Posted February 17th, 2009 by
rybolov
This weekend, Joe Faraone (Vlad the Impaler), Graydon Mckee, and I teamed up to be a guest panel for Michael Santarcangelo’s Security Catalyst podcast. We wax esoterically on the fine points of certification and accreditation and what kind of value that it brings to an agency or company that does it right.
You can check it out here.
Similar Posts:
Posted in Speaking, What Works | No Comments »
Tags: accreditation • C&A • certification • fisma • government • infosec • security • speaking
Posted February 10th, 2009 by
rybolov
The accreditation decision is one of the most key activities in how the US Government secures its systems. It’s also one of the most misunderstood activities. This slideshow aims to explain the role of the Authorizing Official and to give you some understanding into why and how accreditation decisions are made.
I would like to give a big thanks to Joe Faraone and Graydon McKee who helped out.
The presentation is licensed under Creative Commons, so feel free to download it, email it, and use it in your own training.
Similar Posts:
Posted in FISMA, NIST, Risk Management, Speaking | 5 Comments »
Tags: 800-37 • accreditation • C&A • certification • compliance • fisma • government • infosec • management • NIST • omb • risk • security • speaking
Posted September 22nd, 2008 by
rybolov
The Potomac Forum crew is back at it again with a C&A seminar on the 15th and 16th. While 2 days isn’t long enough to earn your black belt at C&A-Foo, it is enough so that if you’re a solid program manager or technical lead, you’ll walk out being at least able to understand the core of the process.
As usual, some of the instructors should be familiar to my blog readers. =)
Similar Posts:
Posted in FISMA, Speaking | No Comments »
Tags: 800-37 • 800-53 • 800-53A • accreditation • C&A • catalogofcontrols • categorization • certification • compliance • datacentric • fips-199 • fisma • government • infosec • management • risk • security • speaking
Posted July 28th, 2008 by
rybolov
Potomac Forum is having a 2-day C&A seminar on August 6th and 7th. It will be unusually good this time because I won’t be there to drag everybody down–I’ll be on the road for some training. =) Anyway, check it out and say hi to my instructors from me.
Similar Posts:
Posted in FISMA, Speaking | 1 Comment »
Tags: 800-53 • 800-53A • C&A • catalogofcontrols • compliance • fisma • gettingtogreen • government • infosec • infosharing • management • omb • risk • scalability • security • seminar • speaking
Posted June 3rd, 2008 by
rybolov
Well, this is a little bit of a departure from my usual random digital scribblings that I call a blog: I partnered up with Vlad the Impaler and we created a slideshow complete with notes about why you should care about security and the Government and what you can learn from watching the Government succeed or fail.
The .pdf of the presentation is here. Feel free to share with your friends, coworkers, and co-conspirators.
Similar Posts:
Posted in FISMA, Speaking | 4 Comments »
Tags: accounting • auditor • collusion • compliance • fisma • government • infosec • infosharing • management • moneymoneymoney • omb • pii • scalability • scap • security • stategovernment
Posted May 13th, 2008 by
rybolov
A couple of weeks ago, Martin McKeay was in town and recorded an interview with me. I wax poetically on my typical things–FISMA, risk assessment, anti-compliance.
The funny thing is, weeks later, I listened to myself and I actually sound like I know something…. Who woulda thunk it? =)
Similar Posts:
Posted in FISMA, Risk Management, Speaking, The Guerilla CISO | No Comments »
Tags: cashcows • compliance • fisma • government • management • security