<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.fiercecio.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>information security</title>
 <link>http://www.fiercecio.com/tags/information-security</link>
 <description></description>
 <language>en</language>
<item>
 <title>More than 300 federal IT jobs up for grabs</title>
 <link>http://www.fiercecio.com/story/more-300-federal-it-jobs-grabs/2008-11-19?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FC0</link>
 <description>&lt;p&gt;President-elect Barack Obama proposed a major IT agenda during his campaign, and this will require many new skilled federal hires, as well as new technology projects and investments. The Plum Book, which lists presidential appointments within the federal government, includes more than 300 technology positions. Topping the list are 21 chief information officers, four chief technology officer positions and four positions dealing with information security. &lt;br /&gt;&lt;br /&gt;The Defense Department listed the most available technology jobs, with nearly 50 openings. Down the road, federal job prospects for IT professionals may be even greater as a large number of Baby Boomer federal workers reach retirement age and leave the government.&lt;/p&gt;
&lt;p&gt;For more tips on the job hut:&lt;br /&gt;- check out this &lt;em&gt;nextgov.com&lt;/em&gt; &lt;a title=&quot;More than 300 federal IT jobs up for grabs&quot; href=&quot;http://www.nextgov.com/nextgov/ng_20081117_9463.php&quot;&gt;article&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related Articles:&lt;br /&gt;&lt;/strong&gt;&lt;a href=&quot;http://www.fiercecio.com/story/tech-companies-may-be-winners-obama-presidency/2008-11-19&quot;&gt;Tech companies may be winners in Obama presidency&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercecontentmanagement.com/story/obamas-victory-proves-power-web-2-0/2008-11-12&quot;&gt;Obama&#039;s victory proves the power of Web 2.0&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercecio.com/tags/barack-obama&quot;&gt;Barack Obama news from &lt;em&gt;FierceCIO&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercecio.com/story/more-300-federal-it-jobs-grabs/2008-11-19#comments</comments>
 <category domain="http://www.fiercecio.com/tags/baby-boomer">baby boomer</category>
 <category domain="http://www.fiercecio.com/tags/barack-obama">Barack Obama</category>
 <category domain="http://www.fiercecio.com/tags/chief-technology-officer">chief technology officer</category>
 <category domain="http://www.fiercecio.com/tags/information-security">information security</category>
 <category domain="http://www.fiercecio.com/tags/technology-jobs">Technology Jobs</category>
 <category domain="http://www.fiercecio.com/tags/lawmakers">U.S. Federal Government</category>
 <pubDate>Wed, 19 Nov 2008 11:15:10 -0500</pubDate>
 <dc:creator>Judi Hasson</dc:creator>
 <guid isPermaLink="false">65654 at http://www.fiercecio.com</guid>
</item>
<item>
 <title>Next president must deal with information security</title>
 <link>http://www.fiercecio.com/story/nezt-president-must-deal-info-security/2008-10-17-0?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FC0</link>
 <description>&lt;p&gt;The next president and the new Congress will have&amp;nbsp;a lot&amp;nbsp;on their plate, including an obligation to move forward on a strategic plan for IT and information security, according to Jon Oltsik, a senior analyst at the Enterprise Strategy Group, in an article for&amp;nbsp;&lt;em&gt;CNET.com&lt;/em&gt;.&amp;nbsp;He says the government is treading water on a number of highly-visible, strategic initiatives like the&amp;nbsp;underfunded Comprehensive National Cyber Security Initiative, which&amp;nbsp;is intended to standardize information security practices and oversee critical information security infrastructure across all federal agencies.&lt;/p&gt;
&lt;p&gt;Also on Oltsik&#039;s list of problems is the implementation of the 2002 Federal Information Security Management Act, which&amp;nbsp;was supposed to provide guidelines and requirements for federal agencies.&amp;nbsp;Many agencies have apparently failed to comply with the law. Finally, there is the failure of Congress to pass a strong national information privacy act and to standardize identity technologies for federal workers and contractors.&lt;/p&gt;
