Congressional breach: balancing security with convenience

Whether or not you believe, as some pundits appear to, that the call for an inquiry into cybersecurity practices in the House of Representatives after the details of an ethics committee inquiry were disclosed is a…

Is de-identification of personal records possible?

Last month Harvard Magazine ran a fantastic article on privacy in the current era, focusing in particular on the work of researcher Latanya Sweeney, who has demonstrated a somewhat alarming ability take personal data that has…

Stiffer U.K. penalties coming for personal data misuse

The British Ministry of Justice recently published proposed new penalties for knowingly misusing personal data in violation of section 55 of the Data Protection Act. The proposals raise the maximum penalty to include jail time, in…

Security issues at NASA highlight challenges in control effectiveness

A report released this month by GAO on what it views as deficiencies in the information security program and security control effectiveness at the National Aeronautics and Space Administration (NASA) serves to highlight once again the…

Need a little more verify to go with that trust

One notable aspect of the widely-reported launch of a Security Metrics Taskforce charged with coming up with new, outcome-based standards for measuring the effectiveness of federal agency information security efforts is a statement written by federal…

Government security looks to address outcomes

In an development that should come as a welcome surprise to security watchers critical of U.S. federal information security efforts as too focused on compliance (at the expense of effectiveness), the Federal CIO Council announced last…

Contributions to CSI Alert on Claims-Based Identity Management

The September issue of the Computer Security Institute Alert focuses on claims-based identity, and includes articles by CSI Alert Editor Sara Peters, policy expert Charles Cresson Wood, “Privacy Professor” Rebecca Herold, and SecurityArchitecture.com’s own Stephen Gantz….