<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>uncompiled.com &#187; Government</title>
	<atom:link href="http://www.uncompiled.com/category/government/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.uncompiled.com</link>
	<description>Technology News That You Need</description>
	<lastBuildDate>Fri, 30 Jul 2010 01:19:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Defense Agency Expands Cloud Computing</title>
		<link>http://www.uncompiled.com/2010/07/defense-agency-expands-cloud-computing/</link>
		<comments>http://www.uncompiled.com/2010/07/defense-agency-expands-cloud-computing/#comments</comments>
		<pubDate>Fri, 30 Jul 2010 01:19:58 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Infrastructure]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1417</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>The Defense Information Systems Agency, an agency that&#8217;s already among the government leaders in cloud computing, is considering offering platform-as-a-service to other military agencies to complement the infrastructure-as-a-service that it already offers via its Rapid Access Computing Environment (RACE) private cloud.</p>
<p>Today, the PaaS offering is an early-stage pilot designed to meet a request from the Air Force, but a broader pilot is forthcoming. &#8220;The Air Force came to us and said, we not only want you to manage the infrastructure, but also the middleware,&#8221; Alfred Rivera, DISA&#8217;s director of computing services, said in a speech Wednesday at DISA&#8217;s Customer and Industry Forum in Washington, D.C.</p>
<p>As part of the PaaS offering, DISA would not just provide the servers themselves, but also the operating system stack and all support services below the application layer, including patching and managing the IT infrastructure.</p>
<p>More broadly, this new PaaS pilot is only one of several cloud computing and shared service projects DISA has in the works. There&#8217;s also a planned Microsoft SharePoint 2010 deployment, virtualized web-based versions of Microsoft Office apps hosted in DISA&#8217;s cloud, and a number of other services on the way. For example, Rivera said that DISA is also considering ways that it could potentially manage applications that don&#8217;t even necessarily reside in DISA data centers &#8212; IT service management as a service, he called it.</p>
<p>DISA&#8217;s VOffice pilot, disclosed earlier this summer, is now up to 1,000 users who have access to web-based versions of Microsoft Word, PowerPoint, Excel, and OneNote hosted in DISA&#8217;s cloud. It&#8217;s an effort that&#8217;s drawn the interest of the office of the Secretary of Defense, and will go into production in January, Rivera said.</p>
<p>The agency also plans to offer SharePoint as a service to other military agencies, with deployment of SharePoint 2010 slated to begin in January 2011.</p>
<p>RACE is also due for some upgrades and improvements, Rivera said. Deployment on the Department of Defense&#8217;s classified SIPRNet &#8212; which has seen a lot of demand, according to Rivera &#8212; is slated to begin by the end of September. Also coming are refinements to the RACE portal, integration with DISA&#8217;s configuration management system, and some automated security accreditation processes.</p>
<p>Eventually, DISA could even begin offering its services outside the Department of Defense. According to Rivera, DISA has had related discussions with the inter-agency Cloud Computing Advisory Council and agencies like the Department of State to discuss the possibilities, but for now, RACE&#8217;s access-control mechanism, which requires a military smartcard, remains a barrier.</p>
<p>DISA&#8217;s cloud push isn&#8217;t over, by a long shot. &#8220;We&#8217;re in the beginning stages, but this certainly allows you to move toward leveraging technology and processing speed without having to build the network and the infrastructure yourself,&#8221; DISA director Lt. Gen. Carroll Pollett said in an interview.</p>
<p><a href="http://www.informationweek.com/news/government/cloud-saas/showArticle.jhtml?articleID=226300273">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/07/defense-agency-expands-cloud-computing/&amp;n=Defense+Agency+Expands+Cloud+Computing&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/07/defense-agency-expands-cloud-computing/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/07/defense-agency-expands-cloud-computing/&amp;title=Defense+Agency+Expands+Cloud+Computing" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/07/defense-agency-expands-cloud-computing/&amp;t=Defense+Agency+Expands+Cloud+Computing" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/07/defense-agency-expands-cloud-computing/&amp;title=Defense+Agency+Expands+Cloud+Computing" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/07/defense-agency-expands-cloud-computing/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/07/defense-agency-expands-cloud-computing/&amp;title=Defense+Agency+Expands+Cloud+Computing&amp;srcUrl=http://www.uncompiled.com/2010/07/defense-agency-expands-cloud-computing/&amp;srcTitle=Defense+Agency+Expands+Cloud+Computing&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/07/defense-agency-expands-cloud-computing/&amp;title=Defense+Agency+Expands+Cloud+Computing&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Defense%20Agency%20Expands%20Cloud%20Computing%22&amp;body=Link: http://www.uncompiled.com/2010/07/defense-agency-expands-cloud-computing/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/07/defense-agency-expands-cloud-computing/&amp;t=Defense+Agency+Expands+Cloud+Computing" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/07/defense-agency-expands-cloud-computing/&amp;title=Defense+Agency+Expands+Cloud+Computing&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/07/defense-agency-expands-cloud-computing/&amp;title=Defense+Agency+Expands+Cloud+Computing" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/07/defense-agency-expands-cloud-computing/&amp;title=Defense+Agency+Expands+Cloud+Computing" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/07/defense-agency-expands-cloud-computing/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Defense+Agency+Expands+Cloud+Computing+-+http://b2l.me/admsfs&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/07/defense-agency-expands-cloud-computing/&amp;submitHeadline=Defense+Agency+Expands+Cloud+Computing&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Defense+Agency+Expands+Cloud+Computing&amp;body=Link: http://www.uncompiled.com/2010/07/defense-agency-expands-cloud-computing/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/07/defense-agency-expands-cloud-computing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Black Hat: U.S. Infrastructure Vulnerable To Cyber Attack</title>
		<link>http://www.uncompiled.com/2010/07/black-hat-u-s-infrastructure-vulnerable-to-cyber-attack/</link>
		<comments>http://www.uncompiled.com/2010/07/black-hat-u-s-infrastructure-vulnerable-to-cyber-attack/#comments</comments>
		<pubDate>Fri, 30 Jul 2010 01:18:41 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Conference]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Infrastructure]]></category>
		<category><![CDATA[Research]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1415</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Cyber terrorists have a number of ways to mount a major cyber attack on U.S. Internet infrastructure due to the general instability of its base, the director of the agency in charge of protecting the federal government&#8217;s IT network said Wednesday.</p>
<p>&#8220;With decades of IT infrastructure built to support changing technologies, there is little ability to baseline the entire infrastructure within the United States,&#8221; said Randy Vickers, director of the United States Computer Emergency Readiness Team (US-CERT), in an interview Wednesday. &#8220;This variety of platforms and applications provides many possible vectors by which to attack infrastructure.&#8221;</p>
<p>Vickers is scheduled to join other IT leaders from government agencies for a panel to discuss the threat of cyber war and how to deter it at the Black Hat security conference in Las Vegas on Thursday.</p>
<p>US-CERT is a division of the Department of Homeland Security (DHS) responsible for responding to and defending against cyber attacks for the federal government&#8217;s IT infrastructure. It also is in charge of sharing information and collaborating with state and local governments as well as the private sector to protect critical infrastructure in the U.S.</p>
