Operational security lessons from the Target breach

In the wake of revelations from major retailer Target that hackers compromised its point-of-sale systems and stole credit card information on tens of millions of its customers during a two-to-three week period in the busy holiday…

Two Amazon Web Services environments attain FedRAMP compliance

Last week, Amazon announced that it had received separate agency authorizations to operate (ATO) from the U.S. Department of Health and Human Services (HHS) for two of its Amazon Web Services cloud computing offerings, and that…

Weaknesses in Census Bureau security symptomatic of poor information security program

A news story in today’s Washington Post calls attention to a recent audit report from the Government Accountability Office, released last month, that identified numerous weaknesses in security controls at the U.S. Census Bureau that pose…

First cloud service provider authorized under FedRAMP

Just over a year after OMB formally announced the the Federal Risk and Authorization Management Program (FedRAMP), which relies on third-party assessments of cloud service providers seeking to offer their services to government agencies, the FedRAMP…

OMB outlines approach for cloud computing security

In the latest follow-up to “cloud first” policy advocated by federal CIO Vivek Kundra and the Federal Cloud Computing Strategy issued last February, OMB released new federal policy guidance directing agencies to use the requirements, security…

Privacy and Security Tiger Team recommends federal PKI cross-certification for all NwHIN participants

In the latest round of security recommendations for the Nationwide Health Information Network (NwHIN), the Privacy and Security Tiger Team (a workgroup of the federal Health IT Policy Committee that advises the National Coordinator for Health…

Mistaken assumptions about authorized users constrains the trustworthiness of information systems

The National Institute of Standards and Technology (NIST) released an updated guide to its Risk Management Framework (RMF) in December when it published the final public draft of Special Publication 800-39. Among several areas where the…