<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.fiercegovernmentit.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Government IT News</title>
 <link>http://www.fiercegovernmentit.com/news</link>
 <description>Latest News Posts</description>
 <language>en</language>
<item>
 <title>Spotlight: Gov.uk opens APIs</title>
 <link>http://www.fiercegovernmentit.com/story/spotlight-govuk-opens-apis/2012-02-08?utm_medium=rss&amp;utm_source=rss</link>
 <description>&lt;p&gt;The application programming interfaces, or APIs, that form the &quot;bedrock on which &lt;a href=&quot;https://www.gov.uk/&quot;&gt;Gov.uk&lt;/a&gt; is built,&quot; are now available to the public, &lt;a href=&quot;http://digital.cabinetoffice.gov.uk/2012/02/07/where-are-those-apis/&quot;&gt;according to&lt;/a&gt; a Feb. 7 blog post from the U.K. Government Digital Service. The United Kingdom&#039;s consolidated government website, which went live Jan. 31, is built on APIs that pull information from back-end content management tools into the applications that populate the pages on the site.&lt;/p&gt;
&lt;p&gt;&quot;As with everything we&#039;ve made, our APIs are subject to iteration and very much in beta,&quot; wrote James Stewart, technical architect at GDS. He added that APIs provide a &quot;reasonable way to get at the content,&quot; but that &amp;nbsp;API content and formats could still change, which would&amp;nbsp;impact developers who plan to use the&amp;nbsp;APIs immediately. &lt;a href=&quot;http://digital.cabinetoffice.gov.uk/2012/02/07/where-are-those-apis/&quot;&gt;Blog post&lt;/a&gt;&lt;/p&gt;</description>
 <category domain="http://www.fiercegovernmentit.com/tags/apis">APIs</category>
 <category domain="http://www.fiercegovernmentit.com/tags/govuk">gov.uk</category>
 <category domain="http://www.fiercegovernmentit.com/tags/government-digital-service">Government Digital Service</category>
 <category domain="http://www.fiercegovernmentit.com/tags/james-stewart">James Stewart</category>
 <category domain="http://www.fiercegovernmentit.com/tags/united-kingdom">United Kingdom</category>
 <pubDate>Wed, 08 Feb 2012 13:09:29 -0500</pubDate>
 <dc:creator>Molly Bernhart Walker</dc:creator>
 <guid isPermaLink="false">19420 at http://www.fiercegovernmentit.com</guid>
</item>
<item>
 <title>Interior rebids cloud email contract; Crypto crack makes satellite phones vulnerable;</title>
 <link>http://www.fiercegovernmentit.com/story/interior-rebids-cloud-email-contract-crypto-crack-makes-satellite-phones-vu/2012-02-08?utm_medium=rss&amp;utm_source=rss</link>
 <description>&lt;p&gt;&amp;gt; Interior rebids cloud email contract. &lt;a href=&quot;http://www.nextgov.com/nextgov/ng_20120208_8479.php?oref=rss&quot;&gt;Article&lt;/a&gt; (&lt;em&gt;Nextgov&lt;/em&gt;)&lt;br /&gt;&amp;gt; Agencies piloting IT fraud prevention tool. &lt;a href=&quot;http://fcw.com/articles/2012/02/07/recovery-board-offers-new-fraud-prevention-it-tool-to-federal-agencies.aspx&quot;&gt;Article&lt;/a&gt; (&lt;em&gt;FCW&lt;/em&gt;)&lt;br /&gt;&amp;gt; Volunteers of the Internet: ICANN wants you. &lt;a href=&quot;http://techdailydose.nationaljournal.com/2012/02/icann-wants-you.php&quot;&gt;Article&lt;/a&gt; (&lt;em&gt;National Journal&lt;/em&gt;)&lt;br /&gt;&amp;gt; DoD OIG takes over classification oversight. &lt;a href=&quot;http://www.fas.org/blog/secrecy/2012/02/dodig_class.html&quot;&gt;Article&lt;/a&gt; (&lt;em&gt;Secrecy News&lt;/em&gt;)&lt;br /&gt;&amp;gt; Crypto crack makes satellite phones vulnerable. &lt;a href=&quot;http://arstechnica.com/business/news/2012/02/crypto-crack-makes-satellite-phones-vulnerable-to-eavesdropping.ars?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+arstechnica%2Findex+%28Ars+Technica+-+Featured+Content%29&quot;&gt;Article&lt;/a&gt; (&lt;em&gt;ars technica&lt;/em&gt;)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;And Finally...&lt;/strong&gt; BBC tracks down a Facebook troll. &lt;a href=&quot;http://www.fiercegovernmentit.com/pages/bbc-tracks-facebook-troll&quot;&gt;Embedded video&lt;/a&gt;&lt;/p&gt;</description>
 <pubDate>Wed, 08 Feb 2012 13:05:36 -0500</pubDate>
 <dc:creator>David Perera</dc:creator>
 <guid isPermaLink="false">19419 at http://www.fiercegovernmentit.com</guid>
</item>
<item>
 <title>NIST instructs agencies on cyber-incident response</title>
 <link>http://www.fiercegovernmentit.com/story/nist-instructs-agencies-cyber-incident-response/2012-02-08?utm_medium=rss&amp;utm_source=rss</link>
 <description>&lt;p&gt;&lt;img src=&quot;http://assets.fiercemarkets.com/files/governmentit/fierceimages/circuitboard.jpg&quot; alt=&quot;&quot; width=&quot;197&quot; height=&quot;214&quot; align=&quot;left&quot; /&gt;New cybersecurity guidance urges federal agencies to have formal incident response plans in place in preparation for the inevitable network or application intrusion. The guidance comes from a draft second revision of the National Institute of Standards and Technology &quot;Computer Security Incident Handling Guide,&quot; or &lt;a href=&quot;http://csrc.nist.gov/publications/drafts/800-61-rev2/draft-sp800-61rev2.pdf&quot;&gt;SP 800-61&lt;/a&gt; (.pdf). NIST published the first version in March 2008.&lt;/p&gt;
&lt;p&gt;Of course, prevention through the use of continuous monitoring is important--especially because threats grew stealthier since the last SP 800-61 revision, write authors.&lt;/p&gt;
&lt;p&gt;&quot;Continually monitoring threats through intrusion detection and prevention systems (IDPSs) and other mechanisms is essential,&quot; says NIST.&lt;/p&gt;
&lt;p&gt;However, incidents will and do happen, and when they do a rapid response will minimize damage.&lt;/p&gt;
&lt;p&gt;In the publication, NIST reminds agencies that the Federal Information Security Management Act requires they designate primary and secondary points of contact with the Homeland Security Department&#039;s computer emergency readiness team, or US-CERT.&lt;/p&gt;
&lt;p&gt;Agencies should have a policy and plan for reporting to US-CERT; procedures for incident handling and reporting; guidelines for communicating with outside parties on incidents; a reporting staff model with clearly designated internal and external relationships; specific services the incident response team is prepared to provide; and appropriate training in place.&lt;/p&gt;
&lt;p&gt;All guidelines for interacting with US-CERT or other organizations following an incident should also be thoroughly documented, recommends NIST--this includes guidance for prioritizing incidents and lessons learned on past incidents. And agencies should be prepared for a broad array of incidents, as well as the most common incidents, such as attacks executed through attachments in email messages or thumb drive-based viruses.&lt;/p&gt;
&lt;p&gt;NIST will accept comments on the latest revision via email through March 16, 2012.&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- &lt;a href=&quot;http://csrc.nist.gov/publications/drafts/800-61-rev2/draft-sp800-61rev2.pdf&quot;&gt;download&lt;/a&gt; NIST SP 800-61 Revision 2 (Draft) (.pdf)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related Articles:&lt;/strong&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercehomelandsecurity.com/story/private-sector-cybersecurity-info-sharing-could-run-roughshod-over-privacy/2012-01-30&quot;&gt;Private sector cybersecurity info sharing could run roughshod over privacy&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/dhs-takes-control-dib-cybersecurity-pilot/2012-01-18&quot;&gt;DHS takes control of DIB cybersecurity pilot&lt;/a&gt; &lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/cybersecurity-threats-require-public-private-partnership-says-langevin/2011-10-27&quot;&gt;Cybersecurity threats require public-private partnership, says Langevin&lt;/a&gt;&lt;/p&gt;</description>
