Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 561
Alerts This Week
Warning Icon 1 561

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Are host-based firewalls still worth using?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/158-are-host-based-firewalls-still-worth-using?task=poll.vote&format=json
158
radio
0
[{"id":510,"title":"Yes \u2014 every server needs one.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":511,"title":"No \u2014 perimeter and cloud security are enough.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":512,"title":"Only Internet-facing systems really benefit.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":513,"title":"iptables.conf is my security policy.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -1 articles for you...
82

Innovative Practices Needed for Federal Cybersecurity Accountability

Granted, popular enterprise technology is nowhere as secure as it should be, but today's federal cybersecurity woes result more from flawed technology management practices than flawed technology. To that end, we need to foster and reward innovative, effective management processes in the federal computer security arena and terminate the current technology management and oversight philosophy that tolerates and rewards idleness and mediocrity while doing little to actually eliminate them. The standards for acceptable cybersecurity are known: it's time to start holding the people in charge accountable to them. . . .. Over the past several years, various Washington entities, from the General Accounting Office to assorted Congressional committees, conducted surveys and issued reports on the state of the federal government's information security posture. In each case, with few exceptions, the findings range from the scathing to the downright embarrassing, and remain essentially unchanged since the mid-1990s. Like any other issue involving government oversight, this process has become an annual Washington tradition - the reports are released; there's back-and-forth blather in Congress about how we need "to do more" to secure our federal networks; agency leaders and CIOs are called to testify on the Hill; some more blather, and perhaps a piece of legislation is introduced and dies before reaching the floor; and then the issue recedes into digital memory until next year's survey results are released -- and the process begins anew, with little or nothing really changing. It's no different than our annual visit to the dentist. We know he's going to admonish us to brush more and cut out the sweets, and we know that we're going to be embarrassed or uncomfortable as he tells us this to our face and makes notes in our patient file, but we endure it year after year, because it's something we have to do for good oral hygiene. Of course, we ignore his advice because it's inconvenient and, besides, candy is a tastier snack thancelery. This seems to be the approach taken by the majority of the federal government when dealing with the security of federal information systems. As you can see in the following articles going back to the late 1990s, there's much bad news and many prescriptions for improving things, but the patient refuses to cooperate....and the dentist is powerless (in this case, unwilling) to force him to change his ways. In some cases, these reports show marked improvements in specific offices or sub-agencies of the federal government, and those success stories should be made known both to the American people (as a sign that there are clueful security people making a difference in their agencies) and throughout the federal government as a helpful roadmap to improve security practices elsewhere. Unfortunately, these few truly noteworthy success stories are seldom reported by the mainstream press because good news doesn't pull in the ratings the way gloom, doom, and old-fashioned Washington finger-pointing does. Like the much-vaunted but ineffective "certification and accreditation" process required for government and military systems, these annual assessments are an exercise in bureaucratic idleness designed to "address" but not "resolve" security problems in any meaningful fashion. After several years, the logic seems to be "why fix the problem when talking about it keeps us (and our contractors) employed?" As a result, and contrary to popular belief and rhetoric, security for federal systems has been reduced to a check-box on our government's annual to-do list -- as long as federal enterprise leaders can prove that work is being done on the matter, that's perfectly acceptable, it seems, because in federal security circles, "activity" (e.g., certification and accreditation) has been confused with "progress" (e.g., actually fixing things) and "job security" has been confused with "effective security." Agency leaders confirming this with Congress each year generally can avoid anything stronger than a verbal reprimandabout their job performance, no matter how dismal security really is back home. The link for this article located at infowarrior.org is no longer available. . Over the past several years, various Washington entities, from the General Accounting Office to asso. granted, popular, enterprise, technology, nowhere, secure, should, today's, federal. . Anthony Pell

