<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CTOvision.com &#187; CERT</title>
	<atom:link href="http://ctovision.com/tag/cert/feed/" rel="self" type="application/rss+xml" />
	<link>http://ctovision.com</link>
	<description>News, analysis and context on enterprise technology for the CTO</description>
	<lastBuildDate>Thu, 09 Feb 2012 21:03:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>New Command to Focus on Cybersecurity for DoD and IC</title>
		<link>http://ctovision.com/2009/04/new-command-to-focus-on-cybersecurity-for-dod-and-ic/</link>
		<comments>http://ctovision.com/2009/04/new-command-to-focus-on-cybersecurity-for-dod-and-ic/#comments</comments>
		<pubDate>Wed, 22 Apr 2009 14:03:28 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[CIA]]></category>
		<category><![CDATA[CTO]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[Cyberspace]]></category>
		<category><![CDATA[DHS]]></category>
		<category><![CDATA[Disruptive IT]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[NSA]]></category>
		<category><![CDATA[ODNI]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[The Future of Technology]]></category>
		<category><![CDATA[White House]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=146</guid>
		<description><![CDATA[Tweet The Wall Street Journal just ran an article titled:  &#8220;New Military Command to Focus on Cybersecurity.&#8221;   In it they indicate &#8220;current and former officials familiar with the plans&#8221; say a new military command will be established to coordinate the defense of Pentagon computer networks and improve US offensive capabilities in cyberwar. WSJ also [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2009%2F04%2Fnew-command-to-focus-on-cybersecurity-for-dod-and-ic%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2009/04/new-command-to-focus-on-cybersecurity-for-dod-and-ic/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2009/04/new-command-to-focus-on-cybersecurity-for-dod-and-ic/"  data-text="New Command to Focus on Cybersecurity for DoD and IC" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2009/04/new-command-to-focus-on-cybersecurity-for-dod-and-ic/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2009/04/new-command-to-focus-on-cybersecurity-for-dod-and-ic/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><img class="alignleft size-full wp-image-179" title="dod" src="http://ctovision.com/wp-content/uploads/2009/04/dod.jpg" alt="dod" width="157" height="157" />The Wall Street Journal just ran an article titled:  &#8220;<a href="http://online.wsj.com/article/SB124035738674441033.html">New Military Command to Focus on Cybersecurity</a>.&#8221;   In it they indicate &#8220;current and former officials familiar with the plans&#8221; say a new military command will be established to coordinate the defense of Pentagon computer networks and improve US offensive capabilities in cyberwar.</p>
<p>WSJ also reports that Defense Secretary Gates plans to announce the creation of a new military cyber command after the rollout of the White House review.</p>
<p>My opinion:  This WSJ article seems more balanced and accurate than the article I discussed in my post &#8220;<a href="http://ctovision.com/2009/04/my-opinion-nyt-wants-cyber-security-to-be-a-divisive-issue/">NYT wants cyber security to be a divisive issue.</a>&#8221;</p>
<p>The WSJ article is in consonance with what is going on and what should be going on.  I believe NSA should be formally given the lead for defending DoD/IC systems, but defense remains a team sport, and DHS should be given the lead for defending the rest of .gov networks (while still leaning on NSA/DoD/DNI as required).  And all players need to work well with industry and allies in a coordinated, fast moving way.</p>
<p>What does this mean for enterprise technologists?  For the most part it is good news.  But for day to day security operations in most enterprises, the relationships you have with other organizations will remain the same as before&#8211; for now.   And the current body of best practices remains in place.  You still need to understand and implement and follow the <a href="http://ctovision.com/2009/02/enhancing-security-and-functionality-at-the-same-time/">Common Audit Guidelines</a>, for example.  Doing that is going to help you and will help others too.</p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_1" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/02/govsec-conference-is-march-29-31-2011/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/001468eb33ec5e4590e7ad40cff3c88d_thumb_govsec.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">GovSec conference is March 29-31 2011</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/07/pros-and-cons-cyber-command/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/6f96223061ef7477c860bacf70a6861b_thumb_200px-2010-05-14-USCYBERCOM_Logo.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Pros and Cons: Cyber Command</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/05/intelligence-community-executive-forum/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/bbe00170f3bafc5d48b28580dfacaa3a_thumb_ICEFsponsors1.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Intelligence Community Executive Forum on Cyber Operations</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/12/defense-bill-passes-after-lengthy-debate/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-city-windows.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Defense bill passes after lengthy debate</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/11/cybersecurity-workforce-framework/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/wave-open-sea.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Cybersecurity Workforce Framework</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/11/pentagon-cio%e2%80%99s-tech-revamp-4-priorities/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/mosaic-detail.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Pentagon CIO’s Tech Revamp: 4 Priorities</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/leadership-changes-in-dod-it-logistics-cyber/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/evening-in-marlborough-sounds.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Leadership changes in DoD IT, logistics, cyber</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2011/12/homeland-security-committee-unveils-cybersecurity-bill/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/wave-open-sea.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Homeland Security Committee Unveils Cybersecurity Bill</span><span class="nr_source">Bob Gourley</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=New+Command+to+Focus+on+Cybersecurity+for+DoD+and+IC&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2009%2F04%2Fnew-command-to-focus-on-cybersecurity-for-dod-and-ic%2F&nr_ad_number=0&nr_div_number=1");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.domain = "ctovision.com";nRelate.fixHeight("nrelate_related_1");nRelate.adAnimation("nrelate_related_1");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2009/04/new-command-to-focus-on-cybersecurity-for-dod-and-ic/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Enhancing Security and Functionality At The Same Time</title>
		<link>http://ctovision.com/2009/02/enhancing-security-and-functionality-at-the-same-time/</link>
		<comments>http://ctovision.com/2009/02/enhancing-security-and-functionality-at-the-same-time/#comments</comments>
		<pubDate>Tue, 24 Feb 2009 21:07:30 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[Disruptive IT]]></category>
		<category><![CDATA[FDCC]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[Information Warfare]]></category>
		<category><![CDATA[Melissa Hathaway]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[standards]]></category>
		<category><![CDATA[Tech/Internet]]></category>
		<category><![CDATA[Technology Leadership]]></category>
		<category><![CDATA[Thin Client]]></category>
		<category><![CDATA[Triumfant]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=130</guid>
