>Transmit IPv6 traffic from the Internet and external peers, through the core (WAN), to the LAN.</li>
<li>Transmit IPv6 traffic from the LAN, through the core (WAN), out to the Internet and external peers.</li>
<li>Transmit IPv6 traffic from the LAN, through the core (WAN), to another LAN (or another node on the same LAN).</li>
</ul>
<p><em>(</em><a href="http://www.whitehouse.gov/omb/egov/documents/IPv6_FAQs.pdf" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.whitehouse.gov');" target="_blank"><em>Source: OMB IPv6 FAQs</em></a><em>)</em></p>
<p>One year ago, the OMB reviewed the Enterprise Architecture Assessment Framework results and found that six of the twenty-four agencies were on track to achieve the June deadline. Two months ago, there was a <a href="http://www.networkworld.com/news/2008/040208-ipv6-feds.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.networkworld.com');" target="_blank">good article by Carolyn Marsan Duffy about the status of compliance</a>. Take a look at this article because it seemed like there was a lot of backpedaling going on about meeting the date – using phrases like “we don’t like the term mandate” and “more of a recommendation than a mandate.” At the time, only three agencies were in compliance.
<p>Duffy just wrote an updated article, “<a href="http://www.networkworld.com/news/2008/062608-ipv6-federal-government.html?page=1" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.networkworld.com');" target="_blank">Feds say they have aced IPv6 deadline</a>”, and suddenly two months later, all lights seem green. As of June 24, ten of the twenty-four agencies sent emails to the OMB stating that “they have successfully transmitted IPv6 packets”. Fourteen still need to report in, but none have asked for an extension. And all of it was done through the regular tech refresh budget over the past three years. So if this is true, kudos to the feds!
<p>Right around the time of the first not-so-rosy article, we <a href="http://blog.sciencelogic.com/whats-in-a-number/04/2008"  target="_blank">ran a survey at FOSE</a>, the big federal government IT show. We asked attendees if their agencies would be ready by the deadline:
<ul>
<li>33% said they would be ready</li>
<li>6% said they were already there</li>
<li>33% said they would NOT be ready</li>
<li>About a quarter didn’t know</li>
</ul>
<p>What was really interesting is that we asked this same question in 2007, and the audience was equally split (yes/no) on whether or not their agencies would meet the mandate – 1 in 5 (2007) instead of 1 in 3 (2008).
<p>So what can explain these numbers? Surprisingly, out of the attendees we talked to, only 65% of them said that IPv6 is important to their operations, making it second to last on the list of IT priorities covered by the survey. Maybe the answer lies in the relative “unimportance” of the milestone – that just the network backbones (and the routers supporting them) be capable of passing IPv6 packets. The true test for government IT workers will be when actual IPv6 applications must be supported which will impact networks, systems, application and monitoring tools throughout the government.
<p>So was this a nice checklist item for the Bush administration? This initial deadline is the only one for IPv6 mandates from the current OMB incarnation. Actually running IPv6 applications, that’s a whole ‘nother story, apparently for a new administration.</p>
<p><a href="http://sharethis.com/item?&wp=2.5.1&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Time%26rsquo%3Bs+Up+%26ndash%3B+IPv6+OMB+Mandate&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Ftimes-up-ipv6-omb-mandate%2F06%2F2008" onclick="javascript:pageTracker._trackPageview('/outbound/article/sharethis.com');">ShareThis</a></p>]]></content:encoded>
      <pubDate>Mon, 30 Jun 2008 15:27:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ipv6">ipv6</category>
      <category domain="http://securityratty.com/tag/aced ipv6 deadline">aced ipv6 deadline</category>
      <category domain="http://securityratty.com/tag/ipv6 packets">ipv6 packets</category>
      <category domain="http://securityratty.com/tag/transmit ipv6 traffic">transmit ipv6 traffic</category>
      <category domain="http://securityratty.com/tag/omb">omb</category>
      <category domain="http://securityratty.com/tag/ipv6 applications">ipv6 applications</category>
      <category domain="http://securityratty.com/tag/actual ipv6 applications">actual ipv6 applications</category>
      <category domain="http://securityratty.com/tag/agencies">agencies</category>
      <category domain="http://securityratty.com/tag/twenty-four agencies">twenty-four agencies</category>
      <source url="http://blog.sciencelogic.com/times-up-ipv6-omb-mandate/06/2008">Times Up IPv6 OMB Mandate</source>
    </item>
    <item>
      <title><![CDATA[Civilians Ask Whats With All the Privacy Act Kerfluffle?]]></title>
      <link>http://securityratty.com/article/d5daa36201f5ba38464b919d3abcc3dc</link>
      <guid>http://securityratty.com/article/d5daa36201f5ba38464b919d3abcc3dc</guid>
      <description><![CDATA[And by kerfluffle, I mean these articles
GAOPrivacy Report
Technology Liberation Front
Center for Democracy and Technology
And how about an analysis of the Privacy Act from DOJ for background reasons...]]></description>
      <content:encoded><![CDATA[<p>And by &#8220;kerfluffle&#8221;, I mean these articles:</p>
<ul>
<li><a href="http://www.gao.gov/new.items/d08536.pdf" target="_blank">GAO Privacy Report</a></li>
<li><a href="http://techliberation.com/2008/06/20/gao-issues-report-on-privacy/" target="_blank">Technology Liberation Front</a></li>
<li><a href="http://www.cdt.org/publications/policyposts/2008/10" target="_blank">Center for Democracy and Technology</a></li>
<li>And how about an <a href="http://www.usdoj.gov/oip/04_7_1.html" target="_blank">analysis of the Privacy Act </a>from DOJ for background reasons?</li>
</ul>
<p>Well, let&#8217;s talk about how privacy and the Government works with Uncle Rybolov (please hold the references to Old Weird Uncle Harold until we&#8217;re through with today&#8217;s lesson please).</p>
<p>We have a law, the Privacy Act of 1974.  Think about it, what significant privacy-wrenching activities happened just a couple of years prior?  Can we say &#8220;<a href="http://en.wikipedia.org/wiki/Watergate_scandal" target="_blank">Watergate Scandal</a>&#8220;?  Can we say &#8220;<a href="http://en.wikipedia.org/wiki/Church_Committee" target="_blank">Church Committee</a>&#8220;?  Suffice it to say, the early 1970s was an era filled with privacy issues and is where most of our privacy policy and law comes from.  Remember this for later:  this was the 1970&#8217;s!</p>
