<?xml version="1.0"?>
<!-- RSS generated by Radio UserLand v8.0.8 on Fri, 07 Jan 2005 18:05:00 GMT -->
<rss version="2.0">
	<channel>
		<title>David Fletcher: Cybersecurity</title>
		<link>http://radio.weblogs.com/0110120/categories/cybersecurity/</link>
		<description>Infrastructure Protection and Cybersecurity News, Information, and Analysis</description>
		<copyright>Copyright 2005 David Fletcher</copyright>
		<lastBuildDate>Fri, 07 Jan 2005 18:05:00 GMT</lastBuildDate>
		<docs>http://backend.userland.com/rss</docs>
		<generator>Radio UserLand v8.0.8</generator>
		<managingEditor>dfletch.geo@yahoo.com</managingEditor>
		<webMaster>dfletch.geo@yahoo.com</webMaster>
		<category domain="http://www.weblogs.com/rssUpdates/changes.xml">rssUpdates</category> 
		<skipHours>
			<hour>23</hour>
			<hour>0</hour>
			<hour>1</hour>
			<hour>2</hour>
			<hour>3</hour>
			<hour>22</hour>
			<hour>18</hour>
			<hour>19</hour>
			</skipHours>
		<cloud domain="radio.xmlstoragesystem.com" port="80" path="/RPC2" registerProcedure="xmlStorageSystem.rssPleaseNotify" protocol="xml-rpc"/>
		<ttl>60</ttl>
		<item>
			<title>Security Checklists at NIST</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2005/01/07.html#a1567</link>
			<description>&lt;P&gt;Karen Evans, the federal egov czar, recently released this report on &lt;A href=&quot;http://www.whitehouse.gov/omb/budintegration/expanding_egov12-2004.pdf&quot;&gt;&lt;STRONG&gt;&lt;EM&gt;Expanding E-Government&lt;/EM&gt;&lt;/STRONG&gt;&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;An &lt;A href=&quot;http://www.fcw.com/geb/articles/2005/0103/web-utah-01-07-05.asp&quot;&gt;article in FCW&lt;/A&gt; discusses the Utah CIO position which currently remains vacant.&lt;/P&gt;
&lt;P&gt;NIST has published this draft &lt;A href=&quot;http://csrc.nist.gov/publications/drafts/draft-FIPS_201-110804-public1.pdf&quot;&gt;standard for Personal Identity Verification&lt;/A&gt; for federal employees.&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://csrc.nist.gov/publications/nistbul/Oct-2004.pdf&quot;&gt;This bulletin&lt;/A&gt; on securing VoIP networks (from NIST) is also interesting.&amp;nbsp; We are preparing to meet with several customers regarding their interest in VoIP.&amp;nbsp; If you&apos;re involved with security, also be sure to check out the NIST security checklist program at &lt;A href=&quot;http://checklists.nist.gov/&quot;&gt;checklists.nist.gov&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2005/01/07.html#a1567</guid>
			<pubDate>Fri, 07 Jan 2005 18:04:16 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=1567&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2005%2F01%2F07.html%23a1567</comments>
			</item>
		<item>
			<title>Cybersecurity for the Homeland</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2004/12/16.html#a1545</link>
			<description>&lt;P&gt;Earlier this week the The House of Representatives Homeland Security Committee&amp;#146;s Cybersecurity Subcommittee released a comprehensive report, &quot;Cybersecurity for the Homeland 
&lt;P&gt;&lt;A href=&quot;http://hsc.house.gov/files/cybersecurityreport12.06.04.pdf&quot;&gt;&lt;a href=&quot;http://hsc.house.gov/files/cybersecurityreport12.06.04.pdf&quot;&gt;http://hsc.house.gov/files/cybersecurityreport12.06.04.pdf&lt;/a&gt;&lt;/A&gt; 
&lt;P&gt;The press release can be found at &lt;A href=&quot;http://hsc.house.gov/release.cfm?id=275&quot;&gt;&lt;a href=&quot;http://hsc.house.gov/release.cfm?id=275&quot;&gt;http://hsc.house.gov/release.cfm?id=275&lt;/a&gt;&lt;/A&gt; &lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2004/12/16.html#a1545</guid>
			<pubDate>Thu, 16 Dec 2004 15:07:53 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=1545&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2004%2F12%2F16.html%23a1545</comments>
			</item>
		<item>
			<title>High Stakes for Security</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2004/09/24.html#a1479</link>
			<description>&lt;P&gt;We need no reminder to emphasize the importance of information security, but here are a few headlines from this week:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN class=articleHeadline&gt;&lt;A href=&quot;http://www.denverpost.com/Stories/0,1413,36~115~2420310,00.html&quot;&gt;Services take sick leave as bugs, viruses plague computers&lt;/A&gt; (Denver Post)&lt;/SPAN&gt; 
&lt;LI&gt;&lt;SPAN class=articleHeadline&gt;&lt;A href=&quot;http://www.coloradoan.com/news/stories/20040923/opinion/1287547.html&quot;&gt;Computer woes prompt questions on preparedness&lt;/A&gt; (The Coloradan)&lt;/SPAN&gt; 
&lt;LI&gt;&lt;SPAN class=articleHeadline&gt;&lt;A href=&quot;http://www.gazette.com/display.php?sid=1234508&quot;&gt;Want a driver&amp;#146;s license? No luck&lt;/A&gt; (Colorado Springs Gazette)&lt;/SPAN&gt; 
&lt;LI&gt;&lt;SPAN class=articleHeadline&gt;&lt;SPAN class=Headline&gt;&lt;A href=&quot;http://live.psu.edu/story/8190&quot;&gt;Faculty and staff preparation key to successful for SSN changeover&lt;/A&gt;&amp;nbsp;(Penn State U.)&lt;/SPAN&gt;&lt;/SPAN&gt; 
&lt;LI&gt;&lt;SPAN class=articleHeadline&gt;&lt;SPAN class=Headline&gt;&lt;A href=&quot;http://www.timesunion.com/AspStories/story.asp?storyID=287870&amp;amp;category=STATE&amp;amp;BCCode=HOME&amp;amp;newsdate=9/22/2004&quot;&gt;Worm burrows way into state computers&lt;/A&gt; (Times Union)&lt;/SPAN&gt;&lt;/SPAN&gt; 
&lt;LI&gt;&lt;SPAN class=articleHeadline&gt;&lt;A href=&quot;http://www.king5.com/sharedcontent/ptech/weblog2/092204ccdrptechweblog.13dde0b.html&quot;&gt;Hacking the Presidential Election&lt;/A&gt;&lt;/SPAN&gt; 
&lt;LI&gt;&lt;SPAN class=articleHeadline&gt;&lt;A href=&quot;http://www.theindependent.com/stories/092104/new_worm21.shtml&quot;&gt;Computer worm impacts drivers license process&lt;/A&gt; (Grand Island Independent)&lt;/SPAN&gt; 
&lt;LI&gt;&lt;SPAN class=articleHeadline&gt;&lt;A href=&quot;http://www.forbes.com/global/2004/0920/104.html&quot;&gt;Cyber-nightmare&lt;/A&gt; (Forbes)&lt;/SPAN&gt; 
&lt;LI&gt;&lt;SPAN class=articleHeadline&gt;&lt;A href=&quot;http://www.crime-research.org/interviews/hacker0904/&quot;&gt;Hackers or cyber soldiers?&lt;/A&gt;&lt;/SPAN&gt; 
&lt;LI&gt;&lt;SPAN class=articleHeadline&gt;&lt;A href=&quot;http://www.dchieftain.com/news/43773-08-25-04.html&quot;&gt;Tech sleuths track hacker&lt;/A&gt;&lt;/SPAN&gt; 
