Posted October 16th, 2008 by
rybolov
After jamming to get a new budget and do annual FISMA reporting, our Government security leaders take a small breather before elections and transition to a new administration.
Similar Posts:
Posted in IKANHAZFIZMA | No Comments »
Tags: government • infosec • lolcats
Posted October 2nd, 2008 by
rybolov
Well, other than the fact that I think TIC isn’t about reducing the attack footprint of the Government (more to follow on this), it makes a fun compliance pinata to whack at.
Similar Posts:
Posted in IKANHAZFIZMA | No Comments »
Tags: itsatrap • lolcats
Posted September 25th, 2008 by
rybolov
Since it’s SCAP week here inside the beltway, I thought that it would be a fitting theme for today’s IKANHAZFIZMA.
Similar Posts:
Posted in IKANHAZFIZMA | 2 Comments »
Tags: government • infosec • lolcats • scap • security
Posted September 10th, 2008 by
rybolov
Not exactly security-related, but relevant nonetheless. And by transition, we mean the activity where all of the senior people in the executive branch rearrange themselves and are replaced by the new president’s appointees like a warped version of “upset the fruit basket”.
Similar Posts:
Posted in IKANHAZFIZMA | No Comments »
Tags: government • lolcats
Posted August 28th, 2008 by
rybolov
Pet peeve of just about every CISO in existance: the so-called “audit requirements”. What they really mean to say is “It’s on the checklist, so it has to be true, just do what I say”.
Without traceability to the actual requirement, items on a checklist are just that: items on a checklist.
Anyway, on to the lulz:
Similar Posts:
Posted in IKANHAZFIZMA | 1 Comment »
Tags: auditor • compliance • government • infosec • lolcats • security
Posted August 26th, 2008 by
rybolov
PE-52 Self-Destructing RFID Implants
Control:
The organization equips all employees with integrated storage media with self-igniting RFID devices so that they can be tracked throughout any government facility and destroyed upon command.
Supplemental Guidance:
All CISOs know that the information inside their employees’ heads is the real culprit. When they get a new job, they take that information–all learned on the taxpayers’ dime–with them. This is a much bigger security risk than the data on a USB drive could ever be. Instead of denying the obvious truth, why don’t we implement security controls to minimize the impact of out-of-control employees? This control is brought to you by L Bob Rife.
Control Enhancements:
(1) The organization destroys the information inside an employee’s head when the employee leaves the organization, much like hard drives need to be degaussed before they are sent for maintenance.
Low: MP-52 Moderate: MP-52(1) High: MP-52(1)
Similar Posts:
Posted in IKANHAZFIZMA | 2 Comments »
Tags: 800-53 • government • lolcats • risk • security