<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-8954966646386655038.comments</id><updated>2009-10-26T07:53:34.002-04:00</updated><category term='IT Security'/><category term='Government 2.0 Security'/><category term='SRF'/><category term='Web Application Security'/><category term='Web 2.0 Security'/><category term='Certification and Accreditation'/><category term='Security Requirements Framework'/><category term='SDLC Security'/><category term='Security Requirements'/><category term='FISMA'/><category term='Secure SDLC'/><category term='Security Resources'/><category term='Security Budget'/><category term='Security Innovation'/><category term='FISMA 2.0'/><category term='Web Application Security 2.0'/><category term='QA Security'/><category term='WAS 2.0'/><title type='text'>Jason Yuen - "Understanding Information Security"</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.jason-yuen.com/feeds/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/comments/default'/><link rel='alternate' type='text/html' href='http://www.jason-yuen.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Jason Yuen</name><uri>http://www.blogger.com/profile/01689037743235268269</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_aVbrSQzZtzw/SXCVKavNwmI/AAAAAAAAAts/ARE75ujHsoM/S220/untitled.JPG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>9</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8954966646386655038.post-8577131523496800734</id><published>2009-05-28T14:57:27.055-04:00</published><updated>2009-05-28T14:57:27.055-04:00</updated><title type='text'>I am a Sr. IT Security contractor for the USDA, an...</title><content type='html'>I am a Sr. IT Security contractor for the USDA, and we are an app dev shop. NIST guidance has largely been written as general guidance at the system level. It is very true that current NIST guidance lacks a security perspective at the application layer.  I am authoring and modeling a process and corresponding documentation similar to what you have indicated here; security tasks as they apply to each phase of the SDLC, including the RA and the C&amp;amp;A process.  &lt;br /&gt;&lt;br /&gt;One other large gap I see in my day-to-day work is lack of written policies or even basic methodology on application level data archival procedures and overall application decommissioning process and policies.&lt;br /&gt;&lt;br /&gt;I certainly have my work cut out for me, but change is coming. It&amp;#39;s a very huge, slow moving locomotive on this side of the wall.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/997520619345174114/comments/default/8577131523496800734'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/997520619345174114/comments/default/8577131523496800734'/><link rel='alternate' type='text/html' href='http://www.jason-yuen.com/2009/01/web-application-security-part-2-how-to.html?showComment=1243537047055#c8577131523496800734' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.jason-yuen.com/2009/01/web-application-security-part-2-how-to.html' ref='tag:blogger.com,1999:blog-8954966646386655038.post-997520619345174114' source='http://www.blogger.com/feeds/8954966646386655038/posts/default/997520619345174114' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1672000139'/></entry><entry><id>tag:blogger.com,1999:blog-8954966646386655038.post-8805534042399812526</id><published>2009-02-13T13:12:00.001-05:00</published><updated>2009-02-13T13:12:00.001-05:00</updated><title type='text'>Jason: As always, well said on a great topic. Anot...</title><content type='html'>Jason: As always, well said on a great topic. Another concern we have is the risk and attack factors associate with Web 2.0. Most of Web app security problems are instigated by user inputs. And the focus on RIA/Web 2.0 is all about user generated content, which broadens the attack surfaces. Also in some cases, a same existing attack can cause bigger impact on Web 2.0 environment than 1.0. For example, clickjacking is not that big of a deal in Web 1.0.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/3199542270491264400/comments/default/8805534042399812526'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/3199542270491264400/comments/default/8805534042399812526'/><link rel='alternate' type='text/html' href='http://www.jason-yuen.com/2009/02/was-20-are-you-ready.html?showComment=1234548720001#c8805534042399812526' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.jason-yuen.com/2009/02/was-20-are-you-ready.html' ref='tag:blogger.com,1999:blog-8954966646386655038.post-3199542270491264400' source='http://www.blogger.com/feeds/8954966646386655038/posts/default/3199542270491264400' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-573474132'/></entry><entry><id>tag:blogger.com,1999:blog-8954966646386655038.post-3799364597288946345</id><published>2009-02-10T11:48:00.000-05:00</published><updated>2009-02-10T11:48:00.000-05:00</updated><title type='text'>Dan, thanks for the feedback.  I agree that web ap...</title><content type='html'>Dan, thanks for the feedback.  I agree that web application security is a glaring omission from NIST's library.  The commercial side is way ahead of NIST; no surprise at all.  The problem is the lack of collaboration between private and government sectors.  Hopefully, this will change in the Obama Administration.&lt;BR/&gt;&lt;BR/&gt;There is a lack of implementation guidance associated with NIST.  I believe that more tools and useable methodologies need to be created.  Only after they have been integrated into existing processes will we see improvement.