<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: US Gov&#8217;t Not Leading By Example</title>
	<atom:link href="http://www.digitalbond.com/index.php/2007/11/15/us-govt-not-leading-by-example/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.digitalbond.com/index.php/2007/11/15/us-govt-not-leading-by-example/</link>
	<description>This Month in Control System Security</description>
	<lastBuildDate>Fri, 30 Jul 2010 09:35:51 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Ralph Langner</title>
		<link>http://www.digitalbond.com/index.php/2007/11/15/us-govt-not-leading-by-example/comment-page-1/#comment-8918</link>
		<dc:creator>Ralph Langner</dc:creator>
		<pubDate>Fri, 16 Nov 2007 15:56:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.digitalbond.com/index.php/2007/11/15/us-govt-not-leading-by-example/#comment-8918</guid>
		<description>You guys have classes on basket weaving and soap opera? Well, that&#039;s what I call leading by example!
;-)</description>
		<content:encoded><![CDATA[<p>You guys have classes on basket weaving and soap opera? Well, that&#8217;s what I call leading by example!<br />
 <img src='http://www.digitalbond.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rybolov</title>
		<link>http://www.digitalbond.com/index.php/2007/11/15/us-govt-not-leading-by-example/comment-page-1/#comment-8916</link>
		<dc:creator>rybolov</dc:creator>
		<pubDate>Fri, 16 Nov 2007 13:31:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.digitalbond.com/index.php/2007/11/15/us-govt-not-leading-by-example/#comment-8916</guid>
		<description>Grades are a metric, and a very simplistic one at that.  What it measures is your information security management capability.  If the agencies don&#039;t have the budget (given by Congress) AND the execution by the agencies, then they will not improve.  If I&#039;m a CISO in an agency, I can only control half of the equation.  Sounds like a plan for failure?  Yes it is.  Tell your congressional representatives that it&#039;s partly their fault, they need to get the message, too.

Now the reason for the sad state of government IT security is simple:  If you&#039;re the Coast Guard, your job is rescuing capsized ships, not securing your IT systems.  IT security is an &quot;enabler&quot; that lets you get your primary mission done.  Now think about that, it means that if you have a choice to buy a new cutter or do IT systems maintenance, which one are you going to choose?

BTW, Congress does not get grades.  The grades are only for Executive Branch agencies, so there are some Legislative and Judicial organizations that might surprise you:  Congressional Printing and Mailing Office (can&#039;t remember the exact name), Capital Police (guard Capital Hill and environs), and Administrative Office of the US Courts (records and archives case data for all cases in the US Federal Courts System).</description>
		<content:encoded><![CDATA[<p>Grades are a metric, and a very simplistic one at that.  What it measures is your information security management capability.  If the agencies don&#8217;t have the budget (given by Congress) AND the execution by the agencies, then they will not improve.  If I&#8217;m a CISO in an agency, I can only control half of the equation.  Sounds like a plan for failure?  Yes it is.  Tell your congressional representatives that it&#8217;s partly their fault, they need to get the message, too.</p>
<p>Now the reason for the sad state of government IT security is simple:  If you&#8217;re the Coast Guard, your job is rescuing capsized ships, not securing your IT systems.  IT security is an &#8220;enabler&#8221; that lets you get your primary mission done.  Now think about that, it means that if you have a choice to buy a new cutter or do IT systems maintenance, which one are you going to choose?</p>
<p>BTW, Congress does not get grades.  The grades are only for Executive Branch agencies, so there are some Legislative and Judicial organizations that might surprise you:  Congressional Printing and Mailing Office (can&#8217;t remember the exact name), Capital Police (guard Capital Hill and environs), and Administrative Office of the US Courts (records and archives case data for all cases in the US Federal Courts System).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jake Brodsky</title>
		<link>http://www.digitalbond.com/index.php/2007/11/15/us-govt-not-leading-by-example/comment-page-1/#comment-8915</link>
		<dc:creator>Jake Brodsky</dc:creator>
		<pubDate>Fri, 16 Nov 2007 11:59:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.digitalbond.com/index.php/2007/11/15/us-govt-not-leading-by-example/#comment-8915</guid>
		<description>That may be true, Dale.  However, this is like classifying a person based upon a single GPA number.  Yes, they might have a very high GPA.  However, it might be because they&#039;re taking classes in basket weaving, music appreciation, and soap operas instead of calculus, literature, and physics.  

