Gmail is one of my favorite email products. Â Its free, its extremely good at collecting and organizing data (in-line with google’s vision of world information organization domination) and its so intuitive.
The gmail security features are kind of tucked away to bring the organization and search functions to the foreground. Â But once you know where they are, its easy.
1. First, browse into your email and sign in.
2. Inside your email under your name, click privacy.
3. Under Account Privacy, hit Security and add alternate recovery email and mobile number. Â This will allow gmail security to alert you of any suspicious activity such as someone attempting to access your account.
On the DIACAP Knowledge Service goto “C&A Transformation”. This page introduces some of the coming changes from Certification & Accreditation changes to the Risk Management Framework seen in NIST SP 800-37.
DIACAP has “Risk Management Framework Transformation Initiative†underway that provides information on use of NIST SP 800-53, NIST SP 800-37, CNSS Instruction 1253.
The site introduces changes being made to DoDD 8500.01, DoDI 8500.2, DoDI 8510.01 and other documents that will be aligned with NIST 800 and FISMA 2013. They will feature an attempt to keep up with new arising cyberthreats, vulnerabilites and security incidence using real-time, “continuous monitoring†technologies such as HP ArcSight, McAfee ESM, ePO, NSP, Retina, Nessuss and other near real-time active monitoring systems.
road to diarmf
Why DIACAP to DIARMF?
Federal government has gotten more serious about security. They realize that enterprise level security and process is a continuous and expensive business. The old certification & accreditation process is not only long and expensive but so slow that it cannot keep up with the constant changes of information technology.
Risk based/cost effective security means creating security systems and policies that focus on “adequate securityâ€. The Executive Branch Office of Management and Budget (OMB) defines as adequate security, or security commensurate with risk, to include the magnitude of harm resulting from the unauthorized access, use, disclosure, disruption, modification, or destruction of information. The feds are also attempting to make the process of implementing and evaluating security controls by creating as much paper-less automation as possible.
note IMHO: Since technology is changing at a rate of what Ray Kurzweil calls “accelerating returns” I think for governments and organizations stuck in “static policy” based systems there is no way they can ever keep up with information technology without revolutionary shift in thinking. Google is probably the closest to understanding what is actually happening. The best any of us can do is observe.
 Source documents for all U.S. Federal information security:
OMB A-130 – Management of Federal Information Resources
FISMA – Federal Information Security Management Act of 2002
Required for all government agencies to develop, document, and implement an agency-wide information security program to provide information security for the information and systems that support the operations and assets of the agency Applies to contractors and other sources.
The federal government has created various acts/laws to implement to changes to the C&A process to a more risk management approach and emphasize a risk-based policy for cost-effective security. These acts include (but are not limited to):
 Federal Information Security Management Act of 2002 (amended as of 2013 April)
The Paperwork Reduction Act of 1995
The Information Technology Management Reform Act of 1996 (Clinger-Cohen Act) supported by Office of Management and Budget (OMB) through Circular A-130, Appendix III, Security of Federal Automated Information Resources
This NIST 800 is a well thought out set of federal security standards that DoD and the Intel world is moving too. It aligns with International Organization for Standardization (ISO) and International Electotechnical Commissions (IEC) 27001:2005, Information Security Management System (ISMS).
who-created-manages-nist-800
NIST 800 is updated and revised by the following organizations:
Joint Task Force Transformation Initiative Interagency (JTFTI) Working Group National Institute of Standards and Technology (NIST)
JTFTI is made up of from the Civil, Defense, and Intelligence Communities. This working group reviews and updates the following documents
    NIST Special Publication 800-37, Revision 1 Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach
   NIST Special Publication 800-39, Enterprise-Wide Risk Management: Organization, Mission, and Information Systems View
   NIST Special Publication 800-53, Revision 3 Recommended Security Controls for Federal Information Systems and Organizations
   NIST Special Publication 800-53A, Revision 1 Guide for Assessing the Security Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans
These core documents are a standard on how to implement FISMA. The organization has done a good job of keeping NIST 800 inline with international standards of ISO 27001. The JTFTI is made up of ODNI, DoD, CNSS. This document is also publicly vetted.