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/997520619345174114/comments/default/3799364597288946345'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/997520619345174114/comments/default/3799364597288946345'/><link rel='alternate' type='text/html' href='http://www.jason-yuen.com/2009/01/web-application-security-part-2-how-to.html?showComment=1234284480000#c3799364597288946345' title=''/><author><name>Jason Yuen</name><uri>http://www.blogger.com/profile/01689037743235268269</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_aVbrSQzZtzw/SXCVKavNwmI/AAAAAAAAAts/ARE75ujHsoM/S220/untitled.JPG'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.jason-yuen.com/2009/01/web-application-security-part-2-how-to.html' ref='tag:blogger.com,1999:blog-8954966646386655038.post-997520619345174114' source='http://www.blogger.com/feeds/8954966646386655038/posts/default/997520619345174114' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-520946566'/></entry><entry><id>tag:blogger.com,1999:blog-8954966646386655038.post-448091244267675506</id><published>2009-02-10T11:28:00.000-05:00</published><updated>2009-02-10T11:28:00.000-05:00</updated><title type='text'>You are right that there is a gap between 800-53 a...</title><content type='html'>You are right that there is a gap between 800-53 and SDLC requirements for each project.  It&amp;#39;s an unfortunate reality that NIST has to write it&amp;#39;s guidance for the broadest audience and then encourage end users to properly adapt them for their own needs.&lt;BR/&gt;&lt;BR/&gt;This may be changing slightly in the future.  NIST can&amp;#39;t be too specific when writing documentation but it has changed its focus in the new FISMA documentation (800-37 Rev 1, 800-53 Rev 3, 800-39, etc.) from a C&amp;amp;A cycle to an authorization process tied to the paired Risk Management Framework and Software Development Life Cycle.  This should help ease the requirements for SDLC practitioners to meet authorization process requirements.&lt;BR/&gt;&lt;BR/&gt;If you haven&amp;#39;t looked at NIST SP 800-64 Rev. 2, Security Considerations in the System Development Life Cycle it is worth reviewing.  While not a perfect document it can aid in the process of identifying authorization requirements for projects.  I recently contacted NIST regarding their plans for what I see as a glaring omission in their guidance, web application security.  They are planning on working on guidance for this but as yet are not actively developing the guidance.&lt;BR/&gt;&lt;BR/&gt;For what it&amp;#39;s worth I am currently working on mapping 800-53 to the newly developed OWASP Software Assurance Maturity Model (SAMM) ( http://opensamm.org/Home.html ). So far I am liking some of the design features of this framework and think it may be useful as a C&amp;amp;A/security authorization process tool.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/997520619345174114/comments/default/448091244267675506'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/997520619345174114/comments/default/448091244267675506'/><link rel='alternate' type='text/html' href='http://www.jason-yuen.com/2009/01/web-application-security-part-2-how-to.html?showComment=1234283280000#c448091244267675506' title=''/><author><name>DanPhilpott</name><uri>http://www.blogger.com/profile/05604476378903988024</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://www.systemsfirm.com/200x200Mev2.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.jason-yuen.com/2009/01/web-application-security-part-2-how-to.html' ref='tag:blogger.com,1999:blog-8954966646386655038.post-997520619345174114' source='http://www.blogger.com/feeds/8954966646386655038/posts/default/997520619345174114' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-896710523'/></entry><entry><id>tag:blogger.com,1999:blog-8954966646386655038.post-5993197808809521032</id><published>2009-02-10T11:11:00.000-05:00</published><updated>2009-02-10T11:11:00.000-05:00</updated><title type='text'>Right on. To complement Jason's points, many organ...</title><content type='html'>Right on. To complement Jason's points, many organizations today develop security requirements based on 800-53. That may be sufficient if your goal merely is “compliance readiness”. Else, we can only generate FUNCTIONAL security requirements from 800-53. Others come from the maturity of the organization’s security program. For example, Requirement generated by historical data: An organization has been performing VA/SCA for a period of time and notice that there is trend in most codes (developers are not validating input). This should be added to what Jason called SRF.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/997520619345174114/comments/default/5993197808809521032'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/997520619345174114/comments/default/5993197808809521032'/><link rel='alternate' type='text/html' href='http://www.jason-yuen.com/2009/01/web-application-security-part-2-how-to.html?showComment=1234282260000#c5993197808809521032' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.jason-yuen.com/2009/01/web-application-security-part-2-how-to.html' ref='tag:blogger.com,1999:blog-8954966646386655038.post-997520619345174114' source='http://www.blogger.com/feeds/8954966646386655038/posts/default/997520619345174114' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1395798501'/></entry><entry><id>tag:blogger.com,1999:blog-8954966646386655038.post-6660658881260766309</id><published>2009-01-30T08:35:00.000-05:00</published><updated>2009-01-30T08:35:00.000-05:00</updated><title type='text'>Andres, thanks for the feedback.&lt;br&gt;&lt;br&gt;Yes I do h...</title><content type='html'>Andres, thanks for the feedback.&lt;BR/&gt;&lt;BR/&gt;Yes I do have a few ideas in the upcoming posts.  It is mainly pertaining to security design reviews and early stages of planning.  