<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://connect.educause.edu" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">
<channel>
 <title>EDUCAUSE | Department of Homeland Security</title>
 <link>http://connect.educause.edu/browse/content/blog/2000</link>
 <image>
    <title>EDUCAUSE CONNECT</title> 
    <link>http://connect.educause.edu/browse/content/blog/2000</link> 
    <url>http://connect.educause.edu/educause/images/e_rss.png</url> 
 </image>

  <itunes:subtitle>events, concepts, and conversation from EDUCAUSE</itunes:subtitle>
  <itunes:author>The EDUCAUSE Podcast Crew</itunes:author>
  <itunes:summary>EDUCAUSE is a nonprofit association whose mission is to advance higher education by promoting the intelligent use of information technology.  Our podcasts provide information about a range of topics including Leadership, Policy and Law, Teaching and Learning, Emerging Technologies, Open Source, Research Computing, Cyberinfrastructure, and Digitial Libraries. </itunes:summary>
  <itunes:new-feed-url>http://connect.educause.edu/browse/content/node/691/list/feed</itunes:new-feed-url>
  <itunes:image href="http://connect.educause.edu/educause/images/e_rss.png" />
  <itunes:category text="Education">
  	<itunes:category text="Education Technology"/>
  	<itunes:category text="Higher Education"/>
  </itunes:category>
  <itunes:category text="Technology">
  	<itunes:category text="Tech News"/>
  </itunes:category>

 <description>Recent blog entries tagged with Department of Homeland Security.</description>
 <language>en</language>

<item>
 <title>DHS and NCSA Launch National Cyber Security Awareness Month with National Press Club Event</title>
 <link>http://connect.educause.edu/display/47394</link>
 <description>&lt;p&gt;The fifth annual National Cyber Security Awareness Month (NCSAM) was kicked off earlier today at an event held at the National Press Club in Washington, D.C. The event featured a panel including DHS Assistant Secretary for Cyber Security and Communications Gregory Garcia, National Cyber Security Alliance (NCSA) Executive Director Michael Kaiser, and Symantec Senior Director for Public Affairs Adam Rak.&lt;/p&gt;&lt;p&gt;Secretary Garcia described DHS efforts to improve cybersecurity and emphasize it as &lt;em&gt;A Shared Responsibility&lt;/em&gt;. He cited increased government investment as a sign of the high priority given to cybersecurity by the federal government. The NCSA&#039;s Kaiser urged Americans to &amp;quot;keep up your defenses and hone your instincts&amp;quot;. He explained that the NCSA will undertake a new &amp;quot;www&amp;quot; campaign in the coming months advising consumers to ask: &lt;strong&gt;who&lt;/strong&gt; is asking for your information, &lt;strong&gt;what&lt;/strong&gt; are they asking for, and &lt;strong&gt;why&lt;/strong&gt; do they need it.&lt;/p&gt;&lt;p&gt;The event also featured the release of a new cyber security study by the NCSA and Symantec, makers of Norton security software. According to a &lt;a href=&quot;http://staysafeonline.mediaroom.com/index.php?s=43&amp;amp;item=33&quot;&gt;press release&lt;/a&gt;, &amp;quot;a large number of Americans still fail to use basic Internet security tools and there remains a substantial gap between the protections people think they have and what is actually installed on their computers.&amp;quot; Most notable is the finding that more than 80 percent of Americans claim to have a firewall -- designed to prevent hackers and criminals from stealing personal information -- installed on their computer. Yet, in reality only 42 percent had adequate firewall protection. More details about the study are provided in a &lt;a href=&quot;http://staysafeonline.mediaroom.com/file.php/92/NCSA_Symantec_Study_FactSheet.pdf&quot;&gt;Fact Sheet&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;The NCSA targets home users, small businesses, k-12 schools, and higher education for its awareness campaigns. The EDUCAUSE/Internet2 Security Task Force takes the leadership for awareness efforts at our nations colleges and universities. A press release that described &lt;a href=&quot;http://www.educause.edu/PressReleases/CybersecurityAwarenessaPriorit/132170&quot;&gt;Cybersecurity Awareness A Priority for Higher Education&lt;/a&gt; was issued last week in advance of NCSAM.&lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/47394#comments</comments>
