<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Laptop Security Blog &#187; cybersecurity</title>
	<atom:link href="http://blog.absolute.com/tag/cybersecurity/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.absolute.com</link>
	<description>Laptop Security blog by Absolute Software</description>
	<lastBuildDate>Fri, 12 Mar 2010 15:00:19 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Cybersecurity Plan Declassified</title>
		<link>http://blog.absolute.com/cybersecurity-plan-declassified/</link>
		<comments>http://blog.absolute.com/cybersecurity-plan-declassified/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 15:00:37 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Government Security]]></category>
		<category><![CDATA[Privacy & Security Laws]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[us government]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=2129</guid>
		<description><![CDATA[The Obama administration has declassified and published part of its cybersecurity plan. Saying that Obama has &#8220;identified cybersecurity as one of the most serious economic and national security challenges&#8221; faced in the US, appointing Howard A. Schmidt as cybersecurity coordinator last year. Schmidt made the declassification announcement at the RSA Security Conference.
Schmidt says there are [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://blog.absolute.com/wp/../uploads/bg-title-nsc_0.jpg" border="0" alt="bg-title-nsc_0.jpg" width="87" height="80" align="left" />The Obama administration has declassified and <a href="http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative">published</a> part of its cybersecurity plan. Saying that Obama has &#8220;identified cybersecurity as one of the most serious economic and national security challenges&#8221; faced in the US, appointing Howard A. Schmidt as cybersecurity coordinator last year. Schmidt made the declassification announcement at the RSA Security Conference.</p>
<p>Schmidt says there are about 40 legal questions surrounding the cybersecurity initiative that the government is working on. The initiative was set to protect US networks &#8211; military, civilian and government networks as well as infrastructure systems &#8211; and to combat cyberwarfare.</p>
<p>The declassified plan includes information on Einstein 2 and 3, intrusion detection systems on federal networks that would detect potential threats. <a href="http://www.wired.com/threatlevel/2010/03/us-declassifies-part-of-secret-cybersecurity-plan/">Wired</a> does a great job discussing the privacy and civil liberty issues surrounding these deployments. The plan outlines several initiatives that are a part of the Comprehensive National Cybersecurity Initiative (CNCI) &#8211; see the outline <a href="http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/cybersecurity-plan-declassified/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cybersecurity Research Bill Passes House</title>
		<link>http://blog.absolute.com/cybersecurity-research-bill-passes-house/</link>
		<comments>http://blog.absolute.com/cybersecurity-research-bill-passes-house/#comments</comments>
		<pubDate>Thu, 18 Feb 2010 15:00:38 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Privacy & Security Laws]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[legislature]]></category>
		<category><![CDATA[us government]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=2088</guid>
		<description><![CDATA[The U.S. House of Representatives has passed a new cybersecurity research bill that would enable the US government to better deal with cyberattacks.
The Cyber Security Research and Development Act of 2009 (HR 4061) would create new research and education programs at the National Science Foundation and the National Institute of Standards and Technology to promote [...]]]></description>
			<content:encoded><![CDATA[<p>The U.S. House of Representatives has passed a new cybersecurity research bill that would enable the US government to better deal with cyberattacks.</p>
<p>The Cyber Security Research and Development Act of 2009 (HR 4061) would create new research and education programs at the National Science Foundation and the National Institute of Standards and Technology to promote research in cybersecurity and to attract more teachers and students to the field.</p>
<blockquote><p>&#8220;This bill will help improve the security of cyberspace by ensuring federal investments in cybersecurity are better focused, more effective, and that research into innovative, transformative security technologies is fully supported,&#8221; said Symantec CTO Mark Bregman. &#8220;HR 4061 represents a major step forward towards defining a clear research agenda that is necessary to stimulate investment in both the private and academic worlds, resulting in the creation of jobs in a badly understaffed industry.&#8221;</p></blockquote>
<p>Aside from the scholarly aspect, the new bill would develop an awareness program to help consumers, organizations and government bodies to keep their computers secure. The National Institute of Standards and Technology has been tasked with improving development of new identity management systems used to control access to buildings, networks and data.</p>
