<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">

<channel>
<title>CERT Announcements</title>
<link>http://www.cert.org/nav/whatsnew.html</link>
<language>en-us</language>
<description>Announcements: What's New on the CERT web site</description>

<item>
<title>Report on Monitoring for Insider Theft of Intellectual Property Released</title>
<link>http://www.cert.orghttp://www.sei.cmu.edu/library/abstracts/reports/12tr008.cfm</link>
<description>This report presents a way organizations can mitigate the risk of theft of intellectual property by departing insiders.</description>
<pubDate>Thu, 03 May 2012 14:12:52 -0400</pubDate>
</item>

<item>
<title>Source Code Analysis Laboratory (SCALe) Technical Note Released</title>
<link>http://www.cert.orghttp://www.sei.cmu.edu/library/abstracts/reports/12tn013.cfm</link>
<description>This technical note describes SCALe, a demonstration process for testing software for conformance against secure coding standards.</description>
<pubDate>Wed, 02 May 2012 14:57:19 -0400</pubDate>
</item>

<item>
<title>Insider Threat Security Reference Architecture Technical Report Released</title>
<link>http://www.cert.orghttp://www.sei.cmu.edu/library/abstracts/reports/12tr007.cfm</link>
<description>This report describes the Insider Threat Security Reference Architecture (ITSRA), an enterprise-wide solution to the threat organizations face from their own insiders.</description>
<pubDate>Tue, 01 May 2012 15:39:41 -0400</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2012/04/cert_basic_fuzzing_framework_v.html</link>
<description>CERT Basic Fuzzing Framework 2.5 Released</description>
<pubDate>Mon, 30 Apr 2012 12:43:00 -0400</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2012/04/cert_triage_tools_10.html</link>
<description>CERT Linux Triage Tools 1.0 Released</description>
<pubDate>Wed, 25 Apr 2012 11:15:23 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Security controls, including those for insider threat, are the safeguards necessary to protect information and information systems.</description>
<pubDate>Tue, 24 Apr 2012 11:53:39 -0400</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2012/04/cert_failure_observation_engin.html</link>
<description>CERT Failure Observation Engine 1.0 Released</description>
<pubDate>Mon, 23 Apr 2012 16:47:59 -0400</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2012/04/vulnerability_severity_using_c.html</link>
<description>Vulnerability Severity Using CVSS</description>
<pubDate>Wed, 11 Apr 2012 23:12:47 -0400</pubDate>
</item>

<item>
<title>The CERT Top 10 List for Winning the Battle Against Insider Threats Released</title>
<link>http://www.cert.org/archive/pdf/CERT-InsiderThreat-RSA2012.pdf</link>
<description>Organizations can use these tips, drawn from the CERT Insider Threat Center's case files, to combat insider threat.</description>
<pubDate>Wed, 28 Mar 2012 13:36:45 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Post</title>
<link>http://www.cert.org/blogs/insider_threat/2012/03/the_cert_guide_to_insider_threats_how_to_prevent_detect_and_respond_to_information_technology_crimes.html</link>
<description>The CERT Guide to Insider Threats: How to Prevent, Detect, and Respond to Information Technology Crimes</description>
<pubDate>Tue, 27 Mar 2012 13:18:35 -0400</pubDate>
</item>

<item>
<title>CERT-RMM V1.1: NIST Special Publication Crosswalk Version 1 Released</title>
<link>http://www.cert.orghttp://www.sei.cmu.edu/library/abstracts/reports/11tn028.cfm</link>
<description>This technical note maps CERT-RMM process areas to 800-series NIST special publications.</description>
<pubDate>Tue, 27 Mar 2012 10:15:37 -0400</pubDate>
</item>

<item>
<title>Principles of Trust for Embedded Systems Technical Note Published</title>
<link>http://www.cert.org/archive/pdf/12tn007.pdf</link>
<description>This paper gives substance and explicit meaning to the terms trust and trustworthy as they relate to automated systems and to embedded systems in particular.</description>
<pubDate>Wed, 07 Mar 2012 09:55:52 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Implementing secure coding standards to reduce the number of vulnerabilities that can escape into operational systems is a sound business decision.</description>
<pubDate>Tue, 28 Feb 2012 13:58:01 -0500</pubDate>
</item>

<item>
<title>Mission Risk Diagnostic (MRD) Method Description Technical Note Released</title>
<link>http://www.cert.orghttp://www.sei.cmu.edu/library/abstracts/reports/12tn005.cfm</link>
<description>This technical note overviews the MRD method developed by the SEI to assess system risk across the lifecycle and supply chain.</description>
<pubDate>Mon, 27 Feb 2012 09:58:04 -0500</pubDate>
</item>

<item>
<title>CERT-RMM Capability Appraisal Method (CAM) Version 1.1 Technical Report Released</title>
<link>http://www.cert.orghttp://www.sei.cmu.edu/library/abstracts/reports/11tr020.cfm</link>
<description>This report demonstrates that SCAMPI V1.2 can be applied to CERT-RMM V1.1 as the reference model for a process appraisal.</description>
<pubDate>Thu, 23 Feb 2012 10:03:57 -0500</pubDate>
</item>

<item>
<title>CERT-RMM V1.1: Code of Practice Crosswalk Commercial Version 1.1 Technical Note Released</title>
<link>http://www.cert.orghttp://www.sei.cmu.edu/library/abstracts/reports/11tn012.cfm</link>
<description>This tech note shows how CERT-RMM process areas, industry standards, and codes of practices are connected.</description>
<pubDate>Thu, 23 Feb 2012 10:03:12 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2012/02/insiders_and_organized_crime.html</link>
<description>The entry "Insiders and Organized Crime" has been posted.</description>
<pubDate>Thu, 16 Feb 2012 15:16:52 -0500</pubDate>
</item>

<item>
<title>The CERT Guide to Insider Threats Book Published</title>
<link>http://www.sei.cmu.edu/library/abstracts/books/9780321812575.cfm?wt.ac=hpLibrary</link>
<description>This book describes the CERT Insider Threat Center's practical findings on insider cyber crimes, as well as guidance and countermeasures for organizations.</description>
<pubDate>Tue, 14 Feb 2012 14:29:43 -0500</pubDate>
</item>

<item>
<title>Risk-Based Measurement and Analysis: Application to Software Security Technical Note Released</title>
<link>http://www.cert.org/archive/pdf/12tn004.pdf</link>
<description>This technical note presents the foundations of a risk-based software security measurement and analysis method.</description>
<pubDate>Tue, 14 Feb 2012 09:26:19 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Protecting the internet and its users against cyber attacks requires a significant increase in the number of skilled cyber warriors.</description>
<pubDate>Tue, 31 Jan 2012 13:42:01 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2012/01/insider_threat_control_using_a_siem_signature_to_detect_potential_precursors_to_it_sabotage.html</link>
<description>The Entry &quot;Insider Threat Control: Using a SIEM signature to detect potential precursors to IT Sabotage&quot; has been posted.</description>
<pubDate>Thu, 26 Jan 2012 13:28:45 -0500</pubDate>
</item>

<item>
<title>Spotlight On: Malicious Insiders and Organized Crime Activity</title>
<link>http://www.cert.org/archive/pdf/12tn001.pdf</link>
<description>This TN is the fifth article in the Spotlight On quarterly series published by the CERT Insider Threat Center.</description>
<pubDate>Fri, 20 Jan 2012 15:20:20 -0500</pubDate>
</item>

<item>
<title>CERT Program Improves Security in C Programming Language Standard</title>
<link>http://www.sei.cmu.edu/newsitems/iso-standard.cfm</link>
<description>The CERT Secure Coding team made key contributions to the newest ISO/IEC C language standard.</description>
<pubDate>Mon, 16 Jan 2012 12:23:17 -0500</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2012/01/cname_flux.html</link>
<description>The entry "CNAME flux" has been posted.</description>
<pubDate>Thu, 05 Jan 2012 14:21:03 -0500</pubDate>
</item>

<item>
<title>Using Defined Processes as a Context for Resilience Measures Technical Note Released</title>
<link>http://www.cert.org/archive/pdf/11tn029.pdf</link>
<description>This technical note describes how implementation-level processes can help organizations define measures of operational resilience.</description>
<pubDate>Thu, 22 Dec 2011 12:17:25 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Electronic health records bring many benefits along with security and privacy challenges.</description>
<pubDate>Tue, 20 Dec 2011 13:35:12 -0500</pubDate>
</item>

<item>
<title>Standards-Based Automated Remediation 2011 Update Released</title>
<link>http://www.cert.org/archive/pdf/11sr016.pdf</link>
<description>This report updates the development of standards for remediation of vulnerabilities and compliance issues on Department of Defense networked systems for 2011.</description>
<pubDate>Mon, 19 Dec 2011 09:46:24 -0500</pubDate>
</item>