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/cybersecurity+awareness/6469">cybersecurity awareness</category>
 <category domain="http://connect.educause.edu/tag/Department+of+Homeland+Security/2000">Department of Homeland Security</category>
 <category domain="http://connect.educause.edu/tag/national+cyber+security+awareness+month/6470">national cyber security awareness month</category>
 <category domain="http://connect.educause.edu/tag/Security+Awareness/258">Security Awareness</category>
 <category domain="http://connect.educause.edu/tag/Washington+Update/5405">Washington Update</category>
 <pubDate>Thu, 02 Oct 2008 21:05:52 -0500</pubDate>
 <dc:creator>Rodney</dc:creator>
 <guid isPermaLink="false">47394 at http://connect.educause.edu</guid>
</item>
<item>
 <title>DHS Releases IT Security Essential Body of Knowledge</title>
 <link>http://connect.educause.edu/display/47387</link>
 <description>&lt;p&gt;The U.S. Department of Homeland Security (DHS) has published the &lt;a href=&quot;http://www.us-cert.gov/ITSecurityEBK/EBK2008.pdf&quot;&gt;IT Security Essential Body of Knowledge&lt;/a&gt; (EBK). A &lt;a href=&quot;http://www.us-cert.gov/ITSecurityEBK/EBKGlossary08.pdf&quot;&gt;Glossary of Key Terms&lt;/a&gt; used in the EBK is also provided.&lt;/p&gt;&lt;p&gt;According to the &lt;a href=&quot;http://www.us-cert.gov/ITSecurityEBK/&quot;&gt;overview on the US-CERT website&lt;/a&gt;:&lt;/p&gt;&lt;blockquote&gt;	&lt;p&gt;The IT Security EBK conceptualizes IT security skill requirements in a new way to address evolving IT security challenges. The EBK characterizes the IT security workforce and provides a national baseline representing the essential knowledge and skills that IT security practitioners should have to perform specific roles and responsibilities.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;The EBK was featured in a November 2007 &lt;a href=&quot;http://net.educause.edu/LIVE0722&quot;&gt;EDUCAUSE Live! presentation&lt;/a&gt; when DHS was accepting comments on a draft version of the document.&lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/47387#comments</comments>
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/Cybersecurity+Policy/633">Cybersecurity Policy</category>
 <category domain="http://connect.educause.edu/tag/cybersecurity+training/6467">cybersecurity training</category>
 <category domain="http://connect.educause.edu/tag/Department+of+Homeland+Security/2000">Department of Homeland Security</category>
 <category domain="http://connect.educause.edu/tag/information+security+officer/6468">information security officer</category>
 <category domain="http://connect.educause.edu/tag/Policy+and+Law%3A+Federal/101">Policy and Law: Federal</category>
 <category domain="http://connect.educause.edu/tag/Security+Task+Force+Announcements/699">Security Task Force Announcements</category>
 <pubDate>Thu, 02 Oct 2008 10:42:24 -0500</pubDate>
 <dc:creator>vvogel</dc:creator>
 <guid isPermaLink="false">47387 at http://connect.educause.edu</guid>
</item>
<item>
 <title>DHS Releases IT Security Essential Body of Knowledge</title>
 <link>http://connect.educause.edu/display/47382</link>
