<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Securing the Realm</title>
	<atom:link href="http://securingtherealm.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://securingtherealm.com</link>
	<description>UK Government Cyber Security</description>
	<lastBuildDate>Mon, 06 Feb 2012 14:21:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='securingtherealm.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/a1623722517185d33f45b0d600e8d4b1?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Securing the Realm</title>
		<link>http://securingtherealm.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://securingtherealm.com/osd.xml" title="Securing the Realm" />
	<atom:link rel='hub' href='http://securingtherealm.com/?pushpress=hub'/>
		<item>
		<title>First Set of PSN Roadmaps Published</title>
		<link>http://securingtherealm.com/2012/02/06/first-set-of-psn-roadmaps-published/</link>
		<comments>http://securingtherealm.com/2012/02/06/first-set-of-psn-roadmaps-published/#comments</comments>
		<pubDate>Mon, 06 Feb 2012 13:37:06 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[PSN & GCN]]></category>
		<category><![CDATA[PSN Roadmaps]]></category>

		<guid isPermaLink="false">http://securingtherealm.com/?p=781</guid>
		<description><![CDATA[High level roadmaps indicating the progress of central and non-central Governement departments/organisations on to the PSN service have been relased &#8230;<p><a href="http://securingtherealm.com/2012/02/06/first-set-of-psn-roadmaps-published/">Continue reading &#187;</a></p><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securingtherealm.com&amp;blog=10510641&amp;post=781&amp;subd=securingtherealm&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:left;">High level roadmaps indicating the progress of central and non-central Governement departments/organisations on to the PSN service have been relased by the PSN programme.</p>
<blockquote><p>This publication represents a starting point but nevertheless reflects the extent of commitment now evident across the entire Public Sector.  It’s important that we start to communicate the development of all sides of the PSN marketplace, beginning with our own organisations, so that both public sector and industry can start to see the big picture more clearly.</p></blockquote>
<p><em>comment from Craig Eblett (PSN Programme Director)</em></p>
<p>Links to the reports:<br />
<a title="PSN Central Government Transition Plan as at 31_January 2012" href="http://www.cabinetoffice.gov.uk/sites/default/files/resources/PSN_Central_Government_Transition_Plan_as_at_31_January_2012.pdf">PSN Central Government Transition Plan, as at 31 January 2012</a><br />
<a title="PSN Non Central Government Transition Plan as at 31 January 2012" href="http://www.cabinetoffice.gov.uk/sites/default/files/resources/PSN_Non_Central_Government_Transition_Plan_as_at_31_January_2012.pdf">PSN Non-Central Government Transition Plan, as at 31 January 2012</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/securingtherealm.wordpress.com/781/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/securingtherealm.wordpress.com/781/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/securingtherealm.wordpress.com/781/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/securingtherealm.wordpress.com/781/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/securingtherealm.wordpress.com/781/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/securingtherealm.wordpress.com/781/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/securingtherealm.wordpress.com/781/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/securingtherealm.wordpress.com/781/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/securingtherealm.wordpress.com/781/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/securingtherealm.wordpress.com/781/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/securingtherealm.wordpress.com/781/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/securingtherealm.wordpress.com/781/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/securingtherealm.wordpress.com/781/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/securingtherealm.wordpress.com/781/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securingtherealm.com&amp;blog=10510641&amp;post=781&amp;subd=securingtherealm&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://securingtherealm.com/2012/02/06/first-set-of-psn-roadmaps-published/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9ca4e6f45108d2412d3c9b4105f1004a?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">a CraZy PeNguIn</media:title>
		</media:content>
	</item>
		<item>
		<title>UK Top for Cyber Preparedness</title>
		<link>http://securingtherealm.com/2012/02/05/uk-top-for-cyber-preparedness/</link>
		<comments>http://securingtherealm.com/2012/02/05/uk-top-for-cyber-preparedness/#comments</comments>
		<pubDate>Sun, 05 Feb 2012 10:37:04 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[HMG IA (General)]]></category>
		<category><![CDATA[Cyber Preparedness]]></category>

		<guid isPermaLink="false">http://securingtherealm.com/?p=779</guid>
		<description><![CDATA[According to a recent report comissioned by McAfee, to survey 250 leading authorities and 80 cyber security experts in the public &#8230;<p><a href="http://securingtherealm.com/2012/02/05/uk-top-for-cyber-preparedness/">Continue reading &#187;</a></p><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securingtherealm.com&amp;blog=10510641&amp;post=779&amp;subd=securingtherealm&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>According to a recent report comissioned by McAfee, to survey 250 leading authorities and 80 cyber security experts in the public and private sectors, the UK was awarded 4 stars and ranked top for Cyber preparedness, alongside the USA and Germany.</p>
<p>Recognition was given for the UK&#8217;s new cyber security strategy and the formation of the Office of Cyber Security and Information Assurance (<a href="http://www.cabinetoffice.gov.uk/content/office-cyber-security-and-information-assurance-ocsia" target="_blank">OSCIA</a>), however it did note that the UK has too high a reliance on the private sector.</p>
<p>The report provides the following top ten recommendations to improve cyber prepardness:</p>
<p>1. Build trust between industry and government stakeholders by setting up bodies to share  information and best practices, like the Common Assurance Maturity Model (CAMM) and the Cloud Security Alliance (CSA).</p>
