<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Information Risk Blog</title>
	<atom:link href="http://informationrisk.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://informationrisk.org</link>
	<description>Information Security, IT Governance, Security Policy and Strategy, Risk Management, Security Metrics, Regulatory Compliance, Global Privacy Laws, House and Senate Bills, Critical Infrastructure Security, Threat Management.</description>
	<lastBuildDate>Tue, 31 Jan 2012 08:39:32 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='informationrisk.org' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Information Risk Blog</title>
		<link>http://informationrisk.org</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://informationrisk.org/osd.xml" title="Information Risk Blog" />
	<atom:link rel='hub' href='http://informationrisk.org/?pushpress=hub'/>
		<item>
		<title>Emerging threats that &#8220;may&#8221; turn into major threats in 2012</title>
		<link>http://informationrisk.org/2012/01/02/emerging-threats-that-may-turn-into-major-threats-in-2012/</link>
		<comments>http://informationrisk.org/2012/01/02/emerging-threats-that-may-turn-into-major-threats-in-2012/#comments</comments>
		<pubDate>Mon, 02 Jan 2012 15:33:10 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Security Strategy]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2210</guid>
		<description><![CDATA[A list of threats that we read/discussed in 2011&#8230;.and agreed that some of them may become major threats in near future. Mobile and Cloud security are going to be the most talked about security issues in 2012 (though, Cloud is missing from this list). Emerging threats from 2011 are on track to become the major [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2210&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A list of threats that we read/discussed in 2011&#8230;.and agreed that some of them may become major threats in near future. Mobile and Cloud security are going to be the most talked about security issues in 2012 (though, Cloud is missing from this list).</p>
<blockquote><p>Emerging threats from 2011 are on track to become the major players for cyberactivity in 2012, including mobile banking, “legal” spam and virtual currency. McAfee Labs also predicts that attacks involving political motivation or notoriety will also make headlines, including high-profile industrial attacks, cyberwarfare demonstrations and hacktivist attacks targeting public figures.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/risk-management/'>Risk Management</a>, <a href='http://informationrisk.org/category/security-strategy/'>Security Strategy</a>, <a href='http://informationrisk.org/category/threat-management/'>Threat Management</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2210/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2210/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2210/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2210/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2210/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2210/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2210/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2210/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2210/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2210/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2210/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2210/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2210/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2210/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2210&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2012/01/02/emerging-threats-that-may-turn-into-major-threats-in-2012/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>White Hat Debit Cards</title>
		<link>http://informationrisk.org/2012/01/02/white-hat-debit-cards/</link>
		<comments>http://informationrisk.org/2012/01/02/white-hat-debit-cards/#comments</comments>
		<pubDate>Mon, 02 Jan 2012 14:02:03 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[DDoS]]></category>
		<category><![CDATA[Security Strategy]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2207</guid>
		<description><![CDATA[Elinor Mills / cnet The researchers, who can make thousands of dollars for reporting just one security hole on the social-networking site, can use the card to make purchases, just like a credit card, or create a PIN and take money out of an ATM. As the researchers find more bugs, Facebook can add more [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2207&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Elinor Mills / <a href="http://news.cnet.com/8301-27080_3-57350464-245/facebook-hands-out-white-hat-debit-cards-to-hackers/" target="_blank">cnet</a></p>
<blockquote><p>The researchers, who can make thousands of dollars for reporting just one security hole on the social-networking site, can use the card to make purchases, just like a credit card, or create a PIN and take money out of an ATM. As the researchers find more bugs, Facebook can add more money to the account.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/ddos/'>DDoS</a>, <a href='http://informationrisk.org/category/security-strategy/'>Security Strategy</a>, <a href='http://informationrisk.org/category/threat-management/'>Threat Management</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2207/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2207/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2207/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2207/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2207/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2207/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2207/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2207&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2012/01/02/white-hat-debit-cards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Santa Gets Hacked!</title>
		<link>http://informationrisk.org/2011/12/31/santa-gets-hacked/</link>
		<comments>http://informationrisk.org/2011/12/31/santa-gets-hacked/#comments</comments>
		<pubDate>Sat, 31 Dec 2011 15:25:49 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2204</guid>
		<description><![CDATA[Potential Information Security Threats (Funny video) Filed under: Uncategorized<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2204&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Potential Information Security Threats (<a href="http://vimeo.com/33402842" target="_blank">Funny video</a>)</p>
<br />Filed under: <a href='http://informationrisk.org/category/uncategorized/'>Uncategorized</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2204/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2204/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2204/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2204/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2204/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2204/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2204/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2204/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2204/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2204/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2204/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2204/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2204/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2204/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2204&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/12/31/santa-gets-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>New Electronic Authentication Guideline for Fed Agengies</title>
		<link>http://informationrisk.org/2011/12/17/new-electronic-authentication-guideline-for-fed-agengies/</link>
		<comments>http://informationrisk.org/2011/12/17/new-electronic-authentication-guideline-for-fed-agengies/#comments</comments>
		<pubDate>Sat, 17 Dec 2011 14:43:07 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Laws and Regulations]]></category>
		<category><![CDATA[Policy and Governance]]></category>
		<category><![CDATA[Risk Management]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2201</guid>
		<description><![CDATA[Electronic Authentication Guideline (NIST Special Publication 800-63-1), from the NIST expands the options for government agencies that need to verify the identity of users of their Web-based services. This recommendation provides technical guidelines for Federal agencies implementing electronic authentication and is not intended to constrict the development or use of standards outside of this purpose. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2201&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Electronic Authentication Guideline (<a href="http://www.nist.gov/customcf/get_pdf.cfm?pub_id=910006" target="_blank">NIST Special Publication 800-63-1</a>), from the NIST expands the options for government agencies that need to verify the identity of users of their Web-based services.</p>
<blockquote><p>This recommendation provides technical guidelines for Federal agencies implementing electronic authentication and is not intended to constrict the development or use of standards outside of this purpose. The recommendation covers remote authentication of users (such as employees, contractors, or private individuals) interacting with government IT systems over open networks. It defines technical requirements for each of four levels of assurance in the areas of identity proofing, registration, tokens, management processes, authentication protocols and related assertions. This publication supersedes NIST SP 800-63.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/authentication/'>Authentication</a>, <a href='http://informationrisk.org/category/laws-and-regulations/'>Laws and Regulations</a>, <a href='http://informationrisk.org/category/policy-and-governance/'>Policy and Governance</a>, <a href='http://informationrisk.org/category/risk-management/'>Risk Management</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2201/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2201&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/12/17/new-electronic-authentication-guideline-for-fed-agengies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Strategic Plan for the Federal Cyber-Security Research and Development Program</title>
		<link>http://informationrisk.org/2011/12/10/strategic-plan-for-the-federal-cyber-security-research-and-development-program/</link>
		<comments>http://informationrisk.org/2011/12/10/strategic-plan-for-the-federal-cyber-security-research-and-development-program/#comments</comments>
		<pubDate>Sat, 10 Dec 2011 16:38:23 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Laws and Regulations]]></category>
		<category><![CDATA[Policy and Governance]]></category>
		<category><![CDATA[Security Strategy]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2199</guid>
		<description><![CDATA[This report outlines the Obama Administration&#8217;s road map of priorities for government agencies that sponsor research and development on cyber-security. As recommended in the Cyberspace Policy Review’s near-term action plan, Trustworthy Cyberspace replaces the piecemeal  approaches of the past with a set of coordinated research priorities whose promise is to “change  the game,” resulting in a [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2199&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This <a href="http://www.whitehouse.gov/sites/default/files/microsites/ostp/fed_cybersecurity_rd_strategic_plan_2011.pdf" target="_blank">report</a> outlines the Obama Administration&#8217;s road map of priorities for government agencies that sponsor research and development on cyber-security.</p>
<blockquote><p>As recommended in the Cyberspace Policy Review’s near-term action plan, Trustworthy Cyberspace replaces the piecemeal  approaches of the past with a set of coordinated research priorities whose promise is to “change  the game,” resulting in a trustworthy cyberspace. As called for in the policy review’s mid-term action plan, this plan identifies opportunities to engage the private sector in activities for transitioning promising R&amp;D into practice. In addition, and consistent with the PCAST recommendations, it prioritizes the development of a “science of security” to derive first  principles and the fundamental building blocks of security and trustworthiness.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/laws-and-regulations/'>Laws and Regulations</a>, <a href='http://informationrisk.org/category/policy-and-governance/'>Policy and Governance</a>, <a href='http://informationrisk.org/category/security-strategy/'>Security Strategy</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2199/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2199&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/12/10/strategic-plan-for-the-federal-cyber-security-research-and-development-program/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Feds launch cloud security standards program</title>
		<link>http://informationrisk.org/2011/12/10/feds-launch-cloud-security-standards-program/</link>
		<comments>http://informationrisk.org/2011/12/10/feds-launch-cloud-security-standards-program/#comments</comments>
		<pubDate>Sat, 10 Dec 2011 16:30:28 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Laws and Regulations]]></category>
		<category><![CDATA[Senate or House Bill]]></category>
		<category><![CDATA[Standard / Framework]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2197</guid>
		<description><![CDATA[Jaikumar Vijayan / ComputerWorld Federal CIO Steven VanRoekel Thursday unveiled the Federal Risk and Authorization Management Program (FedRAMP), which establishes a set of baseline security and privacy standards that all cloud service providers will need to meet in order to sell their products to government agencies. The program requires that all federal agencies use only [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2197&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Jaikumar Vijayan / <a href="http://www.computerworld.com/s/article/9222525/Feds_launch_cloud_security_standards_program?taxonomyId=17" target="_blank">ComputerWorld</a></p>
<blockquote><p>Federal CIO Steven VanRoekel Thursday unveiled the Federal Risk and Authorization Management Program (FedRAMP), which establishes a set of baseline security and privacy standards that all cloud service providers will need to meet in order to sell their products to government agencies.</p>
<p>The program requires that all federal agencies use only FedRAMP-certified cloud services and technologies for public clouds, private clouds, hybrid clouds and community clouds. The program also covers all cloud service models, including Software as a Service (SaaS) and Platform as a Service (PaaS).</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/cloud-computing/'>Cloud Computing</a>, <a href='http://informationrisk.org/category/laws-and-regulations/'>Laws and Regulations</a>, <a href='http://informationrisk.org/category/senate-or-house-bill/'>Senate or House Bill</a>, <a href='http://informationrisk.org/category/standard-framework/'>Standard / Framework</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2197/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2197/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2197/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2197/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2197/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2197/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2197/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2197/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2197/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2197/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2197/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2197/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2197/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2197/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2197&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/12/10/feds-launch-cloud-security-standards-program/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Using science to generate truly random numbers</title>
		<link>http://informationrisk.org/2011/12/01/using-science-to-generate-truly-random-numbers/</link>
		<comments>http://informationrisk.org/2011/12/01/using-science-to-generate-truly-random-numbers/#comments</comments>
		<pubDate>Thu, 01 Dec 2011 21:21:12 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Communication]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2195</guid>
		<description><![CDATA[Tom Spears / Ottawa Citizens To people who want to encrypt data, this is a potential source of randomly-chosen numbers that are used as a &#8220;key&#8221; to lock and unlock sensitive data — military transmissions, banking transactions, or your email. The idea is that if no one knows how the key was created in the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2195&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Tom Spears / <a href="http://www.ottawacitizen.com/technology/Ottawa+physicist+uses+science+generate+truly+random+numbers/5779618/story.html" target="_blank">Ottawa Citizens</a></p>
<blockquote><p>To people who want to encrypt data, this is a potential source of randomly-chosen numbers that are used as a &#8220;key&#8221; to lock and unlock sensitive data — military transmissions, banking transactions, or your email.</p>
