<?xml version='1.0' encoding='UTF-8'?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-2769126005503757042</id><updated>2008-08-29T15:30:22.953-07:00</updated><title type='text'>IT Policy at LBL, Berkeley Lab</title><subtitle type='html'>Office of the Liaison Policy Blog for Information Technology Policy issues at LBL including FISMA, Clinger-Cohen, Enterprise Architecture, University of California IT Policy, Security, Cybersecurity, and more.  Disclaimer: Some components of this blog may not represent the official position of the University or the CIO and they most certainly do not represent the position of the DOE.</subtitle><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/blog.html'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default?start-index=26&amp;max-results=25'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default'/><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>28</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-2878029816700332315</id><published>2008-08-29T15:04:00.000-07:00</published><updated>2008-08-29T15:30:22.967-07:00</updated><title type='text'>Historical Contract Trivia</title><content type='html'>My work today involved some contract perusal, which always turns up interesting things.  It would be fascinating to find out when these three first turned up in Lab M&amp; Contracts.&lt;br /&gt;&lt;br /&gt;1. Clause I.20&lt;br /&gt;Except as provided in paragraph (b) of this clause, the Contractor shall not employ in the performance of this contract any person undergoing a sentence of imprisonment imposed by any court of a State, the District of Columbia, Puerto Rico, the Northern Mariana Islands, American Samoa, Guam, or the U.S. Virgin Islands. &lt;br /&gt;&lt;br /&gt;2. I.23&lt;br /&gt;The Contractor agrees that it does not and will not maintain or provide for its employees any segregated facilities at any of its establishments, and that it does not and will not permit its employees to perform their services at any location under its control where segregated facilities are maintained.  The Contractor agrees that a breach of this clause is a violation of the Equal Opportunity clause in this contract.&lt;br /&gt;&lt;br /&gt;3. I.25&lt;br /&gt;It is a violation of Executive Order 11246 for a Contractor to refuse to employ any applicant or not to assign any person hired in the United States, Puerto Rico, the Northern Mariana Islands, American Samoa, Guam, the U.S. Virgin Islands, or Wake Island, on the basis that the individual’s race, color, religion, sex, or national origin is not compatible with the policies of the country where or for whom the work will be performed (41 CFR 60-1.10).  &lt;br /&gt;Adam Note: Does this apply to the USG?</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2008/08/that-wacky-contract.html' title='Historical Contract Trivia'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=2878029816700332315' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/2878029816700332315'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/2878029816700332315'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-2542017191077902823</id><published>2008-07-30T09:37:00.000-07:00</published><updated>2008-07-30T09:38:43.316-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='fisma'/><title type='text'>We put the fun in federally funded.</title><content type='html'>New motto for the Policy, Assurance, and Risk Management function of LBL.</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2008/07/we-put-fun-in-federally-funded.html' title='We put the fun in federally funded.'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=2542017191077902823' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/2542017191077902823'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/2542017191077902823'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-1799114900278696317</id><published>2008-07-29T09:51:00.000-07:00</published><updated>2008-07-29T09:53:48.738-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='pra'/><category scheme='http://www.blogger.com/atom/ns#' term='fisma'/><category scheme='http://www.blogger.com/atom/ns#' term='agency'/><category scheme='http://www.blogger.com/atom/ns#' term='clinger cohen'/><title type='text'>Why doesn't anyone remember what an agency is?</title><content type='html'>Basically every law before FISMA rationally makes a distinction between National Labs and Feds.  FISMA does too, it's just that everyone behaves as if it's not true.&lt;br /&gt;Repeat after me: An M&amp;O Contractor is not a "Contractor".&lt;br /&gt;  &lt;br /&gt;&lt;br /&gt;(1) the term "agency" means any executive department, military department, Government corporation, Government controlled corporation, or other establishment in the executive branch of the Government (including the Executive Office of the President), or any independent regulatory agency, but does not include--&lt;br /&gt;&lt;br /&gt;    (A) the General Accounting Office;&lt;br /&gt;&lt;br /&gt;    (B) Federal Election Commission;&lt;br /&gt;&lt;br /&gt;    (C) the governments of the District of Columbia and of the territories and possessions of the United States, and their various subdivisions; or&lt;br /&gt;&lt;br /&gt;    (D) Government-owned contractor-operated facilities, including laboratories engaged in national defense research and production activities;</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2008/07/why-doesnt-anyone-remember-what-agency.html' title='Why doesn&apos;t anyone remember what an agency is?'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=1799114900278696317' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/1799114900278696317'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/1799114900278696317'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-3102894384086934211</id><published>2008-07-08T08:47:00.000-07:00</published><updated>2008-07-08T08:50:02.001-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='badblogger'/><category scheme='http://www.blogger.com/atom/ns#' term='pemp'/><title type='text'>Blogging is hard.