<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>The Guerilla CISO</title>
	
	<link>http://www.guerilla-ciso.com</link>
	<description>Life in the information assurance salt mines.</description>
	<pubDate>Thu, 09 Jul 2009 20:13:36 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<geo:lat>38.959673</geo:lat><geo:long>-77.346206</geo:long><creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/TheGuerillaCiso" type="application/rss+xml" /><feedburner:emailServiceId>TheGuerillaCiso</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
		<title>LOLCATS, CISOs, and Horror Stories</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/z9xAB-vEE1U/1115</link>
		<comments>http://www.guerilla-ciso.com/archives/1115#comments</comments>
		<pubDate>Thu, 09 Jul 2009 13:15:11 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[IKANHAZFIZMA]]></category>

		<category><![CDATA[cashcows]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[lolcats]]></category>

		<category><![CDATA[moneymoneymoney]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1115</guid>
		<description><![CDATA[Sometimes it takes a little bit of dramatization to get the funding for your security program. Here at IKANHAZFIZMA, well, maybe we take it a bit too far.



Bookmark to:


















Hide Sites



$$('div.d1115').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); ]]></description>
			<content:encoded><![CDATA[<p>Sometimes it takes a little bit of dramatization to get the funding for your security program. Here at IKANHAZFIZMA, well, maybe we take it a bit too far.</p>
<p style="text-align: center;"><a href="http://cheezburger.com/view.aspx?ciid=4463120"><img class="aligncenter" src="http://images.cheezburger.com/completestore/2009/6/17/128897650768063716.jpg" alt="funny pictures" /></a></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1115').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1115" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1115" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1115&amp;title=LOLCATS%2C+CISOs%2C+and+Horror+Stories" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1115&amp;title=LOLCATS%2C+CISOs%2C+and+Horror+Stories" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1115" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=LOLCATS%2C+CISOs%2C+and+Horror+Stories&amp;url=http://www.guerilla-ciso.com/archives/1115&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1115&amp;title=LOLCATS%2C+CISOs%2C+and+Horror+Stories" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1115&amp;h=LOLCATS%2C+CISOs%2C+and+Horror+Stories" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1115&amp;title=LOLCATS%2C+CISOs%2C+and+Horror+Stories" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1115&amp;title=LOLCATS%2C+CISOs%2C+and+Horror+Stories" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1115&amp;title=LOLCATS%2C+CISOs%2C+and+Horror+Stories" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1115" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=LOLCATS%2C+CISOs%2C+and+Horror+Stories&amp;link_href=http://www.guerilla-ciso.com/archives/1115" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1115" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1115&amp;t=LOLCATS%2C+CISOs%2C+and+Horror+Stories" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1115').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1115').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=z9xAB-vEE1U:-0mEdJOOn4M:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=z9xAB-vEE1U:-0mEdJOOn4M:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=z9xAB-vEE1U:-0mEdJOOn4M:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/z9xAB-vEE1U" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1115/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1115</feedburner:origLink></item>
		<item>
		<title>Guerilla CISO “Staff” Hit the Campaign Trail</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/gKXUX4k146g/1191</link>
		<comments>http://www.guerilla-ciso.com/archives/1191#comments</comments>
		<pubDate>Thu, 09 Jul 2009 13:10:31 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[Public Policy]]></category>

		<category><![CDATA[Speaking]]></category>

		<category><![CDATA[cyberwar]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[infosec]]></category>

		<category><![CDATA[speaking]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1191</guid>
		<description><![CDATA[Dan and I were on the Beyond the Perimeter Podcast Featuring Amrit Williams and will be for a couple more episodes.  It&#8217;s hard work to not sound like my usual dorky self.  =)
Check out Episode I here


Bookmark to:


















Hide Sites



$$('div.d1191').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); ]]></description>
			<content:encoded><![CDATA[<p>Dan and I were on the <a href="http://blogs.bigfix.com/beyondtheperimeter/" target="_blank">Beyond the Perimeter Podcast Featuring Amrit Williams</a> and will be for a couple more episodes.  It&#8217;s hard work to not sound like my usual dorky self.  =)</p>
<p><a href="http://blogs.bigfix.com/beyondtheperimeter/2009/07/07/episode-32-cybsersecurity-cyberdefense-and-cyberwarfare-part-i/" target="_blank">Check out Episode I here</a></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1191').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1191" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1191" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1191&amp;title=Guerilla+CISO+%26%238220%3BStaff%26%238221%3B+Hit+the+Campaign+Trail" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1191&amp;title=Guerilla+CISO+%26%238220%3BStaff%26%238221%3B+Hit+the+Campaign+Trail" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1191" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Guerilla+CISO+%26%238220%3BStaff%26%238221%3B+Hit+the+Campaign+Trail&amp;url=http://www.guerilla-ciso.com/archives/1191&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1191&amp;title=Guerilla+CISO+%26%238220%3BStaff%26%238221%3B+Hit+the+Campaign+Trail" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1191&amp;h=Guerilla+CISO+%26%238220%3BStaff%26%238221%3B+Hit+the+Campaign+Trail" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1191&amp;title=Guerilla+CISO+%26%238220%3BStaff%26%238221%3B+Hit+the+Campaign+Trail" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1191&amp;title=Guerilla+CISO+%26%238220%3BStaff%26%238221%3B+Hit+the+Campaign+Trail" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1191&amp;title=Guerilla+CISO+%26%238220%3BStaff%26%238221%3B+Hit+the+Campaign+Trail" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1191" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=Guerilla+CISO+%26%238220%3BStaff%26%238221%3B+Hit+the+Campaign+Trail&amp;link_href=http://www.guerilla-ciso.com/archives/1191" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1191" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1191&amp;t=Guerilla+CISO+%26%238220%3BStaff%26%238221%3B+Hit+the+Campaign+Trail" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1191').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1191').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=gKXUX4k146g:OPeJkf57wok:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=gKXUX4k146g:OPeJkf57wok:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=gKXUX4k146g:OPeJkf57wok:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/gKXUX4k146g" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1191/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1191</feedburner:origLink></item>
		<item>
		<title>Hackers, Protesters, Iran, Twitter, and Lolcats</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/q_UnwetA-pA/1183</link>
		<comments>http://www.guerilla-ciso.com/archives/1183#comments</comments>
		<pubDate>Fri, 03 Jul 2009 00:10:44 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[IKANHAZFIZMA]]></category>

		<category><![CDATA[infosharing]]></category>

		<category><![CDATA[lolcats]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1183</guid>
		<description><![CDATA[A big thanks to all the hackers and wannabees who have kept and continue to keep the Internet routing around censorship so that the people of Iran can get to twitter.



Bookmark to:


















Hide Sites



$$('div.d1183').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); ]]></description>
			<content:encoded><![CDATA[<p>A big thanks to all the hackers and wannabees who have kept and continue to keep the Internet routing around censorship so that the people of Iran can get to twitter.</p>
<p style="text-align: center;"><a href="http://cheezburger.com/view.aspx?ciid=4598427"><img class="alignnone" src="http://images.cheezburger.com/completestore/2009/7/2/128910531346607022.jpg" alt="funny pictures" /></a></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1183').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1183" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1183" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1183&amp;title=Hackers%2C+Protesters%2C+Iran%2C+Twitter%2C+and+Lolcats" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1183&amp;title=Hackers%2C+Protesters%2C+Iran%2C+Twitter%2C+and+Lolcats" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1183" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Hackers%2C+Protesters%2C+Iran%2C+Twitter%2C+and+Lolcats&amp;url=http://www.guerilla-ciso.com/archives/1183&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1183&amp;title=Hackers%2C+Protesters%2C+Iran%2C+Twitter%2C+and+Lolcats" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1183&amp;h=Hackers%2C+Protesters%2C+Iran%2C+Twitter%2C+and+Lolcats" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1183&amp;title=Hackers%2C+Protesters%2C+Iran%2C+Twitter%2C+and+Lolcats" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1183&amp;title=Hackers%2C+Protesters%2C+Iran%2C+Twitter%2C+and+Lolcats" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1183&amp;title=Hackers%2C+Protesters%2C+Iran%2C+Twitter%2C+and+Lolcats" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1183" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=Hackers%2C+Protesters%2C+Iran%2C+Twitter%2C+and+Lolcats&amp;link_href=http://www.guerilla-ciso.com/archives/1183" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1183" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1183&amp;t=Hackers%2C+Protesters%2C+Iran%2C+Twitter%2C+and+Lolcats" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1183').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1183').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=q_UnwetA-pA:3t7K2PJtud0:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=q_UnwetA-pA:3t7K2PJtud0:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=q_UnwetA-pA:3t7K2PJtud0:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/q_UnwetA-pA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1183/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1183</feedburner:origLink></item>
		<item>
		<title>Security Automation Developers Conference Slides</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/y8Plh3ncDLg/1176</link>
		<comments>http://www.guerilla-ciso.com/archives/1176#comments</comments>
		<pubDate>Thu, 02 Jul 2009 23:13:56 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[NIST]]></category>

		<category><![CDATA[Technical]]></category>

		<category><![CDATA[800-53A]]></category>

		<category><![CDATA[8500.2]]></category>

		<category><![CDATA[catalogofcontrols]]></category>

		<category><![CDATA[compatibility]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[fdcc]]></category>

		<category><![CDATA[genius]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[infosec]]></category>

		<category><![CDATA[infosharing]]></category>

		<category><![CDATA[management]]></category>

		<category><![CDATA[pci-dss]]></category>

		<category><![CDATA[scalability]]></category>

		<category><![CDATA[scap]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[seminar]]></category>

		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1176</guid>
		<description><![CDATA[Eh? What&#8217;s that mean?  Developer Days is a weeklong conference where they get down into the weeds about the various SCAP schemas and how they fit into the overall program of security automation. 
Highlights and new ideas:
Remedial Markup Language: Fledgeling schema to describe how to remediate a vulnerability.  A fully automated security system would scan and [...]]]></description>
			<content:encoded><![CDATA[<p>Eh? What&#8217;s that mean?  Developer Days is a weeklong conference where they get down into the weeds about the various <a href="http://www.guerilla-ciso.com/index.php?s=scap">SCAP schemas</a> and how they fit into the overall program of security automation. </p>
<p>Highlights and new ideas:</p>
<p><strong>Remedial Markup Language:</strong> Fledgeling schema to describe how to remediate a vulnerability.  A fully automated security system would scan and then use the RML content to automagically fix the finding&#8230; say, changing a configuration setting or installing a patch.  this would be much awesome if combined with the CVE/CWE so you have a vulnerability scanner that scans and fixes the problem.  Also needs to be kept in a bottle because the operations guys will have a heartattack if we are doing this without any human intervention.</p>
<p><strong>Computer Network Defense:</strong> There is a pretty good scenario slide deck on using SCAP to automate hardening, auditing, monitoring, and defense.  The key from this deck is how the information flows using automation.</p>
<p><strong>Common Control Identifier:</strong>  This schema is basically a catalog of controls (800-53, 8500.2, PCI, SoX, etc) in XML.  The awesomeness with this is that one control can contain a reference implementation for each technology and the checklist to validate it in XCCDF.  At this point, I get all misty&#8230;</p>
<p><strong>Open Checklist Interactive Language:</strong> This schema is to capture questionaires.  Think managerial controls, operational controls, policy, and procedure captured in electronic format and fed into the regular mitigation and workflow tools that you use so that you can view &#8220;security of the enterprise at a glance&#8221; across technical and non-technical security.</p>
<p><strong>Network Event Content Automation Protocol:</strong>  This is just a concept floating around right now on using XML to describe and automate responses to attacks.  If you&#8217;re familiar with ArcSight&#8217;s Common Event Format, this would be something similar but on steroids with workflow and a pony!</p>
<p>Attendance at developer days is limited, but thanks to all the &#8220;Powar of teh Intarwebs, you can <a href="http://makingsecuritymeasurable.mitre.org/participation/devdays.html" target="_blank">go here and read the slides!</a></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1176').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1176" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1176" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1176&amp;title=Security+Automation+Developers+Conference+Slides" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1176&amp;title=Security+Automation+Developers+Conference+Slides" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1176" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Security+Automation+Developers+Conference+Slides&amp;url=http://www.guerilla-ciso.com/archives/1176&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1176&amp;title=Security+Automation+Developers+Conference+Slides" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1176&amp;h=Security+Automation+Developers+Conference+Slides" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1176&amp;title=Security+Automation+Developers+Conference+Slides" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1176&amp;title=Security+Automation+Developers+Conference+Slides" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1176&amp;title=Security+Automation+Developers+Conference+Slides" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1176" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=Security+Automation+Developers+Conference+Slides&amp;link_href=http://www.guerilla-ciso.com/archives/1176" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1176" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1176&amp;t=Security+Automation+Developers+Conference+Slides" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1176').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1176').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=y8Plh3ncDLg:G29GQ1gFrcE:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=y8Plh3ncDLg:G29GQ1gFrcE:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=y8Plh3ncDLg:G29GQ1gFrcE:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/y8Plh3ncDLg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1176/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1176</feedburner:origLink></item>
		<item>
		<title>GAO’s 5 Steps to “Fix” FISMA</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/Zg_cS3XTTpI/1168</link>
		<comments>http://www.guerilla-ciso.com/archives/1168#comments</comments>
		<pubDate>Thu, 02 Jul 2009 21:54:51 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[FISMA]]></category>

		<category><![CDATA[accounting]]></category>

		<category><![CDATA[accreditation]]></category>

		<category><![CDATA[auditor]]></category>

		<category><![CDATA[catalogofcontrols]]></category>

		<category><![CDATA[certification]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[fisma]]></category>

		<category><![CDATA[FUD]]></category>

		<category><![CDATA[gao]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[infosec]]></category>

		<category><![CDATA[itsatrap]]></category>

		<category><![CDATA[management]]></category>

		<category><![CDATA[metrics]]></category>

		<category><![CDATA[omb]]></category>

		<category><![CDATA[S773]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1168</guid>
		<description><![CDATA[Letter from GAO on how Congress can fix FISMA.  And oh yeah, the press coverage on it.
Now supposedly this was in response to an inquiry from Congress about &#8220;Please comment on the need for improved cyber security relating to S.773, the proposed Cybersecurity Act of 2009.&#8221;  This is S.773.
GAO is mixing issues and has missed [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://docs.govinfosecurity.com/files/external/2009June30-FISMAreform.pdf" target="_blank">Letter from GAO on how Congress can fix FISMA.</a>  And oh yeah, <a href="http://www.govinfosecurity.com/articles.php?art_id=1590" target="_blank">the press coverage on it.</a></p>
<p>Now supposedly this was in response to an inquiry from Congress about <em>&#8220;Please comment on the need for improved cyber security relating to S.773, the proposed Cybersecurity Act of 2009.&#8221;</em>  <a href="http://www.guerilla-ciso.com/index.php?s=S.773">This is S.773</a>.</p>
<p>GAO is mixing issues and has missed the mark on what Congress asked for.  S.773 is all about protecting critical infrastructure.  It only rarely mentions government internal IT issues.  S.773 has nothing at all to do with FISMA reform.  However, GAO doesn&#8217;t have much expertise in cybersecurity outside of the Federal Agencies (they have some, but I would never call it extensive), so they reported on what they know.</p>
<p>The GAO report used the often-cited metric of an increase in cybersecurity attacks against Government IT systems growing from &#8220;5,503 incidents reported in fiscal year 2006 to 16,843 incidents in fiscal year 2008&#8243; as proof that the agencies are not doing anything to fix the problem.  I&#8217;ve questioned these figures before, it&#8217;s associated with the measurement problem and increased reporting requirements more than an increase in attacks.  Truth be told, nobody knows if the attacks are increasing and, if so, at what rate.  I would guess they&#8217;re increasing, but we don&#8217;t know, so quit citing some &#8220;whacked&#8221; metric as proof.</p>
<p style="text-align: center;"><em><img class="alignnone" title="Reform" src="http://farm2.static.flickr.com/1371/955426097_633f75039d.jpg?v=0" alt="" width="324" height="322" /></em></p>
<p style="text-align: center;"><em>Reform photo by </em><a title="Link to shevy's photostream" rel="dc:creator cc:attributionURL" href="http://www.guerilla-ciso.com/photos/shevy_dk/"><strong><span style="color: #0063dc;"><em>shevy</em></span></strong></a><em>.</em></p>
<p><strong>GAO&#8217;s recommendations for FISMA Reform:</strong></p>
<p><strong>Clarify requirements for testing and evaluating security controls.</strong>  In other words, the auditing shall continue until the scores improve.  Hate to tell you this, but really all you can test at the national level is if the FISMA framework is in place, the execution of the framework (and by extension, if an agency is secure or not) is largely untestable using any kind of a framework.</p>
<p><strong>Require agency heads to provide an assurance statement on the overall adequacy and effectiveness of the agency&#8217;s information security program.</strong>  This is harkening back to the accounting roots of GAO.  Basically what we&#8217;re talking here is for the agency head to attest that his agency has made the best effort that it can to protect their IT.  I like part of this because part of what&#8217;s missing is &#8221;executive support&#8221; for IT security.  To be honest, though, most agency heads aren&#8217;t IT security dweebs, they would be signing an assurance statement based upon what their CIO/CISO put in the executive summary.</p>
<p><strong>Enhance independent annual evaluations.</strong>  This has significant cost implications.  Besides, we&#8217;re getting more and more evaluations as time goes on with an increase in audit burden.  IE, in the Government IT security space, how much of your time is spent providing proof to auditors versus building security?  For some people, it&#8217;s their full-time job.</p>
<p><strong>Strengthen annual reporting mechanisms.</strong>  More reporting.  I don&#8217;t think it needs to get strengthened, I think it needs to get &#8220;fixed&#8221;.  And by &#8220;fixed&#8221; I mean real metrics.  I&#8217;ve touched on this at least a hundred times, go check out some of it&#8230;.</p>
<p><strong>Strengthen OMB oversight of agency information security programs.</strong>  This one gives me brain-hurt.  OMB has exactly the amount of oversight that they need to do their job.  Just like more auditing, if you increase the oversight and the people doing the execution have the same amount of people and the same amount of funding and the same types of skills, do you really expect them to perform differently?</p>
<p><strong>Rybolov&#8217;s synopsis:</strong></p>
<p>When the only tool you have is a hammer, every problem looks like a nail, and I think that&#8217;s what GAO is doing here.  Since performance in IT security is obviously down, they suggest that more auditing and oversight will help.  But then again, at what point does the audit burden tip to the point where nobody is really doing any work at all except for answering to audit requests?</p>
<p>Going back to what Congress really asked for, We run up against a problem.  There isn&#8217;t a huge set of information about how the rest of the nation is doing with cybersecurity.  There&#8217;s the <a href="http://www.verizonbusiness.com/resources/security/reports/2009_databreach_rp.pdf" target="_blank">Verizon DBIR</a>, the <a href="http://datalossdb.org/" target="_blank">Data Loss DB</a>, some surveys, and that&#8217;s about it.</p>
<p>So really, when you ask GAO to find out what the national cybersecurity situation is, all you&#8217;re going to get is a bunch of information about how government IT systems line up and maybe some anecdotes about critical infrastructure.</p>
<p><em>Coming to a blog near you (hopefully soon): Rybolov&#8217;s 5 steps to &#8220;fix&#8221; FISMA.</em></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1168').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1168" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1168" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1168&amp;title=GAO%26%238217%3Bs+5+Steps+to+%26%238220%3BFix%26%238221%3B+FISMA" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1168&amp;title=GAO%26%238217%3Bs+5+Steps+to+%26%238220%3BFix%26%238221%3B+FISMA" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1168" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=GAO%26%238217%3Bs+5+Steps+to+%26%238220%3BFix%26%238221%3B+FISMA&amp;url=http://www.guerilla-ciso.com/archives/1168&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1168&amp;title=GAO%26%238217%3Bs+5+Steps+to+%26%238220%3BFix%26%238221%3B+FISMA" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1168&amp;h=GAO%26%238217%3Bs+5+Steps+to+%26%238220%3BFix%26%238221%3B+FISMA" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1168&amp;title=GAO%26%238217%3Bs+5+Steps+to+%26%238220%3BFix%26%238221%3B+FISMA" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1168&amp;title=GAO%26%238217%3Bs+5+Steps+to+%26%238220%3BFix%26%238221%3B+FISMA" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1168&amp;title=GAO%26%238217%3Bs+5+Steps+to+%26%238220%3BFix%26%238221%3B+FISMA" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1168" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=GAO%26%238217%3Bs+5+Steps+to+%26%238220%3BFix%26%238221%3B+FISMA&amp;link_href=http://www.guerilla-ciso.com/archives/1168" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1168" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1168&amp;t=GAO%26%238217%3Bs+5+Steps+to+%26%238220%3BFix%26%238221%3B+FISMA" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1168').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1168').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=Zg_cS3XTTpI:7ejSsmaeA5s:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=Zg_cS3XTTpI:7ejSsmaeA5s:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=Zg_cS3XTTpI:7ejSsmaeA5s:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/Zg_cS3XTTpI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1168/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1168</feedburner:origLink></item>
		<item>
		<title>Your Security “Requirements” are Teh Suxxorz</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/qhh05fLpfuY/1131</link>
		<comments>http://www.guerilla-ciso.com/archives/1131#comments</comments>
		<pubDate>Wed, 01 Jul 2009 17:01:10 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[BSOFH]]></category>

