<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Risk Management and Compliance &#187; Computer security</title>
	<atom:link href="http://blog.kraasecurity.com/tag/computer-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kraasecurity.com</link>
	<description>Risk Assessment, Vulnerabilities, Website Security</description>
	<lastBuildDate>Wed, 06 Jul 2011 01:12:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Whitehouse has released a cybersecurity plan</title>
		<link>http://blog.kraasecurity.com/2011/05/13/whitehouse-has-released-a-cybersecurity-plan/</link>
		<comments>http://blog.kraasecurity.com/2011/05/13/whitehouse-has-released-a-cybersecurity-plan/#comments</comments>
		<pubDate>Fri, 13 May 2011 19:26:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Government Security]]></category>
		<category><![CDATA[Identity theft]]></category>
		<category><![CDATA[Security Policy]]></category>
		<category><![CDATA[Web 2.0]]></category>
		<category><![CDATA[Computer security]]></category>
		<category><![CDATA[Critical infrastructure]]></category>
		<category><![CDATA[Federal Information Security Management Act of 2002]]></category>
		<category><![CDATA[Intrusion prevention system]]></category>
		<category><![CDATA[Local Government]]></category>
		<category><![CDATA[United States]]></category>
		<category><![CDATA[United States Department of Homeland Security]]></category>
		<category><![CDATA[White House]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=313</guid>
		<description><![CDATA[According to the press release they say  "Our critical infrastructure – such as the electricity grid, financial sector, and transportation networks that sustain our way of life – have suffered repeated cyber intrusions, and cyber crime has increased dramatically over the last decade. The President has thus made cybersecurity an Administration priority. When the President released his Cyberspace Policy Review almost two years ago, he declared that the “cyber threat is one of the most serious economic and national security challenges we face as a nation.” ]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div class="wp-caption alignright" style="width: 141px"><a href="http://commons.wikipedia.org/wiki/File:US_Department_of_Homeland_Security_Seal.svg"><img title="Seal of the United States Department of Homela..." src="http://upload.wikimedia.org/wikipedia/commons/thumb/4/4c/US_Department_of_Homeland_Security_Seal.svg/300px-US_Department_of_Homeland_Security_Seal.svg.png" alt="Seal of the United States Department of Homela..." width="131" height="130" /></a><p class="wp-caption-text">Image via Wikipedia</p></div>
</div>
<p><a class="zem_slink" title="White House" rel="geolocation" href="http://maps.google.com/maps?ll=38.8976694444,-77.03655&amp;spn=0.01,0.01&amp;q=38.8976694444,-77.03655%20%28White%20House%29&amp;t=h">The Whitehouse</a> has release a cybersecurity plan.  &#8220;White House Cybersecurity Plan: What You Need To Know&#8221; (http://www.huffingtonpost.com/2011/05/12/white-houses-cybersecurity-plan_n_861382.html). Perhaps the administration is finally waking up to the need.</p>
<p>According to the press release they say  &#8220;Our critical infrastructure – such as the electricity grid, financial  sector, and transportation networks that sustain our way of life – have  suffered repeated cyber intrusions, and cyber crime has increased  dramatically over the last decade. The President has thus made  cybersecurity an Administration priority. When the President released  his Cyberspace Policy Review almost two years ago, he declared that the  “cyber threat is one of the most serious economic and national security  challenges we face as a nation.” The Administration has since taken  significant steps to better protect America against cyber threats. As  part of that work, it has become clear that our Nation cannot fully  defend against these threats unless certain parts of cybersecurity law  are updated.&#8221;</p>
<p>There are a couple of key elements to the proposed legislation:</p>
<p><strong>Protecting the American People</strong></p>
<ol>
<li> National Data Breach Reporting. Proposal to help  businesses by simplifying and standardizing the existing patchwork of 47  state laws that contain these requirements. (I personally do not think we will have 1 national privacy policy anytime soon. States rights!!)</li>
<li> Penalties for Computer Criminals. Clarifies the penalties for computer crimes, synchronizes them with  other crimes, and sets mandatory minimums for cyber intrusions into  critical infrastructure</li>
</ol>
<p><strong>Protecting our Nation’s <a class="zem_slink" title="Critical infrastructure" rel="wikipedia" href="http://en.wikipedia.org/wiki/Critical_infrastructure">Critical Infrastructure</a></strong></p>
<ol>
<li> Voluntary Government Assistance to Industry, States, and Local  Government. Proposal to enable <a class="zem_slink" title="United States Department of Homeland Security" rel="geolocation" href="http://maps.google.com/maps?ll=38.9380555556,-77.0822222222&amp;spn=0.01,0.01&amp;q=38.9380555556,-77.0822222222%20%28United%20States%20Department%20of%20Homeland%20Security%29&amp;t=h">DHS</a> to  quickly help a private-sector company, state, or local government in a breach</li>
<li> Voluntary Information Sharing with Industry, States, and Local  Government.  Proposal to help entities share information. ( Sure ATT will share information with Sprint and Bank of America will share information with the government)</li>
<li> Critical Infrastructure Cybersecurity Plans. Proposal to enable transparency to help market forces ensure that  critical-infrastructure operators are accountable for their  cybersecurity.(Thats way to vague)</li>