</title><content type='html'>My new FY resolution is more consistent blogging.&lt;br /&gt;In the meantime, by way of an update, I am working on:&lt;br /&gt;1. Access without consent policy and procedure&lt;br /&gt;2. Rewrite of 1.01 and 5.0X of the RPM.&lt;br /&gt;3. Campus Calnet/Cal1 integration issues&lt;br /&gt;4. FY09 PEMP Contract Measure Negotiations&lt;br /&gt;5. PII Training</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2008/07/blogging-is-hard.html' title='Blogging is hard.'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=3102894384086934211' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/3102894384086934211'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/3102894384086934211'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-7389109527090045854</id><published>2008-05-22T17:56:00.001-07:00</published><updated>2008-05-22T17:58:31.456-07:00</updated><title type='text'>Denial of Service</title><content type='html'>The largest and most sophisticated denial of service attack I am aware of occupied the National Laboratories yesterday.  Would you care to guess who did it?</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2008/05/denial-of-service.html' title='Denial of Service'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=7389109527090045854' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/7389109527090045854'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/7389109527090045854'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-5185677288841142978</id><published>2008-05-07T10:28:00.000-07:00</published><updated>2008-05-07T10:33:40.002-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='laboratories'/><category scheme='http://www.blogger.com/atom/ns#' term='fisma'/><category scheme='http://www.blogger.com/atom/ns#' term='doe nsf'/><title type='text'>Live from the NSF Large Facilities Conference</title><content type='html'>I'm in DC for the NSF Large Facilities Security conference.  Excellent keynotes this morning (if a little depressing) and an enjoyable roundtable going on now.  More on these a bit later, but in the meantime, here is the entirety of the NSF regulation on cyber security:&lt;br /&gt;&lt;br /&gt;54.&lt;br /&gt;Information Security&lt;br /&gt;Security for all information technology (IT) systems employed in the performance of this award, including equipment and information, is the awardee’s responsibility. Within a time mutually agreed upon by the awardee and the cognizant NSF Program Officer, the awardee shall provide a written Summary of the policies, procedures, and practices employed by the awardee’s organization as part of the organization’s IT security program, in place or planned, to protect research and education activities in support of the award.&lt;br /&gt;The Summary shall describe the information security program appropriate for the project including, but not limited to: roles and responsibilities, risk assessment, technical safeguards, administrative safeguards, physical safeguards, policies and procedures, awareness and training, and notification procedures in the event of a cyber-security breach. The Summary shall include the institution’s evaluation criteria that will measure the successful implementation of the IT Security Program.&lt;br /&gt; In addition, the Summary shall address appropriate security measures&lt;br /&gt;required of all subawardees, subcontractors, researchers and others who will have access to the systems employed in support of this award.&lt;br /&gt;The Summary will be the basis of a dialog which NSF will have with the awardee, directly or through community meetings. Discussions will address a number of topics, such as, but not limited to, evolving security concerns and concomitant cyber-security policy and procedures within the government and at awardees' institutions, available education and training activities in cyber-security, and coordination activities among NSF awardees. &lt;br /&gt;&lt;br /&gt;Why can't DOE have this?</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2008/05/live-from-nsf-large-facilities.html' title='Live from the NSF Large Facilities Conference'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=5185677288841142978' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/5185677288841142978'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/5185677288841142978'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-4749673168653119380</id><published>2008-04-26T12:21:00.000-07:00</published><updated>2008-04-26T12:42:32.892-07:00</updated><title type='text'>Random Bits</title><content type='html'>Upcoming:&lt;br /&gt;Co-facilitating with Aaron from PSC the "Building an Effective Security Program" breakout at the NSF Large Facilities conference.  It's nice that the topic is so clearly defined and narrow (!).  &lt;br /&gt;&lt;br /&gt;At NLIT 2008, something about federated identity management - but I haven't exactly figured out what yet.  &lt;br /&gt;&lt;br /&gt;Speaking of NLIT, we have way too many things that begin with NL now, most of them unpronounceable.  NLDC, NLCC, NLCIO, NLIT, NLCRO, NLCOO..  they need to take some lessons from DOD on pronounceable (and badass) acronyms.&lt;br /&gt;&lt;br /&gt;Random Bits:&lt;br /&gt;I really enjoyed the discussion &lt;a href="http://listserv.educause.edu/cgi-bin/wa.exe?A2=ind0804&amp;L=security&amp;T=0&amp;F=&amp;S=&amp;P=29402"&gt;here&lt;/a&gt; about blocking outbound SMTP.  When you get halfway through the UC people really come out in force against the trend towards locking things down in a research setting.  Mother May I is not a good game to play with researchers, unless you can make it extraordinarily transparent and simple. &lt;br /&gt;&lt;br /&gt;Finally, all of our colleagues in both R&amp;E and .gov are struggling with what to do about new rounds of highly targeted phishing. It isn't clear to me where this ends. You can train people to avoid paypal phishing, but this new stuff isn't nearly so straightforward.  