<item>
<title>Insider Threat Control Released</title>
<link>http://www.cert.org/archive/pdf/SIEM-Control.pdf</link>
<description>Insider Threat Control: Using a SIEM Signature to Detect Potential Precursors to IT Sabotage presents a technique for detecting potential insider sabotage over an organization's network.</description>
<pubDate>Thu, 15 Dec 2011 13:21:15 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2011/12/preparing_for_negative_workplace_events_-_managing_employee_expectations.html</link>
<description>The entry "Preparing for Negative Workplace Events - Managing Employee Expectations" has been posted.</description>
<pubDate>Thu, 15 Dec 2011 10:21:17 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2011/11/insider_threat_controls.html</link>
<description>The entry "Insider Threat Controls" has been posted.</description>
<pubDate>Wed, 16 Nov 2011 09:41:51 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2011/10/data_exfiltration_and_output_devices_-_an_overlooked_threat.html</link>
<description>The entry "Data Exfiltration and Output Devices - An Overlooked Threat" has been posted.</description>
<pubDate>Mon, 17 Oct 2011 13:43:37 -0400</pubDate>
</item>

<item>
<title>CERT Oracle Secure Coding Standard for Java Book Published</title>
<link>http://www.cert.orghttp://www.sei.cmu.edu/library/abstracts/books/9780321803955.cfm</link>
<description>The CERT Oracle Secure Coding Standard for Java has been published by Addison-Wesley Professional.</description>
<pubDate>Fri, 14 Oct 2011 11:17:39 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Demonstration Series Launched</title>
<link>http://www.cert.org/insider_threat/demonstrations/ITDS01.mp4</link>
<description>The CERT Insider Threat Center has released the first video in a series of insider threat demonstrations.</description>
<pubDate>Wed, 12 Oct 2011 15:12:45 -0400</pubDate>
</item>

<item>
<title>Insider Threat Control Technical Note Released</title>
<link>http://www.cert.org/archive/pdf/11tn024.pdf</link>
<description>This technical note describes how organizations can use Splunk to detect insider theft of intellectual property.</description>
<pubDate>Wed, 12 Oct 2011 10:26:26 -0400</pubDate>
</item>

<item>
<title>Agenda Now Available for Upcoming Workshop</title>
<link>http://www.cert.orghttp://www.thei3p.org/events/cybercpr.html</link>
<description>The Institute for Information Infrastructure Protection (I3P) and the CERT Program will present the workshop "Cyber Security CPR: Coordinated Private Response to Computer Security Incidents" in Arlington, VA on October 12-13. See the web page for a link to the agenda.</description>
<pubDate>Thu, 06 Oct 2011 12:18:04 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Measures of operational resilience should answer key questions, inform decisions, and affect behavior.</description>
<pubDate>Tue, 04 Oct 2011 12:03:49 -0400</pubDate>
</item>

<item>
<title>Community College Education Report Published</title>
<link>http://www.cert.orgarchive/pdf/11tr017.pdf</link>
<description>The fourth volume in the Software Assurance Curriculum Project focuses on community college courses for software assurance.</description>
<pubDate>Thu, 29 Sep 2011 10:50:48 -0400</pubDate>
</item>

<item>
<title>2010 CERT Research Report Published</title>
<link>http://www.cert.org/research/researchreport.html</link>
<description>The CERT Program is internationally known for developing practices and technologies to protect, detect, and respond to attacks, accidents, and failures on networked systems. This report describes progress in our innovative research projects and activities.</description>
<pubDate>Fri, 23 Sep 2011 10:25:26 -0400</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2011/09/challenges_in_network_monitori.html</link>
<description>The entry "Challenges in Network Monitoring above the Enterprise" has been published.</description>
<pubDate>Fri, 23 Sep 2011 10:15:33 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Use of Domain Name System security extensions can help prevent website hijacking attacks.</description>
<pubDate>Tue, 06 Sep 2011 13:08:52 -0400</pubDate>
</item>

<item>
<title>Registration Open for Webinar and Workshop</title>
<link>http://www.thei3p.org/events/cybercpr.html</link>
<description>The Institute for Information Infrastructure Protection (I3P) and the CERT Program will present the workshop "Cyber Security CPR: Coordinated Private Response to Computer Security Incidents" in Arlington, VA on October 12-13. There is a pre-event webinar on September 8. See the workshop web page for links to online registration forms.</description>
<pubDate>Tue, 06 Sep 2011 13:07:42 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2011/08/in_2009_the_cert_insider.html</link>
<description>The entry "The Necessity of Best Practices for the Prevention and Detection of Insider Threats" has been posted.</description>
<pubDate>Wed, 31 Aug 2011 09:55:22 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.orgblogs/insider_threat/2011/08/the_cert_insider_threat_database.html</link>
<description>The entry "The CERT Insider Threat Database" has been posted.</description>
<pubDate>Mon, 15 Aug 2011 10:08:26 -0400</pubDate>
</item>

<item>
<title>Keeping Your Family Safe in a Highly Connected World</title>
<link>http://www.cert.org/archive/pdf/KYFS2011.pdf</link>
<description>As our world becomes highly connected where endless data is just a click away and using networked devices has become almost a necessity, protecting your personal information and family privacy is of great concern.</description>
<pubDate>Thu, 11 Aug 2011 09:19:32 -0400</pubDate>
</item>

<item>
<title>Measures for Managing Operational Resilience Technical Report Published</title>
<link>http://www.cert.org/archive/pdf/11tr019.pdf</link>
<description>In this technical report Resilient Enterprise Management (REM) team members suggest a set of top ten strategic measures for managing operational resilience.</description>
<pubDate>Fri, 05 Aug 2011 13:17:15 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Depending on the service model, cloud providers and customers can monitor and implement controls to better protect their sensitive information.</description>
<pubDate>Tue, 02 Aug 2011 11:21:47 -0400</pubDate>
</item>

<item>
<title>Standards-Based Automated Remediation Special Report Released</title>
<link>http://www.cert.org/archive/pdf/11sr007.pdf</link>
<description>This report describes the development of standards for remediation of vulnerabilities and compliance issues on Department of Defense networked systems.</description>
<pubDate>Thu, 21 Jul 2011 16:05:40 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2011/07/insider_threat_methods_of_exfiltration.html</link>
<description>The entry "Theft of Intellectual Property and Tips for Prevention" has been published.</description>
<pubDate>Thu, 21 Jul 2011 13:44:32 -0400</pubDate>
</item>

<item>
<title>Request for Proposal - SEI Code Review Process</title>
<link>http://www.cert.org/secure-coding/CodeReviewRFP/</link>
<description>The SEI is issuing a Request for Proposal seeking interested organizations with experience performing web penetration and source code audits in systems developed in C#, Java, Ruby, Perl, Python, JavaScript, and PHP.</description>
<pubDate>Wed, 13 Jul 2011 09:06:46 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Analyzing malware is essential to assess the damage and reduce the impact associated with ongoing infection.</description>
<pubDate>Tue, 12 Jul 2011 11:38:11 -0400</pubDate>
</item>

<item>
<title>New CERT PGP Key</title>
<link>http://www.cert.org/contact_cert/encryptmail.html</link>
<description>CERT has updated its PGP key. We strongly urge you to encrypt sensitive information.</description>
<pubDate>Fri, 08 Jul 2011 13:27:12 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.orghttp://www.cert.org/blogs/insider_threat/2011/06/insider_threat_deep_dive_theft_of_intellectual_property.html</link>
<description>The entry "Insider Threat Deep Dive: Theft of Intellectual Property" has been posted.</description>
<pubDate>Mon, 27 Jun 2011 14:07:30 -0400</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2011/06/signed_java_and_cisco_anyconne.html</link>
<description>The entry &quot;Signed Java and Cisco AnyConnect&quot; has been posted.</description>
<pubDate>Thu, 09 Jun 2011 14:12:44 -0400</pubDate>
</item>

<item>
<title>A Preliminary Model of Insider Theft of Intellectual Property Technical Note Published</title>
<link>http://www.cert.org/archive/pdf/11tn013.pdf</link>
<description>This technical note presents research findings on insider theft of intellectual property.</description>
<pubDate>Fri, 03 Jun 2011 08:57:28 -0400</pubDate>
</item>

<item>
<title>CERT Used XNET for Forensics Challenge</title>
<link>http://www.cert.orghttp://www.sei.cmu.edu/newsitems/CERT-Team-Uses-XNET.cfm</link>
<description>This article describes the role that XNET played in the CERT Forensics Challenge, designed for the 2011 National Security Agency Cyber Defense Exercise.</description>
<pubDate>Thu, 02 Jun 2011 09:30:37 -0400</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2011/05/effectiveness_of_microsoft_off.html</link>
<description>The entry "Effectiveness of Microsoft Office File Validation" has been published.</description>
<pubDate>Thu, 19 May 2011 15:04:08 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2011/05/insider_threat_and_physical_security_of_organizations.html</link>
<description>The entry "Insider Threat and Physical Security of Organizations" has been published.</description>
<pubDate>Tue, 10 May 2011 14:34:40 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Over 100 electric power utilities are accelerating their transformation to the smart grid by using the Smart Grid Maturity Model.</description>
<pubDate>Thu, 05 May 2011 13:04:22 -0400</pubDate>
</item>

