<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Laptop Security Blog &#187; Government Security</title>
	<atom:link href="http://blog.absolute.com/category/government-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.absolute.com</link>
	<description>Laptop Security blog by Absolute Software</description>
	<lastBuildDate>Fri, 20 Nov 2009 21:57:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>GAO Requests Agencies be Held Accountable for Security Programs</title>
		<link>http://blog.absolute.com/gao-requests-agencies-be-held-accountable-for-security-programs/</link>
		<comments>http://blog.absolute.com/gao-requests-agencies-be-held-accountable-for-security-programs/#comments</comments>
		<pubDate>Wed, 26 Aug 2009 15:57:26 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Government Security]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1531</guid>
		<description><![CDATA[The U.S. Government Accountability Office (GAO) has released another information security report in July, which indicates that federal agencies continue to make progress with information security policies and practices, but there is still the need to &#8220;mitigate persistent weaknesses.&#8221; Just like the report issued earlier this year, the report indicates progress made under the Federal [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/gao-report.jpg" alt="" width="200" height="259" />The U.S. Government Accountability Office (GAO) has released another information security report in July, which indicates that federal agencies continue to make progress with information security policies and practices, but there is still the need to &#8220;mitigate persistent weaknesses.&#8221; Just like the <a href="http://blog.absolute.com/gao-recommends-fisma-changes/">report issued earlier this year</a>, the report indicates progress made under the Federal Information Security Management Act of 2002 (FISMA).</p>
<p>The report says that for the fiscal year 2008, <strong>almost all 24 major federal agencies had weaknesses in information security controls.</strong> These weaknesses include issues with access control, configuration management, segregation of duties, continuity of operations and security management.</p>
<p>The GAO says these weaknesses are the result of<strong> security programs not being fully implemented</strong>. While control activities &#8211; such as awareness training &#8211; have gone up, several agencies reported decreased levels of testing security controls and training for employees with significant security responsibilities.</p>
<p>The GAO recommends that the Director of the Office of Management and Budget (OMB) make several changes to their guidance policies, including the implementation of an &#8220;approve&#8221; or &#8220;disapprove&#8221; of agency security programs after review periods. This is suggested so that <strong>agencies are held accountable</strong> for implementing effective security programs.</p>
<p><strong>You can download the full report <a href="http://www.gao.gov/new.items/d09546.pdf">here</a> [PDF]. </strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/gao-requests-agencies-be-held-accountable-for-security-programs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GAO Recommends FISMA Changes</title>
		<link>http://blog.absolute.com/gao-recommends-fisma-changes/</link>
		<comments>http://blog.absolute.com/gao-recommends-fisma-changes/#comments</comments>
		<pubDate>Tue, 26 May 2009 18:06:11 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Government Security]]></category>
		<category><![CDATA[Surveys & Reports]]></category>
		<category><![CDATA[fisma]]></category>
		<category><![CDATA[gao]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1383</guid>
		<description><![CDATA[The US Government Accountability Office (GAO) has released a draft report summarizing the progress government agencies have made in the implementation of information security polices and practices under the Federal Information Security Management Act of 2002 (FISMA).
