<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>security blog</title>
	<atom:link href="http://elamb.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://elamb.org</link>
	<description>cyber-punk techno-babble &#38; security fiction, security news, howtos</description>
	<lastBuildDate>Sat, 04 Jul 2009 15:47:47 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<!-- podcast_generator="podPress/8.8" -->
		<copyright>&#xA9;rob elam </copyright>
		<managingEditor>elamb.security@gmail.com (rob elam)</managingEditor>
		<webMaster>elamb.security@gmail.com(rob elam)</webMaster>
		<category></category>
		<ttl>1440</ttl>
		<itunes:keywords>infosec, integral hacking, howtos, malware news, security fiction, techno-babble, cyber punk philosopy, security, hacking, geek, phreaks, chic, pr0n</itunes:keywords>
		<itunes:subtitle>security blog - cyber punk technobable  security fiction from nobody to nobody</itunes:subtitle>
		<itunes:summary>infosec, integral hacking, howtos, malware news, security fiction, techno-babble, cyber punk philosopy</itunes:summary>
		<itunes:author>rob elam</itunes:author>
		<itunes:category text="Technology">
  <itunes:category text="Podcasting"/>
</itunes:category>
<itunes:category text="Society &amp; Culture">
  <itunes:category text="Philosophy"/>
</itunes:category>
<itunes:category text="Technology"/>
		<itunes:owner>
			<itunes:name>rob elam</itunes:name>
			<itunes:email>elamb.security@gmail.com</itunes:email>
		</itunes:owner>
		<itunes:block>No</itunes:block>
		<itunes:explicit>yes</itunes:explicit>
		<itunes:image href="http://elamb.org/hacked/images/thevigilante.jpg" />
		<image>
			<url>http://elamb.org/hacked/images/thevigilante.jpg</url>
			<title>security blog</title>
			<link>http://elamb.org</link>
			<width>144</width>
			<height>144</height>
		</image>
		<item>
		<title>CNSSI 12-53: New Security Control Catalog for National Security Systems</title>
		<link>http://elamb.org/cnssi-12-53-new-security-control-catalog-for-national-security-systems/</link>
		<comments>http://elamb.org/cnssi-12-53-new-security-control-catalog-for-national-security-systems/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 05:39:49 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/Netcentric]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[security]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1746</guid>
		<description><![CDATA[New DIACAP Certification &#038; Accreditation IA Controls
The DoD has had the same IA controls since DoD 8510.1-M, controls since DoD 8510.1-M, Department of Defense Information Technology System Certification &#038; Accreditation Process (DITSCAP), July 31, 2000 – it was developed late last century.
The DoD has a total of 157 IA controls spread across 8 subject areas [...]]]></description>
			<content:encoded><![CDATA[<p><strong>New DIACAP Certification &#038; Accreditation IA Controls</strong></p>
<p>The DoD has had the same IA controls since DoD 8510.1-M, controls since DoD 8510.1-M, Department of Defense Information Technology System Certification &#038; Accreditation Process (DITSCAP), July 31, 2000 <em>– it was developed late last century.</em></p>
<p><strong>The DoD has a total of 157 IA controls spread across 8 subject areas in 4 classes:</strong></p>
<blockquote><p>
DC – Security Design &#038; Configuration</p>
<p>IA – Identification and Authentication</p>
<p>EC – Enclave &#038; Computing</p>
<p>EB – Enclave Boundary Defense</p>
<p>PE – Physical &#038; Environmental</p>
<p>PR – Personnel</p>
<p>CO – Continuity</p>
<p>VI – Vulnerability </p></blockquote>
<p>There is a huge change coming in certification &#038; accreditation for the DoD coming.  The IA controls are being expanded and changed.  The last two DIACAP classes I’ve been to mentioned that there is a big change coming.  Essentially, all the IA Controls (security controls, safeguards, countermeasures.. whatever your organization is calling them) are getting expanded.  All federal organizations will have security controls that look more like what is in the National Institute of Standards and Technology Special Publication 800-53.  This is all being placed in the Committee on National Security Systems Instruction (CNSSI) 1253.  As of 25 June 2009, the CNSSI 1253 is still in draft. </p>
<p>The draft has 17 families &#038; identifiers in three security control classes.  </p>
<p>TABLE 1: SECURITY CONTROL CLASSES, FAMILIES, AND IDENTIFIERS<br />
IDENTIFIER FAMILY CLASS</p>