&lt;p&gt;Oltsik said the federal government faces&amp;nbsp;&quot;increasingly dangerous information security threats&#039;&#039; that cannot be ignored. Regardless of who becomes our next president, Oltsik said, he will&amp;nbsp;&quot;judge progress in Washington by the government&#039;s ability to pass and fund legislation, meet regulatory compliance mandates, improve information security, and strive for constant improvement.&#039;&#039;&lt;/p&gt;
&lt;p&gt;For more on challenges for the next president:&lt;br /&gt;- check out this&lt;em&gt; CNET.com&lt;/em&gt; &lt;a title=&quot;Next president must deal with info security&quot; href=&quot;http://news.cnet.com/8301-1009_3-10068782-83.html?part=rss&amp;amp;subj=news&amp;amp;tag=2547-1_3-0-5&quot;&gt;article&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related Article:&lt;br /&gt;&lt;/strong&gt;&lt;a href=&quot;http://www.fiercecio.com/story/government-private-it-address-cyber-threats/2008-09-17&quot;&gt;Government, private IT address cyber threats&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercecio.com/story/nezt-president-must-deal-info-security/2008-10-17-0#comments</comments>
 <category domain="http://www.fiercecio.com/tags/cybersecurity">Cybersecurity</category>
 <category domain="http://www.fiercecio.com/tags/information-security">information security</category>
 <category domain="http://www.fiercecio.com/tags/information-security-infrastructure">Information Security Infrastructure</category>
 <category domain="http://www.fiercecio.com/tags/president">President</category>
 <category domain="http://www.fiercecio.com/tags/security-practices">security practices</category>
 <category domain="http://www.fiercecio.com/tags/lawmakers">U.S. Federal Government</category>
 <pubDate>Fri, 17 Oct 2008 16:38:38 -0400</pubDate>
 <dc:creator>Judi Hasson</dc:creator>
 <guid isPermaLink="false">65383 at http://www.fiercecio.com</guid>
</item>
<item>
 <title>Warning: Spam posing as CNN.com infects millions of PCs</title>
 <link>http://www.fiercecio.com/story/warning-spam-posing-cnn-com-infects-millions-pcs/2008-08-10?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FC0</link>
 <description>&lt;p&gt;There has been a major ongoing spam attack that has tricked users into clicking a fake message from a &lt;em&gt;CNN.com&lt;/em&gt; Top 10 list. MX Logic, a Colorado security vendor, said the Top 10 list peaked at close to 11 million messages per hour one day last week, and has shown no signs of subsiding.&lt;/p&gt;
&lt;p&gt;In fact, Sam Masiello, MX Logic&#039;s vice president of information security,&amp;nbsp;told &lt;em&gt;Computerworld&lt;/em&gt; that the attacks have morphed to include subject headings such &quot;CNN Alerts: My Custom Alert&quot; and have used a variety of file names in the malicious URL. Users who click on the links and download a bogus Flash update have been trapped in an endless loop of pop-ups. The only options for users then has been shut down their browser or and install malware.&lt;/p&gt;
&lt;p&gt;For more on this threat:&lt;br /&gt;- see this &lt;em&gt;Computerworld.com&lt;/em&gt; &lt;a title=&quot;Warning: Spam posing as CNN.com infects millions of PCs&quot; href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9112138&amp;amp;intsrc=hm_list&quot;&gt;article&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercecio.com/story/warning-spam-posing-cnn-com-infects-millions-pcs/2008-08-10#comments</comments>
 <category domain="http://www.fiercecio.com/tags/cnn">CNN</category>
 <category domain="http://www.fiercecio.com/tags/information-security">information security</category>
 <category domain="http://www.fiercecio.com/tags/malware">Malware</category>
 <category domain="http://www.fiercecio.com/tags/mx-logic">MX Logic</category>
 <category domain="http://www.fiercecio.com/tags/sam-masiello">Sam Masiello</category>
 <category domain="http://www.fiercecio.com/tags/spam-attack-0">Spam Attack</category>
 <category domain="http://www.fiercecio.com/tags/subject-headings">Subject Headings</category>
 <pubDate>Sun, 10 Aug 2008 14:52:58 -0400</pubDate>
 <dc:creator>Judi Hasson</dc:creator>
 <guid isPermaLink="false">64848 at http://www.fiercecio.com</guid>
</item>
<item>
 <title>Microsoft to share more security information</title>