 <description>&lt;p&gt;The U.S. Department of Homeland Security (DHS) has published the &lt;a href=&quot;http://www.us-cert.gov/ITSecurityEBK/EBK2008.pdf&quot;&gt;IT Security Essential Body of Knowledge&lt;/a&gt; (EBK). A &lt;a href=&quot;http://www.us-cert.gov/ITSecurityEBK/EBKGlossary08.pdf&quot;&gt;Glossary of Key Terms&lt;/a&gt; used in the EBK is also provided.&lt;/p&gt;&lt;p&gt;According to the &lt;a href=&quot;http://www.us-cert.gov/ITSecurityEBK/&quot;&gt;overview on the US-CERT website&lt;/a&gt;:&lt;/p&gt;&lt;blockquote&gt;	&lt;p&gt;The IT Security EBK conceptualizes IT security skill requirements in a new way to address evolving IT security challenges. The EBK characterizes the IT security workforce and provides a national baseline representing the essential knowledge and skills that IT security practitioners should have to perform specific roles and responsibilities.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;The EBK was featured in November 2007 on &lt;a href=&quot;http://net.educause.edu/LIVE0722&quot;&gt;EDUCAUSE Live! presentation&lt;/a&gt; when DHS was accepting comments on a draft version of the document.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/47382#comments</comments>
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/Cybersecurity+Policy/633">Cybersecurity Policy</category>
 <category domain="http://connect.educause.edu/tag/cybersecurity+training/6467">cybersecurity training</category>
 <category domain="http://connect.educause.edu/tag/Department+of+Homeland+Security/2000">Department of Homeland Security</category>
 <category domain="http://connect.educause.edu/tag/information+security+officer/6468">information security officer</category>
 <category domain="http://connect.educause.edu/tag/Policy+and+Law%3A+Federal/101">Policy and Law: Federal</category>
 <category domain="http://connect.educause.edu/tag/Washington+Update/5405">Washington Update</category>
 <pubDate>Wed, 01 Oct 2008 18:38:14 -0500</pubDate>
 <dc:creator>Rodney</dc:creator>
 <guid isPermaLink="false">47382 at http://connect.educause.edu</guid>
</item>
<item>
 <title>Top 10 Challenges Facing Next Secretary of Homeland Security</title>
 <link>http://connect.educause.edu/display/47339</link>
 <description>&lt;p&gt;In anticipation of an administration change following the next presidential election, the Homeland Security Advisory Council has issued a report entitled &lt;a href=&quot;http://www.dhs.gov/xlibrary/assets/hsac_dhs_top_10_challenges_report.pdf&quot;&gt;Top Ten Challenges Facing The Next Secretary of Homeland Security.&lt;/a&gt; The report concluded:&lt;/p&gt;&lt;div class=&quot;fright&quot;&gt;	&lt;p&gt;Ultimately, homeland security is about synchronizing efforts with multiple partners across the landscape of America. The ability to successfully establish and maintain meaningful partnerships at all levels of government and society for the purpose of securing the homeland may be the greatest, ongoing challenge facing the next Secreatary, as well as his or her successors.&lt;/p&gt;&lt;/div&gt;&lt;p&gt;The key challenges and recommendations follow:&lt;/p&gt;&lt;ul&gt;	&lt;li&gt;#1: Homeland security is more than just a single cabinet Department.&lt;/li&gt;	&lt;li&gt;#2: Quickly get an inventory of the Department&#039;s commitments and deadlines and work with Congress to achieve a rational system of oversight.&lt;/li&gt;	&lt;li&gt;#3: Continue to improve intelligence and information sharing.&lt;/li&gt;	&lt;li&gt;#4: Build a cadre of homeland security leadership through a unified national system of training and education.&lt;/li&gt;	&lt;li&gt;#5: Build the strong research and development, procurement and acquisition process necessary to support the Department&#039;s various missions.&lt;/li&gt;	&lt;li&gt;#6: The work of strengthening our Nation&#039;s disaster response capabilities is not complete.&lt;/li&gt;	&lt;li&gt;#7: Lead the building of a resilient America.&lt;/li&gt;	&lt;li&gt;#8: Find the right balance between secure borders and open doors to travelers, students, and commerce.&lt;/li&gt;	&lt;li&gt;#9: Improve risk management and risk communications for homeland security.&lt;/li&gt;	&lt;li&gt;#10: Sustainability of our Nation&#039;s homeland security efforts.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;In discussing the role for academia, the report also observes:&lt;/p&gt;&lt;div class=&quot;fright&quot;&gt;	&lt;p&gt;Over 200 colleges and universities are now providing degrees in homeland security and related fields. For a homeland security degree to mean something, however, people must know what a homeland security degree means. [The Department of Homeland Security] must lead an effort to align curriculum, develop education standards, define the loose boundaries of the profession, and support the academic foundation of a homeland security education system. The concept of the Homeland Security University System must be expanded to include a systematic, national approach to homeland security education.&lt;/p&gt;&lt;/div&gt;</description>