<p>The idea is that if no one knows how the key was created in the first place, hackers and code-breakers won&#8217;t be able to figure out the secret and decode the messages.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/communication/'>Communication</a>, <a href='http://informationrisk.org/category/cryptography/'>Cryptography</a>, <a href='http://informationrisk.org/category/threat-management/'>Threat Management</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2195/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2195/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2195/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2195/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2195/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2195/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2195/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2195/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2195/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2195/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2195/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2195/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2195/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2195/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2195&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/12/01/using-science-to-generate-truly-random-numbers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>APT Or Not APT? Depends upon how clear the patterns are!</title>
		<link>http://informationrisk.org/2011/11/26/apt-or-not-apt-depends-upon-how-clear-the-patterns-are/</link>
		<comments>http://informationrisk.org/2011/11/26/apt-or-not-apt-depends-upon-how-clear-the-patterns-are/#comments</comments>
		<pubDate>Sat, 26 Nov 2011 17:29:14 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Social Engineering / Phishing]]></category>
		<category><![CDATA[Training / Awareness]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2192</guid>
		<description><![CDATA[Rober Lemos / Dark Reading Separating persistent threats from more opportunistic cybercrime-focused attacks is not easy, but can help inform defense, according to security experts. Block an opportunistic attack and the crisis is averted; block a persistent attacker and they will come back tomorrow&#8230; &#8230;.. In many cases, the patterns are not clear. Even &#8220;advanced&#8221; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2192&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Rober Lemos / <a href="http://www.darkreading.com/advanced-threats/167901091/security/client-security/232200009/apt-or-not-apt-discovering-who-is-attacking-the-network.html" target="_blank">Dark Reading</a></p>
<blockquote><p>Separating persistent threats from more opportunistic cybercrime-focused attacks is not easy, but can help inform defense, according to security experts. Block an opportunistic attack and the crisis is averted; block a persistent attacker and they will come back tomorrow&#8230;</p>
<p>&#8230;..</p>
<p>In many cases, the patterns are not clear. Even &#8220;advanced&#8221; attackers will only use, for example, the minimum force necessary to compromise a network. In some cases, attackers have rented botnets; in others, they&#8217;ve used standard cybercrime tools.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/application-security/'>Application Security</a>, <a href='http://informationrisk.org/category/information-security-2/'>Information Security</a>, <a href='http://informationrisk.org/category/social-engineering-phishing/'>Social Engineering / Phishing</a>, <a href='http://informationrisk.org/category/training-awareness/'>Training / Awareness</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2192/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2192&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/11/26/apt-or-not-apt-depends-upon-how-clear-the-patterns-are/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Whose Job Is Virtualization Security?</title>
		<link>http://informationrisk.org/2011/11/26/whose-job-is-virtualization-security/</link>
		<comments>http://informationrisk.org/2011/11/26/whose-job-is-virtualization-security/#comments</comments>
		<pubDate>Sat, 26 Nov 2011 17:21:31 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Infrastructure Security]]></category>
		<category><![CDATA[Security Strategy]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2190</guid>
		<description><![CDATA[Richard Dreger / InformationWeek To provide segmentation, you need the physical hardware team, and maybe the systems team, to configure the SAN disk arrays to balance performance, storage, and access requirements. Sure, you could physically carve up the disks and give different slices to each customer to provide a physical boundary, but this concept is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2190&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Richard Dreger / <a href="http://www.informationweek.com/news/storage/virtualization/231903497" target="_blank">InformationWeek</a></p>
<blockquote><p>To provide segmentation, you need the physical hardware team, and maybe the systems team, to configure the SAN disk arrays to balance performance, storage, and access requirements. Sure, you could physically carve up the disks and give different slices to each customer to provide a physical boundary, but this concept is anathema to performance-minded shops and the private cloud model.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/cloud-computing/'>Cloud Computing</a>, <a href='http://informationrisk.org/category/infrastructure-security/'>Infrastructure Security</a>, <a href='http://informationrisk.org/category/security-strategy/'>Security Strategy</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2190/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2190/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2190/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2190/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2190/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2190/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2190/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2190/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2190/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2190/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2190/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2190/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2190/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2190/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2190&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/11/26/whose-job-is-virtualization-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>A tool to identify malicious insiders</title>
		<link>http://informationrisk.org/2011/11/24/a-tool-to-identify-malicious-insiders/</link>
		<comments>http://informationrisk.org/2011/11/24/a-tool-to-identify-malicious-insiders/#comments</comments>
		<pubDate>Thu, 24 Nov 2011 21:38:35 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Secure Coding]]></category>
		<category><![CDATA[Social Engineering / Phishing]]></category>
		<category><![CDATA[Training / Awareness]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2188</guid>
		<description><![CDATA[William Jackson / GCN The system, which is being tested in a lab environment, uses a host-based agent to “learn” a user’s behavior and to look for anomalous behavior or other signatures, said computer scientist and project leader Justin Beaver. &#8230;&#8230;&#8230;. Among the characteristic information leveraged by the system are system call sequences. Each function [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2188&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>William Jackson / <a href="http://gcn.com/articles/2011/11/17/oak-ridge-lab-stop-insider-exfiltration.aspx" target="_blank">GCN</a></p>
<blockquote><p>The system, which is being tested in a lab environment, uses a host-based agent to “learn” a user’s behavior and to look for anomalous behavior or other signatures, said computer scientist and project leader Justin Beaver.</p>
<p>&#8230;&#8230;&#8230;.</p>
<p>Among the characteristic information leveraged by the system are system call sequences. Each function on a computer initiates a series of calls for services. This occurs at a low level in the operating system, out of the user’s view, and creates a characteristic pattern for each user over time. Researchers found that normal patterns remain surprisingly consistent for individuals as they switch between computers and jobs.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/risk-management/'>Risk Management</a>, <a href='http://informationrisk.org/category/secure-coding/'>Secure Coding</a>, <a href='http://informationrisk.org/category/social-engineering-phishing/'>Social Engineering / Phishing</a>, <a href='http://informationrisk.org/category/training-awareness/'>Training / Awareness</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2188/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2188/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2188/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2188/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2188/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2188/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2188/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2188/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2188/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2188/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2188/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2188/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2188/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2188/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2188&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/11/24/a-tool-to-identify-malicious-insiders/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Warding off cyberattacks through collaboration</title>
		<link>http://informationrisk.org/2011/11/24/warding-off-cyberattacks-through-collaboration/</link>
		<comments>http://informationrisk.org/2011/11/24/warding-off-cyberattacks-through-collaboration/#comments</comments>
		<pubDate>Thu, 24 Nov 2011 21:34:55 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Consumer Information Protection]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Infrastructure Security]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2186</guid>
		<description><![CDATA[By Ellen Nakashima / Washington Post It’s easy to feel overwhelmed by the increasingly bad news in cyberspace, but there are a few bright spots. Government and commercial techies are finding some success in trying to protect computer users — often from their own careless behavior. Filed under: Consumer Information Protection, Cybersecurity, Information Security, Infrastructure [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2186&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>By Ellen Nakashima / <a href="http://www.washingtonpost.com/national/national-security/government-companies-taking-steps-to-ward-off-cyberattacks/2011/11/10/gIQAdvERVN_story.html" target="_blank">Washington Post</a></p>
<blockquote><p>It’s easy to feel overwhelmed by the increasingly bad news in cyberspace, but there are a few bright spots. Government and commercial techies are finding some success in trying to protect computer users — often from their own careless behavior.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/consumer-information-protection/'>Consumer Information Protection</a>, <a href='http://informationrisk.org/category/cybersecurity/'>Cybersecurity</a>, <a href='http://informationrisk.org/category/information-security-2/'>Information Security</a>, <a href='http://informationrisk.org/category/infrastructure-security/'>Infrastructure Security</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2186/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2186/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2186/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2186/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2186/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2186/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2186/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2186/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2186/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2186/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2186/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2186/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2186/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2186/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2186&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/11/24/warding-off-cyberattacks-through-collaboration/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Security Predictions for 2012</title>
		<link>http://informationrisk.org/2011/11/24/security-predictions-for-2012/</link>
		<comments>http://informationrisk.org/2011/11/24/security-predictions-for-2012/#comments</comments>
		<pubDate>Thu, 24 Nov 2011 21:31:01 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Report / Paper]]></category>
		<category><![CDATA[Security Strategy]]></category>
		<category><![CDATA[Survey]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2184</guid>
		<description><![CDATA[Websense With an influx of bring your own devices (BYOD) and mobility, social media exploding, cloud computing  knocking, and other operational challenges thrown in for good measure, if 2011 was the shocker, then 2012 is  likely to be the kitchen sink of security concern Filed under: Report / Paper, Security Strategy, Survey<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2184&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.websense.com/assets/reports/2012-Predictions-WS-Security-Labs.pdf?cmpid=slblog" target="_blank">Websense</a></p>
<blockquote><p>With an influx of bring your own devices (BYOD) and mobility, social media exploding, cloud computing  knocking, and other operational challenges thrown in for good measure, if 2011 was the shocker, then 2012 is  likely to be the kitchen sink of security concern</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/report-paper/'>Report / Paper</a>, <a href='http://informationrisk.org/category/security-strategy/'>Security Strategy</a>, <a href='http://informationrisk.org/category/survey/'>Survey</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2184/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2184/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2184/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2184/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2184/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2184/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2184/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2184/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2184/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2184/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2184/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2184/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2184/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2184/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2184&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/11/24/security-predictions-for-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Turning to Crowdsourcing for Intelligence</title>
		<link>http://informationrisk.org/2011/11/21/turning-to-crowdsourcing-for-intelligence/</link>
		<comments>http://informationrisk.org/2011/11/21/turning-to-crowdsourcing-for-intelligence/#comments</comments>
		<pubDate>Tue, 22 Nov 2011 04:11:09 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Communication]]></category>
		<category><![CDATA[Metrics]]></category>
		<category><![CDATA[Security Strategy]]></category>
		<category><![CDATA[Survey]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2182</guid>
		<description><![CDATA[Dan Parsons / National Defense Magazine The goal is to demonstrate better accuracy in predicting near-term and middle-term events than an opinion poll by the end of the four-year experiment. In the first year, Warnaar is seeking to achieve a 20 percent improvement over traditional polling methods. If its predictions turn out more accurate, the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2182&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Dan Parsons /<a href="http://www.nationaldefensemagazine.org/archive/2011/December/Pages/USGovernmentTurnstoCrowdsourcingforIntelligence.aspx" target="_blank"> National Defense Magazine</a></p>
<blockquote><p>The goal is to demonstrate better accuracy in predicting near-term and middle-term events than an opinion poll by the end of the four-year experiment. In the first year, Warnaar is seeking to achieve a 20 percent improvement over traditional polling methods. If its predictions turn out more accurate, the program will be made available to government decision makers.</p>