<p>Vickers said that critical infrastructure is not likely to become less prone to attacks anytime soon. He cited ongoing changes in the IT landscape &#8212; such as cloud computing and an increasingly mobile workforce &#8212; as conditions that only open up infrastructure to more threats.</p>
<p>&#8220;The environment is only going to increase in complexity, and as more threat capabilities are developed the risk to our information infrastructure that we are so heavily dependent upon also increases,&#8221; he said.</p>
<p>To achieve its goal to keep an eye on federal networks, the DHS is currently deploying an intrusion-detection and security system called EINSTEIN 2, Vickers said. The system is currently operational at 12 of 19 federal agencies, providing US-CERT with, on average, visibility into more than 278,000 indicators of potentially malicious activity per month, he said.</p>
<p>EINSTEIN 2 should be fully deployed at the federal government by the end of the year, after which the DHS will take security to the next level with EINSTEIN 3, Vickers said.</p>
<p>EINSTEIN 3, developed by the National Security Agency, is the third phase of the Comprehensive National Cybersecurity Initiative (CNCI), and will provide intrusion prevention on top of EINSTEIN 2&#8242;s intrusion-detection capability, he said. The first phase of the system &#8212; EINSTEIN 1 &#8212; is currently in deployment as system that gathers information about network traffic.</p>
<p>US-CERT first revealed details about EINSTEIN 3 in March. At the time, the DHS said the system will do real-time, deep packet inspection and make decisions based on threats by examining network traffic at the edge of federal agency networks.</p>
<p>This activity will redirect agency Internet traffic to DHS cybersecurity systems, which will determine which traffic might be associated with cyber threats and how to respond, they said. The DHS worked with a commercial Internet service provider to do a test deployment of EINSTEIN 3 earlier this year. Vickers said these types of private-public partnerships will continue as the federal government continues to work to secure its network infrastructure against cyber attacks.</p>
<p>&#8220;At the end of the day, the architecture for the dot-gov&#8217;s cyber perimeter defense will be hybrid of government and private technologies,&#8221; he said.</p>
<p><a href="http://www.informationweek.com/news/government/security/showArticle.jhtml?articleID=226300202">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/07/black-hat-u-s-infrastructure-vulnerable-to-cyber-attack/&amp;n=Black+Hat%3A+U.S.+Infrastructure+Vulnerable+To+Cyber+Attack&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/07/black-hat-u-s-infrastructure-vulnerable-to-cyber-attack/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/07/black-hat-u-s-infrastructure-vulnerable-to-cyber-attack/&amp;title=Black+Hat%3A+U.S.+Infrastructure+Vulnerable+To+Cyber+Attack" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/07/black-hat-u-s-infrastructure-vulnerable-to-cyber-attack/&amp;t=Black+Hat%3A+U.S.+Infrastructure+Vulnerable+To+Cyber+Attack" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/07/black-hat-u-s-infrastructure-vulnerable-to-cyber-attack/&amp;title=Black+Hat%3A+U.S.+Infrastructure+Vulnerable+To+Cyber+Attack" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/07/black-hat-u-s-infrastructure-vulnerable-to-cyber-attack/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/07/black-hat-u-s-infrastructure-vulnerable-to-cyber-attack/&amp;title=Black+Hat%3A+U.S.+Infrastructure+Vulnerable+To+Cyber+Attack&amp;srcUrl=http://www.uncompiled.com/2010/07/black-hat-u-s-infrastructure-vulnerable-to-cyber-attack/&amp;srcTitle=Black+Hat%3A+U.S.+Infrastructure+Vulnerable+To+Cyber+Attack&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/07/black-hat-u-s-infrastructure-vulnerable-to-cyber-attack/&amp;title=Black+Hat%3A+U.S.+Infrastructure+Vulnerable+To+Cyber+Attack&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Black%20Hat%3A%20U.S.%20Infrastructure%20Vulnerable%20To%20Cyber%20Attack%22&amp;body=Link: http://www.uncompiled.com/2010/07/black-hat-u-s-infrastructure-vulnerable-to-cyber-attack/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/07/black-hat-u-s-infrastructure-vulnerable-to-cyber-attack/&amp;t=Black+Hat%3A+U.S.+Infrastructure+Vulnerable+To+Cyber+Attack" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/07/black-hat-u-s-infrastructure-vulnerable-to-cyber-attack/&amp;title=Black+Hat%3A+U.S.+Infrastructure+Vulnerable+To+Cyber+Attack&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/07/black-hat-u-s-infrastructure-vulnerable-to-cyber-attack/&amp;title=Black+Hat%3A+U.S.+Infrastructure+Vulnerable+To+Cyber+Attack" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/07/black-hat-u-s-infrastructure-vulnerable-to-cyber-attack/&amp;title=Black+Hat%3A+U.S.+Infrastructure+Vulnerable+To+Cyber+Attack" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/07/black-hat-u-s-infrastructure-vulnerable-to-cyber-attack/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Black+Hat%3A+U.S.+Infrastructure+Vulnerable+To+Cyber+Attack+-+http://b2l.me/admsau&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/07/black-hat-u-s-infrastructure-vulnerable-to-cyber-attack/&amp;submitHeadline=Black+Hat%3A+U.S.+Infrastructure+Vulnerable+To+Cyber+Attack&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Black+Hat%3A+U.S.+Infrastructure+Vulnerable+To+Cyber+Attack&amp;body=Link: http://www.uncompiled.com/2010/07/black-hat-u-s-infrastructure-vulnerable-to-cyber-attack/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/07/black-hat-u-s-infrastructure-vulnerable-to-cyber-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DHS exec takes hard questions on cybersecurity</title>
		<link>http://www.uncompiled.com/2010/07/dhs-exec-takes-hard-questions-on-cybersecurity/</link>
		<comments>http://www.uncompiled.com/2010/07/dhs-exec-takes-hard-questions-on-cybersecurity/#comments</comments>
		<pubDate>Fri, 30 Jul 2010 01:12:38 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[Industry]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1411</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>The U.S. Department of Homeland Security sent its highest-ranking official ever to speak at the Black Hat conference this week, and its Deputy Secretary Jane Holl Lute ended up fielding a few tough questions from skeptical computer security professionals in attendance.</p>
<p>During a question-and-answer session at the end of her Wednesday keynote address, one attendee asked if we should expect the DHS to give cybersecurity the same kind of treatment it&#8217;s given air travel with the Transportation Security Administration. &#8220;Why should we believe that DHS, going forward, is going to protect cyber in something other than the same way?&#8221; he asked, scoring the loudest applause of the session with the question. &#8220;Now as the TSA slows down the air travel, DHS will slow down the commerce.&#8221;</p>
<p>The undersecretary disagreed with this characterization of the TSA, but conceded that there is a &#8220;tension&#8221; in the DHS&#8217; mission. &#8220;We want to keep out people who might be dangerous, but we want to expedite legitimate trade and travel.&#8221;</p>
<p>&#8220;We happen to believe that we can achieve our security, we can protect our rights, we can protect commerce and lawful interchange,&#8221; she said. &#8220;We can have all of these things, but we need to engage in a debate about how we will prioritize and how we will strike the balance.&#8221;</p>
<p>Security experts such as Bruce Schneier have long slammed the TSA&#8217;s procedures, saying that they are ineffective and poorly thought out. Schneier calls U.S. airport screenings &#8220;security theater.&#8221;</p>
<p>Some have also criticized the DHS as slow in its response to cyber-incidents. As industrial systems were being targeted with the Stuxnet worm two weeks ago, it took DHS&#8217; Industrial Control Systems Computer Emergency Response Team five days to push out a public alert. Critics say that was too long.</p>
<p>Hitting on a theme of her keynote, Lute called for real dialogue between government and industry and said she hoped that her department could be a &#8220;portal for that debate.&#8221;</p>
<p>&#8220;You know, societies used to have conversations with themselves through their governments. In that respect, we&#8217;re not talking to each other any more,&#8221; she said. &#8220;In many respects we&#8217;re throwing assertions back and forth at each other and seeing who has the more clever report, who has thought of the newer idea.&#8221;</p>
