<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title>Dyman &amp; Associates Risk Management Projects by Grien Lee</title>
      <link>https://padlet.com/grienlee/fyzjcn4ndn</link>
      <description>Dyman &amp; Associates Risk Management Projects utilizes its decades-old track record in cyber security to provide protection for your employees, intellectual property, and other precious assets. Our consultants not only have many years of experience, but are also dedicated to the regular honing of their skills and keeping current on the innovations in hacking techniques and security trends.</description>
      <language>en-us</language>
      <pubDate>2013-11-29 04:45:45 UTC</pubDate>
      <lastBuildDate>2014-02-19 05:54:15 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url></url>
      </image>
      <item>
         <title>Dyman &amp; Associates Risk Management Projects</title>
         <author>grienlee</author>
         <link>https://padlet.com/grienlee/fyzjcn4ndn/wish/17533196</link>
         <description><![CDATA[<p>





<p><b><a href="http://dymanassociatesprojects.org/"><span>Source</span></a>
<br></b></p>



<p><a href="http://dymanassociatesprojects.org/">Dyman
&amp; Associates</a> Risk Management Projects is a Risk Management
firm whose main office is based in Boston, MA. We operate in the following
fields: Cyber Security, Project Management, Emergency Management, Technology
Governance, and Physical Security. Our company is a minority-owned enterprise
with both MBE &amp; DBE certifications.</p>
<p>Quite often, organizations muddle through crises in
isolation, undertaking prime decisions within a vacuum. Dyman &amp; Associates
Risk Management Projects has the collective know-how to minimize your exposure
to risk and help make your business become more resilient. We will work
diligently for your benefit. We believe that honesty, reliability, and
excellent customer service serve as the foundation for lasting relationships.
Moreover, we supply empathy, humility, and a promise to give back to our
community.</p>
<p><b>Cyber
Security</b></p>



<p>The increase of incidents of cyber-attacks against
businesses and government agencies in the United States continues. FBI Director
Robert Mueller revealed that, "Terrorism is still FBI's top priority. But
very soon, we expect that the cyber threat will replace terrorism as the number
one threat to national security".</p>
<p><a href="http://dymanassociatesprojects.org/blog">Dyman
&amp; Associates Risk Management Projects</a> utilizes its decades-old track
record in cyber security to provide protection for your employees, intellectual
property, and other precious assets. Our consultants not only have many years
of experience, but are also dedicated to the regular honing of their skills and
keeping current on the innovations in hacking techniques and security trends.</p>
<p><b>Our
services include:</b></p>

