<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">

<channel>
<title>CERT Announcements</title>
<link>http://www.cert.org/nav/whatsnew.html</link>
<language>en-us</language>
<description>Announcements: What's New on the CERT web site</description>

<item>
<title>Technical Note on Foreign Involvement in Insider Intellectual Property Theft Released</title>
<link> http://www.sei.cmu.edu/library/abstracts/reports/13tn009.cfm</link>
<description>This entry in the Spotlight On series summarizes such cases and insiders and provides recommendations for mitigating these incidents.</description>
<pubDate>Mon, 20 May 2013 16:57:11 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>A common language is essential to develop a shared understanding to better analyze malicious code.</description>
<pubDate>Thu, 09 May 2013 11:16:28 -0400</pubDate>
</item>

<item>
<title>New Blog Post: Keep Calm and Deploy EMET</title>
<link>http://www.cert.org/blogs/certcc/2013/05/keep_calm_and_deploy_emet.html</link>
<description>This blog post provides information about an effective approach to blocking exploits of CVE-2013-1347, the Internet Explorer 8 CGeneric Element object use-after-free vulnerability.</description>
<pubDate>Wed, 08 May 2013 09:50:47 -0400</pubDate>
</item>

<item>
<title>New Blog Entry: Controlling the Malicious Use of USB Media</title>
<link>http://www.cert.org/blogs/insider_threat/2013/05/controlling_the_malicious_use_of_usb_media.html</link>
<description>This blog post explains the importance of protecting your organization from the theft of sensitive information using USB media.</description>
<pubDate>Mon, 06 May 2013 06:45:20 -0400</pubDate>
</item>

<item>
<title>New Blog Entry: Don't Sign that Applet&#33;</title>
<link>http://www.cert.org/blogs/certcc/2013/04/dont_sign_that_applet.html</link>
<description>This blog post describes how Oracle's new guidance for Java applets may cause more harm than good.</description>
<pubDate>Tue, 30 Apr 2013 06:31:59 -0400</pubDate>
</item>

<item>
<title>New Blog Entry: Finding Patterns of Malicious Use in Bulk Registrations</title>
<link>http://www.cert.org/blogs/certcc/2013/04/finding_patterns_of_malicious.html</link>
<description>This blog post describes how finding patterns in bulk registrations can help identify potentially malicious domains.</description>
<pubDate>Wed, 24 Apr 2013 08:23:24 -0400</pubDate>
</item>

<item>
<title>GeoIP in Your SOC (Security Operations Center)</title>
<link>http://www.cert.org/blogs/certcc/2013/04/geoip_in_your_soc_security_ope.html</link>
<description>This blog entry describes how to use geoIP to view data and help your network situational awareness.</description>
<pubDate>Wed, 17 Apr 2013 10:56:42 -0400</pubDate>
</item>

<item>
<title>Call for Participation: FloCon 2014</title>
<link>http://www.cert.org/flocon/</link>
<description>We are accepting abstracts for presentations, posters, and demonstrations for FloCon 2014, a network security conference that takes place in Charleston, South Carolina, on January 13-16, 2014.</description>
<pubDate>Fri, 12 Apr 2013 03:53:52 -0400</pubDate>
</item>

<item>
<title>New Blog Entry: Second Level Domain Usage in 2012 for Common Top Level Domains</title>
<link>http://www.cert.org/blogs/certcc/2013/04/sld_usage_in_2012_for_common_t.html</link>
<description>This blog post looks at second level domain usage in 2012 for the most common generic Top Level Domains.</description>
<pubDate>Thu, 04 Apr 2013 15:16:59 -0400</pubDate>
</item>

<item>
<title>New Book Released: Secure Coding in C and C++, Second Edition</title>
<link>http://www.cert.org/books/secure-coding/</link>
<description>Secure Coding in C and C++, Second Edition identifies the root causes of today's most widespread software vulnerabilities, shows how they can be exploited, reviews the potential consequences, and presents secure alternatives.</description>
<pubDate>Thu, 28 Mar 2013 11:54:15 -0400</pubDate>
</item>

<item>
<title>New Blog Entry: The Growth of IPv6 Announcements</title>
<link>http://www.cert.org/blogs/certcc/2013/03/the_growth_of_ipv6_announcemen.html</link>
<description>This blog post presents a method for assessing how popular IPv6 is on the internet.</description>
<pubDate>Wed, 27 Mar 2013 08:45:47 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Ensuring the security of personal mobile devices that have access to enterprise networks requires action from employees and users.</description>
<pubDate>Tue, 26 Mar 2013 11:23:24 -0400</pubDate>
</item>

<item>
<title>New Blog Entry: An Alternate View of Announced IPv4 Space</title>
<link>http://www.cert.org/blogs/certcc/2013/03/an_alternate_view_of_announced.html</link>
<description>This blog post describes an alternate way to view advertised IP address space on the internet using publicly available information.</description>
<pubDate>Thu, 21 Mar 2013 10:25:24 -0400</pubDate>
</item>

<item>
<title>Justification of a Pattern for Detecting Intellectual Property Theft by Departing Insiders Released</title>
<link> http://www.sei.cmu.edu/library/abstracts/reports/13tn013.cfm</link>
<description>This technical note describes an analysis of the pattern "Increased Review for Intellectual Property (IP) Theft by Departing Insiders," which helps organizations mitigate the risk of insider theft of IP.</description>
<pubDate>Tue, 19 Mar 2013 19:59:01 -0400</pubDate>
</item>

<item>
<title>New Blog Entry: The Growth Rate of IP Addresses That Are Advertised as Usable on the Internet</title>
<link>http://www.cert.org/blogs/certcc/2013/03/_v_behaviorurldefaultvml_o_beh.html</link>
<description>This blog post describes how you can calculate the growth rate of advertised IP address space on the internet using publicly available information.</description>
<pubDate>Wed, 13 Mar 2013 13:19:06 -0400</pubDate>
</item>

<item>
<title>New Blog Entry: How Ontologies Can Help Build a Science of Cybersecurity</title>
<link>http://www.cert.org/blogs/insider_threat/2013/03/how_ontologies_can_help_build_a_science_of_cybersecurity.html</link>
<description>This blog post introduces you to work done on an ontology for malware.</description>
<pubDate>Tue, 12 Mar 2013 06:40:47 -0400</pubDate>
</item>

<item>
<title>New Blog Entry: Watching Domains That Change DNS Servers Frequently</title>
<link>http://www.cert.org/blogs/certcc/2013/03/watching_domains_that_change_d.html</link>
<description>This blog entry describes the results of our three-month study of domains that change their name servers frequently.</description>
<pubDate>Mon, 11 Mar 2013 09:13:04 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>371 cases of insider attacks lead to 4 new and 15 updated best practices for mitigating insider threat.</description>
<pubDate>Thu, 28 Feb 2013 13:00:26 -0500</pubDate>
</item>

<item>
<title>Malware Analysis Lexicon Released</title>
<link> http://www.sei.cmu.edu/library/abstracts/reports/13tn010.cfm</link>
<description>This technical note presents the first common vocabulary for malware analysis.</description>
<pubDate>Wed, 27 Feb 2013 16:20:37 -0500</pubDate>
</item>

<item>
<title>New Blog Entry: CERT Insider Threat Events at the RSA Conference</title>
<link>http://www.cert.org/blogs/insider_threat/2013/02/cert_insider_threat_at_the_rsa_conference.html</link>
<description>This blog entry provides you with an opportunity to meet members of the CERT Insider Threat Center at the RSA Conference and describes events supported by these members at the conference.</description>
<pubDate>Tue, 19 Feb 2013 07:15:58 -0500</pubDate>
</item>

<item>
<title>New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 19 (of 19)</title>
<link>http://www.cert.org/blogs/insider_threat/2013/02/common_sense_guide_to_mitigating_insider_threats_-_best_practice_19_of_19.html</link>
<description>This last of 19 blog posts about the fourth edition of the Common Sense Guide to Mitigating Insider Threats describes Practice 19: Close the doors to unauthorized data exfiltration.</description>
<pubDate>Wed, 13 Feb 2013 07:39:19 -0500</pubDate>
</item>

<item>
<title>New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 18 (of 19)</title>
<link>http://www.cert.org/blogs/insider_threat/2013/02/common_sense_guide_to_mitigating_insider_threats_-_best_practice_18_of_19.html</link>
<description>This eighteenth of 19 blog posts about the fourth edition of the Common Sense Guide to Mitigating Insider Threats describes Practice 18: Be especially vigilant regarding social media.</description>
<pubDate>Mon, 11 Feb 2013 07:28:13 -0500</pubDate>
</item>

<item>
<title>New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 17 (of 19)</title>
<link>http://www.cert.org/blogs/insider_threat/2013/02/common_sense_guide_to_mitigating_insider_threats_-_best_practice_17_of_19.html</link>
<description>This seventeenth of 19 blog posts about the fourth edition of the Common Sense Guide to Mitigating Insider Threats describes Practice 17: Establish a baseline of normal network device behavior.</description>
<pubDate>Fri, 08 Feb 2013 06:37:35 -0500</pubDate>
</item>

<item>
<title>New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 16 (of 19)</title>
<link>http://www.cert.org/blogs/insider_threat/2013/02/common_sense_guide_to_mitigating_insider_threats_-_best_practice_16_of_19.html</link>
<description>This sixteenth of 19 blog posts about the fourth edition of the Common Sense Guide to Mitigating Insider Threats describes Practice 16: Develop a formalized insider threat program.</description>
<pubDate>Wed, 06 Feb 2013 06:38:07 -0500</pubDate>
</item>

<item>
<title>New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 15 (of 19)</title>
<link>http://www.cert.org/blogs/insider_threat/2013/02/common_sense_guide_to_mitigating_insider_threats_-_best_practice_15_of_19.html</link>
<description>This fifteenth of 19 blog posts about the fourth edition of the Common Sense Guide to Mitigating Insider Threats describes Practice 15: Implement secure backup and recovery processes.</description>
<pubDate>Mon, 04 Feb 2013 09:32:45 -0500</pubDate>
</item>

<item>
<title>New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 14 (of 19)</title>
<link>http://www.cert.org/blogs/insider_threat/2013/02/common_sense_guide_to_mitigating_insider_threats_-_best_practice_14_of_19.html</link>
<description>This fourteenth of 19 blog posts about the fourth edition of the Common Sense Guide to Mitigating Insider Threats describes Practice 14: Develop a comprehensive employee termination procedure.</description>
<pubDate>Fri, 01 Feb 2013 11:03:49 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Governments and markets are calling for the integration of plans for and responses to disruptive events.</description>
<pubDate>Thu, 31 Jan 2013 12:09:46 -0500</pubDate>
</item>

<item>
<title>New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 13 (of 19)</title>
<link>http://www.cert.org/blogs/insider_threat/2013/01/common_sense_guide_to_mitigating_insider_threats_-_best_practice_13_of_19.html</link>
<description>This thirteenth of 19 blog posts about the fourth edition of the Common Sense to Mitigating Insider Threats describes Practice 13: Monitor and control remote access from all end points, including mobile devices.</description>
<pubDate>Wed, 30 Jan 2013 07:46:53 -0500</pubDate>
</item>

<item>
<title>New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 12 (of 19)</title>
<link>http://www.cert.org/blogs/insider_threat/2013/01/common_sense_guide_to_mitigating_insider_threats_-_best_practice_12_of_19.html</link>
<description>This twelfth of 19 blog posts about the fourth edition of the Common Sense to Mitigating Insider Threats describes Practice 12: Use a log correlation engine or security information and event management (SIEM) system to log, monitor, and audit employee actions.</description>
<pubDate>Mon, 28 Jan 2013 08:04:46 -0500</pubDate>
</item>

<item>
<title></title>
<link>http://www.cert.orgCommon Sense Guide to Mitigating Insider Threats - Best Practice 11 (of 19)/blogs/insider_threat/2013/01/common_sense_guide_to_mitigating_insider_threats_-_best_practice_11_of_19.html</link>
<description>This eleventh of 19 blog posts about the fourth edition of the Common Sense to Mitigating Insider Threats describes Practice 11: Institutionalize system change controls.</description>
<pubDate>Fri, 25 Jan 2013 07:27:13 -0500</pubDate>
</item>

<item>
<title>New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 10 (of 19) </title>
<link>http://www.cert.org/blogs/insider_threat/2013/01/common_sense_guide_to_mitigating_insider_threats_-_best_practice_10_of_19.html</link>
<description>This tenth of 19 blog posts about the fourth edition of the Common Sense Guide to Mitigating Insider Threats describes Practice 10: Institute stringent access controls and monitoring policies on privileged users.</description>
<pubDate>Wed, 23 Jan 2013 08:14:08 -0500</pubDate>
</item>

<item>
<title>New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 9 (of 19)</title>
<link>http://www.cert.org/blogs/insider_threat/2013/01/common_sense_guide_to_mitigating_insider_threats_-_best_practice_9_of_19.html</link>
<description>This ninth of 19 blog posts about the fourth edition of the Common Sense Guide to Mitigating Insider Threats describes Practice 9: Define explicit security agreements for any cloud services, especially access restrictions and monitoring capabilities.</description>
<pubDate>Mon, 21 Jan 2013 06:34:29 -0500</pubDate>
</item>

<item>
<title>New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 8 (of 19)</title>
<link>http://www.cert.org/blogs/insider_threat/2013/01/common_sense_guide_to_mitigating_insider_threats_-_best_practice_8_of_19.html</link>
<description>This eighth of 19 blog posts about the fourth edition of the Common Sense Guide to Mitigating Insider Threats describes Practice 8: Enforce separation of duties and least privilege.</description>
<pubDate>Fri, 18 Jan 2013 07:54:48 -0500</pubDate>
</item>