		<description><![CDATA[Tweet Have you ever been sucked into the false debate over how much IT spending should be spent on security?  I used to all the time.  Some folks point to a rule of thumb that goes something like &#8220;ten percent of the IT budget should be applied to security.&#8221;  That old school formula may well [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2009%2F02%2Fenhancing-security-and-functionality-at-the-same-time%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2009/02/enhancing-security-and-functionality-at-the-same-time/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2009/02/enhancing-security-and-functionality-at-the-same-time/"  data-text="Enhancing Security and Functionality At The Same Time" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2009/02/enhancing-security-and-functionality-at-the-same-time/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2009/02/enhancing-security-and-functionality-at-the-same-time/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>Have you ever been sucked into the false debate over how much IT spending should be spent on security?  I used to all the time.  Some folks point to a rule of thumb that goes something like &#8220;ten percent of the IT budget should be applied to security.&#8221;  That old school formula may well be part of the reason we got into the mess we are currently in.  It contributes to thoughts that lead you to think security can be separated.  By my way of thinking, 100% of the budget goes to security and functionality and that is the calculus.</p>
<p>Really, security is about ensuring information confidentiality, availability and integrity. And those constructs are totally connected to functionality of IT.   I try whenever possible to use the term security and functionality in the same context just to underscore that point.</p>
<p>For example, the goal I continually push regarding security in the federal space is not just one dealing with security.  I put it this way:  &#8220;Security and functionality of all federal IT will be increased by two orders of magnitude in the next 24 months.&#8221;  Putting the goal this ways also underscores that it is not security vs. functionality.  Both need to increase.</p>
<p>This goal also cries out for the need for metrics in security and functionality.  For functionality there are many customer focused survey methods that can help collect the right metrics.  For security, I think one metric stands out above all others:  Detected unauthorized intrusions.  There are many other important metrics for other dimensions of the security problem, but that one is key.  So, a goal that expects both security and functionality of federal enterprise IT to improve by two orders of magnitude will expect customer survey satisfaction to go through the roof, and will expect detected intrusions to drop significantly.  If there were 50,000 detected intrusions in 2008, there should be less than 5000 in 2010.</p>
<p>That is a dramatic goal.  What makes me think it is achievable?  In part the dramatic action being put in place today in the federal space.  And in part by dramatic new technologies and approaches like private clouds and thin client computing and enhanced identity management and authorization methods.  But of more importance and more relevance than all of that, in my opinion, is the coordinated action and leadership underway by CIOs and CISOs and the security  experts in the federal space today.</p>
<p>As evidence of this incredible positive action I&#8217;d like to bring your attention to a release by a Consortium of US Federal Cybersecurity Experts on Consensus Audit Guidelines.  Details of this effort are at <a href="http://www.sans.org/cag/">http://www.sans.org/cag/</a></p>
<p>The Consensus Audit Guidelines provide the twenty most important controls and metrics for effective cyber defense and continuous FISMA compliance.   These controls and metrics include:</p>
<p><strong>Critical Controls Subject to Automated Measurement and Validation:</strong></p>
<ol>
<li>Inventory of Authorized and Unauthorized Hardware.</li>
<li>Inventory of Authorized and Unauthorized Software.</li>
<li>Secure Configurations for Hardware and Software on Laptops, Workstations, and Servers.</li>
<li>Secure Configurations of Network Devices Such as Firewalls and Routers.</li>
<li>Boundary Defense</li>
<li>Maintenance and Analysis of Complete Security Audit Logs</li>
<li>Application Software Security</li>
<li>Controlled Use of Administrative Privileges</li>
<li>Controlled Access Based On Need to Know</li>
<li>Continuous Vulnerability Testing and Remediation</li>
<li>Dormant Account Monitoring and Control</li>
<li>Anti-Malware Defenses</li>
<li>Limitation and Control of Ports, Protocols and Services</li>
<li>Wireless Device Control</li>
<li>Data Leakage Protection</li>
</ol>
<p><strong>Additional Critical Controls (not directly supported by automated measurement and validation):</strong></p>
<ol>
<li>Secure Network Engineering</li>
<li>Red Team Exercises</li>
<li>Incident Response Capability</li>
<li>Data Recovery Capability</li>
<li>Security Skills Assessment and Training to Fill Gaps</li>
</ol>
<p>The site at <a href="http://www.sans.org/cag">http://www.sans.org/cag</a> provides more details on each, including detailed descriptions of the controls, how to implement them, how to measure them, and how to continuously improve them.   The site also spells out the fact that this is a work in progress and processes are in place to ensure this great effort remains relevant and maximizes our ability to protect ourselves.</p>
<p>What should CTOs think about this guidance?  As for me, I most strongly endorse it. In my mind the appropriate implementation of these controls will reduce unauthorized intrusions in any enterprise.</p>
<p>The deeply respected community leader Alan Paller said it this way:</p>
<p>&#8220;This is the best example of risk-based security I have ever seen,&#8221; said<br />
Alan Paller, director of research at the SANS Institute.  &#8220;The team that was<br />
brought together represents the nation&#8217;s most complete understanding of<br />
the risk faced by our systems. In the past cybersecurity was driven by<br />
people who had no clue of how the attacks are carried out. They created an<br />
illusion of security. The CAG will turn that illusion to reality.&#8221;</p>
<p>Please give these controls a read, and please help get them into the hands of the security and functionality professionals in your enterprise.</p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_2" class="nrelate nrelate_related nrelate_default nr_100"><!-- no data found 200 --></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_2");nRelate.adAnimation("nrelate_related_2");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2009/02/enhancing-security-and-functionality-at-the-same-time/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>We Have A Cyber Czar, and He Has Spoken</title>
		<link>http://ctovision.com/2009/01/we-have-a-cyber-czar-and-he-has-spoken/</link>
		<comments>http://ctovision.com/2009/01/we-have-a-cyber-czar-and-he-has-spoken/#comments</comments>
		<pubDate>Fri, 30 Jan 2009 15:37:32 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[cio]]></category>
		<category><![CDATA[CTO]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Russian government]]></category>
		<category><![CDATA[Technology Leadership]]></category>
		<category><![CDATA[The Future of Technology]]></category>
		<category><![CDATA[Vladimir Putin]]></category>
		<category><![CDATA[YouTube]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=122</guid>
		<description><![CDATA[Tweet A debate has been running for months both among government thought leaders and the technical literati on whether or not the US should appoint a &#8220;Cyber Czar&#8221; who can exert authority over IT security in the federal space or perhaps even aspects of the nation&#8217;s IT defenses.  This is a complex discussion that has [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2009%2F01%2Fwe-have-a-cyber-czar-and-he-has-spoken%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2009/01/we-have-a-cyber-czar-and-he-has-spoken/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2009/01/we-have-a-cyber-czar-and-he-has-spoken/"  data-text="We Have A Cyber Czar, and He Has Spoken" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2009/01/we-have-a-cyber-czar-and-he-has-spoken/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2009/01/we-have-a-cyber-czar-and-he-has-spoken/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><img class="alignleft size-medium wp-image-401" title="DAVOS/" src="http://ctovision.com/wp-content/uploads/2009/01/putinatdavos-300x200.jpg" alt="DAVOS/" width="300" height="200" />A debate has been running for months both among government thought leaders and the technical literati on whether or not the US should appoint a &#8220;Cyber Czar&#8221; who can exert authority over IT security in the federal space or perhaps even aspects of the nation&#8217;s IT defenses.  This is a complex discussion that has had some of the greatest thinkers in and out of government involved.   A great snapshot of issues and the opinions of many well reasoned experts are expressed in the CSIS report <a href="http://ctovision.com/2008/12/ctos-global-cyberwar-and-our-collective-future/">&#8220;Securing Cyberspace for the 44th Presidency&#8221;</a> and other thoughts are here: <a href="http://ctovision.com/2009/01/the-future-of-cyber-security-and-cyber-conflict/">The Future of Cyber Security</a> and here: <a href="http://ctovision.com/2009/01/threats-in-the-age-of-obama/">Threats In the Age of Obama</a> .</p>