<p>·<span>&nbsp;
</span>Cloud Security</p>

<p>·<span>&nbsp;
</span>Mobile Security</p>

<p>·<span>&nbsp;
</span>Incident Response</p>

<p>·<span>&nbsp;
</span>Computer Forensics</p>

<p>·<span>&nbsp;
</span>Electronic Discovery</p>

<p>·<span>&nbsp;
</span>Penetration Testing</p>
</p>]]></description>
         <enclosure url="" />
         <pubDate>2013-11-29 04:46:33 UTC</pubDate>
         <guid>https://padlet.com/grienlee/fyzjcn4ndn/wish/17533196</guid>
      </item>
      <item>
         <title>Program Teaches Cybersecurity Students How to Think
like Hackers, Dyman &amp;amp; Associates Risk Management Projects</title>
         <author>grienlee</author>
         <link>https://padlet.com/grienlee/fyzjcn4ndn/wish/19671390</link>
         <description><![CDATA[<p><b>RICK KARR:</b> The bad guys stole more than three million Social Security numbers from the State of South
Carolina. As many as seventy million credit card numbers from Sony <a href="http://dymanassociatesprojects.com/blog/">PlayStation</a>. They got
access to all of the personal details of some customers of a nationwide
mortgage lending firm. But cybercriminals aren’t just looking to steal personal
information and credit card numbers when they break into corporate computers --
they’re looking for other valuable information.</p>
<p><b>STEWART BAKER:</b> Everything about your business is accessible to an attacker.</p>
<p><b>RICK KARR:</b>&nbsp; Stuart Baker is former general counsel of the
NSA who’s now a computer security consultant.</p>
<p><b>STEWART BAKER:</b> They can steal your designs. They can steal your-- knowhow.&nbsp;
They can steal your customer list and your internal analysis of what the
biggest problems are in your product. This is pretty scary.</p>
<p><b>RICK KARR:</b> The bad guys are mostly working from China and former Soviet states. They’re well-trained.
Some of them are protected by -- or even working for -- their governments, so
they don’t care about getting caught. And they might be able to do even more
that steal information from businesses. Security experts worry that they could
cripple the banking system ... or shut down parts of the electric grid. Baker
says ... American businesses need a new mindset if they’re going to defend
themselves.</p>
<p><b>STEWART BAKER:</b> I'm a big believer that-- the best defense is an offense.&nbsp;
And-- if we're going to have an offense-- we've got to have people who
are really talented drawn to that field.</p>
<p><b>RICK KARR:</b> People like these college undergraduates, who just might be able to save America’s
corporations and governments from the bad-guy hackers: They’re students at
Carnegie Mellon University, one of the nation’s top computer science schools
... and they’re learning to fight off the bad guys&nbsp; ... by thinking the same way they do. They’re
learning to be the good guy hackers.</p>
<p><b>DAVID BRUMLEY:</b> You have to understand and be able to anticipate how attackers are going to come at
you.&nbsp; 'Cause if you're only doing
defense, if you don't look at offense at all, you're always reacting and you're
always one step behind.</p>
<p><b>RICK KARR</b>: Is that different?&nbsp; Is that a change in the way
computer science faculties have approached this?</p>
<p><b>DAVID BRUMLEY:</b> Traditionally,
yeah.&nbsp; Traditionally, there hasn't been a
lot of expertise in offensive computer security.&nbsp; And it really hasn't been taught at the
university level.</p>
<p><b>RICK KARR:</b> Computer security professor David Brumley says ... its tough stuff to teach ... because
the brand-new, cutting-edge <a href="http://dymanassociatesprojects.com/">cyber-attack</a>
of today will be available to anyone with a web browser by next week.</p>
<p><b>DAVID BRUMLEY:</b> For example, my courses in computer security?&nbsp; We don't
have textbooks.&nbsp; Everything's so new.&nbsp; We have to go out and look at
websites, we have to go look at-- the latest things from conferences, and
really teach from that.&nbsp; Every year it's
a significant update.</p>
<p><b>RICK KARR:</b> Is it ever the case that you actually have a student discovers something that nobody knew
about, in the middle of a semester?</p>
<p><b>DAVID BRUMLEY:</b> Oh, that's actually a course requirement.&nbsp; One of
the things we ask students to do is go out and find a vulnerability that no one
else has found, figure out if it's exploitable, and then report it ethically.</p>
<p><b>RICK KARR:</b> Which means what?</p>
<p><b>DAVID BRUMLEY:</b> It really means they're going and finding something they could use to break into someone's
computer.&nbsp; And then they go tell the programmer, look, here is a flaw; fix it.</p>
<p><b>RICK KARR: All</b> those flaw that
Carnegie Mellon’s undergrads find every semester ... don’t necessarily mean