<item>
<title>New CERT Blogs Index</title>
<link>http://www.cert.org/blogs/</link>
<description>This main index page displays the ten most recent entries across all of our blogs. You can reach this page through the blogs link in the bottom navigation.</description>
<pubDate>Tue, 03 May 2011 11:55:23 -0400</pubDate>
</item>

<item>
<title>Trusted Computing in Embedded Systems Workshop Released</title>
<link>http://www.cert.org/archive/pdf/11SR002.pdf</link>
<description>This SEI Special Report describes the November 2010 Trusted Computing in Embedded Systems Workshop held at Carnegie Mellon University.</description>
<pubDate>Fri, 29 Apr 2011 13:57:52 -0400</pubDate>
</item>

<item>
<title>Software Security Measurement and Analysis Presentation Released</title>
<link>http://www.cert.org/archive/pdf/SecurityMeasurementandAnalysis.pdf</link>
<description>Cyber Security Engineering researchers at CERT have released a presentation describing their Security Measurement and Analysis (SMA) Project.</description>
<pubDate>Thu, 28 Apr 2011 13:26:06 -0400</pubDate>
</item>

<item>
<title>SPREE Workshop</title>
<link>http://www.cert.org/spree</link>
<description>SPREE Workshop registration is now open. You can register by using this form (pdf).</description>
<pubDate>Tue, 26 Apr 2011 13:27:00 -0400</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2011/04/office_shootout_microsoft_offi.html</link>
<description>The entry "A Security Comparison: Microsoft Office vs. Oracle Openoffice" has been published.</description>
<pubDate>Wed, 13 Apr 2011 14:58:49 -0400</pubDate>
</item>

<item>
<title>CERT Staff Presenting at SEPG Europe 2011</title>
<link>http://www.sei.cmu.edu/sepg/europe/2011/tutorials.cfm</link>
<description>To reinforce the "Global Excellence in Software and Security" theme, CERT staff members are presenting tutorials on a variety of security topics.</description>
<pubDate>Thu, 07 Apr 2011 13:02:25 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2011/04/insider_threat_best_practices_from_industry.html</link>
<description>The entry "Insider Threat Best Practices from Industry" has been published.</description>
<pubDate>Wed, 06 Apr 2011 11:17:48 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>BuBusiness l leaders must address risk at the enterprise, business process, and system levels to effectively protect against today's and tomorrow's threats.</description>
<pubDate>Tue, 29 Mar 2011 16:35:47 -0400</pubDate>
</item>

<item>
<title>2011 CyberSecurity Watch Survey Released</title>
<link>http://www.cert.org/archive/pdf/CyberSecuritySurvey2011.pdf</link>
<description>The 2011 CyberSecurity Watch Survey press release and data sample have been released.</description>
<pubDate>Fri, 04 Mar 2011 10:30:47 -0500</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2011/02/cert_basic_fuzzing_framework_b.html</link>
<description>The entry "Announcing the CERT Basic Fuzzing Framework 2.0" has been published.</description>
<pubDate>Mon, 28 Feb 2011 15:57:24 -0500</pubDate>
</item>

<item>
<title>Function Extraction (FX) Research for Computation of Software Behavior Technical Report Released</title>
<link>http://www.cert.org/archive/pdf/11tr009.pdf</link>
<description>This technical report discusses use of algorithms to compute overall malware behavior.</description>
<pubDate>Mon, 28 Feb 2011 13:29:14 -0500</pubDate>
</item>

<item>
<title>Risk and Resilience: Considerations for Information Security Risk Assessment and Management</title>
<link>http://www.cert.org/archive/pdf/GRC-202_Cebula_Allen.pdf</link>
<description>Julia Allen and Jim Cebula gave this presentation at RSA Conference 2011 in San Francisco, California.</description>
<pubDate>Wed, 23 Feb 2011 21:30:20 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2011/02/insider_threats_in_the_software_development_lifecycle.html</link>
<description>The entry "Insider Threats in the Software Development Lifecycle" has been published.</description>
<pubDate>Wed, 23 Feb 2011 15:06:45 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Scenario-based exercises help organizations, governments, and nations prepare for, identify, and mitigate cyber risks.</description>
<pubDate>Tue, 22 Feb 2011 15:37:18 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Presentation Published</title>
<link>http://www.cert.org/archive/pdf/HT2-108_Cappelli_MontelibanoJan26.pdf</link>
<description>"Combat IT Sabotage: Technical Solutions From The CERT Insider Threat Lab," presentated at RSA Conference 2011 in San Francisco, California, is now available.</description>
<pubDate>Mon, 21 Feb 2011 13:54:31 -0500</pubDate>
</item>

<item>
<title>An Analysis of Technical Observations in Insider Theft of Intellectual Property Cases Technical Note Published</title>
<link>http://www.cert.org/archive/pdf/11tn006.pdf</link>
<description>This techincal note provides an overview of techniques employed by malicious insiders to steal intellectual property.</description>
<pubDate>Mon, 21 Feb 2011 13:04:17 -0500</pubDate>
</item>

<item>
<title>Integrating the MSwA Reference Curriculum into the MSIS Model Curriculum Technical Note Published</title>
<link>http://www.cert.org/archive/pdf/11tn004.pdf</link>
<description>This technical note examines how the MSwA Reference Curriculum recommendations might be integrated into the model curriculum recommendations for a MSIS degree.</description>
<pubDate>Wed, 16 Feb 2011 14:51:54 -0500</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2011/02/network_monitoring_for_web-bas.html</link>
<description>The entry "'Network Monitoring for Web-Based Threats' released" has been published.</description>
<pubDate>Mon, 14 Feb 2011 13:36:55 -0500</pubDate>
</item>

<item>
<title>Changes to Vulnerability Analysis Blog</title>
<link>http://www.cert.org/blogs/certcc/2011/02/blog_reorganization.html</link>
<description>To allow for expansion into other technical areas, the Vulnerability Analysis Blog has been converted to the CERT/CC Blog.</description>
<pubDate>Fri, 11 Feb 2011 15:31:15 -0500</pubDate>
</item>

<item>
<title>Network Monitoring for Web-Based Threats Report Published</title>
<link>http://www.cert.org/archive/pdf/11tr005.pdf</link>
<description>This report models the approach a focused attacker would take in order to breach an organization through web-based protocols and provides detection or prevention methods to counter that approach.</description>
<pubDate>Thu, 10 Feb 2011 15:04:29 -0500</pubDate>
</item>

<item>
<title>Security and Privacy Engineering (SPREE) Workshop Scheduled for June</title>
<link>http://www.cert.org/spree</link>
<description>The SPREE Workshop will be held at Carnegie Mellon University on June 15-16, 2011. Discussions will focus on security and privacy challenges associated with developing and maintaining software as data-driven technology continues to advance.</description>
<pubDate>Mon, 31 Jan 2011 10:05:57 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2011/01/insider_threat_case_trends_of_technical_and_non-technical_employees.html</link>
<description>The entry "Insider Threat Case Trends of Technical and Non-Technical Employees" has been published.</description>
<pubDate>Wed, 26 Jan 2011 10:17:18 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Technical controls may be effective in helping prevent, detect, and respond to insider crimes.</description>
<pubDate>Tue, 25 Jan 2011 11:30:53 -0500</pubDate>
</item>

<item>
<title>Trust and Trusted Computing Platforms Technical Note Published</title>
<link>http://www.cert.org/archive/pdf/11tn005.pdf</link>
<description>This technical note examines the capabilities and limitations of hardware-based trusted platforms in general, and the Trusted Platform Module (TPM) from the perspective of trusted applications in particular.</description>
<pubDate>Fri, 21 Jan 2011 14:42:42 -0500</pubDate>
</item>

<item>
<title>Deriving Candidate Technical Controls and Indicators of Insider Attack from Socio-Technical Models and Data Technical Note Published</title>
<link>http://www.cert.org/archive/pdf/11tn003.pdf</link>
<description>This paper demonstrates how to extract and map technical information from previous insider crimes.</description>
<pubDate>Mon, 17 Jan 2011 10:19:50 -0500</pubDate>
</item>

<item>
<title>Software Supply Chain Risk Management Technical Note Published</title>
<link>http://www.cert.org/archive/pdf/10tn026.pdf</link>
<description>This technical note considers current practices in software supply chain analysis and suggests foundational practices.</description>
<pubDate>Tue, 04 Jan 2011 11:39:42 -0500</pubDate>
</item>

<item>
<title>CERT Resilience Management Model Book Published</title>
<link>http://www.sei.cmu.edu/newsitems/CERT-RMM-Book-Published.cfm</link>
<description>The CERT Resilience Management Model (CERT-RMM) Version 1.1 has been published by Addison-Wesley Professional.</description>
<pubDate>Mon, 03 Jan 2011 11:55:30 -0500</pubDate>
</item>

<item>
<title>A Taxonomy of Operational Cyber Security Risks Published</title>
<link>http://www.cert.org/archive/pdf/10tn028.pdf</link>
<description>This technical note presents a taxonomy of operational cyber security risks that attempts to identify and organize the sources of operational cyber security risk.</description>
<pubDate>Wed, 29 Dec 2010 10:52:32 -0500</pubDate>
</item>