<p>Unfortunately for those who would like to still debate and discuss this issue, there is already a Cyber Czar who can accomplish most all his objectives in our networks.  His name is Russian Prime Minister Vladimir Putin.  This former KGB operative now controls Russia with an iron fist and has shown others again and again he will exert influence anywhere he needs to in order to accomplish his objectives.  He will use tanks when required and cyber when desired and combinations when it suits him.  There are indications his agents are also in our networks now.  If our objectives are to keep players like him out, we cannot say  we are accomplishing them.  If his objectives are to get in, then we can say he is accomplishing them.  Till this situation changes, we need to confront then this new reality:  <strong>Vladimir Putin is the Cyber Czar.</strong></p>
<p>We have our own great technologists and wizards of cyber, of course. And we have great hero entrepreneurs of technology who have built the cyber world we all use today.  One of those greats is Michael Dell, creator of an idea and corporation that develops, manufactures, sells and distributes personal computers we all depend on.</p>
<p>But he is someone who will now think twice before thinking he can interact as a peer to Cyber Czar Putin.  After listening to Putin&#8217;s speech at the <a href="http://www.weforum.org/en/index.htm">World Economic Forum</a> in Davos, Michael Dell praised Russia&#8217;s technical and scientific prowess and asked a nice, friendly question:  &#8220;How can we help.&#8221;  As a former govie CTO I would get asked that type of question all the time from industry and really appreciated it whenever a senior thought leader would ask that.  But not Czar Putin.  He did not appreciate that at all.   Putin was offended by the assertion that the mighty Russia might need help in anything Cyber. The exchange is captured here on YouTube:</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="src" value="http://www.youtube.com/v/OMR1BZ9aYM8&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;feature=player_embedded&amp;fs=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/OMR1BZ9aYM8&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;feature=player_embedded&amp;fs=1" allowfullscreen="true"></embed></object></p>
<p><a href="http://money.cnn.com/2009/01/28/news/companies/dell.davos.fortune/">Fortune</a>: described the exchange this way:</p>
<p>&#8220;Putin&#8217;s withering reply to Dell: &#8220;We don&#8217;t need help. We are not invalids. We don&#8217;t have limited mental capacity.&#8221; The slapdown took many of the people in the audience by surprise. Putin then went on to outline some of the steps the Russian government has taken to wire up the country, including remote villages in Siberia. And, in a final dig at Dell, he talked about how Russian scientists were rightly respected not for their hardware, but for their software. The implication: Any old fool can build a PC outfit.&#8221;</p>
<p>Clearly cyber domination is personal with Putin.  He is the Cyber Czar.</p>
<p>I think I should end with a plea to all who care about cyber freedom and all who know the potential positive contributions of IT:  Please don&#8217;t be pleased with this current situation.  Please don&#8217;t just think the title of Cyber Czar I&#8217;ve now used to describe Putin is something we should be proud of.  It is not.  We should continue to act till we are able to  assert that we are masters of our own networks.  Our nation&#8217;s intellectual property, including the intellectual property of all our companies and citizens, is too important to let it be given away without at least a cyber fight.</p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_3" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/07/pros-and-cons-cyber-command/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/6f96223061ef7477c860bacf70a6861b_thumb_200px-2010-05-14-USCYBERCOM_Logo.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Pros and Cons: Cyber Command</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/05/intelligence-community-executive-forum/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/bbe00170f3bafc5d48b28580dfacaa3a_thumb_ICEFsponsors1.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Intelligence Community Executive Forum on Cyber Operations</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/10/defending-against-stuxnet-type-threats/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/d2333f6f4e0094cfb2b563c4ded3f948_thumb_natanz_visit-300x201.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Defending Against Stuxnet Type Threats</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/pnnl-seeks-chief-cyber-security-research-scientist/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/4304dc0f2b6e825a1a293cf8aaefa161_thumb_RichlandWaPNNL_1.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">PNNL Seeks Chief Cyber Security Research Scientist</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/04/cyber-and-physical-security-the-discussion-continues/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/6ee17c0cee7314e47f9c339640603391_thumb_cyber-221x300.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Cyber And Physical Security: The discussion continues</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.haftofthespear.com/?p=1913"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/img.youtube.com/abb436d2b0d3ef01fb85b13c2baeccc8_thumb_0.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Is your “cyber security expert” full of s***?</span><span class="nr_source">Haft of the Spear</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.haftofthespear.com/?p=1875"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/65008238cd4f0cfc80b47d90b89940a0_thumb_Cyber-Spreadsheet-Bullshit-300x297.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Yea! Legislation!</span><span class="nr_source">Haft of the Spear</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2010/06/cto-perspectives-on-cyber-security-bill-of-the-us-senate-homeland-security-and-governmental-affairs-comittee/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/c91e4caea6e3b96614f0ae61090ec4b3_thumb_hsgac-liberman-collins.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">CTO Perspectives on Cyber Security Bill</span><span class="nr_source">CTOvision.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2012/01/alexs-2012-tech-predictions/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/c2ca6b33dbce7e4646c5f3874a9380e3_thumb_2012.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Alex's 2012 Tech Predictions</span><span class="nr_source">CTOvision.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2011/07/deputy-secretary-of-defense-lynn-cyber-strategy%e2%80%99s-thrust-is-defensive/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/fa5ccb5775a00b753a4d3a3d6317d2a6_thumb_200px-2010-05-14-USCYBERCOM_Logo.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Deputy Secretary of Defense Lynn: Cyber Strategy’s Thrust is Defensive</span><span class="nr_source">CTOvision.com</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=We+Have+A+Cyber+Czar%2C+and+He+Has+Spoken&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2009%2F01%2Fwe-have-a-cyber-czar-and-he-has-spoken%2F&nr_ad_number=0&nr_div_number=3");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_3");nRelate.adAnimation("nrelate_related_3");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2009/01/we-have-a-cyber-czar-and-he-has-spoken/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>CTOs, Global Cyberwar and Our Collective Future</title>
