<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>The Guerilla CISO</title>
	
	<link>http://www.guerilla-ciso.com</link>
	<description>Life in the information assurance salt mines.</description>
	<lastBuildDate>Sun, 08 Nov 2009 04:05:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<geo:lat>38.959673</geo:lat><geo:long>-77.346206</geo:long><creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/TheGuerillaCiso" type="application/rss+xml" /><feedburner:emailServiceId>TheGuerillaCiso</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
		<title>DojoCon 2009 Presentation</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/GzSUXUNlgvM/1409</link>
		<comments>http://www.guerilla-ciso.com/archives/1409#comments</comments>
		<pubDate>Sat, 07 Nov 2009 18:55:13 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[FISMA]]></category>
		<category><![CDATA[Speaking]]></category>
		<category><![CDATA[800-53]]></category>
		<category><![CDATA[accreditation]]></category>
		<category><![CDATA[auditor]]></category>
		<category><![CDATA[C&A]]></category>
		<category><![CDATA[catalogofcontrols]]></category>
		<category><![CDATA[certification]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[fisma]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[itsatrap]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[scalability]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[speaking]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1409</guid>
		<description><![CDATA[For those of you who didn&#8217;t know the real purpose of DojoCon, it was to raise money and awareness for Hackers for Charity.  If you like anything that is in this post, go to HFC and make a donation of time, equipment, tech support, and maybe money.  If you&#8217;ve never heard of HFC [...]]]></description>
			<content:encoded><![CDATA[<p>For those of you who didn&#8217;t know the real purpose of DojoCon, it was to raise money and awareness for Hackers for Charity.  If you like anything that is in this post, <a href="http://www.hackersforcharity.org/">go to HFC and make a donation of time, equipment, tech support, and maybe money</a>.  If you&#8217;ve never heard of HFC because you&#8217;re not one of the &#8220;InfoSec Cool Kids&#8221;, now is your chance&#8211;go read about them.</p>
<p>The video of my dojocon presentation.  The microphone was off for the first couple of minutes but I look pretty animated.</p>
<div align="center">
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="480" height="386" id="utv420337" name="utv_n_958388"><param name="flashvars" value="loc=%2F&amp;autoplay=false&amp;vid=2504315" /><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.ustream.tv/flash/video/2504315" /><embed flashvars="loc=%2F&amp;autoplay=false&amp;vid=2504315" width="480" height="386" allowfullscreen="true" allowscriptaccess="always" id="utv420337" name="utv_n_958388" src="http://www.ustream.tv/flash/video/2504315" type="application/x-shockwave-flash" /></object>
</div>
<p>And then the compliance panel that I tried not to dominate:</p>
<div align="center">
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="480" height="386" id="utv213659" name="utv_n_377908"><param name="flashvars" value="loc=%2F&amp;autoplay=false&amp;vid=2504680" /><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.ustream.tv/flash/video/2504680" /><embed flashvars="loc=%2F&amp;autoplay=false&amp;vid=2504680" width="480" height="386" allowfullscreen="true" allowscriptaccess="always" id="utv213659" name="utv_n_377908" src="http://www.ustream.tv/flash/video/2504680" type="application/x-shockwave-flash" /></object>
</div>
<p>And finally, my slides are up on slideshare:</p>
<div align="center">
<div style="width:425px;text-align:left" id="__ss_2445910"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/rybolov/dojo-con-09-2445910" title="Dojo Con 09">Dojo Con 09</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=dojocon09-091107122405-phpapp01&#038;stripped_title=dojo-con-09-2445910" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=dojocon09-091107122405-phpapp01&#038;stripped_title=dojo-con-09-2445910" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object>
<div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/rybolov">Michael Smith</a>.</div>
</div>
</div>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1409').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1409" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1409" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1409&amp;title=DojoCon+2009+Presentation" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1409&amp;title=DojoCon+2009+Presentation" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1409" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1409&amp;title=DojoCon+2009+Presentation" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1409&amp;h=DojoCon+2009+Presentation" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1409&amp;title=DojoCon+2009+Presentation" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1409&amp;title=DojoCon+2009+Presentation" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1409&amp;title=DojoCon+2009+Presentation" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1409" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1409" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1409&amp;t=DojoCon+2009+Presentation" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1409').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1409').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=GzSUXUNlgvM:F9wa8VyGkMY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=GzSUXUNlgvM:F9wa8VyGkMY:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=GzSUXUNlgvM:F9wa8VyGkMY:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/GzSUXUNlgvM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1409/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1409</feedburner:origLink></item>
		<item>
		<title>AppSec DC Press and Themes</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/0gF8Bw2Ohck/1392</link>
		<comments>http://www.guerilla-ciso.com/archives/1392#comments</comments>
		<pubDate>Mon, 02 Nov 2009 14:11:13 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[Odds-n-Sods]]></category>
		<category><![CDATA[What Works]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1392</guid>
		<description><![CDATA[So I&#8217;m working with the AppSecDC folks doing press relations amongst other things.  I&#8217;ve noticed several themes for the conference that might be of interest to the rest of the world.  Of course there&#8217;s the usual &#8220;The end is nigh, and not even Norton can save you!!!!!&#8221; stuff that&#8217;s been the staple of security conferences [...]]]></description>
			<content:encoded><![CDATA[<p>So I&#8217;m working with the AppSecDC folks doing press relations amongst other things.  I&#8217;ve noticed several themes for the conference that might be of interest to the rest of the world.  Of course there&#8217;s the usual &#8220;The end is nigh, and not even Norton can save you!!!!!&#8221; stuff that&#8217;s been the staple of security conferences for the past 5 years or so (oh noes, teh Internetz are broken.  Again)</p>
<p>However, AppSecDC has another set of themes that are mostly unique to OWASP and AppSecDC in particular:</p>
<ul>
<li><strong>The OWASP Approach to Security:</strong> it&#8217;s not process/product, it&#8217;s education and outreach.  Thanks to Doug Wilson for this idea.  Basically with host and network security, the option is to buy stuff and throw it at the problem.  With application security, it&#8217;s &#8220;go out and touch a developer today&#8221; and &#8220;use <a href="http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API" target="_blank">ESAPI</a> as a tool to help the developers write better and secure code more quickly&#8221;.  This is a new concept to the system integrator that I am, but I like it much better than my usual approach.</li>
<li><strong>Government and Application Security:</strong> we&#8217;re about 5 years behind industry, how do we catch up?  To this effort, we have some notable Government speakers such as a keynote by Joe Jarzombek, Director for Software Assurance in the National Cyber Security Division of the U.S. Department of Homeland Security.</li>
<li><strong>OWASP Top 10 2009/2010:</strong> This will be announced at AppSecDC with much w00tness and excitement.</li>
<li><strong>OWASP National Summit:</strong> this will be held the day before the official conference.</li>
</ul>
<p>Convinced you want to go?  <a href="http://www.appsecdc.org" target="_blank">Check out the conference site.</a></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1392').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1392" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1392" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1392&amp;title=AppSec+DC+Press+and+Themes" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1392&amp;title=AppSec+DC+Press+and+Themes" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1392" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1392&amp;title=AppSec+DC+Press+and+Themes" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1392&amp;h=AppSec+DC+Press+and+Themes" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1392&amp;title=AppSec+DC+Press+and+Themes" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1392&amp;title=AppSec+DC+Press+and+Themes" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1392&amp;title=AppSec+DC+Press+and+Themes" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1392" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1392" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1392&amp;t=AppSec+DC+Press+and+Themes" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1392').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1392').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=0gF8Bw2Ohck:iyX1VduSheE:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=0gF8Bw2Ohck:iyX1VduSheE:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=0gF8Bw2Ohck:iyX1VduSheE:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/0gF8Bw2Ohck" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1392/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1392</feedburner:origLink></item>
		<item>
		<title>Look Out, Sir Bruce, IKANHAZFIZMA is Coming for You</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/erU-DjXkaFo/1397</link>
		<comments>http://www.guerilla-ciso.com/archives/1397#comments</comments>
		<pubDate>Fri, 23 Oct 2009 01:51:01 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[IKANHAZFIZMA]]></category>
		<category><![CDATA[crypto]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[lolcats]]></category>
		<category><![CDATA[schneier]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1397</guid>
		<description><![CDATA[This week&#8217;s lolcat is a shout-out to Bruce Schneier Facts who have kept me rollin&#8217; on the floor laughing quite a few times.



Bookmark to:
















Hide Sites



$$('div.d1397').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); ]]></description>
			<content:encoded><![CDATA[<p>This week&#8217;s lolcat is a shout-out to <a href="http://www.schneierfacts.com/" target="_blank">Bruce Schneier Facts</a> who have kept me rollin&#8217; on the floor laughing quite a few times.</p>
<p style="text-align: center;"><a href="http://cheezburger.com/View.aspx?aid=2752817152"><img id="_r_a_2752817152" class="aligncenter" title="ciso kitteh iz rdy to take on broose schnayer and his roundhouse kick" src="http://images.cheezburger.com/completestore/2009/10/22/129007356711823425.jpg" alt="ciso kitteh iz rdy to take on broose schnayer and his roundhouse kick" /></a></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1397').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1397" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1397" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1397&amp;title=Look+Out%2C+Sir+Bruce%2C+IKANHAZFIZMA+is+Coming+for+You" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1397&amp;title=Look+Out%2C+Sir+Bruce%2C+IKANHAZFIZMA+is+Coming+for+You" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1397" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1397&amp;title=Look+Out%2C+Sir+Bruce%2C+IKANHAZFIZMA+is+Coming+for+You" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1397&amp;h=Look+Out%2C+Sir+Bruce%2C+IKANHAZFIZMA+is+Coming+for+You" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1397&amp;title=Look+Out%2C+Sir+Bruce%2C+IKANHAZFIZMA+is+Coming+for+You" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1397&amp;title=Look+Out%2C+Sir+Bruce%2C+IKANHAZFIZMA+is+Coming+for+You" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1397&amp;title=Look+Out%2C+Sir+Bruce%2C+IKANHAZFIZMA+is+Coming+for+You" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1397" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1397" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1397&amp;t=Look+Out%2C+Sir+Bruce%2C+IKANHAZFIZMA+is+Coming+for+You" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1397').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1397').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=erU-DjXkaFo:83aLuQZx79Q:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=erU-DjXkaFo:83aLuQZx79Q:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=erU-DjXkaFo:83aLuQZx79Q:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/erU-DjXkaFo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1397/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1397</feedburner:origLink></item>
		<item>
		<title>Massively Scaled Security Solutions for Massively Scaled IT</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/wq-zYtK5Ddw/1383</link>
		<comments>http://www.guerilla-ciso.com/archives/1383#comments</comments>
		<pubDate>Fri, 16 Oct 2009 21:39:29 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[FISMA]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[Public Policy]]></category>
		<category><![CDATA[Speaking]]></category>
		<category><![CDATA[The Guerilla CISO]]></category>
		<category><![CDATA[What Works]]></category>
		<category><![CDATA[catalogofcontrols]]></category>
		<category><![CDATA[certification]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[fisma]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[infosharing]]></category>
		<category><![CDATA[law]]></category>
		<category><![CDATA[legislation]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[publicpolicy]]></category>
		<category><![CDATA[scalability]]></category>
		<category><![CDATA[scap]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[speaking]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1383</guid>
		<description><![CDATA[My presentation slides from Sector 2009.  This was a really fun conference, the Ontario people are really, really nice.
Presentation Abstract:
The US Federal Government is the world&#8217;s largest consumer of IT products and, by extension, one of the largest consumers of IT security products and services. This talk covers some of the problems with security on [...]]]></description>
			<content:encoded><![CDATA[<p>My presentation slides from <a href="http://www.sector.ca/" target="_blank">Sector 2009</a>.  This was a really fun conference, the Ontario people are really, really nice.</p>
<p>Presentation Abstract:</p>
<blockquote><p><em>The US Federal Government is the world&#8217;s largest consumer of IT products and, by extension, one of the largest consumers of IT security products and services. This talk covers some of the problems with security on such a massive scale; how and why some technical, operational, and managerial solutions are working or not working; and how these lessons can be applied to smaller-scale security environments.</em></p></blockquote>
<div align="center">
<div style="width:425px;text-align:left" id="__ss_2247950"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/rybolov/massively-scaled-security-solutions-for-massively-scaled-itsector-09" title="Massively Scaled Security Solutions for Massively Scaled IT:SecTor 09">Massively Scaled Security Solutions for Massively Scaled IT:SecTor 09</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=sector09-091016155501-phpapp02&#038;stripped_title=massively-scaled-security-solutions-for-massively-scaled-itsector-09" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=sector09-091016155501-phpapp02&#038;stripped_title=massively-scaled-security-solutions-for-massively-scaled-itsector-09" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object>
<div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/rybolov">Michael Smith</a>.</div>
</div>
</div>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1383').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1383" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1383" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1383&amp;title=Massively+Scaled+Security+Solutions+for+Massively+Scaled+IT" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1383&amp;title=Massively+Scaled+Security+Solutions+for+Massively+Scaled+IT" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1383" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1383&amp;title=Massively+Scaled+Security+Solutions+for+Massively+Scaled+IT" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1383&amp;h=Massively+Scaled+Security+Solutions+for+Massively+Scaled+IT" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1383&amp;title=Massively+Scaled+Security+Solutions+for+Massively+Scaled+IT" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1383&amp;title=Massively+Scaled+Security+Solutions+for+Massively+Scaled+IT" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1383&amp;title=Massively+Scaled+Security+Solutions+for+Massively+Scaled+IT" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1383" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1383" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1383&amp;t=Massively+Scaled+Security+Solutions+for+Massively+Scaled+IT" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1383').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1383').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=wq-zYtK5Ddw:NwDkmukmSWo:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=wq-zYtK5Ddw:NwDkmukmSWo:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=wq-zYtK5Ddw:NwDkmukmSWo:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/wq-zYtK5Ddw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1383/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1383</feedburner:origLink></item>
		<item>
		<title>Lolcats Coming to you from the Cloud</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/Iotb7IhiH2k/1341</link>
		<comments>http://www.guerilla-ciso.com/archives/1341#comments</comments>
		<pubDate>Thu, 08 Oct 2009 13:55:15 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[IKANHAZFIZMA]]></category>
		<category><![CDATA[cloudcomputing]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[lolcats]]></category>
		<category><![CDATA[scalability]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1341</guid>
		<description><![CDATA[Today our IKANHAZFIZMA lolcats come to you from &#8220;Teh Cloud&#8221;.  Even though here at The Guerilla-CISO we&#8217;re far from being an enterprise solution, we&#8217;ve been living in the cloud for 6 months.  Our setup is a Cloud Server from Mosso which is owned by Rackspace.  Now with GSA&#8217;s cloud application store open for business, the [...]]]></description>
			<content:encoded><![CDATA[<p>Today our IKANHAZFIZMA lolcats come to you from &#8220;Teh Cloud&#8221;.  Even though here at The Guerilla-CISO we&#8217;re far from being an enterprise solution, we&#8217;ve been living in the cloud for 6 months.  Our setup is a <a href="http://www.rackspacecloud.com/cloud_hosting_products/servers" target="_blank">Cloud Server from Mosso</a> which is owned by <a href="http://www.rackspace.com/index.php" target="_blank">Rackspace</a>.  Now with GSA&#8217;s cloud application store open for business, the government world is rushing headlong into cloud computing.</p>
<p>The part where I pitch for Hoff:  Chris Hoff has some awesome ideas on security and cloud computing, <a href="http://www.rationalsurvivability.com/blog/" target="_blank">check out his blog and presentations</a>.</p>
<p style="text-align: center;"><a href="http://cheezburger.com/View.aspx?aid=2647039232"><img id="_r_a_2647039232" class="aligncenter" title="kum join the cloud" src="http://images.cheezburger.com/completestore/2009/9/20/128979283846016520.jpg" alt="kum join the cloud" /></a></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1341').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1341" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1341" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1341&amp;title=Lolcats+Coming+to+you+from+the+Cloud" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1341&amp;title=Lolcats+Coming+to+you+from+the+Cloud" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1341" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1341&amp;title=Lolcats+Coming+to+you+from+the+Cloud" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1341&amp;h=Lolcats+Coming+to+you+from+the+Cloud" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1341&amp;title=Lolcats+Coming+to+you+from+the+Cloud" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1341&amp;title=Lolcats+Coming+to+you+from+the+Cloud" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1341&amp;title=Lolcats+Coming+to+you+from+the+Cloud" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1341" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1341" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1341&amp;t=Lolcats+Coming+to+you+from+the+Cloud" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1341').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1341').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=Iotb7IhiH2k:T1sqqmcfLgU:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=Iotb7IhiH2k:T1sqqmcfLgU:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=Iotb7IhiH2k:T1sqqmcfLgU:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/Iotb7IhiH2k" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1341/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1341</feedburner:origLink></item>
		<item>
		<title>I’m on the OWASP Podcast</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/y2FKTzDOCeM/1379</link>
		<comments>http://www.guerilla-ciso.com/archives/1379#comments</comments>
		<pubDate>Fri, 02 Oct 2009 03:05:34 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[FISMA]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[Public Policy]]></category>
		<category><![CDATA[Rants]]></category>
		<category><![CDATA[Speaking]]></category>
		<category><![CDATA[The Guerilla CISO]]></category>
		<category><![CDATA[800-53]]></category>
		<category><![CDATA[C&A]]></category>
		<category><![CDATA[cashcows]]></category>
		<category><![CDATA[catalogofcontrols]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[fisma]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[infosharing]]></category>
		<category><![CDATA[itsatrap]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[moneymoneymoney]]></category>
		<category><![CDATA[omb]]></category>
		<category><![CDATA[publicpolicy]]></category>
		<category><![CDATA[scalability]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[speaking]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1379</guid>
		<description><![CDATA[I sat down with Jim Manico a month or so ago when he was in DC and recorded a podcast for the OWASP Podcast.  It&#8217;s now live, check it out.