<item>
<title>Source Code Analysis Laboratory (SCALe) for Energy Delivery Systems Report Published</title>
<link>http://www.cert.org/archive/pdf/10tr021.pdf</link>
<description>The Source Code Analysis Laboratory (SCALe) is an operational capability that tests software applications for conformance to one of the CERT secure coding standards.</description>
<pubDate>Wed, 29 Dec 2010 09:49:20 -0500</pubDate>
</item>

<item>
<title>CERT Approach to Cybersecurity Workforce Development Report Published</title>
<link>http://www.cert.org/archive/PDF/10tr045.pdf</link>
<description>This report presents a new, continuous approach to cybersecurity workforce development.</description>
<pubDate>Wed, 22 Dec 2010 14:01:12 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2010/12/case_trends_for_type_and_status_of_insiders.html</link>
<description>The entry "Insider Threat Case Trends for Employee Type and Employment Status" has been published.</description>
<pubDate>Wed, 22 Dec 2010 11:15:47 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2010/12/case_trends_for_type_and_status_of_insiders.html</link>
<description>The entry "Insider Threat Case Trends for Employee Type and Employment Status" has been published.</description>
<pubDate>Tue, 21 Dec 2010 10:48:35 -0500</pubDate>
</item>

<item>
<title>How Resilient Is My Organization?</title>
<link>http://www.cert.org/podcast/show/20101209caralli.html</link>
<description>Use the CERT Resilience Management Model (CERT-RMM) to help ensure that critical assets and services perform as expected in the face of stress and disruption.</description>
<pubDate>Thu, 09 Dec 2010 13:45:24 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2010/12/upcoming_insider_threat_presentations.html</link>
<description>The entry "Upcoming Insider Threat Presentations" has been published.</description>
<pubDate>Mon, 06 Dec 2010 09:42:40 -0500</pubDate>
</item>

<item>
<title>CERT Career Fair Scheduled for January</title>
<link>http://certcareerfair.org/</link>
<description>Representatives from CERT will be in Arlington, VA on January 26-27 to meet with candidates interested in job opportunities. Applicants must submit resumes in advance for this appointment-only event.</description>
<pubDate>Fri, 03 Dec 2010 15:10:38 -0500</pubDate>
</item>

<item>
<title>Best Practices for National Cyber Security: Building a National Computer Security Incident Management Capability</title>
<link>http://www.cert.org/archive/pdf/10sr009.pdf</link>
<description>This special report is the first in a series of best practices information that interested organizations and governments can use to begin to develop a national incident management capability.</description>
<pubDate>Fri, 03 Dec 2010 10:26:56 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Government agencies and private industry must build effective partnerships to secure national critical infrastructures.</description>
<pubDate>Tue, 30 Nov 2010 13:54:04 -0500</pubDate>
</item>

<item>
<title>Measuring Operational Resilience Using the CERT Resilience Management Model </title>
<link>http://www.cert.org/archive/pdf/10tn030.pdf</link>
<description>This Technical Note is the first in a series of publications designed to start a dialog on the topic of meaningful measurement.</description>
<pubDate>Fri, 19 Nov 2010 17:03:21 -0500</pubDate>
</item>

<item>
<title>New CERT PGP Key</title>
<link>http://www.cert.org/contact_cert/encryptmail.html</link>
<description>CERT has updated its PGP public key. We strongly urge you to encrypt sensitive information.</description>
<pubDate>Mon, 01 Nov 2010 15:27:40 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Knowledge about software assurance is essential to ensure that complex systems function as intended.</description>
<pubDate>Tue, 26 Oct 2010 13:32:50 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2010/10/interesting_insider_threat_statistics.html</link>
<description>The entry "Interesting Insider Threat Statistics" has been published.</description>
<pubDate>Mon, 25 Oct 2010 11:52:44 -0400</pubDate>
</item>

<item>
<title>FloCon 2011 Keynote Speaker Announced</title>
<link>http://blogs.cisco.com/author/JohnStewart/</link>
<description>John Stewart, vice president and chief security officer of Cisco, will deliver one of the keynote addresses at FloCon 2011.</description>
<pubDate>Fri, 22 Oct 2010 13:11:39 -0400</pubDate>
</item>

<item>
<title>FloCon 2011 Registration Open</title>
<link>http://www.cert.org/flocon/</link>
<description>Registration for FloCon 2011 is now open. The early bird registration fee will begin at $660.00 until November 22, 2010. Please use discount code FLOCONNEB when registering on or before November 22, 2010.</description>
<pubDate>Fri, 22 Oct 2010 12:14:37 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2010/10/a_threat-centric_approach_to_detecting_and_preventing_insider_threat.html</link>
<description>The entry "A Threat-Centric Approach to Detecting and Preventing Insider Threat" has been published.</description>
<pubDate>Mon, 11 Oct 2010 15:55:15 -0400</pubDate>
</item>

<item>
<title>Participation Opportunities for FloCon 2011 Published</title>
<link>http://www.cert.org/flocon/</link>
<description>The call for presentations, a description of sponsorship opportunities, and the sponsorship agreement have been released.</description>
<pubDate>Thu, 07 Oct 2010 15:38:21 -0400</pubDate>
</item>

<item>
<title>Integrated Measurement and Analysis Framework for Software Security Technical Note Published</title>
<link>http://www.cert.org/archive/pdf/10tn025.pdf</link>
<description>This report is the first in a series that addresses how to measure software security in complex environments using the Integrated Measurement and Analysis Framework (IMAF) for software security.</description>
<pubDate>Wed, 06 Oct 2010 16:32:18 -0400</pubDate>
</item>

<item>
<title>Security Requirements Reusability and the SQUARE Methodology</title>
<link>http://www.cert.org/archive/pdf/10tn027.pdf</link>
<description>R-SQUARE incorporates reusable security goals and requirements into a variant of Security Quality Requirements Engineering (SQUARE).</description>
<pubDate>Fri, 01 Oct 2010 11:56:26 -0400</pubDate>
</item>

<item>
<title>Building Assured Systems Framework Report Published</title>
<link>http://www.cert.org/archive/pdf/10tr025.pdf</link>
<description>The BASF addresses the customer and researcher challenges of selecting security methods and research approaches for building assured systems.</description>
<pubDate>Thu, 30 Sep 2010 14:11:58 -0400</pubDate>
</item>

<item>
<title>Upcoming IEEE Smart Grid Survivability Workshop</title>
<link>http://www.cert.org/cisw/sg2010/</link>
<description>This workshop will take place October 13-14, 2010 in Arlington, Virginia</description>
<pubDate>Thu, 30 Sep 2010 13:47:28 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Organizations can benchmark their software security practices against 109 observed activities from 30 organizations.</description>
<pubDate>Tue, 28 Sep 2010 10:40:24 -0400</pubDate>
</item>

<item>
<title>New Vulnerability Analysis Blog Entry</title>
<link>http://www.cert.org/blogs/vuls/2010/09/cert_basic_fuzzing_framework_u.html</link>
<description>The entry "CERT Basic Fuzzing Framework Update" has been published.</description>
<pubDate>Wed, 22 Sep 2010 11:31:22 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2010/09/insider_threat_deep_dive_it_sabotage.html</link>
<description>The entry "Insider Threat Deep Dive: IT Sabotage" has been published.</description>
<pubDate>Wed, 22 Sep 2010 10:36:45 -0400</pubDate>
</item>

<item>
<title>New CERT PGP Key</title>
<link>http://www.cert.org/contact_cert/encryptmail.html</link>
<description>CERT has updated its PGP public key. We strongly urge you to encrypt sensitive information.</description>
<pubDate>Tue, 14 Sep 2010 12:41:39 -0400</pubDate>
</item>

<item>
<title>Insider Threat Blog Released</title>
<link>http://www.cert.org/blogs/insider_threat/</link>
<description>The first entry in our new insider threat blog has been published.</description>
<pubDate>Wed, 08 Sep 2010 14:34:00 -0400</pubDate>
</item>

<item>
<title>FloCon 2010 Proceedings Available</title>
<link>http://www.cert.org/flocon/2010/proceedings.html</link>
<description>Proceedings from FloCon 2010 have been released.</description>
<pubDate>Fri, 03 Sep 2010 12:16:51 -0400</pubDate>
</item>

<item>
<title>Software Assurance Curriculum Materials Available</title>
<link>http://www.cert.org/mswa</link>
<description>A Master of Software Assurance Reference Curriculum and undergraduate course outlines are now available for download.</description>
<pubDate>Wed, 01 Sep 2010 16:03:44 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Internet-connected mobile devices are becoming increasingly attractive targets.</description>
<pubDate>Tue, 31 Aug 2010 10:57:33 -0400</pubDate>
</item>

<item>
<title>FloCon 2011 Announced</title>
<link>http://www.cert.org/flocon/</link>
<description>FloCon 2011 will take place in Salt Lake City, Utah, January 10-13, 2011.</description>
<pubDate>Fri, 27 Aug 2010 10:18:49 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>A national CSIRT is essential for protecting national and economic security, and ensuring the continuity of government agencies and critical infrastructures.</description>
<pubDate>Thu, 19 Aug 2010 08:18:09 -0400</pubDate>
</item>