&lt;LI&gt;&lt;A href=&quot;http://www.utahstatesman.com/news/2004/09/10/CampusNews/Required.Computer.Registration.Reduces.Virus.Attacks-715634.shtml&quot;&gt;Required computer registration reduces virus attacks&lt;/A&gt;
&lt;LI&gt;&lt;SPAN class=articleHeadline&gt;&lt;A href=&quot;http://www.detnews.com/2004/metro/0409/01/d01-260445.htm&quot;&gt;Security failures exposed records&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;SPAN class=articleHeadline&gt;Hackers and viruses are &lt;A href=&quot;http://thewhir.com/marketwatch/wrap092404.cfm&quot;&gt;not the only threat&lt;/A&gt;.&amp;nbsp; We must all get more serious about &lt;A href=&quot;http://www.tmcnet.com/usubmit/2004/Sep/1070133.htm&quot;&gt;business continuity&lt;/A&gt;.&amp;nbsp; And here&apos;s an interesting &lt;A href=&quot;http://www.latimes.com/technology/la-hm-spyware23sep23,1,2674452.story?coll=la-headlines-technology&quot;&gt;article on spyware&lt;/A&gt; in the LA Times with this quote:&lt;/SPAN&gt;&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;
&lt;P&gt;&lt;SPAN class=articleHeadline&gt;&lt;EM&gt;&quot;Spyware is generally legal (in every state except Utah) as long as its original intent is to monitor browsing and shopping habits.Unfortunately, unscrupulous marketers and criminals have hidden their software under the spyware cloak to avoid being called viruses. Some spyware authors get paid about 15 cents a hit, while virus writers seem to be more motivated by the thrill of hacking into computer networks or disrupting corporations and government.&quot;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2004/09/24.html#a1479</guid>
			<pubDate>Fri, 24 Sep 2004 21:13:33 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=1479&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2004%2F09%2F24.html%23a1479</comments>
			</item>
		<item>
			<title>Utah Information Security Conference</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2004/07/29.html#a1420</link>
			<description>&lt;P&gt;I spent yesterday morning at the State information security conference.&amp;nbsp; Governor Walker (video stream coming) announced an increased focus on cybersecurity and asked for each department to appoint a Chief Security Officer that will be part of the State Information Security Council.&amp;nbsp; She was followed by Rob Clyde, CTO of Symantec, who gave an excellent presentation.&amp;nbsp; While hunting around, I found&lt;A href=&quot;http://ir.thomsonfn.com/InvestorRelations/PubMultimedia.aspx?partner=9918&quot;&gt; these video / audio&amp;nbsp;streams&lt;/A&gt; of several recent conferences that have some interesting information on current trends. Simple registration is required. &lt;/P&gt;
&lt;P&gt;Yesterday afternoon, we signed off on the Omnilink installation at UCAN.&amp;nbsp; I learned that Indiana and Ohio are using the same technology to support their statewide wireless initiatives.&amp;nbsp; Indiana&apos;s &lt;A href=&quot;http://www.in.gov/ipsc/safe-t/pdfs/STA.pdf&quot;&gt;Project Hoosier SAFE-T&lt;/A&gt; is at a similar stage and is being coordinated between all levels of government.&amp;nbsp; Here&apos;s a &lt;A href=&quot;http://www.in.gov/ipsc/safe-t/pdfs/126_site.pdf&quot;&gt;map&lt;/A&gt; of their current and planned implementation.&amp;nbsp; The terrain makes the task very different from Utah where we have the mountains to deal with.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2004/07/29.html#a1420</guid>
			<pubDate>Thu, 29 Jul 2004 14:12:47 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=1420&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2004%2F07%2F29.html%23a1420</comments>
			</item>
		<item>
			<title>Morning thoughts</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2004/04/21.html#a1293</link>
			<description>&lt;P&gt;&lt;A href=&quot;http://www.daylate.com/blog/archives/000322.html&quot;&gt;Jeff&lt;/A&gt; says that &quot;web services are really cool.&quot;&amp;nbsp; Yes they are and we have only begun to tap their potential.&lt;/P&gt;
&lt;P&gt;Kinja is being discussed in Cre8asite.&amp;nbsp; Here&apos;s my initial &lt;A href=&quot;http://www.kinja.com/user/dfletcher&quot;&gt;Kinja site&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;https://www.nascio.org/&quot;&gt;NASCIO&lt;/A&gt; is &lt;A href=&quot;http://www.governing.com/articles/4nascio.htm&quot;&gt;naming a new executive director&lt;/A&gt; on the eve of its midyear conference.&lt;/P&gt;
&lt;P&gt;The &lt;A href=&quot;http://www.cyberpartnership.org/&quot;&gt;National Cyber Security Partnership&lt;/A&gt; Task Force on Technical Standards and Common Criteria &lt;A href=&quot;http://www.cyberpartnership.org/041904.html&quot;&gt;released&lt;/A&gt; its &lt;A href=&quot;http://www.cyberpartnership.org/TF4TechReport.pdf&quot;&gt;recommendations&lt;/A&gt; this week.&amp;nbsp; Meanwhile &lt;A href=&quot;http://www.internetwk.com/breakingNews/showArticle.jhtml?articleID=18902471&quot;&gt;reports&lt;/A&gt; are circulating on a new Cisco vulnerability.&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://gotzespace.dk/archives/000920.html&quot;&gt;John Gotze&lt;/A&gt; points out that Denmark garners the #1 spot in this year&apos;s &lt;A href=&quot;http://www-5.ibm.com/dk/news/pressepdf/e_ready04_full_report.pdf&quot;&gt;eReadiness Report&lt;/A&gt;.&amp;nbsp; The U.S. has fallen to number 6 in the report.&amp;nbsp; The report, which is supported by IBM and the Economist, points out that the differences between the top eight were relatively minor.&amp;nbsp; Why is the U.S. falling behind.&amp;nbsp; One major reason is the relatively slow rollout of broadband services.&amp;nbsp; Four of the top five are in Scandinavia.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2004/04/21.html#a1293</guid>
			<pubDate>Wed, 21 Apr 2004 14:52:49 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=1293&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2004%2F04%2F21.html%23a1293</comments>
			</item>
		<item>
			<title>Spyware Control Debate Continues</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2004/04/20.html#a1292</link>
			<description>&lt;P&gt;Spyware is at the center of a growing debate.&amp;nbsp; Earlier this month, following the passage of the &lt;A href=&quot;http://www.le.state.ut.us/~2004/bills/hbillenr/hb0323.htm&quot;&gt;Utah Spyware Control Act&lt;/A&gt;, Andis Kaulins of &lt;A href=&quot;http://www.lawpundit.com/blog/lawpundit.htm&quot;&gt;LawPundit&lt;/A&gt; &lt;A href=&quot;http://www.lawpundit.com/blog/2004_04_01_lawpunditarchive.htm#108134425274968874&quot;&gt;wrote&lt;/A&gt;,&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;