<item>
<title>New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 7 (of 19)</title>
<link>http://www.cert.org/blogs/insider_threat/2013/01/common_sense_guide_to_mitigating_insider_threats_-_best_practice_7_of_19.html</link>
<description>This seventh of 19 blog posts about the fourth edition of the Common Sense Guide to Mitigating Insider Threats describes Practice 7: Implement strict password and account management policies and practices.</description>
<pubDate>Wed, 16 Jan 2013 08:21:10 -0500</pubDate>
</item>

<item>
<title>New CERT/CC Blog Post: Anatomy of Java Exploits </title>
<link>http://www.cert.org/blogs/certcc/2013/01/anatomy_of_java_exploits.html</link>
<description>This blog post examines the vulnerabilities that permitted Java to be exploited in two recent cases.</description>
<pubDate>Tue, 15 Jan 2013 14:11:17 -0500</pubDate>
</item>

<item>
<title>New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 6 (of 19)</title>
<link>http://www.cert.org/blogs/insider_threat/2013/01/common_sense_guide_to_mitigating_insider_threats_-_best_practice_5_of_19.html</link>
<description>This sixth of 19 blog posts about the fourth edition of the Common Sense Guide to Mitigating Insider Threats describes Practice 6: Know your assets.</description>
<pubDate>Mon, 14 Jan 2013 06:52:31 -0500</pubDate>
</item>

<item>
<title>New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 5 (of 19)</title>
<link>http://www.cert.org/blogs/insider_threat/2013/01/common_sense_guide_to_mitigating_insider_threats_-_best_practice_5_of_19.html</link>
<description>This fifth of 19 blog posts about the fourth edition of the Common Sense Guide to Mitigating Insider Threats describes Practice 5: Anticipate and manage negative issues in the work environment.</description>
<pubDate>Fri, 11 Jan 2013 10:07:22 -0500</pubDate>
</item>

<item>
<title>New CERT/CC Blog Post: Java in Web Browser: Disable Now!</title>
<link>http://www.cert.org/blogs/certcc/2013/01/java_in_web_browser_disable_no.html</link>
<description>In light of a recent Java vulnerability, this blog post discusses why you should disable Java.</description>
<pubDate>Thu, 10 Jan 2013 17:33:04 -0500</pubDate>
</item>

<item>
<title>New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 4 (of 19)</title>
<link>http://www.cert.org/blogs/insider_threat/2013/01/common_sense_guide_to_mitigating_insider_threats_-_best_practice_4_of_19.html</link>
<description>This fourth of 19 blog posts about the fourth edition of the Common Sense Guide to Mitigating Insider Threats describes Practice 4: Beginning with the hiring process, monitor and respond to suspicious or disruptive behavior.</description>
<pubDate>Wed, 09 Jan 2013 12:21:12 -0500</pubDate>
</item>

<item>
<title>New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 3 (of 19)</title>
<link>http://www.cert.org/blogs/insider_threat/2013/01/common_sense_guide_to_mitigating_insider_threats_-_best_practice_2_of_19.html</link>
<description>This third of 19 blog posts about the fourth edition of the Common Sense Guide to Mitigating Insider Threats describes Practice 3: Incorporate insider threat awareness into periodic security training for all employees.</description>
<pubDate>Tue, 08 Jan 2013 09:22:28 -0500</pubDate>
</item>

<item>
<title>New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 2 (of 19)</title>
<link>http://www.cert.org/blogs/insider_threat/2013/01/common_sense_guide_to_mitigating_insider_threats_-_best_practice_2_of_19.html</link>
<description>This second of 19 blog posts about the fourth edition of the Common Sense Guide to Mitigating Insider Threats describes Practice 2: Clearly document and consistently enforce policies and controls.</description>
<pubDate>Fri, 04 Jan 2013 13:28:59 -0500</pubDate>
</item>

<item>
<title>New Blog Entry: Common Sense Guide to Mitigating Insider Threats - Best Practice 1 (of 19)</title>
<link>http://www.cert.org/blogs/insider_threat/2013/01/common_sense_guide_to_mitigating_insider_threats_-_best_practice_1_of_19.html</link>
<description>This first of 19 blog posts about the fourth edition of the Common Sense Guide to Mitigating Insider Threats describes Practice 1: Consider threats from insiders and business partners in enterprise-wide risk assessments.</description>
<pubDate>Thu, 03 Jan 2013 12:02:44 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Today's high-risk, global, fast, and very public business environment demands a more integrated approach to not be surprised by disruptive events.</description>
<pubDate>Wed, 19 Dec 2012 12:06:10 -0500</pubDate>
</item>

<item>
<title>New Blog Post: The Common Sense Guide to Prevention and Detection of Insider Threats Expanded</title>
<link>http://www.cert.org/blogs/insider_threat/2012/12/release_of_the_4th_edition_of_the_common_sense_guide_to_prevention_and_detection_of_insider_threats.html</link>
<description>The release of the Common Sense Guide to Prevention and Detection of Insider Threats, 4th Edition introduces four new best practices for preventing and detecting insider threats and a number of new features.</description>
<pubDate>Fri, 14 Dec 2012 17:08:55 -0500</pubDate>
</item>

<item>
<title>New Blog Entry: Fourth Edition of the Common Sense Guide Is Released</title>
<link>http://www.cert.org/blogs/insider_threat/2012/12/fourth_edition_of_the_common_sense_guide_to_mitigating_insider_threats_is_released.html</link>
<description>The newest edition of the Common Sense Guide to Mitigating Insider Threats is based on our significantly expanded database of more than 700 insider threat cases and continued research and analysis, and it covers new technologies and new threats.</description>
<pubDate>Thu, 13 Dec 2012 06:35:08 -0500</pubDate>
</item>

<item>
<title>Common Sense Guide to Mitigating Insider Threats, 4th Edition, Released</title>
<link> http://www.sei.cmu.edu/library/abstracts/reports/12tr012.cfm</link>
<description>The CERT Insider Threat Center presents new and revised organizational practices for preventing and detecting insider threats.</description>
<pubDate>Wed, 12 Dec 2012 14:43:01 -0500</pubDate>
</item>

<item>
<title>Technical Note Released about Research Study on Resilience Success and Failure</title>
<link> http://www.sei.cmu.edu/library/abstracts/reports/12tn025.cfm</link>
<description>This technical note describes the SEI research study designed to help organizations understand the business value of implementing resilience processes and practices, and determine which ones to implement.</description>
<pubDate>Tue, 11 Dec 2012 20:05:45 -0500</pubDate>
</item>

<item>
<title>Forking and Joining Python Coroutines to Collect Coverage Data</title>
<link>http://www.cert.org/blogs/certcc/2012/12/forking_and_joining_python_cor.html</link>
<description>In this blog post, Jonathan Foote explains how to expand on David Beazley's cobroadcast pattern by adding a join capability that can bring multiple forked coroutine paths back together.</description>
<pubDate>Wed, 05 Dec 2012 17:38:06 -0500</pubDate>
</item>

<item>
<title>Helping Developers Address Security with the CERT C Secure Coding Standard</title>
<link>http://www.cert.orghttp://blog.sei.cmu.edu/post.cfm/helping-developers-address-security-with-the-cert-c-secure-coding-standard</link>
<description>This blog post describes our latest set of rules and recommendations, which aims to help developers avoid undefined and&#47;or unexpected behavior in deployed code.</description>
<pubDate>Thu, 15 Nov 2012 10:00:17 -0500</pubDate>
</item>

<item>
<title>Writing Effective YARA Signatures to Identify Malware</title>
<link>http://www.cert.orghttp://blog.sei.cmu.edu/post.cfm/writing-effective-yara-signatures-to-identify-malware</link>
<description>This blog post provides guidelines for using YARA effectively, focusing on selection of objective criteria derived from malware, the type of criteria most useful in identifying related malware (including strings, resources, and functions), and guidelines for creating YARA signatures using these criteria.</description>
<pubDate>Thu, 15 Nov 2012 09:50:46 -0500</pubDate>
</item>

<item>
<title>Insider Threats in State and Local Government</title>
<link>http://www.cert.org/blogs/insider_threat/2012/11/insider_threats_in_state_and_local_government_organizations.html</link>
<description>This blog post describes insider threats in state and local government sectors, including who the insiders are, why they attack, and how they attack.</description>
<pubDate>Wed, 14 Nov 2012 07:29:00 -0500</pubDate>
</item>

<item>
<title>New CERT/CC Blog Post: A Look Inside CERT Fuzzing Tools</title>
<link>http://www.cert.org/blogs/certcc/2012/11/a_look_inside_certs_fuzzing_fr.html</link>
<description>This blog post introduces recent reports that describe some heuristics and algorithms implemented in CERT fuzzing tools.</description>
<pubDate>Mon, 05 Nov 2012 11:38:27 -0500</pubDate>
</item>

<item>
<title>Spotlight On: Insider Threat from Trusted Business Partners Article Revised and Released</title>
<link>http://www.cert.org/blogs/insider_threat/2012/11/updated_and_revised_spotlight_on_insider_threat_from_trusted_business_partners.html</link>
<description>In this blog post, the Insider Threat team announces the release of the revised Spotlight On: Insider Threat from Trusted Business Partners article.</description>
<pubDate>Fri, 02 Nov 2012 13:03:18 -0400</pubDate>
</item>

<item>
<title>Updates to CERT Fuzzing Tools (BFF 2.6 and FOE 2.0.1)</title>
<link>http://www.cert.org/blogs/certcc/2012/10/updates_to_cert_fuzzing_tools.html</link>
<description>In this blog post, the CERT Vulnerability Analysis team announces the release of updates to the CERT Basic Fuzzing Framework (BFF) version 2.6 and the CERT Failure Observation Engine (FOE) version 2.01.</description>
<pubDate>Thu, 25 Oct 2012 15:52:45 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>A network profile can help identify unintended points of entry, misconfigurations, and other weaknesses that may be visible to attackers.</description>
<pubDate>Tue, 23 Oct 2012 12:28:07 -0400</pubDate>
</item>

<item>
<title>Technical Note Released on Communication Among Incident Responders</title>
<link> http://www.sei.cmu.edu/library/abstracts/reports/12tn028.cfm</link>
<description>This technical note describes three factors that are likely to help or hinder the cooperation of incident responders.</description>
<pubDate>Tue, 16 Oct 2012 17:48:51 -0400</pubDate>
</item>

<item>
<title>External Threat Analysis</title>
<link>http://www.cert.org/blogs/insider_threat/2012/10/external_threat_analysis.html</link>
<description>This blog post discusses extending the methodologies used in insider threat research to external threats.</description>
<pubDate>Fri, 05 Oct 2012 13:06:54 -0400</pubDate>
</item>

<item>
<title>Insider Threats Related to Cloud Computing--Installment 10: Conclusion</title>
<link>http://www.cert.org/blogs/insider_threat/2012/10/insider_threats_related_to_cloud_computing--installment_10_conclusion.html</link>
<description>The last installment of a 10-part series on cloud-related insider threats summarizes the blog series and provides advice for organizations.</description>
<pubDate>Mon, 01 Oct 2012 07:02:55 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Deploy vulnerability exploit prevention and mitigation techniques to thwart attacks and manage the arms race.</description>
<pubDate>Tue, 25 Sep 2012 12:22:09 -0400</pubDate>
</item>

<item>
<title>The Insider Threat Awareness Virtual Roundtable Webinar</title>
<link>http://www.cert.org/blogs/insider_threat/2012/09/webinar_the_insider_threat_awareness_virtual_roundtable_sponsored_by_dhs_office_of_infrastructure_pr.html</link>
<description>Dawn Cappelli discusses the Insider Threat Awareness Virtual Roundtable webinar that took place on September 18, 2012.</description>
<pubDate>Tue, 25 Sep 2012 10:45:11 -0400</pubDate>
</item>

<item>
<title>Insider Threats Related to Cloud Computing--Installment 9: Two More Proposed Directions for Future Research</title>
<link>http://www.cert.org/blogs/insider_threat/2012/09/insider_threats_related_to_cloud_computing--installment_9_two_more_proposed_directions_for_future_re.html</link>
<description>Installment 9 of a 10-part series on cloud-related insider threats discusses in detail two final areas of future research for cloud-related insider threats: normal user behavior analysis and policy integration.</description>
<pubDate>Mon, 24 Sep 2012 07:51:20 -0400</pubDate>
</item>

<item>
<title>Insider Threats Related to Cloud Computing--Installment 8: Three More Proposed Directions for Future Research in Detail</title>
<link>http://www.cert.org/blogs/insider_threat/2012/09/insider_threats_related_to_cloud_computing--installment_8_three_more_proposed_directions_for_future.html</link>
<description>Installment 8 of a 10-part series on cloud-related insider threats discusses three more areas of future research for cloud-related insider threats.</description>
<pubDate>Mon, 17 Sep 2012 07:50:57 -0400</pubDate>
</item>

<item>
<title>Insider Threats Related to Cloud Computing--Installment 7: Seven Proposed Directions for Research and Two in Detail</title>
<link>http://www.cert.org/blogs/insider_threat/2012/09/insider_threats_related_to_cloud_computing--installment_7_seven_proposed_directions_for_research_and.html</link>
<description>Installment 7 of a 10-part series on cloud-related insider threats introduces seven proposed directions for cloud-related insider threat research.</description>
<pubDate>Wed, 12 Sep 2012 09:09:12 -0400</pubDate>
</item>

<item>
<title>Competency Lifecycle Roadmap Technical Note Released</title>
<link> http://www.sei.cmu.edu/library/abstracts/reports/12tn020.cfm</link>
<description>This technical note describes a preliminary roadmap for understanding and building workforce readiness.</description>
<pubDate>Tue, 11 Sep 2012 16:26:34 -0400</pubDate>
</item>