And as we found the last time we really stepped up awareness on this issue, making people overly fearful of email doesn't exactly do the institution any favors either.  As in all things security, it's a delicate balance - but the risk is clearly shifting again.</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2008/04/random-bits.html' title='Random Bits'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=4749673168653119380' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/4749673168653119380'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/4749673168653119380'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-2459131437374210329</id><published>2008-02-22T08:49:00.000-08:00</published><updated>2008-03-14T11:19:38.946-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ca'/><category scheme='http://www.blogger.com/atom/ns#' term='fisma'/><category scheme='http://www.blogger.com/atom/ns#' term='federal policy'/><category scheme='http://www.blogger.com/atom/ns#' term='doe'/><title type='text'>NIST it by that much redux.</title><content type='html'>Steve Lau and my talk at Internet2, NIST It By That Much, is looking more perceptive by the day.  The Department of Energy Office of the CIO has released hundreds of page of new draft policy which, in my opinion, misunderstands NIST in precisely the way we described: it fails to recognize that the NIST documents create a baseline of controls from which you as the system owner are supposed to tailor your set of controls, NIST 800-53 is a baseline, not a set of minimum security standards for all systems. &lt;br /&gt;&lt;br /&gt;The critical step in the NIST C&amp;amp;A process is "Tailoring the Baseline".  This is where NIST moves from a set of well founded but ultimately arbitrary checklists, to something of value.  When you tailor the baseline you start with the prescribed NIST baseline, then use scoping guidance, compensating controls, and parameterization to created an initial tailored baseline.  These three activities allow you to customize the set of controls for your environment.  With that tailored baseline in mind, you assess the remaining residual risk.  If that risk is unacceptable, you go back to tailoring the baseline again.&lt;br /&gt;&lt;br /&gt;The new DOE CIO Policies attempt to turn 800-53 into a set of Minimum Security Standards across the Department of Energy.  The problem is that 800-53 is not a set of Minimum Standards, it's a catalog of controls from which you adopt the ones that are right for your system and its level of risk.   Unfortunately, the concept of a tailored baseline doesn't exist in these new documents.&lt;br /&gt;&lt;br /&gt;More on tailoring:&lt;br /&gt;&lt;br /&gt;&lt;iframe src='http://docs.google.com/EmbedSlideshow?docid=d3bkm36_0w6rkmc' frameborder='0' width='410' height='342'&gt;&lt;/iframe&gt;</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2008/02/nist-it-by-that-much-redux.html' title='NIST it by that much redux.'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=2459131437374210329' title='1 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/2459131437374210329'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/2459131437374210329'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-5692679745842833136</id><published>2008-01-17T13:53:00.000-08:00</published><updated>2008-01-17T14:09:11.597-08:00</updated><title type='text'>A hundred small conservative decisions, and the impact on science.</title><content type='html'>Yesterday, I played a bit with some lightweight coding (which is neither my job nor my expertise).  I was quite unsuccessful in getting my little project to work, but about half way through I realized that while I might be able to get the program to work, my code was certainly not going to be secure.  I realized that even if I got it working, I wouldn't put it on an LBL server because of the off chance that it might be hacked.&lt;br /&gt;&lt;br /&gt;You may think this is a morality tale about the importance of thinking about security, but in fact, it's almost the reverse. The truth is that my insecure code would have posed a very limited risk to the Lab, and if it had been exploited (unlikely) it would have done almost no damage to turn it off and clean it up.  Yet, because of the attention to security, the perceptual risk is far greater then the real one.&lt;br /&gt;&lt;br /&gt;Every day, a few thousand scientists - those the organization selects for their ability to ask new questions in new ways and to develop new tools to ask those questions - are faced with this same issue.  And every day, perhaps a few small decisions are made to be conservative and not attempt to create the tool, try the new thing, or play with something interesting because of these kinds of worries.  The losses from this behavior are unknown to us, they may be imperceptible, or they may be substantial.  What we know is that the great research institutions in history have valued an atmosphere of open expression and freedom to explore the new, the unproven, and the risky. &lt;br /&gt;&lt;br /&gt;Will the next World Wide Web or Cyclotron go unbuilt because a researcher feared what might happen if they didn't implement it securely?</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2008/01/hundred-small-conservative-decisions.html' title='A hundred small conservative decisions, and the impact on science.'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=5692679745842833136' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/5692679745842833136'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/5692679745842833136'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-994802174372057163</id><published>2008-01-17T13:43:00.000-08:00</published><updated>2008-01-17T13:53:10.650-08:00</updated><title type='text'>First Quarter Preliminary Reportcards</title><content type='html'>We are now publishing our quarterly scorecards for the UC/DOE Contract for both IT and Cyber-Security.  