		<link>http://ctovision.com/2008/12/ctos-global-cyberwar-and-our-collective-future/</link>
		<comments>http://ctovision.com/2008/12/ctos-global-cyberwar-and-our-collective-future/#comments</comments>
		<pubDate>Mon, 08 Dec 2008 22:49:50 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[AFCEA]]></category>
		<category><![CDATA[Barack Obama]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[DHS]]></category>
		<category><![CDATA[DIA]]></category>
		<category><![CDATA[Disruptive IT]]></category>
		<category><![CDATA[DNI]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[FDCC]]></category>
		<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[Melissa Hathaway]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[ODNI]]></category>
		<category><![CDATA[OMB]]></category>
		<category><![CDATA[Open Source Software]]></category>
		<category><![CDATA[R&D]]></category>
		<category><![CDATA[standards]]></category>
		<category><![CDATA[Sun]]></category>
		<category><![CDATA[Sun Ray]]></category>
		<category><![CDATA[Technology Leadership]]></category>
		<category><![CDATA[Thin Client]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=9</guid>
		<description><![CDATA[Tweet If you are a technologist, please take a moment to download the PDF of the report by the U.S. Commission on Cybersecurity.  This report, titled Securing Cyberspace for the 44th Presidency, is the best proclamation of the challenges of cyber I have read.  It is also a roadmap that will help any trying to [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2008%2F12%2Fctos-global-cyberwar-and-our-collective-future%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2008/12/ctos-global-cyberwar-and-our-collective-future/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2008/12/ctos-global-cyberwar-and-our-collective-future/"  data-text="CTOs, Global Cyberwar and Our Collective Future" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2008/12/ctos-global-cyberwar-and-our-collective-future/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2008/12/ctos-global-cyberwar-and-our-collective-future/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a style="float: left;" href="http://ctovision.typepad.com/.a/6a00e3933705b588340105369188b0970b-pi"><img class="at-xid-6a00e3933705b588340105369188b0970b " style="margin: 0px 5px 5px 0px; width: 216px; height: 279px;" src="http://ctovision.typepad.com/.a/6a00e3933705b588340105369188b0970b-320wi" alt="Ccis" /></a> If you are a technologist, please take a moment to download the PDF of the report by the U.S. Commission on Cybersecurity.  This report, titled <a href="http://www.csis.org/component/option,com_csis_pubs/task,view/id,5157/" target="_blank">Securing Cyberspace for the 44th Presidency</a>, is the best proclamation of the challenges of cyber I have read.  It is also a roadmap that will help any trying to navigate these very tough issues.</p>
<p>I&#8217;ve been involved in things cyber for a long time.  My deepest<br />
involvement began in December 1998, almost 10 years ago to the day.  In all that time I&#8217;ve seen lots of studies and lots of papers and many treatments of the issues.  But I&#8217;ve never seen one that captures the complexities and the need for specific actions as well as this one.</p>
<p>I&#8217;d really recommend you read every word, if you want to be considered literate in this field.   But if it will be a little while till you get to it, here are some key points:</p>
<p>The three major findings are:  1) Cybersecurity is now a major national security problem for the U.S., 2) Decisions and actins must respect privacy and civil liberties, and 3) only a comprehensive national security strategy that embraces both the domestic and international  aspects of cybersecurity will make us more secure.</p>
<p>The report makes a few points about the Bush Administration&#8217;s Comprehensive National Cybersecurity Initiative (CNCI).  In general the give credit to that initiative, and call it good.  I agree, it is a great activity I&#8217;ve previously written about that is led by one of the most effective people in government today and has done great work.  But as the commission points out, the work of the CNCI is good but not sufficient.</p>
<p>The biggest shock for me in this study:  The amount of funding on R&amp;D for cyber security.  I have been looking into the many activities underway, and maybe that look made me deceive myself into thinking it was a well funded effort.  According to the comission, however, they estimate that the total R&amp;D funding in the federal government for cybersecurity is about $300million.  Less than two-tenths of one percent of the total federal R&amp;D.</p>
<p>The report has a great section on identity manangement.</p>
<p>I am convinced the organizational approaches outlined in the study are the right ones as well.  There is only one place in our government where we can lead solutions to this challenge.  Where is that?  Hey read the report!</p>
<p>What else do I recommend CTOs do besides read the report?  I think one way we can all help the cybersecurity effort is to think through which standards bodies are the most important to engage with regarding security.   A few are here:<br />
<a href="http://ctovision.com/2008/05/standards-organizations-ctos-should-track/">http://ctovision.com/2008/05/standards-organizations-ctos-should-track/</a></p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_4" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/12/cyberwar-what-cyberwar/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/e19501bff258cb53ea0010fc21bcf2cf_thumb_stop.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Cyberwar? What Cyberwar?</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/12/enterprise-technology-developments-in-2010-and-2011/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/613f5bad2c0bb8f03cc87edc5dbc303d_thumb_NISTcloudcomputing.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Enterprise Technology Developments in 2010 and 2011</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/01/privacy-security-functionality-and-enhanced-benefits-of-free-commerce/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/2301d827ec6cefe43a600f6667a35354_thumb_600px-US-DeptOfCommerce-Seal-300x300.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Privacy, Security, Functionality and Enhanced Benefits of Free Commerce</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/redesign-of-ctolabs-com/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/9dccfb7a04a2201957a4252fa3e285d7_thumb_p1.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Redesign of CTOlabs.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/if-you-could-pick-one-thing-for-congress-to-do-regarding-cybersecurity-what-would-it-be/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/blue-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">If You Could Pick One Thing For Congress To Do Regarding CyberSecurity, What  ...</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/cyberattack-as-covert-action/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-old-wood.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Cyberattack as Covert Action</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2012/01/join-cloudera-and-carahsoft-for-big-data-success-in-government/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/mountains-dust.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Join Cloudera and Carahsoft for Big Data Success in Government</span><span class="nr_source">Bob Gourley</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=CTOs%2C+Global+Cyberwar+and+Our+Collective+Future&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2008%2F12%2Fctos-global-cyberwar-and-our-collective-future%2F&nr_ad_number=0&nr_div_number=4");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_4");nRelate.adAnimation("nrelate_related_4");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2008/12/ctos-global-cyberwar-and-our-collective-future/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>One to watch regarding standards and security</title>
		<link>http://ctovision.com/2008/11/one-to-watch-regarding-standards-and-security/</link>
		<comments>http://ctovision.com/2008/11/one-to-watch-regarding-standards-and-security/#comments</comments>