<item>
<title>Digital Investigation Workforce Development</title>
<link>http://www.cert.orgwww.cert.org/archive/pdf/Digital-Investigation-Workforce-Development.pdf</link>
<description>This paper identifies the digital investigation capabilities that law-enforcement agencies, businesses, and other organizations must develop in order to combat criminal acts being perpetrated in cyberspace.</description>
<pubDate>Tue, 11 Sep 2012 15:04:24 -0400</pubDate>
</item>

<item>
<title>CERT Insider Threat Center in the News</title>
<link>http://www.cert.org/blogs/insider_threat/2012/09/cert_insider_threat_center_in_the_news.html</link>
<description>This blog post summarizes recent news articles that highlight the Insider Threat Center.</description>
<pubDate>Mon, 10 Sep 2012 09:30:48 -0400</pubDate>
</item>

<item>
<title>Insider Threats Evident in All Industry Sectors</title>
<link>http://www.cert.org/blogs/insider_threat/2012/09/hello_this_is_todd_lewellen.html</link>
<description>This blog post explains that no industry sector is free from the actions of malicious insiders.</description>
<pubDate>Fri, 07 Sep 2012 06:46:27 -0400</pubDate>
</item>

<item>
<title>Study on Insider Cyber Fraud in Financial Services Released</title>
<link>http://www.cert.org/blogs/insider_threat/2012/09/certs_study_on_insider_cyber_fraud_in_financial_services_released.html</link>
<description>This blog post describes a study of cyber fraud in the financial services sector, including the new report that documents the results.</description>
<pubDate>Thu, 06 Sep 2012 05:59:08 -0400</pubDate>
</item>

<item>
<title>New CERT/CC Blog Post: Java 7 Attack Vectors, Oh My!</title>
<link>http://www.cert.org/blogs/certcc/2012/09/java_7_attack_vectors_oh_my.html</link>
<description>In this post, we discuss how and why to disable Java support in web browsers.</description>
<pubDate>Wed, 05 Sep 2012 18:02:23 -0400</pubDate>
</item>

<item>
<title>The Report "Network Profiling Using Flow" Released</title>
<link>http://www.cert.org/blogs/certcc/2012/09/network_profiling_using_flow_r.html</link>
<description>This report describes how to inventory assets on a network using network flow data.</description>
<pubDate>Wed, 05 Sep 2012 06:25:20 -0400</pubDate>
</item>

<item>
<title>Insider Threats Related to Cloud Computing--Installment 6: Securing Against Other Cloud-Related Insiders</title>
<link>http://www.cert.org/blogs/insider_threat/2012/09/insider_threats_related_to_cloud_computing--installment_6_securing_against_other_cloud-related_insid.html</link>
<description>Installment 6 of a 10-part series on cloud-related insider threats presents how to secure against other cloud-related insiders.</description>
<pubDate>Tue, 04 Sep 2012 09:06:57 -0400</pubDate>
</item>

<item>
<title>Upcoming Appearances by CERT Insider Threat Experts</title>
<link>http://www.cert.org/blogs/insider_threat/2012/08/upcoming_appearances_of_cert_experts.html</link>
<description>This blog post lets you know about where some members of the Insider Threat Team will be appearing in the coming weeks.</description>
<pubDate>Thu, 30 Aug 2012 14:17:49 -0400</pubDate>
</item>

<item>
<title>New CERT/CC Blog Post: Java Security Manager Bypass Vulnerability</title>
<link>http://www.cert.org/blogs/certcc/2012/08/disabling_the_java_7_plug-in_o.html</link>
<description>We describe a recently reported, major Java vulnerability.</description>
<pubDate>Wed, 29 Aug 2012 09:50:54 -0400</pubDate>
</item>

<item>
<title>Insider Threats Related to Cloud Computing--Installment 5: Securing Against Cloud-Related Insiders</title>
<link>http://www.cert.org/blogs/insider_threat/2012/08/insider_threats_related_to_cloud_computing--installment_5_securing_against_cloud-related_insiders.html</link>
<description>Installment 5 of a 10-part series on cloud-related insider threats presents how to secure against rogue administrators.</description>
<pubDate>Mon, 27 Aug 2012 06:36:15 -0400</pubDate>
</item>

<item>
<title>Report on Network Profiling Using Flow Publishedd</title>
<link> http://www.sei.cmu.edu/library/abstracts/reports/12tr006.cfm </link>
<description>This report provides a step-by-step guide for creating a profile to see a potential attacker.s view of an external network.</description>
<pubDate>Fri, 24 Aug 2012 08:01:53 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>CERT-RMM can be used to establish and meet resilience requirements for a wide range and diverse set of business objectives.</description>
<pubDate>Tue, 21 Aug 2012 14:00:44 -0400</pubDate>
</item>

<item>
<title>Insider Threats Related to Cloud Computing--Installment 4: Using the Cloud to Conduct Nefarious Activity</title>
<link>http://www.cert.org/blogs/insider_threat/2012/08/insider_threats_related_to_cloud_computing--installment_4_using_the_cloud_to_conduct_nefarious_activ.html</link>
<description>Installment 4 of a 10-part series on cloud-related insider threats presents a third type of cloud-related insider threat: those who uses cloud services to carry out an attack on his own employer.</description>
<pubDate>Mon, 20 Aug 2012 06:23:53 -0400</pubDate>
</item>

<item>
<title>New Tutorial Released - Cloud Computing Security</title>
<link>http://www.cert.org/archive/pdf/COMPSAC2012-CloudComptingSecurityTutorialSlides.pdf</link>
<description>This tutorial was presented at IEEE COMPSAC 2012.</description>
<pubDate>Wed, 15 Aug 2012 09:57:22 -0400</pubDate>
</item>

<item>
<title>Insider Threats Related to Cloud Computing--Installment 3: Insiders Who Exploit Cloud Vulnerabilities</title>
<link>http://www.cert.org/blogs/insider_threat/2012/08/title_insider_threats_related_to_cloud_computing--installment_3_insiders_who_exploit_cloud_vulnerabi.html</link>
<description>Installment 3 of a 10-part series on cloud-related insider threats presents a second type of cloud-related insider threat: those that exploit weaknesses introduced by use of the cloud.</description>
<pubDate>Mon, 13 Aug 2012 10:51:06 -0400</pubDate>
</item>

<item>
<title>Insider Threats Related to Cloud Computing--Installment 2: The Rogue Administrator</title>
<link>http://www.cert.org/blogs/insider_threat/2012/08/title_insider_threats_related_to_cloud_computing--installment_2_the_rogue_administrator.html</link>
<description>Installment 2 of a 10-part series on cloud-related insider threats presents three types of cloud-related insiders and discusses one in detail - the rogue administrator.</description>
<pubDate>Mon, 06 Aug 2012 13:17:32 -0400</pubDate>
</item>

<item>
<title>Insider Threats Related to Cloud Computing--Installment 1: Introduction</title>
<link>http://www.cert.org/blogs/insider_threat/2012/07/title_insider_threats_related_to_cloud_computing--.html</link>
<description>First in a series of blog posts that discuss problems related to insiders in the cloud, defending against them, and researching approaches that could help solve some of these problems.</description>
<pubDate>Tue, 31 Jul 2012 07:22:53 -0400</pubDate>
</item>

<item>
<title>Insider Threat Report on Fraud in Financial Services Published</title>
<link> http://www.sei.cmu.edu/library/abstracts/reports/12sr004.cfm</link>
<description>This report describes insights and risk indicators of malicious insider activity within the banking and finance sector.</description>
<pubDate>Mon, 30 Jul 2012 09:07:40 -0400</pubDate>
</item>

<item>
<title>New CERT/CC Blog Post: CERT Failure Observation Engine 2.0 Released</title>
<link>http://www.cert.org/blogs/certcc/2012/07/cert_failure_observation_engin_1.html</link>
<description>We describe version 2.0 of the CERT Failure Observation Engine (FOE).</description>
<pubDate>Tue, 24 Jul 2012 07:24:47 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Implementing CERT-RMM requires well-defined improvement objectives, sponsorship, proper scoping and diagnosis, and defined processes and measures.</description>
<pubDate>Tue, 17 Jul 2012 11:52:37 -0400</pubDate>
</item>

<item>
<title>New CERT/CC Blog Post: Vulnerability Data Archive</title>
<link>http://www.cert.org/blogs/certcc/2012/07/vulnerability_data_archive.html</link>
<description>We have published an archive of much of the non-sensitive vulnerability information in our vulnerability reports database.</description>
<pubDate>Wed, 11 Jul 2012 07:49:01 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Post</title>
<link>http://www.cert.org/blogs/insider_threat/2012/07/pay_attention_are_your_company_secrets_at_risk_from_insiders.html</link>
<description>Pay attention: Are your company secrets at risk from insiders&#63;</description>
<pubDate>Mon, 02 Jul 2012 14:59:37 -0400</pubDate>
</item>

<item>
<title>FloCon 2013 Call for Papers</title>
<link>http://www.cert.org/flocon/index.html</link>
<description>FloCon 2013 takes place in Albuquerque, New Mexico, on January 7-10, 2013. Visit the FloCon website for information about the Call for Papers.</description>
<pubDate>Fri, 15 Jun 2012 14:09:39 -0400</pubDate>
</item>

<item>
<title>New CERT/CC Blog Post</title>
<link>http://www.cert.org/blogs/certcc/2012/06/amd_video_drivers_prevent_the.html</link>
<description>AMD video drivers prevent the use of the most secure setting for Microsoft's Exploit Mitigation Experience Toolkit (EMET)</description>
<pubDate>Wed, 06 Jun 2012 10:55:26 -0400</pubDate>
</item>

<item>
<title>Report from the First CERT-RMM Users Group Workshop Series Released</title>
<link> http://www.sei.cmu.edu/library/abstracts/reports/12tn008.cfm</link>
<description>This report describes the first CERT RMM Users Group (RUG) Workshop Series and relays the experiences of participating members and CERT staff.</description>
<pubDate>Mon, 04 Jun 2012 07:50:36 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2012/05/the_cert_insider_threat_center_has_been_busy_this_spring.html</link>
<description>The CERT Insider Threat Center has been busy this spring.</description>
<pubDate>Thu, 31 May 2012 12:08:39 -0400</pubDate>
</item>

<item>
<title>New CERT PGP Key</title>
<link>http://www.cert.org/contact_cert/encryptmail.html</link>
<description>CERT has updated its PGP key. We strongly urge you to encrypt sensitive information.</description>
<pubDate>Fri, 25 May 2012 12:03:21 -0400</pubDate>
</item>

<item>
<title>Report on Monitoring for Insider Theft of Intellectual Property Released</title>
<link>http://www.sei.cmu.edu/library/abstracts/reports/12tr008.cfm</link>
<description>This report presents a way organizations can mitigate the risk of theft of intellectual property by departing insiders.</description>
<pubDate>Thu, 03 May 2012 14:12:52 -0400</pubDate>
</item>

<item>
<title>Source Code Analysis Laboratory (SCALe) Technical Note Released</title>
<link>http://www.sei.cmu.edu/library/abstracts/reports/12tn013.cfm</link>
<description>This technical note describes SCALe, a demonstration process for testing software for conformance against secure coding standards.</description>
<pubDate>Wed, 02 May 2012 14:57:19 -0400</pubDate>
</item>

<item>
<title>Insider Threat Security Reference Architecture Technical Report Released</title>
<link>http://www.sei.cmu.edu/library/abstracts/reports/12tr007.cfm</link>
<description>This report describes the Insider Threat Security Reference Architecture (ITSRA), an enterprise-wide solution to the threat organizations face from their own insiders.</description>
<pubDate>Tue, 01 May 2012 15:39:41 -0400</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2012/04/cert_basic_fuzzing_framework_v.html</link>
<description>CERT Basic Fuzzing Framework 2.5 Released</description>
<pubDate>Mon, 30 Apr 2012 12:43:00 -0400</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2012/04/cert_triage_tools_10.html</link>
<description>CERT Linux Triage Tools 1.0 Released</description>
<pubDate>Wed, 25 Apr 2012 11:15:23 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Security controls, including those for insider threat, are the safeguards necessary to protect information and information systems.</description>
<pubDate>Tue, 24 Apr 2012 11:53:39 -0400</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2012/04/cert_failure_observation_engin.html</link>
<description>CERT Failure Observation Engine 1.0 Released</description>
<pubDate>Mon, 23 Apr 2012 16:47:59 -0400</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2012/04/vulnerability_severity_using_c.html</link>
<description>Vulnerability Severity Using CVSS</description>
<pubDate>Wed, 11 Apr 2012 23:12:47 -0400</pubDate>
</item>

<item>
<title>The CERT Top 10 List for Winning the Battle Against Insider Threats Released</title>
<link>http://www.cert.org/archive/pdf/CERT-InsiderThreat-RSA2012.pdf</link>
<description>Organizations can use these tips, drawn from the CERT Insider Threat Center's case files, to combat insider threat.</description>
<pubDate>Wed, 28 Mar 2012 13:36:45 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Post</title>
<link>http://www.cert.org/blogs/insider_threat/2012/03/the_cert_guide_to_insider_threats_how_to_prevent_detect_and_respond_to_information_technology_crimes.html</link>
<description>The CERT Guide to Insider Threats: How to Prevent, Detect, and Respond to Information Technology Crimes</description>
<pubDate>Tue, 27 Mar 2012 13:18:35 -0400</pubDate>
</item>

<item>
<title>CERT-RMM V1.1: NIST Special Publication Crosswalk Version 1 Released</title>
<link>http://www.sei.cmu.edu/library/abstracts/reports/11tn028.cfm</link>
<description>This technical note maps CERT-RMM process areas to 800-series NIST special publications.</description>
<pubDate>Tue, 27 Mar 2012 10:15:37 -0400</pubDate>
</item>