</ol>
<p><strong>Protecting Federal Government Computers and Networks</strong></p>
<ol>
<li> Management. Update the <a class="zem_slink" title="Federal Information Security Management Act of 2002" rel="wikipedia" href="http://en.wikipedia.org/wiki/Federal_Information_Security_Management_Act_of_2002">Federal  Information Security Management Act</a> (FISMA) and formalize DHS’ current  role in managing cybersecurity for the Federal Government’s civilian  computers and networks. (They definitely need this now!).</li>
<li> Personnel. Recruit and retain highly-qualified  cybersecurity professionals. (With reduced funding for education, we will probably have to recruit from China)</li>
<li> <a class="zem_slink" title="Intrusion prevention system" rel="wikipedia" href="http://en.wikipedia.org/wiki/Intrusion_prevention_system">Intrusion Prevention Systems</a>. Implement better IDS systems. (Imagine having to read all the log files from all the government agencies, need to outsource this effort)</li>
<li> Data Centers. Embrace Cloud Computing. (if you use cloud computing, you will rely on Facebook for your security requirements?)</li>
</ol>
<p><strong>New Framework to Protect Individuals’ Privacy and Civil Liberties</strong></p>
<p>The Administration does propose protecting civil liberties. Can the plan be any worse that everyone giving away all their information anyway on Facebook, Twitter, <a class="zem_slink" title="LinkedIn" rel="homepage" href="http://www.linkedin.com">LinkedIn</a> etc?</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.informationweek.com/news/government/security/229500148?cid=RSSfeed_IWK_ALL">White House Releases Cybersecurity Plans</a> (informationweek.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=504f89fd-f24b-4581-a4f2-f057594508de" alt="Enhanced by Zemanta" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2011/05/13/whitehouse-has-released-a-cybersecurity-plan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ponemon Institute Cyber megatrends &#8211; Some Additions Needed</title>
		<link>http://blog.kraasecurity.com/2009/11/28/ponemon-institute-cyber-megratrends-some-additions-needed/</link>
		<comments>http://blog.kraasecurity.com/2009/11/28/ponemon-institute-cyber-megratrends-some-additions-needed/#comments</comments>
		<pubDate>Sun, 29 Nov 2009 00:17:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Corporate Stupidity]]></category>
		<category><![CDATA[Could Computing]]></category>
		<category><![CDATA[Outsourcing]]></category>
		<category><![CDATA[Unstructured Data]]></category>
		<category><![CDATA[Web 2.0]]></category>
		<category><![CDATA[Cloud computing]]></category>
		<category><![CDATA[Computer security]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=170</guid>
		<description><![CDATA[Ponemon Institute recently released their  Cyber megratrends as listed below. While I agree with these I think there were a couple that could easily be added to the list. First, I would either add or modify Web 2.0 into Web 3.0. Lets look to what is going to happen versus what is happening. Incremental change [...]]]></description>
			<content:encoded><![CDATA[<p>Ponemon Institute recently released their  Cyber megratrends as listed below. While I agree with these I think there were a couple that could easily be added to the list. First, I would either add or modify Web 2.0 into Web 3.0. Lets look to what is going to happen versus what is happening. Incremental change may not be the trend.  Secondly, I suggest adding <a href="http://www.kraasecurity.com/consulting-services/network-solutions/supplier-security-assessment" target="_blank">Vendor Risk Management</a>. The vendor does not have to be offshore to pose a problem. Vendors are so integrated into companies and business processes that they are like an employee but are not subjected to the same <a href="http://www.kraasecurity.com/consulting-services/network-solutions/host-security-assessment">Network Security Assessment</a> requirements in many cases.</p>
<p>Its a difficult thing to try and forecast. The good thing about it is that no one really remembers your forecaste anyway.</p>
<p>Regards<br />
Gary Bahadur</p>
<p><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></p>
<p style="background: none transparent scroll repeat 0% 0%;"><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></p>
<p style="background: #c0c0c0;"><a onclick="javascript:pageTracker._trackPageview('/outbound/article/twitter.com');" href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a><br />
Managed Security Services<br />
<a href="http://www.kraasecurity.com/managed-services/intrusion-defense/firewall" target="_blank">Managed Firewall</a><br />
<a href="http://www.kraasecurity.com/managed-services/vulnerability-defense/internal-external-scanning" target="_blank">Managed Vulnerability Scanning</a></p>
<p>++++++++++++++++++++++++++++++++++++++++++++++++<br />
<strong>Cyber Security Mega Trends Study<br />
</strong>Prepared by Dr. Larry Ponemon, November 18, 2009</p>
<p>Related articles by Zemanta</p>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.readwriteweb.com/archives/top_web_trends_security_risks.php">Think Tank Study Shows Top Web Trends Are Security Risks</a> (readwriteweb.com)</li>
<li class="zemanta-article-ul-li"><a href="http://myventurepad.com/MVP/78391">The cloud is a powder keg</a> (myventurepad.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/b7fe4b47-d582-49fc-8e62-74349ac6b73d/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=b7fe4b47-d582-49fc-8e62-74349ac6b73d" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/11/28/ponemon-institute-cyber-megratrends-some-additions-needed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

