<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1189434011500461359</id><updated>2012-01-27T07:34:03.199-06:00</updated><category term='cybersecurity'/><category term='2009 2010 Perspective Predictions Cyber Information Security'/><category term='cyber security top stories 2008 predictions 2009 control system'/><category term='CERT Security Awareness Month National Cyber'/><category term='CIP'/><category term='tools'/><category term='DNS'/><category term='Symantec Stuxnet Breakthrough Critical Infrastructure Iran Enrichment'/><category term='SCADA Cybersecurity attack water utility DHS'/><category term='security breach bank outsourcing secruity risk Satyam Computer Services'/><category term='Decade Singularity &quot;Ray Kurzweil&quot; &quot;Daniel Suarez&quot; &quot;Bill Joy&quot; Nanotechnology 2020 KurzweilAI.net'/><category term='Time Warner'/><category term='Ralph Langner'/><category term='Smartgrid cyber security IOActive smartmeter'/><category term='DIgitalBond'/><category term='News TCP Sockstress Attack Vulnerability Microsoft Emergency Control Systems Security DHS CSSP Program Tools SecurityNow 164 WLAN ZigBee Wireless WLAN OPSEC CS2SAT Assessment'/><category term='Cyberwar BlackHat Stuxnet Schneier 2011'/><category term='ISP'/><category term='incident'/><category term='nuclear'/><category term='archive'/><category term='Compliance'/><category term='Organization'/><category term='NCSD'/><category term='AutoIT Script Microsoft Windows XP Vista Windows7 Compile Screensaver Delay Utility Cyber Security &quot;Egg Timer&quot; CDS SourceForge'/><category term='Top10'/><category term='Privacy'/><category term='NERC'/><category term='EMP Cyber Security Electric Grid NERC &quot;Lofty Perch&quot;'/><category term='Obama'/><category term='AIM Institute'/><category term='Project Basecamp'/><category term='NERC CIP Revisions Comment Period  FERC &quot;Order 706&quot;'/><category term='&quot;Cloud Computing&quot; vSphere Azure CSA &quot;Cloud Security Alliance&quot;'/><category term='SCADA'/><category term='Critial Infrastructure Protection'/><category term='Defcon'/><category term='2010 SCADA and Process Control Summit APT Utilities Contested Territories NERC INL DHS CIP'/><category term='Targeted Attacks'/><category term='Manager'/><category term='DHS'/><category term='FERC'/><category term='cyber'/><category term='Security Assessment'/><category term='Convergence'/><category term='Cyberwar Cybersecurity BlackHat 2011 Stuxnet'/><category term='FACTA FTC Enforcement Delay News six months'/><category term='Cyber Security Program'/><category term='security'/><category term='critical infrastructure'/><category term='Top 10'/><category term='Corporate'/><category term='Tim Roxey'/><category term='Penetration Testing'/><category term='Assante'/><category term='ICS'/><category term='lowcost'/><category term='Singularity Kurzweil'/><category term='Omaha'/><category term='Welcome'/><category term='Top Cyber Security Sites Resources'/><category term='Security Expert'/><category term='Alerts'/><category term='Hearings'/><category term='NIST NERC NRC Smartgrid BlackHat NIST cyber security hacking worm smartmeter'/><category term='federal'/><category term='Cybersecurity NRC CFR 73.54 NERC CIP-002 regulatory'/><category term='Infotec09'/><category term='FERC FPL $25M NERC'/><category term='Information Security Program'/><category term='Black Hat'/><category term='cybersecurity Senate FISMA NERC CIP SANS Paller Lieberman'/><title type='text'>This Week In Security - Orlando Stevenson</title><subtitle type='html'>Security topics with a special interest in critical infrastructure cyber protection, supporting strategy and programs, business drivers, and the future.   &lt;a href="http://thisweekinsecurity.blogspot.com"&gt;Home &lt;/a&gt;</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>36</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-4503339286932780430</id><published>2012-01-26T23:37:00.020-06:00</published><updated>2012-01-27T07:34:03.213-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Project Basecamp'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='Ralph Langner'/><category scheme='http://www.blogger.com/atom/ns#' term='SCADA'/><category scheme='http://www.blogger.com/atom/ns#' term='DIgitalBond'/><category scheme='http://www.blogger.com/atom/ns#' term='ICS'/><title type='text'>Project Basecamp 2012 a Hit...  Are We Really Ripe for More Attacks Like Stuxnet?-Researcher Ralph Langner says "Yes" at NATO Keynote.</title><content type='html'>&lt;span style="font-weight: bold; color: rgb(102, 0, 0);"&gt;&lt;br /&gt;Project &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;Basecamp&lt;/span&gt;&lt;/span&gt; A Hit- But Will It work? &lt;/span&gt;&lt;br style="color: rgb(102, 0, 0);"&gt;&lt;a href="http://www.digitalbond.com/2012/01/26/basecamp-1-week-later-outrage/"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 161px; height: 240px;" src="https://www.digitalbond.com/wp-content/uploads/2012/01/screem.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Researchers &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_1"&gt;participating&lt;/span&gt; in &lt;a href="http://www.digitalbond.com/?s=Basecamp"&gt;Project &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;Basecamp&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; clearly demonstrated just how extremely fragile and vulnerable many Industrial Control Systems (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;ICSs&lt;/span&gt;&lt;/span&gt;) remain to targeted &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;cyber&lt;/span&gt;&lt;/span&gt; attacks during &lt;a href="http://www.digitalbond.com/s4/"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;DigitalBond's&lt;/span&gt;&lt;/span&gt; S4 conference&lt;/a&gt; this month.      Amazingly, a number of persistent &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_6"&gt;vulnerabilities&lt;/span&gt; include poorly devised "features" in addition to a bucket load of underlying software flaws.  Tools released include point and click easy &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;Metasploit&lt;/span&gt;&lt;/span&gt; modules.  All of this effort to extensively demonstrate persistent &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;ICS&lt;/span&gt;&lt;/span&gt; security problems is &lt;span style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_9"&gt;ultimately&lt;/span&gt; intended to wake up C-level executives to help amp up &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_10"&gt;pressure&lt;/span&gt; on the vendors for secure replacements&lt;/span&gt; ("a &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;Firesheep&lt;/span&gt;&lt;/span&gt; moment").      Regardless, don't expect much soon as many experts agree we've seen ten years pass with few &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;ICS&lt;/span&gt;&lt;/span&gt; vendor security improvements.   &lt;a href="http://www.digitalbond.com/"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;DigitalBond's&lt;/span&gt;&lt;/span&gt; site&lt;/a&gt;  continues dishing up excellent interviews (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;podcasts&lt;/span&gt;&lt;/span&gt;), videos, and blog entries  worth paying attention to for those interested in &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_15"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;ICS&lt;/span&gt;&lt;/span&gt; security.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(102, 0, 0);"&gt;What about &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_16"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;Stuxnet&lt;/span&gt;&lt;/span&gt; - More to come or really just a one time event?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:black;"&gt;Here’s one of the most  insightful, solid presentations&lt;/span&gt; available &lt;span style="color:black;"&gt;exp&lt;/span&gt;&lt;a href="http://vimeo.com/25710852"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 320px; height: 178px;" src="http://4.bp.blogspot.com/-_PiyEzLq6QQ/TyI3uF63OMI/AAAAAAAAACY/j1D410PLFZ0/s320/RalphLangnerNATO2011.jpg" alt="" id="BLOGGER_PHOTO_ID_5702181343207045314" border="0" /&gt;&lt;/a&gt;&lt;span style="color:black;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_17"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;lainin&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color:black;"&gt;g h&lt;/span&gt;&lt;span style="color:black;"&gt;o&lt;/span&gt;&lt;span style="color:black;"&gt;w  Ralph &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_18"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;Langer&lt;/span&gt;&lt;/span&gt; &amp;amp; team pulled apart &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_19"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_15"&gt;Stuxnet&lt;/span&gt;&lt;/span&gt;, what they found, and broader &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_20"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_16"&gt;implicati&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color:black;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_21"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_17"&gt;ons&lt;/span&gt;&lt;/span&gt;.   While the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_22"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_18"&gt;Stuxnet&lt;/span&gt;&lt;/span&gt; windows “dropper” was t&lt;/span&gt;&lt;span style="color:black;"&gt;op tier &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_23"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_19"&gt;malware&lt;/span&gt;&lt;/span&gt; in many ways,  including m&lt;/span&gt;&lt;span style="color:black;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_24"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_20"&gt;ultiple&lt;/span&gt;&lt;/span&gt; zero-days,   &lt;b&gt;&lt;i&gt;the real rocket science was approx. 15,000 lines of crafted industrial control system (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_25"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_21"&gt;ICS&lt;/span&gt;&lt;/span&gt;) &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_26"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_22"&gt;malware&lt;/span&gt;&lt;/span&gt; payload  “digital warhead” developed by seasoned engineers&lt;/i&gt;&lt;/b&gt; (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_27"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_23"&gt;Langner&lt;/span&gt;&lt;/span&gt;’s opinion- not just “hackers”) targeting &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_28"&gt;specific&lt;/span&gt;&lt;/span&gt;&lt;span style="color:black;"&gt; nuclear enrichment &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_29"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_24"&gt;ICS&lt;/span&gt;&lt;/span&gt; assets.&lt;/span&gt;&lt;span style="font-family: Wingdings;font-family:Wingdings;" &gt;&lt;span style=""&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;&lt;a href="http://vimeo.com/25710852"&gt;Ralph &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_30"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_25"&gt;Langner's&lt;/span&gt;&lt;/span&gt; keynote "The first deployed &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_31"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_26"&gt;cyber&lt;/span&gt;&lt;/span&gt; weapon in history: &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_32"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_27"&gt;Stuxnet&lt;/span&gt;&lt;/span&gt;’s architecture and implications"&lt;/a&gt;&lt;/b&gt;    (1:05)  6/2011&lt;i&gt;   NATO Cooperative &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_33"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_28"&gt;Cyber&lt;/span&gt;&lt;/span&gt; Defence Centre of Excellence  -   NATO &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_34"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_29"&gt;CCD&lt;/span&gt;&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_35"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_30"&gt;COE&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoListParagraph" style="text-indent:-.25in;mso-list:l0 level1 lfo1"&gt;  &lt;/p&gt;&lt;p class="MsoNormal"&gt;Mr. Langner makes a solid case that this was a highly successful attack (like a missile) which invites an escalation for more to come.  The code and modular approach itself is reusable in many ways.    He’s also written a book "&lt;strong&gt;Robust Control System Networks: How to Achieve Reliable Control After &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_36"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_31"&gt;Stuxnet&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;"  that &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_37"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_32"&gt;ICS&lt;/span&gt;&lt;/span&gt; engineers, others can benefit from focusing on designing &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_38"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_33"&gt;ICS&lt;/span&gt;&lt;/span&gt; systems with robust security baked in  &lt;a href="http://www.digitalbond.com/2011/08/15/langner-book-review-robust-control-system-networks/"&gt;..more&lt;/a&gt;.&lt;br /&gt;&lt;/p&gt;&lt;p style="font-style: italic;" class="MsoNormal"&gt;Today (1/26) &lt;a href="http://safaribooksonline.com/"&gt;Safari Books Online&lt;/a&gt; has followed through on their promise to make &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_39"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_34"&gt;Langner's&lt;/span&gt;&lt;/span&gt; book available to members at my request in 2011- oh yeah!&lt;br /&gt;&lt;/p&gt;&lt;p style="font-weight: bold;" class="MsoNormal"&gt;More:&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Specific &lt;a href="http://en.wikipedia.org/wiki/Operations_security"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_40"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_35"&gt;OPSEC&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; lapses may have helped also helped &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_41"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_36"&gt;Stuxnet&lt;/span&gt;&lt;/span&gt; creators:  &lt;a href="http://www.langner.com/en/2011/12/11/an-accurate-ir-1-cascade-model/"&gt;An accurate IR-1 cascade model – &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_42"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_37"&gt;langner&lt;/span&gt;&lt;/span&gt;.com &lt;/a&gt; 12/11/11 &amp;amp;  &lt;a href="http://www.langner.com/en/2011/12/07/the-prez-shows-his-cascade-shape/"&gt;The &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_43"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_38"&gt;Prez&lt;/span&gt;&lt;/span&gt; shows his cascade shape  - &lt;span style="font-size:100%;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_44"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_39"&gt;langner&lt;/span&gt;&lt;/span&gt;.com&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:100%;"&gt;  12/07/11    /    More:    &lt;/span&gt;&lt;span style=";font-family:&amp;quot;;font-size:100%;"  &gt;&lt;a href="http://www.ted.com/talks/lang/eng/ralph_langner_cracking_stuxnet_a_21st_century_cyberweapon.html"&gt;TED talk &lt;/a&gt; (10m)  3/11&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.csmonitor.com/USA/2011/0922/From-the-man-who-discovered-Stuxnet-dire-warnings-one-year-later"&gt;From the man who discovered Stuxnet, dire warnings one year later&lt;/a&gt; - &lt;i&gt;&lt;a href="http://www.csmonitor.com/tags/topic/The+Christian+Science+Monitor" target="_self" class="inform_link"&gt;CSMonitor.com&lt;/a&gt; &lt;/i&gt;  9/22/2011&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-4503339286932780430?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/4503339286932780430/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=4503339286932780430' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/4503339286932780430'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/4503339286932780430'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2012/01/project-basecamp-2012-hit-are-we-ripe.html' title='Project Basecamp 2012 a Hit...  Are We Really Ripe for More Attacks Like Stuxnet?&lt;br&gt;&lt;i&gt;-Researcher Ralph Langner says &quot;Yes&quot; at NATO Keynote.&lt;/i&gt;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-_PiyEzLq6QQ/TyI3uF63OMI/AAAAAAAAACY/j1D410PLFZ0/s72-c/RalphLangnerNATO2011.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-2853361358454259050</id><published>2012-01-12T22:39:00.034-06:00</published><updated>2012-01-19T23:34:53.811-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Singularity Kurzweil'/><title type='text'>Welcome 2012:  Leaping Into The Future With A Singularity Primer-"On track"  per Ray Kurzweil as he answers the latest critics.</title><content type='html'>&lt;a href="http://nhne-pulse.org/wp-content/uploads/2011/06/singularity-summit-2011.jpg"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 288px; height: 288px;" src="http://nhne-pulse.org/wp-content/uploads/2011/06/singularity-summit-2011.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;The future is something I've always enjoyed focused, insightful perspective around and seems like a good topic to get my blogging &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;mojo&lt;/span&gt; back in gear for 2012.&lt;br /&gt;&lt;br /&gt;As I've touched on in a decade-plus forward look &lt;a style="color: rgb(51, 51, 255);" href="http://thisweekinsecurity.blogspot.com/2010/01/security-issues-into-next-decade-leap.html"&gt;2010 posting&lt;/a&gt;,  &lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:black;"  &gt;Ray &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;Kurzweil&lt;/span&gt;’s  “&lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.amazon.com/gp/product/0143037889?ie=UTF8&amp;amp;tag=thiweeinsec-20&amp;amp;linkCode=as2&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=0143037889"&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;" &gt;Singularity is Near: When Humans Transcend Biology&lt;/span&gt;&lt;/a&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-family:&amp;quot;;color:black;"  &gt;” 2005 book (672p) provides a science derived, profound view of how &lt;i&gt;exponentially &lt;/i&gt;accelerating IT is driving ever increasing broader advancements.  A very well executed, cited work in my opinion, with anticipated continuing advancements resulting in very dramatic changes affecting humanity over the next several decades (2020s genetics, 2030s, &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;nanotech&lt;/span&gt;, followed by an intelligence take off, already in progress – i.e. &lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://en.wikipedia.org/wiki/Technological_singularity"&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;font-family:&amp;quot;;" &gt;technological singularity&lt;/span&gt;&lt;/a&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:black;"  &gt;).  One does not have to agree with all the points and conclusions raised in order to appreciate and gain much. &lt;i&gt;This work was also released in 2011 as an &lt;/i&gt;&lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.audible.com/pd/ref=sr_1_1?asin=B004Z48FYU&amp;amp;qid=1325016174&amp;amp;sr=1-1"&gt;&lt;i&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;font-family:&amp;quot;;" &gt;Audible &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;audiobook&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;i&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:#1F497D;"  &gt;  &lt;/span&gt;&lt;/i&gt;&lt;i&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:black;"  &gt;(unabridged, 25 hours).&lt;/span&gt;&lt;/i&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:black;"  &gt;    &lt;/span&gt;&lt;/span&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:enableopentypekerning/&gt;    &lt;w:dontflipmirrorindents/&gt;    &lt;w:overridetablestylehps/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-priority:99;  mso-style-parent:"";  mso-padding-alt:0in 5.4pt 0in 5.4pt;  mso-para-margin:0in;  mso-para-margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:10.0pt;  font-family:"Times New Roman","serif";} &lt;/style&gt; &lt;![endif]--&gt;  &lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;&lt;b&gt;&lt;u&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;" &gt;Singularity Primer 2012&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;" &gt;:&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:black;"  &gt;Video: &lt;/span&gt;&lt;/b&gt;&lt;a href="http://online.wsj.com/video/kurzweil-a-future-of-humans-merged-with-machines/3966A6F7-F89D-457B-8880-701319EBA11B.html"&gt;&lt;span style="color: rgb(51, 51, 255);font-family:&amp;quot;;color:#0000CC;"  &gt;Futurist Ray&lt;/span&gt;&lt;span style="color: rgb(51, 51, 255);font-family:&amp;quot;;color:#1F497D;"  &gt; Kurzweil &lt;/span&gt;&lt;span style="color: rgb(51, 51, 255);font-family:&amp;quot;;color:#0000CC;"  &gt;Says Mankind Will One Day Live Forever&lt;/span&gt;&lt;span style="color: rgb(51, 51, 255);font-family:&amp;quot;;color:#1F497D;"  &gt;, &lt;/span&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-family:&amp;quot;;color:#0000CC;"  &gt;&lt;span style="color: rgb(51, 51, 255);"&gt;WSJ June20&lt;/span&gt;1&lt;/span&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-family:&amp;quot;;color:#1F497D;"  &gt;1 (10m)&lt;/span&gt;&lt;/a&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-family:&amp;quot;;color:#0000CC;"  &gt; &lt;/span&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-family:&amp;quot;;color:#1F497D;"  &gt; &lt;/span&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-family:&amp;quot;;color:black;"  &gt;Quick overview.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:black;"  &gt;Video: &lt;/span&gt;&lt;/b&gt;&lt;a href="http://www.zentation.com/viewer/index.php?passcode=rJukJRYuFz"&gt;&lt;span style="color: rgb(51, 51, 255);font-family:&amp;quot;;color:#0000CC;"  &gt;The Impact of Accelerating IT on War and Peace- Army 26&lt;sup&gt;th&lt;/sup&gt; Science Conference- Kurzweil Dec 2008&lt;/span&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-family:&amp;quot;;color:#1F497D;"  &gt;&lt;span style="color: rgb(51, 51, 255);"&gt;)  (55m&lt;/span&gt;)&lt;/span&gt;&lt;/a&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-family:&amp;quot;;color:black;"  &gt;  and supporting &lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://dl.dropbox.com/u/1712646/KAIN12108-26th_Army_Science_Conference.pdf"&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;" &gt;slides&lt;/span&gt;&lt;/a&gt;&lt;span style="color: rgb(51, 51, 255);font-family:&amp;quot;;color:#0000CC;"  &gt; &lt;/span&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:black;"  &gt;help explain his views&lt;/span&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:#1F497D;"  &gt;. &lt;/span&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:black;"  &gt;The talk was much broader than “War and Peace” and centered more around the implications for humanity in the not so distant future from continuing IT driven advancements.   &lt;/span&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:#1F497D;"  &gt; &lt;/span&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:black;"  &gt;I found this a compelling update on his&lt;/span&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:#1F497D;"  &gt; &lt;/span&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:black;"  &gt;fascinating views-  even if not all goes as predicted.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:black;"  &gt;Video:  &lt;/span&gt;&lt;/b&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.youtube.com/watch?v=WPqjYrLhDnk&amp;amp;list=UU1zny_jKmgnEbQitfPgAlxg&amp;amp;index=2&amp;amp;feature=plcp"&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;font-family:&amp;quot;;" &gt;Ray Kurzweil on "From Eliza to Watson to Passing the Turing Test" at Singularity Summit 2011 (65m)&lt;/span&gt;&lt;/a&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:#1F497D;"  &gt;&lt;span style="color: rgb(51, 51, 255);"&gt; &lt;/span&gt; &lt;/span&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:black;"  &gt;Ray Kurzweil kicked off the 2011 &lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.singularitysummit.com/"&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;" &gt;Singularity Summit&lt;/span&gt;&lt;/a&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:black;"  &gt;  with some specific updates in his projections and responses to the skeptics, e.g. Paul Allan’s recent essay &lt;span style="color: rgb(51, 51, 255);"&gt;(&lt;/span&gt;&lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.technologyreview.com/blog/guest/27263/"&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;" &gt;article&lt;/span&gt;&lt;/a&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:black;"  &gt;&lt;span style="color: rgb(51, 51, 255);"&gt;)&lt;/span&gt;.&lt;b&gt; &lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;&lt;b&gt;&lt;u&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;" &gt;Mor&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;" &gt;e:&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;&lt;span style=";font-family:&amp;quot;;color:black;"  &gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:black;"  &gt;Seminar Podcast:&lt;/span&gt;&lt;/b&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:black;"  &gt;  &lt;/span&gt;&lt;a href="http://longnow.org/seminars/02005/sep/23/kurzweils-law/"&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:#0000CC;"  &gt;“Kurzweil's Law”-  Ray Kurzweil (106m)&lt;/span&gt;&lt;/a&gt;&lt;span style=";font-family:&amp;quot;;" &gt; &lt;span style="color:black;"&gt;-  The Long Now Foundation&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;font-family:&amp;quot;;" &gt;&lt;span style="color:black;"&gt; -  &lt;/span&gt;&lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://download.fora.tv/rss_media/Long_Now_Podcasts/podcast-2005-09-23-kurzweil.mp3"&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;font-family:&amp;quot;;" &gt;audio download&lt;/span&gt;&lt;/a&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:black;"  &gt;  is free&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:black;"  &gt;Video/Article:&lt;/span&gt;&lt;/b&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:black;"  &gt;  “&lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://singularityhub.com/2011/05/03/kurzweil-3-supplements-to-let-you-live-until-the-singularity-video/"&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;font-family:&amp;quot;;" &gt;Kurzweil: 3 Supplements To Let You Live Until The Singularity (1m)&lt;/span&gt;&lt;/a&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-family:&amp;quot;;color:#1F497D;"  &gt;”&lt;/span&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-family:&amp;quot;;color:black;"  &gt; &lt;/span&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:#1F497D;"  &gt; &lt;span style="color: rgb(0, 0, 0);"&gt;May 2011 &lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);font-family:&amp;quot;;color:black;"  &gt; &lt;/span&gt;&lt;br /&gt;- Coenzyme Q10&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:black;"  &gt;&lt;br /&gt;- Phosphatidylcholine (&lt;/span&gt;&lt;span class="st1"&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;mso-ansi-language:ENfont-family:&amp;quot;;color:#222222;" lang="EN"  &gt;derived from lecithin&lt;/span&gt;&lt;/span&gt;)&lt;span style="font-size:100%;"&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:black;"  &gt;&lt;br /&gt;- Vitamin D (perhaps the most critical of the three)&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-family:&amp;quot;;color:black;"  &gt;Movie:  &lt;/span&gt;&lt;/b&gt;&lt;a href="http://movies.netflix.com/Movie/Transcendent-Man/70117003"&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;font-family:&amp;quot;;color:#0000CC;"  &gt;Transcendent Man (2009)- Netflix Instant Play&lt;/span&gt;&lt;/a&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-family:&amp;quot;;color:#0000CC;"  &gt; &lt;/span&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-family:&amp;quot;;color:#1F497D;"  &gt; &lt;/span&gt;&lt;i&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-family:&amp;quot;;color:black;"  &gt;Inventor and futurist Ray Kurzweil is the subject of this documentary that follows him on a world speaking tour in which he expounds on his ideas about the merging of man and machine, which he predicts will occur in the not-so-distant future. The visionary who invented the first text-to-speech synthesizer and much more raises eyebrows here with his wildly optimistic views of a technology-enhanced future.   &lt;/span&gt;&lt;/i&gt;I give it B- rating.. but worth seeing once for most. &lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;The Singularity is something that may utimately be an overwelming primary factor in shaping our future- very interesting indeed!  &lt;/span&gt;      &lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:enableopentypekerning/&gt;    &lt;w:dontflipmirrorindents/&gt;    &lt;w:overridetablestylehps/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-priority:99;  mso-style-parent:"";  mso-padding-alt:0in 5.4pt 0in 5.4pt;  mso-para-margin:0in;  mso-para-margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:10.0pt;  font-family:"Times New Roman","serif";} &lt;/style&gt; &lt;![endif]--&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-2853361358454259050?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/2853361358454259050/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=2853361358454259050' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/2853361358454259050'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/2853361358454259050'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2012/01/welcome-2012-taking-look-into-future.html' title='Welcome 2012:  Leaping Into The Future With A Singularity Primer&lt;br&gt;&lt;i&gt;-&quot;On track&quot;  per Ray Kurzweil as he answers the latest critics.&lt;/i&gt;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-8772881368379803847</id><published>2011-11-19T22:30:00.059-06:00</published><updated>2012-01-05T23:01:39.914-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SCADA Cybersecurity attack water utility DHS'/><title type='text'>False Alarm? Russia Cyber Attack on Water System SCADA Reported-Cybersecurity back in limelight, asserting more intrusion(s)</title><content type='html'>&lt;div&gt;&lt;div&gt;&lt;span class="Apple-style-span"   style="font-family:arial;font-size:100%;"&gt;&lt;b&gt;&lt;span style="color: rgb(51, 51, 255); text-decoration: underline;" class="Apple-style-span"&gt;1&lt;/span&gt;&lt;span class="Apple-style-span"&gt;&lt;span style="color: rgb(51, 51, 255); text-decoration: underline;"&gt;1/23/2011 Update - A  False Alarm?&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span class="Apple-style-span"   style="font-family:arial;font-size:100%;"&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"   style="font-family:arial;font-size:100%;"&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;*&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span class="Apple-style-span"   style="font-family:arial;font-size:100%;"&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;** ANSWER:  Yes ***  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;b   style="font-family:arial;font-size:100%;"&gt;&lt;span class="Apple-style-span"&gt;&lt;span style="color: rgb(51, 51, 255); text-decoration: underline;"&gt;&lt;em&gt;&lt;br /&gt;For the initial Nov14th report per DHS- with more "pr0f" (proof) hackery being demonstrated and investigated !&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="text-decoration: underline;font-family:arial;font-size:100%;"  &gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:arial;font-size:100%;"&gt;As the week of Nov 14&lt;/span&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"   style="font-family:arial;font-size:100%;"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;th&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:arial;font-size:100%;"&gt; closed, a reportedly "confirmed" water system intrusion discovered after equipment damage prompted a sensitive fusion center advisory, quickly followed by more public coverage:&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span"   style="font-family:arial;font-size:100%;"&gt;&lt;br /&gt;- Issue discovered Nov 8&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;th&lt;/span&gt;&lt;/span&gt; after pump burned up due to power cycling.&lt;br /&gt;- Believed credentials used stemmed from supplier/vendor breach (e.g. perhaps via &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;phishing&lt;/span&gt;&lt;/span&gt;)&lt;br /&gt;&lt;span&gt;- &lt;/span&gt;&lt;span&gt;May have been compromised for months with ongoing "instability glitches" dismissed &lt;/span&gt;&lt;br /&gt;- Involved access from Russian Internet addresses.&lt;br /&gt;&lt;br /&gt;A Nov 10&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;th&lt;/span&gt;&lt;/span&gt; Illinois fusion center report serving as initial notice regarding this matter was obtained by &lt;a href="http://news.cnet.com/8301-27080_3-20004505-245.html"&gt;Joe Weiss,  crusader f&lt;/a&gt;&lt;a href="http://news.cnet.com/8301-27080_3-20004505-245.html"&gt;or critical infrastructure security&lt;/a&gt;, who then broke the story  providing some particulars to major media.   A statement released by &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;DHS&lt;/span&gt;&lt;/span&gt; spokesman Peter &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;Boogaard&lt;/span&gt;&lt;/span&gt;  downplayed the matter “At this time there is no  credible corroborated data that indicates a risk to critical infrastructure  entities or a threat to public safety.”&lt;/span&gt;&lt;div  style="font-family:arial;"&gt;&lt;span class="Apple-style-span"  style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div  style="font-family:arial;"&gt;&lt;div style="color: rgb(51, 51, 255);"&gt;&lt;span class="Apple-style-span"  style="font-size:100%;"&gt;&lt;b&gt;&lt;u&gt;11/23/2011 Update&lt;/u&gt; &lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: rgb(51, 51, 255);"&gt;&lt;span class="Apple-style-span"  style="font-size:100%;"&gt;Illinois intelligence fusion center reported Tuesday 11/22 that earlier reports of a water utility hacked cannot be substantiated, according to a &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;DHS&lt;/span&gt;&lt;/span&gt; announcement.   Joe Weiss's quote to Wired.com - &lt;i&gt;“This smells to high holy heaven, because when you look at the Illinois report,  nowhere was the word preliminary ever used,” Weiss said, noting that  the fusion center — which is composed of Illinois state police, as well as  representatives from the FBI and &lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;DHS&lt;/span&gt;&lt;/span&gt; — distributed the report to other critical  infrastructure facilities in that state. “It was just laying out facts. How do  the facts all of a sudden all fall apart?”&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div  style="font-family:arial;"&gt;&lt;span class="Apple-style-span"  style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;/div&gt;&lt;div  style="font-family:arial;"&gt;&lt;span class="Apple-style-span"  style="font-size:100%;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://i41.tinypic.com/ip0aa0.png"&gt;&lt;/a&gt;Following the initial DHS statement, a &lt;a href="http://pastebin.com/Wx90LLum"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;PGP&lt;/span&gt;&lt;/span&gt; signed posting by "&lt;span style="font-weight: bold;"&gt;pr0f&lt;/span&gt;"&lt;/a&gt; asserted evidence of &lt;a href="http://1.bp.blogspot.com/-kb0owgf2jwA/TvvdqxBoEgI/AAAAAAAAACM/M6f5mt_NbmE/s1600/Screen_shot_2011-11-18-Houston.png"&gt;&lt;img style="margin: 0px 0px 10px 10px; width: 320px; height: 218px; float: right; cursor: pointer;" id="BLOGGER_PHOTO_ID_5691386280897155586" border="0" alt="" src="http://1.bp.blogspot.com/-kb0owgf2jwA/TvvdqxBoEgI/AAAAAAAAACM/M6f5mt_NbmE/s320/Screen_shot_2011-11-18-Houston.png" /&gt;&lt;/a&gt;gaining unauthorized access a second water treatment facility &lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;SCADA&lt;/span&gt;&lt;/span&gt; with five screen shots and statement, excerpt: &lt;span style="font-style: italic;"&gt; "I dislike, immensely, how the &lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;DHS&lt;/span&gt;&lt;/span&gt; tend to downplay h&lt;/span&gt;&lt;span style="font-style: italic;"&gt;ow absolutely F*****D the state of national infrastructure is....I've also seen various people doubt the possibility an attack like this could be done. So, &lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;y'know&lt;/span&gt;&lt;/span&gt;. The city of South&lt;/span&gt;&lt;span style="font-style: italic;"&gt; Houston has a really insecure system. Wanna see? I know ya do... "&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span&gt;&lt;br /&gt;&lt;div style="color: rgb(51, 51, 255); font-weight: normal;"&gt;&lt;span class="Apple-style-span"&gt;&lt;b&gt;&lt;u&gt;11/23/2011 Update&lt;/u&gt; &lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div  style="font-family:arial;"&gt;&lt;span class="Apple-style-span"&gt;&lt;span style="color: rgb(51, 51, 255);" class="Apple-style-span"&gt;&lt;span id="SPELLING_ERROR_12" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_12" class="blsp-spelling-error"&gt;Sophos's&lt;/span&gt;&lt;/span&gt; Chester &lt;span id="SPELLING_ERROR_13" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_13" class="blsp-spelling-error"&gt;Wisniewski&lt;/span&gt;&lt;/span&gt; was contacted by the hacker "pr0f" regarding the South Houston, Texas intrusion.    