 <comments>http://connect.educause.edu/display/47339#comments</comments>
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/Cybersecurity+Policy/633">Cybersecurity Policy</category>
 <category domain="http://connect.educause.edu/tag/Department+of+Homeland+Security/2000">Department of Homeland Security</category>
 <category domain="http://connect.educause.edu/tag/homeland+security/3402">homeland security</category>
 <category domain="http://connect.educause.edu/tag/Policy+and+Law%3A+Federal/101">Policy and Law: Federal</category>
 <category domain="http://connect.educause.edu/tag/Washington+Update/5405">Washington Update</category>
 <pubDate>Wed, 24 Sep 2008 10:46:57 -0500</pubDate>
 <dc:creator>Rodney</dc:creator>
 <guid isPermaLink="false">47339 at http://connect.educause.edu</guid>
</item>
<item>
 <title>Soliciting Higher Education Input to the Commission on Cyber Security for the 44th Presidency</title>
 <link>http://connect.educause.edu/display/46370</link>
 <description>&lt;p&gt;The Center for Strategic and International Studies (CSIS) has established a &lt;a href=&quot;http://www.csis.org/media/csis/pubs/cyber_commission_factsheet.pdf&quot;&gt;Commission on Cyber Security for the 44th Presidency&lt;/a&gt; &amp;#8211; the administration that will take office in January 2009.&amp;#160; The goal of the nonpartisan Commission is to develop recommendations for a comprehensive strategy to improve cyber security in federal systems and in critical infrastructure.&lt;/p&gt;&lt;p&gt;The &lt;a href=&quot;http://www.educause.edu/security&quot;&gt;EDUCAUSE/Internet2 Security Task Force&lt;/a&gt; has been invited to provide input to the Commission and welcomes your comments in the following areas:&lt;/p&gt;&lt;ul&gt;	&lt;li&gt;What role has the Federal government played to improve cybersecurity these past few years that has been useful for the higher education sector?&lt;/li&gt;	&lt;li&gt;Are there ways in which the Federal government has hindered progress? If so, please describe.&lt;/li&gt;	&lt;li&gt;Are there new initiatives you would like to see from the Federal government help to improve cybersecurity?&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Please comment by &lt;strong&gt;Wednesday, March 12th, 2008&lt;/strong&gt;, by using the &amp;quot;Post new comment&amp;quot; section below or sending your comments to &lt;a href=&quot;mailto:Security-Task-Force@educause.edu&quot;&gt;Security-Task-Force@educause.edu&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/46370#comments</comments>
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/Cybersecurity+Policy/633">Cybersecurity Policy</category>
 <category domain="http://connect.educause.edu/tag/Department+of+Homeland+Security/2000">Department of Homeland Security</category>
 <category domain="http://connect.educause.edu/tag/Federal+Policy/943">Federal Policy</category>
 <category domain="http://connect.educause.edu/tag/National+Strategy+to+Secure+Cyberspace/5245">National Strategy to Secure Cyberspace</category>
 <category domain="http://connect.educause.edu/tag/Policy+and+Law%3A+Federal/101">Policy and Law: Federal</category>
 <category domain="http://connect.educause.edu/tag/Washington+Update/5405">Washington Update</category>
 <pubDate>Thu, 06 Mar 2008 15:31:21 -0600</pubDate>
 <dc:creator>Rodney</dc:creator>
 <guid isPermaLink="false">46370 at http://connect.educause.edu</guid>
</item>
<item>
 <title>Congress Expresses “Apprehension” About DHS Framework for Cybersecurity</title>
 <link>http://connect.educause.edu/display/45442</link>
