<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0">
<channel>
<title>GovInfoSecurity.com RSS Syndication</title>
<link>http://www.govinfosecurity.com/rss_feed/rss_main.xml</link>
<description>GovInfoSecurity.com RSS News Feeds on government information security news, regulations, and education.</description>
<pubDate>Wed, 10 Mar 2010 06:10:01 -0600</pubDate>
	<item>
	<title>Survey: 9% Have Experienced ID Theft</title>
	<link>http://www.govinfosecurity.com/articles.php?art_id=2271</link>
	<guid>http://www.govinfosecurity.com/articles.php?art_id=2271</guid>
	<description>&lt;img src=&quot;http://docs.govinfosecurity.com/files/images_articles/2271_artid_2271.jpg&quot; align=right hspace=4&gt;&lt;b&gt;Of Theft Cases, 6% Involve Medical ID&lt;/b&gt;&lt;br&gt;About 9 percent of Americans have experienced an identity theft crime directly or through an immediate family member, a new survey shows.</description>
	</item>
	<item>
	<title>GAO: CNCI's Goals are at Risk</title>
	<link>http://www.govinfosecurity.com/articles.php?art_id=2268</link>
	<guid>http://www.govinfosecurity.com/articles.php?art_id=2268</guid>
	<description>&lt;img src=&quot;http://docs.govinfosecurity.com/files/images_articles/2268_Kundra2.jpg&quot; align=right hspace=4&gt;&lt;b&gt;Kundra Says GAO Misguided on One Recommendation&lt;/b&gt;&lt;br&gt;The Comprehensive National Cybersecurity Initiative will not fully achieve its goal to reduce vulnerabilities, protect against intrusions and anticipate future threats unless several challenges to its objectives are met.</description>
	</item>
	<item>
	<title>Howard Schmidt Dismisses Cyberwar Fears</title>
	<link>http://www.govinfosecurity.com/articles.php?art_id=2267</link>
	<guid>http://www.govinfosecurity.com/articles.php?art_id=2267</guid>
	<description>&lt;img src=&quot;http://docs.govinfosecurity.com/files/images_articles/2267_2087_Howard_Schmidt_with_name.jpg&quot; align=right hspace=4&gt;&lt;b&gt;Cybersecurity Coordinator: Defense of Critical IT Improved&lt;/b&gt;&lt;br&gt;White House Cybersecurity Coordinator Howard Schmidt isn't buying into the grim forecasts that the United States is ill prepared to defend the government's and nation's critical information assets from an immense virtual attack by political adversaries or cyber criminals.</description>
	</item>
	<item>
	<title>NIST Special Publication 800-73-3: Interfaces for Personal Identity Verification, Part 4</title>
	<link>http://www.govinfosecurity.com/regulations.php?reg_id/1919</link>
	<guid>http://www.govinfosecurity.com/regulations.php?reg_id/1919</guid>
	<description>The PIV Transitional Interfaces and DataModel Specification</description>
	</item>
	<item>
	<title>NIST Special Publication 800-73-3: Interfaces for Personal Identity Verification, Part 3</title>
	<link>http://www.govinfosecurity.com/regulations.php?reg_id/1918</link>
	<guid>http://www.govinfosecurity.com/regulations.php?reg_id/1918</guid>
	<description>End-Point PIV Client Application Programming Interface</description>
	</item>
	<item>
	<title>NIST SP 800-73-3: Interfaces for Personal Identity Verification, Part 2</title>
	<link>http://www.govinfosecurity.com/regulations.php?reg_id/1917</link>
	<guid>http://www.govinfosecurity.com/regulations.php?reg_id/1917</guid>
	<description>End-Point PIV Card Application Card Command Interface</description>
	</item>
	<item>
	<title>NIST SP 800-73-3: Interfaces for Personal Identity Verification, Part 1</title>
	<link>http://www.govinfosecurity.com/regulations.php?reg_id/1916</link>
	<guid>http://www.govinfosecurity.com/regulations.php?reg_id/1916</guid>
	<description>End-Point PIV Card Application Namespace, Data Model and Representation</description>
	</item>
	<item>
	<title>Defending Against Cyberattack: Emerging Solutions for Today's Threats</title>
	<link>http://www.govinfosecurity.com/webinars.php?webinarID=179</link>
	<guid>http://www.govinfosecurity.com/webinars.php?webinarID=179</guid>
	<description>Last July 4, key federal government websites were disrupted by a series of distributed denial of service attacks.

