<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The New New Internet &#187; Amara Channell</title>
	<atom:link href="http://www.thenewnewinternet.com/author/amara-channell/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thenewnewinternet.com</link>
	<description>The Latest News in Cybersecurity</description>
	<lastBuildDate>Fri, 10 Feb 2012 18:32:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Kundra Creates Blog to Accompany Federal IT Dashboard</title>
		<link>http://www.thenewnewinternet.com/2009/07/15/kundra-creates-blog-to-accompany-federal-it-dashboard/</link>
		<comments>http://www.thenewnewinternet.com/2009/07/15/kundra-creates-blog-to-accompany-federal-it-dashboard/#comments</comments>
		<pubDate>Wed, 15 Jul 2009 19:39:25 +0000</pubDate>
		<dc:creator>Amara Channell</dc:creator>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Federal IT Dashboard]]></category>
		<category><![CDATA[Vivek Kundra]]></category>

		<guid isPermaLink="false">http://thenewnewinternet.com/?p=1039</guid>
		<description><![CDATA[Vivek Kundra, the Federal Chief Information Officer, has started a blog to accompany the Federal IT Dashboard that was launched just two weeks ago. The blog is designed to start a conversation on the public’s views of the site and share information that is not included on the actual IT Dashboard site. According to Kundra, [...]]]></description>
			<content:encoded><![CDATA[<p>Vivek Kundra, the Federal Chief Information Officer, has started a blog to accompany the Federal IT Dashboard that was launched just two weeks ago. The blog is designed to start a conversation on the public’s views of the site and share information that is not included on the actual IT Dashboard site.</p>
<p>According to <a href="http://www.fiercegovernmentit.com/story/kundras-blog-joins-it-dashboard/2009-07-14?utm_medium=nl&amp;utm_source=internal">Kundra</a>, &#8220;[W]e can&#8217;t simply make this an exercise in federal agency reporting, that is why we started this blog. We want to hear from you about what works and what doesn&#8217;t with the site. Is there a more innovative approach that an investment should consider? Does the contract data look incorrect to you? Is there an application that we should add? This is a site to serve you, and to do that, we need to hear from you.&#8221;</p>
<p>The Federal IT Dashboard, </span><a href="http://it.usaspending.gov/" target="_BLANK㵤〲芄殼㌀㋰〲"><span style="font-size: small; font-family: Times New Roman;">http://it.usaspending.gov</span></a> tracks U.S. government spending on information technology and the progress of various IT projects.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thenewnewinternet.com/2009/07/15/kundra-creates-blog-to-accompany-federal-it-dashboard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Study Finds Social Security Numbers to be Compromised</title>
		<link>http://www.thenewnewinternet.com/2009/07/09/study-finds-social-security-numbers-to-be-compromised/</link>
		<comments>http://www.thenewnewinternet.com/2009/07/09/study-finds-social-security-numbers-to-be-compromised/#comments</comments>
		<pubDate>Thu, 09 Jul 2009 17:57:42 +0000</pubDate>
		<dc:creator>Amara Channell</dc:creator>
				<category><![CDATA[Cyber]]></category>
		<category><![CDATA[SSA]]></category>

		<guid isPermaLink="false">http://thenewnewinternet.com/?p=958</guid>
		<description><![CDATA[Researchers from Carnegie Melon University have found that Social Security numbers can be guessed based on easy to access information, such as individual&#8217;s birthday and the town in which they were born. Social Security  uses the same formula for all of the numbers, the first three numbers are based on the zip code on the application, [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-959" title="ssa" src="http://www.thenewnewinternet.com/wp-content/uploads/2009/07/ssa.jpg" alt="ssa" width="124" height="124" /></p>
<p>Researchers from Carnegie Melon University have found that Social Security numbers can be guessed based on easy to access information, such as individual&#8217;s birthday and the town in which they were born.</p>
<p>Social Security  uses the same formula for all of the numbers, the first three numbers are based on the zip code on the application, the forth and fifth are based on regional numbers that change slowly over several years, and the last four are assigned in sequential order. In the study, researchers used these commonly known facts about the Social Security numbers combined with the public “DeathMaster file” to guess SSNs. They were able to guess the first 5 numbers 40 percent of the time and all 9 numbers 8.5 percent of the time, in less than 1000 tries.</p>
<p>The numbers were even more accurate for people who have been born more recently, as the Enumeration at Birth Initiative of 1989 encouraged parents to sign their children up at birth. It was also easier to guess numbers in less populated states.</p>
<p>One of the <a href="http://www.washingtonpost.com/wp-dyn/content/article/2009/07/06/AR2009070602955.html?hpid=topnews">Carnegie Melon </a>researchers, Alessandro Acquisti stated, “Our work shows that Social Security numbers are compromised as authentication devices because if they are predictable from public data, then they can not be considered sensitive.”</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thenewnewinternet.com/2009/07/09/study-finds-social-security-numbers-to-be-compromised/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Is FISMA a “Showstopper” for Health IT?</title>
