<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:admin="http://webns.net/mvcb/"
	xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Bruce Levinson &#45; CircleID</title>
		<link>http://www.circleid.com/</link>
		<description>Postings from Bruce Levinson on CircleID</description>
		<dc:language>en</dc:language>
		<dc:rights>Copyright 2012, unless where otherwise noted.</dc:rights>
		<dc:date>2011-10-27T08:35:00-08:00</dc:date>
		

		
		<item>
			<title> The Coming Cybersecurity Regulatory Revolution (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/20111027_the_coming_cybersecurity_regulatory_revolution</guid>
			<link>http://www.circleid.com/posts/20111027_the_coming_cybersecurity_regulatory_revolution</link>
			<description><![CDATA[Cybersecurity regulation will take its place alongside environmental regulation, health and safety regulation and financial regulation as a major federal activity. What is not yet clear is what form the regulations will take. FISMA controls, performance standards, consensus standards and industry-specific consortia standards are all possible regulatory approaches. What is not likely is an extended continuation of the current situation in which federal authorities have only limited, informal oversight of private sector cyberdefenses (or lack thereof). <a href="http://www.circleid.com/posts/20111027_the_coming_cybersecurity_regulatory_revolution">More...</a>]]></description>
			<dc:date>2011-10-27T08:35:00-08:00</dc:date>
		</item>
		
		<item>
			<title> Federal Cybersecurity Best Practices: FISMA Continuous Monitoring (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/federal_cybersecurity_best_practices_fisma_continuous_monitoring</guid>
			<link>http://www.circleid.com/posts/federal_cybersecurity_best_practices_fisma_continuous_monitoring</link>
			<description><![CDATA[Studies have found only limited, insufficient agency adherence with FISMA's (Federal Information Security Management Act) continuous monitoring mandates. One survey found almost half of federal IT professionals were unaware of continuous monitoring requirements. A recent GAO report found that two-thirds of agencies "did not adequately monitor networks" to protect them "from intentional or unintentional harm." <a href="http://www.circleid.com/posts/federal_cybersecurity_best_practices_fisma_continuous_monitoring">More...</a>]]></description>
			<dc:date>2011-10-13T16:59:00-08:00</dc:date>
		</item>
		
		<item>
			<title> FedRAMP: Critical to Cost-Effective Cloud Computing Cybersecurity (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/20110330_fedramp_critical_to_cost_effective_cloud_computing_cybersecurity</guid>
			<link>http://www.circleid.com/posts/20110330_fedramp_critical_to_cost_effective_cloud_computing_cybersecurity</link>
			<description><![CDATA[In September 2009, the Obama Administration announced the Federal Cloud Computing Initiative. As the government's CIO explained, cloud computing "has the potential to greatly reduce waste, increase data center efficiency and utilization rates, and lower operating costs." The Federal Risk and Authorization Management Program (FedRAMP) addresses the key elements of a cloud computing framework for federal agencies. <a href="http://www.circleid.com/posts/20110330_fedramp_critical_to_cost_effective_cloud_computing_cybersecurity">More...</a>]]></description>
			<dc:date>2011-03-30T07:41:00-08:00</dc:date>
		</item>
		
		<item>
			<title> NIST Cancels FISMA Continuous Monitoring Document's 2nd Public Draft (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/20110111_nist_cancels_fisma_continuous_monitoring_docs_2nd_public_draft</guid>
			<link>http://www.circleid.com/posts/20110111_nist_cancels_fisma_continuous_monitoring_docs_2nd_public_draft</link>
			<description><![CDATA[NIST has released a revised FIMSA Implementation Schedule that omits a previously planned Second Public Draft of SP 800-137: Information Security Continuous Monitoring for Federal Information Systems and Organizations. Instead, NIST plans to proceed directly to a Final Public Draft, now expected in May 2011. <a href="http://www.circleid.com/posts/20110111_nist_cancels_fisma_continuous_monitoring_docs_2nd_public_draft">More...</a>]]></description>
			<dc:date>2011-01-11T13:39:00-08:00</dc:date>
		</item>
		