		<category><![CDATA[Outsourcing]]></category>

		<category><![CDATA[Technical]]></category>

		<category><![CDATA[800-53A]]></category>

		<category><![CDATA[C&A]]></category>

		<category><![CDATA[catalogofcontrols]]></category>

		<category><![CDATA[certification]]></category>

		<category><![CDATA[compatibility]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[fips-200]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[infosec]]></category>

		<category><![CDATA[management]]></category>

		<category><![CDATA[pwnage]]></category>

		<category><![CDATA[risk]]></category>

		<category><![CDATA[scalability]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[tailoring]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1131</guid>
		<description><![CDATA[Face it, your security requirements suck. I&#8217;ll tell you why.  You write down controls verbatim from your catalog of controls (800-53, SoX, PCI, 27001, etc), put it into a contract, and wonder how come when it comes time for security testing, we just aren&#8217;t talking the same language.  Even worse, you put in the cr*ptastic [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Face it, your security requirements suck. </strong>I&#8217;ll tell you why.  You write down controls verbatim from your catalog of controls (800-53, SoX, PCI, 27001, etc), put it into a contract, and wonder how come when it comes time for security testing, we just aren&#8217;t talking the same language.  Even worse, you put in the cr*ptastic <em>&#8220;Contractor shall be compliant with FISMA and all applicable NIST standards&#8221;.</em>  Yes, this happens more often than I could ever care to count, and I&#8217;ve seen it from both sides.</p>
<p>The problem with quoting back the &#8220;requirements&#8221; from a catalog of controls is that they&#8217;re not really requirements, they&#8217;re control objectives&#8211;abstract representations of what you need in order to protect your data, IT system, or business.  It&#8217;s a bit like brain surgery using a hammer and chisel&#8211;yes, it might work out for you, but I don&#8217;t really feel comfortable doing it or being on the receiving end.</p>
<p>And this is my beef with the way we manage security controls nowadays.  They&#8217;re not requirements, functionally they&#8217;re a high-level needs statement or even a security concept of operations.  Security controls need to be tailored into real requirements that are buildable, testable, measurable, and achievable.</p>
<p style="text-align: center;"><img class="alignnone" title="Requirements" src="http://farm3.static.flickr.com/2171/2401835598_f7b439f0e7.jpg?v=0" alt="" width="375" height="500" /></p>
<p style="text-align: center;"><em>Requirements photo by </em><a title="Link to yummiec00kies' photostream" rel="dc:creator cc:attributionURL" href="http://www.guerilla-ciso.com/photos/yummiec00kies/"><strong><span style="color: #0063dc;"><em>yummiec00kies</em></span></strong></a><em>.  There&#8217;s a social commentary in there about &#8220;Single, slim, and pleasant looking&#8221; but even I&#8217;m afraid to touch that one. =)</em></p>
<p style="text-align: left;"><strong>Did you say &#8220;Wrecks and Female Pigs&#8217;? </strong>In the contracting world, we have 2 vehicles that we use primarily for security controls: Statements of Work (SOW) and Engineering Requirements.</p>
<ul>
<li>
<div style="text-align: left;"><strong>Statements of Work</strong> follow along the lines of activities performed by people.  For instance, &#8220;contractor shall perform monthly 100% vulnerability scanning of the $FooProject.&#8221;</div>
</li>
<li>
<div style="text-align: left;"><strong>Engineering Requirements</strong> are exactly what you want to have build.  For instance, &#8220;Prior to displaying the login screen, the application shall display the approved Generic Government Agency warning banner as shown below&#8230;&#8221;</div>
</li>
</ul>
<p style="text-align: left;"><strong>Let&#8217;s have a quick exercise, shall we?</strong></p>
<p><strong>What 800-53 says: </strong>The information system produces audit records that contain sufficient information to, at a minimum, establish what type of event occurred, when (date and time) the event occurred, where the event occurred, the source of the event, the outcome (success or failure) of the event, and the identity of any user/subject associated with the event.</p>
<p><strong>How It gets translated into a contract:</strong> Since it&#8217;s more along the lines of a security functional requirement (ie, it&#8217;s a specific functionality not a task we want people to do), we brake it out into multiple requirements:</p>
<p><em>The $BarApplication shall produce audit records with the following content:</em></p>
<ul>
<li><em>Event description such as the following: </em>
<ul>
<li><em>Access the $Baz subsystem</em></li>
<li><em>Mounting external hard drive</em></li>
<li><em>Connecting to database</em></li>
<li><em>User entered administrator mode</em></li>
</ul>
</li>
<li><em>Date/time stamp in &#8216;YYYY-MM-DD HH:MM:SS&#8217; format;</em></li>
<li><em>Hostname where the event occured;</em></li>
<li><em>Process name or program that generated the event;</em></li>
<li><em>Outcome of the event as one of the following: success, warn, or fail; and</em></li>
<li><em>Username and UserID that generated the event.</em></li>
</ul>
<p>For a COTS product (ie, Windows 2003 server, Cisco IOS), when it comes to logging, I get what I get, and this means I don&#8217;t have a requirement for logging unless I&#8217;m designing the engineering requirements for Windows.</p>
<p><strong>What 800-53 says: </strong>The The organization configures the information system to provide only essential capabilities and specifically prohibits and/or restricts the use of the following functions, ports, protocols, and/or services: [Assignment: organization-defined list of prohibited and/or restricted functions, ports, protocols, and/or services].</p>
<p><strong>How It gets translated into a contract:</strong> Since it&#8217;s more along the lines of a security functional requirement, we brake it out into multiple requirements:</p>
<p><em>The $Barsystem shall have the software firewall turned on and only the following traffic shall be allowed:</em></p>
<ul>
<li><em>TCP port 443 to the command server</em></li>
<li><em>UDP port 123 to the time server at this address</em></li>
<li><em>etc&#8230;..</em></li>
</ul>
<p>If we drop the system into a pre-existing infrastructure, we don&#8217;t need firewall rules per-se as part of the requirements, what we do need is a SOW along the following lines:</p>
<p><em>The system shall use our approved process for firewall change control, see a copy here&#8230;</em></p>
<p><strong>So what&#8217;s missing, and how do we fix the sorry state of requirements?</strong></p>
<p>This is the interesting part, and right now I&#8217;m not sure if we can, given the state of the industry and the infosec labor shortage:  we need security engineers who understand engineering requirements and project management in addition to vulnerability management.</p>
<p>Don&#8217;t abandon hope yet, let&#8217;s look at some things that can help&#8230;.</p>
<p>Security requirements are a &#8220;best effort&#8221; proposition.  By this, I mean that we have our requirements and they don&#8217;t fit in all cases, so what we do is we throw them out there and if you can&#8217;t meet the requirement, we waiver it (live with it, hope for the best) or apply a compensating control (shield it from bad things happening).  This is unnerving because what we end up doing is arguing all the time over whether the requirements that were written need to be done or not.  This drives the engineers nuts.</p>
<p>It&#8217;s a significant amount of work to translate control objectives into requirements.  The easiest, fastest way to fix the &#8220;controls view&#8221; of a project is to scope out things that are provided by infrastructure or by policies and procedures at the enterprise level.  Hmmm, sounds like explicitly stating what our shared/common controls are.</p>
<p>You can manage controls by exclusion or inclusion:</p>
<ul>
<li><strong>Inclusion:</strong>  We have a &#8220;default null&#8221; for controls and we will explicitly say in the requirements what controls you do need.  This works for small projects like standing up a pair of webservers in an existing infrastructure.</li>
<li><strong>Exclusion:</strong>  We give you the entire catalog of controls and then tell you which ones don&#8217;t apply to you.  This works best with large projects such as the outsourcing of an entire IT department.</li>
</ul>
<p>We need a reference implementation per technology.  Let&#8217;s face it, how many times have I taken the 800-53 controls and broken them down into controls relevant for a desktop OS?  At least 5 in the last 3 years.  The way you really need to do this is that you have a hardening guide and that is the authoritative set of requirements for that technology.  It makes life simple.  Not that I&#8217;m saying deviate from doctrine and don&#8217;t do 800-53 controls and 800-53A test procedures, but that&#8217;s the point of having a hardening guide&#8211;it&#8217;s really just a set of tailored controls specific to a certain technology type.  The work has been done for you, quit trying to re-engineer the wheel.</p>
<p>Use a Joint Responsibilities Matrix.  Basically this breaks down the catalog of controls into the following columns:</p>
<ul>
<li>Control Designator</li>
<li>Control Title</li>
<li>Provided by the Government/Infrastructure/Common Control</li>
<li>Provided by the Contractor/Project Team/Engineer</li>
</ul>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1131').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1131" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1131" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1131&amp;title=Your+Security+%26%238220%3BRequirements%26%238221%3B+are+Teh+Suxxorz" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1131&amp;title=Your+Security+%26%238220%3BRequirements%26%238221%3B+are+Teh+Suxxorz" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1131" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Your+Security+%26%238220%3BRequirements%26%238221%3B+are+Teh+Suxxorz&amp;url=http://www.guerilla-ciso.com/archives/1131&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1131&amp;title=Your+Security+%26%238220%3BRequirements%26%238221%3B+are+Teh+Suxxorz" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1131&amp;h=Your+Security+%26%238220%3BRequirements%26%238221%3B+are+Teh+Suxxorz" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1131&amp;title=Your+Security+%26%238220%3BRequirements%26%238221%3B+are+Teh+Suxxorz" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1131&amp;title=Your+Security+%26%238220%3BRequirements%26%238221%3B+are+Teh+Suxxorz" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1131&amp;title=Your+Security+%26%238220%3BRequirements%26%238221%3B+are+Teh+Suxxorz" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1131" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=Your+Security+%26%238220%3BRequirements%26%238221%3B+are+Teh+Suxxorz&amp;link_href=http://www.guerilla-ciso.com/archives/1131" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1131" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1131&amp;t=Your+Security+%26%238220%3BRequirements%26%238221%3B+are+Teh+Suxxorz" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1131').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1131').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=qhh05fLpfuY:8OtI0ROxq8k:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=qhh05fLpfuY:8OtI0ROxq8k:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=qhh05fLpfuY:8OtI0ROxq8k:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/qhh05fLpfuY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1131/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1131</feedburner:origLink></item>
		<item>
		<title>IKANHAZFIZMA’s take on Security Appliances</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/-TuQsnNNcEI/1119</link>
		<comments>http://www.guerilla-ciso.com/archives/1119#comments</comments>
		<pubDate>Thu, 25 Jun 2009 12:44:09 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[IKANHAZFIZMA]]></category>

		<category><![CDATA[cashcows]]></category>

		<category><![CDATA[lolcats]]></category>

		<category><![CDATA[moneymoneymoney]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1119</guid>
		<description><![CDATA[Why sell security software when you can bundle it with pre-installed hardware and operating system and sell it as an appliance?  We took some of our best lolcats and put them to work building us something we could &#8220;productize&#8221; and this is what they came up with&#8230;.



Bookmark to:


















Hide Sites



$$('div.d1119').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); ]]></description>
			<content:encoded><![CDATA[<p>Why sell security software when you can bundle it with pre-installed hardware and operating system and sell it as an appliance?  We took some of our best lolcats and put them to work building us something we could &#8220;productize&#8221; and this is what they came up with&#8230;.</p>
<p style="text-align: center;"><a href="http://cheezburger.com/view.aspx?ciid=4463409"><img class="aligncenter" src="http://images.cheezburger.com/completestore/2009/6/17/128897668078759421.jpg" alt="funny pictures" /></a></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1119').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1119" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1119" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1119&amp;title=IKANHAZFIZMA%26%238217%3Bs+take+on+Security+Appliances" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1119&amp;title=IKANHAZFIZMA%26%238217%3Bs+take+on+Security+Appliances" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1119" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=IKANHAZFIZMA%26%238217%3Bs+take+on+Security+Appliances&amp;url=http://www.guerilla-ciso.com/archives/1119&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1119&amp;title=IKANHAZFIZMA%26%238217%3Bs+take+on+Security+Appliances" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1119&amp;h=IKANHAZFIZMA%26%238217%3Bs+take+on+Security+Appliances" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1119&amp;title=IKANHAZFIZMA%26%238217%3Bs+take+on+Security+Appliances" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1119&amp;title=IKANHAZFIZMA%26%238217%3Bs+take+on+Security+Appliances" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1119&amp;title=IKANHAZFIZMA%26%238217%3Bs+take+on+Security+Appliances" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1119" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=IKANHAZFIZMA%26%238217%3Bs+take+on+Security+Appliances&amp;link_href=http://www.guerilla-ciso.com/archives/1119" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1119" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1119&amp;t=IKANHAZFIZMA%26%238217%3Bs+take+on+Security+Appliances" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1119').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1119').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=-TuQsnNNcEI:XgCJV3d7JcQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=-TuQsnNNcEI:XgCJV3d7JcQ:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=-TuQsnNNcEI:XgCJV3d7JcQ:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/-TuQsnNNcEI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1119/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1119</feedburner:origLink></item>
		<item>
		<title>The Spanish Civil War and the Rise of Cyberwar</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/LaN5PtkuTAg/1139</link>
		<comments>http://www.guerilla-ciso.com/archives/1139#comments</comments>
		<pubDate>Mon, 22 Jun 2009 16:26:47 +0000</pubDate>
		<dc:creator>ian99</dc:creator>
		
		<category><![CDATA[Public Policy]]></category>

		<category><![CDATA[Rants]]></category>

		<category><![CDATA[The Guerilla CISO]]></category>

		<category><![CDATA[cybercommand]]></category>

		<category><![CDATA[cyberwar]]></category>

		<category><![CDATA[FUD]]></category>

		<category><![CDATA[georgia]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[incidentresponse]]></category>