The hacker gained access through several methods (&lt;a href="http://en.wikipedia.org/wiki/Virtual_Network_Computing"&gt;&lt;span id="SPELLING_ERROR_14" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_14" class="blsp-spelling-error"&gt;VNC&lt;/span&gt;&lt;/span&gt; &lt;span id="SPELLING_ERROR_15" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_15" class="blsp-spelling-corrected"&gt;variant&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;, web &lt;span id="SPELLING_ERROR_16" class="blsp-spelling-corrected"&gt;portal&lt;/span&gt;) claiming he still has access.    He also commented "&lt;i&gt;Don't worry, I use my powers for good and such.&lt;/i&gt;"    And also pointed out, &lt;i&gt;"..  I am under no illusions about my level of skill. These are the least secure systems. .. &lt;/i&gt;&lt;/span&gt;&lt;span style="color: rgb(51, 51, 255); background-color: rgb(255, 255, 255);" class="Apple-style-span"&gt;&lt;i&gt;&lt;span class="Apple-style-span"&gt;I was furious at the lack of proper government response. The response they gave was nothing more than 'Nothing happened. Probably.' When clearly something did happen."&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;What should utilities do?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Mr. Weiss provided some constructive broader recommendations in his post "&lt;a href="http://community.controlglobal.com/content/water-system-hack-system-broken"&gt;Water System Hack - The System is Broken&lt;/a&gt;"   Here are some specific suggestions for near term critical infrastructure &lt;span id="SPELLING_ERROR_17" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_16" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt; risk mitigation, especially for industrial control system (&lt;span id="SPELLING_ERROR_18" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_17" class="blsp-spelling-error"&gt;ICS&lt;/span&gt;&lt;/span&gt;) settings where &lt;span id="SPELLING_ERROR_19" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_18" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt; security may be lapsing, not addressed in a robust manner:&lt;br /&gt;&lt;/span&gt;&lt;ol&gt;&lt;li&gt;  &lt;span class="Apple-style-span"&gt;&lt;span style="font-weight: bold;"&gt;Identify all &lt;span id="SPELLING_ERROR_20" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_19" class="blsp-spelling-error"&gt;ICS&lt;/span&gt;&lt;/span&gt; systems and their organizational management owners.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"&gt;&lt;span style="font-weight: bold;"&gt;Audit key baseline IT security controls, identify any serious remote and local access issues&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;- e.g. protected perimeter, all accounts have defined need, management approval/review, access activity logging for review, antivirus where feasible, patching.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"&gt;&lt;span style="font-weight: bold;"&gt;Consider how to assert stronger positive owner access control, especially for remote access&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;i&gt;-e.g. remote access normally disabled when not needed, logging all access events, &lt;span id="SPELLING_ERROR_21" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_20" class="blsp-spelling-error"&gt;multifactor&lt;/span&gt;&lt;/span&gt; token required/kept in house for vendor call in, protected jump box use instead of opening full throat network paths, segmentation when multiple vendor solutions are involved.&lt;/i&gt;&lt;br /&gt;&lt;i style="color: rgb(51, 51, 255);"&gt;&lt;span style="font-weight: bold;"&gt;Note:&lt;/span&gt;  A good place to start is closely studying &lt;span style="font-weight: bold;" id="SPELLING_ERROR_22" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_21" class="blsp-spelling-error"&gt;NERC's&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt; July 2011 "&lt;/span&gt;&lt;a style="font-weight: bold;" href="http://www.nerc.com/fileUploads/File/Events%20Analysis/FINAL-Guidance_for_Secure_Interactive_Remote_Access.pdf"&gt;Guidance for Secure Interactive Remote Access&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;" &lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"&gt;&lt;span style="font-weight: bold;"&gt;Implemented initial improvement options based on risk informed priority.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;- proceed based on management engaged approval/direction, document and implement, monitor and report progress.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"&gt;&lt;span style="font-weight: bold;"&gt;Pursue ongoing, broader &lt;span id="SPELLING_ERROR_23" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_22" class="blsp-spelling-error"&gt;ICS&lt;/span&gt;&lt;/span&gt; security improvements &lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;- after getting basic IT-centric hardening measures in place, tools such as &lt;/span&gt;&lt;a style="font-style: italic; font-weight: bold;" href="http://www.us-cert.gov/control_systems/satool.html"&gt;&lt;span id="SPELLING_ERROR_24" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_23" class="blsp-spelling-error"&gt;DHS's&lt;/span&gt;&lt;/span&gt; &lt;span id="SPELLING_ERROR_25" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_24" class="blsp-spelling-error"&gt;CSET&lt;/span&gt;&lt;/span&gt; (&lt;span id="SPELLING_ERROR_26" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_25" class="blsp-spelling-error"&gt;Cyber&lt;/span&gt;&lt;/span&gt; Security Evaluation Tool) - free for critical infrastructure organizations&lt;/a&gt;&lt;span style="font-style: italic;"&gt; are available to build better understanding of &lt;span id="SPELLING_ERROR_27" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_26" class="blsp-spelling-error"&gt;ICS&lt;/span&gt;&lt;/span&gt; security susceptibilities and consequences, measure risk, and identify, prioritize further security improvements. &lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;span class="Apple-style-span"  style="font-size:100%;"&gt;&lt;span&gt;Any such attack damaging a water utility's pump is more akin to amateur antics than part of any organized nation state effort in my opinion. Regardless, even if this turns out to be a false alarm for causing of equipment damage, many related "what ifs" will be asked by media and others.  We can expect various hats of hackers (white, grey, black) interest will also increase  (&lt;a href="http://www.digitalbond.com/2010/11/02/what-you-should-know-about-shodan-and-scada/"&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;&lt;span id="SPELLING_ERROR_28" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_27" class="blsp-spelling-error"&gt;SHODAN&lt;/span&gt;&lt;/span&gt; anyone?&lt;/span&gt;&lt;/a&gt;).  Industrial control systems, including &lt;span id="SPELLING_ERROR_29" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_28" class="blsp-spelling-error"&gt;SCADA&lt;/span&gt;&lt;/span&gt;, are widely used to support a number of critical infrastructure functions.   Secured communication paths and protected remote access must be ensured.  Organizations that have blindly entrusted their vendor to adequately address &lt;span id="SPELLING_ERROR_30" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_29" class="blsp-spelling-error"&gt;cybersecurity&lt;/span&gt;&lt;/span&gt; in an increasing risk environment need to do more.   People, process, technology requirements addressing security in such settings must be understood, documented, supported (with enforcement), and continue to be further developed.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;More/sources:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;-&lt;span class="Apple-style-span"&gt; &lt;a href="http://krebsonsecurity.com/2011/11/cyber-strike-on-city-water-system/#more-12401"&gt;&lt;span id="SPELLING_ERROR_31" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_30" class="blsp-spelling-error"&gt;Cyber&lt;/span&gt;&lt;/span&gt; Intrusion Blamed for Hardware Failure at Water Utility&lt;/a&gt;- &lt;span id="SPELLING_ERROR_32" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_31" class="blsp-spelling-error"&gt;KrebsonSecurity&lt;/span&gt;&lt;/span&gt; 11/18/2011&lt;br /&gt;- &lt;a href="http://www.wired.com/threatlevel/2011/11/hackers-destroy-water-pump/2"&gt;H(&lt;span id="SPELLING_ERROR_33" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_32" class="blsp-spelling-error"&gt;ackers&lt;/span&gt;&lt;/span&gt;)&lt;sub&gt;2&lt;/sub&gt;O: Attack on City Water Station Destroys Pump&lt;/a&gt;-  Wired.com 11/18/2011&lt;br /&gt;- &lt;a href="http://www.linkedin.com/share?viewLink=&amp;amp;sid=s710264200&amp;amp;url=http%3A%2F%2Ft%2Eco%2Fx4CIJsul&amp;amp;urlhash=ARvK&amp;amp;uid=5543737463152840704&amp;amp;trk=NUS_UNIU_SHARE-lnk"&gt;Second Water Utility Reportedly hit by hack attack &lt;/a&gt;-  The Register 11/18/2011&lt;br /&gt;&lt;span style="font-style: italic;"&gt;      -proof of concept Intrusion&lt;/span&gt;&lt;br /&gt;- &lt;a href="http://www.chron.com/news/houston-texas/article/Hacker-targets-South-Houston-sewer-system-2277795.php"&gt;Hacker targets South Houston Sewer System &lt;/a&gt;- The Houston Chronicle   11/19/2011&lt;/span&gt;&lt;br /&gt;- &lt;a href="http://www.digitalbond.com/2010/11/02/what-you-should-know-about-shodan-and-scada/"&gt;What You Should Know About &lt;span id="SPELLING_ERROR_34" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_33" class="blsp-spelling-error"&gt;SHODAN&lt;/span&gt;&lt;/span&gt; and &lt;span id="SPELLING_ERROR_35" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_34" class="blsp-spelling-error"&gt;SCADA&lt;/span&gt;&lt;/span&gt; &lt;/a&gt;- &lt;span id="SPELLING_ERROR_36" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_35" class="blsp-spelling-error"&gt;DigitalBond&lt;/span&gt;&lt;/span&gt;  11/2/2010&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: rgb(51, 51, 255);font-family:arial;" &gt;&lt;span class="Apple-style-span"  style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: rgb(51, 51, 255);"&gt;&lt;div&gt;&lt;span style="color: rgb(51, 51, 255);font-family:arial;font-size:100%;" class="Apple-style-span"  &gt;&lt;u&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;11/23/2011 Update - False Alarm&lt;/span&gt;?&lt;/b&gt;&lt;/u&gt;&lt;span style="text-decoration: underline;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;-  &lt;a href="http://www.wired.com/threatlevel/2011/11/scada-hack-report-wrong/"&gt;Confusion Center: Feds Now Say Hacker &lt;span id="SPELLING_ERROR_37" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_36" class="blsp-spelling-error"&gt;Didn&lt;/span&gt;&lt;/span&gt;’t Destroy Water Pump&lt;/a&gt; - Wired.com 11/22/2011&lt;br /&gt;-  &lt;a href="http://nakedsecurity.sophos.com/2011/11/22/interview-with-scada-hacker-pr0f-about-the-state-of-infrastructure-security/"&gt;Interview with &lt;span id="SPELLING_ERROR_38" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_37" class="blsp-spelling-error"&gt;SCADA&lt;/span&gt;&lt;/span&gt; hacker pr0f about the state of infrastructure security&lt;/a&gt; - &lt;span id="SPELLING_ERROR_39" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_38" class="blsp-spelling-error"&gt;NakedSecurity&lt;/span&gt;&lt;/span&gt;, &lt;span id="SPELLING_ERROR_40" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_39" class="blsp-spelling-error"&gt;Sophos&lt;/span&gt;&lt;/span&gt;.com 11/22/2011&lt;/span&gt;&lt;span style="color: rgb(51, 51, 255);font-family:arial;font-size:100%;"  &gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(51, 51, 255);font-family:arial;font-size:100%;"  &gt;- &lt;/span&gt;&lt;span style="color: rgb(51, 51, 255);font-family:arial;font-size:100%;"  &gt;&lt;a href="http://community.controlglobal.com/content/illinois-water-hack-test-system-disclosure-%E2%80%93-it-broken"&gt;The Illinois Water Hack Is a Test of the System for Disclosure – Is It Broken?&lt;/a&gt;&lt;/span&gt;&lt;span style="color: rgb(51, 51, 255);font-family:arial;font-size:100%;"  &gt; - Joe Weiss, Unfettered Blog&lt;/span&gt;&lt;span style="font-family:arial;font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-8772881368379803847?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/8772881368379803847/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=8772881368379803847' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/8772881368379803847'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/8772881368379803847'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2011/11/cyber-attack-from-russia-breaches-water.html' title='False Alarm? Russia Cyber Attack on Water System SCADA Reported&lt;br&gt;&lt;i&gt;-Cybersecurity back in limelight, asserting more intrusion(s)&lt;/i&gt;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-kb0owgf2jwA/TvvdqxBoEgI/AAAAAAAAACM/M6f5mt_NbmE/s72-c/Screen_shot_2011-11-18-Houston.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-6180216847402499620</id><published>2011-09-20T22:23:00.006-05:00</published><updated>2011-09-21T22:18:02.655-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cyberwar BlackHat Stuxnet Schneier 2011'/><title type='text'>EU BlackHat 2011:  Cyberwar Overhyped, Escalating Cyber Conflict  The Issue-  EU  Keynote counters Ex-CIA Official's Warning</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.blackhat.com/images/bh-eu-11/bh11eu_160x600.png"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 160px; height: 600px;" src="http://www.blackhat.com/images/bh-eu-11/bh11eu_160x600.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;While imminent Cyberwar concerns have ramped up as of late, e.g.,  &lt;a href="http://thisweekinsecurity.blogspot.com/2011/08/blackhat-2011-cyberwar-is-coming-ex-cia.html"&gt;BlackHat  2011: Cyberwar is Coming- Ex-CIA Official Warns Black Hat 2011  Attendees&lt;/a&gt;,   an insightful &lt;a href="http://www.youtube.com/watch?v=K-0dVbCaGZk"&gt;EU Black Hat 2011 - Keynote (video 1:15)&lt;/a&gt;  with &lt;a href="http://en.wikipedia.org/wiki/Bruce_Schneier"&gt;&lt;span style="font-style: italic;"&gt;Bruce Schneier&lt;/span&gt;&lt;/a&gt; offers constructive and useful perspective:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;   “It’s not that that we’re fighting cyberwar, we’re increasingly seeing war-like tactics used in broader cyber conflicts.  Non-nations can now deploy war-like tactics&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;...  &lt;/span&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;a bunch of criminals getting tanks.. now what do you do?"&lt;/span&gt;  - Bruce Schneier  EU BlackHat 2011&lt;br /&gt;&lt;br /&gt;Schneier points out that cyber war clearly is not happening now. Rhetoric surrounding cyberwar is exaggerated and harmful in its influence over policy.  The debate language lacks good definitions &lt;span style="font-style: italic;"&gt;- Don’t know when it starts, what it looks like, who is doing it, or when it’s over.   &lt;/span&gt;Using the term “war” implies we’re helpless, we need to duck and cover, the government should handle it.   Many measures merited in war time pose greater risk in peace time.  Advantage is on the attackers side in cyber space with technology pushing capabilities out&lt;span style="font-style: italic;"&gt;- so easy, kids can do it.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Further cyberwar high-level analysis commentary addresses topics such as preparing the battlefield, conducting attacks, etc.   All advanced nations will need to have some cyber offensive capability as it's part of the war fighting theater now.  It's also understood that the most advanced nations have extensive capabilities, e.g., placing logic bombs into enemy systems, potentially before broader conflicts starts.  Reoccurring examples of precursor cyber-attacks being followed by more traditional military conflicts.  US continues dragging feet on pursing international rules and treaties  involving cyber conflicts  given a perceived advantage.   This stance really feeds the cyber arms race problem where every side assumes the worse.    Related offensive decisions also need to be made at higher levels of government-   &lt;span style="font-style: italic;"&gt; &lt;a href="http://en.wikipedia.org/wiki/Stuxnet"&gt;Stuxnet&lt;/a&gt; types of attacks are reasonable to view as an act of war.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Critical Infrastructure concerns include widely believed examples of non-US criminal extortions, blackouts from hacking, e.g. Brazil.   History is rich with market failure examples where common defense not adequately addressed by private industry.  Private industry can only go so far and why we need government, with regulations only part of answer.    The US is clearly more vulnerable than other nations; with risk is increasing, it's  important to further address.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;More:&lt;/span&gt;&lt;br /&gt;-   60 minutes exposé  -  &lt;a href="http://www.cbsnews.com/video/watch/?id=6578069n&amp;amp;tag=segementExtraScroller;housing"&gt;Cyber War: Sabotaging the System  6/13/2010 (video 18:02)    &lt;/a&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;- “Next war might start with blackout, not a bang.”    “Art of the Poss&lt;/span&gt;ible”&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-6180216847402499620?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/6180216847402499620/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=6180216847402499620' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/6180216847402499620'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/6180216847402499620'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2011/09/blackhat-2011-eu-cyberwar-overhyped.html' title='EU BlackHat 2011:  Cyberwar Overhyped, Escalating Cyber Conflict  The Issue&lt;br&gt;&lt;i&gt;-  EU  Keynote counters Ex-CIA Official&apos;s Warning&lt;/i&gt;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-5819360828110680831</id><published>2011-09-06T20:48:00.023-05:00</published><updated>2011-09-06T22:13:26.315-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Black Hat'/><category scheme='http://www.blogger.com/atom/ns#' term='archive'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='Defcon'/><category scheme='http://www.blogger.com/atom/ns#' term='Top 10'/><title type='text'>BlackHat and Defcon 2011:  Top 10 Scariest Hacks-  Network World's take on a handful meriting the most concern</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-PZBr4esckSA/TmbeKqSCXQI/AAAAAAAAAB4/tsp020Zzw-0/s1600/Top10Scary.png"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 320px; height: 231px;" src="http://1.bp.blogspot.com/-PZBr4esckSA/TmbeKqSCXQI/AAAAAAAAAB4/tsp020Zzw-0/s320/Top10Scary.png" alt="" id="BLOGGER_PHOTO_ID_5649447057312865538" border="0" /&gt;&lt;/a&gt;Las Vegas hosted Black Hat USA 2011 and Defcon 2011 conferences dished up a number of interesting hacking demonstrations applicable for critical infrastructure organizations.   The wide ranging top ten identified by Network World (&lt;a href="http://www.networkworld.com/slideshows/2011/081011-blackhat-defcon-hacks.html#slide1"&gt;full slide show&lt;/a&gt;)  included   SCADA issues (Siemens, of course) and even a pretty significant ERP system issue (SAP).&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Summary:&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;a href="http://www.networkworld.com/slideshows/2011/081011-blackhat-defcon-hacks.html#slide2"&gt;&lt;span style="font-weight: bold;"&gt;Siemens S7 hack  (top one!)&lt;/span&gt;&lt;/a&gt;.   Very scary considering just how dependent real world facilities are to systems with related security problems, issues go well beyond being specific to Siemens solutions!&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;a href="http://www.networkworld.com/slideshows/2011/081011-blackhat-defcon-hacks.html#slide3"&gt;VoIP botnet control&lt;/a&gt;. &lt;/b&gt;Clever data ex-filtration, command and control methods using VoIP channel, touch tones phones.&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;a href="http://www.networkworld.com/slideshows/2011/081011-blackhat-defcon-hacks.html#slide4"&gt;Powerline device takeover&lt;/a&gt;.  &lt;/b&gt; Demonstrating a device that can tap into home power lines, monitor and control home alarm/security cameras, e.g.,  enable intruders to jam security gear then break in.  &lt;/li&gt;&lt;li&gt;&lt;a style="font-weight: bold;" href="http://www.networkworld.com/slideshows/2011/081011-blackhat-defcon-hacks.html#slide5"&gt;Hacker drone&lt;/a&gt;.   Off-the-shelf electronics used to create WASP (wireless aerial surveillance platform) executing flight plans while doing its work (crack codes, pick up cellphone calls, etc).&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;a href="http://www.networkworld.com/slideshows/2011/081011-blackhat-defcon-hacks.html#slide6"&gt;Car hijack via phone networks&lt;/a&gt;.    &lt;/b&gt;Using text messages over phone links to hack a Subaru Outback car alarm, unlock doors, starting vehicle.  Similar to devices used in some critical infrastructure  settings, raising concerns about knocking out power grids and water supplies.&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;a href="http://www.networkworld.com/slideshows/2011/081011-blackhat-defcon-hacks.html#slide7"&gt;Hack faces to find Social Security numbers&lt;/a&gt;.    &lt;/b&gt;Acquiring a person's Social Security number using nothing more than social networking photo, face recognition software, and a deducing algorithm.. interesting!&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;a href="http://www.networkworld.com/slideshows/2011/081011-blackhat-defcon-hacks.html#slide8"&gt;Remotely shut down insulin pumps&lt;/a&gt;.   &lt;/b&gt;Exposing a very difficult to resolve wireless security problem- could be fatal in wrong circumstances.   The diabetic security researcher focused on issues with his own wireless pump..  "devices weren't designed with security in mind"&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;a href="http://www.networkworld.com/slideshows/2011/081011-blackhat-defcon-hacks.html#slide9"&gt;Embedded Web server menace&lt;/a&gt;.   &lt;/b&gt; Embedded web servers in photocopiers, printers may them easier to administer and be compromised, potentially pilfering produced documents.   Easy fingerprinting and attack approaches demonstrated.&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;a href="http://www.networkworld.com/slideshows/2011/081011-blackhat-defcon-hacks.html#slide10"&gt;Spreading false router tables&lt;/a&gt;.&lt;/b&gt;   Demonstrated OSPF (open shortest path first) routing protocol having weaknesses permitting attackers to install false table entries on uncompromised routers, potentially affecting data streams (sending info to remote attacker) or just crippling networks. &lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;a href="http://www.networkworld.com/slideshows/2011/081011-blackhat-defcon-hacks.html#slide11"&gt;SAP flaw- Authentication&lt;/a&gt;. &lt;/b&gt;   Showed how SAP system can be broken into, gaining administrative privileges.   The researcher determined that half the systems examined were vulnerable to this issue.   Easy to locate target systems with Google search.  SAP is working towards releasing a related security update.&lt;/li&gt;&lt;/ol&gt;&lt;span style="font-weight: bold;"&gt;More:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;-  &lt;/span&gt;&lt;a class="l" href="http://www.blogger.com/url?url=http://www.theregister.co.uk/2011/08/19/insulin_pump_hack/&amp;amp;rct=j&amp;amp;sa=X&amp;amp;ei=b91mTt_2F46tgQfEtOjNDA&amp;amp;sqi=2&amp;amp;ved=0CDIQ-AsoATAA&amp;amp;q=accountability+insulin+office+c&amp;amp;usg=AFQjCNGiLVjwaj_Ya-kmhWKbG7ZrnJolzw"&gt;&lt;em style="font-style: italic;"&gt;&lt;/em&gt;Insulin pump attack prompts call for federal probe&lt;/a&gt;‎ -  &lt;span class="f xsm"&gt;Register&lt;/span&gt; 8/19/2011- &lt;span style="font-style: italic;"&gt;Committee urges investigation into security standards for wireless medical devices.&lt;/span&gt;&lt;br /&gt;- &lt;a href="https://www.blackhat.com/html/bh-us-11/bh-us-11-archives.html"&gt;Black Hat 2011 USA Archive&lt;/a&gt; video, audio, slides added since Aug 2011 conference&lt;br /&gt;- &lt;a href="https://www.defcon.org/html/links/dc-archives/dc-19-archive.html"&gt;DEF CON 19 Archive &lt;/a&gt; - site stood up 9/5 w/slides, etc from Aug 2011 conference&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-5819360828110680831?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/5819360828110680831/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=5819360828110680831' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/5819360828110680831'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/5819360828110680831'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2011/09/blackhat-and-defcon-2011-top-10.html' title='BlackHat and Defcon 2011:  Top 10 Scariest Hacks&lt;br&gt;&lt;i&gt;-  Network World&apos;s take on a handful meriting the most concern&lt;/i&gt;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-PZBr4esckSA/TmbeKqSCXQI/AAAAAAAAAB4/tsp020Zzw-0/s72-c/Top10Scary.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-4792122891073125447</id><published>2011-08-24T21:21:00.035-05:00</published><updated>2011-09-10T11:15:38.697-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cyberwar Cybersecurity BlackHat 2011 Stuxnet'/><title type='text'>BlackHat 2011:  Cyberwar is Coming-  Ex-CIA Official Warns Black Hat 2011 Attendees</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://www.blackhat.com/images/bh-us-11/bh11usa_300x600.png"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 300px; height: 600px;" src="https://www.blackhat.com/images/bh-us-11/bh11usa_300x600.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;font-family:verdana;font-size:100%;color:black;"   &gt;Former U.S. counter-terrorism official &lt;a href="http://en.wikipedia.org/wiki/Cofer_Black"&gt;Cofer Black&lt;/a&gt;, who warned of 9/11 terrorist attacks, raised the alarm earlier this month during his Black Hat 2011 keynote that cyberwar is an imminent threat.&lt;/span&gt;&lt;span style=" Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;font-size:100%;" &gt;&lt;span style="font-family:verdana;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Cyber warfare has been brought up as a significant concern by US intelligence, former officials for some time – even concerns of potential tampering with IT supply chains, etc. &lt;/span&gt;&lt;b style="font-family: verdana;"&gt;Most view US leading with others catching up in offensive capabilities.&lt;/b&gt;&lt;span style="font-family:verdana;"&gt; Turnabout is fair game. Besides the obvious appeal and resonance this official’s message has with the Black Hat community and media coverage, some related points that can be &lt;/span&gt;made: &lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;span style="font-family:verdana;font-size:100%;"&gt;  &lt;/span&gt;&lt;ul  type="disc" style="font-family:verdana;"&gt;&lt;li class="MsoNormal" style="mso-margin-top-alt:auto;margin-bottom:12.0pt;      mso-list:l0 level1 lfo1;tab-stops:list .5in"&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;&lt;span style="Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;mso-ansi-language:      EN" lang="EN"&gt;S&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;tuxnet      is the most significant example of a cyber attack against another nation      state’s critical infrastructure since the Russian gas pipeline explosion      in June 1982&lt;/span&gt;&lt;/b&gt;&lt;span style=";"&gt;.      &lt;i&gt;In the June 1982 attack, a CIA operation was launched that embedded a      Trojan horse in gas pipeline regulator software the CIA knew would be      stolen by the Russians. The Russians did indeed steal the software and      used it in a production gas line in Siberia. The Trojan horse corrupted the      gas pipeline regulation which resulted in a massive explosion, initially      thought to be nuclear, until later evidence showed this wasn’t the case.      The incident was classified, then later released and &lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;&lt;i&gt;infamously &lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;&lt;i&gt;documented in      the &lt;/i&gt;&lt;a href="http://www.nytimes.com/2004/02/02/opinion/02SAFI.html"&gt;&lt;i&gt;Farewell      Dossier&lt;/i&gt;&lt;/a&gt;&lt;i&gt;. T&lt;/i&gt;&lt;/span&gt;&lt;i&gt;&lt;span style="      Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;mso-ansi-language:EN" lang="EN"&gt;he KGB at the      time said the blast was accidental. (Source: &lt;/span&gt;&lt;/i&gt;&lt;span style="Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;&lt;a href="http://www.invincea.com/blog/tag/siemens-industrial-control-system/"&gt;&lt;i&gt;&lt;span style="mso-ansi-language:EN" lang="EN"&gt;Defending Against Stuxnet Type      Threats&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;/span&gt;&lt;i&gt;&lt;span style="      Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;mso-ansi-language:EN" lang="EN"&gt; – invincea      blog)&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="mso-margin-top-alt:auto;margin-bottom:12.0pt;      mso-list:l0 level1 lfo1;tab-stops:list .5in"&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;&lt;i&gt;&lt;span style="Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Government officials fear      that foreign powers could surreptitiously design something into a      component or printed circuit board that would end up in a piece of      equipment used by the government&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style="Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt; &lt;i&gt;"Maliciously      tampered ICs cannot be patched," retired General Wesley Clark said in      2009. "They are the ultimate sleeper cell."&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;      mso-list:l0 level1 lfo1;tab-stops:list .5in"&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;&lt;i&gt;&lt;span style="Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Many are very skeptical that      a huge US electronic 9/11 or Perl Harbor event is imminent – a view I      share.&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;i&gt;&lt;span style="Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;      &lt;/span&gt;&lt;/i&gt;&lt;span style="Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;All      advanced militaries have cyber­attack capabilities, including &lt;a href="http://en.wikipedia.org/wiki/Electromagnetic_pulse"&gt;EMP strike&lt;/a&gt;      options against information technology based systems. We can      expect significant nation state sponsored cyber incursions to continue,      often for information gathering purposes. This may not be a true “war” but      that doesn't mean we aren't losing.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;span style="font-family: verdana;font-family:arial;font-size:100%;"  &gt;More:&lt;/span&gt;&lt;ul  style="font-family: verdana;font-family:times new roman;"&gt;&lt;li  style="font-family:times new roman;"&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://www.informationweek.com/news/government/security/226900005"&gt;Ex-CIA Official Warns Black Hat Attendees of Coming Cyber-War - eWeek 8/4/2011&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li  style="font-family:times new roman;"&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://www.informationweek.com/news/government/security/226900005"&gt;&lt;span style=""&gt;Air Force To Tackle Supply Chain Security   -  InformationWeek 8/20/2010&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://www.usnews.com/opinion/articles/2010/03/29/to-protect-the-us-against-cyberwar-best-defense-is-a-good-offense"&gt;&lt;span style="Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;To Protect the U.S. Against Cyberwar, Best Defense Is a Good Offense,  US News- Guest Opinion 3/29/1010 &lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family:arial;font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: arial;font-family:&amp;quot;;font-size:130%;"  &gt; &lt;/span&gt;&lt;span style="color: rgb(0, 0, 0); font-family:arial;font-size:130%;"  &gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-4792122891073125447?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/4792122891073125447/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=4792122891073125447' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/4792122891073125447'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/4792122891073125447'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2011/08/blackhat-2011-cyberwar-is-coming-ex-cia.html' title='BlackHat 2011:  Cyberwar is Coming&lt;br&gt;&lt;i&gt;-  Ex-CIA Official Warns Black Hat 2011 Attendees&lt;/i&gt;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-1508358745544020934</id><published>2010-11-19T00:04:00.008-06:00</published><updated>2010-11-26T00:01:05.266-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Symantec Stuxnet Breakthrough Critical Infrastructure Iran Enrichment'/><title type='text'>Symantec's W32.Stuxnet Dossier- Breakthrough v1.3,  Nov 2010   Dutch Profibus expert provides crucial pieces to the puzzle</title><content type='html'>As of October, much had already been research and shared with critical infrastructure organizations around Stuxnet given the broader industrial control system,  DCS, SCADA implications.  As provided in the publicly available Symantec's research blog series and W32.Stuxnet Dossier white paper:&lt;br /&gt;&lt;span style=""&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;Stuxnet has been in play since at least 2009.&lt;/li&gt;&lt;li&gt;Specifically looks for Siemens PLC models S7-417 and S7-315-2, both widely deployed in the US.&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt; PLC infection only occurs when the PLC contains the&lt;/span&gt;&lt;span&gt;  &lt;/span&gt;&lt;span&gt;Profibus-DP communications processor&lt;/span&gt;&lt;/li&gt;&lt;li&gt;Windows 64-bit platforms not affected (32-bit targeted).&lt;span style=""&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;Malware package very sophisticated even with some sloppy controls (could’ve been more restricted and targeted, and stayed hidden longer).&lt;/li&gt;&lt;li&gt;The question of how to ensure the integrity of PLC code has not been addressed in detail&lt;span style=""&gt;.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;Stuxnet raises the bar, serves as a road map even if not viewed as easy to repurpose by talented security researchers and hackers studying it.   There has also been speculation that this type of malware may have been used to make several  Iranian petrochemical facilities dramatically "go bang" in 2009.&lt;br /&gt;&lt;br /&gt;On Nov 12th,   Eric Chien's posting &lt;a href="http://www.symantec.com/connect/blogs/stuxnet-breakthrough"&gt;Stuxnet:  A Breakthrough&lt;/a&gt; keyed in on important tips and insights provided by a Dutch Profibus expert that helps determine exactly the purpose for Stuxnet.    Symantec's updated &lt;a href="http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_stuxnet_dossier.pdf"&gt;W32.Stuxnet Dossier v1.3 Nov 2010&lt;/a&gt; white paper now more clearly describes how the malware targets and sabotages specific models of higher speed motor driving frequency converters over an extended time frame.&lt;br /&gt;&lt;br /&gt;This additional insight underscores the need to increasingly manage similar potential "Advanced Persistent Threat" risks to critical infrastructure.    