 <link>http://www.fiercecio.com/story/microsoft-share-more-security-information/2008-08-06?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FC0</link>
 <description>&lt;p&gt;Facing countless and unending security issues, Microsoft this week announced a new initiative to help IT administrators evaluate vulnerabilities in the company&#039;s software and to share that information with other security vendors.&lt;/p&gt;
&lt;p&gt;The Microsoft Exploitability Index, as it is known, is aimed at helping business professionals prioritize patching. But &lt;em&gt;Informationweek.com&lt;/em&gt; notes that it is really an attempt to deal with an unfortunate problem: &quot;Microsoft issues a Security Bulletin and cybercriminals answer with code designed to exploit the newly disclosed vulnerabilities.&#039;&#039;&lt;/p&gt;
&lt;p&gt;Under the new plan starting in October, Microsoft will rate the likelihood that vulnerabilities will be exploited based on three designations: Consistent Exploit Code Likely, Inconsistent Exploit Code Likely, and Functioning Exploit Code Unlikely. Whether this will help remains to be seen. Some experts said it all depends on the accuracy of the information provided by Microsoft.&lt;/p&gt;
&lt;p&gt;For more on Microsoft:&lt;br /&gt;&amp;nbsp;- see this &lt;em&gt;informationweek.com&lt;/em&gt; &lt;a title=&quot;Microsoft to share more security information&quot; href=&quot;http://www.informationweek.com/news/security/management/showArticle.jhtm&quot;&gt;article&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercecio.com/story/microsoft-share-more-security-information/2008-08-06#comments</comments>
 <category domain="http://www.fiercecio.com/tags/information-security">information security</category>
 <category domain="http://www.fiercecio.com/channel/it-security">IT Security</category>
 <category domain="http://www.fiercecio.com/tags/microsoft">Microsoft</category>
 <pubDate>Wed, 06 Aug 2008 22:14:24 -0400</pubDate>
 <dc:creator>Judi Hasson</dc:creator>
 <guid isPermaLink="false">64829 at http://www.fiercecio.com</guid>
</item>
<item>
 <title>Gartner: Seven cloud-commuting security risks</title>
 <link>http://www.fiercecio.com/story/gartner-seven-cloud-commuting-security-risks/2008-07-05?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FC0</link>
 <description>&lt;p&gt;Cloud computing may be the wave of the future, but one cannot ignore dangers involving data integrity, recovery, privacy and regulatory compliance. Gartner, in a new report entitled, &quot;Assessing the Security Risks of Cloud Computing,&quot; cautions that users of cloud computing must ask tough questions and consider getting a security assessment from a neutral third party before committing to a cloud vendor.&lt;/p&gt;
&lt;p&gt;Gartner says customers should avoid vendors that do not provide detailed information on security programs or make available the qualifications of policy makers, architects, coders and operators. The Gartner report also outlined seven specific security issues that should always be be raised with the cloud vendor. They include: knowing whether there is privileged user access to sensitive data and what kinds of controls are in place; whether the cloud computing provider undertakes external audits and security certifications; knowing where your data is hosted; and confirming that they will make a contractual commitment to obey local privacy requirements on behalf of their customers.&lt;/p&gt;
&lt;p&gt;For more advice:&lt;br /&gt;&amp;nbsp;- See this &lt;em&gt;networkworld.com&lt;/em&gt; &lt;a title=&quot;Gartner: Seven cloud-commuting security risks&quot; href=&quot;http://www.networkworld.com/news/2008/070208-cloud.html?hpg1=bn&quot;&gt;article&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;More tech stories from the &lt;em&gt;FierceCIO&lt;/em&gt; network:&lt;/strong&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&amp;gt; Hackers hijack Internet organizations. &lt;a href=&quot;http://www.fiercecio.com/story/hackers-hijack-internet-organizations/2008-07-01&quot;&gt;Article&lt;/a&gt;&lt;br /&gt;&amp;gt; Microsoft stops offering boxed Window XP. &lt;a href=&quot;http://www.fiercecio.com/story/microsoft-stops-offering-boxed-windows-xp/2008-07-01&quot;&gt;Article&lt;/a&gt;&lt;br /&gt;&amp;gt; New hands-free cell phone law takes effect in California. &lt;a href=&quot;http://www.fiercemobileit.com/story/new-hands-free-cell-phone-law-takes-effect-california/2008-07-02&quot;&gt;Article&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercecio.com/story/gartner-seven-cloud-commuting-security-risks/2008-07-05#comments</comments>