Bookmark to:
















Hide Sites



$$('div.d1379').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); ]]></description>
			<content:encoded><![CDATA[<p>I sat down with Jim Manico a month or so ago when he was in DC and <a href="http://www.owasp.org/index.php/Podcast_43" target="_blank">recorded a podcast for the OWASP Podcast</a>.  It&#8217;s now live, check it out.</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1379').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1379" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1379" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1379&amp;title=I%26%238217%3Bm+on+the+OWASP+Podcast" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1379&amp;title=I%26%238217%3Bm+on+the+OWASP+Podcast" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1379" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1379&amp;title=I%26%238217%3Bm+on+the+OWASP+Podcast" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1379&amp;h=I%26%238217%3Bm+on+the+OWASP+Podcast" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1379&amp;title=I%26%238217%3Bm+on+the+OWASP+Podcast" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1379&amp;title=I%26%238217%3Bm+on+the+OWASP+Podcast" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1379&amp;title=I%26%238217%3Bm+on+the+OWASP+Podcast" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1379" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1379" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1379&amp;t=I%26%238217%3Bm+on+the+OWASP+Podcast" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1379').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1379').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=y2FKTzDOCeM:KX5YjUcj14I:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=y2FKTzDOCeM:KX5YjUcj14I:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=y2FKTzDOCeM:KX5YjUcj14I:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/y2FKTzDOCeM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1379/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1379</feedburner:origLink></item>
		<item>
		<title>The Guerilla CISO Rants: Don’t Write a System Security Plan</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/Avn7Hmyu-QU/1351</link>
		<comments>http://www.guerilla-ciso.com/archives/1351#comments</comments>
		<pubDate>Fri, 02 Oct 2009 01:59:33 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[FISMA]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[800-53]]></category>
		<category><![CDATA[800-53A]]></category>
		<category><![CDATA[accreditation]]></category>
		<category><![CDATA[auditor]]></category>
		<category><![CDATA[C&A]]></category>
		<category><![CDATA[catalogofcontrols]]></category>
		<category><![CDATA[categorization]]></category>
		<category><![CDATA[certification]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[infosharing]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[scalability]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1351</guid>
		<description><![CDATA[OK, I know you&#8217;re shocked&#8230;I&#8217;m saying something controversial.  But hear me out on this one, I&#8217;ll explain.
Now this is my major beef with the way we write SSPs today:  this is all information that is contained in other artifacts that I have to pay people to do cut-and-paste to get it into a SSP template.  [...]]]></description>
			<content:encoded><![CDATA[<p>OK, I know you&#8217;re shocked&#8230;I&#8217;m saying something controversial.  But hear me out on this one, I&#8217;ll explain.</p>
<p>Now this is my major beef with the way we write SSPs today:  this is all information that is contained in other artifacts that I have to pay people to do cut-and-paste to get it into a SSP template.  As practiced, we seriously have a problem with polyinstantiation of data in various lifecycle artifacts that is cut-and-pasted into an SSP.  Every time you change the upstream document, you create a difference between that document and the SSP.</p>
<p>This is a practice I would like to change, but I can&#8217;t do it all by myself.</p>
<p>This is the skeleton outline of an SSP from Special Publication 800-18, the guide to writing an SSP:</p>
<ol>
<li>Information System Name/Title&#8211;On the investment/FISMA inventory, the Exhibit 300/53, etc</li>
<li>Information System Categorization&#8211;usually on a FIPS-199 memorandum</li>
<li>Information System Owner&#8211;In an assignment memo</li>
<li>Authorizing Official&#8211;In an assignment memo</li>
<li>Other Designated Contacts&#8211;In an assignment memo</li>
<li>Assignment of Security Responsibility&#8211;In assignment memos</li>
<li>Information System Operational Status&#8211;On the investment/FISMA inventory, the Exhibit 300/53, etc</li>
<li>Information System Type&#8211;On the investment/FISMA inventory, the Exhibit 300/53, etc</li>
<li>General System Description/Purpose&#8211;In the design document, Exhibit 300/53</li>
<li>System Environment&#8211;Common controls not inside the scope of our system</li>
<li>System Interconnections/Information Sharing&#8211;from Interconnection Security Agreements</li>
<li>Related Laws/Regulations/Policies&#8211;Should be part of the system categorization but hardly ever is on templates</li>
<li>Minimum Security Controls&#8211;800-53 controls descriptions which can easily be done in a Requirements Traceability Matrix</li>
<li>Information System Security Plan Completion Date&#8211;specific to each document</li>
<li> Information System Security Plan Approval Date&#8211;specific to each document</li>
</ol>
<p>Now some of this has changed in practice a little bit&#8211;# 10 can functionally be replaced with a designation of common controls and hybrid controls.</p>
<p>So my line of thinking is that if we provide a 2-6-page system description with the names of the &#8220;guilty parties&#8221; and some inventory information, controls-specific Requirements Traceability Matrix, and a System Design Document, then we have the functional equivalent of an SSP.</p>
<p><strong> </strong></p>
<p><strong> Why have I declared an InfoSec fatwah against SSPs as currently practiced?</strong></p>
<p>Well, my philosophy for operation is based on some concepts I&#8217;ve picked up through the years:</p>
<ul>
<li>Why run when you can walk, why walk when you can sit, why sit when you can lay down.  There is a time to spend effort on determining what the security controls are for a project.  You need to have them documented but it&#8217;s not cost-effective to be worried about format, which we do probably too much of today.</li>
<li>Make it easy to do the right thing.  If we polyinstantiate security information, we have made something harder to maintain.  Easier to maintain means that it will get maintained instead of being shelfware.  I would rather have updated and accurate security information than overly verbose and well-polished documents that are inaccurate.</li>
<li>Security is not a &#8220;security guy thing&#8221;&#8211;most problems are actually a management and project team problem.  My idea uses their SDLC artifacts instead of security-specific versions of artifacts.  My idea puts the project problems back in the project space where it belongs.</li>
<li>If I have a security engineer who has a finite amount of hours in a day, I have to choose what they spend their time on.  If it&#8217;s a matter of vulnerability mitigation, patching, etc, or correcting SSP grammar, I know what I want him to do.  Then again, I&#8217;m still an infantryman deep down inside and I realize I have biases against flowery writing.</li>
</ul>
<p><strong>Criticisms to not writing a dedicated SSP document:</strong></p>
<p><em>&#8220;My auditors are used to seeing the information in the same format at someplace they worked previously&#8221;.</em> Believe it or not, I hear this quite a bit.  My response is along the lines of the fact that if you make your standard be what I&#8217;m suggesting for a security plan, then you&#8217;ve met all of the FISMA and 800-53 requirements and my personal requirement to &#8220;don&#8217;t do stupid stuff if you can help it&#8221;.</p>
<p><em>&#8220;My auditors will grill me to death if they have to page back and forth between several documents&#8221;</em>.  This one also I&#8217;ve heard.  There are a couple of ways to deal with this.  One way to deal with this is that in your 800-53 Requirements Traceability Matrix you reference the source document.  Most auditors at this point bring up that you need to reference the official name, date of publication, and specific page/section of the reference and I think they need to get a life because they&#8217;ve taken us back to the maintainability problem.</p>
<p><em>&#8220;This is all too new-school and I can&#8217;t get over it&#8221;.</em> Then you are a dinosaur and your kind deserves extinction.  =)</p>
<p><strong><span style="color: #525252;">.</span><br />
</strong></p>
<p>This blog post is for grecs at <a href="http://www.novainfosecportal.com/" target="_blank">novainfosecportal.com</a> who perked up instantly when I mentioned the concept months ago.  Finally got around to putting the text somewhere.</p>
<p style="text-align: center;"><em><img class="alignnone" title="How to Plan the Perfect Dinner Party" src="http://farm4.static.flickr.com/3205/2811157950_a08da7e19e.jpg" alt="" width="500" height="495" /></em></p>
<p style="text-align: center;"><em>How to Plan the Perfect Dinner Party photo by <a title="Link to kevindooley's photostream" rel="dc:creator cc:attributionURL" href="http://www.flickr.com/photos/pagedooley/"><strong>kevindooley</strong></a>.</em></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1351').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1351" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1351" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1351&amp;title=The+Guerilla+CISO+Rants%3A+Don%26%238217%3Bt+Write+a+System+Security+Plan" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1351&amp;title=The+Guerilla+CISO+Rants%3A+Don%26%238217%3Bt+Write+a+System+Security+Plan" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1351" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1351&amp;title=The+Guerilla+CISO+Rants%3A+Don%26%238217%3Bt+Write+a+System+Security+Plan" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1351&amp;h=The+Guerilla+CISO+Rants%3A+Don%26%238217%3Bt+Write+a+System+Security+Plan" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1351&amp;title=The+Guerilla+CISO+Rants%3A+Don%26%238217%3Bt+Write+a+System+Security+Plan" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1351&amp;title=The+Guerilla+CISO+Rants%3A+Don%26%238217%3Bt+Write+a+System+Security+Plan" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1351&amp;title=The+Guerilla+CISO+Rants%3A+Don%26%238217%3Bt+Write+a+System+Security+Plan" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1351" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1351" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1351&amp;t=The+Guerilla+CISO+Rants%3A+Don%26%238217%3Bt+Write+a+System+Security+Plan" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1351').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1351').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=Avn7Hmyu-QU:YRw0Mf-6FeI:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=Avn7Hmyu-QU:YRw0Mf-6FeI:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=Avn7Hmyu-QU:YRw0Mf-6FeI:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/Avn7Hmyu-QU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1351/feed</wfw:commentRss>
		<slash:comments>11</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1351</feedburner:origLink></item>
		<item>
		<title>Lolcats Attend B-Sides</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/IAdVZQ7Fino/1338</link>
		<comments>http://www.guerilla-ciso.com/archives/1338#comments</comments>
		<pubDate>Thu, 01 Oct 2009 13:39:40 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[IKANHAZFIZMA]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[lolcats]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[speaking]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1338</guid>
		<description><![CDATA[This week&#8217;s lolcats are a shout-out to the B-Sides crew who manage to do unconferences at major security conferences.  Think of it as emerging ideas for the security set.