<item>
<title>Principles of Trust for Embedded Systems Technical Note Published</title>
<link>http://www.cert.org/archive/pdf/12tn007.pdf</link>
<description>This paper gives substance and explicit meaning to the terms trust and trustworthy as they relate to automated systems and to embedded systems in particular.</description>
<pubDate>Wed, 07 Mar 2012 09:55:52 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Implementing secure coding standards to reduce the number of vulnerabilities that can escape into operational systems is a sound business decision.</description>
<pubDate>Tue, 28 Feb 2012 13:58:01 -0500</pubDate>
</item>

<item>
<title>Mission Risk Diagnostic (MRD) Method Description Technical Note Released</title>
<link>http://www.sei.cmu.edu/library/abstracts/reports/12tn005.cfm</link>
<description>This technical note overviews the MRD method developed by the SEI to assess system risk across the lifecycle and supply chain.</description>
<pubDate>Mon, 27 Feb 2012 09:58:04 -0500</pubDate>
</item>

<item>
<title>CERT-RMM Capability Appraisal Method (CAM) Version 1.1 Technical Report Released</title>
<link>http://www.sei.cmu.edu/library/abstracts/reports/11tr020.cfm</link>
<description>This report demonstrates that SCAMPI V1.2 can be applied to CERT-RMM V1.1 as the reference model for a process appraisal.</description>
<pubDate>Thu, 23 Feb 2012 10:03:57 -0500</pubDate>
</item>

<item>
<title>CERT-RMM V1.1: Code of Practice Crosswalk Commercial Version 1.1 Technical Note Released</title>
<link>http://www.sei.cmu.edu/library/abstracts/reports/11tn012.cfm</link>
<description>This tech note shows how CERT-RMM process areas, industry standards, and codes of practices are connected.</description>
<pubDate>Thu, 23 Feb 2012 10:03:12 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2012/02/insiders_and_organized_crime.html</link>
<description>The entry "Insiders and Organized Crime" has been posted.</description>
<pubDate>Thu, 16 Feb 2012 15:16:52 -0500</pubDate>
</item>

<item>
<title>The CERT Guide to Insider Threats Book Published</title>
<link>http://www.sei.cmu.edu/library/abstracts/books/9780321812575.cfm?wt.ac=hpLibrary</link>
<description>This book describes the CERT Insider Threat Center's practical findings on insider cyber crimes, as well as guidance and countermeasures for organizations.</description>
<pubDate>Tue, 14 Feb 2012 14:29:43 -0500</pubDate>
</item>

<item>
<title>Risk-Based Measurement and Analysis: Application to Software Security Technical Note Released</title>
<link>http://www.cert.org/archive/pdf/12tn004.pdf</link>
<description>This technical note presents the foundations of a risk-based software security measurement and analysis method.</description>
<pubDate>Tue, 14 Feb 2012 09:26:19 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Protecting the internet and its users against cyber attacks requires a significant increase in the number of skilled cyber warriors.</description>
<pubDate>Tue, 31 Jan 2012 13:42:01 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2012/01/insider_threat_control_using_a_siem_signature_to_detect_potential_precursors_to_it_sabotage.html</link>
<description>The Entry &quot;Insider Threat Control: Using a SIEM signature to detect potential precursors to IT Sabotage&quot; has been posted.</description>
<pubDate>Thu, 26 Jan 2012 13:28:45 -0500</pubDate>
</item>

<item>
<title>Spotlight On: Malicious Insiders and Organized Crime Activity</title>
<link>http://www.cert.org/archive/pdf/12tn001.pdf</link>
<description>This TN is the fifth article in the Spotlight On quarterly series published by the CERT Insider Threat Center.</description>
<pubDate>Fri, 20 Jan 2012 15:20:20 -0500</pubDate>
</item>

<item>
<title>CERT Program Improves Security in C Programming Language Standard</title>
<link>http://www.sei.cmu.edu/newsitems/iso-standard.cfm</link>
<description>The CERT Secure Coding team made key contributions to the newest ISO/IEC C language standard.</description>
<pubDate>Mon, 16 Jan 2012 12:23:17 -0500</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2012/01/cname_flux.html</link>
<description>The entry "CNAME flux" has been posted.</description>
<pubDate>Thu, 05 Jan 2012 14:21:03 -0500</pubDate>
</item>

<item>
<title>Using Defined Processes as a Context for Resilience Measures Technical Note Released</title>
<link>http://www.cert.org/archive/pdf/11tn029.pdf</link>
<description>This technical note describes how implementation-level processes can help organizations define measures of operational resilience.</description>
<pubDate>Thu, 22 Dec 2011 12:17:25 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Electronic health records bring many benefits along with security and privacy challenges.</description>
<pubDate>Tue, 20 Dec 2011 13:35:12 -0500</pubDate>
</item>

<item>
<title>Standards-Based Automated Remediation 2011 Update Released</title>
<link>http://www.cert.org/archive/pdf/11sr016.pdf</link>
<description>This report updates the development of standards for remediation of vulnerabilities and compliance issues on Department of Defense networked systems for 2011.</description>
<pubDate>Mon, 19 Dec 2011 09:46:24 -0500</pubDate>
</item>

<item>
<title>Insider Threat Control Released</title>
<link>http://www.cert.org/archive/pdf/SIEM-Control.pdf</link>
<description>Insider Threat Control: Using a SIEM Signature to Detect Potential Precursors to IT Sabotage presents a technique for detecting potential insider sabotage over an organization's network.</description>
<pubDate>Thu, 15 Dec 2011 13:21:15 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2011/12/preparing_for_negative_workplace_events_-_managing_employee_expectations.html</link>
<description>The entry "Preparing for Negative Workplace Events - Managing Employee Expectations" has been posted.</description>
<pubDate>Thu, 15 Dec 2011 10:21:17 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2011/11/insider_threat_controls.html</link>
<description>The entry "Insider Threat Controls" has been posted.</description>
<pubDate>Wed, 16 Nov 2011 09:41:51 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2011/10/data_exfiltration_and_output_devices_-_an_overlooked_threat.html</link>
<description>The entry "Data Exfiltration and Output Devices - An Overlooked Threat" has been posted.</description>
<pubDate>Mon, 17 Oct 2011 13:43:37 -0400</pubDate>
</item>

<item>
<title>CERT Oracle Secure Coding Standard for Java Book Published</title>
<link>http://www.sei.cmu.edu/library/abstracts/books/9780321803955.cfm</link>
<description>The CERT Oracle Secure Coding Standard for Java has been published by Addison-Wesley Professional.</description>
<pubDate>Fri, 14 Oct 2011 11:17:39 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Demonstration Series Launched</title>
<link>http://www.cert.org/insider_threat/demonstrations/ITDS01.mp4</link>
<description>The CERT Insider Threat Center has released the first video in a series of insider threat demonstrations.</description>
<pubDate>Wed, 12 Oct 2011 15:12:45 -0400</pubDate>
</item>

<item>
<title>Insider Threat Control Technical Note Released</title>
<link>http://www.cert.org/archive/pdf/11tn024.pdf</link>
<description>This technical note describes how organizations can use Splunk to detect insider theft of intellectual property.</description>
<pubDate>Wed, 12 Oct 2011 10:26:26 -0400</pubDate>
</item>

<item>
<title>Agenda Now Available for Upcoming Workshop</title>
<link>http://www.cert.orghttp://www.thei3p.org/events/cybercpr.html</link>
<description>The Institute for Information Infrastructure Protection (I3P) and the CERT Program will present the workshop "Cyber Security CPR: Coordinated Private Response to Computer Security Incidents" in Arlington, VA on October 12-13. See the web page for a link to the agenda.</description>
<pubDate>Thu, 06 Oct 2011 12:18:04 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Measures of operational resilience should answer key questions, inform decisions, and affect behavior.</description>
<pubDate>Tue, 04 Oct 2011 12:03:49 -0400</pubDate>
</item>

<item>
<title>Community College Education Report Published</title>
<link>http://www.cert.orgarchive/pdf/11tr017.pdf</link>
<description>The fourth volume in the Software Assurance Curriculum Project focuses on community college courses for software assurance.</description>
<pubDate>Thu, 29 Sep 2011 10:50:48 -0400</pubDate>
</item>

<item>
<title>2010 CERT Research Report Published</title>
<link>http://www.cert.org/research/researchreport.html</link>
<description>The CERT Program is internationally known for developing practices and technologies to protect, detect, and respond to attacks, accidents, and failures on networked systems. This report describes progress in our innovative research projects and activities.</description>
<pubDate>Fri, 23 Sep 2011 10:25:26 -0400</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2011/09/challenges_in_network_monitori.html</link>
<description>The entry "Challenges in Network Monitoring above the Enterprise" has been published.</description>
<pubDate>Fri, 23 Sep 2011 10:15:33 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Use of Domain Name System security extensions can help prevent website hijacking attacks.</description>
<pubDate>Tue, 06 Sep 2011 13:08:52 -0400</pubDate>
</item>

<item>
<title>Registration Open for Webinar and Workshop</title>
<link>http://www.thei3p.org/events/cybercpr.html</link>
<description>The Institute for Information Infrastructure Protection (I3P) and the CERT Program will present the workshop "Cyber Security CPR: Coordinated Private Response to Computer Security Incidents" in Arlington, VA on October 12-13. There is a pre-event webinar on September 8. See the workshop web page for links to online registration forms.</description>
<pubDate>Tue, 06 Sep 2011 13:07:42 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2011/08/in_2009_the_cert_insider.html</link>
<description>The entry "The Necessity of Best Practices for the Prevention and Detection of Insider Threats" has been posted.</description>
<pubDate>Wed, 31 Aug 2011 09:55:22 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.orgblogs/insider_threat/2011/08/the_cert_insider_threat_database.html</link>
<description>The entry "The CERT Insider Threat Database" has been posted.</description>
<pubDate>Mon, 15 Aug 2011 10:08:26 -0400</pubDate>
</item>

<item>
<title>Keeping Your Family Safe in a Highly Connected World</title>
<link>http://www.cert.org/archive/pdf/KYFS2011.pdf</link>
<description>As our world becomes highly connected where endless data is just a click away and using networked devices has become almost a necessity, protecting your personal information and family privacy is of great concern.</description>
<pubDate>Thu, 11 Aug 2011 09:19:32 -0400</pubDate>
</item>

<item>
<title>Measures for Managing Operational Resilience Technical Report Published</title>
<link>http://www.cert.org/archive/pdf/11tr019.pdf</link>
<description>In this technical report Resilient Enterprise Management (REM) team members suggest a set of top ten strategic measures for managing operational resilience.</description>
<pubDate>Fri, 05 Aug 2011 13:17:15 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Depending on the service model, cloud providers and customers can monitor and implement controls to better protect their sensitive information.</description>
<pubDate>Tue, 02 Aug 2011 11:21:47 -0400</pubDate>
</item>

<item>
<title>Standards-Based Automated Remediation Special Report Released</title>
<link>http://www.cert.org/archive/pdf/11sr007.pdf</link>
<description>This report describes the development of standards for remediation of vulnerabilities and compliance issues on Department of Defense networked systems.</description>
<pubDate>Thu, 21 Jul 2011 16:05:40 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2011/07/insider_threat_methods_of_exfiltration.html</link>
<description>The entry "Theft of Intellectual Property and Tips for Prevention" has been published.</description>
<pubDate>Thu, 21 Jul 2011 13:44:32 -0400</pubDate>
</item>

<item>
<title>Request for Proposal - SEI Code Review Process</title>
<link>http://www.cert.org/secure-coding/CodeReviewRFP/</link>
<description>The SEI is issuing a Request for Proposal seeking interested organizations with experience performing web penetration and source code audits in systems developed in C#, Java, Ruby, Perl, Python, JavaScript, and PHP.</description>
<pubDate>Wed, 13 Jul 2011 09:06:46 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Analyzing malware is essential to assess the damage and reduce the impact associated with ongoing infection.</description>
<pubDate>Tue, 12 Jul 2011 11:38:11 -0400</pubDate>
</item>

<item>
<title>New CERT PGP Key</title>
<link>http://www.cert.org/contact_cert/encryptmail.html</link>
<description>CERT has updated its PGP key. We strongly urge you to encrypt sensitive information.</description>
<pubDate>Fri, 08 Jul 2011 13:27:12 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.orghttp://www.cert.org/blogs/insider_threat/2011/06/insider_threat_deep_dive_theft_of_intellectual_property.html</link>
<description>The entry "Insider Threat Deep Dive: Theft of Intellectual Property" has been posted.</description>
<pubDate>Mon, 27 Jun 2011 14:07:30 -0400</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2011/06/signed_java_and_cisco_anyconne.html</link>
<description>The entry &quot;Signed Java and Cisco AnyConnect&quot; has been posted.</description>
<pubDate>Thu, 09 Jun 2011 14:12:44 -0400</pubDate>
</item>

<item>
<title>A Preliminary Model of Insider Theft of Intellectual Property Technical Note Published</title>
<link>http://www.cert.org/archive/pdf/11tn013.pdf</link>
<description>This technical note presents research findings on insider theft of intellectual property.</description>
<pubDate>Fri, 03 Jun 2011 08:57:28 -0400</pubDate>
</item>

