<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
<channel>
<title>GovInfoSecurity.com  RSS Syndication</title>
<link>http://www.govinfosecurity.com/rssFeeds.php?type=main</link>
<description>GovInfoSecurity.com RSS News Feeds on government information security news, regulations, blogs and education</description>
<pubDate>Thu, 31 May 2012 10:20:15 -0500</pubDate>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/govinfosecurity/com" /><feedburner:info uri="govinfosecurity/com" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:browserFriendly></feedburner:browserFriendly><item>
			<title>Breaches: The Investigation Challenges</title>
			<link>http://www.govinfosecurity.com/breaches-investigation-challenges-a-4814</link>
			<guid>http://www.govinfosecurity.com/breaches-investigation-challenges-a-4814</guid>
			<description>&lt;img src="http://docs.govinfosecurity.com/files/images_articles/4814_ostertag_dave_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;Tracking a Payments Breach Can Take Months, Investigator Says&lt;/b&gt;&lt;br&gt;Why are breaches in the payments arena so difficult to trace and investigate? Verizon breach investigator Dave Ostertag offers insights about the forensics complexities of a processor breach.</description>
			</item>
			<item>
			<title>9 Principles to Battle Botnets</title>
			<link>http://www.govinfosecurity.com/9-principles-to-battle-botnets-a-4812</link>
			<guid>http://www.govinfosecurity.com/9-principles-to-battle-botnets-a-4812</guid>
			<description>&lt;img src="http://docs.govinfosecurity.com/files/images_articles/4812_bot_net_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;Feds, Business Team Up to Limit Harm Caused by Botnets&lt;/b&gt;&lt;br&gt;The proliferation of botnets and malware in cyberspace threatens to undermine the efficiencies, innovation and economic growth of the Internet and diminishes the trust and confidence of online users.</description>
			</item>
			<item>
			<title>Pension Hack Exposed 123,000 Accounts</title>
			<link>http://www.govinfosecurity.com/pension-hack-exposed-123000-accounts-a-4811</link>
			<guid>http://www.govinfosecurity.com/pension-hack-exposed-123000-accounts-a-4811</guid>
			<description>&lt;img src="http://docs.govinfosecurity.com/files/images_articles/4811_logo_thrift_savings_plan_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;What Was the Motivation Behind the Federal Attack?&lt;/b&gt;&lt;br&gt;An attack on the Thrift Savings Plan exposed personal details about more than 120,000 federal pension participants. Learn why one expert says the breach could have serious long-term implications.</description>
			</item>
			<item>
			<title>NIST Issues Long-Awaited Cloud Guidance</title>
			<link>http://www.govinfosecurity.com/nist-issues-long-awaited-cloud-guidance-a-4810</link>
			<guid>http://www.govinfosecurity.com/nist-issues-long-awaited-cloud-guidance-a-4810</guid>
			<description>&lt;img src="http://docs.govinfosecurity.com/files/images_articles/4810_NIST_logo_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;SP 800-146 Describes Cloud's Strengths, Weaknesses&lt;/b&gt;&lt;br&gt;The National Institute of Standards and Technology's guidance recommends how and when cloud computing is appropriate, addresses risk management issues and indicates the limits of current knowledge and areas for future research and analysis.</description>
			</item>
			<item>
			<title>DoD: Notice of Proposed Rulemaking on Privacy Training</title>
			<link>http://www.govinfosecurity.com/agency-releases/dod-notice-proposed-rulemaking-on-privacy-training-r-2575</link>
			<guid>http://www.govinfosecurity.com/agency-releases/dod-notice-proposed-rulemaking-on-privacy-training-r-2575</guid>
			<description>The Department of Defense and two other government agencies have issued a proposed rule designed to help ensure that government contractors provide adequate privacy training to their staff members.</description>
			</item>
			<item>
			<title>NIST SP 800-61 Revision 1: Computer Security Incident Handling Guide</title>
			<link>http://www.govinfosecurity.com/agency-releases/nist-sp-800-61-revision-1-computer-security-incident-handling-r-2383</link>
			<guid>http://www.govinfosecurity.com/agency-releases/nist-sp-800-61-revision-1-computer-security-incident-handling-r-2383</guid>
			<description>Guidance on establishing processes to rapidly detect and respond to cyber incidents.</description>
			</item>
			<item>
			<title>NIST FIPS PUB 201-2: Personal Identity Verification of Federal Employees and Contractors DRAFT</title>
			<link>http://www.govinfosecurity.com/agency-releases/nist-fips-pub-201-2-personal-identity-verification-federal-r-2379</link>
			<guid>http://www.govinfosecurity.com/agency-releases/nist-fips-pub-201-2-personal-identity-verification-federal-r-2379</guid>