 <category domain="http://www.fiercecio.com/tags/gartner-report">Gartner Report</category>
 <category domain="http://www.fiercecio.com/tags/information-security">information security</category>
 <category domain="http://www.fiercecio.com/channel/it-security">IT Security</category>
 <category domain="http://www.fiercecio.com/tags/sensitive-data">sensitive data</category>
 <pubDate>Sat, 05 Jul 2008 23:20:34 -0400</pubDate>
 <dc:creator>Judi Hasson</dc:creator>
 <guid isPermaLink="false">64603 at http://www.fiercecio.com</guid>
</item>
<item>
 <title>Watch out for your IT security scorecard</title>
 <link>http://www.fiercecio.com/story/watch-out-for-your-it-security-scorecard/2008-03-06?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FC0</link>
 <description>
&lt;P&gt;A quarterly review of a company&#039;s information security is essential for top IT personnel trying to ensure their systems are airtight. While it&#039;s important for the IT department not to get lost in trivial details, it&#039;s key to recognize the company&#039;s vulnerability. And that means sharing the results of the information security scorecard with the IT team and moving quickly to seal any security holes. For most CIOs, it&#039;s essential to know about viruses and a system&#039;s susceptibility to an attack.&amp;nbsp;&lt;/p&gt;
&lt;P&gt;For more on the importance of the scorecard:&lt;BR /&gt;- see this &lt;EM&gt;ComputerWorld &lt;/em&gt;&lt;A href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyId=17&amp;articleId=313218&amp;intsrc=hm_topic&quot;&gt;article&lt;/a&gt;&lt;/p&gt;

</description>
 <comments>http://www.fiercecio.com/story/watch-out-for-your-it-security-scorecard/2008-03-06#comments</comments>
 <category domain="http://www.fiercecio.com/tags/business-operations">Business Operations</category>
 <category domain="http://www.fiercecio.com/tags/bpm">Business Process Management (BPM)</category>
 <category domain="http://www.fiercecio.com/tags/c-level">C-Level</category>
 <category domain="http://www.fiercecio.com/tags/information-security">information security</category>
 <category domain="http://www.fiercecio.com/channel/it-security">IT Security</category>
 <category domain="http://www.fiercecio.com/tags/security-holes">security holes</category>
 <category domain="http://www.fiercecio.com/tags/viruses">Viruses</category>
 <category domain="http://www.fiercecio.com/tags/vulnerability">Vulnerability</category>
 <pubDate>Thu, 06 Mar 2008 06:59:58 -0500</pubDate>
 <dc:creator />
 <guid isPermaLink="false">32775 at http://www.fiercecio.com</guid>
</item>
<item>
 <title>Bluetooth security still a challenge</title>
 <link>http://www.fiercecio.com/story/bluetooth-security-still-challenge/2007-09-24?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FC0</link>
 <description>
&lt;P&gt;Bluetooth offers a tremendous opportunity for mobile users, but Ooi Szu-Khiam, senior security consultant at Symantec, says that security is still a big issue. Indeed, research firm InsightExpress revealed that 73 percent of mobile device users are not aware of security issues that could put mobile devices such as cell phones and Bluetooth-equipped notebooks at risk. &quot;There are many other methods that (launch) a variety of denial-of-service attacks, and even some that could allow an attack to eavesdrop on private conversations,&quot; Szu-Khiam told &lt;EM&gt;Cnet&lt;/em&gt;. &amp;nbsp;He also noted that &quot;numerous instances of mobile viruses, worms and Trojan horses&quot; have occurred in the last year. Some of the terms used to describe these security vulnerabilities: bluejacking, bluespamming and bluebugging.&lt;/p&gt;
&lt;P&gt;For more information on Bluetooth security:&lt;BR /&gt;- see the &lt;A href=&quot;http://www.news.com/Symantec-warns-users-over-Bluetooth-security/2100-1029_3-6209361.html?tag=cd.lede&quot;&gt;article&lt;/a&gt; in &lt;EM&gt;Cnet&lt;/em&gt;&lt;/p&gt;

</description>
 <comments>http://www.fiercecio.com/story/bluetooth-security-still-challenge/2007-09-24#comments</comments>
 <category domain="http://www.fiercecio.com/tags/cell-phones">cell phones</category>