		<pubDate>Sun, 16 Nov 2008 16:54:54 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[collaboration]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[DHS]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[Intel]]></category>
		<category><![CDATA[Melissa Hathaway]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[standards]]></category>
		<category><![CDATA[Technology Leadership]]></category>
		<category><![CDATA[White House]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=10</guid>
		<description><![CDATA[Tweet In May 2008 I provided an overview of Standards Organizations CTOs Should Track.  Standards groups don&#8217;t change that fast, so the list is still pretty much ok, but I was very light on industry consortia.  Industry groups can play a large role in setting and implementing standards.  Industry reps send the majority of thinkers [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2008%2F11%2Fone-to-watch-regarding-standards-and-security%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2008/11/one-to-watch-regarding-standards-and-security/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2008/11/one-to-watch-regarding-standards-and-security/"  data-text="One to watch regarding standards and security" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2008/11/one-to-watch-regarding-standards-and-security/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2008/11/one-to-watch-regarding-standards-and-security/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>In May 2008 I provided an overview of <a href="http://www.ctovision.com/2008/05/standards-organizations-ctos-should-track.html" target="_blank">Standards Organizations CTOs Should Track</a>.  Standards groups don&#8217;t change that fast, so the list is still pretty much ok, but I was very light on industry consortia.  Industry groups can play a large role in setting and implementing standards.  Industry reps send the majority of thinkers to standards bodies and industry management decides what standards to follow or ignore.  Tracking industry consortia can be very important to the CTO.</p>
<p>Since security is such a hot topic  I wanted to point out one I think we should all watch.  The Industry Consortium for Advancement of Security on the Internet or <a href="http://www.icasi.org" target="_blank">ICASI</a>.</p>
<p>ICASI was formed as a non-profit organization by a group of global IT leaders including Cisco, IBM, Intel, Juniper and Microsoft.  ICASI establishes trust mechanisms to allow those vendors to work very close together in a multi-lateral way to address international, multi-product threats.  Member companies can work in ways that protect sensitive information but enable effective collaboration.  Global leaders were sought for membership because of both the need to serve global customers and the challenges of defending against threats to global supply chains.</p>
<p>The ICASI is an informed group that is clearly aware of and supportive of many other efforts, like those sponsored by the White House and Department of Homeland Security.  For example, the ICASI cites reporting from National Security and Telecommunications Advisory Committee, like the NSTAC Report to the <a href="http://www.ncs.gov/nstac/reports/2007/NSTAC%20International%20Report.pdf" target="_blank">President on International Communications dated 16 August 2007</a> which highlights the need for a group like ICASI.</p>
<p>The ICASI vision:  Drive excellence and innovation in security response and share it with industry.</p>
<p>ICASI was formed by some of the greatest companies in the IT community.  As an optimist I believe they will help enhance security and look forward to their upcoming report on accomplishments.   But still, they are trying to tackle some very hard problems.  And they have not been providing information to the public on their internal dialog.  Should we be concerned that this was another good attempt that fell short of the vision?  Will the huge cuts in IT companies impact the people and resources provided to ICASI?  Stay tuned for more info&#8230;</p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_5" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2012/01/what-you-need-to-know-about-fedramp/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/bda0dcd0f166c28b500a9f792aef8301_thumb_FedRAMP_Logo_small.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">What You Need To Know About FedRAMP</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/04/the-cloud-and-cybersecurity/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/700c8717c268633701cd882a4a5a9058_thumb_CloudSecurity_1.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The Cloud and Cybersecurity</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/06/a-national-strategy-for-trusted-identities-in-cyberspace/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/bbe0732b555dbbfcbe1c5ac118144ea3_thumb_howardschmidt-300x200.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">A National Strategy for Trusted Identities in Cyberspace</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/04/standardizing-the-cloud/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/5c0eeba523c46bdd92f86186b8b3c0cb_thumb_cloud.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Standardizing the Cloud</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/02/oracle-sun-and-the-enterprise-cto/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/cut-log.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Oracle, Sun and the Enterprise CTO</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/02/previstar-continual-preparedness/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/ice-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Previstar: Continual Preparedness</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/yesterday%e2%80%99s-security-doesn%e2%80%99t-work-for-today%e2%80%99s-threats/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/ice-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Yesterday’s Security Doesn’t Work for Today’s Threats</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/nist-identifies-cloud-computing-standards-gaps/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/evening-in-marlborough-sounds.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">NIST identifies cloud computing standards gaps</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.haftofthespear.com/?p=1860"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/www.haftofthespear.com/65008238cd4f0cfc80b47d90b89940a0_thumb_Cyber-Spreadsheet-Bullshit-300x297.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The End of Cyber Security (Part IV)</span><span class="nr_source">Haft of the Spear</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/02/us-offers-10m-to-jump-start-id-security-tech-research/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-red.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">US Offers $10M to Jump-Start ID Security Tech Research</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=One+to+watch+regarding+standards+and+security&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2008%2F11%2Fone-to-watch-regarding-standards-and-security%2F&nr_ad_number=0&nr_div_number=5");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_5");nRelate.adAnimation("nrelate_related_5");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2008/11/one-to-watch-regarding-standards-and-security/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Performance Management In Organizations and Computers</title>
		<link>http://ctovision.com/2008/10/performance-management-in-organizations-and-computers/</link>
		<comments>http://ctovision.com/2008/10/performance-management-in-organizations-and-computers/#comments</comments>
		<pubDate>Tue, 14 Oct 2008 02:05:22 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[DHS]]></category>
		<category><![CDATA[Disruptive IT]]></category>
		<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[FDCC]]></category>
		<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[Information Warfare]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[OMB]]></category>
		<category><![CDATA[standards]]></category>
		<category><![CDATA[Tech/Internet]]></category>
		<category><![CDATA[Technology Leadership]]></category>
		<category><![CDATA[Triumfant]]></category>
		<category><![CDATA[Web/Tech]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=21</guid>