<item>
<title>Technical Note on Adapting the SQUARE Process for Privacy Requirements Engineering Published</title>
<link>http://www.cert.org/archive/pdf/10tn022.pdf</link>
<description>This technical note explores the use of a disciplined approach to identifying privacy requirements, primarily how the Security Quality Requirements Engineering (SQUARE) process, which was developed for security requirements engineering, can be adapted for privacy requirements engineering in software development.</description>
<pubDate>Mon, 02 Aug 2010 09:42:50 -0400</pubDate>
</item>

<item>
<title>Spotlight On: Insider Threat from Trusted Business Partners Published</title>
<link>http://www.cert.org/archive/pdf/TrustedBusinessPartners0210.pdf</link>
<description>This article focuses on cases in the CERT Insider Threat Center database in which malicious insiders were employed by a trusted business partner of the victim organization. These cases involve outsourcing as well as individual contractors and consultants.</description>
<pubDate>Thu, 29 Jul 2010 16:44:17 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Securing systems that control physical switches, valves, pumps, meters, and manufacturing lines as these systems connect to the internet is critical for service continuity.</description>
<pubDate>Tue, 27 Jul 2010 10:36:09 -0400</pubDate>
</item>

<item>
<title>CERT/CC Enhancing Collaboration Between National CSIRTs</title>
<link>http://www.cert.org/csirts/national/</link>
<description>The CERT/CC has created both a wiki and an operational mailing list for authorized technical staff at national CSIRTs. These tools will promote collaboration and information exchange about technical projects and other relevant work.</description>
<pubDate>Thu, 08 Jul 2010 10:45:45 -0400</pubDate>
</item>

<item>
<title>Upcoming SEI Webinar on the CERT Resilience Management Model</title>
<link>http://www.sei.cmu.edu/events/Event-Details.cfm?customel_dataPageID_4744=587174</link>
<description>On July 28, 2010, Rich Caralli will present "Transforming Your Operational Resilience Management Capabilities: CERT's Resilience Management Model" as part of the Software Engineering Institute's webinar series.</description>
<pubDate>Fri, 02 Jul 2010 11:03:47 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Complex, distributed, multi-year investigations of computer crimes require sophisticated methods, techniques, and tools.</description>
<pubDate>Tue, 29 Jun 2010 10:39:13 -0400</pubDate>
</item>

<item>
<title>National CSIRTs to Meet in Miami</title>
<link>http://www.cert.org/csirts/national/conference.html</link>
<description>On June 19-20, the CERT/CC is hosting a meeting of CSIRTs with national responsibility in Miami, Florida. Attendees will discuss the unique challenges facing national CSIRTs and will share information about projects and solutions.</description>
<pubDate>Wed, 09 Jun 2010 12:33:42 -0400</pubDate>
</item>

<item>
<title>Fuzz Testing Tool Available</title>
<link>http://www.cert.org/download/bff/</link>
<description>The CERT Basic Fuzzing Framework (BFF) is a Linux-based tool for fuzz testing software that runs on Linux. This free tool is now available for download.</description>
<pubDate>Wed, 09 Jun 2010 12:12:55 -0400</pubDate>
</item>

<item>
<title>Java Concurrency Guidelines Report Published</title>
<link>http://www.cert.org/archive/pdf/10tr015.pdf</link>
<description>The CERT Oracle Secure Coding Standard for Java provides guidelines for securrogramming language</description>
<pubDate>Mon, 07 Jun 2010 17:22:27 -0400</pubDate>
</item>

<item>
<title>Second Edition of Specifications for Managed Strings Report Published</title>
<link>http://www.cert.org/archive/pdf/10tr018.pdf</link>
<description>This report describes a managed string library for the C programming language.</description>
<pubDate>Mon, 07 Jun 2010 17:13:25 -0400</pubDate>
</item>

<item>
<title>Survivability Analysis Framework Technical Note Published</title>
<link>http://www.cert.org/archive/pdf/10tn013.pdf</link>
<description>The technical note describes the Survivability Analysis Framework (SAF), which can be used to examine the elements of an operational process and evaluate the survivability of an organization.</description>
<pubDate>Wed, 02 Jun 2010 09:50:05 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>To help identify and eliminate security vulnerabilities, subject all software that you build and buy to fuzz testing.</description>
<pubDate>Tue, 25 May 2010 14:23:58 -0400</pubDate>
</item>

<item>
<title>Resilience Management Model Report Published</title>
<link>http://www.cert.org/archive/pdf/10tr012.pdf</link>
<description>The CERT-RMM report describes the key concepts, components, and process area relationships of the model, which is an innovative way to approach the challenge of managing operational resilience in complex, risk-evolving environments.</description>
<pubDate>Mon, 24 May 2010 09:35:14 -0400</pubDate>
</item>

<item>
<title>Technical Report About Network Behavior Published</title>
<link>http://www.cert.org/archive/pdf/10tr010.pdf</link>
<description>The report, Identifying Anomalous Port-Specific Network Behavior, describes a method for detecting behavior that may be a precursor to internet-wide attacks.</description>
<pubDate>Fri, 21 May 2010 09:42:52 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Organized criminals recruit unsuspecting intermediaries to help steal funds from small businesses.</description>
<pubDate>Tue, 27 Apr 2010 10:19:54 -0400</pubDate>
</item>

<item>
<title>2009 CERT Research Annual Report Published</title>
<link>http://www.cert.org/research/2009research-report.pdf</link>
<description>CERT is developing theoretical foundations and engineering methods to help ensure the security of critical systems and networks. This report describes progress in CERT research projects and opportunities for collaboration.</description>
<pubDate>Mon, 05 Apr 2010 11:16:55 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Presentation Published</title>
<link>http://www.cert.org/archive/pdf/Insider-Threat-RSA-2010.pdf</link>
<description>"The Key to Successful Monitoring for Detection of Insider Attacks," presentated at RSA Conference 2010 in San Francisco, California, is now available.</description>
<pubDate>Mon, 05 Apr 2010 10:15:19 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Being able to respond effectively when faced with a disruptive event requires that staff members learn to become more resilient.</description>
<pubDate>Tue, 30 Mar 2010 10:43:16 -0400</pubDate>
</item>

<item>
<title>New CERT PGP Public Key</title>
<link>http://www.cert.org/contact_cert/encryptmail.html</link>
<description>CERT has updated its PGP public key. We strongly urge you to encrypt sensitive information.</description>
<pubDate>Fri, 05 Mar 2010 14:52:00 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>CISOs must leave no room for anyone to deny that they understand what is expected of them when developing secure software.</description>
<pubDate>Tue, 02 Mar 2010 09:41:55 -0500</pubDate>
</item>

<item>
<title>2010 Vulnerability Discovery Workshop</title>
<link>http://www.cert.org/vuls/discovery/workshop_2010.html</link>
<description>On February 1, 2010, CERT hosted a workshop with vulnerability researchers and software vendors to discuss ideas, tools, and techniques used to find vulnerabilities.</description>
<pubDate>Thu, 25 Feb 2010 16:48:28 -0500</pubDate>
</item>

<item>
<title>MITRE CWE and CERT Secure Coding Standards</title>
<link>http://www.cert.org/archive/pdf/CWE_CERT.pdf</link>
<description>This paper describes the Common Weakness Enumeration (CWE) and the CERT secure coding standards and explains the relationship between them.</description>
<pubDate>Thu, 18 Feb 2010 13:39:28 -0500</pubDate>
</item>

<item>
<title>Instrumented Fuzz Testing Using AIR Integers Published</title>
<link>http://www.cert.org/archive/pdf/Fuzzing-AIRintegers.pdf</link>
<description>This paper presents the as-if infinitely ranged (AIR) integer model, which provides a largely automated mechanism for eliminating integer overflow, truncation, and other integral exceptional conditions.</description>
<pubDate>Thu, 18 Feb 2010 13:36:31 -0500</pubDate>
</item>

<item>
<title>Results of 2010 CyberSecurity Watch Survey Released</title>
<link>http://www.cert.org/archive/pdf/ecrimesummary10.pdf</link>
<description>This survey, a cooperative effort of multiple organizations, collected answers from more than 500 rent executives, professionals, and consultants.</description>
<pubDate>Fri, 12 Feb 2010 09:55:10 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Students learn how to combine multiple facets of digital forensics and draw conclusions to support full-scale investigations.</description>
<pubDate>Tue, 02 Feb 2010 09:32:46 -0500</pubDate>
</item>

<item>
<title>New CERT PGP Public Key</title>
<link>http://www.cert.org/contact_cert/encryptmail.html</link>
<description>CERT has updated its PGP public key. We strongly urge you to encrypt sensitive information.</description>
<pubDate>Wed, 20 Jan 2010 14:14:25 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>The SGMM provides a roadmap to guide an organization's transformation to the smart grid.</description>
<pubDate>Tue, 12 Jan 2010 09:51:21 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Addressing privacy during software development is just as important as addressing security.</description>
<pubDate>Tue, 22 Dec 2009 09:44:19 -0500</pubDate>
</item>