You can find the first quarter reports under the &lt;a href="http://lbl.gov/CIO/Assurance/"&gt;Assurance&lt;/a&gt; section. &lt;br /&gt;&lt;br /&gt;Current policy projects include: revisiting non-consensual access, improving our assurance-crosswalk, and updating 9.02.&lt;br /&gt;&lt;br /&gt;Current audit-management projects include the Internal Audit of data centers (ongoing), and continued response to both the draft IG Websites audit (see blog post) and related impacts from the previously published IG IT Hardware Audit (which we vehemently disagree with).&lt;br /&gt;&lt;br /&gt;Current DOE policy projects include RevCom for the newly released 200.1A.&lt;br /&gt;&lt;br /&gt;Current Contract-Management task: negotiation around the incorporation of the DOE Privacy Reporting directive, which we believe is duplicative with State Law (SB1386) and in conflict with other prime contract clauses.&lt;br /&gt;&lt;br /&gt;Current Process Improvement Goals: Business Continuity Planning</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2008/01/first-quarter-preliminary-reportcards.html' title='First Quarter Preliminary Reportcards'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=994802174372057163' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/994802174372057163'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/994802174372057163'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-6628143941003925289</id><published>2007-12-19T06:59:00.000-08:00</published><updated>2007-12-19T07:10:27.479-08:00</updated><title type='text'>Winter Reading List</title><content type='html'>After some recent discussions with a colleague, I was prompted to compose the following:&lt;br /&gt;&lt;br /&gt;Required Reading List for Those Working at LBL&lt;br /&gt;(best for those in operations and management, but useful for all).&lt;br /&gt;&lt;br /&gt;Number 1&lt;br /&gt;Objective: Gain an understanding of the core governance problems between the National Laboratories and the Department of Energy&lt;br /&gt;Reading: Galvin Report&lt;br /&gt;Focus On: Governance issues, oversight issues, Directives.&lt;br /&gt;Location: http://www.lbl.gov/LBL-PID/Galvin-Report/Galvin-Report.html&lt;br /&gt;&lt;br /&gt;Number 2&lt;br /&gt;Objective: Gain an appreciation for the history of LBL vis a vis DOE / Manhattan Project / etc.&lt;br /&gt;Reading: Brotherhood of the Bomb&lt;br /&gt;Focus On: Historical administration, relationship between DOE precursors and National Labs, Development of Military Industrial Science Complex&lt;br /&gt;Location: Library&lt;br /&gt;&lt;br /&gt;Number 3&lt;br /&gt;Objective: Understand LBL Position on Management Challenges and Improvement Opportunities Between DOE and M&amp;amp;O Contractors&lt;br /&gt;Reading: LBL/DOE Best Practices Study&lt;br /&gt;Focus On: Alternative Governance Models, NCAR&lt;br /&gt;Location: http://www.lbl.gov/Workplace/Ops/assets/docs/best_practices.pdf&lt;br /&gt;&lt;br /&gt;Number 4&lt;br /&gt;Objective: Understand How Organizational Responses to Regulation and Oversight in National Laboratories Impact Compliance and Assurance&lt;br /&gt;Reading: Regulatory Ecology: Strategy, Compliance, and Assurance in Complex Organizations&lt;br /&gt;Focus On: Motivation of Internal Regulator Proxies, Communication Challenges&lt;br /&gt;Location: Forthcoming (my dissertation).</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2007/12/winter-reading-list.html' title='Winter Reading List'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=6628143941003925289' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/6628143941003925289'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/6628143941003925289'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-5105626558169047552</id><published>2007-12-13T13:17:00.000-08:00</published><updated>2007-12-13T13:26:59.621-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='fisma'/><category scheme='http://www.blogger.com/atom/ns#' term='oig'/><category scheme='http://www.blogger.com/atom/ns#' term='audits'/><title type='text'>Audit of the Department's Websites</title><content type='html'>The OIG has a draft out of their Audit of the Department's websites.  Unfortunately, the cover letter asks that the draft not be shared.  However, our response to the draft report can be shared (or in this case summarized).&lt;br /&gt;&lt;br /&gt;LBL requires that all systems, whether they are workstations, servers, devices, microscopes, PDAs, or webservers, be managed in an appropriate, secure manner which integrates security into the lifecycle.&lt;br /&gt;&lt;br /&gt;This approach is consistent with the philosophy that line management owns security - we want to push responsibility for appropriate configuration to the person responsible for using and managing the machine.  This approach is also consistent with how most large research Universities manage websites (many servers, run at the Department or project level). &lt;br /&gt;&lt;br /&gt;It is not consistent with the view that consolidation is always superior to decentralization.</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2007/12/audit-of-departments-websites.html' title='Audit of the Department&apos;s Websites'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=5105626558169047552' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/5105626558169047552'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/5105626558169047552'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-8077759224284635820</id><published>2007-12-11T12:07:00.000-08:00</published><updated>2007-12-11T12:08:21.031-08:00</updated><title type='text'>This is a test.</title><content type='html'>This is a test of some new monitoring ideas we have been working on.  XXX Viagra&lt;br /&gt;We now return you to your regularly scheduled blog and apologize for the spammy words.</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2007/12/this-is-test.html' title='This is a test.'