		<category><![CDATA[infosec]]></category>

		<category><![CDATA[publicpolicy]]></category>

		<category><![CDATA[pwnage]]></category>

		<category><![CDATA[risk]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[subversion]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1139</guid>
		<description><![CDATA[As usual, I greatly enjoyed your blog from 17 June, A Short History of Cyberwar Look-alikes, Rybolov.  Moreover I really appreciated your historical examples.  It warms my heart whenever an American uses the Russo-Japanese War of 1904/5 as a historic example of anything.  Most Americans have never even heard of it.  [...]]]></description>
			<content:encoded><![CDATA[<p>As usual, I greatly enjoyed your <a href="http://www.guerilla-ciso.com/archives/806">blog from 17 June, A Short History of Cyberwar Look-alikes</a>, Rybolov.  Moreover I really appreciated your historical examples.  It warms my heart whenever an American uses the Russo-Japanese War of 1904/5 as a historic example of anything.  Most Americans have never even heard of it.  Yet, it is important event today if for no other reason than it established the tradition of having the US President intercede as a peace negotiator and win the Nobel Prize for Peace for his efforts.  Because of this, some historians mark it as the historic point at which the US entered the world stage as a great power.  By the way the President involved was Teddy Roosevelt.</p>
<p>Concerning the state and nature of Cyberwar today, I’ve seen Rybolov&#8217;s models and I think they make sense.  Cyberwar as an extension of electronic warfare makes some sense.  The analogy does break down at some point because of the peculiarity of the medium.  For example, when considering exploitation of SCADA systems as we have seen in the Baltic States and in a less focused manner here in North America, it is hard to see a clear analogy in electronic warfare.  The consequences look more like old-fashion kinetic warfare.  Likewise, there are aspects of Cyberwarfare that look like good old-fashion human intelligence and espionage.  Of course I also have reservations with the electronic warfare model based on government politics.  Our friends at NSA have been suggesting that Cyberwarfare is an extension of signals intelligence for years, with the accompanying claim that they (NSA) should have the technical, legal, and of course budgetary resources that go along with it.</p>
<p>I&#8217;ve also have seen other writers propose other models of Cyberwarfare and they tend to be a mixed bag at best.  At worst, many of the models proposed appear to be the laughable writings of individuals with no more insight to or knowledge of intelligence operations beyond the latest James Bond movie. My own opinion is that two models or driving forces behind international Cyberwarfare activity.  The first is pure opportunism.  Governments and criminal organizations alike, even authoritarian governments have seen the Hollywood myths and the media hysteria about hacker exploits.  Over time, criminal gangs have created and expanded on their cyber capabilities driven by a calculation of profits and risks much like conventional businesses.  Combine an international banking environment that allows funds to be transferred across borders with little effort and less time and an international legal environment that is largely out of touch with the Internet and international telecommunications, and we have a breeding ground for Cyber criminals in which the risks of cross-border criminal activity is often much less risky than domestic criminal activity.</p>
<p>As successful Cyber criminal gangs have emerged in totalitarian regimes, it shouldn&#8217;t be a surprise that eventually the governments involved would eventually take an interest in both their activities and techniques.  There are several reasons that totalitarian government might want to do this.  Perhaps the simplest motivation is that the corrupt officials would be drawn to share in the profits in exchange for protection.  In addition, the intelligence arms of these nations could also leverage their services and techniques at a fraction of the cost of developing similar capabilities themselves.  Additionally, using these capabilities would also provide the intelligence agencies and even the host government with an element of deniability if operations assigned to the criminal gangs were detected.</p>
<p style="text-align: center;"><img class="aligncenter" title="Monument to the International Brigade" src="http://farm2.static.flickr.com/1396/1324168056_d5e9d56b44.jpg?v=0" alt="" width="375" height="500" /></p>
<p style="text-align: center;"><em>Monument to the International Brigade photo by <a title="Link to Secret Pilgrim's photostream" rel="dc:creator cc:attributionURL" href="http://www.flickr.com/photos/umdrums/"><strong>Secret Pilgrim</strong></a>.  For more information, read the <a href="http://en.wikipedia.org/wiki/International_Brigades" target="_blank">history of the International Brigade</a>.<br />
</em></p>
<p>Perhaps the most interesting model of development and Cyberwarfare activity today would be based on the pre-WW II example of the <a href="http://en.wikipedia.org/wiki/Spanish_Civil_War" target="_blank">Spanish Civil War</a>.  After World War I, a period of mental and societal exhaustion followed on the part of all participating nations.  This was quickly follow by a period of self-assessment and rebuilding.  In the case of the defeated Germany the reconstruction period protracted due to difficult economic conditions, in part created by the harsh conditions of surrender imposed by the winning European governments.</p>
<p>It was also important to remember that these same victorious European governments undermined many of social and moral underpinnings of German society by systematically all the basis of traditional German government and governmental legitimacy without regard for what should replace it.  The assessments of most historians is that these factors combined to sow the seed of hatred against the victorious powers and created a social climate in which a return to open warfare at some time in the future was seen as unavoidable and perhaps desirable.  The result was that Germany actively prepared and planned for what was seen as the commonly inevitable war in the future.  New systems and technologies were considered, tested.  However, treaty limitations also hampered some of these efforts.</p>
<p>In the Soviet Union a similar set of conclusions developed during this period of history within the ruling elite, specifically that renewed war with Germany was inevitable in the near term.  Like Germany, the Soviet Union also actively prepared for this war.  Likewise they considered and studied new technologies and approaches to war.  Somewhat surprisingly, they also secretly conspired with the Germans to provide them with secret proving grounds and test facilities to study some to the new technologies and approaches to war that would otherwise have been banned under provisions of the peace treaties of World War I.</p>
<p>So, when Civil War broke out in Spain in the summer of 1936, both Germany and the Soviet Union were positively delirious at the prospects of testing their new military equipment and theories out under battlefield conditions but, without the risks of participating in a real shooting war as an active belligerent.  So, both governments sent every military technology possible to their proxies in Spain under the auspices of &#8220;aid&#8221;.  In some cases they even sent &#8220;advisors&#8221; who were nothing less than active soldiers and pilots in the conflict.  At first, this activity took place under a shroud of secrecy.  But, when you send military equipment and people to fight in foreign lands it usually takes no time at all for someone to notice that, &#8220;those guys aren&#8217;t from here&#8221;.</p>
<p style="text-align: center;"><em><img class="alignnone" title="Bomber During Spanish Civil War" src="http://farm4.static.flickr.com/3599/3367016917_c954a9b07b.jpg?v=0" alt="" width="363" height="500" /></em></p>
<p style="text-align: center;"><em>Bomber During the Spanish Civil War photo by <a title="Link to -Merce-'s photostream" rel="dc:creator cc:attributionURL" href="http://www.flickr.com/photos/merceblanco/"><strong>-Merce-</strong></a>.  Military aviation, bombing in particular, was one of the new technologies that was tested during the Spanish Civil War.</em></p>
<p>Since the fall of the Soviet Union, I think the world has looked at the United States as the world&#8217;s sole superpower.  Many, view this situation with fear and suspicion.  Even some of our former Cold War allies have taken this view.  Certainly our primary Cold War adversaries have adopted this stance.  If you look at contemporary Chinese and Russian military writing it is clear that they have adopted a position similar to the pre- World War II notion that war between the US and Russia or war between the US and China is inevitable.  To make matters worse, during much of the Cold War the US never seemed to pull it together militarily long enough to actually win a war.  Toward the end of the Cold War we started smacking smaller allies of the Soviet Union like Grenada and succeeded.</p>
<p>We then moved on to give Iraq a real drubbing after the Cold War.  The so-call &#8220;Hyperwar&#8221; in Iraq terrified the Russians and Chinese alike.  The more they studied what we did in Iraq the more terrified they became.  On of the many counters they have written about is posing asymmetric threats to the US, that is to say threatening the US in a way in which it is uniquely, or unusually vulnerable. One of these areas of vulnerability is Cyberspace. All sorts of press reporting indicate that the Russians and Chinese have made significant investments in this area.  The Russians and Chinese deny these reports as quickly as they emerge.  So, it is difficult to determine what the truth is.  The fact that the Russians and Chinese are so sensitive to these claims may be a clear indication that they have active programs – the guilty men in these cases have a clear record of protesting to much when they are most guilty.</p>
<p>Assuming that all of this post-Cold War activity is true, I believe this puts us in much the same situation that existed in the pre-World War II Spanish Civil War era.  I think the Russian and Chinese governments are just itching to test and refine their Cyberwarfare capabilities.  But, at the same time I think they want to operate in a manner similar to how the Germans and the Soviet Union operated in that conflict.  I think they want and are testing their capabilities but in a limited way that provides them with some deniability and diplomatic cover.  This is important to them because the last thing they want now is to create a Cyber-incident that will precipitate a general conflict or even a major shift in diplomatic or trade relationships.</p>
<p>One of the major differences between the Spanish Civil War example and our current situation of course is that there is no need for a physical battlefield to exist to provide as a live testing environment for Cyber weapons and techniques.  However, at least in the case of Russia with respect to Georgia, they are exploiting open military conflicts to use Cyberwar techniques when those conflicts do arise.  We have seen similar, but much smaller efforts on the part of Iran, and the Palestinian Authority as embrace what is seen as a cheap and low risk weapon.  However, their efforts seem to be more reactionary and rudimentary.  The point is, the longer this game goes on without serious consequence the more it will escalate both vertically (in sophistication) and horizontally (be embraced by more countries).  Where all of this will lead is anyone guess.  But, I think the safe money is betting that the concept of Cyberwar is here to stay and eventually the tools and techniques and full potential of Cyberwar will eventually be used as part of as part of a strategy including more traditional weapons and techniques.</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1139').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1139" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1139" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1139&amp;title=The+Spanish+Civil+War+and+the+Rise+of+Cyberwar" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1139&amp;title=The+Spanish+Civil+War+and+the+Rise+of+Cyberwar" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1139" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=The+Spanish+Civil+War+and+the+Rise+of+Cyberwar&amp;url=http://www.guerilla-ciso.com/archives/1139&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1139&amp;title=The+Spanish+Civil+War+and+the+Rise+of+Cyberwar" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1139&amp;h=The+Spanish+Civil+War+and+the+Rise+of+Cyberwar" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1139&amp;title=The+Spanish+Civil+War+and+the+Rise+of+Cyberwar" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1139&amp;title=The+Spanish+Civil+War+and+the+Rise+of+Cyberwar" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1139&amp;title=The+Spanish+Civil+War+and+the+Rise+of+Cyberwar" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1139" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=The+Spanish+Civil+War+and+the+Rise+of+Cyberwar&amp;link_href=http://www.guerilla-ciso.com/archives/1139" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1139" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1139&amp;t=The+Spanish+Civil+War+and+the+Rise+of+Cyberwar" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1139').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1139').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=LaN5PtkuTAg:L2ZGnsjwisQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=LaN5PtkuTAg:L2ZGnsjwisQ:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=LaN5PtkuTAg:L2ZGnsjwisQ:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/LaN5PtkuTAg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1139/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1139</feedburner:origLink></item>
		<item>
		<title>Desperately Seeking a Cybersecurity Czar^wCoordinator</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/CbRvYixtJvg/1122</link>
		<comments>http://www.guerilla-ciso.com/archives/1122#comments</comments>
		<pubDate>Thu, 18 Jun 2009 12:54:13 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[IKANHAZFIZMA]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[lolcats]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1122</guid>
		<description><![CDATA[Well, we have half a bazillion people saying that we need a Cybersecurity person of some sort at the White House, but nobody&#8217;s stepped up to take the job and to be honest, I don&#8217;t anybody wants it all that badly. It might be time to call out for real heroes.



Bookmark to:


















Hide Sites



$$('div.d1122').each( function(e) { [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;">Well, we have half a bazillion people saying that we need a Cybersecurity person of some sort at the White House, but nobody&#8217;s stepped up to take the job and to be honest, I don&#8217;t anybody wants it all that badly. It might be time to call out for real heroes.</p>
<p style="text-align: center;"><a href="http://cheezburger.com/view.aspx?ciid=4463506"><img class="aligncenter" src="http://images.cheezburger.com/completestore/2009/6/17/128897674225106080.jpg" alt="funny pictures" /></a></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1122').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1122" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1122" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1122&amp;title=Desperately+Seeking+a+Cybersecurity+Czar%5EwCoordinator" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1122&amp;title=Desperately+Seeking+a+Cybersecurity+Czar%5EwCoordinator" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1122" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Desperately+Seeking+a+Cybersecurity+Czar%5EwCoordinator&amp;url=http://www.guerilla-ciso.com/archives/1122&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1122&amp;title=Desperately+Seeking+a+Cybersecurity+Czar%5EwCoordinator" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1122&amp;h=Desperately+Seeking+a+Cybersecurity+Czar%5EwCoordinator" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1122&amp;title=Desperately+Seeking+a+Cybersecurity+Czar%5EwCoordinator" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1122&amp;title=Desperately+Seeking+a+Cybersecurity+Czar%5EwCoordinator" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1122&amp;title=Desperately+Seeking+a+Cybersecurity+Czar%5EwCoordinator" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1122" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=Desperately+Seeking+a+Cybersecurity+Czar%5EwCoordinator&amp;link_href=http://www.guerilla-ciso.com/archives/1122" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1122" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1122&amp;t=Desperately+Seeking+a+Cybersecurity+Czar%5EwCoordinator" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1122').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1122').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=CbRvYixtJvg:EgmQM1IgFao:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=CbRvYixtJvg:EgmQM1IgFao:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=CbRvYixtJvg:EgmQM1IgFao:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/CbRvYixtJvg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1122/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1122</feedburner:origLink></item>
		<item>
		<title>A Short History of Cyberwar Lookalikes</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/Hvd5hYY8vNI/806</link>
		<comments>http://www.guerilla-ciso.com/archives/806#comments</comments>
		<pubDate>Thu, 18 Jun 2009 01:30:26 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[Technical]]></category>

		<category><![CDATA[The Guerilla CISO]]></category>

		<category><![CDATA[What Doesn't Work]]></category>

		<category><![CDATA[What Works]]></category>

		<category><![CDATA[cashcows]]></category>

		<category><![CDATA[cybercommand]]></category>

		<category><![CDATA[cybercorps]]></category>

		<category><![CDATA[cyberwar]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[infosec]]></category>

		<category><![CDATA[infosharing]]></category>

		<category><![CDATA[itsatrap]]></category>

		<category><![CDATA[moneymoneymoney]]></category>

		<category><![CDATA[pwnage]]></category>

		<category><![CDATA[risk]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=806</guid>
		<description><![CDATA[Rybolov&#8217;s Note: Hello all, I&#8217;m venturing into an open-ended series of blog posts aimed at starting conversation.  Note that I&#8217;m not selling anything *yet* but ideas and maybe some points for discussion.
Let&#8217;s get this out there from the very beginning: I agree with Ranum that full-scale, nation-v/s-nation Cyberwar is not a reality.  Not yet [...]]]></description>
			<content:encoded><![CDATA[<p><em>Rybolov&#8217;s Note: Hello all, I&#8217;m venturing into an open-ended series of blog posts aimed at starting conversation.  Note that I&#8217;m not selling anything *yet* but ideas and maybe some points for discussion.</em></p>
<p>Let&#8217;s get this out there from the very beginning: I agree with Ranum that full-scale, nation-v/s-nation Cyberwar is not a reality.  Not yet anyway, and hopefully it never will be.  However, on a smaller scale with well-defined objectives, cyberwar is not only happening now, but it is also a natural progression over the past century.</p>
<div align="center">
<object width="400" height="300"><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=3519680&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0&amp;color=&amp;fullscreen=1" /><embed src="http://vimeo.com/moogaloop.swf?clip_id=3519680&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0&amp;color=&amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="400" height="300"></embed></object>
<p><a href="http://vimeo.com/3519680">DojoSec Monthly Briefings - March 2009 - Marcus J. Ranum</a> from <a href="http://vimeo.com/marcuscarey">Marcus Carey</a> on <a href="http://vimeo.com">Vimeo</a>.</p>
</div>
<p>Looking at where we&#8217;re coming from in the existing models and techniques for activities similar to cyberwar, it frames our present state very nicely :</p>
<p style="padding-left: 30px;"><strong>Electronic Countermeasures.</strong> This has been <a href="http://en.wikipedia.org/wiki/Electronic_countermeasures" target="_blank">happening for some time</a>.  The first recorded use of electronic countermeasures (ECM) was in 1905 when the Russians tried to <a href="http://en.wikipedia.org/wiki/Siege_of_Port_Arthur" target="_blank">jam radio signals of the Japananese fleet besieging Port Arthur</a>.  If you think about ECM as DOS based on radio, sonar, etc, then it seems like cyberwar is just an extension of the same denial of communications that we&#8217;ve been doing since communication was &#8220;invented&#8221;.</p>
<p style="padding-left: 30px;"><strong>Modern Tactical Collection and Jamming.</strong> This is where Ranum&#8217;s point about spies and soldiers falls apart, mostly because we don&#8217;t have clandestine operators doing electronic collection at the tactical level&#8211;they&#8217;re doing both collection and &#8220;attack&#8221;.  The typical battle flow goes something along the lines of scanning for items of interest, collecting on a specific target, then jamming once hostilities have begun.  Doctrinally, <a href="http://en.wikipedia.org/wiki/Electronic_warfare" target="_blank">collection is called Electronic Support and jamming is called Electronic Attack</a>.  What you can expect in a cyberwar is a period of reconnaissance and surveillance for an extended length of time followed by &#8220;direct action&#8221; during other &#8220;kinetic&#8221; hostilities.</p>
<p style="padding-left: 30px;"><strong>Radio Station Jamming.</strong> This is a wonderful little world that most of you never knew existed.  The Warsaw Pact used to <a href="http://en.wikipedia.org/wiki/Radio_jamming#Cold_War_era" target="_blank">jam Radio America</a> and other sorts of fun propaganda that we would send at them.  Apparently we&#8217;ve had some interesting radio jamming since the end of the Cold War, with China, Cuba, North Korea, and South Korea implicated in some degree or another.</p>
<p style="padding-left: 30px;"><strong>Website Denial-of-Service.</strong> Since only old people listen to radio anymore and most news is on the Internet, so it makes sense to DOS news sites with an opposing viewpoint.  This happens all the time, with attacks ranging from script kiddies doing ping floods to massive DOSBots and some kind of racketeering action&#8230; &#8220;You got a nice website, it would be pretty bad if nobody could see it.&#8221;  Makes me wonder why the US hasn&#8217;t taken Al Jazeera off the Internet.  Oh, that&#8217;s right, <a href="http://www.infoworld.com/t/applications/al-jazeera-hobbled-ddos-attack-495" target="_blank">somebody already tried it</a>.  However, in my mind, jamming something like Al Jazeera is very comparable to jamming Voice of America.</p>
<p style="padding-left: 30px;"><strong>Estonia and Gruzija DOS.</strong> These worked pretty well from a denial-of-communications standpoint, but only because of the size of the target.  And so what if it did block the Internet, when it comes to military forces, it&#8217;s at best an annoyance, at most it will slow you down just enough.  Going back to radio jamming, blocking out a signal only works when you have more network to throw at the target than the target has network to communicate with the other end.  Believe it or not, there are calculators to determine this.</p>
<p>Given this evolution of communications denial, it&#8217;s not unthinkable that people wouldn&#8217;t be launching electronic attacks at each other via radar, radio, carrier pigeon, IP or any other way they can.</p>
<p>However, as in the previous precedents and more to some of the points of Ranum&#8217;s talk at DojoSec, electronic attacks by themselves only achieve limited objectives.  Typically the most likely type of attack is to conduct a physical attack and use the electronic attack, whether it&#8217;s radio, radar, or IT assets, to delay the enemy&#8217;s response.  This is why you have to take an electronic attack seriously if it&#8217;s being launched by a country which has a military capable of attacking you physically&#8211;it might be just a jamming attack, it might be a precursor to an invasion.</p>
<p>Bottom line here is this: if you use it for communication, it&#8217;s a target and has been for some time.</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d806').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d806" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/806" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/806&amp;title=A+Short+History+of+Cyberwar+Lookalikes" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/806&amp;title=A+Short+History+of+Cyberwar+Lookalikes" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/806" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=A+Short+History+of+Cyberwar+Lookalikes&amp;url=http://www.guerilla-ciso.com/archives/806&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/806&amp;title=A+Short+History+of+Cyberwar+Lookalikes" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/806&amp;h=A+Short+History+of+Cyberwar+Lookalikes" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/806&amp;title=A+Short+History+of+Cyberwar+Lookalikes" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/806&amp;title=A+Short+History+of+Cyberwar+Lookalikes" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/806&amp;title=A+Short+History+of+Cyberwar+Lookalikes" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/806" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=A+Short+History+of+Cyberwar+Lookalikes&amp;link_href=http://www.guerilla-ciso.com/archives/806" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/806" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/806&amp;t=A+Short+History+of+Cyberwar+Lookalikes" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d806').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d806').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=Hvd5hYY8vNI:BKhbrFS8aI0:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=Hvd5hYY8vNI:BKhbrFS8aI0:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=Hvd5hYY8vNI:BKhbrFS8aI0:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/Hvd5hYY8vNI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/806/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/806</feedburner:origLink></item>
		<item>
		<title>Cyber-Ninja Lolcats Caught on Film</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/i1EpAIHTz8c/1104</link>
		<comments>http://www.guerilla-ciso.com/archives/1104#comments</comments>
		<pubDate>Thu, 11 Jun 2009 19:53:53 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[IKANHAZFIZMA]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[infosec]]></category>

		<category><![CDATA[lolcats]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1104</guid>
		<description><![CDATA[After the presentation of a ninja last year at Daycon, I needed a break from IT ninjas.  A year later, however, I seem to have captured a picture of a cyber-ninja lolcat.