6 years after FISMA was enacted, the GAO reports that poor information security is still a widespread issue in [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://gao.gov/products/GAO-09-701T"><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/gao-summary.jpg" border="0" alt="" width="170" height="219" /></a>The US Government Accountability Office (GAO) has released a draft report summarizing the <strong>progress government agencies have made in the implementation of information security polices and practices</strong> under the Federal Information Security Management Act of 2002 (FISMA).</p>
<p>6 years after <strong>FISMA</strong> was enacted, the GAO reports that poor information security is still a widespread issue in the Federal government. In the 2008 performance and accountability reports,<strong> 20 out of 24 major agencies</strong> noted that <strong>information system controls</strong> over their financial systems and information were either a <strong>&#8220;significant deficiency&#8221; or a &#8220;material weakness.&#8221;</strong></p>
<p>The GAO summary notes that:</p>
<blockquote><p>Over the last several years, most agencies have not implemented controls to sufficiently prevent, limit, or detect access to computer networks, systems, or information. An underlying cause for information security weaknesses identified at federal agencies is that they have not yet fully or effectively implemented key elements for an agencywide information security program, as required by FISMA.</p></blockquote>
<p><strong>23 out of 24 agencies were found to have weaknesses </strong>in their agencywide information security programs in 2008. Although agencies reported an increased compliance in implementing security controls in 2008, the GAO notes that there are shortcomings with implementing key control activities for the year.</p>
<blockquote><p>For fiscal year 2008 reporting, agencies reported higher levels of FISMA implementation for most information security metrics and lower levels for others. Increases were reported in the number and percentage of employees and contractors receiving security awareness training, the number and percentage of systems with tested contingency plans, and the number and percentage of systems that were certified and accredited. However, the number and percentage of employees who had significant security responsibilities and had received specialized training decreased significantly and the number and percentage of systems that had been tested and evaluated at least annually decreased slightly.</p></blockquote>
<p>The GAO recommends that current <strong>reporting requirements change</strong> in order that inspector generals be required to report on the agencies&#8217; effectiveness of activities, which would help determine if agencies are effectively implementing their policies, procedures and practices. The full list of GAO recommendations can be found in <a href="http://www.gao.gov/new.items/d09701t.pdf">this PDF</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/gao-recommends-fisma-changes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>White House Talks Cybersecurity</title>
		<link>http://blog.absolute.com/white-house-talks-cybersecurity/</link>
		<comments>http://blog.absolute.com/white-house-talks-cybersecurity/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 16:39:58 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Government Security]]></category>
		<category><![CDATA[Privacy & Security Laws]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[white house]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1311</guid>
		<description><![CDATA[Melissa Hathaway, who was appointed earlier this year to conduct a 60-day review of the cyber security efforts of the U.S. Government, presented at the RSA Conference on information security, with the report set to be released in a few days.
Melissa notes that our global digital infrastructure is neither secure nor resilient, driven by interoperability [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Melissa Hathaway</strong>, who was <a href="http://blog.absolute.com/government-auditing-cybersecurity-efforts/">appointed</a> earlier this year to conduct a 60-day <strong>review of the cyber security efforts of the U.S. Government,</strong> presented at the <a href="http://www.rsaconference.com/2009/us/index.htm">RSA Conference</a> on information security, with the report set to be released in a few days.</p>
<p>Melissa notes that our global digital infrastructure is neither secure nor resilient, driven by interoperability and efficiency rather than security. She notes that previous attempts at cybersecurity have been made in isolation and have failed; the Federal government is not organized to address this growing issue because <strong>responsibilities for cyberspace are distributed widely</strong> across federal departments and agencies.</p>
<p>During the 60-day review, the cybersecurity team identified <strong>250 needs, tasks and recommendations for a national cyber security plan</strong>. The recommendation outlines a top-down approach to cyber security, with the White House leading the way and overseeing and working with other government agencies, State and local stakeholders, as well as those in academia and the industry.</p>
<blockquote><p>Protecting cyberspace requires strong vision and leadership and will require changes in policy, technology, education, and perhaps law. We need to demonstrate abroad and here at home that the United States takes cyberspace issues, policies, and activities seriously. Achieving this vision requires leadership and commitment from the highest levels of government, industry, and civil society.</p></blockquote>
<p>Here&#8217;s a video of Melissa&#8217;s speech:</p>