Furthermore, security is one of those disciplines where the average doesn&#039;t matter.  If you&#039;ve got a really strong front gate, but a wide open back door, you&#039;re not better off than someone with two reasonably secure doors.  

Single letter grades for security are a prelude to a political attack.  It doesn&#039;t matter on what basis these grades were given.  They&#039;re meaningless except to those who seek to make policy all over you.</description>
		<content:encoded><![CDATA[<p>That may be true, Dale.  However, this is like classifying a person based upon a single GPA number.  Yes, they might have a very high GPA.  However, it might be because they&#8217;re taking classes in basket weaving, music appreciation, and soap operas instead of calculus, literature, and physics.  </p>
<p>Furthermore, security is one of those disciplines where the average doesn&#8217;t matter.  If you&#8217;ve got a really strong front gate, but a wide open back door, you&#8217;re not better off than someone with two reasonably secure doors.  </p>
<p>Single letter grades for security are a prelude to a political attack.  It doesn&#8217;t matter on what basis these grades were given.  They&#8217;re meaningless except to those who seek to make policy all over you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dale Peterson</title>
		<link>http://www.digitalbond.com/index.php/2007/11/15/us-govt-not-leading-by-example/comment-page-1/#comment-8911</link>
		<dc:creator>Dale Peterson</dc:creator>
		<pubDate>Thu, 15 Nov 2007 23:32:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.digitalbond.com/index.php/2007/11/15/us-govt-not-leading-by-example/#comment-8911</guid>
		<description>Jake - I believe these grades are based on their compliance with SP800-53, which is the standard that some of the House Committee members suggested should replace NERC CIP. The systems may be apples to oranges, but the criteria is somewhat consistent.</description>
		<content:encoded><![CDATA[<p>Jake &#8211; I believe these grades are based on their compliance with SP800-53, which is the standard that some of the House Committee members suggested should replace NERC CIP. The systems may be apples to oranges, but the criteria is somewhat consistent.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jake Brodsky</title>
		<link>http://www.digitalbond.com/index.php/2007/11/15/us-govt-not-leading-by-example/comment-page-1/#comment-8910</link>
		<dc:creator>Jake Brodsky</dc:creator>
		<pubDate>Thu, 15 Nov 2007 22:16:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.digitalbond.com/index.php/2007/11/15/us-govt-not-leading-by-example/#comment-8910</guid>
		<description>These grades compare apples to oranges.  I wouldn&#039;t put too much stock in them.  Those who create such things usually have an axe to grind.  This axe is then used to cut some political opponent down to size.  

If cyber security for normal business applications is hard, it pales in comparison to the situations we typically encounter with industrial control systems.  While I agree that unless legislation happens, we&#039;re not likely to see much activity on this front; I still maintain that people who lob these idiotic one letter grades at each other are not suited for the job of writing such legislation.</description>
		<content:encoded><![CDATA[<p>These grades compare apples to oranges.  I wouldn&#8217;t put too much stock in them.  Those who create such things usually have an axe to grind.  This axe is then used to cut some political opponent down to size.  </p>
<p>If cyber security for normal business applications is hard, it pales in comparison to the situations we typically encounter with industrial control systems.  While I agree that unless legislation happens, we&#8217;re not likely to see much activity on this front; I still maintain that people who lob these idiotic one letter grades at each other are not suited for the job of writing such legislation.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