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=8077759224284635820' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/8077759224284635820'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/8077759224284635820'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-5222803637410913175</id><published>2007-12-03T20:11:00.000-08:00</published><updated>2007-12-03T20:15:03.778-08:00</updated><title type='text'>UC Trust</title><content type='html'>UC Trust is an identity federation for the University of California, based on InCommon.  Since it is becoming more a part of UCOP's central services plans, this post is really designed to be a googleable thing for people in Ops (or elsewhere) who might need to know who to contact.  Answer: cppm</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2007/12/uc-trust.html' title='UC Trust'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=5222803637410913175' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/5222803637410913175'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/5222803637410913175'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-2817615173547419456</id><published>2007-11-28T10:34:00.000-08:00</published><updated>2007-11-28T10:40:01.784-08:00</updated><title type='text'>Reminder: Credit Card Numbers Are Account Numbers (and thus not permitted in non-business systems).</title><content type='html'>A quick reminder that credit card numbers are protected PII at LBNL.  This means that credit card numbers, and devices which collect them, are &lt;span style="font-weight: bold;"&gt;only &lt;/span&gt;permitted in the web-facing Institutional Business Systems.  You may not attach a credit card terminal to any LBNL network, nor collect credit card numbers of LBNL workstations or servers (except those managed as part of the Business Systems).  More info: http://www.lbl.gov/CIO/Privacy/</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2007/11/reminder-credit-card-numbers-are.html' title='Reminder: Credit Card Numbers Are Account Numbers (and thus not permitted in non-business systems).'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=2817615173547419456' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/2817615173547419456'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/2817615173547419456'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-6486932647385402260</id><published>2007-11-18T12:22:00.000-08:00</published><updated>2007-11-18T12:30:36.691-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='hipaa'/><category scheme='http://www.blogger.com/atom/ns#' term='fisma'/><category scheme='http://www.blogger.com/atom/ns#' term='cyber security policy'/><title type='text'>Impact of HIPAA on US Medical / Public Health Research</title><content type='html'>Interesting article in Science this week reporting on a study in JAMA on the impact of the HIPAA Privacy Rule on Epidemiological researchers:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;About 68% said the Privacy Rule has made research a great deal more difficult; half reported major delays; and nearly 40% faced much higher costs (see table). Only one-quarter said the rule has greatly improved confidentiality. Of those who modified a protocol to comply with HIPAA, two-thirds said it was much harder to recruit subjects.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;/span&gt;The article goes on to talk about how the impacts come not just from the actual rule, but from uncertainty about how to apply the rule and, of course, cautiousness (risk-aversion).&lt;br /&gt;&lt;br /&gt;For those who follow the micro-level of cyber security policy, this is not surprising but is always worth paying attention to.  The impact of cyber security policy is not just felt in the rule itself, but in uncertainty regarding how far to take it and the over-cautiousness some rules and organizational relationships seem to impart.&lt;br /&gt;&lt;br /&gt;Obviously, we want end users and developers to be aware of the risks they face, but in a research environment, the impact of this kind of uncertainty can lead to direct impacts on innovation and effective research.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2007/11/impact-of-hipaa-on-us-medical-public.html' title='Impact of HIPAA on US Medical / Public Health Research'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=6486932647385402260' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/6486932647385402260'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/6486932647385402260'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-1554151097849151337</id><published>2007-11-09T11:37:00.000-08:00</published><updated>2007-11-09T13:41:11.029-08:00</updated><title type='text'>RPM 5.02 Updated</title><content type='html'>We have updated RPM 5.02 on scientific and technical publications, mostly for readability and clarification.  As you may or may know, the policy on division review (that is, review of published work within divisions) was modified after almost a year of discussion.  The final version was approved by the SLC.   That modification clarified the expectations for internal review of published work as follows:&lt;br /&gt;&lt;br /&gt;&lt;h3 style="font-style: italic;"&gt; &lt;a name="RTFToC9"&gt;E. REVIEW OF SCIENTIFIC AND TECHNICAL PUBLICATIONS &lt;/a&gt;&lt;/h3&gt; &lt;p style="font-style: italic;"&gt;LBNL values the role of peer review   in ensuring the integrity of scientific research. Researchers are expected   to seek ongoing internal review of their work before publication. It   is expected that employees will adhere to the highest ethical standards in   their publishing, including those detailed in the University’s Statement   of Ethical Values, especially as regards to the integrity and originality of   work, and the recognition of the contributions of colleagues. Researchers   must ensure that any information of a nonpublishable nature (such as that   protected by human subjects protocol or a nondisclosure agreement) is excluded   from publication. Per   &lt;a href="http://www.lbl.gov/Workplace/RPM/R5.03.html"&gt;Section 5.03&lt;/a&gt; of the RPM, researchers   must identify potentially patentable discoveries to the Technology Transfer   and Intellectual Property Management prior to any form of publication.  &lt;/p&gt; &lt;p style="font-style: italic;"&gt;All publications must be reviewed within a division before receiving an LBNL/PUB   or LBID number. Each division will ensure that (1) a reasonable scientific   process has been followed, (2) papers include proper crediting of affiliations   and acknowledgments as required by DOE, and (3) any other requirements   indicated by their Division Director have been met.   Divisional   procedures must ensure that the review is fair and unbiased, and that freedom   of scientific inquiry is not unfairly constrained.&lt;/p&gt;Basically, this policy statement set the minimum expectation for internal division review; a brief review for scientific process, ensuring citations and credit line are correct, and any other expectations set by the Division Director.  It's important to understand that the role previously played by RCO, which attempted to provide assurance of some of these things, will now entirely be the responsibility of the divisions.&lt;br /&gt;&lt;br /&gt;There are some potential pitfalls to avoid with regards to the internal division procedures.  Specifically, it's important to avoid any potential discriminatory biases in the review, as well as avoid the appearance of any kind of review for certain kinds of content.  This is further explained&lt;a href="http://www.lbl.gov/CIO/Policy/Publications/"&gt; here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Further guidance is also forthcoming on the RCO Website.</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2007/11/rpm-502-updated.html' title='RPM 5.02 Updated'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=1554151097849151337' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/1554151097849151337'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/1554151097849151337'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-3770433591415586009</id><published>2007-10-12T08:19:00.001-07:00</published><updated>2007-10-12T08:41:41.886-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='nih'/><category scheme='http://www.blogger.com/atom/ns#' term='incommon'/><category scheme='http://www.blogger.com/atom/ns#' term='limiting'/><category scheme='http://www.blogger.com/atom/ns#' term='internet2'/><category scheme='http://www.blogger.com/atom/ns#' term='feds'/><category scheme='http://www.blogger.com/atom/ns#' term='uc'/><category scheme='http://www.blogger.com/atom/ns#' term='uctrust'/><category scheme='http://www.blogger.com/atom/ns#' term='nasa'/><title type='text'>Internet2 Report</title><content type='html'>I was at the Internet2 conference in San Diego this week, presenting on the R&amp;amp;E view of the Federal Cyber Security Picture.  While it wasn't clear that this was the right audience for this talk (note to program committee), the other talks I attended were excellent and a stark contrast to the somewhat gloomy federal picture.&lt;br /&gt;&lt;br /&gt;In particular, it's inspiring to see the the cyberinfrastructure that is starting to appear for next generation science applications.  At the keynote, a 9.8gig virtual circuit was deployed between Fermi and U. Wisconsin as the prototype for the LHC data flows.  The virtual circuit crossed Internet2, ESnet, and the RON that serves U. Wisconsin.  The technology underlying this was developed by the R&amp;amp;E networks (ESnet, I2, and I2 members) and the institutions themselves (Fermi, for instance, helped to develop the scheduler).  This is a remarkable achievement and is a testament to the power of self-organization within the research community.&lt;br /&gt;&lt;br /&gt;It also stands in stark contrast to Federal efforts to consolidate and separate federal networks from other networks.  While this may or may not work well for traditional parts of the government, for the research community (DOE Labs, NASA, parts of NIH) it would be an unmitigated disaster.  This is because the underlying assumption (that components of government agencies talk to each other and that this needs to be protected) is not the reality of science collaboration.  The DOE labs talk to each other, but they mostly talk to external Universities and International Collaborators.  And of course, when I say "talk" I mean at speeds and data flows that dwarf nearly all commercial and government data traffic in this country. (streaming video of keynote &lt;a href="http://winmedia.internet2.edu/fmm07-vod/fmm07-2.wmv"&gt;here)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Some of the proposals assume a world that would be equivalent to the UC campuses trusting each other completely across a regional optical network.  This setup is bad for security and even worse for actual mission, because the underlying assumption - that we mostly talk to each other - is wrong.  It's not just wrong because I say so either - ESnet is a net exporter of data: that is, more data flows between the labs and the R&amp;amp;E community then flows between the labs themselves.&lt;br /&gt;&lt;br /&gt;Other useful stuff from the I2 meeting included discussions with Incommon, which Berkeley Lab is in the process of joining.  Incommon is an R&amp;amp;E identity federation based on Shibboleth, which also forms the basis of the UCTrust federation.  Incommon will eventually allow LBL researchers to authenticate to a variety of resources, perhaps most importantly, NIH Grant Administration tools.  I am generally skeptical of arguments that "having multiple passwords" is a problem worth solving, but this one turns out to be a real issue with some very unique characteristics - it is a problem worth solving.  It will take some time for us to modify some our IDM policies and practices to complete our federation, and this must be prioritized, but we are moving in that direction barring unforeseen technical problems.  (Note to Fed readers: it's not that we are a government institution and need to interact with NIH, it's that we are a research institution that needs to interact with NIH - that is, the critical thing is that we are like any other grantee institution of NIH and need to interact with them as a University grantee does).</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2007/10/internet2-report.html' title='Internet2 Report'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=3770433591415586009' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/3770433591415586009'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/3770433591415586009'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-4620717946428248197</id><published>2007-09-26T10:58:00.000-07:00</published><updated>2007-09-26T11:19:41.885-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ca'/><category scheme='http://www.blogger.com/atom/ns#' term='fisma'/><category scheme='http://www.blogger.com/atom/ns#' term='ATO'/><category scheme='http://www.blogger.com/atom/ns#' term='certification'/><title type='text'>ATO Granted</title><content type='html'>The DOE through its DAA, the Manager of the BSO, has granted all five lbl enclaves new Authorities to Operate good for three years.  This was the penultimate step in what was basically a two year long process throughout the Office of Science, led by SC SIME Mike Robertson, to not only improve cyber security throughout the DOE Office of Science, but to improve it in a way that truly takes advantage of the unique risks, capabilities, and missions of the various Office of Science sites, while still maximizing the similarities of the approach to documentation and risk-assessment.&lt;br /&gt;&lt;br /&gt;The Certification and Accreditation process is described further &lt;a href="http://www.lbl.gov/CIO/Policy/Certification/"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The new ATOs are good through September of 2010.&lt;br /&gt;&lt;br /&gt;Getting this done in a way that actually reflects what we do here is no small feat.  The security teams of the enclaves did an amazing job, as did oversight group at BSO, supported by Oak Ridge and Headquarters - in particular Mike Robertson.&lt;br /&gt;&lt;br /&gt;By the way, I say penultimate because, of course, the process doesn't end with the granting of the ATO.  The continued operation, management, and improvement of LBNL's cyber security program is what the DAA accepts, and that is where the actual productive work of the LBNL cyber security teams resides.</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2007/09/ato-granted.html' title='ATO Granted'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=4620717946428248197' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/4620717946428248197'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/4620717946428248197'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-7990142463017941968</id><published>2007-09-11T10:00:00.000-07:00</published><updated>2007-09-11T10:16:36.998-07:00</updated><title type='text'>Security Test and Evaluation Complete</title><content type='html'>The ST&amp;E vendor completed our external security test and evaluation and we received high marks.  There were four issues, two of which were previously identified, which we are now tracking as corrective actions.  The Site Office currently has the full results of our ATO package and we are briefing the site office this week.   More soon.</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2007/09/security-test-and-evaluation-complete.html' title='Security Test and Evaluation Complete'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=7990142463017941968' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/7990142463017941968'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/7990142463017941968'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-5917333171456545133</id><published>2007-08-12T16:01:00.000-07:00</published><updated>2007-08-12T16:07:36.223-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ca'/><category scheme='http://www.blogger.com/atom/ns#' term='fisma'/><category scheme='http://www.blogger.com/atom/ns#' term='compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='ucop'/><category scheme='http://www.blogger.com/atom/ns#' term='certification'/><category scheme='http://www.blogger.com/atom/ns#' term='is-3'/><title type='text'>Contract Measures and C&amp;A</title><content type='html'>Certification and Accreditation process is proceeding apace.  The external auditors are completing their assessment and our documentation is nearly done.&lt;br /&gt;&lt;br /&gt;It's also summer which means its contract performance measures time (PEMP-o-Rama).  We'll be adding our own assurance section to the CIO blog as soon as these are finalized.  Right now, it looks like we'll have a new leadership metric for communication to senior management about cyber security risks and threats, as well as "Section 8" cyber metrics and a new, albeit small, scorecard for IT successes at LBL.&lt;br /&gt;&lt;br /&gt;On the policy front, UCOP issued a whole new set of requirements which are quite well conceived, especially the new IS-3.  We'll be evaluating what, if anything, needs to be done to update our community-facing (RPM) or internal facing (CSPP) policies to reflect the new UC policies in the coming weeks.&lt;br /&gt;&lt;br /&gt;As a final note, the word for the week is: Burdensomeness.</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2007/08/contract-measures-and-c.html' title='Contract Measures and C&amp;A'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=5917333171456545133' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/5917333171456545133'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/5917333171456545133'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-8142197231427017912</id><published>2007-08-05T14:51:00.000-07:00</published><updated>2007-08-05T15:00:23.315-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='fisma'/><title type='text'>Update, C&amp;A, FISMA</title><content type='html'>The auditors we hired to perform our external Security Test and Evaluation for our C&amp;A were onsite last week for the second phase of their testing.  