		<item>
			<title> FISMA Standards Could Have a Major Impact on the Private Sector (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/20101123_fisma_standards_could_have_a_major_impact_on_the_private_sector</guid>
			<link>http://www.circleid.com/posts/20101123_fisma_standards_could_have_a_major_impact_on_the_private_sector</link>
			<description><![CDATA[The public is taking an increasing interest in ensuring that IT assets of federal agencies are protected from cybersecurity attacks. FISMA is addressing this concern, in part, by initiating a standard setting process for continuous monitoring. The actions taken by NIST for the federal sector could have a very significant impact on the private sector because pending legislation would provide the federal government with the authority to mandate cybesecurity measures on the private sector. <a href="http://www.circleid.com/posts/20101123_fisma_standards_could_have_a_major_impact_on_the_private_sector">More...</a>]]></description>
			<dc:date>2010-11-23T11:32:00-08:00</dc:date>
		</item>
		
		<item>
			<title> FISMA Focus: Continuously Monitoring the Cyber-Levee (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/fisma_focus_continuously_monitoring_the_cyber_levee</guid>
			<link>http://www.circleid.com/posts/fisma_focus_continuously_monitoring_the_cyber_levee</link>
			<description><![CDATA[NIST's release of their initial public draft of SP 800-137, <em>Guide for Continuous Monitoring of Information Systems and Organizations</em> will create a set of challenges for the federal cybersecurity community. Agencies and contractors will need to shape the document through the multi-stage revision process while continuing to implement their own continuous monitoring measures. <a href="http://www.circleid.com/posts/fisma_focus_continuously_monitoring_the_cyber_levee">More...</a>]]></description>
			<dc:date>2010-11-09T09:30:00-08:00</dc:date>
		</item>
		
		<item>
			<title> Protection of Intellectual Property: The Core of the Net Neutrality Debate (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/20100817_protection_of_intellectual_property_core_of_net_neutrality_debate</guid>
			<link>http://www.circleid.com/posts/20100817_protection_of_intellectual_property_core_of_net_neutrality_debate</link>
			<description><![CDATA[It didn't take long for criticism of the Verizon/Google net neutrality proposal to start pouring in. "[I]nterest groups, bloggers, and even Google fanboys [have started] discrediting the plan" according to one trade publication. Although most of the commentary simply echoes various groups' long-held positions, the Electronic Frontier Foundation, the nation's foremost cyber-rights watchdog, provided a crucial insight about the plan that goes to the core of the net neutrality issue. <a href="http://www.circleid.com/posts/20100817_protection_of_intellectual_property_core_of_net_neutrality_debate">More...</a>]]></description>
			<dc:date>2010-08-17T08:13:00-08:00</dc:date>
		</item>
		
		<item>
			<title> Time to Regulate Google? (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/time_to_regulate_google</guid>
			<link>http://www.circleid.com/posts/time_to_regulate_google</link>
			<description><![CDATA[Should Google's provision of information services be regulated? Yes, if the decision is based on Google's own standards for determining whether to regulate tele-information companies. In recent comments to the FCC, Google described "broadband openness" rules, aka net neutrality, as a "fundamental necessity." Without such rules, the search engine giant, aka Big Search, fears that broadband providers would "promote only their own pecuniary interests over the far broader interests of Internet users..." As the Wall Street Journal noted last year, however, Google engages in the same type of discriminatory service practices they want the federal government to prohibit... <a href="http://www.circleid.com/posts/time_to_regulate_google">More...</a>]]></description>
			<dc:date>2010-06-22T08:14:00-08:00</dc:date>
		</item>
		
		<item>
			<title> The U.N.'s Threat to the Net (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/the_un_threat_to_the_net</guid>
			<link>http://www.circleid.com/posts/the_un_threat_to_the_net</link>
			<description><![CDATA[United Nations Secretary General Kofi Annan, writing in <em>The Washington Post</em>, declared that it is a "mistaken notion" that the U.N. "wants to 'take over,' police or otherwise control the Internet." Unfortunately, neither the World Summit on the Information Society (WSIS), the WSIS' Working Group on Internet Governance (WGIG) or the Secretary General's column give comfort to those committed to cyber-freedom. <a href="http://www.circleid.com/posts/the_un_threat_to_the_net">More...</a>]]></description>
			<dc:date>2005-11-08T18:04:46-08:00</dc:date>
		</item>
		