&lt;P&gt;&lt;EM&gt;Utah has thus begun what will surely be a necessary and welcome surge in legislation prohibiting or restricting spyware and/or similarly intrusive unwanted software programs.&lt;/EM&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;The FTC just held a workshop to explore the spyware issue and, while &quot;calling spyware the next great internet scourge&quot; has also urged restraint in adopting new laws to control it.&amp;nbsp; The Center for Democracy &amp;amp; Technology presented what they are calling a &lt;A href=&quot;http://www.cdt.org/publications/pp_10.07.shtml#1&quot;&gt;&quot;consensus list&quot; of deceptive spyware scenarios&lt;/A&gt; at the conference.&amp;nbsp; I expect that we will need both techological and legal solutions to the growth of these practices including hijacking, surreptitious surveillance, and &quot;inhibiting termination&quot;.&amp;nbsp; I&apos;ve already seen a lot of this when you install something and then can&apos;t completely get rid of it.&lt;/P&gt;
&lt;P&gt;Several weeks ago, &lt;A href=&quot;http://www.bespacific.com/mt/archives/005397.html&quot;&gt;Sabrina Pacifici&lt;/A&gt; asked if the Utah bill would start a trend.&amp;nbsp; But spyware legislation is not new.&amp;nbsp; Sen. John Edwards &lt;A href=&quot;http://grc.com/spywarelegislation.htm&quot;&gt;introduced legislation&lt;/A&gt; in October 2000.&amp;nbsp; Burns, Wyden and Boxer &lt;A href=&quot;http://burns.senate.gov/index.cfm?FuseAction=PressReleases.Detail&amp;amp;PressRelease_id=1077&quot;&gt;introduced more legislation&lt;/A&gt; in February of this year.&amp;nbsp; I have no idea how many spyware bills have been issued in between that time.&lt;/P&gt;
&lt;P&gt;Many marketers insist that it is a critical part of their marketing efforts and fully supportable.&amp;nbsp;&amp;nbsp; But opposition is growing.&amp;nbsp; Bambi Francisco of CBS Marketwatch, &lt;A href=&quot;http://cbs.marketwatch.com/news/story.asp?guid=%7B5EEBBC61-838C-4026-81CE-0A5DFF774F0D%7D&amp;amp;siteid=google&amp;amp;dist=google&quot;&gt;rebuts&lt;/A&gt; the arguments that its simply a marketer&apos;s right:&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;
&lt;P dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;&lt;EM&gt;&quot;...it&apos;s not just being a smart consumer.&amp;nbsp; We&apos;re moving beyond the wild west of the World Wide Web. There should be some protection and controls, like those established in Utah recently.&quot;&lt;/EM&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;An America Online exec (&lt;A href=&quot;http://www.pcworld.com/news/article/0,aid,115765,00.asp&quot;&gt;quoted in PC World&lt;/A&gt;) who opposes excessive legislation argues that the industry will be somewhat self-regulating, &quot;&lt;EM&gt;We&apos;ll learn what the consumer thinks based on how they respond; it&apos;s not tied to any legal definition&lt;/EM&gt;.&quot;&amp;nbsp;&amp;nbsp; I&apos;m not quite convinced of that.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2004/04/20.html#a1292</guid>
			<pubDate>Wed, 21 Apr 2004 01:10:00 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=1292&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2004%2F04%2F20.html%23a1292</comments>
			</item>
		<item>
			<title>Federal eGov</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2004/04/16.html#a1291</link>
			<description>&lt;P&gt;The &lt;A href=&quot;http://www.whitehouse.gov/&quot;&gt;Whitehouse website&lt;/A&gt; has become much more interactive.&amp;nbsp; Recently, they have added features such as &lt;A href=&quot;http://www.whitehouse.gov/radio/index.html&quot;&gt;Whitehouse radio&lt;/A&gt; and &lt;A href=&quot;http://www.whitehouse.gov/interactive/index.html&quot;&gt;Whitehouse interactive&lt;/A&gt; (direct response to email), along with themed sites like &lt;A href=&quot;http://www.whitehouse.gov/baseball/index.html&quot;&gt;Presidents and Baseball&lt;/A&gt;&amp;nbsp;and the Easter Egg Roll.&lt;/P&gt;
&lt;P&gt;It should be time for the March 31st &lt;A href=&quot;http://www.results.gov/agenda/scorecard.html&quot;&gt;scorecard&lt;/A&gt; to come out for federal agencies.&amp;nbsp; According to the last scorecard, only two federal agencies have met the standards for eGov - the &lt;A href=&quot;http://www.opm.gov/&quot;&gt;Office of Personnel Management&lt;/A&gt; and the &lt;A href=&quot;http://www.nsf.gov&quot;&gt;National Science Foundation&lt;/A&gt;.&amp;nbsp; I am not quite sure what sets these agencies apart from the rest.&lt;/P&gt;
&lt;P&gt;I did initiate a customized profile with NSF that provides you with a personalized page along with options for email notifications.&amp;nbsp; In doing so, I noticed an item on &lt;A href=&quot;http://www.nsf.gov/od/lpa/news/04/tip040414.htm#second&quot;&gt;data mining for pinpointing network intrusions&lt;/A&gt;.&amp;nbsp; The &lt;A href=&quot;http://www.cs.umn.edu/research/minds/MINDS.htm&quot;&gt;Minnesota Intrusion Detection System&lt;/A&gt; (MINDS), funded by an NSF grant looks at the challenging issue of drilling through massive amounts of data to real attacks vs. false alarms.&lt;/P&gt;
&lt;P&gt;New Mexico provides an additional incentive for tax filers who file online -&lt;A href=&quot;http://www.abqjournal.com/news/state/aptax04-15-04.htm&quot;&gt; they have until April 30th to do it&lt;/A&gt;.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2004/04/16.html#a1291</guid>
			<pubDate>Fri, 16 Apr 2004 14:58:09 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=1291&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2004%2F04%2F16.html%23a1291</comments>
			</item>
		<item>
			<title>Global Assault</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2004/03/18.html#a1256</link>
			<description>&lt;P&gt;A &lt;A href=&quot;http://www.menafn.com/qn_news_story.asp?StoryId=CqfFBueidD2vIlwHHy2TLCNm&quot;&gt;UPI article&lt;/A&gt; examines the cyberwar that is taking place on the internet.&amp;nbsp; We are impacted by it everyday.&amp;nbsp; We installed MT blacklist yesterday to ward off the comment spam that had infiltrated the MT stuff that we are using to generate RSS feeds for production services.&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;
