<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">

<channel>
<title>CERT Announcements</title>
<link>http://www.cert.org/nav/whatsnew.html</link>
<language>en-us</language>
<description>Announcements: What's New on the CERT web site</description>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Students learn how to combine multiple facets of digital forensics and draw conclusions to support full-scale investigations.</description>
<pubDate>Tue, 02 Feb 2010 09:32:46 -0500</pubDate>
</item>

<item>
<title>New CERT PGP Public Key</title>
<link>http://www.cert.org/contact_cert/encryptmail.html</link>
<description>CERT has updated its PGP public key. We strongly urge you to encrypt sensitive information.</description>
<pubDate>Wed, 20 Jan 2010 14:14:25 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>The SGMM provides a roadmap to guide an organization's transformation to the smart grid.</description>
<pubDate>Tue, 12 Jan 2010 09:51:21 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Addressing privacy during software development is just as important as addressing security.</description>
<pubDate>Tue, 22 Dec 2009 09:44:19 -0500</pubDate>
</item>

<item>
<title>SQUARE Tool Is Now Available</title>
<link>http://www.cert.org</link>
<description></description>
<pubDate>Fri, 04 Dec 2009 16:32:28 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Network defenders and business leaders can use NetSA measures and evidence to better protect their networks.</description>
<pubDate>Tue, 01 Dec 2009 09:49:51 -0500</pubDate>
</item>

<item>
<title>CERT Tactical Response and Analysis Challege Tests Cybersecurity Skills</title>
<link>http://www.cert.orghttp://www.sei.cmu.edu/newsitems/cert_TRAC.cfm</link>
<description>Twenty-nine competing teams from 20 countries participated in the Tactical Response and Analysis Challenge (TRAC) conducted by the SEI's CERT PRogram as part of the weeklong International Cyber Defense Workshop (ICDW), which concluded November 13, 2009.</description>
<pubDate>Tue, 17 Nov 2009 14:39:21 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Providing critical services during times of stress depends on documented, tested business continuity plans.</description>
<pubDate>Tue, 10 Nov 2009 10:24:37 -0500</pubDate>
</item>

<item>
<title>Spotlight On - Insider Theft of Intellectual Property inside the U.S. Involving Foreign Governments or Organizations</title>
<link>http://www.cert.org/archive/pdf/CyLabForeignTheftIP.pdf</link>                                                                                             
<description>This report is the third in the quarterly series, Spotlight On, published by the Insider Threat Center at CERT and funded by CyLab. This article focuses on insider theft of intellectual property inside the U.S. involving foreign governments or organizations.</description>
<pubDate>Mon, 09 Nov 2009 13:23:01 -0500</pubDate>
</item>

<item>
<title>Deadline for FloCon Abstracts Extended</title>
<link>http://www.cert.org/flocon/</link>
<description>The deadline to submit abstracts for presentations and demonstrations for FloCon 2010 has been extended to Monday, November 9.</description>
<pubDate>Tue, 27 Oct 2009 11:35:44 -0400</pubDate>
</item>

<item>
<title>Secure Design Patterns</title>
<link>http://www.cert.org/archive/pdf/09tr010.pdf</link>
<description>This newly updated technical report describes a set of secure design patterns, which are descriptions or templates describing a general solution to a security problem that can be applied in many different situations.</description>
<pubDate>Fri, 23 Oct 2009 11:49:52 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>A defined, managed process for third party relationships is essential, particularly when business is disrupted.</description>
<pubDate>Tue, 20 Oct 2009 14:52:15 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>The smart grid is the use of digital technology to modernize the power grid, which comes with some new privacy and security challenges.</description>
<pubDate>Tue, 29 Sep 2009 10:27:54 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Electronic health records (EHRs) are possibly the most complicated area of IT today, more difficult than defense.</description>
<pubDate>Tue, 08 Sep 2009 10:52:58 -0400</pubDate>
</item>

<item>
<title>Effectiveness of the Vulnerability Response Decision Assistance (VRDA) Framework</title>
<link>http://www.cert.org/archive/pdf/VRDA_Effectiveness.pdf</link>
<description>This paper examines the effectiveness of VRDA in terms of how well it predicts responses.</description>
<pubDate>Tue, 25 Aug 2009 11:18:10 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>282 cases of actual insider attacks suggest 16 best practices for preventing and detecting insider threat.</description>
<pubDate>Tue, 18 Aug 2009 11:20:50 -0400</pubDate>
</item>

<item>
<title>Spotlight On: Malicious Insiders with Ties to the Internet Underground Community (pdf), March 2009</title>
<link>http://www.cert.org/insider_threat/docs/CyLab%20Insider%20Threat%20Quarterly%20on%20Internet%20Underground%20-%20March%202009P.pdf</link>
<description>This report is the second in the quarterly series, Spotlight On, published by the Insider Threat Center at CERT and funded by CyLab. This article focuses on insider threat cases in which the insider had relationships with the internet underground community.</description>
<pubDate>Fri, 31 Jul 2009 11:46:23 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Automation, innovation, reaction, and expansion are the foundation for obtaining meaningful network traffic intelligence in today's extended enterprise.</description>
<pubDate>Tue, 28 Jul 2009 09:55:42 -0400</pubDate>
</item>