<blockquote><p>AC Access Control Technical</p>
<p>AT Awareness and Training Operational</p>
<p>AU Audit and Accountability Technical</p>
<p>CA Certification, Accreditation, and Security Assessments Management</p>
<p>CM Configuration Management Operational</p>
<p>CP Contingency Planning Operational</p>
<p>IA Identification and Authentication Technical</p>
<p>IR Incident Response Operational</p>
<p>MA Maintenance Operational</p>
<p>MP Media Protection Operational</p>
<p>PE Physical and Environmental Protection Operational</p>
<p>PL Planning Management</p>
<p>PS Personnel Security Operational</p>
<p>RA Risk Assessment Management</p>
<p>SA System and Services Acquisition Management</p>
<p>SC System and Communications Protection Technical</p></blockquote>
<p>The CNSSI has about 500 controls with pretty good granularity.  </p>
<p>One of the really cool thing about 1253 was the security control mapping.  It’s a table that matches up 800-53, DCID 6/3 and DODI 8500.2.</p>
<img src="http://elamb.org/?ak_action=api_record_view&id=1746&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/cnssi-12-53-new-security-control-catalog-for-national-security-systems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DIACAP Essentials + IA Control Validation Training (part 4): DIACAP/AFCAP Day 4 &amp; 5</title>
		<link>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day-4-5/</link>
		<comments>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day-4-5/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 05:21:11 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/Netcentric]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[emass]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sissu]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1744</guid>
		<description><![CDATA[Days 4 &#038; 5 bring the DIACAP/AFCAP Essentials Class to a close.  The
biggest things I learned were:  CNSSI 4009 is the the official glossary of DOD IA, there is a big difference between theory, policy and practice, Agents of the Certifying Authority (ACA) are official validators and there is a difference between acquisition [...]]]></description>
			<content:encoded><![CDATA[<p>Days 4 &#038; 5 bring the DIACAP/AFCAP Essentials Class to a close.  The<br />
biggest things I learned were:  CNSSI 4009 is the the official glossary of DOD IA, there is a big difference between theory, policy and practice, Agents of the Certifying Authority (ACA) are official validators and there is a difference between acquisition Mission criticality and IA MAC levels.   </p>
<p><strong>Stuff I learned from people in the class:</strong></p>
<blockquote><p>-AFCA is changing its name (to what?)</p>
<p>DOD is going to put the new IA controls in NCSSI 12-53 (currently in draft)</p>
<p>-a lot of what I need in there is in NIST 800-53</p>
<p>Marines use something called Exacta</p>
<p>Site called securitycritics.org</p>
<p>33-202 is now completely irrelevant and obsolete (not even mentioned ONCE in the class)</p>
<p>800-30</p>
<p>Feds call Certification &#038;Accreditation (C&#038;A) “Security authorization” </p>
<p>NIST SP 800-37</p></blockquote>
<p><strong>Day 4:</strong></p>
<blockquote><p>Validator Activities &#038; Issue Accreditation Decision</p>
<p>Prepare POA&#038;M</p>
<p>Validate Results/Scorecard</p>
<p>Scorecard</p>
<p>Make certification determination</p>
<p>CA/DAA Package review </p></blockquote>
<p><strong>Day 5:</strong></p>
<blockquote><p>Validation procedures were discussed.  On day five, we looked at how the validators look at a system.</p>
<p>I thought is was interesting.  It should help me get through the EITDR/DIACAP process easier.</p>
<p>Maintain Situational Awareness</p>
<p>Maintain IA Posture</p>
<p>Conduct Review</p>
<p>R-Accreditation</p>
<p>Retire system </p></blockquote>
<img src="http://elamb.org/?ak_action=api_record_view&id=1744&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day-4-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DIACAP Essentials + IA Control Validation Training (part 4): DIACAP/AFCAP Day3</title>
		<link>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day3/</link>
		<comments>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day3/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 04:37:14 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/Netcentric]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[sissu]]></category>
		<category><![CDATA[DIACAP]]></category>