&lt;P&gt;&quot;&lt;EM&gt;A global assault for control of millions of computers is occurring,&quot; Steven Sundermeier, said. &quot;This appears to be a war for power and seniority among these authors.&quot;&lt;/EM&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;According to &lt;A href=&quot;http://www.detnews.com/2004/technology/0403/14/b01-91022.htm&quot;&gt;another article&lt;/A&gt; in the Detroit News, the annual cost in software and lost productivity related to spam is between 10 and 87 billion dollars.&lt;/P&gt;
&lt;P&gt;Bruce Schneier provides his monthly &lt;A href=&quot;http://www.schneier.com/crypto-gram.html&quot;&gt;Crypto-Gram&lt;/A&gt; newsletter as an&lt;A href=&quot;http://www.schneier.com/crypto-gram-rss.xml&quot;&gt; RSS feed&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Public Technology also recently published &lt;A href=&quot;http://www.publictechnology.net/modules.php?op=modload&amp;amp;name=News&amp;amp;file=article&amp;amp;sid=700&quot;&gt;an analysis of global digital warfare&lt;/A&gt;.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2004/03/18.html#a1256</guid>
			<pubDate>Thu, 18 Mar 2004 19:38:04 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=1256&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2004%2F03%2F18.html%23a1256</comments>
			</item>
		<item>
			<title>Cybersecurity Update</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2004/03/01.html#a1231</link>
			<description>&lt;P&gt;Senator Ron Wyden (OR)&amp;nbsp;is sponsoring the &lt;A href=&quot;http://www.cdt.org/legislation/108th/wiretaps/030729cpfda.pdf&quot;&gt;Citizens&apos; Protection in Federal Databases Act&lt;/A&gt; that prohibits the use of databases to mine for hypothetical scenarios and prevents government agencies from browsing bank records, online purchases or travel plans without regard to actual intelligence or law-enforcement information.&amp;nbsp; That bill was assigned to the Senate Judicial Committee last summer and has not been seen since.&amp;nbsp; Last week, Wyden teamed with Barbara Boxer to&lt;A href=&quot;http://www.esecurityplanet.com/trends/article.php/3319091&quot;&gt; sponsor a new anti-spyware bill&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;The Judicial Committee held a &lt;A href=&quot;http://judiciary.senate.gov/hearing.cfm?id=1054&quot;&gt;hearing on cyberterrorism&lt;/A&gt; last week.&amp;nbsp; Speaking of cyberterrorism, Bill Gratsch&apos;s &lt;A href=&quot;http://egovlinks.com/&quot;&gt;eGovLinks site&lt;/A&gt; was hacked over the weekend by the &quot;EmpEror SeCUriTy Team&quot;.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;The Department of Homeland Security is working with the &lt;A href=&quot;http://www.naag.org/&quot;&gt;National Association of Attorneys General&lt;/A&gt; (&amp;#147;NAAG&amp;#148;) to compile the Computer Crime Point-of-Contact List, a 50-state list of state and local prosecutors and investigators who are responsible for computer-related crimes within their respective jurisdictions. This list allows agents and prosecutors from one jurisdiction to call upon their colleagues in another jurisdiction for rapid response in cybercrime matters. &lt;/P&gt;
&lt;P&gt;Here&apos;s a good &lt;A href=&quot;http://www.apjii.or.id/apec/Training%20Powerpoints/LFFCC%20Substantive%20Laws%20to%20Fight%20Cybercrime%20(Arg).ppt&quot;&gt;powerpoint&lt;/A&gt; on legal frameworks for combatting cybercrime.&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://www.f-secure.com/&quot;&gt;F-Secure&lt;/A&gt; &lt;A href=&quot;http://www.f-secure.com/v-descs/netsky_d.shtml&quot;&gt;reports&lt;/A&gt; that&amp;nbsp;&quot;a new variant of Netsky worm - Netsky.D was found on March 1st, 2004 and is spreading fast in the wild. This worm variant lacks many text strings that were present in NetSky.C variant and it does not copy itself to shared folders.&quot;&amp;nbsp; We saw a lot of NetSky last week so I guess we&apos;ll be continuing to screen thousands of attempted intrusions.&lt;BR&gt;&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2004/03/01.html#a1231</guid>
			<pubDate>Mon, 01 Mar 2004 15:49:02 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=1231&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2004%2F03%2F01.html%23a1231</comments>
			</item>
		<item>
			<title>Security/Privacy Problem</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/12/29.html#a1107</link>
			<description>&lt;P&gt;Virginia&apos;s auditor during an &lt;A href=&quot;http://www.apa.state.va.us/data/download/reports/audit_local/Surplus03.pdf&quot;&gt;audit of surplus computers&lt;/A&gt; found the following information on old computers being auctioned to the public:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Vaccination information; 
&lt;LI&gt;Women Infant and Children (WIC) personal information; 
&lt;LI&gt;Personnel evaluations of individuals; 
&lt;LI&gt;Personnel records of grievances of individuals; 
&lt;LI&gt;Scholastic evaluations of individually identifiable students; and 
&lt;LI&gt;Personal credit card number of a Dean of a college.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;With all the effort spent to comply with HIPAA, other privacy laws, and standard information security, this is one hole that needs to be plugged everywhere, not just in Virginia.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/12/29.html#a1107</guid>
			<pubDate>Mon, 29 Dec 2003 15:27:31 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=1107&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2003%2F12%2F29.html%23a1107</comments>
			</item>
		<item>
			<title>December Infragard Meeting</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/12/08.html#a1056</link>
			<description>&lt;FONT face=Arial size=2&gt;The Infragard meeting on 12/17/03 will be at the Salt Lake City Public Library, 210 East 400 South, Salt Lake City, UT in Conference Room B, Level 1.&amp;nbsp; The speakers for this month&apos;s meeting have changed slightly.&amp;nbsp; The speakers and their&amp;nbsp; topics&amp;nbsp;will be as follows:&lt;/FONT&gt; 
&lt;UL&gt;
&lt;LI&gt;&lt;FONT face=Arial size=2&gt;Ken Crook - &quot;Terrorism - The Threat&quot;&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Arial size=2&gt;Karl Schmae - &quot;Securing the Homeland and Terrorism Indicators&quot;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/12/08.html#a1056</guid>