<item>
<title>Insider Theft of Intellectual Property for Business Advantage: A Preliminary Model</title>
<link>http://www.cert.org/insider_threat/docs/Insider_Theft_of_IP_Model_MIST09.pdf</link>
<description>This paper provides observations about and a preliminary system dynamics model of one class of insider crime based on empirical data.</description>
<pubDate>Mon, 20 Jul 2009 14:30:18 -0400</pubDate>
</item>

<item>
<title>As-if Infinitely Ranged Integer Model Published</title>
<link>http://www.cert.org/archive/pdf/09tn023.pdf</link>
<description>This paper presents a model for automating the elimination of integer overflow and truncation in C and C++ programming code.</description>
<pubDate>Fri, 17 Jul 2009 16:18:45 -0400</pubDate>
</item>

<item>
<title>First Time Offering, Register Now: Secure Coding in C and C++</title>
<link>http://www.sei.cmu.edu/products/courses/p63.html</link>
<description>This four-day course provides a detailed explanation of common programming errors in C and C++ and describes how these errors can lead to code that is vulnerable to exploitation. The course concentrates on security issues intrinsic to the C and C++ programming languages and associated libraries. The intent is for thiscourse to be useful to anyone involved in developing secure C and C++ programs regardless of the specific application.</description>
<pubDate>Tue, 14 Jul 2009 16:14:49 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Business leaders need new approaches to address multi-enterprise, systems of systems risks across the life cycle and supply chain.</description>
<pubDate>Tue, 07 Jul 2009 12:37:52 -0400</pubDate>
</item>

<item>
<title>Resiliency Management Model v1.0 Released</title>
<link>http://www.cert.org/resiliency/rmm.html</link>
<description>CERT has published the first process areas of the Resiliency Management Model, a capability model for operational resiliency management.</description>
<pubDate>Thu, 02 Jul 2009 08:52:59 -0400</pubDate>
</item>

<item>
<title>Winners of Best Practices Contest 2009 Announced</title>
<link>http://www.cert.org/csirts/national/contest_2009.html</link>
<description>The winners of the Best Practices Contest 2009 were announced at the FIRST conference in Kyoto, Japan. Read the winning submissions.</description>
<pubDate>Mon, 29 Jun 2009 20:31:46 -0400</pubDate>
</item>

<item>
<title>New CERT PGP Public Key</title>
<link>http://www.cert.org/contact_cert/encryptmail.html</link>
<description>CERT has updated its PGP public key. We strongly urge you to encrypt sensitive information.</description>
<pubDate>Mon, 22 Jun 2009 15:18:31 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>When considering cloud services, business leaders need to weigh the economic benefits against the security and privacy risks.</description>
<pubDate>Tue, 16 Jun 2009 10:36:38 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Business leaders need to take action to better mitigate sophisticated social engineering attacks.</description>
<pubDate>Tue, 26 May 2009 10:21:57 -0400</pubDate>
</item>

<item>
<title>Attend the SEI Webinar on May 14</title>
<link>https://www1.gotomeeting.com/register/845945576</link>
<description>Register for the webinar SQUARE Up Your Security Requirements Engineering with SQUARE. This webinar provides an overview of the SQUARE process and discusses current activities and plans.</description>
<pubDate>Fri, 08 May 2009 13:54:42 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Now may be the time to examine our responsibilities when developing software with known, preventable errors - along with some possible consequences.</description>
<pubDate>Tue, 05 May 2009 09:53:59 -0400</pubDate>
</item>

<item>
<title>Making the Business Case for Software Assurance Published</title>
<link>http://www.cert.org/archive/pdf/09sr001.pdf</link>
<description>This report provides guidance for making the business case for building software assurance into software products during each software development life-cycle activity.</description>
<pubDate>Thu, 30 Apr 2009 14:46:23 -0400</pubDate>
</item>

<item>
<title>Register for First Insider Threat Workshop</title>
<link>http://www.sei.cmu.edu/products/courses/p76.html</link>
<description>Learn how to identify and manage the risk of insider threat in your organization. Register now for the two-day Insider Threat Workshop in Arlington, VA.</description>
<pubDate>Fri, 24 Apr 2009 10:45:29 -0400</pubDate>
</item>

<item>
<title>CERT Releases Dranzer Tool</title>
<link>http://www.cert.org/vuls/discovery/dranzer.html</link>
<description>As part of their vulnerability discovery efforts, CERT has released Dranzer, an open source tool that software developers can use to test for ActiveX vulnerabilities.</description>
<pubDate>Thu, 16 Apr 2009 07:29:02 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Capitalizing on the cultural norms of the Net Generation is essential when developing security awareness programs.</description>
<pubDate>Tue, 14 Apr 2009 09:39:41 -0400</pubDate>
</item>

<item>
<title>Linux Forensics Tools Repository Released</title>
<link>http://www.cert.org/forensics/tools/</link>
<description>The CERT forensics tools repository, a collection of add-on packages for Fedora, provides many useful cyber forensics tools for analysts and practitioners.</description>
<pubDate>Mon, 13 Apr 2009 08:54:16 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Observed practice, represented as a maturity model, can serve as a basis for developing more secure software.</description>
<pubDate>Tue, 31 Mar 2009 14:13:41 -0400</pubDate>
</item>