Bookmark to:


















Hide Sites



$$('div.d1104').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); ]]></description>
			<content:encoded><![CDATA[<p>After the presentation of a ninja last year at Daycon, I needed a break from IT ninjas.  A year later, however, I seem to have captured a picture of a cyber-ninja lolcat.</p>
<p style="text-align: center;"><a href="http://cheezburger.com/view.aspx?ciid=4409472"><img class="aligncenter" src="http://images.cheezburger.com/completestore/2009/6/11/128892235146203765.jpg" alt="funny pictures" /></a></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1104').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1104" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1104" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1104&amp;title=Cyber-Ninja+Lolcats+Caught+on+Film" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1104&amp;title=Cyber-Ninja+Lolcats+Caught+on+Film" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1104" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Cyber-Ninja+Lolcats+Caught+on+Film&amp;url=http://www.guerilla-ciso.com/archives/1104&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1104&amp;title=Cyber-Ninja+Lolcats+Caught+on+Film" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1104&amp;h=Cyber-Ninja+Lolcats+Caught+on+Film" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1104&amp;title=Cyber-Ninja+Lolcats+Caught+on+Film" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1104&amp;title=Cyber-Ninja+Lolcats+Caught+on+Film" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1104&amp;title=Cyber-Ninja+Lolcats+Caught+on+Film" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1104" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=Cyber-Ninja+Lolcats+Caught+on+Film&amp;link_href=http://www.guerilla-ciso.com/archives/1104" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1104" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1104&amp;t=Cyber-Ninja+Lolcats+Caught+on+Film" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1104').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1104').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=i1EpAIHTz8c:mNUG2AeGsok:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=i1EpAIHTz8c:mNUG2AeGsok:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=i1EpAIHTz8c:mNUG2AeGsok:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/i1EpAIHTz8c" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1104/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1104</feedburner:origLink></item>
		<item>
		<title>Privacy Camp DC on June 20th</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/5L12rqM1Wbs/1101</link>
		<comments>http://www.guerilla-ciso.com/archives/1101#comments</comments>
		<pubDate>Thu, 11 Jun 2009 11:19:01 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[Public Policy]]></category>

		<category><![CDATA[Speaking]]></category>

		<category><![CDATA[collusion]]></category>

		<category><![CDATA[datacentric]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[infosec]]></category>

		<category><![CDATA[infosharing]]></category>

		<category><![CDATA[law]]></category>

		<category><![CDATA[legislation]]></category>

		<category><![CDATA[privacy]]></category>

		<category><![CDATA[publicpolicy]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[seminar]]></category>

		<category><![CDATA[speaking]]></category>

		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1101</guid>
		<description><![CDATA[Saturday, June 20, 2009 from 8:00 AM - 5:00 PM (ET) in downtown DC.
I&#8217;ll be going.  This will be a &#8220;Bar Camp Stylie&#8221; event, where you&#8217;re not just an attendee, you&#8217;re also a volunteer to make it all happen.  You might end up running a conversation on your favorite privacy topic, so you have been [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://privacycampdc09.eventbrite.com/" target="_blank"><img class="alignnone" title="Privacy Camp DC" src="http://images.eventbrite.com/logos/337395158.jpg" alt="" width="450" height="80" /></a></p>
<p><a href="http://privacycampdc09.eventbrite.com/" target="_blank">Saturday, June 20, 2009 from 8:00 AM - 5:00 PM (ET) in downtown DC.</a></p>
<p>I&#8217;ll be going.  This will be a <a href="http://barcamp.org/WhatToExpect" target="_blank">&#8220;Bar Camp Stylie&#8221;</a> event, where you&#8217;re not just an attendee, you&#8217;re also a volunteer to make it all happen.  You might end up running a conversation on your favorite privacy topic, so you have been warned. =)</p>
<p>*Most* of the folks going are of the civil libertarian slant.  With my background and where I work, I usually &#8220;bat for the other team on this issue&#8221;.  The organizers have assured me that I&#8217;ll be welcome and can play the heretic role.</p>
<p>How to play:</p>
<ul>
<li><a href="http://privacycampdc09.eventbrite.com/" target="_blank">Sign up here.</a></li>
<li><a href="http://barcamp.org/PrivacyCampDC" target="_blank">Check out the wiki, help out with preparation.</a></li>
<li><a href="http://twitter.com/PrivacyCampDC" target="_blank">Follow @PrivacyCampDC on twitter</a></li>
<li>Be a sponsor.</li>
</ul>
<p>Some themes that I&#8217;ve seen develop so far:</p>
<ul>
<li>How some concepts (System of Record) from the Privacy Act are outdated or at least showing their age</li>
<li>How the open government &#8220;movement&#8221; and the push for raw data means we need to look at the privacy concerns</li>
<li>FOIA and privacy data</li>
<li>Ending the political robocalls</li>
</ul>
<p><strong>See Y&#8217;all there!</strong></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1101').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1101" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1101" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1101&amp;title=Privacy+Camp+DC+on+June+20th" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1101&amp;title=Privacy+Camp+DC+on+June+20th" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1101" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Privacy+Camp+DC+on+June+20th&amp;url=http://www.guerilla-ciso.com/archives/1101&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1101&amp;title=Privacy+Camp+DC+on+June+20th" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1101&amp;h=Privacy+Camp+DC+on+June+20th" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1101&amp;title=Privacy+Camp+DC+on+June+20th" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1101&amp;title=Privacy+Camp+DC+on+June+20th" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1101&amp;title=Privacy+Camp+DC+on+June+20th" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1101" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=Privacy+Camp+DC+on+June+20th&amp;link_href=http://www.guerilla-ciso.com/archives/1101" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1101" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1101&amp;t=Privacy+Camp+DC+on+June+20th" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1101').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1101').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=5L12rqM1Wbs:DlGU-02sK1o:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=5L12rqM1Wbs:DlGU-02sK1o:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=5L12rqM1Wbs:DlGU-02sK1o:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/5L12rqM1Wbs" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1101/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1101</feedburner:origLink></item>
		<item>
		<title>Why We Need PCI-DSS to Survive</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/e5vavwqkfO0/1092</link>
		<comments>http://www.guerilla-ciso.com/archives/1092#comments</comments>
		<pubDate>Wed, 10 Jun 2009 02:26:41 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[Public Policy]]></category>

		<category><![CDATA[Rants]]></category>

		<category><![CDATA[auditor]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[infosec]]></category>

		<category><![CDATA[itsatrap]]></category>

		<category><![CDATA[law]]></category>

		<category><![CDATA[legislation]]></category>

		<category><![CDATA[management]]></category>

		<category><![CDATA[metrics]]></category>

		<category><![CDATA[pci-dss]]></category>

		<category><![CDATA[publicpolicy]]></category>

		<category><![CDATA[risk]]></category>

		<category><![CDATA[scalability]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1092</guid>
		<description><![CDATA[And by &#8220;We&#8221;, I mean the security industry as a whole.  And yes, this is your public-policy lesson for today, let me drag my soapbox over here and sit for a spell while I talk at you.
By &#8220;Survive&#8221;, I mean that we need some kind of self-regulatory framework that fulfills the niche that PCI-DSS occupies currently. Keep [...]]]></description>
			<content:encoded><![CDATA[<p>And by &#8220;We&#8221;, I mean the security industry as a whole.  And yes, this is your public-policy lesson for today, let me drag my soapbox over here and sit for a spell while I talk at you.</p>
<p>By &#8220;Survive&#8221;, I mean that we need some kind of self-regulatory framework that fulfills the niche that PCI-DSS occupies currently. Keep reading, I&#8217;ll explain.</p>
<p>And the &#8220;Why&#8221; is a magical phrase, everybody say it after me: <a href="http://en.wikipedia.org/wiki/Self-regulatory_organization" target="_blank">self-regulatory organization</a>.  In other words, the IT industry (and the Payment Card Industry) needs to regulate itself before it crosses the line into being considered for statutory regulation (ie, making a law) by the Federal Government.</p>
<p>Remember the <a href="http://hsc.house.gov/Hearings/index.asp?ID=185" target="_blank">PCI-DSS hearings</a> with the <a href="http://hsc.house.gov/" target="_blank">House Committe on Homeland Security</a> (AKA the Thompson Committee)?  All the <a href="http://www.security-twits.com/" target="_blank">Security Twits</a> were abuzz about it, and it did my heart great justice to hear all the cool kids become security and public policy wonks at least for an afternoon.  Well, there is a little secret here and that is that when Congress gets involved, they&#8217;re gathering information to determine if they need to regulate an industry.  That&#8217;s about all Congress can do: make laws that you (and the Executive Branch) have to follow, maybe divvy up some tax money, and bring people in to testify.  Other than that, it&#8217;s just positioning to gain favor with other politicians and maybe some votes in the next election.</p>
<p>Regulation means audits and more compliance.  They go together like TCP and IP.  Most regulatory laws have at least some designation for a party who will perform oversight.  They have to do this because, well, if you&#8217;re not audited/assessed/evaluated/whatever, then it&#8217;s really an optional law, which doesn&#8217;t make sense at all.</p>
<p style="text-align: center;"><em><img class="alignnone" title="Audits Rock!" src="http://farm3.static.flickr.com/2408/1764153258_11bbbcb337.jpg?v=0" alt="" width="500" height="375" /></em></p>
<p style="text-align: center;"><em>Yay Audits photo by </em><a title="Link to joebeone's photostream" rel="dc:creator cc:attributionURL" href="http://www.guerilla-ciso.com/photos/joebeone/"><strong><span style="color: #0063dc;"><em>joebeone</em></span></strong></a><em>.</em></p>
<p>Another magical phrase that the public policy sector can share with the information security world: audit burden.  Audit burden is how much a company or individual pays both in direct costs (paying the auditors) and in indirect costs (babysitting the auditors, producing evidence for the auditors, taking people away from making money to talk to auditors, &#8220;audit requirements&#8221;, etc).  I think we can all agree that low audit burden is good, high audit burden is bad.  In fact, I think that&#8217;s one of the problems with FISMA as implemented is that it has a high audit burden with moderately tangible results. But I digress, this post is about PCI-DSS.</p>
<p>There&#8217;s even a concept that is mulling around in the back of my head to make a metric that compares the audit burden to the amount of security that it provides to the amount of assurance that it provides against statutory regulation.  It almost sounds like the start of a balanced scorecard for security management frameworks, now if I could get @alexhutton to jump on it, his quant brain would churn out great things in short order.</p>
<p>But this is the lesson for today: self-regulation is preferrable to legislation.</p>
<ul>
<li>Self-regulation is defined by people in the industry.  Think about the State Bar Association setting the standards for who is allowed to practice law.</li>
<li>Standards ideally become codified versions of &#8220;best practices&#8221;.  OK, this is if they&#8217;re done correctly, more to follow.</li>
<li>Standards are more flexible than laws.  As hard/cumbersome as it is to change a standard, the time involved in changing a law is prohibitive most of the time unless you&#8217;re running for reelection.</li>
<li>Standards sometimes can be &#8220;tainted&#8221; to force out competition, laws are even more so.</li>
</ul>
<p>The sad fact here is that if we don&#8217;t figure out as an industry how to make PCI-DSS or any other forms of self-regulation work, Congress will regulate for us.  Don&#8217;t like PCI-DSS because of the audit burden, wait until you have a law that requires you to do the same controls framework.  It will be the same thing, only with bigger penalties for failure, larger audit burdens to avoid the larger penalties, larger industries created to satisfy the market demand for audit.  Come meet the new regulatory body, same as the old only bigger and meaner. =)</p>
<p>However, self-regulation works if you do it right, and by right I mean this:</p>
<ul>
<li>The process is transparent and not the product of a secret back-room cabbal.</li>
<li>Representation from all the shareholders.  For PCI-DSS, that would be Visa/MasterCard, banks, processors, large merchants, small merchants, and some of the actual customers.</li>
<li>The standards committee knows how to compromise and come to a consensus.  IE, we can&#8217;t have both full hard drive encryption, a WAF, code review, and sacrificing of chickens in the server room, so we&#8217;ll make one of the 4 mandatory.</li>
<li>The regulatory organization has a grievance process for its constituency to present valid (AKA &#8220;Not just more whining&#8221;) discrepencies in the standards and processes for clarification or consideration for change.</li>
<li>The standard is &#8220;owned&#8221; by every member of the constituency.  Right now, people governed by PCI-DSS are not feeling that the standard is <em>their</em> standard and that they have a say in what comprises the standard and that they are the ones being helped by the standard.  Some of that is true, some of that is an image problem.  The way you combat this is by doing the things that I mentioned in the previous bullets.</li>
</ul>
<p>Hmm, sounds like making an ISO standard, which brings its own set of politics.</p>
<p>While we need some form of self-regulation, right now PCI-DSS and ISO 27001 are the closest that we have in the private sector.  Yeah, it sucks, but it sucks the least, just like our form of government.</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1092').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1092" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1092" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1092&amp;title=Why+We+Need+PCI-DSS+to+Survive" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1092&amp;title=Why+We+Need+PCI-DSS+to+Survive" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1092" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Why+We+Need+PCI-DSS+to+Survive&amp;url=http://www.guerilla-ciso.com/archives/1092&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1092&amp;title=Why+We+Need+PCI-DSS+to+Survive" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1092&amp;h=Why+We+Need+PCI-DSS+to+Survive" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1092&amp;title=Why+We+Need+PCI-DSS+to+Survive" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1092&amp;title=Why+We+Need+PCI-DSS+to+Survive" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1092&amp;title=Why+We+Need+PCI-DSS+to+Survive" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1092" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=Why+We+Need+PCI-DSS+to+Survive&amp;link_href=http://www.guerilla-ciso.com/archives/1092" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1092" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1092&amp;t=Why+We+Need+PCI-DSS+to+Survive" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1092').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1092').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=e5vavwqkfO0:Q1m68rC8Deg:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=e5vavwqkfO0:Q1m68rC8Deg:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=e5vavwqkfO0:Q1m68rC8Deg:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/e5vavwqkfO0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1092/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1092</feedburner:origLink></item>
		<item>
		<title>Some Thoughts on POA&amp;M Abuse</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/wyiHSSxDE4s/1046</link>
		<comments>http://www.guerilla-ciso.com/archives/1046#comments</comments>
		<pubDate>Mon, 08 Jun 2009 20:40:11 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[BSOFH]]></category>

		<category><![CDATA[FISMA]]></category>

		<category><![CDATA[accreditation]]></category>

		<category><![CDATA[C&A]]></category>

		<category><![CDATA[certification]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[fisma]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[infosec]]></category>

		<category><![CDATA[management]]></category>

		<category><![CDATA[metrics]]></category>

		<category><![CDATA[risk]]></category>

		<category><![CDATA[scalability]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1046</guid>
		<description><![CDATA[Ack, Plans of Action and Milestones.  I love them and I hate them.
For those of you who &#8220;don&#8217;t habla Federali&#8221;, a POA&#38;M is basically an IOU from the system owner to the accreditor that yes, we will fix something but for some reason we can&#8217;t do it right now.  Usually these are findings from Security [...]]]></description>
			<content:encoded><![CDATA[<p>Ack, Plans of Action and Milestones.  I love them and I hate them.</p>
<p>For those of you who &#8220;don&#8217;t habla Federali&#8221;, a POA&amp;M is basically an IOU from the system owner to the accreditor that yes, we will fix something but for some reason we can&#8217;t do it right now.  Usually these are findings from Security Test and Evaluation (ST&amp;E) or Certification and Accreditation (C&amp;A).  In fact, some places I&#8217;ve worked, they won&#8217;t make new POA&amp;Ms unless they&#8217;re traceable back to ST&amp;E results.</p>
<p>Functions that a POA&amp;M fulfills:</p>
<ul>
<li>Issue tracking to resolution</li>
<li>Serves as a &#8220;risk register&#8221;</li>
<li>Used as the justification for budget</li>
<li>Generate mitigation metrics</li>
<li>Can be used for data-mining to find common vulnerabilities across systems</li>
</ul>
<p>But today, we&#8217;re going to talk about POA&amp;M abuse.  I&#8217;ve seen my fair share of this.</p>
<p><strong>Conflicting Goals:</strong> The basic problem is that we want POA&amp;Ms to satisfy too many conflicting functions.  IE, if we use the number of open POA&amp;Ms as a metric to determine if our system owners are doing their job and closing out issues but we also turn around and report these at an enterprise level to OMB or at the department level, then it&#8217;s a conflict of interest to get these closed as fast as possible, even if it means losing your ability to track things at the system level or to spend the time doing things that solve long-term security problems&#8211;our vulnerability/weakness/risk management process forces us into creating small, easily-to-satisfy POA&amp;Ms instead of long-term projects.</p>
<p><strong>Near-Term v/s Long-Term:</strong>  If we set up POA&amp;Ms with due dates of 30-60-90 (for high, moderate, and low risks) days, we don&#8217;t really have time at all to turn these POA&amp;Ms into budget support.  Well, if we manage the budget up to 3 years in advance and we have 90 days for high-risk findings, then that means we&#8217;ll have exactly 0 input into the budget from any POA&amp;M unless we can delay the bugger for 2 years or so, much too long for it to actually be fixable.</p>
<p><strong>Bad POA&amp;Ms:</strong>  Let&#8217;s face it, sometimes the one-for-one nature of ST&amp;E, C&amp;A, and risk assessment findings to POA&amp;Ms means that you get POA&amp;Ms that are &#8220;bad&#8221; and by that I mean that they can&#8217;t be satisfied or they&#8217;re not really something that you need to fix.</p>
<p>Some of the bad POA&amp;Ms I&#8217;ve seen, these are paraphrased from the original:</p>
<ul>
<li>The solution uses {Microsoft|Sun|Oracle} products which has a history of vulnerabilities.</li>
<li>The project team needs to tell the vendor to put IPV6 into their product roadmap</li>
<li>The project team needs to implement X which is a common control provided at the enterprise level</li>
<li>The System Owner and DAA have accepted this risk but we&#8217;re still turning it into a POA&amp;M</li>
<li>This is a common control that we really should handle at the enterprise level but we&#8217;re putting it on your POA&amp;M list for a simple web application</li>
</ul>
<p style="text-align: center;"><em><img class="alignnone" title="Plan of Action" src="http://farm4.static.flickr.com/3439/3194105413_c4c4d81501.jpg?v=0" alt="" width="500" height="500" /></em></p>
<p style="text-align: center;"><em>Plan of Action for Refresh Philly photo by </em><a title="Link to jonny goldstein's photostream" rel="dc:creator cc:attributionURL" href="http://www.guerilla-ciso.com/photos/jonnygoldstein/"><strong><span style="color: #0063dc;"><em>jonny goldstein</em></span></strong></a><em>.</em></p>
<p><strong>Keys to POA&amp;M Nirvana:</strong>  So over the years, I&#8217;ve observed some techniques for success in working with POA&amp;Ms:</p>
<ul>
<li>Agree on the evidence/proof of POA&amp;M closure when the POA&amp;M is created</li>
<li>Fix it before it becomes a POA&amp;M</li>
<li>Have a waiver or exception process that requires a cost-benefit-risk analysis</li>
<li>Start with&#8221;high-level&#8221; POA&amp;Ms and work down to more detailed POA&amp;Ms as your security program matures</li>
<li>POA&amp;Ms are between the System Owner and the DAA, but the System Owner can turn around and negotiate a POA&amp;M as a cedural with an outsourced IT provider</li>
</ul>
<p>And then the keys to Building Good POA&amp;Ms:</p>
<ul>
<li>Actionable&#8211;ie, they have something that you need to do</li>
<li>Achievable&#8211;they can be accomplished</li>
<li>Demonstrable&#8211;you can demonstrate that the POA&amp;M has been satisfied</li>
<li>Properly-Scoped&#8211;absorbed at the agency level, the common control level, or the system level</li>
<li>They are SMART: <strong>S</strong>pecific, <strong>M</strong>anageable, <strong>A</strong>ttainable, <strong>R</strong>elevant, and within a specified <strong>T</strong>imeframe</li>
<li>They are DUMB: <strong>D</strong>oable, <strong>U</strong>nderstandable, <strong>M</strong>anageable, and <strong>B</strong>eneficial</li>
</ul>
<p>Yes, I stole the last 2 bullets from the picture above, but they make really good sense in a way that &#8220;know thyself&#8221; is awesome advice from the Oracle at Delphi.</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1046').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1046" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1046" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1046&amp;title=Some+Thoughts+on+POA%26%23038%3BM+Abuse" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1046&amp;title=Some+Thoughts+on+POA%26%23038%3BM+Abuse" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1046" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Some+Thoughts+on+POA%26%23038%3BM+Abuse&amp;url=http://www.guerilla-ciso.com/archives/1046&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1046&amp;title=Some+Thoughts+on+POA%26%23038%3BM+Abuse" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1046&amp;h=Some+Thoughts+on+POA%26%23038%3BM+Abuse" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1046&amp;title=Some+Thoughts+on+POA%26%23038%3BM+Abuse" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1046&amp;title=Some+Thoughts+on+POA%26%23038%3BM+Abuse" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1046&amp;title=Some+Thoughts+on+POA%26%23038%3BM+Abuse" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1046" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=Some+Thoughts+on+POA%26%23038%3BM+Abuse&amp;link_href=http://www.guerilla-ciso.com/archives/1046" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1046" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1046&amp;t=Some+Thoughts+on+POA%26%23038%3BM+Abuse" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1046').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1046').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=wyiHSSxDE4s:p_0DPTZJsX8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=wyiHSSxDE4s:p_0DPTZJsX8:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=wyiHSSxDE4s:p_0DPTZJsX8:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/wyiHSSxDE4s" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1046/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1046</feedburner:origLink></item>
		<item>
		<title>Working with Interpreters, a Risk Manager’s Guide</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/zn9S1dKz_d8/1075</link>
		<comments>http://www.guerilla-ciso.com/archives/1075#comments</comments>
		<pubDate>Thu, 04 Jun 2009 02:31:50 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[Army]]></category>