Calendar%202 Mar 23, 2004 User Avatar Anthony Pell Government
82

Howard Schmidt's Exit Sparks Concerns Over Federal Cybersecurity Focus

White House cybersecurity adviser Howard Schmidt will step down from his post at the end of the month. The move comes only two months after Richard Clarke resigned as special adviser to the president for cyberspace security, shortly after the release . . . . White House cybersecurity adviser Howard Schmidt will step down from his post at the end of the month. The move comes only two months after Richard Clarke resigned as special adviser to the president for cyberspace security, shortly after the release of the Bush administration's strategy to secure cyberspace. Security analysts and vendors worry that cybersecurity is less of a priority for the federal government and that there will be no single administration official focused on getting the private and public sectors working together to secure the nation's digital infrastructure. "It's a revolving door at the top," says Pete Lindstrom, research director at Spire Security. "Is that indicative of the lack of authority of the position?" The top cybersecurity official in the administration after Schmidt's expected departure will be Robert Liscouski. As assistant secretary of infrastructure protection at the Homeland Security Department, Liscouski has responsibility for securing both the country's physical and digital infrastructures. The link for this article located at InformationWeek is no longer available. . The departure of Jane Collins from the Pentagon introduces doubts regarding national defense initiatives.. Federal Cybersecurity,Cybersecurity Roles,Digital Threats. . Anthony Pell

Calendar%202 Apr 30, 2003 User Avatar Anthony Pell Government
82

Govnet Strategy: Clarke's Vision for Federal Cybersecurity Enhancement

Speaking before a conference of hundreds of federal technology personnel and industry officials Wednesday morning, Richard Clarke, President Bush's point man on national cybersecurity, outlined the next phase in the controversial plan to build an impenetrable information network for the federal government, known as Govnet. . . .. Speaking before a conference of hundreds of federal technology personnel and industry officials Wednesday morning, Richard Clarke, President Bush's point man on national cybersecurity, outlined the next phase in the controversial plan to build an impenetrable information network for the federal government, known as Govnet. Clarke said a team from the General Services Administration had completed a review of more than 167 responses from technology companies on how the network could be built, and that the reviewers had concluded that creating a stand-alone network, one not connected to the vulnerable systems of any other networks, is technologically feasible. Clarke added that some Defense Department and intelligence agencies, as well as some organizations in the Energy Department, already operate these kinds of solo networks today. The government can't afford to put off major upgrades to information security, Clarke said, noting that terrorists have continued to call upon their followers to attack the nation's critical infrastructure of power grids and information systems, many of which are connected to the Internet. The link for this article located at GovExec is no longer available. . Speaking before a conference of hundreds of federal technology personnel and industry officials Wedn. speaking, conference, hundreds, federal, technology, personnel, industry, officials. . Anthony Pell

Calendar%202 Apr 19, 2002 User Avatar Anthony Pell Government
74

Federal Cybersecurity Concerns: SANS Insights From Executives

The SANS Institute revealed Tuesday that the top computer security concerns of 56 federal executives and administrators are: systems being used to attack other agencies' systems; computers being taken off-line for weeks because of hacker-caused corruption; and hackers changing data on . . . . The SANS Institute revealed Tuesday that the top computer security concerns of 56 federal executives and administrators are: systems being used to attack other agencies' systems; computers being taken off-line for weeks because of hacker-caused corruption; and hackers changing data on websites to mislead the public, according to a study conducted by the security research and education organization. The study also found that the most difficult barriers to overcome in improving federal network security included lack of security skills in system and network administrators; inability to gain consensus or standards on which problems to fix first; and resistance to security initiatives. The link for this article located at TechWeb is no longer available. . Uncover leading safety challenges voiced by 56 government leaders, encompassing cyber intrusions and information reliability threats.. federal security concerns, network security issues, executive insights, SANS report, cybersecurity challenges. . Anthony Pell

Calendar%202 Sep 14, 2000 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Are host-based firewalls still worth using?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/158-are-host-based-firewalls-still-worth-using?task=poll.vote&format=json
158
radio
0
[{"id":510,"title":"Yes \u2014 every server needs one.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":511,"title":"No \u2014 perimeter and cloud security are enough.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":512,"title":"Only Internet-facing systems really benefit.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":513,"title":"iptables.conf is my security policy.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200