<item>
<title>Secure Design Patterns</title>
<link>http://www.cert.org/archive/pdf/09tr010.pdf</link>
<description>This technical report describes a set of secure design patters, which are descriptions or templates describing a general solution to a security problem that can be applied in many different situations.</description>
<pubDate>Mon, 30 Mar 2009 15:36:06 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Requiring secure coding practices when building or buying software can dramatically reduce vulnerabilities.</description>
<pubDate>Tue, 17 Mar 2009 10:44:00 -0400</pubDate>
</item>

<item>
<title>CERT Program Hosts Leaders in Security</title>
<link>http://www.sei.cmu.edu/about/press/releases/certtechsymposium1.html</link>
<description>On March 10, the CERT Program at Carnegie Mellon University's Software Engineering Institute began a two-day technical symposium for a select group of leaders in experts in the cyber security field.</description>
<pubDate>Wed, 11 Mar 2009 14:48:22 -0400</pubDate>
</item>

<item>
<title>2008 CERT Research Annual Report Published</title>
<link>http://www.cert.org/research/2008research-report.pdf</link>
<description>CERT is developing theoretical foundations and engineering methods to help ensure the security of critical systems and networks. This report describes progress in CERT research projects and opportunities for collaboration.</description>
<pubDate>Fri, 06 Mar 2009 15:20:06 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Making security strategic to business innovation involves seven strategies and calculating risk-reward based on risk appetite.</description>
<pubDate>Tue, 03 Mar 2009 10:40:51 -0500</pubDate>
</item>

<item>
<title>New Course Offering: Insider Threat Workshop</title>
<link>http://www.sei.cmu.edu/products/courses/p76.html</link>
<description>CERT's insider threat research serves as the foundation for this two-day workshop.</description>
<pubDate>Mon, 02 Mar 2009 15:04:56 -0500</pubDate>
</item>

<item>
<title>The CERT/CC and FIRST Announce Best Practices Contest 2009</title>
<link>http://www.first.org/global/practices/</link>
<description>For the second year in a row, the CERT/CC and FIRST are jointly hosting an international competition to honor best practices and advances in safeguarding the security of computer systems and networks.</description>
<pubDate>Wed, 25 Feb 2009 10:42:45 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Teams are better prepared to respond to incidents if realistic, hands-on training is part of their normal routine.</description>
<pubDate>Tue, 17 Feb 2009 11:17:20 -0500</pubDate>
</item>

<item>
<title>Richard Pethia Receives CSO Compass Award</title>
<link>http://www.sei.cmu.edu/about/press/releases/pethia.html</link>
<description>Richard D. Pethia, director of the Carnegie Mellon Software Engineering Institute (SEI) CERT Program has been named a recipient of the 2009 CSO Compass Award sponsored by CSO Magazine.</description>
<pubDate>Tue, 10 Feb 2009 08:28:32 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Standard, compliance, and process are more effective than risk management for ensuring an adequate level of information and software security.</description>
<pubDate>Tue, 03 Feb 2009 11:04:14 -0500</pubDate>
</item>

<item>
<title>Common Sense Guide to Prevention and Detection of Insider Threats, Version 3.1</title>
<link>http://www.cert.org/archive/pdf/CSG-V3.pdf</link>
<description>The third version of this guide includes new and updated practices based on an analysis of approximately 100 recent insider threat cases that occurred from 2003 to 2007 in the United States.</description>
<pubDate>Wed, 28 Jan 2009 09:10:16 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Rich Pethia reflects on CERTs 20-year history and discusses how he is positioning the program to tackle future IT and security challenges.</description>
<pubDate>Tue, 20 Jan 2009 10:48:51 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Being able to effectively respond to e-discovery requests depends on well-defined, enacted policies, procedures, and processes.</description>
<pubDate>Tue, 06 Jan 2009 11:31:58 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Climate change requires new strategies for dealing with traditional IT and information security risks.</description>
<pubDate>Tue, 09 Dec 2008 10:45:28 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Virtual training environments can deliver high quality content to security professionals on-demand, anywhere, anytime.</description>
<pubDate>Tue, 25 Nov 2008 15:05:40 -0500</pubDate>
</item>

<item>
<title>CERT Resiliency Engineering Framework (REF) Outline Published</title>
<link>http://www.cert.org/archive/pdf/REFv0.95R_outline.pdf</link>
<description>This document provides a brief overview of the CERT Resiliency Engineering Framework, including purpose statements, goals, and specific practices for each capability area.</description>
<pubDate>Thu, 13 Nov 2008 09:22:28 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Responding to an e-discovery request involves many of the same steps and roles as responding to a security incident.</description>
<pubDate>Tue, 11 Nov 2008 10:12:01 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>A sustainable security program is based on business-aligned strategy, policy, awareness, implementation, monitoring, and remediation.</description>
<pubDate>Tue, 28 Oct 2008 12:12:47 -0400</pubDate>
</item>

<item>
<title>The CERT C Secure Coding Standard Published</title>
<link>http://www.cert.org/secure-coding/index.html</link>
<description>This book is an essential desktop reference documenting the first official release of the CERT C Secure Coding Standard.</description>
<pubDate>Mon, 20 Oct 2008 11:21:40 -0400</pubDate>
</item>

<item>
<title>CERT Statistics Updated</title>
<link>http://www.cert.org/stats/</link>
<description>The CERT statistics have been updated with numbers from the third quarter of 2008.</description>
<pubDate>Fri, 17 Oct 2008 11:54:32 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>When considering whether to conduct business in online, virtual communities, business leaders need to evaluate risks and opportunities.</description>
<pubDate>Tue, 14 Oct 2008 11:04:29 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Integrating security into university curricula is one of the key solutions to developing more secure software.</description>
<pubDate>Tue, 30 Sep 2008 15:24:21 -0400</pubDate>
</item>