<p>If the bill becomes law, NIST would have one year to develop a plan for Congress about how it would participate in creating International cybersecurity standards and would have 90 days for a plan on its cybersecurity awareness program.</p>
<p>Via <a href="http://news.cnet.com/8301-27080_3-10447627-245.html">CNet</a> &amp; <a href="http://www.opencongress.org/bill/111-h4061/show">opencongress</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/cybersecurity-research-bill-passes-house/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Organizations Fail to Mitigate Security Risks</title>
		<link>http://blog.absolute.com/organizations-fail-to-mitigate-security-risks/</link>
		<comments>http://blog.absolute.com/organizations-fail-to-mitigate-security-risks/#comments</comments>
		<pubDate>Tue, 29 Sep 2009 17:00:56 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Business Security]]></category>
		<category><![CDATA[Surveys & Reports]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[risk factors]]></category>
		<category><![CDATA[statistics]]></category>
		<category><![CDATA[study]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1700</guid>
		<description><![CDATA[The SANS Institute has just released the results of a comprehensive study on the topic of cyber security risks. The study is based upon prevention systems in 6,000 organizations and vulnerability data from 9 million systems. The study indicates that there are two major risks out there to organizations, both of which could be mitigated.
Cyber [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.sans.org/top-cyber-security-risks/">SANS Institute</a> has just released the results of a comprehensive study on the topic of <strong>cyber security risks</strong>. The study is based upon prevention systems in 6,000 organizations and vulnerability data from 9 million systems. The study indicates that there are two major risks out there to organizations, both of which could be mitigated.</p>
<p>Cyber attacks are a growing issue to organizations of all sorts, with new and sophisticated attacks being created every day. Though organizations may have difficulty keeping up with the threat landscape, this study found that organizations are not doing what they could to mitigate the two largest risk areas. Specifically, client-side <strong>software is remaining un-patched </strong>and <strong>websites are not being scanned for common flaws</strong> that criminals use to exploit visitors to those sites.</p>
<blockquote><p>Waves of targeted email attacks, often called spear phishing, are exploiting client-side vulnerabilities in commonly used programs such as Adobe PDF Reader, QuickTime, Adobe Flash and Microsoft Office. This is currently the primary initial infection vector used to compromise computers that have Internet access.</p></blockquote>
<p><img style="float: right; margin: 5px" src="http://blog.absolute.com/wp/../uploads/figure1.jpg" border="0" alt="figure1.jpg" width="255" height="181" />The ultimate goal of attackers is to steal information and to install &#8220;back doors&#8221; so that the attacker can return to further exploit organizational systems. The study found that major organizations take <strong>at least twice as long to patch client-side vulnerabilities</strong> as they do to patch operating system vulnerabilities. Addressing this single issue could drastically reduce your risk of being exploited. What this also means is that the question of Mac vs PC is not going to be your solution to mitigating risk, as these risks come from cross-platform applications and from the Internet.</p>
<p>The report, which is available <a href="http://www.sans.org/top-cyber-security-risks/">here</a>, targets major organizations who want to ensure their defenses are up to date. The report shows some interesting patterns to data and includes a tutorial on how some of the most damaging attacks actually work. You may find it handy to print this report off to study the graphs in detail.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/organizations-fail-to-mitigate-security-risks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cybercrimes More Sophisticated, But So Too Are Countermeasures</title>
		<link>http://blog.absolute.com/cybercrimes-more-sophisticated-but-so-too-are-countermeasures/</link>
		<comments>http://blog.absolute.com/cybercrimes-more-sophisticated-but-so-too-are-countermeasures/#comments</comments>
		<pubDate>Mon, 27 Jul 2009 17:28:21 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Surveys & Reports]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[research organization]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1455</guid>
		<description><![CDATA[According to the Cisco 2009 Midyear Security Report, internet criminals are becoming more sophisticated, using increasingly targeted attacks. However, Cisco predicts that increased collaboration between organizations, like what we saw with Conficker, and new security policies may make it more difficult for attacks to infiltrate and spread.