<p>2. Increase public awareness of how individuals can protect their own internet data, and promote cyber-security education and training.</p>
<p>3. New problems and opportunities created by smart phones and cloud computing must be examined. Cloud computing needs an appropriate architecture to achieve optimum security levels.</p>
<p>4. Prioritise information protection, knowing that no one size fits all. The three key goals that need to be achieved are confidentiality, integration and availability in different doses according to the situation.</p>
<p>5. Consider establishing cyber-confidence building measures as an alternative to a global treaty, or at least as a stopgap measure, knowing that many countries view a treaty as unverifiable, unenforceable and impractical.</p>
<p>6. Improve communication between the various communities, from policy-makers to technological experts to business leaders both at national and international levels.</p>
<p>7. Enhance attribution capabilities by investing in new technologies, and establishing rules and standards.</p>
<p>8. Follow the Dutch model of a third party cyber-exchange for improved private-public partnership on internet security.</p>
<p>9. Despite the many practical hurdles in the way of transparency, both for private companies and for governments, find ways of establishing assurance – or trust – through the use of security mechanisms and processes.</p>
<p>10. Move the ball forward and encourage integration of cyber into existing processes and structures. Make sure cyber considerations and investment are present at every level.</p>
<p>Read the full report <a href="http://www.securitydefenceagenda.org/Portals/14/Documents/Publications/SDA_Cyber_report_FINAL.pdf" target="_blank">here</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/securingtherealm.wordpress.com/779/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/securingtherealm.wordpress.com/779/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/securingtherealm.wordpress.com/779/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/securingtherealm.wordpress.com/779/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/securingtherealm.wordpress.com/779/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/securingtherealm.wordpress.com/779/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/securingtherealm.wordpress.com/779/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/securingtherealm.wordpress.com/779/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/securingtherealm.wordpress.com/779/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/securingtherealm.wordpress.com/779/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/securingtherealm.wordpress.com/779/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/securingtherealm.wordpress.com/779/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/securingtherealm.wordpress.com/779/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/securingtherealm.wordpress.com/779/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securingtherealm.com&amp;blog=10510641&amp;post=779&amp;subd=securingtherealm&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://securingtherealm.com/2012/02/05/uk-top-for-cyber-preparedness/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9ca4e6f45108d2412d3c9b4105f1004a?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">a CraZy PeNguIn</media:title>
		</media:content>
	</item>
		<item>
		<title>New Course: IA Protective Monitoring and Incident Management</title>
		<link>http://securingtherealm.com/2012/02/01/new-course-ia-protective-monitoring-and-incident-management-topic-programme-3/</link>
		<comments>http://securingtherealm.com/2012/02/01/new-course-ia-protective-monitoring-and-incident-management-topic-programme-3/#comments</comments>
		<pubDate>Wed, 01 Feb 2012 19:26:18 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[Education & Certification]]></category>
		<category><![CDATA[HMG IA Training]]></category>

		<guid isPermaLink="false">http://securingtherealm.com/?p=773</guid>
		<description><![CDATA[I&#8217;ve just noticed a new course added to the National School of Government IA page:- IA Protective Monitoring and Incident &#8230;<p><a href="http://securingtherealm.com/2012/02/01/new-course-ia-protective-monitoring-and-incident-management-topic-programme-3/">Continue reading &#187;</a></p><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securingtherealm.com&amp;blog=10510641&amp;post=773&amp;subd=securingtherealm&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve just noticed a new course added to the National School of Government IA page:-</p>
<p><strong>IA Protective Monitoring and Incident Management </strong><a href="http://www.nationalschool.gov.uk/programmes/programme.asp?id=22914&amp;tab=1">http://www.nationalschool.gov.uk/programmes/programme.asp?id=22914&amp;tab=1</a></p>
<h2>What you will learn:</h2>
<p>This course will give you an in-depth understanding of the principles policy and issues affecting protective monitoring, forensic readiness and incident management.<br />
At the end of the course you will be able to:</p>
<ul>
<li>describe the purpose of audit</li>
<li>describe government protective monitoring policy</li>
<li>explain how to manage an IA incident</li>
<li>produce a Forensic Readiness plan</li>
<li>describe sanitisation and the issues around re-use of media</li>
<li>describe ways of monitoring compliance, including the IA Maturity Model.</li>
</ul>
<h2>What the programme covers:</h2>
<ul>
<li>Overview of audit</li>
<li>IA protective monitoring policy</li>
<li>System monitoring</li>
<li>Incident management</li>
<li>Backup and data storage</li>
<li>Forensic readiness</li>
<li>Sanitisation</li>
<li>Business continuity and disaster recovery</li>
<li>Compliance and the IA Maturity Model</li>