<p>Each of the various sections of the Privacy Act deals with a particular data type.  For instance, Title 13 refers to data collected by the Census Bureau when they&#8217;ll go count everybody in 2010.</p>
<p>The Privacy Act talks about the stuff that everybody in the Government needs to know about:  how you&#8217;re going to jail if you disclose this information to a third party.  For those of you who have ever been in the military or had to fill out a government form that required your social security number, the light in the back of your head should be going off right now because they all have the warnings about disclosure.</p>
<p style="text-align: center;"><em><img src="http://farm3.static.flickr.com/2095/2054565713_1d20d5f90a.jpg?v=0" alt="Huts and Chairs Need Privacy Too" width="376" height="500" /></em></p>
<p style="text-align: center;"><em>Remember to respect the privacy of the beach huts and chairs photo by </em><a href="http://www.flickr.com/photos/joeshlabotnik/" target="_blank"><em>Joe Shlabotnik</em></a></p>
<p>When it comes to IT security, the Privacy Act works like this:</p>
<ul>
<li>You realize a need to collect PII on individuals.</li>
<li>You do a privacy impact assessment to determine if you can legally collect this data and what the implications of collecting the data are.</li>
<li>You build rules about what you can do normally with the data once you have collected it.  This is called the &#8220;routine use&#8221;.</li>
<li>You write a report on how, why, and about whom you&#8217;re collecting this information.  This is known as the &#8220;System of Record Notice&#8221;.</li>
<li>You file this report with the Federal Register to notify the public.</li>
<li>This IT system becomes the authoritative source of that information.</li>
</ul>
<p>IE, no secret dossiers on the public.  We&#8217;ll suspend our disbelief in FISA for a minute, this conversation is about non-intelligence data collection.</p>
<p>Now the problem with all this is that if you stop and think about it, I was 1 year old when the Privacy Act was signed.  Our technology for information sharing has gone above and beyond that.  We can exchange data much much much more quickly than the Privacy Act originally intended.  As a result, we have PII everywhere.  Most of the PII is needed to provide services to the citizens, except that it&#8217;s a royal PITA to protect it all, and that&#8217;s the lesson of the past 2 years in Government data breaches.</p>
<p>Problems with the Privacy Act:</p>
<ul>
<li>The SORN is hard to read and is not easy to find.</li>
<li>Privacy Act data given to contractors or &#8220;business partners&#8221; (aka, state and local government or NGOs) does not have the same amount of oversight as it does in the Government.</li>
<li>Data given to the Government by a third-party is not susceptible to the Privacy Act because the Government did not collect it.  Wow, lots of room for abuse&#8211;waterboarding-esque abuse.</li>
<li>Privacy Act procedures were written for mainframes.  Mainframes have been replaced with clusters of servers.  It&#8217;s easy to add a new server to this setup.  Yes, this <strong>is</strong> a feature.</li>
<li>If you build a new system with the same data types and routine uses as an already existing SORN, you can &#8220;piggyback&#8221; on that existing SORN.</li>
<li>It&#8217;s very easy to use the data in a way that isn&#8217;t on your &#8220;routine use&#8221; statement, thus breaking the entire privacy system.</li>
</ul>
<p>Obviously, at this point, you should have gotten the hint that maybe we need to revise the Privacy Act.  I think GAO and OMB would agree with you here.</p>
<p>So, what alternatives do we have to the existing system?</p>
<ul>
<li>Make blanket data types and do a PIA and SORN on them regardless of where that data lies.</li>
<li>Bend the Paperwork Reduction act and OMB guidance so that we don&#8217;t collect as much information.</li>
<li>Make the Privacy Act more specific on what should be in SORN, PIA, and routine use statements.</li>
</ul>
<p>To be honest, it seems like most of this is already in place, it just needs to get tuned a little bit so we&#8217;re doing the right things.  Once again, the scale of the Government&#8217;s IT infrastructure is keeping us from doing the right thing:    there isn&#8217;t enough time in the day to do PIAs on a per-server basis or to keep track of every little bit of data.  You have to automate our privacy efforts in some fashion.</p>
<p>And this is why, dear readers, I think the Government needs DLP solutions more than the private sector does.  Too bad the DLP vendors are stuck on credit cards and social security numbers.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/424&amp;title=Civilians+Ask+%26%238220%3BWhat%26%238217%3Bs+With+All+the+Privacy+Act+Kerfluffle%3F%26%238221%3B" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Del.icio.us" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/424&amp;title=Civilians+Ask+%26%238220%3BWhat%26%238217%3Bs+With+All+the+Privacy+Act+Kerfluffle%3F%26%238221%3B" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to digg" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/424&amp;title=Civilians+Ask+%26%238220%3BWhat%26%238217%3Bs+With+All+the+Privacy+Act+Kerfluffle%3F%26%238221%3B" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to reddit" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Civilians+Ask+%26%238220%3BWhat%26%238217%3Bs+With+All+the+Privacy+Act+Kerfluffle%3F%26%238221%3B&amp;url=http://www.guerilla-ciso.com/archives/424&amp;version=0.7" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Feed Me Links" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/424" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Technorati" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/424&amp;t=Civilians+Ask+%26%238220%3BWhat%26%238217%3Bs+With+All+the+Privacy+Act+Kerfluffle%3F%26%238221%3B" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Yahoo My Web" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/424&amp;title=Civilians+Ask+%26%238220%3BWhat%26%238217%3Bs+With+All+the+Privacy+Act+Kerfluffle%3F%26%238221%3B" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Stumble Upon" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/424&amp;title=Civilians+Ask+%26%238220%3BWhat%26%238217%3Bs+With+All+the+Privacy+Act+Kerfluffle%3F%26%238221%3B" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Google Bookmarks" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/424" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Squidoo" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/424" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Bloglines" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=iZflJI"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=iZflJI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=SHBmQi"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=SHBmQi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/320829287" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 17:51:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/privacy act">privacy act</category>