Stuxnet's very clever payload is just one example of how similar hidden, targeted malware could pose a substantial threat to critical infrastructure even as this real world example has focused more on sabotaging systems akin to those used in uranium enrichment activities.&lt;br /&gt;&lt;br /&gt;More:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://www.wired.com/threatlevel/2010/11/stuxnet-clues/"&gt;Sneak Attack?  Clues Suggest Stuxnet Virus Was Built for Subtle Nuclear Sabotage - Wired 11/15/2010&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-priority:99;  mso-style-qformat:yes;  mso-style-parent:"";  mso-padding-alt:0in 5.4pt 0in 5.4pt;  mso-para-margin:0in;  mso-para-margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:10.0pt;  font-family:"Times New Roman","serif";} &lt;/style&gt; &lt;![endif]--&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;&lt;span style=";font-family:&amp;quot;;font-size:100%;"  &gt; &lt;a href="http://www.digitalbond.com/index.php/2010/08/19/we-will-never-be-perfect/"&gt;We will Never Be Perfect&lt;/a&gt;  and &lt;a href="http://www.digitalbond.com/index.php/2010/09/07/perfection-part-ii/"&gt;Perfection – Part II&lt;span style="font-weight: normal;"&gt;   &lt;/span&gt;&lt;/a&gt;&lt;b&gt;&lt;a href="http://www.digitalbond.com/index.php/2010/09/07/perfection-part-ii/"&gt;&lt;span style="font-weight: normal;"&gt;- &lt;/span&gt;&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;a href="http://www.digitalbond.com/index.php/2010/09/07/perfection-part-ii/"&gt;&lt;span style=";font-family:&amp;quot;;" &gt;Dale Peterson, Digital Bond&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style=";font-family:&amp;quot;;font-size:11pt;"  &gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;&lt;span style=";font-family:&amp;quot;;font-size:11pt;"  &gt; &lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.symantec.com/connect/symantec-blogs/sr"&gt;&lt;span style="font-size:100%;"&gt;Symantec Security Response&lt;/span&gt; Blog&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-1508358745544020934?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/1508358745544020934/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=1508358745544020934' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/1508358745544020934'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/1508358745544020934'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2010/11/symantecs-w32stuxnet-dossier.html' title='Symantec&apos;s W32.Stuxnet Dossier- Breakthrough v1.3,  Nov 2010 &lt;br&gt; &lt;i&gt; Dutch Profibus expert provides crucial pieces to the puzzle&lt;/i&gt;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-5981684245355872502</id><published>2010-07-04T15:38:00.041-05:00</published><updated>2010-07-10T00:19:58.773-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity Senate FISMA NERC CIP SANS Paller Lieberman'/><title type='text'>Senate Committee Unanimously Passes Major Cybersecurity Bill-  Risk mitigation shifting to continuous monitoring and dynamic response</title><content type='html'>On June 24&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;th&lt;/span&gt;&lt;/span&gt;, the Senate Homeland Security and Governmental Affairs Committee unanimously approved an amended 200 page version of a controversial &lt;a href="http://hsgac.senate.gov/public/index.cfm?FuseAction=Files.View&amp;amp;FileStore_id=4ee63497-ca5b-4a4b-9bba-04b7f4cb0123"&gt;The Protecting Cyberspace as a National Asset Act of 2010&lt;/a&gt; &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt; security bill which will move forward to the full Senate floor for consideration.&lt;br /&gt;&lt;br /&gt;SANS Director Alan &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;Paller&lt;/span&gt;&lt;/span&gt;’s related testimony (&lt;a href="http://hsgac.senate.gov/public/index.cfm?FuseAction=Files.View&amp;amp;FileStore_id=23084bec-f487-4e1c-ace9-90b7231660c2"&gt;written&lt;/a&gt; – 17 pages, and discussed) at the June 15&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;th&lt;/span&gt;&lt;/span&gt; Senate hearing: &lt;a href="http://hsgac.senate.gov/public/index.cfm?FuseAction=Hearings.Hearing&amp;amp;Hearing_ID=f56ace2f-7ac6-49ff-80e3-652371bb6fa6"&gt;Protecting Cyberspace as a National Asset: Comprehensive Legislation for the 21st Century&lt;/a&gt; (&lt;a href="http://www.senate.gov/fplayers/I2009/urlPlayer.cfm?fn=govtaff061510p&amp;amp;st=795&amp;amp;dur=8580"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;webcast&lt;/span&gt;&lt;/a&gt;) strongly emphasizes more effective risk management and less "&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;paperchasing&lt;/span&gt;" as&lt;/span&gt; currently demanded by &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;FISMA&lt;/span&gt;&lt;/span&gt; (with &lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;NIST&lt;/span&gt;&lt;/span&gt; standards and guidance mandatory). “When you demand that someone perform huge numbers of things, with limited budgets, you get dysfunctional results.”&lt;br /&gt;&lt;br /&gt;The committee's bill includes a number of key elements, many of particular interest to critical infrastructure organizations:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Creates an Office of Cyberspace Policy in the President's Executive Office to be ran by a Senate-confirmed Director. The Director will advise the President on all &lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;cybersecurity&lt;/span&gt;&lt;/span&gt; matters, harmonize federal efforts to secure cyberspace and will develop a national strategy that incorporates all elements of cyberspace policy, including military, law enforcement, intelligence, and diplomatic. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Creates a National Center for &lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;Cybersecurity&lt;/span&gt;&lt;/span&gt; and Communications (&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;NCCC&lt;/span&gt;&lt;/span&gt;) at the Department of Homeland Security (&lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;DHS&lt;/span&gt;&lt;/span&gt;) to be ran by the Director. This will elevate and strengthen the Department’s &lt;span id="SPELLING_ERROR_12" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_12" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt; security capabilities and authorities. The &lt;span id="SPELLING_ERROR_13" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_13" class="blsp-spelling-error"&gt;NCCC&lt;/span&gt;&lt;/span&gt; will include the United States Computer Emergency Response Team (US-CERT). &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Updates the Federal Information Security Management Act (&lt;span id="SPELLING_ERROR_14" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_14" class="blsp-spelling-error"&gt;FISMA&lt;/span&gt;&lt;/span&gt;) to modernize federal agencies practices of protecting their internal networks and systems. Reforms will allow agencies to &lt;strong&gt;move towards real-time monitoring to secure critical systems&lt;/strong&gt; (and away from the system of after-the-fact paperwork compliance). &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Requires the &lt;span id="SPELLING_ERROR_15" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_15" class="blsp-spelling-error"&gt;NCCC&lt;/span&gt;&lt;/span&gt; to work with the private sector to establish &lt;strong&gt;risk-based security requirements that strengthen &lt;span id="SPELLING_ERROR_16" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_16" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt; security for the nation’s most critical infrastructure&lt;/strong&gt; that, if disrupted, would result in a national or regional catastrophe. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Requires critical infrastructure to report significant breaches&lt;/strong&gt; to the &lt;span id="SPELLING_ERROR_17" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_17" class="blsp-spelling-error"&gt;NCCC&lt;/span&gt;&lt;/span&gt; to ensure the federal government has a complete picture of the security of these sensitive networks. The &lt;span id="SPELLING_ERROR_18" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_18" class="blsp-spelling-error"&gt;NCCC&lt;/span&gt;&lt;/span&gt; must share information, including threat analysis, with owners and operators regarding risks to their networks. The Act will provide &lt;strong&gt;specified liability protections to owners/operators that comply with the new risk-based security requirements&lt;/strong&gt;. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Creates a responsible framework, developed in coordination with the private sector, for the &lt;strong&gt;President to authorize emergency measures to protect the nation’s most critical infrastructure&lt;/strong&gt; if a &lt;span id="SPELLING_ERROR_19" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_19" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt; vulnerability is being exploited or is about to be exploited. The President must notify Congress in advance before exercising these emergency powers. Any emergency measures imposed must be the least disruptive necessary to respond to the threat and will expire after 30 days unless the President extends them. The bill authorizes no new surveillance authorities and does not authorize the government to “take over” private networks. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Develops a &lt;strong&gt;comprehensive supply chain risk management strategy to address risks and threats to information technology products and services&lt;/strong&gt; the federal government relies upon. This strategy will allow agencies to make informed decisions when purchasing IT products and services. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Requires the Office of Personnel Management to &lt;strong&gt;reform the way &lt;span id="SPELLING_ERROR_20" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_20" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt; security personnel are recruited, hired, and trained&lt;/strong&gt; to ensure that the federal government has the talent necessary to lead the national &lt;span id="SPELLING_ERROR_21" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_21" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt; security effort and protect its own networks. &lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;With respect to &lt;a href="http://www.nerc.com/page.php?cid=220"&gt;&lt;span id="SPELLING_ERROR_22" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_22" class="blsp-spelling-error"&gt;NERC&lt;/span&gt;&lt;/span&gt; Reliability Standards&lt;/a&gt;, including the &lt;span id="SPELLING_ERROR_23" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_23" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt; security focused &lt;span id="SPELLING_ERROR_24" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_24" class="blsp-spelling-error"&gt;CIPs&lt;/span&gt;&lt;/span&gt;, an extensive compliance &lt;span id="SPELLING_ERROR_25" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_25" class="blsp-spelling-error"&gt;paperchase&lt;/span&gt;&lt;/span&gt; remains underway in 2010 with both industry and regulatory bodies facing a substantial phase in of standards going through their first extensive audits. Much of the focus is based on the the language and &lt;span id="SPELLING_ERROR_26" class="blsp-spelling-error"&gt;intepretation&lt;/span&gt; of the Standards and associated &lt;a href="http://www.nerc.com/page.php?cid=3"&gt;Reliability Standard Audit Worksheets (&lt;span id="SPELLING_ERROR_27" class="blsp-spelling-error"&gt;RSAWS&lt;/span&gt;) &lt;em&gt;- visit Resources at link&lt;/em&gt;&lt;/a&gt;. Even if this bill would become law today, it could be years before related expectations and improvements are &lt;span id="SPELLING_ERROR_28" class="blsp-spelling-error"&gt;signficantly&lt;/span&gt; reflected in the Standards.&lt;br /&gt;&lt;br /&gt;More:&lt;br /&gt;&lt;br /&gt;- &lt;a href="http://hsgac.senate.gov/public/index.cfm?FuseAction=Press.MajorityNews&amp;amp;ContentRecord_id=227d9e1e-5056-8059-765f-2239d301fb7f"&gt;Lieberman, Collins, Carper Unveil Major &lt;span id="SPELLING_ERROR_26" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_29" class="blsp-spelling-error"&gt;Cybersecurity&lt;/span&gt;&lt;/span&gt; Bill to Modernize, Strengthen, and Coordinate &lt;span id="SPELLING_ERROR_27" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_30" class="blsp-spelling-error"&gt;Cyber&lt;/span&gt;&lt;/span&gt; Defenses (w/video ~10m)  6/10/2010&lt;/a&gt; &lt;br /&gt;- &lt;em&gt;Other recent hearings, such as before the House &lt;span id="SPELLING_ERROR_31" class="blsp-spelling-corrected"&gt;Appropriations&lt;/span&gt; Committee, also &lt;span id="SPELLING_ERROR_32" class="blsp-spelling-corrected"&gt;emphasizing&lt;/span&gt; key elements in the bill&lt;/em&gt;: &lt;a href="http://appropriations.house.gov/index.php?option=com_jcalpro&amp;amp;Itemid=117&amp;amp;extmode=view&amp;amp;extid=1934&amp;amp;date=2010-04-15&amp;amp;return_to=L2luZGV4LnBocD9vcHRpb249Y29tX2pjYWxwcm8mYW1wO0l0ZW1pZD0xMTcmYW1wO2V4dG1vZGU9ZmxhdCZhbXA7ZGF0ZT0yMDEwLTQtMQ=="&gt;&lt;span id="SPELLING_ERROR_33" class="blsp-spelling-error"&gt;DHS&lt;/span&gt; &lt;span id="SPELLING_ERROR_34" class="blsp-spelling-error"&gt;Cyber&lt;/span&gt; Security Programs – What progress has been made and what still needs to be improved? 4/15/2010&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-5981684245355872502?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/5981684245355872502/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=5981684245355872502' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/5981684245355872502'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/5981684245355872502'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2010/07/senate-committee-unanijmously-passes.html' title='Senate Committee Unanimously Passes Major Cybersecurity Bill&lt;br&gt;&lt;i&gt;-  Risk mitigation shifting to continuous monitoring and dynamic response&lt;/i&gt;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-8343692460925294718</id><published>2010-03-17T23:26:00.017-05:00</published><updated>2010-04-20T23:49:11.422-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='2010 SCADA and Process Control Summit APT Utilities Contested Territories NERC INL DHS CIP'/><title type='text'>Cybersecurity: Utilities are Contested Territories - Fact or Hype?</title><content type='html'>SANS Director Allan &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;Paller's&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; recent &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;EnergyBiz&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-corrected"&gt;opinion&lt;/span&gt; piece &lt;a href="http://www.nxtbook.com/nxtbooks/energycentral/energybiz0310/index.php?startid=47#/49/OnePage"&gt;&lt;strong&gt;Utilities are Contested Territories&lt;/strong&gt;&lt;/a&gt; presents illuminating facts driving &lt;a href="http://en.wikipedia.org/wiki/Advanced_Persistent_Threat"&gt;&lt;em&gt;Advanced Persistent Threat&lt;/em&gt; (APT)&lt;/a&gt; &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;cybersecurity&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; concerns in utility settings.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;The FBI reeled in 31 major utility &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-corrected"&gt;executives&lt;/span&gt; for some &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-corrected"&gt;forensic&lt;/span&gt;-grade calibration on how their systems have been unknowingly &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-corrected"&gt;compromised&lt;/span&gt; over extended &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-corrected"&gt;time frames&lt;/span&gt;.&lt;/li&gt;&lt;li&gt;The attacks, also affecting other areas of &lt;span id="SPELLING_ERROR_8" class="blsp-spelling-corrected"&gt;government&lt;/span&gt; and major businesses, are nation-state level in &lt;span id="SPELLING_ERROR_9" class="blsp-spelling-corrected"&gt;sophistication&lt;/span&gt; and persistence.&lt;/li&gt;&lt;li&gt;&lt;a href="http://itknowledgeexchange.techtarget.com/security-corner/what-is-weaponized-email/"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;Weaponized&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; email&lt;/a&gt; is the current preferred &lt;span id="SPELLING_ERROR_11" class="blsp-spelling-corrected"&gt;technique&lt;/span&gt; &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-corrected"&gt;facilitating&lt;/span&gt; ongoing waves of attacks.&lt;/li&gt;&lt;li&gt;Key defenses were determined &lt;span id="SPELLING_ERROR_12" class="blsp-spelling-corrected"&gt;insufficient&lt;/span&gt; to prevent, detect, deter, and recover from the attacks.&lt;/li&gt;&lt;/ul&gt;The article goes on to assert that more advanced utilities have learned to treat their environments as though they do not have complete control of their systems as an underlying assumption. Many of these organizations are stated to have an unprecedented level of additional defensive measures now deployed to help manage APT risks (extensive encryption, access controls, monitoring, etc).&lt;br /&gt;&lt;br /&gt;A preview, request-only SANS &lt;span id="SPELLING_ERROR_13" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;Webcast&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; delving into this topic is scheduled ahead of upcoming &lt;a href="http://www.sans.org/scada-security-summit-2010/event.php"&gt;&lt;strong&gt;2010 &lt;span id="SPELLING_ERROR_14" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;SCADA&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; and Process Control Summit (March 24th - April 1st)&lt;/strong&gt;&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color:#cc0000;"&gt;&lt;strong&gt;Hurry if you're interested in catching this free, one-time, by request only &lt;span id="SPELLING_ERROR_15" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;webcast&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;:&lt;/em&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.sans.org/scada-security-summit-2010/#webcast"&gt;&lt;strong&gt;Exclusive &lt;span id="SPELLING_ERROR_16" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;Webcast&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;: Digging Deeper Into The Advanced Persistent Threat March 19, 2010 1:30pm EDT&lt;/strong&gt;&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The Summit's optional workshops (provided by &lt;span id="SPELLING_ERROR_17" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;DHS&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;, &lt;span id="SPELLING_ERROR_18" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;INL&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;span id="SPELLING_ERROR_19" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;NERC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;) include a very interesting new full day offering: &lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;u&gt;&lt;a href="http://www.sans.org/scada-security-summit-2010/description.php?tid=4332"&gt;&lt;strong&gt;&lt;span id="SPELLING_ERROR_20" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_12" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_12" class="blsp-spelling-error"&gt;NERC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;span id="SPELLING_ERROR_21" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_13" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_13" class="blsp-spelling-error"&gt;Cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Risk Preparedness Assessment for the BPS Asset Owners and Operators&lt;br /&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/u&gt;This Summit workshop on April 1st should be of particular interest for utilities further developing &lt;span id="SPELLING_ERROR_22" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_14" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_14" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; security exercises. Will cover useful scenarios to learn from and apply&lt;br /&gt;&lt;em&gt;- “Each entity will be provided an exercise development kit” - &lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-8343692460925294718?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/8343692460925294718/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=8343692460925294718' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/8343692460925294718'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/8343692460925294718'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2010/03/cybersecurty-utilities-are-contested.html' title='Cybersecurity: Utilities are Contested Territories - Fact or Hype?'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-266307408211412452</id><published>2010-01-17T22:00:00.039-06:00</published><updated>2010-01-31T10:07:06.516-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cybersecurity NRC CFR 73.54 NERC CIP-002 regulatory'/><title type='text'>2010 Blasts in with Regulatory Cybersecurity Bar Raising-  NERC CIP-002-4 (Project 706 Ph II) and NRC RG 5.71- both with NIST Enhancements</title><content type='html'>&lt;span style="font-size:xx-small;color:#660000;"&gt;&lt;strong&gt;&lt;u&gt;Last updated 1/24/2010&lt;/u&gt;&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;As 2010 opens, beefed up regulatory scope and rigor around cybersecurity on both the &lt;strong&gt;Bulk Electric System (BES)&lt;/strong&gt; and commercial &lt;strong&gt;Nuclear Power Plant (NPP)&lt;/strong&gt; fronts are forming up&lt;em&gt;- even as expanding regulatory scrutiny has been focusing on assessing the status of current requirements and programs. &lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;Draft NERC CIP-002-4 Released&lt;/u&gt;. &lt;/strong&gt;Now in Phase II, &lt;a href="http://www.nerc.com/filez/standards/Project_2008-06_Cyber_Security.html"&gt;NERC Project 706&lt;/a&gt; (to address &lt;a href="http://www.ferc.gov/industries/electric/indus-act/reliability.asp"&gt;FERC Order 706-A&lt;/a&gt;), released &lt;em&gt;draft&lt;/em&gt; standard &lt;a href="http://www.nerc.com/docs/standards/sar/CIP-002-4_2009Dec29.pdf"&gt;&lt;strong&gt;CIP-002-4, Cyber Security - BES Cyber System Categorization&lt;/strong&gt;&lt;/a&gt; (16 pages, w/VSLs)&lt;strong&gt; &lt;/strong&gt;in December for an informal comment period through February 12th. This version calls for significantly more extensive risk assessment process:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Substantially addresses concerns raised in Assante’s April 2009 letter – see &lt;a href="http://www.digitalbond.com/index.php/2009/04/07/assante-throws-down-the-gauntlet-on-cip-002/"&gt;Assante Throws Down the Gauntlet on CIP-002 &lt;/a&gt;- DigitalBond.com. &lt;/li&gt;&lt;li&gt;Rather just focusing what to include, requires a complete inventory list of BES Cybersecurity systems for determinations to be made.&lt;/li&gt;&lt;li&gt;Getting NISTy (&lt;a href="http://thisweekinsecurity.blogspot.com/2009/08/nist-on-roll-with-historic-security.html"&gt;more&lt;/a&gt;) with graded BES impact assessment and commensurate controls- high, medium, low (catch all) impact ranking &lt;/li&gt;&lt;li&gt;Emphasizes functional assurance, not just security around functions.&lt;/li&gt;&lt;li&gt;Specific Violation Severity Levels (VSLs) penalties called for if mis-categorization is determined to have taken place.&lt;/li&gt;&lt;li&gt;NPP applicability- structures, components, equipment and systems of facilities within a nuclear generation plant not regulated by the U.S. Nuclear Regulatory Commission or the Canadian Nuclear Safety.&lt;/li&gt;&lt;li&gt;&lt;em&gt;More-&lt;/em&gt; effective date is two years after approval (“eighth calendar quarter”), bottom up conservative approach with granular assessment/engineering evaluation expectations, various impact categorizations for assessment addressing inadvertent/adverse changes, example fishbone diagramming dependencies- see &lt;a href="http://www.nerc.com/docs/standards/sar/CIP-002-4_Guidance_Doc_2009Dec29.pdf"&gt;Draft Guidance Document&lt;/a&gt; (10 pages)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:xx-small;color:#660000;"&gt;&lt;u&gt;&lt;strong&gt;Updated 1/24/2010&lt;/strong&gt;&lt;/u&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color:#660000;"&gt;&lt;span style="color:blue;"&gt;On Feb 3rd, 2010 at 1pm EST, NERC is scheduled to host a webinar &lt;strong&gt;"Proposed Revisions to CIP-002-4"&lt;/strong&gt;&lt;/span&gt; (&lt;/span&gt;&lt;a href="https://cc.readytalk.com/cc/schedule/display.do?udc=tomq37wyp8y3"&gt;&lt;span style="color:#660000;"&gt;&lt;span style="color:#660000;"&gt;&lt;strong&gt;register&lt;/strong&gt;&lt;/span&gt;)&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;strong&gt;&lt;u&gt;NRC RG 5.71 Released. &lt;/u&gt;&lt;/strong&gt;Following the November 23, 2009 deadline for NPPs to file required Cyber Security Plans for review and approval (per &lt;a href="http://www.nrc.gov/reading-rm/doc-collections/cfr/part073/part073-0054.html"&gt;NRC Reg 10 CFR 73.54&lt;/a&gt;), the NRC released regulatory guide &lt;a href="http://dl.dropbox.com/u/1712646/NRC-RG5.71_CyberSecurityProgramsForNuclearFaciliites%28public_Jan2010%29.pdf"&gt;&lt;strong&gt;RG 5.71, Cyber Security Programs for Nuclear Facilities&lt;/strong&gt;&lt;/a&gt; (copy, 100+ pages, including template/appendixes) earlier this month, source: &lt;a href="http://www.nrc.gov/reading-rm/doc-collections/reg-guides/protection/active/"&gt;NRC Regulatory Guides - Materials and Plant Protection (Division 5)&lt;/a&gt;. This now public regulatory guide formally expands and supersedes prior NRC endorsed NEI 04-04 developed by the industry. Some argue it’s like going back to a blank piece of paper to stand up a new program – not entirely true but still very dense as regulatory guides go, and also getting more NIST aligned (&lt;a href="http://thisweekinsecurity.blogspot.com/2009/08/nist-on-roll-with-historic-security.html"&gt;more&lt;/a&gt;). Commercial nuclear has gone through a number of development steps over the last decade, see &lt;a href="http://www.nei.org/keyissues/safetyandsecurity/factsheets/powerplantsecuritypage5/"&gt;NEI Power Plant Security- Cybersecurity&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;More perspective around RG 5.71 can be gained from reviewing NRC's &lt;a href="http://dl.dropbox.com/u/1712646/ACRS567-CyberRG5.71_Nov2009.pdf"&gt;Advisory Committee on Reactor Safeguards (ACRS) 567th Meeting- Nov2009 - Official Transcript&lt;/a&gt; (copy, - 330 pages, good place to start is page 98 for "cybersecurity", jump to page 275 for more specific RG 5.71 coverage). &lt;em&gt;This guide is writen for the cybersecurity professional and covers aspects that others may miss when reading through it.&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;FERC Order 706-B - NRC/NERC MOU Released&lt;/u&gt;&lt;/strong&gt;. FERC recognized a regulatory gap with &lt;a href="http://www.ferc.gov/industries/electric/indus-act/reliability.asp"&gt;Order 706B&lt;/a&gt;; the NRC, primarily focused on public safety and nuclear significant aspects of NPPs, does not have regulatory scope addressing continuity of power. FERC Order 706-B states that balance of plant systems at NPPs not regulated by the NRC must comply with NERC CIP Standards and requires NRC to make a compliance filing outlining implementation schedule. A &lt;a href="http://www.nerc.com/fileUploads/File/News/NERC-NRC%20MOU%2020091230%20executed.PDF"&gt;NRC/NERC MOU&lt;/a&gt; released last week, establishes a working agreement consistent with FERC Order 706-B recommendations. &lt;em&gt;FERC's Dec 17th filing expects additional compliance filing from NERC to more clearly address (i) how determinations of systems will be made that that fall under either program (NRC Cyber or NERC CIP), and (ii) establishing an exception process for exempting systems that fall under NRC Cyber from CIP compliance.&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;More:&lt;/strong&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;a href="https://www.nerc.net/nercsurvey/Survey.aspx?s=927d1020f2174bbe8d4ebaeb8c9825b6"&gt;Informal Comment Form: Project 2008-06 Cyber Security Order 706 CIP-002-4&lt;/a&gt; &lt;span style="color:#660000;"&gt;(due 2/12/2010)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.morganlewis.com/pubs/Energy_CyberSecurityReqs_LF_12jan10.pdf"&gt;NRC and NERC Execute Memorandum of Understanding Regarding Enforcement of Cyber Security Requirements-&lt;/a&gt; Morgan Lewis Energy Lawflash, January 12, 2010&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.nrc.gov/reading-rm/doc-collections/cfr/part073/part073-0054.html"&gt;NRC Reg (10 CFR 73.54) Protection of digital computer and communication systems and networks.&lt;/a&gt; &lt;/li&gt;&lt;li&gt;&lt;a href="http://thisweekinsecurity.blogspot.com/2009/08/nist-on-roll-with-historic-security.html"&gt;NIST on a roll with "Historic" Security Controls Guidance (SP 800-53 Rev 3)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-266307408211412452?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/266307408211412452/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=266307408211412452' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/266307408211412452'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/266307408211412452'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2010/01/2010-blasts-in-with-regulatory.html' title='2010 Blasts in with Regulatory Cybersecurity Bar Raising&lt;br&gt;&lt;i&gt;-  NERC CIP-002-4 (Project 706 Ph II) and NRC RG 5.71- both with NIST Enhancements&lt;/i&gt;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-7774364964595748986</id><published>2010-01-09T00:48:00.036-06:00</published><updated>2010-04-10T18:09:46.232-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Decade Singularity &quot;Ray Kurzweil&quot; &quot;Daniel Suarez&quot; &quot;Bill Joy&quot; Nanotechnology 2020 KurzweilAI.net'/><title type='text'>Security Challenges Into the Next Decade and Beyond- A Leap Into the Future with Kurzweil, Suarez &amp; Joy</title><content type='html'>Over the New Year's Holiday, I dusted off and finished pressing my way through a stunning, expansive view into the not so distant future with &lt;a href="http://en.wikipedia.org/wiki/Raymond_Kurzweil"&gt;Ray Kurzweil’s&lt;/a&gt; tome &lt;a href="http://www.amazon.com/gp/product/0143037889?ie=UTF8&amp;amp;tag=thiweeinsec-20&amp;amp;linkCode=as2&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=0143037889"&gt;The Singularity Is Near: When Humans Transcend Biology&lt;/a&gt;. In his richly cited work, huge advancements in renewable energy and storage efficiency, with microscopic fuel cells and other technologies, will capture abundant energy available for the taking in a distributed manner- intrinsically reducing unique security risks associated with centralized power stations.&lt;br /&gt;&lt;br /&gt;Looking at accelerating trends continuing with information technology, Kurzweil argues that &lt;a href="http://www.kurzweilai.net/articles/art0134.html?printable=1"&gt;The Law of Accelerating Returns&lt;/a&gt; applies to many problems once sufficiently addressed with information technology based approaches.  For example, rather than traditional experimental trial by error, exponentially improving computing environments are increasingly being used to effectively model and test medical treatments virtually.  Expect significant life extension and expansion improvements over the next 20 years, as well as rapidly emerging non-biological intelligence fundamentally going beyond various narrow artificial intelligence applications widely used today. Related nanotechnology will drive expanding human intelligence and also result in new existential threats as we eventually transcend our biology&lt;em&gt;- some heady prognostications.&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;If you haven’t read about or heard Ray Kurzweil in depth before, here’s an informative Dec 2008 Ray Kurzweil presentation from the &lt;em&gt;26th Army Science Conference&lt;/em&gt; &lt;a href="http://www.zentation.com/viewer/index.php?passcode=rJukJRYuFz"&gt;The Impact of Accelerating IT on War and Peace - Dec 2008, &lt;span style="color:#660000;"&gt;video 54m&lt;/span&gt;)&lt;/a&gt; This talk was broader than the title implies, providing his updated views and supporting presentations slides (142 w/&lt;a href="http://dl.dropbox.com/u/1712646/KAIN12108-26th_Army_Science_Conference.pdf"&gt;pdf&lt;/a&gt;, &lt;a href="http://dl.dropbox.com/u/1712646/KAIN12108-26th_Army_Science_Conference.pptx"&gt;pptx&lt;/a&gt; formats) regarding IT driven advancements and unfolding implications.&lt;br /&gt;&lt;br /&gt;Focusing on cyber security, non-biological computer infections or actions taken by malicious actors will increasingly be less just about compromising computers and more about harming the physical environment including humanity &lt;em&gt;- who wants to let their bio or nano augmented substrate be chewed up and spit out as grey goo by rapidly replicating nano-nasties or otherwise adversely repurposed?&lt;/em&gt; So much promise and notable perils which many baby boomers may be able to witness if they stick around long enough. Kurzweil, turning 62 in Feb, is taking several hundred supplements daily and adhering to a strictly formulated diet- striving to bridge into his predicted, further life extended future bridges with continuing advancements in GNR (genetics, nanotechnology, and robotics).&lt;br /&gt;&lt;br /&gt;From a more current perspective, the emerging best-seller “fiction” hit in 2009 &lt;a href="http://www.amazon.com/gp/product/0525951113?ie=UTF8&amp;amp;tag=thiweeinsec-20&amp;amp;linkCode=as2&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=0525951113"&gt;&lt;em&gt;Daemon&lt;/em&gt;&lt;/a&gt;&lt;img style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; MARGIN: 0px; BORDER-TOP: medium none; BORDER-RIGHT: medium none" border="0" alt="" src="http://www.assoc-amazon.com/e/ir?t=thiweeinsec-20&amp;amp;l=as2&amp;amp;o=1&amp;amp;a=0525951113" width="1" height="1" /&gt;by Daniel Suarez (&lt;a href="http://www.audible.com/adbl/site/enSearch/searchResults.jsp?D=daemon&amp;amp;Ntt=Daniel+Suarez&amp;amp;Dx=mode%2bmatchallpartial&amp;amp;Ntk=S_Author_Search&amp;amp;Ntx=mode%2bmatchallpartial&amp;amp;N=0&amp;amp;BV_UseBVCookie=Yes"&gt;audio clips&lt;/a&gt; at audible.com) provides a present day look into what could go wrong with runaway non-biological intelligence. His &lt;a href="http://www.amazon.com/gp/product/0525951113?ie=UTF8&amp;amp;tag=thiweeinsec-20&amp;amp;linkCode=as2&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=0525951113"&gt;first book&lt;/a&gt;, and just released sequel &lt;a href="http://www.amazon.com/gp/product/0525951571?ie=UTF8&amp;amp;tag=thiweeinsec-20&amp;amp;linkCode=as2&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=0525951571"&gt;Freedom (TM)&lt;/a&gt;&lt;img style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; MARGIN: 0px; BORDER-TOP: medium none; BORDER-RIGHT: medium none" border="0" alt="" src="http://www.assoc-amazon.com/e/ir?t=thiweeinsec-20&amp;amp;l=as2&amp;amp;o=1&amp;amp;a=0525951571" width="1" height="1" /&gt; provides subtle and ruthless ways civilization could be systemically torn down by a cleverly designed artificial entity savvy in human behavior, reaching out from cyber space via &lt;strong&gt;online gaming&lt;/strong&gt; and other methods, recruiting and exploiting human agents, etc. While entertaining and recommended reading, his informative, non-fiction presentation &lt;a href="http://fora.tv/2008/08/08/Daniel_Suarez_Daemon_Bot-Mediated_Reality#fullprogram"&gt;Daemon: Bot-Mediated Reality- The Long Now Foundation (&lt;span style="color:#660000;"&gt;video 1:20&lt;/span&gt;)&lt;/a&gt; emphasizes underlying themes with concerns about how humanity is increasingly facing the prospects of a Darwinian struggle with non-biological intelligence.  He emphasizes key strategies and controls &lt;u&gt;needed now&lt;/u&gt; to address the growing risk.&lt;br /&gt;&lt;br /&gt;For more on concerns about the perils – here’s a provocatively titled article &lt;a href="http://www.wired.com/wired/archive/8.04/joy_pr.html"&gt;“Why the future doesn't need us.”- Bill Joy, Wired, April 2000&lt;/a&gt; “Our most powerful 21st-century technologies — robotics, genetic engineering, and nanotech — are threatening to make humans an endangered species."