<li>Service management.</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/securingtherealm.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/securingtherealm.wordpress.com/773/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/securingtherealm.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/securingtherealm.wordpress.com/773/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/securingtherealm.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/securingtherealm.wordpress.com/773/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/securingtherealm.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/securingtherealm.wordpress.com/773/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/securingtherealm.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/securingtherealm.wordpress.com/773/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/securingtherealm.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/securingtherealm.wordpress.com/773/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/securingtherealm.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/securingtherealm.wordpress.com/773/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securingtherealm.com&amp;blog=10510641&amp;post=773&amp;subd=securingtherealm&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://securingtherealm.com/2012/02/01/new-course-ia-protective-monitoring-and-incident-management-topic-programme-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9ca4e6f45108d2412d3c9b4105f1004a?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">a CraZy PeNguIn</media:title>
		</media:content>
	</item>
		<item>
		<title>Government bodies responsible for cyber security</title>
		<link>http://securingtherealm.com/2012/01/31/government-bodies-responsible-for-cyber-security/</link>
		<comments>http://securingtherealm.com/2012/01/31/government-bodies-responsible-for-cyber-security/#comments</comments>
		<pubDate>Tue, 31 Jan 2012 09:00:12 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[HMG Policy]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Government Body]]></category>
		<category><![CDATA[Remit]]></category>
		<category><![CDATA[Roles]]></category>

		<guid isPermaLink="false">http://securingtherealm.com/?p=767</guid>
		<description><![CDATA[Below is a list of the defined roles and remit of the Government bodies responsible for Cyber Security. Policy co-ordination &#8230;<p><a href="http://securingtherealm.com/2012/01/31/government-bodies-responsible-for-cyber-security/">Continue reading &#187;</a></p><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securingtherealm.com&amp;blog=10510641&amp;post=767&amp;subd=securingtherealm&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Below is a list of the defined roles and remit of the Government bodies responsible for Cyber Security.</p>
<p><strong>Policy co-ordination</strong> [<a href="http://www.cabinetoffice.gov.uk/content/office-cyber-security-and-information-assurance-ocsia" target="_blank">Office of Cyber Security and Information Assurace (OSCIA)</a>]<br />
Based in the Cabinet Office and set up at the same time as CSOC (see below) to provide coherence and strategic leadership across the Government’s cyber security policy interests. This includes horizon scanning to consider impact of an evolving cyber landscape for the UK’s cyber security and working with partners across government to identify and implement the appropriate policy responses.</p>
<p><strong>Strategic Analysis</strong> [Cyber Security Operations Centre (CSOC)]<strong><br />
</strong>Established in September 2009 as part of GCHQ with staff from a range of government and other stakeholders.</p>
<p>Provides a hub for strategic analysis of developments in cyberspace and improving the co-ordination of the UK’s response to cyber incidents.</p>
<p>CSOC’s work aims to draw together a range of sources to enable a better understanding of the risks and opportunities of cyberspace, ensure information is coherently distributed to government, industry, international partners and the public and help inform strategic decision making.<strong><br />
</strong></p>
<p><strong>Response &amp; Analysis</strong> [<a href="http://www.govcertuk.gov.uk/" target="_blank">GovCert UK</a> | CERTs | CSIRTUK]<br />
GovCertUK provide response and analysis to the public sector.<br />
CERTs (MOD Computer Emergency Response Teams) provide response to MOD.<br />
CSIRTUK (Combined Security Incident Response Team) provide response and analysis to critical infrastructure providers.</p>
<p><strong>Advice &amp; Guidance</strong> [<a href="http://www.cpni.gov.uk/" target="_blank">CPNI </a>| <a href="http://www.cesg.gov.uk/" target="_blank">CESG</a>]<br />
Provide advice and guidance on electronic attack/cyber attack to the critical national infrastructure and to government departments.</p>
<p>Information taken from SN/SC/5832 June 2011</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/securingtherealm.wordpress.com/767/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/securingtherealm.wordpress.com/767/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/securingtherealm.wordpress.com/767/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/securingtherealm.wordpress.com/767/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/securingtherealm.wordpress.com/767/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/securingtherealm.wordpress.com/767/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/securingtherealm.wordpress.com/767/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/securingtherealm.wordpress.com/767/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/securingtherealm.wordpress.com/767/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/securingtherealm.wordpress.com/767/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/securingtherealm.wordpress.com/767/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/securingtherealm.wordpress.com/767/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/securingtherealm.wordpress.com/767/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/securingtherealm.wordpress.com/767/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securingtherealm.com&amp;blog=10510641&amp;post=767&amp;subd=securingtherealm&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://securingtherealm.com/2012/01/31/government-bodies-responsible-for-cyber-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9ca4e6f45108d2412d3c9b4105f1004a?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">a CraZy PeNguIn</media:title>
		</media:content>
	</item>
		<item>
		<title>Free Crypto course with Stanford University</title>
		<link>http://securingtherealm.com/2012/01/27/free-crypto-course-with-stanford-university/</link>
		<comments>http://securingtherealm.com/2012/01/27/free-crypto-course-with-stanford-university/#comments</comments>
		<pubDate>Fri, 27 Jan 2012 08:31:31 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[ComSec]]></category>
		<category><![CDATA[Education & Certification]]></category>