Office of the Director of National Intelligence (ODNI)
The DNI is a position required by Intelligence Reform and Terrorism Prevention Act of 2004. This office serves as adviser to the president, Homeland Security and National Security Counsil as well and director of National Intelligence.
Department of Defense (DoD)
DoD is composed of (but not limited to) the USAF, US Army, DON and Marines. It is the most powerful military organization in recorded history.
Committee on National Security Systems (CNSS)
This committee was created to satisfy National Security Directive 42, “National Policy for the Security of National Security Telecommunications and Information Systems“,
the group has represtatives from NSA, CIA, FBI, DOD, DOJ, DIA and is focused on protecting the US crititcal infrastructure.
Creating separate user accounts is important to the security and privacy of your personal computer. Â Once you create another user you should also password protect each account and disable the guest account if you are not using it.
1. Click Start then go to Control Panel.
2. Under Control Panel, click User Accounts and Family Safety.
Windows 7 – Create User
(Must be Administrator)
3. In User Accounts, hit Add or Remove user accounts.
Create Windows 7 User
4. Below the list of the User accounts. Hit create new accounts to add a new account.
Make sure you create a password as well.
create User Windows 7
Select what type of account you want it to be:  Standard or Administrator.  Remember that a standard user is much safer.  And its perfect if you are making an account that does not require installations and modifications to the operating system.  Standard user account is great for  friends and family.  Be stingy with the administrator account because its susceptible to viruses and misconfigurations.  Only the owner of the system should have an Administrator account.
Did you lock yourself out of your Windows system? Â Forgot your Windows password? Â What is the best Windows password recovery?
The best way is to have a Windows Recovery disc ready. Â But this is something you must do BEFORE you get locked out.
reset-password
There are tools you can use to get into your system, but the first think you should try is to use “Administrator” as the user with no password. Â “Administrator” is a default account on Windows systems. Â On Windows 7 it is disabled by default but if someone has used the account you may be able to use it as backdoor into the system.
If their is not Administrator account and no Windows Recovery disc you will have to use a Windows password recovery tool. Â ONTP&RE is a password recovery tool that allows quick access to windows systems.
2. Â Unzip ONTP&E: Â Files are compressed into 1 folder named ( cd110511.zip). Â Unzip the file.
3.  Create CD with ISO:  Set the cd disc creator into ‘image to  disc’’. Burn the image to the cd.  Each CD burner software is different, so you will have to figure out how to create a CD from the ISO.  Sometimes its as easy as double clicking the ISO but it depends on the type of software.
4. Â Reboot & Insert: Â Actually, you need to make sure your Windows system is able to boot from the CD. Â Once its done , insert the cd back to the CD ROM Â and reboot your computer.
5. Â Computer Boot from CD: Â As your computer reboots, keep hitting F2 to go through the BIOS. Â Select “Boot Options”. Â Some versions of BIOS call this “Boot”. Â But the idea is the same. Â Go into the BIOS and make sure CDROM is on the top of the list for boot options. Â This means that the computer first looks at the CD before going to the Hard Drive. Â Instructions on modifying BIOS settings will be listed on the page.
6.  Boot into ONTRE:  Once the BIOS boot option is set, save and exit.  Your system will boot into your ONTRE disc.  Software will start running. Just follow the steps.  “Press enter” to boot into the “Offline NT Password & Registry Editor” CD.
screen shot of Offline NT Password & Registry Editor
7. Â Select an Account: Â It will ask you to select an account. Â If you hit “Enter” it will automatically boot into the [Administrator] account.
*note: Anything in [brackets] is the default value, so if you hit “Enter” it will auto-magically choose that [bracket] value.. its a linux thing.. you wouldn’t understand.
If you choose the “Administrator” account, you may need to Enable the account since the built-in Administrator account is  disabled by default in certain versions of Windows.
8.  Enable Built-in Administrator Account:  The Windows account  needs to be enabled.  Select 4  and enter ‘to Unlock and enable user Account’.
windows ontpre menu
9. Â Clear (blank) User Password: Â After selecting 4-Unlock and Enable user account, you will be sent back to the User Edit Menu. If you want to clear the Administrator password (if it has one) then hit enter or type Administrator and Select 1 and “Enter” – to clear the user password.