<div><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="432" height="362" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="FlashVars" value="playerMode=embedded&amp;allowFullScreen=1&amp;flavor=EmbeddedPlayerVersion&amp;showOptions=0&amp;skin=http://image.com.com/gamespot/images/cne_flash/production/media_player/proteus/one/skins/proteus-zdnet.png&amp;autoPlay=false&amp;movieAspect=4.3&amp;embeddingAllowed=true&amp;clockColor=0x3b3b3b&amp;paramsURI=http%3A%2F%2Fnews.zdnet.com%2F2461-1_22-291079.xml%3Fwidth%3D432%26height%3D362%26ptype%3D6475%26mode%3Dembedded%26siteId%3D24%26autoplay%3Dtrue%26ttag%3DRichard%2BKoman%26assetId%3D4680%26nc%3D1240529635704%26nodeId%3D11155" /><param name="wmode" value="transparent" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://image.com.com/gamespot/images/cne_flash/production/media_player/proteus/one/proteus2.swf" /><embed type="application/x-shockwave-flash" width="432" height="362" src="http://image.com.com/gamespot/images/cne_flash/production/media_player/proteus/one/proteus2.swf" allowscriptaccess="always" wmode="transparent" flashvars="playerMode=embedded&amp;allowFullScreen=1&amp;flavor=EmbeddedPlayerVersion&amp;showOptions=0&amp;skin=http://image.com.com/gamespot/images/cne_flash/production/media_player/proteus/one/skins/proteus-zdnet.png&amp;autoPlay=false&amp;movieAspect=4.3&amp;embeddingAllowed=true&amp;clockColor=0x3b3b3b&amp;paramsURI=http%3A%2F%2Fnews.zdnet.com%2F2461-1_22-291079.xml%3Fwidth%3D432%26height%3D362%26ptype%3D6475%26mode%3Dembedded%26siteId%3D24%26autoplay%3Dtrue%26ttag%3DRichard%2BKoman%26assetId%3D4680%26nc%3D1240529635704%26nodeId%3D11155"></embed></object></div>
<p>The speech, if somewhat repetitive and littered with political fluff, does hint at many changes to come. Almost nothing was specified yet, and <a href="http://blog.ncircle.com/blogs/sync/archives/2009/04/the_obama_administrations_cybe.html">many</a> are critical of it. Let&#8217;s hope the report released in a few days will specify a bit more. Attempting to muster resources on the National and International level, across the government and private sectors, won&#8217;t be an easy task!</p>
<p><strong>Download Melissa Hathaway&#8217;s prepared remarks <a href="http://voices.washingtonpost.com/securityfix/Melissa%20Hathaway%20Speech%20at%20RSA.pdf">here</a></strong> [PDF]</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/white-house-talks-cybersecurity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Cybersecurity Legislation Proposed</title>
		<link>http://blog.absolute.com/new-cybersecurity-legislation-proposed/</link>
		<comments>http://blog.absolute.com/new-cybersecurity-legislation-proposed/#comments</comments>
		<pubDate>Mon, 20 Apr 2009 19:05:08 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Government Security]]></category>
		<category><![CDATA[Privacy & Security Laws]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[legislature]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1283</guid>
		<description><![CDATA[A new National cybersecurity bill is currently being introduced to legislation by Senator Rockefeller (Chairman for the Committee on Commerce, Science, and Transportation) and Senator Snowe. The bill would create the Office of the National Cybersecurity Advisor within the Executive Office of the President, an advisory position that would report directly to the President and [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/j0351700.gif" alt="" width="192" height="192" />A new National <strong>cybersecurity bill is currently being introduced</strong> to legislation by Senator <a href="http://rockefeller.senate.gov/">Rockefeller</a> (Chairman for the Committee on Commerce, Science, and Transportation) and Senator <a href="http://snowe.senate.gov/public/">Snowe</a>. The bill would create the Office of the <strong>National Cybersecurity Advisor</strong> within the Executive Office of the President, an advisory position that would report directly to the President and serve as lead on all cyber matters. This position would co-ordinate with the intelligence community as well as civilian agencies.</p>
<p>The new cybersecurity legislation proposes additional changes to address issues of cyber crime, global cyber espionage and cyber attacks.</p>
<blockquote><p>&#8220;I believe Congress must bring new high-level governmental attention to develop a fully integrated, thoroughly coordinated, public-private partnership to our cybersecurity efforts in the 21st century.&#8221; &#8211; <em>Senator Rockefeller</em></p></blockquote>
<p><strong>The Rockefeller-Snow initiative would include provisions for:</strong></p>
<ul>
<li><strong>Raising the profile of cybersecurity within the Federal government</strong>, including the aforementioned Office plus a comprehensive national strategy, a quadrennial cybersecurity review and a threat and vulnerability assessment</li>
<li><strong>Promoting public awareness and protecting civil liberties</strong>, including a legal review of the statutory and regulatory framework applicable, changes required, and a report on identity management and civil liberties</li>
<li><strong>Remaking the relationship between government and the private sector on cybersecurity</strong>, including a public-private clearinghouse for cyber threat and vulnerability information sharing, an Advisory Panel, enforceable cybersecurity standards, licensing for cybersecurity professionals, State and regional cybersecurity centers for small and medium-sized businesses, and more</li>
<li><strong>Fostering innovation and creativity in cybersecurity to develop long-term solutions, </strong>including increased recruitment for students into cybersecurity, increased funding for R&amp;D, and an attempt to place a dollar value on cybersecurity risk</li>
</ul>
<p><strong>Read more about the new cybersecurity legislation being proposed <a href="http://commerce.senate.gov/public/index.cfm?FuseAction=PressReleases.Detail&amp;PressRelease_id=bb7223ef-1d78-4de4-b1d5-4cf54fc38662&amp;Month=4&amp;Year=2009">here</a>.</strong></p>
<p>Via <a href="http://www.securityfocus.com/brief/939?ref=rss">SecurityFocus</a> ; <em>Image: clipart</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/new-cybersecurity-legislation-proposed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Antiterror Officer in UK Resigns After Documents Revealed</title>
		<link>http://blog.absolute.com/antiterror-officer-in-uk-resigns-after-documents-revealed/</link>
		<comments>http://blog.absolute.com/antiterror-officer-in-uk-resigns-after-documents-revealed/#comments</comments>
		<pubDate>Thu, 16 Apr 2009 16:21:55 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Government Security]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Security Policy]]></category>
		<category><![CDATA[top secret]]></category>
		<category><![CDATA[uk news]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1280</guid>
		<description><![CDATA[In a clear oversight of security protocols, Britain&#8217;s most senior counterterrorism officer, Bob Quick, took Top Secret documents out of the office. The documents, in clear view in his arms, were then photographed by the press as he carried the documents up Downing Street. Bob Quick has resigned as a result of the incident.