<item>
<title>SQUARE Tool Is Now Available</title>
<link>http://www.cert.org</link>
<description></description>
<pubDate>Fri, 04 Dec 2009 16:32:28 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Network defenders and business leaders can use NetSA measures and evidence to better protect their networks.</description>
<pubDate>Tue, 01 Dec 2009 09:49:51 -0500</pubDate>
</item>

<item>
<title>CERT Tactical Response and Analysis Challege Tests Cybersecurity Skills</title>
<link>http://www.sei.cmu.edu/newsitems/cert_TRAC.cfm</link>
<description>Twenty-nine competing teams from 20 countries participated in the Tactical Response and Analysis Challenge (TRAC) conducted by the SEI's CERT PRogram as part of the weeklong International Cyber Defense Workshop (ICDW), which concluded November 13, 2009.</description>
<pubDate>Tue, 17 Nov 2009 14:39:21 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Providing critical services during times of stress depends on documented, tested business continuity plans.</description>
<pubDate>Tue, 10 Nov 2009 10:24:37 -0500</pubDate>
</item>

<item>
<title>Spotlight On - Insider Theft of Intellectual Property inside the U.S. Involving Foreign Governments or Organizations</title>
<link>http://www.cert.org/archive/pdf/CyLabForeignTheftIP.pdf</link>                                                                                             
<description>This report is the third in the quarterly series, Spotlight On, published by the Insider Threat Center at CERT and funded by CyLab. This article focuses on insider theft of intellectual property inside the U.S. involving foreign governments or organizations.</description>
<pubDate>Mon, 09 Nov 2009 13:23:01 -0500</pubDate>
</item>

<item>
<title>Deadline for FloCon Abstracts Extended</title>
<link>http://www.cert.org/flocon/</link>
<description>The deadline to submit abstracts for presentations and demonstrations for FloCon 2010 has been extended to Monday, November 9.</description>
<pubDate>Tue, 27 Oct 2009 11:35:44 -0400</pubDate>
</item>

<item>
<title>Secure Design Patterns</title>
<link>http://www.cert.org/archive/pdf/09tr010.pdf</link>
<description>This newly updated technical report describes a set of secure design patterns, which are descriptions or templates describing a general solution to a security problem that can be applied in many different situations.</description>
<pubDate>Fri, 23 Oct 2009 11:49:52 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>A defined, managed process for third party relationships is essential, particularly when business is disrupted.</description>
<pubDate>Tue, 20 Oct 2009 14:52:15 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>The smart grid is the use of digital technology to modernize the power grid, which comes with some new privacy and security challenges.</description>
<pubDate>Tue, 29 Sep 2009 10:27:54 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Electronic health records (EHRs) are possibly the most complicated area of IT today, more difficult than defense.</description>
<pubDate>Tue, 08 Sep 2009 10:52:58 -0400</pubDate>
</item>

<item>
<title>Effectiveness of the Vulnerability Response Decision Assistance (VRDA) Framework</title>
<link>http://www.cert.org/archive/pdf/VRDA_Effectiveness.pdf</link>
<description>This paper examines the effectiveness of VRDA in terms of how well it predicts responses.</description>
<pubDate>Tue, 25 Aug 2009 11:18:10 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>282 cases of actual insider attacks suggest 16 best practices for preventing and detecting insider threat.</description>
<pubDate>Tue, 18 Aug 2009 11:20:50 -0400</pubDate>
</item>

<item>
<title>Spotlight On: Malicious Insiders with Ties to the Internet Underground Community (pdf), March 2009</title>
<link>http://www.cert.org/insider_threat/docs/CyLab%20Insider%20Threat%20Quarterly%20on%20Internet%20Underground%20-%20March%202009P.pdf</link>
<description>This report is the second in the quarterly series, Spotlight On, published by the Insider Threat Center at CERT and funded by CyLab. This article focuses on insider threat cases in which the insider had relationships with the internet underground community.</description>
<pubDate>Fri, 31 Jul 2009 11:46:23 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Automation, innovation, reaction, and expansion are the foundation for obtaining meaningful network traffic intelligence in today's extended enterprise.</description>
<pubDate>Tue, 28 Jul 2009 09:55:42 -0400</pubDate>
</item>

<item>
<title>Insider Theft of Intellectual Property for Business Advantage: A Preliminary Model</title>
<link>http://www.cert.org/insider_threat/docs/Insider_Theft_of_IP_Model_MIST09.pdf</link>
<description>This paper provides observations about and a preliminary system dynamics model of one class of insider crime based on empirical data.</description>
<pubDate>Mon, 20 Jul 2009 14:30:18 -0400</pubDate>
</item>

<item>
<title>As-if Infinitely Ranged Integer Model Published</title>
<link>http://www.cert.org/archive/pdf/09tn023.pdf</link>
<description>This paper presents a model for automating the elimination of integer overflow and truncation in C and C++ programming code.</description>
<pubDate>Fri, 17 Jul 2009 16:18:45 -0400</pubDate>
</item>

<item>
<title>First Time Offering, Register Now: Secure Coding in C and C++</title>
<link>http://www.sei.cmu.edu/products/courses/p63.html</link>
<description>This four-day course provides a detailed explanation of common programming errors in C and C++ and describes how these errors can lead to code that is vulnerable to exploitation. The course concentrates on security issues intrinsic to the C and C++ programming languages and associated libraries. The intent is for thiscourse to be useful to anyone involved in developing secure C and C++ programs regardless of the specific application.</description>
<pubDate>Tue, 14 Jul 2009 16:14:49 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Business leaders need new approaches to address multi-enterprise, systems of systems risks across the life cycle and supply chain.</description>
<pubDate>Tue, 07 Jul 2009 12:37:52 -0400</pubDate>
</item>

<item>
<title>Resiliency Management Model v1.0 Released</title>
<link>http://www.cert.org/resiliency/rmm.html</link>
<description>CERT has published the first process areas of the Resiliency Management Model, a capability model for operational resiliency management.</description>
<pubDate>Thu, 02 Jul 2009 08:52:59 -0400</pubDate>
</item>

<item>
<title>Winners of Best Practices Contest 2009 Announced</title>
<link>http://www.cert.org/csirts/national/contest_2009.html</link>
<description>The winners of the Best Practices Contest 2009 were announced at the FIRST conference in Kyoto, Japan. Read the winning submissions.</description>
<pubDate>Mon, 29 Jun 2009 20:31:46 -0400</pubDate>
</item>

<item>
<title>New CERT PGP Public Key</title>
<link>http://www.cert.org/contact_cert/encryptmail.html</link>
<description>CERT has updated its PGP public key. We strongly urge you to encrypt sensitive information.</description>
<pubDate>Mon, 22 Jun 2009 15:18:31 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>When considering cloud services, business leaders need to weigh the economic benefits against the security and privacy risks.</description>
<pubDate>Tue, 16 Jun 2009 10:36:38 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Business leaders need to take action to better mitigate sophisticated social engineering attacks.</description>
<pubDate>Tue, 26 May 2009 10:21:57 -0400</pubDate>
</item>

<item>
<title>Attend the SEI Webinar on May 14</title>
<link>https://www1.gotomeeting.com/register/845945576</link>
<description>Register for the webinar SQUARE Up Your Security Requirements Engineering with SQUARE. This webinar provides an overview of the SQUARE process and discusses current activities and plans.</description>
<pubDate>Fri, 08 May 2009 13:54:42 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Now may be the time to examine our responsibilities when developing software with known, preventable errors - along with some possible consequences.</description>
<pubDate>Tue, 05 May 2009 09:53:59 -0400</pubDate>
</item>

<item>
<title>Making the Business Case for Software Assurance Published</title>
<link>http://www.cert.org/archive/pdf/09sr001.pdf</link>
<description>This report provides guidance for making the business case for building software assurance into software products during each software development life-cycle activity.</description>
<pubDate>Thu, 30 Apr 2009 14:46:23 -0400</pubDate>
</item>

<item>
<title>Register for First Insider Threat Workshop</title>
<link>http://www.sei.cmu.edu/products/courses/p76.html</link>
<description>Learn how to identify and manage the risk of insider threat in your organization. Register now for the two-day Insider Threat Workshop in Arlington, VA.</description>
<pubDate>Fri, 24 Apr 2009 10:45:29 -0400</pubDate>
</item>

<item>
<title>CERT Releases Dranzer Tool</title>
<link>http://www.cert.org/vuls/discovery/dranzer.html</link>
<description>As part of their vulnerability discovery efforts, CERT has released Dranzer, an open source tool that software developers can use to test for ActiveX vulnerabilities.</description>
<pubDate>Thu, 16 Apr 2009 07:29:02 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Capitalizing on the cultural norms of the Net Generation is essential when developing security awareness programs.</description>
<pubDate>Tue, 14 Apr 2009 09:39:41 -0400</pubDate>
</item>