      <category domain="http://securityratty.com/tag/privacy act procedures">privacy act procedures</category>
      <category domain="http://securityratty.com/tag/privacy act deals">privacy act deals</category>
      <category domain="http://securityratty.com/tag/privacy act data">privacy act data</category>
      <category domain="http://securityratty.com/tag/privacy">privacy</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data lies">data lies</category>
      <category domain="http://securityratty.com/tag/privacy act talks">privacy act talks</category>
      <category domain="http://securityratty.com/tag/privacy policy">privacy policy</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/320829287/424">Civilians Ask Whats With All the Privacy Act Kerfluffle?</source>
    </item>
    <item>
      <title><![CDATA[Security Certification Rules Could Shake Up IT Mgmt]]></title>
      <link>http://securityratty.com/article/4f82425b41fbf0177d2fd2faa45c0e29</link>
      <guid>http://securityratty.com/article/4f82425b41fbf0177d2fd2faa45c0e29</guid>
      <description><![CDATA[This seems to a well intentioned but, misguided attempt by the Office of Management and Budget. They are attempting to establish minimum requirements for professional certification for IT workers
Hmm...]]></description>
      <content:encoded><![CDATA[<p>This seems to a well intentioned but, misguided attempt by the Office of Management and Budget. They are attempting to establish minimum requirements for professional certification for IT workers. </p>
<p>Hmm.</p>
<p>From GCN:</p>
<blockquote><p>“This is a change we have not faced in the IT security industry before,” he added.</p>
<p>The closest parallel has been in the Defense Department, which anticipated OMB’s reaction in this area. DOD’s Directive 8570 on information assurance, approved in December 2005, requires all of the department’s information assurance workers to obtain an accredited commercial certification in computer security. DOD has approved 13 certifications for the directive.</p>
<p>The DOD requirement already has thrown what one conference attendee called a giant monkey wrench into the IT security manpower market.</p>
<p>“If OMB issues a similar requirement, it’s going to throw the supply and demand curve even more out of balance,” he said.</p>
<p>Datesman agreed, saying it probably would take years for the supply of certified workers to catch up with demand. A CISSP certification requires five years’ experience. “You don’t mint them out of college,” he said. </p></blockquote>
<p>OK, this is where this trolley leaves the track. I have met CISSP certified folks that I would wager they&#8217;d be lucky to fight their way out of a wet paper bag. &#8220;Don&#8217;t mint them out of college&#8221; is a phrase that I&#8217;d argue. I would offer that the ISC2 should start auditing certified members. The validity of the CISSP cert is becoming diluted in the eyes of the market.</p>
<p>A picture is worth a thousand words.</p>
<p><center><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2007/08/notacissp.jpg" alt="Myrcurial at Defcon" /></center></p>
<p>It&#8217;s great for the mandatory HR tick box but, how many of these folks actually have the ability? Sure they can memorize some flash cards and pass a test but, are they effective? Some, not so much.</p>
<p>On the face of it this is a good idea. </p>
<p>Like all good intentions, they make great paving stones on the road to hell. </p>
<p><a href="http://www.gcn.com/online/vol1_no1/46543-1.html">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=qIkGql"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=qIkGql" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=CehK5I"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=CehK5I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=CQohOi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=CQohOi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=xF5oKi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=xF5oKi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=qY7Wui"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=qY7Wui" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=TNh3Mi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=TNh3Mi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/320492452" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 08:33:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cissp cert">cissp cert</category>
      <category domain="http://securityratty.com/tag/cissp">cissp</category>
      <category domain="http://securityratty.com/tag/cissp certification requires">cissp certification requires</category>
      <category domain="http://securityratty.com/tag/requires">requires</category>
      <category domain="http://securityratty.com/tag/market">market</category>
      <category domain="http://securityratty.com/tag/security manpower market">security manpower market</category>
      <category domain="http://securityratty.com/tag/giant monkey wrench">giant monkey wrench</category>
      <category domain="http://securityratty.com/tag/dod requirement">dod requirement</category>
      <category domain="http://securityratty.com/tag/establish minimum requirements">establish minimum requirements</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/320492452/">Security Certification Rules Could Shake Up IT Mgmt</source>
    </item>
    <item>
      <title><![CDATA[OMB Makes it to LOLCAT Fame]]></title>
      <link>http://securityratty.com/article/21d16bc0594e3e5f829a7176005093f6</link>
      <guid>http://securityratty.com/article/21d16bc0594e3e5f829a7176005093f6</guid>
      <description><![CDATA[Love them or hate them, OMB has the unenviable job of setting executive-branch policy through their memos. Not a place I would ever want to be