<p>Hitting on another theme that the government&#8217;s response to cyberthreats has been more rhetorical than practical, another attendee asked if Lute thought the U.S. would be able to secure computer systems without first experiencing a cyberdisaster, equivalent to the Sept. 11 terrorist attacks. &#8220;In Homeland Security, at the water cooler, do your peers say, &#8216;It&#8217;s just a matter of time before something horrible happens and that&#8217;s when we&#8217;re going to need to do what we actually need to do, instead of just talking about what needs to be done?&#8221;</p>
<p>&#8220;I&#8217;m a person who believes that this country can protect itself,&#8221; Lute said. &#8220;I don&#8217;t know what&#8217;s inevitable, and I think that anybody who lived through the events of 1989 [when the Berlin Wall fell] or who lived through the events of 2001 has lost the right to say that anything is impossible.&#8221;</p>
<p><a href="http://www.networkworld.com/news/2010/072810-dhs-exec-takes-hard-questions.html">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/07/dhs-exec-takes-hard-questions-on-cybersecurity/&amp;n=DHS+exec+takes+hard+questions+on+cybersecurity&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/07/dhs-exec-takes-hard-questions-on-cybersecurity/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/07/dhs-exec-takes-hard-questions-on-cybersecurity/&amp;title=DHS+exec+takes+hard+questions+on+cybersecurity" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/07/dhs-exec-takes-hard-questions-on-cybersecurity/&amp;t=DHS+exec+takes+hard+questions+on+cybersecurity" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/07/dhs-exec-takes-hard-questions-on-cybersecurity/&amp;title=DHS+exec+takes+hard+questions+on+cybersecurity" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/07/dhs-exec-takes-hard-questions-on-cybersecurity/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/07/dhs-exec-takes-hard-questions-on-cybersecurity/&amp;title=DHS+exec+takes+hard+questions+on+cybersecurity&amp;srcUrl=http://www.uncompiled.com/2010/07/dhs-exec-takes-hard-questions-on-cybersecurity/&amp;srcTitle=DHS+exec+takes+hard+questions+on+cybersecurity&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/07/dhs-exec-takes-hard-questions-on-cybersecurity/&amp;title=DHS+exec+takes+hard+questions+on+cybersecurity&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22DHS%20exec%20takes%20hard%20questions%20on%20cybersecurity%22&amp;body=Link: http://www.uncompiled.com/2010/07/dhs-exec-takes-hard-questions-on-cybersecurity/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/07/dhs-exec-takes-hard-questions-on-cybersecurity/&amp;t=DHS+exec+takes+hard+questions+on+cybersecurity" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/07/dhs-exec-takes-hard-questions-on-cybersecurity/&amp;title=DHS+exec+takes+hard+questions+on+cybersecurity&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/07/dhs-exec-takes-hard-questions-on-cybersecurity/&amp;title=DHS+exec+takes+hard+questions+on+cybersecurity" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/07/dhs-exec-takes-hard-questions-on-cybersecurity/&amp;title=DHS+exec+takes+hard+questions+on+cybersecurity" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/07/dhs-exec-takes-hard-questions-on-cybersecurity/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=DHS+exec+takes+hard+questions+on+cybersecurity+-+File: /data/app/webapp/functions.php<br />Line: 7<br />Message: Too many connections&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/07/dhs-exec-takes-hard-questions-on-cybersecurity/&amp;submitHeadline=DHS+exec+takes+hard+questions+on+cybersecurity&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=DHS+exec+takes+hard+questions+on+cybersecurity&amp;body=Link: http://www.uncompiled.com/2010/07/dhs-exec-takes-hard-questions-on-cybersecurity/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/07/dhs-exec-takes-hard-questions-on-cybersecurity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why no one wants DHS to play cyber mall cop</title>
		<link>http://www.uncompiled.com/2010/07/why-no-one-wants-dhs-to-play-cyber-mall-cop/</link>
		<comments>http://www.uncompiled.com/2010/07/why-no-one-wants-dhs-to-play-cyber-mall-cop/#comments</comments>
		<pubDate>Mon, 26 Jul 2010 14:13:42 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Government]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1406</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>The Homeland Security Department recently announced an initiative aimed at creating a more secure system of online identification. According to its Web site, the National Strategy for Trusted Identities in Cyberspace seeks to “improve cyberspace for everyone — individuals, private sector and governments — who conducts business online.”</p>
<p>That&#8217;s certainly a noble goal. But the very existence of NSTIC begs two very important questions: Does protecting me and my fellow citizens while we transact business online fall within the department’s areas of responsibility? And does DHS truly believe it can do what the private sector, driven by a clear and compelling profit motive, has yet to successfully accomplish?</p>
<p>The answer to both questions is a resounding no. DHS should focus on doing what its name implies — protecting the homeland — and resist the urge to demote itself into the role of national cyber mall cop.</p>
<p>I say this not to demean the department, which shoulders a weighty load in addressing the manifold threats to our shores in this age of terrorism, but because any effort by DHS to create a voluntary trusted identity program is doomed to fail.</p>
<p>The recent experience and backlash associated with Real ID — rebuffed by the general public and legislatively rejected by 11 states before being scrapped — and high-tech passports — subject to ongoing criticism for their security vulnerabilities — demonstrate that the public is uneasy at best and at worst dead set against any attempts by the federal government to centralize identification in any form. Another national identification storm cloud is gathering on the horizon in the form of the Biometric Enrollment, Locally-stored Information, and Electronic Verification of Employment provision of pending immigration reform. With every attempt at using technology to track citizens, George Orwell’s shadow grows longer.</p>
<p>Conspiracy theories aside, lessons learned from the evolution of Social Security numbers into a de facto national financial credential — in spite of being prohibited by the law that created them for any use other than the management of Social Security benefits — should be enough to remind us of what can happen with a national identification program even when it is conceived with the best of intentions.</p>
<p>Of course, DHS would not be the first organization to fail at creating a broadly successful universal digital identifier. Devices such as smart cards and tokens have been in use for years and are effective for managing identity-based access to secure enterprise systems. But such technology works best in a single organization because cost and management issues temper their advantages in broader applications.</p>
<p>At the consumer level, where individuals might be using multiple identities for a broad range of applications, any secure identity system would need to take into account the highly complex vagaries of human behavior. Doing so successfully in the private sector would be a feat with a multibillion-dollar payday — and there’s plenty of money and brainpower being spent on that effort already.</p>
<p>Consider, too, the challenges DHS faces in successfully launching a trusted identity program when the agency lacks the trust of the general public. In the Ponemon Institute’s annual Privacy Trust Study of the United States Government, DHS ranked 70th among the 75 federal agencies studied. The Citizenship and Immigration Services agency and Customs and Border Protection agency, both of which are part of DHS, ranked 74th and 75th, respectively.</p>
<p>If DHS believes that a more secure online experience will enhance homeland defense, that goal would be better served by the creation of an educational program that makes people more aware of how to safely conduct online activities. When you get beyond the Beltway, you find that too many people are making unsafe decisions online not because the technologies and techniques are lacking but because they simply don’t know any better. If left to persist, public ignorance will be the downfall of any trusted identity strategy.</p>