The documents outline [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/uploads/topsecret.jpg" alt="" />In a clear oversight of security protocols, Britain&#8217;s most senior counterterrorism officer, Bob Quick, took <strong>Top Secret documents out of the office</strong>. The documents, in <a href="http://www.guardian.co.uk/uk/2009/apr/09/bob-quick-terror-raids-leak#zoomed-picture">clear view in his arms</a>, were then <strong>photographed by the press</strong> as he carried the documents up Downing Street. Bob Quick has <a href="http://www.nytimes.com/2009/04/10/world/europe/10britain.html?_r=1">resigned</a> as a result of the incident.</p>
<p>The documents outline a Metropolitan Police Service and MI5 counterterrorist operation against al-Qaeda suspects. The document revealed <strong>details for a planned arrest of terrorist suspects</strong> following a long covert surveillance operation. Steps were made to censor the photographs (only successful in Britain) and Mr. Quick&#8217;s location fearing that information would tip off the suspects. The operation was able to continue, with <strong>arrests made sooner than was planned</strong>, but it is still a major security blunder.</p>
<p>Bob Quick <a href="http://news.bbc.co.uk/1/hi/uk/7990719.stm">says</a> he &#8220;deeply regretted&#8221; revealing the documents to photographers, and some people seem willing to <a href="http://news.bbc.co.uk/1/hi/uk/7990719.stm">forgive him</a> for simply holding the paper the wrong way. However, the secret documents should not have been carried outside of secure areas in printed format &#8211; at the very least, they could have been transported in an encrypted drive. This is <strong>not the first incident</strong> where a government official has accidentally shown secret notes to the journalists who often wait outside of Downing Street.</p>
<p><strong>Bob Quick <a href="http://www.guardian.co.uk/uk/2009/apr/09/bob-quick-terror-raids-leak#">resigned</a></strong> soon after the incidence, following a meeting with the home secretary and the Metropolitan Police commissioner.</p>
<blockquote><p>&#8220;I have today offered my resignation in the knowledge that my action could have compromised a major counterterrorism operation.</p>
<p>I deeply regret the disruption caused to colleagues undertaking the operation, and remain grateful for the way in which they adapted quickly and professionally to a revised timescale.&#8221;</p></blockquote>
<p>It is a pity that the breach was made, but the repercussions are already wide-ranging. Not only has the public outcry damaged the trust in government security, but the MPS has lost its most senior, and experienced, counterterrorism specialist. This should underscore the importance of having a <strong>clear security policy and ongoing employee training &#8211; at all levels</strong> &#8211; to ensure compliance to basic security measures.</p>
<p>Via <a href="http://www.schneier.com/blog/archives/2009/04/how_not_to_carr.html">Schneier</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/antiterror-officer-in-uk-resigns-after-documents-revealed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GAO Lists 12 Cybersecuity Strategy Improvements</title>
		<link>http://blog.absolute.com/gao-lists-12-cybersecuity-strategy-improvements/</link>
		<comments>http://blog.absolute.com/gao-lists-12-cybersecuity-strategy-improvements/#comments</comments>
		<pubDate>Wed, 01 Apr 2009 19:18:26 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Government Security]]></category>
		<category><![CDATA[Surveys & Reports]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[gao]]></category>
		<category><![CDATA[report]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1219</guid>
		<description><![CDATA[The US Government Accountability Office (GAO) recently released highlights of their study on Cybersecurity. The report notes that key improvements are needed to strengthen the Nation&#8217;s posture and criticizes the Department of Homeland Security (DHS) strongly for having &#8220;yet to fully satisfy its responsibilities designated by the national cybersecurity strategy.&#8221; Here&#8217;s a summary of the [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/gao.jpg" alt="" width="213" height="155" />The US Government Accountability Office (GAO) recently released <a href="http://www.gao.gov/products/GAO-09-432T">highlights</a> of their <strong>study on Cybersecurity</strong>. The report notes that key improvements are needed to strengthen the Nation&#8217;s posture and <strong>criticizes the Department of Homeland Security</strong> (DHS) strongly for having &#8220;yet to fully satisfy its responsibilities designated by the national cybersecurity strategy.&#8221; <strong>Here&#8217;s a summary of the report:</strong></p>
