<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0">
<channel>
<title>GovInfoSecurity.com RSS Syndication</title>
<link>http://www.govinfosecurity.com/rss_feed/rss_main.xml</link>
<description>GovInfoSecurity.com RSS News Feeds on government information security news, regulations, and education.</description>
<pubDate>Mon, 08 Feb 2010 12:10:01 -0600</pubDate>
	<item>
	<title>China: Police Shutter Hacker Site</title>
	<link>http://www.govinfosecurity.com/articles.php?art_id=2174</link>
	<guid>http://www.govinfosecurity.com/articles.php?art_id=2174</guid>
	<description>&lt;b&gt;Training Site Said to Be China's Largest&lt;/b&gt;&lt;br&gt;The Chinese government, accused by experts in the West of fostering attacks on foreign commercial and government IT systems, has shuttered that country's largest hacker training site and arrested three people.</description>
	</item>
	<item>
	<title>Melissa Hathaway Joins Terremark's Board</title>
	<link>http://www.govinfosecurity.com/articles.php?art_id=2173</link>
	<guid>http://www.govinfosecurity.com/articles.php?art_id=2173</guid>
	<description>&lt;img src=&quot;http://docs.govinfosecurity.com/files/images_articles/2173_Melissa_Hathaway_at_Cisco_cropped.jpg&quot; align=right hspace=4&gt;&lt;b&gt;Cyberspace Policy Review Leader Expanding Her Post-Government Role&lt;/b&gt;&lt;br&gt;Melissa Hathaway, who led President Obama's 60-day cyberspace policy review, has joined the board of directors of Terremark Worldwide Inc., a provider of managed IT infrastructure services.</description>
	</item>
	<item>
	<title>Technology as a Substitute for the IT Security Pro</title>
	<link>http://www.govinfosecurity.com/articles.php?art_id=2170</link>
	<guid>http://www.govinfosecurity.com/articles.php?art_id=2170</guid>
	<description>&lt;img src=&quot;http://docs.govinfosecurity.com/files/images_articles/2170_Zal_Azmi_FBI_portrait.jpg&quot; align=right hspace=4&gt;&lt;b&gt;Filling the Gap Caused by Dearth of Skilled Government Staffers&lt;/b&gt;&lt;br&gt;&quot;We are providing a technical solution that will eliminate the need for a lot of cyber professionals because we just don't have enough of them,&quot; Zalmai Azmi says.

&lt;p&gt;Can technology replace the IT security professional to safeguard government information systems?

&lt;p&gt;Zalmai Azmi, the former Federal Bureau of Investigation chief information officer, thinks so, at least in some situation, and could fill the gap caused by a shortage in government of qualified IT security personnel.</description>
	</item>
	<item>
	<title>NIST IR 7628 (Draft): Smart Grid Cybersecurity Strategy and Requirements</title>
	<link>http://www.govinfosecurity.com/regulations.php?reg_id/1895</link>
	<guid>http://www.govinfosecurity.com/regulations.php?reg_id/1895</guid>
	<description>A high-level risk assessment process used to define the cybersecurity strategy for the smart grid.</description>
	</item>
	<item>
	<title>NIST SP 800-38E: Recommendation for Block Cipher Modes of Operation</title>
	<link>http://www.govinfosecurity.com/regulations.php?reg_id/1852</link>
	<guid>http://www.govinfosecurity.com/regulations.php?reg_id/1852</guid>
	<description>The XTS-AES Mode for Confidentiality on Storage Devices</description>
	</item>
	<item>
	<title>NIST SP 800-57: Recommendations for Key Management, Part 3</title>
	<link>http://www.govinfosecurity.com/regulations.php?reg_id/1829</link>
	<guid>http://www.govinfosecurity.com/regulations.php?reg_id/1829</guid>
	<description>Application-Specific Key Management Guidance</description>
	</item>
	<item>
	<title>GAO: Managing Sensitive Information</title>
	<link>http://www.govinfosecurity.com/regulations.php?reg_id/1828</link>
	<guid>http://www.govinfosecurity.com/regulations.php?reg_id/1828</guid>
	<description>Actions needed to prevent unintended public disclosures of U.S. nuclear sites and activities.</description>
	</item>
	<item>
	<title>Emerging Threats in Financial Data Breaches</title>
	<link>http://www.govinfosecurity.com/webinars.php?webinarID=169</link>
	<guid>http://www.govinfosecurity.com/webinars.php?webinarID=169</guid>
	<description>Ten years ago, the Department of Justice was prosecuting mischief-makers for defacing web pages. Today, federal prosecutors are targeting international crime rings behind such high-profile hacks as Heartland Payment Systems, which exposed an estimated 130 million consumer accounts.
 
&lt;p&gt;&quot;We've gone from card farms to card resellers to international hackers,&quot; says Kimberly Peretti, senior counsel in the department's computer crime section.

&lt;p&gt;Peretti, who plays a prominent role in prosecutions against notorious international hackers such as Albert Gonzalez, offers an insider's view of financial data breaches. In this session, she will cover:
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Background on carding:&lt;/b&gt; discussion on the current &quot;carding scene,&quot; carding forums and carding activity (online, in-store, gift cards, PIN cashing). 
&lt;br&gt;&lt;br&gt;
&lt;li&gt;&lt;b&gt;Evolution of prosecutions:&lt;/b&gt; From carding forums in 2004 to major resellers in 2006, and now the new, international hacking rings - including the Gonzalez case.
&lt;br&gt;&lt;br&gt;
&lt;li&gt;&lt;b&gt;What we know:&lt;/b&gt; Lessons learned from the breaches and the criminals, as well as emerging methods - and victims.
&lt;br&gt;&lt;br&gt;
&lt;li&gt;&lt;b&gt;How we can respond:&lt;/b&gt; Emerging technologies and steps organizations can take today to minimize their exposure to financial data breaches. 
&lt;/ul&gt;</description>
	</item>
	<item>
	<title>Putting Threats of Cloud Computing in Perspective</title>
	<link>http://www.govinfosecurity.com/podcasts.php?podcastID=436</link>
	<guid>http://www.govinfosecurity.com/podcasts.php?podcastID=436</guid>
	<description>&lt;b&gt;David Matthews, Deputy Chief Information Security Officer, City of Seattle&lt;/b&gt;

&lt;p&gt;The hack on Gmail e-mail accounts of activists promoting human rights emanating from China is a reminder to government officials about the security and privacy threats cloud computing - Gmail is a cloud computing offering from Google - pose.