		<category><![CDATA[Risk Management]]></category>

		<category><![CDATA[The Guerilla CISO]]></category>

		<category><![CDATA[What Works]]></category>

		<category><![CDATA[afghanistan]]></category>

		<category><![CDATA[infosharing]]></category>

		<category><![CDATA[interpreters]]></category>

		<category><![CDATA[itsatrap]]></category>

		<category><![CDATA[management]]></category>

		<category><![CDATA[pwnage]]></category>

		<category><![CDATA[risk]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1075</guid>
		<description><![CDATA[So how does the Guerilla-CISO staff communicate with the locals on jaunts to foreign lands such as Deleware, New Jersey, and Afghanistan?  The answer is simple, we use interpreters, known in infantrese as &#8220;terps&#8221;.  Yes, you might not trust them deep down inside because they harbor all kinds of loyalties so complex that you can [...]]]></description>
			<content:encoded><![CDATA[<p>So how does the Guerilla-CISO staff communicate with the locals on jaunts to foreign lands such as Deleware, New Jersey, and Afghanistan?  The answer is simple, we use interpreters, known in <em>infantrese</em> as &#8220;terps&#8221;.  Yes, you might not trust them deep down inside because they harbor all kinds of loyalties so complex that you can spend the rest of your life figuring out, but you can&#8217;t do the job without them.</p>
<p>But in remembering how we used our interpreters, I&#8217;m reminded of some basic concepts that might be transferable to the IT security and risk management world.  Or maybe not, at least kick back and enjoy the storytelling while it&#8217;s free. =)</p>
<p><strong>Know When to Treat Them Like Mushrooms:</strong> And by that, we mean &#8220;keep them in the dark and feed them bullsh*t&#8221;.  What really mean is to tell potentially adversarial people that you&#8217;re working with the least amount of information that they need to do their job in order to limit the frequency and impact of them doing something nasty.  When you&#8217;re planning a patrol, the worst way to ruin your week is to tell the terps when you&#8217;re leaving and where you&#8217;re going.  That way, they can call their Taliban friends when you&#8217;re not looking and they&#8217;ll have a surprise waiting for you.  No, it won&#8217;t be a birthday cake.  The way I would get a terp is that one would be assigned to me by our battalion staff and the night before the patrol I would tell the specific terp that we were leaving in the morning, give them a time that I would come by to check up on them, and that they would need to bring enough gear for 5 days.  Before they got into my vehicles and we rolled away, I would look through their gear to make sure they didn&#8217;t have any kind of communications device (radio or telephone) to let their buddies know where we were at.</p>
<p><strong>Fudge the Schedule to Minimize Project Risk:</strong> Terps&#8211;even the good ones&#8211;are notorious for being on &#8220;local time&#8221;, which for a patrol means one hour later than you told them you were leaving.  The good part about this is that it&#8217;s way better than true local time, which has a margin of error of a week and a half.  In order to keep from being late, always tell the terps when you&#8217;ll need them an hour and a half before you really do, then check up on them every half hour or so.  Out on patrol, I would cut that margin down to half an hour because they didn&#8217;t have all the typical distractions to make them late.</p>
<p><strong>Talk Slowly, Avoid Complex Sentences:</strong> The first skill to learn when using terps is to say things that their understanding of English can handle.  When they&#8217;re doing their job for you, simple sentences works best.  I know I&#8217;m walking down the road of heresy, but this is where quantitative risk assessment <em>done poorly</em> doesn&#8217;t work for me because now I something that&#8217;s entirely too complex to interpret to the non-IT crowd.  In fact, it probably is worse than no risk assessment at all because it comes accross as &#8220;consultantspeak&#8221; with no tangible link back to reality.</p>
<p><strong>Put Your Resources Where the Greatest Risk Is: </strong> To a vehicle patrol out in the desert, most of the action happens at the front of the patrol.  That&#8217;s where you need a terp.  That way, the small stuff, such as asking a local farmer to move his goats and sheep out of the road so you can drive through, stays small&#8211;without a terp up front, a 2-minute conversation becomes 15 minutes of hassle as you first have to get the terp up to the front of the patrol then tell them what&#8217;s going on.</p>
<p><strong>Pigs, Chicken, and Roadside Bombs: </strong>We all know the story about how in the eggs and bacon breakfast, the chicken is a participant but the pig is committed.  Well, when I go on a patrol with a terp, I want them to be committed.  That means riding in the front vehicle with me.  It&#8217;s my &#8220;poison pill&#8221; defense in knowing that if my terp tipped off the Taliban and they blow up the lead vehicle with me in it, at least they would also get the terp.  A little bit of risk-sharing in a venture goes a long way at getting honesty out of people.</p>
<p><strong>Share Risk in a Culturally-Acceptable Way:</strong> Our terps would balk at the idea of riding in the front vehicle most of the time.  I don&#8217;t blame them, it&#8217;s the vehicle most likely to be turned into 2 tons of slag metal thanks to pressure plates hooked up to IEDs.  The typical American response is something along the lines of &#8220;It&#8217;s your country, you&#8217;re riding up front with me so if I get blown up, you do to&#8221;.  Yes, I share that ideal, but the Afghanis don&#8217;t understand country loyalties, the only thing they understand is their tribe, their village, and their family.  The Guerilla-CISO method here is to get down inside their heads by saying &#8220;Come ride with me, if we die, we die together like brothers&#8221;.  You&#8217;re saying the same thing basically but you&#8217;re framing it in a cultural context that they can&#8217;t say no to.</p>
<p><strong>Reward People Willing to Embrace Your Risks: </strong> One of the ways that I was effective in dealing with the terps was that I would check in occassionally to see if they were doing alright during down-time from missions.  They would show me some Bollywood movies dubbed into Pashto, I would give them fatty American foods (Little Debbie FTW!).  They would play their music.  I would make fun of their music and amaze them because they never figured out how I knew that the song had drums, a stringed instrument, and somebody singing (hey, all their favorite songs have that).  They would share their &#8220;foot bread&#8221; (the bread is stamped flat by people walking on it before it&#8217;s cooked, I was too scared to ask if they washed their feet first) with me.  I would teach them how to say &#8220;Barbara (their assignment scheduler back on an airbase) was a <strong>&lt;censored&gt;</strong> for putting them out in the middle of nowhere on this assignment&#8221; and other savory phrases.  These forays weren&#8217;t for my own enjoyment, but to build rapport with the terps so that they would understand when I would give them some risk management love, Guerilla-CISO style.</p>
<p style="text-align: center;"><em><img class="alignnone" title="Police, Afghan Army and an Interpreter" src="http://farm4.static.flickr.com/3148/2895035735_cb15d00c17.jpg?v=0" alt="" width="500" height="375" /></em></p>
<p style="text-align: center;"><em>Police, Afghan Army and an Interpreter photo by <a href="http://www.flickr.com/photos/rybolov/" target="_blank">ME!</a>.  The guy in the baseball cap and glasses is one of the best terps I ever worked with.</em></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1075').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1075" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1075" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1075&amp;title=Working+with+Interpreters%2C+a+Risk+Manager%26%238217%3Bs+Guide" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1075&amp;title=Working+with+Interpreters%2C+a+Risk+Manager%26%238217%3Bs+Guide" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1075" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Working+with+Interpreters%2C+a+Risk+Manager%26%238217%3Bs+Guide&amp;url=http://www.guerilla-ciso.com/archives/1075&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1075&amp;title=Working+with+Interpreters%2C+a+Risk+Manager%26%238217%3Bs+Guide" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1075&amp;h=Working+with+Interpreters%2C+a+Risk+Manager%26%238217%3Bs+Guide" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1075&amp;title=Working+with+Interpreters%2C+a+Risk+Manager%26%238217%3Bs+Guide" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1075&amp;title=Working+with+Interpreters%2C+a+Risk+Manager%26%238217%3Bs+Guide" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1075&amp;title=Working+with+Interpreters%2C+a+Risk+Manager%26%238217%3Bs+Guide" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1075" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=Working+with+Interpreters%2C+a+Risk+Manager%26%238217%3Bs+Guide&amp;link_href=http://www.guerilla-ciso.com/archives/1075" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1075" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1075&amp;t=Working+with+Interpreters%2C+a+Risk+Manager%26%238217%3Bs+Guide" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1075').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1075').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=zn9S1dKz_d8:yWr82lahT30:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=zn9S1dKz_d8:yWr82lahT30:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=zn9S1dKz_d8:yWr82lahT30:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/zn9S1dKz_d8" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1075/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1075</feedburner:origLink></item>
		<item>
		<title>LOLCATS and the 60-Day Cybersecurity Review</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/57-zTLonO54/1059</link>
		<comments>http://www.guerilla-ciso.com/archives/1059#comments</comments>
		<pubDate>Thu, 28 May 2009 21:43:38 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[IKANHAZFIZMA]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[infosec]]></category>

		<category><![CDATA[infosharing]]></category>

		<category><![CDATA[lolcats]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[transition]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1059</guid>
		<description><![CDATA[Ooh ooh, the review is supposed to be announced tomorrow!



Bookmark to:


















Hide Sites



$$('div.d1059').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); ]]></description>
			<content:encoded><![CDATA[<p>Ooh ooh, the review is supposed to be announced tomorrow!</p>
<p style="text-align: center;"><a href="http://cheezburger.com/view.aspx?ciid=4294344"><img class="aligncenter" src="http://images.icanhascheezburger.com/completestore/2009/5/28/128880204198941061.jpg" alt="funny pictures" /></a></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1059').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1059" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1059" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1059&amp;title=LOLCATS+and+the+60-Day+Cybersecurity+Review" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1059&amp;title=LOLCATS+and+the+60-Day+Cybersecurity+Review" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1059" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=LOLCATS+and+the+60-Day+Cybersecurity+Review&amp;url=http://www.guerilla-ciso.com/archives/1059&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1059&amp;title=LOLCATS+and+the+60-Day+Cybersecurity+Review" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1059&amp;h=LOLCATS+and+the+60-Day+Cybersecurity+Review" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1059&amp;title=LOLCATS+and+the+60-Day+Cybersecurity+Review" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1059&amp;title=LOLCATS+and+the+60-Day+Cybersecurity+Review" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1059&amp;title=LOLCATS+and+the+60-Day+Cybersecurity+Review" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1059" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=LOLCATS+and+the+60-Day+Cybersecurity+Review&amp;link_href=http://www.guerilla-ciso.com/archives/1059" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1059" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1059&amp;t=LOLCATS+and+the+60-Day+Cybersecurity+Review" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1059').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1059').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=57-zTLonO54:QD02RsT--Ak:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=57-zTLonO54:QD02RsT--Ak:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=57-zTLonO54:QD02RsT--Ak:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/57-zTLonO54" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1059/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1059</feedburner:origLink></item>
		<item>
		<title>When Standards Aren’t Good Enough</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/NNkiLOLjiRg/1035</link>
		<comments>http://www.guerilla-ciso.com/archives/1035#comments</comments>
		<pubDate>Fri, 22 May 2009 13:52:46 +0000</pubDate>
		<dc:creator>Vlad the Impaler</dc:creator>
		
		<category><![CDATA[Rants]]></category>

		<category><![CDATA[Risk Management]]></category>

		<category><![CDATA[Technical]]></category>

		<category><![CDATA[accreditation]]></category>

		<category><![CDATA[certification]]></category>

		<category><![CDATA[compatibility]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[cryptography]]></category>

		<category><![CDATA[fips-140]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[infosec]]></category>

		<category><![CDATA[itsatrap]]></category>

		<category><![CDATA[management]]></category>

		<category><![CDATA[NIST]]></category>

		<category><![CDATA[pwnage]]></category>

		<category><![CDATA[risk]]></category>

		<category><![CDATA[scalability]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[tailoring]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1035</guid>
		<description><![CDATA[One of the best things about being almost older than dirt is that I&#8217;ve seen several cycles within the security community.  Just like fashion and ladies&#8217; hemlines, if you pay attention long enough, you&#8217;ll see history repeat itself, or something that closely resembles history.  Time for a short trip &#8220;down memory lane&#8230;&#8221;
In the early days [...]]]></description>
			<content:encoded><![CDATA[<p>One of the best things about being almost older than dirt is that I&#8217;ve seen several cycles within the security community.  Just like fashion and ladies&#8217; hemlines, if you pay attention long enough, you&#8217;ll see history repeat itself, or something that closely resembles history.  Time for a short trip &#8220;down memory lane&#8230;&#8221;</p>
<p>In the early days of computer security, all eyes were fixed on Linthicum and the security labs associated with the NSA.  In the late 80&#8217;s and early 90&#8217;s the NSA evaluation program was notoriously slow - glacial would be a word one could use&#8230;  Bottom line, the process just wasn&#8217;t responsive enough to keep up with the changes and improvements in technology.  Products would be in evaluation for years before coming out of the process with their enabling technology nearly obsolete.   It didn&#8217;t matter, it was the only game in town until NIST and the Common Criteria labs  came onto the scene.  This has worked well, however the reality is, it&#8217;s not much better at vetting and moving technology from vendors to users.  The problem is, the evaluation process takes time and time means money, but it also means that the code submitted for evaluation will most likely be several revisions old by the time it emerges from evaluation.   Granted, it may only be 6 months, but it might take a year - regardless, this is far better than before.</p>
<p>So&#8230;  practically speaking, if the base version of FooOS submitted for evaluation is, say Version 5.0.1, several revisions &#8211;  each solving operational problems affecting the  organization &#8212; may have been released.  We may find that we need to run Version 5.6.10r3 in order to pass encrypted traffic via the network.  Because we encrypt traffic we must use FIPS-Level 2 certified code - but in the example above, the validated version of the FooOS will not work in our network&#8230;    What does the CISO do?  We&#8217;ll return to this in a moment, it gets better!</p>
<p>In order to reach levels of FIPS-140 goodness, one vendor in particular has instituted &#8220;FIPS Mode.&#8221;  What this does is require administration of the box from apposition directly in front  of the equipment, or at the length of your longest console cable&#8230;  Clearly, this is not suitable for organizations with equipment deployed worldwide to locations that do not have qualified administrators or network engineers.  Further, having to fly a technician to Burundi to clear sessions on a box every time it becomes catatonic is ridiculous at worst.  At best it&#8217;s not in accordance with the network concept of operations.  How does the CISO propose a workable, secure solution?</p>
<p style="text-align: center;"><img class="alignnone" title="Standard Hill" src="http://farm4.static.flickr.com/3207/2436223445_74769c0353.jpg?v=0" alt="" width="500" height="331" /><br />
Standard Hill photo by  <a title="Link to timparkinson's photostream" rel="dc:creator cc:attributionURL" href="http://www.flickr.com/photos/timparkinson/"><strong>timparkinson</strong></a>.</p>
<p>Now to my point.  (about time Vlad)   How does the CISO approach this situation?  Allow me to tell you the approach I&#8217;ve taken&#8230;.</p>
<p>1. Accept the fact that once Foo OS has achieved a level of FIPS-140 goodness, the likelihood that the modules of code within the OS implementing cryptographic functionality in follow-on versions have not been changed.  This also means you have to assume the vendor has done a good job of documenting the changes to their baseline in their release notes, and that they HAVE modular code&#8230;</p>
<p style="text-align: left;">2. Delve into vendor documentation and FIPS-140 to find out exactly what &#8220;FIPS Mode&#8221; is, its benefits and the requirement.  Much of the written documentation in the standard deals with physical security of the cryptographic module itself (e.g., tamper-evident seals) - but most helpful is Table 1.</p>
<div>
<table border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td width="128" valign="top"></td>
<td width="128" valign="top"><strong>Security   Level  1</strong></td>
<td width="128" valign="top"><strong>Security   Level 2</strong></td>
<td width="128" valign="top"><strong>Security   Level 3</strong></td>
<td width="128" valign="top"><strong>Security   Level 4</strong></td>
</tr>
<tr>
<td width="128" valign="top"><strong>Cryptographic </strong></p>
<p><strong>Module Specification</strong></td>
<td colspan="4" width="511" valign="top">Specification of cryptographic module,   cryptographic boundary, Approved algorithms, and Approved modes of operation.   Description of cryptographic module, including all hardware, software, and   firmware components. Statement of module security policy.</td>
</tr>
<tr>
<td width="128" valign="top"><strong>Cryptographic Module Ports and Interfaces</strong></td>
<td colspan="2" width="255" valign="top">Required and optional interfaces.   Specification of all interfaces and of all input and output data paths.</td>
<td colspan="2" width="255" valign="top">Data ports for unprotected critical   security parameters logically or physically separated from other data ports.</td>
</tr>
<tr>
<td width="128" valign="top"><strong>Roles, Services, and Authentication</strong></td>
<td width="128" valign="top">Logical separation of required and   optional roles and services</td>
<td width="128" valign="top">Role-based or identity-based operator   authentication</td>
<td colspan="2" width="255" valign="top">Identity-based operator authentication.</td>
</tr>
<tr>
<td width="128" valign="top"><strong>Finite State Model</strong></td>
<td colspan="4" width="511" valign="top">Specification of finite state   model.  Required and optional   states.  State transition diagram and   specification of state transitions.</td>
</tr>
<tr>
<td width="128" valign="top"><strong>Physical   Security</strong></td>
<td width="128" valign="top">Production grade equipment.</td>
<td width="128" valign="top">Locks or tamper evidence.</td>
<td width="128" valign="top">Tamper detection and response for   covers and doors.</td>
<td width="128" valign="top">Tamper detection and response   envelope.  EFP or EFT.</td>
</tr>
<tr>
<td width="128" valign="top"><strong>Operational   Environment</strong></td>
<td width="128" valign="top">Single operator. Executable code.   Approved integrity technique.</td>
<td width="128" valign="top">Referenced PPs evaluated at EAL2 with   specified discretionary access control mechanisms and auditing.</td>
<td width="128" valign="top">Referenced PPs plus trusted path   evaluated at EAL3 plus security policy modeling.</td>
<td width="128" valign="top">Referenced PPs plus trusted path   evaluated at EAL4.</td>
</tr>
<tr>
<td rowspan="2" width="128" valign="top"><strong>Cryptographic   Key Management</strong></td>
<td colspan="4" width="511" valign="top">Key management mechanisms: random   number and key generation, key establishment, key distribution, key   entry/output, key storage, and key zeroization.</td>
</tr>
<tr>
<td colspan="2" width="255" valign="top">Secret and private keys established   using manual methods may be entered or output in plaintext form.</td>
<td colspan="2" width="255" valign="top">Secret and private keys established   using manual methods shall be entered or output encrypted or with split   knowledge procedures.</td>
</tr>
<tr>
<td width="128" valign="top"><strong>EMI/EMC</strong></td>
<td colspan="2" width="255" valign="top">47 CFR FCC Part 15. Subpart B, Class A   (Business use). Applicable FCC requirements (for radio).</td>
<td colspan="2" width="255" valign="top">47 CFR FCC Part 15. Subpart B, Class B   (Home use).</td>
</tr>
<tr>
<td width="128" valign="top"><strong>Self-Tests</strong></td>
<td colspan="4" width="511" valign="top">Power-up tests: cryptographic algorithm   tests, software/firmware integrity tests, critical functions tests.   Conditional tests.</td>
</tr>
<tr>
<td width="128" valign="top"><strong>Design   Assurance</strong></td>
<td width="128" valign="top">Configuration management (CM). Secure   installation and generation. Design and policy correspondence. Guidance   documents.</td>
<td width="128" valign="top">CM system. Secure distribution.   Functional specification.</td>
<td width="128" valign="top">High-level language implementation.</td>
<td width="128" valign="top">Formal model. Detailed explanations   (informal proofs). Preconditions and postconditions.</td>
</tr>
<tr>
<td width="128" valign="top"><strong>Mitigation   of Other Attacks</strong></td>
<td style="text-align: left;" colspan="4" width="511" valign="top">Specification of mitigation of attacks   for which no testable requirements are currently availabl<em>e.</em></td>
</tr>
</tbody>
</table>
<p style="text-align: center;"><em>Summary of Security Requirements From FIPS-140-2</em></p>
</div>
<p>Bottom line &#8212; some &#8220;features&#8221; are indeed useful,  but this one particular vendor&#8217;s implementation into a &#8220;one-size fits all&#8221; option tends to limit the use of the feature at all in some operational scenarios (most notably, the one your humble author is dealing with.)  BTW, changing vendors is not an option.</p>
<p>3. Upon analyzing the FIPS requirements against operational needs, and (importantly) the environment the equipment is operating in, one has to draw the line between &#8220;operating in vendor FIPS Mode,&#8221; and using FIPS 140-2 encryption.</p>
<p>4. Document the decision and the rationale.</p>
<p>Once again, security professionals have to help managers to strike a healthy balance between &#8220;enough&#8221; security and operational requirements.   You would think that using approved equipment, operating systems, and vendors using the CC evaluation process would be enough.  Reading the standard, we see the official acknowledgement that &#8220;Your Mileage May Indeed Vary:&#8221; <sup>TM</sup></p>
<p style="padding-left: 30px;"><em>&#8220;</em><em>While the security requirements specified in this standard are intended to maintain the security provided by a cryptographic module, conformance to this standard is not sufficient to ensure that a particular module is secure. The operator of a cryptographic module is responsible for ensuring that the security provided by a module is sufficient and acceptable to the owner of the information that is being protected and that any residual risk is acknowledged and accepted.&#8221;     FIPS 140-2 Sec 15, Qualifications</em></p>
<p>The next paragraph constitutes validation of the approach I&#8217;ve embraced:</p>
<p style="padding-left: 30px;"><em>&#8220;Similarly, the use of a validated cryptographic module in a computer or telecommunications system does not guarantee the security of the overall system. <strong>The responsible authority in each agency shall ensure that the security of the system is sufficient and acceptable.</strong>&#8220;  (Emphasis added.)</em></p>
<p>One could say, &#8220;it depends,&#8221; but you wouldn&#8217;t think so at first glance - it&#8217;s a <strong><em>Standard</em></strong> for Pete&#8217;s sake!</p>
<p>Then again, nobody said this job would be easy!</p>
<p>Vlad</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1035').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1035" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1035" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1035&amp;title=When+Standards+Aren%26%238217%3Bt+Good+Enough" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1035&amp;title=When+Standards+Aren%26%238217%3Bt+Good+Enough" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1035" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=When+Standards+Aren%26%238217%3Bt+Good+Enough&amp;url=http://www.guerilla-ciso.com/archives/1035&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1035&amp;title=When+Standards+Aren%26%238217%3Bt+Good+Enough" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1035&amp;h=When+Standards+Aren%26%238217%3Bt+Good+Enough" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1035&amp;title=When+Standards+Aren%26%238217%3Bt+Good+Enough" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1035&amp;title=When+Standards+Aren%26%238217%3Bt+Good+Enough" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1035&amp;title=When+Standards+Aren%26%238217%3Bt+Good+Enough" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1035" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=When+Standards+Aren%26%238217%3Bt+Good+Enough&amp;link_href=http://www.guerilla-ciso.com/archives/1035" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1035" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1035&amp;t=When+Standards+Aren%26%238217%3Bt+Good+Enough" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1035').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1035').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=NNkiLOLjiRg:YDSH7AR1zdQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=NNkiLOLjiRg:YDSH7AR1zdQ:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=NNkiLOLjiRg:YDSH7AR1zdQ:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/NNkiLOLjiRg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1035/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1035</feedburner:origLink></item>
		<item>
		<title>Wanted: Some SCAP Wranglers</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/cdYCm0Hzhb0/1029</link>
		<comments>http://www.guerilla-ciso.com/archives/1029#comments</comments>
		<pubDate>Mon, 18 May 2009 13:21:41 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[NIST]]></category>