<item>
<title>Interactive Vulnerability Reporting Form Released</title>
<link>https://forms.cert.org/VulReport/</link>
<description>The interactive form enhances CERT's vulnerability analysis efforts by making it easier for vulnerability reporters to securely submit valuable information.</description>
<pubDate>Wed, 17 Sep 2008 15:23:06 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>OCTAVE Allegro provides a streamlined assessment method that focuses on risks to information used by critical business services.</description>
<pubDate>Tue, 16 Sep 2008 10:25:10 -0400</pubDate>
</item>

<item>
<title>Java Secure Coding Standard Released</title>
<link>https://www.securecoding.cert.org/confluence/display/java/CERT+Java+Secure+Coding+Standard</link>
<description>CERT has released the Java Secure Coding Standard in addition to existing secure coding standards for the C and C++ programming languages. CERT invites the Java community to participate in this effort by reviewing content in the Java space and providing comments.</description>
<pubDate>Mon, 08 Sep 2008 15:15:00 -0400</pubDate>
</item>

<item>
<title>New Technical Note Released</title>
<link>http://http://www.cert.org/archive/pdf/08tn017.pdf</link>
<description>Computer Forensics: Results of Live Response Inquiry vs. Memory Image Analysis presents a live response scenario and compares various approaches and tools used to capture and analyze evidence from computer memory.</description>
<pubDate>Tue, 02 Sep 2008 15:46:50 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Well-defined metrics are essential to determine which security practices are worth the investment.</description>
<pubDate>Tue, 02 Sep 2008 10:16:44 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Software security is accomplished by thinking like an attacker and integrating security practices into your software development lifecycle.</description>
<pubDate>Wed, 20 Aug 2008 09:55:06 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Protecting critical infrastructures and the information they use are essential for preserving our way of life.</description>
<pubDate>Tue, 05 Aug 2008 13:22:13 -0400</pubDate>
</item>

<item>
<title>CERT Statistics Updated</title>
<link>http://www.cert.org/stats/</link>
<description>The CERT statistics have been updated with numbers from the second quarter of 2008.</description>
<pubDate>Tue, 29 Jul 2008 15:11:11 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Determining which security vulnerabilities to address should be based on the importance of the information asset.</description>
<pubDate>Tue, 22 Jul 2008 11:39:55 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description></description>
<pubDate>Tue, 22 Jul 2008 11:35:23 -0400</pubDate>
</item>

<item>
<title>CERT Autoresponder Disabled</title>
<link>http://www.cert.org</link>
<description>Because of ongoing problems with the autoresponder messages being interpreted as spam, we have decided to discontinue providing an automatic acknowledgement of email sent to cert@cert.org. This change does not affect how we handle email sent to that address.</description>
<pubDate>Fri, 18 Jul 2008 11:22:39 -0400</pubDate>
</item>


<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>During requirements engineering, software engineers need to think deeply about (and document) how software should behave when under attack.</description>
<pubDate>Tue, 08 Jul 2008 10:54:21 -0400</pubDate>
</item>

<item>
<title>Winners of Best Practices Security Awards Announced</title>
<link>http://www.cert.org/csirts/national/contest_2008.html</link>
<description>The winning papers from the first international competition honoring best practices and advances in safeguarding the security of computer systems and networks have been posted.</description>
<pubDate>Fri, 27 Jun 2008 11:58:07 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Targeted, innovative communications and a robust life cycle are keys for security policy success.</description>
<pubDate>Tue, 24 Jun 2008 11:00:03 -0400</pubDate>
</item>

<item>
<title>Evaluation of CERT Secure Coding Rules through Integration with Source Code Analysis Tools Published</title>
<link>http://www.cert.org/archive/pdf/08tr014.pdf</link>
<description>This report describes a study conducted by the CERT Secure Coding Initiative and JPCERT to evaluate the efficacy of the CERT Secure Coding Standards and source code analysis tools in improving the quality and security of commercial software projects.</description>
<pubDate>Tue, 17 Jun 2008 11:35:48 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Managing software that is developed by an outside organization can be more challenging than building it yourself.</description>
<pubDate>Tue, 10 Jun 2008 11:19:16 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Software security is about building better, more defect-free software to reduce vulnerabilities that are targeted by attackers.</description>
<pubDate>Tue, 27 May 2008 11:52:08 -0400</pubDate>
</item>

<item>
<title>New CERT PGP Public Key</title>
<link>http://www.cert.org/contact_cert/encryptmail.html</link>
<description>CERT has updated its PGP public key. We strongly urge you to encrypt sensitive information.</description>
<pubDate>Fri, 23 May 2008 15:44:07 -0400</pubDate>
</item>

<item>
<title>Making the Business Case for Software Assurance</title>
<link>http://www.sei.cmu.edu/community/assurance.html</link>
<description>This one-day workshop will explore methods for capturing development costs and benefits associated with software assurance and making the case to executive management. A call for papers has been posted; registration information will soon be available.</description>
<pubDate>Thu, 15 May 2008 13:35:04 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>High performing organizations effectively integrate information security controls into mainstream IT operational processes.</description>
<pubDate>Tue, 13 May 2008 11:07:30 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Helping your staff learn how to identify social engineering attempts is the first step in thwarting them.</description>
<pubDate>Tue, 29 Apr 2008 14:37:46 -0400</pubDate>
</item>