 <category domain="http://www.fiercegovernmentit.com/tags/cybersecurity-0">cybersecurity</category>
 <category domain="http://www.fiercegovernmentit.com/tags/dhs-0">DHS</category>
 <category domain="http://www.fiercegovernmentit.com/tags/fisma">FISMA</category>
 <category domain="http://www.fiercegovernmentit.com/tags/incident-response">incident response</category>
 <category domain="http://www.fiercegovernmentit.com/tags/nist">NIST</category>
 <category domain="http://www.fiercegovernmentit.com/tags/nist-special-publication">NIST Special Publication</category>
 <category domain="http://www.fiercegovernmentit.com/tags/us-cert">US CERT</category>
 <pubDate>Wed, 08 Feb 2012 12:39:33 -0500</pubDate>
 <dc:creator>Molly Bernhart Walker</dc:creator>
 <guid isPermaLink="false">19417 at http://www.fiercegovernmentit.com</guid>
</item>
<item>
 <title>SEC lacks in configuration management, says OIG</title>
 <link>http://www.fiercegovernmentit.com/story/sec-lacks-configuration-management-says-oig/2012-02-08?utm_medium=rss&amp;utm_source=rss</link>
 <description>&lt;p&gt;&lt;img src=&quot;http://assets.fiercemarkets.com/files/governmentit/fierceimages/sechq_0.jpg&quot; alt=&quot;&quot; width=&quot;224&quot; height=&quot;189&quot; align=&quot;left&quot; /&gt;The Securities and Exchange Commission hasn&#039;t kept its cybersecurity documentation up to date, resulting in it&amp;nbsp;not conducting baseline control configuration scans and not meeting other requirements of the Federal Information Security Management Act, says the SEC office of inspector general.&lt;/p&gt;
&lt;p&gt;In a redacted report dated Feb. 2, the SEC OIG, basing its findings on an assessment conducted by Phoenix, Ariz.-based Networking Institute of Technology, says the agency does have a continuous monitoring program that assesses the security state of information system, including vulnerability scanning, patch management, and ongoing assessment of security controls.&lt;/p&gt;
&lt;p&gt;But it lacks an updated specification for the controls that should be placed on its systems in the first place and hasn&#039;t scanned to see that even the outdated specifications have been configured correctly, the OIG report says.&lt;/p&gt;
&lt;p&gt;The agency&#039;s standard baseline configuration of absolute minimum controls is at least 3 years old, the report adds, meaning it hasn&#039;t incorporated revisions in the governmentwide control catalog, a special publication published by the National Institute of Standards and Technology known as SP 800-53. (NIST is also preparing to release yet another revision to SP 800-53 later this month.)&lt;/p&gt;
&lt;p&gt;Auditors also chastise the agency for mistakenly believing that it need not tailor baseline controls set for low- moderate- and high- risk systems as set in SP 800-53. While agencies typically do align actual controls closely to low-, moderate- and high-risk control buckets as articulated in SP 800-53, under FISMA agencies are also supposed to review those generic sets of controls for effectiveness within their own information technology environments.&lt;/p&gt;
&lt;p&gt;SEC&#039;s &quot;use of a generic controls set based only on security categorization without additional tailoring may result in its understating or overstating the security requirements for systems,&quot; the report notes.&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- &lt;a href=&quot;http://www.sec-oig.gov/Reports/AuditsInspections/2012/501.pdf&quot;&gt;download&lt;/a&gt; the report, no. 501 (.pdf)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related Articles:&lt;br /&gt;&lt;/strong&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/sec-it-systems-vulnerable/2011-08-18&quot;&gt;SEC IT systems vulnerable&lt;/a&gt;&amp;nbsp;&lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/ig-sec-has-deficiencies-nearly-every-aspect-hspd-12-implementation/2011-04-07&quot;&gt;IG: SEC has &#039;deficiencies in nearly every aspect&#039; of HSPD-12 implementation&lt;/a&gt;&amp;nbsp;&lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/sec-slow-patch-management-says-ig-report/2011-03-23&quot;&gt;SEC slow with patch management, says IG report&lt;/a&gt;&lt;/p&gt;</description>
 <category domain="http://www.fiercegovernmentit.com/tags/cybersecurity-0">cybersecurity</category>
 <category domain="http://www.fiercegovernmentit.com/tags/fisma">FISMA</category>
 <category domain="http://www.fiercegovernmentit.com/tags/networking-institute-technology">Networking Institute of Technology</category>
 <category domain="http://www.fiercegovernmentit.com/tags/nist">NIST</category>
 <category domain="http://www.fiercegovernmentit.com/tags/nist-special-publication">NIST Special Publication</category>
 <category domain="http://www.fiercegovernmentit.com/tags/sec-0">SEC</category>
 <pubDate>Wed, 08 Feb 2012 12:35:25 -0500</pubDate>
 <dc:creator>David Perera</dc:creator>
 <guid isPermaLink="false">19416 at http://www.fiercegovernmentit.com</guid>
</item>
<item>
 <title>Kendall: Cyber acquisition is unique</title>
 <link>http://www.fiercegovernmentit.com/story/kendall-cyber-acquisition-unique/2012-02-08?utm_medium=rss&amp;utm_source=rss</link>
 <description>&lt;p&gt;&lt;img src=&quot;http://assets.fiercemarkets.com/files/governmentit/fierceimages/kendall3.jpg&quot; alt=&quot;&quot; width=&quot;244&quot; height=&quot;205&quot; align=&quot;left&quot; /&gt;The Defense Department is drafting a plan it will soon present to Congress to more effectively acquire cyber defense capabilities, according to Frank Kendall, acting under secretary of defense for acquisition, technology and logistics.&lt;/p&gt;
&lt;p&gt;&quot;What we&#039;re going to try to put in place is a way to respect the fact that cyber has to move at a much faster pace than anything else we do,&quot; said Kendall Feb. 6, during a Center for Strategic and International Studies event in Washington, D.C.&lt;/p&gt;
&lt;p&gt;&quot;We have to react instantaneously to many of the threats, we can&#039;t sit around and wait for a [Defense Acquisition Board] or a [Joint Requirements Oversight Council] for these things,&quot; he added. &quot;We have to take it outside the conventional system for the major, long term weapons systems.&quot;&lt;/p&gt;
&lt;p&gt;By &quot;cyber,&quot; Kendall said he means information technology used specifically for defending the networks, some IT used for intelligence gathering and &quot;the things that we might buy to attack other people.&quot;&lt;/p&gt;
&lt;p&gt;In crafting an acquisition strategy that deviates from traditional DoD procurement, it&#039;s important that cyber programs are still reviewed within the bigger picture, he said. Cyber programs would typically not be so expensive that they reach same level of review as a major defense acquisition program, said Kendall, &quot;but they&#039;re terribly important.&quot;&lt;/p&gt;