&lt;p&gt;In January, Google and 30 other major companies revealed they'd been the targets of another sophisticated cyberattack.

&lt;p&gt;These incidents confirm what we all have long believed: Our critical infrastructure is under constant attack, and the potential cost of a successful attack is staggering.

&lt;p&gt;In fact, the estimated cost from downtime caused by major attacks exceeds $6M per day. In a recent survey of federal agencies, the top security concern was the inability to protect sensitive and confidential data.

&lt;p&gt;Some eye-opening facts: 
&lt;ul&gt;
&lt;li&gt;Nearly one- third of IT executives surveyed said their own sector was either &quot;not at all prepared&quot; or &quot;not very prepared&quot; to deal with attacks or infiltration by high-level adversaries;&lt;br&gt;&lt;br&gt;

&lt;li&gt;50% of IT and security executives also identified the United States as one of the three countries &quot;most vulnerable to critical infrastructure cyberattack.&quot; 
&lt;/ul&gt;

&lt;p&gt;The solution? Increasingly, organizations turn to end-to-end encryption and tokenization coupled with hardened cryptographic operations to ensure that no matter where data goes, it is always protected. 

&lt;p&gt;This webinar will examine these solutions in detail, using the nation's payment system as an example to illustrate how data can be protected from cyber attack.

&lt;p&gt;Thales and Voltage Security have teamed to make protecting data end-to-end easier. In this webinar, you'll learn about:
&lt;ul&gt;
&lt;li&gt;End-to-End data protection via encryption and tokenization;
&lt;li&gt;Hardened operational environments that ensure sensitive data is always protected;
&lt;li&gt;How key management and a secure environment for encryption provide complete protection.
&lt;/ul&gt;</description>
	</item>
	<item>
	<title>Heartland Works with Feds to Secure IT</title>
	<link>http://www.govinfosecurity.com/podcasts.php?podcastID=462</link>
	<guid>http://www.govinfosecurity.com/podcasts.php?podcastID=462</guid>
	<description>&lt;b&gt;Steve Elefant, CIO, Heartland Payment Systems&lt;/b&gt;

&lt;p&gt;One &lt;b&gt;&lt;a href='http://blogs.govinfosecurity.com/posts.php?postID=472'&gt;theme&lt;/a&gt;&lt;/b&gt; repeated by every major Obama administration officials speaking RSA Conference 2010, the IT security conference held in early March in San Francisco, was the need for the government and business to work together to protect the nation's critical IT systems.

&lt;p&gt;Among those listening to these officials was Steve Elefant, chief information officer of  payment processor Heartland Payment Systems, a victim of a &lt;b&gt;&lt;a href='http://www.bankinfosecurity.com/heartland_breach.php'&gt;2009 breach&lt;/a&gt;&lt;/b&gt; considered the largest criminal breach of card data ever, exposing information on upward of 100 million cards.

&lt;p&gt;In an interview with Information Security Media Group Executive Editor Eric Chabrow, Elefant discusses the impact of the breach on Heartland's relationship with the government and other financial institutions to secure critical IT systems operated by the private sector.</description>
	</item>
	<item>
	<title>Hathaway Speaks Out on CNCI Declassification</title>
	<link>http://www.govinfosecurity.com/podcasts.php?podcastID=460</link>
	<guid>http://www.govinfosecurity.com/podcasts.php?podcastID=460</guid>
	<description>Melissa Hathaway worked on the development of Comprehensive National Cybersecurity Initiative when she worked in the Bush White House and assessed the CNCI as the leader of President Obama's 60-day cyberspace policy review.