<blockquote><p>Pervasive and sustained computerbased (cyber) attacks against federal and private-sector infrastructures pose a potentially devastating impact to systems and operations and the critical infrastructures that they support. To address these threats, President Bush issued a 2003 national strategy and related policy directives aimed at improving cybersecurity nationwide. Congress and the Executive Branch, including the new administration, have subsequently taken actions to examine the adequacy of the strategy and identify areas for improvement. Nevertheless, GAO has identified this area as high risk and has reported on needed improvements in implementing the national cybersecurity strategy.</p></blockquote>
<p>The GAO made <strong>30 recommendations in key cybersecurity areas,</strong> including bolstering cyber analysis and warning capabilities, completing actions identified during cyber exercises, improving cybersecurity of infrastructure control systems, strengthening DHS&#8217; ability to help recover from Internet disruptions and addressing cybercrime.</p>
<p>In addition to these areas identified as needing improvement, the GAO report identified <strong>12 key strategy improvements</strong>:</p>
<ol>
<li>Develop a national strategy that clearly articulates strategic objectives, goals, and priorities</li>
<li>Establish White House responsibility and accountability for leading and overseeing national cybersecurity policy</li>
<li>Establish a governance structure for strategy implementation</li>
<li>Publicize and raise awareness about the seriousness of the cybersecurity problem</li>
<li>Create an accountable, operational cybersecurity organization</li>
<li>Focus more actions on prioritizing assets, assessing vulnerabilities, and reducing vulnerabilities than on developing additional plans</li>
<li>Bolster public/private partnerships through an improved value proposition and use of incentives</li>
<li>Focus greater attention on addressing the global aspects of cyberspace</li>
<li>Improve law enforcement efforts to address malicious activities in cyberspace</li>
<li>Place greater emphasis on cybersecurity research and development, including consideration of how to better coordinate government and private sector efforts</li>
<li>Increase the cadre of cybersecurity professionals</li>
<li>Make the federal government a model for cybersecurity</li>
</ol>
<p>The GAO says that the nation&#8217;s federal and private-sector infrastructure systems remain at risk without these improvements. They suggest the new administration consider these improvements as part of the nation&#8217;s cybersecurity strategy.</p>
<p>Via <a href="http://www.networkworld.com/community/node/39557">network world</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/gao-lists-12-cybersecuity-strategy-improvements/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Consensus Audit Guidelines</title>
		<link>http://blog.absolute.com/consensus-audit-guidelines/</link>
		<comments>http://blog.absolute.com/consensus-audit-guidelines/#comments</comments>
		<pubDate>Wed, 11 Mar 2009 16:03:20 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Government Security]]></category>
		<category><![CDATA[Surveys & Reports]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[report]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1138</guid>
		<description><![CDATA[A consortium of federal agencies and private organizations announced the Consensus Audit
Guidelines (CAG) last week. This list of 20 items defines the most critical security controls needed to protect federal and contractor information and information systems. These guidelines won&#8217;t duplicate or replace existing federal IT security requirements, but rather supplement the standards (like FISMA).