		<category><![CDATA[DIACAP Team]]></category>
		<category><![CDATA[ditpr]]></category>
		<category><![CDATA[dod]]></category>
		<category><![CDATA[emass]]></category>
		<category><![CDATA[IA]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1736</guid>
		<description><![CDATA[Day 3 heats up a little.  We start talking about what it take to actually get validated.  The DIACAP Implementers Guide &#038; the DIACAP Validators guide is opened up and reviewed.  I think we all learned a little something during this discussion because there have been some challenges with this.  Unfortunately, [...]]]></description>
			<content:encoded><![CDATA[<p>Day 3 heats up a little.  We start talking about what it take to actually get validated.  The DIACAP Implementers Guide &#038; the DIACAP Validators guide is opened up and reviewed.  I think we all learned a little something during this discussion because there have been some challenges with this.  Unfortunately, we don&#8217;t to far into the validator stuff.</p>
<p><strong>Day 3:</strong>  </p>
<blockquote><p>DIACAP Structure</p>
<p>Terminology Review</p>
<p>Assemble DIACAP Team</p>
<p>Registered System/System Information Profile</p>
<p>Assign IA Controls</p>
<p>Initiate DIACAP Implementation Plan </p></blockquote>
<img src="http://elamb.org/?ak_action=api_record_view&id=1736&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DIACAP Essentials + IA Control Validation Training (part 3): DIACAP/AFCAP Day2</title>
		<link>http://elamb.org/diacap-essentials-ia-control-validation-training-part-3-diacapafcap-day2/</link>
		<comments>http://elamb.org/diacap-essentials-ia-control-validation-training-part-3-diacapafcap-day2/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 04:32:44 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/Netcentric]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[apms]]></category>
		<category><![CDATA[federal]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1733</guid>
		<description><![CDATA[Day 1 &#038; 2 have been all about the very basics of DIACAP.  Were introduced to the terminologies, key players of the C&#038;A process and basically given the big picture.  Like I said, GREAT for beginners, but just lots of theory and refresher if you&#8217;ve been doing C&#038;A since DITSCAP.
Day 1 &#038;2:  [...]]]></description>
			<content:encoded><![CDATA[<p>Day <a href="http://elamb.org/diacap-essentials-ia-control-validation-training-part-2-diacapafcap-day1/">1 </a>&#038; 2 have been all about the very basics of DIACAP.  Were introduced to the terminologies, key players of the C&#038;A process and basically given the big picture.  Like I said, GREAT for beginners, but just lots of theory and refresher if you&#8217;ve been doing C&#038;A since DITSCAP.</p>
<p><strong>Day 1 &#038;2: </strong> </p>
<blockquote><p>Getting the Big Picture</p>
<p>DIACAP/AFCAP Policy &#038; Terminology</p>
<p>Roles and Responsibilities for the C&#038;A process</p>
<p>Accreditation  &#038; Approval to Connect</p>
<p>Homework: review terminology  </p></blockquote>
<p>In between longer breaks, during lunch and just before class we sneak in episode of the The IT Crowd.  Its the first time I&#8217;ve watched it so its a real treat for me.  Hilarious show.  </p>
<img src="http://elamb.org/?ak_action=api_record_view&id=1733&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/diacap-essentials-ia-control-validation-training-part-3-diacapafcap-day2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Unable to create directory-parent directory writable? wordpress 2.7</title>
		<link>http://elamb.org/unable-to-create-directory-parent-directory-writeable/</link>
		<comments>http://elamb.org/unable-to-create-directory-parent-directory-writeable/#comments</comments>
		<pubDate>Sun, 28 Jun 2009 15:33:18 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Other Stuff]]></category>
		<category><![CDATA[blogging/blog hack]]></category>
		<category><![CDATA[blogging/blog howto]]></category>
		<category><![CDATA[blogging/blogging tricks]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[tutorials]]></category>
		<category><![CDATA[wordpress]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1740</guid>
		<description><![CDATA[I was having uploading images on one of my Wordpress 2.7 &#038; 2.8 blogs.  It gave me the following error:
Unable to create directory /home/username/server/wp-content/uploads/20XX/MM/   Is it parent directory writable by the server?
