<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>elamb &#187; FDCC</title>
	<atom:link href="http://elamb.org/category/fdcc/feed/" rel="self" type="application/rss+xml" />
	<link>http://elamb.org</link>
	<description>information system security, risk management, scam research</description>
	<lastBuildDate>Mon, 28 Nov 2011 02:27:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Certification &amp; Accreditation Change</title>
		<link>http://elamb.org/certification-accreditation-change/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=certification-accreditation-change</link>
		<comments>http://elamb.org/certification-accreditation-change/#comments</comments>
		<pubDate>Wed, 27 Aug 2008 00:55:54 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[FDCC]]></category>
		<category><![CDATA[federal]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[System security engineering]]></category>
		<category><![CDATA[CA]]></category>
		<category><![CDATA[Committee on National Security Systems]]></category>
		<category><![CDATA[DIACAP]]></category>
		<category><![CDATA[dod]]></category>
		<category><![CDATA[IA]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[nist 800]]></category>

	<!-- AutoMeta Start -->
	<category>metafile</category>
	<category>picture</category>
	<category>intelligence</category>
	<category>accreditation</category>
	<category>cnss</category>
	<category>cnssâ ™</category>
	<category>ehlers</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/certification-accreditation-change/</guid>
		<description><![CDATA[Standard-issue security Certification and accreditation process for national security systems to extend to the rest of government. A two-year-old effort to standardize processes for certifying and accrediting government IT systems could soon bear fruit, according to officials from several agencies. &#8230; <a href="http://elamb.org/certification-accreditation-change/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>Standard-issue security</strong><br />
Certification and accreditation process for national security systems to extend to the rest of government.  A two-year-old effort to standardize processes for certifying and accrediting government IT systems could soon bear fruit, according to officials from several agencies.</p>
<p>The <strong>Committee on National Security Systems</strong> is preparing instructions for implementing a unified certification and accreditation (C&#038;A) process that could be used on all national security systems, including those in the Defense Department and intelligence community, said Tony Cornish, chairman of the CNSSâ€™ C&#038;A working group.</p>
<p>At the same time, the National Institute of Standards and Technology plans to update its C&#038;A guidance for systems covered by the <strong>Federal Information Security Management Act</strong>, said Ron Ross, a senior computer scientist and FISMA implementation lead at NIST.</p>
<p>â€œWe are very close to producing a unified C&#038;A process for the entire federal government,â€ Ross said in July at a government security symposium hosted by Symantec. â€œWithin the next six to eight months, you are going to see a plethora of new things coming outâ€ from CNSS and NIST.</p>
<p>CNSSâ€™ instructions will be incorporated into NIST guidelines in its 800 series of special publications. Ross said a major update of SP 800-53 Rev. 2, â€œRecommended Security Controls for Federal Information Systems,â€ is expected in December, and a draft of the first revision of SP 800-37, â€œGuide for the Security Certification and Accreditation of Federal Information Systems,â€ is expected to be released for comment soon.</p>
<p>A single, governmentwide approach would make it easier for agencies to share data and cooperate with one another and with states, foreign allies and the private sector.</p>
<p>It could enable reciprocity, or the acceptance of other agenciesâ€™ C&#038;A processes, without requiring recertification, and also could streamline acquisition processes by making it easier for vendors and developers to meet one set of standards.</p>
<p>C&#038;A is a process for ensuring that IT systems are operating with an appropriate level of security. In the certification phase, the security of the system is documented; for accreditation, a designated authority signs off on the systemâ€™s fitness to go into operation. The concept has been around for some time, but there has been little standardization.</p>