 <description>&lt;p&gt;In a hearing before the &lt;a href=&quot;http://hsc.house.gov/&quot;&gt;U.S. House of Representatives Homeland Security Committee&lt;/a&gt; &lt;a href=&quot;http://hsc.house.gov/about/subcommittees.asp?subcommittee=12&quot;&gt;Subcommittee on Emerging Threats, Cybersecurity, and Science and Technology&lt;/a&gt;, subcommittee chair Rep. James R. Langevin (Dem.-RI) said, &amp;#8220;I have great apprehension about the current framework DHS is creating with the sector specific plans (SSP&amp;#8217;s) as they relate to cybersecurity.&amp;#8221;&amp;#160; He continued, &amp;#8220;The Federal government and the American people want to ensure there is a high level of cybersecurity protections on our critical infrastructure.&lt;/p&gt;&lt;p&gt;Dr. Lawrence A. Gordon, a professor from the University of Maryland, &lt;a href=&quot;http://hsc.house.gov/SiteDocuments/20071031155020-22632.pdf&quot;&gt;testified&lt;/a&gt; regarding ways of encouraging investments (i.e., incentives) that are directed at improving cybersecurity in profit-oriented organizations.&amp;#160; &amp;#8220;The most powerful incentive for an organization in the private sector to invest in cybersecurity activities is the motivation to increase the organization&amp;#8217;s value to its owners,&amp;#8221; he said.&amp;#160; &amp;#8220;A fundamental problem in coming up with estimates of the benefits derived from cybersecurity investments is that the most important potential losses are due to unobservable lost customers resulting from cyber breaches and the potential liabilities associated with cyber breaches.&amp;#8221; &amp;#160;Sally Katzen, a visiting professor of law at George Mason University (GMU) and senior consultant to the GMU Critical Infrastructure Protection (CIP) Program, observed in her &lt;a href=&quot;http://hsc.house.gov/SiteDocuments/20071031154853-26197.pdf&quot;&gt;testimony&lt;/a&gt; that the key to addressing cybersecurity both within and across sectors is the integration of various existing standards into Enterprise Risk Management (ERM) principles and techniques.&amp;#160; She remarked, &amp;#8220;ERM shines a light on cyber-CIP risks and all other enterprise risks at very high levels of accountability, including the boardroom.&amp;#8221;&lt;/p&gt;&lt;p&gt;The hearing, &lt;a href=&quot;http://hsc.house.gov/hearings/index.asp?ID=100&quot;&gt;&amp;#8220;Enhancing and Implementing the Cybersecurity Elements of the Sector Specific Plans&amp;#8221;&lt;/a&gt;, was designed to highlight the cyber elements of the &lt;a href=&quot;http://www.dhs.gov/xprevprot/programs/editorial_0827.shtm#2&quot;&gt;plans submitted by the critical infrastructure sectors&lt;/a&gt; as required by the &lt;a href=&quot;http://www.dhs.gov/xprevprot/programs/editorial_0827.shtm&quot;&gt;National Infrastructure Protection Plan&lt;/a&gt;.&amp;#160; Although higher education cyber systems are not considered &amp;#8220;critical infrastructure&amp;#8221; according to the Federal government&amp;#8217;s current framework, the U.S. Department of Education has submitted an SSP on behalf of &amp;#8220;educational facilities&amp;#8221; that references the need to maintain the security of college and university cyber systems.&amp;#160; A &lt;a href=&quot;http://www.gao.gov/new.items/d08113.pdf&quot;&gt;report&lt;/a&gt; issued by the Government Accountability Office concluded that the sector specific plans varied in how comprehensively they addressed the cyber security aspects of their sectors.&lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/45442#comments</comments>
 <category domain="http://connect.educause.edu/tag/critical+infrastructure+protection/5458">critical infrastructure protection</category>
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/Cybersecurity+Policy/633">Cybersecurity Policy</category>
 <category domain="http://connect.educause.edu/tag/Department+of+Homeland+Security/2000">Department of Homeland Security</category>
 <category domain="http://connect.educause.edu/tag/DHS/5711">DHS</category>
 <category domain="http://connect.educause.edu/tag/National+Strategy+to+Secure+Cyberspace/5245">National Strategy to Secure Cyberspace</category>
 <category domain="http://connect.educause.edu/tag/Washington+Update/5405">Washington Update</category>