10.  Save Changes:  Once you have made all the changes you want (enabled the Administrator account & cleared any passwords), you are ready for the next step.  Hit  ‘!’ and enter.
Windows ONTP&RE password save change
On the screen it asks ‘What to do’?  hit q to quit. You will see:
Step FOUR: Â Writing back changes
“About to write file(s) back.  Do it ?’’
Hit   Y  and enter to save changes.
11. Â Last Step: Â Hit “Ctrl-Alt-Del” to reboot and eject the cd quickly. Â This will allow the system to boot into Windows on the Hard drive.
You can now login as “Administrator” with NO password.
Once you are in as Administrator you can change passwords of any local accounts in Control Panel | Users.
DISCLAIMER: I have no first hand knowledge of the NSA PRISM program. Â This is just my personal opinion of Edward Swowden’s release of classified information and the impacts.
What is PRISM:
PRISM is the code name for the data collection program which was born out of the Protect America Act.
Recently Mr. Edward Snowden released classified information to the international media and fled the U.S. Â He was working on the PRISM program and felt that the right thing to do was to tell U.S. citizens about their loss of privacy.
snowden-manning-heros
SHH!! Don’t tell anybody this.. but privacy has BEEN gone if you are on Facebook, Google or any other social network. Â These organization are storing our private data. Â But what do these organizations do with that data?
Do they try to protect your data?
Do they sometime release it to third parties?
Can certain data you store on their system be used against you in a court of law?
All of the Above 🙂
Encrypt your data. That is the only real way to have privacy to a trusted party.  Don’t use FB or Google for stuff you want hidden.
The Need for Some Sort of PRISM:
Spies get a very very bad rap lately. Â Analysts are unsung heros. Â It that world nothing is what it seems. Â The media presents one side of everything. Â You have to dig and cross reference to get facts. Â Intelligence provides a proactive answer to security. Â I am speaking from the perspective of someone who has done security defensively. Â There is a need for gathering data within the U.S. infrastructure. Â Once data is gathered, it can be correlated to detect patterns of potential threats.
So I think we MUST have something like PRISM (especially in the US) due to the exposure of our assets and the subsequent likelihood of attack. We have a high risk. Â And the greatest risk is from INSIDERS (ironically enough PRISM cannot protect itself).
There are three main issues with the programs current setup:
1.  Lack of Oversight & Transparency: There seems to be very little transparency and oversight that represents US citizens regarding privacy and controlling how far the government can go.  US Senators are led away from what is really going on.
2. Â Total Information Awareness: Â This system may be too DAMN powerful as far as what it is capable of. Â In fact, it seems to be like using GOD Mode 24/7 to gather information. Â Snowden mentioned that it can track ANY email.. is this on a whim? Â does there need to be some sort of probable cause or “reason to believe” or is this left to the discretion of the guy with his finger on the button.. this leads to the next issue..
3. The Patriot Act II + Protect America Act = Â Its too DAMN politically powerful. Â This program has the legal backing to do anything with NO checks and balances.
Is SNOWDEN A HERO?
Would I call Snowden/Manning heros/martyrs?  I would not group Snowden with Manning.  The information that Snowden released (so far) is showing a the capability of NSA spying (something that was done by whistle blower William Binney in 2002). PVT First Class Bradley Manning leaked a lot of war material that risked a lot of people’s lives:
The problem with this is that it actually endangered the lives of informants, and some people that were on the ground in Afghan/Iraq. Â Manning fucked up big time. Â Snowden is a hacktivist who will have to spend sometime in prison or in Iceland evading the US government unless the American public rallies to sway the politicians.
Whistleblower Protection:
My hope is that there is due care taken on this issue. Because there is a real concern regarding the Constitution, Privacy and uncheck powers of the government. If not, perhaps the next administration will take up the call of the people. Sarbanes–Oxley Act of 2002 has a Whistleblower Protection Act that would be helpful if such a law could apply to Snowden. I am not so sure about that.
Transparency & Accountability
I know their needs to be transparency and accountability. But I think its naive to think that we should release all information on all classified data to the world as the Wikileaks crowd believes. Â
Why?
Organizations & States have an obligation to maintain Confidentiality of critical data.
That means databases with witness protection programs must be kept Confidential, bank transactions must be protected..