<item>
<title>CERT Used XNET for Forensics Challenge</title>
<link>http://www.sei.cmu.edu/newsitems/CERT-Team-Uses-XNET.cfm</link>
<description>This article describes the role that XNET played in the CERT Forensics Challenge, designed for the 2011 National Security Agency Cyber Defense Exercise.</description>
<pubDate>Thu, 02 Jun 2011 09:30:37 -0400</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2011/05/effectiveness_of_microsoft_off.html</link>
<description>The entry "Effectiveness of Microsoft Office File Validation" has been published.</description>
<pubDate>Thu, 19 May 2011 15:04:08 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2011/05/insider_threat_and_physical_security_of_organizations.html</link>
<description>The entry "Insider Threat and Physical Security of Organizations" has been published.</description>
<pubDate>Tue, 10 May 2011 14:34:40 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Over 100 electric power utilities are accelerating their transformation to the smart grid by using the Smart Grid Maturity Model.</description>
<pubDate>Thu, 05 May 2011 13:04:22 -0400</pubDate>
</item>

<item>
<title>New CERT Blogs Index</title>
<link>http://www.cert.org/blogs/</link>
<description>This main index page displays the ten most recent entries across all of our blogs. You can reach this page through the blogs link in the bottom navigation.</description>
<pubDate>Tue, 03 May 2011 11:55:23 -0400</pubDate>
</item>

<item>
<title>Trusted Computing in Embedded Systems Workshop Released</title>
<link>http://www.cert.org/archive/pdf/11SR002.pdf</link>
<description>This SEI Special Report describes the November 2010 Trusted Computing in Embedded Systems Workshop held at Carnegie Mellon University.</description>
<pubDate>Fri, 29 Apr 2011 13:57:52 -0400</pubDate>
</item>

<item>
<title>Software Security Measurement and Analysis Presentation Released</title>
<link>http://www.cert.org/archive/pdf/SecurityMeasurementandAnalysis.pdf</link>
<description>Cyber Security Engineering researchers at CERT have released a presentation describing their Security Measurement and Analysis (SMA) Project.</description>
<pubDate>Thu, 28 Apr 2011 13:26:06 -0400</pubDate>
</item>

<item>
<title>SPREE Workshop</title>
<link>http://www.cert.org/spree</link>
<description>SPREE Workshop registration is now open. You can register by using this form (pdf).</description>
<pubDate>Tue, 26 Apr 2011 13:27:00 -0400</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2011/04/office_shootout_microsoft_offi.html</link>
<description>The entry "A Security Comparison: Microsoft Office vs. Oracle Openoffice" has been published.</description>
<pubDate>Wed, 13 Apr 2011 14:58:49 -0400</pubDate>
</item>

<item>
<title>CERT Staff Presenting at SEPG Europe 2011</title>
<link>http://www.sei.cmu.edu/sepg/europe/2011/tutorials.cfm</link>
<description>To reinforce the "Global Excellence in Software and Security" theme, CERT staff members are presenting tutorials on a variety of security topics.</description>
<pubDate>Thu, 07 Apr 2011 13:02:25 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2011/04/insider_threat_best_practices_from_industry.html</link>
<description>The entry "Insider Threat Best Practices from Industry" has been published.</description>
<pubDate>Wed, 06 Apr 2011 11:17:48 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>BuBusiness l leaders must address risk at the enterprise, business process, and system levels to effectively protect against today's and tomorrow's threats.</description>
<pubDate>Tue, 29 Mar 2011 16:35:47 -0400</pubDate>
</item>

<item>
<title>2011 CyberSecurity Watch Survey Released</title>
<link>http://www.cert.org/archive/pdf/CyberSecuritySurvey2011.pdf</link>
<description>The 2011 CyberSecurity Watch Survey press release and data sample have been released.</description>
<pubDate>Fri, 04 Mar 2011 10:30:47 -0500</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2011/02/cert_basic_fuzzing_framework_b.html</link>
<description>The entry "Announcing the CERT Basic Fuzzing Framework 2.0" has been published.</description>
<pubDate>Mon, 28 Feb 2011 15:57:24 -0500</pubDate>
</item>

<item>
<title>Function Extraction (FX) Research for Computation of Software Behavior Technical Report Released</title>
<link>http://www.cert.org/archive/pdf/11tr009.pdf</link>
<description>This technical report discusses use of algorithms to compute overall malware behavior.</description>
<pubDate>Mon, 28 Feb 2011 13:29:14 -0500</pubDate>
</item>

<item>
<title>Risk and Resilience: Considerations for Information Security Risk Assessment and Management</title>
<link>http://www.cert.org/archive/pdf/GRC-202_Cebula_Allen.pdf</link>
<description>Julia Allen and Jim Cebula gave this presentation at RSA Conference 2011 in San Francisco, California.</description>
<pubDate>Wed, 23 Feb 2011 21:30:20 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2011/02/insider_threats_in_the_software_development_lifecycle.html</link>
<description>The entry "Insider Threats in the Software Development Lifecycle" has been published.</description>
<pubDate>Wed, 23 Feb 2011 15:06:45 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Scenario-based exercises help organizations, governments, and nations prepare for, identify, and mitigate cyber risks.</description>
<pubDate>Tue, 22 Feb 2011 15:37:18 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Presentation Published</title>
<link>http://www.cert.org/archive/pdf/HT2-108_Cappelli_MontelibanoJan26.pdf</link>
<description>"Combat IT Sabotage: Technical Solutions From The CERT Insider Threat Lab," presentated at RSA Conference 2011 in San Francisco, California, is now available.</description>
<pubDate>Mon, 21 Feb 2011 13:54:31 -0500</pubDate>
</item>

<item>
<title>An Analysis of Technical Observations in Insider Theft of Intellectual Property Cases Technical Note Published</title>
<link>http://www.cert.org/archive/pdf/11tn006.pdf</link>
<description>This techincal note provides an overview of techniques employed by malicious insiders to steal intellectual property.</description>
<pubDate>Mon, 21 Feb 2011 13:04:17 -0500</pubDate>
</item>

<item>
<title>Integrating the MSwA Reference Curriculum into the MSIS Model Curriculum Technical Note Published</title>
<link>http://www.cert.org/archive/pdf/11tn004.pdf</link>
<description>This technical note examines how the MSwA Reference Curriculum recommendations might be integrated into the model curriculum recommendations for a MSIS degree.</description>
<pubDate>Wed, 16 Feb 2011 14:51:54 -0500</pubDate>
</item>

<item>
<title>New CERT/CC Blog Entry</title>
<link>http://www.cert.org/blogs/certcc/2011/02/network_monitoring_for_web-bas.html</link>
<description>The entry "'Network Monitoring for Web-Based Threats' released" has been published.</description>
<pubDate>Mon, 14 Feb 2011 13:36:55 -0500</pubDate>
</item>

<item>
<title>Changes to Vulnerability Analysis Blog</title>
<link>http://www.cert.org/blogs/certcc/2011/02/blog_reorganization.html</link>
<description>To allow for expansion into other technical areas, the Vulnerability Analysis Blog has been converted to the CERT/CC Blog.</description>
<pubDate>Fri, 11 Feb 2011 15:31:15 -0500</pubDate>
</item>

<item>
<title>Network Monitoring for Web-Based Threats Report Published</title>
<link>http://www.cert.org/archive/pdf/11tr005.pdf</link>
<description>This report models the approach a focused attacker would take in order to breach an organization through web-based protocols and provides detection or prevention methods to counter that approach.</description>
<pubDate>Thu, 10 Feb 2011 15:04:29 -0500</pubDate>
</item>

<item>
<title>Security and Privacy Engineering (SPREE) Workshop Scheduled for June</title>
<link>http://www.cert.org/spree</link>
<description>The SPREE Workshop will be held at Carnegie Mellon University on June 15-16, 2011. Discussions will focus on security and privacy challenges associated with developing and maintaining software as data-driven technology continues to advance.</description>
<pubDate>Mon, 31 Jan 2011 10:05:57 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2011/01/insider_threat_case_trends_of_technical_and_non-technical_employees.html</link>
<description>The entry "Insider Threat Case Trends of Technical and Non-Technical Employees" has been published.</description>
<pubDate>Wed, 26 Jan 2011 10:17:18 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Technical controls may be effective in helping prevent, detect, and respond to insider crimes.</description>
<pubDate>Tue, 25 Jan 2011 11:30:53 -0500</pubDate>
</item>

<item>
<title>Trust and Trusted Computing Platforms Technical Note Published</title>
<link>http://www.cert.org/archive/pdf/11tn005.pdf</link>
<description>This technical note examines the capabilities and limitations of hardware-based trusted platforms in general, and the Trusted Platform Module (TPM) from the perspective of trusted applications in particular.</description>
<pubDate>Fri, 21 Jan 2011 14:42:42 -0500</pubDate>
</item>

<item>
<title>Deriving Candidate Technical Controls and Indicators of Insider Attack from Socio-Technical Models and Data Technical Note Published</title>
<link>http://www.cert.org/archive/pdf/11tn003.pdf</link>
<description>This paper demonstrates how to extract and map technical information from previous insider crimes.</description>
<pubDate>Mon, 17 Jan 2011 10:19:50 -0500</pubDate>
</item>

<item>
<title>Software Supply Chain Risk Management Technical Note Published</title>
<link>http://www.cert.org/archive/pdf/10tn026.pdf</link>
<description>This technical note considers current practices in software supply chain analysis and suggests foundational practices.</description>
<pubDate>Tue, 04 Jan 2011 11:39:42 -0500</pubDate>
</item>

<item>
<title>CERT Resilience Management Model Book Published</title>
<link>http://www.sei.cmu.edu/newsitems/CERT-RMM-Book-Published.cfm</link>
<description>The CERT Resilience Management Model (CERT-RMM) Version 1.1 has been published by Addison-Wesley Professional.</description>
<pubDate>Mon, 03 Jan 2011 11:55:30 -0500</pubDate>
</item>

<item>
<title>A Taxonomy of Operational Cyber Security Risks Published</title>
<link>http://www.cert.org/archive/pdf/10tn028.pdf</link>
<description>This technical note presents a taxonomy of operational cyber security risks that attempts to identify and organize the sources of operational cyber security risk.</description>
<pubDate>Wed, 29 Dec 2010 10:52:32 -0500</pubDate>
</item>

<item>
<title>Source Code Analysis Laboratory (SCALe) for Energy Delivery Systems Report Published</title>
<link>http://www.cert.org/archive/pdf/10tr021.pdf</link>
<description>The Source Code Analysis Laboratory (SCALe) is an operational capability that tests software applications for conformance to one of the CERT secure coding standards.</description>
<pubDate>Wed, 29 Dec 2010 09:49:20 -0500</pubDate>
</item>

<item>
<title>CERT Approach to Cybersecurity Workforce Development Report Published</title>
<link>http://www.cert.org/archive/PDF/10tr045.pdf</link>
<description>This report presents a new, continuous approach to cybersecurity workforce development.</description>
<pubDate>Wed, 22 Dec 2010 14:01:12 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2010/12/case_trends_for_type_and_status_of_insiders.html</link>
<description>The entry "Insider Threat Case Trends for Employee Type and Employment Status" has been published.</description>
<pubDate>Wed, 22 Dec 2010 11:15:47 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2010/12/case_trends_for_type_and_status_of_insiders.html</link>
<description>The entry "Insider Threat Case Trends for Employee Type and Employment Status" has been published.</description>
<pubDate>Tue, 21 Dec 2010 10:48:35 -0500</pubDate>
</item>

<item>
<title>How Resilient Is My Organization?</title>
<link>http://www.cert.org/podcast/show/20101209caralli.html</link>
<description>Use the CERT Resilience Management Model (CERT-RMM) to help ensure that critical assets and services perform as expected in the face of stress and disruption.</description>
<pubDate>Thu, 09 Dec 2010 13:45:24 -0500</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2010/12/upcoming_insider_threat_presentations.html</link>
<description>The entry "Upcoming Insider Threat Presentations" has been published.</description>
<pubDate>Mon, 06 Dec 2010 09:42:40 -0500</pubDate>
</item>

<item>
<title>CERT Career Fair Scheduled for January</title>
<link>http://certcareerfair.org/</link>
<description>Representatives from CERT will be in Arlington, VA on January 26-27 to meet with candidates interested in job opportunities. Applicants must submit resumes in advance for this appointment-only event.</description>
<pubDate>Fri, 03 Dec 2010 15:10:38 -0500</pubDate>
</item>

<item>
<title>Best Practices for National Cyber Security: Building a National Computer Security Incident Management Capability</title>
<link>http://www.cert.org/archive/pdf/10sr009.pdf</link>
<description>This special report is the first in a series of best practices information that interested organizations and governments can use to begin to develop a national incident management capability.</description>
<pubDate>Fri, 03 Dec 2010 10:26:56 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Government agencies and private industry must build effective partnerships to secure national critical infrastructures.</description>
<pubDate>Tue, 30 Nov 2010 13:54:04 -0500</pubDate>
</item>

<item>
<title>Measuring Operational Resilience Using the CERT Resilience Management Model </title>
<link>http://www.cert.org/archive/pdf/10tn030.pdf</link>
<description>This Technical Note is the first in a series of publications designed to start a dialog on the topic of meaningful measurement.</description>
<pubDate>Fri, 19 Nov 2010 17:03:21 -0500</pubDate>
</item>

<item>
<title>New CERT PGP Key</title>
<link>http://www.cert.org/contact_cert/encryptmail.html</link>
<description>CERT has updated its PGP public key. We strongly urge you to encrypt sensitive information.</description>
<pubDate>Mon, 01 Nov 2010 15:27:40 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Knowledge about software assurance is essential to ensure that complex systems function as intended.</description>
<pubDate>Tue, 26 Oct 2010 13:32:50 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2010/10/interesting_insider_threat_statistics.html</link>
<description>The entry "Interesting Insider Threat Statistics" has been published.</description>
<pubDate>Mon, 25 Oct 2010 11:52:44 -0400</pubDate>
</item>