that the software on your P-C or your bank’s web site is badly written. Almost
every piece of software, every computer system has vulnerabilities that can be
exploited -- it’s virtually impossible to make anything that’s connected to the
internet perfectly secure. And today -- compared to 10 or 20 years ago, all of
us have just so many more computers and smartphones and tablets -- all of them
connected and vulnerable. So we’re vulnerable, too.</p>
<p>Carnegie
Mellon’s students are so good at exploiting those vulnerabilities ... that the
NSA enlisted them to create a game that teaches hacking skills to
high-school-aged students -- and paid for the job. Cylab, the university’s
cybersecurity institute, is home to the to-ranked competitive hacking team in
the world: the Plaid Parliament of Pawning -- “pwn” is hacker-speak for “own”,
as in the hacker takes a computer over and owns it. For third straight year,
the team won top honors at international contests that pit teams of hackers
against one another ... and utterly demolished the competition at a prestigious
contest in Las Vegas.</p>
<p><b>DAVID BRUMLEY:</b> It's a little bit like a little, mini-cyber-war that's going on.&nbsp; And you get points by how well you find
exploits in your adversaries and how well you can defend against their attacks.&nbsp; They're-- secure from the
normal internet and they're set up specifically for this purpose.</p>
<p><b>RICK KARR:</b>&nbsp; How stiff is the competition here?&nbsp; I mean, who's on your heels in terms of the
top ten rankings.</p>
<p><b>MALE STUDENT #3:</b> Man, so, you know who's not?&nbsp; There's all sorts of
government contractors who have, you know, teams that we compete with.&nbsp; And, you know, they do this professionally.&nbsp; </p>
<p><b>RICK KARR:</b>&nbsp; “Hacker” is a label the students embrace. The
word has a long history in computer science circles -- where it was originally
meant as praise. The students say ... it still can be.</p>
<p><b>MALE STUDENT #2:</b> We don't think
of it as bad.&nbsp; We think of it as--
getting a deeper understanding for how something works in order to make it do
something that maybe it wasn't intended to do but it's capable of doing.</p>
<p><b>ANDREW CONTE:</b>&nbsp; It's often the people who as young high
school students they started goofing' around with-- electronics or computers,
and they started figuring out, you know, how to do simple attacks, how to get
inside of-- machines.</p>
<p><b>RICK KARR:</b> Andrew Conte is
an investigative reporter at the Pittsburgh Tribune-Review who’s written dozens
of articles about hackers and cybersecurity.</p>
<p><b>ANDREW CONTE:</b> And at some
point they make the decision.&nbsp; You know,
"Am I going to be-- a good hacker or a bad hacker? And there's not that
much difference between them in terms of-- their abilities.&nbsp; Huge difference in terms of their
motivations.</p>
<p><b>RICK KARR:</b> That raises the
question of how wise it is to teach these abilities to students barely out of
their teens ... with unknown motivations. Cylab graduate student Peter Chapman
says not to worry.</p>
<p><b>RICK KARR:</b> If you're
figuring out how to attack things, isn't it possible that somebody who comes
outta here isn't going to do it for the right reasons? </p>
<p><b>PETER CHAPMAN:</b> If that
person's motivated, they can certainly find it out on their own.&nbsp; This isn't hidden information. Someone who's
determined to break into a system, they can take normal courses and just add
this, "How am I going to ruin the world mindset" to it.&nbsp; It's the same way a locksmith who knows how
to fix locks can probably also break into them. </p>
<p><b>RICK KARR:</b>&nbsp; <a href="http://www.pbs.org/newshour/bb/science/jan-june14/cylab_01-19.html">Cybersecurity</a> consultant Stewart Baker says ... sometimes it makes sense for a company that’s
been the target of bad-guy hackers to engage in a little digital breaking and
entering of its own -- to hack back, in other words. He thinks it could be an
important weapon in the cybersecurity arsenal. But it isn’t always so clear-cut
ethically. Or legally, because in can violate federal computer security laws.</p>
<p><b>STEWART BAKER:</b> I have been making a very public-- argument that we should allow this and we should read
the Computer Fraud and Abuse Act to permit it.</p>
<p><b>RICK KARR:</b> What if the machine in question is outside the U.S.?&nbsp; I mean, is that still a violation of the act?</p>
<p><b>STEWART BAKER:</b> Unfortunately, it is.</p>
<p><b>RICK KARR:</b>&nbsp; Baker says good-guy hackers who have “hacked back” have learned that cybercriminals aren’t always as clever as they seem to
be. Take the example of a hacker who broke into law-enforcement computers, copied personal information about officers ... and posted it online. He also