 <pubDate>Thu, 01 Nov 2007 17:01:42 -0500</pubDate>
 <dc:creator>Rodney</dc:creator>
 <guid isPermaLink="false">45442 at http://connect.educause.edu</guid>
</item>
<item>
 <title>Congressional Resolution Introduced in Support of National Cyber Security Awareness Month</title>
 <link>http://connect.educause.edu/display/45262</link>
 <description>&lt;p&gt;The U.S. House of Representatives has introduced H. Res. 716 &amp;quot;expressing the sense of Congress with respect to raising awareness and enhancing the state of computer security in the United States, and supporting the goals and ideals of National Cyber Security Awareness Month.&amp;quot; The resolution was presented by Rep. James R. Langevin (Dem-RI), chair of the &lt;a href=&quot;http://homeland.house.gov/about/subcommittees.asp?subcommittee=12&quot;&gt;Subcommittee on Emerging Threats, Cybersecurity, and Science and Technology&lt;/a&gt; of the &lt;a href=&quot;http://homeland.house.gov/&quot;&gt;House Homeland Security Committee&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;While introducing the resolution on the House floor, Rep. Langevin said:&lt;/p&gt;	&lt;p&gt;Each year, the National Cyber Security Division, NCSD, of the Department of Homeland Security, DHS, joins with the National Cyber Security Alliance, NCSA, the Multi-State Information Sharing and Analysis Center, MS-ISAC, and other partners to support National Cyber Security Awareness Month. The goal of National Cyber Security Awareness Month is to show everyday Internet users that by taking simple steps, they can safeguard themselves from the latest online threats and respond to potential cyber-crime incidents. &lt;/p&gt;&lt;p&gt;He also commented that cybersecurity issues have been largely ignored and misunderstood for too long. &amp;quot;The oversight that the Homeland Security Committee is undertaking will help change that,&amp;quot; he observed, &amp;quot;but much work remains to be done.&amp;quot;&lt;/p&gt;&lt;p&gt;National Cyber Security Awareness Month is organized by the National Cyber Security Alliance (&lt;a href=&quot;http://www.StaySafeOnline.org&quot;&gt;www.StaySafeOnline.org&lt;/a&gt;) and is supported by the &lt;a href=&quot;http://www.educause.edu/security&quot;&gt;EDUCAUSE/Internet2 Computer and Network Security Task Force&lt;/a&gt;. For more information about how educational institutions can get involved, see the &lt;a href=&quot;http://www.educause.edu/security/resourcekit&quot;&gt;Resource Kit for NCSAM&lt;/a&gt; developed by the task force.&lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/45262#comments</comments>
 <category domain="http://connect.educause.edu/tag/computer+security+awareness/2745">computer security awareness</category>
 <category domain="http://connect.educause.edu/tag/Congress/3894">Congress</category>
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/Cybersecurity+Policy/633">Cybersecurity Policy</category>
 <category domain="http://connect.educause.edu/tag/Department+of+Homeland+Security/2000">Department of Homeland Security</category>
 <category domain="http://connect.educause.edu/tag/Policy+and+Law%3A+Federal/101">Policy and Law: Federal</category>
 <category domain="http://connect.educause.edu/tag/Security+Awareness/258">Security Awareness</category>
 <category domain="http://connect.educause.edu/tag/Washington+Update/5405">Washington Update</category>
 <pubDate>Fri, 12 Oct 2007 17:11:40 -0500</pubDate>
 <dc:creator>Rodney</dc:creator>
 <guid isPermaLink="false">45262 at http://connect.educause.edu</guid>
</item>
<item>
 <title>IT Security Essential Body of Knowledge:  Federal Register Notice Request for Comments</title>
 <link>http://connect.educause.edu/display/45240</link>