Bookmark...]]></description>
      <content:encoded><![CDATA[<p>Love them or hate them, OMB has the unenviable job of setting executive-branch policy through their memos.  Not a place I would ever want to be.</p>
<p style="text-align: center;"><a href="http://mine.icanhascheezburger.com/view.aspx?ciid=1143320"><img src="http://images.icanhascheezburger.com/completestore/2008/5/14/ombsendznothe128552894108101786.jpg" alt="funny pictures" /></a></p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/394&amp;title=OMB+Makes+it+to+LOLCAT+Fame" title="Add 'OMB Makes it to LOLCAT Fame' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'OMB Makes it to LOLCAT Fame' to Del.icio.us" alt="Add 'OMB Makes it to LOLCAT Fame' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/394&amp;title=OMB+Makes+it+to+LOLCAT+Fame" title="Add 'OMB Makes it to LOLCAT Fame' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'OMB Makes it to LOLCAT Fame' to digg" alt="Add 'OMB Makes it to LOLCAT Fame' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/394&amp;title=OMB+Makes+it+to+LOLCAT+Fame" title="Add 'OMB Makes it to LOLCAT Fame' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'OMB Makes it to LOLCAT Fame' to reddit" alt="Add 'OMB Makes it to LOLCAT Fame' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=OMB+Makes+it+to+LOLCAT+Fame&amp;url=http://www.guerilla-ciso.com/archives/394&amp;version=0.7" title="Add 'OMB Makes it to LOLCAT Fame' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'OMB Makes it to LOLCAT Fame' to Feed Me Links" alt="Add 'OMB Makes it to LOLCAT Fame' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/394" title="Add 'OMB Makes it to LOLCAT Fame' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'OMB Makes it to LOLCAT Fame' to Technorati" alt="Add 'OMB Makes it to LOLCAT Fame' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/394&amp;t=OMB+Makes+it+to+LOLCAT+Fame" title="Add 'OMB Makes it to LOLCAT Fame' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'OMB Makes it to LOLCAT Fame' to Yahoo My Web" alt="Add 'OMB Makes it to LOLCAT Fame' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/394&amp;title=OMB+Makes+it+to+LOLCAT+Fame" title="Add 'OMB Makes it to LOLCAT Fame' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'OMB Makes it to LOLCAT Fame' to Stumble Upon" alt="Add 'OMB Makes it to LOLCAT Fame' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/394&amp;title=OMB+Makes+it+to+LOLCAT+Fame" title="Add 'OMB Makes it to LOLCAT Fame' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'OMB Makes it to LOLCAT Fame' to Google Bookmarks" alt="Add 'OMB Makes it to LOLCAT Fame' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/394" title="Add 'OMB Makes it to LOLCAT Fame' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'OMB Makes it to LOLCAT Fame' to Squidoo" alt="Add 'OMB Makes it to LOLCAT Fame' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/394" title="Add 'OMB Makes it to LOLCAT Fame' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'OMB Makes it to LOLCAT Fame' to Bloglines" alt="Add 'OMB Makes it to LOLCAT Fame' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=05gPhI"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=05gPhI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=uVTrui"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=uVTrui" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/300591773" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 29 May 2008 10:41:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/omb">omb</category>
      <category domain="http://securityratty.com/tag/unenviable job">unenviable job</category>
      <category domain="http://securityratty.com/tag/memos">memos</category>
      <category domain="http://securityratty.com/tag/bookmark">bookmark</category>
      <category domain="http://securityratty.com/tag/policy">policy</category>
      <category domain="http://securityratty.com/tag/love">love</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/300591773/394">OMB Makes it to LOLCAT Fame</source>
    </item>
    <item>
      <title><![CDATA[FISMA Report Cards IssuedResponse is Rote by Now]]></title>
      <link>http://securityratty.com/article/c4fec28ddd80fa55d26b93033e54c7fc</link>
      <guid>http://securityratty.com/article/c4fec28ddd80fa55d26b93033e54c7fc</guid>
      <description><![CDATA[Yay, FISMA report card for 2007 has been issued. You can go check it out here . I cant believe it, but DHS scored a B against all odds
And of course, by now the response to the report card is all...]]></description>
      <content:encoded><![CDATA[<p>Yay, FISMA report card for 2007 has been issued.  You can go <a href="http://republicans.oversight.house.gov/media/PDFs/Reports/FY2007FISMAReportCard.pdf" target="_blank">check it out here</a>.  I can&#8217;t believe it, but DHS scored a &#8220;B&#8221; against all odds. =)</p>