		<category><![CDATA[Outsourcing]]></category>

		<category><![CDATA[800-53]]></category>

		<category><![CDATA[fisma]]></category>

		<category><![CDATA[infosec]]></category>

		<category><![CDATA[infosharing]]></category>

		<category><![CDATA[management]]></category>

		<category><![CDATA[metrics]]></category>

		<category><![CDATA[moneymoneymoney]]></category>

		<category><![CDATA[scalability]]></category>

		<category><![CDATA[scap]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1029</guid>
		<description><![CDATA[So I was doing my usual &#8220;Beltway Bandit Perusal of Opportunities for Filthy Lucre&#8221; also known as diving into FedBizOps and I found this gem.  Basically what this means is that sometime this summer, NIST is going to put out an RFP for contractors to further develop SCAP using ARRA funds.
Keeping in mind that this [...]]]></description>
			<content:encoded><![CDATA[<p>So I was doing my usual &#8220;Beltway Bandit Perusal of Opportunities for Filthy Lucre&#8221; also known as diving into FedBizOps and <a href="https://www.fbo.gov/spg/DOC/NIST/AcAsD/09-893-Sources_Sought-01/listing.html" target="_blank">I found this gem</a>.  Basically what this means is that sometime this summer, NIST is going to put out an RFP for contractors to further develop SCAP using <a href="http://www.recovery.gov/" target="_blank">ARRA funds</a>.</p>
<p>Keeping in mind that this isn&#8217;t the official list of what NIST wants done under this contract, but it&#8217;s interesting to look at from an angle of where SCAP will go over the next couple of years:</p>
<ol>
<li>Evolution of the SCAP protocol and specifications thereof</li>
<li>Feasibility studies, development, documenting, prototyping, and road-mapping of SCAP expansions (e.g., remediation capability) and analog protocols (e.g., Network Event Content Automation Protocol</li>
<li>Implementation and maintenance support for the Security Automation Content Validation Program</li>
<li>Maintenance support for the SCAP Product Validation Program</li>
<li>Pilot, beta, and production support for SCAP and security automation use-cases</li>
<li>Content development, modification, and testing</li>
<li>Infrastructure and reference implementation development in JAVA, C++, and C programming languages</li>
<li>Data trust models and data provenance solutions.</li>
</ol>
<p>So how do you play?  Well, the first thing is that you respond to the notice with a capabilities statement saying &#8220;yes, we have experience in doing what you want&#8221;&#8211;there is a list of specifics in the original notice.  Then sign up for FedBizOps and follow the announcement so you can get changes and the RFP when it comes out.</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1029').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1029" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1029" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1029&amp;title=Wanted%3A+Some+SCAP+Wranglers" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1029&amp;title=Wanted%3A+Some+SCAP+Wranglers" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1029" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Wanted%3A+Some+SCAP+Wranglers&amp;url=http://www.guerilla-ciso.com/archives/1029&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1029&amp;title=Wanted%3A+Some+SCAP+Wranglers" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1029&amp;h=Wanted%3A+Some+SCAP+Wranglers" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1029&amp;title=Wanted%3A+Some+SCAP+Wranglers" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1029&amp;title=Wanted%3A+Some+SCAP+Wranglers" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1029&amp;title=Wanted%3A+Some+SCAP+Wranglers" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1029" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=Wanted%3A+Some+SCAP+Wranglers&amp;link_href=http://www.guerilla-ciso.com/archives/1029" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1029" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1029&amp;t=Wanted%3A+Some+SCAP+Wranglers" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1029').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1029').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=cdYCm0Hzhb0:jgia2k7yGiA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=cdYCm0Hzhb0:jgia2k7yGiA:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=cdYCm0Hzhb0:jgia2k7yGiA:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/cdYCm0Hzhb0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1029/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1029</feedburner:origLink></item>
		<item>
		<title>The World Asks: is S.773 Censorship?</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/743QEADAdZM/1016</link>
		<comments>http://www.guerilla-ciso.com/archives/1016#comments</comments>
		<pubDate>Fri, 15 May 2009 14:05:26 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[Public Policy]]></category>

		<category><![CDATA[Rants]]></category>

		<category><![CDATA[blog]]></category>

		<category><![CDATA[comments]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[incidentresponse]]></category>

		<category><![CDATA[infosec]]></category>

		<category><![CDATA[infosharing]]></category>

		<category><![CDATA[itsatrap]]></category>

		<category><![CDATA[law]]></category>

		<category><![CDATA[legislation]]></category>

		<category><![CDATA[publicpolicy]]></category>

		<category><![CDATA[pwnage]]></category>

		<category><![CDATA[S773]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1016</guid>
		<description><![CDATA[Here in the information assurance salt mines, we sure do loves us some conspiracies, so here&#8217;s the conspiracy of the month: S.773 gives the Government the ability to view your private data and the President disconnect authority over the Internet, which means he can sensor it.
Let&#8217;s look at the sections and paragraphs that would seem [...]]]></description>
			<content:encoded><![CDATA[<p>Here in the information assurance salt mines, we sure do loves us some conspiracies, so here&#8217;s the conspiracy of the month: S.773 gives the Government the ability to view your private data and the President disconnect authority over the Internet, which means he can sensor it.</p>
<p>Let&#8217;s look at the sections and paragraphs that would seem to say this:</p>
<p style="padding-left: 30px;"><em>Section 14:</em></p>
<p style="padding-left: 30px;"><em>(b) FUNCTIONS- The Secretary of Commerce&#8211;</em></p>
<p style="padding-left: 30px;"><em> (1) shall have access to all relevant data concerning such networks without regard to any provision of law, regulation, rule, or policy restricting such access;</em></p>
<p style="padding-left: 30px;"><em>Section 18:       The President&#8211;</em></p>
<p style="padding-left: 30px;"><em> (2) may declare a cybersecurity emergency and order the limitation or shutdown of Internet traffic to and from any compromised Federal Government or United States critical infrastructure information system or network;</em></p>
<p style="padding-left: 30px;"><em>(6) may order the disconnection of any Federal Government or United States critical infrastructure information systems or networks in the interest of national security;</em></p>
<p><em></em></p>
<p>Taken completely by itself, it would seem like this gives the president the authorities to do all sorts of wrong stuff, all he has to do is to declare something as critical infrastructure and declare it compromised or in the interests of national security.  And some people have:</p>
<ul>
<li><a href="http://knowthelies.com/?q=node/4096" target="_blank">S773&#8230; Government Control of Internet, Censoring Talk Radio!</a></li>
<li><a href="http://my.opera.com/lutherjw/blog/2009/04/14/censorship-a-political-rant" target="_blank">Censorship - A Political Rant</a></li>
<li><a href="http://politics4all.com/us/congress/111/bills/S773" target="_blank">Politics 4 All Comments</a></li>
</ul>
<p>And some movies (we all love movies):</p>
<div align="center">
<object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/qd2nnq-Sbo8&#038;hl=en&#038;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/qd2nnq-Sbo8&#038;hl=en&#038;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"></embed></object></p>
<p>Actually, Shelly is pretty astute and makes some good points, she just doens&#8217;t have the background in information security.</p>
<p><object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/WkVdGAjYIoI&#038;hl=en&#038;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/WkVdGAjYIoI&#038;hl=en&#038;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"></embed></object></p>
<p><object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/MbrjFuGbUWM&#038;hl=en&#038;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/MbrjFuGbUWM&#038;hl=en&#038;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"></embed></object>
</div>
<p>It makes me wonder since when have people considered social networking sites or the Internet as a whole as &#8220;critical infrastructure&#8221;.  Then the BSOFH in me things &#8220;Ye gods, when did our society sink so low?&#8221;</p>
<p>Now, as far as going back to Section 14 of S.773, it exists because most of the critical infrastructure is privately-held.  There is a bit of history to understand here and that is that the critical infrastructure owners and operators are very reluctant to give the information on their piece of critical infrastructure to the Government.  Don&#8217;t blame them, I had the same problem as a contractor: if you give the Government information, the next step is them telling you how to change it and how to run your business.  Since the owners/operators are somewhat non-helpful, the Government needs more teeth to get what it needs.</p>
<p>But as far as private data traversing the critical infrastructure?  I think it&#8217;s a stretch to say that&#8217;s part of the requirements of Section 14, it&#8217;s to collect data &#8220;about&#8221; (the language of the bill) the critical infrastructure, not &#8220;processed, stored, or forwarded&#8221; on the critical infrastructure.  But yeah, let&#8217;s scope this a little bit better, CapHill Staffers.</p>
<p>On to Section 18.  Critical infrastructure is defined elsewhere in law.  Let&#8217;s see the definitions section from <a href="http://www.dhs.gov/xabout/laws/gc_1214597989952.shtm" target="_blank">HSPD-7, Critical Infrastructure Identification, Prioritization, and Protection</a>:</p>
<p style="padding-left: 30px;"><em>In this directive:</em></p>
<p style="padding-left: 30px;"><em> The term &#8220;critical infrastructure&#8221; has the meaning given to that term in section <a href="http://www.law.cornell.edu/uscode/uscode42/usc_sec_42_00005195---c000-.html" target="_blank">1016(e) of the USA PATRIOT Act of 2001 (42 U.S.C. 5195c(e))</a>.</em></p>
<p style="padding-left: 30px;"><em>The term &#8220;key resources&#8221; has the meaning given that term in section 2(9) of the Homeland Security Act of 2002 (6 U.S.C. 101(9)).<br />
</em></p>
<p style="padding-left: 30px;"><em>The term &#8220;the Department&#8221; means the Department of Homeland Security.<br />
</em></p>
<p style="padding-left: 30px;"><em>The term &#8220;Federal departments and agencies&#8221; means those executive departments enumerated in 5 U.S.C. 101, and the Department of Homeland Security; independent establishments as defined by 5 U.S.C. 104(1);Government corporations as defined by 5 U.S.C. 103(1); and the United States Postal Service.<br />
</em></p>
<p style="padding-left: 30px;"><em>The terms &#8220;State,&#8221; and &#8220;local government,&#8221; when used in a geographical sense, have the same meanings given to those terms in section 2 of the Homeland Security Act of 2002 (6 U.S.C. 101).<br />
</em></p>
<p style="padding-left: 30px;"><em>The term &#8220;the Secretary&#8221; means the Secretary of Homeland Security.<br />
</em></p>
<p style="padding-left: 30px;"><em>The term &#8220;Sector-Specific Agency&#8221; means a Federal department or agency responsible for infrastructure protection activities in a designated critical infrastructure sector or key resources category. Sector-Specific Agencies will conduct their activities under this directive in accordance with guidance provided by the Secretary.<br />
</em></p>
<p style="padding-left: 30px;"><em>The terms &#8220;protect&#8221; and &#8220;secure&#8221; mean reducing the vulnerability of critical infrastructure or key resources in order to deter, mitigate, or neutralize terrorist attacks.</em></p>
<p>And referencing the Patriot Act gives us the following definition for critical infrastructure:</p>
<p style="padding-left: 30px;"><em>In this section, the term “critical infrastructure” means systems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters. </em></p>
<p>Since it&#8217;s not readily evident from what we really consider to be critical infrastructure, let&#8217;s look at the implemention of HSPD-7.  They&#8217;ve defined critical infrastructure sectors and key resources, each of which have a <a href="http://www.dhs.gov/xprevprot/programs/gc_1189168948944.shtm" target="_blank">sector-specific plan on how to protect them</a>.</p>
<ul>
<li>Agriculture and Food</li>
<li> Banking and Finance</li>
<li> Chemical</li>
<li> Commercial Facilities</li>
<li>Communications</li>
<li> Critical Manufacturing</li>
<li> Dams</li>
<li> Defense Industrial Base</li>
<li> Emergency Services</li>
<li>Energy</li>
<li>Government Facilities</li>
<li>Healthcare and Public Health</li>
<li>Information Technology</li>
<li>National Monuments and Icons</li>
<li>Nuclear Reactors, Materials and Waste</li>
<li> Postal and Shipping</li>
<li>Transportation System</li>
<li>Water</li>
</ul>
<p>And oh yeah, S.773 doesn&#8217;t mention key resources, only critical infrastructure.  Some of this key infrastructure isn&#8217;t even networked (*cough* icons and national monuments *cough*). Also note that &#8220;Teh Interblagosphere&#8221; isn&#8217;t listed, although you could make a case that information technology and communications sectors might include it.</p>
<p>Yes, this is not immediately obvious, you have to stitch about half a dozen laws together, but if we didn&#8217;t do pointers to other laws, we would have the legislative version of spaghetti code.</p>
<p>Going back to Section 18 of S.773, what paragraph 2 does is give the President the authority to disconnect critical infrastructure or government-owned IT systems from the Internet if they have been compromised.  That&#8217;s fairly scoped, I think.  I know I&#8217;ll get some non-technical readers on this blog post, but basically one of the first steps in incident response is to disconnect the system, fix it, then restore service.</p>
<p>Paragraph 6 is the part that scares me, mostly because it has the same disconnect authority as paragraph 2and the same scope (critical infrastructure and  but the only justification is &#8220;in the interests of national security&#8221;.  In other words, we don&#8217;t have to tell you why we disconnected your systems from the Internet because you don&#8217;t have the clearances to understand.</p>
<p><strong>So how do we fix this bill?</strong></p>
<p>Section 14 needs an enumeration of the types of data that we can request from critical infrastructure owners and operators.  Something like the following:</p>
<ul>
<li>Architecture and toplogy</li>
<li>Vulnerability scan results</li>
<li>Asset inventories</li>
<li>Audit results</li>
</ul>
<p>The bill has a definitions section&#8211;Section 23.  We need to adopt the verbiage from HSPD-7 and include it in Section 23.  That takes care of some of the scoping issues.</p>
<p>We need a definition for &#8220;compromise&#8221; and we need a definition for &#8220;national security&#8221;.  Odds are these will be references to other laws.</p>
<p>Add a recourse for critical infrastructure owners who have been disconnected:  At the very minimum, give them the conditions under which they can be reconnected and some method of appeal.</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1016').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1016" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1016" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1016&amp;title=The+World+Asks%3A+is+S.773+Censorship%3F" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1016&amp;title=The+World+Asks%3A+is+S.773+Censorship%3F" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1016" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=The+World+Asks%3A+is+S.773+Censorship%3F&amp;url=http://www.guerilla-ciso.com/archives/1016&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1016&amp;title=The+World+Asks%3A+is+S.773+Censorship%3F" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1016&amp;h=The+World+Asks%3A+is+S.773+Censorship%3F" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1016&amp;title=The+World+Asks%3A+is+S.773+Censorship%3F" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1016&amp;title=The+World+Asks%3A+is+S.773+Censorship%3F" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1016&amp;title=The+World+Asks%3A+is+S.773+Censorship%3F" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1016" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=The+World+Asks%3A+is+S.773+Censorship%3F&amp;link_href=http://www.guerilla-ciso.com/archives/1016" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1016" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1016&amp;t=The+World+Asks%3A+is+S.773+Censorship%3F" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1016').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1016').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=743QEADAdZM:1m1JulAixDo:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=743QEADAdZM:1m1JulAixDo:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=743QEADAdZM:1m1JulAixDo:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/743QEADAdZM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1016/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1016</feedburner:origLink></item>
		<item>
		<title>Sir Bruce Mentions FDCC, World Goes Nuts</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/RG6Aaxc_IxQ/1008</link>
		<comments>http://www.guerilla-ciso.com/archives/1008#comments</comments>
		<pubDate>Thu, 07 May 2009 21:51:39 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[Technical]]></category>

		<category><![CDATA[cashcows]]></category>

		<category><![CDATA[certification]]></category>

		<category><![CDATA[compatibility]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[fdcc]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[infosec]]></category>

		<category><![CDATA[moneymoneymoney]]></category>

		<category><![CDATA[NIST]]></category>

		<category><![CDATA[omb]]></category>

		<category><![CDATA[scalability]]></category>

		<category><![CDATA[scap]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=1008</guid>
		<description><![CDATA[Check out this blog post.  Wow, all sorts of crazies decend out of the woodwork when Bruce talks about something that&#8217;s been around for years and suddenly everyone&#8217;s redesigning the desktop from the ground up.
Quick recap on comments:

60-day password changes suck
You can do this at home, the GPOs are available from NIST
My blue-haired sheepdog can&#8217;t use the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.schneier.com/blog/archives/2009/05/secure_version.html" target="_blank">Check out this blog post</a>.  Wow, all sorts of crazies decend out of the woodwork when Bruce talks about something that&#8217;s been around for years and suddenly everyone&#8217;s redesigning the desktop from the ground up.</p>
<p>Quick recap on comments:</p>
<ul>
<li>60-day password changes suck</li>
<li>You can do this at home, the GPOs are available from NIST</li>
<li>My blue-haired sheepdog can&#8217;t use the FDCC image, it&#8217;s broken for commercial use!</li>
<li>You wouldn&#8217;t have to do this in Linux</li>
<li>Linux is teh suxx0rz</li>
<li>My computer started beeping and smoke came out of it, is this FDCC?</li>
</ul>
<p>Proving once again that you can&#8217;t talk about Windows desktop security without it evolving into a flamewar.  Might as well pull out &#8220;vi v/s emacs&#8221; while you&#8217;re at it, Bruce.  =)</p>
<p style="text-align: center;"><em><img class="alignnone" title="Computer Setup" src="http://farm1.static.flickr.com/73/368529056_b128901028.jpg?v=0" alt="" width="500" height="358" /></em></p>
<p style="text-align: center;"><em>Computer Setup photo by </em><a title="Link to karindalziel's photostream" rel="dc:creator cc:attributionURL" href="http://www.guerilla-ciso.com/photos/nirak/"><strong><span style="color: #0063dc;"><em>karindalziel</em></span></strong></a><em>.  Yes, one of them is a linux box, I used this picture for that very same reason.  =)</em></p>
<p>But there is one point that people need to understand.  The magic of FDCC is not in the fact that the Government used its IT-buying muscle to get Microsoft to cooperate.  Oh no, that&#8217;s to be expected&#8211;the guys at MS are used to working with a lot of people now on requests.</p>
<p>The true magic of FDCC is getting the application vendors to play along.  To wit:</p>
<ul>
<li>The FDCC GPOs are freely available from NIST</li>
<li>You can download images from NIST with a preconfigured FDCC setup</li>
<li>Application vendors can test their product against FDCC in their own lab</li>
<li>There is no external audit burden (yet, it might be coming) for software vendors because it&#8217;s a self-certification</li>
<li>FDCC-compatible software doesn&#8217;t require administrative privileges</li>
</ul>
<p>In other words, if your software works with FDCC, it&#8217;s probably built to run on a security-correct operating system in the first place.  This is a good thing, and in this case the Government is using its IT budget to bring the application vendors into some sort of minimal security to the rest of the world.</p>
<p>This statement is from the <a href="http://nvd.nist.gov/fdcc/fdcc_faq.cfm#17" target="_blank">FDCC FAQ</a>, comments in parenthesis are mine:</p>
<p style="padding-left: 30px;"><strong>&#8220;How are vendors required to prove FDCC compliance<em>?</em></strong><span class="style2"><br />
<em>There is no formal compliance process; vendors of information technology products must self-assert FDCC compliance. They are expected to ensure that their products function correctly with computers configured with the FDCC settings. The product installation process must make no changes to the FDCC settings. Applications must work with users who do not have administrative privileges, the only acceptable exception being information technology management tools. Vendors must test their products on systems configured with the FDCC settings, they must use SCAP validated tools with FDCC Scanner capability to certify their products operate correctly with FDCC configurations and do not alter FDCC settings. The OMB provided suggested language in this memo: </em><a href="http://www.whitehouse.gov/omb/memoranda/fy2007/m07-18.pdf"><span style="color: #0000ff;"><em>http://www.whitehouse.gov/omb/memoranda/fy2007/m07-18.pdf</em></span></a><em>, vendors are likely to encounter similar language when negotiating with agencies.&#8221;</em></span></p>
<p>So really what you get out of self-certification is something like this:</p>
<ul>
<li><a href="http://www-01.ibm.com/support/docview.wss?rs=3200&amp;context=SS3HEA&amp;context=SSSTY3&amp;context=SSCSNZN&amp;context=SSSTWP&amp;dc=DB600&amp;uid=swg21298277&amp;loc=en_US&amp;cs=UTF-8&amp;lang=en" target="_blank">IBM Rational Tools FDCC compatibility</a></li>
<li><a href="http://www.quest.com/public-sector/fdcc.aspx" target="_blank">Quest Software FDCC compatibility</a></li>
<li><a href="www.sas.com/govedu/fdcc-compliance.html" target="_blank">SAS FDCC compatibility</a></li>
</ul>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d1008').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d1008" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/1008" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/1008&amp;title=Sir+Bruce+Mentions+FDCC%2C+World+Goes+Nuts" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/1008&amp;title=Sir+Bruce+Mentions+FDCC%2C+World+Goes+Nuts" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/1008" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Sir+Bruce+Mentions+FDCC%2C+World+Goes+Nuts&amp;url=http://www.guerilla-ciso.com/archives/1008&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/1008&amp;title=Sir+Bruce+Mentions+FDCC%2C+World+Goes+Nuts" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/1008&amp;h=Sir+Bruce+Mentions+FDCC%2C+World+Goes+Nuts" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/1008&amp;title=Sir+Bruce+Mentions+FDCC%2C+World+Goes+Nuts" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/1008&amp;title=Sir+Bruce+Mentions+FDCC%2C+World+Goes+Nuts" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/1008&amp;title=Sir+Bruce+Mentions+FDCC%2C+World+Goes+Nuts" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/1008" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=Sir+Bruce+Mentions+FDCC%2C+World+Goes+Nuts&amp;link_href=http://www.guerilla-ciso.com/archives/1008" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/1008" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/1008&amp;t=Sir+Bruce+Mentions+FDCC%2C+World+Goes+Nuts" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d1008').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d1008').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=RG6Aaxc_IxQ:RLiREWgdUs0:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=RG6Aaxc_IxQ:RLiREWgdUs0:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=RG6Aaxc_IxQ:RLiREWgdUs0:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/RG6Aaxc_IxQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/1008/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/1008</feedburner:origLink></item>
		<item>
		<title>Where For Art Thou, 60-Day Review</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/5f_PhFEamQE/993</link>
		<comments>http://www.guerilla-ciso.com/archives/993#comments</comments>
		<pubDate>Thu, 07 May 2009 16:37:21 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[Public Policy]]></category>

		<category><![CDATA[Risk Management]]></category>

		<category><![CDATA[awareness]]></category>

		<category><![CDATA[clearances]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[infosec]]></category>

		<category><![CDATA[infosharing]]></category>

		<category><![CDATA[management]]></category>

		<category><![CDATA[publicpolicy]]></category>

		<category><![CDATA[risk]]></category>

		<category><![CDATA[scalability]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=993</guid>
		<description><![CDATA[April Fools Day pranks aside, I&#8217;m wondering what happened to the 60-day Cybersecurity Review.  Supposedly, it was turned into the President on the 17th.  I guess all I can do is sigh and say &#8220;So much for transparency in Government&#8221;.
I&#8217;m trying hard to be understanding here, I really am.  But isn&#8217;t the administration pulling the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.guerilla-ciso.com/archives/889">April Fools Day pranks</a> aside, I&#8217;m wondering what happened to the 60-day Cybersecurity Review.  Supposedly, it was turned into the President on the 17th.  I guess all I can do is sigh and say &#8220;So much for transparency in Government&#8221;.</p>
<p>I&#8217;m trying hard to be understanding here, I really am.  But isn&#8217;t the administration pulling the same Comprehensive National Cybersecurity Initiative thing again, telling the professionals out in the private sector that it depends on, &#8220;You can&#8217;t handle the truth!&#8221;</p>
<p>And this is the problem.  Let&#8217;s face it, our information sharing from Government to private sector really sucks right now.  I understand why this is&#8211;when you have threats and intentions that come from classified sources, if you share that information, you risk losing your sources.  (ref: <a href="http://en.wikipedia.org/wiki/Ultra#Safeguarding_of_sources" target="_blank">Ultra</a> and  <a href="http://en.wikipedia.org/wiki/Coventry_Blitz#Coventry_and_Ultra" target="_blank">Coventry</a>, although it&#8217;s semi-controversial)</p>
<p style="text-align: center;"><em><img class="alignnone" title="Secret Passage" src="http://farm1.static.flickr.com/120/314362272_f28cf5ec5d.jpg?v=0" alt="" width="375" height="500" /></em></p>
<p style="text-align: center;"><em>Secret Passage photo by </em><a title="Link to electricinca's photostream" rel="dc:creator cc:attributionURL" href="http://www.guerilla-ciso.com/photos/electricinca/"><strong><span style="color: #0063dc;"><em>electricinca</em></span></strong></a><em>.</em></p>
<p>Looking back at one of the weaknesses of our information-sharing strategy so far:</p>
<ul>
<li>Most of the critical infrastructure is owned and operated by the private sector.  Government (and the nation at-large) depends on these guys and the resilience of the IT that these</li>
<li>The private sector (or at least critical infrastructure owners and operators) need the information to protect their infrastructure.</li>
<li>Our process for clearing someone to receive sensitive information is to do a criminal records investigation, credit report, and talk to a handful of their friends to find out who they really are.  It takes 6-18 months.  This is not quick.</li>
<li>We have some information-sharing going on.  <a href="http://www.dhs.gov/xinfoshare/programs/gc_1156888108137.shtm" target="_blank">HSIN</a> and <a href="http://www.infragard.net/">Infragard</a> are pretty good so far&#8211;we give you a background check and some SBU-type information.  Problem is that they don&#8217;t have enough uptake out in the security industry.  If you make/sell security products and services for Government and critical infrastructure, you owe it to yourself to be part of these.</li>
<li>I&#8217;ve heard people from Silicon Valley talk about how the Government doesn&#8217;t listen to them and that they have good ideas.  Yes they do have some ideas, but they&#8217;re detached from the true needs because they don&#8217;t have the information that they need to build the right products and services, so all they can do is align themselves with compliance frameworks and wonder why the Government doesn&#8217;t buy their kit.  It&#8217;s epic fail on a macromarket scale.</li>
</ul>
<p>In my opinion, Government can&#8217;t figure out if they are a partner or a regulator.  Choose wisely, it&#8217;s hard to be both.</p>
<p>As a regulator, we just establish the standard and, in theory anyway, the private sector folks don&#8217;t need to know the reasoning behind the standard.   It&#8217;s fairly easy to manage but not very flexible&#8211;you don&#8217;t get much innovation and new technology if people don&#8217;t understand the business case.  This is also a more traditional role for Government to take.</p>
<p>As a partner, we can share information and consequences with the private sector.  It&#8217;s more flexible in response but takes much more effort and money to bring them information.  It also takes participation from both sides&#8211;Government and private sector.</p>
<p>Now to tie it all off by going back to the 60-Day Cybersecurity Review&#8230;.  The private sector needs information contained in the review.  Not all of it, mind you, just the parts that they need to do their job.  They need it to help the Government.  They need it to build products that fit the Government&#8217;s needs.  They need it to secure their own infrastructure.</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d993').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d993" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/993" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/993&amp;title=Where+For+Art+Thou%2C+60-Day+Review" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/993&amp;title=Where+For+Art+Thou%2C+60-Day+Review" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/993" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Where+For+Art+Thou%2C+60-Day+Review&amp;url=http://www.guerilla-ciso.com/archives/993&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/993&amp;title=Where+For+Art+Thou%2C+60-Day+Review" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/993&amp;h=Where+For+Art+Thou%2C+60-Day+Review" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/993&amp;title=Where+For+Art+Thou%2C+60-Day+Review" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/993&amp;title=Where+For+Art+Thou%2C+60-Day+Review" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/993&amp;title=Where+For+Art+Thou%2C+60-Day+Review" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/993" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=Where+For+Art+Thou%2C+60-Day+Review&amp;link_href=http://www.guerilla-ciso.com/archives/993" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/993" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/993&amp;t=Where+For+Art+Thou%2C+60-Day+Review" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d993').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d993').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=5f_PhFEamQE:Gz0GTuzlCfQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=5f_PhFEamQE:Gz0GTuzlCfQ:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=5f_PhFEamQE:Gz0GTuzlCfQ:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/5f_PhFEamQE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/993/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/993</feedburner:origLink></item>
		<item>
		<title>Preparing for Cybergeddon</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/fp66gykSVA8/997</link>
		<comments>http://www.guerilla-ciso.com/archives/997#comments</comments>
		<pubDate>Thu, 07 May 2009 14:24:11 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[IKANHAZFIZMA]]></category>

		<category><![CDATA[cybercommand]]></category>

		<category><![CDATA[cybercorps]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[infosec]]></category>

		<category><![CDATA[lolcats]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=997</guid>
		<description><![CDATA[Infantrymen have this crude-but-effective method of unarmed combat known as &#8220;Combatives&#8221;.  It&#8217;s a small stretch to envision our cyber-warriors practicing their own brand of cyber-combatives.
This lolcat is almost dedicated to our security twit/bloggers and jiu-jitsu fiends Chris Hoff and Jeremiah Grossman.



Bookmark to:


















Hide Sites



$$('div.d997').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); ]]></description>
			<content:encoded><![CDATA[<p>Infantrymen have this crude-but-effective method of unarmed combat known as <a href="http://en.wikipedia.org/wiki/Combatives" target="_blank">&#8220;Combatives&#8221;</a>.  It&#8217;s a small stretch to envision our cyber-warriors practicing their own brand of cyber-combatives.</p>
<p>This lolcat is almost dedicated to our security twit/bloggers and jiu-jitsu fiends <a href="http://rationalsecurity.typepad.com/" target="_blank">Chris Hoff</a> and <a href="http://jeremiahgrossman.blogspot.com/" target="_blank">Jeremiah Grossman</a>.</p>
<p style="text-align: center;"><a href="http://mine.icanhascheezburger.com/view.aspx?ciid=4121278"><img class="aligncenter" src="http://images.icanhascheezburger.com/completestore/2009/5/7/128861794749147032.jpg" alt="funny pictures" /></a></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d997').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d997" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/997" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/997&amp;title=Preparing+for+Cybergeddon" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/997&amp;title=Preparing+for+Cybergeddon" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/997" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Preparing+for+Cybergeddon&amp;url=http://www.guerilla-ciso.com/archives/997&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/997&amp;title=Preparing+for+Cybergeddon" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/997&amp;h=Preparing+for+Cybergeddon" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/997&amp;title=Preparing+for+Cybergeddon" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/997&amp;title=Preparing+for+Cybergeddon" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/997&amp;title=Preparing+for+Cybergeddon" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/997" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=Preparing+for+Cybergeddon&amp;link_href=http://www.guerilla-ciso.com/archives/997" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/997" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/997&amp;t=Preparing+for+Cybergeddon" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d997').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d997').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=fp66gykSVA8:VzhTgGk0V3E:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=fp66gykSVA8:VzhTgGk0V3E:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=fp66gykSVA8:VzhTgGk0V3E:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/fp66gykSVA8" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/997/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/997</feedburner:origLink></item>
		<item>
		<title>Blow-By-Blow on S.773–The Cybersecurity Act of 2009–Part 5</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/680CwFTBiZs/973</link>
		<comments>http://www.guerilla-ciso.com/archives/973#comments</comments>
		<pubDate>Mon, 04 May 2009 13:52:47 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[Public Policy]]></category>

		<category><![CDATA[cashcows]]></category>

		<category><![CDATA[comments]]></category>

		<category><![CDATA[dhs]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[infosec]]></category>

		<category><![CDATA[infosharing]]></category>

		<category><![CDATA[itsatrap]]></category>

		<category><![CDATA[law]]></category>

		<category><![CDATA[legislation]]></category>

		<category><![CDATA[management]]></category>

		<category><![CDATA[moneymoneymoney]]></category>

		<category><![CDATA[NIST]]></category>

		<category><![CDATA[publicpolicy]]></category>

		<category><![CDATA[risk]]></category>

		<category><![CDATA[S773]]></category>

		<category><![CDATA[scalability]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[stategovernment]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=973</guid>
		<description><![CDATA[Rybolov Note: this is part 4 in a series about S.773.  Go read the bill here.  Go read part one here.  Go read part two here.  Go read part three here. Go read part four here.

Themes: I&#8217;ve read this thing back and forth, and one theme emerges overall: We&#8217;ve talked for the better part of [...]]]></description>
			<content:encoded><![CDATA[<p><em>Rybolov Note: this is part 4 in a series about S.773.  <a href="http://thomas.loc.gov/cgi-bin/query/z?c111:S.773:" target="_blank">Go read the bill here</a>.  <a href="http://www.guerilla-ciso.com/archives/905">Go read part one here</a>.  <a href="http://www.guerilla-ciso.com/archives/914">Go read part two here</a>.  <a href="http://www.guerilla-ciso.com/archives/932">Go read part three here</a>. <a href="http://www.guerilla-ciso.com/archives/956">Go read part four here</a>.<br />
</em></p>
<p><strong>Themes:</strong> I&#8217;ve read this thing back and forth, and one theme emerges overall: We&#8217;ve talked for the better part of a decade about what it&#8217;s going to take to &#8220;solve&#8221; this problem that is IT security, from an internal Federal Government standpoint, from a military-industrial complex standpoint, from a state and local government standpoint, from a private-sector standpoint, and from an end-user standpoint.  This bill takes some of the best though on the issue, wraps it all up, and presents it as a &#8220;if you want to get the job done, this is the way to do it&#8221;.</p>
<p><strong>Missing: </strong>The role of DHS.  Commerce is highly represented, over-represented to my mindset.  Looking at the pieces of who owns what:</p>
<p>Commerce security organizations:</p>
<p style="padding-left: 30px;"><a href="http://www.ntia.doc.gov/" target="_blank">NTIA</a>&#8211;Technically not a security organization, but they manage the DNS root and set telecom policy.</p>
<p style="padding-left: 30px;"><a href="http://www.nist.gov/" target="_blank">NIST</a>&#8211;They write the standards for security.</p>
<p style="padding-left: 30px;"><a href="http://www.ftc.gov" target="_blank">FTC</a>&#8211;They regulate trade and have oversight over business fraud.</p>
<p>DHS Security organizations:</p>
<p style="padding-left: 30px;"><a href="http://www.dhs.gov/xabout/structure/editorial_0794.shtm" target="_blank">NPPD</a>&#8211;They are responsible for critical infrastructure and national risk management.</p>
<p style="padding-left: 30px;"><a href="http://www.dhs.gov/xabout/structure/editorial_0839.shtm" target="_blank">NCSD</a>&#8211;They do the security operations side of our national cybersecurity strategy and run US-CERT. (BTW, hi guys!)</p>
<p style="padding-left: 30px;"><a href="http://www.secretservice.gov/" target="_blank">Secret Service</a>&#8211;They have the primary responsibility of protecting the US Currency which also includes computer crimes against financial infrastructure.</p>
<p style="padding-left: 30px;"><a href="http://www.dhs.gov/xabout/structure/editorial_0530.shtm" target="_blank">Science and Technology Directorate</a>&#8211;They are responsible for research and development, including IT security.</p>
<p>DOJ Security Organizations:</p>
<p style="padding-left: 30px;"><a href="www.fbi.gov/" target="_blank">FBI</a>&#8211;Surprise, they do investigations.</p>
<p>So you see, some of the things that are tasked to Commerce are done by DHS and DOJ.  This is probably the nature of the bill, it was introduced in the Commerce committee so it&#8217;s understandable that it would be Commerce-centric.</p>
<p><strong>Cost:</strong> One thing kept nagging me in the back of my head while going through this bill is the cost to do everything  We&#8217;re asking to do a lot in this bill, now what&#8217;s the total cost?  Typically what happens when a bill makes it out of committee is that the Congressional Budget Office attached a price to the legislation as far as the total cost and then what&#8217;s the breakdown for the average American household.  That data isn&#8217;t published yet on the bill&#8217;s page, so we&#8217;ll see in the next iteration.</p>
<p><strong>In-Your-Face Politics:</strong> Really, this bill is showing us how to do the full security piece.  It includes everything.  It&#8217;s challenging people to come up with alternatives.  It&#8217;s challenging people to delete the sections that don&#8217;t make sense.  It&#8217;s challenging people to fix the scope issues.  Like it or hate it, it definitely stirs up debate.</p>
<p><strong>Final Thoughts:</strong> S.773 is a pretty decent bill.  It has some warts that need to be fixed, but overall it&#8217;s a pretty positive step.</p>
<p style="text-align: center;"><em><img class="alignnone" title="Capitol" src="http://farm4.static.flickr.com/3119/2819320860_64752e033c.jpg?v=0" alt="" width="500" height="333" /></em></p>
<p style="text-align: center;"><em>Capitol photo by <a title="Link to bigmikesndtech's photostream" rel="dc:creator cc:attributionURL" href="http://www.flickr.com/photos/bigmikesndtech/"><strong>bigmikesndtech</strong></a>.</em></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d973').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d973" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/973" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/973&amp;title=Blow-By-Blow+on+S.773%26%238211%3BThe+Cybersecurity+Act+of+2009%26%238211%3BPart+5" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/973&amp;title=Blow-By-Blow+on+S.773%26%238211%3BThe+Cybersecurity+Act+of+2009%26%238211%3BPart+5" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/973" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Blow-By-Blow+on+S.773%26%238211%3BThe+Cybersecurity+Act+of+2009%26%238211%3BPart+5&amp;url=http://www.guerilla-ciso.com/archives/973&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/973&amp;title=Blow-By-Blow+on+S.773%26%238211%3BThe+Cybersecurity+Act+of+2009%26%238211%3BPart+5" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/973&amp;h=Blow-By-Blow+on+S.773%26%238211%3BThe+Cybersecurity+Act+of+2009%26%238211%3BPart+5" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/973&amp;title=Blow-By-Blow+on+S.773%26%238211%3BThe+Cybersecurity+Act+of+2009%26%238211%3BPart+5" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/973&amp;title=Blow-By-Blow+on+S.773%26%238211%3BThe+Cybersecurity+Act+of+2009%26%238211%3BPart+5" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/973&amp;title=Blow-By-Blow+on+S.773%26%238211%3BThe+Cybersecurity+Act+of+2009%26%238211%3BPart+5" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/973" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=Blow-By-Blow+on+S.773%26%238211%3BThe+Cybersecurity+Act+of+2009%26%238211%3BPart+5&amp;link_href=http://www.guerilla-ciso.com/archives/973" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/973" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/973&amp;t=Blow-By-Blow+on+S.773%26%238211%3BThe+Cybersecurity+Act+of+2009%26%238211%3BPart+5" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d973').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d973').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=680CwFTBiZs:GdFGJwDhdKg:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=680CwFTBiZs:GdFGJwDhdKg:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=680CwFTBiZs:GdFGJwDhdKg:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/680CwFTBiZs" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/973/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/973</feedburner:origLink></item>
		<item>
		<title>Blow-By-Blow on S.773–The Cybersecurity Act of 2009–Part 4</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/63PrE8wL03c/956</link>
		<comments>http://www.guerilla-ciso.com/archives/956#comments</comments>
		<pubDate>Fri, 01 May 2009 13:44:52 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[Public Policy]]></category>