<item>
<title>Vulnerability Analysis Blog Published</title>
<link>http://www.cert.org/blogs/vuls/</link>
<description>In a new blog on the CERT website, CERT staff members will address various issues related to vulnerability analysis.</description>
<pubDate>Fri, 18 Apr 2008 12:41:55 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Benchmark results can be used to compare with peers, drive performance, and help determine how much security is enough.</description>
<pubDate>Tue, 15 Apr 2008 12:49:22 -0400</pubDate>
</item>

<item>
<title>CERT Statistics Updated</title>
<link>http://www.cert.org/stats/</link>
<description>The CERT statistics have been updated with numbers from the first quarter of 2008.</description>
<pubDate>Mon, 14 Apr 2008 12:26:34 -0400</pubDate>
</item>

<item> <title>CERT Authors Publish Book About Building Security into Software Products</title> 
<link>http://www.sei.cmu.edu/publications/books/cert/software-security-engineering.html</link> <description>Software Security 
Engineering: A Guide for Project Managers will be published by Addison-Wesley in early May 2008. The book shows project managers how to build 
security into their software products throughout the development life cycle.</description> <pubDate>Tue, 01 Apr 2008 15:12:28 -0400</pubDate> </item>

<item>
<title>Reminder: Entries for Security Awards Due April 30</title>
<link>http://www.first.org/conference/2008/contest.html</link>
<description>Submissions for the first international competition honoring best practices and advances in safeguarding the security of computer systems and networks are due by April 30. The contest is being hosted by FIRST and the CERT/CC.</description>
<pubDate>Tue, 01 Apr 2008 14:08:07 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Aligning with business objectives, integrating with enterprise risks, and collaborating with stakeholders are key to ensuring information privacy.</description>
<pubDate>Tue, 01 Apr 2008 12:43:36 -0400</pubDate>
</item>

<item>
<title>Incident Management Mission Diagnostic Method, Version 1.0 Published</title>
<link>http://www.cert.org/archive/pdf/08tr007.pdf</link>
<description>This report presents a risk-based approach for determining the potential for success of an organization's incident management capability.</description>
<pubDate>Mon, 31 Mar 2008 11:29:16 -0400</pubDate>
</item>

<item>
<title>CERT Sponsors FIRST Conference</title>
<link>http://www.first.org/conference/2008/</link>
<description>CERT is a sponsor for the 2008 FIRST Conference, which will be held in Canada in June. This year marks the 20th annual FIRST conference as well as the 20th anniversary of CERT.</description>
<pubDate>Fri, 28 Mar 2008 11:59:12 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>A sound security metrics program is grounded in selecting data that is relevant to consumers and collecting it from repeatable processes.</description>
<pubDate>Tue, 18 Mar 2008 09:58:37 -0400</pubDate>
</item>

<item>
<title>CERT Resiliency Engineering Framework, v0.95R Available</title>
<link>http://www.cert.org/resiliency_engineering/framework.html</link>
<description>A draft version of the CERT Resiliency Engineering Framework is now available.  We welcome and encourage your feedback on these materials.</description>
<pubDate>Mon, 17 Mar 2008 10:58:45 -0400</pubDate>
</item>

<item>
<title>2007 CERT Research Annual Report Published</title>
<link>http://www.cert.org/research/2007research-report.pdf</link>
<description>CERT is developing theoretical foundations and engineering methods to help ensure the security of critical systems and networks. This report describes progress in CERT research projects and opportunities for collaboration.</description>
<pubDate>Thu, 06 Mar 2008 10:36:25 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Significant insider threat vulnerabilities can be introduced (and mitigated) during all phases of the software development life cycle.</description>
<pubDate>Tue, 04 Mar 2008 10:27:36 -0500</pubDate>
</item>

<item>
<title>FIRST and Carnegie Mellon Software Enginnering Institute CERT Coordination Center Unveil New Security Awards</title>
<link>http://www.first.org/conference/2008/contest.html</link>
<description>The first-ever international competition honoring best practices and advances in safeguarding the security of computer systems and 
networks is announced today by the Forum of Incident Response and Security Teams (FIRST) and Carnegie Software Engineering Institute (SEI) CERT Coordination Center (CERT/CC).</description>
<pubDate>Tue, 26 Feb 2008 09:12:17 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Business leaders need to understand the risks to their organizations caused by the proliferation of botnets.</description>
<pubDate>Tue, 19 Feb 2008 11:20:14 -0500</pubDate>
</item>

<item>
<title>CERT to Participate in Second Annual Counter eCrime Operations Summit</title>
<link>http://www.antiphishing.org/events/2008_operationsSummit.html</link>
<description>CERT will be participating in the Counter eCrime Operations Summit II May 26-27 Tokyo, Japan.</description>
<pubDate>Thu, 14 Feb 2008 11:30:38 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Selecting and reporting meaningful security metrics depend on picking topics of great interest, defining the business context, and having access to sound data.</description>
<pubDate>Tue, 05 Feb 2008 10:47:48 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Selecting and reporting meaningful security metrics depend on picking topics of great interest, defining the business context, and having access to sound data.</description>
<pubDate>Tue, 05 Feb 2008 10:38:57 -0500</pubDate>
</item>