<p>And of course, by now the response to the report card is all rote&#8211;everybody wonders what the letters really mean:</p>
<ul>
<li><a href="http://www.scmagazineus.com/Federal-agencies-FISMA-grade-up-slightly/article/110375/" target="_blank">SC Magazine</a></li>
<li><a href="http://news.idg.no/cw/art.cfm?id=08F0A29C-17A4-0F78-3113197D5C06A6C5" target="_blank">IDG</a></li>
<li><a href="http://www.itbusinessedge.com/blogs/hdw/?p=2238" target="_blank">IT Business Edge</a></li>
<li><a href="http://federaltimes.com/index.php?S=3539078" target="_blank">Federal Times</a></li>
<li><a href="http://blog.washingtonpost.com/securityfix/2008/05/govt_earns_grade_of_c_for_comp.html?nav=rss_blog" target="_blank">Washington Post</a></li>
<li><a href="http://www.securityfocus.com/brief/741" target="_blank">Security Focus</a></li>
</ul>
<p>Yeah, yeah, I guess it just goes to prove what we say about the classified world: the people who know don&#8217;t talk and the people who talk don&#8217;t know.  In this case, everybody attacks the metric because, well, it&#8217;s a bad metric&#8211;what action are we supposed to take because of what the results are?  It&#8217;s also pretty much ignored by this point anyway except for the witty sound bites from some of my &#8220;favorite people&#8221;, so it&#8217;s nothing to get all hot and bothered about.  The GAO and OMB reports that <a href="http://www.guerilla-ciso.com/archives/348" target="_blank">I&#8217;ve covered in much detail </a>are much better and have a pretty decent level of analysis.</p>
<p>But fer chrissakes, the report card is issued by Congress, how much detail do you think it will ever contain?  =)</p>
<p>My rapidly expanding queue of pet peeves about this time of the year:</p>
<ul>
<li><strong>People who think that FISMA is just a report card and that we should re-examine how we measure security:</strong>  the grades are not even required by the law, it&#8217;s just technique and we can change that easily enough.</li>
<li><strong>People who criticize but do not offer an alternative:</strong>  even if you had an alternative plan, the environment for execution still involves the same IT assets and the same front-line employees.</li>
<li><strong>People who don&#8217;t understand enterprise-wide security much less a federation of semi-independent enterprises:</strong> it&#8217;s the nature of government-wide security metrics that they&#8217;ll be indicators which can be faked.</li>
<li><strong>Sound bites from people who have never implemented any aspect of FISMA:</strong>  come on, SANS and Gartner?  GAO and the Cyber Security Industry Alliance are a little bit better but taken out of context.</li>
<li><strong>Nobody ever asks me for a quote on FISMA numminess:</strong>  I&#8217;ll be pouting for the rest of the week, TYVM.  =)</li>
</ul>
<p>Not that I&#8217;m the world&#8217;s best expert at fact-checking, but something caught my eye in the report:  it&#8217;s issued by Tom Davis and the url is from the <a href="http://republicans.oversight.house.gov/" target="_blank">Minority Office</a> for the <a href="http://oversight.house.gov/" target="_blank">House Committee on Oversight and Government Reform</a>.  Tom Davis is the representative from Northern Virginia and is the sponsor for FISMA back when it was signed.  Until the last election, he was the chairman of the House Committee on Oversight and Government Reform.  The committee is now chaired by <a href="http://oversight.house.gov/about/chairmanwaxman.asp" target="_blank">Henry Waxman</a>. </p>
<p>Time for a new concept in your vocabulary:  LGOPP (OK, actually it&#8217;s <a href="http://pagentsprogress.com/?p=555" target="_blank">LGOP</a>, but I added an extra &#8220;P&#8221; for comedy purposes).  Imagine June 6th, 1944, paratroopers scattered all over the French countryside.  What happens is you pick up the people around you, the senior person becomes the leader, and you carry out the mission.</p>
<p style="text-align: center;"><img src="http://farm1.static.flickr.com/115/299334216_8f9593d01f.jpg?v=0" alt="Paratrooper Stained Glass Window" width="257" height="500" /></p>
<p style="text-align: center;"><em>Photo of Paratrooper Stained Glass in Sainte Mère Église by</em><a href="http://www.flickr.com/photos/nelsonminar/" target="_blank"><em> Nelson Minar</em></a></p>
<p>Hence the true meaning of LGOPP: Little Groups of P*ssed-off Paratroopers.  An equivalent phrase is &#8220;isolated pockets of brilliance&#8221;.</p>
<p>In the words of somebody I went off to war with: <em> &#8220;LGOPPS are the spirit of the infantry:  a handfull of 18- and 19-year-olds with fully automatic weapons who can barely remember what their mission is running around the woods raising hell&#8221;</em>.</p>
