tag:blogger.com,1999:blog-7652481.post3902967003034854046..comments2022-01-23T23:10:44.623-05:00Comments on Infosec Potpourri: Tired of all the talkDavidJBiancohttp://www.blogger.com/profile/09760835714791462863noreply@blogger.comBlogger3125tag:blogger.com,1999:blog-7652481.post-88135917847680919732007-07-04T11:22:00.000-04:002007-07-04T11:22:00.000-04:00The government does care, it's that how do you man...The government does care, it's that how do you manage a $68Billion IT budget and include security? It's hard to do, and all the naysayers for the most part have never tried to do it. There isn't any security management model that we have today that scales to that size.<BR/><BR/>I teach FISMA and C&A to contractors, vendors, and government employees and security in the government is a lot harder than you would think.<BR/><BR/>Anyway, I talk about this stuff all the time on my blog. Check it out: <A HREF="http://www.guerilla-ciso.com/" REL="nofollow">http://www.guerilla-ciso.com/</A>. For the really juicy stuff, hit the FISMA topic.rybolovhttps://www.blogger.com/profile/09022232218670789122noreply@blogger.comtag:blogger.com,1999:blog-7652481.post-37944664654794438052007-07-04T00:16:00.000-04:002007-07-04T00:16:00.000-04:00I disagree, in that I do think the government care...I disagree, in that I do think the government cares about cybersecurity. It's just that they don't seem to know how to <B>do</B> it, or even <B>what security actually means</B>. <BR/><BR/>Don't get me wrong: I recognize that there are significant challenges to be overcome here. Even at the level of individual Departments, the organizations are huge, and meaningful change is slow and painful. But even if the Departments <B>want</B> to change, it's pretty clear that they don't know how. <BR/><BR/>It comes down to the fact that cybersecurity is usually confused with compliance, reporting and other paperwork. All important pieces, to be sure, but they're fundamentally crippled without adequate people and resources.DavidJBiancohttps://www.blogger.com/profile/09760835714791462863noreply@blogger.comtag:blogger.com,1999:blog-7652481.post-11730727809496055272007-07-03T15:02:00.000-04:002007-07-03T15:02:00.000-04:00Persanally I do not think the Federal Government r...Persanally I do not think the Federal Government really cares about cybersecurity. You talk about the different agencies but each agency is broken up into dozens of separate fiefdoms. Each of these duplicate efforts which costs even more money taxpayer money.Unknownhttps://www.blogger.com/profile/04540029428151790839noreply@blogger.com