&lt;p&gt;GovInfoSecurity.com's Executive Editor Eric Chabrow ran into Hathaway at the RSA Conference 2010 in San Francisco earlier this month, just after the White House issued a &lt;b&gt;&lt;a href='http://www.govinfosecurity.com/articles.php?art_id=2257'&gt;declassified summary of CNCI&lt;/a&gt;&lt;/b&gt;, a series of initiatives aimed at securing federal government information assets and the nation's critical IT infrastructure. Besides responding to a question whether declassifying parts of CNCI was a good idea, Hathaway also addressed:

&lt;ul&gt;
&lt;li&gt; Collaboration between government and the private sector and the private sector and private sector on developing cyber defenses. &lt;/li&gt;
&lt;li&gt; How much regulation the government should impose on the private sector to assure IT security. &lt;/li&gt;
&lt;li&gt; A new idea she hadn't thought of before attending the RSA IT security conference. &lt;/li&gt; &lt;/ul&gt;

&lt;p&gt;Hathaway &lt;b&gt;&lt;a href='http://www.govinfosecurity.com/articles.php?art_id=1680'&gt;left government service&lt;/a&gt;&lt;/b&gt; last summer, forming an IT security consultancy. Among her clients: Harvard Kennedy School's Belfer Center for Science and International Affairs and Cisco.

&lt;p&gt;Hathaway is a protégé of retired Adm. Mike McConnell, who resigned a year ago as the nation's National Intelligence director, returning to the management consultancy Booz Allen Hamilton. Under McConnell, Hathaway served as a senior adviser and cyber coordination executive. She chaired the National Cyber Study Group, contributing to the development of the CNCI. That led to her appointment as director of the Joint Interagency Cyber Task Force in January 2008. At Booz Allen, where she first worked with McConnell, Hathaway served as a cybersecurity strategist, leading the information operations and long-range strategy and policy support business units.

&lt;p&gt;In February 2009, President Obama charged Hathaway to conduct a wide-ranging, 60-day interagency review the government's cybersecurity plans and activities and gave her the title acting senior director for cyberspace for the National Security and Homeland Security Councils.

&lt;p&gt;Hathaway, who holds a BA from American University and a special certificate in information operations at the U.S. Armed Force Staff College.

&lt;p&gt;Here are other interviews and stories about Hathaway from the GovInfoSecurity.com archives:
 &lt;ul&gt;
&lt;li&gt;&lt;b&gt;&lt;a href='http://www.govinfosecurity.com/articles.php?art_id=1972'&gt;What Worries Melissa Hathaway?&lt;/a&gt;&lt;/b&gt; (Interview)&lt;/li&gt;

&lt;li&gt;&lt;b&gt;&lt;a href=' http://www.govinfosecurity.com/podcasts.php?podcastID=372'&gt;White House Must Lead&lt;/a&gt;&lt;/b&gt;(Interview)&lt;/li&gt;

&lt;li&gt;&lt;b&gt;&lt;a href='http://www.govinfosecurity.com/articles.php?art_id=1216'&gt;The Influencers: Melissa Hathaway&lt;/a&gt;&lt;/b&gt; (Profile)&lt;/li&gt;

&lt;li&gt;&lt;b&gt;&lt;a href='http://blogs.govinfosecurity.com/posts.php?postID=441'&gt;The Melissa Hathaway Not-So-Mystery Tour&lt;/a&gt;&lt;/b&gt; (Blog)&lt;/li&gt;
&lt;/ul&gt;</description>
	</item>
	<item>
	<title>Warren Axelrod on Banking Information Security</title>
	<link>http://www.govinfosecurity.com/podcasts.php?podcastID=456</link>
	<guid>http://www.govinfosecurity.com/podcasts.php?podcastID=456</guid>
	<description>C. Warren Axelrod is a veteran banking/security executive and thought-leader, and in an exclusive interview he discusses top security trends and threats, including:

&lt;div id='blist'&gt;Insider fraud; &lt;/div&gt;
&lt;div id='blist'&gt;Application security; &lt;/div&gt;
&lt;div id='blist'&gt;Cloud computing. &lt;/div&gt;


&lt;p&gt;Axelrod is currently executive advisor for the Financial Services Technology Consortium. Previously, he was a director of Pershing LLC, a BNY Securities Group Co., where he was responsible for global information security. He has been a senior information technology manager on Wall Street for more than 25 years, has contributed to numerous conferences and seminars, and has published extensively. He holds a Ph.D. in managerial economics from Cornell University, and a B.Sc. in electrical engineering and an M.A. in economics and statistics from Glasgow University. He is certified as a CISSP and CISM.

&lt;p&gt;&lt;div style=&quot;float:right; padding:10px;&quot;&gt;&lt;a href=&quot;rsa2010.php&quot;&gt;&lt;img src=&quot;images/rsacoverage.jpg&quot; width=&quot;300&quot; height=&quot;48&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/div&gt;</description>
	</item></channel></rss>