<p>Now, I know you guys, you&#8217;re wondering what this has to do with security?  Well, this is relevant because it&#8217;s an election year.  What that means is that instead of being bothered with all this security stuff, Congress is involved in playing &#8220;gotcha&#8221; with the Executive branch.  After the election, it&#8217;s rearranging deck chairs on the Titanic and all of the leadership will change.</p>
<p>Instead of any national-level security agendas and strategizing, we&#8217;ll have to be content with security LGOPPs fighting the fight wherever they end up gaining enough critical mass.</p>
<p>And in the case of this year&#8217;s FISMA report card, the LGOPP that is Tom Davis&#8217;s staffers issued the report while the rest of the committee was busy worrying about elections.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/400&amp;title=FISMA+Report+Cards+Issued%26%238211%3BResponse+is+Rote+by+Now" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Del.icio.us" alt="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/400&amp;title=FISMA+Report+Cards+Issued%26%238211%3BResponse+is+Rote+by+Now" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to digg" alt="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/400&amp;title=FISMA+Report+Cards+Issued%26%238211%3BResponse+is+Rote+by+Now" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to reddit" alt="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=FISMA+Report+Cards+Issued%26%238211%3BResponse+is+Rote+by+Now&amp;url=http://www.guerilla-ciso.com/archives/400&amp;version=0.7" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Feed Me Links" alt="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/400" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Technorati" alt="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/400&amp;t=FISMA+Report+Cards+Issued%26%238211%3BResponse+is+Rote+by+Now" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Yahoo My Web" alt="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/400&amp;title=FISMA+Report+Cards+Issued%26%238211%3BResponse+is+Rote+by+Now" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Stumble Upon" alt="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/400&amp;title=FISMA+Report+Cards+Issued%26%238211%3BResponse+is+Rote+by+Now" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Google Bookmarks" alt="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/400" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Squidoo" alt="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/400" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Bloglines" alt="Add 'FISMA Report Cards Issued&#8211;Response is Rote by Now' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=cUasoI"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=cUasoI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=3r3Ssi"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=3r3Ssi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/295120811" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 21 May 2008 11:36:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/report">report</category>
      <category domain="http://securityratty.com/tag/fisma">fisma</category>
      <category domain="http://securityratty.com/tag/fisma report card">fisma report card</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/measure security">measure security</category>
      <category domain="http://securityratty.com/tag/enterprise-wide security">enterprise-wide security</category>
      <category domain="http://securityratty.com/tag/report card">report card</category>
      <category domain="http://securityratty.com/tag/security stuff">security stuff</category>
      <category domain="http://securityratty.com/tag/security lgopps">security lgopps</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/295120811/400">FISMA Report Cards IssuedResponse is Rote by Now</source>
    </item>
    <item>
      <title><![CDATA[Spear Phishing with Better Business Bureau complaints]]></title>
      <link>http://securityratty.com/article/d79eeaa5be648b1fcd84802746adde05</link>
      <guid>http://securityratty.com/article/d79eeaa5be648b1fcd84802746adde05</guid>
      <description><![CDATA[I received the following email yesterday purporting to be from the BBB. It looked phishy to me, so of course I did not click the link and did a little investigating. However, I could see how someone...]]></description>
      <content:encoded><![CDATA[<p>I received the following email yesterday purporting to be from the BBB. It looked phishy to me, so of course I did not click the link and did a little investigating. However, I could see how someone would be fooled on this one, thinking someone filed a bogus complaint against them. Almost as good as the subpoena story I heard from a customer last week. Beware of stuff like this!</p>