After a long time searching I found this solution from http://www.cyriac.me
Step 1: Log into your admin panel
Step 2: Go to Settings>>Miscellaneous
You [...]]]></description>
			<content:encoded><![CDATA[<p>I was having uploading images on one of my Wordpress 2.7 &#038; 2.8 blogs.  It gave me the following error:<br />
Unable to create directory /home/username/server/wp-content/uploads/20XX/MM/   Is it parent directory writable by the server?</p>
<p>After a long time searching I found this <a href="http://www.cyriac.me/how-to-solve-image-upload-error-in-wordpress-27/">solution from http://www.cyriac.me</a></p>
<blockquote><p>Step 1: Log into your admin panel</p>
<p>Step 2: Go to Settings>>Miscellaneous</p>
<p>You will see two options,</p>
<p>Store uploads in this folder<br />
Full URL path to files<br />
Most probably you will see</p>
<p>/home/.boogee/XXXXX/XXXXXXX/wp-content/uploads</p>
<p>in the first field.</p>
<p>Step 3: Edit that to just</p>
<p>wp-contents/uploads</p></blockquote>
<p>Some people were suggesting that you solve the problem my making the folders permissions 777, meaning anyone can do anything to that particular folder.  As a security guy, I knew this was a bad idea (and it also did work for me <img src='http://elamb.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ).  I kept searching and ran into that solution.</p>
<p>Worked like a charm!  thanks cyriac for putting solution on the blog.</p>
<img src="http://elamb.org/?ak_action=api_record_view&id=1740&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/unable-to-create-directory-parent-directory-writeable/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>DIACAP Essentials + IA Control Validation Training (part 2): DIACAP/AFCAP Day1</title>
		<link>http://elamb.org/diacap-essentials-ia-control-validation-training-part-2-diacapafcap-day1/</link>
		<comments>http://elamb.org/diacap-essentials-ia-control-validation-training-part-2-diacapafcap-day1/#comments</comments>
		<pubDate>Tue, 23 Jun 2009 01:29:26 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/Netcentric]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[Certification/CISSP]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[federal]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[AFCAP]]></category>
		<category><![CDATA[apms]]></category>
		<category><![CDATA[architectural views]]></category>
		<category><![CDATA[DIACAP]]></category>
		<category><![CDATA[DIACAP Team]]></category>
		<category><![CDATA[ditpr]]></category>
		<category><![CDATA[ditprdon]]></category>
		<category><![CDATA[dod]]></category>
		<category><![CDATA[emass]]></category>
		<category><![CDATA[IA]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[sissu]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1731</guid>
		<description><![CDATA[DIACAP/AFCAP Day 1.
This is the second installment of the DIACAP Essentials journal.