Nations have some serious enemies (ESPECIALLY the US). Â The US governments duty is to protect its people from those enemies (foreign or domestic).
Consider this: Â Certain information on the physical/logical locations of weapons systems, pattens on lethal biochemicals, information on the capabilities of a nation are very effective tools in the hands of really bad people.
Its naive to think that opening up all classified data is going to set the world free. Â I wish humanity was in a kinder, gentler situation.. but the reality is some crazy people want to kill as many people as possible.
Yes! I agree that governments with unrestricted power can be MUCH more dangerous. Some transparency with check and balances are necessary.
WAR OF INFORMATION
The post modern war conflict is a fight over ideology. Its less about my nation versus your nation and more and more about belief systems. Â
RIGHT NOW there is someone with the intent to kill as many people as possible. With the capability and opportunity they would strike.  There IS an enemy and they are anywhere and everywhere.  You can no longer point at a map and say “All these people are my enemy.”
Now there is an enemy willing to kill you over what you believe, what you represent and what they think you are. Â And more than likely, THEY are living in your city. Â Who are “THEY”?
Figuring out who THEY are.. is where data mining and correlation comes in.
The threat-source can be from ANY country, race, creed, or religious faction. They are more and more likely to have a citizenship in your country for the sake of having free reign to make the most damage on the most people that represent what they seek to destroy.
Its sounds crazy until a bomb goes off in the middle of a Boston Marathon with the attackers on their way to Time Square. Luckily, there was surveillance to help deter further killings.
How do we fight against these threats?
Threats can be detected via patterns within information.
Solution: Â The government should allow the program manager of the system to explain why its necessary, provide proof of its usefulness. Â Limit the use and extent of PRISMs power.
I hope the president will listen to the Internet community on this. Â I hope that some political party will hear the cries of thousands of potential constituents then take an intelligent look at the public’s concerns. Â Realistically, the American public voted on the reps that backed the laws that created this system. Â They accepted it by proxy. Â But the shock is from the alleged reach of this program. Â Its too bad it took Snowden is risking years away from home and possibly prison for the US to wake up and start talking about something that was leaked years ago.
me with picture of CAP notificaiton
I had studied all night after freaking out about the test. I was sick and had to drive to another city to take that damn test. I was exhausted and tired.. lame excuse for being ugly lol. Its all good.. I still get laid.. but enough about ME.. lets talk about the test 😀
How to get a certification
– ISC2 Certified Authorization Professional (ISC2 CAP)
– Risk Management Certification
– Passing Score 700 out of 1000 points (125 questions on the test *25 test questions not counted toward the results)
– Application Fee: $419
– Verify 2 years experience in this field
– Endorsement Form
– Answer questions to criminal history and background
– Other Info: its a CBT, 3 hours to test, based on NIST 800 series
How Hard is the CAP Exam
I just took the ISC2 Certified Authorization Professional test (CAP Exam). I just want to give others who are about to take this test some idea of what they are up against. I noticed there is not a lot of Security Professionals talking about it. I keep hearing that there are only *1000 CAP certified people on Earth (circa 2011). I don’t think its because of the difficulty level (lol.. i mean i would not call it an EASY test, but its no CISSP or CCIE.. btw CCIE has about 25,000 certified as of about 2010 individuals on early despite being around for since 1993… according to Cisco, “fewer than 3% of Cisco certified individuals attain CCIE certification”). I think there are so few CAP certified people because its not a well know certification and its in a specialized field. Perhaps the numbers of CAP certified individuals will always be low.
My overall impression is that it is much harder than Security+ but much easier than CISSP. If you have recent experience with DoD Information Assurance Certification & Accreditation Process (DIACAP) you should have an easy time grasping the National Institute of Standards & Technology (NIST) Special Publication 800 series concepts allowing you to pass the CAP exam. I would say the same about all the C&A frameworks, NIACAP, NISPOM, DCID 6/3, DITSCAP etc. If you know the certification & accreditation process well than you will pick up risk management framework fast. If you have been doing the NIST C&A and/or Risk Management Framework, the test should be a mere refresher course for you and a couple of weeks of reviewing NIST 800 regulations and OMBs you already know might be enough for you to pass the CAP Exam and get this certifications. You should know, however, that quite a bit has changed since 2009 in the certification & accreditation process of getting authorization.