 <description>&lt;p&gt;A &lt;em&gt;&lt;a href=&quot;http://a257.g.akamaitech.net/7/257/2422/01jan20071800/edocket.access.gpo.gov/2007/E7-19566.htm&quot;&gt;Federal Register Notice&lt;/a&gt;&lt;/em&gt; has been published for the Department of Homeland Security&#039;s &amp;quot;Information Technology (IT) Security Essential Body of Knowledge (EBK): A Competency and Functional Framework for IT Security Workforce Development.&amp;quot; &lt;strong&gt;The deadline for comments is December 7, 2007.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;According to the &lt;em&gt;Notice&lt;/em&gt;:&lt;/p&gt;&lt;div&gt;			&lt;p&gt;The EBK is not an additional set of DHS guidelines, and it is not intended to represent a standard, directive, or policy by DHS. Instead, it further clarifies key IT security terms and concepts for well-defined competencies, identifies notional security roles, defines four primary functional perspectives, and establishes an IT Security Role, Competency, and Functional Matrix.&lt;/p&gt;	&lt;/div&gt;&lt;p&gt;More information, including a downloadable version of the &lt;a href=&quot;http://www.us-cert.gov/ITSecurityEBK/&quot;&gt;IT Security EBK&lt;/a&gt;, is available at &lt;a href=&quot;http://www.us-cert.gov/ITSecurityEBK/&quot; title=&quot;http://www.us-cert.gov/ITSecurityEBK/&quot;&gt;http://www.us-cert.gov/ITSecurityEBK/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;There will be a briefing for the higher education sector with Brenda Oldfield from DHS as part of an &lt;a href=&quot;http://www.educause.edu/live&quot;&gt;EDUCAUSE Live&lt;/a&gt; on November 14, 2007, at 1 p.m. &lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/45240#comments</comments>
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/Department+of+Homeland+Security/2000">Department of Homeland Security</category>
 <category domain="http://connect.educause.edu/tag/Federal+Policy/943">Federal Policy</category>
 <category domain="http://connect.educause.edu/tag/IT+Security/5633">IT Security</category>
 <category domain="http://connect.educause.edu/tag/IT+Security+Officer/5634">IT Security Officer</category>
 <category domain="http://connect.educause.edu/tag/Job+Descriptions/223">Job Descriptions</category>
 <category domain="http://connect.educause.edu/tag/Professional+Development/224">Professional Development</category>
 <category domain="http://connect.educause.edu/tag/Security+Certification/5303">Security Certification</category>
 <category domain="http://connect.educause.edu/tag/security+training/2758">security training</category>
 <category domain="http://connect.educause.edu/tag/Training/230">Training</category>
 <category domain="http://connect.educause.edu/tag/Washington+Update/5405">Washington Update</category>
 <pubDate>Tue, 09 Oct 2007 11:20:50 -0500</pubDate>
 <dc:creator>Rodney</dc:creator>
 <guid isPermaLink="false">45240 at http://connect.educause.edu</guid>
</item>
<item>
 <title>2007 Federal Computer Security Report Card</title>
 <link>http://connect.educause.edu/display/44539</link>
 <description>&lt;p&gt;The 7th Annual Computer Security Report Card at Federal Departments and Agencies gave the government an overall grade of C- which is up from a D+ the previous two years. Other notable changes include:&lt;/p&gt;&lt;ul&gt;	&lt;li&gt;NSF received an A+ in 2006, rebounding sharply from a C+ it received in 2004&lt;/li&gt;	&lt;li&gt;NASA received a D- in 2006 - the same grade it received in 2003 and 2004 - although its grade temporarily jumped to a B- in 2005&lt;/li&gt;	&lt;li&gt;The Department of Defense and Department of Education both received an F in 2006&lt;/li&gt;	&lt;li&gt;The Department of Veterans Affairs, infamous for its lost laptop that exposed the records of 26.5 million veterans in 2006, failed to submit a FY06 FISMA Report. The VA had received an F in the previous two years.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The full report is attached or available at &lt;a href=&quot;http://republicans.oversight.house.gov/Media/PDFs/FY06FISMA.pdf&quot;&gt;http://republicans.oversight.house.gov/Media/PDFs/FY06FISMA.pdf&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &amp;#160;&lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/44539#comments</comments>
 <enclosure url="http://connect.educause.edu/files/FY06FISMA.pdf" length="34565" type="application/x-download" />