<p><a href="http://fcw.com/articles/2010/07/26/comment-mike-spinney-dhs-trusted-identities.aspx">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/07/why-no-one-wants-dhs-to-play-cyber-mall-cop/&amp;n=Why+no+one+wants+DHS+to+play+cyber+mall+cop&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/07/why-no-one-wants-dhs-to-play-cyber-mall-cop/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/07/why-no-one-wants-dhs-to-play-cyber-mall-cop/&amp;title=Why+no+one+wants+DHS+to+play+cyber+mall+cop" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/07/why-no-one-wants-dhs-to-play-cyber-mall-cop/&amp;t=Why+no+one+wants+DHS+to+play+cyber+mall+cop" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/07/why-no-one-wants-dhs-to-play-cyber-mall-cop/&amp;title=Why+no+one+wants+DHS+to+play+cyber+mall+cop" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/07/why-no-one-wants-dhs-to-play-cyber-mall-cop/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/07/why-no-one-wants-dhs-to-play-cyber-mall-cop/&amp;title=Why+no+one+wants+DHS+to+play+cyber+mall+cop&amp;srcUrl=http://www.uncompiled.com/2010/07/why-no-one-wants-dhs-to-play-cyber-mall-cop/&amp;srcTitle=Why+no+one+wants+DHS+to+play+cyber+mall+cop&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/07/why-no-one-wants-dhs-to-play-cyber-mall-cop/&amp;title=Why+no+one+wants+DHS+to+play+cyber+mall+cop&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Why%20no%20one%20wants%20DHS%20to%20play%20cyber%20mall%20cop%22&amp;body=Link: http://www.uncompiled.com/2010/07/why-no-one-wants-dhs-to-play-cyber-mall-cop/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/07/why-no-one-wants-dhs-to-play-cyber-mall-cop/&amp;t=Why+no+one+wants+DHS+to+play+cyber+mall+cop" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/07/why-no-one-wants-dhs-to-play-cyber-mall-cop/&amp;title=Why+no+one+wants+DHS+to+play+cyber+mall+cop&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/07/why-no-one-wants-dhs-to-play-cyber-mall-cop/&amp;title=Why+no+one+wants+DHS+to+play+cyber+mall+cop" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/07/why-no-one-wants-dhs-to-play-cyber-mall-cop/&amp;title=Why+no+one+wants+DHS+to+play+cyber+mall+cop" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/07/why-no-one-wants-dhs-to-play-cyber-mall-cop/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Why+no+one+wants+DHS+to+play+cyber+mall+cop+-+http://b2l.me/actv85&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/07/why-no-one-wants-dhs-to-play-cyber-mall-cop/&amp;submitHeadline=Why+no+one+wants+DHS+to+play+cyber+mall+cop&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Why+no+one+wants+DHS+to+play+cyber+mall+cop&amp;body=Link: http://www.uncompiled.com/2010/07/why-no-one-wants-dhs-to-play-cyber-mall-cop/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/07/why-no-one-wants-dhs-to-play-cyber-mall-cop/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Iran was prime target of SCADA worm</title>
		<link>http://www.uncompiled.com/2010/07/iran-was-prime-target-of-scada-worm/</link>
		<comments>http://www.uncompiled.com/2010/07/iran-was-prime-target-of-scada-worm/#comments</comments>
		<pubDate>Mon, 26 Jul 2010 14:02:15 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1402</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Computers in Iran have been hardest hit by a dangerous computer worm that tries to steal information from industrial control systems.</p>
<p>According to data compiled by Symantec, nearly 60 percent of all systems infected by the worm are located in Iran. Indonesia and India have also been hard-hit by the malicious software, known as Stuxnet.</p>
<p>Looking at the dates on digital signatures generated by the worm, the malicious software may have been in circulation since as long ago as January, said Elias Levy, senior technical director with Symantec Security Response.</p>
<p>Stuxnet was discovered last month by VirusBlokAda, a Belarus-based antivirus company that said it found the software on a system belonging to an Iranian customer. The worm seeks out Siemens SCADA (supervisory control and data acquisition) management systems, used in large manufacturing and utility plants, and tries to upload industrial secrets to the Internet.</p>
<p>Symantec isn&#8217;t sure why Iran and the other countries are reporting so many infections. &#8220;The most we can say is whoever developed these particular threats was targeting companies in those geographic areas,&#8221; Levy said.</p>
<p>The U.S. has a long-running trade embargo against Iran. &#8220;Although Iran is probably one of the countries that has the worst infections of this, they are also probably a place where they don&#8217;t have much AV right now,&#8221; Levy said.</p>
<p>Siemens wouldn&#8217;t say how many customers it has in Iran, but the company now says that two German companies have been infected by the virus. A free virus scanner posted by Siemens earlier this week has been downloaded 1,500 times, a company spokesman said.</p>
<p>Earlier this year, Siemens said it planned to wind down its Iranian business &#8212; a 290-employee unit that netted €438 million (US$562.9 million) in 2008, according to the Wall Street Journal. Critics say the company&#8217;s trade there has helped feed Iran&#8217;s nuclear development effort.</p>
<p>Symantec compiled its data by working with the industry and redirecting traffic aimed at the worm&#8217;s command and control servers to its own computers. Over a three-day period this week, computers located at 14,000 IP addresses tried to connect with the command and control servers, indicating that a very small number of PCs worldwide have been hit by the worm. The actual number of infected machines is probably in the 15,000 to 20,000 range, because many companies place several systems behind one IP address, according to Symantec&#8217;s Levy.</p>
<p>Because Symantec can see the IP address used by machines that try to connect with the command and control servers, it can tell which companies have been infected. &#8220;Not surprisingly, infected machines include a variety of organizations that would use SCADA software and systems, which is clearly the target of the attackers,&#8221; the company said in its blog post Thursday.</p>
<p>Stuxnet spreads via USB devices. When an infected USB stick is viewed on a Windows machine, the code looks for a Siemens system and copies itself to any other USB devices it can find.</p>
<p>A temporary workaround for the Windows bug that allows Stuxnet to spread can be found <a href="http://support.microsoft.com/kb/2286198">here</a>.</p>
<p><a href="http://www.computerworld.com/s/article/9179618/Iran_was_prime_target_of_SCADA_worm">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/07/iran-was-prime-target-of-scada-worm/&amp;n=Iran+was+prime+target+of+SCADA+worm&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/07/iran-was-prime-target-of-scada-worm/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/07/iran-was-prime-target-of-scada-worm/&amp;title=Iran+was+prime+target+of+SCADA+worm" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/07/iran-was-prime-target-of-scada-worm/&amp;t=Iran+was+prime+target+of+SCADA+worm" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/07/iran-was-prime-target-of-scada-worm/&amp;title=Iran+was+prime+target+of+SCADA+worm" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/07/iran-was-prime-target-of-scada-worm/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/07/iran-was-prime-target-of-scada-worm/&amp;title=Iran+was+prime+target+of+SCADA+worm&amp;srcUrl=http://www.uncompiled.com/2010/07/iran-was-prime-target-of-scada-worm/&amp;srcTitle=Iran+was+prime+target+of+SCADA+worm&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/07/iran-was-prime-target-of-scada-worm/&amp;title=Iran+was+prime+target+of+SCADA+worm&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Iran%20was%20prime%20target%20of%20SCADA%20worm%22&amp;body=Link: http://www.uncompiled.com/2010/07/iran-was-prime-target-of-scada-worm/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/07/iran-was-prime-target-of-scada-worm/&amp;t=Iran+was+prime+target+of+SCADA+worm" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/07/iran-was-prime-target-of-scada-worm/&amp;title=Iran+was+prime+target+of+SCADA+worm&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/07/iran-was-prime-target-of-scada-worm/&amp;title=Iran+was+prime+target+of+SCADA+worm" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/07/iran-was-prime-target-of-scada-worm/&amp;title=Iran+was+prime+target+of+SCADA+worm" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/07/iran-was-prime-target-of-scada-worm/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Iran+was+prime+target+of+SCADA+worm+-+http://b2l.me/actvb2&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/07/iran-was-prime-target-of-scada-worm/&amp;submitHeadline=Iran+was+prime+target+of+SCADA+worm&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Iran+was+prime+target+of+SCADA+worm&amp;body=Link: http://www.uncompiled.com/2010/07/iran-was-prime-target-of-scada-worm/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/07/iran-was-prime-target-of-scada-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Overcome E-Health Record Security Challenge</title>