<item>
<title>SQUARE Instructional Materials Released</title>
<link>http://www.cert.org/sse/square/square-description.html</link>
<description>Workshop, tutorial, and academic educational materials on SQUARE (Security Quality Requirements Engineering) are now available for download.</description>
<pubDate>Tue, 22 Jan 2008 10:54:03 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Peer-to-peer networks are being used today to unintentionally disclose government, commercial, and personal information.</description>
<pubDate>Tue, 22 Jan 2008 10:20:34 -0500</pubDate>
</item>

<item>
<title>CERT Statistics Updated</title>
<link>http://www.cert.org/stats/</link>
<description>The numbers from the fourth quarter have been incorporated, completing the 2007 statistics.</description>
<pubDate>Tue, 15 Jan 2008 16:29:00 -0500</pubDate>
</item>

<item>
<title>Insider Threat Studies Released</title>
<link>http://www.cert.org/insider_threat/</link>
<description>Insider Threat Study: Illicit Cyber Activity in the Government Sector and Insider Threat Study: Illicit Cyber Activity in the Information Technology and Telecommunications Sector have been released. These reports present the findings of research efforts to examine reported insider incidents within their respective sectors.</description>
<pubDate>Wed, 09 Jan 2008 08:54:15 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Directors and senior executives are personally accountable for protecting information entrusted to their care.</description>
<pubDate>Tue, 08 Jan 2008 10:24:08 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Internal Audit can serve a key role in putting an effective information security program in place, and keeping it there.</description>
<pubDate>Mon, 10 Dec 2007 22:22:17 -0500</pubDate>
</item>

<item>
<title>FloCon 2008 Schedule Available</title>
<link>http://www.cert.org/flocon/2008/schedule/</link>
<description>The schedule for the FloCon 2008 conference has been released.</description>
<pubDate>Thu, 29 Nov 2007 12:43:57 -0500</pubDate>
</item>

<item>
<title>FBI Announces Results of Operation Bot Roast II</title>
<link>http://www.fbi.gov/page2/nov07/botnet112907.html</link>
<description>In the second phase of the FBI investigation of botnets, 8 people were indicted, pled guilty, or were sentenced. So far, more than $20 million in losses and more than 1 million victim computers have been identified. Learn how to prevent and report attacks.</description>
<pubDate>Thu, 29 Nov 2007 11:14:16 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Information security degree programs are proliferating, but what do they really offer business leaders who are seeking knowledgeable employees&#63;</description>
<pubDate>Tue, 27 Nov 2007 12:22:15 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Information security risk assessment, performed in concert with operational risk management, can contribute to compliance as an outcome.</description>
<pubDate>Tue, 13 Nov 2007 12:11:08 -0500</pubDate>
</item>

<item>
<title>CERT NetSA Group Participates in Anti-Phishing Working Group eCrime Research Summit</title>
<link>http://www.cert.org/netsa/</link>
<description>Members of the CERT Network Situational Awarness Group presented Fishing for Phishes: Applying Capture-Recaputre Methods to Estimate Phishing Populations at the APWG eCrime Researchers Summit. They also 
participated in the Report out and Panel: Uncleanliness: Quantifying network reputation.</description>
<pubDate>Thu, 01 Nov 2007 11:54:42 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Business Leaders can play a key role in computer forensics by establishing strong policies and proactively testing to ensure those policies work in tough situations.</description>
<pubDate>Tue, 30 Oct 2007 11:55:11 -0400</pubDate>
</item>

<item>
<title>CERT Statistics Updated</title>
<link>http://www.cert.org/stats/</link>
<description>The CERT statistics have been updated with numbers from the third quarter of 2007.</description>
<pubDate>Tue, 16 Oct 2007 14:45:14 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>A business resilience argument can bridge the communication gap that often exists between information security officers and business leaders.</description>
<pubDate>Tue, 16 Oct 2007 11:19:12 -0400</pubDate>
</item>

<item>
<title>Vodcast - Secure Coding Initiative: Project</title>
<link>http://www.cert.org/vodcast/secure-coding/project.html</link>
<description>Robert Seacord discusses the Secure Coding project.</description>
<pubDate>Tue, 09 Oct 2007 11:17:59 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>By taking a holistic view of business resilience - similar in many ways to classical engineering - business leaders can help their operations stand up to known and unknown threats.</description>
<pubDate>Tue, 02 Oct 2007 11:33:23 -0400</pubDate>
</item>

<item>
<title>FloCon 2008 Call for Presentations</title>
<link>http://www.cert.org/flocon/2008/index.html</link>
<description>The submission deadline for FloCon 2008 is fast approaching! Send a description of your presentation in before midnight October 5, 2007.</description>
<pubDate>Fri, 21 Sep 2007 10:01:39 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>It's easy to think of security as a collection of technologies and tools - but people are the real key to any security effort.</description>
<pubDate>Tue, 18 Sep 2007 11:23:42 -0400</pubDate>
</item>

<item>
<title>Ranged Integers for the C Programming Language</title>
<link>http://www.cert.org/archive/pdf/07tn027.pdf</link>
<description>This report describes an extension to the C programming language to introduce the notion of ranged integers, that is, integer types with a defined range of values.</description>
<pubDate>Thu, 13 Sep 2007 09:48:48 -0400</pubDate>
</item>

