<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; federal-information-security-management-act</title>
	<atom:link href="http://www.darknet.org.uk/tag/federal-information-security-management-act/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>OpenFISMA &#8211; FISMA Compliance &amp; Risk Management Application</title>
		<link>http://www.darknet.org.uk/2010/08/openfisma-fisma-compliance-risk-management-application/</link>
		<comments>http://www.darknet.org.uk/2010/08/openfisma-fisma-compliance-risk-management-application/#comments</comments>
		<pubDate>Tue, 10 Aug 2010 10:13:50 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Legal Issues]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[federal-information-security-management-act]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[fisma audit]]></category>
		<category><![CDATA[fisma compliance]]></category>
		<category><![CDATA[fisma tool]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[nist audit]]></category>
		<category><![CDATA[nist scanner]]></category>
		<category><![CDATA[nist tool]]></category>
		<category><![CDATA[open fisma]]></category>
		<category><![CDATA[openfisma]]></category>
		<category><![CDATA[risk management application]]></category>
		<category><![CDATA[risk management frameowork]]></category>
		<category><![CDATA[risk management tool]]></category>
		<category><![CDATA[risk-management]]></category>
		<category><![CDATA[rmf]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2788</guid>
		<description><![CDATA[The OpenFISMA project is an open source application designed to reduce the complexity and automate the regulatory requirements of the Federal Information Security Management Act (FISMA) and the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF). OpenFISMA is built on a modern, standardized platform called Zend Framework, which is an open source, [...]]]></description>
			<content:encoded><![CDATA[<p>The OpenFISMA project is an open source application designed to reduce the complexity and automate the regulatory requirements of the  Federal Information Security Management Act (FISMA) and the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF).</p>
<p>OpenFISMA is built on a modern, standardized platform called Zend Framework, which is an open source, object-oriented web application framework with a flexible architecture.</p>
<p>The OpenFISMA project is unique in several ways.</p>
<ul>
<li><strong>Open source</strong> &#8211; OpenFISMA is the largest open source project for the U.S. federal government. See the open source section for an explanation of the advantages of open source.</li>
<li><strong>Highly customizable</strong> &#8211; OpenFISMA is highly customizable through our web-based administration interface. The branding can be changed. The workflow can be changed. The roles and privileges can be changed. New reports can be added to the system without writing a single line of code.</li>
<li>
<strong>Easy to deploy</strong> &#8211; OpenFISMA comes with built-in security controls that allow you to easily C&#038;A your OpenFISMA implementation with ease. OpenFISMA also provides configurable security policies so that your implementation will fall in-line with your agency&#8217;s specific security policies as well.</li>
</ul>
<p><strong>Features</strong></p>
<ul>
<li><strong>Track security weaknesses to closure</strong>
<p>OpenFISMA provides a proven business process for tracking the remediation of security weaknesses. This business process enforces quality controls and segregation of duty, pulling together individuals from different areas of the organization to plan, execute, and review all remediation actions.</li>
<li><strong>Role-based access control</strong>
<p>Access control is based on roles; each role has fine-grained access to certain privileges on each information system that is being tracked. The roles are completely customizable.</li>
<li><strong>Active Directory/OpenLDAP Authentication</strong>
<p>      Authentication in OpenFISMA can be handled by any LDAP-compatible service, such as Microsoft Active Directory (AD) or OpenLDAP, in order to provide single sign-on convenience for your agency&#8217;s users.</li>
<li><strong>Scan Injection</strong>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-BodyRec */
google_ad_slot = "8649785837";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div></p>
<p>      If you run automated scans as part of your C&#038;A process or as part of a continuous monitoring program, you can upload your scan results in XML format directly into OpenFISMA. OpenFISMA uses the information in scans to create new findings, assess risk exposure, and even update your asset inventory.</p>
<p>      The scan injection provides some smarts, too. OpenFISMA matches new scan results against past scan results. Based on a simple set of rules, it decides whether to supress duplicate findings or to flag multiple, similar findings for human review. This reduces the overhead of redundant findings and can also help your organization identify systemic weaknesses that could be addressed more efficiently at the enterprise level.</li>
<li><strong>E-mail Notifications</strong>
<p>      OpenFISMA sends notifications directly to users&#8217; inboxes when action is needed from them. This automated notification system relieves security managers of the burden of manually monitoring the workflow. The notification system also reduces turn-around time by alerting users quickly when their action is needed.</li>
<li><strong>Rich Text Editing</strong>
<p>      Data about findings is entered using a rich text editor that allows for formatting (bold, italics, underline, and outline formats) as well as spell checking.</li>
<li>
<strong>Plug-in Reports</strong></p>
<p>      Reporting is one of the most critical requirements for any process management tool. OpenFISMA provides the ability to &#8220;plug in&#8221; a report without writing any code. These reports are created by writing SQL and updating a configuration file. OpenFISMA then creates the interface and data export features on-the-fly. The plug-in architecture drastically reduces the cost and time involved in creating custom reports.</li>