		<link>http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/</link>
		<comments>http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/#comments</comments>
		<pubDate>Mon, 26 Jul 2010 13:57:58 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Medical]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1396</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Many large healthcare organizations have been securing electronic health records for years. But now, industrywide adoption will include providers of all shapes and sizes—most of which don&#8217;t have chief security officers, compliance specialists, CIOs, or even full-time IT staffs.<br />
Helping them secure their electronic records is an unprecedented challenge. The products and technologies needed are available, but the trick is in getting all providers to understand what&#8217;s required, prepare physicians and staff, and tap into the appropriate expertise.</p>
<p>The Health Insurance Portability And Accountability Act, or HIPAA, requires that EHRs and the data in them be guarded throughout their life cycles. Risk assessments must be performed and access privileges determined. You&#8217;ll need policies to secure all possible points of data leakage, including desktops, servers, databases, mobile devices, and the Internet.</p>
<p>In short, you must protect data at rest and in motion, and prepare for the inevitable breaches.</p>
<p>Creation And Use</p>
<p>When a patient walks into a provider&#8217;s office for the first time, the terminal at reception must be hardened, hosted on a trusted network, and continually scanned for viruses and malware. Receptionists should be able to add basic patient information but have limited access to executable files.</p>
<p>Access privileges should be assigned that strictly regulate employees&#8217; ability to view, enter, edit, and delete data based on what they need for their jobs. For example, billing personnel don&#8217;t need to see the results of the medical tests that they&#8217;re charging patients for.</p>
<p>Attending physicians should use unique credentials to access the EHR application to record diagnoses. E-medical records must be signed with electronic signatures, which include PIN codes and are saved in encrypted files. Signatures verify that information has been reviewed every time a physician signs off on an EHR. They also let the medical staff sign off on records from any location, expediting processing, reducing workflow costs, and maintaining HIPAA compliance.</p>
<p><a href="http://www.informationweek.com/news/healthcare/EMR/showArticle.jhtml?articleID=226200102">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;n=Overcome+E-Health+Record+Security+Challenge&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;title=Overcome+E-Health+Record+Security+Challenge" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;t=Overcome+E-Health+Record+Security+Challenge" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;title=Overcome+E-Health+Record+Security+Challenge" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;title=Overcome+E-Health+Record+Security+Challenge&amp;srcUrl=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;srcTitle=Overcome+E-Health+Record+Security+Challenge&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;title=Overcome+E-Health+Record+Security+Challenge&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Overcome%20E-Health%20Record%20Security%20Challenge%22&amp;body=Link: http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;t=Overcome+E-Health+Record+Security+Challenge" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;title=Overcome+E-Health+Record+Security+Challenge&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;title=Overcome+E-Health+Record+Security+Challenge" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;title=Overcome+E-Health+Record+Security+Challenge" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Overcome+E-Health+Record+Security+Challenge+-+http://b2l.me/acttwh&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;submitHeadline=Overcome+E-Health+Record+Security+Challenge&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Overcome+E-Health+Record+Security+Challenge&amp;body=Link: http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyberwarrior Shortage Threatens U.S. Security</title>
		<link>http://www.uncompiled.com/2010/07/cyberwarrior-shortage-threatens-u-s-security/</link>
		<comments>http://www.uncompiled.com/2010/07/cyberwarrior-shortage-threatens-u-s-security/#comments</comments>
		<pubDate>Mon, 19 Jul 2010 16:40:06 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Cyber Warfare]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Military]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1388</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>There may be no country on the planet more vulnerable to a massive cyberattack than the United States, where financial, transportation, telecommunications and even military operations are now deeply dependent on data networking.</p>
<p>What&#8217;s worse: U.S. security officials say the country&#8217;s cyberdefenses are not up to the challenge. In part, it&#8217;s due to a severe shortage of computer security specialists and engineers with the skills and knowledge necessary to do battle against would-be adversaries. The protection of U.S. computer systems essentially requires an army of cyberwarriors, but the recruitment of that force is suffering.</p>
<p>&#8220;We don&#8217;t have sufficiently bright people moving into this field to support those national security objectives as we move forward in time,&#8221; says James Gosler, a veteran cybersecurity specialist who has worked at the CIA, the National Security Agency and the Energy Department.</p>
<p>If U.S. cyberdefenses are to be improved, more people like Gosler will be needed on the front lines. Gosler, 58, works at the Energy Department&#8217;s Sandia National Laboratory in Albuquerque, N.M., where he focuses on ways to counter efforts to penetrate U.S. data networks. It&#8217;s an ever-increasing challenge.</p>
<p>&#8220;You can have vulnerabilities in the fundamentals of the technology, you can have vulnerabilities introduced based on how that technology is implemented, and you can have vulnerabilities introduced through the artificial applications that are built on that fundamental technology,&#8221; Gosler says. &#8220;It takes a very skilled person to operate at that level, and we don&#8217;t have enough of them.&#8221;</p>
<p>Gosler estimates there are now only 1,000 people in the entire United States with the sophisticated skills needed for the most demanding cyberdefense tasks. To meet the computer security needs of U.S. government agencies and large corporations, he says, a force of 20,000 to 30,000 similarly skilled specialists is needed.</p>
<p>Some are currently being trained at the nonprofit SANS (SysAdmin, Audit, Network, Security) Institute outside Washington, D.C., but the demand for qualified cybersecurity specialists far exceeds the supply.</p>
<p>&#8220;You go looking for those people, but everybody else is looking for the same thousand people,&#8221; says SANS Research Director Alan Paller. &#8220;So they&#8217;re just being pushed around from NSA to CIA to DHS to Boeing. It&#8217;s a mess.&#8221;</p>
<p>The Center for Strategic and International Studies highlights the problem in a forthcoming report, &#8220;A Human Capital Crisis in Cybersecurity.&#8221;</p>
<p>According to the report, a key element of a &#8220;robust&#8221; cybersecurity strategy is &#8220;having the right people at every level to identify, build and staff the defenses and responses.&#8221;</p>
<p>The CSIS report highlights a &#8220;desperate shortage&#8221; of people with the skills to &#8220;design secure systems, write safe computer code, and create the ever more sophisticated tools needed to prevent, detect, mitigate and reconstitute from damage due to system failures and malicious acts.&#8221;</p>