In the first day of class we&#8217;ve taken a high level look at the big picture of the Department of Defense Information Assurance Certification &#038; Accreditation Process (DIACAP) and Air Force Certification &#038; Accreditation Program (AFCAP).  It is a very valuable tool for [...]]]></description>
			<content:encoded><![CDATA[<p><strong>DIACAP/AFCAP Day 1.</strong><br />
<a href="http://elamb.org/diacap-essentials-ia-control-validation-training-part-1/">This is the second installment of the DIACAP Essentials journal.</a></p>
<p>In the first day of class we&#8217;ve taken a high level look at the big picture of the Department of Defense Information Assurance Certification &#038; Accreditation Process (DIACAP) and Air Force Certification &#038; Accreditation Program (AFCAP).  It is a very valuable tool for a beginner. </p>
<p>Since I&#8217;ve gone through the entire process (with a legacy system) more than once through all the growing pains of Air Force C&#038;A from DITSCAP to DIACAP, I found that I knew about 90% of everything taught.  I don&#8217;t mind having a refresher, though and quite frankly, I need the CPE&#8217;s for my CISSP <img src='http://elamb.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> .</p>
<p>There were a couple of golden nuggets that I&#8217;ve been able to get out of some of the old timers.  I learned some interesting things about how the Navy, Marines and Army do things.<br />
Navy (as weird as their dumb ass rank system.. yep, I said it.. its dumb) have like three systems: DITPR-DON, DA-DUMB and some other BS, Marines have something called Exacta and the Army has APMS (Army Profile Management System).  Also learned cool off topic stuff like history of eMass.</p>
<p>I must admit I&#8217;m looking forward to day two.<br />
pros of day 1: Good solid start on basics GREAT for beginners.  <a href="http://www.secureinfo.com/">SecureInfo</a> gets mad props for have a great instructor John M.(don&#8217;t know if he wants his full name published.. but he&#8217;s highly, highly knowledgeable and very positive).</p>
<p>cons of day 1: Right off the bat I am noticing a huge hole in the training&#8230; a lack of in depth teaching of <a href="http://elamb.org/eitdr-enterprise-information-technology-data-repository/">EITDR</a>, which is how the Air Force implements, manages and maintains the entire DIACAP/AFCAP process.  I don&#8217;t really see how you can teach one without the other these days.  I guess contractually, SecureInfo can not touch it since some other company has the contract.  But unfortunately, the folks that are new to this are going to suffer.  Because if they goto this class without knowing the EITDR they will know why but now how, and if they go to the EITDR class without knowing the DIACAP they will know how but not Why.</p>
<img src="http://elamb.org/?ak_action=api_record_view&id=1731&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/diacap-essentials-ia-control-validation-training-part-2-diacapafcap-day1/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Jeff Moss + DHS = Super Security</title>
		<link>http://elamb.org/jeff-moss-dhs-super-security/</link>
		<comments>http://elamb.org/jeff-moss-dhs-super-security/#comments</comments>
		<pubDate>Wed, 10 Jun 2009 04:57:23 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[DHS]]></category>
		<category><![CDATA[Defcon]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[hackers]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1729</guid>
		<description><![CDATA[&#8220;Godfather of Hackers&#8221; Jeff Moss, founder of the Black Hat and Defcon hacker and security conferences, was sworn in as one of the new members of the Department of Homeland Security’s Advisory Council (HSAC). And we think it&#8217;s a shrewd and thoughtful move. Obama seems to be getting serious about cyber security now by hiring [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;Godfather of Hackers&#8221; Jeff Moss, founder of the Black Hat and Defcon hacker and security conferences, was sworn in as one of the new members of the Department of Homeland Security’s Advisory Council (HSAC). And we think it&#8217;s a shrewd and thoughtful move. Obama seems to be getting serious about cyber security now by hiring &#8220;Dark Tangent.&#8221;</p>
<p>on <a href="http://www.gizmodo.com.au/2009/06/obama_administration_adds_renowned_hacker_to_homeland_security_advisory_council-2/">gizmodo</a> </p>
<p>Jeff Moss is not only a celebrity in the world of hacking, he is also a powerbroker.  He is a respected force to be reckoned with.  I am not going to say that I think he is some sort of cyber mafia boss but I will say that he could destroy just about anyone with a 100 word post on a forum.   Getting “street cred” in the hacker world is something that must be truly earned usually by technical expertise proven by hundreds or even thousands of your hacker peers validated by published technical papers, famous/infamous system infiltrations, the discovery of 0-day exploits that make major corporations take notice, or some combination of these.</p>
<p>Jeff has his finger on the pulse of the entire spectrum of hacking.</p>
<p>Jeff is now going to advise the president. </p>
<p>Now that is good judgement.</p>
<img src="http://elamb.org/?ak_action=api_record_view&id=1729&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/jeff-moss-dhs-super-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DIACAP Essentials + IA Control Validation Training (part 1)</title>
		<link>http://elamb.org/diacap-essentials-ia-control-validation-training-part-1/</link>
		<comments>http://elamb.org/diacap-essentials-ia-control-validation-training-part-1/#comments</comments>
		<pubDate>Wed, 10 Jun 2009 04:49:25 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Security Awareness]]></category>
		<category><![CDATA[ditpr]]></category>
		<category><![CDATA[information assurance]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1727</guid>
		<description><![CDATA[I&#8217;ve been scheduled to go to DIACAP Essentials + IA Control Validation training.  It is the same training that is given to validators at AFCA, so I guess it is pretty serious stuff.  I was very reluctant to go until I realized that I actually really need the CPE&#8217;s to maintain my CISSP.