&lt;br /&gt;&lt;br /&gt;More:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.nydailynews.com/opinions/2009/12/13/2009-12-13_top_futurist_ray_kurzweil_predicts_how_technology_will_change_humanity_by_2020.html"&gt;Top futurist, Ray Kurzweil, predicts how technology will change humanity by 2020&lt;/a&gt; and&lt;br /&gt; &lt;a href="http://www.nydailynews.com/opinions/2009/12/13/2009-12-13_ray_kurzweils_crystal_ball.html"&gt;Ray Kurzweil's Crystal Ball&lt;/a&gt; - New York Daily News, Dec 2009&lt;/li&gt;&lt;li&gt;&lt;a href="http://bitbucket.kylewelsh.com/2009/12/24/china-blames-online-games-for-drugs-murder-teen-pregnancy/"&gt;China blames online games for drugs, murder, teen pregnancy&lt;/a&gt; - bitbucket.kylewelsh.com, Dec 2009&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.youtube.com/watch?v=1uIzS1uCOcE&amp;amp;NR=1"&gt;Ray Kurzweil Explains the Coming Singularity (video, 7m)&lt;/a&gt; - bigthink.com, Apr 2009&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-7774364964595748986?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/7774364964595748986/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=7774364964595748986' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/7774364964595748986'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/7774364964595748986'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2010/01/security-issues-into-next-decade-leap.html' title='Security Challenges Into the Next Decade and Beyond&lt;br&gt;&lt;i&gt;- A Leap Into the Future with Kurzweil, Suarez &amp; Joy&lt;/i&gt;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-4921818485949499453</id><published>2010-01-02T22:45:00.036-06:00</published><updated>2010-01-02T23:35:27.486-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='2009 2010 Perspective Predictions Cyber Information Security'/><title type='text'>Cyber Security Happy New Year 2010 - Perspective and Predictions</title><content type='html'>&lt;span style="color: #000099; font-size: 78%;"&gt;First Cut&amp;nbsp;1/2/2009&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;&lt;/u&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color: #990000;"&gt;&lt;u&gt;2009 Perspective&lt;/u&gt; &lt;span style="color: #000099;"&gt;- &lt;/span&gt;&lt;em&gt;&lt;span style="color: #000099;"&gt;hot stories and list of lists&lt;/span&gt;.&lt;/em&gt;&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.computerworld.com/s/article/9135944/U.S._seeks_top_guns_for_cybersecurity_"&gt;U.S. seeks 'top guns' for cybersecurity&lt;/a&gt; - ComputerWorld, Jul 27, 2009&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.eweek.com/c/a/Security/Rogue-Antivirus-Operations-Thrive-in-2009-651924/"&gt;Rogue Antivirus Operations Thrive in 2009&lt;/a&gt; -eWeek, Dec 22, 2009&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.boston.com/business/technology/articles/2009/12/23/obama_names_a_cyber_security_chief/"&gt;Obama names a cyber security chief&lt;/a&gt;&amp;nbsp; - Boston Globe, Dec 22, 2009&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.verizonbusiness.com/resources/security/reports/2009_databreach_rp.pdf"&gt;Verizon Business Issues 2009 Data Breach Supplimental Report Profiling 15 Most Common Attacks (32p)&lt;/a&gt;&amp;nbsp;Anatomy of a Data Breach' Sheds New Light on How and Why Attacks Occur&amp;nbsp; &lt;br /&gt;&lt;em&gt;- Results from 600 incidents over five years make a strong case against the long-abiding and deeply held belief that insiders are behind most breaches. &lt;/em&gt;&lt;br /&gt;&lt;div&gt;&lt;em&gt;-&amp;nbsp; &lt;/em&gt;&lt;a href="http://www.flickr.com/photos/verizonbusiness/4158917874/"&gt;&lt;em&gt;Top 15 threat action types &lt;/em&gt;&lt;/a&gt;&lt;em&gt;&amp;nbsp;(flckr link) from 2009 DBIR (page 6 of 32):&lt;br /&gt;&lt;/em&gt;- Where should mitigation efforts be focused?&lt;br /&gt;&lt;em&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; a. Ensure essential controls are met.&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; b. Find, track, and assess data.&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; c. Collect and monitor event logs.&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;d. Audit user accounts and credentials.&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; e. Test and review web applications.&lt;/em&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.eweek.com/c/a/Security/Top-Security-Stories-of-2009-725639/"&gt;Top Security Stories of 2009&lt;/a&gt; - eWeek, Dec 28, 2009&lt;br /&gt;1. &lt;span style="color: red;"&gt;&lt;span style="color: #cc0000;"&gt;Conficker Countdown&lt;/span&gt;&lt;/span&gt;, see &lt;a href="http://www.cbsnews.com/video/watch/?id=4908267n&amp;amp;tag=contentMain;contentBody"&gt;"The Internet is Infected" -&amp;nbsp;60 Minutes - April 2009&lt;/a&gt;&lt;br /&gt;2. Cyber Security Coordinator (Czar)&lt;br /&gt;3. Gonzalez and His Gang Taken Down (huge takedown!)&lt;br /&gt;4. Social Networking and You (organizations, regulators wressle with privacy, security issues)&lt;br /&gt;5. Apple iPhone Security Woes (Dutch teanager discovery leads to worm attacking jailbroken phones)&lt;br /&gt;6. Hacktivists Stay&amp;nbsp;Busy (twitter redirection to Iranina cyber army, DDos attacks, etc)&lt;br /&gt;7. &lt;span style="color: #cc0000;"&gt;Electric Grid Lights Out&lt;/span&gt; (hacker spies causing power outages, infiltrating national defenses) see &lt;a href="http://www.cbsnews.com/video/watch/?id=5578986n&amp;amp;tag=related;photovideo"&gt;"Sabotaging The System" - 60 Minutes - Nov 2009&lt;/a&gt;&lt;br /&gt;8. F-35 Fighter Plans Hijacked by Hackers&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/trend_micro_2010_future_threat_report_final.pdf"&gt;The Future of Threats and Threat Technologies: How the Landscape is Changing (24 p)&lt;/a&gt; TrendMicro, Dec 2009&lt;em&gt;-&amp;nbsp; Several threat area predictions that&amp;nbsp;that came true in 2009:&lt;br /&gt;&lt;/em&gt;- Social networking sites will grow as targets;&lt;br /&gt;- Social engineering will become increasingly prevalent and clever - Unlike the global economy, the underground economy will continue to flourish.&lt;br /&gt;&lt;strong&gt;&lt;br /&gt;More:&amp;nbsp; &lt;a href="http://thisweekinsecurity.blogspot.com/2009/01/cyber-security-happly-new-year-2009.html"&gt;Perspective One Year Ago&lt;/a&gt;&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;strong&gt;&lt;span style="color: #990000;"&gt;&lt;u&gt;2010 and Beyond Predictions&lt;/u&gt; &lt;/span&gt;&lt;em&gt;&lt;span style="color: #000099;"&gt;- more hot stories and list of lists.&lt;/span&gt;&lt;span id="goog_1262487842488"&gt;&amp;nbsp; &lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/trend_micro_2010_future_threat_report_final.pdf"&gt;The Future of Threats and Threat Technologies: How the Landscape is Changing (24 p)&lt;/a&gt; TrendMicro, Dec 2009&lt;br /&gt;-&amp;nbsp;No global outbreaks, but localized and targeted attacks.&lt;br /&gt;- It’s all about money, so cybercrime will not go away.&lt;br /&gt;-&amp;nbsp;Windows 7 will have an impact since it is less secure than Vista in the default configuration.&lt;br /&gt;-&amp;nbsp;Risk mitigation is not as viable an option anymore—even with alternative browsers/OSs&lt;br /&gt;-&amp;nbsp;Malware is changing its shape—every few hours.&lt;br /&gt;- Drive-by infections are the norm—one Web visit is enoughto get infected.&lt;br /&gt;-&amp;nbsp;New attack vectors will arise for virtualized/cloud environments.&lt;br /&gt;- Bots cannot be stopped anymore, and will be around forever.&lt;br /&gt;-&amp;nbsp;Company/Social networks will continue to be shaken by data breaches.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://risky.biz/RB137"&gt;Risky Business #137 -- Year in review special!&lt;/a&gt;&amp;nbsp;&amp;nbsp; - Patrick Gray, Dec 2009&amp;nbsp; (&lt;a href="http://risky.biz/news_and_opinion"&gt;news and opinion&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;More: &lt;/strong&gt;&lt;a href="http://thisweekinsecurity.blogspot.com/2009/01/cyber-security-happly-new-year-2009.html"&gt;&lt;strong&gt;Predictions One Year Ago&lt;/strong&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-4921818485949499453?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/4921818485949499453/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=4921818485949499453' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/4921818485949499453'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/4921818485949499453'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2010/01/cyber-security-happy-new-year-2010.html' title='Cyber Security Happy New Year 2010 - Perspective and Predictions'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-6350723263667788057</id><published>2009-12-25T22:38:00.030-06:00</published><updated>2011-11-24T00:18:00.832-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='&quot;Cloud Computing&quot; vSphere Azure CSA &quot;Cloud Security Alliance&quot;'/><title type='text'>Cloud Security FUD Addressed with Executive Overview- guidance and news as 2009 comes to a close</title><content type='html'>&lt;span style="color: rgb(51, 51, 255);"&gt;(Updated 11/24/2011)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Cloud computing technology and solutions hit many critical infrastructure organizations head on in 2009, transitioning from being a vague concept to a must-have, at times mandated, in-house technology for many, a.k.a. private clouds. During this time, vendor offerings hosted in public cloud settings increasingly also provided quick start, low cost, flexibility with extensive integration options.. without much of the extra lifting and hassles running all the footprint requirements in-house. While some state that clear cloud security standards are still years off, the reality is we're already well into the realm of having to deal with public and private cloud security issues- especially at the business network level. &lt;p&gt;The following provides a good executive thumbnail of what decision makers need to understand in addition to the latest in more specific guidance for secure cloud computing:&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://virtualization.sys-con.com/node/1230998"&gt;The Busy Executive’s Quick Cloud Computing Reference Guide&lt;/a&gt; - &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;Virtualization&lt;/span&gt; Journal Dec 2009 &lt;em&gt;— As an executive, you may be hearing many different viewpoints about Cloud Computing; some of them promising significant IT cost reductions and reductions in capital expenditures. Don't get caught off guard regarding all the technical complexities of developing and offering Cloud Computing services, the whole reason you're considering this option is so others will take care of these factors for you. Although you still need to be an educated consumer, you don't need to be in the weeds to ensure you're not caught with your pants around your ankles if you decide to use Cloud Computing services.&lt;/em&gt;&lt;/li&gt;&lt;p&gt;&lt;/p&gt;&lt;li&gt;&lt;a href="http://www.cloudsecurityalliance.org/csaguide.pdf"&gt;Guidance for Critical Areas of Focus in Cloud Computing- Version 2.1 - Dec 2009 (76 pages)&lt;/a&gt;. The &lt;a href="http://www.cloudsecurityalliance.org/"&gt;Cloud Security Alliance (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;CSA&lt;/span&gt;)&lt;/a&gt; newly released second version of guidance for secure adoption of cloud computing services provides more details with a good overview, addressing risks and timing, and helps simplify the decision process involved. This non-profit released their first version during the &lt;a href="https://365.rsaconference.com/community/connect/rsa-conference-usa-2009?view=overview"&gt;2009 &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;RSA&lt;/span&gt; Conference&lt;/a&gt;.  &lt;br /&gt;&lt;em&gt;&lt;b&gt;Excerpt-&lt;/b&gt;  It is hard to believe that just seven short months ago, we pulled together a diverse group of individuals from all corners of the technology industry to publish the first “Security Guidance for Critical Areas in Cloud Computing.” Since its launch, this seminal publication has continued to exceed our expectations for helping organizations around the world make informed decisions regarding if, when, and how they will adopt Cloud Computing services and technologies. But over those seven months our knowledge, and cloud computing technologies, have evolved at an astounding rate. This second version is designed to provide both new knowledge and greater depth to support these challenging decisions.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255); font-weight: bold;"&gt;11/24/2011 Update&lt;/span&gt;&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;The &lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.cloudsecurityalliance.org/"&gt;Cloud Security Alliance (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;CSA&lt;/span&gt;)&lt;/a&gt;&lt;span style="color: rgb(51, 51, 255);"&gt; &lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="https://cloudsecurityalliance.org/research/initiatives/security-guidance/"&gt;released Security Considerations for Critical Areas of Cloud Computing- Version 3&lt;/a&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;, 11/14/2011&lt;/span&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;/em&gt;&lt;/li&gt;&lt;p&gt;&lt;/p&gt;&lt;li&gt;&lt;a href="http://csrc.nist.gov/groups/SNS/cloud-computing/"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;NIST&lt;/span&gt; Cloud Computing Project Site&lt;/a&gt;. &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;NIST's&lt;/span&gt; Role in cloud computing is to promote the effective and secure use of the technology within government and industry by providing technical guidance and promoting standards. &lt;/li&gt;&lt;/ul&gt;Of course, there is devil in the details which vendors are working feverishly to address and differentiate with. Microsoft's cloud undergoes annual audits for &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;PCI&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;DSS&lt;/span&gt;, &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;SOX&lt;/span&gt;, and &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;HIPAA&lt;/span&gt; compliance, as well as internal assessments throughout the year. Remarkably, the Microsoft cloud has also obtained IS/&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;IEC&lt;/span&gt; 27001:2005 certification (this year) in addition to &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;SAS&lt;/span&gt; 70 Type 1 and II attestations.  &lt;em&gt;ISO 27001 (formerly ISO 17799) remains one of the best information security standards available - a superset when compared with other standards (&lt;a href="http://blogs.msdn.com/uspublicsector/archive/2009/10/14/secure-the-datacenter-secure-the-cloud.aspx"&gt;more&lt;/a&gt;). &lt;/em&gt;Microsoft's &lt;a href="http://www.microsoft.com/windowsazure/"&gt;Azure&lt;/a&gt; branded public cloud computing platform long in development, is set to go live on New Year's Day. Plans include expanding the new technology into customer settings.&lt;em&gt; &lt;/em&gt;&lt;br /&gt;&lt;br /&gt;At a technology execution level, the release of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;vSphere&lt;/span&gt; in early 2009 extended &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;VMware's&lt;/span&gt; lead with significant performance, features, and security improvements - a game changer - which includes robust &lt;a href="http://blogs.vmware.com/networking/2009/12/cisco-nexus-1000v-r12-for-vsphere-4-released.html"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;Cisco&lt;/span&gt; Nexus 1000V &lt;/a&gt;software appliance support. Regardless of technology mix deployed, many organizations are coming to grips with &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;virtualization's&lt;/span&gt; broader implications and working to spin up capabilities while the technology race presses on.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;Bottom Line for Critical Infrastructure&lt;/u&gt;&lt;/strong&gt;. The implications go well beyond the basic &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_15"&gt;virtualization&lt;/span&gt; strategy of seeking tactical operational benefits with fewer physical servers and more virtual servers. For even the most critical infrastructure settings, private cloud (aka virtualization) computing is increasingly a must have for any new large investments going forward. The cloud technology benefits are compelling (fault tolerance, hot recovery, managing growing functional and regulatory complexity, layering defenses, etc) even while introducing its own complexity and risks to manage. The future will have layered information landscapes, and underlying systems, networks, and storage increasingly &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_16"&gt;virtualized&lt;/span&gt; and extending deeper into and well beyond the comfort zone of today's typical organizational and outsourcing boundaries.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;More:&lt;/strong&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;a href="http://www.infoworld.com/d/cloud-computing/five-big-questions-about-cloud-computing-814?source=IFWNLE_nlt_cloud_2009-12-28"&gt;Five big Questions about cloud computing, InfoWorld, Dec 28, 2009&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blogs.msdn.com/uspublicsector/archive/2009/10/14/secure-the-datacenter-secure-the-cloud.aspx"&gt;Secure the Datacenter, Secure the Cloud - Microsoft Federal Blog, Oct 2009&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://akamai.infoworld.com/sites/infoworld.com/files/pdf/infoworld_cloudcomputing_premium.pdf"&gt;Cloud Computing Deep Dive Special Report (21 pages)- &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_18"&gt;InfoWorld&lt;/span&gt;, Dec 2009 &lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.isaca.org/cloud"&gt;Cloud Computing: Business Benefits with Security, Governance and Assurance Perspectives (10 pages)- &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_19"&gt;ISACA&lt;/span&gt;,&lt;em&gt; Emerging Technology White Paper &amp;amp; more&lt;/em&gt;, Oct 2009 &lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.microsoft.com/events/podcasts/default.aspx?topic=Topic-e1a84e52-b637-4385-9260-2f14fe077c07&amp;amp;audience=Audience-b046181f-3333-4c19-977e-c230ed48d9c0&amp;amp;seriesID=Series-0f616e6e-59b3-4ed4-bc66-b1edd7522b72.xml&amp;amp;pageId=x5385&amp;amp;source=Windows-Server-Podcasts-about-Managing-a-Microsoft-Infrastructure:-Improve-Reliability-and-Performance--for-IT-Professionals"&gt;Microsoft Thrive Live! IT Professional &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_20"&gt;Virtualization&lt;/span&gt; Tour Podcast&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.vmware.com/technical-resources/podcasts/vsphere.html"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_21"&gt;VMWare&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_22"&gt;vSphere&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_23"&gt;Podcasts&lt;/span&gt; Series&lt;/a&gt; &amp;amp; &lt;a href="http://www.youtube.com/user/vmwaretv"&gt;YouTube &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_24"&gt;VMwareTV&lt;/span&gt; Channel&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.infoworld.com/d/cloud-computing/five-big-questions-about-cloud-computing-814?source=IFWNLE_nlt_cloud_2009-12-28"&gt;Cloud Computing Grows Up - Forbes, Dec 22, 2009&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.informationweek.com/cloud-computing/"&gt;Plug Into the Cloud- InformationWeek's Cloud Computing Destination&lt;/a&gt; -  perspective, hot topics&lt;/li&gt;&lt;/ol&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-6350723263667788057?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/6350723263667788057/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=6350723263667788057' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/6350723263667788057'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/6350723263667788057'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2009/12/cloud-security-fud-addressed-with.html' title='Cloud Security FUD Addressed with Executive Overview&lt;br&gt;&lt;i&gt;- guidance and news as 2009 comes to a close&lt;/i&gt;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-3346840244459997655</id><published>2009-10-18T23:00:00.005-05:00</published><updated>2011-08-23T21:20:59.287-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='FERC FPL $25M NERC'/><title type='text'>FERC Hammers Florida Power &amp; Light Co with $25M Civil Penalty  - $5M to go above and beyond current regulatory requirements</title><content type='html'>On Oct 8&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;th&lt;/span&gt;, &lt;a href="http://www.fpl.com/"&gt;Florida Power &amp;amp; Light (&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;FPL&lt;/span&gt;)&lt;/a&gt; agreed to pay a $25 million penalty after blunders by a field engineer led to a service outage affecting nearly a million customers - i.e. &lt;a href="http://www.time.com/time/nation/article/0,8599,1717878,00.html"&gt;2008 Florida Blackout&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;This marks the first settlement resulting from a reliability investigation by the &lt;a href="http://www.ferc.gov/"&gt;Federal Energy Regulatory Commission (&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;FERC&lt;/span&gt;)&lt;/a&gt; enforcing a 2005 law establishing electric reliability standards. This fine won't be going to customers. Instead &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;FPL,&lt;/span&gt; facing a potential of $1B+ in fines, agreed to pay $10M to the United States Treasury, $10M to the &lt;a href="http://www.nerc.com/"&gt;North American Electric Reliability Corp. (&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;NERC&lt;/span&gt;)&lt;/a&gt;. The remaining $5 million is to go towards measures &lt;em&gt;beyond&lt;/em&gt; current reliability requirements in a &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;regulatorily&lt;/span&gt; approved manner- &lt;em&gt;otherwise, whatever remains of the last $5M will be evenly split between US Treasury and &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;NERC&lt;/span&gt;.&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;"Today's settlement demonstrates the high priority the commission places on electric reliability,'' said Norman Bay, director of the commission's Office of Enforcement. ``The message to the industry is clear: Compliance with the standards is critical.'' &lt;/li&gt;&lt;/ul&gt;&lt;strong&gt;&lt;u&gt;Holly smokes&lt;/u&gt;!&lt;/strong&gt; This &lt;a href="http://www.ferc.gov/EventCalendar/Files/20091008102212-IN08-5-0001.pdf"&gt;civil settlement&lt;/a&gt; clearly marks the end of wrist slaps for reliability violations with a whole new level of realizable penalty levels. It's also worth emphasizing that &lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;NERC&lt;/span&gt; &lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;CIPs&lt;/span&gt; &lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;cyber&lt;/span&gt; security focus represents just one of &lt;em&gt;fourteen &lt;/em&gt;reliability groupings in current &lt;a href="http://www.nerc.com/page.php?cid=220"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;NERC&lt;/span&gt; Reliability Standards&lt;/a&gt;. The process reaching this settlement clarifies how &lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;FERC&lt;/span&gt; will increasingly be taking a very active role in industry reliability investigations going forward. Industry compliance programs will need to be reviewed and appropriately bolstered to help ensure sufficient program measures are defined and being maintained. The &lt;span id="SPELLING_ERROR_12" class="blsp-spelling-corrected"&gt;settlement&lt;/span&gt; also speaks to the need for continuous improvement efforts by industry aiming well beyond meeting today's reliability requirements- i.e. increasing regulatory margin. &lt;em&gt;Increasingly akin to commercial nuclear regulatory challenges and supporting programs- with heavy doses of auditable evidence required.&lt;br /&gt;&lt;/em&gt;&lt;br /&gt;More:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;October 8, 2009 - &lt;span id="SPELLING_ERROR_13" class="blsp-spelling-error"&gt;FERC&lt;/span&gt; approves settlement, $25 million fine for &lt;span id="SPELLING_ERROR_14" class="blsp-spelling-error"&gt;FPL's&lt;/span&gt; 2008 Blackout &lt;a href="http://www.ferc.gov/news/news-releases/2009/2009-4/10-08-09.asp"&gt;News Release&lt;/a&gt; &lt;a href="http://www.ferc.gov/EventCalendar/Files/20091008102212-IN08-5-0001.pdf"&gt;Decision&lt;/a&gt; - &lt;span id="SPELLING_ERROR_15" class="blsp-spelling-error"&gt;ferc&lt;/span&gt;.gov&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;&lt;a href="http://www.miamiherald.com/news/southflorida/story/1273730.html" target="_self"&gt;&lt;span id="SPELLING_ERROR_16" class="blsp-spelling-error"&gt;FPL&lt;/span&gt; to pay $25M for blackout blunder&lt;/a&gt; – Miami Herald (Oct 8, 2009)&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;&lt;a href="http://weblogs.sun-sentinel.com/business/realestate/housekeys/blog/2009/01/fpl_could_face_more_than_25_mi.html"&gt;&lt;span id="SPELLING_ERROR_17" class="blsp-spelling-error"&gt;FPL&lt;/span&gt; could face $1 billion in fines&lt;/a&gt; – &lt;span id="SPELLING_ERROR_18" class="blsp-spelling-error"&gt;SunSentinel&lt;/span&gt;.com, (Jan 28, 2009) &lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;&lt;strong&gt;Interesting - &lt;/strong&gt;&lt;a href="http://dl.dropbox.com/u/1712646/Upd-1_FPL-20080229.mp3"&gt;&lt;span id="SPELLING_ERROR_19" class="blsp-spelling-error"&gt;FPL&lt;/span&gt; Conference Call with Major Media- Preliminary Investigation Results (Audio ~45m)&lt;/a&gt; - (Feb 29, 2009) - from &lt;span id="SPELLING_ERROR_20" class="blsp-spelling-error"&gt;FPL&lt;/span&gt; 2008 website posting. (&lt;span style="color:#990000;"&gt;updated link- 8/2011&lt;/span&gt;)&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-3346840244459997655?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/3346840244459997655/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=3346840244459997655' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/3346840244459997655'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/3346840244459997655'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2009/10/florida-power-light-co-hammered-with_18.html' title='FERC Hammers Florida Power &amp; Light Co with $25M Civil Penalty &lt;br&gt;&lt;i&gt; - $5M to go above and beyond current regulatory requirements&lt;/i&gt;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-9206690821732353171</id><published>2009-10-04T21:14:00.012-05:00</published><updated>2010-11-26T00:04:46.593-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='AutoIT Script Microsoft Windows XP Vista Windows7 Compile Screensaver Delay Utility Cyber Security &quot;Egg Timer&quot; CDS SourceForge'/><title type='text'>Striking the Right Balance: MS Windows Screensaver Locking - AutoIt: A Potential Cure for Headaches</title><content type='html'>&lt;strong&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;&lt;span style="color: rgb(0, 0, 153);font-size:78%;" &gt;&lt;u&gt;Updated 11-16-2010&lt;/u&gt;&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;/strong&gt;While there has been plenty of higher stake &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;cyber&lt;/span&gt;&lt;/span&gt; security challenges dominating my team's attention lately, I stumbled on an interesting approach to address an issue many organizations wrestle with.&lt;br /&gt;&lt;br /&gt;The basic, consistent implementation of automatic locking Microsoft Windows PC screen savers, requiring password entry for access after a period of inactivity, poses a number of challenges. At least Microsoft's Active Directory (w/Group Policy Objects) makes implementation technically manageable. However, areas taking issue with implementing a required inactivity lockout often only have occasional legitimate business needs that are not suitable for a full exception. For example, personnel may give presentations and don't want to have disruptions, others may burn DVDs, view network traffic in a locked room, or occasionally engage in other unique activities where there is less interactive PC use- making realistic automatic screen locking burdensome.&lt;br /&gt;&lt;br /&gt;To help address this issue, we've been looking at several "Egg Timer" type of PC utilities to provide the means of temporary relief when merited so we can pursue a more consistent implementation of mandatory inactivity screen saver lockouts technical policy measures company-wide. One particular commercial offering has not yet gone to a new release (that we've been waiting on since 4Q2008) with expected pricing $10-$20 per PC plus annual maintenance.&lt;br /&gt;&lt;br /&gt;Alternatively, a very interesting, freeware scripting and compilation tool called &lt;a href="http://www.autoitscript.com/autoit3/"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1" style="color: rgb(0, 0, 153);"&gt;&lt;strong&gt;AutoIt&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; has been available and improving for years. I haven't coded seriously in a long time and wasn't aware of this tool or its capabilities until recently. Surprisingly, the tool and associated slick editor along with lots of &lt;a href="http://www.xipher.dk/WordPress/?tag=autoit"&gt;&lt;span style="color: rgb(0, 0, 153);"&gt;sample code&lt;/span&gt;&lt;/a&gt;, and large community of users together helped rapidly put me at ease. Although I didn't have much time available over the weekend, I still plunged ahead anyway and developed a "Beta" solution for review and feedback. &lt;span style="color: rgb(0, 0, 153);"&gt;The &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;CDS&lt;/span&gt;&lt;/span&gt; utility developed since with &lt;/span&gt;&lt;a href="http://www.autoitscript.com/autoit3/"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3" style="color: rgb(0, 0, 153);"&gt;&lt;strong&gt;AutoIt&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: rgb(0, 0, 153);"&gt; seems to do pretty much what we need and compiles into a reasonably small, single executable file that can just be dropped on the menu or just the desktop - &lt;em&gt;sweet&lt;/em&gt;. The latest version supports use of Active Directory groups to authorize specific systems and logs user startup, activation, and exit events (user, timeout) of CDS to the local Windows Application event log and a designated central logging server (if assigned and available).&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;This excursion is aimed at saving us some hard cash - a good thing in tough times - while also helping make the consistent implementation of screen saver technical controls easier to live with for all involved. Additionally, the sheer ease of using &lt;a href="http://www.autoitscript.com/autoit3/"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4" style="color: rgb(0, 0, 153);"&gt;&lt;strong&gt;AutoIt&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; underscores how open source-like technology tools are continuing to develop &lt;em&gt;so even the free stuff can be the very good stuff&lt;/em&gt;.&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;strong&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;&lt;span style="font-size:85%;"&gt;Updated 11-16-2010&lt;/span&gt; &lt;/span&gt;&lt;/strong&gt;&lt;/u&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 51, 153);"&gt;A &lt;a href="http://www.sourceforge.org/"&gt;SourceForge&lt;/a&gt; open source edition of the Corporate Delay Screensaver (CDS) utility - CDS-v100-Open- is now available for download with commented source code, use documentation, and an example AutoIT complied executable at &lt;/span&gt;&lt;a href="http://coporatedelaysc.sourceforge.net/"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-priority:99;  mso-style-qformat:yes;  mso-style-parent:"";  mso-padding-alt:0in 5.4pt 0in 5.4pt;  mso-para-margin-top:0in;  mso-para-margin-right:0in;  mso-para-margin-bottom:10.0pt;  mso-para-margin-left:0in;  line-height:115%;  mso-pagination:widow-orphan;  font-size:11.0pt;  font-family:"Calibri","sans-serif";  mso-ascii-font-family:Calibri;  mso-ascii-theme-font:minor-latin;  mso-fareast-font-family:"Times New Roman";  mso-fareast-theme-font:minor-fareast;  mso-hansi-font-family:Calibri;  mso-hansi-theme-font:minor-latin;  mso-bidi-font-family:"Times New Roman";  mso-bidi-theme-font:minor-bidi;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;/a&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://corpdelayscnsvr.sourceforge.net/"&gt;http://corpdelayscnsvr.sourceforge.net&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-9206690821732353171?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/9206690821732353171/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=9206690821732353171' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/9206690821732353171'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/9206690821732353171'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2009/10/password-locking-screensavers-autoit.html' title='Striking the Right Balance: MS Windows Screensaver Locking&lt;br&gt;&lt;i&gt; - AutoIt: A Potential Cure for Headaches&lt;/i&gt;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-8372266040444133051</id><published>2009-08-08T12:28:00.001-05:00</published><updated>2009-09-06T08:32:21.127-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Smartgrid cyber security IOActive smartmeter'/><title type='text'>BlackHat Smartgrid Worm Attack Simulation - Aug 27th   Live Webcast: Smart Grid Device Security - Mike Davis, IOActive </title><content type='html'>&lt;span style="color:#660000;"&gt;&lt;u&gt;&lt;span style="font-size:78%;"&gt;Updated 9-5-2009&lt;/span&gt;&lt;/u&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Following &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;BlackHat&lt;/span&gt;&lt;/span&gt; 2009 in July, the archived &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;webcast&lt;/span&gt;&lt;/span&gt; below highlights critical research Mike Davis and other &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;IOActive&lt;/span&gt;&lt;/span&gt; researchers performed on Smart Grid technology.&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.brighttalk.com/webcasts/5642/attend"&gt;&lt;strong&gt;Smart Grid Device Security - Mike Davis, &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;IOActive&lt;/span&gt;&lt;/span&gt; 8/27 - 4-5 pm CST&lt;/strong&gt;&lt;/a&gt; &lt;span style="font-size:78%;"&gt;&lt;span style="color:#660000;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color:#990000;"&gt;&lt;span style="color:#660000;"&gt;- References several video simulations of 22,000 node smart-meter worm propagation using GPS points gathered from &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;geo&lt;/span&gt;&lt;/span&gt;-coded home addresses purchased from a bulk mailing list. Radio range and other factors are reflected once a compromised "Patient 0" meter is introduced. - &lt;/span&gt;&lt;a href="http://www.youtube.com/watch?v=xy0vDYd22Rk"&gt;&lt;span style="color:#660000;"&gt;Video 1&lt;/span&gt;&lt;/a&gt;, &lt;span style="color:#660000;"&gt;&lt;/span&gt;&lt;a href="http://www.youtube.com/watch?v=kc_ijB7VPd8"&gt;&lt;span style="color:#660000;"&gt;Video 2&lt;/span&gt;&lt;/a&gt;, &lt;a href="http://www.youtube.com/watch?v=gEzg1K-T9nA"&gt;&lt;span style="color:#660000;"&gt;Video 3&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;- BrighTALK.com registration required. &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Davis and other &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;IOActive&lt;/span&gt;&lt;/span&gt; researchers developed a proof-of-concept malicious code that self-propagated in a peer-to-peer fashion from one meter to the next as part of their effort to identify Smart Grid &lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt; security risks and threats. &lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;Webcast&lt;/span&gt;&lt;/span&gt; also addresses this attack simulation and discovered Smart Grid vulnerabilities to attack- such as susceptibilities to buffer overflows and root kits.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;As one of the top Black Hat conference presentations, this has stirred up further attention to Smart Grid &lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt; security just as &lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;NIST&lt;/span&gt;&lt;/span&gt; is working to stand up and plow through developing related requirements and standards on an accelerated schedule. For those that missed out on the Blank Hat session, this recap is very informative.