<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Software Associates. &#187; FISMA</title>
	<atom:link href="http://www.software.co.il/tag/fisma/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.software.co.il</link>
	<description>Security and compliance specialists for medical device and healthcare companies</description>
	<lastBuildDate>Wed, 08 Feb 2012 06:36:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Overspending on security</title>
		<link>http://www.software.co.il/2009/09/overspending-on-security/</link>
		<comments>http://www.software.co.il/2009/09/overspending-on-security/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 12:54:24 +0000</pubDate>
		<dc:creator>Danny Lieberman</dc:creator>
				<category><![CDATA[Information security]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[Obama]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=1922</guid>
		<description><![CDATA[From Allan Paller&#8217;s testimony before the US Senate I think the quote speaks for itself. Outside the US &#8211; it seems even stranger to believe that US companies have enough money for two cyber security organizations paid for by the US taxpayer. However, federal agencies cannot move effectively to more secure systems unless you shift ...]]></description>
			<content:encoded><![CDATA[<p>From <a title="Testimony of Alan Paller1 of the SANS Institute2 Before the US Senate" href="hsgac.senate.gov/public/_files/042809Paller.pdf" target="_blank">Allan Paller&#8217;s testimony before the US Senate</a> I think the quote speaks for itself. Outside the US &#8211; it seems even stranger to believe that US companies have enough money for two cyber security organizations paid for by the US taxpayer.</p>
<blockquote><p>However, federal agencies cannot move effectively to more secure systems unless you shift the  emphasis of the FISMA assessments from paper reporting to automated monitoring of essential  controls. &#8230;  Two  weeks ago, a federal CIO told me, “I have a CISO who always gets me to green on my FISMA  grades, but the reports he produces have no impact at all on security of our computers or  networks, <em><strong>I am setting up a separate group to do real security.” This CIO can do both because  of a surge of funding his organization has received from the new stimulus bill</strong></em>.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/2009/09/overspending-on-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