 <category domain="http://www.fiercecio.com/tags/data-protection">Data Protection</category>
 <category domain="http://www.fiercecio.com/tags/data-security">Data Security</category>
 <category domain="http://www.fiercecio.com/tags/denial-service">denial of service</category>
 <category domain="http://www.fiercecio.com/tags/denial-service-attacks">denial of service attacks</category>
 <category domain="http://www.fiercecio.com/tags/information-security">information security</category>
 <category domain="http://www.fiercecio.com/tags/notebooks">notebooks</category>
 <category domain="http://www.fiercecio.com/tags/protective-measures">Security</category>
 <category domain="http://www.fiercecio.com/tags/symantec">Symantec</category>
 <category domain="http://www.fiercecio.com/tags/trojan-attacks">Trojan horses</category>
 <category domain="http://www.fiercecio.com/channel/it-wireless">Wireless</category>
 <pubDate>Mon, 24 Sep 2007 06:59:58 -0400</pubDate>
 <dc:creator />
 <guid isPermaLink="false">4359 at http://www.fiercecio.com</guid>
</item>
<item>
 <title>CIOs and CSOs: Why can&#039;t they get along?</title>
 <link>http://www.fiercecio.com/story/cios-and-csos-why-cant-they-get-along/2007-09-17?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FC0</link>
 <description>
&lt;P&gt;CIOs and CSOs don&#039;t always see eye to eye. That, at least, was the message last week in Chicago at The Security Standard conference. Geir Ramleth, senior vice president and CIO at Bechtel and Andy Ellis, senior director of information security and chief security architect with Akamai, took the stage to discuss priorities of the two disciplines: as it turns out, they do not always match up. Ellis contends that CIOs should be more forthcoming with their technology plans and should consult CSOs in advance. Security professionals shouldn&#039;t be put in the position of always having to retrofit security, he said. Meanwhile, Ramleth said that security professionals are not always open to suggestions from IT. &quot;Security people have this phrase, &#039;yes, but&amp;#8230;&#039;&quot; he said, explaining that the phrase generally translates as: &quot;I agree with you, but I don&#039;t agree with you, and therefore I&#039;m going to mess you up,&quot; he said. Fixing the problem has a lot to do with communication, both execs agree. Having more information about the business drivers behind technology decisions would help CSOs understand strategic priorities. &lt;/p&gt;
&lt;P&gt;For more information:&lt;BR /&gt;- see the &lt;A href=&quot;http://www.networkworld.com/news/2007/091207-security-standard-cio-cso.html&quot;&gt;article&lt;/a&gt; in &lt;EM&gt;NetworkWorld&lt;/em&gt;&lt;/p&gt;

</description>
 <comments>http://www.fiercecio.com/story/cios-and-csos-why-cant-they-get-along/2007-09-17#comments</comments>
 <category domain="http://www.fiercecio.com/tags/business-strategy">Business Strategy</category>
 <category domain="http://www.fiercecio.com/tags/cso">CSO</category>
 <category domain="http://www.fiercecio.com/tags/csos">csos</category>
 <category domain="http://www.fiercecio.com/tags/information-security">information security</category>
 <category domain="http://www.fiercecio.com/channel/it-management-leadership">Management/ Leadership</category>
 <pubDate>Mon, 17 Sep 2007 06:59:59 -0400</pubDate>
 <dc:creator />
 <guid isPermaLink="false">4332 at http://www.fiercecio.com</guid>
</item>
<item>
 <title>SaaS-based security gets some buzz</title>
 <link>http://www.fiercecio.com/story/saas-based-security-gets-some-buzz/2007-08-23?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FC0</link>
 <description>
&lt;P&gt;Executives are learning that security technologies delivered via the SaaS (software-as-a-service) business model are proving to be a big success. Imperial Chemical Industries--a London-based maker of paints and chemicals, which is in the process of being acquired by industrial conglomerate Akzo Nobel for $16 billion--is engaged In a focused effort to secure its assets and data. The company is using SaaS applications--like vulnerability scanning tools, email and spam filtering and Web filtering. &quot;We&#039;re pushing the envelope in terms of what&#039;s out there with security SaaS, but so far, it&#039;s been a fantastic success,&quot; Paul Simmonds, global information security director at ICI, told &lt;EM&gt;Infoworld&lt;/em&gt;. Still, he says that not all security applications should be offered using a SaaS model, including security tools like NAC systems and endpoint-oriented products. &lt;/p&gt;