&lt;p&gt;These smaller, but critical cyber programs should be reviewed thoroughly, just as long-term, large-scale defense expenses would be, he said. The department is well aware of the threats and while much is being done to address cyber on a granular level, Kendall said the department level needs &quot;to get a better handle on exactly what we&#039;re getting for our money and exactly what our posture is.&quot;&lt;/p&gt;
&lt;p&gt;&quot;We really want to understand where we are,&quot; said Kendall. &quot;We want to know what&amp;nbsp;our defense levels are, what our abilities are to attack,...what kind of gaps we have...and what our investments are giving us.&quot;&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- &lt;a href=&quot;http://csis.org/event/acquisition-implications-dod-strategic-guidance-and-fy2013-budget&quot;&gt;see&lt;/a&gt; archived video from the event&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related Articles:&lt;/strong&gt;&lt;br /&gt;&lt;a title=&quot;Clapper sounds alarm on cyber capabilities of Iran, China and Russia&quot; href=&quot;http://www.fiercegovernmentit.com/story/clapper-sounds-alarm-cyber-capabilities-iran-china-and-russia/2012-02-01&quot;&gt;Clapper sounds alarm on cyber capabilities of Iran, China and Russia&lt;/a&gt;&lt;br /&gt;&lt;a title=&quot;Panetta: DoD cyber spending won&#039;t be cut&quot; href=&quot;http://www.fiercegovernmentit.com/story/panetta-dod-cyber-spending-wont-be-cut/2012-01-30&quot;&gt;Panetta: DoD cyber spending won&#039;t be cut&lt;/a&gt;&lt;br /&gt;&lt;a title=&quot;DHS takes control of DIB cybersecurity pilot&quot; href=&quot;http://www.fiercegovernmentit.com/story/dhs-takes-control-dib-cybersecurity-pilot/2012-01-18&quot;&gt;DHS takes control of DIB cybersecurity pilot&lt;/a&gt;&lt;/p&gt;</description>
 <category domain="http://www.fiercegovernmentit.com/tags/cyber-defense">Cyber Defense</category>
 <category domain="http://www.fiercegovernmentit.com/tags/cybersecurity-0">cybersecurity</category>
 <category domain="http://www.fiercegovernmentit.com/tags/dod-0">DoD</category>
 <category domain="http://www.fiercegovernmentit.com/tags/dod-acquisition">DoD Acquisition</category>
 <category domain="http://www.fiercegovernmentit.com/tags/frank-kendall">Frank Kendall</category>
 <pubDate>Wed, 08 Feb 2012 11:20:37 -0500</pubDate>
 <dc:creator>Molly Bernhart Walker</dc:creator>
 <guid isPermaLink="false">19413 at http://www.fiercegovernmentit.com</guid>
</item>
<item>
 <title>NIST calls for two-tier NSTIC governance body</title>
 <link>http://www.fiercegovernmentit.com/story/nist-calls-two-tier-nstic-governance-body/2012-02-08?utm_medium=rss&amp;utm_source=rss</link>
 <description>&lt;p&gt;&lt;img src=&quot;http://assets.fiercemarkets.com/files/governmentit/fierceimages/matryoshkaa.jpg&quot; alt=&quot;&quot; width=&quot;210&quot; height=&quot;156&quot; align=&quot;left&quot; /&gt;A government effort to establish a national online identity ecosystem should be led by a new, self-sustaining and privately-led steering group, says a new set of governance &lt;a href=&quot;http://www.nist.gov/nstic/2012-nstic-governance-recs.pdf&quot;&gt;recommendations&lt;/a&gt; (.pdf) released Feb. 7 by the National Strategy for Trusted Identities in Cyberspace program office.&lt;/p&gt;
&lt;p&gt;NSTIC seeks to create a new web-based identity and attribute authentication methodology through the private sector, which would offer services such as identity certificates or attribute verification. The program office, a part of the National Institute of Standards and Technology, &lt;a href=&quot;http://www.fiercegovernmentit.com/story/nist-releases-nstic-pilots-solicitation/2012-02-01&quot;&gt;released&lt;/a&gt; Feb. 1 a solicitation for pilot projects.&lt;/p&gt;
&lt;p&gt;In the new governance recommendations, the NSTIC program office calls for a two-tier steering group governance structure: A plenary containing working groups and committees, and a management council &amp;nbsp;to provide strategic guidance.&lt;/p&gt;
&lt;p&gt;The steering group should be self-sustaining after an initial period of government support, the recommendations state, without specifying a method for doing so. Possibilities to be considered include transaction fees assessed on identity ecosystem transactions, fees assessed on organizations participating in the ecosystem (e.g., identity providers, relying partners, etc.), or a steering group membership fee, the recommendations add. There should be no correlation between the amount any organization pays in fees and its standing in the steering group, the recommendations state.&lt;/p&gt;
&lt;p&gt;Membership of the steering group would be open to organizations and individuals with an interest in development of the identity ecosystem, the recommendation says, including international participants. NSTIC &quot;has to be interoperable worldwide,&quot; said White House cyber czar Howard Schmidt speaking Jan. 31 at an &lt;a href=&quot;http://csis.org/event/rethinking-identity-management-perspectives-government-and-industry&quot;&gt;event&lt;/a&gt; put on by the Center for Strategic and International Studies in Washington, D.C.&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- &lt;a href=&quot;http://www.nist.gov/nstic/2012-nstic-governance-recs.pdf&quot;&gt;download&lt;/a&gt; the NSTIC governance recommendations (.pdf)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related Articles:&lt;br /&gt;&lt;/strong&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/nist-releases-nstic-pilots-solicitation/2012-02-01&quot;&gt;NIST releases NSTIC pilots solicitation&lt;/a&gt;&amp;nbsp;&lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/nstic-will-require-privacy-legislation-say-groups/2011-07-28&quot;&gt;NSTIC will require privacy legislation, say groups&lt;/a&gt;&amp;nbsp;&lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/oasis-forms-electronic-identity-credential-technical-committee/2011-08-07&quot;&gt;OASIS forms electronic identity credential technical committee&lt;/a&gt;&lt;/p&gt;</description>
 <category domain="http://www.fiercegovernmentit.com/tags/howard-schmidt">Howard Schmidt</category>
 <category domain="http://www.fiercegovernmentit.com/tags/identity-ecosystem">identity ecosystem</category>
 <category domain="http://www.fiercegovernmentit.com/tags/identity-management">identity management</category>
 <category domain="http://www.fiercegovernmentit.com/tags/nist">NIST</category>
 <category domain="http://www.fiercegovernmentit.com/tags/nstic">NSTIC</category>
 <pubDate>Wed, 08 Feb 2012 10:46:33 -0500</pubDate>
 <dc:creator>David Perera</dc:creator>
 <guid isPermaLink="false">19412 at http://www.fiercegovernmentit.com</guid>
</item>
<item>
 <title>FedRAMP CONOPS calls for big DHS role</title>
 <link>http://www.fiercegovernmentit.com/story/fedramp-conops-calls-big-dhs-role/2012-02-08?utm_medium=rss&amp;utm_source=rss</link>
 <description>&lt;p&gt;&lt;img src=&quot;http://assets.fiercemarkets.com/files/governmentit/fierceimages/cloudcomputing_0.jpg&quot; alt=&quot;&quot; width=&quot;114&quot; height=&quot;87&quot; align=&quot;left&quot; /&gt;A concept of operations for the &lt;a href=&quot;http://www.fiercegovernmentit.com/tags/fedramp&quot;&gt;FedRAMP&lt;/a&gt; governmentwide assessment and authorization of low- and moderate-impact cloud services released Feb. 7 by the program office shows that the Homeland Security Department will have an active role in continuous monitoring and incident response.&lt;/p&gt;