		<link>http://www.thenewnewinternet.com/2009/07/08/is-fisma-a-%e2%80%9cshowstopper%e2%80%9d-for-health-it/</link>
		<comments>http://www.thenewnewinternet.com/2009/07/08/is-fisma-a-%e2%80%9cshowstopper%e2%80%9d-for-health-it/#comments</comments>
		<pubDate>Wed, 08 Jul 2009 16:26:23 +0000</pubDate>
		<dc:creator>Amara Channell</dc:creator>
				<category><![CDATA[GovCon Industry]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Julie Boughn]]></category>
		<category><![CDATA[Vish Sankaran]]></category>

		<guid isPermaLink="false">http://thenewnewinternet.com/?p=930</guid>
		<description><![CDATA[As the “meaningful use” criteria is being written for the adoption of health IT for healthcare providers, government officials are beginning to worry about the implications of the Federal Information Security Management Act (FISMA) regulations on such a new industry. Many organizations are struggling to meet the Health Insurance Portability and Accountability Act (HIPAA) regulations [...]]]></description>
			<content:encoded><![CDATA[<p>As the “meaningful use” criteria is being written for the adoption of health IT for healthcare providers, government officials are beginning to worry about the implications of the Federal Information Security Management Act (FISMA) regulations on such a new industry. Many organizations are struggling to meet the Health Insurance Portability and Accountability Act (HIPAA) regulations and other state laws on security.  Some officials believe that forcing them to comply with FISMA as well could stop companies from adopting electronic health records (EHRs).</p>
<p><a href="http://govhealthit.com/docs/magazine/GHIT_v4n4_final_cover.pdf">Vish Sankaran</a>, Director of the Federal Health Architecture for the Office of the National Coordinator, called FISMA “a showstopper for us.”</p>
<p>Under FISMA regulations, private-sector healthcare would have to meet FISMA standards before receiving information from the National Health Information Network (NHIN). Government officials are looking to the Office of Management and Budget to set lower guidelines that would allow private-sector providers to exchange information with federal agencies without full adoption of FISMA.</p>
<p>Julie Boughn, the CIO for the Center for Medicaid Services (CMS), believes that health providers should have strict FISMA-like standards because it is a good business practice, yet she does not want government agencies to be stuck with the job of certifying all of the companies. She thinks that they should set their own standards, similar to the way that online stores set theirs.</p>
<p>Boughn said “we should be doing this because if the public would lose confidence in us, then we would set this goal of electronic health records back,” but she also believes that “scaling FISMA oversight to millions of healthcare providers would be a daunting and expensive challenge.”</p>
<p>What officials are calling for is some sort of compromise between the two sets of regulations. Sankaran has suggested a “HIPAA-plus” or “FISMA-lite” set of standards that would create a realistic system for certifying private healthcare providers. HIPAA, which was designed for hospitals and doctors before the electronic age, has only 101 security controls while FISMA has 171 controls.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thenewnewinternet.com/2009/07/08/is-fisma-a-%e2%80%9cshowstopper%e2%80%9d-for-health-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GAO Proposes Changes to FISMA</title>
		<link>http://www.thenewnewinternet.com/2009/07/02/gao-proposes-changes-to-fisma/</link>
		<comments>http://www.thenewnewinternet.com/2009/07/02/gao-proposes-changes-to-fisma/#comments</comments>
		<pubDate>Thu, 02 Jul 2009 14:13:58 +0000</pubDate>
		<dc:creator>Amara Channell</dc:creator>
				<category><![CDATA[Cyber]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[GAO]]></category>

		<guid isPermaLink="false">http://thenewnewinternet.com/?p=820</guid>
		<description><![CDATA[The Government Accountablitity Office has written a letter, to the House Oversight and Government Reform Committee’s Government Management, Organization and Procurement Subcommittee, proposing changes to the Federal Information Security Management Act of 2002. They believe that the changes would decrease the amount of risk involved in federal information security.   The GAO has proposed that [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="font-size: small;"><span style="font-family: Times New Roman;"><span style="COLOR: black">The Government Accountablitity Office has written a letter, to the </span><span style="COLOR: black; mso-ansi-language: EN" lang="EN">House <img class="alignright size-full wp-image-821" title="gao" src="http://www.thenewnewinternet.com/wp-content/uploads/2009/07/gao.png" alt="gao" width="156" height="156" />Oversight and Government Reform Committee’s Government Management, Organization and Procurement Subcommittee,</span><span style="COLOR: black" lang="EN"> </span><span style="COLOR: black">proposing changes to the </span><span style="COLOR: black; mso-ansi-language: EN" lang="EN">Federal Information Security Management Act of 2002. They believe that the changes would decrease the amount of risk involved in federal information security. </span></span></span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="COLOR: black; mso-ansi-language: EN" lang="EN"><span style="font-size: small; font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="COLOR: black; mso-ansi-language: EN" lang="EN"><span style="font-size: small;"><span style="font-family: Times New Roman;">The GAO has proposed that although FISMA has sound risk-management principles, the testing, reporting, and oversight requirements need to be more specific. They also believe that Congress should require Agency heads to give written guarantees that their information security programs are effective.