		<category><![CDATA[comsec]]></category>
		<category><![CDATA[Crypto]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://securingtherealm.com/?p=762</guid>
		<description><![CDATA[For those, like myself, involved in crypto, Stanford University are offering a free online course in cryptography. It covers the &#8230;<p><a href="http://securingtherealm.com/2012/01/27/free-crypto-course-with-stanford-university/">Continue reading &#187;</a></p><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securingtherealm.com&amp;blog=10510641&amp;post=762&amp;subd=securingtherealm&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>For those, like myself, involved in crypto, Stanford University are offering a free online course in cryptography. It covers the internal workings of crypto (not for those who don&#8217;t like the more advance mathematics).</p>
<p>The course information:</p>
<blockquote><p>Cryptography is an indispensable tool for protecting information in computer systems. This course explains the inner workings of cryptographic primitives and how to correctly use them.   Students will learn how to reason about the security of cryptographic constructions and how to apply this knowledge to real-world applications.   The course begins with a detailed discussion of how two parties who have a shared secret key can communicate securely when a powerful adversary eavesdrops and tampers with traffic.  We will examine many deployed protocols and analyze mistakes in existing systems.   The second half of the course discusses public-key techniques that let two or more parties generate a shared secret key. We will cover the relevant number theory and discuss public-key encryption, digital signatures, and authentication protocols. Towards the end of the course we will cover more advanced topics such as zero-knowledge, distributed protocols such as secure auctions, and a number of privacy mechanisms.   Throughout the course students will be exposed to many exciting open problems in the field.</p>
<p>The course will include written homeworks and programming labs.  The course is self-contained, however it will be helpful to have a basic understanding of discrete probability theory.</p></blockquote>
<p>The course starts in Feb so sign up now at <a href="http://www.crypto-class.org/" target="_blank">http://www.crypto-class.org/</a></p>
<p>In addition, Sanford have an online Computer Security course also starting in Feb you might be interested in &#8211; visit <a href="http://www.security-class.org/" target="_blank">http://www.security-class.org/</a> today.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/securingtherealm.wordpress.com/762/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/securingtherealm.wordpress.com/762/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/securingtherealm.wordpress.com/762/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/securingtherealm.wordpress.com/762/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/securingtherealm.wordpress.com/762/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/securingtherealm.wordpress.com/762/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/securingtherealm.wordpress.com/762/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/securingtherealm.wordpress.com/762/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/securingtherealm.wordpress.com/762/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/securingtherealm.wordpress.com/762/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/securingtherealm.wordpress.com/762/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/securingtherealm.wordpress.com/762/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/securingtherealm.wordpress.com/762/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/securingtherealm.wordpress.com/762/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securingtherealm.com&amp;blog=10510641&amp;post=762&amp;subd=securingtherealm&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://securingtherealm.com/2012/01/27/free-crypto-course-with-stanford-university/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9ca4e6f45108d2412d3c9b4105f1004a?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">a CraZy PeNguIn</media:title>
		</media:content>
	</item>
		<item>
		<title>HMG IA Training</title>
		<link>http://securingtherealm.com/2012/01/25/hmg-ia-training/</link>
		<comments>http://securingtherealm.com/2012/01/25/hmg-ia-training/#comments</comments>
		<pubDate>Wed, 25 Jan 2012 08:19:10 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[Education & Certification]]></category>
		<category><![CDATA[course]]></category>
		<category><![CDATA[HMG IA Course]]></category>
		<category><![CDATA[IAS 1 Practitioner]]></category>
		<category><![CDATA[IAS2]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://securingtherealm.com/?p=749</guid>
		<description><![CDATA[Quick post to mention some training courses that are available for those working in the HMG IA field. [ National &#8230;<p><a href="http://securingtherealm.com/2012/01/25/hmg-ia-training/">Continue reading &#187;</a></p><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securingtherealm.com&amp;blog=10510641&amp;post=749&amp;subd=securingtherealm&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Quick post to mention some training courses that are available for those working in the HMG IA field.</p>
<h1>[ <a href="http://www.nationalschool.gov.uk/" target="_blank">National School of Government</a> ]</h1>
<p><a href="http://www.nationalschool.gov.uk/programmes/programme.asp?id=20074" target="_blank">Introduction to Information Assurance &#8211; Finding your way around IA in Government</a> - £925 (2 days)</p>
<p>Topics covered:-</p>
<ul>
<li>IA governance within an organisation</li>
<li>Threats, risks and impacts</li>
<li>Overview of key legislation and regulation</li>
<li>Government IA strategy</li>
<li>Government IA policy and standards</li>
<li>Assurance</li>
<li>Maintaining confidence</li>
</ul>
<p><a href="http://www.nationalschool.gov.uk/programmes/programme.asp?id=22907" target="_blank">Information Assurance Standards IS2 and IS1 (Topic Programme 1) Process and practice</a> &#8211; £1775 (4 days)</p>
<p>Topics covered:-</p>
<ul>
<li>IS2 &#8211; risk management and accreditation</li>
<li>Content and development of the RMADS</li>
<li>Privacy Impact Assessments and IS6</li>
<li>The accreditation process</li>
<li>Information risk and assets</li>