<li><strong>NIST SP 800-53 Rev. 2</strong>
<p>      OpenFISMA contains many of the NIST SP 800-53 security controls required for a FIPS-199 &#8220;high&#8221; impact information system. This helps you get your OpenFISMA instance authorized to operate quickly. The built-in controls include system use notification, rules of behavior, electronic privacy policy (p3p), and many, many more.</p>
<p>      OpenFISMA also contains a catalog of all NIST SP 800-53 Rev. 2 controls built-in. Findings in OpenFISMA can be matched against these security controls to provide supplemental information for remediation and planning. The catalog includes descriptions of the controls, scoping, and supplemental guidance.</li>
</ul>
<p>You can download OpenFISMA here:</p>
<p><a href="http://openfisma.org/content/downloads-0">OpenFISMA</a> (registration required)</p>
<p>Or read more <a href="http://openfisma.org/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=OpenFISMA+%E2%80%93+FISMA+Compliance+%26+Risk+Management+Application+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2788+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/08/openfisma-fisma-compliance-risk-management-application/&amp;t=OpenFISMA+%E2%80%93+FISMA+Compliance+%26+Risk+Management+Application" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/08/openfisma-fisma-compliance-risk-management-application/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/08/openfisma-fisma-compliance-risk-management-application/&amp;title=OpenFISMA+%E2%80%93+FISMA+Compliance+%26+Risk+Management+Application" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/08/openfisma-fisma-compliance-risk-management-application/&amp;title=OpenFISMA+%E2%80%93+FISMA+Compliance+%26+Risk+Management+Application" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/08/openfisma-fisma-compliance-risk-management-application/&amp;title=OpenFISMA+%E2%80%93+FISMA+Compliance+%26+Risk+Management+Application" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/08/openfisma-fisma-compliance-risk-management-application/&amp;title=OpenFISMA+%E2%80%93+FISMA+Compliance+%26+Risk+Management+Application" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F08%2Fopenfisma-fisma-compliance-risk-management-application%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/08/openfisma-fisma-compliance-risk-management-application/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Homeland Security Scores an F for Internal Security AGAIN</title>
		<link>http://www.darknet.org.uk/2006/04/homeland-security-scores-an-f-for-internal-security-again/</link>
		<comments>http://www.darknet.org.uk/2006/04/homeland-security-scores-an-f-for-internal-security-again/#comments</comments>
		<pubDate>Mon, 10 Apr 2006 00:17:29 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General News]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[f-grade]]></category>
		<category><![CDATA[failing]]></category>
		<category><![CDATA[federal-information-security-management-act]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[homeland]]></category>
		<category><![CDATA[homeland-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/04/homeland-security-scores-an-f-for-internal-security-again/</guid>
		<description><![CDATA[Well I would have thought these guys should have had a little better security.. The Department of Homeland Security received an F (Failing) grade in cybersecurity from the House Government Reform Committee for the third year in a row. The Committee will likely give the Fed a D+ overall for its cybersecurity efforts. The grades [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Well I would have thought these guys should have had a little better security..</p>
<blockquote><p>The Department of Homeland Security received an F (Failing) grade in cybersecurity from the House Government Reform Committee for the third year in a row. The Committee will likely give the Fed a D+ overall for its cybersecurity efforts. The grades will be unveiled today during a Committee oversight hearing, &#8220;Is the Government Ready for a Digital Pearl Harbor?&#8221; The grades are based on how well the comply with standards defined by the Federal Information Security Management Act (FISMA)</p></blockquote>
<p><img src="http://static.flickr.com/49/125399527_e4c93cb85d.jpg?v=0" alt="Homeland Scores an F" /></p>
<p>Better hope the cyber warfare cells from &#8216;enemy countries&#8217; don&#8217;t notice this eh?</p>
<p></p>
<p>Source: <a href="http://blogs.zdnet.com/BTL/?p=2723">Zdnet Blogs</a> &#8211; <a href="http://www.washingtonpost.com/wp-srv/business/documents/fismachart.html">Full Chart</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Homeland+Security+Scores+an+F+for+Internal+Security+AGAIN+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D123+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/04/homeland-security-scores-an-f-for-internal-security-again/&amp;t=Homeland+Security+Scores+an+F+for+Internal+Security+AGAIN" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/04/homeland-security-scores-an-f-for-internal-security-again/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/04/homeland-security-scores-an-f-for-internal-security-again/&amp;title=Homeland+Security+Scores+an+F+for+Internal+Security+AGAIN" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/04/homeland-security-scores-an-f-for-internal-security-again/&amp;title=Homeland+Security+Scores+an+F+for+Internal+Security+AGAIN" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/04/homeland-security-scores-an-f-for-internal-security-again/&amp;title=Homeland+Security+Scores+an+F+for+Internal+Security+AGAIN" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/04/homeland-security-scores-an-f-for-internal-security-again/&amp;title=Homeland+Security+Scores+an+F+for+Internal+Security+AGAIN" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F04%2Fhomeland-security-scores-an-f-for-internal-security-again%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/04/homeland-security-scores-an-f-for-internal-security-again/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