<item>
<title>FloCon 2011 Keynote Speaker Announced</title>
<link>http://blogs.cisco.com/author/JohnStewart/</link>
<description>John Stewart, vice president and chief security officer of Cisco, will deliver one of the keynote addresses at FloCon 2011.</description>
<pubDate>Fri, 22 Oct 2010 13:11:39 -0400</pubDate>
</item>

<item>
<title>FloCon 2011 Registration Open</title>
<link>http://www.cert.org/flocon/</link>
<description>Registration for FloCon 2011 is now open. The early bird registration fee will begin at $660.00 until November 22, 2010. Please use discount code FLOCONNEB when registering on or before November 22, 2010.</description>
<pubDate>Fri, 22 Oct 2010 12:14:37 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2010/10/a_threat-centric_approach_to_detecting_and_preventing_insider_threat.html</link>
<description>The entry "A Threat-Centric Approach to Detecting and Preventing Insider Threat" has been published.</description>
<pubDate>Mon, 11 Oct 2010 15:55:15 -0400</pubDate>
</item>

<item>
<title>Participation Opportunities for FloCon 2011 Published</title>
<link>http://www.cert.org/flocon/</link>
<description>The call for presentations, a description of sponsorship opportunities, and the sponsorship agreement have been released.</description>
<pubDate>Thu, 07 Oct 2010 15:38:21 -0400</pubDate>
</item>

<item>
<title>Integrated Measurement and Analysis Framework for Software Security Technical Note Published</title>
<link>http://www.cert.org/archive/pdf/10tn025.pdf</link>
<description>This report is the first in a series that addresses how to measure software security in complex environments using the Integrated Measurement and Analysis Framework (IMAF) for software security.</description>
<pubDate>Wed, 06 Oct 2010 16:32:18 -0400</pubDate>
</item>

<item>
<title>Security Requirements Reusability and the SQUARE Methodology</title>
<link>http://www.cert.org/archive/pdf/10tn027.pdf</link>
<description>R-SQUARE incorporates reusable security goals and requirements into a variant of Security Quality Requirements Engineering (SQUARE).</description>
<pubDate>Fri, 01 Oct 2010 11:56:26 -0400</pubDate>
</item>

<item>
<title>Building Assured Systems Framework Report Published</title>
<link>http://www.cert.org/archive/pdf/10tr025.pdf</link>
<description>The BASF addresses the customer and researcher challenges of selecting security methods and research approaches for building assured systems.</description>
<pubDate>Thu, 30 Sep 2010 14:11:58 -0400</pubDate>
</item>

<item>
<title>Upcoming IEEE Smart Grid Survivability Workshop</title>
<link>http://www.cert.org/cisw/sg2010/</link>
<description>This workshop will take place October 13-14, 2010 in Arlington, Virginia</description>
<pubDate>Thu, 30 Sep 2010 13:47:28 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Organizations can benchmark their software security practices against 109 observed activities from 30 organizations.</description>
<pubDate>Tue, 28 Sep 2010 10:40:24 -0400</pubDate>
</item>

<item>
<title>New Vulnerability Analysis Blog Entry</title>
<link>http://www.cert.org/blogs/vuls/2010/09/cert_basic_fuzzing_framework_u.html</link>
<description>The entry "CERT Basic Fuzzing Framework Update" has been published.</description>
<pubDate>Wed, 22 Sep 2010 11:31:22 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Blog Entry</title>
<link>http://www.cert.org/blogs/insider_threat/2010/09/insider_threat_deep_dive_it_sabotage.html</link>
<description>The entry "Insider Threat Deep Dive: IT Sabotage" has been published.</description>
<pubDate>Wed, 22 Sep 2010 10:36:45 -0400</pubDate>
</item>

<item>
<title>New CERT PGP Key</title>
<link>http://www.cert.org/contact_cert/encryptmail.html</link>
<description>CERT has updated its PGP public key. We strongly urge you to encrypt sensitive information.</description>
<pubDate>Tue, 14 Sep 2010 12:41:39 -0400</pubDate>
</item>

<item>
<title>Insider Threat Blog Released</title>
<link>http://www.cert.org/blogs/insider_threat/</link>
<description>The first entry in our new insider threat blog has been published.</description>
<pubDate>Wed, 08 Sep 2010 14:34:00 -0400</pubDate>
</item>

<item>
<title>FloCon 2010 Proceedings Available</title>
<link>http://www.cert.org/flocon/2010/proceedings.html</link>
<description>Proceedings from FloCon 2010 have been released.</description>
<pubDate>Fri, 03 Sep 2010 12:16:51 -0400</pubDate>
</item>

<item>
<title>Software Assurance Curriculum Materials Available</title>
<link>http://www.cert.org/mswa</link>
<description>A Master of Software Assurance Reference Curriculum and undergraduate course outlines are now available for download.</description>
<pubDate>Wed, 01 Sep 2010 16:03:44 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Internet-connected mobile devices are becoming increasingly attractive targets.</description>
<pubDate>Tue, 31 Aug 2010 10:57:33 -0400</pubDate>
</item>

<item>
<title>FloCon 2011 Announced</title>
<link>http://www.cert.org/flocon/</link>
<description>FloCon 2011 will take place in Salt Lake City, Utah, January 10-13, 2011.</description>
<pubDate>Fri, 27 Aug 2010 10:18:49 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>A national CSIRT is essential for protecting national and economic security, and ensuring the continuity of government agencies and critical infrastructures.</description>
<pubDate>Thu, 19 Aug 2010 08:18:09 -0400</pubDate>
</item>

<item>
<title>Technical Note on Adapting the SQUARE Process for Privacy Requirements Engineering Published</title>
<link>http://www.cert.org/archive/pdf/10tn022.pdf</link>
<description>This technical note explores the use of a disciplined approach to identifying privacy requirements, primarily how the Security Quality Requirements Engineering (SQUARE) process, which was developed for security requirements engineering, can be adapted for privacy requirements engineering in software development.</description>
<pubDate>Mon, 02 Aug 2010 09:42:50 -0400</pubDate>
</item>

<item>
<title>Spotlight On: Insider Threat from Trusted Business Partners Published</title>
<link>http://www.cert.org/archive/pdf/TrustedBusinessPartners0210.pdf</link>
<description>This article focuses on cases in the CERT Insider Threat Center database in which malicious insiders were employed by a trusted business partner of the victim organization. These cases involve outsourcing as well as individual contractors and consultants.</description>
<pubDate>Thu, 29 Jul 2010 16:44:17 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Securing systems that control physical switches, valves, pumps, meters, and manufacturing lines as these systems connect to the internet is critical for service continuity.</description>
<pubDate>Tue, 27 Jul 2010 10:36:09 -0400</pubDate>
</item>

<item>
<title>CERT/CC Enhancing Collaboration Between National CSIRTs</title>
<link>http://www.cert.org/csirts/national/</link>
<description>The CERT/CC has created both a wiki and an operational mailing list for authorized technical staff at national CSIRTs. These tools will promote collaboration and information exchange about technical projects and other relevant work.</description>
<pubDate>Thu, 08 Jul 2010 10:45:45 -0400</pubDate>
</item>

<item>
<title>Upcoming SEI Webinar on the CERT Resilience Management Model</title>
<link>http://www.sei.cmu.edu/events/Event-Details.cfm?customel_dataPageID_4744=587174</link>
<description>On July 28, 2010, Rich Caralli will present "Transforming Your Operational Resilience Management Capabilities: CERT's Resilience Management Model" as part of the Software Engineering Institute's webinar series.</description>
<pubDate>Fri, 02 Jul 2010 11:03:47 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Complex, distributed, multi-year investigations of computer crimes require sophisticated methods, techniques, and tools.</description>
<pubDate>Tue, 29 Jun 2010 10:39:13 -0400</pubDate>
</item>

<item>
<title>National CSIRTs to Meet in Miami</title>
<link>http://www.cert.org/csirts/national/conference.html</link>
<description>On June 19-20, the CERT/CC is hosting a meeting of CSIRTs with national responsibility in Miami, Florida. Attendees will discuss the unique challenges facing national CSIRTs and will share information about projects and solutions.</description>
<pubDate>Wed, 09 Jun 2010 12:33:42 -0400</pubDate>
</item>

<item>
<title>Fuzz Testing Tool Available</title>
<link>http://www.cert.org/download/bff/</link>
<description>The CERT Basic Fuzzing Framework (BFF) is a Linux-based tool for fuzz testing software that runs on Linux. This free tool is now available for download.</description>
<pubDate>Wed, 09 Jun 2010 12:12:55 -0400</pubDate>
</item>

<item>
<title>Java Concurrency Guidelines Report Published</title>
<link>http://www.cert.org/archive/pdf/10tr015.pdf</link>
<description>The CERT Oracle Secure Coding Standard for Java provides guidelines for securrogramming language</description>
<pubDate>Mon, 07 Jun 2010 17:22:27 -0400</pubDate>
</item>

<item>
<title>Second Edition of Specifications for Managed Strings Report Published</title>
<link>http://www.cert.org/archive/pdf/10tr018.pdf</link>
<description>This report describes a managed string library for the C programming language.</description>
<pubDate>Mon, 07 Jun 2010 17:13:25 -0400</pubDate>
</item>

<item>
<title>Survivability Analysis Framework Technical Note Published</title>
<link>http://www.cert.org/archive/pdf/10tn013.pdf</link>
<description>The technical note describes the Survivability Analysis Framework (SAF), which can be used to examine the elements of an operational process and evaluate the survivability of an organization.</description>
<pubDate>Wed, 02 Jun 2010 09:50:05 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>To help identify and eliminate security vulnerabilities, subject all software that you build and buy to fuzz testing.</description>
<pubDate>Tue, 25 May 2010 14:23:58 -0400</pubDate>
</item>

<item>
<title>Resilience Management Model Report Published</title>
<link>http://www.cert.org/archive/pdf/10tr012.pdf</link>
<description>The CERT-RMM report describes the key concepts, components, and process area relationships of the model, which is an innovative way to approach the challenge of managing operational resilience in complex, risk-evolving environments.</description>
<pubDate>Mon, 24 May 2010 09:35:14 -0400</pubDate>
</item>

<item>
<title>Technical Report About Network Behavior Published</title>
<link>http://www.cert.org/archive/pdf/10tr010.pdf</link>
<description>The report, Identifying Anomalous Port-Specific Network Behavior, describes a method for detecting behavior that may be a precursor to internet-wide attacks.</description>
<pubDate>Fri, 21 May 2010 09:42:52 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Organized criminals recruit unsuspecting intermediaries to help steal funds from small businesses.</description>
<pubDate>Tue, 27 Apr 2010 10:19:54 -0400</pubDate>
</item>

<item>
<title>2009 CERT Research Annual Report Published</title>
<link>http://www.cert.org/research/2009research-report.pdf</link>
<description>CERT is developing theoretical foundations and engineering methods to help ensure the security of critical systems and networks. This report describes progress in CERT research projects and opportunities for collaboration.</description>
<pubDate>Mon, 05 Apr 2010 11:16:55 -0400</pubDate>
</item>

<item>
<title>New Insider Threat Presentation Published</title>
<link>http://www.cert.org/archive/pdf/Insider-Threat-RSA-2010.pdf</link>
<description>"The Key to Successful Monitoring for Detection of Insider Attacks," presentated at RSA Conference 2010 in San Francisco, California, is now available.</description>
<pubDate>Mon, 05 Apr 2010 10:15:19 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Being able to respond effectively when faced with a disruptive event requires that staff members learn to become more resilient.</description>
<pubDate>Tue, 30 Mar 2010 10:43:16 -0400</pubDate>
</item>

<item>
<title>New CERT PGP Public Key</title>
<link>http://www.cert.org/contact_cert/encryptmail.html</link>
<description>CERT has updated its PGP public key. We strongly urge you to encrypt sensitive information.</description>
<pubDate>Fri, 05 Mar 2010 14:52:00 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>CISOs must leave no room for anyone to deny that they understand what is expected of them when developing secure software.</description>
<pubDate>Tue, 02 Mar 2010 09:41:55 -0500</pubDate>
</item>

<item>
<title>2010 Vulnerability Discovery Workshop</title>
<link>http://www.cert.org/vuls/discovery/workshop_2010.html</link>
<description>On February 1, 2010, CERT hosted a workshop with vulnerability researchers and software vendors to discuss ideas, tools, and techniques used to find vulnerabilities.</description>
<pubDate>Thu, 25 Feb 2010 16:48:28 -0500</pubDate>
</item>

<item>
<title>MITRE CWE and CERT Secure Coding Standards</title>
<link>http://www.cert.org/archive/pdf/CWE_CERT.pdf</link>
<description>This paper describes the Common Weakness Enumeration (CWE) and the CERT secure coding standards and explains the relationship between them.</description>
<pubDate>Thu, 18 Feb 2010 13:39:28 -0500</pubDate>
</item>

<item>
<title>Instrumented Fuzz Testing Using AIR Integers Published</title>
<link>http://www.cert.org/archive/pdf/Fuzzing-AIRintegers.pdf</link>
<description>This paper presents the as-if infinitely ranged (AIR) integer model, which provides a largely automated mechanism for eliminating integer overflow, truncation, and other integral exceptional conditions.</description>
<pubDate>Thu, 18 Feb 2010 13:36:31 -0500</pubDate>
</item>

<item>
<title>Results of 2010 CyberSecurity Watch Survey Released</title>
<link>http://www.cert.org/archive/pdf/ecrimesummary10.pdf</link>
<description>This survey, a cooperative effort of multiple organizations, collected answers from more than 500 rent executives, professionals, and consultants.</description>
<pubDate>Fri, 12 Feb 2010 09:55:10 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Students learn how to combine multiple facets of digital forensics and draw conclusions to support full-scale investigations.</description>
<pubDate>Tue, 02 Feb 2010 09:32:46 -0500</pubDate>
</item>