&lt;p&gt;&quot;It makes us more aware of some of the things we need to be doing as we need to do to be ready to go into cloud computing,&quot; David Matthews, Seattle deputy chief information security officer, said in an interview with GovInfoSecurity.com. &quot;It was kind of a wake up call, in a way, for all of us to really think about this is (as) security as usual. We really need to pay attention to our security and our issues and be aware of what we're jumping into when we jump into cloud computing and be ready for it.&quot;

&lt;p&gt;Matthews, who is a member of the American Bar Association's Science and Technology Committee, which has been conversing about the legal and privacy concerns of cloud computing the past few years, spoke with GovInfoSecurity.com's Eric Chabrow.

&lt;p&gt;In the interview, Matthews also addressed the:

&lt;div id='blist'&gt;Pros and cons of cloud computing for government agencies.&lt;/div&gt;
&lt;div id='blist'&gt;Pressures being mounted by government officials to exploit the financial benefits of cloud computing.&lt;/div&gt;
&lt;div id='blist'&gt;Importance of contracts with cloud computing service providers, especially in defining data ownership and auditing.&lt;/div&gt;

&lt;p&gt;Further reading:
&lt;p&gt;
&lt;b&gt;&lt;a href=' http://www.govinfosecurity.com/articles.php?art_id=1791'&gt;Interview with David Matthews: Creativity Replaces Dollars to Safeguard IT&lt;/a&gt;&lt;/b&gt;</description>
	</item>
	<item>
	<title>Improving Cyber Awareness - Strategies from Dena Haritos Tsamitis of Carnegie Mellon</title>
	<link>http://www.govinfosecurity.com/podcasts.php?podcastID=433</link>
	<guid>http://www.govinfosecurity.com/podcasts.php?podcastID=433</guid>
	<description>Dena Haritos Tsamitis has an ambitious goal for the year: to improve cyber awareness among 8 million people globally.

&lt;p&gt;The Director of Education, Training and Outreach at Carnegie Mellon University's CyLab, Dena discusses:

&lt;div id='blist'&gt;The cyber awareness challenge among people of all ages;&lt;/div&gt; 
&lt;div id='blist'&gt;Effective techniques for improving awareness; &lt;/div&gt;
&lt;div id='blist'&gt;How organizations can improve and maximize their own efforts.&lt;/div&gt;
 
&lt;p&gt;Dena oversees education, training and outreach for Carnegie Mellon CyLab, the university's cybersecurity research center. She leads the MySecureCyberspace initiative to raise &quot;cyber awareness&quot; in Internet users of all ages through a portal, game and curriculum. She guides the education initiatives of the NSF Situational Awareness for Everyone center, which explores ways to improve computer defenses by incorporating models of human, computer and attack interactions into the defenses themselves. Also through CyLab, she serves as Principle Investigator on two NSF-funded programs: the Scholarship for Service (SFS) program and the Information Assurance Capacity Building Program (IACBP). The SFS program provides full scholarships to highly qualified students pursuing studies in information assurance. The IACBP is an intensive summer program to help build information assurance education and research capacity at minority-serving colleges and universities.</description>
	</item>
	<item>
	<title>Setting Tone at the Top: Jennifer Bayuk on Leadership</title>
	<link>http://www.govinfosecurity.com/podcasts.php?podcastID=431</link>
	<guid>http://www.govinfosecurity.com/podcasts.php?podcastID=431</guid>
	<description>When it comes to enterprise security, an organization gets its tone from the top - even when the tone is set accidentally.

&lt;p&gt;How do you set the right tone? That's the topic of the new book from former CISO Jennifer Bayuk: &quot;Enterprise Security for the Executive: Setting the Tone from the Top.&quot;

&lt;p&gt;In an interview about her book, Bayuk discusses:

&lt;p&gt;&lt;div id=&quot;blist&quot;&gt;The key audience she wants to reach; &lt;/div&gt;
&lt;div id=&quot;blist&quot;&gt;The main message for enterprise leaders; &lt;/div&gt;
&lt;div id=&quot;blist&quot;&gt;Today's top enterprise security challenges and how leaders should tackle them.&lt;/div&gt;

&lt;p&gt;Bayuk is an independent consultant on topics of information confidentiality, integrity and availability. She is engaged in a wide variety of industries with projects ranging from oversight policy and metrics to technical architecture and requirements. She has a wide variety of experience in virtually every aspect of the Information Security. She was a Chief Information Security Officer, a Security Architect, a Manager of Information Systems Internal Audit, a Big 4 Security Principal Consultant and Auditor, and a Security Software Engineer. Bayuk frequently publishes on information security and audit topics. She has lectured for organizations that include ISACA, NIST, and CSI. She is certified in Information Systems Audit (CISA), Information Security Management (CISM), Information Systems Security (CISSP), and IT Governance (CGEIT). She has Masters Degrees in Computer Science and Philosophy.</description>
	</item></channel></rss>