The test is in the style of the CISSP in that you must choose what is MOST right in many cases. All questions are 4-multiple choice type questions.
Study Material for the Certified Authorization Professional
One of my biggest issues about the CAP material is that is has almost NO decent study material. There is “The CISSP and CAP prep guide” by Russell Dean & Ronald L. Krutz, this is the ONLY book I have found aside from one or two lame ebooks (as of 2011).
What I used to get a CAP Certification
The very first thing you should do is become a member of Isc2.org and download the ISC2 CAP Candidate Information Bulletin. The CAP Exam CIB breaks down all the objectives that you need to be knowledgeable in.
Read and/or be very familiar with the following NIST & OMB documents:
– NIST 800-37
– NIST 800-53
– NIST 800-53A
– NIST 800-64
– NIST 800-30
– NIST 800-100
– NIST 800-83
– NIST 800-53
OMB circular A-130
Privacy Act of 1974
FISMA Act of 2002
**The full list of documents & regs to be familiar with are located in CAP CIB
Another great resource is practice tests. Ucertify.com has GREAT content for the CAP, some of the best you will find for the Certified Authorization Professional.
Areas to Spend a LOT of time on:
I would definitely know and fully understand the Risk Management Framework (800-37). You need to know the tasks on each of the six steps of the Risk Management Framework (800-37). System Development Lifecycle is also HUGE on this test(800-64). I would know how Risk Management Framework lines up with SDLC and Risk Assessment process (800-37, 64, 30). Risk Assessment process, Risk Management Framework and SDLC are all interconnected. You should know how they work together. Tasks that are done at each stage and step in all those process and what role does each task is a need to know. Roles and Responsibilities should be fully understood and memorized. Although everyone of the steps in the Risk Management framework are covered pretty good, I feel like the following two steps were beaten to death: Continuous Monitoring & assessments (security control assessor)
The test is computer based and randomized so you might get a completely different set of subject areas. Your best bet is to study what is in the CAP-CIB and use a bunch of practice tests.
What I DID NOT see on the Exam:
I was surprised not to see anything on the NIACAP, DIACAP, FITSAP, DCID 6/3 and DITSCAP. I was fully expecting it and prepared for it. Many of the practice test go on and on about Project/Program Management subject areas. But the only question I recall on that had to do with knowing the role of a Program Manager… thats about it.
Pro & CON on the ISC2 CAP Cert
CONS: I feel like the CAP is currently (2011) not in great demand. If you do a search on any job database (monster, indeed, simplyhired) you see that there are not many employees listing it as a requirement. For example, a 2011 search on isc2 CAP anywhere in the US gives 49 results — http://jobsearch.monster.com/search/?q=isc2-cap
I also think that the certification is WAY over priced. Its $419 which I think is even more than the ISC2 CISSP concentrations.
There is almost no study material for it.
PROS: Covers very important risk management framework material. Its computer based, so the results are instant. Its good lead up and practice for the ISSEP. The ISSEP covers a lot of what is in the CAP. NIST will get increasingly more important as DoD, NSA and other national security system agencies take on the NIST.
*CAP Exam: CAP certified people in the world (circa 2011):
Canada 6
Germany 1
Korea, Republic of 2
Puerto Rico 2
United States 997
reference: https://www.isc2.org/member-counts.aspx#cap
**Certification Authorization Professional Candidate Information Bulletin is on ISC2.org. May have to be a member to get the document
Understand the Risk Management Approach to Security Authorization
The concept of management of information security risks across an enterprise is discussed in 800-39. An organization takes a multitier approach to the risk management at the organizational, mission, and system levels. Risk management framework is a process that is broken down in NIST 800-37, Risk Management Framework. The CAP addresses the following:
Distinguish between applying risk management principles and satisfying compliance requirements
Identify and maintain information systems inventory
Understand the criticality of securing information
Understand organizational operations
Distinguish between applying risk management principles and satisfying compliance
Risk management includes satisfying compliance. Even though some controls may not be able to be made fully compliant due to limited resources, residual risk to the organization can still be mitigated and managed. – Concepts of NIST SP 800-37, Guide of RMF
Identifying and maintaining information system (IS) inventory is addressed in NIST 800-37, Risk Management Framework, 800-18, System Security Plan & 800-64, System Development Life Cycle. 800-37 addresses inventory of the IS in RMF Step 1 – Categorization of IS. Of the tasks of categorization includes information system registration which begins with by identifying the information system in the system inventory. This is documented in the security plan. NIST SP 800-18 discusses how the inventory is documents, and logically separates the system authorization boundary. That inventory is maintained and monitored throughout the life cycle of the IS (from imitation to disposal and from categorization to monitoring of the system).