<p>The cyber manpower crisis in the United States stands in sharp contrast to the situation in China, where the training of computer experts is a top national priority. In the most recent round of the International Collegiate Programming Contest, co-sponsored by IBM and the Association for Computing Machinery, Chinese universities took four of the top 10 places. No U.S. university made the list.</p>
<p>The Chinese government, in fact, appears to be systematically building a cyberwarrior force.</p>
<p>&#8220;Every military district of the Peoples&#8217; Liberation Army runs a competition every spring,&#8221; says Alan Paller of SANS, &#8220;and they search for kids who might have gotten caught hacking.&#8221;</p>
<p>One of the Chinese youths who won that competition had earlier been caught hacking into a Japanese computer, according to Paller, only to be rewarded with extra training.</p>
<p>&#8220;Later that year, we found him hacking into the Pentagon,&#8221; Paller says. &#8220;So they find them, they train them, and they get them into operation very, very fast.&#8221;</p>
<p>Some members of Congress, eager to follow China&#8217;s example, are now promoting a U.S. Cyber Challenge, a national talent search at the high school level. The aim is to find up to 10,000 potential cyberwarriors, ready to play both offense and defense.</p>
<p>&#8220;The idea is for schools around the country to field teams, and the teams would compete against one another,&#8221; says Sen. Thomas Carper, a Delaware Democrat who is one of the backers of the effort. He sees the challenge as an opportunity &#8220;not only for them to hone their skills on being able to hack into other systems, particularly those of folks we may not be fond of, but also to use what they learn to strengthen our defenses.&#8221;</p>
<p>In order to protect a computer system, one needs to know how someone might attack it. Last year&#8217;s preliminary Cyber Challenge game was won by a 17-year-old from Connecticut — Michael Coppola — who was smart enough to hack into the game computer and add points to his own score.</p>
<p>&#8220;There&#8217;s actually a flaw within that Web application,&#8221; Coppola says. &#8220;Using that, I was able to execute commands on the computer running the scoring software, and I was able to add points and basically do whatever I wanted.&#8221;</p>
<p>It was certainly an unconventional approach, but the competition judges were so impressed by Coppola&#8217;s ability to hack into the computer game that they actually rewarded him for changing his score.</p>
<p>&#8220;It&#8217;s cheating,&#8221; Michael says, &#8220;but it&#8217;s like the entire game is cheating.&#8221;</p>
<p>Indeed. People who know how to cheat will soon be on the front lines of cyber defense, because the best way to defend a computer system from attack is to figure out how an adversary would be able to hack into it.</p>
<p>Now 18, Coppola is himself looking to a career in cybersecurity.</p>
<p><a href="http://www.npr.org/templates/story/story.php?storyId=128574055">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/07/cyberwarrior-shortage-threatens-u-s-security/&amp;n=Cyberwarrior+Shortage+Threatens+U.S.+Security&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/07/cyberwarrior-shortage-threatens-u-s-security/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/07/cyberwarrior-shortage-threatens-u-s-security/&amp;title=Cyberwarrior+Shortage+Threatens+U.S.+Security" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/07/cyberwarrior-shortage-threatens-u-s-security/&amp;t=Cyberwarrior+Shortage+Threatens+U.S.+Security" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/07/cyberwarrior-shortage-threatens-u-s-security/&amp;title=Cyberwarrior+Shortage+Threatens+U.S.+Security" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/07/cyberwarrior-shortage-threatens-u-s-security/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/07/cyberwarrior-shortage-threatens-u-s-security/&amp;title=Cyberwarrior+Shortage+Threatens+U.S.+Security&amp;srcUrl=http://www.uncompiled.com/2010/07/cyberwarrior-shortage-threatens-u-s-security/&amp;srcTitle=Cyberwarrior+Shortage+Threatens+U.S.+Security&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/07/cyberwarrior-shortage-threatens-u-s-security/&amp;title=Cyberwarrior+Shortage+Threatens+U.S.+Security&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Cyberwarrior%20Shortage%20Threatens%20U.S.%20Security%22&amp;body=Link: http://www.uncompiled.com/2010/07/cyberwarrior-shortage-threatens-u-s-security/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/07/cyberwarrior-shortage-threatens-u-s-security/&amp;t=Cyberwarrior+Shortage+Threatens+U.S.+Security" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/07/cyberwarrior-shortage-threatens-u-s-security/&amp;title=Cyberwarrior+Shortage+Threatens+U.S.+Security&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/07/cyberwarrior-shortage-threatens-u-s-security/&amp;title=Cyberwarrior+Shortage+Threatens+U.S.+Security" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/07/cyberwarrior-shortage-threatens-u-s-security/&amp;title=Cyberwarrior+Shortage+Threatens+U.S.+Security" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/07/cyberwarrior-shortage-threatens-u-s-security/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Cyberwarrior+Shortage+Threatens+U.S.+Security+-+File: /data/app/webapp/functions.php<br />Line: 23<br />Message: Incorrect key file for table './b2l_shrinker/phurl_settings.MYI'; try to repair it&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/07/cyberwarrior-shortage-threatens-u-s-security/&amp;submitHeadline=Cyberwarrior+Shortage+Threatens+U.S.+Security&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Cyberwarrior+Shortage+Threatens+U.S.+Security&amp;body=Link: http://www.uncompiled.com/2010/07/cyberwarrior-shortage-threatens-u-s-security/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/07/cyberwarrior-shortage-threatens-u-s-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Suspected Russian spies charged in US</title>
		<link>http://www.uncompiled.com/2010/07/suspected-russian-spies-charged-in-us/</link>
		<comments>http://www.uncompiled.com/2010/07/suspected-russian-spies-charged-in-us/#comments</comments>
		<pubDate>Sat, 17 Jul 2010 16:57:44 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[Legal]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1376</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>US strategy expert Stephen Flanagan: &#8216;The suspects had been under surveillance by the FBI for some years&#8217;<br />
Ten alleged members of a Russian spy-ring have been charged in the US with acting as foreign agents.</p>
<p>The suspects are accused of posing as ordinary citizens, some living together as couples for years.</p>
<p>They were charged with conspiracy to act as unlawful agents of a foreign government, a crime which carries up to five years in prison.</p>
<p>A Russian foreign ministry spokesman said the allegations were contradictory.</p>
<p>&#8220;We are studying the information. There are a lot of contradictions,&#8221; spokesman Igor Lyakin-Frolov told the AFP news agency, declining further comment.</p>
<p>Russian Foreign Minister Sergei Lavrov later said Moscow expected Washington to provide an explanation over the the spying row, Russia&#8217;s Interfax news agency reports.</p>
<p>Nine of the alleged spies also face a charge of conspiracy to launder money, which carries a 20-year prison sentence.</p>
<p>An 11th suspect remains at large, according to the US justice department.</p>
