<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Practical Issues in InfoSec &#187; Government</title>
	<atom:link href="http://www.dlstrom.com/category/government/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.dlstrom.com</link>
	<description>... putting information security within reach of everyone!</description>
	<lastBuildDate>Tue, 27 Jul 2010 13:26:02 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Youth Safety on a Living Internet</title>
		<link>http://www.dlstrom.com/2010/06/28/youth-safety-on-a-living-internet/</link>
		<comments>http://www.dlstrom.com/2010/06/28/youth-safety-on-a-living-internet/#comments</comments>
		<pubDate>Mon, 28 Jun 2010 14:05:47 +0000</pubDate>
		<dc:creator>d.strom, cissp, gsec, gsna</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[K-12 Education]]></category>
		<category><![CDATA[NTIA]]></category>
		<category><![CDATA[OSTWG]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=324</guid>
		<description><![CDATA[Earlier in the month, the Online Safety and Technology Working Group within the NTIA submitted their report entitled Youth Safety on a Living Internet, along with their recommendations to the Dept of Commerce and members of the House and Senate. Here is a summary of the objectives of the report which is take directly from [...]]]></description>
			<content:encoded><![CDATA[<p>Earlier in the month, the <a href="http://www.ntia.doc.gov/advisory/onlinesafety/">Online Safety and Technology Working Group</a> within the NTIA submitted their report entitled <a href="http://www.ntia.doc.gov/reports/2010/OSTWG_Final_Report_060410.pdf">Youth Safety on a Living Internet</a>, along with their recommendations to the Dept of Commerce and members of the House and Senate.</p>
<p>Here is a summary of the objectives of the report which is take directly from the introductory comments&#8230;</p>
<blockquote>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;">On behalf of the Online Safety and Technology Working Group (OSTWG), we are pleased to transmit this report to you. As mandated, we reviewed and evaluated:</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;"> </p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;">1.<span style="white-space: pre;"> </span>The status of industry efforts to promote online safety through educational efforts, parental control technology, blocking and filtering software, age-appropriate labels for content or other technologies or initiatives designed to promote a safe online environment for children;</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;"> </p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;">2.<span style="white-space: pre;"> </span>The status of industry efforts to promote online safety among providers of electronic communications services and remote computing services by reporting apparent child pornography, including any obstacles to such reporting;</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;"> </p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;">3.<span style="white-space: pre;"> </span>The practices of electronic communications service providers and remote computing service providers related to record retention in connection with crimes against children; and</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;"> </p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;">4.<span style="white-space: pre;"> </span>The development of technologies to help parents shield their children from inappropriate material on the Internet.</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;"> </p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;">The report contains recommendations in each of the above categories, as well some general recommendations. We believe these recommendations will further advance our collective goal to provide a safer online experience to our children.﻿</p>
</blockquote>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;"><span style="color: #000000;"><span style="font-size: medium;"><span style="color: #1a1a18;"><br /></span></span></span></p>
<p>This is an important document. If you have children, know children or are involved with kids at church or school you should take the time to read this report.</p>
<p>- Dan</p>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2010/06/28/youth-safety-on-a-living-internet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyberwar &#8211; Halted ’03 Iraq Plan Illustrates U.S. Fear of Cyberwar Risk &#8211; Series &#8211; NYTimes.com</title>
		<link>http://www.dlstrom.com/2009/08/03/cyberwar-halted-%e2%80%9903-iraq-plan-illustrates-u-s-fear-of-cyberwar-risk-series-nytimes-com/</link>
		<comments>http://www.dlstrom.com/2009/08/03/cyberwar-halted-%e2%80%9903-iraq-plan-illustrates-u-s-fear-of-cyberwar-risk-series-nytimes-com/#comments</comments>
		<pubDate>Mon, 03 Aug 2009 13:02:49 +0000</pubDate>
		<dc:creator>d.strom, cissp, gsec, gsna</dc:creator>
				<category><![CDATA[CyberSecurity]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[Iraq]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=272</guid>
		<description><![CDATA[Cyberwar &#8211; Halted ’03 Iraq Plan Illustrates U.S. Fear of Cyberwar Risk &#8211; Series &#8211; NYTimes.com This came across Twitter this morning. If you have any interest in cyberwarfare and the implications, you should read this. According to the article, this was scrapped, but yet many aspects are still classified. The plan was to use [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.nytimes.com/2009/08/02/us/politics/02cyber.html?_r=3&#038;hpw">Cyberwar &#8211; Halted ’03 Iraq Plan Illustrates U.S. Fear of Cyberwar Risk &#8211; Series &#8211; NYTimes.com</a></p>
<p>This came across Twitter this morning. If you have any interest in cyberwarfare and the implications, you should read this. According to the article, this was scrapped, but yet many aspects are still classified.</p>
<p>The plan was to use a cyberattack to freeze financial assets of Saddam Hussein.</p>
<p>Take a look at this&#8230;</p>
<blockquote><p>“We knew we could pull it off — we had the tools,” said one senior official who worked at the Pentagon when the highly classified plan was developed.</p></blockquote>
<p>The U.S. Government had the technology and abilities. Later it is revealed that the attack was not authorized because of fears over worldwide financial fallout.</p>
<p>It seems like the prudent course of action was taken here. Just because you <em>can</em> do something doesn&#8217;t mean that you <em>should</em>.</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2009/08/03/cyberwar-halted-%e2%80%9903-iraq-plan-illustrates-u-s-fear-of-cyberwar-risk-series-nytimes-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>July 2009 DDoS thoughts</title>