<p>Questions from informed policy makers could then be fed into ACES and predictions would be based on weighted answers from program participants.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/communication/'>Communication</a>, <a href='http://informationrisk.org/category/metrics/'>Metrics</a>, <a href='http://informationrisk.org/category/security-strategy/'>Security Strategy</a>, <a href='http://informationrisk.org/category/survey/'>Survey</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2182/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2182/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2182/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2182/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2182/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2182/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2182/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2182/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2182/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2182/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2182/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2182/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2182/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2182/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2182&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/11/21/turning-to-crowdsourcing-for-intelligence/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Life Logging Risk Assessment</title>
		<link>http://informationrisk.org/2011/11/21/life-logging-risk-assessment-2/</link>
		<comments>http://informationrisk.org/2011/11/21/life-logging-risk-assessment-2/#comments</comments>
		<pubDate>Tue, 22 Nov 2011 04:05:16 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Consumer Information Protection]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Social Engineering / Phishing]]></category>
		<category><![CDATA[Tech and Laws]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2162</guid>
		<description><![CDATA[ENISA&#8217;s Report The top risk for individuals utilising life-logging devices and scenarios is the threat to privacy that accompany using them. Loss of control over this data might result in individuals being subjected to financial fraud or unauthorised access might result in reputational harm or discrimination and exclusion. This risk is compounded by the nature [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2162&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.enisa.europa.eu/act/rm/emerging-and-future-risk/deliverables/life-logging-risk-assessment/to-log-or-not-to-log-risks-and-benefits-of-emerging-life-logging-applications/at_download/fullReport" target="_blank">ENISA&#8217;s Report</a></p>
<blockquote><p>The top risk for individuals utilising life-logging devices and scenarios is the threat to privacy that accompany using them. Loss of control over this data might result in individuals being subjected to financial fraud or unauthorised access might result in reputational harm or discrimination and exclusion. This risk is compounded by the nature of life-logging in that apart from privacy threat to individuals coming from commercial entities and governmental agencies, there is also a threat of deliberate or accidental data collection about one person by other individuals.</p>
<p>Dependency on the availability of certain devices or services is also increasing the risks for individuals, as the mobile devices, sensors or services become more attractive targets for attackers. In this direction, it is particularly important the link between tangible and intangible assets, as we can also see in Future Internet scenarios; a related risk is the loss of autonomy.</p>
<p>Finally, we should consider risks such as psychological damage, related to discrimination, exclusion, harassing, cyberstalking, child grooming, feeling of being continuously under surveillance (paranoid behaviour), pressures related to work performance, peering into other peoples life etc.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/consumer-information-protection/'>Consumer Information Protection</a>, <a href='http://informationrisk.org/category/risk-management/'>Risk Management</a>, <a href='http://informationrisk.org/category/social-engineering-phishing/'>Social Engineering / Phishing</a>, <a href='http://informationrisk.org/category/tech-and-laws/'>Tech and Laws</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2162/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2162/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2162/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2162/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2162/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2162/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2162/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2162&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/11/21/life-logging-risk-assessment-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Life Logging Risk Assessment</title>
		<link>http://informationrisk.org/2011/11/21/life-logging-risk-assessment/</link>
		<comments>http://informationrisk.org/2011/11/21/life-logging-risk-assessment/#comments</comments>
		<pubDate>Tue, 22 Nov 2011 04:03:42 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://informationrisk.org/2011/11/21/life-logging-risk-assessment/</guid>
		<description><![CDATA[ENISA&#8217;s Report The top risk for individuals utilising life-logging devices and scenarios is the threat to privacy that accompany using them. Loss of control over this data might result in individuals being subjected to financial fraud or unauthorised access might result in reputational harm or discrimination and exclusion. This risk is compounded by the nature [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2178&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.enisa.europa.eu/act/rm/emerging-and-future-risk/deliverables/life-logging-risk-assessment/to-log-or-not-to-log-risks-and-benefits-of-emerging-life-logging-applications/at_download/fullReport" target="_blank">ENISA&#8217;s Report</a></p>
<blockquote><p>The top risk for individuals utilising life-logging devices and scenarios is the threat to privacy that accompany using them. Loss of control over this data might result in individuals being subjected to financial fraud or unauthorised access might result in reputational harm or discrimination and exclusion. This risk is compounded by the nature of life-logging in that apart from privacy threat to individuals coming from commercial entities and governmental agencies, there is also a threat of deliberate or accidental data collection about one person by other individuals.</p>
<p>Dependency on the availability of certain devices or services is also increasing the risks for individuals, as the mobile devices, sensors or services become more attractive targets for attackers. In this direction, it is particularly important the link between tangible and intangible assets, as we can also see in Future Internet scenarios; a related risk is the loss of autonomy.</p>
<p>Finally, we should consider risks such as psychological damage, related to discrimination, exclusion, harassing, cyberstalking, child grooming, feeling of being continuously under surveillance (paranoid behaviour), pressures related to work performance, peering into other peoples life etc.</p>
</blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/uncategorized/'>Uncategorized</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2178/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2178/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2178/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2178/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2178/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2178/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2178/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2178&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/11/21/life-logging-risk-assessment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>DARPA Boosts Cybersecurity Research Spending</title>
		<link>http://informationrisk.org/2011/11/11/darpa-boosts-cybersecurity-research-spending/</link>
		<comments>http://informationrisk.org/2011/11/11/darpa-boosts-cybersecurity-research-spending/#comments</comments>
		<pubDate>Sat, 12 Nov 2011 03:49:09 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Laws and Regulations]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Security Strategy]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2160</guid>
		<description><![CDATA[J. Nicholas Hoover / InformationWeek  &#8220;We are losing ground because we are inherently divergent from the threat,&#8221; she said, noting that while the size of viruses has remained small over the years, the defensive security apparatus continues to grow. &#8220;Such divergences are the seeds of surprise, and this [size disparity] is a striking example of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2160&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>J. Nicholas Hoover / <a href="http://www.informationweek.com/news/government/security/231902495" target="_blank">InformationWeek </a></p>
<blockquote><p>&#8220;We are losing ground because we are inherently divergent from the threat,&#8221; she said, noting that while the size of viruses has remained small over the years, the defensive security apparatus continues to grow. &#8220;Such divergences are the seeds of surprise, and this [size disparity] is a striking example of why it&#8217;s currently easier to play offense rather than defense in cyber. This is not to suggest that we stop doing what we are doing in cybersecurity. But if we continue only down the current path, we will not converge with the threat.&#8221;</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/laws-and-regulations/'>Laws and Regulations</a>, <a href='http://informationrisk.org/category/risk-management/'>Risk Management</a>, <a href='http://informationrisk.org/category/security-strategy/'>Security Strategy</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2160/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2160&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/11/11/darpa-boosts-cybersecurity-research-spending/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Tim Berners-Lee on vision for the future of IT security</title>
		<link>http://informationrisk.org/2011/11/05/tim-berners-lee-on-vision-for-the-future-of-it-security/</link>
		<comments>http://informationrisk.org/2011/11/05/tim-berners-lee-on-vision-for-the-future-of-it-security/#comments</comments>
		<pubDate>Sat, 05 Nov 2011 16:30:40 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2157</guid>
		<description><![CDATA[Ron Condon / SearchSecurity Berners-Lee also outlined the notion of a security friendly Web interface in which users would be able to divide their lives into their different activities – for instance, family, work, public – each of which could be colour coded and assigned a different level of privacy, set by the user. This way, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2157&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Ron Condon / <a href="http://searchsecurity.techtarget.co.uk/news/2240101589/Web-inventor-Tim-Berners-Lee-on-vision-for-the-future-of-IT-security" target="_blank">SearchSecurity</a></p>
<blockquote><p>Berners-Lee also outlined the notion of a security friendly Web interface in which users would be able to divide their lives into their different activities – for instance, family, work, public – each of which could be colour coded and assigned a different <a href="http://searchsecurity.techtarget.co.uk/news/2240047818/ICO-approves-policy-changes-after-Google-Street-View-privacy-issues">level of privacy</a>, set by the user. This way, even when filling out a form, the different fields could be given different colours according to their privacy rating. This kind of approach, he said, could create “an explosion of interesting new applications.”</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/cryptography/'>Cryptography</a>, <a href='http://informationrisk.org/category/information-security-2/'>Information Security</a>, <a href='http://informationrisk.org/category/privacy/'>Privacy</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2157/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2157&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/11/05/tim-berners-lee-on-vision-for-the-future-of-it-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>NIST Issues Cloud Computing Roadmap</title>
		<link>http://informationrisk.org/2011/11/05/nist-issues-cloud-computing-roadmap/</link>
		<comments>http://informationrisk.org/2011/11/05/nist-issues-cloud-computing-roadmap/#comments</comments>
		<pubDate>Sat, 05 Nov 2011 15:56:44 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Infrastructure Security]]></category>
		<category><![CDATA[Laws and Regulations]]></category>
		<category><![CDATA[Policy and Governance]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2155</guid>
		<description><![CDATA[Eric Chabrow / BankInfoSecurity The National Institute of Standards and Technology said the draft publication defines high-priority requirements for standards, official guidance and technology developments that need to be met in order for agencies to accelerate their migration of existing IT systems to the cloud computing model. &#8220;A key contribution of the roadmap effort is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2155&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Eric Chabrow / <a href="http://www.bankinfosecurity.com/articles.php?art_id=4209" target="_blank">BankInfoSecurity</a></p>
<blockquote><p>The National Institute of Standards and Technology said the draft publication defines high-priority requirements for standards, official guidance and technology developments that need to be met in order for agencies to accelerate their migration of existing IT systems to the cloud computing model. &#8220;A key contribution of the roadmap effort is to focus the discussion to achieve a clear understanding between the government and private sector, particularly on the specific technical steps &#8211; standards, guidance and technology solutions &#8211; needed to move federal IT from its current early-cloud state to a cloud-based foundation, as envisioned in the Federal Cloud Computing Strategy.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/cloud-computing/'>Cloud Computing</a>, <a href='http://informationrisk.org/category/infrastructure-security/'>Infrastructure Security</a>, <a href='http://informationrisk.org/category/laws-and-regulations/'>Laws and Regulations</a>, <a href='http://informationrisk.org/category/policy-and-governance/'>Policy and Governance</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2155/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2155&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/11/05/nist-issues-cloud-computing-roadmap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Tool to plan for Cyberattack</title>
		<link>http://informationrisk.org/2011/10/29/tool-to-plan-for-cyberattack/</link>
		<comments>http://informationrisk.org/2011/10/29/tool-to-plan-for-cyberattack/#comments</comments>
		<pubDate>Sat, 29 Oct 2011 04:40:11 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Policy and Governance]]></category>
		<category><![CDATA[Security Strategy]]></category>
		<category><![CDATA[Tech and Laws]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2153</guid>
		<description><![CDATA[ComputerWorld / Nancy Gohring The Small Biz Cyber Planner will ask a series of questions such as &#8220;Does your business use credit cards?&#8221; and &#8220;Does your business have a public website?&#8221; Based on the responses, it will generate a planning guide to help companies put in place basic policies to protect against cyberthreats. Filed under: [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2153&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.computerworld.com/s/article/9221163/FCC_unveils_tool_to_help_small_businesses_plan_for_cyberattack" target="_blank">ComputerWorld</a> / Nancy Gohring</p>
<blockquote><p>The Small Biz Cyber Planner will ask a series of questions such as &#8220;Does your business use credit cards?&#8221; and &#8220;Does your business have a public website?&#8221; Based on the responses, it will generate a planning guide to help companies put in place basic policies to protect against cyberthreats.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/policy-and-governance/'>Policy and Governance</a>, <a href='http://informationrisk.org/category/security-strategy/'>Security Strategy</a>, <a href='http://informationrisk.org/category/tech-and-laws/'>Tech and Laws</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2153/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2153/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2153/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2153/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2153/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2153/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2153/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2153/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2153/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2153/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2153/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2153/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2153/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2153/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2153&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/10/29/tool-to-plan-for-cyberattack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Alternate Internet to Secure Critical Infrastructures</title>
		<link>http://informationrisk.org/2011/10/29/alternate-internet-to-secure-critical-infrastructures/</link>
		<comments>http://informationrisk.org/2011/10/29/alternate-internet-to-secure-critical-infrastructures/#comments</comments>