Bookmark to:
















Hide Sites



$$('div.d1338').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); ]]></description>
			<content:encoded><![CDATA[<p>This week&#8217;s lolcats are a shout-out to the <a href="http://www.securitybsides.com/">B-Sides crew</a> who manage to do unconferences at major security conferences.  Think of it as emerging ideas for the security set.</p>
<p style="text-align: center;"><a href="http://cheezburger.com/View.aspx?aid=2647009792"><img id="_r_a_2647009792" class="aligncenter" title="b-sidez: the informal conferenz for ciso kittehs" src="http://images.cheezburger.com/completestore/2009/9/20/128979274239861291.jpg" alt="b-sidez: the informal conferenz for ciso kittehs" /></a></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1338').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1338" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1338" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1338&amp;title=Lolcats+Attend+B-Sides" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1338&amp;title=Lolcats+Attend+B-Sides" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1338" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1338&amp;title=Lolcats+Attend+B-Sides" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1338&amp;h=Lolcats+Attend+B-Sides" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1338&amp;title=Lolcats+Attend+B-Sides" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1338&amp;title=Lolcats+Attend+B-Sides" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1338&amp;title=Lolcats+Attend+B-Sides" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1338" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1338" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1338&amp;t=Lolcats+Attend+B-Sides" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1338').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1338').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=IAdVZQ7Fino:hCA6MEtQCkw:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=IAdVZQ7Fino:hCA6MEtQCkw:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=IAdVZQ7Fino:hCA6MEtQCkw:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/IAdVZQ7Fino" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1338/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1338</feedburner:origLink></item>
		<item>
		<title>Web 2.0 and Social Media Threats for Government</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/6FuoHyQQ1ng/1325</link>
		<comments>http://www.guerilla-ciso.com/archives/1325#comments</comments>
		<pubDate>Thu, 01 Oct 2009 03:22:42 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[gov20]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[infosharing]]></category>
		<category><![CDATA[itsatrap]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[pwnage]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[socialmedia]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1325</guid>
		<description><![CDATA[So most of the security world is familiar with the Web 2.0 and Social Media threats in the private sector.  Today we&#8217;re going to have an expose on the threats specific to Government because I don&#8217;t feel that they&#8217;ve been adequately represented in this whole push for Government 2.0 and transparency.
Threat: Evil Twin Agency Attack. [...]]]></description>
			<content:encoded><![CDATA[<p>So most of the security world is familiar with the Web 2.0 and Social Media threats in the private sector.  Today we&#8217;re going to have an expose on the threats specific to Government because I don&#8217;t feel that they&#8217;ve been adequately represented in this whole push for <a href="http://en.wikipedia.org/wiki/Government_2.0" target="_blank">Government 2.0 and transparency</a>.</p>
<p><strong>Threat: Evil Twin Agency Attack.</strong> A person registers on a social media site using the name of a Government entity.  They then represent that entity to the public and say whatever it is that they want that agency to say.</p>
<p><strong>What&#8217;s the Big Deal: </strong>Since for the most part there is no way to prove the authenticity of Government entities on social media sites short of a &#8220;catch us on &lt;social media site&gt;&#8221; tag on their .gov homepage.  This isn&#8217;t an attack unique to Government but because of the authority that people give to Government Internet presences means that the attacker gains perceived legitimacy.</p>
<p><strong>Countermeasures:</strong> Monitoring by the agencies looking for their official and unofficial presences on Social Media and Web 2.0 sites.  Any new registrations on social media are vetted for authenticity through the agency&#8217;s public affairs office.  Agencies should have an official presence on social media to reserve their namespace and put these account names on their official website.</p>
<p><strong>References:</strong></p>
<ul>
<li><a href="http://www.gnucitizen.org/blog/social-networks-evil-twin-attacks/" target="_blank">Evil Twin Attack on GNUCITIZEN</a></li>
</ul>
<p><span style="color: #525252;"><strong>.</strong></span></p>
<p><strong>Threat: Web Hoax. </strong>A non-government person sets up their own social media or website and claims to be the Government.</p>
<p><strong>What&#8217;s the Big Deal:</strong> This is similar to the evil twin attack only maybe of a different scale.  For example, an entire social media site can be set up pretending to be a Government agency doing social networking and collecting data on citizens or asking citizens to do things on behalf of the Government.  There is also a thin line between parody and</p>
<p><strong>Countermeasures: </strong>Monitoring of URLs that claim to be Government-owned.  This is easily done with some Google advanced operators and some RSS fun.</p>
<p><strong>References:</strong></p>
<ul>
<li><a href="http://www.dhsnnw.org/" target="_blank">Network Neighborhood Watch</a></li>
</ul>
<p><span style="color: #525252;"><strong>.</strong></span></p>
<p><strong>Threat: Privacy Violations on Forums.</strong> A Government-operated social media site collects Personally Identifiable Information about visitors when they register to participate in forums, blog comments, etc.</p>
<p><strong>What&#8217;s the Big Deal:</strong> If you&#8217;re a Government agency and going to be collecting PII, you need to do a Privacy Impact Assessment which is overkill if you&#8217;re collecting names and email which could be false anyway.  However, the PIA is a lengthy process and utterly destroys the quickness of web development as we know it.</p>
<p><strong>Countermeasures: </strong>It has been proposed in some circles that Government social media sites use third-party ID providers such as OpenID to authenticate simple commenters and forum posts.  This isn&#8217;t an original idea, Noel Dickover has been asking around about it for at least 9 months that I know of.</p>
<p><strong>References:</strong></p>
<ul>
<li><a href="http://www.thesocialweb.tv/blog/2009/01/episode-25-an-open-letter-to-the-obama-administration.html" target="_blank">Should Government be an ID Provider</a></li>
<li><a href="http://openid.net/" target="_blank">OpenID</a></li>
</ul>
<p><span style="color: #525252;"><strong>.</strong></span></p>
<p><strong>Threat: Monitoring v/s Law Enforcement v/s Intelligence Collection.</strong> The Government has to be careful about monitoring social media sites.  Depending on which agency is doing it, at some point you collect enough information from enough sources that you&#8217;re now monitoring US persons.</p>
<p><strong>What&#8217;s the Big Deal: </strong>If you&#8217;re collecting information and doing traffic analysis on people, you&#8217;re most likely running up against wiretap laws and/or FISA.</p>
<p><strong>Countermeasures:</strong> Government needs Rules of Engagement for creating 2-way dialog with citizens complete with standards for the following practices:</p>
<ul>
<li>RSS feed aggregation for primary and secondary purposes</li>
<li>RSS feed republishing</li>
<li>Social networking monitoring for evil twin and hoax site attacks</li>
<li>Typical &#8220;Web 2.0 Marketing&#8221; tactics such as group analysis</li>
</ul>
<p><strong>References:</strong></p>
<ul>
<li><a href="http://www.mike-manuel.com/blog/2008/07/17/how-to-create-a-social-media-monitoring-strategy/" target="_blank">How to Create a Social Media Monitoring Strategy</a>.  Note that most of what this blog post advises can get a Government agency in trouble even though it&#8217;s sound advice for the private sector.</li>
</ul>
<p><span style="color: #525252;"><strong>.</strong></span></p>
<p><strong>Threat: Hacked?  Not Us!</strong> The Government does weird stuff with web sites.  My web browser always carps at the government-issued SSL certificates because they use their own certificate authority.</p>
<p><strong>What&#8217;s the Big Deal: </strong>Even though I know a Government site is legitimate, I still have problems getting alert popups.  Being hacked with a XSS or other attack has much more weight than for other sites because people expect to get weird errors from Government sites and just click through.  Also the sheer volume of traffic on Government websites means that they are a lucrative target if the attacker&#8217;s end goal is to infect desktops.</p>
<p><strong>Countermeasures:</strong> The standard web server anti-XSS and other web application security stuff works here.  Another happy thing would be to get the Federal CA Certificate embedded in web browsers by default like Thawt and Verisign.</p>
<p><strong>References:</strong></p>
<ul>
<li><a href="http://www.theregister.co.uk/2009/01/27/myobama_malware_scam/" target="_blank">MyBarackObama profile hack punts malware</a></li>
<li><a href="http://securitylabs.websense.com/content/Blogs/3284.aspx" target="_blank">Barack Obama&#8217;s Site Leading to Trojan</a></li>
</ul>
<p><span style="color: #525252;"><strong>.</strong></span></p>
<p><strong>Threat: Oh Hai I Reset Your Password For You</strong> AKA &#8220;The Sarah Palin Attack&#8221;.  The password reset functions in social media sites work if you&#8217;re not a public figure.  Once the details of your life become scrutinized, your pet&#8217;s name, mother&#8217;s maiden name, etc, all become public knowledge.</p>
<p><strong>What&#8217;s the Big Deal: </strong>It depends on what kind of data you have in the social media site.  This can range anywhere from the attacker getting access to one social media site that they get lucky with to complete pwnage of your VIP&#8217;s online accounts.</p>
<p><strong>Countermeasures:</strong> Engagement with the social media site to get special considerations for Government VIPS.  Use of organizational accounts v/s personal accounts on social media sites.  Information poisoning on password reset questions for VIPs&#8211;don&#8217;t put the real data up there.  =)</p>
<p><strong>References:</strong></p>
<ul>
<li><a href="http://www.wired.com/threatlevel/2008/09/palin-e-mail-ha/" target="_blank">Sarah Palin &#8220;hack&#8221;</a></li>
</ul>
<p style="text-align: center;"><em><img class="alignnone" title="Transparency in Action" src="http://farm1.static.flickr.com/4/6475939_d06599ed54.jpg" alt="" width="356" height="500" /></em></p>
<p style="text-align: center;"><em>Tranparency in Action photo by <a title="Link to Jeff Belmonte's photostream" rel="dc:creator cc:attributionURL" href="http://www.flickr.com/photos/jeffbelmonte/"><strong>Jeff Belmonte</strong></a>.</em></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1325').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1325" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1325" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1325&amp;title=Web+2.0+and+Social+Media+Threats+for+Government" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1325&amp;title=Web+2.0+and+Social+Media+Threats+for+Government" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1325" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1325&amp;title=Web+2.0+and+Social+Media+Threats+for+Government" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1325&amp;h=Web+2.0+and+Social+Media+Threats+for+Government" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1325&amp;title=Web+2.0+and+Social+Media+Threats+for+Government" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1325&amp;title=Web+2.0+and+Social+Media+Threats+for+Government" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1325&amp;title=Web+2.0+and+Social+Media+Threats+for+Government" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1325" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1325" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1325&amp;t=Web+2.0+and+Social+Media+Threats+for+Government" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1325').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1325').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=6FuoHyQQ1ng:qS1Ux2RZy1o:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=6FuoHyQQ1ng:qS1Ux2RZy1o:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=6FuoHyQQ1ng:qS1Ux2RZy1o:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/6FuoHyQQ1ng" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1325/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1325</feedburner:origLink></item>
		<item>
		<title>IKANHAZFIZMA and Transparency</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/svme2q1Fp_I/1335</link>
		<comments>http://www.guerilla-ciso.com/archives/1335#comments</comments>
		<pubDate>Thu, 24 Sep 2009 13:08:44 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[IKANHAZFIZMA]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[itsatrap]]></category>
		<category><![CDATA[lolcats]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[transparency]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1335</guid>
		<description><![CDATA[It&#8217;s a complete change on how the Government does business, but agency CISOs are marching along to the transparency and openness beat, still feeling like somehow somewhere it;s not really the right idea security-wise.  Welcome to life in the fish bowl.  =)
On another note, I know that one day I&#8217;ll walk into somebody&#8217;s office or [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s a complete change on how the Government does business, but agency CISOs are marching along to the transparency and openness beat, still feeling like somehow somewhere it;s not really the right idea security-wise.  Welcome to life in the fish bowl.  =)</p>
<p>On another note, I know that one day I&#8217;ll walk into somebody&#8217;s office or cubicle and they will have IKANHAZFIZMA lolcats pinned to the wall and it will be the highlight of the week for me.  If you&#8217;re a lolcat printer, drop me an email.</p>
<p style="text-align: center;"><a href="http://cheezburger.com/View.aspx?aid=2646962944"><img id="_r_a_2646962944" class="aligncenter" title="ciso kitteh gears up for transparensee" src="http://images.cheezburger.com/completestore/2009/9/20/128979255586773162.jpg" alt="ciso kitteh gears up for transparensee" /></a></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1335').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1335" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1335" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1335&amp;title=IKANHAZFIZMA+and+Transparency" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1335&amp;title=IKANHAZFIZMA+and+Transparency" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1335" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1335&amp;title=IKANHAZFIZMA+and+Transparency" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1335&amp;h=IKANHAZFIZMA+and+Transparency" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1335&amp;title=IKANHAZFIZMA+and+Transparency" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1335&amp;title=IKANHAZFIZMA+and+Transparency" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1335&amp;title=IKANHAZFIZMA+and+Transparency" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1335" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1335" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1335&amp;t=IKANHAZFIZMA+and+Transparency" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1335').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1335').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=svme2q1Fp_I:rg_FaR5NWe0:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=svme2q1Fp_I:rg_FaR5NWe0:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=svme2q1Fp_I:rg_FaR5NWe0:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/svme2q1Fp_I" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1335/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1335</feedburner:origLink></item>
		<item>
		<title>CIO Council Guidelines on Social Media Meet IKANHAZFIZMA</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/TThJDVNTKvM/1346</link>
		<comments>http://www.guerilla-ciso.com/archives/1346#comments</comments>
		<pubDate>Mon, 21 Sep 2009 21:25:05 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[IKANHAZFIZMA]]></category>
		<category><![CDATA[gov20]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[lolcats]]></category>
		<category><![CDATA[publicpolicy]]></category>
		<category><![CDATA[socialnetworking]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1346</guid>
		<description><![CDATA[Due to the the CIO Council&#8217;s Guidelines on Social Media being carried by, well, just about everybody out there who can spell &#8220;Gov 2.0&#8243; (including the crazy folks at GovTwit), we here at the Guerilla CISO have decided to release an out-of-cycle lolcat to commemorate the event.



Bookmark to:
















Hide Sites



$$('div.d1346').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); ]]></description>
			<content:encoded><![CDATA[<p>Due to the the CIO Council&#8217;s Guidelines on Social Media being carried by, well, just about everybody out there who can spell &#8220;Gov 2.0&#8243; (including the crazy folks at <a href="http://govtwit.wordpress.com/2009/09/21/govtwit-week-in-review-914-920/" target="_blank">GovTwit</a>), we here at the Guerilla CISO have decided to release an out-of-cycle lolcat to commemorate the event.</p>
<p style="text-align: center;"><a href="http://cheezburger.com/View.aspx?aid=2651263744"><img id="_r_a_2651263744" class="aligncenter" title="cio kounsil" src="http://images.cheezburger.com/completestore/2009/9/21/128980411473112143.jpg" alt="cio kounsil" /></a></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1346').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1346" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1346" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1346&amp;title=CIO+Council+Guidelines+on+Social+Media+Meet+IKANHAZFIZMA" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1346&amp;title=CIO+Council+Guidelines+on+Social+Media+Meet+IKANHAZFIZMA" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1346" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1346&amp;title=CIO+Council+Guidelines+on+Social+Media+Meet+IKANHAZFIZMA" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1346&amp;h=CIO+Council+Guidelines+on+Social+Media+Meet+IKANHAZFIZMA" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1346&amp;title=CIO+Council+Guidelines+on+Social+Media+Meet+IKANHAZFIZMA" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1346&amp;title=CIO+Council+Guidelines+on+Social+Media+Meet+IKANHAZFIZMA" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1346&amp;title=CIO+Council+Guidelines+on+Social+Media+Meet+IKANHAZFIZMA" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1346" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1346" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1346&amp;t=CIO+Council+Guidelines+on+Social+Media+Meet+IKANHAZFIZMA" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1346').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1346').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=TThJDVNTKvM:-wnmcgoaO0o:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=TThJDVNTKvM:-wnmcgoaO0o:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=TThJDVNTKvM:-wnmcgoaO0o:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/TThJDVNTKvM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1346/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1346</feedburner:origLink></item>
		<item>
		<title>Where is Rybolov?</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/l0QaVYFNxuM/1328</link>
		<comments>http://www.guerilla-ciso.com/archives/1328#comments</comments>
		<pubDate>Mon, 21 Sep 2009 14:44:56 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[Speaking]]></category>
		<category><![CDATA[The Guerilla CISO]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[speaking]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1328</guid>
		<description><![CDATA[Been busy lately.  This is a quick rundown on where I&#8217;ll be over the next couple of months so you can stalk me.