<p><a href="http://www.bbc.co.uk/news/10442223">Read More</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/07/suspected-russian-spies-charged-in-us/&amp;n=Suspected+Russian+spies+charged+in+US&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/07/suspected-russian-spies-charged-in-us/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/07/suspected-russian-spies-charged-in-us/&amp;title=Suspected+Russian+spies+charged+in+US" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/07/suspected-russian-spies-charged-in-us/&amp;t=Suspected+Russian+spies+charged+in+US" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/07/suspected-russian-spies-charged-in-us/&amp;title=Suspected+Russian+spies+charged+in+US" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/07/suspected-russian-spies-charged-in-us/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/07/suspected-russian-spies-charged-in-us/&amp;title=Suspected+Russian+spies+charged+in+US&amp;srcUrl=http://www.uncompiled.com/2010/07/suspected-russian-spies-charged-in-us/&amp;srcTitle=Suspected+Russian+spies+charged+in+US&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/07/suspected-russian-spies-charged-in-us/&amp;title=Suspected+Russian+spies+charged+in+US&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Suspected%20Russian%20spies%20charged%20in%20US%22&amp;body=Link: http://www.uncompiled.com/2010/07/suspected-russian-spies-charged-in-us/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/07/suspected-russian-spies-charged-in-us/&amp;t=Suspected+Russian+spies+charged+in+US" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/07/suspected-russian-spies-charged-in-us/&amp;title=Suspected+Russian+spies+charged+in+US&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/07/suspected-russian-spies-charged-in-us/&amp;title=Suspected+Russian+spies+charged+in+US" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/07/suspected-russian-spies-charged-in-us/&amp;title=Suspected+Russian+spies+charged+in+US" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/07/suspected-russian-spies-charged-in-us/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Suspected+Russian+spies+charged+in+US+-+http://b2l.me/aba2h9&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/07/suspected-russian-spies-charged-in-us/&amp;submitHeadline=Suspected+Russian+spies+charged+in+US&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Suspected+Russian+spies+charged+in+US&amp;body=Link: http://www.uncompiled.com/2010/07/suspected-russian-spies-charged-in-us/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/07/suspected-russian-spies-charged-in-us/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IT Official Blames N. Korea for Cyber Attacks</title>
		<link>http://www.uncompiled.com/2010/07/it-official-blames-n-korea-for-cyber-attacks/</link>
		<comments>http://www.uncompiled.com/2010/07/it-official-blames-n-korea-for-cyber-attacks/#comments</comments>
		<pubDate>Wed, 07 Jul 2010 14:35:36 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Attack]]></category>
		<category><![CDATA[Cyber Warfare]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Military]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1363</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>North Korea was behind the cyber attacks that occurred a year ago Wednesday, according to a government IT source in South Korea.<br />
The distributed denial of service, or DDoS, attacks paralyzed more than 20 domestic sites including those of the presidential office and major portal sites.</p>
<p>On foreign media reports saying no evidence linked the North to the attacks, Jeong Seok-hwa, investigation director at the Cyber Terror Response Center in charge of the investigation, said, “No country including the U.S. could identify the origin of the DDoS attacks that occurred a year ago. Thankfully, the discovery by Korean investigation agencies has been the most credible so far.”</p>
<p>On how he was sure that it was Pyongyang, Jeong said, “It might be too early to conclude this, but the facts so far have shown that the IP address used for the attacks was the same one rented by North Korea’s Posts and Telecommunications Ministry from a Chinese Internet provider.”</p>
<p>“The attack was waged by dozens of people, not one individual,” he added.</p>
<p>According to the National Police Agency, the cyber center in October last year found that the attacks originated from the IP of the North’s ministry.</p>
<p>A lieutenant on the investigation team was promoted to inspector in recognition of this discovery. He refused to disclose more, however, saying “Giving out more details will compromise our national strategy,” but added, “It was possible thanks to the technical capability we’ve accumulated for more than 10 years since the cyber center’s launch.”</p>
<p>Amid rising fears over a second cyber attack from the North, Jeong said, “Attack rumors were prevalent in April and May, but nothing really happened. But there certainly is the possibility of another attack. One of the servers that made the attack order seems to have copied all files saved on zombie PCs, or those in charge of the attack.”</p>
<p>This indicates that zombie PCs analyzed the files South Koreans frequently use to make more of them when starting an attack.</p>
<p>On preventing a cyber attack, Jeong said, “We cannot prevent zombie PCs from multiplying even with the latest vaccine program. The government must distribute free firewall programs (used for protection in Internet banking services).</p>
<p>With the investigation over last year’s cyber attacks ongoing, Jeong pledged to find the culprit. “We’ve done everything we can within the country. Since the attack originated from China, which is beyond our investigative jurisdiction, we will collaborate with China to find who did it,” he said.</p>
<p><a href="http://english.donga.com/srv/service.php3?bicode=040000&#038;biid=2010070747078">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/07/it-official-blames-n-korea-for-cyber-attacks/&amp;n=IT+Official+Blames+N.+Korea+for+Cyber+Attacks&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/07/it-official-blames-n-korea-for-cyber-attacks/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/07/it-official-blames-n-korea-for-cyber-attacks/&amp;title=IT+Official+Blames+N.+Korea+for+Cyber+Attacks" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/07/it-official-blames-n-korea-for-cyber-attacks/&amp;t=IT+Official+Blames+N.+Korea+for+Cyber+Attacks" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/07/it-official-blames-n-korea-for-cyber-attacks/&amp;title=IT+Official+Blames+N.+Korea+for+Cyber+Attacks" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/07/it-official-blames-n-korea-for-cyber-attacks/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/07/it-official-blames-n-korea-for-cyber-attacks/&amp;title=IT+Official+Blames+N.+Korea+for+Cyber+Attacks&amp;srcUrl=http://www.uncompiled.com/2010/07/it-official-blames-n-korea-for-cyber-attacks/&amp;srcTitle=IT+Official+Blames+N.+Korea+for+Cyber+Attacks&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/07/it-official-blames-n-korea-for-cyber-attacks/&amp;title=IT+Official+Blames+N.+Korea+for+Cyber+Attacks&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22IT%20Official%20Blames%20N.%20Korea%20for%20Cyber%20Attacks%22&amp;body=Link: http://www.uncompiled.com/2010/07/it-official-blames-n-korea-for-cyber-attacks/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/07/it-official-blames-n-korea-for-cyber-attacks/&amp;t=IT+Official+Blames+N.+Korea+for+Cyber+Attacks" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/07/it-official-blames-n-korea-for-cyber-attacks/&amp;title=IT+Official+Blames+N.+Korea+for+Cyber+Attacks&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/07/it-official-blames-n-korea-for-cyber-attacks/&amp;title=IT+Official+Blames+N.+Korea+for+Cyber+Attacks" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/07/it-official-blames-n-korea-for-cyber-attacks/&amp;title=IT+Official+Blames+N.+Korea+for+Cyber+Attacks" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/07/it-official-blames-n-korea-for-cyber-attacks/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=IT+Official+Blames+N.+Korea+for+Cyber+Attacks+-+http://b2l.me/9gk24&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/07/it-official-blames-n-korea-for-cyber-attacks/&amp;submitHeadline=IT+Official+Blames+N.+Korea+for+Cyber+Attacks&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=IT+Official+Blames+N.+Korea+for+Cyber+Attacks&amp;body=Link: http://www.uncompiled.com/2010/07/it-official-blames-n-korea-for-cyber-attacks/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/07/it-official-blames-n-korea-for-cyber-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA encryption: meeting today&#8217;s regulations</title>
		<link>http://www.uncompiled.com/2010/07/hipaa-encryption-meeting-todays-regulations/</link>
		<comments>http://www.uncompiled.com/2010/07/hipaa-encryption-meeting-todays-regulations/#comments</comments>
		<pubDate>Thu, 01 Jul 2010 13:44:32 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Medical]]></category>
		<category><![CDATA[Research]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1359</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>There are a couple of reasons for this increased focus on encryption.</p>
<p>First, the U.S. Department of the Health and Human Services (HHS) issued guidance wherein &#8220;unsecure protected health information (PHI)&#8221; is essentially any PHI that is not encrypted or destroyed. Under this definition, it doesn&#8217;t matter how many chains, walls, doors, biometric gizmos and guards with lethal weapons you have at your service. As long as PHI is not encrypted, it is considered unsecured.<br />