</span></span></span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="COLOR: black; mso-ansi-language: EN" lang="EN"><span style="font-size: small; font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="COLOR: black; mso-ansi-language: EN" lang="EN"><span style="font-size: small;"><span style="font-family: Times New Roman;"><span style="mso-spacerun: yes"> </span>FISMA was designed to provide a standardized way of securing government information technology resources but in the last three years security incidents have tripled and at least 20 of 24 government agencies have weak information system programs and security controls. </span></span></span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="COLOR: black; mso-ansi-language: EN" lang="EN"><span style="font-size: small; font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0in 0in 7.5pt"><span style="COLOR: black; mso-ansi-language: EN" lang="EN"><span style="font-size: small;"><span style="font-family: Times New Roman;">According to the letter, “Clarifying or strengthening FISMA and its implementing guidance for determining the frequency, depth and breadth of security control tests and evaluations could help agencies better assess the effectiveness of the controls protecting the information and systems supporting their programs, operations and assets.” </span></span></span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="COLOR: black"><span style="font-size: small; font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="COLOR: black; mso-ansi-language: EN" lang="EN"><span style="font-size: small;"><span style="font-family: Times New Roman;">In their letter <a href="http://gcn.com/articles/2009/07/01/gao-congress-fisma-improvements.aspx">GAO</a> suggested the following changes:</span></span></span></p>
<ul>
<li>
<div class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="font-size: small;"><span style="font-family: Times New Roman;"><span style="COLOR: black; mso-ansi-language: EN" lang="EN">Developing a national strategy that clearly articulates strategic objectives, goals and priorities. </span><span style="COLOR: black"></span></span></span></div>
</li>
<li>
<div class="MsoNormal" style="BACKGROUND: white; MARGIN: 0in 0in 0pt"><span style="COLOR: black; mso-ansi-language: EN" lang="EN"><span style="font-size: small;"><span style="font-family: Times New Roman;">Establishing White House leadership on the issue. </span></span></span></div>
</li>
<li>
<div class="MsoNormal" style="BACKGROUND: white; MARGIN: 0in 0in 0pt"><span style="COLOR: black; mso-ansi-language: EN" lang="EN"><span style="font-size: small;"><span style="font-family: Times New Roman;">Publicizing and raising awareness about the seriousness of the cybersecurity problem. </span></span></span></div>
</li>
<li>
<div class="MsoNormal" style="BACKGROUND: white; MARGIN: 0in 0in 0pt"><span style="COLOR: black; mso-ansi-language: EN" lang="EN"><span style="font-size: small;"><span style="font-family: Times New Roman;">Focusing more efforts on prioritizing assets, assessing vulnerabilities and reducing them than on developing additional plans. </span></span></span></div>
</li>
<li>
<div class="MsoNormal" style="BACKGROUND: white; MARGIN: 0in 0in 0pt"><span style="COLOR: black; mso-ansi-language: EN" lang="EN"><span style="font-size: small;"><span style="font-family: Times New Roman;">Bolstering public/private partnerships through an improved value proposition and use of incentives. </span></span></span></div>
</li>
<li>
<div class="MsoNormal" style="BACKGROUND: white; MARGIN: 0in 0in 0pt"><span style="COLOR: black; mso-ansi-language: EN" lang="EN"><span style="font-size: small;"><span style="font-family: Times New Roman;">Focusing greater attention on addressing the global aspects of cyberspace. </span></span></span></div>
</li>
<li>
<div class="MsoNormal" style="BACKGROUND: white; MARGIN: 0in 0in 0pt"><span style="COLOR: black; mso-ansi-language: EN" lang="EN"><span style="font-size: small;"><span style="font-family: Times New Roman;">Placing greater emphasis on cybersecurity research and development, including how to better coordinate government and private-sector efforts. </span></span></span></div>
</li>
<li>
<div class="MsoNormal" style="BACKGROUND: white; MARGIN: 0in 0in 0pt"><span style="COLOR: black; mso-ansi-language: EN" lang="EN"><span style="font-size: small;"><span style="font-family: Times New Roman;">Increasing the cadre of cybersecurity professionals.</span></span></span></div>
</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.thenewnewinternet.com/2009/07/02/gao-proposes-changes-to-fisma/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