<li>IS1 Part 1 &#8211; risk assessment</li>
<li>IS1 Part 2 &#8211; risk treatment</li>
</ul>
<p><a href="http://www.nationalschool.gov.uk/programmes/programme.asp?id=22920" target="_blank">Risk Management and Accreditation Specialist Programme &#8211; IA Professionalism Stage 3 for accreditors</a> - £630 (1 day)</p>
<p>Topics covered:-</p>
<ul>
<li>Accreditation and the Accreditor Accreditation skills and competencies</li>
<li>Accreditation plan and process</li>
<li>Tools of the trade</li>
<li>Support and advice</li>
</ul>
<p><span style="color:#2e77aa;font-size:x-small;"><span style="color:#2e77aa;font-size:x-small;"><a href="http://www.nationalschool.gov.uk/programmes/programme.asp?id=22914" target="_blank">IA Protective Monitoring and Incident Management (Topic Programme 3)</a></span></span></p>
<p>Topics covered:-</p>
<ul>
<li>Overview of audit</li>
<li>IA protective monitoring policy</li>
<li>System monitoring</li>
<li>Incident management</li>
<li>Backup and data storage</li>
<li>Forensic readiness</li>
<li>Sanitisation</li>
<li>Business continuity and disaster recovery</li>
<li>Compliance and the IA Maturity Model</li>
<li>Service management.</li>
</ul>
<h1>[ <a href="http://www.amethystrisk.com/" target="_blank">Amethyst Risk Management</a> ]</h1>
<p><a href="http://www.amethystrisk.com/rmads.html" target="_blank">RMADS Introduction &#8211; Risk Management and Accreditation Document Sets</a> - (1 day)</p>
<p>Topics covered:-</p>
<ul>
<li>Background and Context of HMG Infosec</li>
<li>Governance and Risk Management Concepts</li>
<li>The Accreditation Process</li>
<li>Risk Management and Accreditation Documents</li>
</ul>
<p><a href="http://www.amethystrisk.com/iastandard1.html" target="_blank">IA1 Practitioners Course &#8211; HMG Information Assurance Standard No.1 (IAS1) Technical Risk Assessment &#8211; (2 day)</a></p>
<p>Topics covered:-</p>
<ul>
<li>The purpose, structure and context of the standard</li>
<li>Changes from previous issues of IAS1</li>
<li>The new Standard framework</li>
<li>Model-based risk analysis method</li>
<li>IAS1 risk assessment methodology</li>
<li>Security Case development</li>
<li>Detailed workshops based on a real-world case study</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/securingtherealm.wordpress.com/749/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/securingtherealm.wordpress.com/749/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/securingtherealm.wordpress.com/749/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/securingtherealm.wordpress.com/749/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/securingtherealm.wordpress.com/749/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/securingtherealm.wordpress.com/749/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/securingtherealm.wordpress.com/749/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/securingtherealm.wordpress.com/749/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/securingtherealm.wordpress.com/749/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/securingtherealm.wordpress.com/749/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/securingtherealm.wordpress.com/749/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/securingtherealm.wordpress.com/749/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/securingtherealm.wordpress.com/749/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/securingtherealm.wordpress.com/749/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securingtherealm.com&amp;blog=10510641&amp;post=749&amp;subd=securingtherealm&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://securingtherealm.com/2012/01/25/hmg-ia-training/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9ca4e6f45108d2412d3c9b4105f1004a?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">a CraZy PeNguIn</media:title>
		</media:content>
	</item>
		<item>
		<title>Business Impact Levels (BIL)</title>
		<link>http://securingtherealm.com/2012/01/22/business-impact-levels-bil/</link>
		<comments>http://securingtherealm.com/2012/01/22/business-impact-levels-bil/#comments</comments>
		<pubDate>Sun, 22 Jan 2012 15:03:42 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[HMG IA (General)]]></category>
		<category><![CDATA[HMG Policy]]></category>

		<guid isPermaLink="false">http://securingtherealm.com/?p=721</guid>
		<description><![CDATA[A successful exploitation by a threat actor or threat source will result in a compromise of one or more of &#8230;<p><a href="http://securingtherealm.com/2012/01/22/business-impact-levels-bil/">Continue reading &#187;</a></p><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securingtherealm.com&amp;blog=10510641&amp;post=721&amp;subd=securingtherealm&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A successful exploitation by a threat actor or threat source will result in a compromise of one or more of the following elements of an information asset:</p>
<ul>
<li>Confidentiality</li>
<li>Integrity</li>
<li>Availability</li>
</ul>
<p>This compromise will have an impact on the business. Within the SPF and IAS1 they identify business impact from IL0 (lowest) to IL6 (highest).</p>
<p>IAS1 states that a business impact is by definition the impact that a compromise has on the operations or efficiency of an organisation, it&#8217;s customers or citizens.</p>
<p>Unlike a protective marking (i.e. RESTRICTED, SECRET etc.) which is concerned with the level of control, handling and management of the information asset, the impact level (IL) determines the value of an information asset if compromised and how it can impact the following:</p>
<ul>
<li>
<div align="LEFT">Financial loss to an organisation;</div>
</li>
<li><span style="font-size:small;">Operational effectiveness of a system/service if compromised; </span></li>
<li><span style="font-size:small;">Reputational damage to an organisation; </span></li>
<li><span style="font-size:small;">Stress caused to an individual/citizen; </span></li>
<li><span style="font-size:small;">International relationships with friendly or allied nations/governments. </span></li>
</ul>
<p>There is a one to one relationship between the protective marking and the impact level (but not the other way around) as can be seen below.</p>
<ul>
<li>Non Protectively Marked (NPM) / Unclassified = IL0/IL1</li>
<li>PROTECT = IL2</li>
<li>RESTRICTED = IL3</li>
<li>CONFIDENTIAL = IL4</li>
<li>SECRET = IL5</li>
<li>TOP SECRET= IL6</li>
</ul>
<p>IL2, IL3, IL4 are also correlated with CIA values as follows:</p>