October 5-7: SecTor, Toronto, ON, Canada.  I&#8217;ll be talking about &#8220;Massively Scaled Security Solutions for Massively Scaled IT&#8221; which an allusion to the size of the US Federal Government IT budget and techniques [...]]]></description>
			<content:encoded><![CDATA[<p>Been busy lately.  This is a quick rundown on where I&#8217;ll be over the next couple of months so you can stalk me.</p>
<ul>
<li><strong>October 5-7:</strong> <a href="http://www.sector.ca/" target="_blank">SecTor, Toronto, ON, Canada</a>.  I&#8217;ll be talking about &#8220;Massively Scaled Security Solutions for Massively Scaled IT&#8221; which an allusion to the size of the US Federal Government IT budget and techniques that they use to manage it.  The <a href="http://www.guerilla-ciso.com/archives/1274">Rybolov Layered Information Security Management Model</a> seen here earlier weighs heavily into the presentation, as does a ton of other ideas trying to get people to understand that hazy information security management area above the enterprise.</li>
<li><strong>November 6-7:</strong> <a href="http://www.dojocon.org/" target="_blank">DojoCon, Laurel, MD</a>.  I&#8217;ll be talking about the &#8220;Current State of Compliance&#8221; which somewhere along the lines has a punchline of &#8220;It&#8217;s going to happen anyway, might as well drive the bus instead of being under the bus&#8221;.  There is also a compliance panel following my talk and I&#8217;ll be on it with <a href="http://howisthatassuranceevidence.blogspot.com/" target="_blank">Cyberhiker</a> and <a href="http://www.fismapedia.org/" target="_blank">Dan Philpott</a>.</li>
<li><strong>November 10-14:</strong> <a href="http://appsecdc.org/" target="_blank">AppSec DC, Washington, DC</a>.  I&#8217;ll be running amok making part of the conference work.  I&#8217;m not speaking at this one which is a good thing because, well, everytime I start talking web apps and security it takes me back to all the bad code I wrote in the late 90&#8217;s.  But hey, didn&#8217;t we all?</li>
</ul>
<p>So in between preparing slides, running amok as a volunteer, and the usual work-life imbalance, I haven&#8217;t had much free time lately to add to the blog.  Plenty of ideas and blog fodder are floating around inside my head.  After the conventions I&#8217;ll put up my materials for the rest of the world to pick on.</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1328').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1328" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1328" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1328&amp;title=Where+is+Rybolov%3F" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1328&amp;title=Where+is+Rybolov%3F" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1328" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1328&amp;title=Where+is+Rybolov%3F" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1328&amp;h=Where+is+Rybolov%3F" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1328&amp;title=Where+is+Rybolov%3F" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1328&amp;title=Where+is+Rybolov%3F" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1328&amp;title=Where+is+Rybolov%3F" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1328" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1328" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1328&amp;t=Where+is+Rybolov%3F" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1328').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1328').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=l0QaVYFNxuM:VMuf0cfT1TQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=l0QaVYFNxuM:VMuf0cfT1TQ:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=l0QaVYFNxuM:VMuf0cfT1TQ:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/l0QaVYFNxuM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1328/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1328</feedburner:origLink></item>
		<item>
		<title>Federal Computer Week and S.773</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/jIR3LuyiLec/1344</link>
		<comments>http://www.guerilla-ciso.com/archives/1344#comments</comments>
		<pubDate>Sun, 20 Sep 2009 15:14:44 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[FUD]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[infosharing]]></category>
		<category><![CDATA[itsatrap]]></category>
		<category><![CDATA[law]]></category>
		<category><![CDATA[legislation]]></category>
		<category><![CDATA[publicpolicy]]></category>
		<category><![CDATA[S773]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1344</guid>
		<description><![CDATA[A phenomenal cartoon that reflects the true depth of discussion on S.773.  You may now return to your regularly-scheduled hacking.
Hat tip to Dan Philpott.


Bookmark to:
