left a ... provocative ... picture of his girlfriend as a calling card, which turned out to be a mistake.</p>
<p><b>STEWART BAKER:</b> They took the picture with an iPhone.&nbsp; And that meant that somebody had helpfully included the-- geographic coordinates where the
picture was taken.&nbsp; So the F.B.I. finds the girlfriend of the hacker, and went and busted the guy in Texas.&nbsp; So these digital clues are everywhere.</p>
<p><b>RICK KARR:</b>&nbsp; The hacker pleaded guilty to accessing a protected computer without authorization; and received a sentence of twenty
seven months in prison. Stewart Baker says ... that’s the kind of outcome he’d
like to see from good-guy hackers, like the students at Carnegie Mellon.</p>]]></description>
         <enclosure url="" />
         <pubDate>2014-01-22 04:59:36 UTC</pubDate>
         <guid>https://padlet.com/grienlee/fyzjcn4ndn/wish/19671390</guid>
      </item>
      <item>
         <title>Dyman &amp;amp; Associates Risk Management Projects: Why Businesses Can’t Ignore US Cybersecurity Framework</title>
         <author>grienlee</author>
         <link>https://padlet.com/grienlee/fyzjcn4ndn/wish/21569527</link>
         <description><![CDATA[]]></description>
         <enclosure url="" />
         <pubDate>2014-02-19 05:53:59 UTC</pubDate>
         <guid>https://padlet.com/grienlee/fyzjcn4ndn/wish/21569527</guid>
      </item>
      <item>
         <title>Dyman &amp;amp; Associates Risk Management Projects: Why Businesses Can’t Ignore US Cybersecurity Framework</title>
         <author>grienlee</author>
         <link>https://padlet.com/grienlee/fyzjcn4ndn/wish/21569538</link>
         <description><![CDATA[<p>
<p>Industry leaders and President Obama call the framework just a first step in creating a <a href="http://dymanassociatesprojects.com/blog/">cybersecurity</a>
playbook for 16 US critical infrastructure sectors. But this is more than just a reference manual.</p>
<p>The Obama administration's new voluntary <a href="https://www.facebook.com/dyamanassociatesproject">Cybersecurity</a> Framework for critical infrastructure providers, announced Feb. 12, won't please everyone. But it does bring together for the first time a useful set of
federally endorsed practices for private <a href="https://twitter.com/dymanassociates">sector security</a>. It also represents a welcome reprieve from the frosty government-industry relationship on matters of cybersecurity preparedness.</p>
<p>Industry leaders as well as President Obama were quick to acknowledge that the framework is just a first step in creating a <a href="http://www.scribd.com/dyman_associates_projects">cybersecurity</a> playbook for the nation's 16 critical infrastructure sectors, including
financial services, communications, and energy providers. It establishes an important precedent not only by defining common security standards, but also by offering carrots to the private sector rather than wielding a regulatory stick.The framework also serves notice to a gridlocked Congress that the White House can give traction to issues of national importance.</p>
<p>First, the framework has cred, as its recommendations come not from Washington regulators, but from industry experts who've combatted <a href="http://dymanassociatesprojects.tumblr.com/">cyberattacks</a>. In pulling together the framework, the National Institute of Standards and <a href="https://foursquare.com/v/dyman--associates-projects/528dbcab498eeba21a51bf91">Technology</a> went to great lengths to collect, distill, and incorporate feedback from security professionals. More than 3,000 individuals and organizations contributed to the framework.</p>
<p>Learn more about the <a href="https://plus.google.com/b/103237330230122996179/103237330230122996179/about">Cybersecurity</a> Framework.</p>
<p>The <a href="http://dymanassociates.livejournal.com/">cybersecurity</a> framework doesn't tell companies what to do or what tools to buy. But it does
standardize the questions all CEOs should ask about their companies' security practices as well as those of their suppliers, partners, and customers. And it shows them what the answers ought to look like. The economic pain hackers caused to Target and its CEO, Gregg W. Steinhafel, may be incentive enough for other CEOs to adopt NIST's recommendations.</p>
<p>A third and even more powerful factor is the likelihood that even without legislation, the framework will become the de facto standard for private sector cybersecurity in the eyes of US lawyers and regulators. That's the view of Gerald Ferguson, who specializes in intellectual property and <a href="http://www.linkedin.com/groups/Dyman-Associates-Projects-7415482">technology</a> issues for law firm BakerHostetler, as expressed in a recent opinion column he wrote fo InformationWeek.</p><p>