			<pubDate>Mon, 08 Dec 2003 15:07:37 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=1056&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2003%2F12%2F08.html%23a1056</comments>
			</item>
		<item>
			<title>Tech</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/09/18.html#a902</link>
			<description>&lt;P&gt;&lt;A href=&quot;http://www.blogalization.info/reorganization/&quot;&gt;Blogalization&lt;/A&gt; has picked up &lt;A href=&quot;http://blogalization.org/feeds/view.php?feed=1760&quot;&gt;my news feed&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://napps.nwfusion.com/compendium/archive/003454.html#003454&quot;&gt;NetWorld Fusion&lt;/A&gt; includes two Utah bloggers on its Top Ten list.&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://www.ratcliffe.com/bizblog/2003/09/15.html#a1137&quot;&gt;Mitch Ratcliffe&lt;/A&gt; presents an interesting application for VoIP.&amp;nbsp; VoIP has been slow taking off here and we need to identify a critical mass of business-oriented applications to drive the conversion.&amp;nbsp; Meanwhile, we need to get serious about how we install technology in new facilities, including the new state archives building.&lt;/P&gt;
&lt;P&gt;At yesterday&apos;s Infragard meeting Brian Grayek suggested that education (colleges, universities, and K-12) presets some of the greatest challenges for cybersecurity.&amp;nbsp; This month&apos;s issue of &lt;A href=&quot;http://www.thejournal.com/&quot;&gt;The Journal&lt;/A&gt; looks at many of those issues and presents some suggestions.&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://www.sltrib.com/2003/Sep/09182003/utah/93444.asp&quot;&gt;Update&lt;/A&gt; on electronic voting in Utah.&lt;/P&gt;
&lt;P&gt;The House just &lt;A href=&quot;http://www.infoworld.com/article/03/09/17/HNhouseinternet_1.html&quot;&gt;passed&lt;/A&gt; an internet tax ban.&amp;nbsp; It does not ban taxes levied on goods sold via the internet.&lt;/P&gt;
&lt;P&gt;Here&apos;s an &lt;A href=&quot;http://weblog.com.pt/&quot;&gt;interesting site&lt;/A&gt; that is tracking the growth of weblog activity in Portugal, a country which &lt;A href=&quot;http://radio.weblogs.com/0110120/2003/09/03.html&quot;&gt;supports weblogs&lt;/A&gt; for all of its legislators.&amp;nbsp; &lt;A href=&quot;http://ecuaderno.com&quot;&gt;Jose Luis Orihuela&lt;/A&gt; references an article in &lt;A href=&quot;http://jn.sapo.pt&quot;&gt;Jornal de Noticias&lt;/A&gt; on the growth of blogging in Portugal.&lt;/P&gt;
&lt;P&gt;DARPA is exploring &lt;A href=&quot;http://www.darpa.mil/dso/thrust/biosci/brainmi.htm&quot;&gt;Brain Machine Interfaces&lt;/A&gt;.&amp;nbsp; A Carnegie-Mellon scientest has been charged by NSF with &lt;A href=&quot;http://www.post-gazette.com/pg/03261/223196.stm&quot;&gt;designing&lt;/A&gt; a new national communications infrastructure.&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://www.weather.gov&quot;&gt;Weather.gov&lt;/A&gt; is down today.&amp;nbsp; Probably overwhelmed by Isabel.&lt;/P&gt;
&lt;P&gt;In Washington, some are &lt;A href=&quot;http://www.washingtonpost.com/wp-dyn/articles/A29520-2003Sep18.html&quot;&gt;calling&lt;/A&gt; the departure of three people a &quot;brain drain&quot; on the nation&apos;s eGov efforts and Intel is claiming it &lt;A href=&quot;http://www.infoworld.com/article/03/09/17/HNh1bhearing_1.html&quot;&gt;can&apos;t find&lt;/A&gt; enough good IT workers in this country of &lt;A href=&quot;http://www.census.gov/cgi-bin/popclock&quot;&gt;292,107,007&lt;/A&gt;&amp;nbsp;people.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/09/18.html#a902</guid>
			<pubDate>Thu, 18 Sep 2003 15:17:44 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=902&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2003%2F09%2F18.html%23a902</comments>
			</item>
		<item>
			<title>Total Security Management</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/09/15.html#a896</link>
			<description>&lt;P&gt;&lt;BR&gt;The next InfraGard (of the Wasatch)&amp;nbsp;meeting will be on 9/17/03 at 12 pm.&amp;nbsp; The meeting will be held at the Parks Department, 2nd Floor,&amp;nbsp;1965 West 500 South, Salt Lake City, UT instead of at the usual location at the City &amp;amp; County Building. If you will be attending the meeting and have not yet rsvp&apos;d, please e-mail&amp;nbsp;Cheney to let him know that you will be attending. &lt;/P&gt;
&lt;P&gt;The speaker will be Brian Grayek, Technology Strategist to the Office of the CTO, Computer Associates.&amp;nbsp; Brian has over 20 years experience in security and is highly regarding for his security expertise in the industry.&amp;nbsp; The topic of his presentation will be &quot;Total Security Management&quot;.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/09/15.html#a896</guid>
			<pubDate>Tue, 16 Sep 2003 00:36:20 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=896&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2003%2F09%2F15.html%23a896</comments>
			</item>
		<item>
			<title>Infragard meeting scheduled for September</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/08/27.html#a869</link>
			<description>&lt;P align=left&gt;The third quarter meeting of the InfraGard of the Wasatch has been scheduled for 9/17/03 at 12 pm. This meeting is being sponsored by Computer Associates. &amp;nbsp;The speaker will be Brian Grayek, Technology Strategist to the Office of the CTO, Computer Associates.&amp;nbsp; Those planning to attend should&amp;nbsp;RSVP to&amp;nbsp;Cheney Eng-Tow via e-mail as soon as possible. The meeting will be held at the Parks Department Building located at 1965 West 500 South, Salt Lake City, UT.&amp;nbsp;&amp;nbsp; If there are any questions, please contact me.&lt;/P&gt;&lt;/FONT&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/08/27.html#a869</guid>
			<pubDate>Wed, 27 Aug 2003 20:42:07 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=869</comments>
			</item>
		<item>
			<title>Security Groups</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/06/23.html#a744</link>
			<description>&lt;P&gt;The first national &lt;A href=&quot;http://www.infragard.com/&quot;&gt;Infragard&lt;/A&gt; &lt;A href=&quot;http://infragard2003.com/&quot;&gt;conference&lt;/A&gt; is &lt;A href=&quot;http://www.washingtonpost.com/wp-dyn/articles/A22237-2003Jun23.html&quot;&gt;being held today&lt;/A&gt; in Washington, DC.&amp;nbsp; I just came across the&lt;A href=&quot;http://www.isaca-ut.org/&quot;&gt; local ISACA website&lt;/A&gt;.&amp;nbsp; Many ISACA members are also involved with Infragard.&amp;nbsp; The &lt;A href=&quot;http://www.isaca.org/nsc2003.htm&quot;&gt;fifth annual Network Security Conference&lt;/A&gt; sponsored by ISACA will be held in Las Vegas in September.&amp;nbsp; The agenda looks useful.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/06/23.html#a744</guid>