<item>
<title>Linux Forensics Tools Repository Released</title>
<link>http://www.cert.org/forensics/tools/</link>
<description>The CERT forensics tools repository, a collection of add-on packages for Fedora, provides many useful cyber forensics tools for analysts and practitioners.</description>
<pubDate>Mon, 13 Apr 2009 08:54:16 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Observed practice, represented as a maturity model, can serve as a basis for developing more secure software.</description>
<pubDate>Tue, 31 Mar 2009 14:13:41 -0400</pubDate>
</item>

<item>
<title>Secure Design Patterns</title>
<link>http://www.cert.org/archive/pdf/09tr010.pdf</link>
<description>This technical report describes a set of secure design patters, which are descriptions or templates describing a general solution to a security problem that can be applied in many different situations.</description>
<pubDate>Mon, 30 Mar 2009 15:36:06 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Requiring secure coding practices when building or buying software can dramatically reduce vulnerabilities.</description>
<pubDate>Tue, 17 Mar 2009 10:44:00 -0400</pubDate>
</item>

<item>
<title>CERT Program Hosts Leaders in Security</title>
<link>http://www.sei.cmu.edu/about/press/releases/certtechsymposium1.html</link>
<description>On March 10, the CERT Program at Carnegie Mellon University's Software Engineering Institute began a two-day technical symposium for a select group of leaders in experts in the cyber security field.</description>
<pubDate>Wed, 11 Mar 2009 14:48:22 -0400</pubDate>
</item>

<item>
<title>2008 CERT Research Annual Report Published</title>
<link>http://www.cert.org/research/2008research-report.pdf</link>
<description>CERT is developing theoretical foundations and engineering methods to help ensure the security of critical systems and networks. This report describes progress in CERT research projects and opportunities for collaboration.</description>
<pubDate>Fri, 06 Mar 2009 15:20:06 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Making security strategic to business innovation involves seven strategies and calculating risk-reward based on risk appetite.</description>
<pubDate>Tue, 03 Mar 2009 10:40:51 -0500</pubDate>
</item>

<item>
<title>New Course Offering: Insider Threat Workshop</title>
<link>http://www.sei.cmu.edu/products/courses/p76.html</link>
<description>CERT's insider threat research serves as the foundation for this two-day workshop.</description>
<pubDate>Mon, 02 Mar 2009 15:04:56 -0500</pubDate>
</item>

<item>
<title>The CERT/CC and FIRST Announce Best Practices Contest 2009</title>
<link>http://www.first.org/global/practices/</link>
<description>For the second year in a row, the CERT/CC and FIRST are jointly hosting an international competition to honor best practices and advances in safeguarding the security of computer systems and networks.</description>
<pubDate>Wed, 25 Feb 2009 10:42:45 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Teams are better prepared to respond to incidents if realistic, hands-on training is part of their normal routine.</description>
<pubDate>Tue, 17 Feb 2009 11:17:20 -0500</pubDate>
</item>

<item>
<title>Richard Pethia Receives CSO Compass Award</title>
<link>http://www.sei.cmu.edu/about/press/releases/pethia.html</link>
<description>Richard D. Pethia, director of the Carnegie Mellon Software Engineering Institute (SEI) CERT Program has been named a recipient of the 2009 CSO Compass Award sponsored by CSO Magazine.</description>
<pubDate>Tue, 10 Feb 2009 08:28:32 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Standard, compliance, and process are more effective than risk management for ensuring an adequate level of information and software security.</description>
<pubDate>Tue, 03 Feb 2009 11:04:14 -0500</pubDate>
</item>

<item>
<title>Common Sense Guide to Prevention and Detection of Insider Threats, Version 3.1</title>
<link>http://www.cert.org/archive/pdf/CSG-V3.pdf</link>
<description>The third version of this guide includes new and updated practices based on an analysis of approximately 100 recent insider threat cases that occurred from 2003 to 2007 in the United States.</description>
<pubDate>Wed, 28 Jan 2009 09:10:16 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Rich Pethia reflects on CERTs 20-year history and discusses how he is positioning the program to tackle future IT and security challenges.</description>
<pubDate>Tue, 20 Jan 2009 10:48:51 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Being able to effectively respond to e-discovery requests depends on well-defined, enacted policies, procedures, and processes.</description>
<pubDate>Tue, 06 Jan 2009 11:31:58 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Climate change requires new strategies for dealing with traditional IT and information security risks.</description>
<pubDate>Tue, 09 Dec 2008 10:45:28 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Virtual training environments can deliver high quality content to security professionals on-demand, anywhere, anytime.</description>
<pubDate>Tue, 25 Nov 2008 15:05:40 -0500</pubDate>
</item>

<item>
<title>CERT Resiliency Engineering Framework (REF) Outline Published</title>
<link>http://www.cert.org/archive/pdf/REFv0.95R_outline.pdf</link>
<description>This document provides a brief overview of the CERT Resiliency Engineering Framework, including purpose statements, goals, and specific practices for each capability area.</description>
<pubDate>Thu, 13 Nov 2008 09:22:28 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Responding to an e-discovery request involves many of the same steps and roles as responding to a security incident.</description>
<pubDate>Tue, 11 Nov 2008 10:12:01 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>A sustainable security program is based on business-aligned strategy, policy, awareness, implementation, monitoring, and remediation.</description>
<pubDate>Tue, 28 Oct 2008 12:12:47 -0400</pubDate>
</item>

<item>
<title>The CERT C Secure Coding Standard Published</title>
<link>http://www.cert.org/secure-coding/index.html</link>
<description>This book is an essential desktop reference documenting the first official release of the CERT C Secure Coding Standard.</description>
<pubDate>Mon, 20 Oct 2008 11:21:40 -0400</pubDate>
</item>

<item>
<title>CERT Statistics Updated</title>
<link>http://www.cert.org/stats/</link>
<description>The CERT statistics have been updated with numbers from the third quarter of 2008.</description>
<pubDate>Fri, 17 Oct 2008 11:54:32 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>When considering whether to conduct business in online, virtual communities, business leaders need to evaluate risks and opportunities.</description>
<pubDate>Tue, 14 Oct 2008 11:04:29 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Integrating security into university curricula is one of the key solutions to developing more secure software.</description>
<pubDate>Tue, 30 Sep 2008 15:24:21 -0400</pubDate>
</item>

<item>
<title>Interactive Vulnerability Reporting Form Released</title>
<link>https://forms.cert.org/VulReport/</link>
<description>The interactive form enhances CERT's vulnerability analysis efforts by making it easier for vulnerability reporters to securely submit valuable information.</description>
<pubDate>Wed, 17 Sep 2008 15:23:06 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>OCTAVE Allegro provides a streamlined assessment method that focuses on risks to information used by critical business services.</description>
<pubDate>Tue, 16 Sep 2008 10:25:10 -0400</pubDate>
</item>

<item>
<title>Java Secure Coding Standard Released</title>
<link>https://www.securecoding.cert.org/confluence/display/java/CERT+Java+Secure+Coding+Standard</link>
<description>CERT has released the Java Secure Coding Standard in addition to existing secure coding standards for the C and C++ programming languages. CERT invites the Java community to participate in this effort by reviewing content in the Java space and providing comments.</description>
<pubDate>Mon, 08 Sep 2008 15:15:00 -0400</pubDate>
</item>

<item>
<title>New Technical Note Released</title>
<link>http://http://www.cert.org/archive/pdf/08tn017.pdf</link>
<description>Computer Forensics: Results of Live Response Inquiry vs. Memory Image Analysis presents a live response scenario and compares various approaches and tools used to capture and analyze evidence from computer memory.</description>
<pubDate>Tue, 02 Sep 2008 15:46:50 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Well-defined metrics are essential to determine which security practices are worth the investment.</description>
<pubDate>Tue, 02 Sep 2008 10:16:44 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Software security is accomplished by thinking like an attacker and integrating security practices into your software development lifecycle.</description>
<pubDate>Wed, 20 Aug 2008 09:55:06 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Protecting critical infrastructures and the information they use are essential for preserving our way of life.</description>
<pubDate>Tue, 05 Aug 2008 13:22:13 -0400</pubDate>
</item>

<item>
<title>CERT Statistics Updated</title>
<link>http://www.cert.org/stats/</link>
<description>The CERT statistics have been updated with numbers from the second quarter of 2008.</description>
<pubDate>Tue, 29 Jul 2008 15:11:11 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Determining which security vulnerabilities to address should be based on the importance of the information asset.</description>
<pubDate>Tue, 22 Jul 2008 11:39:55 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description></description>
<pubDate>Tue, 22 Jul 2008 11:35:23 -0400</pubDate>
</item>

<item>
<title>CERT Autoresponder Disabled</title>
<link>http://www.cert.org</link>
<description>Because of ongoing problems with the autoresponder messages being interpreted as spam, we have decided to discontinue providing an automatic acknowledgement of email sent to cert@cert.org. This change does not affect how we handle email sent to that address.</description>
<pubDate>Fri, 18 Jul 2008 11:22:39 -0400</pubDate>
</item>