			<description>Specifying architecture and technical requirements for a common identification standard for federal employees and contractors.</description>
			</item>
			<item>
			<title>NIST SP 800-39: Managing Information Security Risk</title>
			<link>http://www.govinfosecurity.com/agency-releases/nist-sp-800-39-managing-information-security-risk-r-2353</link>
			<guid>http://www.govinfosecurity.com/agency-releases/nist-sp-800-39-managing-information-security-risk-r-2353</guid>
			<description>Organization, Mission and Information System View</description>
			</item>
			<item>
			<title>2012 Cloud Security Agenda: Expert Insights on Security and Privacy in the Cloud</title>
			<link>http://www.govinfosecurity.com/webinars/2012-cloud-security-agenda-expert-insights-on-security-privacy-in-cloud-w-276</link>
			<guid>http://www.govinfosecurity.com/webinars/2012-cloud-security-agenda-expert-insights-on-security-privacy-in-cloud-w-276</guid>
			<description>What are organizations' top cloud security concerns, and how are security leaders addressing these concerns through policy, technology and improved vendor management?
&lt;p&gt;&lt;p&gt;
This is the key question posed by the 2012 Cloud Security Survey.
&lt;p&gt;
No longer just an emerging technology practice, cloud computing today is embraced globally as a means of gaining efficient access to critical applications, processes and storage. It's now common for organizations to rely on cloud service providers for functions and business applications such as customer relationship management, messaging or storage via a public, private or hybrid cloud. Further, industry-specific cloud-based applications such as electronic health records or mobile banking and payment applications are emerging at an unprecedented pace.
&lt;p&gt;
But these engagements come with questions about risks:
&lt;ul&gt;
&lt;li&gt;What are your cloud service provider's security and privacy measures, and have they been audited?&lt;/li&gt;
&lt;li&gt;Where geographically is cloud data being stored, and how do operational practices comply with government, industry and organizational privacy regulations?&lt;/li&gt;
&lt;li&gt;How is a multi-tenant cloud environment managed, and in the event of system compromise - what will be the incident response escalation process?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
Yes, cloud computing is about efficiencies and new technologies, but it's also about security, privacy and an organization's reputation.
&lt;p&gt;
The 2012 Cloud Security Survey was crafted with assistance from leading experts in cloud computing, security and privacy, with a mission to:
&lt;ul&gt;
&lt;li&gt;Chart the latest cloud trends, including types of cloud implementations most common by industry and region;&lt;/li&gt;
&lt;li&gt;Gauge organizations' top cloud security concerns, from vendor security to data governance and breach preparedness;&lt;/li&gt;
&lt;li&gt;Predict the top areas of investment for organizations most concerned about cloud security.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;
This webinar will draw upon survey results and expert insight from a special roundtable panel to discuss:
&lt;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Top Security Concerns&lt;/b&gt; - Are organizations more concerned about where their data is stored, or whether a malicious insider might be a threat to it?&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Success Factors&lt;/b&gt; - On a scale with cost savings and availability of services, how does security now rank among elements critical to a successful cloud computing implementation?&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Protective Measures&lt;/b&gt; - What are some of the practices organizations are employing, from instituting more stringent contracts to enforcing third-party audits and even participating in mock security exercises with cloud service providers?&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;</description>
			</item>
			<item>
			<title>Protect IBM i Data from FTP, ODBC and Remote Command</title>
			<link>http://www.govinfosecurity.com/webinars/protect-ibm-i-data-from-ftp-odbc-remote-command-w-272</link>
			<guid>http://www.govinfosecurity.com/webinars/protect-ibm-i-data-from-ftp-odbc-remote-command-w-272</guid>
			<description>Each year, PowerTech releases its "State of IBM i Security" study, documenting how well organizations manage their security. And, each year, the  study shows that the vast majority of organizations still rely on menu security to protect their data. Unfortunately, today's users have access to interfaces (such as FTP, ODBC, JDBC, and remote command) that completely bypass these controls and make it easy to view, update, and delete data in the database. If you need to comply with government or industry regulations, or if you simply want to ensure the integrity of your application data, understanding these interfaces is critical. 
