<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>FedScoop &#187; IT Security</title>
	<atom:link href="http://www.fedscoop.com/blog/tag/it-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.fedscoop.com/blog</link>
	<description>One Stop for All Your government Business News</description>
	<lastBuildDate>Tue, 31 Aug 2010 01:34:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Innovative IT Security Tools and Techniques at the Department of State</title>
		<link>http://www.fedscoop.com/blog/2009/02/05/innovative-it-security-tools-and-techniques-at-the-department-of-state/</link>
		<comments>http://www.fedscoop.com/blog/2009/02/05/innovative-it-security-tools-and-techniques-at-the-department-of-state/#comments</comments>
		<pubDate>Thu, 05 Feb 2009 18:00:42 +0000</pubDate>
		<dc:creator>Gary Galloway</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Department of State]]></category>
		<category><![CDATA[Gary Galloway]]></category>
		<category><![CDATA[IT Security]]></category>

		<guid isPermaLink="false">http://www.fedscoop.com/blog/?p=224</guid>
		<description><![CDATA[Gary Galloway is the Deputy Director of the Office of Information Assurance at the Department of State
  For those of you in the Federal IT community who are not  engaged in the area of IT security as your primary pursuit, I thought you might  be interested in hearing about some of the [...]]]></description>
			<content:encoded><![CDATA[<p><strong><em>Gary Galloway is the Deputy Director of the Office of Information Assurance at the Department of State</em></strong></p>
<p>  For those of you in the Federal IT community who are not  engaged in the area of IT security as your primary pursuit, I thought you might  be interested in hearing about some of the innovative tools and techniques that  we employ at the Department of State to secure our worldwide wide network.  This is the first of a series that will  hopefully inform and enlighten the IT Federal community, resulting in an  exchange of ideas. </p>
<p> In this fast-paced world of information technology, new  threats appear daily that result in volumes of lost personally identifiable  information and crimes including identity fraud.  To enable the Department’s mission of foreign  policy and diplomacy while protecting sensitive information, the Department’s  IT security professionals are working non-stop to prevent cyber attacks and  engage Department staff in actively thwarting efforts to hack systems.</p>
<p> Reporting directly to the Chief Information Officer at the  Department of State, the Information Resource Management Bureau’s Office of  Information Assurance (IRM/IA) has instituted several initiatives to  proactively address cyber security risk and assist IT professionals in managing  their bureau and post information system security.  These initiatives include the Site Risk  Scoring program, customer toolkits, and the Joint State-USAID Solution (JSAS) for  cyber security awareness training. </p>
<p><strong>Site  Risk Scoring</strong></p>
<p>  The initiative known as Site Risk Scoring is helping the  Department increase security awareness and reduce risk at sites connected to  our global network.  Site Risk Scoring  monitors system vulnerabilities and compliance settings to alert system  administrators as well as senior management of the risk associated with their  network site.  Notification of these  system weaknesses prompt immediate attention where the need and risk is  greatest.  Since program inception, risk  scores have steadily decreased across the Department by 50%. </p>
<p><strong>Customer  Toolkits</strong></p>
<p>  IRM/IA developed online toolkits to assist IT professionals  understand how best to complete IT security requirements designed to better  protect Department information. These toolkits are organized in an  easy-to-understand question-and-answer format, and are continually updated to  reflect new policies and procedures.  The  toolkits aim to create secure, cyber-savvy environments throughout Department  offices, thus making IT security more accessible, understandable, relevant, and  timely.<br />
  The topics covered by the toolkits include how to inventory  information systems; the process of Certification and Accreditation; tracking  and closing Plan of Action and Milestones; conducting Annual Control  Assessments, and Site Risk Scoring.</p>
<p><strong>JSAS –  Providing Cyber Security Awareness Training  </strong></p>
<p>  Selected by Office of Management and Budget as one of only  three providers for the Information Systems Security Line of Business (ISSLOB)  for information security awareness training, JSAS provides a joint State  Department and USAID solution for cyber security awareness training. JSAS  provides an automated, yearly cyber security awareness training course and a  recurring cyber security “Tip of the Day” program.<br />
  The annual cyber security awareness course provides  real-world scenarios that help users understand how best to apply information  security policies.  The course annually  tests users’ knowledge and understanding of policies and procedures to ensure  comprehension.</p>
<p> The “Tip of the Day” application provides a recurring  security reminder and can be implemented for all network users or specialized  groups of users.  Each time a user logs  in, a pop-up window opens with a security question that must be answered in  order to close the screen. Responses to the security questions are recorded  along with user IDs, so that managers can track progress.  Combining the data from the tip of the day  questions and annual security awareness course allows management to detect and  remediate weak spots in cyber security awareness.</p>
<p> Because technology changes daily and users need to be aware  of new security requirements when they arise, not months later, the Tips of the  Day tool provides the flexibility to insert tips on timely threats.  Site Risk Scoring, customer toolkits, and the  JSAS cyber security awareness training are all tools in the Department of  State’s effort to educate users and reduce risk. One of the Department of  State’s missions is to continually assess standards for improvement to protect  Department information while supporting Department business needs.</p>
<p>I am about to embark on a two-week TDY  assignment to Southern Africa to visit our missions and gain a better  understanding of overseas posts’ operating realities and mission.  During my visit to South   Africa, Swaziland,  Mozambique and Botswana I want  to better understand how we can serve our diplomats in securing the  Department’s information.  Look for my  reports from the field as I experience this wonderful journey!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fedscoop.com/blog/2009/02/05/innovative-it-security-tools-and-techniques-at-the-department-of-state/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