<ul>
<li>IL2 corresponds to 2-2-4</li>
<li>IL3 corresponds to 3-3-4</li>
<li>IL4 corresponds to 4-4-4</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/securingtherealm.wordpress.com/721/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/securingtherealm.wordpress.com/721/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/securingtherealm.wordpress.com/721/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/securingtherealm.wordpress.com/721/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/securingtherealm.wordpress.com/721/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/securingtherealm.wordpress.com/721/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/securingtherealm.wordpress.com/721/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/securingtherealm.wordpress.com/721/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/securingtherealm.wordpress.com/721/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/securingtherealm.wordpress.com/721/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/securingtherealm.wordpress.com/721/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/securingtherealm.wordpress.com/721/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/securingtherealm.wordpress.com/721/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/securingtherealm.wordpress.com/721/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securingtherealm.com&amp;blog=10510641&amp;post=721&amp;subd=securingtherealm&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://securingtherealm.com/2012/01/22/business-impact-levels-bil/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9ca4e6f45108d2412d3c9b4105f1004a?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">a CraZy PeNguIn</media:title>
		</media:content>
	</item>
		<item>
		<title>What is the PSN?</title>
		<link>http://securingtherealm.com/2012/01/22/what-is-the-psn/</link>
		<comments>http://securingtherealm.com/2012/01/22/what-is-the-psn/#comments</comments>
		<pubDate>Sun, 22 Jan 2012 11:37:34 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[PSN & GCN]]></category>
		<category><![CDATA[PSN]]></category>

		<guid isPermaLink="false">http://securingtherealm.com/?p=712</guid>
		<description><![CDATA[The PSN, or Public Service Network, is the Government cloud (G-Cloud) computing layer sitting on top of the GCN (Government Conveyance &#8230;<p><a href="http://securingtherealm.com/2012/01/22/what-is-the-psn/">Continue reading &#187;</a></p><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securingtherealm.com&amp;blog=10510641&amp;post=712&amp;subd=securingtherealm&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The PSN, or Public Service Network, is the Government cloud (G-Cloud) computing layer sitting on top of the GCN (Government Conveyance Network (the network layer)) where it will host a number of service applications alongside enterprise services such as DNS, PKI, VoIP, eMail etc.</p>
<p>The plan with the PSN is that approved suppliers to the Government can offer services through a market place providing great oppertunities for industry and large savings for the public sector.</p>
<p>The PSN offers a consolidated network of services for the modern Government in a unique flat network architecture with different security impact levels all operating off the same infrastructure. The PSN network will be IL2 accredited  but will be able to store and process data up to a protective marking of RESTRICTED (IL3) via CESG approved encryption.</p>
<p>Kent and Hampshire are the first to trial the PSN service with further contracts for connectivity in early 2012.</p>
<p>It is expected that public sector organisations/departments will migrate to the PSN as existing contracts with service providers expire. The Government is keen to migrate all departments/agencies over to the PSN as soon as they can. This shift to the PSN could mean a shift in business for current service providers to HMG.</p>
<p>Links:<br />
<a href="http://www.cabinetoffice.gov.uk/resource-library/public-services-network">http://www.cabinetoffice.gov.uk/resource-library/public-services-network</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/securingtherealm.wordpress.com/712/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/securingtherealm.wordpress.com/712/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/securingtherealm.wordpress.com/712/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/securingtherealm.wordpress.com/712/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/securingtherealm.wordpress.com/712/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/securingtherealm.wordpress.com/712/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/securingtherealm.wordpress.com/712/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/securingtherealm.wordpress.com/712/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/securingtherealm.wordpress.com/712/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/securingtherealm.wordpress.com/712/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/securingtherealm.wordpress.com/712/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/securingtherealm.wordpress.com/712/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/securingtherealm.wordpress.com/712/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/securingtherealm.wordpress.com/712/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securingtherealm.com&amp;blog=10510641&amp;post=712&amp;subd=securingtherealm&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://securingtherealm.com/2012/01/22/what-is-the-psn/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9ca4e6f45108d2412d3c9b4105f1004a?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">a CraZy PeNguIn</media:title>
		</media:content>
	</item>
		<item>
		<title>Mapping SPF v6 MR to SPF v7 MR</title>
		<link>http://securingtherealm.com/2012/01/18/mapping-spf-v6-mr-to-spf-v7-mr/</link>
		<comments>http://securingtherealm.com/2012/01/18/mapping-spf-v6-mr-to-spf-v7-mr/#comments</comments>
		<pubDate>Wed, 18 Jan 2012 08:52:46 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[HMG Policy]]></category>

		<guid isPermaLink="false">http://acrazypenguin.com/?p=703</guid>