The CAG [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/j0353661.gif" alt="" width="192" height="192" />A consortium of federal agencies and private organizations announced the <a href="http://www.sans.org/cag/">Consensus Audit<br />
Guidelines</a> (CAG) last week. This list of 20 items defines the <strong>most critical security controls needed to protect federal and contractor information and information systems</strong>. These guidelines won&#8217;t duplicate or replace existing federal IT security requirements, but rather supplement the standards (like <a href="http://csrc.nist.gov/groups/SMA/fisma/">FISMA</a>).</p>
<p>The CAG initiative is part of a larger effort to advance recommendations from the CSIS Commission report on Cybersecurity for the 44th Presidency. The goal of the consortium was to come up with a <strong>risk-based standard to counter known forms of cyber attack</strong>. The 20 actions should help the government or private organizations mitigate or prevent cyber attacks. The controls cover areas including access controls, wireless security, data leakage and training. Each control details what threat it covers and how the control could be automated &amp; tested for effectiveness.</p>
<h2>20 Controls &amp; Metrics for Effective Cyber Defense</h2>
<ol>
<li>Inventory of authorized and unauthorized hardware.</li>
<li>Inventory of authorized and unauthorized software; enforcement of white lists of authorized software.</li>
<li>Secure configurations for hardware and software on laptops, workstations, and servers.</li>
<li>Secure configurations of network devices such as firewalls, routers, and switches.</li>
<li>Boundary Defense</li>
<li>Maintenance, Monitoring and Analysis of Complete Audit Logs</li>
<li>Application Software Security</li>
<li>Controlled Use of Administrative Privileges</li>
<li>Controlled Access Based On Need to Know</li>
<li>Continuous Vulnerability Testing and Remediation</li>
<li>Dormant Account Monitoring and Control</li>
<li>Anti-Malware Defenses</li>
<li>Limitation and Control of Ports, Protocols and Services</li>
<li>Wireless Device Control</li>
<li>Data Leakage Protection</li>
<li>Secure Network Engineering</li>
<li>Red Team Exercises</li>
<li>Incident Response Capability</li>
<li>Data Recovery Capability</li>
<li>Security Skills Assessment and Appropriate Training To Fill Gaps</li>
</ol>
<p>The CAG is still in draft and they are actively soliciting criticism and suggestions. You can learn more about how to contact them <a href="http://www.sans.org/cag/guidelines.php">here</a> for most of March. After a public review of the standards, pilots will be conducted in several federal agencies and the draft will be reviewed and audited.</p>
<p>Hat tip to <a href="http://blog.ironkey.com/?p=597">Dave Jevans</a> ; <em>Image: Clipart</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/consensus-audit-guidelines/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Government Auditing Cybersecurity Efforts</title>
		<link>http://blog.absolute.com/government-auditing-cybersecurity-efforts/</link>
		<comments>http://blog.absolute.com/government-auditing-cybersecurity-efforts/#comments</comments>
		<pubDate>Wed, 25 Feb 2009 16:27:25 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Government Security]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[barack obama]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[us government]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1067</guid>
		<description><![CDATA[President Barack Obama named Melissa Hathaway to lead a 60-day review of the cybersecurity efforts of the US Government. Hathaway thus became the Acting Senior Director for Cyberspace for the National Security and Homeland Security Councils.
Melissa Hathaway, who has served as Cyber Coordination Executive to the Director of National Intelligence, chaired the National Cyber Study [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/j0439824.gif" alt="" width="155" height="155" />President Barack Obama <a href="http://www.whitehouse.gov/the_press_office/AdvisorsToConductImmediateCyberSecurityReview/">named</a> Melissa Hathaway to lead a <strong>60-day review of the cybersecurity efforts of the US Government. </strong>Hathaway thus became the Acting Senior Director for Cyberspace for the National Security and Homeland Security Councils.</p>
<p><strong>Melissa Hathaway</strong>, who has served as Cyber Coordination Executive to the Director of National Intelligence, chaired the National Cyber Study Group, a group responsible for helping develop a 5-year $30 billion dollar plan to secure federal systems and infrastructure against online threats. This <a href="http://www.nextgov.com/nextgov/ng_20080801_9053.php">Comprehensive National Cyber Security Initiative</a> (CNCI) was approved by Bush earlier last year and is still being implemented.</p>