<item>
<title>New CERT PGP Public Key</title>
<link>http://www.cert.org/contact_cert/encryptmail.html</link>
<description>CERT has updated its PGP public key. We strongly urge you to encrypt sensitive information.</description>
<pubDate>Wed, 20 Jan 2010 14:14:25 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>The SGMM provides a roadmap to guide an organization's transformation to the smart grid.</description>
<pubDate>Tue, 12 Jan 2010 09:51:21 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Addressing privacy during software development is just as important as addressing security.</description>
<pubDate>Tue, 22 Dec 2009 09:44:19 -0500</pubDate>
</item>

<item>
<title>SQUARE Tool Is Now Available</title>
<link>http://www.cert.org</link>
<description></description>
<pubDate>Fri, 04 Dec 2009 16:32:28 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Network defenders and business leaders can use NetSA measures and evidence to better protect their networks.</description>
<pubDate>Tue, 01 Dec 2009 09:49:51 -0500</pubDate>
</item>

<item>
<title>CERT Tactical Response and Analysis Challege Tests Cybersecurity Skills</title>
<link>http://www.sei.cmu.edu/newsitems/cert_TRAC.cfm</link>
<description>Twenty-nine competing teams from 20 countries participated in the Tactical Response and Analysis Challenge (TRAC) conducted by the SEI's CERT PRogram as part of the weeklong International Cyber Defense Workshop (ICDW), which concluded November 13, 2009.</description>
<pubDate>Tue, 17 Nov 2009 14:39:21 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Providing critical services during times of stress depends on documented, tested business continuity plans.</description>
<pubDate>Tue, 10 Nov 2009 10:24:37 -0500</pubDate>
</item>

<item>
<title>Spotlight On - Insider Theft of Intellectual Property inside the U.S. Involving Foreign Governments or Organizations</title>
<link>http://www.cert.org/archive/pdf/CyLabForeignTheftIP.pdf</link>                                                                                             
<description>This report is the third in the quarterly series, Spotlight On, published by the Insider Threat Center at CERT and funded by CyLab. This article focuses on insider theft of intellectual property inside the U.S. involving foreign governments or organizations.</description>
<pubDate>Mon, 09 Nov 2009 13:23:01 -0500</pubDate>
</item>

<item>
<title>Deadline for FloCon Abstracts Extended</title>
<link>http://www.cert.org/flocon/</link>
<description>The deadline to submit abstracts for presentations and demonstrations for FloCon 2010 has been extended to Monday, November 9.</description>
<pubDate>Tue, 27 Oct 2009 11:35:44 -0400</pubDate>
</item>

<item>
<title>Secure Design Patterns</title>
<link>http://www.cert.org/archive/pdf/09tr010.pdf</link>
<description>This newly updated technical report describes a set of secure design patterns, which are descriptions or templates describing a general solution to a security problem that can be applied in many different situations.</description>
<pubDate>Fri, 23 Oct 2009 11:49:52 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>A defined, managed process for third party relationships is essential, particularly when business is disrupted.</description>
<pubDate>Tue, 20 Oct 2009 14:52:15 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>The smart grid is the use of digital technology to modernize the power grid, which comes with some new privacy and security challenges.</description>
<pubDate>Tue, 29 Sep 2009 10:27:54 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Electronic health records (EHRs) are possibly the most complicated area of IT today, more difficult than defense.</description>
<pubDate>Tue, 08 Sep 2009 10:52:58 -0400</pubDate>
</item>

<item>
<title>Effectiveness of the Vulnerability Response Decision Assistance (VRDA) Framework</title>
<link>http://www.cert.org/archive/pdf/VRDA_Effectiveness.pdf</link>
<description>This paper examines the effectiveness of VRDA in terms of how well it predicts responses.</description>
<pubDate>Tue, 25 Aug 2009 11:18:10 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>282 cases of actual insider attacks suggest 16 best practices for preventing and detecting insider threat.</description>
<pubDate>Tue, 18 Aug 2009 11:20:50 -0400</pubDate>
</item>

<item>
<title>Spotlight On: Malicious Insiders with Ties to the Internet Underground Community (pdf), March 2009</title>
<link>http://www.cert.org/insider_threat/docs/CyLab%20Insider%20Threat%20Quarterly%20on%20Internet%20Underground%20-%20March%202009P.pdf</link>
<description>This report is the second in the quarterly series, Spotlight On, published by the Insider Threat Center at CERT and funded by CyLab. This article focuses on insider threat cases in which the insider had relationships with the internet underground community.</description>
<pubDate>Fri, 31 Jul 2009 11:46:23 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Automation, innovation, reaction, and expansion are the foundation for obtaining meaningful network traffic intelligence in today's extended enterprise.</description>
<pubDate>Tue, 28 Jul 2009 09:55:42 -0400</pubDate>
</item>

<item>
<title>Insider Theft of Intellectual Property for Business Advantage: A Preliminary Model</title>
<link>http://www.cert.org/insider_threat/docs/Insider_Theft_of_IP_Model_MIST09.pdf</link>
<description>This paper provides observations about and a preliminary system dynamics model of one class of insider crime based on empirical data.</description>
<pubDate>Mon, 20 Jul 2009 14:30:18 -0400</pubDate>
</item>

<item>
<title>As-if Infinitely Ranged Integer Model Published</title>
<link>http://www.cert.org/archive/pdf/09tn023.pdf</link>
<description>This paper presents a model for automating the elimination of integer overflow and truncation in C and C++ programming code.</description>
<pubDate>Fri, 17 Jul 2009 16:18:45 -0400</pubDate>
</item>

<item>
<title>First Time Offering, Register Now: Secure Coding in C and C++</title>
<link>http://www.sei.cmu.edu/products/courses/p63.html</link>
<description>This four-day course provides a detailed explanation of common programming errors in C and C++ and describes how these errors can lead to code that is vulnerable to exploitation. The course concentrates on security issues intrinsic to the C and C++ programming languages and associated libraries. The intent is for thiscourse to be useful to anyone involved in developing secure C and C++ programs regardless of the specific application.</description>
<pubDate>Tue, 14 Jul 2009 16:14:49 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Business leaders need new approaches to address multi-enterprise, systems of systems risks across the life cycle and supply chain.</description>
<pubDate>Tue, 07 Jul 2009 12:37:52 -0400</pubDate>
</item>

<item>
<title>Resiliency Management Model v1.0 Released</title>
<link>http://www.cert.org/resiliency/rmm.html</link>
<description>CERT has published the first process areas of the Resiliency Management Model, a capability model for operational resiliency management.</description>
<pubDate>Thu, 02 Jul 2009 08:52:59 -0400</pubDate>
</item>

<item>
<title>Winners of Best Practices Contest 2009 Announced</title>
<link>http://www.cert.org/csirts/national/contest_2009.html</link>
<description>The winners of the Best Practices Contest 2009 were announced at the FIRST conference in Kyoto, Japan. Read the winning submissions.</description>
<pubDate>Mon, 29 Jun 2009 20:31:46 -0400</pubDate>
</item>

<item>
<title>New CERT PGP Public Key</title>
<link>http://www.cert.org/contact_cert/encryptmail.html</link>
<description>CERT has updated its PGP public key. We strongly urge you to encrypt sensitive information.</description>
<pubDate>Mon, 22 Jun 2009 15:18:31 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>When considering cloud services, business leaders need to weigh the economic benefits against the security and privacy risks.</description>
<pubDate>Tue, 16 Jun 2009 10:36:38 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Business leaders need to take action to better mitigate sophisticated social engineering attacks.</description>
<pubDate>Tue, 26 May 2009 10:21:57 -0400</pubDate>
</item>

<item>
<title>Attend the SEI Webinar on May 14</title>
<link>https://www1.gotomeeting.com/register/845945576</link>
<description>Register for the webinar SQUARE Up Your Security Requirements Engineering with SQUARE. This webinar provides an overview of the SQUARE process and discusses current activities and plans.</description>
<pubDate>Fri, 08 May 2009 13:54:42 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Now may be the time to examine our responsibilities when developing software with known, preventable errors - along with some possible consequences.</description>
<pubDate>Tue, 05 May 2009 09:53:59 -0400</pubDate>
</item>

<item>
<title>Making the Business Case for Software Assurance Published</title>
<link>http://www.cert.org/archive/pdf/09sr001.pdf</link>
<description>This report provides guidance for making the business case for building software assurance into software products during each software development life-cycle activity.</description>
<pubDate>Thu, 30 Apr 2009 14:46:23 -0400</pubDate>
</item>

<item>
<title>Register for First Insider Threat Workshop</title>
<link>http://www.sei.cmu.edu/products/courses/p76.html</link>
<description>Learn how to identify and manage the risk of insider threat in your organization. Register now for the two-day Insider Threat Workshop in Arlington, VA.</description>
<pubDate>Fri, 24 Apr 2009 10:45:29 -0400</pubDate>
</item>

<item>
<title>CERT Releases Dranzer Tool</title>
<link>http://www.cert.org/vuls/discovery/dranzer.html</link>
<description>As part of their vulnerability discovery efforts, CERT has released Dranzer, an open source tool that software developers can use to test for ActiveX vulnerabilities.</description>
<pubDate>Thu, 16 Apr 2009 07:29:02 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Capitalizing on the cultural norms of the Net Generation is essential when developing security awareness programs.</description>
<pubDate>Tue, 14 Apr 2009 09:39:41 -0400</pubDate>
</item>

<item>
<title>Linux Forensics Tools Repository Released</title>
<link>http://www.cert.org/forensics/tools/</link>
<description>The CERT forensics tools repository, a collection of add-on packages for Fedora, provides many useful cyber forensics tools for analysts and practitioners.</description>
<pubDate>Mon, 13 Apr 2009 08:54:16 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Observed practice, represented as a maturity model, can serve as a basis for developing more secure software.</description>
<pubDate>Tue, 31 Mar 2009 14:13:41 -0400</pubDate>
</item>

<item>
<title>Secure Design Patterns</title>
<link>http://www.cert.org/archive/pdf/09tr010.pdf</link>
<description>This technical report describes a set of secure design patters, which are descriptions or templates describing a general solution to a security problem that can be applied in many different situations.</description>
<pubDate>Mon, 30 Mar 2009 15:36:06 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Requiring secure coding practices when building or buying software can dramatically reduce vulnerabilities.</description>
<pubDate>Tue, 17 Mar 2009 10:44:00 -0400</pubDate>
</item>

<item>
<title>CERT Program Hosts Leaders in Security</title>
<link>http://www.sei.cmu.edu/about/press/releases/certtechsymposium1.html</link>
<description>On March 10, the CERT Program at Carnegie Mellon University's Software Engineering Institute began a two-day technical symposium for a select group of leaders in experts in the cyber security field.</description>
<pubDate>Wed, 11 Mar 2009 14:48:22 -0400</pubDate>
</item>

<item>
<title>2008 CERT Research Annual Report Published</title>
<link>http://www.cert.org/research/2008research-report.pdf</link>
<description>CERT is developing theoretical foundations and engineering methods to help ensure the security of critical systems and networks. This report describes progress in CERT research projects and opportunities for collaboration.</description>
<pubDate>Fri, 06 Mar 2009 15:20:06 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Making security strategic to business innovation involves seven strategies and calculating risk-reward based on risk appetite.</description>
<pubDate>Tue, 03 Mar 2009 10:40:51 -0500</pubDate>
</item>

<item>
<title>New Course Offering: Insider Threat Workshop</title>
<link>http://www.sei.cmu.edu/products/courses/p76.html</link>
<description>CERT's insider threat research serves as the foundation for this two-day workshop.</description>
<pubDate>Mon, 02 Mar 2009 15:04:56 -0500</pubDate>
</item>

<item>
<title>The CERT/CC and FIRST Announce Best Practices Contest 2009</title>
<link>http://www.first.org/global/practices/</link>
<description>For the second year in a row, the CERT/CC and FIRST are jointly hosting an international competition to honor best practices and advances in safeguarding the security of computer systems and networks.</description>
<pubDate>Wed, 25 Feb 2009 10:42:45 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Teams are better prepared to respond to incidents if realistic, hands-on training is part of their normal routine.</description>
<pubDate>Tue, 17 Feb 2009 11:17:20 -0500</pubDate>
</item>

<item>
<title>Richard Pethia Receives CSO Compass Award</title>
<link>http://www.sei.cmu.edu/about/press/releases/pethia.html</link>
<description>Richard D. Pethia, director of the Carnegie Mellon Software Engineering Institute (SEI) CERT Program has been named a recipient of the 2009 CSO Compass Award sponsored by CSO Magazine.</description>
<pubDate>Tue, 10 Feb 2009 08:28:32 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Standard, compliance, and process are more effective than risk management for ensuring an adequate level of information and software security.</description>
<pubDate>Tue, 03 Feb 2009 11:04:14 -0500</pubDate>
</item>

<item>
<title>Common Sense Guide to Prevention and Detection of Insider Threats, Version 3.1</title>
<link>http://www.cert.org/archive/pdf/CSG-V3.pdf</link>
<description>The third version of this guide includes new and updated practices based on an analysis of approximately 100 recent insider threat cases that occurred from 2003 to 2007 in the United States.</description>
<pubDate>Wed, 28 Jan 2009 09:10:16 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Rich Pethia reflects on CERTs 20-year history and discusses how he is positioning the program to tackle future IT and security challenges.</description>
<pubDate>Tue, 20 Jan 2009 10:48:51 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Being able to effectively respond to e-discovery requests depends on well-defined, enacted policies, procedures, and processes.</description>
<pubDate>Tue, 06 Jan 2009 11:31:58 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Climate change requires new strategies for dealing with traditional IT and information security risks.</description>
<pubDate>Tue, 09 Dec 2008 10:45:28 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Virtual training environments can deliver high quality content to security professionals on-demand, anywhere, anytime.</description>
<pubDate>Tue, 25 Nov 2008 15:05:40 -0500</pubDate>
</item>