		<description><![CDATA[A quick reference post for the mappings of the latest SPF (Security Policy Framework) 7 to SPF 6 (these are &#8230;<p><a href="http://securingtherealm.com/2012/01/18/mapping-spf-v6-mr-to-spf-v7-mr/">Continue reading &#187;</a></p><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securingtherealm.com&amp;blog=10510641&amp;post=703&amp;subd=securingtherealm&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A quick reference post for the mappings of the latest SPF (Security Policy Framework) 7 to SPF 6 (these are also available in the SPF 7 appendix):</p>
<table border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td width="240">
<p align="center"><strong>SPF Version 7 &#8211; Oct 2011<br />
</strong><strong>MR Structure</strong></p>
</td>
<td valign="top" width="308">
<p align="center"><strong>SPF Version 6 &#8211; Apr 2011<br />
</strong><strong>MR Structure</strong></p>
</td>
</tr>
<tr>
<td width="240">
<p align="center"><strong>MR 1<br />
</strong><strong>SECURITY ORGANISATION</strong></p>
</td>
<td valign="top" width="308">3 –   Board Level Responsibilities<br />
4 –   DSO Responsibilities<br />
9 –   DSU Training<br />
35 – IA Roles and Responsibilities</td>
</tr>
<tr>
<td width="240">
<p align="center"><strong>MR 2<br />
</strong><strong>RISK MANAGEMENT APPROACHES</strong></p>
</td>
<td valign="top" width="308">5 –   Risk Management Approaches<br />
32 &#8211; Managing Information Risk</td>
</tr>
<tr>
<td width="240">
<p align="center"><strong>MR 3<br />
</strong><strong>CULTURE, EDUCATION AND AWARENESS</strong></p>
</td>
<td valign="top" width="308">1 –   Education and Awareness for Staff<br />
9 –   Protective Security Culture<br />
21 – Personal Responsibilities for Safeguarding   Assets</td>
</tr>
<tr>
<td width="240">
<p align="center"><strong>MR 4<br />
</strong><strong>MANAGING AND RECOVERING FROM INCIDENTS</strong><strong></strong></p>
</td>
<td valign="top" width="308">9 –   Reporting of Security Incidents<br />
21   – Security Breach System<br />
49   – Disaster Recovery Planning<br />
70 – Business Continuity</td>
</tr>
<tr>
<td width="240">
<p align="center"><strong>MR 5<br />
</strong><strong>ASSURANCE AND REPORTING</strong></p>
</td>
<td valign="top" width="308">6 –   Self Assessment and Systems of Assurance<br />
7 –   Annual Security Returns<br />
8 –   Audit and Review<br />
34   – Statement of Internal Control<br />
69 – CT Assurance Statements</td>
</tr>
<tr>
<td width="240">
<p align="center"><strong>MR 6<br />
</strong><strong>INFORMATION SECURITY POLICY</strong><strong></strong></p>
</td>
<td valign="top" width="308">31   &#8211; Information Security Policy<br />
10   &#8211; International Security Agreements<br />
11   &#8211; Government Protective Marking System (GPMS)<br />
12   &#8211; Legal Requirements<br />
15 &#8211; FOI</td>
</tr>
<tr>
<td width="240">
<p align="center"><strong>MR 7<br />
</strong><strong>GOVERNMENT PROTECTIVE MARKING SYSTEM</strong><strong></strong></p>
</td>
<td valign="top" width="308">10   &#8211; International Security Agreements<br />
11   &#8211; Government Protective Marking System (GPMS)<br />
16   &#8211; Need to know principle<br />
18   &#8211; Material originating outside the HMG<br />
19   &#8211; Universal controls<br />
20- Special handling</td>
</tr>
<tr>
<td width="240">
<p align="center"><strong>MR 8<br />
</strong><strong>RISK ASSESSMENT AND ACCREDITATION OF ICT   SYSTEMS</strong><strong></strong></p>
</td>
<td valign="top" width="308">32   &#8211; Managing Information Risk<br />
33   &#8211; Business impact levels<br />
14   &#8211; HMG IA no 6 – Protecting personal data<br />
36   &#8211; Accreditation and audit<br />
37 &#8211; Compliance checks – RMADS</td>
</tr>
<tr>
<td width="240">
<p align="center"><strong>MR 9<br />
</strong><strong>TECHNICAL CONTROLS</strong><strong></strong></p>
</td>
<td valign="top" width="308">39-   Codes of connection and technical controls<br />
40-   Cryptography<br />
41-   Eavesdropping and Electro-Magnetic Countermeasures<br />
42-   Remote working/mobile media<br />
45- Secure Disposal</td>
</tr>
<tr>
<td width="240">
<p align="center"><strong>MR 10<br />
</strong><strong>PROCEDURAL MEASURES</strong><strong></strong></p>
</td>
<td valign="top" width="308">38   &#8211; Authentication controls<br />
46   &#8211; Personnel security<br />
48   &#8211; Education, training and awareness<br />
42 &#8211; Mobile working</td>
</tr>
<tr>
<td width="240">
<p align="center"><strong>MR 11<br />
</strong><strong>DELIVERY PARTNERS AND SUPPLIERS</strong><strong></strong></p>
</td>
<td valign="top" width="308">2 –   SPF Compliance among Delivery Partners and Suppliers<br />
31   &#8211; Information Security Policy DPs &amp; 3PS<br />
43 – Procurement</td>
</tr>
<tr>
<td width="240">
<p align="center"><strong>MR 12<br />
</strong><strong>MANAGING AND REPORTING SECURITY INCIDENTS</strong></p>
</td>
<td valign="top" width="308">9 –   Reporting Incidents<br />
21   – Security Breach System<br />
44 &#8211; Reporting ICT Incidents</td>
</tr>
<tr>
<td width="240">
<p align="center"><strong>MR 13<br />
REC</strong><strong>RUITMENT CHECKS AND NATIONAL SECURITY   VETTING</strong></p>
</td>
<td valign="top" width="308">23   – BPSS compliance<br />
24   – National Security Vetting compliance<br />
26 – Clearance Decisions</td>
</tr>
<tr>
<td width="240">
<p align="center"><strong>MR 14<br />
</strong><strong>ONGOING PERSONNEL SECURITY MANAGEMENT</strong></p>
</td>
<td valign="top" width="308">22   – Applying Personal Security Controls<br />
25   – National Security Vetting Issues<br />
27 – National Security Vetting Aftercare</td>
</tr>
<tr>
<td width="240">
<p align="center"><strong>MR 15<br />
</strong><strong>APPEALS</strong></p>
</td>
<td valign="top" width="308">28   – National Security Vetting Appeals<br />
MR 29 &#8211; Notifying GSS of Legal Challenges</td>
</tr>
<tr>
<td width="240">
<p align="center"><strong>MR 16<br />
</strong><strong>SECURITY RISK ASSESSMENT</strong></p>
</td>
<td valign="top" width="308">50-   Defence in Depth<br />
51-   Storage of Sensitive Assets<br />
55-   Building Security<br />
62- Operational Requirements</td>
</tr>
<tr>
<td width="240">
<p align="center"><strong>MR 17<br />
</strong><strong>INTERNAL CONTROLS</strong></p>
</td>
<td valign="top" width="308">47   – Physical Security of ICT Assets<br />
52-   Secure Containers<br />
53-   Secure Rooms<br />
54- Officer Areas</td>
</tr>
<tr>
<td width="240">
<p align="center"><strong>MR 18<br />
</strong><strong>BUILDING AND PERIMETER SECURITY</strong><strong></strong></p>
</td>
<td valign="top" width="308">56-   Physical Access Control<br />
57-   Physical Access Control<br />
58   &#8211; Access Control Policies<br />