A CAP candidate can understand the criticality of security information from reading FIPS 199, categorization of federal information systems.
Understanding the organizational operations of the system is imperative to a CAP candidate for the purpose of scope guidance described in NIST SP 800-53.
Understanding the Security Authorization of federal information systems
The ISC2 CAP candidate needs to understand the multitier approach to evaluating strategic & tactical risk across an organization/enterprise. This is discussed thoroughly in NIST SP 800-39, Managing Information Security Risk. 800-39 explains risk management from the organization, mission, and system perspective.
800-39 explains how and organization does risk framing by making risk assumptions, knowing risk constraints, risk tolerance, priorities & tradeoffs. Implementation of an organization’s risk management strategy is also based it’s governance structure.
Security Authorization is a risk management process that based on identification of threats, vulnerabilities and countermeasures. 800-39 and 800-37 explains what must be included in a risk assessments that will evaluated residual risks and determine if they are acceptable or unacceptable to the organization as whole. Unacceptable risks can be reduced by implementing security controls.
Understanding the Security Authorization of federal information systems covers the following key areas:
Understand the Risk Management Approach to Security Authorization Understanding and distinguishing among the Risk Management Framework (RMF) steps
Define and Understand Roles & Responsibilities
Understand the Relationship between the RMF and SDLC
Understand Legal, Regulatory, and Other Requirements for Security Authorization
Understand Common Controls and Security Control Inheritance
Understand Ongoing Monitoring Strategies
Understand How the Security Authorization Process Relates to:
1. Organization-wide risk management
2. System Development Life Cycle (SDLC)
3. Information system boundaries
4. Authorization decisions
SSL is the short term for Secure Sockets Layer. It is a protocol designed to enable applications to transmit information back and forth securely. Applications that used Secure Sockets layer protocol inherently know how to give and receive encryption keys with other applications, as well as how to encrypt and decrypt data sent between the two. While the S-HTTP is an extension protocol of HTTP to support sending data over World Wide Web. Not all Web browsers and servers support S-HTTP. SSL and S-HTTP have very different designs and goals so it is possible to use the two protocols together. Both protocols have been submitted to the Internet Engineering Task Force (IETF) for approval as a standard.
Some applications that are configured to run SSL include web browsers like FireFox, Internet Explorer, and Google Chrome, email programs like Outlook, Mozilla Thunderbird, Apple Mail app., and Secure File Protocol programs, etc. These programs are able to automatically receive SSL connections. To establish a secure SSL connection, however, your application must first have an encryption key assigned to it by a Certification Authority in the form of a Certificate. Once it has a unique key of its own, you can establish a secure connection using the SSL protocol.
These Technologies are mostly used in e-commerce and banking sites to avoid stealing information from the user. Web browsers automatically notify users when connections are insecure. Your potential E-commerce customers and online banking transactions are used to secure shopping and banking process, and will NOT send their private information unless their browser assures them it’s safe to do so! You cannot offer secure authentication to your customers without an SSL or S-HTTP Certificate. There are cheap SSL certificates out there; you can search over the internet.
Here is some information that might help you to determine whether the website you are browsing has a secure connection.
• When you are logging in at yahoo the left side of your address bar is in colour blue, try to point the mouse over the blue area and it will appear that the website was verified by DigiCert Inc.
• In google, it is also colour blue and was verified by Thawte Consulting (Pty) Ltd.
• In other websites, like website of a bank it has a lock icon on the left side of the address bar.
You can easily notice if the site you are browsing is not verified and has no certificate because it will appear an X on the upper left side of the browser. It means it is not safe to feed confidential information. So I hope this will help all of you.