Since [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been scheduled to go to DIACAP Essentials + IA Control Validation training.  It is the same training that is given to validators at AFCA, so I guess it is pretty serious stuff.  I was very reluctant to go until I realized that I actually really need the CPE&#8217;s to maintain my CISSP.</p>
<p>Since I&#8217;ve been doing the DIACAP stuff for about 2 years now, I&#8217;m not certain there is any new information for me to learn.</p>
<blockquote><p><strong>DIACAP Essentials </strong><br />
The Department of Defense Information Assurance Certification and<br />
Accreditation Process (DIACAP) Essentials course blends lecture and hands-on<br />
exercises to introduce students to DIACAP policy (to include FISMA<br />
requirements of a comprehensive, repeatable, and auditable Information<br />
Security process). </p></blockquote>
<blockquote><p><strong>IA Control Validation In-Depth </strong>- 3 Days<br />
The IA Control Validation In-Depth course takes the students DIACAP<br />
education and turns the view from an implementor to a Validator perspective<br />
and involves the students in the validation process for the IA Controls<br />
(DoDI 8500.2).</p></blockquote>
<p>What I am hoping to get from the course is a better handle on the FISMA process.<br />
I don&#8217;t feel like I really have a handle on what is supposed to happen with it.</p>
<img src="http://elamb.org/?ak_action=api_record_view&id=1727&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/diacap-essentials-ia-control-validation-training-part-1/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Subject: GET BACK TO ME AT YOUR EARLIEST CONVINIENCE *scam*</title>
		<link>http://elamb.org/subject-get-back-to-me-at-your-earliest-convinience-scam/</link>
		<comments>http://elamb.org/subject-get-back-to-me-at-your-earliest-convinience-scam/#comments</comments>
		<pubDate>Tue, 09 Jun 2009 01:56:40 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[scam]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1725</guid>
		<description><![CDATA[OFFICE OF THE NATIONAL SECURITY ADVISE
TO THE PRESIDENT FEDERAL REPUBLIC OF NIGERIA
GET BACK TO ME AT YOUR EARLIEST CONVINIENCE
Dear Sir/Madam, 
I am Lt.  Gen. Peter Olu, National Security Adviser to the President Umar Musa Yar’ Adua Federal Republic of Nigeria. I decided to contact you because of the prevailing security report reaching my office [...]]]></description>
			<content:encoded><![CDATA[<p>OFFICE OF THE NATIONAL SECURITY ADVISE<br />
TO THE PRESIDENT FEDERAL REPUBLIC OF NIGERIA<br />
GET BACK TO ME AT YOUR EARLIEST CONVINIENCE</p>
<p>Dear Sir/Madam, </p>
<p>I am Lt.  Gen. Peter Olu, National Security Adviser to the President Umar Musa Yar’ Adua Federal Republic of Nigeria. I decided to contact you because of the prevailing security report reaching my office and the intense nature of policy in Nigeria. This is to inform you about our plan to send your fund to you via cash delivery. This system will be easier for you and for us. We are going to send your contract part payment of US$4.1 Million to you via diplomatic courier service.</p>
<p>Note: The money is coming on two security proof boxes. The boxes are sealed with synthetic nylon seal and padded with machine. This fund was brought to us from America; it was meant for our Local AFEM market. But since the money was not used, I will use my position as the National Security Adviser to the President to send this fund to you.</p>
<p>The boxes are coming with a Diplomatic agent who will accompany the boxes to your house address in your country. All you need to do now is to send to me</p>
<p>Your full name<br />
Your house address<br />
Your age<br />
Your marital statue<br />
Your identity such as, international passport or driver license<br />
Your contact phone and fax numbers, </p>
<p>The Diplomatic attached will travel with it. He will call you immediately he arrives your country&#8217;s airport. I hope you understand me.</p>
<p>I will let you know by the special grace of God when the boxes are airlifted.</p>