59-   Incoming Mail<br />
60-   Manned Guarding<br />
61- Perimeter Security</td>
</tr>
<tr>
<td width="240">
<p align="center"><strong>MR 19<br />
</strong><strong>PREPARING FOR CRITICAL INCIDENTS</strong></p>
</td>
<td valign="top" width="308">64-   Categorisation of the Government Estate<br />
65- Government Estate Response Level System</td>
</tr>
<tr>
<td width="240">
<p align="center"><strong>MR 20<br />
</strong><strong>RESPONDING TO CRITICAL INCIDENTS</strong></p>
</td>
<td valign="top" width="308">67-   CT Protective Security Policy and Plans<br />
68- Testing CT Arrangements</td>
</tr>
</tbody>
</table>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/securingtherealm.wordpress.com/703/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/securingtherealm.wordpress.com/703/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/securingtherealm.wordpress.com/703/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/securingtherealm.wordpress.com/703/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/securingtherealm.wordpress.com/703/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/securingtherealm.wordpress.com/703/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/securingtherealm.wordpress.com/703/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/securingtherealm.wordpress.com/703/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/securingtherealm.wordpress.com/703/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/securingtherealm.wordpress.com/703/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/securingtherealm.wordpress.com/703/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/securingtherealm.wordpress.com/703/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/securingtherealm.wordpress.com/703/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/securingtherealm.wordpress.com/703/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securingtherealm.com&amp;blog=10510641&amp;post=703&amp;subd=securingtherealm&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://securingtherealm.com/2012/01/18/mapping-spf-v6-mr-to-spf-v7-mr/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9ca4e6f45108d2412d3c9b4105f1004a?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">a CraZy PeNguIn</media:title>
		</media:content>
	</item>
		<item>
		<title>What is the GCN?</title>
		<link>http://securingtherealm.com/2012/01/18/what-is-the-gcn/</link>
		<comments>http://securingtherealm.com/2012/01/18/what-is-the-gcn/#comments</comments>
		<pubDate>Wed, 18 Jan 2012 08:25:46 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[PSN & GCN]]></category>

		<guid isPermaLink="false">http://acrazypenguin.com/?p=700</guid>
		<description><![CDATA[The GCN, or Government Conveyance Network is the replacement for the aging siloed GSi (Government Secure Intranet) network that interconnects multiple UK &#8230;<p><a href="http://securingtherealm.com/2012/01/18/what-is-the-gcn/">Continue reading &#187;</a></p><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securingtherealm.com&amp;blog=10510641&amp;post=700&amp;subd=securingtherealm&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The GCN, or Government Conveyance Network is the replacement for the aging siloed GSi (Government Secure Intranet) network that interconnects multiple UK Government networks. The idea behind the GCN is to provide a flat network space across multiple service providers to provide a more harmonised network that can provide the services needed in both today and tomorrow&#8217;s Government market. The services will form the PSN (Public Services Network) in a cloud based solution where the underlying hardware architecture is abstracted away from the application layer.</p>
<p>The official definition is:</p>
<blockquote><p>The GCN will provide the core backbone infrastructure of the PSN – and it will be a <em>mesh </em>of existing telecoms industry networks. It will be built to Industry standards. Suppliers who meet the standards will be able to supply GCN services.</p></blockquote>
<p>The network layout will look like:</p>
<p><a href="http://securingtherealm.files.wordpress.com/2012/01/gcn.jpg"><img class="aligncenter size-full wp-image-701" title="GCN - Government Conveyance Network" src="http://securingtherealm.files.wordpress.com/2012/01/gcn.jpg?w=529&#038;h=373" alt="GCN - Government Conveyance Network" width="529" height="373" /></a><br />
For more information on the GCN, check out the <a href="http://www.cabinetoffice.gov.uk/media/203634/gcn_ser_description.pdf">GCN Service Description</a> document.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/securingtherealm.wordpress.com/700/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/securingtherealm.wordpress.com/700/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/securingtherealm.wordpress.com/700/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/securingtherealm.wordpress.com/700/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/securingtherealm.wordpress.com/700/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/securingtherealm.wordpress.com/700/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/securingtherealm.wordpress.com/700/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/securingtherealm.wordpress.com/700/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/securingtherealm.wordpress.com/700/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/securingtherealm.wordpress.com/700/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/securingtherealm.wordpress.com/700/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/securingtherealm.wordpress.com/700/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/securingtherealm.wordpress.com/700/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/securingtherealm.wordpress.com/700/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securingtherealm.com&amp;blog=10510641&amp;post=700&amp;subd=securingtherealm&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://securingtherealm.com/2012/01/18/what-is-the-gcn/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9ca4e6f45108d2412d3c9b4105f1004a?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">a CraZy PeNguIn</media:title>
		</media:content>

		<media:content url="http://securingtherealm.files.wordpress.com/2012/01/gcn.jpg" medium="image">
			<media:title type="html">GCN - Government Conveyance Network</media:title>
		</media:content>
	</item>
	</channel>
</rss>