<p>Fourth, the <a href="http://dymanassociates.blogspot.nl/">cybersecurity</a> framework isn't just another set of NIST guidelines, but the outcome of President Obama's Executive Order on "Improving Critical Infrastructure <a href="http://www.pinterest.com/valerioanema/dyman-associates-projects/">Cybersecurity</a>," which he announced in his 2013 State of the Union address.</p>
<p>"Cyber threats pose one of the gravest national security dangers that the United States faces," the president said earlier this week, a point reinforced in a new Defense News poll that found that nearly half of national security leaders think cyber warfare is bigger threat to the US than terrorism.</p>
<p>But not everyone thinks the president's cybersecurity framework provides the right set of standards or adequately addresses how to make networks resilient against inevitable attacks.</p>
<p>Gerald Cauley, CEO of the North American Electric Reliability Corp., which develops reliability standards for power companies,
argues that NIST's framework could undermine existing -- and in some cases more
advanced -- cybersecurity practices already in effect.</p>

<br></p>

</p>]]></description>
         <enclosure url="" />
         <pubDate>2014-02-19 05:54:33 UTC</pubDate>
         <guid>https://padlet.com/grienlee/fyzjcn4ndn/wish/21569538</guid>
      </item>
      <item>
         <title>Dyman &amp;amp; Associates Risk Management Projects on
Data privacy shapes up as a next-generation trade barrier</title>
         <author>grienlee</author>
         <link>https://padlet.com/grienlee/fyzjcn4ndn/wish/25022607</link>
         <description><![CDATA[<p>

<p>Revelations
about U.S. digital eavesdropping have fanned concerns about Internet privacy
and may complicate U.S. attempts to write rules enshrining the free flow of
data into trade pacts with European and Pacific trading partners. </p>
<p>As
more and more consumers and businesses shop and sign up for services online,
the <b><a href="http://bluesky.chicagotribune.com/chi-data-privacy-trade-barrier-bsi-news,0,0.story">IT
industry</a></b> is working to fend off rising digital protectionism it sees as
threatening an e-commerce marketplace estimated at up to $8 trillion a year.</p>
<p>"Restrictions
on information flows are trade barriers,"Google'sexecutive
chairman,Eric
Schmidt, said at a Cato Institute event last month, warning that the worst
possible outcome would be for the Internet to turn into "<b><a href="http://dymanassociatesprojects.com/">Splinternet</a></b>."</p>
<p>The
unease of U.S. technology companies has mounted in lockstep with rising worries
overseas about data privacy.</p>
<p>German
ChancellorAngela
Merkel—
a target of U.S. spying — has called for a European Internet protected from
Washington's snooping. Brazil and theEuropean Unionplan
to lay their own undersea communications cable to reduce reliance on the United
States. And other countries are showing a preference for storing data on local
servers rather than in the United States.</p>

<p>PresidentBarack
Obamaacknowledged
this week that it would take time to win back the trust of even friendly
governments.</p>
<p>Trade
experts predict the United States will have to make concessions on data privacy
in the Transatlantic Trade and Investment Partnership talks (<b><a href="http://dymanassociatesprojects.com/cyber.html">TTIP</a></b>) with the EU,
and will probably not get all it wants in Pacific Rim trade talks either.</p>
<p>"It
is unfortunate because there were some good nuanced conversations happening
before the spying allegations," said Adam Schlosser, director of the
Center for Global Regulatory Cooperation at theU.S.
Chamber of Commerce.</p>
<p>"But
there is now a tendency to inappropriately conflate national security and law
enforcement with ... commercial privacy practices, which has put a damper on
rational debate."</p>

<p>The
TTIP and the Trans-Pacific Partnership (TPP) talks are billed as
next-generation trade negotiations, covering not only tariffs and goods trade
but also common standards and goals in areas ranging from labor standards and
environmental protection to intellectual property and data flows.</p>
<p>The
last two issues are key for digital trade, which encompasses everything from
U.S. cherry farmers selling direct to Chinese families via Alibaba Group
Holdings' Tmall electronic shopping platform to plane makerBoeingmonitoring
in-flight diagnostic data on-line.</p>
<p><b><a href="http://acworth.patch.com/groups/business-updates/p/dyman--associates-risk-management-projects-safety-products-webbased-driver-risk-management">$8
TRILLION QUESTION</a></b></p>