		<description><![CDATA[Tweet There are some interesting analogies between performance management applied to organizations and performance management applied to computers. In both cases, performance metrics are crucial to success.  In organizations, what we reward gets measured, and what gets measured can be more efficiently and effectively done.   In our computers, what we decide is important gets measured, [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2008%2F10%2Fperformance-management-in-organizations-and-computers%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2008/10/performance-management-in-organizations-and-computers/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2008/10/performance-management-in-organizations-and-computers/"  data-text="Performance Management In Organizations and Computers" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2008/10/performance-management-in-organizations-and-computers/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2008/10/performance-management-in-organizations-and-computers/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>There are some interesting analogies between performance management applied to organizations and performance management applied to computers.</p>
<p>In both cases, performance metrics are crucial to success.  In organizations, what we reward gets measured, and what gets measured can be more efficiently and effectively done.   In our computers, what we decide is important gets measured, and those measurements can help us drive to increasingly effective and efficient performance.</p>
<p>Computer metrics apply to a broad range of disciplines and needs, including needs like:</p>
<ul>
<li>Improved power efficiencies</li>
<li>Lower heat generation</li>
<li>Smaller footprint and lighter weight</li>
<li>Higher reliability</li>
<li>Multi-threaded execution</li>
<li>Continuous availability</li>
<li>Enhanced security</li>
<li>Enhanced information assurance</li>
<li>Enhanced agility in the face of change</li>
<li>Enhanced ability to ensure compliance</li>
</ul>
<p>Metrics in these areas drive improvements, but they also help drive decision-making, both by the IT management team and, when done appropriately, by automated management computer systems.  Just as agile, high-performance organizations can rapidly assess metrics and drive decision-making based on them, the agile, high-performance IT enterprise can leverage metrics to drive decisions and actions.  Automated remediation of problems and automated implementation of new policies are only possible with well through out, integrated metrics solutions.</p>
<p>Well thought out metrics solutions also provide built in ways to measure compliance with directives and regulations, including:</p>
<ul>
<li>SOX: The Sarbanes-Oxley act of 2002, which establishes many standards for public companies, including internal controls for assuring the accuracy of key data and audits on key information.</li>
<li>FISMA: The Federal Information Security Management Act of 2002, which bolsters computer and network security in the federal goverment and many contractors.</li>
<li>OMB M06-16:  A security checklist coordinated by NIST and promulgated by OMB.</li>
<li>FDCC: Federal Desktop Core Configuration, NIST coordinated, OMB mandated requirement for 300 settings on each Windows XP and Vista computer.</li>
<li>SCAP: Security Content Automation Protocol, a US government multi-agency initiative to enable automation and standardization of technical security operations.  SCAP is the method for using specific standards to enable automated vulnerability management, measurement and policy compliance evalation.</li>
</ul>
<p>Compliance with these and related directives, and compliance with the governance guidance of the enterprise CIO and CTO, are good governance.  This sort of compliance can be automated with tools like <a href="http://triumfant.com" target="_blank">Triumfant&#8217;s compliance manager</a>, and when automated generally provide a very rapid return on investment (ROI).</p>
<p>My conclusion:  in this case, the computers in your enteprise should be treated like an optimized organization: use metrics to enable compliance, agility and continually improving performance.  And use those metrics to drive decisions, and automate the entire process to the greatest degree possible.</p>
<p>For more on this topic also see: <a href="http://www.ctovision.com/2008/08/compliance-enhances-it-support-to-the-mission.html"></a><a href="http://ctovision.com/2008/08/compliance-enhances-it-support-to-the-mission/">http://ctovision.com/2008/08/compliance-enhances-it-support-to-the-mission/</a></p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_6" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/07/the-technology-of-voltdb/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/5cf72a28feb70640d3a9dcf05bcd87f5_thumb_voltdb1.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The Technology of VoltDB</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/06/data-wizards-know-hadoop-is-powerful-but-they-want-more-automation/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/3feabd9723f0994091e1088fd98c78e3_thumb_trade-data.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Data Wizards Know Hadoop is Powerful: But they want more automation</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/hadoop-world-breakout-sessions-8-and-9-nov-recommendations-for-the-enterprise-cto/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/5795a505ac3bd51a6489c9c8337befb8_thumb_decide.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Hadoop World Breakout Sessions 8 and 9 Nov: Recommendations for the enterpris ...</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/12/a-look-at-vmwares-vfabric-cloud-application-platform/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/0717589ce7df6c98de9d81caca8a3571_thumb_vmware.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">A look at VMware's vFabric Cloud Application Platform</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/one-trillion-reasons-one-year-later/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/59248b821876d8d2eb9f94619bfdfd7b_thumb_161998_158368190875976_4298046_n.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">One Trillion Reasons: One Year Later</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/ttps-cradas-mrm-and-fixmo/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/spiral-seashells-painted-gold.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">TTPs, CRADAs, MRM, and Fixmo</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/11/enterprise-customers-gain-business-insight-and-competitive-advantage-with-netapp-and-cloudera/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/weather-station-robe-south-australia.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Enterprise Customers Gain Business Insight and Competitive Advantage With Net ...</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2011/12/a-look-at-vmware%e2%80%99s-vfabric-cloud-application-platform/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-blue-stripes.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">A look at VMware’s vFabric Cloud Application Platform</span><span class="nr_source">Bob Gourley</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2012/01/join-cloudera-and-carahsoft-for-big-data-success-in-government/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/sunset-free-wallpaper.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Join Cloudera and Carahsoft for Big Data Success in Government</span><span class="nr_source">Bob Gourley</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/01/cloudera-and-carahsoft-webinar-big-data-success-in-government-19-jan-2012/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-macro-plant.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Cloudera and Carahsoft Webinar: Big Data Success in Government 19 Jan 2012</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Performance+Management+In+Organizations+and+Computers&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2008%2F10%2Fperformance-management-in-organizations-and-computers%2F&nr_ad_number=0&nr_div_number=6");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_6");nRelate.adAnimation("nrelate_related_6");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2008/10/performance-management-in-organizations-and-computers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ITIL for CTOs</title>