Hide Sites



$$('div.d1344').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); ]]></description>
			<content:encoded><![CDATA[<p><a href="http://fcw.com/articles/2009/09/21/ink-tank.aspx" target="_blank">A phenomenal cartoon that reflects the true depth of discussion on S.773</a>.  You may now return to your regularly-scheduled hacking.</p>
<p>Hat tip to <a href="http://www.guerilla-ciso.com/about">Dan Philpott</a>.</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1344').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1344" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1344" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1344&amp;title=Federal+Computer+Week+and+S.773" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1344&amp;title=Federal+Computer+Week+and+S.773" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1344" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1344&amp;title=Federal+Computer+Week+and+S.773" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1344&amp;h=Federal+Computer+Week+and+S.773" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1344&amp;title=Federal+Computer+Week+and+S.773" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1344&amp;title=Federal+Computer+Week+and+S.773" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1344&amp;title=Federal+Computer+Week+and+S.773" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1344" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1344" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1344&amp;t=Federal+Computer+Week+and+S.773" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1344').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1344').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=jIR3LuyiLec:3Jh_qAkzPb8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=jIR3LuyiLec:3Jh_qAkzPb8:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=jIR3LuyiLec:3Jh_qAkzPb8:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/jIR3LuyiLec" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1344/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1344</feedburner:origLink></item>
		<item>
		<title>Federal CIO Council’s Guidelines on Security and Social Media</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/NqBrZvUmbW0/1320</link>
		<comments>http://www.guerilla-ciso.com/archives/1320#comments</comments>
		<pubDate>Fri, 18 Sep 2009 01:04:39 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[Odds-n-Sods]]></category>
		<category><![CDATA[The Guerilla CISO]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[collusion]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[infosharing]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[pwnage]]></category>
		<category><![CDATA[socialnetworking]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1320</guid>
		<description><![CDATA[I got an email today from the author who said that it&#8217;s now officially on the street: Guidelines for Secure Use of Social Media by Federal Departments and Agencies, v1.0.  I&#8217;m listed as a reviewer/contributor, which means that maybe I have some good ideas from time to time or that I know some people who [...]]]></description>
			<content:encoded><![CDATA[<p>I got an email today from the author who said that it&#8217;s now officially on the street: <a href="http://www.cio.gov/Library/documents_details.cfm?id=Guidelines for Secure Use of Social Media by Federal Departments and Agencies, v1.0&amp;structure=Information Technology&amp;category=Best Practices" target="_blank">Guidelines for Secure Use of Social Media by Federal Departments and Agencies, v1.0</a>.  I&#8217;m listed as a reviewer/contributor, which means that maybe I have some good ideas from time to time or that I know some people who know people.  =)</p>
<p style="padding-left: 30px;"><em><strong>Abstract: </strong>The use of social media for federal services and interactions is growing tremendously, supported by initiatives from the administration, directives from government leaders, and demands from the public. This situation presents both opportunity and risk. Guidelines and recommendations for using social media technologies in a manner that minimizes the risk are analyzed and presented in this document.</em></p>
<p style="padding-left: 30px;"><em>This document is intended as guidance for any federal agency that uses social media services to collaborate and communicate among employees, partners, other federal agencies, and the public.</em></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1320').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1320" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1320" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1320&amp;title=Federal+CIO+Council%26%238217%3Bs+Guidelines+on+Security+and+Social+Media" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1320&amp;title=Federal+CIO+Council%26%238217%3Bs+Guidelines+on+Security+and+Social+Media" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1320" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1320&amp;title=Federal+CIO+Council%26%238217%3Bs+Guidelines+on+Security+and+Social+Media" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1320&amp;h=Federal+CIO+Council%26%238217%3Bs+Guidelines+on+Security+and+Social+Media" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1320&amp;title=Federal+CIO+Council%26%238217%3Bs+Guidelines+on+Security+and+Social+Media" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1320&amp;title=Federal+CIO+Council%26%238217%3Bs+Guidelines+on+Security+and+Social+Media" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1320&amp;title=Federal+CIO+Council%26%238217%3Bs+Guidelines+on+Security+and+Social+Media" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1320" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1320" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1320&amp;t=Federal+CIO+Council%26%238217%3Bs+Guidelines+on+Security+and+Social+Media" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1320').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1320').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=NqBrZvUmbW0:NUilIdl0yak:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=NqBrZvUmbW0:NUilIdl0yak:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=NqBrZvUmbW0:NUilIdl0yak:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/NqBrZvUmbW0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1320/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1320</feedburner:origLink></item>
		<item>
		<title>Risk Management and Crazy People, a Script Using Stock Characters</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/R0yfvatVCgc/1312</link>
		<comments>http://www.guerilla-ciso.com/archives/1312#comments</comments>
		<pubDate>Fri, 11 Sep 2009 02:58:25 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[BSOFH]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[The Guerilla CISO]]></category>
		<category><![CDATA[crazies]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[itsatrap]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1312</guid>
		<description><![CDATA[Our BSOFH meets a Crazy Homeless Guy on the street just outside the Pentagon City metro station.
Crazy Homeless Guy: (walks up to BSOFH) Can I ask you a question?
BSOFH: (Somewhat startled, nobody really talks to him unless they&#8217;re trying to sell him something) Uhhhh, sure.
Crazy Homeless Guy: You know that there are people who claim [...]]]></description>
			<content:encoded><![CDATA[<p>Our <strong>BSOFH</strong> meets a <strong>Crazy Homeless Guy</strong> on the street just outside the Pentagon City metro station.</p>
<p><strong>Crazy Homeless Guy:</strong> (walks up to BSOFH) Can I ask you a question?</p>
<p><strong>BSOFH:</strong> (Somewhat startled, nobody really talks to him unless they&#8217;re trying to sell him something) Uhhhh, sure.</p>
<p><strong>Crazy Homeless Guy:</strong> You know that there are people who claim to be able to say&#8230; take that truck over there and just by moving their finger make it fly into the Washington Monument.  Don&#8217;t you think that this is a threat to national security?</p>
<p><strong>BSOFH:</strong> (Realizes that Crazy Homeless Guy is crazy and homeless) Not necessarily, you see.  I would definitely classify it as a threat.  However, when you&#8217;re looking at threats from people, you have to look at motives, opportunity, and motives.  Until you have all three, it&#8217;s more of an unrealized threat.</p>
<p><strong>Crazy Homeless Guy:</strong> But what if these same guys could kill the President the same way, isn&#8217;t that a national threat?</p>
<p><strong>BSOFH:</strong> Um, could be.  But then again, let&#8217;s look at a similar analogy:  firearm ownership.  Millions of people safely own weapons and yet there isn&#8217;t this huge upswell to shoot the President now is there?  Really, we have laws against shooting people and when somebody does that, we find them and put them in jail or *something*.  We don&#8217;t criminalize the threat, we criminalize the action.  Flicking a finger doesn&#8217;t kill people, psycho people kill people.</p>
<p><strong>Crazy Homeless Guy:</strong> Or even if these same people could use the same amount of effort to kill everybody on the planet.  You know the <strong>&lt;censored, I don&#8217;t like being sued by cults&gt;</strong> people claim to have this ability.</p>
<p><strong>BSOFH:</strong> (Jokingly, realizing that somebody has been taking 4chan too seriously) Well, I wouldn&#8217;t care too much because I would be&#8230; well, dead.  But yes, possibly.  But then again, since the dawn of the nuclear age and all through the Cold War we&#8217;ve had similar threats and people with capabilities created by technology instead of word study and the power of the human mind.  You have to look at these things from a risk standpoint.  While yes, these people have the capability to do something of high impact such as kill every human on the face of the earth, the track record of something like this happening is relatively small.  I mean, is there any historical record of a <strong>&lt;censored, I don&#8217;t like being sued by cults&gt;</strong> actually killing anybody through sheer force of their mind?  In other words, this is a very high impact, low probability event&#8211;something some people call a black swan event.  While yes, this is a matter of national security that these people potentially have this capability, we only have so many resources to protect things and we have our hands full dealing with risks that actually have occured in recent history.  In other words, risk management would say that this event you&#8217;re speaking of is an acceptable risk because of more pressing risks.</p>
<p><strong>Crazy Homeless Guy:</strong> (Obviously beaten into oblivion by somebody crazier than himself) Well, I&#8217;ve never thought about it that way.  I&#8217;m really scared by these people.  Hold me, BSOFH.</p>
<p><strong>BSOFH:</strong> Um, how about no?  You&#8217;re a Crazy Homeless Guy after all.  I have to get back to work now.  Come hang out sometime if you want to talk some quantitative risk analysis and we&#8217;ll start attaching dollar figures to the risks of <strong>&lt;censored, I don&#8217;t like being sued by cults&gt;<strong> </strong></strong>killing all of humanity.  Doesn&#8217;t that sound like fun?  If we can get you cleared to get into the building, we can have a couple of whiteboarding sessions to determine the process flow and maybe an 800-30-stylie risk assessment just to present our case to the DHS Psychic Warfare Division.<strong></strong></p>
<p><strong>Crazy Homeless Guy:</strong> Uh, I gotta find a better corner to stand on.  Maybe over by 16th and Pennsylvania I can find somebody more sympathetic to my cause.</p>
<p><strong>BSOFH:</strong> You&#8217;re crazy, man!</p>
<p><strong>Crazy Homeless Guy:</strong> You&#8217;re crazy, too, man!</p>
<p>And the moral of the story is that no matter how crazy you think you are, somebody else will always show up to prove you wrong.  And yeah, black swan events where we all die are dumb to prepare for because we&#8217;ll all be dead&#8211;near total fatalities only matter if you&#8217;re one of the survivors.</p>
<p>This story is dedicated to Alex H, David M, and some guy named Bayes.</p>
<p style="text-align: center;"><em><img class="alignnone" title="Black Swan" src="http://farm4.static.flickr.com/3465/3209135920_0d82f67267.jpg" alt="" width="500" height="326" /></em></p>
<p style="text-align: center;"><em>OMG It&#8217;s a Psychic Black Swan photo by <a title="Link to gnuckx cc0's photostream" rel="dc:creator cc:attributionURL" href="http://www.flickr.com/photos/34409164@N06/"><strong>gnuckx cc0</strong></a>.</em></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1312').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1312" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1312" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1312&amp;title=Risk+Management+and+Crazy+People%2C+a+Script+Using+Stock+Characters" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1312&amp;title=Risk+Management+and+Crazy+People%2C+a+Script+Using+Stock+Characters" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1312" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1312&amp;title=Risk+Management+and+Crazy+People%2C+a+Script+Using+Stock+Characters" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1312&amp;h=Risk+Management+and+Crazy+People%2C+a+Script+Using+Stock+Characters" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1312&amp;title=Risk+Management+and+Crazy+People%2C+a+Script+Using+Stock+Characters" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1312&amp;title=Risk+Management+and+Crazy+People%2C+a+Script+Using+Stock+Characters" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1312&amp;title=Risk+Management+and+Crazy+People%2C+a+Script+Using+Stock+Characters" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1312" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1312" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1312&amp;t=Risk+Management+and+Crazy+People%2C+a+Script+Using+Stock+Characters" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1312').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1312').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=R0yfvatVCgc:4N5pmhyaW0w:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=R0yfvatVCgc:4N5pmhyaW0w:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=R0yfvatVCgc:4N5pmhyaW0w:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/R0yfvatVCgc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1312/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1312</feedburner:origLink></item>
		<item>
		<title>Special Publication 800-53 Revision 3 Workshop</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/wCJN3R4HPjw/1310</link>
		<comments>http://www.guerilla-ciso.com/archives/1310#comments</comments>
		<pubDate>Tue, 01 Sep 2009 12:53:57 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[NIST]]></category>
		<category><![CDATA[800-39]]></category>
		<category><![CDATA[800-53]]></category>
		<category><![CDATA[C&A]]></category>
		<category><![CDATA[catalogofcontrols]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[fisma]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[seminar]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1310</guid>
		<description><![CDATA[My friends at Potomac Forum are having a workshop on SP 800-53 R3 on the 15th of September.  This is an update to the Government&#8217;s catalog of controls.
The workshop will also be about standards convergence: how ODNI, DoD, and NIST are moving towards one standard and what this means for the intelligence community and military.
Ron [...]]]></description>
			<content:encoded><![CDATA[<p>My friends at Potomac Forum are having a workshop on <a href="http://www.potomacforum.org/?view=314" target="_blank">SP 800-53 R3 on the 15th of September</a>.  This is an update to the Government&#8217;s catalog of controls.</p>
<p>The workshop will also be about standards convergence: how ODNI, DoD, and NIST are moving towards one standard and what this means for the intelligence community and military.</p>
<p>Ron Ross from NIST will talk about how the NIST Risk Management Framework is changing from a static, controls-based approach to a more dynamic &#8220;real-time continuous monitoring&#8221;.</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1310').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1310" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1310" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1310&amp;title=Special+Publication+800-53+Revision+3+Workshop" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1310&amp;title=Special+Publication+800-53+Revision+3+Workshop" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1310" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1310&amp;title=Special+Publication+800-53+Revision+3+Workshop" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1310&amp;h=Special+Publication+800-53+Revision+3+Workshop" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1310&amp;title=Special+Publication+800-53+Revision+3+Workshop" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1310&amp;title=Special+Publication+800-53+Revision+3+Workshop" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1310&amp;title=Special+Publication+800-53+Revision+3+Workshop" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1310" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1310" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1310&amp;t=Special+Publication+800-53+Revision+3+Workshop" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1310').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1310').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=wCJN3R4HPjw:uh87jbNX83I:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=wCJN3R4HPjw:uh87jbNX83I:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=wCJN3R4HPjw:uh87jbNX83I:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/wCJN3R4HPjw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1310/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1310</feedburner:origLink></item>
		<item>
		<title>Stress-Test Apache with Intent to Tune: BSOFH Tip for the Software Masochist</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/IjWj9OKH3mY/1299</link>
		<comments>http://www.guerilla-ciso.com/archives/1299#comments</comments>
		<pubDate>Sat, 29 Aug 2009 01:21:09 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[Technical]]></category>
		<category><![CDATA[The Guerilla CISO]]></category>
		<category><![CDATA[What Works]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1299</guid>
		<description><![CDATA[So I&#8217;ve been having some problems with my server for a month or so&#8211;periodically the number of apache servers would skyrocket and the box would get so overloaded (load of ~50 or so) that I couldn&#8217;t even run simple commands on it.  I would have to get into the hardware console and give the box [...]]]></description>
			<content:encoded><![CDATA[<p>So I&#8217;ve been having some problems with my server for a month or so&#8211;periodically the number of apache servers would skyrocket and the box would get so overloaded (load of ~50 or so) that I couldn&#8217;t even run simple commands on it.  I would have to get into the hardware console and give the box a hard boot (a graceful reboot wouldn&#8217;t work).</p>
<p>Root cause is I&#8217;m a dork, but more about that later.</p>
<p>Anyway, I needed a way to troubleshoot and fix it.  The biggest problem I had was that the problem was very sporadic&#8211;sometime it would be 2 weeks between crashes, other times it would be 3 times in one day.  This is so begging for a stress-test really badly.  Looking on the Internet, I found a couple of articles about running a load-tester on apache and information on the tuning settings but not really much about a methodology (yeah yeah I work for a Big 4 firm, the word still makes me shudder even though it&#8217;s the right one to use here) to actually solve the problem of apache tuning.</p>
<p>So the &#8220;materials&#8221; I needed:</p>
<ul>
<li>One server running apache.  Mine runs Apache2 under Debian Stable.  This is a little bit different from the average distro out there in that the process is apache2 and the command is apache2ctl where normally you would have httpd and httpdctl.  If you try this at home, you&#8217;ll need to use the latter commands.</li>
<li>An apache tuning guide or 3.  <a href="http://www.devside.net/articles/apache-performance-tuning" target="_blank">Here&#8217;s the simplest/most straightforward one I&#8217;ve seen</a>.</li>
<li>A stress-tester.  <a href="http://www.joedog.org/index/siege-home" target="_blank">Siege is awesome for this</a>.</li>
<li>Some simple shell commands: <a href="http://htop.sourceforge.net/" target="_blank">htop</a> (top works here too), ps, grep, and wc.</li>
</ul>
<p>Now for the method to my madness&#8230;</p>
<p>I ssh into my server using three different sessions.  On one I run htop.  Htop is a version of top that gives you a colored output and supports multiple processors.  The output without stress-testing looks something like this:</p>
<p style="text-align: center;"><em><a href="http://farm3.static.flickr.com/2575/3865505507_fbb883fa76_o_d.jpg" target="_blank"><img class="aligncenter" title="htop with no load" src="http://farm3.static.flickr.com/2575/3865505507_a9c96edf12_b.jpg" alt="" width="614" height="405" /></a>(Click for a life-size image)</em></p>
<p>I keep one session free to edit files and do an emergency &#8220;killall apache2&#8243; if things get out of hand (and they will really quickly, I had to pull the plug about 20 times throughout this process).   I run a simple command on another ssh session to get a count of how many apache threads I have running:</p>
<blockquote>
<pre>rybolov@server:~$ ps aux | grep apache2 | grep start | wc -l
11</pre>
</blockquote>
<p>OK, so far so good.  I&#8217;ve got 11 threads running with no load and RAM usage of 190MB.  I needed the extra &#8220;grep start&#8221; because it removes the text editor I have open on apache2.conf and anything else I might be doing in the background.</p>
<p>I also killed apache, waited 10 seconds, and looked at the typical RAM use.  With no apache running, I use about 80MB just for the OS and everything else I&#8217;m running.  This means that I&#8217;m using 110MB of RAM for 11 apache threads, which means I&#8217;m using ~10MB of RAM for each apache thread.  Now that&#8217;s something important I can use.</p>
<p>I took my tuning settings in apache2.conf (httpd.conf for most distros) (Apache2 uses the prefork module which uses threads, read the tuning guide for more info) and set them at the defaults listed in the tuning guide.  They became something like the following:</p>
<blockquote>
<pre>&lt;IfModule prefork.c&gt;
  StartServers            8
  MinSpareServers         5
  MaxSpareServers        20
  MaxClients            150
  MaxRequestsPerChild  1000
&lt;/IfModule&gt;</pre>
</blockquote>
<p>Notice how the MaxClients is set at 150?  This will prove to be my downfall later.  Turns out that my server is RAM-poor for as much processor as it has or Wordpress is a RAM hog (or both, which is the case =)  ).  I&#8217;ll eventually upgrade my server, but since it&#8217;s a cloud server from Mosso, I pay by the RAM and drive space.</p>
<p>After each edit of apache2.conf, you need to give apache a configuration test and reload:</p>
<blockquote>
<pre>server:~# apache2ctl configtest
Syntax OK                        &lt;- If something else comes back, fix it!!
server:~# apache2ctl restart</pre>
</blockquote>
<p>I&#8217;m now ready to stress-test using the default setup.  This is the awesome part.  First, I need to simulate a load.  I make an url seedfile so that siege will bounce around between a handful of pages.  I make a file siege.urls.txt and put in a collection of urls so that it looks like the following:</p>
<blockquote>
<pre>http://www.guerilla-ciso.com/
http://www.guerilla-ciso.com/about
http://www.guerilla-ciso.com/contact
http://www.guerilla-ciso.com/papers-and-presentations
....&lt;about 20 lines deleted here, you get the point&gt;
http://www.guerilla-ciso.com/page/2
http://www.guerilla-ciso.com/page/3
http://www.guerilla-ciso.com/page/4</pre>
</blockquote>
<p>I&#8217;m sure there is an efficient and fun way to make this, like say, a text-only sitemap or <a href="http://www.joedog.org/index/sproxy-home" target="_blank">sproxy which is made by the same guy who does siege</a>, but since I only needed about 30 urls, I just cut-n-pasted them off the blog homepage.</p>
<p>I fire up siege and give my webserver a thorough drubbing, running 50 connections for 10 minutes and using my url seedfile.  BTW, I&#8217;m running siege on the webserver itself, so there isn&#8217;t anything in the way of network latency.  <strong><em>&lt;enter sinister laugh of evil as I sadistically torture my apache and the underlying OS&gt;</em></strong></p>
<blockquote>
<pre>server:~# siege -c 50 -t 600s -f siege.urls.txt
** SIEGE 2.66
** Preparing 50 concurrent users for battle.    &lt;-The guy writing siege has a wicked sense of humor.
The server is now under siege...                &lt;-Man the ramparts, Apache, they're coming for you!
HTTP/1.1 200   1.08 secs:   16416 bytes ==&gt; /
HTTP/1.1 200   1.07 secs:   16416 bytes ==&gt; /
....&lt;about 2 bazillion lines deleted here, you get the idea&gt;
HTTP/1.1 200   4.66 secs:    8748 bytes ==&gt; /about
HTTP/1.1 200   3.92 secs:    8748 bytes ==&gt; /about
Lifting the server siege...      done.