&lt;p&gt;The &lt;a href=&quot;http://www.gsa.gov/graphics/staffoffices/FedRAMP_CONOPS.pdf&quot;&gt;document&lt;/a&gt; (.pdf) assigns DHS multiple responsibilities, including real-time monitoring of security posture reports from cloud service providers. Federal officials &lt;a href=&quot;http://www.fiercegovernmentit.com/story/fedramp-mandatory-cloud-providers-says-mcclure/2012-01-12&quot;&gt;say&lt;/a&gt; any provider of multi-tenant cloud computing at the low and moderate risk level must go through the FedRAMP process, which grants providers a provisional authorization valid at any federal agency. Provisional authorization doesn&#039;t substitute the need for a local agency official to sign an authorization to operate on the local network, but it should significantly speed up the process since agencies won&#039;t have to reassess provider compliance with &lt;a href=&quot;http://www.fiercegovernmentit.com/story/fedramp-baseline-controls-released/2012-01-09&quot;&gt;baseline security controls&lt;/a&gt;, federal officials say.&lt;/p&gt;
&lt;p&gt;To ensure ongoing compliance with the baseline, cloud service providers will have to provide agencies with automated security posture data feeds, which must share them with DHS, the concept of operations states.&lt;/p&gt;
&lt;p&gt;In addition, DHS, in the form of US-CERT, will have an active role in incident response, the document adds, working with the FedRAMP program office on matters including root cause analysis and recommending remedial actions.&lt;/p&gt;
&lt;p&gt;The concept of operations also explains somewhat more what constitutes a &quot;significant change&quot; that could potentially affect a cloud service provider&#039;s provisional authorization. Significant changes don&#039;t include routine changes covered by a configuration management plan, but rather changes that affect &quot;the scope of an approved provisional authorization or impact the authorization boundary.&quot;&lt;/p&gt;
&lt;p&gt;Examples include changes to applications that reside on the cloud system, changes to cloud infrastructure, to the risk posture, or in the point of contact to the FedRAMP program office.&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- &lt;a href=&quot;http://www.gsa.gov/graphics/staffoffices/FedRAMP_CONOPS.pdf&quot;&gt;download&lt;/a&gt; the FedRAMP CONOPS, v 1.0 (.pdf)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related Articles:&lt;/strong&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/fedramp-mandatory-cloud-providers-says-mcclure/2012-01-12&quot;&gt;FedRAMP is mandatory for cloud providers, says McClure&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/fedramp-baseline-controls-released/2012-01-09&quot;&gt;FedRAMP baseline controls released&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/federal-officials-launch-fedramp/2011-12-08&quot;&gt;Federal officials launch FedRAMP&lt;/a&gt;&lt;/p&gt;</description>
 <category domain="http://www.fiercegovernmentit.com/tags/configuration-management">configuration management</category>
 <category domain="http://www.fiercegovernmentit.com/tags/cybersecurity-0">cybersecurity</category>
 <category domain="http://www.fiercegovernmentit.com/tags/dhs-0">DHS</category>
 <category domain="http://www.fiercegovernmentit.com/tags/federal-cloud-computing-0">federal cloud computing</category>
 <category domain="http://www.fiercegovernmentit.com/tags/fedramp">FedRAMP</category>
 <category domain="http://www.fiercegovernmentit.com/tags/us-cert-0">US-CERT</category>
 <pubDate>Wed, 08 Feb 2012 07:17:24 -0500</pubDate>
 <dc:creator>David Perera</dc:creator>
 <guid isPermaLink="false">19409 at http://www.fiercegovernmentit.com</guid>
</item>
<item>
 <title>Air Force shopping for 18,000 iPads; Agencies still struggle with telework;</title>
 <link>http://www.fiercegovernmentit.com/story/air-force-shopping-18000-ipads-agencies-still-struggle-telework/2012-02-06?utm_medium=rss&amp;utm_source=rss</link>
 <description>&lt;p&gt;&amp;gt; Air Force shopping for 18,000 iPads. &lt;a href=&quot;http://www.nextgov.com/nextgov/ng_20120206_6067.php?oref=topnews&quot;&gt;Article&lt;/a&gt; (&lt;em&gt;NextGov&lt;/em&gt;)&lt;br /&gt;&amp;gt; Former CIO at ICE moves to DOJ. &lt;a href=&quot;http://fcw.com/articles/2012/02/03/justice-department-cio.aspx&quot;&gt;Article&lt;/a&gt; (&lt;em&gt;FCW&lt;/em&gt;)&lt;br /&gt;&amp;gt; NSA pilots smartphones. &lt;a href=&quot;http://www.informationweek.com/news/government/mobile/232600238&quot;&gt;Article&lt;/a&gt; (&lt;em&gt;InfoWeek&lt;/em&gt;)&lt;br /&gt;&amp;gt; Agencies still struggle with telework. &lt;a href=&quot;http://www.federalnewsradio.com/285/2733381/Survey-Telework-still-elusive-at-many-agencies&quot;&gt;Article&lt;/a&gt; (&lt;em&gt;FedNewsRadio&lt;/em&gt;)&lt;br /&gt;&amp;gt; FDA lawsuit raises questions about federal employee email monitoring. &lt;a href=&quot;http://www.federaltimes.com/article/20120205/IT03/202050303/1001&quot;&gt;Article&lt;/a&gt; (&lt;em&gt;Federal Times&lt;/em&gt;)&lt;br /&gt;&amp;gt; Aneesh Chopra&amp;nbsp;on&amp;nbsp;his innovation agenda. &lt;a href=&quot;http://www.theatlantic.com/politics/archive/2012/02/the-interview-aneesh-chopra/252606/&quot;&gt;Article&lt;/a&gt; (&lt;em&gt;TheAtlantic&lt;/em&gt;)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;And Finally... &amp;nbsp;&lt;/strong&gt;The Best and Worst Super Bowl Ads. &lt;a href=&quot;http://www.slate.com/articles/business/ad_report_card/2012/02/_2012_super_bowl_ads_coke_vw_chevrolet_and_other_highlights_.single.html&quot;&gt;Article&lt;/a&gt;&amp;nbsp;(&lt;em&gt;Slate&lt;/em&gt;)&lt;/p&gt;</description>
 <pubDate>Mon, 06 Feb 2012 13:16:37 -0500</pubDate>
 <dc:creator>Molly Bernhart Walker</dc:creator>
 <guid isPermaLink="false">19388 at http://www.fiercegovernmentit.com</guid>
</item>
<item>
 <title>U.K. website consolidation, open gov efforts move forward</title>
 <link>http://www.fiercegovernmentit.com/story/uk-website-consolidation-open-gov-efforts-move-forward/2012-02-06?utm_medium=rss&amp;utm_source=rss</link>
 <description>&lt;p&gt;&lt;img src=&quot;http://assets.fiercemarkets.com/files/governmentit/fierceimages/maude1.jpg&quot; alt=&quot;&quot; width=&quot;213&quot; height=&quot;265&quot; align=&quot;left&quot; /&gt;The United Kingdom launched Jan. 31 a new site called &lt;a href=&quot;https://www.gov.uk/&quot;&gt;Gov.uk&lt;/a&gt;, which serves as the single, citizen-facing government website for&amp;nbsp;all British-government information, &lt;a href=&quot;http://digital.cabinetoffice.gov.uk/2012/01/31/beta/&quot;&gt;according&lt;/a&gt; to an announcement from Tom Loosemore, project director of BBC 2.0.&amp;nbsp;The site is still considered &quot;beta,&quot; as further expansion and functionality is expected in the next two months. Gov.uk&#039;s development drew from&amp;nbsp;comments and testing in the now-shuttered website protoype, known as&amp;nbsp;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/united-kingdom-tackles-website-bloat/2011-08-03&quot;&gt;alpha.gov.uk&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In the next few weeks, Loosemore expects a private beta test of a shared Gov.uk &quot;corporate&quot; publishing platform, which will replace much of agencies&#039; activities in siloed content management systems. And by the end of March, the Government Digital Service will release the first draft of a &quot;global experience language&quot;--a guide for keeping a consistent design and user-experience as agencies develop sites within the Gov.uk domain, says the blog post.&lt;/p&gt;