A second and more compelling reason why encryption is now a requirement is the introduction of HITECH&#8217;s breach notification initiative, which requires HIPAA-covered entities to send notification letters if there is a breach of unsecured PHI. However, as HHS pointed out, the use of encryption grants safe harbor in the event of a breach because encrypted PHI is not unsecured PHI. </p>
<p>Oddly enough, in the same breath, HHS also notes that &#8220;covered entities and business associates are not required to follow the guidance.&#8221; However, cleaning up the mess behind a breach notification can cost millions of dollars, so one would have to be supremely confident — or reckless — in not taking advantage of the encryption safe harbor. With such mixed signals, though, it is not hard to see why encryption is called ade facto requirement.</p>
<p>What type of encryption?</p>
<p>Since encryption means different things to different people, an important question is &#8220;what type of encryption should I use?&#8221;</p>
<p>In the past, companies offered hard drives that used strong encryption. However, analysis showed that strong encryption was used but only to protect the password and not the data that was stored on the devices. The actual data stored on the hard drive was encrypted with an encryption algorithm developed by the company, which proved to be anything but strong.</p>
<p>This illustrates the potential pitfalls of choosing any type of encryption package — a lack of strong, secure encryption. Obviously, some encryption programs do a better job of protecting data than others, but how can a company choose the right one? </p>
<p>HHS does not provide any guidance in this area, and that is a smart move. HHS does many things, but it is not in the position to determine the technical requirements that would separate strong from weak encryption. Instead, HHS defers to the National Institute of Standards and Technology (NIST) to direct organizations to a number of special publications on the subject.</p>
<p>The publications are endless, tedious documents which are long on theory and short on technical requirements.  However, a little detective work leads to concrete specifications that one can work with.</p>
<p>While these requirements are for federal agencies, they could also serve as a great guide for private practices. Since HHS deferred to NIST when it comes to encryption, companies need to meet the expectations of what NIST considers &#8220;proper&#8221; encryption for sensitive data.</p>
<p>Further proof that HHS deferred to NIST is found in the guidance, where encryption for &#8220;data at rest&#8221; and &#8220;data in motion&#8221; are specifically mentioned. The latter refers to data going through networks, including wireless networks.  The former refers to data that is stored: laptops, external hard drives, CDs or DVDs, backup tapes, etc.</p>
<p>Data in motion</p>
<p>Of the two, encrypting data in motion is more straightforward: Valid encryption processes must &#8220;comply with the requirements of Federal Information Processing Standards (FIPS) 140–2.&#8221;  While there are many technical requirements involved, many vendors offer products that are FIPS 140-2 validated, so finding such a solution is easy.</p>
<p>Organizations must look for a solution that is FIPS140-2 validated, not FIPS140-2 certified. The former means that NIST evaluated, and validated, the encryption. The latter is used interchangeably with the former, but is technically meaningless and is mostly marketing speak. While encryption is in the spirit of NIST&#8217;s requirements, it hasn&#8217;t been validated.</p>
<p>Data at rest</p>
<p>Finding appropriate data at rest encryption requires a little digging. According to the suggested NIST publication — Special Publication 800–111, Guide to Storage Encryption Technologies for End User Devices — &#8220;Federal agencies must use FIPS-approved algorithms contained in validated cryptographic modules. Whenever possible, AES (Advanced Encryption Standard) should be used for the encryption algorithm because of its strength and speed.&#8221;</p>
<p>Also, a footnote makes reference to NIST SP 800-57, &#8220;Recommendation for Key Management,&#8221; and notes that it &#8220;provides detailed information on key management planning, algorithm selection and appropriate key sizes, cryptographic policy and cryptographic module selection.&#8221;</p>
<p>This information is relegated to a footnote. This is unfortunate since this publication is what most HIPAA-covered entities are looking for.  As organizations review section 5.6.2 of the publication, they can identify encryption algorithms that are valid for use, the minimum key sizes and the length of their validity. In addition, examples are given on how all of the above comes together, and summarized in a table. Any encryption weaker than this, and you might not be covered.</p>
<p>HIPAA-covered entities can expect safe harbor if, and only if, they adhere to these strict standards and guidelines. The fact that a company&#8217;s data is encrypted is meaningless without taking into account the NIST requirements. Organizations that properly adhere to HIPAA standards understand the impact of breach notifications. By proactively leveraging the proper encryption technologies, companies of all sizes can avoid these breach notifications while ensuring the security of their sensitive data.</p>
<p><a href="http://www.scmagazineus.com/hipaa-encryption-meeting-todays-regulations/article/173661/">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/07/hipaa-encryption-meeting-todays-regulations/&amp;n=HIPAA+encryption%3A+meeting+today%27s+regulations&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/07/hipaa-encryption-meeting-todays-regulations/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/07/hipaa-encryption-meeting-todays-regulations/&amp;title=HIPAA+encryption%3A+meeting+today%27s+regulations" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/07/hipaa-encryption-meeting-todays-regulations/&amp;t=HIPAA+encryption%3A+meeting+today%27s+regulations" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/07/hipaa-encryption-meeting-todays-regulations/&amp;title=HIPAA+encryption%3A+meeting+today%27s+regulations" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/07/hipaa-encryption-meeting-todays-regulations/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/07/hipaa-encryption-meeting-todays-regulations/&amp;title=HIPAA+encryption%3A+meeting+today%27s+regulations&amp;srcUrl=http://www.uncompiled.com/2010/07/hipaa-encryption-meeting-todays-regulations/&amp;srcTitle=HIPAA+encryption%3A+meeting+today%27s+regulations&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/07/hipaa-encryption-meeting-todays-regulations/&amp;title=HIPAA+encryption%3A+meeting+today%27s+regulations&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22HIPAA%20encryption%3A%20meeting%20today%27s%20regulations%22&amp;body=Link: http://www.uncompiled.com/2010/07/hipaa-encryption-meeting-todays-regulations/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/07/hipaa-encryption-meeting-todays-regulations/&amp;t=HIPAA+encryption%3A+meeting+today%27s+regulations" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/07/hipaa-encryption-meeting-todays-regulations/&amp;title=HIPAA+encryption%3A+meeting+today%27s+regulations&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/07/hipaa-encryption-meeting-todays-regulations/&amp;title=HIPAA+encryption%3A+meeting+today%27s+regulations" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/07/hipaa-encryption-meeting-todays-regulations/&amp;title=HIPAA+encryption%3A+meeting+today%27s+regulations" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/07/hipaa-encryption-meeting-todays-regulations/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=HIPAA+encryption%3A+meeting+today%27s+regulations+-+http://b2l.me/73pxp&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/07/hipaa-encryption-meeting-todays-regulations/&amp;submitHeadline=HIPAA+encryption%3A+meeting+today%27s+regulations&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=HIPAA+encryption%3A+meeting+today%27s+regulations&amp;body=Link: http://www.uncompiled.com/2010/07/hipaa-encryption-meeting-todays-regulations/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/07/hipaa-encryption-meeting-todays-regulations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