Transactions:                  61 hits   &lt;-No, this isn't actual, I abbreviated the siege output
Availability:              100.00 %      &lt;-with a ctrl-c just to get some results so I didn't
Elapsed time:                6.70 secs   &lt;-have to scroll through all that output from the real test.
Data transferred:            0.87 MB
Response time:                3.27 secs
Transaction rate:            9.10 trans/sec
Throughput:                0.13 MB/sec
Concurrency:               29.75
Successful transactions:          61
Failed transactions:               0
Longest transaction:            5.61
Shortest transaction:            1.07</pre>
</blockquote>
<p>Now I watch the output of htop.  Under stress, the output looks something like this:</p>
<p style="text-align: center;"><a href="http://farm4.static.flickr.com/3437/3866289738_10caa3d970_o_d.jpg" target="_blank"><img class="alignnone" title="htop under a load" src="http://farm4.static.flickr.com/3437/3866289738_10caa3d970_o.jpg" alt="" width="458" height="332" /></a></p>
<p style="text-align: center;">(Click for a life-size image)</p>
<p>Hmm, looks like I have a ton of apache threads soaking up all my RAM.  What happens is that in about 30 seconds, the OS starts swapping and the swap use just keeps growing until the OS is unresponsive.  This is a very interesting cascade failure because writing to swap incurs a load which makes the OS write to swap more.  Maybe I need to limit either the amount of RAM used per apache or limit the maximum amount of threads that apache spawns.  The tuning guide tells us how&#8230;</p>
<p>There is one setting that is the most important in tuning apache, it&#8217;s MaxClients.  This is the maximum number of servers (with the worker module) or threads (prefork module).  Looking at my apache tuning guide, I get a wonderful formula: ($SizeOfTotalRAM &#8211; $SizeOfRAMForOS) / $RAMUsePerThread = MaxClients.  So in my case, (512 &#8211; 80) / 11 = 39.something.  Oops, this is a far cry from the 150 that comes as default.  I also know that the RAM/thread number I used was without any load on apache, so with a load on and generating dynamic content (aka Wordpress) , I&#8217;ll probably use ~15MB per thread.</p>
<p>One other trick that I can use:  Since I think that what&#8217;s killing me is the number of apache threads, I can run with a reduced amount of simultaneous connections and watch htop.  When htop shows that I&#8217;ve just started to write to swap, I can run my ps command to find out how many apache threads I have running.</p>
<blockquote>
<pre>rybolov@server:~$ ps aux | grep apache2 | grep start | wc -l
28</pre>
</blockquote>
<p>Now this is about what I expected:  With 28 threads going, I tipped over into using swap.  Reversing my tuning formula, I get (28 threads x 15 MB/thread) +80 MB for OS = 500 MB used.  Hmm, this makes much sense to me, since the OS starts swapping when you use ~480MB of RAM.</p>
<p>So I go back to my prefork module tuning.</p>
<blockquote>
<pre>&lt;IfModule mpm_prefork_module&gt;
 StartServers          8
 MinSpareServers       5
 MaxSpareServers      10
 MaxClients           25
 MaxRequestsPerChild   2000
&lt;/IfModule&gt;</pre>
</blockquote>
<p>I set MaxClients at 25 because 28 seems to be the tipping point, so that gives me a little bit of &#8220;wiggle room&#8221; in case something else happens at the same time I&#8217;m serving under a huge load.  I also tweaked some of the other settings slightly.</p>
<p>Then it&#8217;s time for another siege torture session.  I run the same command as above and watch the htop output.  With the tuning settings I have now, the server dips into swap about 120MB and survives the full 10 minutes.  I&#8217;m sure the performance is degraded somewhat by going into swap, but I&#8217;m happy with it for now because the server stays alive.  It wasn&#8217;t all <em>that</em> smooth, I had to do a little bit of trial and error first, starting with MaxClients 25 and working my way up to 35 under a reduce siege load (-c 25 -t 60s) to see what would happen, then increasing the load from siege (-c50 -t 600s) and ratcheting MaxClients back down to 25.</p>
<p>And as far as me being a dork&#8230; well, aside from the huge MaxClients setting (That&#8217;s the default, don&#8217;t blame me), I set MaxRequestsPerChild to 100 instead of 1000, meaning that every 100 http requests I was rolling over and making a new thread.  That would lead to cascade failure under a load. (duh!)</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1299').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1299" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1299" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1299&amp;title=Stress-Test+Apache+with+Intent+to+Tune%3A+BSOFH+Tip+for+the+Software+Masochist" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1299&amp;title=Stress-Test+Apache+with+Intent+to+Tune%3A+BSOFH+Tip+for+the+Software+Masochist" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1299" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1299&amp;title=Stress-Test+Apache+with+Intent+to+Tune%3A+BSOFH+Tip+for+the+Software+Masochist" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1299&amp;h=Stress-Test+Apache+with+Intent+to+Tune%3A+BSOFH+Tip+for+the+Software+Masochist" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1299&amp;title=Stress-Test+Apache+with+Intent+to+Tune%3A+BSOFH+Tip+for+the+Software+Masochist" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1299&amp;title=Stress-Test+Apache+with+Intent+to+Tune%3A+BSOFH+Tip+for+the+Software+Masochist" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1299&amp;title=Stress-Test+Apache+with+Intent+to+Tune%3A+BSOFH+Tip+for+the+Software+Masochist" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1299" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1299" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1299&amp;t=Stress-Test+Apache+with+Intent+to+Tune%3A+BSOFH+Tip+for+the+Software+Masochist" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1299').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1299').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=IjWj9OKH3mY:keVr8iBRI4s:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=IjWj9OKH3mY:keVr8iBRI4s:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=IjWj9OKH3mY:keVr8iBRI4s:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/IjWj9OKH3mY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1299/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1299</feedburner:origLink></item>
		<item>
		<title>OMB Wants a Direct Report</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/8bLMv9TIEuA/1288</link>
		<comments>http://www.guerilla-ciso.com/archives/1288#comments</comments>
		<pubDate>Fri, 28 Aug 2009 15:39:20 +0000</pubDate>
		<dc:creator>DanPhilpott</dc:creator>
				<category><![CDATA[FISMA]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[Public Policy]]></category>
		<category><![CDATA[auditor]]></category>
		<category><![CDATA[catalogofcontrols]]></category>
		<category><![CDATA[certification]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[fisma]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[infosharing]]></category>
		<category><![CDATA[itsatrap]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[omb]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1288</guid>
		<description><![CDATA[A quick review of changes in OMB's FY 2009 Reporting Instructions for FISMA and Agency Privacy Management and some irreverent speculation for good measure.]]></description>
			<content:encoded><![CDATA[<p>The big news in OMB&#8217;s <a href="http://www.whitehouse.gov/omb/asset.aspx?AssetId=1698" target="_blank">M-09-29 FY 2009 Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Management</a> is that instead of fiddling with document files reporting will now be done directly through an online tool. This has been <a href="http://www.govinfosecurity.com/articles.php?art_id=1727" target="_blank">covered</a> <a href="http://www.nextgov.com/nextgov/ng_20090824_1492.php" target="_blank">elsewhere</a> and it is the one big change since last year.  However having less paper in the paperwork is not the only change.</p>
<p style="text-align: center"><em><img class="alignnone" src="http://farm3.static.flickr.com/2061/1783247600_c5db9b0abf.jpg" alt="" width="500" height="375" /></em></p>
<p style="text-align: center"><em>Piles of Paper photo by <a title="Link to °Florian's photostream" rel="dc:creator cc:attributionURL" href="http://www.flickr.com/photos/fboyd/"><strong>°Florian</strong></a>.</em></p>
<p>So what will this tool be like? It is hard to tell at this point. Some information will be entered directly but the system appears designed to accept uploads of some documents, such as those supporting M-07-16. Similar to the spreadsheets used for FY 2008 there will be separate questions for the Chief Information Officer, Inspector General and Senior Agency Official for Privacy. Microagencies will still have abbreviated questions to fill out. Additional information on the automated tool, including full instructions and a beta version will be available in August, 2009.<br />
<img src="/Users/DAN%7E1.SYS/AppData/Local/Temp/moz-screenshot.png" alt="" /><br />
Given the required information has changed very little the automated system is unlikely to significantly ease the reporting burden. This system appears primarily designed to ease the data processing requirements for OMB. With Excel spreadsheets no longer holding data many concerns relating to file versions, data aggregation and analysis are greatly eased.</p>
<p>It is worth noting that a common outcome of systems re-engineered to become more efficient is that managers look to find ways to utilize the new efficiency. What does this mean? Now that OMB has the ability to easily analyze data which took a great amount of effort to process before they may want to improve what is reported. A great deal has been said over the years about the inefficiencies in the current reporting regime. This may be OMB&#8217;s opportunity to start collecting an increased amount of information that may better reflect agencies actual security posture. This is pure speculation and other factors may moderate OMB&#8217;s next steps, such as the reporting burden on agencies, but it is worth consideration.</p>
<p>One pleasant outcome to the implementation of this new automated tool is the reporting deadline has been pushed back to November 18, 2009.</p>
<p>Agencies are still responsible for submitting document files to satisfy M-07-16. The automated tool does not appear to allow direct input of this information. However the document requirements are slightly different. Breach notification policy document need only be submitted if it has changed. It is no longer sufficient to simply report progress on eliminating SSNs and reducing PII, an implementation plan and a progress update must be submitted. The requirement for a policy document covering rules of behavior and consequences has been removed.</p>
<p>In addition to the automated tool there are other, more subtle changes to OMB&#8217;s FY 2009 reporting. Let&#8217;s step through them, point by point:</p>
<p style="padding-left: 30px">10. It is reiterated that NIST guidance is required. This point has been expanded to state that legacy systems, agencies have one year to come into compliance with NIST documents new material. For new systems agencies are expected to be in compliance upon system deployment.</p>
<p style="padding-left: 30px">13 &amp; 15. Wording indicating that disagreements on reports should be resolved prior to submission and that the agency head&#8217;s view will be authoritative have been removed. This may have been done to reduce redundancy as M-09-29&#8217;s preface indicates agency reports must reflect the agency head&#8217;s view.</p>
<p style="padding-left: 30px">52. The requirement for an central web page with working links to agency PIAs and Federal Register published SORNs has been removed.</p>
<p>A complete side-by-side comparison of changes between the two documents is available at <a href="http://fismapedia.org/index.php?title=M-08-21_M-09-23_Comparison" target="_blank">FISMApedia.org</a>.</p>
<p>All in all the changes to OMB&#8217;s guidance this year will not change agencies reporting burden significantly. And that may not be a bad thing.</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1288').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1288" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1288" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1288&amp;title=OMB+Wants+a+Direct+Report" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1288&amp;title=OMB+Wants+a+Direct+Report" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1288" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1288&amp;title=OMB+Wants+a+Direct+Report" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1288&amp;h=OMB+Wants+a+Direct+Report" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1288&amp;title=OMB+Wants+a+Direct+Report" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1288&amp;title=OMB+Wants+a+Direct+Report" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1288&amp;title=OMB+Wants+a+Direct+Report" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1288" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1288" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1288&amp;t=OMB+Wants+a+Direct+Report" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1288').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1288').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=8bLMv9TIEuA:4wq1IjIDKUk:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=8bLMv9TIEuA:4wq1IjIDKUk:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=8bLMv9TIEuA:4wq1IjIDKUk:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/8bLMv9TIEuA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1288/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1288</feedburner:origLink></item>
		<item>
		<title>Note to the Data People: Give us Some Raw InfoSec Data</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/c-4EBMOrABw/1281</link>
		<comments>http://www.guerilla-ciso.com/archives/1281#comments</comments>
		<pubDate>Tue, 25 Aug 2009 03:07:59 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[Public Policy]]></category>
		<category><![CDATA[datadotgov]]></category>
		<category><![CDATA[fisma]]></category>
		<category><![CDATA[infosharing]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[metrics]]></category>
		<category><![CDATA[omb]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1281</guid>
		<description><![CDATA[We have all these data wonks running around now in the information security field thanks to a couple of people (Jaquith, Shostack, Stewart, and our friends at Verizon Business) who brought us some books and some data.
Well, earlier this year, the Government started a website called Data.gov.  This is much awesomeness, Viva Las Transpareny!  However, [...]]]></description>
			<content:encoded><![CDATA[<p>We have all these data wonks running around now in the information security field thanks to a couple of people (Jaquith, Shostack, Stewart, and our friends at Verizon Business) who brought us some books and some data.</p>
<p>Well, earlier this year, the Government started a website called <a href="http://www.data.gov/" target="_blank">Data.gov</a>.  This is much awesomeness, Viva Las Transpareny!  However, it&#8217;s missing something very relevant to my interests: information security management data.</p>
<p>So, I want people to go to <a href="http://www.data.gov/suggestdataset" target="_blank">data.gov&#8217;s &#8220;request a dataset&#8221; page</a> and request the following:</p>
<p style="padding-left: 30px;"><em>Complete responses from the Departments and Agencies to the FISMA reporting requirements for FY2004-2009 based on OMB Memoranda 04-25, 05-15, 06-20, 07-19, 08-21, and 09-29.</em></p>
<p style="padding-left: 30px;"><em>Raw incident data for years 2005-2007 as reported to OMB and summarized in their report to Congress on FY2007 FISMA performance and published at http://www.whitehouse.gov/omb/inforeg/reports/2007_fisma_report.pdf</em></p>
<p style="padding-left: 30px;"><em>Raw incident data for years 2007 and later in any type and format similar to the Verizon Data Breach Incident Report available at </em>http://www.verizonbusiness.com/resources/security/reports/2009_databreach_rp.pdf</p>
<p style="padding-left: 30px;"><em>This information is necessary for researchers to study the effectiveness of information security management techniques and regulatory schemes and for industry to propose changes to national-level information security management frameworks and legislation such as FISMA.  This information for the most part has been released in a summary format to Congress and the release of the complete dataset on data.gov would greatly aid the information security community.<br />
</em></p>
<p>It might be a fool&#8217;s errand at this point, but it doesn&#8217;t hurt to ask, and it only takes a couple of minutes to do.  =)</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1281').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1281" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1281" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1281&amp;title=Note+to+the+Data+People%3A+Give+us+Some+Raw+InfoSec+Data" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1281&amp;title=Note+to+the+Data+People%3A+Give+us+Some+Raw+InfoSec+Data" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1281" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1281&amp;title=Note+to+the+Data+People%3A+Give+us+Some+Raw+InfoSec+Data" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1281&amp;h=Note+to+the+Data+People%3A+Give+us+Some+Raw+InfoSec+Data" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1281&amp;title=Note+to+the+Data+People%3A+Give+us+Some+Raw+InfoSec+Data" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1281&amp;title=Note+to+the+Data+People%3A+Give+us+Some+Raw+InfoSec+Data" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1281&amp;title=Note+to+the+Data+People%3A+Give+us+Some+Raw+InfoSec+Data" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1281" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1281" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1281&amp;t=Note+to+the+Data+People%3A+Give+us+Some+Raw+InfoSec+Data" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1281').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1281').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=c-4EBMOrABw:hYjqVJIJPI4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=c-4EBMOrABw:hYjqVJIJPI4:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=c-4EBMOrABw:hYjqVJIJPI4:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/c-4EBMOrABw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1281/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1281</feedburner:origLink></item>
		<item>
		<title>A Layered Model for Massively-Scaled Security Management</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/rlZI7YQWgio/1274</link>
		<comments>http://www.guerilla-ciso.com/archives/1274#comments</comments>
		<pubDate>Tue, 25 Aug 2009 02:13:51 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[Public Policy]]></category>
		<category><![CDATA[categorization]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[Cyberwar]]></category>
		<category><![CDATA[dhs]]></category>
		<category><![CDATA[fisma]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[infosharing]]></category>
		<category><![CDATA[law]]></category>
		<category><![CDATA[legislation]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[publicpolicy]]></category>
		<category><![CDATA[scalability]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1274</guid>
		<description><![CDATA[So we all know the OSI model by heart, right?   Well, I&#8217;m offering up my model of technology management.  Really at this stage I&#8217;m looking for feedback