<p>Note: The diplomatic does not know the original contents of the boxes. What l declared to them as the contents is Sensitive Photographic Film Material. I did not declare money to them please. If they call you and ask you the contents please tell them the same thing Ok, i will let you know how far I have gone with the arrangement. I will secure the Diplomatic immunity clearance certificate that will be tagged on the boxes to make it stand as a diplomatic consignment.</p>
<p>This clearance will make it pass every custom checkpoint all over the world without hitch. Confirm the receipt of this message and send the requirements to me immediately you receive this message. If you need more information about this, I will give you the contact of the diplomatic agents for more information on how to carry out the plan.</p>
<p>Please I need urgent reply because the boxes are schedule to leave as soon as we hear from you. Reply me immediately you receive this message via my private E-mail <img src='http://elamb.org/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> generalpeterolu2029@yahoo.com.hk) Call me on my direct phone  : (234-7026905160) or Fax: (234-8029402741)</p>
<p>Best Regards,</p>
<p>Lt. Gen. Peter Olu,<br />
National Security Adviser to the President<br />
Federal Republic of Nigeria</p>
<img src="http://elamb.org/?ak_action=api_record_view&id=1725&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/subject-get-back-to-me-at-your-earliest-convinience-scam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>I always feel like GOOGLE is watching meeee</title>
		<link>http://elamb.org/i-always-feel-like-google-is-watching-meeee/</link>
		<comments>http://elamb.org/i-always-feel-like-google-is-watching-meeee/#comments</comments>
		<pubDate>Wed, 03 Jun 2009 05:56:44 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[google]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1720</guid>
		<description><![CDATA[If Google was woman I would make sweet passionate love to her.  And she&#8217;d be a psycho-stalker.
I love Google, but it conflicts with my finely honed skill of not trusting.  I use Google for just about everything knowing they have a dangerous amount of information about me and everything else readily available in [...]]]></description>
			<content:encoded><![CDATA[<p>If Google was woman I would make sweet passionate love to her.  And she&#8217;d be a psycho-stalker.</p>
<p>I love Google, but it conflicts with my finely honed skill of not trusting.  I use Google for just about everything knowing they have a dangerous amount of information about me and everything else readily available in a search friendly little package.</p>
<blockquote><p>Google showed up as the most conspicuous tracker on third-party sites. Google Analytics, a free product that allows online publishers to gather statistics about visitors to their sites, was used on 81 of the top 100 sites. Cookies from the advertising company DoubleClick, which is owned by Google, were present on 70 of those sites. When combining trackers from those two services, Google had a presence on 92 of the top 100 sites. Others weren’t far behind. Cookies from Atlas, Microsoft’s DoubleClick rival, appeared on 60 sites, and trackers from two other analytics companies, Quantcast and Omniture, showed up on 54 sites.</p></blockquote>
<p> &#8211; <a href="http://bits.blogs.nytimes.com/2009/06/02/google-is-top-tracker-of-surfers-in-study/">Ny time</a></p>
<p>I still love Google and I still believe, perhaps foolishly, that they are not evil.  Even so, one day I think Google will turn evil, not unlike any empire that has become too powerful.  The culture of the company will change in a generation and a new dynasty will reign using personal information as a weapon rather than a useful tool for making better searching.  I hope I am very, very wrong.</p>
<img src="http://elamb.org/?ak_action=api_record_view&id=1720&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/i-always-feel-like-google-is-watching-meeee/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