&lt;p&gt;The&amp;nbsp;American federal web reform effort is watching developments in the United Kingdom closely, &lt;a href=&quot;http://www.fiercegovernmentit.com/story/vanroekel-release-final-federal-mobility-strategy-march/2012-01-17&quot;&gt;said&lt;/a&gt; Federal Chief Information Officer Steven VanRoekel earlier this year. &lt;a href=&quot;http://business.usa.gov/&quot;&gt;Business.USA.gov&lt;/a&gt;, a new website now under development, aims to consolidate business-centric information from across government in a single&amp;nbsp;place. VanRoekel said the U.K. government&#039;s move to &lt;a href=&quot;http://www.fiercegovernmentit.com/story/united-kingdom-tackles-website-bloat/2011-08-03&quot;&gt;consolidate&lt;/a&gt; all federal websites down to two domains--a business interface and a consumer interface--is &quot;actually a pretty good model on the whole...I want to learn from and see how it works out and we&#039;re talking to the British government about analytics.&quot;&lt;/p&gt;
&lt;p&gt;Gov.uk was built around 667 actions, or &quot;needs people have of Government,&quot; but the blog post notes there are more needs to be addressed. The site is optimized for search, rather than browsing, notes Loosemore, who says browsing by section also still needs work. In creating the site, the Government Digital Service built a scalable, modular open source platform to support needs across many government departments.&lt;/p&gt;
&lt;p&gt;Helping citizens find information more easily through Gov.uk is just one piece of the United Kingdom&#039;s broader open government efforts. The government is opening more data around health outcomes, education, transportation, criminal justice, and central and local government spending, said Francis Maude, the U.K. minister for the Cabinet Office, while speaking Jan. 30 at a World Bank event in Washington, D.C.&lt;/p&gt;
&lt;p&gt;&quot;There&#039;s nothing soft, or fluffy, or cozy about transparency. It&#039;s hard and it&#039;s difficult. And it makes life difficult for those who govern, but it makes life better for those who are governed,&quot; said Maude.&lt;/p&gt;
&lt;p&gt;One major initiative underway&amp;nbsp;is a program called &lt;a href=&quot;http://www.fiercegovernmentit.com/story/uk-govt-unveils-midata-initiative/2011-11-14&quot;&gt;Midata&lt;/a&gt;, which aims to give British consumers access to the personal data companies collect on them in an electronic format. Personal information empowers the individual, said Maude. &lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&quot;Our ambition is to transform high-tech consumer information markets, through the provision of online citizen access to personal data including medical records online,&quot; he said.&lt;/p&gt;
&lt;p&gt;Opening data does present challenges, however, in that some data is not accurate or easy to use. Maude said its important to keep in mind that speed trumps accuracy.&lt;/p&gt;
&lt;p&gt;&quot;Get the data out there, let people and organizations scrutinize it, examine it, interrogate it, and if it isn&#039;t high quality to being with--and a lot of it isn&#039;t--it will pretty soon improve,&quot; said Maude.&lt;/p&gt;
&lt;p&gt;In April, the United Kingdom will take over as co-chair of the &lt;a href=&quot;http://www.fiercegovernment.com/tags/open-government-partnership&quot;&gt;Open Government Partnership&lt;/a&gt; and Maude said he hopes his government can share important lessons learned from its experience with open government.&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- &lt;a href=&quot;http://digital.cabinetoffice.gov.uk/2012/01/31/beta/&quot;&gt;see&lt;/a&gt; the Government Digital Service blog post&lt;br /&gt;- &lt;a href=&quot;mms://wbmswebcast1.worldbank.org/CITPO/2012-01-30/Open_Government.asf&quot;&gt;download&lt;/a&gt; archived video from the World Bank event&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related Articles: &lt;br /&gt;&lt;/strong&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/europe-unveils-open-data-strategy-hopes-see-economic-benefits/2011-12-14&quot;&gt;Europe unveils open data strategy, hopes to see economic benefits&lt;/a&gt; &lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/uk-govt-unveils-midata-initiative/2011-11-14&quot;&gt;U.K. government unveils &#039;midata&#039; initiative&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/uk-liberal-democrats-urge-open-source/2011-09-28&quot;&gt;U.K. Liberal Democrats urge open source&lt;/a&gt; &lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/united-kingdom-tackles-website-bloat/2011-08-03&quot;&gt;United Kingdom tackles website bloat&lt;/a&gt;&lt;/p&gt;</description>
 <category domain="http://www.fiercegovernmentit.com/tags/federal-websites-0">federal websites</category>
 <category domain="http://www.fiercegovernmentit.com/tags/francis-maude">Francis Maude</category>
 <category domain="http://www.fiercegovernmentit.com/tags/midata">midata</category>
 <category domain="http://www.fiercegovernmentit.com/tags/open-government">Open Government</category>
 <category domain="http://www.fiercegovernmentit.com/tags/open-government-partnership">Open Government Partnership</category>
 <category domain="http://www.fiercegovernmentit.com/tags/steven-vanroekel">Steven VanRoekel</category>
 <category domain="http://www.fiercegovernmentit.com/tags/tom-loosemore">Tom Loosemore</category>
 <category domain="http://www.fiercegovernmentit.com/tags/united-kingdom">United Kingdom</category>
 <pubDate>Mon, 06 Feb 2012 12:33:16 -0500</pubDate>
 <dc:creator>Molly Bernhart Walker</dc:creator>
 <guid isPermaLink="false">19387 at http://www.fiercegovernmentit.com</guid>
</item>
<item>
 <title>NASA looks for small satellite swarming technology</title>
 <link>http://www.fiercegovernmentit.com/story/nasa-looks-small-satellite-swarming-technology/2012-02-06?utm_medium=rss&amp;utm_source=rss</link>
 <description>&lt;p&gt;&lt;img src=&quot;http://assets.fiercemarkets.com/files/governmentit/fierceimages/cubesat-a.jpg&quot; alt=&quot;&quot; width=&quot;228&quot; height=&quot;181&quot; align=&quot;left&quot; /&gt;As small satellites that weigh less than 400 pounds proliferate, NASA says it sees potential and challenges in operating them together as a coordinated constellation.&lt;/p&gt;
&lt;p&gt;To that end, NASA says it&#039;s willing to fund &quot;Edison SmallSat&quot; projects&amp;nbsp;worth up to $15 million that demonstrate key technologies such as command and control communications between small satellites. Also of interest are propulsion technologies--specifically utilizing high performance, low-toxicity propellants such as electrical propulsion, solar sail or tethers--and a combination of control systems, sensors and software permitting small satellites to work in close proximity, even physically joining other spacecraft.&lt;/p&gt;