		<link>http://www.dlstrom.com/2009/07/08/july-2009-ddos-thoughts/</link>
		<comments>http://www.dlstrom.com/2009/07/08/july-2009-ddos-thoughts/#comments</comments>
		<pubDate>Wed, 08 Jul 2009 13:07:05 +0000</pubDate>
		<dc:creator>d.strom, cissp, gsec, gsna</dc:creator>
				<category><![CDATA[CyberSecurity]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[DDoS]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=257</guid>
		<description><![CDATA[Reports are coming out this morning of distributed denial of service attacks coming from North Korea and targeting South Korean government and business web sites. I heard one report which stated that US government sites are also being targeted. I&#8217;ve never really thought USA Today was a bastion of InfoSec news, but they have a [...]]]></description>
			<content:encoded><![CDATA[<p>Reports are coming out this morning of distributed denial of service attacks coming from North Korea and targeting South Korean government and business web sites. I heard one report which stated that US government sites are also being targeted.</p>
<p>I&#8217;ve never really thought USA Today was a bastion of InfoSec news, but they have a report <a href="http://www.usatoday.com/news/world/2009-07-08-northkorea-cyberattacks_N.htm">here</a> that gives a basic understanding of what is going on.</p>
<p>It is evident that the information is not complete. Unnamed sources that are &#8220;not authorized&#8221; to speak are providing sanitized information.</p>
<p>I would expect there to be more information coming out a little at a time.</p>
<p><strong>UPDATE</strong>: Information is starting to come out <a href="http://www.google.com/hostednews/ap/article/ALeqM5icTKBW9_fm-oKDzns75BI-ykokSwD999UN580">http://www.google.com/hostednews/ap/article/ALeqM5icTKBW9_fm-oKDzns75BI-ykokSwD999UN580</a>.</p>
<p>My plan is to use this as an opportunity and reminder to revisit our plans and procedures in the event any of our computers are a part of a botnet, or in the event our organization becomes a target.</p>
<p>Steps I plan to take specifically for this threat:</p>
<ul>
<li>
Work with ISP to make sure that they are filtering DDoS at their routers for traffic that is headed our way.</li>
<li>
Verify that all of our computers have current antivirus running and that signatures are current.</li>
<li>
Force an AV scan on all workstations.</li>
<li>
Force an AV scan on all servers using a secondary AV engine.</li>
<li>
Monitor in-bound traffic closely and pay attention to alerts.</li>
<li>
Notify Management of the situation if anything begins to develop.</li>
</ul>
<p>Sleep tight, y&#8217;all.</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2009/07/08/july-2009-ddos-thoughts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Know Thy Vendors</title>
		<link>http://www.dlstrom.com/2008/05/02/know-thy-vendors/</link>
		<comments>http://www.dlstrom.com/2008/05/02/know-thy-vendors/#comments</comments>
		<pubDate>Fri, 02 May 2008 22:06:34 +0000</pubDate>
		<dc:creator>d.strom, cissp, gsec, gsna</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[K-12 Education]]></category>
		<category><![CDATA[Vendor Management]]></category>

		<guid isPermaLink="false">http://dlstrom.com/wp/?p=21</guid>
		<description><![CDATA[Computerworld reported last week that more people have been indicted on E-Rate fraud charges. Basically they have been accused of stealing money that was intended to help schools and libraries with technology for education. It is important that you know your vendors. Many vendors will approach schools with proposals for solutions they say qualify for [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&#038;articleId=9080659&#038;source=NLT_AM&#038;nlid=1"><b>Computerworld</b></a> reported last week that more people have been indicted on <a href="http://www.fcc.gov/learnnet/welcome.html"><b>E-Rate</b></a> fraud charges. Basically they have been accused of stealing money that was intended to help schools and libraries with technology for education.</p>
<p>It is important that you know your vendors. Many vendors will approach schools with proposals for solutions they say qualify for E-Rate funding. Sometimes the school or library will create an RFP (Request for Proposal) and send to potential vendors. While the technology may qualify, not all vendors are created equal. How are we to know which vendors are reputable?</p>
<ul>
<li><strong>References</strong> &#8211; Ask for at least four companies or schools that this vendor has done work for. Contact these organizations and get their opinions on the quality, timliness and cost of the work. Find out about any negative interactions with the company. This would be very similar to checking references for a possible new employee.</li>
<li><strong>Research</strong> &#8211; Do your own research into the vendor. How long have they been in business? How big is the company? You are seeking information that will give you an idea of the stability and longevity of the company. You want to make sure that this vendor will be around in case there are issues following the project implementation.</li>
<li><strong>Warranty or money back guarantee</strong> &#8211; We all want a project to be done on time and within budget. We also expect the solution to work as presented. But, sometimes these things don&#8217;t happen. Does this vendor offer any warranty on their work or a money back guarantee in the event of a complete failure to deliver?</li>
<li><strong>Capability</strong> &#8211; This seems obvious, but does this company have the expertise and capability to deliver on what they are selling?</li>
<li><strong>Design</strong> &#8211; If an RFP has been developed and sent out, you should closely review the proposals that are returned by the vendors. Make sure that their solutions really fit the requirements and that extraneous items are not included. You can be assured that if they are trying to get unneeded items or work into their proposal then they are not a company you want to enter into a relationship with. You want to be able to trust your vendors.</li>
</ul>
<p>The vast majority of vendors are reputable. Only a few are guilty of fraudulent behavior. Do you homework and you will be able to avoid the ones working to rip you off.</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2008/05/02/know-thy-vendors/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