		<pubDate>Sat, 29 Oct 2011 04:36:22 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Infrastructure Security]]></category>
		<category><![CDATA[Policy and Governance]]></category>
		<category><![CDATA[Risk Management]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2151</guid>
		<description><![CDATA[ExecutiveGov / Katelyn Noland The alternate Internet would be built with the intention of securing critical systems where there would be strict access rules and those who are allowed entry must report any suspicious behavior. Filed under: Infrastructure Security, Policy and Governance, Risk Management<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2151&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.executivegov.com/2011/10/fbis-shawn-henry-proposes-alternate-internet-to-secure-critical-infrastructures/" target="_blank">ExecutiveGov</a> / Katelyn Noland</p>
<blockquote><p>The alternate Internet would be built with the intention of securing critical systems where there would be strict access rules and those who are allowed entry must report any suspicious behavior.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/infrastructure-security/'>Infrastructure Security</a>, <a href='http://informationrisk.org/category/policy-and-governance/'>Policy and Governance</a>, <a href='http://informationrisk.org/category/risk-management/'>Risk Management</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2151/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2151&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/10/29/alternate-internet-to-secure-critical-infrastructures/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Insecure encryption standard?</title>
		<link>http://informationrisk.org/2011/10/24/insecure-encryption-standard/</link>
		<comments>http://informationrisk.org/2011/10/24/insecure-encryption-standard/#comments</comments>
		<pubDate>Tue, 25 Oct 2011 00:58:48 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Communication]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Vulnerability Analysis]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2149</guid>
		<description><![CDATA[Computer World / Lucian Constantin Researchers Juraj Somorovsky and Tibor Jager from the Ruhr University of Bochum (RUB) in Germany, devised an attack that decrypts data secured with the DES (Data Encryption Standard) or the AES (Advanced Encryption Standard) in CBC (cipher block chaining) mode. They plan to present their findings in more detail at the ACM [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2149&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.computerworld.com/s/article/9221122/Widely_used_encryption_standard_is_insecure_say_experts" target="_blank">Computer World</a> / Lucian Constantin</p>
<p>Researchers Juraj Somorovsky and Tibor Jager from the Ruhr University of Bochum (RUB) in Germany, devised an attack that decrypts data secured with the DES (Data Encryption Standard) or the AES (Advanced Encryption Standard) in CBC (cipher block chaining) mode. They plan to present their findings in more detail at the ACM Conference on Computer and Communications Security later this year.</p>
<p>According to Jrg Schwenk who teaches of Electrical Engineering and Information Technology at RUB, all data encryption algorithms recommended in the XML Encryption standard are affected by this attack, which relies on sending modified ciphertexts to the server and analyzing the errors for clues.</p>
<br />Filed under: <a href='http://informationrisk.org/category/communication/'>Communication</a>, <a href='http://informationrisk.org/category/cryptography/'>Cryptography</a>, <a href='http://informationrisk.org/category/vulnerability-analysis/'>Vulnerability Analysis</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2149/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2149&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/10/24/insecure-encryption-standard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Classified Smart Phones</title>
		<link>http://informationrisk.org/2011/10/23/classified-smart-phones/</link>
		<comments>http://informationrisk.org/2011/10/23/classified-smart-phones/#comments</comments>
		<pubDate>Mon, 24 Oct 2011 02:45:39 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Infrastructure Security]]></category>
		<category><![CDATA[Report / Paper]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2147</guid>
		<description><![CDATA[GCN / Henry Kenyon A research team from Google, George Mason University and the National Security Agency have developed a hardened kernel for the Android 3.0 operating system that could solve the problem of using smart phones in military operations and emergency response. The kernel, which is in the final stages of certification testing, opens the way [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2147&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://gcn.com/articles/2011/10/11/ausa-secure-andriod-kernel-technology.aspx" target="_blank">GCN</a> / Henry Kenyon</p>
<blockquote><p>A research team from Google, George Mason University and the National Security Agency have developed a hardened kernel for the Android 3.0 operating system that could solve the problem of using smart phones in military operations and emergency response.</p>
<p>The kernel, which is in the final stages of certification testing, opens the way for the Army to begin issuing smart phones or tablet-type wireless devices to troops in combat operations.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/infrastructure-security/'>Infrastructure Security</a>, <a href='http://informationrisk.org/category/report-paper/'>Report / Paper</a>, <a href='http://informationrisk.org/category/threat-management/'>Threat Management</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2147/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2147/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2147/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2147/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2147/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2147/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2147/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2147/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2147/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2147/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2147/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2147/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2147/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2147/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2147&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/10/23/classified-smart-phones/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Cloud Security Layer</title>
		<link>http://informationrisk.org/2011/10/11/cloud-security-layer/</link>
		<comments>http://informationrisk.org/2011/10/11/cloud-security-layer/#comments</comments>
		<pubDate>Wed, 12 Oct 2011 03:58:20 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[DDoS]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2145</guid>
		<description><![CDATA[Wolfgang Gruener / Tom&#8217;s Hardware Researchers at North Carolina State University and IBM said they may have found a way to effectively protect certain information in cloud and services environments. A new technique called Strongly Isolated Computing Environment” (SICE) aims to isolate sensitive information and workload from the rest of the functions performed by a [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2145&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Wolfgang Gruener /<a href="http://www.tomshardware.com/news/cloud-computing-hypervisor-security,13641.html" target="_blank"> Tom&#8217;s Hardware</a></p>
<blockquote><p>Researchers at North Carolina State University and IBM said they may have found a way to effectively protect certain information in cloud and services environments. A new technique called Strongly Isolated Computing Environment” (SICE) aims to isolate sensitive information and workload from the rest of the functions performed by a hypervisor, which serves as gateway to a virtual, cross-platform workspace shared by users in a cloud system.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/cloud-computing/'>Cloud Computing</a>, <a href='http://informationrisk.org/category/cybersecurity/'>Cybersecurity</a>, <a href='http://informationrisk.org/category/ddos/'>DDoS</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2145/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2145/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2145/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2145/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2145/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2145/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2145/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2145/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2145/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2145/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2145/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2145/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2145/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2145/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2145&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/10/11/cloud-security-layer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Monthly Security Reports For Agencies</title>
		<link>http://informationrisk.org/2011/10/02/monthly-security-reports-for-agencies/</link>
		<comments>http://informationrisk.org/2011/10/02/monthly-security-reports-for-agencies/#comments</comments>
		<pubDate>Mon, 03 Oct 2011 00:28:27 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Metrics]]></category>
		<category><![CDATA[Risk Management]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2142</guid>
		<description><![CDATA[In private sector, security dashboards have become a norm&#8230;..for fed agengies, the requirement has been known for a while &#8211; but now it&#8217;s time to comply to ensure  more focused action plans for improving their IS posture. The Department of Homeland Security (DHS) outlined new requirements for FISMA, the National Institute of Standards and Technology (NIST) [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2142&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In private sector, security dashboards have become a norm&#8230;..for fed agengies, the requirement has been known for a while &#8211; but now it&#8217;s <a href="http://www.informationweek.com/news/government/security/231601481" target="_blank">time to comply </a>to ensure  more focused action plans for improving their IS posture.</p>
<blockquote><p>The Department of Homeland Security (DHS) <a href="http://www.whitehouse.gov/sites/default/files/omb/memoranda/2011/m11-33.pdf">outlined new requirements</a> for FISMA, the National Institute of Standards and Technology (NIST) security standard for federal IT solutions. One of them calls for agencies to establish monthly data feeds to CyberScope, a compliance tool developed to help the feds to better and more actively monitor cybersecurity.</p>
<p>&#8230;&#8230;</p>
<p>Indeed, CyberScope represents a major shift in the way federal agencies report FISMA compliance in that it replaces once-a-year compliance reporting with a more operational, consistent approach.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/cybersecurity/'>Cybersecurity</a>, <a href='http://informationrisk.org/category/metrics/'>Metrics</a>, <a href='http://informationrisk.org/category/risk-management/'>Risk Management</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2142/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2142/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2142/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2142/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2142/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2142/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2142/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2142/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2142/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2142/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2142/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2142/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2142/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2142/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2142&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/10/02/monthly-security-reports-for-agencies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Understanding Cloud Security Standards</title>
		<link>http://informationrisk.org/2011/10/02/understanding-cloud-security-standards/</link>
		<comments>http://informationrisk.org/2011/10/02/understanding-cloud-security-standards/#comments</comments>
		<pubDate>Sun, 02 Oct 2011 16:34:52 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cybersecurity]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2140</guid>
		<description><![CDATA[Gunnar Peterson, in his feed on Intel&#8217;s Cloud Access Security blog, discusses four Anti-Patterns that have emerged in Cloud Security The first step to dealing with Cloud Security Anti-Patterns is deploying a Policy Enforcement Point to give the Information Security team a place to implement controls that avoid the Anti-Patterns and enable more robust security [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2140&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Gunnar Peterson, in his <a href="http://blogs.intel.com/cloud-access-security/2011/09/understanding-cloud-security-s.php" target="_blank">feed</a> on Intel&#8217;s Cloud Access Security blog, discusses four Anti-Patterns that have emerged in Cloud Security</p>
<blockquote><p>The first step to dealing with Cloud Security Anti-Patterns is deploying a Policy Enforcement Point to give the Information Security team a place to implement controls that avoid the Anti-Patterns and enable more robust security architecture.</p>
<p>A checklist for Mitigating the Anti-Patterns</p>
<ul>
<li>Low/no access control &#8211; strong access control protocols for authentication and authorization</li>
<li>Replicating user accounts &#8211; retain enterprise provisioning on Cloud Consumer side</li>
<li>Copying credentials &#8211; implement federated identity</li>
<li>“Trusted” proxy &#8211; improved audit logging and monitoring on the Gateway</li>
</ul>
</blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/authentication/'>Authentication</a>, <a href='http://informationrisk.org/category/cloud-computing/'>Cloud Computing</a>, <a href='http://informationrisk.org/category/cybersecurity/'>Cybersecurity</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2140/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2140/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2140/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2140/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2140/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2140/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2140/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2140/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2140/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2140/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2140/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2140/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2140/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2140/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2140&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/10/02/understanding-cloud-security-standards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Kevin Mitnick&#8217;s New Book: Ghost in the Wires</title>
		<link>http://informationrisk.org/2011/10/01/kevin-mitnicks-new-book-ghost-in-the-wires/</link>
		<comments>http://informationrisk.org/2011/10/01/kevin-mitnicks-new-book-ghost-in-the-wires/#comments</comments>
		<pubDate>Sun, 02 Oct 2011 02:15:56 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Report / Paper]]></category>
		<category><![CDATA[Social Engineering / Phishing]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2136</guid>
		<description><![CDATA[Ghost in the Wires is a thrilling true story of intrigue, suspense, and unbelievable escape, and a portrait of a visionary whose creativity, skills, and persistence forced the authorities to rethink the way they pursued him, inspiring ripples that brought permanent changes in the way people and companies protect their most sensitive information. Filed under: Report [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2136&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><em><a href="http://www.amazon.com/exec/obidos/ASIN/0316037702/shoppingwebsi-20" target="_blank">Ghost in the Wires</a></em> is a thrilling true story of intrigue, suspense, and unbelievable escape, and a portrait of a visionary whose creativity, skills, and persistence forced the authorities to rethink the way they pursued him, inspiring ripples that brought permanent changes in the way people and companies protect their most sensitive information.</p>
<br />Filed under: <a href='http://informationrisk.org/category/report-paper/'>Report / Paper</a>, <a href='http://informationrisk.org/category/social-engineering-phishing/'>Social Engineering / Phishing</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2136/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2136&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/10/01/kevin-mitnicks-new-book-ghost-in-the-wires/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Sound Database Security Starts With Segmentation</title>