&lt;p&gt;The propulsion technology demonstration is restricted to CubeSats, the one liter square-shaped nanosatellites developed for research.&lt;/p&gt;
&lt;p&gt;NASA &lt;a href=&quot;http://www.nasa.gov/home/hqnews/2012/feb/HQ_12-042_Edison_Smallsat.html&quot;&gt;announced&lt;/a&gt; the funding opportunity in a &lt;a href=&quot;http://nspires.nasaprs.com/external/solicitations/summary.do?method=init&amp;amp;solId=%7b8D91056C-FD45-817A-3393-C9252FDF3326%7d&amp;amp;path=open&quot;&gt;broad agency announcement&lt;/a&gt; dated Feb. 2, with initial proposal summaries due by March 4.&lt;/p&gt;
&lt;p&gt;The demonstration satellites will launch as secondary or hosted payloads with other spacecraft missions, but the BAA says they could be launched as primary payloads on very small launch vehicles, &quot;if and when these launch vehicles come into existence.&quot;&lt;/p&gt;
&lt;p&gt;The notion of small satellites flung into space with small rockets has been a long-standing dream of the space community, particularly the military, which hopes to develop a tactical response capability it dubs &quot;operationally responsive space.&quot;&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- &lt;a href=&quot;http://nspires.nasaprs.com/external/solicitations/summary.do?method=init&amp;amp;solId=%7b8D91056C-FD45-817A-3393-C9252FDF3326%7d&amp;amp;path=open&quot;&gt;go to&lt;/a&gt; a NASA webpage with links to the BAA &lt;br /&gt;- &lt;a href=&quot;http://nspires.nasaprs.com/external/viewrepositorydocument/cmdocumentid=304776/solicitationId=%7B8D91056C-FD45-817A-3393-C9252FDF3326%7D/viewSolicitationDocument=1/Edison%20BAA.pdf&quot;&gt;download&lt;/a&gt; the BAA directly (.pdf)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related Articles: &lt;br /&gt;&lt;/strong&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/darpa-plans-make-space-trash-treasure/2012-01-05&quot;&gt;DARPA plans to make space trash into treasure&lt;/a&gt;&amp;nbsp;&lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/air-force-plans-launch-wgs-4/2012-01-18&quot;&gt;Air Force plans launch of WGS-4&lt;/a&gt;&amp;nbsp;&lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/nasa-acquisition-capabilities-questioned-jpss-hearing/2011-09-26&quot;&gt;NASA acquisition capabilities questioned at JPSS hearing&lt;/a&gt;&lt;/p&gt;</description>
 <category domain="http://www.fiercegovernmentit.com/tags/cubesat">CubeSat</category>
 <category domain="http://www.fiercegovernmentit.com/tags/edison-smallsat">Edison SmallSat</category>
 <category domain="http://www.fiercegovernmentit.com/tags/nanosatellite">nanosatellite</category>
 <category domain="http://www.fiercegovernmentit.com/tags/nasa">NASA</category>
 <category domain="http://www.fiercegovernmentit.com/tags/operationally-responsive-space">operationally responsive space</category>
 <category domain="http://www.fiercegovernmentit.com/tags/satellites">satellites</category>
 <pubDate>Mon, 06 Feb 2012 11:53:18 -0500</pubDate>
 <dc:creator>David Perera</dc:creator>
 <guid isPermaLink="false">19386 at http://www.fiercegovernmentit.com</guid>
</item>
<item>
 <title>FEMA focuses on speed, not perfection in using social media</title>
 <link>http://www.fiercegovernmentit.com/story/fema-focuses-speed-not-perfection-using-social-media/2012-02-06?utm_medium=rss&amp;utm_source=rss</link>
 <description>&lt;p&gt;&lt;img src=&quot;http://assets.fiercemarkets.com/files/governmentit/fierceimages/fugate3.jpg&quot; alt=&quot;&quot; width=&quot;213&quot; height=&quot;210&quot; align=&quot;left&quot; /&gt;The Federal Emergency Management Agency is using information gathered from social media monitoring when deciding how to respond to a disaster. While official assessments are more thorough, speed is more important than precision, said FEMA Administrator Craig Fugate at a Feb. 3 event hosted by the State Department called &lt;a href=&quot;http://tech.state.gov/profiles/blogs/tech-state-real-time-awareness-agenda&quot;&gt;Tech@State&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&quot;Disasters are like horseshoes, hand grenades and thermo nuclear devices; you just have to be close,&quot; said Fugate. &quot;You won&#039;t get that time back...speed in response is the most perishable commodity in a disaster.&quot;&lt;/p&gt;
&lt;p&gt;Recovery following Hurricane Katrina failed because FEMA spent the first 12 to 24 hours of the disaster getting teams&amp;nbsp;into the area to make an assessment and send information back to headquarters, said Fugate. That means within 12 to 24 hours people with survivable injuries were worsening and nothing was actually accomplished.&lt;/p&gt;
&lt;p&gt;When tornadoes ripped through Joplin, Mo. in May 2011, FEMA had enough information--although imperfect--from Twitter and Facebook to suggest that the situation was dire, said Fugate.&lt;/p&gt;
&lt;p&gt;&quot;The &#039;official&#039; part is overplayed,&quot; said Fugate. &quot;If you want to make social media real you have to see [the public] as a resource rather than a liability.&quot;&lt;/p&gt;
&lt;p&gt;Despite FEMA&#039;s increasing reliance on social media in disaster response, Fugate said he is not &quot;a big advocate of technology.&quot; Rather, technology is &quot;just another tool,&quot; he said.&lt;/p&gt;
&lt;p&gt;&quot;I&#039;m in the business of trying to changed outcomes. Disasters happen, I can&#039;t stop them,&quot; said Fugate. &quot;No tweet stops bleeding...unless something has actually changed, it&#039;s just information.&quot;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related Articles:&lt;br /&gt;&lt;/strong&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/disaster-response-increasingly-linked-social-media/2011-08-31&quot;&gt;Disaster response increasingly linked to social media &lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;a href=&quot;http://www.fiercehomelandsecurity.com/story/fema-cant-be-experimental-and-quick-says-dhs-oig/2012-01-19&quot;&gt;FEMA can&#039;t be experimental and quick, says DHS OIG&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/social-media-primary-source-intel-says-fbi/2012-01-25&quot;&gt;Social media a &#039;primary source&#039; of intel, says FBI&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/twitter-enables-global-state-department-briefings/2012-01-09&quot;&gt;Twitter enables global State Department briefings&lt;/a&gt;&lt;/p&gt;</description>
 <category domain="http://www.fiercegovernmentit.com/tags/craig-fugate">Craig Fugate</category>
 <category domain="http://www.fiercegovernmentit.com/tags/disaster-response">disaster response</category>
 <category domain="http://www.fiercegovernmentit.com/tags/fema-0">FEMA</category>
 <category domain="http://www.fiercegovernmentit.com/tags/hurricane-katrina">Hurricane Katrina</category>
 <category domain="http://www.fiercegovernmentit.com/tags/joplin">Joplin</category>
 <category domain="http://www.fiercegovernmentit.com/tags/social-media-0">social media</category>
 <category domain="http://www.fiercegovernmentit.com/tags/tech-state">Tech at State</category>
 <category domain="http://www.fiercegovernmentit.com/tags/tornados">Tornados</category>
 <category domain="http://www.fiercegovernmentit.com/tags/twitter">Twitter</category>
 <pubDate>Mon, 06 Feb 2012 09:46:13 -0500</pubDate>
 <dc:creator>Molly Bernhart Walker</dc:creator>
 <guid isPermaLink="false">19382 at http://www.fiercegovernmentit.com</guid>