<p>â€œIn the past, we each had our own set of policies, and we didnâ€™t look at each otherâ€™s,â€ said Sherrill Nicely, deputy associate director of national intelligence at the Office of the Director of National Intelligence.</p>
<p>FISMA requires C&#038;A of information technology systems, but that does not apply to national security systems. And within the national security community, the military and intelligence sectors each have had their own way of doing things.</p>
<p>â€œSince about 1993, the Defense Department had its program, the Defense IT Security Certification and Accreditation Process,â€ said Eustace King, DOD chief of acquisition and technology oversight. â€œIt worked pretty wellâ€ in a time before DODâ€™s emphasis on network- centric systems and information sharing, but it lacked enterprise visibility.</p>
<p>That C&#038;A program was replaced with the Defense Information Assurance Certification and Accreditation Process. DOD was moving to the program in 2006 to harmonize military and intelligence processes when, a year later, it was expanded to include the rest of the national security community by bringing in the CNSS.</p>
<p>Through NIST, C&#038;A procedures eventually will be standardized across all of government. However, policies do not change mind-sets, and old habits still remain one of the primary challenges to a standardized process. At DOD, there is a reluctance to accept reciprocity â€” that is, to give full credit to another agencyâ€™s C&#038;A process without recertification, King said.</p>
<p>The intelligence community faces a similar hurdle, said Sharon Ehlers, an assistant deputy associate director of national intelligence.</p>
<p>â€œThe cultural change has been the biggest challenge,â€ Ehlers said. â€œWhen it is not invented here, people donâ€™t want to look at it.â€</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/certification-accreditation-change/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Standard Desktop Configuration (SDC) News</title>
		<link>http://elamb.org/standard-desktop-configuration-sdc-news/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=standard-desktop-configuration-sdc-news</link>
		<comments>http://elamb.org/standard-desktop-configuration-sdc-news/#comments</comments>
		<pubDate>Mon, 16 Jul 2007 18:20:19 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[FDCC]]></category>
		<category><![CDATA[federal]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[SDC]]></category>

	<!-- AutoMeta Start -->
	<category>sdc</category>
	<category>gunter</category>
	<category>afecmo</category>
	<category>configuration</category>
	<category>desktop</category>
	<category>core</category>
	<category>standard</category>
	<category>mil</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/standard-desktop-configuration-sdc-news/</guid>
		<description><![CDATA[The Department of Defense has implemented the Standard Desktop Configuration (SDC)Â environment which allow all systemsÂ to have aÂ uniform level of security.Â  ALL SDC all the time: https://afecmo.gunter.af.mil/default.aspx Now the rest of the federal goverment is jumping on theÂ Information Assurance Bandwagon with &#8230; <a href="http://elamb.org/standard-desktop-configuration-sdc-news/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>The Department of Defense has implemented the Standard Desktop Configuration (SDC)Â environment which allow all systemsÂ to have aÂ uniform level of security.Â </p>
<p>ALL SDC all the time: <a href="https://afecmo.gunter.af.mil/default.aspx">https://afecmo.gunter.af.mil/default.aspx</a></p>
<p>Now the rest of the federal goverment is jumping on theÂ Information Assurance Bandwagon with something called the <a title="federal desktop core configuration" href="http://www.fcw.com/article97974-03-19-07-Web">Federal Desktop Core Configuration</a> (FDCC).</p>
<p>SDC version 2 (Vista) is already in the works as well as Standard Server Configuration (SCC).</p>
<p class="tags">Tags: <a href="http://technorati.com/tag/FDCC" title="See the Technorati tag page for 'FDCC'." rel="tag">FDCC</a>, <a href="http://technorati.com/tag/SDC" title="See the Technorati tag page for 'SDC'." rel="tag">SDC</a>, <a href="http://technorati.com/tag/ia" title="See the Technorati tag page for 'ia'." rel="tag">ia</a>, <a href="http://technorati.com/tag/federal" title="See the Technorati tag page for 'federal'." rel="tag">federal</a>, <a href="http://technorati.com/tag/" title="See the Technorati tag page for ''." rel="tag"></a></p>]]></content:encoded>
			<wfw:commentRss>http://elamb.org/standard-desktop-configuration-sdc-news/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