<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>During requirements engineering, software engineers need to think deeply about (and document) how software should behave when under attack.</description>
<pubDate>Tue, 08 Jul 2008 10:54:21 -0400</pubDate>
</item>

<item>
<title>Winners of Best Practices Security Awards Announced</title>
<link>http://www.cert.org/csirts/national/contest_2008.html</link>
<description>The winning papers from the first international competition honoring best practices and advances in safeguarding the security of computer systems and networks have been posted.</description>
<pubDate>Fri, 27 Jun 2008 11:58:07 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Targeted, innovative communications and a robust life cycle are keys for security policy success.</description>
<pubDate>Tue, 24 Jun 2008 11:00:03 -0400</pubDate>
</item>

<item>
<title>Evaluation of CERT Secure Coding Rules through Integration with Source Code Analysis Tools Published</title>
<link>http://www.cert.org/archive/pdf/08tr014.pdf</link>
<description>This report describes a study conducted by the CERT Secure Coding Initiative and JPCERT to evaluate the efficacy of the CERT Secure Coding Standards and source code analysis tools in improving the quality and security of commercial software projects.</description>
<pubDate>Tue, 17 Jun 2008 11:35:48 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Managing software that is developed by an outside organization can be more challenging than building it yourself.</description>
<pubDate>Tue, 10 Jun 2008 11:19:16 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Software security is about building better, more defect-free software to reduce vulnerabilities that are targeted by attackers.</description>
<pubDate>Tue, 27 May 2008 11:52:08 -0400</pubDate>
</item>

<item>
<title>New CERT PGP Public Key</title>
<link>http://www.cert.org/contact_cert/encryptmail.html</link>
<description>CERT has updated its PGP public key. We strongly urge you to encrypt sensitive information.</description>
<pubDate>Fri, 23 May 2008 15:44:07 -0400</pubDate>
</item>

<item>
<title>Making the Business Case for Software Assurance</title>
<link>http://www.sei.cmu.edu/community/assurance.html</link>
<description>This one-day workshop will explore methods for capturing development costs and benefits associated with software assurance and making the case to executive management. A call for papers has been posted; registration information will soon be available.</description>
<pubDate>Thu, 15 May 2008 13:35:04 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>High performing organizations effectively integrate information security controls into mainstream IT operational processes.</description>
<pubDate>Tue, 13 May 2008 11:07:30 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Helping your staff learn how to identify social engineering attempts is the first step in thwarting them.</description>
<pubDate>Tue, 29 Apr 2008 14:37:46 -0400</pubDate>
</item>

<item>
<title>Vulnerability Analysis Blog Published</title>
<link>http://www.cert.org/blogs/vuls/</link>
<description>In a new blog on the CERT website, CERT staff members will address various issues related to vulnerability analysis.</description>
<pubDate>Fri, 18 Apr 2008 12:41:55 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Benchmark results can be used to compare with peers, drive performance, and help determine how much security is enough.</description>
<pubDate>Tue, 15 Apr 2008 12:49:22 -0400</pubDate>
</item>

<item>
<title>CERT Statistics Updated</title>
<link>http://www.cert.org/stats/</link>
<description>The CERT statistics have been updated with numbers from the first quarter of 2008.</description>
<pubDate>Mon, 14 Apr 2008 12:26:34 -0400</pubDate>
</item>

<item> <title>CERT Authors Publish Book About Building Security into Software Products</title> 
<link>http://www.sei.cmu.edu/publications/books/cert/software-security-engineering.html</link> <description>Software Security 
Engineering: A Guide for Project Managers will be published by Addison-Wesley in early May 2008. The book shows project managers how to build 
security into their software products throughout the development life cycle.</description> <pubDate>Tue, 01 Apr 2008 15:12:28 -0400</pubDate> </item>

<item>
<title>Reminder: Entries for Security Awards Due April 30</title>
<link>http://www.first.org/conference/2008/contest.html</link>
<description>Submissions for the first international competition honoring best practices and advances in safeguarding the security of computer systems and networks are due by April 30. The contest is being hosted by FIRST and the CERT/CC.</description>
<pubDate>Tue, 01 Apr 2008 14:08:07 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Aligning with business objectives, integrating with enterprise risks, and collaborating with stakeholders are key to ensuring information privacy.</description>
<pubDate>Tue, 01 Apr 2008 12:43:36 -0400</pubDate>
</item>

<item>
<title>Incident Management Mission Diagnostic Method, Version 1.0 Published</title>
<link>http://www.cert.org/archive/pdf/08tr007.pdf</link>
<description>This report presents a risk-based approach for determining the potential for success of an organization's incident management capability.</description>
<pubDate>Mon, 31 Mar 2008 11:29:16 -0400</pubDate>
</item>

<item>
<title>CERT Sponsors FIRST Conference</title>
<link>http://www.first.org/conference/2008/</link>
<description>CERT is a sponsor for the 2008 FIRST Conference, which will be held in Canada in June. This year marks the 20th annual FIRST conference as well as the 20th anniversary of CERT.</description>
<pubDate>Fri, 28 Mar 2008 11:59:12 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>A sound security metrics program is grounded in selecting data that is relevant to consumers and collecting it from repeatable processes.</description>
<pubDate>Tue, 18 Mar 2008 09:58:37 -0400</pubDate>
</item>

<item>
<title>CERT Resiliency Engineering Framework, v0.95R Available</title>
<link>http://www.cert.org/resiliency_engineering/framework.html</link>
<description>A draft version of the CERT Resiliency Engineering Framework is now available.  We welcome and encourage your feedback on these materials.</description>
<pubDate>Mon, 17 Mar 2008 10:58:45 -0400</pubDate>
</item>

<item>
<title>2007 CERT Research Annual Report Published</title>
<link>http://www.cert.org/research/2007research-report.pdf</link>
<description>CERT is developing theoretical foundations and engineering methods to help ensure the security of critical systems and networks. This report describes progress in CERT research projects and opportunities for collaboration.</description>
<pubDate>Thu, 06 Mar 2008 10:36:25 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Significant insider threat vulnerabilities can be introduced (and mitigated) during all phases of the software development life cycle.</description>
<pubDate>Tue, 04 Mar 2008 10:27:36 -0500</pubDate>
</item>

<item>
<title>FIRST and Carnegie Mellon Software Enginnering Institute CERT Coordination Center Unveil New Security Awards</title>
<link>http://www.first.org/conference/2008/contest.html</link>
<description>The first-ever international competition honoring best practices and advances in safeguarding the security of computer systems and 
networks is announced today by the Forum of Incident Response and Security Teams (FIRST) and Carnegie Software Engineering Institute (SEI) CERT Coordination Center (CERT/CC).</description>
<pubDate>Tue, 26 Feb 2008 09:12:17 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Business leaders need to understand the risks to their organizations caused by the proliferation of botnets.</description>
<pubDate>Tue, 19 Feb 2008 11:20:14 -0500</pubDate>
</item>

<item>
<title>CERT to Participate in Second Annual Counter eCrime Operations Summit</title>
<link>http://www.antiphishing.org/events/2008_operationsSummit.html</link>
<description>CERT will be participating in the Counter eCrime Operations Summit II May 26-27 Tokyo, Japan.</description>
<pubDate>Thu, 14 Feb 2008 11:30:38 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Selecting and reporting meaningful security metrics depend on picking topics of great interest, defining the business context, and having access to sound data.</description>
<pubDate>Tue, 05 Feb 2008 10:47:48 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Selecting and reporting meaningful security metrics depend on picking topics of great interest, defining the business context, and having access to sound data.</description>
<pubDate>Tue, 05 Feb 2008 10:38:57 -0500</pubDate>
</item>

<item>
<title>SQUARE Instructional Materials Released</title>
<link>http://www.cert.org/sse/square/square-description.html</link>
<description>Workshop, tutorial, and academic educational materials on SQUARE (Security Quality Requirements Engineering) are now available for download.</description>
<pubDate>Tue, 22 Jan 2008 10:54:03 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Peer-to-peer networks are being used today to unintentionally disclose government, commercial, and personal information.</description>
<pubDate>Tue, 22 Jan 2008 10:20:34 -0500</pubDate>
</item>

<item>
<title>CERT Statistics Updated</title>
<link>http://www.cert.org/stats/</link>
<description>The numbers from the fourth quarter have been incorporated, completing the 2007 statistics.</description>
<pubDate>Tue, 15 Jan 2008 16:29:00 -0500</pubDate>
</item>

<item>
<title>Insider Threat Studies Released</title>
<link>http://www.cert.org/insider_threat/</link>
<description>Insider Threat Study: Illicit Cyber Activity in the Government Sector and Insider Threat Study: Illicit Cyber Activity in the Information Technology and Telecommunications Sector have been released. These reports present the findings of research efforts to examine reported insider incidents within their respective sectors.</description>
<pubDate>Wed, 09 Jan 2008 08:54:15 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Directors and senior executives are personally accountable for protecting information entrusted to their care.</description>
<pubDate>Tue, 08 Jan 2008 10:24:08 -0500</pubDate>
</item>

</channel>
</rss>