</item>
<item>
 <title>OMB Shared First should include open source, says group</title>
 <link>http://www.fiercegovernmentit.com/story/omb-shared-first-should-include-open-source-says-group/2012-02-06?utm_medium=rss&amp;utm_source=rss</link>
 <description>&lt;p&gt;&lt;img src=&quot;http://assets.fiercemarkets.com/files/government/fierceimages/opensigna.jpg&quot; alt=&quot;&quot; width=&quot;232&quot; height=&quot;178&quot; align=&quot;left&quot; /&gt;Open source advocates urge the Office of Management and Budget to expand its Shared First strategy to include open source software development in a Feb. 2 comment posted online.&lt;/p&gt;
&lt;p&gt;OMB &lt;a href=&quot;http://www.fiercegovernmentit.com/story/share-says-omb/2011-12-14&quot;&gt;released&lt;/a&gt; Dec. 8 a draft &amp;nbsp;strategy calling on agencies to develop a plan to shift at minimum two commodity IT areas &quot;to a shared environment&quot; by Dec. 31, 2012. The agency says it will have a final strategy developed by April to guide agencies toward the common utilization of commodity and support IT at the intra- and inter- agency level, &quot;culminating with improvement in mission IT.&quot;&lt;/p&gt;
&lt;p&gt;&quot;There is no explicit mention of open source in the plan at this time, we believe that there should be,&quot; &lt;a href=&quot;http://opensourceforamerica.org/2012/02/osfa-responds-to-draft-shared-first-policy/&quot;&gt;says&lt;/a&gt; the comment form Open Source For America, a group consisting of open source companies and supporters promoting open source adoption within the federal government.&lt;/p&gt;
&lt;p&gt;Were the shared first mandate to extend toward the sharing of development resources as federal agencies work toward sharing mission software, the degree of application customization necessary from one agency to the next could be reduced were agencies to develop software under open source licenses, the comment asserts. Open source also has a solution for the discoverability of potential shared services through online websites like sourceforge.net and github.net, the comment states.&lt;/p&gt;
&lt;p&gt;&quot;Open source excels at the Shared First design goals, including visibility, commoditization, reusability, extensibility, and standardization,&quot; the comment says.&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- &lt;a href=&quot;http://opensourceforamerica.org/2012/01/osfa-responds-to-the-us-open-government-national-action-plan/&quot;&gt;go to&lt;/a&gt; the OSFA shared first comment&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related Articles: &lt;br /&gt;&lt;/strong&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/nasa-looks-lower-open-source-licensing-barriers/2012-01-18&quot;&gt;NASA looks to lower open source licensing barriers&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/disa-revises-software-guideline-clarifying-open-source-rules/2012-01-04&quot;&gt;DISA revises software guideline clarifying open source rules&lt;/a&gt;&amp;nbsp;&lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/share-says-omb/2011-12-14&quot;&gt;Share, says OMB&lt;/a&gt;&lt;/p&gt;</description>
 <category domain="http://www.fiercegovernmentit.com/tags/omb-0">OMB</category>
 <category domain="http://www.fiercegovernmentit.com/tags/open-source">open source</category>
 <category domain="http://www.fiercegovernmentit.com/tags/open-source-america">Open Source for America</category>
 <category domain="http://www.fiercegovernmentit.com/tags/shared-first">Shared First</category>
 <pubDate>Mon, 06 Feb 2012 06:25:31 -0500</pubDate>
 <dc:creator>David Perera</dc:creator>
 <guid isPermaLink="false">19378 at http://www.fiercegovernmentit.com</guid>
</item>
<item>
 <title>Trojan masquerading as Windows updater targets defense contractors</title>
 <link>http://www.fiercegovernmentit.com/story/trojan-masquerading-widows-updater-target-defense-contractors/2012-02-05?utm_medium=rss&amp;utm_source=rss</link>
 <description>&lt;p&gt;&lt;img src=&quot;http://assets.fiercemarkets.com/files/governmentit/fierceimages/domenicotiepolo-1.jpg&quot; alt=&quot;&quot; width=&quot;232&quot; height=&quot;243&quot; align=&quot;left&quot; /&gt;Security researchers say they&#039;ve uncovered a remote access Trojan masquerading as a Microsoft&amp;nbsp;(&lt;a href=&quot;http://www.fiercegovernmentit.com/tags/microsoft&quot;&gt;NASDAQ: MSFT&lt;/a&gt;)&amp;nbsp;operating system updater targeting U.S. and foreign defense, aero- and geo- space contractors.&lt;/p&gt;
&lt;p&gt;In a joint paper published Jan. 31, security firms Zscaler and Seculert say they both observed in 2010 Internet traffic to a malicious command and control servers trying to appear as though it were related to Microsoft&#039;s Windows Update. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;In the paper, they dub the Trojan the &quot;MSUpdater,&quot; adding that its spread has been aided by phishing emails with infected .pdf attachment that take advantage of zero day exploits in Adobe Reader. Infected emails have been sent since at least spring 2009, according to data in the paper.&lt;/p&gt;
&lt;p&gt;Its operators have favored conference-related subjects as phishing lure. For example, one message used an attachment related to the International Conference on Intelligence Sensors, Sensors Networks and Information Processing. Other malicious attachments reference the IEEE Aerospace Conference and the International Conference and Communications System Software and Middleware.&lt;/p&gt;
&lt;p&gt;The Trojan is virtual machine aware, meaning that it is coded to detect whether it is running in a virtualized environment. That makes its detection difficult, since malware analysis is typically done on virtual machines. Once downloaded onto a machine, using the file name msupdater.exe, the Trojan will run in the computer&#039;s memory as a common process, often svchost.exe, the paper says.&lt;/p&gt;
&lt;p&gt;In a &lt;a href=&quot;http://research.zscaler.com/2012/01/msupdater-trojan-and-link-to-targeted.html&quot;&gt;blog post&lt;/a&gt;, Zscaler researchers say the combination of the Trojan file name and the HTTP paths used to reach the command and control server (often something like /microsoftupdate/getupdate/default.aspx) combine to keep the infection under the radar. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- &lt;a href=&quot;http://zscaler.com/pdf/whitepapers/msupdater_trojan_whitepaper.pdf&quot;&gt;download&lt;/a&gt; the paper, &quot;The&#039;MSUpdater&#039; Trojan and Ongoing Targeted Attacks&quot; (.pdf)&lt;br /&gt;- &lt;a href=&quot;http://research.zscaler.com/2012/01/msupdater-trojan-and-link-to-targeted.html&quot;&gt;go to&lt;/a&gt; the Zscaler blog post&lt;br /&gt;- &lt;a href=&quot;http://blog.seculert.com/2012/01/msupdater-trojan-and-conference-invite.html&quot;&gt;go to&lt;/a&gt; a Seculert blog post about the Trojan&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related Articles: &lt;br /&gt;&lt;/strong&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/keyloggers-and-trojan-horses-ssa-workstations/2010-11-02&quot;&gt;Keyloggers and Trojan horses on SSA workstations&lt;/a&gt;&amp;nbsp;&lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/china-suspected-operation-shady-rat-hacks/2011-08-03&quot;&gt;China suspected in Operation Shady RAT hacks&lt;/a&gt;&amp;nbsp;&lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/dhs-takes-control-dib-cybersecurity-pilot/2012-01-18&quot;&gt;DHS takes control of DIB cybersecurity pilot&lt;/a&gt;&lt;/p&gt;</description>
