<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Keep an eye on the moon - NASA fails security inspection in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Keep-an-eye-on-the-moon-NASA-fails-security-inspection/m-p/20265#M2404</link>
    <description>&lt;P&gt;I suspect the mentality is "we are a research organisation we don't have to play by the rules" and it permeates from the top clear down to the maintenance staff.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe their funding should be stopped until they get a&amp;nbsp;&lt;A href="https://www.infosecurity-magazine.com/news/nasas-poor-cybersecurity-1-1-1/" target="_blank" rel="noopener"&gt;passing&lt;/A&gt;&amp;nbsp;grade!?!?&lt;/P&gt;</description>
    <pubDate>Tue, 19 Mar 2019 18:29:51 GMT</pubDate>
    <dc:creator>Flyslinger2</dc:creator>
    <dc:date>2019-03-19T18:29:51Z</dc:date>
    <item>
      <title>Keep an eye on the moon - NASA fails security inspection</title>
      <link>https://community.isc2.org/t5/Industry-News/Keep-an-eye-on-the-moon-NASA-fails-security-inspection/m-p/20265#M2404</link>
      <description>&lt;P&gt;I suspect the mentality is "we are a research organisation we don't have to play by the rules" and it permeates from the top clear down to the maintenance staff.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe their funding should be stopped until they get a&amp;nbsp;&lt;A href="https://www.infosecurity-magazine.com/news/nasas-poor-cybersecurity-1-1-1/" target="_blank" rel="noopener"&gt;passing&lt;/A&gt;&amp;nbsp;grade!?!?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 18:29:51 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Keep-an-eye-on-the-moon-NASA-fails-security-inspection/m-p/20265#M2404</guid>
      <dc:creator>Flyslinger2</dc:creator>
      <dc:date>2019-03-19T18:29:51Z</dc:date>
    </item>
    <item>
      <title>Re: Keep an eye on the moon - NASA fails security inspection</title>
      <link>https://community.isc2.org/t5/Industry-News/Keep-an-eye-on-the-moon-NASA-fails-security-inspection/m-p/20266#M2405</link>
      <description>&lt;P&gt;clearly NASA is 'over the moon' about information security -- lol&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 19:36:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Keep-an-eye-on-the-moon-NASA-fails-security-inspection/m-p/20266#M2405</guid>
      <dc:creator>Cousy14</dc:creator>
      <dc:date>2019-03-19T19:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: Keep an eye on the moon - NASA fails security inspection</title>
      <link>https://community.isc2.org/t5/Industry-News/Keep-an-eye-on-the-moon-NASA-fails-security-inspection/m-p/20268#M2406</link>
      <description>&lt;P&gt;Yeah, well, similar attitude I saw when I worked with engineers and developers at a major multi-national.&amp;nbsp; They all thought as they were "technical" people that a) they should get admin access to their systems and b) they were creative people and security just got in their way of doing their job.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I work with clients in other industries, I see the same thing.&amp;nbsp; In medical field, security "gets in the way" of doing whatever job they are doing, being creative, etc.&amp;nbsp; Or security is "IT's responsibility", not theirs...&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 21:20:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Keep-an-eye-on-the-moon-NASA-fails-security-inspection/m-p/20268#M2406</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2019-03-19T21:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: Keep an eye on the moon - NASA fails security inspection</title>
      <link>https://community.isc2.org/t5/Industry-News/Keep-an-eye-on-the-moon-NASA-fails-security-inspection/m-p/20278#M2407</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1590936133"&gt;@emb021&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Yeah, well, similar attitude I saw when I worked with engineers and developers at a major multi-national.&amp;nbsp; They all thought as they were "technical" people that a) they should get admin access to their systems and b) they were creative people and security just got in their way of doing their job.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I work with clients in other industries, I see the same thing.&amp;nbsp; In medical field, security "gets in the way" of doing whatever job they are doing, being creative, etc.&amp;nbsp; Or security is "IT's responsibility", not theirs...&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;My current customer is a DoD research group and same thing applies. Thankfully they were commanded to make IA happen so now they are dragging their feet and kicking pebbles trying to obstruct but at least it is moving forward.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 11:37:33 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Keep-an-eye-on-the-moon-NASA-fails-security-inspection/m-p/20278#M2407</guid>
      <dc:creator>Flyslinger2</dc:creator>
      <dc:date>2019-03-20T11:37:33Z</dc:date>
    </item>
    <item>
      <title>Re: Keep an eye on the moon - NASA fails security inspection</title>