&lt;p&gt;
In this webinar, Robin Tatam, Director of Security Technologies for PowerTech, discusses: 
&lt;p&gt;
&lt;ul&gt;
&lt;li&gt;What you need to know about IBM i security&lt;/li&gt;
&lt;li&gt;How to close the "back doors" not covered by traditional menu security schemes&lt;/li&gt;
&lt;li&gt;How to implement policies that restrict access to only those users who need it&lt;/li&gt;
&lt;/ul&gt;
Tatam also demonstrates PowerTech's Network Security, the exit point monitoring and access control software that can help you secure your system.</description>
			</item>
			<item>
			<title>2012 Faces of Fraud Survey: Complying with the FFIEC Guidance</title>
			<link>http://www.govinfosecurity.com/webinars/2012-faces-fraud-survey-complying-ffiec-guidance-w-270</link>
			<guid>http://www.govinfosecurity.com/webinars/2012-faces-fraud-survey-complying-ffiec-guidance-w-270</guid>
			<description>A follow-up to ISMG's 2011 Faces of Fraud Survey, this webinar looks not only at the latest fraud trends and how institutions are fighting back, but also at their progress in putting together layered security controls in conformance with the FFIEC Authentication Guidance.
&lt;p&gt;
&lt;p&gt;
Given the persistence of fraud threats and the demands of the FFIEC Authentication Guidance, the 2012 Faces of Fraud Survey is crafted with assistance from leading experts in fraud detection and prevention, with a mission to: 
&lt;ul&gt;
&lt;li&gt;Chart the latest fraud trends, including account takeover, skimming and payment card breaches;&lt;/li&gt;
&lt;li&gt;Gauge institutions' preparedness to conform to the FFIEC Authentication Guidance, including where they are prioritizing their efforts;&lt;/li&gt;
&lt;li&gt;Predict the top areas of focus for 2012, from real-time fraud monitoring tools to new layered security controls.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;</description>
			</item>
			<item>
			<title>The Great Application Security Debate: Static vs. Dynamic vs. Manual Penetration Testing</title>
			<link>http://www.govinfosecurity.com/webinars/great-application-security-debate-static-vs-dynamic-vs-manual-w-268</link>
			<guid>http://www.govinfosecurity.com/webinars/great-application-security-debate-static-vs-dynamic-vs-manual-w-268</guid>
			<description>Software applications are an integral part of 21st century business processes. The majority  of  software  is  still  installed  in-house,  either  as  specially  developed custom applications or commercially acquired packages. However, the proportion of software procured as a service is on the rise, as is the use of mobile apps and open source components. In addition, more and more in-house applications are being web-enabled and exposed to the outside world. 
&lt;p&gt;
&lt;p&gt;
Regardless of its origin, the vast majority of software will contain flaws which can constitute a security risk, especially for those applications that are web-enabled. The cost of fixing a flaw increases the later that they are found in the development, acquisition and deployment life-cycle. There are a number of measures that can be taken to mitigate the problem and reduce the overall cost of managing software whilst ensuring better security. Increasingly, businesses are recognizing the benefits of outsourcing at least some of the effort through the use of on-demand software testing services. 
&lt;p&gt; 
This webinar explores how businesses are deploying software and what measures are in place for checking the security of applications. This webinar will present new research conducted amongst US and UK enterprises from a range of industries and assesses the scale of the software security problem, the ways in which it can be mitigated, the extent to which this is being achieved, the costs involved and how these can be minimized.