 <category domain="http://www.fiercegovernmentit.com/tags/cybersecurity-0">cybersecurity</category>
 <category domain="http://www.fiercegovernmentit.com/tags/defense-industrial-base">defense industrial base</category>
 <category domain="http://www.fiercegovernmentit.com/tags/msupdater">MSUpdater</category>
 <category domain="http://www.fiercegovernmentit.com/tags/phishing">phishing</category>
 <category domain="http://www.fiercegovernmentit.com/tags/seculert">Seculert</category>
 <category domain="http://www.fiercegovernmentit.com/tags/zscaler">Zscaler</category>
 <pubDate>Sun, 05 Feb 2012 23:19:34 -0500</pubDate>
 <dc:creator>David Perera</dc:creator>
 <guid isPermaLink="false">19376 at http://www.fiercegovernmentit.com</guid>
</item>
<item>
 <title>FAA reauthorization would create NextGen czar UPDATED</title>
 <link>http://www.fiercegovernmentit.com/story/faa-reauthorization-would-create-nextgen-czar/2012-02-02?utm_medium=rss&amp;utm_source=rss</link>
 <description>&lt;p&gt;&lt;img src=&quot;http://assets.fiercemarkets.com/files/governmentit/fierceimages/faa.jpg&quot; alt=&quot;&quot; width=&quot;230&quot; height=&quot;172&quot; align=&quot;left&quot; /&gt;A four year, $63.6 billion Federal Aviation Administration authorization bill agreed to by a conference committee of House and Senate lawmakers would require creation of a Chief NextGen Officer. The bill would also authorize the agency to spend nearly $16 billion annually on the air traffic control modernization effort.&lt;/p&gt;
&lt;p&gt;Already being dubbed the &quot;NextGen czar,&quot; the officer will report to the FAA administrator, should Congress approve the bill and the president sign it. The bill is likely to gain approval on both fronts and could pass Congress as early as Feb. 3. The bill would end a series of short-term authorizations the agency has operated under since 2008. During a month-long period in mid-2011, the agency underwent a partial shutdown after Congress failed to approve another temporary extension.&lt;img src=&quot;http://assets.fiercemarkets.com/files/governmentit/fierceimages/nextgenauthorization.jpg&quot; alt=&quot;&quot; width=&quot;461&quot; height=&quot;277&quot; align=&quot;left&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The authorization bill also affirms the agency&#039;s decision to require ADS-B Out avionics on board most airplanes by 2020, and doesn&#039;t make the deadline 2015 as previous authorization had required. Language from an &lt;a href=&quot;http://www.fiercegovernmentit.com/story/house-faa-reauthorization-would-make-ads-b-mandatory/2011-02-14&quot;&gt;earlier version&lt;/a&gt; of the authorization bill making ADS-B In mandatory also is not included in the final, conference version. ADS-B is the backbone of NextGen, which seeks to largely replace radars with Global Positioning System-derived data for tracking aircraft positions. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;The bill also requires the Transportation secretary to accelerate the integrating of unmanned aerial vehicles into national airspace by producing a plan within 270 days of the bill&#039;s passage into law. The plan would be incorporated into the NextGen implementation plan.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;UPDATED Feb. 2, 3:00 p.m.: NextGen authorization figures added to story.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- &lt;a href=&quot;http://docs.house.gov/billsthisweek/20120130/CRPT-112HPRT-HR658.pdf&quot;&gt;download&lt;/a&gt; the FAA authorization conference bill (.pdf) &lt;br /&gt;- &lt;a href=&quot;http://docs.house.gov/billsthisweek/20120130/CRPT-112HPRT-HR658JSOM.pdf&quot;&gt;download&lt;/a&gt; the conference committee&#039;s joint explanatory statement (.pdf)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related Articles: &lt;br /&gt;&lt;/strong&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/top-faa-execs-lack-institutional-knowledge-says-official-agency-must-be-pre/2012-01-22&quot;&gt;Top FAA execs lack institutional knowledge, says official; agency must be prepared for cuts&lt;/a&gt;&amp;nbsp;&lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/eram-now-ioc-four-more-artccs-says-faa/2012-01-16&quot;&gt;ERAM now IOC at four more ARTCCs, says FAA&lt;/a&gt;&amp;nbsp;&lt;br /&gt;&lt;a href=&quot;http://www.fiercegovernmentit.com/story/auditors-question-faa-oversight-ads-b-towers/2011-08-10&quot;&gt;Auditors question FAA oversight of ADS-B towers&lt;/a&gt;&lt;/p&gt;</description>
 <category domain="http://www.fiercegovernmentit.com/tags/ads-b">ADS-B</category>
 <category domain="http://www.fiercegovernmentit.com/tags/congress">Congress</category>
 <category domain="http://www.fiercegovernmentit.com/tags/faa-0">FAA</category>
 <category domain="http://www.fiercegovernmentit.com/tags/faa-modernization-and-reform-act-2012">FAA Modernization and Reform Act of 2012</category>
 <category domain="http://www.fiercegovernmentit.com/tags/nextgen">NextGen</category>
 <category domain="http://www.fiercegovernmentit.com/tags/nextgen-czar">NextGen czar</category>
 <category domain="http://www.fiercegovernmentit.com/tags/uavs">UAVs</category>
 <pubDate>Thu, 02 Feb 2012 13:06:54 -0500</pubDate>
 <dc:creator>David Perera</dc:creator>
 <guid isPermaLink="false">19360 at http://www.fiercegovernmentit.com</guid>
</item>
<item>
 <title>FBI calls cyber attacks a top terror threat; HASC Chairman: Kill BRAC;</title>
 <link>http://www.fiercegovernmentit.com/story/fbi-calls-cyber-attacks-top-terror-threat-hasc-chairman-kill-brac/2012-02-02?utm_medium=rss&amp;utm_source=rss</link>
 <description>&lt;p&gt;&amp;gt; HASC Chairman: Kill BRAC. &lt;a href=&quot;http://www.dodbuzz.com/2012/02/02/hasc-chairman-on-brac-kill-it/&quot;&gt;Article&lt;/a&gt; (&lt;em&gt;DoD Buzz&lt;/em&gt;)&lt;br /&gt;&amp;gt; $638M contract to deliver Navy ships with common computing network. &lt;a href=&quot;http://www.nextgov.com/nextgov/ng_20120201_5077.php?oref=topstory&quot;&gt;Article&lt;/a&gt; (&lt;em&gt;NextGov&lt;/em&gt;)&lt;br /&gt;&amp;gt; White House pushes Congress to fast track reorganization authority. &lt;a href=&quot;http://www.federaltimes.com/article/20120131/AGENCY04/201310303/1018/DEPARTMENTS&quot;&gt;Article&lt;/a&gt; (&lt;em&gt;Federal Times&lt;/em&gt;)&lt;br /&gt;&amp;gt; FBI calls cyber attacks a top terror threat. &lt;a href=&quot;http://www.informationweek.com/news/government/security/232600046&quot;&gt;Article&lt;/a&gt; (&lt;em&gt;InfoWeek&lt;/em&gt;)&lt;br /&gt;&amp;gt; MyTSA mobile app expanding. &lt;a href=&quot;http://fedscoop.com/expanding-the-mytsa-app/&quot;&gt;Article&lt;/a&gt; (&lt;em&gt;FedScoop&lt;/em&gt;)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;And Finally... &lt;/strong&gt;Inside the offices of LEGO. &lt;a href=&quot;http://www.dezeen.com/2012/01/31/lego-pmd-by-rosan-bosch-and-rune-fjord/&quot;&gt;Article&lt;/a&gt; (&lt;em&gt;Dezeen&lt;/em&gt;)&lt;/p&gt;</description>
 <pubDate>Thu, 02 Feb 2012 12:34:45 -0500</pubDate>
 <dc:creator>Molly Bernhart Walker</dc:creator>
 <guid isPermaLink="false">19359 at http://www.fiercegovernmentit.com</guid>
</item>
</channel>
</rss>