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;u&gt;&lt;span style="font-size:78%;color:#000099;"&gt;Update 8-20-2009&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/em&gt;&lt;em&gt;Davis's &lt;/em&gt;&lt;a href="http://www.blackhat.com/html/bh-usa-09/bh-usa-09-speakers.html#MDavis"&gt;&lt;em&gt;Recoverable Advanced Metering Infrastructure&lt;/em&gt;&lt;/a&gt;&lt;em&gt; presentation slides (23 pages, some thoughtful &lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;redactions&lt;/span&gt;&lt;/span&gt;) are now posted in the &lt;/em&gt;&lt;a href="https://www.blackhat.com/html/bh-usa-09/bh-usa-09-archives.html#MDavis"&gt;&lt;em&gt;Black Hat USA 2009 Archive area&lt;/em&gt;&lt;/a&gt;&lt;em&gt;. &lt;/em&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-8372266040444133051?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/8372266040444133051/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=8372266040444133051' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/8372266040444133051'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/8372266040444133051'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2009/08/blackhat-smartgrid-worm-attack.html' title='BlackHat Smartgrid Worm Attack Simulation - Aug 27th &lt;br&gt; &lt;i&gt; Live Webcast: Smart Grid Device Security - Mike Davis, IOActive &lt;/i&gt;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-6940772728107249720</id><published>2009-08-02T09:24:00.003-05:00</published><updated>2010-01-17T22:06:26.178-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NIST NERC NRC Smartgrid BlackHat NIST cyber security hacking worm smartmeter'/><title type='text'>NIST on a roll with "Historic" Security Controls Guidance &amp; SmartGrid 3rd Workshop Aug 3-4-Plus: BlackHat Smartmeter Worm Attack Simulation</title><content type='html'>&lt;u&gt;&lt;strong&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;NIST&lt;/span&gt;&lt;/span&gt; SP800-53 Rev 3 is Final&lt;/strong&gt;&lt;/u&gt;&lt;br /&gt;The voluminous &lt;a href="http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final.pdf"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;NIST&lt;/span&gt;&lt;/span&gt; SP800-53 &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;Revison&lt;/span&gt;&lt;/span&gt; 3&lt;/a&gt; (~40 core pages plus supporting sections, 236 pages total) released on Friday addresses and deliverers a unifying &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;cyber&lt;/span&gt;&lt;/span&gt; security framework for use across governmental, civilian, and critical infrastructure entities on Friday. The focus remains establishing a solid baseline security posture across eighteen control set families Consensus developed &lt;em&gt;&lt;/em&gt;&lt;a class="l" href="http://www.sans.org/cag/guidelines.php" onmousedown="return clk(this.href,'','','res','3','')"&gt;&lt;em&gt;SANS Institute - 20 Critical Security Controls - Version 2.0&lt;/em&gt;&lt;/a&gt;&lt;em&gt; provides an updated mapping to this &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;NIST&lt;/span&gt; release. &lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;NIST&lt;/span&gt;&lt;/span&gt; said the updated security control catalogue incorporates best practices in information security from the Department of Defense, intelligence community and civilian agencies to produce the most broad-based and comprehensive set of safeguards and countermeasures ever developed for information systems.&lt;br /&gt;&lt;br /&gt;Significant changes include:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;A simplified, six-step risk management framework&lt;/li&gt;&lt;li&gt;Additional enhancements for advanced &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;cyber&lt;/span&gt;&lt;/span&gt; threats; &lt;/li&gt;&lt;li&gt;Prioritizing or sequencing security controls during implementation or deployment;&lt;/li&gt;&lt;li&gt;New references section in revised security control structure; &lt;/li&gt;&lt;li&gt;Supplemental guidance security requirements eliminated;&lt;/li&gt;&lt;li&gt;Addresses risk management framework for legacy information systems and for external providers of information system services; &lt;/li&gt;&lt;li&gt;Current threat information and known &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;cyber&lt;/span&gt;&lt;/span&gt; attacks factored into security control baselines updates.&lt;/li&gt;&lt;li&gt;Addresses organization-level security controls for managing information security programs; &lt;/li&gt;&lt;li&gt;Guidance on the management of common controls within organizations; and &lt;/li&gt;&lt;li&gt;Strategy for harmonizing Federal Information Security Management Act security standards and guidelines with international security standard ISO/&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;IEC&lt;/span&gt;&lt;/span&gt; 27001.&lt;/li&gt;&lt;li&gt;Tailoring industrial control systemsm, including&amp;nbsp;compensating controls-&amp;nbsp; Appendix I&lt;/li&gt;&lt;/ol&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;NERC&lt;/span&gt;&lt;/span&gt; emphasized ISO/&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;IEC&lt;/span&gt;&lt;/span&gt; 27001 (aka ISO 17799) with the introduction of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;CIPs&lt;/span&gt;&lt;/span&gt; and 40+ security requirements; this major enhancement to SP 800-53 should help towards &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;NERC&lt;/span&gt;&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;CIPs&lt;/span&gt;&lt;/span&gt; getting even more &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;NISTy&lt;/span&gt;&lt;/span&gt;.&lt;br /&gt;&lt;u&gt;&lt;strong&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_15"&gt;NIST&lt;/span&gt;&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_15"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_16"&gt;SmartGrid&lt;/span&gt;&lt;/span&gt; Workshop - Aug 3rd -4&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_17"&gt;th&lt;/span&gt;&lt;/strong&gt;&lt;/u&gt;&lt;br /&gt;Third major &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_16"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_18"&gt;NIST&lt;/span&gt;&lt;/span&gt; Smart Grid workshop - web/teleconference options:&lt;br /&gt;&lt;em&gt;A key objective of the public workshop is to engage standards development organizations (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_17"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_19"&gt;SDOs&lt;/span&gt;&lt;/span&gt;) in addressing standards-related priorities. Sessions will be devoted to discussing individual &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_18"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_20"&gt;SDO&lt;/span&gt;&lt;/span&gt; perspectives on the evolving &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_19"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_21"&gt;roadmap&lt;/span&gt;&lt;/span&gt; for Smart Grid interoperability standards, reaching agreement on which organizations should resolve specific standards needs, and developing plans and setting &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_20"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_22"&gt;timelines&lt;/span&gt;&lt;/span&gt; for meeting these responsibilities.&lt;/em&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://collaborate.nist.gov/twiki-sggrid/bin/view/_SmartGridInterimRoadmap/SmartGridStandardsWorkshop"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_21"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_23"&gt;Webcast&lt;/span&gt;&lt;/span&gt; information will be posted on this link before the first session begins&lt;/a&gt; (&lt;a href="http://www.nist.gov/smartgrid/"&gt;more&lt;/a&gt;)Agenda worth checking out, e.g. Tuesday – &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_22"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_24"&gt;Cyber&lt;/span&gt;&lt;/span&gt; Security Strategy - 8am start (CST) , workshop wrap-up Tuesday PM includes report out from multiple topic tracks.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;u&gt;&lt;strong&gt;Smart Meter Worm Could Spread Like A Virus&lt;/strong&gt;&lt;/u&gt; - Black Hat Presentation.&lt;br /&gt;At Black Hat last week, &lt;a href="http://www.ioactive.com/services/scada-smart-grid.php"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_23"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_25"&gt;IOActive&lt;/span&gt;&lt;/span&gt;’s&lt;/a&gt; Mike Davis and team created a simulation demonstrating how, over a period of 24 hours, about 15,000 out of 22,000 homes had their smart meters taken over by a software worm that placed the devices under the control of the worm’s designers. More: &lt;a href="http://earth2tech.com/2009/07/31/smart-meter-worm-could-spread-like-a-virus/"&gt;Smart Meter Worm Could Spread Like A Virus&lt;/a&gt; &lt;br /&gt;&lt;em&gt;Some speculation-&lt;/em&gt; the simulation likely focused on a single managed smart grid environment (not across multiple, independent smart-grid settings). The meter manufacturer reportedly first dismissed the claims until they were proven. The vulnerabilities are similar to what happens when computers are linked over the Internet. By exploiting weaknesses in the way computers talk to each other, hackers designed attacks can size control. The &lt;a href="http://www.blackhat.com/html/bh-usa-09/bh-usa-09-speakers.html#MDavis"&gt;Recoverable Advanced Metering Infrastructure&lt;/a&gt; presentation information is not posted yet in the &lt;a href="https://www.blackhat.com/html/bh-usa-09/bh-usa-09-archives.html"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_24"&gt;Black Hat&lt;/span&gt; USA 2009 Archive area&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.blackhat.com/"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_25"&gt;Black Hat&lt;/span&gt;&lt;/a&gt; and &lt;a href="http://www.defcon.org/"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_26"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_26"&gt;Defcon&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; draws some of the best talent around to crack security e.g. &lt;a href="http://www.pcworld.com/article/169370/black_hat_researchers_find_free_parking_in_san_francisco.html"&gt;Black Hat Researchers Find 'Free' Parking in San Francisco&lt;/a&gt; and &lt;a href="http://news.google.com/news?q=blackhat%20hacking&amp;amp;sourceid=ie7&amp;amp;rls=com.microsoft:en-US&amp;amp;oe=utf8&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;sa=N&amp;amp;hl=en&amp;amp;tab=wn"&gt;more news&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-6940772728107249720?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/6940772728107249720/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=6940772728107249720' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/6940772728107249720'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/6940772728107249720'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2009/08/nist-on-roll-with-historic-security.html' title='NIST on a roll with &quot;Historic&quot; Security Controls Guidance &amp; SmartGrid 3rd Workshop Aug 3-4&lt;br&gt;&lt;i&gt;-Plus: BlackHat Smartmeter Worm Attack Simulation&lt;/i&gt;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-5188307228920771267</id><published>2009-07-26T22:50:00.000-05:00</published><updated>2009-08-10T18:34:23.511-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='EMP Cyber Security Electric Grid NERC &quot;Lofty Perch&quot;'/><title type='text'>Securing the Modern Electric Grid from Physical and Cyber Attacks -  Homeland Security Committee Hearing 7/21/2009</title><content type='html'>The Homeland Security Committee hearing &lt;a href="http://homeland.house.gov/hearings/index.asp?ID=206"&gt;“&lt;span style="color:#000099;"&gt;&lt;strong&gt;Securing the Modern Electric Grid from Physical and &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;Cyber&lt;/span&gt;&lt;/span&gt; Attacks&lt;/strong&gt;&lt;/span&gt;”&lt;/a&gt; on 7/21/2009 provided solid industry perspective on improving &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt; security. Additionally, serious committee attention now is also focusing on the growing threat of physical damage from &lt;a href="http://en.wikipedia.org/wiki/Electromagnetic_pulse"&gt;&lt;span style="color:#000099;"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;EMP&lt;/span&gt;&lt;/span&gt; (Electromagnetic Pulse)&lt;/span&gt;&lt;/a&gt; threats. An &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;EMP&lt;/span&gt;&lt;/span&gt; attack, using one or several high attitude nuclear detonations, risks taking out all digital and electrical infrastructure across wide swaths of North America. The &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;EMP&lt;/span&gt;&lt;/span&gt; threat is not new; however, there is growing risk of a deliberate attack from either a rouge group or nation sponsored effort, &lt;em&gt;e.g. Iran sea based delivery testing for such a device with high attitude explosion&lt;/em&gt;. Our vulnerability to this issue serves to increase risk. &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;EMP&lt;/span&gt;&lt;/span&gt; is a national security issue long overdue for realistic mitigation - there is a need to get beyond just studying the issue. Congress sees the potential consequences from the &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;EMP&lt;/span&gt; threat as unacceptable, the cost to substantially mitigate reasonable, and is challenging industry to get after &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;EMP&lt;/span&gt;&lt;/span&gt; risk mitigation.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Mr. &lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;Fabro&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;, from &lt;a href="http://www.loftyperch.com/"&gt;&lt;span style="color:#000099;"&gt;Lofty Perch&lt;/span&gt;&lt;/a&gt;, helped bolster the perspective that industry is substantially improving &lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt; security- good technical, constructive views, recommendations and responses to congressional Q&amp;amp;A. &lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;NERC&lt;/span&gt;&lt;/span&gt;’s &lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;CSO&lt;/span&gt;&lt;/span&gt;&lt;strong&gt; &lt;/strong&gt;Mr. &lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_12" class="blsp-spelling-error"&gt;Assante&lt;/span&gt;&lt;/span&gt; emphasizing progress since joining &lt;span id="SPELLING_ERROR_12" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_13" class="blsp-spelling-error"&gt;NERC&lt;/span&gt;&lt;/span&gt; in September of 2008- e.g. &lt;span id="SPELLING_ERROR_13" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_14" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt; event reporting, communicating more effectively with +1800 entities, improving analysis of threats and industry alerting. He also clearly stated the grid is not immune to &lt;span id="SPELLING_ERROR_14" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_15" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt; or physical threats. and more will be done with industry engaged, factoring &lt;span id="SPELLING_ERROR_15" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_16" class="blsp-spelling-error"&gt;NIST&lt;/span&gt;&lt;/span&gt; in further &lt;span id="SPELLING_ERROR_16" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_17" class="blsp-spelling-error"&gt;CIPs&lt;/span&gt;&lt;/span&gt; development. &lt;span id="SPELLING_ERROR_17" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_18" class="blsp-spelling-error"&gt;NERC&lt;/span&gt;&lt;/span&gt; also still views a need for more &lt;span id="SPELLING_ERROR_18" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_19" class="blsp-spelling-error"&gt;FERC&lt;/span&gt;&lt;/span&gt; authority to better address the risk of immediate, severe threats in a timely manner. &lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;Some committee members remain very skeptical about industry treating &lt;span id="SPELLING_ERROR_19" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_20" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt; security seriously, emphasizing concerns about being lied to by industry, lack of progress. Now questions are also focusing on what industry is really doing about the &lt;a href="http://en.wikipedia.org/wiki/Electromagnetic_pulse"&gt;&lt;span style="color:#000099;"&gt;&lt;span id="SPELLING_ERROR_20" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_21" class="blsp-spelling-error"&gt;EMP&lt;/span&gt;&lt;/span&gt; threat&lt;/span&gt;&lt;/a&gt; - whether from a premeditated attack or natural in origin, e.g. &lt;a href="http://en.wikipedia.org/wiki/Solar_storm"&gt;&lt;span style="color:#000099;"&gt;solar storms&lt;/span&gt;&lt;/a&gt;. &lt;em&gt;Nothing&lt;strong&gt;?&lt;/strong&gt;&lt;/em&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;em&gt;- &lt;strong&gt;Rep. Bill &lt;span id="SPELLING_ERROR_21" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_22" class="blsp-spelling-error"&gt;Pascrell&lt;/span&gt;&lt;/span&gt;, JR’s (from NJ&lt;/strong&gt;) plainly spoken, eviscerating comments and questions provide an instructive example of some hardball congressional Q&amp;amp;A (jump to about &lt;strong&gt;1:16:05&lt;/strong&gt; in &lt;a href="http://homeland.edgeboss.net/wmedia/homeland/chs/elecgrid.wvx"&gt;&lt;span style="color:#000099;"&gt;recorded hearing&lt;/span&gt;&lt;/a&gt;)&lt;/em&gt; &lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;span id="SPELLING_ERROR_22" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_23" class="blsp-spelling-error"&gt;NERC&lt;/span&gt;&lt;/span&gt;. working with DOE, formed up special invitation-only group July 2&lt;span id="SPELLING_ERROR_23" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_24" class="blsp-spelling-error"&gt;nd&lt;/span&gt;&lt;/span&gt; to further look at high impact, low probability, or better stated - low frequency, events (&lt;span id="SPELLING_ERROR_24" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_25" class="blsp-spelling-error"&gt;EMP&lt;/span&gt;&lt;/span&gt;, solar weather, terrorism, etc)&lt;br /&gt;&lt;br /&gt;&lt;u&gt;More&lt;/u&gt;:&lt;br /&gt;-&lt;span style="color:#000099;"&gt;&lt;strong&gt; &lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.washingtontimes.com/news/2009/jul/20/an-avoidable-catastrophe/?feat=home_commentary"&gt;&lt;span style="color:#000099;"&gt;&lt;strong&gt;An avoidable catastrophe&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt; – Opinion Commentary. – Washington Times 7/20/2009&lt;br /&gt;- &lt;a href="http://www.empcommission.org/docs/A2473-EMP_Commission-7MB.pdf"&gt;&lt;span style="color:#000099;"&gt;&lt;strong&gt;Report of the Commission to Assess the Threat to the United Status from Electromagnetic Pulse (&lt;span id="SPELLING_ERROR_25" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_26" class="blsp-spelling-error"&gt;EMP&lt;/span&gt;&lt;/span&gt;) Attack&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;, April 2008 (208 pages) &lt;em&gt;- Well organized update to the 2004 report, walks through key scenarios and consequences.&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-5188307228920771267?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/5188307228920771267/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=5188307228920771267' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/5188307228920771267'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/5188307228920771267'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2009/07/securing-modern-electric-grid-from.html' title='Securing the Modern Electric Grid from Physical and Cyber Attacks &lt;br&gt;&lt;i&gt;-  Homeland Security Committee Hearing 7/21/2009&lt;/i&gt;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-1533618655507040174</id><published>2009-04-15T22:09:00.000-05:00</published><updated>2009-04-16T07:55:39.136-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Convergence'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='Infotec09'/><category scheme='http://www.blogger.com/atom/ns#' term='Compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='AIM Institute'/><category scheme='http://www.blogger.com/atom/ns#' term='Privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='Omaha'/><title type='text'>Yes- Omaha's Infotec09 Rocked !</title><content type='html'>After taking a year off and regrouping, &lt;a href="http://www.infotec.org/"&gt;&lt;span style="color:#000099;"&gt;&lt;strong&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;Infotec&lt;/span&gt;&lt;/span&gt;09&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt; April 14-&lt;span style="color:#000000;"&gt;15, 2009 &lt;strong&gt;rocked.&lt;/strong&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;This bargain conference offered excellent keynotes, including Erik &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;Wahl's&lt;/span&gt;&lt;/span&gt; phenomenal opening "Art of Vision" message (&lt;a href="http://www.theartofvision.com/"&gt;&lt;span style="color:#000099;"&gt;website&lt;/span&gt;&lt;/a&gt;), and a broad set of innovation themed tracks addressing security, infrastructure, collaboration, leadership, culture and more. There were plenty of excellent, oft published speakers, industry leaders- one of my favorites being the pragmatic, candid security leadership guru &lt;a href="http://securityincite.com/"&gt;&lt;span style="color:#000099;"&gt;Mike &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;Rothman&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;. Also well represented, a &lt;a href="http://www.infotec.org/sponsors.aspx"&gt;&lt;span style="color:#000099;"&gt;sponsor mix&lt;/span&gt;&lt;/a&gt; across a wide solution space of products and services. It was also great seeing some folks I haven't seen in a while, catching up and talking shop, and making new contacts.&lt;br /&gt;&lt;br /&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"  style="color:#000099;"&gt;&lt;a href="http://www.infotec.org/"&gt;&lt;strong&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;Infotec's&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/span&gt; solid comeback with an unofficial 600+ reportedly attending this week at &lt;a href="http://en.wikipedia.org/wiki/Qwest_Center_Omaha"&gt;&lt;span style="color:#000099;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;Qwest&lt;/span&gt;&lt;/span&gt; Center Omaha&lt;/span&gt;&lt;/a&gt; made its mark- a success to build on bolstered with online and informative&lt;span style="color:#000099;"&gt; &lt;/span&gt;&lt;a href="http://www.infotec.org/sessions.aspx"&gt;&lt;span style="color:#000099;"&gt;session&lt;/span&gt;&lt;/a&gt; &lt;a href="http://blog.infotec.org/"&gt;&lt;span style="color:#000099;"&gt;&lt;strong&gt;blog summaries w/slides&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-1533618655507040174?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/1533618655507040174/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=1533618655507040174' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/1533618655507040174'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/1533618655507040174'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2009/04/yes-infotec-2009-rocked.html' title='Yes- Omaha&apos;s Infotec09 Rocked !'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-4289713185040166087</id><published>2009-04-06T06:54:00.000-05:00</published><updated>2009-04-07T23:43:17.668-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='FERC'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='Obama'/><category scheme='http://www.blogger.com/atom/ns#' term='NERC'/><category scheme='http://www.blogger.com/atom/ns#' term='cyber'/><category scheme='http://www.blogger.com/atom/ns#' term='critical infrastructure'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='federal'/><category scheme='http://www.blogger.com/atom/ns#' term='nuclear'/><title type='text'>Feds Backing Up Rhetoric with Cybersecurity Action -plus Joe Weiss's latest testimony</title><content type='html'>Lawmakers and the Obama Administration continue ratcheting up federal level attention to private sector critical infrastructure &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;cyber&lt;/span&gt; security defenses. Concurrently, with a 60-day review ordered by the Administration yet underway (&lt;a href="http://www.darkreading.com/security/government/showArticle.jhtml?articleID=215800529"&gt;&lt;span style="color:#000099;"&gt;interim update&lt;/span&gt;&lt;/a&gt; -3/3), the Senate is developing &lt;strong&gt;sweeping legislation that would &lt;/strong&gt;&lt;a href="http://www.washingtonpost.com/wp-dyn/content/article/2009/03/31/AR2009033103684_pf.html"&gt;&lt;span style="color:#000099;"&gt;&lt;strong&gt;Federalize &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;Cybersecurity&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;. Many of the proposals stem from recommendations provided within the seminal &lt;a href="http://www.csis.org/tech/cyber/"&gt;&lt;span style="color:#000099;"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;Cybersecurity&lt;/span&gt; for the 44&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;th&lt;/span&gt; Presidency study&lt;/span&gt;&lt;/a&gt; submitted last year by the Center for Strategic and International Studies, including:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;appointing a White House &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;cyber&lt;/span&gt; security "czar" with the authority to shut down government and private computer networks during a &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;-attack&lt;/li&gt;&lt;li&gt;charging the National Institute of Standards and Technology (&lt;a href="http://www.nist.gov/"&gt;&lt;span style="color:#000099;"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;NIST&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;) to establish "measurable and &lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;auditable&lt;/span&gt; &lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;cyber&lt;/span&gt; security standards" &lt;/li&gt;&lt;li&gt;mandating an ongoing, quadrennial review of the nation's &lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;cyber&lt;/span&gt; defenses&lt;/li&gt;&lt;li&gt;requiring licensing and certification of &lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;cyber&lt;/span&gt; security professionals.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Also notable, &lt;a href="http://www.nsa.gov/"&gt;&lt;span style="color:#000099;"&gt;NSA&lt;/span&gt;&lt;/a&gt;’s increasing role in such developments is causing growing concerns about privacy and pursuing an inherently flawed strategy by charging the organization with both ongoing intelligence gathering and an expansive new mission around national &lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;cyber&lt;/span&gt; defenses. The &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9129218"&gt;&lt;span style="color:#000099;"&gt;resignation of Rod &lt;span id="SPELLING_ERROR_12" class="blsp-spelling-error"&gt;Beckstrom&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; from an executive-level &lt;span id="SPELLING_ERROR_13" class="blsp-spelling-error"&gt;cyber&lt;/span&gt; security federal government position underscores such concerns.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;&lt;span id="SPELLING_ERROR_14" class="blsp-spelling-error"&gt;FERC&lt;/span&gt; Order - Nuclear "Regulatory Gap" Update&lt;/u&gt;&lt;em&gt;.&lt;/em&gt;&lt;/strong&gt;&lt;br /&gt;The Federal Energy Regulatory Commission (&lt;a href="http://www.ferc.gov/"&gt;&lt;span style="color:#000099;"&gt;&lt;span id="SPELLING_ERROR_15" class="blsp-spelling-error"&gt;FERC&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;) is pressing forward to resolve commercial nuclear &lt;span id="SPELLING_ERROR_16" class="blsp-spelling-error"&gt;cyber&lt;/span&gt; security jurisdictional “regulatory gap” concerns raised last year. A &lt;span id="SPELLING_ERROR_17" class="blsp-spelling-error"&gt;FERC&lt;/span&gt; issued &lt;a href="http://edocket.access.gpo.gov/2009/E9-6503.htm"&gt;“&lt;span style="color:#000099;"&gt;clarification&lt;/span&gt;”&lt;/a&gt; (~17 pages; Docket No. RM06-22-000; Order No. 706-B) on March 25&lt;span id="SPELLING_ERROR_18" class="blsp-spelling-error"&gt;th&lt;/span&gt; addresses previously requested industry input. It also concludes with a determination insisting that the portions of a nuclear power plant, not specifically addressed with tighter security program coverage in the forthcoming regulations from the Nuclear Regulatory Commission (&lt;a href="http://www.nrc.gov/"&gt;&lt;span style="color:#000099;"&gt;NRC&lt;/span&gt;&lt;/a&gt;), will be required to adhere to &lt;a href="http://www.nerc.com/page.php?cid=2"&gt;&lt;span style="color:#000099;"&gt;&lt;span id="SPELLING_ERROR_19" class="blsp-spelling-error"&gt;NERC&lt;/span&gt; Critical Infrastructure Protection (&lt;span id="SPELLING_ERROR_20" class="blsp-spelling-error"&gt;CIP&lt;/span&gt;) Reliability Standards&lt;/span&gt;&lt;/a&gt;. This rule became effective March 25, 2009. The combination of enhanced NRC requirements and the addition of &lt;span id="SPELLING_ERROR_21" class="blsp-spelling-error"&gt;FERC&lt;/span&gt;/&lt;span id="SPELLING_ERROR_22" class="blsp-spelling-error"&gt;NERC&lt;/span&gt; expectations into the mix make addressing &lt;span id="SPELLING_ERROR_23" class="blsp-spelling-error"&gt;cyber&lt;/span&gt; security an even more important licensing and compliance challenge for commercial nuclear power. &lt;em&gt;Some good news- &lt;/em&gt;&lt;span id="SPELLING_ERROR_24" class="blsp-spelling-error"&gt;FERC&lt;/span&gt; is providing implementation schedule flexibility which will first be addressed by the Electric Reliability Organization (&lt;span id="SPELLING_ERROR_25" class="blsp-spelling-error"&gt;ERO&lt;/span&gt;). &lt;a href="http://www.nerc.com/"&gt;&lt;span id="SPELLING_ERROR_26" class="blsp-spelling-error"&gt;NERC&lt;/span&gt;&lt;/a&gt;, as &lt;span id="SPELLING_ERROR_27" class="blsp-spelling-error"&gt;ERO&lt;/span&gt;, is is required to submit related compliance filing to &lt;span id="SPELLING_ERROR_28" class="blsp-spelling-error"&gt;FERC&lt;/span&gt; within 180 days.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;Congressional Hearing- Latest Round on &lt;span id="SPELLING_ERROR_29" class="blsp-spelling-error"&gt;Cybersecurity&lt;/span&gt; w/Joe Weiss&lt;/u&gt;.&lt;/strong&gt;&lt;br /&gt;On Thursday, March 19, 2009, the US Senate Committee on Commerce,Science, and Transportation held a hearing titled &lt;strong&gt;&lt;span id="SPELLING_ERROR_30" class="blsp-spelling-error"&gt;Cybersecurity&lt;/span&gt;: Assessing Our Vulnerabilities and Developing an Effective Defense&lt;/strong&gt; (&lt;a href="http://commerce.senate.gov/public/index.cfm?FuseAction=Hearings.Hearing&amp;amp;Hearing_ID=d59f00d0-0ad9-41cd-bde8-b96babb08b7e"&gt;&lt;span style="color:#000099;"&gt;&lt;span id="SPELLING_ERROR_31" class="blsp-spelling-error"&gt;webcast&lt;/span&gt;-&lt;em&gt;jump 12m to session start&lt;/em&gt;, testimony&lt;/span&gt;&lt;/a&gt;) Among the witnesses offering testimony was Mr. Joseph Weiss, a nuclear and industrial controls system (&lt;span id="SPELLING_ERROR_32" class="blsp-spelling-error"&gt;ICS&lt;/span&gt;) engineer, who long has been critical of most vendor, industry, and governmental/regulatory measures addressing related &lt;span id="SPELLING_ERROR_33" class="blsp-spelling-error"&gt;cyber&lt;/span&gt; security risks. His statement included pointing out how industrial control systems have experienced at least 125 significant &lt;span id="SPELLING_ERROR_34" class="blsp-spelling-error"&gt;cyber&lt;/span&gt; security incidents during the past decade (&lt;a href="http://commerce.senate.gov/public/_files/WeissTestimony.pdf"&gt;&lt;span style="color:#000099;"&gt;written testimony&lt;/span&gt;&lt;/a&gt;). The effects include environmental damage, mechanical damage and in once case, death. He said that a coordinated attack could have devastating consequences, "taking months to recover." &lt;em&gt;(Editorial note: Potential physical and other electronic systemic attacks yet to be substantively experienced remain a noteworthy risk with conceivably even lengthier recovery periods.) &lt;/em&gt;&lt;strong&gt;Worth watching&lt;/strong&gt; as each of the witnesses had their perspective backed with solid points followed by Q&amp;amp;A that pressed for answers around concerns raised and improvement approaches needed. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;It's increasingly clear that &lt;span id="SPELLING_ERROR_35" class="blsp-spelling-error"&gt;cyber&lt;/span&gt; security in critical infrastructure settings, especially the &lt;/strong&gt;&lt;a href="http://www.esisac.com/"&gt;&lt;strong&gt;Electric Sector&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;, will continue gathering growing attention at a national level that goes well beyond sensationalized media coverage. &lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-4289713185040166087?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/4289713185040166087/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=4289713185040166087' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/4289713185040166087'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/4289713185040166087'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2009/04/feds-rammping-up-cybersecurity-action.html' title='Feds Backing Up Rhetoric with Cybersecurity Action &lt;br&gt;&lt;i&gt;-plus Joe Weiss&apos;s latest testimony&lt;/i&gt;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-5541376376990590808</id><published>2009-03-21T23:15:00.000-05:00</published><updated>2009-04-06T18:56:30.291-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tim Roxey'/><category scheme='http://www.blogger.com/atom/ns#' term='Assante'/><category scheme='http://www.blogger.com/atom/ns#' term='CIP'/><category scheme='http://www.blogger.com/atom/ns#' term='Alerts'/><category scheme='http://www.blogger.com/atom/ns#' term='NERC'/><category scheme='http://www.blogger.com/atom/ns#' term='Critial Infrastructure Protection'/><category scheme='http://www.blogger.com/atom/ns#' term='Manager'/><title type='text'>Assante Pressing NERC Cyber Security Program Forward -Tim Roxey appointment and NERC Alerts changes</title><content type='html'>&lt;span style="font-size:78%;color:#000099;"&gt;Updated 3/29/2009&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.google.com/search?hl=en&amp;amp;rls=com.microsoft%3A*%3AIE-SearchBox&amp;amp;rlz=1I7SUNA&amp;amp;q=%22Michael+Assante%22+security"&gt;&lt;span style="color:#000099;"&gt;&lt;strong&gt;Michael &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;Assante&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt; continues making program progress at &lt;a href="http://www.nerc.com/"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;NERC&lt;/span&gt;&lt;/a&gt; since his &lt;a href="http://www.nerc.com/news_pr.php?npr=146"&gt;&lt;span style="color:#000099;"&gt;appointment in August 2008&lt;/span&gt;&lt;/a&gt; into a newly formed Chief Security Officer (&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;CSO&lt;/span&gt;) position. &lt;em&gt;His focus&lt;/em&gt;- establishing &lt;a href="http://www.nerc.com/page.php?cid=220"&gt;&lt;span style="color:#000099;"&gt;Critical Infrastructure Protection (&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;CIP&lt;/span&gt;)&lt;/span&gt;&lt;/a&gt; as one of the mainstream functions at &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;NERC&lt;/span&gt; alongside continuing standards development, compliance and enforcement, and reliability assessment programs. Some notable developments:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;The recent &lt;/strong&gt;&lt;a href="http://www.nerc.com/news_pr.php?npr=246"&gt;&lt;strong&gt;&lt;span style="color:#000099;"&gt;appointment of Tim &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;Roxey&lt;/span&gt; as &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;NERC&lt;/span&gt; as Manager of Critical Infrastructure Protection&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&lt;span style="color:#000099;"&gt;.&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;- Mr. &lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;Roxey&lt;/span&gt; has extensive commercial nuclear power physical and &lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;cyber&lt;/span&gt; security program experience.