<p>A
2011 report by the McKinsey Global Institute found almost $8 trillion changed
hands each year through e-commerce, something that explains the keen interest
IT firms and industry associations are taking in the trade agreements.</p>
<p>According
to data compiled by the Sunlight Foundation, the computing and IT industry has
been the second-biggest lobbyist on the TPP, after the pharmaceutical industry.</p>

<p>Industry
groups such as the Software &amp; Information Industry Association say free
exchange of data is the key focus.</p>
<p>"For
SIIA and its members, the most crucial issue in the trade agreements under
negotiation is to get provisions permitting cross-border data flows," said
Carl Schonander, international public policy director at SIIA, whose members
include Reuters News parentThomson Reuters.</p>

<p>BSA
the Software Alliance, an advocacy group for the software industry has warned
that TPP partners Australia, Canada, Chile, Mexico, Peru and Vietnam are among
countries adopting or proposing rules banning or limiting companies from
transferring personal information off-shore. This might mean U.S. companies
have to set up local servers in every country.</p>
<p>"Data
flows are the lifeblood of the digital economy," said BSA policy director
David Ohrenstein. "Trade agreements (must) ensure borders are open to data
flows."</p>
<p><b><a href="http://www.dailymotion.com/video/x1cdisv_dyman-associates-risk-management-projects-targets-cyber-security-staff-raised-concerns-in-months-bef_tech">CONCESSIONS
EYED</a></b></p>



<p>In
an ideal world for IT companies, countries signing the TPP would promise not to
impede cross-border data flows or make companies set up local servers.</p>
<p>U.S-based
lobbyists expect those provisions to make it in, possibly with exceptions, but
say work is still needed to convince trading partners to promise that any new
regulations - including on privacy - will not restrict trade unnecessarily.</p>
<p>In
Europe, where the backlash against U.S. spying has been the strongest,
policymakers want changes by mid-2014 to the Safe Harbor Agreement, which
allows U.S. companies with European-level privacy standards access to European
data.</p>
<p>An
opinion poll by the Atlantic Council and the Bertelsmann Foundation found rules
governing cross border data flows and the alignment of privacy protections were
among the most contentious and important, issues in the U.S.-Europe talks.</p>
<p>Atlantic
Council Vice President Fran Burwell said it would be hard to get support from
theEuropean Parliamentor countries like Germany without an agreement on
data protection.</p>
<p>"I
think the big concession that (the U.S.) will have to make will be in the data
privacy area," she said.</p>

<p>Tension
is also brewing over intellectual property. U.S. music, book and software
companies see piracy of copyright material as the biggest threat to their
exports, while companies like Google worry about being held responsible for the
actions of clients on their networks.</p>
<p>Data
privacy group Electronic Frontier Foundation said proposals in draft TPP
chapters would restrict flexibility in allowing fair use of copyright materials
and encourage low-quality software patents by setting the bar too low.</p>
<p>A
group of 29 smaller tech companies wrote toU.S. Senate Finance CommitteeChairmanRon
Wydenlast
week and warned against including harsher criminal penalties for minor
copyright infringements in the TPP. The committee has jurisdiction over trade
issues in theU.S.
Congress.</p>
<p>"Reddit
is a platform the same way that the telephone is a platform," said Erik
Martin, general manager of on-line news hub Reddit, one of the signatories to
the letter.</p>
<p>"To
put so much burden on the providers to deal with problems from individual users
is just really going to put a chill on investment and put a chill on
innovation."</p>
</p>]]></description>
         <enclosure url="" />
         <pubDate>2014-04-02 02:26:47 UTC</pubDate>
         <guid>https://padlet.com/grienlee/fyzjcn4ndn/wish/25022607</guid>
      </item>
   </channel>
</rss>