		<link>http://informationrisk.org/2011/10/01/sound-database-security-starts-with-segmentation/</link>
		<comments>http://informationrisk.org/2011/10/01/sound-database-security-starts-with-segmentation/#comments</comments>
		<pubDate>Sun, 02 Oct 2011 02:09:32 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Infrastructure Security]]></category>
		<category><![CDATA[Risk Management]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2134</guid>
		<description><![CDATA[Ericka Chickowski / Dark Reading While database security activities in and of themselves might not necessarily be enormous tasks to tackle individually, it is scale that trips up organization. It can take a long time to implement a carefully planned security program blanketed across hundreds or even thousands of databases. In the meantime, organizations can&#8217;t [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2134&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Ericka Chickowski / <a href="http://www.darkreading.com/database-security/167901020/security/news/231602086/sound-database-security-starts-with-segmentation.html" target="_blank">Dark Reading</a></p>
<blockquote><p>While database security activities in and of themselves might not necessarily be enormous tasks to tackle individually, it is scale that trips up organization. It can take a long time to implement a carefully planned security program blanketed across hundreds or even thousands of databases. In the meantime, organizations can&#8217;t afford to leave critical data flapping in the wind. By segmenting the network and compartmentalizing data by criticality, you can effectively perform a database security triage to put other compensating controls around the most important data.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/information-security-2/'>Information Security</a>, <a href='http://informationrisk.org/category/infrastructure-security/'>Infrastructure Security</a>, <a href='http://informationrisk.org/category/risk-management/'>Risk Management</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2134/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2134&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/10/01/sound-database-security-starts-with-segmentation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>NIST&#8217;s Guide for Conducting  Risk Assessments</title>
		<link>http://informationrisk.org/2011/10/01/nists-guide-for-conducting-risk-assessments/</link>
		<comments>http://informationrisk.org/2011/10/01/nists-guide-for-conducting-risk-assessments/#comments</comments>
		<pubDate>Sat, 01 Oct 2011 14:01:05 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Policy and Governance]]></category>
		<category><![CDATA[Report / Paper]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Standard / Framework]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2129</guid>
		<description><![CDATA[The National Institute for Standards and Technology (NIST) is currently seeking comments through Nov. 4 on its Guide for Conducting Risk Assessments. In addition to providing a comprehensive process for assessing information security risk, the publication also describes how to apply the process at the three tiers in the risk management hierarchy—the organization level, mission/business process [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2129&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The National Institute for Standards and Technology (NIST) is currently seeking comments through Nov. 4 on its <a href="http://csrc.nist.gov/publications/drafts/800-30-rev1/SP800-30-Rev1-ipd.pdf">Guide for Conducting Risk Assessments</a>.</p>
<blockquote><p>In addition to providing a comprehensive process for assessing information security risk, the publication also describes how to apply the process at the three tiers in the risk management hierarchy—the organization level, mission/business process level, and information system level.</p>
<p>To facilitate ease of use for individuals or groups conducting risk assessments within organizations, a set of exemplary templates, tables, and assessment scales for common risk factors is also provided. The templates, tables, and assessment scales give maximum flexibility in designing risk assessments based on the express purpose, scope, assumptions, and constraints established by organizations.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/policy-and-governance/'>Policy and Governance</a>, <a href='http://informationrisk.org/category/report-paper/'>Report / Paper</a>, <a href='http://informationrisk.org/category/risk-management/'>Risk Management</a>, <a href='http://informationrisk.org/category/standard-framework/'>Standard / Framework</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2129/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2129/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2129/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2129/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2129/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2129/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2129/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2129/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2129/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2129/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2129/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2129/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2129/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2129/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2129&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/10/01/nists-guide-for-conducting-risk-assessments/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Measuring Impact of Wi-Fi Denial-of-Service Attacks</title>
		<link>http://informationrisk.org/2011/09/17/measuring-impact-of-wi-fi-denial-of-service-attacks/</link>
		<comments>http://informationrisk.org/2011/09/17/measuring-impact-of-wi-fi-denial-of-service-attacks/#comments</comments>
		<pubDate>Sat, 17 Sep 2011 18:27:39 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Communication]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[Infrastructure Security]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2125</guid>
		<description><![CDATA[John Cox / CSO In a Wi-Fi network, the Denial of Service attacks are usually generated by so called &#8216;backoff misbehavior,&#8217;&#8221; she says. Based on the Wi-Fi protocols, client radios &#8220;listen&#8221; to see if the radio channel is being used. If it is, it &#8220;backs off&#8221; and waits for a set period, and then listens again. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2125&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>John Cox / <a href="http://www.csoonline.com/article/689875/measuring-impact-of-wi-fi-denial-of-service-attacks" target="_blank">CSO</a></p>
<blockquote><p>In a Wi-Fi network, the Denial of Service attacks are usually generated by so called &#8216;backoff misbehavior,&#8217;&#8221; she says. Based on the Wi-Fi protocols, client radios &#8220;listen&#8221; to see if the radio channel is being used. If it is, it &#8220;backs off&#8221; and waits for a set period, and then listens again. If the channel is clear, it can claim it, and send or receive data.</p>
<p>But an attacker can manipulate this process, changing the rules, Wang says. &#8220;[W]hen attacks change the rules of backoff time, it is similar to crashing a queue and occupying it forever,&#8221; she says. &#8220;Of course, [the] other users do not know what happened and would assume the entire network is down.&#8221;</p>
<p>By shortening its own backoff time, the attacker &#8220;can increase the chances of connecting to the access point dramatically, resulting in a much higher probability of access success.&#8221;</p></blockquote>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<br />Filed under: <a href='http://informationrisk.org/category/communication/'>Communication</a>, <a href='http://informationrisk.org/category/ddos/'>DDoS</a>, <a href='http://informationrisk.org/category/infrastructure-security/'>Infrastructure Security</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2125/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2125&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/09/17/measuring-impact-of-wi-fi-denial-of-service-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Cybersecurity Education  Strategic Plan</title>
		<link>http://informationrisk.org/2011/09/14/cybersecurity-education-strategic-plan/</link>
		<comments>http://informationrisk.org/2011/09/14/cybersecurity-education-strategic-plan/#comments</comments>
		<pubDate>Thu, 15 Sep 2011 02:12:55 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Report / Paper]]></category>
		<category><![CDATA[Security Strategy]]></category>
		<category><![CDATA[Training / Awareness]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2115</guid>
		<description><![CDATA[Ispitzner / SecuringTheHuman Blog NIST (the US National Institute of Standards and Technology) recently published a draft version on its strategy for promoting cyber security awareness and education. From page 2 of the document, the three stated goals are. Raise awareness among the American public about the risks of online activities. Broaden the pool of skilled workers [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2115&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Ispitzner / <a href="http://www.securingthehuman.org/blog/2011/08/19/nist-nice-security-awareness-and-education-strategy#" target="_blank">SecuringTheHuman Blog</a></p>
<blockquote><p>NIST (the US National Institute of Standards and Technology) recently <a href="http://csrc.nist.gov/nice/documents/nicestratplan/Draft_NICE-Strategic-Plan_Aug2011.pdf">published a draft version on its strategy</a> for promoting cyber security awareness and education. From page 2 of the document, the three stated goals are.</p>
<ol>
<li>Raise awareness among the American public about the risks of online activities.</li>
<li>Broaden the pool of skilled workers capable of supporting a cyber-secure nation.</li>
<li>Develop and maintain an unrivaled, globally competitive cybersecurity workforce.</li>
</ol>
</blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/report-paper/'>Report / Paper</a>, <a href='http://informationrisk.org/category/security-strategy/'>Security Strategy</a>, <a href='http://informationrisk.org/category/training-awareness/'>Training / Awareness</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2115/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2115/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2115/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2115/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2115/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2115/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2115/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2115/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2115/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2115/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2115/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2115/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2115/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2115/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2115&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/09/14/cybersecurity-education-strategic-plan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Catching up on credit card security</title>
		<link>http://informationrisk.org/2011/09/13/catching-up-on-credit-card-security/</link>
		<comments>http://informationrisk.org/2011/09/13/catching-up-on-credit-card-security/#comments</comments>
		<pubDate>Wed, 14 Sep 2011 00:22:32 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Communication]]></category>
		<category><![CDATA[Consumer Information Protection]]></category>
		<category><![CDATA[Cryptography]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2117</guid>
		<description><![CDATA[Peter Svensson / USA Today The problem with that black magnetic stripe on the back of your credit card is that it&#8217;s about as secure as writing your account information on a postcard: everything is in the clear and can be copied. Card fraud, and the measures taken to prevent it, costs U.S. merchants, banks [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2117&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Peter Svensson / <a href="http://www.usatoday.com/tech/news/story/2011-09-09/smart-credit-cards-security/50340578/1" target="_blank">USA Today</a></p>
<blockquote><p>The problem with that black magnetic stripe on the back of your credit card is that it&#8217;s about as secure as writing your account information on a postcard: everything is in the clear and can be copied. Card fraud, and the measures taken to prevent it, costs U.S. merchants, banks and consumers billions each year.</p>
<p>The smart cards can&#8217;t be copied, which greatly reduces the potential for fraud. Smart cards with built-in chips are the equivalent of a safe: they can hide information so it can only be unlocked with the right key. Because the important information is hidden, the cards can&#8217;t be replicated.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/authentication/'>Authentication</a>, <a href='http://informationrisk.org/category/communication/'>Communication</a>, <a href='http://informationrisk.org/category/consumer-information-protection/'>Consumer Information Protection</a>, <a href='http://informationrisk.org/category/cryptography/'>Cryptography</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2117/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2117/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2117/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2117/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2117/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2117/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2117/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2117/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2117/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2117/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2117/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2117/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2117/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2117/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2117&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/09/13/catching-up-on-credit-card-security/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Lightweight Portable Security (LPS)</title>
		<link>http://informationrisk.org/2011/09/13/lightweight-portable-security-lps/</link>
		<comments>http://informationrisk.org/2011/09/13/lightweight-portable-security-lps/#comments</comments>
		<pubDate>Wed, 14 Sep 2011 00:22:01 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Communication]]></category>
		<category><![CDATA[Infrastructure Security]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2113</guid>
		<description><![CDATA[Software Protection Initiative / Department of Defense Lightweight Portable Security (LPS) creates a secure end node from trusted media on almost any Intel-based computer (PC or Mac). LPS boots a thin Linux operating system from a CD or USB flash stick without mounting a local hard drive. Administrator privileges are not required; nothing is installed. The [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2113&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.spi.dod.mil/lipose.htm" target="_blank">Software Protection Initiative</a> / Department of Defense</p>
<blockquote><p>Lightweight Portable Security (LPS) creates a secure end node from trusted media on almost any Intel-based computer (PC or Mac). LPS boots a thin Linux operating system from a CD or USB flash stick without mounting a local hard drive. Administrator privileges are not required; nothing is installed.</p>
<p>The idea behind it is that workers can use a CDROM or USB stick to boot into a tamper proof, pristine desktop when using insecure computers such as those available in hotels or a worker’s own home. The environment that it offers should be largely resistant to Internet-borne security threats such as viruses and spyware, particularly when launched from read-only media such as a CDROM. The LPS system does not mount the hard drive of the host machine, so no trace of work activity can be written to the local computer.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/communication/'>Communication</a>, <a href='http://informationrisk.org/category/infrastructure-security/'>Infrastructure Security</a>, <a href='http://informationrisk.org/category/threat-management/'>Threat Management</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2113/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2113&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/09/13/lightweight-portable-security-lps/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Security Benchmarking: Going Beyond Metrics</title>
		<link>http://informationrisk.org/2011/09/11/security-benchmarking-going-beyond-metrics/</link>
		<comments>http://informationrisk.org/2011/09/11/security-benchmarking-going-beyond-metrics/#comments</comments>
		<pubDate>Sun, 11 Sep 2011 22:26:41 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Metrics]]></category>
		<category><![CDATA[Security Strategy]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2111</guid>
