|
[an error occurred while processing this directive]
CyberSecurity
BNA's Web Watch is prepared by Laura
Gordon-Murnane. Documents and Reports are arranged first by
federal government, state governments, international governments,
and nongovernment organizations. E-mail suggestions for future weekly
topics always welcome.
Federal Government
Department of Energy - Inspector General's Office
Inspection
of Cyber Security Standards for Sensitive Personal Information
(November 2001)
The Federal Computer Incident Response Center (FedCIRC)
FedCIRC is
the central coordination and analysis facility dealing with computer
security related issues affecting the civilian agencies and departments
of the Federal Government. FedCIRC releases advisories, incident
notes, anti-virus tools, and opportunities to report incidents.
General Accounting Office
Statement of Joel C. Willemssen Managing Director, Information
Technology Issues on Critical
Infrastructure Protection: Significant Challenges in Safeguarding
Government and Privately Controlled Systems from Computer-Based
Attacks (September 26, 2001)
Statement of Robert Dacey, director, information security issues
– “Computer
Security: Improvements Needed to Reduce Risk to Critical Federal
Operations and Assets.” (November 9, 2001)
The National Infrastructure Protection Center
Cyber
Protests: The Threat to the U.S. Information Infrastructure October
2001 (October 2001)
NIPC is the
point agency that deals with “threat assessment, warning,
investigation, and response for threats or attacks against”
the nation’s critical infrastructures in telecommunications,
energy, banking and finance, water systems, government operations,
and emergency services.
NIPC Cyber Notes
NIPC publishes a biweekly newsletter called Cyber
Notes. The newsletter provides a summary of software vulnerabilities
that have been identified during the previous two weeks. The summary
includes information on the vendor, operating system, software name,
potential vulnerability/impact, identified patches/workarounds/alerts,
common name of the vulnerability, potential risk, and an indication
of whether attacks have utilized this vulnerability or an exploit
script is known to exist.
National Institute of Standards and Technology
Guidelines
for the Security Certification and Accreditation of Federal Information
Technology Systems (October 2002)
International Organizations
ORGANISATION FOR ECONOMIC CO-OPERATION AND DEVELOPMENT
OECD
Guidelines for the Security of Information Systems and Networks:
Toward A Culture of Security (July 2002)
Nongovernment Organizations
The CERT® Coordination Center (CERT/CC)
The CERT/CC is
a major reporting center for Internet security problems. CERT publishes
on a daily basis advisories, incident notes, and vulnerability notes.
Computer Sciences Corporation
14th
Annual Critical Issues of Information Systems Study (2001)
Infosecurity Magazine
“Info
Security Survey 2001.” (October 2001)
The St. Paul Companies
New Challenges to Corporate Risk Management– Executive
Summary - Summary
Data (2001)
|