The Midyear Security Report provides an overview of Cisco [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://cisco.com/en/US/prod/vpndevc/annual_security_report.html"><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/security-report09-mid.gif" alt="" width="200" height="158" /></a>According to the <a href="http://cisco.com/en/US/prod/vpndevc/annual_security_report.html">Cisco 2009 Midyear Security Report</a>, <strong>internet criminals are becoming more sophisticated</strong>, using increasingly targeted attacks. However, Cisco predicts that increased collaboration between organizations, like what we saw with Conficker, and <strong>new security policies may make it more difficult for attacks</strong> to infiltrate and spread.</p>
<p>The Midyear Security Report provides an overview of Cisco security intelligence, including information about new threats and trends, for the first half of 2009. <strong>Highlights from the Report:</strong></p>
<ul>
<li>Criminals are exploiting traditional vulnerabilities because they believe security experts and users are paying little attention to these types of threats.</li>
<li>Compromising legitimate websites to propagate malware remains a highly effective technique</li>
<li>Web 2.0 applications have become lures for criminals</li>
<li>Criminals are now targeting online banking customers using well-designed, localized text message scams</li>
<li>The Obama administration has made strengthening U.S. cybersecurity a high priority, and plans to meet threats by using technological innovations and partnering with the private sector. Other countries are following suit.</li>
<li>Compared to 2008, the number of vulnerabilities and discrete threats has not risen as quickly.</li>
</ul>
<p>Given the interest in insider threats, the report also details a possible increase in this threat given the current economic instability. This section of the report simply reiterates other studies and articles on the topic, simply providing context for what could be a growing security trend.</p>
<p><strong><a href="http://cisco.com/en/US/prod/vpndevc/annual_security_report.html">Download the report here.</a></strong></p>
<p>Via <a href="http://securitywatch.eweek.com/enterprise_security_strategy/tying_cyber-crime_to_a_struggling_economy.html?kc=rss">eweek</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/cybercrimes-more-sophisticated-but-so-too-are-countermeasures/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>McAfee H*Commerce Web Series</title>
		<link>http://blog.absolute.com/mcafee-hcommerce-web-series/</link>
		<comments>http://blog.absolute.com/mcafee-hcommerce-web-series/#comments</comments>
		<pubDate>Fri, 22 May 2009 17:22:16 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Video Reports]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[h*commerce]]></category>
		<category><![CDATA[mcafee]]></category>
		<category><![CDATA[videos]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1380</guid>
		<description><![CDATA[McAfee launched a new web series this week entitled H*Commerce: The Business of Hacking You at StopHCommerce.com
H*Commerce, Hacker Commerce, is the &#8220;business of making money through the illegal use of technology to compromise personal and business data.&#8221; The new series will air 6 episodes, one episode being added every two weeks. Each episode involves real [...]]]></description>
			<content:encoded><![CDATA[<p>McAfee <a href="http://www.avertlabs.com/research/blog/index.php/2009/05/20/mcafee-unveils-hcommerce-web-film-series-on-cybercrime/">launched</a> a new web series this week entitled <em><strong>H*Commerce: The Business of Hacking You</strong></em> at <a href="http://www.stophcommerce.com/">StopHCommerce.com</a></p>
<p>H*Commerce, Hacker Commerce, is the &#8220;business of making money through the illegal use of technology to compromise personal and business data.&#8221; The new series will air 6 episodes, one episode being added every two weeks. Each episode involves real people doing normal online activities who are then attacked by cybercriminals. Each episode focuses on <strong>real stories in a documentary-style</strong>.</p>
<p>Here is the first webisode, &#8220;Unexpected Beginnings&#8221;, telling the story of Janella Spears, who lost more than <strong>$440,000 as the result of an email scam.</strong> The video explores the effects this cybercrime had on Janella and her family as well as Janella&#8217;s education in how to clean her system, handle hackers and stop cybercrime scams.</p>
<div><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="498" height="309" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="id" value="eplayer" /><param name="align" value="middle" /><param name="allowScriptAccess" value="sameDomain" /><param name="allowFullScreen" value="true" /><param name="quality" value="high" /><param name="bgcolor" value="#000000" /><param name="src" value="http://www.stophcommerce.com/eplayer.swf?code=07" /><embed id="eplayer" type="application/x-shockwave-flash" width="498" height="309" src="http://www.stophcommerce.com/eplayer.swf?code=07" quality="high" bgcolor="#000000" allowscriptaccess="sameDomain" allowfullscreen="true" align="middle"></embed></object></div>