		<description><![CDATA[Securosis How do you answer the inevitable question “Are we good at security?” If you are like most organizations, you stutter quite a bit and then fall back to either irrelevant numbers (like AV or patch coverage) or a qualitative assessment – “We had 2 incidents last month, down from 5 the prior month prior”. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2111&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.securosis.com/research/publication/security-benchmarking-going-beyond-metrics" target="_blank">Securosis</a></p>
<blockquote><p>How do you answer the inevitable question “Are we good at security?” If you are like most organizations, you stutter quite a bit and then fall back to either irrelevant numbers (like AV or patch coverage) or a qualitative assessment – “We had 2 incidents last month, down from 5 the prior month prior”. Either way, the answer isn’t what management needs, or deserves.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/metrics/'>Metrics</a>, <a href='http://informationrisk.org/category/security-strategy/'>Security Strategy</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2111/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2111&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/09/11/security-benchmarking-going-beyond-metrics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>From “IT Governance” to “Governance of Enterprise IT”</title>
		<link>http://informationrisk.org/2011/09/11/from-%e2%80%9cit-governance%e2%80%9d-to-%e2%80%9cgovernance-of-enterprise-it%e2%80%9d/</link>
		<comments>http://informationrisk.org/2011/09/11/from-%e2%80%9cit-governance%e2%80%9d-to-%e2%80%9cgovernance-of-enterprise-it%e2%80%9d/#comments</comments>
		<pubDate>Sun, 11 Sep 2011 22:16:29 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Policy and Governance]]></category>
		<category><![CDATA[Report / Paper]]></category>
		<category><![CDATA[Standard / Framework]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2109</guid>
		<description><![CDATA[Steven De Haes / ISACA Blog &#8230;..Governance of Enterprise IT (GEIT) is an integral part of corporate governance and addresses the definition and implementation of processes, structures and relational mechanisms in the organizations that enable both business and IT personnel to execute their responsibilities in support of business-IT alignment and the creation of business value [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2109&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Steven De Haes / <a href="http://www.isaca.org/Journal/Blog/Lists/Posts/Post.aspx?ID=80" target="_blank">ISACA Blog</a></p>
<blockquote><p>&#8230;..Governance of Enterprise IT (GEIT) is an integral part of corporate governance and addresses the definition and implementation of processes, structures and relational mechanisms in the organizations that enable both business and IT personnel to execute their responsibilities in support of business-IT alignment and the creation of business value from IT-enabled investments. GEIT clearly goes beyond the IT-related responsibilities and expands toward (IT-related) business processes needed for business value creation. ISACA frameworks such as <a href="http://www.isaca.org/Knowledge-Center/Val-IT-IT-Value-Delivery-/Pages/Val-IT1.aspx">Val IT</a> and the upcoming <a href="http://www.isaca.org/Knowledge-Center/cobit/Pages/COBIT-5-Initiative-Status-Update.aspx">COBIT 5</a> fully embrace these concepts.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/policy-and-governance/'>Policy and Governance</a>, <a href='http://informationrisk.org/category/report-paper/'>Report / Paper</a>, <a href='http://informationrisk.org/category/standard-framework/'>Standard / Framework</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2109/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2109&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/09/11/from-%e2%80%9cit-governance%e2%80%9d-to-%e2%80%9cgovernance-of-enterprise-it%e2%80%9d/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Thank Goodness for Fraud</title>
		<link>http://informationrisk.org/2011/09/11/thank-goodness-for-fraud/</link>
		<comments>http://informationrisk.org/2011/09/11/thank-goodness-for-fraud/#comments</comments>
		<pubDate>Sun, 11 Sep 2011 22:07:23 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Metrics]]></category>
		<category><![CDATA[Survey]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2107</guid>
		<description><![CDATA[Wade Baker / Verizon Security Blog we’ve isolated such cases from the larger DBIR dataset and include stats around IP and classified data theft in these presentations (don’t get too upset – we’re sharing some of this with you too). The differences between these datasets are often substantial and provide plenty of food for thought…which brings [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2107&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Wade Baker / <a href="http://securityblog.verizonbusiness.com/2011/09/07/thank-goodness-for-fraud/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+verizonbusiness%2FtWvQ+%28Verizon+Business+Security+Blog%29" target="_blank">Verizon Security Blog</a></p>
<blockquote><p>we’ve isolated such cases from the larger DBIR dataset and include stats around IP and classified data theft in these presentations (don’t get too upset – <a title="New Views in the 2011 DBIR" href="http://securityblog.verizonbusiness.com/2011/06/23/new-views-into-the-2011-dbir/" target="_blank">we’re sharing some of this with you too</a>). The differences between these datasets are often substantial and provide plenty of food for thought…which brings us back to breach discovery, fraud, and the number 44.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/metrics/'>Metrics</a>, <a href='http://informationrisk.org/category/survey/'>Survey</a>, <a href='http://informationrisk.org/category/threat-management/'>Threat Management</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2107/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2107/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2107/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2107/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2107/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2107/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2107/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2107/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2107/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2107/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2107/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2107/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2107/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2107/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2107&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/09/11/thank-goodness-for-fraud/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Email That Led To The RSA Hack</title>
		<link>http://informationrisk.org/2011/08/29/email-that-led-to-the-rsa-hack/</link>
		<comments>http://informationrisk.org/2011/08/29/email-that-led-to-the-rsa-hack/#comments</comments>
		<pubDate>Tue, 30 Aug 2011 01:56:07 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2104</guid>
		<description><![CDATA[Mikko / F-Secure The current theory is that a nation-state wanted to break in to Lockheed-Martin and Northrop-Grumman to steal military secrets. They couldn&#8217;t do it, since these companies were using RSA SecurID tokens for network authentication. So, the hackers broke into RSA with a targeted email attack. They planted a backdoor and eventually were able to gain access to SecurID [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2104&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Mikko / <a href="http://www.f-secure.com/weblog/archives/00002226.html" target="_blank">F-Secure</a></p>
<blockquote><p>The current theory is that a nation-state wanted to break in to Lockheed-Martin and Northrop-Grumman to steal military secrets. They couldn&#8217;t do it, since these companies were using RSA SecurID tokens for network authentication. So, the hackers broke into RSA with a targeted email attack. They planted a backdoor and eventually were able to gain access to SecurID information that enabled them to go back to their original targets and succesfully break into there. In the aftermath of the attack, RSA was forced to replace SecurID tokens for their customers around the world.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/authentication/'>Authentication</a>, <a href='http://informationrisk.org/category/cryptography/'>Cryptography</a>, <a href='http://informationrisk.org/category/threat-management/'>Threat Management</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2104/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2104/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2104/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2104/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2104/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2104/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2104/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2104/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2104/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2104/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2104/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2104/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2104/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2104/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2104&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/08/29/email-that-led-to-the-rsa-hack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Defense against wireless man-in-middle attacks</title>
		<link>http://informationrisk.org/2011/08/25/defense-against-wireless-man-in-middle-attacks/</link>
		<comments>http://informationrisk.org/2011/08/25/defense-against-wireless-man-in-middle-attacks/#comments</comments>
		<pubDate>Fri, 26 Aug 2011 03:40:21 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Communication]]></category>
		<category><![CDATA[Consumer Information Protection]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2100</guid>
		<description><![CDATA[John Cox / Network World Dubbed Tamper-evident pairing, or TEP, the technique is based on understanding how man-in-the-middle attacks tamper with wireless messages, and then detects and in some cases blocks the tampering. The researchers suggest that TEP could have detected the reported but still unconfirmed cellular man-in-the-middle attack that unfolded at the Defcon conference earlier this [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2100&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>John Cox / <a href="http://www.networkworld.com/news/2011/082411-mit-tep-250077.html" target="_blank">Network World</a></p>
<blockquote><p>Dubbed Tamper-evident pairing, or TEP, the technique is based on understanding how man-in-the-middle attacks tamper with wireless messages, and then detects and in some cases blocks the tampering. The researchers suggest that TEP could have detected the reported but still unconfirmed cellular man-in-the-middle attack that unfolded at the Defcon conference earlier this month in Las Vegas.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/communication/'>Communication</a>, <a href='http://informationrisk.org/category/consumer-information-protection/'>Consumer Information Protection</a>, <a href='http://informationrisk.org/category/threat-management/'>Threat Management</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2100/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2100&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/08/25/defense-against-wireless-man-in-middle-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Taxonomy of Operational Cyber Security Risks</title>
		<link>http://informationrisk.org/2011/08/20/taxonomy-of-operational-cyber-security-risks-2/</link>
		<comments>http://informationrisk.org/2011/08/20/taxonomy-of-operational-cyber-security-risks-2/#comments</comments>
		<pubDate>Sat, 20 Aug 2011 14:16:00 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Policy and Governance]]></category>
		<category><![CDATA[Report / Paper]]></category>
		<category><![CDATA[Risk Management]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2098</guid>
		<description><![CDATA[Cebula and Young / Carnegie Mellon This report presents a taxonomy of operational cyber security risks that attempts to identify and organize the sources of operational cyber security risk into four classes: (1) actions of people, (2) systems and technology failures, (3) failed internal processes, and (4) external events. Each class is broken down into [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2098&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Cebula and Young /<a href="http://www.cert.org/archive/pdf/10tn028.pdf" target="_blank"> Carnegie Mellon</a></p>
<blockquote><p>This report presents a taxonomy of operational cyber security risks that attempts to identify and organize the sources of operational cyber security risk into four classes: (1) actions of people, (2) systems and technology failures, (3) failed internal processes, and (4) external events. Each class is broken down into subclasses, which are described by their elements. This report discusses the harmonization of the taxonomy with other risk and security activities, particularly those described by the Federal Information Security Management Act (FISMA), the National Institute of Standards and Technology (NIST) Special Publications, and the CERT Operationally Critical Threat, Asset, and Vulnerability EvaluationSM (OCTAVE®) method.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/information-security-2/'>Information Security</a>, <a href='http://informationrisk.org/category/policy-and-governance/'>Policy and Governance</a>, <a href='http://informationrisk.org/category/report-paper/'>Report / Paper</a>, <a href='http://informationrisk.org/category/risk-management/'>Risk Management</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2098/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2098/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2098/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2098/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2098/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2098/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2098/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2098/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2098/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2098/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2098/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2098/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2098/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2098/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2098&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/08/20/taxonomy-of-operational-cyber-security-risks-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>PIN Requirement With Credit Card Purchases</title>
		<link>http://informationrisk.org/2011/08/14/pin-requirement-with-credit-card-purchases/</link>
		<comments>http://informationrisk.org/2011/08/14/pin-requirement-with-credit-card-purchases/#comments</comments>
		<pubDate>Sun, 14 Aug 2011 14:35:24 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Consumer Information Protection]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2091</guid>
		<description><![CDATA[Mathew J. Schwartz / InformationWeek Visa announced that it&#8217;s putting its muscle behind the adoption of &#8220;chip and PIN&#8221; capabilities in U.S. credit cards, which require in-person purchasers to input a PIN code into a point-of-sale machine before the card can be used. Also known as EMV&#8211;for Europay, MasterCard, and Visa, referring to their global [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2091&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Mathew J. Schwartz / <a href="http://www.informationweek.com/news/security/vulnerabilities/231400073" target="_blank">InformationWeek</a></p>
<blockquote><p>Visa announced that it&#8217;s putting its muscle behind the adoption of &#8220;chip and PIN&#8221; capabilities in U.S. credit cards, which require in-person purchasers to input a PIN code into a point-of-sale machine before the card can be used. Also known as EMV&#8211;for Europay, MasterCard, and Visa, referring to their global standard for integrated circuit chips built into cards&#8211;the U.S. chip will include contactless chip technology, laying the groundwork for greater adoption of mobile payments using near-field communications (NFC).</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/authentication/'>Authentication</a>, <a href='http://informationrisk.org/category/consumer-information-protection/'>Consumer Information Protection</a>, <a href='http://informationrisk.org/category/pci/'>PCI</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2091/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2091/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2091/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2091/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2091/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2091/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2091/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2091/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2091/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2091/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2091/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2091/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2091/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2091/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2091&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/08/14/pin-requirement-with-credit-card-purchases/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Most Common Passcodes</title>