Stay tuned!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/594169772115755085/comments/default/6660658881260766309'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/594169772115755085/comments/default/6660658881260766309'/><link rel='alternate' type='text/html' href='http://www.jason-yuen.com/2009/01/builders-and-breakers.html?showComment=1233322500000#c6660658881260766309' title=''/><author><name>Jason Yuen</name><uri>http://www.blogger.com/profile/01689037743235268269</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_aVbrSQzZtzw/SXCVKavNwmI/AAAAAAAAAts/ARE75ujHsoM/S220/untitled.JPG'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.jason-yuen.com/2009/01/builders-and-breakers.html' ref='tag:blogger.com,1999:blog-8954966646386655038.post-594169772115755085' source='http://www.blogger.com/feeds/8954966646386655038/posts/default/594169772115755085' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-520946566'/></entry><entry><id>tag:blogger.com,1999:blog-8954966646386655038.post-2106866134220528465</id><published>2009-01-28T11:11:00.000-05:00</published><updated>2009-01-28T11:11:00.000-05:00</updated><title type='text'>I hope you are right.&lt;br&gt;&lt;br&gt;I'm tired of "paper s...</title><content type='html'>I hope you are right.&lt;BR/&gt;&lt;BR/&gt;I'm tired of "paper security" instead of real security. The tax payers spend millions of dollars in having government agencies writing documents instead of putting the effort on really securing the applications.&lt;BR/&gt;&lt;BR/&gt;By the way, I like the topic of your blog and your writing style.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/5561454087629133874/comments/default/2106866134220528465'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/5561454087629133874/comments/default/2106866134220528465'/><link rel='alternate' type='text/html' href='http://www.jason-yuen.com/2009/01/does-it-security-matter.html?showComment=1233159060000#c2106866134220528465' title=''/><author><name>Andres Vivas</name><uri>http://blog.andresvivas.com</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.jason-yuen.com/2009/01/does-it-security-matter.html' ref='tag:blogger.com,1999:blog-8954966646386655038.post-5561454087629133874' source='http://www.blogger.com/feeds/8954966646386655038/posts/default/5561454087629133874' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-439152266'/></entry><entry><id>tag:blogger.com,1999:blog-8954966646386655038.post-7626536573921393335</id><published>2009-01-28T10:59:00.000-05:00</published><updated>2009-01-28T10:59:00.000-05:00</updated><title type='text'>Jason, you are making an excellent point.&lt;br&gt;&lt;br&gt;D...</title><content type='html'>Jason, you are making an excellent point.&lt;BR/&gt;&lt;BR/&gt;Do you have any suggestion for the project manager that is required by the customer to meet a short deadline and with a small budget? How to add security as part of the requirements for the applications under these constraints?&lt;BR/&gt;&lt;BR/&gt;A big part of the issue, in my opinion, is the lack of understanding by the business and application owners. It is simply not that important to them, until their application gets hacked, but then it is too late.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/594169772115755085/comments/default/7626536573921393335'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/594169772115755085/comments/default/7626536573921393335'/><link rel='alternate' type='text/html' href='http://www.jason-yuen.com/2009/01/builders-and-breakers.html?showComment=1233158340000#c7626536573921393335' title=''/><author><name>Andres Vivas</name><uri>http://blog.andresvivas.com</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.jason-yuen.com/2009/01/builders-and-breakers.html' ref='tag:blogger.com,1999:blog-8954966646386655038.post-594169772115755085' source='http://www.blogger.com/feeds/8954966646386655038/posts/default/594169772115755085' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1026376240'/></entry><entry><id>tag:blogger.com,1999:blog-8954966646386655038.post-5119795229570626467</id><published>2009-01-23T08:23:00.000-05:00</published><updated>2009-01-23T08:23:00.000-05:00</updated><title type='text'>"President Obama's cybersecurity plan released"&lt;br...</title><content type='html'>"President Obama's cybersecurity plan released"&lt;BR/&gt;&lt;BR/&gt;"Among the federal government's goals around cybersecurity: Initiate increased research-and-development effort, increase collaboration with the private sector to establish new standards and appoint a cyber adviser who will report directly to Obama."&lt;BR/&gt;&lt;BR/&gt;Yes, change!&lt;BR/&gt;&lt;BR/&gt;http://www.scmagazineus.com/President-Obamas-cybersecurity-plan-released/article/126252/</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/4878174675629105105/comments/default/5119795229570626467'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/4878174675629105105/comments/default/5119795229570626467'/><link rel='alternate' type='text/html' href='http://www.jason-yuen.com/2009/01/evolution-essential-for-innovation.html?showComment=1232716980000#c5119795229570626467' title=''/><author><name>Jason Yuen</name><uri>http://www.blogger.com/profile/01689037743235268269</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_aVbrSQzZtzw/SXCVKavNwmI/AAAAAAAAAts/ARE75ujHsoM/S220/untitled.JPG'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.jason-yuen.com/2009/01/evolution-essential-for-innovation.html' ref='tag:blogger.com,1999:blog-8954966646386655038.post-4878174675629105105' source='http://www.blogger.com/feeds/8954966646386655038/posts/default/4878174675629105105' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-520946566'/></entry></feed>