		<link>http://ctovision.com/2008/06/itil-for-ctos/</link>
		<comments>http://ctovision.com/2008/06/itil-for-ctos/#comments</comments>
		<pubDate>Mon, 16 Jun 2008 10:58:51 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[Books]]></category>
		<category><![CDATA[CTO]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[Disruptive IT]]></category>
		<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[Great CTOs]]></category>
		<category><![CDATA[information technology]]></category>
		<category><![CDATA[ITIL]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[standards]]></category>
		<category><![CDATA[Tech/Internet]]></category>
		<category><![CDATA[Technology Leadership]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=54</guid>
		<description><![CDATA[Tweet ITIL is the Information Technology Infrastructure Library, a set of tips, techniques, processes and concepts for managing an IT enterprise.  ITIL focuses on infrastructure, application development and operations. ITIL is without a doubt the most widely accepted approach to enterprise management.  It provides a full set of best practices. I&#8217;ve come to believe that [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2008%2F06%2Fitil-for-ctos%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2008/06/itil-for-ctos/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2008/06/itil-for-ctos/"  data-text="ITIL for CTOs" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2008/06/itil-for-ctos/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2008/06/itil-for-ctos/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>ITIL is the <a href="http://www.itil-officialsite.com/home/home.asp" target="_blank">Information Technology Infrastructure Library</a>, a set of tips, techniques, processes and concepts for managing an IT enterprise.  ITIL focuses on infrastructure, application development and operations. ITIL is without a doubt the most widely accepted approach to enterprise management.  It provides a full set of best practices.</p>
<p>I&#8217;ve come to believe that all CTOs should learn ITIL.  I don&#8217;t believe ITIL holds all the answers for enterprises, but it has many useful models and many best practices that can be of enormous benefit, so enterprise class CTOs will increasingly find a familiarity with ITIL comes in handy.  For CTOs in vendors, integrators or startups, you will be interacting with enterprise technologists and should understand the power of ITIL as well.</p>
<p>ITIL came out of the UK and the name ITIL remains a registered trademark of the UK&#8217;s Office of Government Commerce (OGC), so I should tip my hat to them.  The OGC and the many other contributors to the ITIL have done enterprises everywhere a great service and they deserve our thanks.</p>
<p>The reference library of ITIL is provided in five core texts:</p>
<ol>
<li>Service Strategy</li>
<li>Service Design</li>
<li>Service Transition</li>
<li>Service Operation</li>
<li>Continual Service Improvement</li>
</ol>
<p>Benefits of ITIL, asserted on the ITIL site, include:</p>
<ul>
<li>reduced costs</li>
<li>improved IT services through the use of proven best practice processes</li>
<li>improved customer satisfaction through a more professional approach to service delivery</li>
<li>standards and guidance</li>
<li>improved productivity</li>
<li>improved use of skills and experience</li>
<li>improved delivery of third party services through the<br />
specification of ITIL or ISO 20000 as the standard for service delivery<br />
in services procurements.</li>
</ul>
<p>The following info on the books of ITIL v3 is condensed from <a href="http://en.wikipedia.org/wiki/ITIL" target="_blank">Wikipedia&#8217;s entry on ITIL</a>:</p>
<h3><span class="mw-headline">Service Strategy</span></h3>
<p>Service strategy encompasses a framework to build best practice in developing a long  term strategy. Topics include: general  strategy, competition and market space, service provider types, service  management as a strategic asset, organization design and development,  key process activities, financial management, service portfolio  management, demand management, and key roles and responsibilities of<br />
staff engaging in service strategy.</p>
<h3><span class="editsection"> </span><span class="mw-headline">Service Design</span></h3>
<p>The design of IT services conforming to best practice, and including  design of architecture, processes, policies, documentation, and allow  for future business requirements. This also encompasses topics such as  Service Design Package (SDP), Service catalog management, Service Level  management, designing for capacity management, IT service continuity,  Information Security, supplier management, and key roles and  responsibilities for staff engaging in service design</p>
<h3><span class="mw-headline">Service Transition</span></h3>
<p>Service transition relates to the delivery of services required by  the business into liveoperational use, and often encompasses the  &#8220;project&#8221; side of IT rather than &#8220;BAU&#8221; (Business As Usual). This area  also covers topics such as managing changes to the environment.  Topics include Service Asset and Configuration Management, Transition  Planning and Support, Release and deployment management, Change<br />
Management, Knowledge Management, as well as the key roles of staff  engaging in Service Transition.</p>
<h3><span class="mw-headline">Service Operation</span></h3>
<p>Best practice for achieving the delivery of agreed levels of  services both to end-users and the customers (where &#8220;customers&#8221; refer  to those individuals who pay for the service and negotiate the SLAs).  Service Operations is the part of the lifecycle where the services and  value is actually directly delivered. Also the monitoring of problems  and balance between service reliability and cost etc are considered.  Topics include balancing conflicting goals (e.g. reliability v cost  etc), Event management, incident management, problem management, event  fulfillment, asset management, service desk, technical and application<br />
management,  as well as key roles and responsibilities for staff  engaging in Service Operation.</p>
<p>The above is just a short introduction.  For more info, I recommend the booklet <a href="http://www.amazon.com/gp/product/0975568612?ie=UTF8&amp;tag=netbooks00&amp;linkCode=as2&amp;camp=1789&amp;creative=390957&amp;creativeASIN=0975568612">The Visible Ops Handbook: Implementing ITIL in 4 Practical and Auditable Steps</a><img style="border:none !important; margin:0px !important;" src="http://www.assoc-amazon.com/e/ir?t=netbooks00&amp;l=as2&amp;o=1&amp;a=0975568612" border="0" alt="" width="1" height="1" />, by Kevin Behr, Gene Kim and George Spafford.  The book is a very fast read and will leave you with enough of an understanding of the power of ITIL to let you decide how fast to move your organization into implementing it.</p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_7" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2012/01/learn-how-to-get-ready-for-the-fdcci-with-bob-gourley-and-carahsoft-webinar/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/6c28995e938ae95f98172682a939d4c1_thumb_vi-and-carahsoft.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Learn how to get ready for the FDCCI with Bob Gourley and Carahsoft (Webinar)</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/11/disruptive-it-list-update-watching-several-dramatically-positive-technologies/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/c8f97a81f16a33cc51ca7ad467c775af_thumb_disruptiveIT-300x201.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Disruptive IT List Update: watching several dramatically positive technologies</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/07/google-announces-apps-for-government-more-choices-for-gov-ctocios/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/9a6d316c394e41f71b79b9899c199a2c_thumb_google_apps-300x283.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Google Announces Apps for Government: More choices for gov CTO/CIOs.</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/survey-says-security-risks-never-higher-or-more-costly/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/1566bfe294df4cdcb855d28ec73cb69a_thumb_protect-e1319104550402.jpeg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Survey says: Security risks never higher, or more costly</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/redesign-of-ctolabs-com/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/9dccfb7a04a2201957a4252fa3e285d7_thumb_p1.