SP 800-128, Guide for Security-Focused Config Management of Info Systems | CSRC
https://csrc.nist.gov/publications/detail/sp/800-128/final
https://csrc.nist.gov/publications/detail/sp/800-128/final
CSRC | NIST
NIST Special Publication (SP) 800-128, Guide for Security-Focused Configuration Management of Information Systems
The purpose of Special Publication 800-128, Guide for Security-Focused Configuration Management of Information Systems, is to provide guidelines for organizations responsible for managing and administering the security of federal information systems and associated…
Хорошая статья сравнения требований по анализу уязвимостей по общим критериям и их усилением по требованиям ЦБ РФ.
Forwarded from ZLONOV security
Gartner Magic Quadrants за первые три квартала 2019 года https://zlonov.ru/gartner-magic-quadrants-2019-q1-q3/
SP 800-189 (Draft), Resilient Interdomain Traffic Exchange | CSRC
https://csrc.nist.gov/publications/detail/sp/800-189/draft
https://csrc.nist.gov/publications/detail/sp/800-189/draft
CSRC | NIST
NIST Special Publication (SP) 800-189 (Draft), Secure Interdomain Traffic Exchange: BGP Robustness and DDoS Mitigation
This document gives technical guidelines and recommendations for secure interdomain traffic exchange. The primary audience include information security specialists and network managers. These guidelines apply to routing and Internet transit service infrastructure…
Радикальный подход-переход в облако как способ избавится от накопленного технического долга в безопасности.
Неоднозначное решение администрации города.
Отдельно эксперты обращают внимание, что скорее всего стоимость страховки больше бюджета на ИБ.
Baltimore Authorizes Purchase of $20M Cyberinsurance Policy
https://www.govtech.com/security/Baltimore-Authorizes-Purchase-of-20M-Cyberinsurance-Policy.html
Отдельно эксперты обращают внимание, что скорее всего стоимость страховки больше бюджета на ИБ.
Baltimore Authorizes Purchase of $20M Cyberinsurance Policy
https://www.govtech.com/security/Baltimore-Authorizes-Purchase-of-20M-Cyberinsurance-Policy.html
GovTech
Baltimore Authorizes Purchase of $20M Cyberinsurance Policy
Months after a ransomware attack cost the city around $18 million, officials approved the purchase of a cyberliability policy to help with any future incidents. The move is one being made by governments across the U.S.
Democratic senator introduces bill to jail tech executives for lying about privacy violations | TheHill
https://thehill.com/policy/technology/466283-democratic-senator-introduces-bill-to-jail-tech-executives-for-lying-about
https://thehill.com/policy/technology/466283-democratic-senator-introduces-bill-to-jail-tech-executives-for-lying-about
TheHill
Democratic senator introduces bill to jail tech executives for lying about privacy violations
Sen. Ron Wyden (D-Ore.), one of the toughest tech critics in Congress, on Thursday introduced his long-awaited bill that would jail tech executives for lying to the government about privacy
Ещё раз - в США обсуждается возможность уголовки для директоров за нарушение требований приватности пользователей и утечку ПДн.