&lt;P&gt;For more on delivering security tech through SaaS:&lt;BR /&gt;- read the &lt;A href=&quot;http://www.infoworld.com/article/07/08/22/Security-SaaS-maturing-fast_1.html&quot;&gt;article&lt;/a&gt; in &lt;EM&gt;Infoworld&lt;/em&gt;&lt;/p&gt;

</description>
 <comments>http://www.fiercecio.com/story/saas-based-security-gets-some-buzz/2007-08-23#comments</comments>
 <category domain="http://www.fiercecio.com/tags/business-model">business model</category>
 <category domain="http://www.fiercecio.com/tags/information-security">information security</category>
 <category domain="http://www.fiercecio.com/tags/open-source">Open-Source</category>
 <category domain="http://www.fiercecio.com/channel/it-outsourcing">Outsourcing</category>
 <category domain="http://www.fiercecio.com/tags/saas">saas</category>
 <category domain="http://www.fiercecio.com/tags/security-applications">security applications</category>
 <category domain="http://www.fiercecio.com/tags/security-breaches">Security Breaches</category>
 <category domain="http://www.fiercecio.com/tags/security-technologies">security technologies</category>
 <category domain="http://www.fiercecio.com/tags/security-tools">security tools</category>
 <category domain="http://www.fiercecio.com/tags/soa">SOA</category>
 <pubDate>Thu, 23 Aug 2007 06:59:58 -0400</pubDate>
 <dc:creator />
 <guid isPermaLink="false">4251 at http://www.fiercecio.com</guid>
</item>
<item>
 <title>Department of Homeland Security CIO comes under fire</title>
 <link>http://www.fiercecio.com/story/department-of-homeland-security-cio-comes-under-fire/2007-06-21?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FC0</link>
 <description>&lt;P&gt;Department of Homeland Security, CIO Scott Charbo, has not been setting a good example and hasn&#039;t shown he&#039;s serious about fixing his departments vulnerabilities. That, at least, is the position of Bennie Thompson (D-Miss.), chairman of the House of Representatives Homeland Security Committee, who says the agency has experienced a continuous flow of cybersecurity flaws under the CIO&#039;s tenure. &quot;How can we ask the private sector to better train employees and implement more consistent access controls when DHS allows employees to send classified emails over unclassified networks and contractors to attach unapproved laptops to the network?&quot; He was referring to the Homeland Security department&#039;s revelation, as part of an ongoing subcommittee probe into its information security practices, that it experienced 844 security-related &quot;incidents&quot; on its computer systems in 2005 and 2006. Charbo, downplayed the list and said that line items didn&#039;t indicate actual penetrations of the system and that they varied widely in the level of severity. &amp;nbsp;&lt;BR&gt;&lt;BR&gt;For all the coverage on Capitol Hill:&lt;BR&gt;- read this &lt;EM&gt;CNET&lt;/EM&gt; &lt;A href=&quot;http://news.com.com/Homeland+Security+IT+chief+blamed+for+cyberwoes/2100-7348_3-6192255.html?tag=cd.lede&quot;&gt;article&lt;/A&gt;&lt;/P&gt;

</description>
 <comments>http://www.fiercecio.com/story/department-of-homeland-security-cio-comes-under-fire/2007-06-21#comments</comments>
 <category domain="http://www.fiercecio.com/tags/access-controls">access controls</category>
 <category domain="http://www.fiercecio.com/tags/capitol-hill">capitol hill</category>
 <category domain="http://www.fiercecio.com/tags/cybersecurity">Cybersecurity</category>
 <category domain="http://www.fiercecio.com/tags/department-homeland-security">Department of Homeland Security</category>
 <category domain="http://www.fiercecio.com/tags/dhs">dhs</category>
 <category domain="http://www.fiercecio.com/tags/information-security">information security</category>
 <category domain="http://www.fiercecio.com/channel/it-security">IT Security</category>
 <category domain="http://www.fiercecio.com/tags/security-practices">security practices</category>
 <pubDate>Wed, 20 Jun 2007 20:01:39 -0400</pubDate>
 <dc:creator />
 <guid isPermaLink="false">4017 at http://www.fiercecio.com</guid>
</item>
</channel>
</rss>