<p>McAfee also recently launched a <a href="http://www.mcafee.com/us/about/corporate/fight_cybercrime/cru/index.html">Cybercrime Response Unit</a> designed to help victims of cybercrime.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/mcafee-hcommerce-web-series/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>White House Talks Cybersecurity</title>
		<link>http://blog.absolute.com/white-house-talks-cybersecurity/</link>
		<comments>http://blog.absolute.com/white-house-talks-cybersecurity/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 16:39:58 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Government Security]]></category>
		<category><![CDATA[Privacy & Security Laws]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[white house]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1311</guid>
		<description><![CDATA[Melissa Hathaway, who was appointed earlier this year to conduct a 60-day review of the cyber security efforts of the U.S. Government, presented at the RSA Conference on information security, with the report set to be released in a few days.
Melissa notes that our global digital infrastructure is neither secure nor resilient, driven by interoperability [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Melissa Hathaway</strong>, who was <a href="http://blog.absolute.com/government-auditing-cybersecurity-efforts/">appointed</a> earlier this year to conduct a 60-day <strong>review of the cyber security efforts of the U.S. Government,</strong> presented at the <a href="http://www.rsaconference.com/2009/us/index.htm">RSA Conference</a> on information security, with the report set to be released in a few days.</p>
<p>Melissa notes that our global digital infrastructure is neither secure nor resilient, driven by interoperability and efficiency rather than security. She notes that previous attempts at cybersecurity have been made in isolation and have failed; the Federal government is not organized to address this growing issue because <strong>responsibilities for cyberspace are distributed widely</strong> across federal departments and agencies.</p>
<p>During the 60-day review, the cybersecurity team identified <strong>250 needs, tasks and recommendations for a national cyber security plan</strong>. The recommendation outlines a top-down approach to cyber security, with the White House leading the way and overseeing and working with other government agencies, State and local stakeholders, as well as those in academia and the industry.</p>
<blockquote><p>Protecting cyberspace requires strong vision and leadership and will require changes in policy, technology, education, and perhaps law. We need to demonstrate abroad and here at home that the United States takes cyberspace issues, policies, and activities seriously. Achieving this vision requires leadership and commitment from the highest levels of government, industry, and civil society.</p></blockquote>
<p>Here&#8217;s a video of Melissa&#8217;s speech:</p>
<div><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="432" height="362" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="FlashVars" value="playerMode=embedded&amp;allowFullScreen=1&amp;flavor=EmbeddedPlayerVersion&amp;showOptions=0&amp;skin=http://image.com.com/gamespot/images/cne_flash/production/media_player/proteus/one/skins/proteus-zdnet.png&amp;autoPlay=false&amp;movieAspect=4.3&amp;embeddingAllowed=true&amp;clockColor=0x3b3b3b&amp;paramsURI=http%3A%2F%2Fnews.zdnet.com%2F2461-1_22-291079.xml%3Fwidth%3D432%26height%3D362%26ptype%3D6475%26mode%3Dembedded%26siteId%3D24%26autoplay%3Dtrue%26ttag%3DRichard%2BKoman%26assetId%3D4680%26nc%3D1240529635704%26nodeId%3D11155" /><param name="wmode" value="transparent" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://image.com.com/gamespot/images/cne_flash/production/media_player/proteus/one/proteus2.swf" /><embed type="application/x-shockwave-flash" width="432" height="362" src="http://image.com.com/gamespot/images/cne_flash/production/media_player/proteus/one/proteus2.swf" allowscriptaccess="always" wmode="transparent" flashvars="playerMode=embedded&amp;allowFullScreen=1&amp;flavor=EmbeddedPlayerVersion&amp;showOptions=0&amp;skin=http://image.com.com/gamespot/images/cne_flash/production/media_player/proteus/one/skins/proteus-zdnet.png&amp;autoPlay=false&amp;movieAspect=4.3&amp;embeddingAllowed=true&amp;clockColor=0x3b3b3b&amp;paramsURI=http%3A%2F%2Fnews.zdnet.com%2F2461-1_22-291079.xml%3Fwidth%3D432%26height%3D362%26ptype%3D6475%26mode%3Dembedded%26siteId%3D24%26autoplay%3Dtrue%26ttag%3DRichard%2BKoman%26assetId%3D4680%26nc%3D1240529635704%26nodeId%3D11155"></embed></object></div>