&lt;br /&gt;- He instrumentally promoted and supported the &lt;a href="http://www.nei.org/"&gt;&lt;span style="color:#000099;"&gt;commercial nuclear power industry&lt;/span&gt;&lt;/a&gt; initiative addressing &lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;cyber&lt;/span&gt; with &lt;a href="http://www.ieee.org/organizations/pes/meetings/gm2008/slides/NPII-Standardized-Cyber-Security-Programs-Initiative.pdf"&gt;&lt;span style="color:#000099;"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;NEI&lt;/span&gt; 04-04 &lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;Cyber&lt;/span&gt; Security Program for Power Reactors&lt;/span&gt; &lt;/a&gt;as a NRC endorsed “acceptable method” - well ahead of related further regulatory framework development and guidance now firming up. &lt;em&gt;I had an excellent learning opportunity working with Tim &lt;span id="SPELLING_ERROR_12" class="blsp-spelling-error"&gt;Roxey&lt;/span&gt; and team as an active Computer Security Standing Committee member back in 2006.&lt;/em&gt; The focus then was getting &lt;span id="SPELLING_ERROR_13" class="blsp-spelling-error"&gt;NEI&lt;/span&gt; 04-04 packaged up into &lt;span id="SPELLING_ERROR_14" class="blsp-spelling-error"&gt;rollout&lt;/span&gt; &lt;span id="SPELLING_ERROR_15" class="blsp-spelling-error"&gt;templated&lt;/span&gt;, presentation form for the fall &lt;a href="http://www.nitsl.org/"&gt;&lt;span style="color:#000099;"&gt;2006 &lt;span id="SPELLING_ERROR_16" class="blsp-spelling-error"&gt;NITSL&lt;/span&gt; workshop&lt;/span&gt;&lt;/a&gt;.&lt;br /&gt;- He extensively helped assess and address &lt;a href="http://www.cnn.com/2007/US/09/26/power.at.risk/index.html"&gt;&lt;span style="color:#000099;"&gt;Aurora vulnerability&lt;/span&gt;&lt;/a&gt; &lt;span id="SPELLING_ERROR_17" class="blsp-spelling-error"&gt;mitigations&lt;/span&gt;- working with &lt;a href="http://www.nei.org/"&gt;&lt;span id="SPELLING_ERROR_18" class="blsp-spelling-error"&gt;NEI&lt;/span&gt;&lt;/a&gt; to help ensure commercial nuclear generation stepped up and robustly addressed the issue. Tim &lt;span id="SPELLING_ERROR_19" class="blsp-spelling-error"&gt;Roxey&lt;/span&gt; also effectively provided &lt;a href="http://homeland.house.gov/hearings/index.asp?ID=95&amp;amp;subcommittee=12"&gt;&lt;span style="color:#000099;"&gt;congressional testimony on actions taken and completion status&lt;/span&gt;&lt;/a&gt; - a stark contrast to &lt;span id="SPELLING_ERROR_20" class="blsp-spelling-error"&gt;FERC&lt;/span&gt; and &lt;span id="SPELLING_ERROR_21" class="blsp-spelling-error"&gt;NERC&lt;/span&gt; testimony.&lt;br /&gt;&lt;em&gt;- Bottom Line:&lt;/em&gt; Tim &lt;span id="SPELLING_ERROR_22" class="blsp-spelling-error"&gt;Roxey's&lt;/span&gt; solid industry experience, connections, dedication and savvy add up to a very good move for &lt;span id="SPELLING_ERROR_23" class="blsp-spelling-error"&gt;NERC&lt;/span&gt;. &lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;A new &lt;span id="SPELLING_ERROR_24" class="blsp-spelling-error"&gt;NERC&lt;/span&gt; &lt;span id="SPELLING_ERROR_25" class="blsp-spelling-error"&gt;CIP&lt;/span&gt; Alert Communication Process.&lt;br /&gt;&lt;/strong&gt;- Communication will use specific email subject lines/levels:&lt;br /&gt;&lt;strong&gt;_ ADVISORY&lt;/strong&gt;: (Title) &lt;em&gt;- No Response Required&lt;br /&gt;&lt;/em&gt;_ &lt;strong&gt;RECOMMENDATION&lt;/strong&gt;: (Title) - &lt;em&gt;&lt;u&gt;Response Required&lt;/u&gt;.&lt;/em&gt;&lt;br /&gt;_ &lt;strong&gt;ESSENTIAL ACTION:&lt;/strong&gt; (Title) - &lt;em&gt;&lt;u&gt;Response Required&lt;/u&gt;.&lt;u&gt; &lt;/u&gt;&lt;/em&gt;&lt;br /&gt;- Entities acknowledgement required in 24 hours if issue rated higher than Advisory. &lt;em&gt;Grace period on this requirement extends to March 31, 2009 after which responses received after the 24-hour acknowledgement period will be noted as late or non-responsive.&lt;/em&gt; Additionally, more sensitive acknowledgement response information may need to be sent via paper until more secure electronic communication facilities established.&lt;br /&gt;- New alert handling &lt;span id="SPELLING_ERROR_26" class="blsp-spelling-error"&gt;signifiers&lt;/span&gt; will future clarify distribution restrictions.&lt;br /&gt;_ &lt;span style="color:#000000;"&gt;&lt;strong&gt;PUBLIC&lt;/strong&gt; (Green):&lt;/span&gt; No Restrictions. Will be posted to &lt;a href="http://www.nerc.com/page.php?cid=563"&gt;&lt;span style="color:#000099;"&gt;&lt;span id="SPELLING_ERROR_27" class="blsp-spelling-error"&gt;NERC&lt;/span&gt;’s website alert page&lt;/span&gt;&lt;/a&gt;.&lt;br /&gt;_ &lt;span style="color:#000000;"&gt;&lt;strong&gt;PRIVATE &lt;/strong&gt;(Yellow):&lt;/span&gt; Restrict to Internal Use and Necessary Consultants / Third-Party Providers&lt;br /&gt;_ &lt;strong&gt;SENSITIVE&lt;/strong&gt; (Red): Internal Use Only (Do Not Distribute Outside Your Company)&lt;br /&gt;_ &lt;strong&gt;CONFIDENTIAL&lt;/strong&gt; (Black): Limited Internal Distribution Decided Upon by an Officer of the Company&lt;br /&gt;- An “alerts manual” instructions book will be developed and released by March 31, 2009 to help entities better understand, organize, and train staff to support the alerts process.&lt;br /&gt;&lt;em&gt;- More background:&lt;/em&gt; &lt;a href="http://www.nerc.com/fileUploads/File/Training/Alerts_Webinar_FINAL-web.pdf"&gt;Alerts Distribution, Reporting &amp;amp; FAQ - Michael &lt;span id="SPELLING_ERROR_28" class="blsp-spelling-error"&gt;Assante&lt;/span&gt; &amp;amp; Doug &lt;span id="SPELLING_ERROR_29" class="blsp-spelling-error"&gt;Newbauer&lt;/span&gt; Jan 22, 2009&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;- &lt;span style="color:#000099;"&gt;&lt;u&gt;&lt;strong&gt;Update 3/28-&lt;/strong&gt;&lt;/u&gt;&lt;/span&gt; On March 24&lt;span id="SPELLING_ERROR_30" class="blsp-spelling-error"&gt;th&lt;/span&gt;, Doug &lt;span id="SPELLING_ERROR_31" class="blsp-spelling-error"&gt;Newbauer&lt;/span&gt;, Manager of &lt;span id="SPELLING_ERROR_32" class="blsp-spelling-error"&gt;NERC&lt;/span&gt; Alerts, indicated that the deadline for mandatory 24 hours response on alerts will be extended: &lt;em&gt;"In response to feed back from registered entities and because &lt;span id="SPELLING_ERROR_33" class="blsp-spelling-error"&gt;NERC&lt;/span&gt; is replacing the current Alerts application, &lt;span id="SPELLING_ERROR_34" class="blsp-spelling-error"&gt;NERC&lt;/span&gt; is delaying the 24 hour response requirement scheduled to begin April 1, 2009, until the new application is on line and operational."&lt;br /&gt;- &lt;/em&gt;The application is expected to be prepared and &lt;span id="SPELLING_ERROR_35" class="blsp-spelling-corrected"&gt;released&lt;/span&gt; 3Q2009.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-5541376376990590808?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/5541376376990590808/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=5541376376990590808' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/5541376376990590808'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/5541376376990590808'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2009/03/assante-pressing-nerc-cyber-security.html' title='Assante Pressing NERC Cyber Security Program Forward&lt;br&gt;&lt;i&gt; -Tim Roxey appointment and NERC Alerts changes&lt;/i&gt;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-4729426796645533441</id><published>2009-03-01T18:39:00.000-06:00</published><updated>2009-08-10T19:24:04.972-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Targeted Attacks'/><category scheme='http://www.blogger.com/atom/ns#' term='DNS'/><category scheme='http://www.blogger.com/atom/ns#' term='ISP'/><category scheme='http://www.blogger.com/atom/ns#' term='Time Warner'/><category scheme='http://www.blogger.com/atom/ns#' term='incident'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber Security Program'/><title type='text'>Significant, targeted attacks even against ISPs?-Absolutely! (just ask Time Warner)</title><content type='html'>One might think that larger financial institutions and other entities with directly exploitable financial or personal information remain the major nexus of criminal &lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; problems. However, even consumer grade &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;ISPs&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; are increasing facing challenges. Time Warner's drawn out efforts now in the limelight represent just the latest example of an organization scrambling to address service and &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-corrected"&gt;reputation&lt;/span&gt; impacts from a disrupting &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; security attack.&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;February 28, 2009&lt;br /&gt;&lt;br /&gt;During the past week, hackers have launched a series of attacks on Time Warner Cable's servers. Time Warner Cable is working with law enforcement agencies to resolve these crimes.&lt;br /&gt;&lt;br /&gt;As a result of these attacks, you may have experienced a temporary "outage" when attempting to surf the Web, including an intermittent "page cannot be displayed" error message. The outages did not result in services being 100% unavailable; and were limited to sporadic timeouts which appeared to be random events. Some users may have experienced a total disconnect, however. These types of attacks are not uncommon, especially for a network as large as ours. We suspect that the attackers are using "zombie computers," or hijacking unsuspecting subscribers' machines to perpetrate the attack without its owner's knowledge.&lt;br /&gt;&lt;br /&gt;All of us at &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;TWC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; take these attacks extremely seriously. As previously mentioned, we are working with the appropriate law enforcement agencies that specialize in investigating these types of crimes. We will pursue prosecution of all perpetrators to the fullest extent of the law. We apologize for the inconvenience that these attacks may have caused and encourage you to report any suspicious activity. Instructions for reporting security abuse are located at &lt;/strong&gt;&lt;a href="http://help.rr.com/" target="_blank"&gt;&lt;strong&gt;http://help.rr.com&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;.&lt;br /&gt;&lt;br /&gt;Sincerely,&lt;br /&gt;Time Warner Cable&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;More: &lt;a href="http://news.google.com/news?ned=us&amp;amp;hl=en&amp;amp;q=time+warner+attack"&gt;Google News Search: Time Warner Attack&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The persistent assault centers on impacting Time Warner’s &lt;a href="http://en.wikipedia.org/wiki/Domain_name_system"&gt;domain naming system (&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;DNS&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;)&lt;/a&gt; services. Given that &lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;DNS&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; supports domain name to &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-corrected"&gt;Internet&lt;/span&gt; address resolution functions, e.g., when &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-corrected"&gt;Internet&lt;/span&gt; surfing, an easy mitigation for customers is to use an alternative provider, such as &lt;a href="http://www.opendns.com/"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;OpenDNS&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;. I've been using both Time Warner and &lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;OpenDNS&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; in my home networking &lt;span id="SPELLING_ERROR_9" class="blsp-spelling-corrected"&gt;environment&lt;/span&gt; for years with great results. &lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;OpenDNS&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; also helps protect users from visiting known harmful and other inappropriate Internet sites.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Much attention is put on specific, in-scope compliance issues within critical infrastructure organizations. The obvious twist is that even basic, persistent attacks increasingly are a factor in considering overall business risk to service and reputation. Additionally, &lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_12" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; security problems that affect non-operational, business network settings, also increase the risk of "pivot attacks" creating more serious operational issues that regulators and senior management are acutely concerned with.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;From a broader perspective, this issue saliently points out how even narrow, basic attacks can impact an organization and their customers. Critical infrastructure organizations risk even larger potential impacts steming from such issues- driving the need for ongoing cyber security improvements. &lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-4729426796645533441?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/4729426796645533441/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=4729426796645533441' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/4729426796645533441'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/4729426796645533441'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2009/03/targeted-attacks-against-isps.html' title='Significant, targeted attacks even against ISPs?&lt;br&gt;-Absolutely! (just ask Time Warner)'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-6819698538121751576</id><published>2009-02-10T22:45:00.002-06:00</published><updated>2011-10-26T20:27:59.067-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Top10'/><category scheme='http://www.blogger.com/atom/ns#' term='Information Security Program'/><category scheme='http://www.blogger.com/atom/ns#' term='Corporate'/><category scheme='http://www.blogger.com/atom/ns#' term='Organization'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber Security Program'/><title type='text'>Top 10 Reasons to NOT Have a  Corporate Cyber Security Program</title><content type='html'>&lt;p&gt;&lt;span style="font-size:78%;color:#000099;"&gt;Updated 8/2/2009&lt;br /&gt;&lt;/span&gt;I regularly walk past a humorous list of posted reasons why a corporate project management office is &lt;em&gt;not&lt;/em&gt; needed based on Jim Chapman’s 1996 list of “&lt;a href="http://www.hyperthot.com/proj_2.htm"&gt;Top 10 Reasons NOT to Use Project Management&lt;/a&gt;” Considering the focus on cost and change challenges many IT organizations are facing, this insightful list inspired me to come up with my own Top 10- enjoy:&lt;/p&gt;&lt;p align="left"&gt;&lt;br /&gt;&lt;u&gt;&lt;strong&gt;&lt;span style="font-family:verdana;font-size:130%;color:#000099;"&gt;Top 10 Reasons to NOT Have a Corporate Cyber Security Program&lt;/span&gt;&lt;/strong&gt;&lt;/u&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p align="left"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;&lt;strong&gt;10.&lt;/strong&gt; Our internal and external customers really love us, so they do not care if company information and systems are appropriately and consistently secured.&lt;/span&gt;&lt;/p&gt;&lt;p align="left"&gt;&lt;span style="font-family:verdana;"&gt;&lt;strong&gt;9.&lt;/strong&gt; Corporately organizing to manage &lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; security risk is not compatible with our culture, and the last thing we need around this place is change.&lt;/p&gt;&lt;p align="left"&gt;&lt;span style="font-family:verdana;"&gt;&lt;strong&gt;8.&lt;/strong&gt; All &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; security work is easy, with little &lt;span id="SPELLING_ERROR_4" class="blsp-spelling-corrected"&gt;guidance&lt;/span&gt;, direction, or accountability needed, and does not have cost, schedule, or any other significant technical, managerial or operational risks anyway.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;7. &lt;/strong&gt;We are not smart enough to develop an enabling &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_12" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; security strategy, program, or architecture without stifling creativity and offending our silos of technical and managerial geniuses.&lt;/p&gt;&lt;p align="left"&gt;&lt;span style="font-family:verdana;"&gt;&lt;strong&gt;6.&lt;/strong&gt; We might have to understand our customers’ requirements and document a lot of stuff for review, input and approval which then would need to be maintained and that is such a bother.&lt;/span&gt;&lt;/p&gt;&lt;p align="left"&gt;&lt;span style="font-family:verdana;"&gt;&lt;strong&gt;5.&lt;/strong&gt; Understanding, applying, and maintaining specific, definitive &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_13" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; security measures and clearly communicating actual status requires integrity and courage, so they would have to pay me extra.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;4.&lt;/strong&gt; Our bosses will not provide support needed for results; they want us to ensure regulatory and legal requirements, congressional concerns, and other related risks are managed through magic.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;3.&lt;/strong&gt; We would have even lengthier debates and still end up applying &lt;span id="SPELLING_ERROR_7" class="blsp-spelling-corrected"&gt;arbitrary&lt;/span&gt;, overly burdensome &lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_14" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; security measures to all projects regardless of size, complexity, or risk and that would be stupid.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;2.&lt;/strong&gt; I know there is well-developed &lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_15" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; security body of knowledge that is applicable to the work I am doing, but it is too hard to understand, apply and help us improve with anyway.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;1.&lt;/strong&gt; We figure it is more beneficial to put increasing time and money into &lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_16" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; security &lt;span id="SPELLING_ERROR_8" class="blsp-spelling-corrected"&gt;independently&lt;/span&gt; in various areas and accept a growing, uneven and obscure patchwork of results than to have an organized, more transparent company approach. &lt;/p&gt;&lt;p align="left"&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="color:#000099;"&gt;&lt;strong&gt;Disclaimer:&lt;/strong&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="color:#000000;"&gt;&lt;em&gt;While there may be times when one or more of the Top 10 resonate, an effective &lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_12" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_17" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;&lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;em&gt; security program should help clearly refute this list at every opportunity.&lt;/em&gt; &lt;/p&gt;&lt;p align="left"&gt;&lt;span style="font-family:Verdana;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p align="left"&gt;There continues to be sporadic debate about whether or not IT Security should be viewed as a profit center versus the cost center realty that the vast majority of practitioners work in, e.g., Mike &lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;Rothman&lt;/span&gt;’s recent commentary: &lt;a href="http://securityincite.com/blog/mike-rothman/compliance-is-so-a-cost-center"&gt;Compliance is SO a Cost Center&lt;/a&gt;. Regardless of how security is organized and executed, the best justification approach around security improvements focuses on business benefit in the form of cost savings or value, centered on mutually well understood reality.&lt;/p&gt;&lt;p align="left"&gt;Many organizations are under increasing pressure to deliver more with internal resources, including addressing growing security expectations, and keeping costs contained. While the means and alignment to meaningfully execute and maintain security improvements remains vital, an even more important success factor in my opinion to manage such risk over the long term requires clearly articulating an overall company program. The program - however thick or thin in scope and resourcing - provides the means for ongoing leadership driven attention to risk management, policy, goals, results, preparations, with sufficient transparency and organizational support across various groups, compliance programs, and increasingly interested and engaged management.&lt;/p&gt;&lt;p align="left"&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-6819698538121751576?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/6819698538121751576/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=6819698538121751576' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/6819698538121751576'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/6819698538121751576'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2009/02/top-10-reasons-to-not-have-corporate.html' title='Top 10 Reasons to NOT Have a  Corporate Cyber Security Program'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-5825412409611062382</id><published>2009-01-06T00:16:00.001-06:00</published><updated>2009-02-07T22:29:44.461-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cyber security top stories 2008 predictions 2009 control system'/><title type='text'>Cyber Security Happy New Year 2009 - Perspective and Predictions </title><content type='html'>&lt;span style="font-size:78%;color:#000099;"&gt;Updated 1/31/2009&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;&lt;/u&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#990000;"&gt;&lt;u&gt;2008 Perspective&lt;/u&gt; &lt;span style="color:#000099;"&gt;- &lt;/span&gt;&lt;em&gt;&lt;span style="color:#000099;"&gt;hot stories and list of lists&lt;/span&gt;.&lt;/em&gt;&lt;/span&gt;&lt;/strong&gt;&lt;span style="color:#990000;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://securitywatch.eweek.com/exploits_and_attacks/most_popular_sites_were_hacked_in_08.html"&gt;&lt;span style="color:#000099;"&gt;Most Popular Sites Were Hacked in '08&lt;/span&gt;&lt;/a&gt; - eWeek, Jan 22, 2009&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/12/08/AR2008120801944.html"&gt;&lt;span style="color:#000099;"&gt;More Cyber Security Regulations Recommended&lt;/span&gt;&lt;/a&gt; - Washington Post, Dec 8, 2008&lt;/li&gt;&lt;li&gt;&lt;a href="http://sip-trunking.tmcnet.com/topics/security/articles/47404-cisco-cyber-attacks-growing-more-sophisticated-targeted.htm"&gt;&lt;span style="color:#000099;"&gt;Cisco: Cyber Attacks Are Growing More Sophisticated, Targeted&lt;/span&gt;&lt;/a&gt;, TMCnet, Dec 15, 2008 &lt;em&gt;- more:&lt;/em&gt; “&lt;a href="http://www.cisco.com/go/securityreport"&gt;&lt;span style="color:#000099;"&gt;Cisco Annual Security Report&lt;/span&gt;&lt;/a&gt;” for 2008 &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.circleid.com/posts/homeland_security_cybercrisis_plan/"&gt;&lt;span style="color:#000099;"&gt;US Homeland Security Still Without Cybercrisis Plan&lt;/span&gt;&lt;/a&gt;, CNET News, Dec 19, 2008 &lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1343727,00.html"&gt;&lt;span style="color:#000099;"&gt;Top Five Cyber Security Stories&lt;/span&gt;&lt;/a&gt; - Information Security Magazine, Dec 29, 2008&lt;br /&gt;1. SQL injection attacks&lt;br /&gt;2. Hannaford Brothers supermarket breach&lt;br /&gt;3. Dan Kaminsky and DNS dangers&lt;br /&gt;4. Microsoft Vista adoption issues&lt;br /&gt;5. Slowing the spam surge&lt;br /&gt;&lt;em&gt;Also noted:&lt;br /&gt;- &lt;/em&gt;&lt;a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1299078,00.html"&gt;&lt;span style="color:#000099;"&gt;Linux Kernel attack code worries security experts&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#000099;"&gt;&lt;br /&gt;&lt;/span&gt;- &lt;a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1319861,00.html"&gt;&lt;span style="color:#000099;"&gt;Microsoft addresses XSS in Internet Explorer&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#000099;"&gt;&lt;br /&gt;&lt;/span&gt;- &lt;a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1332898,00.html"&gt;&lt;span style="color:#000099;"&gt;New attacks reveal fundamental problems with TCP&lt;/span&gt;&lt;/a&gt; i.e. &lt;a href="http://www.grc.com/securitynow.htm#164"&gt;&lt;span style="color:#660000;"&gt;sockstress &lt;/span&gt;&lt;/a&gt;&lt;br /&gt;- &lt;a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1335819,00.html"&gt;&lt;span style="color:#000099;"&gt;Microsoft releases Out of Cycle Windows patch to stop worm attack&lt;/span&gt;&lt;/a&gt; &lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;a title="Top Ten SCADA Security Stories of 2008" href="http://www.digitalbond.com/index.php/2009/01/01/top-ten-scada-security-stories-of-2008/"&gt;&lt;span style="color:#000099;"&gt;Top Ten SCADA Security Stories of 2008&lt;/span&gt;&lt;/a&gt; - Digital Bond&lt;br /&gt;1. Vulnerabilities now being discovered by non-control system companies e.g. Core&lt;br /&gt;2. Process Control System Forum (PCSF) demise&lt;br /&gt;3. FERC throws NERC under the bus / Congress warms to regulation&lt;br /&gt;4. Published control system exploit code in form of metasploit module - yikes&lt;br /&gt;5. Blue Ribbon CSIC cyber security recommendations for Obama&lt;br /&gt;6. Very active &lt;a href="http://news.infracritical.com/pipermail/scadasec/"&gt;&lt;span style="color:#000099;"&gt;SCADASEC list&lt;/span&gt;&lt;/a&gt; started&lt;br /&gt;7. Control System vulnerabilities as “Candy To The Press”&lt;br /&gt;8. &lt;a href="http://www.digitalbond.com/wiki/index.php/Bandolier"&gt;&lt;span style="color:#000099;"&gt;Bandolier Security Audit Files&lt;/span&gt;&lt;/a&gt; audit hundreds of configuration elements.&lt;br /&gt;9. CIA FUD &lt;a href="http://www.digitalbond.com/index.php/2008/01/21/lack-of-information-and-parsing-words/"&gt;&lt;span style="color:#000099;"&gt;quote from Tom Donahue from CIA&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;10. Water Sector roadmap progress.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="color:#990000;"&gt;&lt;u&gt;2009 Predictions&lt;/u&gt; &lt;/span&gt;&lt;em&gt;&lt;span style="color:#000099;"&gt;- more hot stories and list of lists.&lt;/span&gt; &lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.controleng.com/article/CA6625494.html?industryid=48515"&gt;&lt;span style="color:#000099;"&gt;Cyber security issues take center stage in 2009&lt;/span&gt;&lt;/a&gt;, Control Engineering, IL - Jan 5, 2009 &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.csoonline.com/article/470968/Cyber_Crime_The_Mega_Threat"&gt;&lt;span style="color:#000099;"&gt;Cyber Crime: The 2009 Mega Threat&lt;/span&gt;&lt;/a&gt;- CSO Magazine, Dec 16, 2008 &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.rightsidenews.com/200901143328/homeland-security/combating-cyber-crime-global-network-operates-24/7.html"&gt;&lt;span style="color:#000099;"&gt;Combating Cyber Crime: Global Network Operates 24/7&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#000099;"&gt;,&lt;/span&gt; FBI, Jan 14, 2009- “sophistication of our adversaries is growing” &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.vnunet.com/vnunet/news/2234667/hackers-exploit-economic"&gt;&lt;span style="color:#000099;"&gt;Hackers to exploit economic downturn in 2009&lt;/span&gt;&lt;/a&gt; - VNUNet.com, UK - Jan 20, 2009 &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.itexaminer.com/mcafee-publishes-2009-threat-predictions.aspx"&gt;&lt;span style="color:#000099;"&gt;McAfee publishes 2009 threat predictions&lt;/span&gt;&lt;/a&gt; IT Examiner, India - Jan 21, 2009 &lt;/li&gt;&lt;li&gt;&lt;a href="http://security.cbronline.com/news/spam_still_causing_it_headache_reports_220109"&gt;&lt;span style="color:#000099;"&gt;Spam still causing IT headache: reports&lt;/span&gt;&lt;/a&gt; Computer Business Review, UK - Jan 22, 2009 &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.govtech.com/gt/614532"&gt;&lt;span style="color:#000099;"&gt;Security Expert: Fight Cyber-Crime Through Procurement&lt;/span&gt;&lt;/a&gt;, Government Technology, CA - Jan 30, 2009 &lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.zdnetasia.com/news/security/0,39044215,62049756,00.htm"&gt;&lt;span style="color:#000099;"&gt;Top 9 security predictions for 2009&lt;/span&gt;&lt;/a&gt;, ZDNet Australia, Jan 5, 2009&lt;br /&gt;1. More bang for the buck: Security consolidation and then some&lt;br /&gt;2. Information security lockdown &lt;em&gt;e.g. mandatory PCI application firewalls&lt;br /&gt;&lt;/em&gt;3. Web 2.0 vulnerabilities multiply&lt;br /&gt;4. Bigger pipes, faster speed: Letting in the good, bad and ugly&lt;br /&gt;5. The next biggest threat to mobile security: 3G&lt;br /&gt;6. More cash to flow in the digital underground&lt;br /&gt;7. Let the games begin – more cyber mayhem in the gaming world&lt;br /&gt;8. Premeditated, targeted attacks on the rise&lt;br /&gt;9. Law enforcement unite online &lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.sans.edu/resources/securitylab/2009_predictions.php"&gt;&lt;span style="color:#000099;"&gt;SANS Technology Institute: 2009 Security Predictions&lt;/span&gt;&lt;/a&gt; – Jan 21, 2009&lt;br /&gt;Broad mix of contributions: more control system issues, compromise of large PCI compliant company (fulfilled), etc&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-5825412409611062382?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/5825412409611062382/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=5825412409611062382' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/5825412409611062382'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/5825412409611062382'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2009/01/cyber-security-happly-new-year-2009.html' title='Cyber Security Happy New Year 2009 &lt;br&gt;&lt;i&gt;- Perspective and Predictions &lt;/i&gt;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-6731936541294335258</id><published>2008-12-28T20:45:00.000-06:00</published><updated>2009-02-14T20:49:48.339-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security breach bank outsourcing secruity risk Satyam Computer Services'/><title type='text'>Cyber Security Debacle- Update on World Bank 'Unprecedented Crisis'</title><content type='html'>It’s been months of stonewalling and denials during a &lt;a href="http://www.foxnews.com/story/0,2933,470964,00.html"&gt;&lt;strong&gt;&lt;span style="color:#000099;"&gt;series of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;FOXNews&lt;/span&gt;&lt;/span&gt;.com reports&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt; covering a variety of in-house World Bank scandals including (i) targeted &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;cyber&lt;/span&gt;&lt;/span&gt; security attacks breaching their most sensitive financial data and (ii) corruption issues with sanctions against at least one supplier determined guilty of wrongdoing. The latest twist, a leading India-based information technology vendor, &lt;a href="http://www.satyam.com/"&gt;&lt;strong&gt;&lt;span style="color:#000099;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;Satyam&lt;/span&gt;&lt;/span&gt; Computer Services&lt;/span&gt;&lt;/strong&gt; &lt;/a&gt;was barred in February from all business with the bank for a period of eight years — the ban started in September.&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Some highlights:&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/u&gt;&lt;br /&gt;The &lt;a href="http://www.worldbank.org/"&gt;&lt;strong&gt;&lt;span style="color:#000099;"&gt;World Bank&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt; provides financial and technical assistance to developing countries, governed by a board of 180+ member nations, with the mission “Working for a World Free of Poverty.”&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;"From 2003 through 2008, as FOX News reported, the World Bank paid &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;Satyam&lt;/span&gt;&lt;/span&gt; hundreds of millions of dollars to write and maintain all the software used by the bank throughout its global information network, including its back-office operations. The engagement scope involved overseeing data that ranged from accounting and personnel records to trust funds administered for many of the world's richest nations."&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;"&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;Satyam&lt;/span&gt;&lt;/span&gt; was straying badly across the bank's ethical warning lines. In 2005, the bank's chief information officer, Mohamed &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;Muhsin&lt;/span&gt;&lt;/span&gt;, was ousted after being accused of improperly buying preferential stock options from &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;Satyam&lt;/span&gt;&lt;/span&gt;, even as he awarded the firm major contracts. A top-secret investigation led to &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;Muhsin&lt;/span&gt;&lt;/span&gt; being banned permanently from the bank in January 2007. But for reasons that remain unclear, &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;Satyam&lt;/span&gt;&lt;/span&gt; was allowed to remain in control of the bank's information network until early October 2008"&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;According to &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;FoxNews&lt;/span&gt;&lt;/span&gt;.com reporting in October, World Bank employees were ordered to change their passwords three times over a three month period as a response to the attacks, which spanned somewhere between 18 and 40 servers in multiple hacks. According to the report, there were six major break-ins in the past year, and that at least five servers containing sensitive data were exposed. &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;FoxNews&lt;/span&gt;&lt;/span&gt; obtained apparent internal e-mail messages regarding the attacks characterizing a complicated series of events and the agency’s response to them.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;“In a frantic midnight &lt;a href="http://www.foxnews.com/projects/pdf/UnprecedentedCrisisEmail.pdf"&gt;&lt;strong&gt;&lt;span style="color:#000099;"&gt;July 22&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;nd&lt;/span&gt;&lt;/span&gt; e-mail&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;, e-mail to colleagues, the bank's senior technology manager &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;Rakesh&lt;/span&gt;&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;Asthana&lt;/span&gt;&lt;/span&gt;, referred to the situation as an "unprecedented crisis” and that "the passwords that have been compromised may have accessed data." &lt;a href="http://www.foxnews.com/projects/pdf/WorldBankDoc1.pdf"&gt;&lt;strong&gt;&lt;span style="color:#000099;"&gt;An e-mail from July 10&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt; explains that a minimum of 18 servers may have been compromised and that five of them contained sensitive data. Yet an &lt;a href="http://www.foxnews.com/projects/pdf/DePoerckmemo.pdf"&gt;&lt;strong&gt;&lt;span style="color:#000099;"&gt;Aug. 19 memo&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt; from the bank's &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;CIO&lt;/span&gt;&lt;/span&gt;, Guy-Pierre De &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_15"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_15"&gt;Poerck&lt;/span&gt;&lt;/span&gt;, downplays the severity of the situation. The staff memo says that controls on external Web sites have been tightened, that passwords have been reset, and that &lt;a href="http://www.rsa.com/node.aspx?id=1156"&gt;&lt;strong&gt;&lt;span style="color:#000099;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_16"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_16"&gt;RSA&lt;/span&gt;&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_17"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_17"&gt;SecurID&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt; tokens have been deployed for Web mail access. It concludes that "there is no evidence that bank staff personal information is at risk from the recent external attempts."&lt;br /&gt;&lt;em&gt;Editorial note: Guy-Pierre De &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_18"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_18"&gt;Poerck&lt;/span&gt;&lt;/span&gt; no longer works at World Bank.