		<link>http://informationrisk.org/2011/07/17/most-common-passcodes/</link>
		<comments>http://informationrisk.org/2011/07/17/most-common-passcodes/#comments</comments>
		<pubDate>Sun, 17 Jul 2011 16:58:07 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2088</guid>
		<description><![CDATA[Any passcode that uses a typical formula or obvious pattern provides the same level of security as no passcode (it&#8217;s like a lock that can be unlocked without a key). These passcodes souldn&#8217;t be used for smart phone devices, security systems, voice mails, debit card PIN, or any external facing devices. Naturally, 1234 is the most common [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2088&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Any passcode that uses a typical formula or obvious pattern provides the same level of security as no passcode (it&#8217;s like a lock that can be unlocked without a key). <a href="http://amitay.us/blog/files/most_common_iphone_passcodes.php" target="_blank">These passcodes </a>souldn&#8217;t be used for smart phone devices, security systems, voice mails, debit card PIN, or any external facing devices.</p>
<blockquote><p>Naturally, 1234 is the most common passcode: mimicking the most common internet passwords. To put this into perspective, these 10 codes represent 15% of all passcodes in use. Most of the top passcodes follow typical formulas, such as four identical digits, moving in a line up/down the pad, repetition. 5683 is the passcode with the least obvious pattern, but it turns out that it is the number representation of LOVE (5683), once again mimicking a very common internet password: “iloveyou.”</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/authentication/'>Authentication</a>, <a href='http://informationrisk.org/category/cybersecurity/'>Cybersecurity</a>, <a href='http://informationrisk.org/category/privacy/'>Privacy</a>, <a href='http://informationrisk.org/category/threat-management/'>Threat Management</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2088/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2088/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2088/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2088/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2088/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2088/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2088/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2088/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2088/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2088/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2088/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2088/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2088/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2088/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2088&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/07/17/most-common-passcodes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Cyber Security Strategy</title>
		<link>http://informationrisk.org/2011/07/16/cyber-security-strategy/</link>
		<comments>http://informationrisk.org/2011/07/16/cyber-security-strategy/#comments</comments>
		<pubDate>Sun, 17 Jul 2011 03:57:14 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Report / Paper]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Security Strategy]]></category>
		<category><![CDATA[Tech and Laws]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2084</guid>
		<description><![CDATA[Stefanie Hoffman / CRN The 19-page document, called the “Department of Defense Strategy for Operating in Cyberspace,” establishes that cyber space be a domain protected by the U.S. military in the same way it defends land, sea and air. In general, the strategy calls for new ways to bolster defenses of critical cyber infrastructure, such [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2084&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Stefanie Hoffman / <a href="http://www.crn.com/news/security/231001852/u-s-dod-releases-cyber-security-strategy.htm;jsessionid=J7UVJdnm+al8R1Ol5CZYVA**.ecappj01" target="_blank">CRN</a></p>
<blockquote><p>The 19-page document, called the “<a href="http://www.defense.gov/news/d20110714cyber.pdf" target="_blank">Department of Defense Strategy for Operating in Cyberspace</a>,” establishes that cyber space be a domain protected by the U.S. military in the same way it defends land, sea and air.</p>
<p>In general, the strategy calls for new ways to bolster defenses of critical cyber infrastructure, such as the computer networks of the U.S. military and defense contractors, while developing new weapons and methods to retaliate against U.S. adversaries launching cyber attacks.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/report-paper/'>Report / Paper</a>, <a href='http://informationrisk.org/category/risk-management/'>Risk Management</a>, <a href='http://informationrisk.org/category/security-strategy/'>Security Strategy</a>, <a href='http://informationrisk.org/category/tech-and-laws/'>Tech and Laws</a>, <a href='http://informationrisk.org/category/uncategorized/'>Uncategorized</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2084/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2084/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2084/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2084/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2084/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2084/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2084/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2084/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2084/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2084/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2084/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2084/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2084/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2084/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2084&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/07/16/cyber-security-strategy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>COBIT 5: Available for Public Comments</title>
		<link>http://informationrisk.org/2011/07/10/cobit-5-available-for-public-comments/</link>
		<comments>http://informationrisk.org/2011/07/10/cobit-5-available-for-public-comments/#comments</comments>
		<pubDate>Sun, 10 Jul 2011 19:01:35 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Policy and Governance]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Security Strategy]]></category>
		<category><![CDATA[Standard / Framework]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2080</guid>
		<description><![CDATA[The Framework and Process Reference guide exposure drafts are available for download from the ISACA site. This foundational COBIT volume introduces the following, which combine to provide a comprehensive, effective framework to support the governance and management of enterprise information and related technology: Principles Drivers Benefits Enablers Other aspects The COBIT 5 Process Reference Guide incorporates and is the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2080&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.isaca.org/Knowledge-Center/Research/Documents/COBIT5-Framework-ED-27June2011.pdf" target="_blank">Framework</a> and <a href="http://www.isaca.org/Knowledge-Center/Research/Documents/COBIT5-Process-Ref-Guide-ED-27June2011.pdf" target="_blank">Process Reference guide</a> exposure drafts are available for download from the <a href="http://www.isaca.org/Knowledge-Center/Research/ResearchDeliverables/Pages/COBIT-5-Exposure-Draft.aspx" target="_blank">ISACA site</a>.</p>
<blockquote><p>This foundational COBIT volume introduces the following, which combine to provide a comprehensive, effective framework to support the governance and management of enterprise information and related technology:</p>
<ul>
<li>Principles</li>
<li>Drivers</li>
<li>Benefits</li>
<li>Enablers</li>
<li>Other aspects</li>
</ul>
<p>The COBIT 5 <em>Process Reference Guide</em> incorporates and is the successor to COBIT 4.1, Val IT and Risk IT processes. It describes the:</p>
<ul>
<li>Goals cascade</li>
<li>Process model</li>
<li>Process reference model</li>
<li>Detailed processes</li>
</ul>
</blockquote>
<div>The online questionnaire will remain open until 31 July 2011.</div>
<br />Filed under: <a href='http://informationrisk.org/category/policy-and-governance/'>Policy and Governance</a>, <a href='http://informationrisk.org/category/risk-management/'>Risk Management</a>, <a href='http://informationrisk.org/category/security-strategy/'>Security Strategy</a>, <a href='http://informationrisk.org/category/standard-framework/'>Standard / Framework</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2080/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2080/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2080/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2080/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2080/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2080/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2080/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2080/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2080/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2080/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2080/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2080/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2080/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2080/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2080&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/07/10/cobit-5-available-for-public-comments/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8220;Security is hard. It&#8217;s even harder at scale.&#8221;</title>
		<link>http://informationrisk.org/2011/07/10/security-is-hard-its-even-harder-at-scale/</link>
		<comments>http://informationrisk.org/2011/07/10/security-is-hard-its-even-harder-at-scale/#comments</comments>
		<pubDate>Sun, 10 Jul 2011 18:44:23 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Security Strategy]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2078</guid>
		<description><![CDATA[Rich Mogull / Dark Reading We security pundits, researchers, and vendors tend to forget how hard real-world operational IT is. If you&#8217;re small, you can control more, but you have fewer resources at your disposal. If you&#8217;re large, you still struggle for resources, but now at an enormous scale. It&#8217;s a no-win situation because no [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2078&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Rich Mogull / <a href="http://www.darkreading.com/blog/231001157/simple-isn-t-simple.html" target="_blank">Dark Reading</a></p>
<blockquote><p>We security pundits, researchers, and vendors tend to forget how hard real-world operational IT is. If you&#8217;re small, you can control more, but you have fewer resources at your disposal. If you&#8217;re large, you still struggle for resources, but now at an enormous scale. It&#8217;s a no-win situation because no one can be perfect all the time. Or even some of the time.</p>
<p>&#8230;&#8230;</p>
<p>Security is hard. It&#8217;s even harder at scale. And we need to stop pretending that even the most basic of practices are always simple, and start focusing on how to make them more effective and easier to manage in a messy, ugly, real world.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/cybersecurity/'>Cybersecurity</a>, <a href='http://informationrisk.org/category/information-security-2/'>Information Security</a>, <a href='http://informationrisk.org/category/security-strategy/'>Security Strategy</a>, <a href='http://informationrisk.org/category/threat-management/'>Threat Management</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2078/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2078/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2078/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2078/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2078/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2078/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2078/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2078/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2078/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2078/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2078/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2078/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2078/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2078/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2078&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/07/10/security-is-hard-its-even-harder-at-scale/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Automate Searching with Google Alerts</title>
		<link>http://informationrisk.org/2011/07/08/automate-searching-with-google-alerts/</link>
		<comments>http://informationrisk.org/2011/07/08/automate-searching-with-google-alerts/#comments</comments>
		<pubDate>Sat, 09 Jul 2011 01:11:26 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Communication]]></category>
		<category><![CDATA[Infrastructure Security]]></category>
		<category><![CDATA[Threat Management]]></category>
		<category><![CDATA[Vulnerability Analysis]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2076</guid>
		<description><![CDATA[Corey Harrell / Journey into Incident Response Google queries show the information currently in Google’s index and cache while Google alerts send email notifications when Google is returning new information. The combination of queries and alerts can be leverage by organizations to identify security issues such as data leakage, website vulnerabilities, and stolen information. The [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2076&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Corey Harrell / <a href="http://journeyintoir.blogspot.com/2011/07/google-security-incident-detector.html" target="_blank">Journey into Incident Response</a></p>
<blockquote><p>Google queries show the information currently in Google’s index and cache while Google alerts send email notifications when Google is returning new information. The combination of queries and alerts can be leverage by organizations to identify security issues such as data leakage, website vulnerabilities, and stolen information.</p>
<p>The majority of the data breaches referenced had two things in common. The first commonality was sensitive company information was exposed to the Internet. The second commonality was the companies were notified about the data leakage after a third party located the information through Google searches.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/communication/'>Communication</a>, <a href='http://informationrisk.org/category/infrastructure-security/'>Infrastructure Security</a>, <a href='http://informationrisk.org/category/threat-management/'>Threat Management</a>, <a href='http://informationrisk.org/category/vulnerability-analysis/'>Vulnerability Analysis</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2076/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2076/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2076/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2076/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2076/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2076/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2076/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2076/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2076/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2076/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2076/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2076/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2076/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2076/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2076&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/07/08/automate-searching-with-google-alerts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Common Weakness Scoring System (CWSS)</title>
		<link>http://informationrisk.org/2011/07/08/common-weakness-scoring-system-cwss/</link>
		<comments>http://informationrisk.org/2011/07/08/common-weakness-scoring-system-cwss/#comments</comments>
		<pubDate>Sat, 09 Jul 2011 01:06:14 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[Secure Coding]]></category>
		<category><![CDATA[Vulnerability Analysis]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2073</guid>
		<description><![CDATA[CWSS: provides a common framework for prioritizing security errors (&#8220;weaknesses&#8221;) that are discovered in software applications provides a quantitative measurement of the unfixed weaknesses that are present within a software application can be used by developers to prioritize unfixed weaknesses within their own software in conjunction with the Common Weakness Risk Analysis Framework (CWRAF), can [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2073&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://cwe.mitre.org/cwss/" target="_blank">CWSS:</a></p>