<p>The speech, if somewhat repetitive and littered with political fluff, does hint at many changes to come. Almost nothing was specified yet, and <a href="http://blog.ncircle.com/blogs/sync/archives/2009/04/the_obama_administrations_cybe.html">many</a> are critical of it. Let&#8217;s hope the report released in a few days will specify a bit more. Attempting to muster resources on the National and International level, across the government and private sectors, won&#8217;t be an easy task!</p>
<p><strong>Download Melissa Hathaway&#8217;s prepared remarks <a href="http://voices.washingtonpost.com/securityfix/Melissa%20Hathaway%20Speech%20at%20RSA.pdf">here</a></strong> [PDF]</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/white-house-talks-cybersecurity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Cybersecurity Legislation Proposed</title>
		<link>http://blog.absolute.com/new-cybersecurity-legislation-proposed/</link>
		<comments>http://blog.absolute.com/new-cybersecurity-legislation-proposed/#comments</comments>
		<pubDate>Mon, 20 Apr 2009 19:05:08 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Government Security]]></category>
		<category><![CDATA[Privacy & Security Laws]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[legislature]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1283</guid>
		<description><![CDATA[A new National cybersecurity bill is currently being introduced to legislation by Senator Rockefeller (Chairman for the Committee on Commerce, Science, and Transportation) and Senator Snowe. The bill would create the Office of the National Cybersecurity Advisor within the Executive Office of the President, an advisory position that would report directly to the President and [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/j0351700.gif" alt="" width="192" height="192" />A new National <strong>cybersecurity bill is currently being introduced</strong> to legislation by Senator <a href="http://rockefeller.senate.gov/">Rockefeller</a> (Chairman for the Committee on Commerce, Science, and Transportation) and Senator <a href="http://snowe.senate.gov/public/">Snowe</a>. The bill would create the Office of the <strong>National Cybersecurity Advisor</strong> within the Executive Office of the President, an advisory position that would report directly to the President and serve as lead on all cyber matters. This position would co-ordinate with the intelligence community as well as civilian agencies.</p>
<p>The new cybersecurity legislation proposes additional changes to address issues of cyber crime, global cyber espionage and cyber attacks.</p>
<blockquote><p>&#8220;I believe Congress must bring new high-level governmental attention to develop a fully integrated, thoroughly coordinated, public-private partnership to our cybersecurity efforts in the 21st century.&#8221; &#8211; <em>Senator Rockefeller</em></p></blockquote>
<p><strong>The Rockefeller-Snow initiative would include provisions for:</strong></p>
<ul>
<li><strong>Raising the profile of cybersecurity within the Federal government</strong>, including the aforementioned Office plus a comprehensive national strategy, a quadrennial cybersecurity review and a threat and vulnerability assessment</li>
<li><strong>Promoting public awareness and protecting civil liberties</strong>, including a legal review of the statutory and regulatory framework applicable, changes required, and a report on identity management and civil liberties</li>
<li><strong>Remaking the relationship between government and the private sector on cybersecurity</strong>, including a public-private clearinghouse for cyber threat and vulnerability information sharing, an Advisory Panel, enforceable cybersecurity standards, licensing for cybersecurity professionals, State and regional cybersecurity centers for small and medium-sized businesses, and more</li>
<li><strong>Fostering innovation and creativity in cybersecurity to develop long-term solutions, </strong>including increased recruitment for students into cybersecurity, increased funding for R&amp;D, and an attempt to place a dollar value on cybersecurity risk</li>
</ul>
<p><strong>Read more about the new cybersecurity legislation being proposed <a href="http://commerce.senate.gov/public/index.cfm?FuseAction=PressReleases.Detail&amp;PressRelease_id=bb7223ef-1d78-4de4-b1d5-4cf54fc38662&amp;Month=4&amp;Year=2009">here</a>.</strong></p>
<p>Via <a href="http://www.securityfocus.com/brief/939?ref=rss">SecurityFocus</a> ; <em>Image: clipart</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/new-cybersecurity-legislation-proposed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GAO Lists 12 Cybersecuity Strategy Improvements</title>
		<link>http://blog.absolute.com/gao-lists-12-cybersecuity-strategy-improvements/</link>
		<comments>http://blog.absolute.com/gao-lists-12-cybersecuity-strategy-improvements/#comments</comments>
		<pubDate>Wed, 01 Apr 2009 19:18:26 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Government Security]]></category>