<item>
<title>Resiliency Engineering Framework and Service Oriented Architecture Information Sessions</title>
<link>http://www.cert.org/resiliency_engineering/index.html#events</link>
<description>Special information sessions for technical managers, software engineers, and decision makers on the CERT Resiliency Engineering Framework (REF) and Service Oriented Architecture (SOA) are scheduled for October 16 in Frankfurt, Germany, and October 18 in London. More information is available on the SEI site.</description>
<pubDate>Wed, 12 Sep 2007 15:27:04 -0400</pubDate>
</item>

<item>
<title>2007 E-Crime Watch Survey</title>
<link>http://www.cert.org/archive/pdf/ecrimesummary07.pdf</link>
<description>The 4th annual E-Crime Watch Survey has been released by CERT, the US Secret Service, CSO Magazine, and Microsoft.</description>
<pubDate>Tue, 11 Sep 2007 08:45:08 -0400</pubDate>
</item>

<item>
<title>Vodcast: Secure Coding Standards Work</title>
<link>http://www.cert.org/vodcast/secure-coding/standards.html</link>
<description>Robert Seacord talks about the development of secure coding rules and recommendations for C, C++. and other programming languages.</description>
<pubDate>Fri, 07 Sep 2007 13:05:04 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Given that you can't secure everything, managing security risk to a &quot;commercially reasonable degree&quot; can lead to the best possible solution.</description>
<pubDate>Tue, 04 Sep 2007 15:39:52 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Business leaders can use national CSIRTs (Computer Security Incident Response Teams) as a key resource when dealing with incidents with a national or worldwide scope.</description>
<pubDate>Tue, 21 Aug 2007 11:43:44 -0400</pubDate>
</item>

<item>
<title>Vodcast: Training Provided through CERT's Secure Coding Initiative</title>
<link>http://www.cert.org/vodcast/training.html</link>
<description>Robert Seacord discusses CERT's offerings in the realm of training in secure coding.</description>
<pubDate>Tue, 07 Aug 2007 11:43:24 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Information security costs can be significantly reduced by enforcing standard configurations for widely deployed systems.</description>
<pubDate>Tue, 07 Aug 2007 11:19:59 -0400</pubDate>
</item>

<item>
<title>Beta Implementation of Managed String Library  Released</title>
<link>http://www.cert.org/secure-coding/managedstring.html</link>
<description>The beta version of the managed string library, developed to improve the quality and security of newly developed C-language programs, is now available.</description>
<pubDate>Thu, 02 Aug 2007 16:03:53 -0400</pubDate>
</item>

<item>
<title>Microsoft Recognizes CERT Analyst</title>
<link>http://www.microsoft.com/technet/security/acknowledge/default.mspx</link>
<description>Microsoft has acknowledged Will Dormann of the CERT/CC for identifying and helping to remediate security vulnerabilities in their online services. Will is one of eleven individuals recognized for their efforts.</description>
<pubDate>Thu, 02 Aug 2007 11:55:15 -0400</pubDate>
</item>

<item>
<title>CERT Statistics Updated</title>
<link>http://www.cert.org/stats/</link>
<description>The layout of the statistics has been updated, and numbers have been added for the second quarter of 2007.</description>
<pubDate>Thu, 26 Jul 2007 10:51:50 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Security is not an option - but it may be time to start viewing it as a business enabler, rather than just a cost of doing business.</description>
<pubDate>Tue, 24 Jul 2007 15:28:42 -0400</pubDate>
</item>

<item>
<title>CERT Secure Coding Tutorial at SANS Network Security 2007</title>
<link>http://www.cert.org</link>
<description>Robert Seacord will conduct a tutorial, "Secure Coding in C and C++" on September 29 - 30, 2007 at SANS Network Security 2007 in Las Vegas, NV.</description>
<pubDate>Tue, 24 Jul 2007 14:06:51 -0400</pubDate>
</item>

<item>
<title>The Use of Malware Analysis in Support of Law Enforcement</title>
<link>http://www.cert.org/archive/pdf/malware-7-07.pdf</link>
<description> This paper explains how examining artifacts of a computer intrusion, such as malicious code, can identify clues to further investigation of computer-related crimes.</description>
<pubDate>Wed, 11 Jul 2007 14:10:56 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast</link>
<description>Business leaders can use international standards to create a business- and risk-based information security program.</description>
<pubDate>Tue, 10 Jul 2007 11:41:00 -0400</pubDate>
</item>

<item>
<title>CERT Secure Coding Tutorial at SANSFIRE 2007</title>
<link><![CDATA[http://www.sans.org/sansfire07/description.php?tid=902&portal=6f34a766fa9e3ceeb565e92155aa06f5]]></link>
<description>Robert Seacord will conduct a one-day tutorial, "Secure Coding in C and C++," on July 25, 2007 at SANSFIRE 2007 in Washington, DC. More details are available on the SANSFIRE 2007 site.</description>
<pubDate>Mon, 02 Jul 2007 14:50:59 -0400</pubDate>
</item>

<item>
<title>New PGP Key</title>
<link>http://www.cert.org/pgp/newpgp2007b.html</link>
<description>The CERT/CC has issued a new PGP key.  It is valid until June 30, 2008.</description>
<pubDate>Thu, 28 Jun 2007 16:19:32 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Enterprise security governance is not just a vague idea - it can be achieved by implementing a defined, repeatable process with specific activities.</description>
<pubDate>Tue, 26 Jun 2007 11:44:59 -0400</pubDate>
</item>