<p>The new review will look at <strong>ongoing security programs</strong>, plans and activities and will develop recommendations to ensure they continue to meet the needs of both the public and private sectors. Essentially, Hathaway will be reviewing the progress of the existing CNCI plan and offering advice to keep it moving forward.</p>
<blockquote><p>&#8220;The national security and economic health of the United States depend on the security, stability, and integrity of our Nation’s cyberspace, both in the public and private sectors. The President is confident that we can protect our nation’s critical cyber infrastructure while at the same time adhering to the rule of law and safeguarding privacy rights and civil liberties,&#8221; <em>said Assistant to the President for Counterterrorism and Homeland Security John Brennan.</em></p></blockquote>
<p>As part of her task, Hathaway will reportedly evaluate a recommendation that a special<strong> White House &#8220;cyberadviser&#8221; role be created</strong> (something Obama <a href="http://online.wsj.com/article/SB123412824916961127.html">echoed</a> on the campaign trail). It is suggested that this role report directly to the President rather than leaving cybersecurity to the Department of Homeland Security. This type of role would help create a comprehensive plan for cybersecurity, an issue that spans all government agencies.</p>
<p>Via <a href="http://www.csoonline.com/article/480180/Obama_Taps_Bush_Aide_to_Review_Federal_Cybersecurity_Efforts">CSO Online</a>, <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9127682&amp;intsrc=news_ts_head">Computerworld</a>, <a href="http://www.govtech.com/gt/articles/617452">Govtech</a>, <a href="http://www.whitehouse.gov/the_press_office/AdvisorsToConductImmediateCyberSecurityReview/">White House</a>, <a href="http://www.usatoday.com/tech/2009-02-16-cybersecurity-expert-obama_N.htm">USA Today</a>, <a href="http://online.wsj.com/article/SB123412824916961127.html">WSJ</a> ; <em>Image: clipart</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/government-auditing-cybersecurity-efforts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Veteran Affairs $20 Million Breach Settlement</title>
		<link>http://blog.absolute.com/veteran-affairs-20-million-breach-settlement/</link>
		<comments>http://blog.absolute.com/veteran-affairs-20-million-breach-settlement/#comments</comments>
		<pubDate>Wed, 28 Jan 2009 10:24:27 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Government Security]]></category>
		<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[Theft News]]></category>
		<category><![CDATA[breach settlement]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[veteran affairs]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=964</guid>
		<description><![CDATA[The U.S. Department of Veteran Affairs (VA), which suffered a data breach affecting 26.5 million people in 2006, has agreed to pay $20 million to veterans affected by the breach.
The VA data breach of 2006, which was listed as one of the 10 largest data breaches since 2000 and as one of the worst breaches [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.va.gov/"><strong>U.S. Department of Veteran Affairs</strong></a> (VA), which suffered a data breach affecting 26.5 million people in 2006, has agreed to <strong>pay $20 million to veterans affected by the breach</strong>.</p>
<p>The VA <a href="http://www.usa.gov/veteransinfo.shtml">data breach of 2006</a>, which was listed as one of the <a href="http://blog.absolute.com/10-largest-data-breaches-since-2000">10 largest data breaches since 2000 </a>and as one of the <a href="http://blog.absolute.com/worst-data-breaches/">worst breaches ever</a>, was the result of <strong>computer going missing from the home of an employee</strong>, who had taken the computer home without permission. The computer contained insurance claim data (including Social Security Numbers and insurance information) for <strong>26.5 million</strong> active duty troops and veterans, leaving them open to to identity theft and fraud.</p>
<p>The FBI was able to <a href="http://www.scmagazineus.com/Infamous-VA-laptop-recovered-appears-not-to-have-been-tampered-with/article/33575/">recover</a> the equipment and <a href="http://www.scmagazineus.com/VA-laptop-thieves-apprehended/article/33768/">apprehended</a> the thieves; the VA found no evidence that data had been compromised. The VA Inspector General faulted the data analyst and his supervisors for <strong>putting veterans at unreasonable risk</strong>. A series of delays after the employee notified his superiors meant that affected veterans were not told about the breach until 3 weeks later.</p>
<p>Five veteran groups filed a <a href="http://www.foxnews.com/story/0,2933,198561,00.html"><strong>class-action lawsuit</strong></a> against the VA alleging invasion of privacy. The lawsuit sought $1000 in damages for violations of privacy for each military personnel affected. This would have amounted to <strong>$26.5 billion in damages</strong>.</p>