<ul>
<li>provides a common framework for prioritizing security errors (&#8220;weaknesses&#8221;) that are discovered in software applications</li>
<li>provides a quantitative measurement of the unfixed weaknesses that are present within a software application</li>
<li>can be used by developers to prioritize unfixed weaknesses within their own software</li>
<li>in conjunction with the <a href="http://cwe.mitre.org/cwraf/">Common Weakness Risk Analysis Framework (CWRAF)</a>, can be used by consumers to identify the most important weaknesses for their business domains, in order to inform their acquisition and protection activities as one part of the larger process of achieving software assurance.</li>
</ul>
<br />Filed under: <a href='http://informationrisk.org/category/application-security/'>Application Security</a>, <a href='http://informationrisk.org/category/ddos/'>DDoS</a>, <a href='http://informationrisk.org/category/secure-coding/'>Secure Coding</a>, <a href='http://informationrisk.org/category/vulnerability-analysis/'>Vulnerability Analysis</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2073/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2073/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2073/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2073/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2073/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2073/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2073/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2073/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2073/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2073/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2073/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2073/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2073/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2073/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2073&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/07/08/common-weakness-scoring-system-cwss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>North Atlantic Cyber Security Organisation (?)</title>
		<link>http://informationrisk.org/2011/07/02/north-atlantic-cyber-security-organisation/</link>
		<comments>http://informationrisk.org/2011/07/02/north-atlantic-cyber-security-organisation/#comments</comments>
		<pubDate>Sat, 02 Jul 2011 18:08:03 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Laws and Regulations]]></category>
		<category><![CDATA[Policy and Governance]]></category>
		<category><![CDATA[Security Strategy]]></category>
		<category><![CDATA[Tech and Laws]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2070</guid>
		<description><![CDATA[Sounds like the right move&#8230; This new security challenge was on the agenda at the June 8th-9th meeting of NATO defence ministers in Brussels. Ministers agreed on an action plan and on a revised cyber defence policy which will not only ensure a quicker and more effective protection of NATO&#8217;s own network, but also provide the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2070&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Sounds like the <a href="http://www.setimes.com/cocoon/setimes/xhtml/en_GB/features/setimes/features/2011/06/24/feature-02" target="_blank">right move</a>&#8230;</p>
<blockquote><p>This new security challenge was on the agenda at the June 8th-9th meeting of NATO defence ministers in Brussels. Ministers agreed on an action plan and on a revised cyber defence policy which will not only ensure a quicker and more effective protection of NATO&#8217;s own network, but also provide the Allies and Partners with more assistance in preventing the cyber attacks, coping with them and limiting their impact.</p>
<p>The new strategy requires that all NATO structures be brought under a centralised protection system, and that all of its networks be monitored round the clock as of 2012.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/laws-and-regulations/'>Laws and Regulations</a>, <a href='http://informationrisk.org/category/policy-and-governance/'>Policy and Governance</a>, <a href='http://informationrisk.org/category/security-strategy/'>Security Strategy</a>, <a href='http://informationrisk.org/category/tech-and-laws/'>Tech and Laws</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2070/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2070/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2070/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2070/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2070/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2070/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2070/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2070/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2070/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2070/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2070/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2070/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2070/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2070/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2070&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/07/02/north-atlantic-cyber-security-organisation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Supplemental Guidance on Authentication</title>
		<link>http://informationrisk.org/2011/07/02/supplemental-guidance-on-authentication/</link>
		<comments>http://informationrisk.org/2011/07/02/supplemental-guidance-on-authentication/#comments</comments>
		<pubDate>Sat, 02 Jul 2011 17:59:52 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Laws and Regulations]]></category>
		<category><![CDATA[Policy and Governance]]></category>
		<category><![CDATA[Risk Management]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2067</guid>
		<description><![CDATA[The Federal Financial Institutions Examination Council (FFIEC) today issued a supplement to the Authentication in an Internet Banking Environment guidance, issued in October 2005. The purpose of the supplement is to reinforce the risk-management framework described in the original guidance and update the FFIEC member agencies&#8217; supervisory expectations regarding customer authentication, layered security, and other [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2067&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The Federal Financial Institutions Examination Council (FFIEC) today issued a <a href="http://www.fdic.gov/news/news/press/2011/pr11111a.pdf" target="_blank">supplement</a> to the <em>Authentication in an Internet Banking Environment</em> guidance, issued in October 2005. The purpose of the supplement is to reinforce the risk-management framework described in the original guidance and update the FFIEC member agencies&#8217; supervisory expectations regarding customer authentication, layered security, and other controls in the increasingly hostile online environment.</p>
<br />Filed under: <a href='http://informationrisk.org/category/authentication/'>Authentication</a>, <a href='http://informationrisk.org/category/laws-and-regulations/'>Laws and Regulations</a>, <a href='http://informationrisk.org/category/policy-and-governance/'>Policy and Governance</a>, <a href='http://informationrisk.org/category/risk-management/'>Risk Management</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2067/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2067/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2067/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2067/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2067/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2067/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2067/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2067/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2067/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2067/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2067/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2067/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2067/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2067/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2067&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/07/02/supplemental-guidance-on-authentication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>LulzSec Calls It Quits</title>
		<link>http://informationrisk.org/2011/06/26/lulzsec-calls-it-quits/</link>
		<comments>http://informationrisk.org/2011/06/26/lulzsec-calls-it-quits/#comments</comments>
		<pubDate>Mon, 27 Jun 2011 00:26:00 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Consumer Information Protection]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2065</guid>
		<description><![CDATA[How does a hacker group get dissolved? But in this shadowy world of claims, boasts and posturing, nothing is quite what it seems. It may have been other members of the hacker &#8220;community&#8221; &#8211; disgruntled with the antics of LulzSec &#8211; who forced the group into retreat. A document posted online in the last 24 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2065&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>How does a hacker group get <a href="http://www.bbc.co.uk/news/uk-13918458" target="_blank">dissolved</a>?</p>
<blockquote><p>But in this shadowy world of claims, boasts and posturing, nothing is quite what it seems. It may have been other members of the hacker &#8220;community&#8221; &#8211; disgruntled with the antics of LulzSec &#8211; who forced the group into retreat. A document posted online in the last 24 hours purports to be a history of LulzSec, complete with full details on its leaders.</p>
<p>&#8230;&#8230;</p>
<p>But even if LulzSec has gone offline, its members and other hackers trying to make a name for themselves may soon pop up elsewhere. And the other question is whether we should take any publicity-hungry group like this too seriously. The real damage is more likely being done by criminal groups who wouldn&#8217;t dream of boasting of their exploits on Twitter or anywhere else.</p></blockquote>
<p><!-- pullout-links--></p>
<br />Filed under: <a href='http://informationrisk.org/category/application-security/'>Application Security</a>, <a href='http://informationrisk.org/category/consumer-information-protection/'>Consumer Information Protection</a>, <a href='http://informationrisk.org/category/ddos/'>DDoS</a>, <a href='http://informationrisk.org/category/threat-management/'>Threat Management</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2065/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2065/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2065/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2065/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2065/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2065/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2065/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2065/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2065/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2065/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2065/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2065/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2065/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2065/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2065&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/06/26/lulzsec-calls-it-quits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Memory encryption breakthrough</title>
		<link>http://informationrisk.org/2011/06/19/memory-encryption-breakthrough/</link>
		<comments>http://informationrisk.org/2011/06/19/memory-encryption-breakthrough/#comments</comments>
		<pubDate>Sun, 19 Jun 2011 16:23:06 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2063</guid>
		<description><![CDATA[Ellen Messmer / InfoWorld Researchers at North Carolina State University claim they&#8217;ve achieved a breakthrough in how encryption can be used in technology called non-volatile main memory, which is seen as an eventual replacement for conventional dynamic random-access memory. &#8212;- In work conducted with graduate students, Solihin says N.C. State researchers completed building a hardware-based [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2063&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Ellen Messmer / <a href="http://www.infoworld.com/d/security/security-researchers-claim-memory-encryption-breakthrough-418" target="_blank">InfoWorld</a></p>
<blockquote><p>Researchers at North Carolina State University claim they&#8217;ve achieved a breakthrough in how encryption can be used in technology called non-volatile main memory, which is seen as an eventual replacement for conventional dynamic random-access memory.</p>
<p>&#8212;-</p>
<p>In work conducted with graduate students, Solihin says N.C. State researchers completed building a hardware-based method to self- encrypt NVMM data. The idea is it might eventually become integrated into chipsets.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/application-security/'>Application Security</a>, <a href='http://informationrisk.org/category/cryptography/'>Cryptography</a>, <a href='http://informationrisk.org/category/threat-management/'>Threat Management</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2063/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2063/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2063/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2063/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2063/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2063/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2063/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2063/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2063/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2063/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2063/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2063/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2063/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2063/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2063&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/06/19/memory-encryption-breakthrough/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
		<item>
		<title>Why &#8220;security&#8221; keeps winning out over privacy</title>
		<link>http://informationrisk.org/2011/06/19/why-security-keeps-winning-out-over-privacy/</link>
		<comments>http://informationrisk.org/2011/06/19/why-security-keeps-winning-out-over-privacy/#comments</comments>
		<pubDate>Sun, 19 Jun 2011 14:55:42 +0000</pubDate>
		<dc:creator>Anuj Goel</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Tech and Laws]]></category>

		<guid isPermaLink="false">http://informationrisk.org/?p=2060</guid>
		<description><![CDATA[Daniel Solove / Salon But it is the job of the courts to balance privacy against security, and they can’t do this job if they refuse to evaluate whether the security measure is really worth the tradeoff. Deference is an abdication of the court’s role in ensuring that the government respects constitutional rights. The deference [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2060&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Daniel Solove / <a href="http://www.salon.com/news/politics/war_room/2011/05/31/solove_privacy_security/index.html" target="_blank">Salon</a></p>
<blockquote><p>But it is the job of the courts to balance privacy against security, and they can’t do this job if they refuse to evaluate whether the security measure is really worth the tradeoff. Deference is an abdication of the court’s role in ensuring that the government respects constitutional rights. The deference argument is one that impedes any effective balancing of interests.</p></blockquote>
<br />Filed under: <a href='http://informationrisk.org/category/information-security-2/'>Information Security</a>, <a href='http://informationrisk.org/category/privacy/'>Privacy</a>, <a href='http://informationrisk.org/category/tech-and-laws/'>Tech and Laws</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inforiskgov.wordpress.com/2060/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inforiskgov.wordpress.com/2060/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inforiskgov.wordpress.com/2060/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inforiskgov.wordpress.com/2060/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inforiskgov.wordpress.com/2060/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inforiskgov.wordpress.com/2060/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inforiskgov.wordpress.com/2060/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inforiskgov.wordpress.com/2060/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inforiskgov.wordpress.com/2060/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inforiskgov.wordpress.com/2060/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inforiskgov.wordpress.com/2060/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inforiskgov.wordpress.com/2060/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inforiskgov.wordpress.com/2060/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inforiskgov.wordpress.com/2060/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=informationrisk.org&amp;blog=13075074&amp;post=2060&amp;subd=inforiskgov&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://informationrisk.org/2011/06/19/why-security-keeps-winning-out-over-privacy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">inforiskgov</media:title>
		</media:content>
	</item>
	</channel>
</rss>