<h1>BBB CASE #841246605</h1>

<table cellspacing="0" cellpadding="0"><tbody><tr><td class="textLabel">Complaint filed by: </td>

<td class="cellMenuContent"><span id="info_consumer_short" style="DISPLAY: inline">Brian Williams</span> </td></tr>

<tr><td class="textLabel">Complaint filed against: </td>

<td class="cellMenuContent"><table cellspacing="0" cellpadding="0"><tbody><tr><td class="textLabel">Business Name:</td>

<td>StillSecure</td></tr>

<tr><td class="textLabel">Contact:</td>

<td>Alan Shimel</td></tr>

<tr><td class="textLabel">BBB Member:</td>

<td>YES</td></tr></tbody></table></td></tr>

<tr><td class="textLabel">Complaint status: </td>

<td class="cellMenuContent"><span id="info_activity_short">-</span> </td></tr>

<tr><td class="textLabel">Category:</td>

<td class="cellMenuContent">Contract Issues </td></tr>

<tr><td class="textLabel">Case opened date:</td>

<td class="cellMenuContent">4/20/2008</td></tr>

<tr><td class="textLabel">Case closed date:</td>

<td class="cellMenuContent">-</td></tr></tbody></table><br><table cellspacing="0" cellpadding="0" width="700"><tbody><tr><td></td></tr>

<tr><td><a title="http://www.go-bbb.org/ViewReport.php?case=841246605&amp;amp;biz=&amp;amp;bbb=1186" href="http://www.go-bbb.org/ViewReport.php?case=841246605&amp;amp;biz=&amp;amp;bbb=1186"><span title="http://www.go-bbb.org/ViewReport.php?case=841246605&amp;amp;biz=&amp;amp;bbb=1186" style="color: #0000ff;"><strong title="http://www.go-bbb.org/ViewReport.php?case=841246605&amp;amp;biz=&amp;amp;bbb=1186">Download a copy of this complaint so you can print it for your records <span style="color: #ff0000;"><em>(DON'T CLICK THIS)</em></span></strong></span></a> </td></tr>