<p>In court filings on Tuesday, lawyers for the VA and the veterans represented in the suit agreed to <strong>settle the lawsuit for $20 million</strong>. VA spokesman Phil Budahn made a statement, after the settlement, that:</p>
<blockquote><p>&#8220;We want to assure veterans there is no evidence that the information involved in this incident was used to harm a single veteran.&#8221;</p></blockquote>
<p>The money for the settlement will come from the U.S. Treasury and will go to veterans who can show they suffered &#8220;actual harm&#8221; (physical symptoms of emotional distress or expenses) as the result of the breach. I&#8217;ll be curious to see how they determine the &#8216;proof&#8217; of these items. Each veteran will receive <strong>$75 &#8211; $1500 upon proving their suffering</strong>. Any remainder of funds will be donated to veterans&#8217; charities. U.S. District Judge James Robertson must approve the terms of this settlement before it becomes final.</p>
<p>In November of 2007, the VA suffered a <a href="http://blog.absolute.com/veterans-affairs-new-breach-arrest/">smaller breach</a>, affecting 12,000, after 3 computers were stolen. They have suffered other data breaches, affecting up to 1.8 million, <a href="http://blog.absolute.com/veterans-affairs-new-breach-arrest/">several times</a> since 2006. Let&#8217;s hope this settlement means that the VA is truly accepting responsibility for the data breach suffered in 2006.</p>
<p>Via <a href="http://news.yahoo.com/s/ap/20090128/ap_on_go_ca_st_pe/veterans_data_theft;_ylt=AvzA5DqoYIIN1fAlHYkryQoDW7oF">Yahoo</a>, <a href="http://www.scmagazineus.com/US-Veteran-Affairs-Department-settles-data-breach-case/article/126518/">SC Magazine</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/veteran-affairs-20-million-breach-settlement/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Beware Fake Obama Websites</title>
		<link>http://blog.absolute.com/beware-fake-obama-websites/</link>
		<comments>http://blog.absolute.com/beware-fake-obama-websites/#comments</comments>
		<pubDate>Wed, 21 Jan 2009 15:54:55 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Government Security]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=918</guid>
		<description><![CDATA[Microsoft issued a warning about malware authors taking advantage of Inauguration Day by creating fake Obama websites to host the Waledec Trojan.
Barack Obama&#8217;s name has been used by an increasing number of malware authors and spammers since he ran for the Presidency, with a whole new spate of social engineering tactics coming out for Inauguration [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft issued a <a href="http://blogs.technet.com/mmpc/archive/2009/01/19/waledac-trojan-hosted-by-fake-obama-website.aspx">warning</a> about <strong>malware authors taking advantage of Inauguration Day</strong> by creating fake Obama websites to host the Waledec Trojan.</p>
<p>Barack Obama&#8217;s name has been used by an increasing number of malware authors and spammers since he ran for the Presidency, with a whole new spate of social engineering <strong>tactics coming out for <a href="http://inaugural.senate.gov/index.cfm">Inauguration Day</a>. </strong></p>
<p>As the Microsoft Malware blog shows, these cybercriminals have set up <strong>fake sites</strong> that mimic the official Barack Obama website, <a href="http://www.barackobama.com/index.php">barackobama.com</a></p>
<p><a href="http://blog.absolute.com/wp/wp-content/uploads/barack-obama-whitehousegov.jpg"><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/barack-obama-whitehousegov.jpg" border="0" alt="" width="300" height="217" /></a>As with any email you get from unknown sources, one of the tips you can use to make sure you don&#8217;t end up on a fake website is to <em>not click the links.</em> Instead, go to your browser and type in the URL. Although <a href="http://blog.absolute.com/malware-via-hacked-sites-growing/">real websites can be taken over</a> to host malware, this way you are avoiding the social engineering tactics that attempt to catch you in your inbox.</p>
<p>Microsoft offers information on what to look for in fake websites, including URLs that include the words &#8220;direct&#8221;, &#8220;online&#8221; or &#8220;great&#8221;, and images such as <a href="http://blogs.technet.com/mmpc/archive/2009/01/19/waledac-trojan-hosted-by-fake-obama-website.aspx">these</a>.</p>
<p>For those of you who have been eagerly awaiting Obama&#8217;s Inauguration, I suggest you also take a look at the <strong>changes now visible on <a href="http://www.whitehouse.gov/">Whitehouse.gov</a></strong>. The nicest that website has ever looked! The transition was captured by <a href="http://news.cnet.com/8301-17939_109-10145852-2.html">CNet</a>, along with the brief bugs apparent during the transition progress.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/beware-fake-obama-websites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