		<category><![CDATA[Surveys & Reports]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[gao]]></category>
		<category><![CDATA[report]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1219</guid>
		<description><![CDATA[The US Government Accountability Office (GAO) recently released highlights of their study on Cybersecurity. The report notes that key improvements are needed to strengthen the Nation&#8217;s posture and criticizes the Department of Homeland Security (DHS) strongly for having &#8220;yet to fully satisfy its responsibilities designated by the national cybersecurity strategy.&#8221; Here&#8217;s a summary of the [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/gao.jpg" alt="" width="213" height="155" />The US Government Accountability Office (GAO) recently released <a href="http://www.gao.gov/products/GAO-09-432T">highlights</a> of their <strong>study on Cybersecurity</strong>. The report notes that key improvements are needed to strengthen the Nation&#8217;s posture and <strong>criticizes the Department of Homeland Security</strong> (DHS) strongly for having &#8220;yet to fully satisfy its responsibilities designated by the national cybersecurity strategy.&#8221; <strong>Here&#8217;s a summary of the report:</strong></p>
<blockquote><p>Pervasive and sustained computerbased (cyber) attacks against federal and private-sector infrastructures pose a potentially devastating impact to systems and operations and the critical infrastructures that they support. To address these threats, President Bush issued a 2003 national strategy and related policy directives aimed at improving cybersecurity nationwide. Congress and the Executive Branch, including the new administration, have subsequently taken actions to examine the adequacy of the strategy and identify areas for improvement. Nevertheless, GAO has identified this area as high risk and has reported on needed improvements in implementing the national cybersecurity strategy.</p></blockquote>
<p>The GAO made <strong>30 recommendations in key cybersecurity areas,</strong> including bolstering cyber analysis and warning capabilities, completing actions identified during cyber exercises, improving cybersecurity of infrastructure control systems, strengthening DHS&#8217; ability to help recover from Internet disruptions and addressing cybercrime.</p>
<p>In addition to these areas identified as needing improvement, the GAO report identified <strong>12 key strategy improvements</strong>:</p>
<ol>
<li>Develop a national strategy that clearly articulates strategic objectives, goals, and priorities</li>
<li>Establish White House responsibility and accountability for leading and overseeing national cybersecurity policy</li>
<li>Establish a governance structure for strategy implementation</li>
<li>Publicize and raise awareness about the seriousness of the cybersecurity problem</li>
<li>Create an accountable, operational cybersecurity organization</li>
<li>Focus more actions on prioritizing assets, assessing vulnerabilities, and reducing vulnerabilities than on developing additional plans</li>
<li>Bolster public/private partnerships through an improved value proposition and use of incentives</li>
<li>Focus greater attention on addressing the global aspects of cyberspace</li>
<li>Improve law enforcement efforts to address malicious activities in cyberspace</li>
<li>Place greater emphasis on cybersecurity research and development, including consideration of how to better coordinate government and private sector efforts</li>
<li>Increase the cadre of cybersecurity professionals</li>
<li>Make the federal government a model for cybersecurity</li>
</ol>
<p>The GAO says that the nation&#8217;s federal and private-sector infrastructure systems remain at risk without these improvements. They suggest the new administration consider these improvements as part of the nation&#8217;s cybersecurity strategy.</p>
<p>Via <a href="http://www.networkworld.com/community/node/39557">network world</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/gao-lists-12-cybersecuity-strategy-improvements/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Government Auditing Cybersecurity Efforts</title>
		<link>http://blog.absolute.com/government-auditing-cybersecurity-efforts/</link>
		<comments>http://blog.absolute.com/government-auditing-cybersecurity-efforts/#comments</comments>
		<pubDate>Wed, 25 Feb 2009 16:27:25 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Government Security]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[barack obama]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[us government]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1067</guid>
		<description><![CDATA[President Barack Obama named Melissa Hathaway to lead a 60-day review of the cybersecurity efforts of the US Government. Hathaway thus became the Acting Senior Director for Cyberspace for the National Security and Homeland Security Councils.