<tr><td>On February 23 2008, the consumer provided the following information: (The consumer indicated he/she DID NOT received any response from the business.) </td></tr>

<tr><td>The form you used to register this complaint is designed to improve public access to the Better Business Bureau of Consumer Protection Consumer Response Center, and is voluntary. Through this form, consumers may electronically register a complaint with the BBB.Under the Paperwork Reduction Act, as amended, an agency may not conduct or sponsor, and a person is not required to respond to, a collection of information unless it displays a currently valid OMB control number. That number is 246-967. </td></tr>

<tr><td>© 2008 US.BBB.org, All Rights Reserved. </td></tr></tbody></table>


<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=k9HYqg"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=k9HYqg" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=uVQyRAG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=uVQyRAG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=v33t2jG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=v33t2jG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=CPBxxaG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=CPBxxaG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=Z5JrGDG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=Z5JrGDG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=I2Djl5g"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=I2Djl5g" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=A47G09g"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=A47G09g" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/277394333" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 24 Apr 2008 20:04:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/complaint">complaint</category>
      <category domain="http://securityratty.com/tag/complaint status">complaint status</category>
      <category domain="http://securityratty.com/tag/complaint filed">complaint filed</category>
      <category domain="http://securityratty.com/tag/filed">filed</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/business bureau">business bureau</category>
      <category domain="http://securityratty.com/tag/bogus complaint">bogus complaint</category>
      <category domain="http://securityratty.com/tag/bbb">bbb</category>
      <category domain="http://securityratty.com/tag/valid omb control">valid omb control</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/277394333/spear-phishing.html">Spear Phishing with Better Business Bureau complaints</source>
    </item>
    <item>
      <title><![CDATA[What impact will increased security budgets have on federal information security systems?]]></title>
      <link>http://securityratty.com/article/bf6dc223e0417daaed99f1f64a559b78</link>
      <guid>http://securityratty.com/article/bf6dc223e0417daaed99f1f64a559b78</guid>
      <description><![CDATA[Increased security budgets are usually a sign that senior management and budgeters agree there may be an increased priority for security issues. But this begs the question: for what security programs...]]></description>
      <content:encoded><![CDATA[<p>Increased security budgets are usually a sign that senior management and budgeters agree there may be an increased priority for security issues. But this begs the question: for what security programs are these funds actually intended? It is difficult to tell from aggregate budget numbers how these budget increases are being applied or what consequent impact they will have on federal information security systems. </p>

<p>As noted, the DOT alone accounted for this lion’s share of this year’s increases, but that increase is not in any way explicitly related to the relative security posture of DOT’s IT environment. It takes a search through the esoterica of DOT’s&nbsp; budget line items to identify what security priorities are being addressed, and they do not appear at a glance to be related to current federal ISS mandates, such as FISMA or HSPD-12. </p>

<p>Partly to address this problem, a new Line of Business (LOB) was added to the federal IT budget last year: the Information Systems Security LOB. But OMB itself has yet to work out how to identify systems security spending in the departments that should be allocated to the ISS LOB, so it is still too early to try and assess federal security spending and security posture improvements. But one hopes the OMB’s establishing the ISS LOB portends more coherent budgeting of security investments in the future. </p>

<p>However, since most current federal security spending is related to either government-wide mandates such as FISMA and HSPD-12, and department-specific operational requirements there is as yet no mature federal strategy for national cybersecurity. The Department of Homeland Security has responsibility for formulating this strategy, so the assignment of DHS as the “Managing Partner” of the federal ISS LOB presents the opportunity to harmonize federal security spending with a strategy, once one is established.</p>]]></content:encoded>
      <pubDate>Tue, 26 Feb 2008 07:44:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/federal">federal</category>
      <category domain="http://securityratty.com/tag/iss lob">iss lob</category>
      <category domain="http://securityratty.com/tag/federal iss lob">federal iss lob</category>
      <category domain="http://securityratty.com/tag/current federal security">current federal security</category>
      <category domain="http://securityratty.com/tag/assess federal security">assess federal security</category>
      <category domain="http://securityratty.com/tag/mature federal strategy">mature federal strategy</category>
      <category domain="http://securityratty.com/tag/federal security">federal security</category>
      <category domain="http://securityratty.com/tag/iss lob portends">iss lob portends</category>
      <category domain="http://securityratty.com/tag/lob">lob</category>
      <source url="http://blogs.forrester.com/srm/2008/02/increased-secur.html">What impact will increased security budgets have on federal information security systems?</source>
    </item>
  </channel>
</rss>