			<pubDate>Mon, 23 Jun 2003 21:39:55 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=744&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2003%2F06%2F23.html%23a744</comments>
			</item>
		<item>
			<title>Enterprise Security</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/05/23.html#a687</link>
			<description>&lt;P&gt;Dave McNamee &lt;A href=&quot;http://radio.weblogs.com/0110870/2003/05/21.html#a153&quot;&gt;said something&lt;/A&gt; VERY important the other day regarding security.&amp;nbsp; He referred to a Gartner study that says that the average employee has access to 15 to 17 applications during employment and that the same employee may still have access to about 10 of those applications after termination.&amp;nbsp; Obviously, this supports the positon of implementing security at the enterprise level where access can be linked to human resource information.&amp;nbsp; We have many critical pieces of that model in place with the Utah Master Directory.&lt;/P&gt;
&lt;P&gt;A recent &lt;A href=&quot;http://www.washingtonpost.com/wp-dyn/articles/A2619-2003May17.html&quot;&gt;series in the Washington Post&lt;/A&gt; points out how hackers in Russia are affecting businesses throughout the U.S.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/05/23.html#a687</guid>
			<pubDate>Fri, 23 May 2003 16:16:26 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=687&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2003%2F05%2F23.html%23a687</comments>
			</item>
		<item>
			<title>Broadband in the Navajo Nation</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/05/20.html#a679</link>
			<description>&lt;P&gt;The US Department of Agriculture is &lt;A href=&quot;http://www.nytimes.com/2003/05/20/technology/20TBRF2.html?tntemail0&quot;&gt;spending&lt;/A&gt; about $20 million on broadband services in rural America.&amp;nbsp; Some of the money will go to help Native American communities in Utah and other states.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;One company involved in the Navajo nation is &lt;A href=&quot;http://www.siliconstrategies.com/pressreleases/prnewswire/62890&quot;&gt;Skyframes&lt;/A&gt;, Inc. which is providing satellite connectivity into northern Arizona.&amp;nbsp; The &lt;A href=&quot;http://www.digitaldividenetwork.org/content/stories/index.cfm?key=44&quot;&gt;Digital Divide Network&lt;/A&gt; suggests that the extension of internet services will help unite the Navajo Nation.&amp;nbsp; The University of New Mexico supports the &lt;A href=&quot;http://eot.ahpcc.unm.edu/Community/Research-Wireless.html&quot;&gt;Native American Distance Education Community Web&lt;/A&gt;&amp;nbsp;which is aggressively supporting a variety of wireless projects throughout the area.&lt;/P&gt;
&lt;P&gt;Ariana Cha with the Washington Post is &lt;A href=&quot;http://discuss.washingtonpost.com/wp-srv/zforum/03/sp_technews_cha052003.htm&quot;&gt;on a live chat right now&lt;/A&gt; (9 am MST) discussing Cybercrime in the US.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/05/20.html#a679</guid>
			<pubDate>Tue, 20 May 2003 16:00:45 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=679&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2003%2F05%2F20.html%23a679</comments>
			</item>
		<item>
			<title>Building the Information Society in Ireland</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/05/14.html#a671</link>
			<description>&lt;P&gt;&lt;IMG src=&quot;http://das.utah.gov/images/irishflag.jpg&quot; align=right&gt;&lt;A href=&quot;http://radio.weblogs.com/0110120/2003/05/13.html#a669&quot;&gt;Yesterday&lt;/A&gt;, I mentioned &lt;A href=&quot;http://www.zentelligence.blogspot.com/&quot;&gt;Simon Moore&apos;s&lt;/A&gt; excellent report on trustworthy computing.&amp;nbsp; Ireland&apos;s Information Society Commission produced a report several months ago entitled, &quot;&lt;A href=&quot;http://www.isc.ie/downloads/legal.pdf&quot;&gt;Building Trust through the Legal Framework&lt;/A&gt;.&quot;&amp;nbsp; The suggestion is that government has an over-riding responsibility to create a trusted digital environment in order for a society to transform into a true &quot;information society&quot; which has become a major objective for the Irish.&amp;nbsp; They would like to move from 27th into the top tier of European nations in areas like eGovernment.&amp;nbsp; In order to build trust, they are suggesting measures like the creation of a &quot;trust and confidence&quot; mark that could be used by Irish electronic commerce providers and the appointment of &quot;data protection commissioners.&quot;&amp;nbsp; Another report, &lt;A href=&quot;http://www.isc.ie/downloads/know.pdf&quot;&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;FONT color=blue&gt;Building the Knowledge Society&lt;/FONT&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/A&gt;, more specifically addresses the issue of building eGovernment.&lt;/P&gt;
&lt;P&gt;Ireland&apos;s &lt;A href=&quot;http://www.electricnews.net/section.html?code=85&quot;&gt;Electric News Network&lt;/A&gt; has a regular column dedicated to eGovernment issues.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/05/14.html#a671</guid>
			<pubDate>Wed, 14 May 2003 20:42:32 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=671&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2003%2F05%2F14.html%23a671</comments>
			</item>
		<item>
			<title>eGovernment and Trust</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/05/13.html#a669</link>
			<description>&lt;P&gt;Dr. Simon Moores, owner of the &lt;A href=&quot;http://www.zentelligence.blogspot.com/&quot;&gt;Zentelligence weblog&lt;/A&gt;, has authored an excellent report entitled, &quot;&lt;A href=&quot;http://www.egovmonitor.com/reports/matteroftrust.pdf&quot;&gt;A Matter of Trust: A Special Report on Trustworthy Computing&lt;/A&gt;.&quot;&amp;nbsp; Read it and let me know what you think.&amp;nbsp; I find his perspectives to be excellent on matters of importance to the success of eGovernment and this is certainly one of those.