Melissa Hathaway, who has served as Cyber Coordination Executive to the Director of National Intelligence, chaired the National Cyber Study [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/j0439824.gif" alt="" width="155" height="155" />President Barack Obama <a href="http://www.whitehouse.gov/the_press_office/AdvisorsToConductImmediateCyberSecurityReview/">named</a> Melissa Hathaway to lead a <strong>60-day review of the cybersecurity efforts of the US Government. </strong>Hathaway thus became the Acting Senior Director for Cyberspace for the National Security and Homeland Security Councils.</p>
<p><strong>Melissa Hathaway</strong>, who has served as Cyber Coordination Executive to the Director of National Intelligence, chaired the National Cyber Study Group, a group responsible for helping develop a 5-year $30 billion dollar plan to secure federal systems and infrastructure against online threats. This <a href="http://www.nextgov.com/nextgov/ng_20080801_9053.php">Comprehensive National Cyber Security Initiative</a> (CNCI) was approved by Bush earlier last year and is still being implemented.</p>
<p>The new review will look at <strong>ongoing security programs</strong>, plans and activities and will develop recommendations to ensure they continue to meet the needs of both the public and private sectors. Essentially, Hathaway will be reviewing the progress of the existing CNCI plan and offering advice to keep it moving forward.</p>
<blockquote><p>&#8220;The national security and economic health of the United States depend on the security, stability, and integrity of our Nation’s cyberspace, both in the public and private sectors. The President is confident that we can protect our nation’s critical cyber infrastructure while at the same time adhering to the rule of law and safeguarding privacy rights and civil liberties,&#8221; <em>said Assistant to the President for Counterterrorism and Homeland Security John Brennan.</em></p></blockquote>
<p>As part of her task, Hathaway will reportedly evaluate a recommendation that a special<strong> White House &#8220;cyberadviser&#8221; role be created</strong> (something Obama <a href="http://online.wsj.com/article/SB123412824916961127.html">echoed</a> on the campaign trail). It is suggested that this role report directly to the President rather than leaving cybersecurity to the Department of Homeland Security. This type of role would help create a comprehensive plan for cybersecurity, an issue that spans all government agencies.</p>
<p>Via <a href="http://www.csoonline.com/article/480180/Obama_Taps_Bush_Aide_to_Review_Federal_Cybersecurity_Efforts">CSO Online</a>, <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9127682&amp;intsrc=news_ts_head">Computerworld</a>, <a href="http://www.govtech.com/gt/articles/617452">Govtech</a>, <a href="http://www.whitehouse.gov/the_press_office/AdvisorsToConductImmediateCyberSecurityReview/">White House</a>, <a href="http://www.usatoday.com/tech/2009-02-16-cybersecurity-expert-obama_N.htm">USA Today</a>, <a href="http://online.wsj.com/article/SB123412824916961127.html">WSJ</a> ; <em>Image: clipart</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/government-auditing-cybersecurity-efforts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