		<category><![CDATA[comments]]></category>

		<category><![CDATA[dhs]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[infosec]]></category>

		<category><![CDATA[infosharing]]></category>

		<category><![CDATA[itsatrap]]></category>

		<category><![CDATA[law]]></category>

		<category><![CDATA[legislation]]></category>

		<category><![CDATA[management]]></category>

		<category><![CDATA[publicpolicy]]></category>

		<category><![CDATA[pwnage]]></category>

		<category><![CDATA[risk]]></category>

		<category><![CDATA[S773]]></category>

		<category><![CDATA[scalability]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=956</guid>
		<description><![CDATA[Rybolov Note: this is part 4 in a series about S.773.  Go read the bill here.  Go read part one here.  Go read part two here.  Go read part three here.  Go read part 5 here. =)
SEC. 18. CYBERSECURITY RESPONSIBILITIES AND AUTHORITY. This section needs to be reviewed line-by-line because it&#8217;s dense:
&#8220;The President&#8211;
(1) within 1 [...]]]></description>
			<content:encoded><![CDATA[<p><em>Rybolov Note: this is part 4 in a series about S.773.  <a href="http://thomas.loc.gov/cgi-bin/query/z?c111:S.773:" target="_blank">Go read the bill here</a>.  <a href="http://www.guerilla-ciso.com/archives/905">Go read part one here</a>.  <a href="http://www.guerilla-ciso.com/archives/914">Go read part two here</a>.  <a href="http://www.guerilla-ciso.com/archives/932">Go read part three here</a>.  <a href="http://www.guerilla-ciso.com/archives/973">Go read part 5 here</a>. =)</em></p>
<p><strong>SEC. 18. CYBERSECURITY RESPONSIBILITIES AND AUTHORITY.</strong> This section needs to be reviewed line-by-line because it&#8217;s dense:</p>
<p style="padding-left: 30px;"><em>&#8220;The President&#8211;</em></p>
<p style="padding-left: 30px;"><em>(1) within 1 year after the date of enactment of this Act, shall develop and implement a comprehensive national cybersecurity strategy, which shall include&#8211;</em></p>
<p style="padding-left: 60px;"><em>(A) a long-term vision of the Nation&#8217;s cybersecurity future; and</em></p>
<p style="padding-left: 60px;"><em>(B) a plan that encompasses all aspects of national security, including the participation of the private sector, including critical infrastructure operators and managers;&#8221;</em></p>
<p>OK, fair enough, this calls for a cybersecurity strategy that includes the agencies and critical infrastructure.  Most of that is in-play already and has overlap with some other sections.</p>
<p style="padding-left: 30px;"><em>(2) may declare a cybersecurity emergency and order the limitation or shutdown of Internet traffic to and from any compromised Federal Government or United States critical infrastructure information system or network;</em></p>
<p>Declaring an emergency is already a President function for natural disasters, this makes sense, except where you militarized cybersecurity and indirectly give the President the authority here to declare a cyberwar, depending on how you interpret this paragraph.</p>
<p>The cutoff authority has been given much talk.  This part pertains only to Government systems and critical infrastructure.  Note that the criteria here is that the part being cutoff has to have been compromised, which makes more sense.  The part that I&#8217;m worried about is when we preemptively cut off the network in anticipation of pwnage.</p>
<p style="padding-left: 30px;"><em>(3) shall designate an agency to be responsible for coordinating the response and restoration of any Federal Government or United States critical infrastructure information system or network affected by a cybersecurity emergency declaration under paragraph (2);</em></p>
<p>This is interesting to me because it leaves the designation up to the President.  Remember, we have all this debate as to who should &#8220;own&#8221; cybersecurity: DHS, DoD, NSA, FBI, and even Commerce have been proposed here.  I don&#8217;t think Congress should leave this designation to the President&#8211;it needs to be decided before an incident so that we don&#8217;t fight over jurisdiction issues during the incident.  Ref: <a href="http://www.guerilla-ciso.com/archives/751">Cyber-Katrina</a>.</p>
<p style="padding-left: 30px;"><em>(4) shall, through the appropriate department or agency, review equipment that would be needed after a cybersecurity attack and develop a strategy for the acquisition, storage, and periodic replacement of such equipment;</em></p>
<p>This is good.  What it means is stockpiling or contracting for equipment in advance of an attack&#8230; think DDoS response teams and you have a pretty good idea.  And hey, this also works in disaster recovery, which I&#8217;ve never understood why we don&#8217;t manage some DR at the national level.  GSA, are you paying attention here?</p>
<p style="padding-left: 30px;"><em>(5) shall direct the periodic mapping of Federal Government and United States critical infrastructure information systems or networks, and shall develop metrics to measure the effectiveness of the mapping process;</em></p>
<p>Enumeration is good, depending on what we&#8217;re using the information for.  If you use it to beat up on the agency CISOs and the critical infrastructure owners/operators, then we have better things to spend our time doing.  If you do this and then use the information to help people Ref: security metrics, architecture support, Federal Enterprise Architecture.  I also have a problem with this because you can map vulnerabilities but how do you get the information to the right people who can fix them?</p>
<p style="padding-left: 30px;"><em>(6) may order the disconnection of any Federal Government or United States critical infrastructure information systems or networks in the interest of national security;</em></p>
<p>OK, this gives the President authority over private networks.  And fo-shizzle, I thought the President already had disconnect authority over Government networks.  If I was an owner of critical infrastructure I would be sh*tting bricks here because this means that the President has disconnect authority for my gear and doesn&#8217;t have to give me an answer on why or a remediation plan to get it turned back on&#8211;Ref: <a href="http://en.wikipedia.org/wiki/National_Security_Letter" target="_blank">National Security Letter</a>.  I think we need the disconnect authority, but there has to be some way for people to get turned back on.</p>
<p style="padding-left: 30px;"><em>(7) shall, through the Office of Science and Technology Policy, direct an annual review of all Federal cyber technology research and development investments;</em></p>
<p>Good stuff, I would be surprised if this isn&#8217;t happening already, what with Congress providing the budget for cyber technology research.</p>
<p style="padding-left: 30px;"><em>(8) may delegate original classification authority to the appropriate Federal official for the purposes of improving the Nation&#8217;s cybersecurity posture;</em></p>
<p>This paragraph is interesting, mostly because it could go anyway.  If we get a Cybersecurity Advisor, this will most likely be dedicated to them, meaning that they get the authority to determine what&#8217;s national security information.  This also works in conjunction with quite a few sections of the bill, including all the information-sharing initiatives and paragraph 6 above.</p>
<p style="padding-left: 30px;"><em>(9) shall, through the appropriate department or agency, promulgate rules for Federal professional responsibilities regarding cybersecurity, and shall provide to the Congress an annual report on Federal agency compliance with those rules;</em></p>
<p>I had to read this paragraph a couple of times.  Really what I think we&#8217;re doing is establishing a case for agency executives to be found negligent in their duty if they do not ensure security inside their agency&#8211;think CEO liability for negligence.</p>
<p style="padding-left: 30px;"><em>(10) shall withhold additional compensation, direct corrective action for Federal personnel, or terminate a Federal contract in violation of Federal rules, and shall report any such action to the Congress in an unclassified format within 48 hours after taking any such action; and</em></p>
<p>There are 2 parts of this paragraph: Federal personnel and contractors.  This is a sanctions part of the legislation.  Note that there is not a penalty and/or authority for anybody outside of Government.  The problem with this is that proving negligence is very hard in the security world.  Combined with Paragraph 9, this is a good combination provided that the professional responsibilities are written correctly.  I still think this has room for abuse because of scoping problems&#8211;we already have rules for sanctions of people (personnel law) and contracts (cure notices, Federal Acquisition Regulations), only they don&#8217;t have much teeth up to this point because it&#8217;s hard to prove negligence.</p>
<p style="padding-left: 30px;"><em>(11) shall notify the Congress within 48 hours after providing a cyber-related certification of legality to a United States person.</em></p>
<p>I had to search around for a description here.  I found some people who said this paragraph pertained to the certification of professionals as in section 7.  This is wrong.  Basically, what happens is that the Department of Justice issues a &#8220;certification of legality&#8221; when somebody (usually inside the Government) asks them if a certain act is legal to perform.  Think legal review for building a wiretap program: the President has to go to DoJ and ask them if the program is legal under existing laws.</p>
<p>What this paragraph really does is it institutes Congressional oversight on a &#8220;FYI-basis&#8221; over Executive Branch decisions on policy to keep them from overstepping their legal bounds.</p>
<p><strong>Verdict: </strong>This section is all over the map.  Like most things in S.773, it has some scope issues but overall this section establishes tasks that you can expect the Cybersecurity Advisor or DHS under the Cybersecurity Advisor&#8217;s auspices to perform.</p>
<p style="text-align: center;"><em><img class="alignnone" title="Capitol Rotunda" src="http://farm4.static.flickr.com/3634/3385101640_73d2f62d66.jpg?v=0" alt="" width="500" height="375" /></em></p>
<p style="text-align: center;"><em>Capitol Rotunda photo by <a title="Link to OakleyOriginals' photostream" rel="dc:creator cc:attributionURL" href="http://www.flickr.com/photos/oakleyoriginals/"><strong>OakleyOriginals</strong></a>.</em></p>
<p><strong>SEC. 19. QUADRENNIAL CYBER REVIEW.</strong> This section mandates a review of the cyberstrategy every 4 years.</p>
<p><strong>Verdict:</strong> We&#8217;ve been doing this so far on an ad-hoc basis, might as well make it official.</p>
<p><strong>SEC. 20. JOINT INTELLIGENCE THREAT ASSESSMENT.</strong> This section mandates an annual report on the bad guys and what they&#8217;re doing.  This is similar to the Congressional testimony we&#8217;ve seen so far on the subject.  If we&#8217;re going to expect Congress to make good public policy decisions, they need the information.</p>
<p><strong>Verdict:</strong> OK, I don&#8217;t see much wrong with this as long as it&#8217;s done right and not abused by politics.</p>
<p><strong>SEC. 21. INTERNATIONAL NORMS AND CYBERSECURITY DETERRANCE MEASURES.</strong> This section authorizes/mandates the President to cooperate with other countries about &#8220;cybersecurity stuff&#8221;.</p>
<p><strong>Verdict:</strong> Not specific enough to mean anything.  If we keep this section, we need to enumerate specifically what we want the Executive Branch to do.</p>
<p><strong>SEC. 22. FEDERAL SECURE PRODUCTS AND SERVICES ACQUISITIONS BOARD. </strong>This section creates a board to review large IT purchases.  Yes, that slows down the purchasing process horribly, as if it isn&#8217;t bad enough by itself.  Um, I thought we were supposed to do this with the Federal Enterprise Architecture.</p>
<p><strong>Verdict:</strong> This is a macro-scale solution for a micro-scale problem.  Sorry, it doesn&#8217;t work for me.  Make FEA responsible for the macro-scale and push good, solid guidance down to the agencies for the micro-scale.  Replace this section with the NIST checklists program and a true security architecture model.</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d956').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d956" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/956" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/956&amp;title=Blow-By-Blow+on+S.773%26%238211%3BThe+Cybersecurity+Act+of+2009%26%238211%3BPart+4" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/956&amp;title=Blow-By-Blow+on+S.773%26%238211%3BThe+Cybersecurity+Act+of+2009%26%238211%3BPart+4" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/956" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Blow-By-Blow+on+S.773%26%238211%3BThe+Cybersecurity+Act+of+2009%26%238211%3BPart+4&amp;url=http://www.guerilla-ciso.com/archives/956&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/956&amp;title=Blow-By-Blow+on+S.773%26%238211%3BThe+Cybersecurity+Act+of+2009%26%238211%3BPart+4" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/956&amp;h=Blow-By-Blow+on+S.773%26%238211%3BThe+Cybersecurity+Act+of+2009%26%238211%3BPart+4" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/956&amp;title=Blow-By-Blow+on+S.773%26%238211%3BThe+Cybersecurity+Act+of+2009%26%238211%3BPart+4" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/956&amp;title=Blow-By-Blow+on+S.773%26%238211%3BThe+Cybersecurity+Act+of+2009%26%238211%3BPart+4" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/956&amp;title=Blow-By-Blow+on+S.773%26%238211%3BThe+Cybersecurity+Act+of+2009%26%238211%3BPart+4" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/956" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=Blow-By-Blow+on+S.773%26%238211%3BThe+Cybersecurity+Act+of+2009%26%238211%3BPart+4&amp;link_href=http://www.guerilla-ciso.com/archives/956" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/956" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/956&amp;t=Blow-By-Blow+on+S.773%26%238211%3BThe+Cybersecurity+Act+of+2009%26%238211%3BPart+4" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d956').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d956').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=63PrE8wL03c:kHwp5_2PiSQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=63PrE8wL03c:kHwp5_2PiSQ:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=63PrE8wL03c:kHwp5_2PiSQ:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/63PrE8wL03c" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/956/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/956</feedburner:origLink></item>
		<item>
		<title>LOLCATS and #CapSec</title>
		<link>http://feedproxy.google.com/~r/TheGuerillaCiso/~3/JejtGhGLVdQ/964</link>
		<comments>http://www.guerilla-ciso.com/archives/964#comments</comments>
		<pubDate>Thu, 30 Apr 2009 17:05:31 +0000</pubDate>
		<dc:creator>rybolov</dc:creator>
		
		<category><![CDATA[IKANHAZFIZMA]]></category>

		<category><![CDATA[infosec]]></category>

		<category><![CDATA[lolcats]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.guerilla-ciso.com/?p=964</guid>
		<description><![CDATA[If you&#8217;re a security geek in the DC area, have a go at CapSecDC.  Good folks, and if you hang around long enough, you&#8217;ll be rewarded with espresso vodka. =)
Thanks to @dallendoug, we now have an invitation to play poker with the Geeks Love Poker crowd who have graciously changed their meeting date to be [...]]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;re a security geek in the DC area, <a href="http://capsecdc.org/blog/" target="_blank">have a go at CapSecDC</a>.  Good folks, and if you hang around long enough, you&#8217;ll be rewarded with espresso vodka. =)</p>
<p>Thanks to <a href="http://twitter.com/dallendoug" target="_blank">@dallendoug</a>, we now have an invitation to play poker with the Geeks Love Poker crowd who have graciously changed their meeting date to be more compatible with CapSecDC.</p>
<p style="text-align: center;"><a href="http://mine.icanhascheezburger.com/view.aspx?ciid=4067133"><img class="aligncenter" src="http://images.icanhascheezburger.com/completestore/2009/4/30/128855840740752915.jpg" alt="funny pictures" /></a></p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d964').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark to:</em></strong></a>
<br />
<div class="d964" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/964" rel="nofollow" title="Add to&nbsp;Bloglines"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/bloglines.png" title="Add to&nbsp;Bloglines" alt="Add to&nbsp;Bloglines" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/964&amp;title=LOLCATS+and+%23CapSec" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/964&amp;title=LOLCATS+and+%23CapSec" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http://www.guerilla-ciso.com/archives/964" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=LOLCATS+and+%23CapSec&amp;url=http://www.guerilla-ciso.com/archives/964&amp;version=0.7" rel="nofollow" title="Add to&nbsp;Feed Me Links"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/feedmelinks.png" title="Add to&nbsp;Feed Me Links" alt="Add to&nbsp;Feed Me Links" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/964&amp;title=LOLCATS+and+%23CapSec" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.newsvine.com/_wine/save?u=http://www.guerilla-ciso.com/archives/964&amp;h=LOLCATS+and+%23CapSec" rel="nofollow" title="Add to&nbsp;Newsvine"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/newsvine.png" title="Add to&nbsp;Newsvine" alt="Add to&nbsp;Newsvine" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/964&amp;title=LOLCATS+and+%23CapSec" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?url=http://www.guerilla-ciso.com/archives/964&amp;title=LOLCATS+and+%23CapSec" rel="nofollow" title="Add to&nbsp;Slashdot"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/slashdot.png" title="Add to&nbsp;Slashdot" alt="Add to&nbsp;Slashdot" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit.php?url=http://www.guerilla-ciso.com/archives/964&amp;title=LOLCATS+and+%23CapSec" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/964" rel="nofollow" title="Add to&nbsp;Squidoo"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/squidoo.png" title="Add to&nbsp;Squidoo" alt="Add to&nbsp;Squidoo" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tailrank.com/share/?title=LOLCATS+and+%23CapSec&amp;link_href=http://www.guerilla-ciso.com/archives/964" rel="nofollow" title="Add to&nbsp;Tailrank"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/tailrank.png" title="Add to&nbsp;Tailrank" alt="Add to&nbsp;Tailrank" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/964" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/964&amp;t=LOLCATS+and+%23CapSec" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.guerilla-ciso.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d964').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
<script type="text/javascript">$$('div.d964').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); </script><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=JejtGhGLVdQ:ONvxChLx1tc:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheGuerillaCiso?a=JejtGhGLVdQ:ONvxChLx1tc:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/TheGuerillaCiso?i=JejtGhGLVdQ:ONvxChLx1tc:D7DqB2pKExk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/JejtGhGLVdQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.guerilla-ciso.com/archives/964/feed</wfw:commentRss>
		<feedburner:origLink>http://www.guerilla-ciso.com/archives/964</feedburner:origLink></item>
	</channel>
</rss><!-- Dynamic page generated in 1.576 seconds. -->