&lt;P&gt;&lt;A href=&quot;http://www.gsa.gov/cm_attachments/GSA_PUBLICATIONS/High-Payoff-finalreport_R2D7J7_0Z5RDZ-i34K-pR.doc&quot;&gt;Another report&lt;/A&gt; (MS Word document), recently released by the Office of Intergovernmental Services discusses the payoff and measurements associated with the implementation of eGov programs.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/05/13.html#a669</guid>
			<pubDate>Wed, 14 May 2003 00:39:05 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=669&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2003%2F05%2F13.html%23a669</comments>
			</item>
		<item>
			<title>Critical Infrastructure Report</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/04/11.html#a624</link>
			<description>&lt;P&gt;&lt;A href=&quot;http://www.bespacific.com/mt/archives/002408.html#2408&quot;&gt;Sabrina Pacifici&lt;/A&gt; points out the latest &lt;A href=&quot;http://www.gao.gov/cgi-bin/getrpt?GAO-03-564T&quot;&gt;GAO report on critical infrastructure&lt;/A&gt;.&amp;nbsp; Like always, the report stresses major weaknesses in the nations computer networks.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/04/11.html#a624</guid>
			<pubDate>Fri, 11 Apr 2003 22:52:09 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=624&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2003%2F04%2F11.html%23a624</comments>
			</item>
		<item>
			<title>Capitol Connections and breaking news and hacker battle</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/03/28.html#a602</link>
			<description>&lt;P&gt;The &lt;A href=&quot;http://www.das.state.ut.us/cc/mar2003/index.html&quot;&gt;March issue&lt;/A&gt; (isn&apos;t it almost April) of Capitol Connections is online.&amp;nbsp; Included in this issue are &lt;A href=&quot;http://www.das.state.ut.us/cc/mar2003/techcorner.html&quot;&gt;an article on DEQ&apos;s efforts&lt;/A&gt; to support NEIEN development and the One-Stop Reporting Project, as well as an article by Doug Chandler on &lt;A href=&quot;http://www.das.state.ut.us/cc/mar2003/its.htm&quot;&gt;ITS wireless operations&lt;/A&gt;.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;The &lt;A href=&quot;http://www.sltrib.com/2003/Mar/03282003/iraq/42697.asp&quot;&gt;Salt Lake Tribune reports&lt;/A&gt; that hackers redirected an Al Jazeera site to a site supported by a Salt Lake-based ISP.&lt;/P&gt;
&lt;P&gt;I just heard on the radio that there is a major denial-of-service attack coming from France, Russia, and China against NetWorld which is the ISP where the Al-Jazeera site was re-directed to...&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/03/28.html#a602</guid>
			<pubDate>Fri, 28 Mar 2003 15:05:40 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=602&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2003%2F03%2F28.html%23a602</comments>
			</item>
		<item>
			<title>Zeichner Report Hammers State Cybersecurity Efforts</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/03/24.html#a591</link>
			<description>&lt;P&gt;A &lt;A href=&quot;http://www.zra.com/docs/summaryReport.pdf&quot;&gt;report released this morning by Zeichner Risk Analytics&lt;/A&gt; criticizes the states for not developing appropriate cyber-security programs.&amp;nbsp; The report states that:&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;
&lt;P&gt;&quot;&lt;EM&gt;At some point, the states may need to leave development of all cyber-security and critical infrastructure guidance exclusively to the Federal government supported by professional organizations&lt;/EM&gt;.&quot;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Among the report&apos;s findings:&lt;/P&gt;&lt;FONT face=TimesNewRoman&gt;
&lt;UL&gt;
&lt;LI&gt;36 states have failed to prepare, adopt, and implement adequate cyber-security policies, as required by Congress.&lt;/FONT&gt;&lt;FONT face=TimesNewRoman&gt;&lt;FONT face=TimesNewRoman&gt; 
&lt;LI&gt;The lack of progress in the states requires insurance companies (and other companies regulated by the states) to waste considerable expense tracking implementation status. 
&lt;LI&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT face=TimesNewRoman&gt;&lt;FONT face=TimesNewRoman&gt;&lt;FONT face=TimesNewRoman&gt;
&lt;P&gt;States have fallen even further behind the Federal government and financial services industry in developing appropriate cyber-security programs.&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;FONT face=TimesNewRoman&gt;&lt;FONT face=TimesNewRoman&gt;&lt;FONT face=TimesNewRoman&gt;
&lt;P&gt;I met with our State risk manager recently to discuss our cybersecurity efforts and am unaware of any insurance company efforts to track our cybersecurity program.&amp;nbsp; I am not aware of any such inquiries.&amp;nbsp; The report recommends adopting the proposed national regulation developed by the &lt;A href=&quot;http://www.naic.org&quot;&gt;National Association of Insurance Commissioners&lt;/A&gt;.&amp;nbsp; I&apos;m trying to figure out what that is.&amp;nbsp; The State&apos;s&lt;A href=&quot;http://insurance.utah.gov&quot;&gt; Insurance Dept&lt;/A&gt;. is just down the hall from me.&amp;nbsp;[followup: the Deputy Insurance Commissioner passed along this link to &lt;A href=&quot;http://www.rules.utah.gov/publicat/code/r590/r590-216.htm&quot;&gt;&lt;EM&gt;Utah&apos;s rule on safeguarding customer information&lt;/EM&gt;&lt;/A&gt;]&amp;nbsp;The NAIC is certainly an active association based on their&lt;A href=&quot;http://www.naic.org/pressroom/releases/rel03/index.htm&quot;&gt; regular press releases&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;The report shows that 15 states are in full compliance with the &lt;A href=&quot;http://www.ftc.gov/privacy/glbact/&quot;&gt;Gramm-Leach-Blilely Act&lt;/A&gt; which requires the states to take specific action with respect to cyber-security measures and guidance.&amp;nbsp; Utah, along with Washington and Virginia,&amp;nbsp;is among the 15 states in compliance.&amp;nbsp; Utah was very involved in infrastructure protection efforts and cyber-security measures prior to 9-11, partially due to its preparations for the 2002 Winter Games, but also in relation to its Y2K preparations.&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/03/24.html#a591</guid>
			<pubDate>Mon, 24 Mar 2003 16:43:16 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=591&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2003%2F03%2F24.html%23a591</comments>
			</item>
		<item>
			<title>Increased Cyber Activity</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/03/18.html#a582</link>