		<item>
			<title> Should the Government Prepare a Preemptive Cyber-Attack? (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/should_the_government_prepare_a_preemptive_cyber_attack</guid>
			<link>http://www.circleid.com/posts/should_the_government_prepare_a_preemptive_cyber_attack</link>
			<description><![CDATA[The House Committee on Science [url=http://www.house.gov/science/hearings/full05/sept15/index.htm]recently held a hearing[/url] to "examine the extent of U.S. vulnerability to cyber attacks on critical infrastructure such as utility systems, and what the federal government and private sector are doing, and should be doing, to prevent and prepare for such attacks." Specific issues addressed at the hearing included whether: 1) the U.S. is able to detect, respond to, and recover from cyber-attacks on critical infrastructure; and 2) is there a clear line of responsibility within the federal government to deal with cybersecurity... <a href="http://www.circleid.com/posts/should_the_government_prepare_a_preemptive_cyber_attack">More...</a>]]></description>
			<dc:date>2005-09-26T15:38:54-08:00</dc:date>
		</item>
		
		<item>
			<title> Ending Cyber-Hubris (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/ending_cyber_hubris</guid>
			<link>http://www.circleid.com/posts/ending_cyber_hubris</link>
			<description><![CDATA[Hurricane Katrina will lead the endless finger pointing about what should have been done to strengthen the levees before the storm. However, as a former senior FEMA official under the Clinton Administration explained, "There's only two kinds of levees. Ones that have failed and those that will fail." The same is true for cyber-levees.  <a href="http://www.circleid.com/posts/ending_cyber_hubris">More...</a>]]></description>
			<dc:date>2005-09-14T06:58:26-08:00</dc:date>
		</item>
		
		<item>
			<title> Time to Play Offense (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/time_to_play_offense</guid>
			<link>http://www.circleid.com/posts/time_to_play_offense</link>
			<description><![CDATA[The United States is under cyber-attack. An article in Time magazine titled "The Invasion of the Chinese Cyberspies" discusses a computer-network security official for Sandia National Laboratories who had been "tirelessly pursuing a group of suspected Chinese cyberspies all over the world." The article notes that the cyberespionage ring, known to US investigators as Titan Rain, has been "penetrating secure computer networks at the country's most sensitive military bases, defense contractors and aerospace companies." <a href="http://www.circleid.com/posts/time_to_play_offense">More...</a>]]></description>
			<dc:date>2005-08-30T09:54:03-08:00</dc:date>
		</item>
		
		<item>
			<title> Creating a National Cybersecurity Framework: Need For New Regulation? (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/creating_a_national_cybersecurity_framework_need_for_new_regulation</guid>
			<link>http://www.circleid.com/posts/creating_a_national_cybersecurity_framework_need_for_new_regulation</link>
			<description><![CDATA[The Congressional Research Service (CRS) recently released a major new study examining cybersecurity. The report, "Creating a National Framework for Cybersecurity: An Analysis of Issues and Options" discusses a variety of significant public and private cybersecurity concerns. The CRS analysis lists several broad options for addressing cybersecurity weaknesses ranging from adopting standards and certification to promulgating best practices and guidelines and use of audits among other measures. <a href="http://www.circleid.com/posts/creating_a_national_cybersecurity_framework_need_for_new_regulation">More...</a>]]></description>
			<dc:date>2005-04-11T12:17:13-08:00</dc:date>
		</item>
		
		<item>
			<title> Controlling Cyber Dissidents? (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/controlling_cyber_dissidents</guid>
			<link>http://www.circleid.com/posts/controlling_cyber_dissidents</link>
			<description><![CDATA[Blogging is not only a well-established element of pop culture, it has become a tremendously influential communications mechanism. As early as March 2002, an article in Wired discussed the blogging "revolution" and declared that blogging "could be to words what Napster was to music - except this time, it'll really work." <a href="http://www.circleid.com/posts/controlling_cyber_dissidents">More...</a>]]></description>
			<dc:date>2005-02-15T10:43:52-08:00</dc:date>
		</item>
		
		<item>
			<title> Preventing A New World Internet Order (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/preventing_a_new_world_internet_order</guid>
			<link>http://www.circleid.com/posts/preventing_a_new_world_internet_order</link>
			<description><![CDATA[If anyone needs another reason why the UN should not be in charge of the internet, they need look no further than the upcoming UNESCO conference on "Freedom of Expression in Cyberspace." The United Nations Education Scientific and Cultural Organization conference will discuss "whether universal free expression standards should be applied to the Internet and how free expression can be protected while respecting individual privacy, national laws and cultural differences." The conference is being held in preparation for the second phase of the UN's World Summit on the Information Society (WSIS)." <a href="http://www.circleid.com/posts/preventing_a_new_world_internet_order">More...</a>]]></description>
			<dc:date>2005-01-18T12:16:49-08:00</dc:date>
		</item>
		
	</channel>
</rss>
