Compliance & Regulations

August 26, 2010, 12:56PM

California Bill Ups the Ante on Breach Notifications

The new bill requires that the company include the type of personal information exposed in the breach; the date or estimated date of the breach; a general description of the incident itself; and toll-free numbers and addresses for credit reporting agencies if the breach included social security numbers, driver's licenses, or California ID cards. Read the full article. [Dark Reading]

Shorten URL: Click to copy short URL. Click to copy to clipboard or post to Twitter

August 24, 2010, 12:13AM Threatpost Original

U.S. Government Publishes List of Top IT Projects

HED: Security and data integration projects top list of top .GOV IT projects
DEK: Stovepipe busting and data sharing are common themes as Uncle Sam details the top IT projects. 
The White House's Office of Management and Budget (OMB) on Monday released its list of the top 26 government IT projects, as part of an Obama Administration effort to reform the way the Federal Government manages IT projects, with a focus on bursting silos that prevent agencies and personnel from sharing valuable data. 
The top projects, totalling $29.3 billion, stretch across almost all the major government departments, many seeking to tie together disparate government agencies or stovepiped stores of government information. IT and Homeland security projects figure prominently on the list, as well, including efforts to revive now notorious boondoggles like the FBI's Sentinel data project, and a $473 million request for a Homeland Security Information Network (HSIN) project. 
The announcement on Monday was part of a larger Obama Administration effort to improve the efficacy of government-funded IT projects, with a goal of faster implementations and fewer cost overruns for a federal bureaucracy that is infamous for allowing IT projects run amok. In a memo dated July 28, Federal CIO Vivek Kundra said that each agency would be asked to identify high-risk IT projects, create a risk profile for them and develop improvement plans for the projects. 
The projects and improvement plans will ultimately be reviewed by Kundra in so-called "TechStat Accountability Sessions" in the fourth quarter, 2010. The outcome of those sessions will determine budget requests for FY 2012 and on further allocations in FY 2011, according to an OMB memo. 
Physical and IT security related projects are top priorities, ranging from the Department of Interior's $122.8 million request for IMARS - the Incident Management Analysis and Reporting System to allow data sharing and analysis, to the FBI's $3.4 billion frequest for a Next Generation Identification (NGI), an effort to improve the FBI's automated fingerprint identification system to reduce print match times from hours to minutes for criminal checks. 
But the list also breathes new life into some moribund government IT projects, notably: the FBI's Sentinel Web based case management project - now estimated to cost Uncle Sam more than $550 million. 
Sentinel, originally awarded to Defense giant Lockheed Martin, is described as a "Web-based case management system" for the FBI to manage both case information and other, non-case related data using elements of both document management and search to improve disjointed and outdated investigation tools at the FBI. The project has already consumed some $375 million since its inception in 2004 and is projected to cost more than $550 million by the time it is completed in 2016. 
In recent months, the FBI announced that it would delay the Sentinel Project and try to shift work on the project to internal IT staff rather than Lockheed Martin contractors. A  critical report from the Justice Department's Inspector General noted that the project was apparently without a clear focus or completion date, despite four years and more than $300 million in taxpayer dollars spent. Estimates at that time put the total cost of the project at $450 million and the completion date in 2011, but the latest report from OMB ups the pricetag  by another $100 million, while pushing the completion date out a full five years. 
That doesn't bode well for the Obama Administration's efforts to reign in the cost of IT projects, said David Williams of the non-profit group Citizens Against Government Waste. 
"What happens is that contracting companies look at government contracts as cash cows, and there's no history of putting contractors feet to the fire," he said. 
Williams said that having a list of priorities is a fine idea - but won't bring about much change without more accountability. 
"Its important to prioritize, but its also important to have links to results," Williams said. 
Williams said that the U.S. government would do well to harness the energies of the private sector to get important IT projects completed - following the model of NASA with its X prize. "Instead of doing it in house, just say 'here's what we want to accomplish. Come up with the design, and we'll award you the contract.'" 
The private sector has already proven much more adept at designing inexpensive and user friendly equivalents of many of the most notorious IT boondoggles on the federal government's roster, said Williams. That could include the Sentinel case management system, or the Department of Transportation's En Route Automation Modernization (ERAM) program to replace aged air traffic control systems used by the FAA -- a 10 year old project that has already cost $2 billion and is now estimated to require another 10 years and $1 billion to complete. 
"The frustruation is that we live in such a fast paced, technological world," said Williams "We need to bring technology into this and unleash the private sector."