&lt;br /&gt;&lt;br /&gt;&lt;/em&gt;&lt;/li&gt;&lt;li&gt;“It is still not known how much information was stolen. But sources inside the bank confirm that servers in the institution's highly-restricted treasury unit were deeply penetrated with spy software in April. Invaders also had full access to the rest of the bank's network for nearly a month in June and July. In total, at least six major intrusions &lt;em&gt;— two of them using the same group of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_19"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_19"&gt;IP&lt;/span&gt;&lt;/span&gt; addresses originating from China&lt;/em&gt; — have been detected at the World Bank since the summer of 2007.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;“It may be the worst security breach ever at a global financial institution. And it has left bank officials scrambling to try to understand the nature of the year-long &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_20"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_20"&gt;cyber&lt;/span&gt;&lt;/span&gt;-assault, while also trying to keep the news from leaking to the public."&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.foxnews.com/video-search/m/21175455/exclusive_world_bank_hacked.htm?pageid=27037"&gt;&lt;span style="color:#000099;"&gt;&lt;strong&gt;Video Interview: World Bank Hack&lt;/strong&gt;&lt;/span&gt; &lt;/a&gt;- &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_21"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_21"&gt;FOXNews&lt;/span&gt;&lt;/span&gt; 10/10/2008&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;u&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Some thoughts:&lt;/span&gt;&lt;/strong&gt;&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;While this isn't your typical bank, banking and the financial sector as a whole is known to generally have &lt;em&gt;much better&lt;/em&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_22"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_22"&gt;cyber&lt;/span&gt;&lt;/span&gt; security than most sectors. It’s alarming that this situation drug out for so long after surfacing internally.&lt;/p&gt;&lt;p&gt;Besides the alleged repeated &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_23"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_23"&gt;CIO&lt;/span&gt;&lt;/span&gt;-level inside dealing by a gorilla-scale &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_24"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_24"&gt;outsourcer&lt;/span&gt;&lt;/span&gt;, a more fundamental issue was the abdication by management in addressing information security risks. Having &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_25"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_25"&gt;CIOs&lt;/span&gt;&lt;/span&gt; released from &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_26"&gt;employment&lt;/span&gt; and named security leadership temporarily in charge will help. Perhaps large gaps in fundamental information security controls are now finally being addressed. Certainly a lack of &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_27"&gt;programmatic&lt;/span&gt; incident handling preparations contributed to the problems before Fox News broke the story. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;&lt;span style="color:#660000;"&gt;Before saying “It can’t happen here.”&lt;/span&gt; &lt;/u&gt;&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;How well is your incident handling program developed? What happens to you and your organization if or when breached by targeted attacks? What about your increasing exposure with outsourcing and how risk is being managed? How about robust enclaves for your critical systems? Do you really have defense in depth with graded, inside-out protective measures? Are there definitive, &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_26"&gt;complimentary&lt;/span&gt;, and &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_28"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_27"&gt;auditable&lt;/span&gt;&lt;/span&gt; MOT controls, i.e., &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_28"&gt;&lt;em&gt;managerial&lt;/em&gt;&lt;/span&gt;, &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_29"&gt;&lt;em&gt;operational&lt;/em&gt;&lt;/span&gt;, and &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_30"&gt;&lt;em&gt;technical&lt;/em&gt;&lt;/span&gt;, in place for your more critical settings that clearly provide and support defense in depth &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_29"&gt;capabilities&lt;/span&gt;, i.e., deny, detect, deter, recover? Who is watching the watchers? How is management being kept abreast of status? Are there regular, transparent reviews involving key internal stakeholders? Are there improvement planning cycles involving &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_30"&gt;decision&lt;/span&gt; makers and are the plans being completed and results objectively reviewed? &lt;em&gt;&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="color:#3333ff;"&gt;&lt;strong&gt;&lt;span style="color:#660000;"&gt;- Think could only happen in the financial sector?&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;What if emergent problems persisted and pulled you and your information security team deeper into the mix after repeated missteps? How do you ensure that your response is viewed as part of the solution and not increasingly part of the problem? What if your organizational leadership "duck and covers" when pressed by providing a shifting story while investigative reporting eagerly pry out pieces of the truth and report it all? &lt;/p&gt;&lt;p&gt;&lt;span style="color:#660000;"&gt;&lt;strong&gt;- Are you just another easy mark?&lt;/strong&gt;&lt;/span&gt; &lt;/p&gt;&lt;p&gt;Just how developed is your incident handling policy and procedures with senior management support to help address when &lt;em&gt;escalating &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_31"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_31"&gt;cyber&lt;/span&gt;&lt;/span&gt; security problems really hit the fan&lt;/em&gt;?&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="color:#660000;"&gt;- Still comfortable?&lt;/span&gt;&lt;/strong&gt; &lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More:&lt;br /&gt;&lt;/strong&gt;- &lt;a href="http://www.informationweek.com/news/security/attacks/showArticle.jhtml?articleID=211100222"&gt;&lt;span style="color:#000099;"&gt;World Bank Besieged By Hackers, Or Not&lt;/span&gt;&lt;/a&gt;, Information Week, 10/10/2008&lt;br /&gt;- &lt;a class="l" onmousedown="return clk(this.href,'','','res','1','')" href="http://www.foxnews.com/story/0,2933,458085,00.html"&gt;&lt;span style="color:#000099;"&gt;World Bank Removes Chief Information Officer&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#000099;"&gt;,&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_32"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_32"&gt;FOXNews&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;.com, 11/27/2008&lt;br /&gt;- &lt;a href="http://www.foxnews.com/story/0,2933,470964,00.html"&gt;&lt;span style="color:#000099;"&gt;World Bank Admits Top Tech Vendor Debarred for 8 Years&lt;/span&gt;&lt;/a&gt;, &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_33"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_33"&gt;FOXNews&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;.com, 12/24/2008&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-6731936541294335258?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/6731936541294335258/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=6731936541294335258' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/6731936541294335258'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/6731936541294335258'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2008/12/cyber-security-debacle-update-world.html' title='Cyber Security Debacle- Update on World Bank &apos;Unprecedented Crisis&apos;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-8201514769817150933</id><published>2008-12-07T11:28:00.000-06:00</published><updated>2009-01-04T02:15:28.493-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NERC CIP Revisions Comment Period  FERC &quot;Order 706&quot;'/><title type='text'>Clock is Ticking for First Round of Pending Changes to NERC CIP Standards - Comments due Jan 5th </title><content type='html'>&lt;div align="left"&gt;&lt;strong&gt;Driven by &lt;a class="l" onmousedown="return clk(this.href,'','','res','3','')" href="http://www.ferc.gov/whats-new/comm-meet/2008/011708/E-2.pdf"&gt;&lt;span style="color:#000099;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;Cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Standards Final Rule - &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;FERC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Order 706&lt;/span&gt;&lt;/a&gt;&lt;/strong&gt;&lt;span style="color:#000099;"&gt;,&lt;/span&gt; the first &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_2"&gt;revision&lt;/span&gt; to &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;NERC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;CIPs&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; addressing &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; security requirements for bulk electric operations is out for review and comments by Jan 5&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;th&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;, 2009. This round of changes include removal of &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_7"&gt;significant&lt;/span&gt; amount of wiggle room based on "business judgement", includes explicit senior management approval of risk methodology (not just critical assets lists), background checking must be completed before permitting access (not in &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;parallel&lt;/span&gt;), and tightens up &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;timeframe&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; requirement for addressing security issues among other changes. &lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;div align="left"&gt;&lt;em&gt;"Emphasis on Order 706 directive for &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;NERC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; to address revisions to the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;CIP&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; standards considering applicable feature of the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;NIST&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Security Risk Management Framework among other resources.&lt;/em&gt; "&lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="left"&gt;While this process with &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;NERC&lt;/span&gt;&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;CIPs&lt;/span&gt;&lt;/span&gt; may seem difficult, at least there is the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;&lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_12"&gt;benefit&lt;/span&gt;&lt;/span&gt; of continuity. Congressional testimony last year and this year raised serious questions about &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;NERC's&lt;/span&gt;&lt;/span&gt; ability to be an effective &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;ERO&lt;/span&gt;&lt;/span&gt; for &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_15"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_15"&gt;FERC&lt;/span&gt;&lt;/span&gt; &lt;em&gt;- &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_16"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_16"&gt;NERC&lt;/span&gt;&lt;/span&gt; Aurora handling and &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_17"&gt;arguably&lt;/span&gt; misleading testimony creating much of this pain, &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_17"&gt;NERC&lt;/span&gt; still not out of the woodshed. &lt;/em&gt;Last year testimony also suggested getting rid of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_18"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_18"&gt;CIPs&lt;/span&gt;&lt;/span&gt; and starting fresh based more on &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_19"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_19"&gt;NIST&lt;/span&gt;&lt;/span&gt; standards as recommended by Mr. Joe Weiss (jump to 2:12:50 for his opening comments in video):&lt;br /&gt;-&lt;span style="color:#000099;"&gt;&lt;strong&gt; &lt;/strong&gt;&lt;u&gt;&lt;strong&gt;&lt;a href="http://homeland.house.gov/hearings/index.asp?ID=95&amp;amp;subcommittee=12"&gt;“The &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_20"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_20"&gt;Cyber&lt;/span&gt;&lt;/span&gt; Threat to Control Systems: Stronger Regulations are Necessary to Secure the Electric Grid.”&lt;/a&gt;&lt;/strong&gt; - &lt;/u&gt;&lt;/span&gt;&lt;a href="http://homeland.house.gov/hearings/index.asp?ID=95&amp;amp;subcommittee=12"&gt;&lt;span style="color:#000099;"&gt;Subcommittee on Emerging Threats, &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_21"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_21"&gt;Cybersecurity&lt;/span&gt;&lt;/span&gt;, and Science and Technology, &lt;/span&gt;&lt;/a&gt;&lt;span style="color:#000099;"&gt;&lt;u&gt;Oct 17&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_22"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_22"&gt;th&lt;/span&gt;&lt;/span&gt;, 2007&lt;/u&gt;&lt;/span&gt; (video/&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_23"&gt;submittals&lt;/span&gt;)&lt;br /&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div align="left"&gt;&lt;strong&gt;Better buckle up, this is just the first round of Order 706 driven changes.&lt;/strong&gt; &lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;div align="left"&gt;&lt;em&gt;"The &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_23"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_24"&gt;SDT&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; met on October 6–8, 2008 and because of the extensive scope and varying complexity of the issues and work in these revisions, the team decided on a multiphase approach for revising this set of standards. This posting of the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_24"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_25"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; standards for industry comment only relates to Phase I of the project.&lt;/em&gt; "&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div align="left"&gt;&lt;strong&gt;More:&lt;br /&gt;&lt;/strong&gt;- &lt;a href="http://www.nerc.com/filez/standards/Project_2008-06_Cyber_Security.html"&gt;&lt;span style="color:#000099;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_25"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_26"&gt;Cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Security (Project 2008-06 Site)&lt;/span&gt;&lt;/a&gt; &lt;span style="font-size:85%;"&gt;- The &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_26"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_27"&gt;Cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Security &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_15"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_27"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_28"&gt;SDT&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; posted its first draft of revised &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_16"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_28"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_29"&gt;Cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Security standards (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_17"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_29"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_30"&gt;CIP&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;-002-1-&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_18"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_30"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_31"&gt;CIP&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;-009-1) for a 45-day public comment period starting November 21, 2008 and ending on January 5, 2009. Both &lt;a href="http://www.nerc.com/docs/standards/sar/Complete_CIP_V2_Clean_Redline_2008Nov20.zip"&gt;&lt;span style="color:#000099;"&gt;clean and &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_19"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_31"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_32"&gt;redline&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; versions (zip files)&lt;/span&gt;&lt;/a&gt; are available for download and review.&lt;/span&gt;&lt;br /&gt;- &lt;a href="http://www.digitalbond.com/index.php/2008/11/24/revised-nerc-cip-standards-out-for-45-day-comment-period/"&gt;&lt;span style="color:#000099;"&gt;Revised &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_20"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_32"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_33"&gt;NERC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_21"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_33"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_34"&gt;CIP&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; standards out for 45 day comment period&lt;/span&gt;&lt;/a&gt;, Digital Bond 11/24/2008&lt;br /&gt;- &lt;a class="l" onmousedown="return clk(this.href,'','','res','3','')" href="http://www.ercot.com/content/meetings/other/keydocs/2008/0513-NERCComplianceW/Cyber_Standards_Final_Rule_-_FERC_Order_706.pdf"&gt;&lt;span style="color:#000099;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_22"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_34"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_35"&gt;Cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Standards Final Rule - &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_23"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_35"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_36"&gt;FERC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Order 706&lt;/span&gt;&lt;/a&gt;, &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_24"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_36"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_37"&gt;NERC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Workshop Presentation (informative 72 slides), 5/13/2008&lt;br /&gt;- &lt;a href="https://www.nerc.net/nercsurvey/Survey.aspx?s=1c6861b1cc1e4ca2a5faf1a7d2e56e76"&gt;&lt;span style="color:#000099;"&gt;Drafted Changes Summary&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#000099;"&gt;,&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_15"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_25"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_37"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_38"&gt;NERC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Comment Form &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-8201514769817150933?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/8201514769817150933/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=8201514769817150933' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/8201514769817150933'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/8201514769817150933'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2008/12/clock-is-ticking-for-feedback-on-nerc.html' title='Clock is Ticking for First Round of Pending Changes to NERC CIP Standards&lt;br&gt;&lt;i&gt; - Comments due Jan 5th &lt;/i&gt;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-2121798326365044133</id><published>2008-11-22T23:12:00.011-06:00</published><updated>2010-01-10T20:13:17.751-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Top Cyber Security Sites Resources'/><title type='text'>My Top Cyber Security Sites - Bookmark This!</title><content type='html'>&lt;span style="color: #660000; font-size: 78%;"&gt;Last Updated: 1-10-2010&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Here's my developing list of top &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; security sites and &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;podcasts&lt;/span&gt;&lt;/span&gt; with supporting rational.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 130%;"&gt;&lt;strong&gt;A. Situational Awareness:&lt;/strong&gt; &lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;a href="http://www.us-cert.gov/"&gt;&lt;strong&gt;&lt;span style="color: #3333ff;"&gt;US-CERT: United States Computer Emergency Response Team &lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size: 78%;"&gt;This is the very first place I check every day for a quick take on relevant &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;threatscape&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; information - i.e. &lt;em&gt;Current Activity &lt;/em&gt;and Alerts. Simple click to drill in on full listing of active national &lt;em&gt;Technical Security Alerts, Bulletins, Vulnerabilities,&lt;/em&gt; etc. Clean, well organized site with great coverage of a number of key &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; security topics.&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.dhs.gov/xinfoshare/programs/editorial_0542.shtm"&gt;&lt;strong&gt;&lt;span style="color: #3333ff;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;DHS&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Daily Open Source Infrastructure Report&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&lt;span style="color: #3333ff; font-size: 130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size: 78%;"&gt;A must read, great source of daily critical infrastructure protection related news organized by sectors and key assets as defined by the &lt;/span&gt;&lt;a href="http://www.dhs.gov/xprevprot/programs/editorial_0827.shtm"&gt;&lt;strong&gt;&lt;span style="font-size: 78%;"&gt;National Infrastructure Protection Plan&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;&lt;span style="font-size: 78%;"&gt; with linked open source references. e.g. Energy, Nuclear Reactors, Government Facilities, Information Technology, Communications, etc.&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;a href="http://isc.sans.org/"&gt;&lt;strong&gt;&lt;span style="color: #3333ff;"&gt;SANS Internet Storm Center- Handler's Diary&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size: 85%;"&gt;&lt;span style="font-size: 78%;"&gt;Especially useful for developing situations- these are the folks that go deep into &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;nitty&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;-gritty details addressing the latest Internet security problems.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;strong&gt;&lt;span style="font-size: 130%;"&gt;B. Program Development:&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;a href="http://www.cisohandbook.com/"&gt;&lt;strong&gt;CISOHandbook.com: Resource site for CISO's, CSO's, and security professionals.&lt;/strong&gt;&lt;/a&gt; &lt;br /&gt;&lt;span style="font-size: x-small;"&gt;Metrics, tools, opinions, and most importantly access to CISO's, CSO's, experts, and other professionals in the field of security. Shares information, ideas, tips, and techniques for addressing security issues faced by today's professional.&amp;nbsp;Content is free; however, some areas&amp;nbsp;require using a registration logon for access.&amp;nbsp; Their &lt;a href="http://www.amazon.com/gp/product/1420089102?ie=UTF8&amp;amp;tag=thiweeinsec-20&amp;amp;linkCode=as2&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=1420089102"&gt;latest book&lt;/a&gt;&amp;nbsp; goes beyond program centered engagement specifics&amp;nbsp;to provide a deeper understanding into what it takes for longer term results.&amp;nbsp;It&amp;nbsp;explains and underscores what really matters in&amp;nbsp;organizations to ensure security programs - regardless of budget and expertise applied to form them up- do not devolve as many do, like an ice sculpture melting into a useless puddle, while internal areas look on- recommended reading:&amp;nbsp; &amp;nbsp;&lt;/span&gt;&lt;a href="http://www.amazon.com/gp/product/1420089102?ie=UTF8&amp;amp;tag=thiweeinsec-20&amp;amp;linkCode=as2&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=1420089102"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="color: #660000;"&gt;&lt;strong&gt;CISO Soft Skills:&lt;/strong&gt; &lt;em&gt;Securing Organizations Impaired by Employee Politics, Apathy, and Intolerant Perspectives&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&amp;nbsp; &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9015080"&gt;&lt;span style="color: #3333ff;"&gt;&lt;strong&gt;Security Manager's Journal - ComputerWorld&lt;/strong&gt;&lt;/span&gt; &lt;/a&gt;&lt;br /&gt;&lt;span style="font-size: 78%;"&gt;Since 2002, a regular series of timely security manager articles addressing real world situations very simliar to a number of challenges many organizations face. The specific companies and assorted ghostwriters remain anonomous to help protect sources while gaining insight from often entertaining real-world hard knocks. &lt;strong&gt;&lt;em&gt;Think your job is tough?&lt;/em&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.csoonline.com/"&gt;&lt;strong&gt;&lt;span style="color: #3333ff;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;CSO&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Online - Security and Risk&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size: 78%;"&gt;A sister publication of &lt;a href="http://www.cio.com/"&gt;&lt;span style="color: #3333ff;"&gt;&lt;strong&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;CIO&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Magazine&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #3333ff;"&gt;&lt;strong&gt;,&lt;/strong&gt;&lt;/span&gt; this is &lt;em&gt;the&lt;/em&gt; primary trade magazine many follow with the latest enterprise views: headlines, data protection, identity &amp;amp; access, business continuity, &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_7"&gt;physical&lt;/span&gt; security, leadership, and some solid blogs.&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;a class="l" href="http://csrc.nist.gov/publications/PubsDrafts.html" onmousedown="return clk(this.href,'','','res','2','')"&gt;&lt;strong&gt;&lt;span style="color: #3333ff;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;NIST&lt;/span&gt;&lt;/span&gt;, Computer Security Division, Computer Security Resource Center&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;&lt;span style="color: #3333ff;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: 78%;"&gt;Regulatory trajectory is &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_9"&gt;promising&lt;/span&gt; to get more "&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;NISTy&lt;/span&gt;&lt;/span&gt;" for critical infrastructure &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_11"&gt;organizations&lt;/span&gt; and this site provides a front door to the National Institute of Standards and Technology well regarded Special Publications, related &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;FIPS&lt;/span&gt;&lt;/span&gt; requirements, and drafts organized by topic clusters, etc. Great complement to an overall framework.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="l" href="http://www.cert.org/podcast/" onmousedown="return clk(this.href,'','','res','2','')"&gt;&lt;strong&gt;&lt;span style="color: #3333ff;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;CERT's&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Podcast Series: Security for Business Leaders&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt; &lt;a href="http://www.us-cert.gov/"&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size: 78%;"&gt;Robust &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; security is increasingly a non-&lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_6"&gt;negotiable&lt;/span&gt; requirement for organizations. Moving corporate culture forward cooking security in poses challenges that must be overcome. CERT has a well done podcast series addressing key principles and strategies: &lt;em&gt;Governing for Enterprise Security, Measuring Security, Privacy, Risk Management and Resilience, Security Educations and Training, Threats, Trends and Lessons Learned, Tips from the Trenches. &lt;/em&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;strong&gt;&lt;span style="font-size: 130%;"&gt;C.&amp;nbsp;Perspectives and Professional Development:&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;a href="http://www.krebsonsecurity.com/"&gt;&lt;span style="color: blue;"&gt;&lt;strong&gt;KrebsonSecurity:&amp;nbsp;In-depth security news and investigation.&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: blue;"&gt;&lt;strong&gt; &lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;Brian Krebs worked as a reporter for The Washington Post from 1995 to 2009, authoring more than 1,300 blog posts for the Security Fix blog, as well as hundreds of stories for washingtonpost.com and The Washington Post newspaper, including eight front-page stories in the dead-tree edition and a Post Magazine cover piece on botnet operators.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="l" href="http://www.digitalbond.com/" onmousedown="return clk(this.href,'','','res','2','')"&gt;&lt;span style="color: #3333ff;"&gt;&lt;strong&gt;Digital Bond: Control System Security Research and Consulting&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size: 78%;"&gt;Digital Bond is a control system security research and consulting practice. They have years of security experience from the National Security Agency (NSA), National Labs, large asset owners and leading security equipment providers.perspective. &lt;strong&gt;&lt;a href="http://www.digitalbond.com/index.php/resources/"&gt;&lt;span style="color: #3333ff;"&gt;Resources&lt;/span&gt;&lt;/a&gt;&lt;/strong&gt;&lt;span style="color: #3333ff;"&gt; &lt;/span&gt;include the well maintained blog, monthly podcast with industry expertise, presentations, annual "S4" research conference proceedings, research, and a solid &lt;/span&gt;&lt;a href="http://www.digitalbond.com/wiki/index.php/Main_Page"&gt;&lt;span style="font-size: 78%;"&gt;&lt;strong&gt;&lt;span style="color: #3333ff;"&gt;SCADApedia&lt;/span&gt;&lt;/strong&gt; &lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: 78%;"&gt;reference.&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;a class="l" href="http://itradio.com.au/security/" onmousedown="return clk(this.href,'','','res','2','')"&gt;&lt;strong&gt;&lt;span style="color: #3333ff;"&gt;ITRadio.com.au: Risky Business Podcast with Patrick Gray&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;&lt;span style="color: #3333ff;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: 78%;"&gt;Excellent latest news coverage and regularly featured interviews all professionally done. Great, timely coverage of hot security topics from the experts closest to the action- all done in a way to help ensure those listening are entertained and gain valuable perspective.&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.manager-tools.com/"&gt;&lt;strong&gt;&lt;span style="color: #3333ff;"&gt;Manager Tools &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_15"&gt;Podcasts&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size: 78%;"&gt;Want to become a more effective leader and manager? This weekly podcast helps with fresh tools and easy techniques for real-world settings that go beyond theory into specific actions that can be used right away to improve your performance. A key set of "&lt;/span&gt;&lt;a href="http://www.manager-tools.com/manager-tools-basics/"&gt;&lt;span style="color: #3333ff; font-size: 78%;"&gt;&lt;strong&gt;&lt;span style="color: #3333ff;"&gt;the&lt;/span&gt; basics&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: 78%;"&gt;" provide a strong starting point you can immediately apply and build on!&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;em&gt;Helpful input welcome. &lt;/em&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-2121798326365044133?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/2121798326365044133/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=2121798326365044133' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/2121798326365044133'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/2121798326365044133'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2008/11/my-top-cyber-security-sites-bookmark.html' title='My Top Cyber Security Sites&lt;br&gt;&lt;i&gt; - Bookmark This!&lt;/i&gt;'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-2280215648562863459</id><published>2008-11-02T21:43:00.000-06:00</published><updated>2008-11-06T15:19:44.148-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='FACTA FTC Enforcement Delay News six months'/><title type='text'>FTC Will Delay 'Red Flags' Rule Enforcement for Six Months</title><content type='html'>&lt;strong&gt;&lt;u&gt;Some Good News on FACTA!&lt;/u&gt;&lt;/strong&gt;&lt;br /&gt;Looks like a number of utilities will get a break in enforcement action with FTC granting a six-month delay. &lt;strong&gt;However&lt;/strong&gt;, this repreave is just for FTC enforcement, and won't affect other federal agencies' enforcement of the original Nov 1, 2008 deadline.&lt;br /&gt;&lt;br /&gt;&gt;&lt;a href="http://www.ftc.gov/opa/2008/10/redflags.shtm"&gt;FTC Will Grant Six-Month Delay of Enforcement Action&lt;/a&gt; , FTC Announcement&lt;br /&gt;&gt;&lt;a href="http://en.wikipedia.org/wiki/Fair_and_Accurate_Credit_Transactions_Act"&gt;More on FACTS (Fair and Accurate Credit Transactions Act)&lt;/a&gt; - &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;Wikipedia&lt;/span&gt; Overview/Links&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-2280215648562863459?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/2280215648562863459/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=2280215648562863459' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/2280215648562863459'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/2280215648562863459'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2008/11/ftc-will-grant-six-month-delay-of.html' title='FTC Will Delay &apos;Red Flags&apos; Rule Enforcement for Six Months'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-8905997375551061957</id><published>2008-10-26T01:39:00.000-05:00</published><updated>2008-11-23T10:08:50.433-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News TCP Sockstress Attack Vulnerability Microsoft Emergency Control Systems Security DHS CSSP Program Tools SecurityNow 164 WLAN ZigBee Wireless WLAN OPSEC CS2SAT Assessment'/><title type='text'>Microsoft Emergency Security Update (Ouch)- Can't Patch Control Systems?- Sockstress TCP Vulnerability Issues Next?</title><content type='html'>&lt;p&gt;On Thursday 10/23, Microsoft spiced up our lives with a emergency security update (i.e. &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-067.mspx"&gt;&lt;span style="color:#000099;"&gt;Microsoft Security Bulletin MS08-067 – Critical&lt;/span&gt;&lt;/a&gt;) to address a “&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;wormable&lt;/span&gt;&lt;/span&gt;” vulnerability specifically exploiting “Server” service via remote network remote procedure calls (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;RPC&lt;/span&gt;&lt;/span&gt;). Similar to &lt;a href="http://en.wikipedia.org/wiki/Blaster_worm"&gt;&lt;span style="color:#000099;"&gt;Blaster&lt;/span&gt;&lt;/a&gt;, unmitigated vulnerable machines can be directly attacked at a network level and immediately, completely compromised. This particular problem is also extremely exploitable once understood; &lt;a href="http://www.nytimes.com/external/idg/2008/10/23/23idg-Attack-code-for.html"&gt;&lt;span style="color:#000099;"&gt;security firm Immunity&lt;/span&gt;&lt;/a&gt; was able to craft a working exploit within two hours after the release of the security fix.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;u&gt;Don’t Neglect Control Systems- especially Critical Infrastructure.