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/Department+of+Defense+%28DoD%29/2138">Department of Defense (DoD)</category>
 <category domain="http://connect.educause.edu/tag/Department+of+Homeland+Security/2000">Department of Homeland Security</category>
 <category domain="http://connect.educause.edu/tag/federal+government/1961">federal government</category>
 <category domain="http://connect.educause.edu/tag/federal+policy+and+law/2418">federal policy and law</category>
 <category domain="http://connect.educause.edu/tag/FISMA/3798">FISMA</category>
 <pubDate>Thu, 21 Jun 2007 09:57:44 -0500</pubDate>
 <dc:creator>Rodney</dc:creator>
 <guid isPermaLink="false">44539 at http://connect.educause.edu</guid>
</item>
<item>
 <title>DHS on Its Own Cybersecurity:  &quot;Do As I Say, Not As I Do&quot;</title>
 <link>http://connect.educause.edu/display/44538</link>
 <description>&lt;p&gt;The Emerging Threats, Cybersecurity, and Science and Technology Subcommittee of the Homeland Security Committee in the U.S. House of Representatives held a hearing yesterday on the topic of &amp;#8220;Hacking the Homeland: Investigating Cybersecurity Vulnerabilities at the Department of Homeland Security&amp;#8221;. Chairman Rep. James Langevin (Dem-RI) commented, &amp;quot;It was a shock and disappointment to learn that the Department of Homeland Security - the agency charged with being the &lt;em&gt;lead&lt;/em&gt; in our national cybersecurity - has suffered so many significant security incidents on its networks.&amp;quot;&lt;/p&gt;&lt;p&gt;The full committee chairman, Rep. Bennie Thompson (Dem-Miss), asked:&lt;/p&gt;	&lt;p&gt;How can the Department of Homeland Security be a real advocate for sound cybersecurity practices without following some of its own advice?&amp;#160; How can we expect improvements in private infrastructure cyberdefense when DHS bureaucrats aren&amp;#8217;t fixing their own configurations? How can we ask others to invest in upgraded security technologies when the Chief Information Officer grows the Department&amp;#8217;s IT security budget at a snail&amp;#8217;s pace?&amp;#160; How can we ask the private sector to better train employees and implement more consistent access controls when DHS allows employees to send classified emails over unclassified networks and contractors to attach unapproved laptops to the network?&amp;#160;&lt;/p&gt;&lt;p&gt;Witnesses which included the CIO from DHS and representatives of the Government Accountability Office were cautious to acknowledge that progress is being made despite shortcomings in DHS information security program. Rep. Thompson remarked, &amp;quot;The American people are tired of hearing that getting a &#039;D&#039; is a security improvement,&amp;quot; referring to the recent &lt;a href=&quot;http://republicans.oversight.house.gov/Media/PDFs/FY06FISMA.pdf&quot; title=&quot;http://republicans.oversight.house.gov/Media/PDFs/FY06FISMA.pdf&quot;&gt;Annual Report Card on Computer Security for Federal Departments and Agencies&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;More information regarding the hearing, including witness testimony and a recorded webcast, is available at &lt;a href=&quot;http://homeland.house.gov/hearings/index.asp?ID=65&quot; title=&quot;http://homeland.house.gov/hearings/index.asp?ID=65&quot;&gt;http://homeland.house.gov/hearings/index.asp?ID=65&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/44538#comments</comments>
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/Department+of+Homeland+Security/2000">Department of Homeland Security</category>
 <category domain="http://connect.educause.edu/tag/Federal+Policy/943">Federal Policy</category>
 <category domain="http://connect.educause.edu/tag/National+Strategy+to+Secure+Cyberspace/5245">National Strategy to Secure Cyberspace</category>
 <category domain="http://connect.educause.edu/tag/Washington+Update/5405">Washington Update</category>
 <pubDate>Thu, 21 Jun 2007 09:28:04 -0500</pubDate>
 <dc:creator>Rodney</dc:creator>
 <guid isPermaLink="false">44538 at http://connect.educause.edu</guid>
</item>
</channel>
</rss>