The White House's Office of Management and Budget (OMB) on Monday released its list of the top 26 government IT projects, as part of an Obama Administration effort to reform the way the Federal Government manages IT projects, with a focus on bursting silos that prevent agencies and personnel from sharing valuable data. 

Shorten URL: Click to copy short URL. Click to copy to clipboard or post to Twitter

August 23, 2010, 10:04AM

Malware Cited As Accomplice to 2008 Spanair Crash

A virus-carrying USB thumb drive has been implicated in the 2008 crash of a Spanish jetliner, the deadliest air disaster in Spanish history. Read the full article. [El Pais]

Shorten URL: Click to copy short URL. Click to copy to clipboard or post to Twitter

August 18, 2010, 5:15PM

A Soldier's Hacked Smartphone Is Risky

Hacked smartphones could endanger troops by sending location data to the enemy using mechanisms similar to those employed by recently discovered Android malware, experts say. Read the full article. [Network World]

Shorten URL: Click to copy short URL. Click to copy to clipboard or post to Twitter

August 17, 2010, 1:14PM Threatpost Original

HP Snags Application Testing Firm Fortify

The drumbeat for more secure application development picked up pace on Tuesday, with news that software giant HP had acquired privately funded Fortify Software, a maker of static code analysis tools, for an undisclosed amount.

Shorten URL: Click to copy short URL. Click to copy to clipboard or post to Twitter

August 11, 2010, 10:15AM Threatpost Original

Like Windows Before It, Is Android Headed For a Fall?

By most measures, Google’s Android operating system for mobile devices has been a raging success. Since it was introduced in late 2007, Android has climbed (quickly), replacing Research in Motion’s Blackberry as the top-ranked mobile phone operating system in the U.S. when measured by market share.

Shorten URL: Click to copy short URL. Click to copy to clipboard or post to Twitter

August 9, 2010, 12:17PM

RBS WorldPay Suspect Extradited to U.S.

Federal prosecutors say they have have extradited one of the leaders of an international crime ring accused of hacking in to bank card processor RBS WorldPay and stealing more than $9.4m in a 12-hour period. Read the full article. [The Register]

Shorten URL: Click to copy short URL. Click to copy to clipboard or post to Twitter

August 9, 2010, 12:10PM

SF Network Admin Terry Childs Gets 4 Years

A city of San Francisco network administrator who refused to hand over administrative passwords to the city's network was sentenced to four years in state prison Friday. Read the full article. [IDG News Service]

Shorten URL: Click to copy short URL. Click to copy to clipboard or post to Twitter

August 5, 2010, 9:53AM Threatpost Original

New Certifications Will Set High Bar for IT Security Pros

A new non-profit group is developing certifications for information technology security professionals that will set a high bar for IT security practitioners in areas like penetration testing, code auditing and control systems operation.

Shorten URL: Click to copy short URL. Click to copy to clipboard or post to Twitter

August 3, 2010, 3:41PM Threatpost Original

Vulnerability Broker Draws Line in Disclosure Sand

Looking to put pressure on software vendors who procrastinate on fixing security flaws, the world's biggest broker of vulnerability data is drawing a line in the sand.

Starting August 4, TippingPoint's Zero Day Initiative (ZDI) will enforce a six-month deadline for patches on all vulnerabilities bought from the security research community and reported to software vendors.

Shorten URL: Click to copy short URL. Click to copy to clipboard or post to Twitter

Syndicate content

 

Copyright © 2010 threatpost.com | Terms of Service | Privacy