<item>
<title>FBI Charges "Bot-Herders"</title>
<link>http://www.fbi.gov/page2/june07/botnet061307.htm</link>
<description>The FBI has identified about 1 million computers across the country that have been compromised by botnets. Learn how to identify, report, and prevent attacks.</description>
<pubDate>Wed, 13 Jun 2007 12:44:22 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Deploying common solutions for physical and IT security is a cost-effective way to reduce risk and save money.</description>
<pubDate>Tue, 12 Jun 2007 11:13:40 -0400</pubDate>
</item>

<item>
<title>Incident Management Capability Metrics Version 0.1</title>
<link>http://www.cert.org/archive/pdf/07tr008.pdf</link>
<description>The metrics presented in this document provide a benchmark of incident management practices.</description>
<pubDate>Tue, 05 Jun 2007 17:53:35 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast</link>
<description> Organizations occasionally may need to redefine their IT infrastructures - but to succeed, they must be prepared to handle tricky situations.</description>
<pubDate>Tue, 29 May 2007 09:57:00 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>As the legal compliance landscape grows increasingly complex, de-identification can help organizations share data more securely.</description>
<pubDate>Tue, 15 May 2007 11:49:29 -0400</pubDate>
</item>

<item>
<title>Resiliency Engineering</title>
<link>http://www.cert.org/resiliency_engineering/</link>
<description>New information about CERT's security and resiliency engineering work is now available.</description>
<pubDate>Thu, 03 May 2007 17:14:10 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Business leaders need to ensure that their organizations can keep critical processes and services up and running in the face of the unexpected.</description>
<pubDate>Tue, 01 May 2007 09:45:17 -0400</pubDate>
</item>

<item>
<title>CERT Statistics Updated</title>
<link>http://www.cert.org/stats/cert_stats.html</link>
<description>The CERT statistics have been updated with the numbers from the first quarter of 2007.</description>
<pubDate>Mon, 30 Apr 2007 13:58:18 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Computer forensics is a critical part of incident response, and business leaders need to understand how to tackle it.</description>
<pubDate>Tue, 17 Apr 2007 10:41:06 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Incident management is a cross-enterprise effort requiring good communication and informed risk management.</description>
<pubDate>Tue, 03 Apr 2007 12:55:52 -0400</pubDate>
</item>

<item>
<title>Podcast series ranks #10</title>
<link>http://www.cert.org</link>
<description>The Security for Business Leaders podcast series came in at #10 on Podcast Bunker's Top 20 list last week.</description>
<pubDate>Thu, 29 Mar 2007 10:29:58 -0400</pubDate>
</item>

<item>
<title>New PGP Key</title>
<link>http://www.cert.org/pgp/newpgp2007.html</link>
<description>The CERT/CC has issued a new PGP key. It is valid until March 21, 2008.</description>
<pubDate>Fri, 23 Mar 2007 16:03:26 -0400</pubDate>
</item>

<item>
<title>Article 2: Defining an Effective Enterprise Security Program (ESP)</title>
<link>http://www.cert.org/archive/pdf/GES_IG_2_0703.pdf</link>
<description>This second article in the Governing for Enterprise Security Impelementation Guide series defines the components and sequence of activities in an effective Enterprise Security Program (ESP).</description>
<pubDate>Fri, 23 Mar 2007 10:15:16 -0400</pubDate>
</item>

<item>
<title>Article 3: Enterprise Security Governance Activities</title>
<link>http://www.cert.org/archive/pdf/GES_IG_3_0703.pdf</link>
<description>This third article in the Governing for Enterprise Security Implementation Guide series elaborates on the governance-based activities necessary to achieve and sustain an ESP.</description>
<pubDate>Fri, 23 Mar 2007 10:13:20 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Business leaders, including legal counsel, need to understand how to tackle complex security issues for a global enterprise.</description>
<pubDate>Tue, 20 Mar 2007 13:24:30 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>System administrators increasingly need business savvy in addition to technical skills, and IT training courses must try to keep pace with this trend.</description>
<pubDate>Tue, 06 Mar 2007 10:25:28 -0500</pubDate>
</item>

<item>
<title>Governing for Enterprise Security</title>
<link>http://www.cert.org/governance/</link>
<description>This new section of the web site highlights research and development in the enterprise security realm. It includes the new Governing for Enterprise Security Implementation Guide</description>
<pubDate>Tue, 20 Feb 2007 12:00:00 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>This conversation discusses how business leaders can prepare to communicate with the media and their staff during a high-profile security incident or crisis.</description>
<pubDate>Tue, 20 Feb 2007 12:00:00 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>This conversation discusses innovative analysis tools needed to assess complex organizational and technological issues.</description>
<pubDate>Tue, 6 Feb 2007 12:00:00 -0500</pubDate>
</item>

<item>
<title>Collaboration Meeting for CSIRTs with National Responsibility</title>
<link>http://www.cert.org/csirts/national/conference2007.html</link>
<description>The CERT Coordination Center will be hosting a meeting of CSIRTs with national responsibility in Madrid, Spain from June 23 to June 25, 2007 after the FIRST annual conference in 
Seville.</description>
<pubDate>Fri, 26 Jan 2007 12:00:00 -0500</pubDate>
</item>

</channel>
</rss>