&lt;/u&gt;&lt;/em&gt; While many business network environments are going through the test and deployment process (not without some problems – e.g. some reported breakage of &lt;a href="http://en.wikipedia.org/wiki/IPsec"&gt;&lt;span style="color:#000099;"&gt;IPSEC&lt;/span&gt;&lt;/a&gt;), there’s also a need to be thinking about critical infrastructure as it increasingly is depending on Microsoft based solutions. These type of problems underscore how the network environment and it’s management infrastructure are such an important and fundamental starting point for establishing and sustaining a defined, effective, defense-in-depth security posture. Many may assume that the environments are well separated by definition; however, when you don’t get the control system network right (or at least sufficient), it undermines everything else being done in the name of security.&lt;br /&gt;&lt;br /&gt;Beyond layered network segmentation with strict boundary communication controls as a vital starting point, basics that are increasingly expected include protective network &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;chokepoints&lt;/span&gt;&lt;/span&gt; (firewalls, gateways, etc), and secure information transfer facilities (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;DMZs&lt;/span&gt;&lt;/span&gt;, &lt;a href="http://en.wikipedia.org/wiki/Unidirectional_network"&gt;&lt;span style="color:#000099;"&gt;Data Diodes&lt;/span&gt;&lt;/a&gt;, NIPS, etc). Other important steps often overlooked include basics such as server system hardening and endpoint protection measures (e.g. AV, HIPS, white listing, etc). As more is done in the name of security, the solutions themselves need to be managed and protected in a scalable manner- perhaps with a distinct network security management environment- also with commensurate protection.&lt;br /&gt;&lt;br /&gt;Having well formed &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;mitigations&lt;/span&gt;&lt;/span&gt; in place in control system settings will help directly address risks from emergent security problems such as this and be in a good position when facing related regulatory scrutiny. Typical business network environments are strikingly different – often quite porous and flat, with less definitive countermeasures- and therefore pressing forward with patches and security updates on a regular basis across a substantial IT foot point. These are very different environments only suited for very specific, understood and controlled interactions - having solid network security controls between the two environments is an essential part a well articulated &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;cyber&lt;/span&gt;&lt;/span&gt; security architecture. &lt;/p&gt;&lt;p&gt;&lt;u&gt;&lt;strong&gt;More-&lt;/strong&gt;&lt;/u&gt; &lt;a href="http://www.us-cert.gov/control_systems/"&gt;&lt;span style="color:#000099;"&gt;&lt;strong&gt;DHS Control Systems Security Program, Idaho National Laboratory&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt; offers the following tools:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.us-cert.gov/control_systems/pdf/Catalog_of_Control_Systems_Security_Recommendations.pdf"&gt;&lt;span style="color:#000099;"&gt;Catalog of Control Systems Security: Recommendations for Standards Developers&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#000099;"&gt; &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://csrp.inl.gov/Self-Assessment_Tool.html"&gt;&lt;span style="color:#000099;"&gt;Control System Cyber Security Self-Assessment Tool (CS2SAT)&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#000099;"&gt; &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.us-cert.gov/control_systems/csdocuments.html#docs"&gt;&lt;span style="color:#000099;"&gt;CSSP Documents&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#000099;"&gt; &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.pcsforum.org/groups/5/documents/Critical_Infrastructure_and_Control_Systems_Security_Curriculum.pdf"&gt;&lt;span style="color:#000099;"&gt;Critical Infrastructure and Control Systems Security Curriculum&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#000099;"&gt; &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.us-cert.gov/control_systems/pdf/SCADA_Procurement_DHS_Final_to_Issue_08-19-08.pdf"&gt;&lt;span style="color:#000099;"&gt;Cyber Security Procurement Language for Control Systems&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#000099;"&gt; &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://csrp.inl.gov/"&gt;&lt;span style="color:#000099;"&gt;&lt;strong&gt;Recommended Practices&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#000099;"&gt;&lt;br /&gt;- Control Systems Cyber Security Defense in Depth Strategies&lt;br /&gt;- Creating Cyber Forensics Plans for Control Systems&lt;br /&gt;- Good Practice Guide on Firewall Deployment&lt;br /&gt;- Hardening Guidelines for OPC Hosts&lt;br /&gt;- Mitigations for Security Vulnerabilities Found in Control System Networks&lt;br /&gt;- Securing Control System Modems&lt;br /&gt;- Securing WLANs Using 802.11i (draft)&lt;br /&gt;- Securing ZigBee Wireless Networks in Process Control System Environments (draft)&lt;br /&gt;- Using Operational Security (OPSEC) to Support a Cyber Security Culture in Control Systems Environments (draft)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.us-cert.gov/control_systems/cstraining.html"&gt;&lt;span style="color:#000099;"&gt;&lt;strong&gt;Training&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#000099;"&gt; - including several introductory web based courses:&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:85%;color:#000099;"&gt;- Cyber Security for Control Systems Engineers &amp;amp; Operators&lt;br /&gt;- OPSEC for Control Systems &lt;span style="color:#990000;"&gt;(NEW)&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What's Next- Sockstress Issues? &lt;/strong&gt;How about long standing weaknesses involving TCP network stack vulnerabilities recently gaining attention with "&lt;a href="http://www.serverwatch.com/eur/article.php/3778221"&gt;Sockstress&lt;/a&gt;" that can be exploited to cause reachable systems to lockup, denial-of-service (DOS)? Indications are that even an attack at one packet per second can take systems down - e.g. dialup Internet. Because this is a state based attack, can't use spoofed packets but even small bot farms are sufficent to carry this attack out.&lt;br /&gt;&gt; &lt;a id="u-AFQjCNG7JpYkY25b329ozjLtXUdRPkrbjg:r-0_1253592087" href="http://news.idg.no/cw/art.cfm?id=C038E4EC-17A4-0F78-31C06772323B1A5E"&gt;&lt;span style="color:#000099;"&gt;Vendors fixing bug that could crash Internet systems&lt;/span&gt;&lt;/a&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;Computerworld&lt;/span&gt;, Norway - Oct 2, 2008&lt;br /&gt;&gt; &lt;a href="http://www.grc.com/securitynow.htm#164"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;SecurityNow&lt;/span&gt;! Episode 164: &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;Sockstress&lt;/span&gt; - Oct 2, 2008&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-8905997375551061957?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/8905997375551061957/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=8905997375551061957' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/8905997375551061957'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/8905997375551061957'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2008/10/microsoft-fire-drill-emergency-security.html' title='Microsoft Emergency Security Update (Ouch)&lt;br&gt;- Can&apos;t Patch Control Systems?&lt;br&gt;- Sockstress TCP Vulnerability Issues Next?'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-503835713774896737</id><published>2008-10-21T23:17:00.001-05:00</published><updated>2008-12-06T16:37:46.199-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CERT Security Awareness Month National Cyber'/><title type='text'>Cyber Security Awareness Month In Full Force-Threats to Security Never Sleep!</title><content type='html'>Every year my group helps support a company wide awareness campaign and that coincides with National Awareness month. Videos, games, posters, online question and answers... and of course booty with some great top prizes (ipods, security system, etc). Yes, enthusasim isn't enough- folks need to enage and submit correct answers to be in drawings. As for the goodies being drawn, we continue to get much of it just for the asking from our suppliers ahead of the event (explaining our internal campaign and asking "would they like to help us out", etc ) - no strings.&lt;br /&gt;&lt;br /&gt;Nationally, many "free" resources continue to be developed by non-profits and governmental sources. Some the best of these online sources follow and are worth taking note of as this month winds down.&lt;br /&gt;&lt;br /&gt;&gt; &lt;a href="http://www.staysafeonline.org/"&gt;&lt;span style="color:#000099;"&gt;&lt;strong&gt;National Cyber Security Alliance&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;strong&gt;&lt;span style="color:#000099;"&gt;&lt;br /&gt;- &lt;/span&gt;Top 8 Cyber Security Practices &lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Protect your personal information. It's valuable.&lt;/li&gt;&lt;li&gt;Know who you're dealing with online.&lt;/li&gt;&lt;li&gt;Use anti-virus software, a firewall, and anti-spyware software to help keep your computer safe and secure.&lt;/li&gt;&lt;li&gt;Be sure to set up your operating system and Web browser software properly, and update them regularly.&lt;/li&gt;&lt;li&gt;Use strong passwords or strong authentication technology to help protect your personal information.&lt;/li&gt;&lt;li&gt;Back up important files.&lt;/li&gt;&lt;li&gt;Learn what to do if something goes wrong.&lt;/li&gt;&lt;li&gt;Protect your children online. &lt;/li&gt;&lt;/ol&gt;&gt; &lt;a href="http://www.educause.edu./security/resourcekit/7479?time=1224650294"&gt;&lt;span style="color:#000099;"&gt;&lt;strong&gt;EDUCAUSE's Online Cyber Resource Kit&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#000099;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&gt; &lt;a href="http://www.msisac.org/awareness/oct08/index.cfm"&gt;&lt;span style="color:#000099;"&gt;&lt;strong&gt;MS-ISAC Multi-State Information Sharing and Analysis Center&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#000099;"&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;- webcast, Cyber Security Tool Kit, etc.&lt;br /&gt;&lt;br /&gt;&gt; &lt;a href="http://www.onguardonline.gov/"&gt;&lt;span style="color:#000099;"&gt;&lt;strong&gt;OnGuardOnline.gov&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;- more information, phamplets, etc&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-503835713774896737?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/503835713774896737/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=503835713774896737' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/503835713774896737'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/503835713774896737'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2008/10/cyber-security-awareness-month-in-full.html' title='Cyber Security Awareness Month In Full Force&lt;br&gt;-Threats to Security Never Sleep!'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-5972917737629264986</id><published>2008-10-18T19:37:00.000-05:00</published><updated>2009-08-03T18:23:07.630-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Security Assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='DHS'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='NCSD'/><category scheme='http://www.blogger.com/atom/ns#' term='lowcost'/><title type='text'>Neat DHS/NCSD Cyber Security Vulnerability Assessment Tool (CSVA) + CS2SAT</title><content type='html'>&lt;span style="font-size:78%;color:#000066;"&gt;&lt;strong&gt;Last updated 8-2-2009&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span id="SPELLING_ERROR_0" class="blsp-spelling-error"&gt;DHS&lt;/span&gt;’s National &lt;span id="SPELLING_ERROR_1" class="blsp-spelling-error"&gt;Cyber&lt;/span&gt; Security Division (&lt;span id="SPELLING_ERROR_2" class="blsp-spelling-error"&gt;NCSD&lt;/span&gt;) has been working to develop an objective, comprehensive &lt;span id="SPELLING_ERROR_3" class="blsp-spelling-error"&gt;cyber&lt;/span&gt; security vulnerability assessment (&lt;span id="SPELLING_ERROR_4" class="blsp-spelling-error"&gt;CSVA&lt;/span&gt;) tool for some time and revving through Betas. Using a simplified methodology, the &lt;span id="SPELLING_ERROR_5" class="blsp-spelling-error"&gt;CSVA&lt;/span&gt; is aimed to quickly assess an organization, facility or system’s &lt;span id="SPELLING_ERROR_6" class="blsp-spelling-error"&gt;cyber&lt;/span&gt; vulnerabilities and recommend options with extensive helpful explanations and examples. Critical infrastructure sectors are encourage by &lt;span id="SPELLING_ERROR_7" class="blsp-spelling-error"&gt;DHS&lt;/span&gt; to use this tool to analyze their &lt;span id="SPELLING_ERROR_8" class="blsp-spelling-error"&gt;cybersecurity&lt;/span&gt; posture.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;I recently got my hands on and fired up &lt;span id="SPELLING_ERROR_9" class="blsp-spelling-error"&gt;CSVA&lt;/span&gt; BETA 5 &lt;em&gt;- &lt;u&gt;some thoughts&lt;/u&gt;&lt;/em&gt;:&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Best if performed with prepared team and good facilitation. &lt;em&gt;&lt;span id="SPELLING_ERROR_10" class="blsp-spelling-error"&gt;Cyber&lt;/span&gt; security knowledgeable folks familiar with the assessment environment can get a running, upfront start. &lt;/em&gt;&lt;/li&gt;&lt;li&gt;An initial determination is made regarding if a Business Network or a Control System is being assessed and adjusts approach- very good!&lt;/li&gt;&lt;li&gt;Truth over harmony needed here folks - some questions are combination issues and not all the answers to pick from fit well. &lt;em&gt;Pick the most conservative answers and capture views in comments to get through the process.&lt;/em&gt;&lt;/li&gt;&lt;li&gt;Credibility bolstered in assessment process with a virtual informed third-party (&lt;span id="SPELLING_ERROR_11" class="blsp-spelling-error"&gt;DHS&lt;/span&gt;/&lt;span id="SPELLING_ERROR_12" class="blsp-spelling-error"&gt;NCSD&lt;/span&gt;) cooked in. &lt;/li&gt;&lt;li&gt;Can save assessment, go back and make adjustments for what ifs or actual improvements and see results.&lt;/li&gt;&lt;li&gt;Strives to leverage concepts from recognized &lt;span id="SPELLING_ERROR_13" class="blsp-spelling-error"&gt;cybersecurity&lt;/span&gt; standards and guidance- e.g. ISO,&lt;span id="SPELLING_ERROR_14" class="blsp-spelling-error"&gt;COBIT&lt;/span&gt;, &lt;span id="SPELLING_ERROR_15" class="blsp-spelling-error"&gt;NIST&lt;/span&gt;, etc &lt;/li&gt;&lt;li&gt;Offers great benefit lift ratio for effort required. &lt;em&gt;Being "free" helps too!&lt;/em&gt; &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;&lt;u&gt;Bottom line&lt;/u&gt;.&lt;/span&gt; &lt;/strong&gt;The &lt;span id="SPELLING_ERROR_16" class="blsp-spelling-error"&gt;CSVA&lt;/span&gt; journey is a short, easy trip and the results are well worth it. The tool offers a solid approach to further develop shared understanding of &lt;span id="SPELLING_ERROR_17" class="blsp-spelling-error"&gt;cybersecurity&lt;/span&gt; posture with various stakeholders to build on and prioritize improvements, For more information or a copy of the tool, contact the Critical Infrastructure Protection / &lt;span id="SPELLING_ERROR_18" class="blsp-spelling-error"&gt;Cyber&lt;/span&gt; Security Program within the &lt;span id="SPELLING_ERROR_19" class="blsp-spelling-error"&gt;DHS&lt;/span&gt; National &lt;span id="SPELLING_ERROR_20" class="blsp-spelling-error"&gt;Cyber&lt;/span&gt; Security Division at &lt;a href="mailto:ncsd_cipcs@hq.dhs.gov"&gt;&lt;span style="color:#000066;"&gt;&lt;strong&gt;ncsd_cipcs@hq.dhs.gov&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;-&lt;em&gt;&lt;strong&gt;&lt;br /&gt;&lt;u&gt;Next- the CS2SAT&lt;/u&gt;.&lt;/strong&gt;&lt;/em&gt; For those needing to go beyond the &lt;span id="SPELLING_ERROR_21" class="blsp-spelling-error"&gt;CSVA&lt;/span&gt;’s high-level approach and focus on more specific risk particulars- factoring in consequences, network topology, requirements, etc - there’s the &lt;a href="http://www.us-cert.gov/control_systems/pdf/CS2SAT.pdf"&gt;&lt;span style="color:#000066;"&gt;&lt;strong&gt;Control System &lt;span id="SPELLING_ERROR_22" class="blsp-spelling-error"&gt;Cyber&lt;/span&gt; Security Self Assessment Tool (CS2SAT)&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt; Haven't looked at it yet but planning to give it a whirl at some point - list pricing, e.g., $1800, is waived ("free") for many energy organizations.&lt;/p&gt;&lt;p&gt;&lt;span style="color:#000099;"&gt;&lt;strong&gt;&lt;u&gt;Update 8-2-2009&lt;/u&gt;&lt;/strong&gt; -&lt;/span&gt; &lt;span style="color:#000066;"&gt;Per &lt;span id="SPELLING_ERROR_23" class="blsp-spelling-error"&gt;DHS&lt;/span&gt;, the &lt;span id="SPELLING_ERROR_24" class="blsp-spelling-error"&gt;CSVA&lt;/span&gt; will be integrated into upcoming versions of the &lt;/span&gt;&lt;a href="http://www.us-cert.gov/control_systems/pdf/CS2SAT.pdf"&gt;&lt;span style="color:#000066;"&gt;CS2SAT&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#000066;"&gt; . The latest Version 2 of the CS2SAT is now specifically configurable to address &lt;span id="SPELLING_ERROR_25" class="blsp-spelling-error"&gt;NERC&lt;/span&gt; &lt;span id="SPELLING_ERROR_26" class="blsp-spelling-error"&gt;CIP&lt;/span&gt;, SANS, etc for assessment activities. Works a lot like the &lt;span id="SPELLING_ERROR_27" class="blsp-spelling-error"&gt;CSVA&lt;/span&gt; - but focused on control system space for now (until &lt;span id="SPELLING_ERROR_28" class="blsp-spelling-error"&gt;CSVA&lt;/span&gt; transitioned). &lt;span id="SPELLING_ERROR_29" class="blsp-spelling-error"&gt;DHS&lt;/span&gt; is very committed to the CS2SAT approach- given freely at one day Industrial Control System &lt;span id="SPELLING_ERROR_30" class="blsp-spelling-error"&gt;cyber&lt;/span&gt; security courses - worth checking out.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-5972917737629264986?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/5972917737629264986/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=5972917737629264986' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/5972917737629264986'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/5972917737629264986'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2008/10/cool-dhsncsd-cyber-security.html' title='Neat DHS/NCSD Cyber Security Vulnerability Assessment Tool (CSVA) + CS2SAT'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-4383743725908271152</id><published>2008-09-14T23:52:00.000-05:00</published><updated>2009-03-05T22:23:10.992-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hearings'/><title type='text'>Protecting the Electric Grid from Cyber-Security Threats</title><content type='html'>On Thursday 9/11/08, the Subcommittee on Energy and Air Quality (of the Committee on Energy and Commerce) held a hearing on the state of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;Cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Security with respect to the electric grid. &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;FERC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;, &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;NERC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;, and &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;APPA&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; were represented. The focus is taking drafted legislation forward to provide &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;FERC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; more &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; security emergency authority to address new and often rapidly developing &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; security risks.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://energycommerce.house.gov/cmte_mtgs/110-eaq-hrg.091108.Cybersecurity.shtml"&gt;&lt;span style="color:#3333ff;"&gt;Protecting the Electric Grid from &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;Cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;-Security Threats&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#3333ff;"&gt;&lt;br /&gt;&lt;/span&gt;Subcommittee on Energy and Air Quality&lt;br /&gt;Committee on Energy and Commerce&lt;br /&gt;- 9/11/2008 testimony, audio, and drafted legislation&lt;br /&gt;&lt;br /&gt;&lt;a href="rtsp://video1.c-span.org/project/ter/ter091108_cybersecurity2.rm"&gt;&lt;span style="color:#3366ff;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;CSPAN&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Video&lt;/span&gt;&lt;/a&gt; now available (requires &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;Realmedia&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; player)&lt;br /&gt;&lt;p&gt;Opening comments emphasized views that the risk is increasing with at least twenty incidents of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; security problems impacting electric systems service. There’s a strong concern in addressing underlying control systems, vital to reliable service, given growing risk with increasingly &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;interconnectivity&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; and use of widely available technology. The risk picture will continue to be developing with the trends toward &lt;a href="http://en.wikipedia.org/wiki/Smart_grid"&gt;&lt;span style="color:#3366ff;"&gt;Smart Grid&lt;/span&gt;&lt;/a&gt; and other control system dependent technology developments.&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;em&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;FERC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Interviews&lt;/em&gt;&lt;/u&gt;. Testimony emphasized &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;FERC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; findings from interviews with 30 utilities – including particular actions taken to address &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;NERC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; voluntary &lt;a href="http://www.cnn.com/2007/US/09/26/power.at.risk/index.html"&gt;&lt;span style="color:#3366ff;"&gt;Aurora Vulnerability&lt;/span&gt; &lt;/a&gt;advisory in 2007:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Of the 30, seven were viewed as in full compliance with the advisory. &lt;/li&gt;&lt;li&gt;All took some steps - one still still &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_15"&gt;using&lt;/span&gt; all default passwords, another had a 10 year plan. &lt;/li&gt;&lt;li&gt;Only 2 went sufficiently far enough to fully address the Aurora vulnerability. &lt;/li&gt;&lt;li&gt;A number of organizations shrunk scope too small - not &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_15"&gt;sufficiently&lt;/span&gt; addressing critical assets/facilities that can affect the bulk electric system. &lt;/li&gt;&lt;li&gt;Cost estimates addressing the Aurora Vulnerability were not gathered in the process- but viewed as important by the &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_16"&gt;committee&lt;/span&gt; with &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_17"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_16"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_15"&gt;FERC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; in agreement- &lt;em&gt;more relevant going forward. &lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;em&gt;The conclusion- self-interest alone &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_18"&gt;is not&lt;/span&gt; sufficient for most utilities to take appropriate actions to specifically address the Aurora Vulnerability.   This situation fueling strong congressional concerns about how well the regulators and utilities are addressing overall  &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_19"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_17"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_16"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; security risk. &lt;/em&gt;&lt;/p&gt;&lt;p&gt;Existing &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_20"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_18"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_17"&gt;FERC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;/&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_21"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_19"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_18"&gt;NERC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; regulatory mechanisms are viewed as insufficient, either lacking enforcement strength (e.g. voluntary &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_22"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_20"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_19"&gt;NERC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Advisories) or take too long following 215 process. &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_23"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_21"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_20"&gt;APPA&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; emphasized cooperation with &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_24"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_22"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_21"&gt;FERC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; staff in developing drafted legislation giving DOE/&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_25"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_23"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_22"&gt;FERC&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; emergency order making powers address &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_26"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_24"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_23"&gt;cyber&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; security issues- with still a few remaining points in disagreement.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-4383743725908271152?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/4383743725908271152/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=4383743725908271152' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/4383743725908271152'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/4383743725908271152'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2008/09/911-hearing-protecting-electric-grid.html' title='Protecting the Electric Grid from Cyber-Security Threats'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-1113607023935761119</id><published>2008-07-06T22:15:00.000-05:00</published><updated>2008-07-06T23:28:15.408-05:00</updated><title type='text'>OWASP - Ira Winkler &amp;  Jeremy Poteet Videos</title><content type='html'>From time to time, I come across some gems.. in particular, the second video available at link below helps provide some solid &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_0"&gt;perspective&lt;/span&gt; on the growing challenges with application security. While many firms don't face the extreme dynamics and poll changing stakes associated with a national political campaign's web site, utility &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_1"&gt;organizations&lt;/span&gt; often have legacy systems that are at increasing risk from the same sort of evolving threats.&lt;br /&gt;&lt;br /&gt;Also, to give Ira Winkler some credit after bashing his utility sector remarks, his presentation below on organizational security, including risk and how people are a very key element in a security program, are spot on. Focusing more on applications, the second presentation below provides some great insights into defense in depth strategies with some real world perspective.&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;strong&gt;Videos(2)&lt;/strong&gt;&lt;/u&gt;&lt;br /&gt;(1) Index 00:00:00 - Secrets of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;Superspies&lt;/span&gt;- &lt;em&gt;Ira &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;Winkler&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;a href="http://video.google.com/videoplay?docid=-9110574247136866679&amp;amp;q=IRA+Winkler+video&amp;amp;ei=iIpxSMfIKIneqQO-vdinDw" target="_top"&gt;&lt;/a&gt;(2) Index 01:01:00 - In the Line of Fire: Defending Highly &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_4"&gt;Visible&lt;/span&gt; Targets - &lt;em&gt;Jeremy &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;Poteet&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;a href="http://video.google.com/videoplay?docid=-9110574247136866679&amp;amp;q=+ira+winkler&amp;amp;ei=NYxxSI24IpH0qQOFxqGgDw"&gt;Google Video Link&lt;/a&gt; (122 min - Oct 13, 2006)&lt;br /&gt;&lt;br /&gt;More: &lt;a href="http://www.owasp.org/"&gt;Open Web Application Security Project (OWASP) - www.owasp.org&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Enjoy!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-1113607023935761119?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/1113607023935761119/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=1113607023935761119' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/1113607023935761119'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/1113607023935761119'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2008/07/owasp-ira-winkler-jeremy-poteet-videos.html' title='OWASP - Ira Winkler &amp;  Jeremy Poteet Videos'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-6772180067346785464</id><published>2008-05-26T23:48:00.010-05:00</published><updated>2011-02-03T08:07:45.862-06:00</updated><title type='text'>GAO Report Rips TVA at “Implications of Cyber Vulnerabilities on the Resiliency and Security of the Electric Grid”  Hearing</title><content type='html'>Scathing GAO testimony/findings from GAO's assessment of TVA cyber security should be of special interest for many electric utility organizations. TVA issues cited included problems stemming from lacking a corporate-level cyber security program and significant security posture weaknesses, unevenness in both operational and corporate network settings. All of which TVA’s COO (William R. McCollum, Jr.) reported significant focus and progress addressing with a strong commitment to continue improving.&lt;br /&gt;&lt;br /&gt;The hearing is available for viewing (~90m) at &lt;a style="FONT-WEIGHT: bold" href="http://www.c-spanvideo.org/program/ElectricG"&gt;C-SPAN Video Library: Security of the Electric Grid - May 21, 2008&lt;/a&gt; &lt;span style="font-size:78%;"&gt;&lt;span style="COLOR: rgb(102,0,0)"&gt;(updated 1/23/2011&lt;/span&gt;)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In my opinion, looking hard at referenced NIST standards to further address specific cyber security topic areas makes sense for NERC CIPs as does looking at broader information security frameworks to help scope and tailor well governed corporate level programs based on recognized frameworks, .e.g. ISO 17799:2005 , COBIT, etc.&lt;br /&gt;&lt;br /&gt;Anyone with a stake in cyber securing critical infrastructure will benefit from reviewing the hearing &lt;u&gt;and&lt;/u&gt; a close study of the 62 page May 2008 GAO report "&lt;a style="FONT-WEIGHT: bold" href="http://www.gao.gov/new.items/d08526.pdf"&gt;Information Security- TVA Needs to Address Weaknesses in Control Systems and Networks&lt;/a&gt;"&lt;br /&gt;&lt;br /&gt;More:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;&lt;a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/05/20/AR2008052002354_pf.html"&gt;TVA Power Plants Vulnerable to Cyber Attacks, GAO Finds - Washington Post 5/21/2008&lt;/a&gt;&lt;br /&gt;&lt;/b&gt;Regulators Want Authority to Require Security Upgrades Industry-wide&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-6772180067346785464?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/6772180067346785464/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=6772180067346785464' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/6772180067346785464'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/6772180067346785464'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2008/05/52108-hearing-available-online.html' title='GAO Report Rips TVA at “Implications of Cyber Vulnerabilities on the Resiliency and Security of the Electric Grid”  Hearing'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-8239519303274413571</id><published>2008-05-18T22:46:00.000-05:00</published><updated>2009-02-14T20:53:26.615-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Expert'/><category scheme='http://www.blogger.com/atom/ns#' term='Penetration Testing'/><title type='text'>Ira Winkler - love him, hate him- he's making headlines..</title><content type='html'>&lt;ul&gt;&lt;li&gt;&lt;a class="l" onmousedown="return clk(this.href,'','','res','3','')" href="http://www.networkworld.com/news/2008/040908-rsa-hack-power-grid.html"&gt;Experts hack power grid in no time - Network World&lt;/a&gt;&lt;br /&gt;Apr 9, 2008 ... "We had to shut down within hours," Winkler says... "&lt;br /&gt;&lt;br /&gt;Press releases around Ira &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;Winkler's&lt;/span&gt; assertions regarding how easy it remains to hack from the Internet into the deepest parts of electric utility critical infrastructure has caught the attention of media, regulators, senior utility management, and security professionals. While Ira's comments go over the top in my opinon when it comes to nuclear reactors and more centered on distributed &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;SCADA&lt;/span&gt;- he is a practitioner that doesn't pull punches.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;Video&lt;/u&gt; &lt;/strong&gt;&lt;br /&gt;(1) &lt;a href="http://video.google.com/videoplay?docid=-7743882779616596738&amp;amp;q=ira+winkler+&amp;amp;ei=WQYySMFNhbCpAuOn7J8F&amp;amp;hl=en" target="_top"&gt;RSA 2008 - Ira Winkler (ISAG) &lt;/a&gt;(7m). Was able to get to nuclear controls - that should have no business network connectivity? Also no "off switch for nuclear" (rant- WTH is he talking about... how about the "off" switch provided by independent safety systems and SCRAM functions??).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Would you hire Ira to do your next organizational penetration testing?&lt;/strong&gt; &lt;em&gt;Please comment and/or vote&lt;/em&gt;&lt;strong&gt;.&lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-8239519303274413571?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/8239519303274413571/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=8239519303274413571' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/8239519303274413571'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/8239519303274413571'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2008/05/ira-winkler-love-him-hate-him-hes.html' title='Ira Winkler - love him, hate him- he&apos;s making headlines..'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1189434011500461359.post-4776256543915601548</id><published>2008-05-18T21:07:00.000-05:00</published><updated>2008-10-29T11:24:05.290-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Welcome'/><title type='text'>Welcome</title><content type='html'>Given all the excellent podcasts and blogs around information assurance aka cyber security, you may wonder why yet another security blog? For me, this is a commitment to post periodically my musings and more serious thoughts related to security with a focus on critical infrastructure topics. Those that are interested in the topics or sharing related views are welcome and encouraged to contribute in a reasonably civil manner - I'll work to hold myself to a simliar standard.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1189434011500461359-4776256543915601548?l=thisweekinsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thisweekinsecurity.blogspot.com/feeds/4776256543915601548/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1189434011500461359&amp;postID=4776256543915601548' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/4776256543915601548'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1189434011500461359/posts/default/4776256543915601548'/><link rel='alternate' type='text/html' href='http://thisweekinsecurity.blogspot.com/2008/05/welcome.html' title='Welcome'/><author><name>Orlando Stevenson</name><uri>http://www.blogger.com/profile/02449151162077284498</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_5nqcR2tOV4w/SZJxtcrPCLI/AAAAAAAAAAk/mgwMW-boy6w/S220/Snapshot+of+me+2.png'/></author><thr:total>0</thr:total></entry></feed>