<item>
<title>CERT Resiliency Engineering Framework (REF) Outline Published</title>
<link>http://www.cert.org/archive/pdf/REFv0.95R_outline.pdf</link>
<description>This document provides a brief overview of the CERT Resiliency Engineering Framework, including purpose statements, goals, and specific practices for each capability area.</description>
<pubDate>Thu, 13 Nov 2008 09:22:28 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Responding to an e-discovery request involves many of the same steps and roles as responding to a security incident.</description>
<pubDate>Tue, 11 Nov 2008 10:12:01 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>A sustainable security program is based on business-aligned strategy, policy, awareness, implementation, monitoring, and remediation.</description>
<pubDate>Tue, 28 Oct 2008 12:12:47 -0400</pubDate>
</item>

<item>
<title>The CERT C Secure Coding Standard Published</title>
<link>http://www.cert.org/secure-coding/index.html</link>
<description>This book is an essential desktop reference documenting the first official release of the CERT C Secure Coding Standard.</description>
<pubDate>Mon, 20 Oct 2008 11:21:40 -0400</pubDate>
</item>

<item>
<title>CERT Statistics Updated</title>
<link>http://www.cert.org/stats/</link>
<description>The CERT statistics have been updated with numbers from the third quarter of 2008.</description>
<pubDate>Fri, 17 Oct 2008 11:54:32 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>When considering whether to conduct business in online, virtual communities, business leaders need to evaluate risks and opportunities.</description>
<pubDate>Tue, 14 Oct 2008 11:04:29 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Integrating security into university curricula is one of the key solutions to developing more secure software.</description>
<pubDate>Tue, 30 Sep 2008 15:24:21 -0400</pubDate>
</item>

<item>
<title>Interactive Vulnerability Reporting Form Released</title>
<link>https://forms.cert.org/VulReport/</link>
<description>The interactive form enhances CERT's vulnerability analysis efforts by making it easier for vulnerability reporters to securely submit valuable information.</description>
<pubDate>Wed, 17 Sep 2008 15:23:06 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>OCTAVE Allegro provides a streamlined assessment method that focuses on risks to information used by critical business services.</description>
<pubDate>Tue, 16 Sep 2008 10:25:10 -0400</pubDate>
</item>

<item>
<title>Java Secure Coding Standard Released</title>
<link>https://www.securecoding.cert.org/confluence/display/java/CERT+Java+Secure+Coding+Standard</link>
<description>CERT has released the Java Secure Coding Standard in addition to existing secure coding standards for the C and C++ programming languages. CERT invites the Java community to participate in this effort by reviewing content in the Java space and providing comments.</description>
<pubDate>Mon, 08 Sep 2008 15:15:00 -0400</pubDate>
</item>

<item>
<title>New Technical Note Released</title>
<link>http://http://www.cert.org/archive/pdf/08tn017.pdf</link>
<description>Computer Forensics: Results of Live Response Inquiry vs. Memory Image Analysis presents a live response scenario and compares various approaches and tools used to capture and analyze evidence from computer memory.</description>
<pubDate>Tue, 02 Sep 2008 15:46:50 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Well-defined metrics are essential to determine which security practices are worth the investment.</description>
<pubDate>Tue, 02 Sep 2008 10:16:44 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Software security is accomplished by thinking like an attacker and integrating security practices into your software development lifecycle.</description>
<pubDate>Wed, 20 Aug 2008 09:55:06 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Protecting critical infrastructures and the information they use are essential for preserving our way of life.</description>
<pubDate>Tue, 05 Aug 2008 13:22:13 -0400</pubDate>
</item>

<item>
<title>CERT Statistics Updated</title>
<link>http://www.cert.org/stats/</link>
<description>The CERT statistics have been updated with numbers from the second quarter of 2008.</description>
<pubDate>Tue, 29 Jul 2008 15:11:11 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Determining which security vulnerabilities to address should be based on the importance of the information asset.</description>
<pubDate>Tue, 22 Jul 2008 11:39:55 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description></description>
<pubDate>Tue, 22 Jul 2008 11:35:23 -0400</pubDate>
</item>

<item>
<title>CERT Autoresponder Disabled</title>
<link>http://www.cert.org</link>
<description>Because of ongoing problems with the autoresponder messages being interpreted as spam, we have decided to discontinue providing an automatic acknowledgement of email sent to cert@cert.org. This change does not affect how we handle email sent to that address.</description>
<pubDate>Fri, 18 Jul 2008 11:22:39 -0400</pubDate>
</item>


<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>During requirements engineering, software engineers need to think deeply about (and document) how software should behave when under attack.</description>
<pubDate>Tue, 08 Jul 2008 10:54:21 -0400</pubDate>
</item>

<item>
<title>Winners of Best Practices Security Awards Announced</title>
<link>http://www.cert.org/csirts/national/contest_2008.html</link>
<description>The winning papers from the first international competition honoring best practices and advances in safeguarding the security of computer systems and networks have been posted.</description>
<pubDate>Fri, 27 Jun 2008 11:58:07 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Targeted, innovative communications and a robust life cycle are keys for security policy success.</description>
<pubDate>Tue, 24 Jun 2008 11:00:03 -0400</pubDate>
</item>

<item>
<title>Evaluation of CERT Secure Coding Rules through Integration with Source Code Analysis Tools Published</title>
<link>http://www.cert.org/archive/pdf/08tr014.pdf</link>
<description>This report describes a study conducted by the CERT Secure Coding Initiative and JPCERT to evaluate the efficacy of the CERT Secure Coding Standards and source code analysis tools in improving the quality and security of commercial software projects.</description>
<pubDate>Tue, 17 Jun 2008 11:35:48 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Managing software that is developed by an outside organization can be more challenging than building it yourself.</description>
<pubDate>Tue, 10 Jun 2008 11:19:16 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Software security is about building better, more defect-free software to reduce vulnerabilities that are targeted by attackers.</description>
<pubDate>Tue, 27 May 2008 11:52:08 -0400</pubDate>
</item>

<item>
<title>New CERT PGP Public Key</title>
<link>http://www.cert.org/contact_cert/encryptmail.html</link>
<description>CERT has updated its PGP public key. We strongly urge you to encrypt sensitive information.</description>
<pubDate>Fri, 23 May 2008 15:44:07 -0400</pubDate>
</item>

<item>
<title>Making the Business Case for Software Assurance</title>
<link>http://www.sei.cmu.edu/community/assurance.html</link>
<description>This one-day workshop will explore methods for capturing development costs and benefits associated with software assurance and making the case to executive management. A call for papers has been posted; registration information will soon be available.</description>
<pubDate>Thu, 15 May 2008 13:35:04 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>High performing organizations effectively integrate information security controls into mainstream IT operational processes.</description>
<pubDate>Tue, 13 May 2008 11:07:30 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Helping your staff learn how to identify social engineering attempts is the first step in thwarting them.</description>
<pubDate>Tue, 29 Apr 2008 14:37:46 -0400</pubDate>
</item>

<item>
<title>Vulnerability Analysis Blog Published</title>
<link>http://www.cert.org/blogs/vuls/</link>
<description>In a new blog on the CERT website, CERT staff members will address various issues related to vulnerability analysis.</description>
<pubDate>Fri, 18 Apr 2008 12:41:55 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Benchmark results can be used to compare with peers, drive performance, and help determine how much security is enough.</description>
<pubDate>Tue, 15 Apr 2008 12:49:22 -0400</pubDate>
</item>

<item>
<title>CERT Statistics Updated</title>
<link>http://www.cert.org/stats/</link>
<description>The CERT statistics have been updated with numbers from the first quarter of 2008.</description>
<pubDate>Mon, 14 Apr 2008 12:26:34 -0400</pubDate>
</item>

<item> <title>CERT Authors Publish Book About Building Security into Software Products</title> 
<link>http://www.sei.cmu.edu/publications/books/cert/software-security-engineering.html</link> <description>Software Security 
Engineering: A Guide for Project Managers will be published by Addison-Wesley in early May 2008. The book shows project managers how to build 
security into their software products throughout the development life cycle.</description> <pubDate>Tue, 01 Apr 2008 15:12:28 -0400</pubDate> </item>

<item>
<title>Reminder: Entries for Security Awards Due April 30</title>
<link>http://www.first.org/conference/2008/contest.html</link>
<description>Submissions for the first international competition honoring best practices and advances in safeguarding the security of computer systems and networks are due by April 30. The contest is being hosted by FIRST and the CERT/CC.</description>
<pubDate>Tue, 01 Apr 2008 14:08:07 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Aligning with business objectives, integrating with enterprise risks, and collaborating with stakeholders are key to ensuring information privacy.</description>
<pubDate>Tue, 01 Apr 2008 12:43:36 -0400</pubDate>
</item>

<item>
<title>Incident Management Mission Diagnostic Method, Version 1.0 Published</title>
<link>http://www.cert.org/archive/pdf/08tr007.pdf</link>
<description>This report presents a risk-based approach for determining the potential for success of an organization's incident management capability.</description>
<pubDate>Mon, 31 Mar 2008 11:29:16 -0400</pubDate>
</item>

<item>
<title>CERT Sponsors FIRST Conference</title>
<link>http://www.first.org/conference/2008/</link>
<description>CERT is a sponsor for the 2008 FIRST Conference, which will be held in Canada in June. This year marks the 20th annual FIRST conference as well as the 20th anniversary of CERT.</description>
<pubDate>Fri, 28 Mar 2008 11:59:12 -0400</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>A sound security metrics program is grounded in selecting data that is relevant to consumers and collecting it from repeatable processes.</description>
<pubDate>Tue, 18 Mar 2008 09:58:37 -0400</pubDate>
</item>

<item>
<title>CERT Resiliency Engineering Framework, v0.95R Available</title>
<link>http://www.cert.org/resiliency_engineering/framework.html</link>
<description>A draft version of the CERT Resiliency Engineering Framework is now available.  We welcome and encourage your feedback on these materials.</description>
<pubDate>Mon, 17 Mar 2008 10:58:45 -0400</pubDate>
</item>

<item>
<title>2007 CERT Research Annual Report Published</title>
<link>http://www.cert.org/research/2007research-report.pdf</link>
<description>CERT is developing theoretical foundations and engineering methods to help ensure the security of critical systems and networks. This report describes progress in CERT research projects and opportunities for collaboration.</description>
<pubDate>Thu, 06 Mar 2008 10:36:25 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Significant insider threat vulnerabilities can be introduced (and mitigated) during all phases of the software development life cycle.</description>
<pubDate>Tue, 04 Mar 2008 10:27:36 -0500</pubDate>
</item>

<item>
<title>FIRST and Carnegie Mellon Software Enginnering Institute CERT Coordination Center Unveil New Security Awards</title>
<link>http://www.first.org/conference/2008/contest.html</link>
<description>The first-ever international competition honoring best practices and advances in safeguarding the security of computer systems and 
networks is announced today by the Forum of Incident Response and Security Teams (FIRST) and Carnegie Software Engineering Institute (SEI) CERT Coordination Center (CERT/CC).</description>
<pubDate>Tue, 26 Feb 2008 09:12:17 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Business leaders need to understand the risks to their organizations caused by the proliferation of botnets.</description>
<pubDate>Tue, 19 Feb 2008 11:20:14 -0500</pubDate>
</item>

<item>
<title>CERT to Participate in Second Annual Counter eCrime Operations Summit</title>
<link>http://www.antiphishing.org/events/2008_operationsSummit.html</link>
<description>CERT will be participating in the Counter eCrime Operations Summit II May 26-27 Tokyo, Japan.</description>
<pubDate>Thu, 14 Feb 2008 11:30:38 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Selecting and reporting meaningful security metrics depend on picking topics of great interest, defining the business context, and having access to sound data.</description>
<pubDate>Tue, 05 Feb 2008 10:47:48 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Selecting and reporting meaningful security metrics depend on picking topics of great interest, defining the business context, and having access to sound data.</description>
<pubDate>Tue, 05 Feb 2008 10:38:57 -0500</pubDate>
</item>

<item>
<title>SQUARE Instructional Materials Released</title>
<link>http://www.cert.org/sse/square/square-description.html</link>
<description>Workshop, tutorial, and academic educational materials on SQUARE (Security Quality Requirements Engineering) are now available for download.</description>
<pubDate>Tue, 22 Jan 2008 10:54:03 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Peer-to-peer networks are being used today to unintentionally disclose government, commercial, and personal information.</description>
<pubDate>Tue, 22 Jan 2008 10:20:34 -0500</pubDate>
</item>

<item>
<title>CERT Statistics Updated</title>
<link>http://www.cert.org/stats/</link>
<description>The numbers from the fourth quarter have been incorporated, completing the 2007 statistics.</description>
<pubDate>Tue, 15 Jan 2008 16:29:00 -0500</pubDate>
</item>

<item>
<title>Insider Threat Studies Released</title>
<link>http://www.cert.org/insider_threat/</link>
<description>Insider Threat Study: Illicit Cyber Activity in the Government Sector and Insider Threat Study: Illicit Cyber Activity in the Information Technology and Telecommunications Sector have been released. These reports present the findings of research efforts to examine reported insider incidents within their respective sectors.</description>
<pubDate>Wed, 09 Jan 2008 08:54:15 -0500</pubDate>
</item>

<item>
<title>New Podcast Released</title>
<link>http://www.cert.org/podcast/</link>
<description>Directors and senior executives are personally accountable for protecting information entrusted to their care.</description>
<pubDate>Tue, 08 Jan 2008 10:24:08 -0500</pubDate>
</item>

</channel>
</rss>