			<description>&lt;p&gt;On the eve of war with Iraq, we are seeing significant increases in cyber activity.&amp;nbsp; Tighten your security and be vigilant.&amp;nbsp; After the elevation of the Homeland Security System to Orange-High, the &lt;A href=&quot;http://isc.incidents.org/&quot;&gt;Internet Storm Center&lt;/A&gt; is now showing a yellow alert status.&amp;nbsp; There is definitely an increase of port 80 attacks.&amp;nbsp; If you&apos;re running on IIS, be sure to check the latest &lt;A href=&quot;http://www.cert.org/advisories/CA-2003-09.html&quot;&gt;CERT advisory&lt;/A&gt;&amp;nbsp;with an &lt;A href=&quot;http://www.nipc.gov/warnings/advisories/2003/03-005.htm&quot;&gt;echo&lt;/A&gt; from the NIPC.</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/03/18.html#a582</guid>
			<pubDate>Tue, 18 Mar 2003 15:29:56 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=582&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2003%2F03%2F18.html%23a582</comments>
			</item>
		<item>
			<title>Emerging Storm: A Gartner Weblog</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/03/17.html#a579</link>
			<description>&lt;P&gt;Gartner has created a weblog entitled &quot;&lt;A href=&quot;http://weblog.gartner.com/weblog/index.php?blogid=4&quot;&gt;Emerging Storm&lt;/A&gt;&quot; that regularly discusses issues like cybersecurity and business continuity.&amp;nbsp; In a recent post, Rich Mogull discusses the role of government agencies in protecting cyberspace:
&lt;BLOCKQUOTE dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;
&lt;P&gt;&lt;EM&gt;&quot;Despite the recent involvement of the &lt;/EM&gt;&lt;A href=&quot;http://www.dhs.gov/dhspublic/index.jsp&quot; target=_blank&gt;&lt;EM&gt;U.S. Department of Homeland Security &lt;/EM&gt;&lt;/A&gt;&lt;EM&gt;(DHS) in coordinating response to the &lt;/EM&gt;&lt;A href=&quot;http://www.wired.com/news/infostructure/0,1377,57945,00.html&quot; target=_blank&gt;&lt;EM&gt;latest Sendmail vulnerability &lt;/EM&gt;&lt;/A&gt;&lt;EM&gt;and the development of an &lt;/EM&gt;&lt;A href=&quot;http://www.computerworld.com/securitytopics/security/story/0,10801,78402,00.html&quot; target=_blank&gt;&lt;EM&gt;EU cybersecurity center&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt;, governments play a minor role in the management of cyberincidents. In the U.S., DHS is still in a formulative stage, without a leader for cyberdefenses or a fully defined organizational structure and operating process. DHS is combining a series of cyberagencies - such as the &lt;/EM&gt;&lt;A href=&quot;http://www.nipc.gov/&quot; target=_blank&gt;&lt;EM&gt;National Infrastructure Protection Center &lt;/EM&gt;&lt;/A&gt;&lt;EM&gt;and the &lt;/EM&gt;&lt;A href=&quot;http://www.ciao.gov/&quot; target=_blank&gt;&lt;EM&gt;Critical Infrastructure Assurance Office&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; (and has &lt;/EM&gt;&lt;A href=&quot;http://www.fcw.com/fcw/articles/2003/0303/web-order-03-04-03.asp&quot; target=_blank&gt;&lt;EM&gt;dissolved&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; the President&apos;s Critical Infrastructure Protection Board) - but none of these agencies have been as effective or responsive as private industry cybersecurity initiatives.&quot;&lt;/EM&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I think Rich is correct, none of these agencies seems to have the reach of something like Symantec, CERT, or the Internet Storm Center.&amp;nbsp; I am hoping that the effectiveness of the Infragard effort will continue to grow.&lt;/P&gt;
&lt;P&gt;Gartner&apos;s weblog was mentioned in a recent Newsfactor article, &quot;&lt;A href=&quot;http://www.ecommercetimes.com/perl/story/20975.html&quot;&gt;Blogging Goes Corporate&lt;/A&gt;.&quot;&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/03/17.html#a579</guid>
			<pubDate>Mon, 17 Mar 2003 15:20:47 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=579&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2003%2F03%2F17.html%23a579</comments>
			</item>
		<item>
			<title>Compromise of Personal Information</title>
			<link>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/03/07.html#a560</link>
			<description>&lt;P&gt;&lt;A href=&quot;http://radio.weblogs.com/0113442/&quot;&gt;Barbara Haven&lt;/A&gt;, blogging from California, refers to a major hack of a University of Texas administrative data reporting system which compromised information on 55,000 individuals.&amp;nbsp; &lt;A href=&quot;http://www.infoworld.com/article/03/03/06/HNtexashack_1.html&quot;&gt;According to Infoworld&lt;/A&gt;, the attacker used a &quot;blunt force&quot; technique by programming inputs of millions of Social Security numbers into the system.&amp;nbsp; Matched records were captured by the intruder.&lt;/P&gt;
&lt;P&gt;On the last night of the legislative session, the state legislature passed &lt;A href=&quot;http://www.le.state.ut.us/~2003/bills/hbillint/hb0105s1.pdf&quot;&gt;substitute House Bill 105&lt;/A&gt;.&amp;nbsp; Part 4 is now referred to as the Government Internet Information Privacy Act.&amp;nbsp; This act applies to any state agency that maintains a public website.&amp;nbsp; For purpose of the bill, personally identifiable information means name, account number, physical address, electronic address (I guess that could mean email or IP address), telephone number, or social security number.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;According to the bill, before a government website can collect personally identifiable information,&amp;nbsp;the website must contain a specific policy statement which (among other things) includes a general description of the security measures in place to protect a user&apos;s personally identifiable information from unintended disclosure.&amp;nbsp; I think our standard &lt;A href=&quot;http://www.utah.gov/privacypolicy.html&quot;&gt;privacy policy statement&lt;/A&gt; addresses the issues as outlined.&amp;nbsp; We just need to review it to make sure.&lt;/P&gt;
&lt;P&gt;The bill also requires the IT Commission to study the issue of popup ads.&amp;nbsp; It would be nice to eliminate them, wouldn&apos;t it?&lt;/P&gt;
&lt;P&gt;I am glad that Google is beginning to &lt;A href=&quot;http://www.securityfocus.com/news/2934&quot;&gt;address issues&lt;/A&gt; associated the security of the Blogger product.&lt;FONT face=&quot;Times New Roman&quot;&gt;&lt;/P&gt;&lt;/FONT&gt;</description>
			<guid>http://radio.weblogs.com/0110120/categories/cybersecurity/2003/03/07.html#a560</guid>
			<pubDate>Fri, 07 Mar 2003 15:42:00 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=110120&amp;amp;p=560&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0110120%2F2003%2F03%2F07.html%23a560</comments>
			</item>
		</channel>
	</rss>