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Redesign of CTOlabs.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2012/01/from-networks-to-swarms-2/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/blue-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">From Networks to Swarms</span><span class="nr_source">Bob Gourley</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/the-evolving-enterprise-threat-environment/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/wave-open-sea.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The Evolving Enterprise Threat Environment</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/12/if-you-use-hadoop-you-have-been-waiting-for-this-cloudera-enterprise-3-7/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/blue-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">If You Use Hadoop You Have Been Waiting For This: Cloudera Enterprise 3.7</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/01/learn-lessons-on-the-fdcci-with-bob-gourley-and-carahsoft-webinar/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-macro-plant.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Learn Lessons On The FDCCI with Bob Gourley and Carahsoft (Webinar)</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2012/01/join-cloudera-and-carahsoft-for-big-data-success-in-government/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/stone-wall-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Join Cloudera and Carahsoft for Big Data Success in Government</span><span class="nr_source">Bob Gourley</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=ITIL+for+CTOs&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2008%2F06%2Fitil-for-ctos%2F&nr_ad_number=0&nr_div_number=7");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_7");nRelate.adAnimation("nrelate_related_7");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2008/06/itil-for-ctos/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>CMU: An impressive resource</title>
		<link>http://ctovision.com/2008/06/cmu-an-impressive-resource/</link>
		<comments>http://ctovision.com/2008/06/cmu-an-impressive-resource/#comments</comments>
		<pubDate>Sun, 08 Jun 2008 00:59:44 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[DHS]]></category>
		<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[standards]]></category>
		<category><![CDATA[Tech/Internet]]></category>
		<category><![CDATA[Technology Leadership]]></category>
		<category><![CDATA[vmware]]></category>
		<category><![CDATA[Web/Tech]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=67</guid>
		<description><![CDATA[Tweet I recently finished a visit to one of our nation&#8217;s greatest intellectual resources, the school of computer science at Carnegie Mellon University.   The incredible work being accomplished at the university includes the globally famous Software Engineering Institute and the equally renowned CERT/CC.  CMU also serves the nation by hosting and supporting Cylab.   More on [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2008%2F06%2Fcmu-an-impressive-resource%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2008/06/cmu-an-impressive-resource/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2008/06/cmu-an-impressive-resource/"  data-text="CMU: An impressive resource" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2008/06/cmu-an-impressive-resource/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2008/06/cmu-an-impressive-resource/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>I recently finished a visit to one of our nation&#8217;s greatest intellectual resources, the school of computer science at Carnegie Mellon University.   The incredible work being accomplished at the university includes the globally famous Software Engineering Institute and the equally renowned CERT/CC.  CMU also serves the nation by hosting and supporting Cylab.   More on each of these is below.</p>
<p>SEI is a Federally Funded Research and Development Center (FFRDC).  SEI processes and practices, which are almost certainly familiar to readers of this blog, are now being taught at universities everywhere.  Their comprehensive approach to quality is being used today by development organizations around the world and is producing fantastic results.  There are many reasons for this, but the short version is that SEI processes like the Capability Maturity Model Integration (CMMI), the Team Software Process (TSP) and the Software Engineering Measurement and Analysis (SEMA) have proven to enhance the quality and performance of software activities while reducing cost and development time.  <a href="http://www.sei.cmu.edu" target="_blank">Read more at: http://www.sei.cmu.edu. </a></p>
<p>The CERT/CC is a group I first stared working with in December 1998 when I was one of the startup grew of the JTF-CND.  I&#8217;ve been a big fan of them sever since, and have tried to track what was going on there, but frankly I lost touch and am really glad I got the in person update.  The CERT/CC is a critical enabler of hte IT industry&#8217;s ability to detect and remediate vulnerabilities, conduct computer forensics, visualize cyber information, and respond to incidents of every scale.  For more on the CERT <a href="http://cert.org" target="_blank">read more at: http://cert.org</a>.</p>
<p>The Cylab is the nation&#8217;s largest university based research and education program focused on cyber security, dependability and privacy.  Cylab conducts sponsored research as one of the <a href="http://www.nsf.gov/funding/pgm_summ.jsp?pims_id=13451" target="_blank">NSF CyberTrust</a> centers.  According to the CyLab website:</p>
<p>The CyLab Strategy is to integrate response, prediction, research  and development, and education both nationally and internationally and  build capacity in:</p>
<ul>
<li><strong>Technology </strong>– by pursuing an aggressive, highly  interdisciplinary research and development agenda that integrates  technology, policy, and management</li>
<li><strong>Human Resources </strong>– by educating professionals in Information Technologies, Business, and Policy, and by creating “cyber-aware” citizens worldwide</li>
<li><strong>Industry </strong>– by transitioning technologies to large, medium, and small companies and by creating start-ups</li>
</ul>
<p><strong style="font-family: yui-tmp;"> </strong>For more on the Cylab<a href="http://www.cylab.cmu.edu/" target="_blank"> read more at: http://www.cylab.cmu.edu/.</a></p>
<p>Thanks to all at CMU for doing what you do, it is really appreciated by computer scientists, CTOs and leaders everywhere.  Please keep it up.</p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_8" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/03/wanted-world-class-best-enterprise-cto/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/e952fd3790e6691d1713bf7c788699ac_thumb_sei-generic-5.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Wanted: World Class Best Enterprise CTO</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/04/twiki-and-gov2-0-innovative-open-architecture-platform-and-solutions/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/water-wallpaper.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Twiki and Gov2.0: Innovative Open Architecture Platform and Solutions</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/cmu-cyber-researcher-to-get-presidential-award/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-red.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">CMU cyber researcher to get presidential award</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/ttps-cradas-mrm-and-fixmo/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/art-rhododendron-flower.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">TTPs, CRADAs, MRM, and Fixmo</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=CMU%3A+An+impressive+resource&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2008%2F06%2Fcmu-an-impressive-resource%2F&nr_ad_number=0&nr_div_number=8");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_8");nRelate.adAnimation("nrelate_related_8");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2008/06/cmu-an-impressive-resource/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