Layer 7: Global Layer. This layer is regulated by treaties with other nation-states or international standards.  I fit cybercrime treaties in here along with the RFCs that make [...]]]></description>
			<content:encoded><![CDATA[<p>So we all know the OSI model by heart, right?   Well, I&#8217;m offering up my model of technology management.  Really at this stage I&#8217;m looking for feedback</p>
<ul>
<li><strong>Layer 7: Global Layer.</strong> This layer is regulated by treaties with other nation-states or international standards.  I fit cybercrime treaties in here along with the RFCs that make the Internet work.  Problem is that security hasn&#8217;t really reached much to this level unless you want to consider multinational vendors and top-level cert coordination centers like CERT-CC.</li>
<li><strong>Layer 6: National-Level Layer.</strong> This layer is an aggregation of Federations and industries and primarily consists of Federal law and everything lumped into a &#8220;critical infrastructure&#8221; bucket.  Most US Federal laws fit into this layer.</li>
<li><strong>Layer 5: Federation/Community Layer.</strong> What I&#8217;m talking here with this layer is an industry federated or formed in some sort of community.  Think major verticals such as energy supply.  It&#8217;s not a coincidence that this layer lines up with DHS&#8217;s <a href="http://www.dhs.gov/files/programs/gc_1179866197607.shtm" target="_blank">critical infrastructure and key resources breakdown</a> but it can also refer to self-regulated industries such as the function of PCI-DSS or NERC.</li>
<li><strong>Layer 4: Enterprise Layer.</strong> Most security thought, products, and tools are focused on this layer and the layers below.  This is the realm of the CSO and CISO and roughly equates to a large corporation.</li>
<li><strong>Layer 3: Project Layer.</strong> Collecting disparate technologies and data into a similar piece such as the LAN/WAN, a web application project, etc.  In the Government world, this is the location for the Information System Security Officer (ISSO) or the System Security Engineer (SSE).</li>
<li><strong>Layer 2: Integration Layer.</strong> Hardware, software, and firmware combine to become products and solutions and is focused primarily on engineering.</li>
<li><strong>Layer 1: Code Layer.</strong> Down into the code that makes everything work.  This is where the application security people live.</li>
</ul>
<p>There are tons of way to use the model.I&#8217;m thinking each layer has a set of characteristics like the following:</p>
<ul>
<li>Scope</li>
<li>Level of centralization</li>
<li>Responsiveness</li>
<li>Domain expertise</li>
<li>Authority</li>
<li>Timeliness</li>
<li>Stakeholders</li>
<li>Regulatory bodies</li>
<li>Many more that I haven&#8217;t thought about yet</li>
</ul>
<p style="text-align: center;"><em><img class="alignnone" title="Layer Cake" src="http://farm1.static.flickr.com/186/441186475_df072a1749.jpg" alt="" width="500" height="375" /></em></p>
<p style="text-align: center;"><em>Chocolate Layer Cake photo by <a title="Link to foooooey's photostream" rel="dc:creator cc:attributionURL" href="http://www.flickr.com/photos/fooey/"><strong>foooooey</strong></a>.</em></p>
<p>My whole point for this model is that I&#8217;m going to try to use it to describe the levels at which a particular problem resides at and to stimulate discussion on what is the appropriate level at which to solve it.  For instance, take a technology and you can trace it up and down the stack.  Say Security Event and Incident Monitoring:</p>
<ul>
<li><strong>Layer 7: Global Layer.</strong> Coordination between national-level CERTs in stopping malware and hacking attacks.</li>
<li><strong>Layer 6: National-Level Layer. </strong> Attack data from Layer 5 is aggregated and correlated to respond to large incidents on the scale of Cyberwar.</li>
<li><strong>Layer 5: Federation/Community Layer.</strong> Events are filtered from Layer 4 and only the confirmed events or interest are correlated to determine trends.</li>
<li><strong>Layer 4: Enterprise Layer.</strong> Events are aggregated by a SIEM with events of interest flagged for response.</li>
<li><strong>Layer 3: Project Layer.</strong> Logs are analyzed in some manner.  This is most likely the highest in the model that we</li>
<li><strong>Layer 2: Integration Layer.</strong> Event logs have to be written to disk and stored for a period of time.</li>
<li><strong>Layer 1: Code Layer.</strong> Code has to be programmed to create event logs.</li>
</ul>
<p>I do have an ulterior motive.  I created this model because most of our security thought, doctrine, tools, products, and solutions work at Layer 4 and below.  What we need is discussion on Layers 5 and above because when we try to create massively-scaled security solutions, we start to run into a drought of information at what to do above the Enterprise.  There are other bits of doctrine that I want to bring up, like trying to solve any problem at the lowest level for which it makes sense.  So in other words, we can use the model to propose changes to the way we manage security&#8230; say we have a problem like the lack of data on data breaches.  What we&#8217;re saying when we say that we need a Federal data breach law is that because of the scope and the amount of responsibility and competing interests at Layer 5, that we need a solution at Layer 6, but in any case we should start at the bottom and work our way up the model until we find an adequate scope and scale.</p>
<p>So, this is my question to you, Internet: have I just reinvented enterprise public policy, IT architecture (Federal Enterprise Architecture) and business blueprinting, or did I create some kind of derivative view of technology, security, and public policy that I can now use?</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1274').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1274" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1274" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1274&amp;title=A+Layered+Model+for+Massively-Scaled+Security+Management" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1274&amp;title=A+Layered+Model+for+Massively-Scaled+Security+Management" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1274" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1274&amp;title=A+Layered+Model+for+Massively-Scaled+Security+Management" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1274&amp;h=A+Layered+Model+for+Massively-Scaled+Security+Management" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1274&amp;title=A+Layered+Model+for+Massively-Scaled+Security+Management" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1274&amp;title=A+Layered+Model+for+Massively-Scaled+Security+Management" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1274&amp;title=A+Layered+Model+for+Massively-Scaled+Security+Management" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1274" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1274" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1274&amp;t=A+Layered+Model+for+Massively-Scaled+Security+Management" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1274').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1274').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=rlZI7YQWgio:SX1QpV5OC0w:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=rlZI7YQWgio:SX1QpV5OC0w:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=rlZI7YQWgio:SX1QpV5OC0w:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/rlZI7YQWgio" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1274/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1274</feedburner:origLink></item>
		<item>
		<title>Save a Kitten, Write SCAP Content</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/lBWPR4wJAlg/1221</link>
		<comments>http://www.guerilla-ciso.com/archives/1221#comments</comments>
		<pubDate>Fri, 07 Aug 2009 21:32:17 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[NIST]]></category>
		<category><![CDATA[Speaking]]></category>
		<category><![CDATA[Technical]]></category>
		<category><![CDATA[scalability]]></category>
		<category><![CDATA[scap]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[speaking]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1221</guid>
		<description><![CDATA[Apparently I&#8217;m the Internet&#8217;s SCAP Evangelist according to Ed Bellis, so at this point all I can do is shrug and say &#8220;OK, I&#8217;ll teach people about SCAP&#8221;.
Right now there is a &#8220;pretty OK&#8221; framework for SCAP.  IE, we have published standards, and there are some SCAP-certified tools out there to do patch and vulnerability [...]]]></description>
			<content:encoded><![CDATA[<p>Apparently I&#8217;m the Internet&#8217;s SCAP Evangelist according to Ed Bellis, so at this point all I can do is shrug and say &#8220;OK, I&#8217;ll teach people about SCAP&#8221;.</p>
<p>Right now there is a &#8220;pretty OK&#8221; framework for SCAP.  IE, we have published standards, and there are some SCAP-certified tools out there to do patch and vulnerability management.</p>
<p>What&#8217;s missing right now is SCAP content.  I don&#8217;t think this is going to get solved en-masse, it&#8217;s more like there needs to be an awareness campaign directed at end-users, vulnerability researchers, and people who write small-ish tools.</p>
<p>So I sat around at home trying to figure out how to get people to use/write more SCAP content and finally settled on &#8220;Everytime you use SCAP content, a kitten runs free&#8221;.</p>
<p>Anyway, this is a presentation I gave at my local OWASP chapter.</p>
<div align="center">
<div style="width:425px;text-align:left" id="__ss_1828884"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/rybolov/security-content-automation-protocol-and-web-application-security" title="Security Content Automation Protocol and Web Application Security">Security Content Automation Protocol and Web Application Security</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=owaspdcscap08-05-09-090807152921-phpapp02&#038;stripped_title=security-content-automation-protocol-and-web-application-security" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=owaspdcscap08-05-09-090807152921-phpapp02&#038;stripped_title=security-content-automation-protocol-and-web-application-security" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object>
<div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/rybolov">Michael Smith</a>.</div>
</div>
</div>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1221').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1221" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1221" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1221&amp;title=Save+a+Kitten%2C+Write+SCAP+Content" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1221&amp;title=Save+a+Kitten%2C+Write+SCAP+Content" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1221" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1221&amp;title=Save+a+Kitten%2C+Write+SCAP+Content" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1221&amp;h=Save+a+Kitten%2C+Write+SCAP+Content" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1221&amp;title=Save+a+Kitten%2C+Write+SCAP+Content" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1221&amp;title=Save+a+Kitten%2C+Write+SCAP+Content" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1221&amp;title=Save+a+Kitten%2C+Write+SCAP+Content" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1221" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1221" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1221&amp;t=Save+a+Kitten%2C+Write+SCAP+Content" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1221').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1221').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=lBWPR4wJAlg:CbZKHekgFnM:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=lBWPR4wJAlg:CbZKHekgFnM:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=lBWPR4wJAlg:CbZKHekgFnM:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/lBWPR4wJAlg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1221/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1221</feedburner:origLink></item>
		<item>
		<title>Random Thoughts on “The FISMA Challenge” in eHealthcare</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/j_LkFHDHHpY/1163</link>
		<comments>http://www.guerilla-ciso.com/archives/1163#comments</comments>
		<pubDate>Tue, 04 Aug 2009 14:09:42 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[FISMA]]></category>
		<category><![CDATA[Rants]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[FUD]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[infosharing]]></category>
		<category><![CDATA[itsatrap]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[omb]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1163</guid>
		<description><![CDATA[OK, so there&#8217;s this article being bounced all over the place.  Basic synopsis is that FISMA is keeping the government from doing any kind of electronic health records stuff because FISMA requirements extend to health care providers and researchers when they take data from the Government.
Read one version of the story here
So the whole solution [...]]]></description>
			<content:encoded><![CDATA[<p>OK, so there&#8217;s this article being bounced all over the place.  Basic synopsis is that FISMA is keeping the government from doing any kind of electronic health records stuff because FISMA requirements extend to health care providers and researchers when they take data from the Government.</p>
<p><a href="http://www.govhealthit.com/Article.aspx?id=71739" target="_blank">Read one version of the story here</a></p>
<p>So the whole solution is that, well, we can&#8217;t extend FISMA to eHealthcare when the data is owned by the Government because that security management stuff gets in the way.  And this post is about why they&#8217;re wrong and right, but not in the places that they think they are.</p>
<p>Government agencies need to protect the data that they have by providing &#8220;adequate security&#8221;.  <a href="http://www.guerilla-ciso.com/archives/559">I&#8217;ve covered this a bazillion places already.</a> Somewhere somehow along the lines we let the definition of adequate security mean &#8220;You have to play by our rulebook&#8221; which is complete and utter bunk.  The framework is an expedient and a level-setting experience across the government.  It&#8217;s not made to be one-size-fits-all, but is instead meant to be tailored to each individual case.</p>
<p>The <a href="http://www.guerilla-ciso.com/index.php?s=trickle-down">Government Information Security Trickle-Down Effect</a> is a name I use for FISMA/NIST Framework requirements being transferred from the Government to service providers, whether they&#8217;re in healthcare or IT or making screws that sometimes can be used on the B2 bombers.  It will hit you if you take Government data but only because you have no regulatory framework of your own with which you can demonstrate that you have &#8220;adequate security&#8221;.  In other words, if you provide a demonstrable level of data protection equal to or superior to what the Government provides, then you should reasonably be able to take the Government data, it&#8217;s finding the right &#8220;esperanto&#8221; to demonstrate your security foo.</p>
<p>If only there was a regulatory scheme already in place that we could use to hold the healthcare industry to.  Oh wait, there is: HIPAA.  Granted, HIPAA doesn&#8217;t really have a lot of teeth and its effects are maybe demonstrable, but it does fill most of the legal requirement to provide &#8220;adequate security&#8221;, and that&#8217;s what&#8217;s the important thing, and more importantly, what is required by FISMA.</p>
<p>And this is my problem with this whole string of articles:  The power vacuum has claimed eHealthcare.  Seriously, there should be somebody who is in charge of the data who can make a decision on what kinds of protections that they want for it.  In this case, there are plenty of people with different ideas on what that level of protection is so they are asking OMB for an official ruling.  If you go to OMB asking for their guidance on applying FISMA to eHealthcare records, you get what you deserve, which is a &#8220;Yes, it&#8217;s in scope, how do you think you should do this?&#8221;</p>
<p>So what the eHealthcare people really are looking for is a set of firm requirements from their handlers (aka OMB) on how to hold service providers accountable for the data that they are giving them.  This isn&#8217;t a binary question on whether FISMA applies to eHealthcare data (yes, it does), it&#8217;s a question of &#8220;how much is enough?&#8221; or even &#8220;what level of compensating controls do we need?&#8221;</p>
<p>But then again, we&#8217;re beaten down by compliance at this point.  I know I feel it from time to time.  After you&#8217;ve been beaten badly for years, all you want to do is for the batterer to tell you what you need to do so the hurting will stop.</p>
<p>So for the eHealthcare agencies, here is a solution for you.  In your agreements/contracts to provide data to the healthcare providers, require the following:</p>
<ul>
<li>Provider shall produde annual statements for HIPAA compliance</li>
<li>Provider shall be certified under a security management program such as an  ISO 27001, SAS-70 Type II, or even PCI-DSS</li>
<li>Provider shall report any incident resulting in a potential data breach of 500 or more records within 24 hours</li>
<li>Financial penalties for data breaches based on number of records</li>
<li>Provider shall allow the Government to perform risk assessments of their data protection controls</li>
</ul>
<p>That should be enough compensating controls to provide &#8220;adequate security&#8221; for your eHealthcare data.  You can even put a line through some of these that are too draconian or high-cost.  Take that to OMB and tell them how you&#8217;re doing it and how they would like to spend the taxpayers&#8217; money to do anything other than this.</p>
<p style="text-align: center;"><em><img class="alignnone" title="Case Files" src="http://farm4.static.flickr.com/3585/3453105624_8a3807ba11.jpg" alt="" width="500" height="375" /></em></p>
<p style="text-align: center;"><em>Case Files and Medical Records photo by <a title="Link to benuski's photostream" rel="dc:creator cc:attributionURL" href="http://www.flickr.com/photos/benuski/"><strong>benuski</strong></a>.</em></p>
<p><strong> </strong></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1163').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1163" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1163" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1163&amp;title=Random+Thoughts+on+%26%238220%3BThe+FISMA+Challenge%26%238221%3B+in+eHealthcare" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1163&amp;title=Random+Thoughts+on+%26%238220%3BThe+FISMA+Challenge%26%238221%3B+in+eHealthcare" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1163" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1163&amp;title=Random+Thoughts+on+%26%238220%3BThe+FISMA+Challenge%26%238221%3B+in+eHealthcare" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1163&amp;h=Random+Thoughts+on+%26%238220%3BThe+FISMA+Challenge%26%238221%3B+in+eHealthcare" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1163&amp;title=Random+Thoughts+on+%26%238220%3BThe+FISMA+Challenge%26%238221%3B+in+eHealthcare" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1163&amp;title=Random+Thoughts+on+%26%238220%3BThe+FISMA+Challenge%26%238221%3B+in+eHealthcare" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1163&amp;title=Random+Thoughts+on+%26%238220%3BThe+FISMA+Challenge%26%238221%3B+in+eHealthcare" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1163" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1163" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1163&amp;t=Random+Thoughts+on+%26%238220%3BThe+FISMA+Challenge%26%238221%3B+in+eHealthcare" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1163').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1163').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=j_LkFHDHHpY:boSJ0ZfAJ-U:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=j_LkFHDHHpY:boSJ0ZfAJ-U:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=j_LkFHDHHpY:boSJ0ZfAJ-U:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/j_LkFHDHHpY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1163/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1163</feedburner:origLink></item>
		<item>
		<title>Help Wanted</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/gU3GovQI2iM/1259</link>
		<comments>http://www.guerilla-ciso.com/archives/1259#comments</comments>
		<pubDate>Tue, 04 Aug 2009 13:14:26 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[Cyberwar]]></category>
		<category><![CDATA[Public Policy]]></category>
		<category><![CDATA[Rants]]></category>
		<category><![CDATA[What Doesn't Work]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[itsatrap]]></category>
		<category><![CDATA[law]]></category>
		<category><![CDATA[legislation]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1259</guid>
		<description><![CDATA[So let me give you a hypothetical job:

You have to give up your high-paying private-sector job to be a Government employee
You have tons of responsibility
You have no real authority
You have no dedicated budget
You have no staffers
The job has had half a dozen people filling it in the last 7 years
The job has been open longer [...]]]></description>
			<content:encoded><![CDATA[<p>So let me give you a hypothetical job:</p>
<ul>
<li>You have to give up your high-paying private-sector job to be a Government employee</li>
<li>You have tons of responsibility</li>
<li>You have no real authority</li>
<li>You have no dedicated budget</li>
<li>You have no staffers</li>
<li>The job has had half a dozen people filling it in the last 7 years</li>
<li>The job has been open longer than it&#8217;s been staffed over the past 7 years</li>
</ul>
<p>And yet this is what we&#8217;re asking candidates to do in order to even be a candidate for the Cybersecurity Coordinator.  Yes, this is the exact same problem that all CISOs have with having a huge helping of responsibility and none of the authority to get things done, only we scaled it up and out to a national-level CISO position.</p>
<p>Somebody&#8217;s even gone as far to say that the lack of candidates for the job is the <a href="http://blog.triumfant.com/2009/08/03/it-is-august-and-the-white-house-has-thrown-out-more-first-pitches-than-cyber-czar-nominees/" target="_blank">security field&#8217;s way of sending the message that you didn&#8217;t scope the job right</a>.  I think this opinion has much merit.  CISOs being what they are, they&#8217;re usually pretty astute at walking into an ambush, and this job has all the makings of a good one.</p>
<p>I&#8217;ll even turn it around the other way and say that the security industry has yet to produce a CISO&#8217;s CISO&#8211;somebody who can do politics, budget, security, IT, and consensus-building all in one person.  We have lots of people who can manage the enterprise and below, but it&#8217;s that additional little bit of political intrigue that is what we&#8217;re missing.  Security people usually avoid politics like the bubonic plague because we&#8217;re an industry full of people who say it like it really is.  This is a detriment in sales and politics.</p>
<p>So in true Guerilla-CISO fashion of not pointing out problems without offering something as a fix (no matter how much of a strawman arguement it really is), this is what we need to do to get people interested in being the Cybersecurity Czar^wCoordinator:</p>
<ul>
<li>A really well-defined scope.  One person cannot do everything that we are asking for at this price (or any price for that matter).</li>
<li>A budget for an operating staff where the number is more than than 8 digits.</li>
<li>Statutory authority over the various departments and agencies responsible for cybersecurity: NCSD, S&amp;T, DoJ, FBI, Commerce.  Indirect influence doesn&#8217;t work here, never has.</li>
<li>The direct ear of the President.  Councils are OK, but puhlease, you want to get the job done, this is what it will take.</li>
</ul>
<p>Then I read back through my list and realized that we really do need a law to create the Cybersecurity Czar position with everything that I just mentioned.  But here&#8217;s the rub: legislation is slow, the bills to make the Cybersecurity Czar aren&#8217;t even going to be looked at until the next congressional session because we&#8217;re still trying to figure out the budget for last year.</p>
<p>I also think that what we&#8217;re calling the Cybersecurity Czar is really 2 jobs.  You need somebody working for the Government CIO Vivek Kundra as the executive-branch CISO and you need a more senior person who worries about the military-industrial base, the critical infrastructure, the support to American commerce, and the protection of little old grandmas who represent the end-users.</p>
<p style="text-align: center;"><em><img class="alignnone" title="Tsars Cannon" src="http://farm2.static.flickr.com/1312/737126718_80250de9d1.jpg" alt="" width="500" height="333" /></em></p>
<p style="text-align: center;"><em>Tsar&#8217;s Cannon photo by <a title="Link to Siyad Ma's photostream" rel="dc:creator cc:attributionURL" href="http://www.flickr.com/photos/siyad/"><strong>Siyad Ma</strong></a>.  Now that&#8217;s some teeth for the position.</em></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1259').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1259" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1259" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1259&amp;title=Help+Wanted" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1259&amp;title=Help+Wanted" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1259" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1259&amp;title=Help+Wanted" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1259&amp;h=Help+Wanted" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1259&amp;title=Help+Wanted" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1259&amp;title=Help+Wanted" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1259&amp;title=Help+Wanted" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1259" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1259" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1259&amp;t=Help+Wanted" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1259').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1259').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=gU3GovQI2iM:eB6l26EWlTw:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=gU3GovQI2iM:eB6l26EWlTw:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=gU3GovQI2iM:eB6l26EWlTw:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/gU3GovQI2iM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1259/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1259</feedburner:origLink></item>
		<item>
		<title>Cyberlolcats Watch the Hackers at DefCon</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/fov58JuQtv8/1255</link>
		<comments>http://www.guerilla-ciso.com/archives/1255#comments</comments>
		<pubDate>Thu, 30 Jul 2009 13:22:44 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[IKANHAZFIZMA]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[lolcats]]></category>
		<category><![CDATA[pwnage]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1255</guid>
		<description><![CDATA[Yeah, tell it to this guy, the Internet&#8217;s lawyer. =)



Bookmark to:
















Hide Sites



$$('div.d1255').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); ]]></description>
			<content:encoded><![CDATA[<p>Yeah, tell it to <a href="http://johndozierjr.typepad.com/dozierinternetlaw/2009/07/internet-lawyer-take-defcon-spinning-out-of-control.html" target="_blank">this guy, the Internet&#8217;s lawyer</a>. =)</p>
<p style="text-align: center;"><a href="http://cheezburger.com/view.aspx?ciid=4832886"><img class="aligncenter" src="http://images.cheezburger.com/completestore/2009/7/29/128933940421233984.jpg" alt="funny pictures" /></a></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1255').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1255" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1255" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1255&amp;title=Cyberlolcats+Watch+the+Hackers+at+DefCon" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1255&amp;title=Cyberlolcats+Watch+the+Hackers+at+DefCon" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1255" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1255&amp;title=Cyberlolcats+Watch+the+Hackers+at+DefCon" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1255&amp;h=Cyberlolcats+Watch+the+Hackers+at+DefCon" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1255&amp;title=Cyberlolcats+Watch+the+Hackers+at+DefCon" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1255&amp;title=Cyberlolcats+Watch+the+Hackers+at+DefCon" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1255&amp;title=Cyberlolcats+Watch+the+Hackers+at+DefCon" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1255" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1255" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1255&amp;t=Cyberlolcats+Watch+the+Hackers+at+DefCon" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1255').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1255').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=fov58JuQtv8:kOhGgbKz_90:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=fov58JuQtv8:kOhGgbKz_90:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=fov58JuQtv8:kOhGgbKz_90:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/fov58JuQtv8" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1255/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1255</feedburner:origLink></item>
		<item>
		<title>The CyberArmy You Have…</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/CuNS9aw3gbc/1235</link>
		<comments>http://www.guerilla-ciso.com/archives/1235#comments</comments>
		<pubDate>Mon, 27 Jul 2009 22:00:00 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
				<category><![CDATA[Cyberwar]]></category>
		<category><![CDATA[Rants]]></category>
		<category><![CDATA[cashcows]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[moneymoneymoney]]></category>
		<category><![CDATA[scalability]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1235</guid>
		<description><![CDATA[In the military, there is a saying: &#8220;You go to war with the army you have, not with the army you wish you had.&#8221;  In other words, you do all your training in peace and once you go off to war, it&#8217;s too late to fix it. Not that I agree with all the Cyber [...]]]></description>
			<content:encoded><![CDATA[<p>In the military, there is a saying: &#8220;You go to war with the army you have, not with the army you wish you had.&#8221;  In other words, you do all your training in peace and once you go off to war, it&#8217;s too late to fix it. Not that I agree with all the Cyber Pearl Harbor doomsayers, but I think that the CyberArmy we got now isn&#8217;t the right one for the job.</p>
<p><strong>So, let&#8217;s talk about services firms, contractors fit into this nicely since, well, they perform services.</strong></p>
<p>There are 4 types of work that services firms do (and contractors are services firms):</p>
<ul>
<li><strong>Brains:</strong> nobody else has done this before, but we hire a whole bunch of PhD people who can research how to get this done.  We charge really high prices but it&#8217;s because in the downtime, our people are doing presentations, going to symposiums, and working on things that you don&#8217;t even know exist.  Think old-school L0pht.  Think half of Mitre.  Think sharks with friggin laser beams, lasing and eating everything in sight.</li>
<li><strong>Gray Hair:</strong> We&#8217;ve done this before and know most of the problems that we can experience, along with the battle scars to prove it.  We charge quite a bit because we&#8217;re good and it takes less of us to get it done than our competitors.  Think most good IT engineers.  Think DLP and DAM right now.  Think infantry platoon sergeants.</li>
<li><strong>Procedural: </strong>There is a fairly sizeable market starting to grow around this service so we have to standardize quite a bit to reduce our costs to provide the service.  We use methodologies and tools so that we can take an army of trained college graduates, put them in a project, and they can execute according to plan.  Think audit staff.  Think help desk staff.  Think of an efficient DMV.</li>
<li><strong>Commodity:</strong> There isn&#8217;t a differentiator between competitors, so companies compete on price.  The way you make money is by making your cost of production lower or selling in volume.  Think Anti-Virus software (sorry friends, it&#8217;s true).  Think security guards.  Think peanut butter.</li>
</ul>
<p>This is also the maturity model for technology, so you can take any kind of tech, drop it in at the top, and it percolates down to the bottom.  Think Internet use: First it was the academics, then the contractors, then the technology early adopters on CompuServe, then free Internet access to all.  For most technology, it&#8217;s a 5-10 year cycle to get from the top to the bottom.  You already know this: the skills you have now will be obsolete in 5 years.</p>
<p style="text-align: center;"><em><img class="alignnone" title="Procedural Permit Required" src="http://farm1.static.flickr.com/141/358636892_892d545cd2.jpg?v=0" alt="" width="500" height="375" /></em></p>
<p style="text-align: center;"><em>Procedural Permit Required photo by <a title="Link to Dawn Endico's photostream" rel="dc:creator cc:attributionURL" href="http://www.flickr.com/photos/candiedwomanire/"><strong>Dawn Endico</strong></a>.</em></p>
<p><strong>Now looking at government contracting&#8230;.</strong></p>
<p>As a government contractor, you are audited financially by DCAA and they add up all your costs and let you keep a fixed margin of around 13-20%.  You can pull some Stupid Contractor Tricks &#8482; like paying salaries and working your people 60 hours/week (this is called uncompensated overtime), but there still is a limit to what you can do.</p>
<p>This fixed margin forces you into high-volume work to turn a profit.  This in turn forces you into procedural or even commodity work.</p>
<p>If your project is strictly time and material, you make more money off the cheaper folks but for quality of work reasons, you have to provide them with a playbook of some sort.  This pushes you directly into the procedural tier.</p>
<p>There are some contractors providing services at the Brains and Gray Hair stages, only they are few and far between.</p>
<p>Traditional types of contractor security services:</p>
<ul>
<li>Security Program Management and Governance</li>
<li>Audit and Penetration Testing</li>
<li>Compliance and Certification and Accreditation Support</li>
<li>Security Operations (think Managed Security Services)</li>
</ul>
<p><strong>Then back around to cyberwar&#8230;</strong></p>
<p>Cyberwar right now is definitely at the top of the skill hierarchy.  We don&#8217;t have an official national strategy.  We have a Cybersecurity Coordinator that hasn&#8217;t been filled yet.  We need Brains people and their skills to figure this out.  In fact, we have a leadership drought.</p>
<p>And yet the existing contractor skillset is based on procedural offerings.  To be honest, I see lots of people with cybersecurity offerings, but what they really have is rebranded service offerings because the skills sets of the workforce haven&#8217;t changed.</p>
<p>Some of the procedural offerings work, but only if you keep them in limited scope.  The security operations folks have quite a few tranferable skills, so do the pen-testers.  However, these are all at the tactical level.  The managerial skills don&#8217;t transfer really at all unless you have people that are just well-rounded, usually with some kind of IT ops background.</p>
<p>But, and this is the important thing, we&#8217;re not ready to hire contractors until we do get some leadership in place. And that&#8217;s why the $25M question right now is &#8220;Who will that person be?&#8221;  Until that time, anything from the vendors and contractors is just posturing.</p>
<p>Once we get a national leadership and direction, then it&#8217;s a matter of lining up the services being offered with the needs at the time.  What I think we&#8217;ll find out at that time is that we&#8217;re grossly underrepresented in some areas and sadly underrepresented in some areas and that these areas are directly inverse to the skills that our current workforce has.  This part scares me.</p>
<p>We need workforce development.  There are some problems with this, mostly because it takes so long to &#8220;grow&#8221; somebody with the skills to get the job done&#8211;maybe 5-10 years with education and experience.  Sadly, about the time we build this workforce, the problem will have slid down the scale so that procedural offerings will probably work.  This frustrates me greatly.</p>
<p><strong>The summary part&#8230;</strong></p>
<p>Well, just like I don&#8217;t want to belong to any club that would stoop so low to have me as a member, it could be possible that almost all the contractors offering services aren&#8217;t the people that you want to hire for the job.</p>
<p>But then again, we need to figure out the leadership part first.  Sadly, that&#8217;s where we need the most love.  It&#8217;s been how many months with a significant leadership vacuum?  9? 12? 7 years?</p>
<p>The most critical step in building a cyberwar/cyberdefense/cyberfoo capability is in building a workforce.  We&#8217;re still stuck with the &#8220;option&#8221; of building the airplane while it&#8217;s taxiing down the runway.</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1235').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1235" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1235" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1235&amp;title=The+CyberArmy+You+Have%26%238230%3B" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1235&amp;title=The+CyberArmy+You+Have%26%238230%3B" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1235" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1235&amp;title=The+CyberArmy+You+Have%26%238230%3B" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1235&amp;h=The+CyberArmy+You+Have%26%238230%3B" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1235&amp;title=The+CyberArmy+You+Have%26%238230%3B" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1235&amp;title=The+CyberArmy+You+Have%26%238230%3B" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1235&amp;title=The+CyberArmy+You+Have%26%238230%3B" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1235" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1235" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1235&amp;t=The+CyberArmy+You+Have%26%238230%3B" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1235').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1235').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=CuNS9aw3gbc:dbpqia8YqIQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=CuNS9aw3gbc:dbpqia8YqIQ:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=CuNS9aw3gbc:dbpqia8YqIQ:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/CuNS9aw3gbc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1235/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1235</feedburner:origLink></item>
	</channel>
</rss><!-- Dynamic page generated in 1.304 seconds. --><!-- Cached page generated by WP-Super-Cache on 2009-11-15 16:08:45 --><!-- Compression = gzip -->