&lt;p&gt;
&lt;ul&gt;
&lt;li&gt;2011 was the Year of the Breach. Some of the world's best companies and brands were attacked making securing your enterprise applications a key information security imperative.&lt;/li&gt;
&lt;li&gt;As applications become more mission critical to the enterprise, so too does the need to secure them.&lt;/li&gt;
&lt;li&gt;Learn how enterprises can leverage the various application testing approaches in their application security programs.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;</description>
			</item>
			<item>
			<title>Five Application Security Tips</title>
			<link>http://www.govinfosecurity.com/interviews/five-application-security-tips-i-1571</link>
			<guid>http://www.govinfosecurity.com/interviews/five-application-security-tips-i-1571</guid>
			<description>Many organizations aren't devoting enough resources to ensure that applications for &lt;a href=" http://www.healthcareinfosecurity.com/mobility-c-212"&gt;&lt;b&gt;mobile devices&lt;/b&gt;&lt;/a&gt; are secure, says security expert Jeff Williams. He offers five tips for adequately addressing mobile &lt;a href=" http://www.healthcareinfosecurity.com/application-security-c-205"&gt;&lt;b&gt;application security&lt;/b&gt;&lt;/a&gt;.</description>
			</item>
			<item>
			<title>Understanding Electronically Stored Info</title>
			<link>http://www.govinfosecurity.com/interviews/understanding-electronically-stored-info-i-1570</link>
			<guid>http://www.govinfosecurity.com/interviews/understanding-electronically-stored-info-i-1570</guid>
			<description>For years, David Matthews, Deputy CISO of the City of Seattle, has been immersed in securing electronically stored information. Now he's written the book on the topic. What are the key themes addressed?</description>
			</item>
			<item>
			<title>Why Boards of Directors Don't Get It</title>
			<link>http://www.govinfosecurity.com/interviews/boards-directors-dont-get-it-i-1569</link>
			<guid>http://www.govinfosecurity.com/interviews/boards-directors-dont-get-it-i-1569</guid>
			<description>IT risk management, cyber insurance, privacy - these are hot topics for security leaders, but not for their boards of directors. Why do senior executives still fail to see IT risks as business risks?</description>
			</item>
			<item>
			<title>How to Respond to Hacktivism</title>
			<link>http://www.govinfosecurity.com/interviews/how-to-respond-to-hacktivism-i-1568</link>
			<guid>http://www.govinfosecurity.com/interviews/how-to-respond-to-hacktivism-i-1568</guid>
			<description>Hacktivist attacks will increase, and researcher Gregory Nowak says organizations can take proactive steps to reduce exposure and protect brand reputation. Why, then, are many organizations failing?</description>
			</item>
			<item>
			<title>Imagine This: NSA Supervising Bank IT</title>
			<link>http://www.govinfosecurity.com/blogs/imagine-this-nsa-supervising-bank-it-p-1281</link>
			<guid>http://www.govinfosecurity.com/blogs/imagine-this-nsa-supervising-bank-it-p-1281</guid>
			<description>&lt;b&gt;Not Likely in U.S., But Such a Scenario Is Developing in Israel&lt;/b&gt;&lt;br /&gt;Israel's intelligence agency supervises commercial banks' IT systems because they're considered part of the critical national infrastructure, and that's okay with the bankers. See why.</description>
			</item>
			<item>
			<title>Israel Seen Fanning Flame of New Spyware</title>
			<link>http://www.govinfosecurity.com/blogs/israel-seen-fanning-flame-new-spyware-p-1280</link>
			<guid>http://www.govinfosecurity.com/blogs/israel-seen-fanning-flame-new-spyware-p-1280</guid>
			<description>&lt;b&gt;Top Government Official Hints Israel is Behind Complex Malware&lt;/b&gt;&lt;br /&gt;Israel is being blamed - or, perhaps, taking credit - for the creation of Flame, the sophisticated cyberspyware that has targeted organizations in the Middle East, especially its mortal enemy, the government of Iran.</description>
			</item>
			<item>
			<title>2006 VA Breach: Assessing the Impact</title>
			<link>http://www.govinfosecurity.com/blogs/2006-va-breach-assessing-impact-p-1279</link>
			<guid>http://www.govinfosecurity.com/blogs/2006-va-breach-assessing-impact-p-1279</guid>
			<description>&lt;b&gt;Significant Action Taken, Lots More to Do&lt;/b&gt;&lt;br /&gt;It's been six years since the Department of Veterans Affairs experienced a huge breach. What breach-prevention steps has the VA taken since then, and what's left to be done?</description>
			</item>
			<item>
			<title>Fighting Hackers With Public Relations</title>
			<link>http://www.govinfosecurity.com/blogs/fighting-hackers-public-relations-p-1278</link>
			<guid>http://www.govinfosecurity.com/blogs/fighting-hackers-public-relations-p-1278</guid>
			<description>&lt;b&gt;Understanding Hacktivists' Goals is Key to Thwarting Attacks&lt;/b&gt;&lt;br /&gt;By understanding the motivations behind hacktivism, organizations can learn why good public relations can play an important role in thwarting attacks or minimizing their impact.</description>
			</item></channel></rss>