      <link>https://community.isc2.org/t5/Industry-News/Keep-an-eye-on-the-moon-NASA-fails-security-inspection/m-p/20290#M2410</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1590936133"&gt;@emb021&lt;/a&gt;&amp;nbsp;wrote:&lt;P&gt;When I work with clients in other industries, I see the same thing.&amp;nbsp; In medical field, security "gets in the way" of doing whatever job they are doing, being creative, etc.&amp;nbsp; Or security is "IT's responsibility", not theirs...&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Yes, very much a prevalent hurdle we security folks face. I've come to the conclusion/approach that more than anything this indicates how security/quality was not integrated from the beginning. It can help deflect the issue from "the problem is you" to "Hey, I need your help in fixing something that has been screwed up from the start." Organizationally, we should be integrating quality (I look at security as a function of quality) from the beginning in any process or&amp;nbsp;role. Instead, we often sacrifice quality in order to capture market share. That's the tendency today - nearly every business model demands a certain scale to succeed. We no longer have the "start small, do it right, and build from there" model. The early days of NASA were all about working the problem (and even then we had some notable failures) but today, too many engineers, of any sort have been raised on the attitude of "we'll fix that with 2.0" Ask Boeing how that's going ....&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 18:01:20 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Keep-an-eye-on-the-moon-NASA-fails-security-inspection/m-p/20290#M2410</guid>
      <dc:creator>JoePete</dc:creator>
      <dc:date>2019-03-20T18:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: Keep an eye on the moon - NASA fails security inspection</title>
      <link>https://community.isc2.org/t5/Industry-News/Keep-an-eye-on-the-moon-NASA-fails-security-inspection/m-p/20303#M2412</link>
      <description>&amp;gt; Flyslinger2 (Community Champion) posted a new topic in Industry News on&lt;BR /&gt;&lt;BR /&gt;&amp;gt; I suspect the mentality is "we are a research organisation we don't have to play&lt;BR /&gt;&amp;gt; by the rules" and it permeates from the top clear down to the maintenance&lt;BR /&gt;&amp;gt; staff.&amp;nbsp;&amp;nbsp; &amp;nbsp; Maybe their funding should be stopped until they get&lt;BR /&gt;&amp;gt; a&amp;nbsp;passing&amp;nbsp;grade!?!?&lt;BR /&gt;&lt;BR /&gt;You think you're funny, but you're not.&lt;BR /&gt;&lt;BR /&gt;I'm a bit surprised that it's fallen so far. (Then again, I taught NASA some years&lt;BR /&gt;back. So maybe I'm not ...) A friend used to be in charge of NASAs networks, and&lt;BR /&gt;he told us, one time, that they were paranoid[1] about security and intrusions.&lt;BR /&gt;That was because, every time *any* NASA machine got hacked (even if it just the&lt;BR /&gt;inventory machine for the gift shop), NASA's budget dropped $10M.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;[1] - How paranoid? Well, when they first wanted to test out this new thing called&lt;BR /&gt;the Internet (actually, it wasn't called the Internet yet), they set up a machine,&lt;BR /&gt;connected it to the outside connection via an RS-232 cable that had had the&lt;BR /&gt;"transmit" pin sheared off, so that it couldn't leak anything. They sent out a&lt;BR /&gt;ping, to test it--and got a response.&lt;BR /&gt;&lt;BR /&gt;OK, how do you get a response if you can't transmit? In those days you had *full*&lt;BR /&gt;TCP/IP networking on pretty much all machines. So their test machine, trying to&lt;BR /&gt;transmit on the outbound connection, got no response, so it started the&lt;BR /&gt;networking thing. Found a local network, and, lo and behold, there was another&lt;BR /&gt;machine on the LAN that had TCP/IP, so it rewrote the routing tables and&lt;BR /&gt;transmitted via it. (This other machine belonged to a researcher who,&lt;BR /&gt;unbeknownst to the network guys, had an account with a local univerity, and&lt;BR /&gt;happened to be online via modem at the time the test was done.) (TCP/IP is&lt;BR /&gt;*really* robust.)&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;The countries that out-educate today will out-perform in the&lt;BR /&gt;future. - Jack Markell&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Wed, 20 Mar 2019 18:54:13 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Keep-an-eye-on-the-moon-NASA-fails-security-inspection/m-p/20303#M2412</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-03-20T18:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: Keep an eye on the moon - NASA fails security inspection</title>
      <link>https://community.isc2.org/t5/Industry-News/Keep-an-eye-on-the-moon-NASA-fails-security-inspection/m-p/20306#M2413</link>
      <description>&amp;gt; emb021 (Newcomer III) posted a new reply in Industry News on 03-19-2019 05:20 PM&lt;BR /&gt;&lt;BR /&gt;&amp;gt; &amp;nbsp; They all thought as they were "technical" people&lt;BR /&gt;&amp;gt; that a) they should get admin access to their systems and b) they were creative&lt;BR /&gt;&amp;gt; people and security just got in their way of doing their job.&lt;BR /&gt;&lt;BR /&gt;Possibly so. I have *way* too many "NASA" stories for the brief time I spent&lt;BR /&gt;teaching them. And remember: I was, literally, teaching "rocket scientists" ...&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;He has achieved success who has lived well, laughed often, and&lt;BR /&gt;loved much; who has enjoyed the trust of pure women, the respect&lt;BR /&gt;of intelligent men, and the love of little children; ... whose&lt;BR /&gt;life was an inspiration, whose memory a benediction.&lt;BR /&gt;- Bessie Anderson Stanley, competition entry to define Success&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Wed, 20 Mar 2019 19:12:13 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Keep-an-eye-on-the-moon-NASA-fails-security-inspection/m-p/20306#M2413</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-03-20T19:12:13Z</dc:date>
    </item>
  </channel>
</rss>