Things seem good and we await their final report. &lt;br /&gt;&lt;br /&gt;I was at the University of California Information Technology Policy and Security in Santa Cruz last week.  Among other interesting topics, some early discussion about the security and policy implications of dedicated on-demand connections of the kind being proposed throughout the R&amp;E community turned out to be very interesting.    Steve Lau and I gave a presentation about NIST and did some theorizing about the misapplication of FISMA to University grants and government partnerships.   If you listen to my &lt;a href="http://connect.educause.edu/blog/mpasiewicz/aninterviewwithadams/1523?time=1186351016"&gt;interview&lt;/a&gt; at Educause 2005, you can hear the outline of the problem we are seeing.&lt;br /&gt;&lt;br /&gt;Basically, as agencies like the VA get into trouble you see broader (and improper) reading of the FISMA "on behalf of" and "government information" definitions, which are so overly broad as to trigger the FISMA requirements in pretty much any situation in which the government is involved (including research grants).   This presents a situation where you might end up doing Certification and Accreditation type processes under small University research environments simply because they receive Federal funds.  Not good.</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2007/08/update-c-fisma.html' title='Update, C&amp;A, FISMA'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=8142197231427017912' title='1 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/8142197231427017912'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/8142197231427017912'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-1249845453154905259</id><published>2007-08-01T14:26:00.000-07:00</published><updated>2007-08-01T14:32:05.394-07:00</updated><title type='text'>e-discovery</title><content type='html'>Since it doesn't appear anywhere else, Nancy Ware is the e-discovery coordinator for LBL.   We have a process in place to analyze and respond to possible e-discovery requests.</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2007/08/e-discovery.html' title='e-discovery'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=1249845453154905259' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/1249845453154905259'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/1249845453154905259'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-9187163608082816041</id><published>2007-07-05T08:43:00.001-07:00</published><updated>2007-07-05T08:58:55.467-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='contingency'/><category scheme='http://www.blogger.com/atom/ns#' term='compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='coop'/><category scheme='http://www.blogger.com/atom/ns#' term='nist'/><category scheme='http://www.blogger.com/atom/ns#' term='disaster recovery'/><title type='text'>Disaster Recovery Testing</title><content type='html'>LBL completed its Contingency Planning / Disaster Recovery testing cycle for the year.  This involved multiple technical tests and several large scale tabletops.  Results were reported on July 4, 2007 to BSO and SC-CIO.</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2007/07/disaster-recovery-testing.html' title='Disaster Recovery Testing'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=9187163608082816041' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/9187163608082816041'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/9187163608082816041'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-2769126005503757042.post-4034734089876705951</id><published>2007-06-29T11:56:00.000-07:00</published><updated>2007-06-29T11:59:16.256-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='policy'/><category scheme='http://www.blogger.com/atom/ns#' term='stewardship'/><category scheme='http://www.blogger.com/atom/ns#' term='uc'/><category scheme='http://www.blogger.com/atom/ns#' term='ucop'/><title type='text'>Revised Stewardship "Policy"</title><content type='html'>UCOP has released a new website (draft?) on the Management of Electronic Information Resources which contains what they used to call stewardship requirements and which we still do.  Excerpt:&lt;br /&gt;&lt;p style="font-style: italic;"&gt;The University of California is committed to high standards of excellence for management of its electronic information resources and therefore endorses information technology management practices that uphold principles of academic freedom, shared governance, open access, and privacy. &lt;/p&gt;&lt;p style="font-style: italic;"&gt;Consistent with the University Statement of Ethical Values and Standards of Ethical Conduct, all members of the University community are accountable for compliance with University policies and procedures for management of electronic information resources over which they have jurisdiction or control.&lt;/p&gt;The website contains useful links to all sorts of policies/guidance &lt;a href="http://www.ucop.edu/irc/itsec/uc/mngt_elec_info_resrcs.html"&gt;appropriate to LBNL &gt;&gt;&lt;/a&gt;</content><link rel='alternate' type='text/html' href='http://www.lbl.gov/CIO/Policy/2007/06/revised-stewardship-policy.html' title='Revised Stewardship &quot;Policy&quot;'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2769126005503757042&amp;postID=4034734089876705951' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.lbl.gov/CIO/Policy/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/4034734089876705951'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2769126005503757042/posts/default/4034734089876705951'/><author><name>IT Policy</name><uri>http://www.blogger.com/profile/06075723233695693482</uri><email>noreply@blogger.com</email></author></entry></feed>
