Saturday, August 22, 2015

:: NIST Hosts 2015 Cybersecurity Innovation Forum, Sept. 9-11 in D.C.

NIST Hosts 2015 Cybersecurity Innovation Forum, Sept. 9-11 in D.C.

From NIST Tech Beat: August 17, 2015


Contact: Evelyn Brown 
301-975-5661
"The National Institute of Standards and Technology (NIST) will host the 2015 Cybersecurity Innovation Forum on Sept. 9 to 11, 2015, at the Walter E. Washington Convention Center in Washington, D.C.
hacker
Credit: © ra2 studio/Fotolia.com
"At this annual meeting, government, industry and university representatives come together to focus on current, emerging and future challenges in areas such as trusted computing, security automation and information sharing. Leading cybersecurity researchers and executives from the cybersecurity industry will participate in the event.
"The forum’s four tracks—security automation, trusted computing, information sharing and cybersecurity research—will be interspersed with general sessions. Session topics include federal research and privacy, risk management and liability. The event will conclude with a review of the challenges and gaps discussed during the forum and next steps in collaborative efforts to resolve them.
"Presentations will cover Windows 10 security, cryptography, derived PIV credentials proof of concept, public safety cybersecurity, security and the Internet of Things, the NIST Privacy Risk Management Framework and augmenting Federal Information Security Management Act (FISMA) practices with the Cybersecurity Framework.
"The forum also will feature demonstrations and an industry expo on Sept. 9 and 10.
"The agenda is available online. Register for the 2015 Cybersecurity Innovation Forum at: https://www.fbcinc.com/e/cif/attendeereg.aspx.

:: NTIA / IANA Contract One Year Extension

August 17, 2015 by Assistant Secretary for Communications and Information and NTIA Administrator Lawrence E. Strickling
Assistant Secretary for Communications and Information and NTIA Administrator Lawrence E. Strickling
"The Internet’s global multistakeholder community has made tremendous progress in its work to develop a proposal to transition the historic stewardship role NTIA has played related to Internet’s domain name system (DNS).
"When we announced our intent in March 2014 to complete the privatization of the DNS, we noted that the base period of our contract with ICANN to perform technical functions related to the DNS, known as the IANA functions, expired on September 30, 2015. However, it has become increasingly apparent over the last few months that the community needs time to complete its work, have the plan reviewed by the U.S. Government and then implement it if it is approved.
"Accordingly, in May we asked the groups developing the transition documents how long it would take to finish and implement their proposals.  After factoring in time for public comment, U.S. Government evaluation and implementation of the proposals, the community estimated it could take until at least September 2016 to complete this process. In response to their feedback, we informed Congress on Friday that we plan to extend our IANA contract with ICANN for one year to September 30, 2016. Beyond 2016, we have options to extend the contract for up to three additional years if needed.
"This one-year extension will provide the community with the time it needs to finish its work. The groups are already far along in planning the IANA transition and are currently taking comments on their IANA transition proposals. As we indicated in a recent Federal Register notice, we encourage all interested stakeholders to engage and weigh in on the proposals.
"In preparation for the implementation phase of the IANA stewardship transition, NTIA also asked Verisign and ICANN to submit a proposal detailing how best to remove NTIA’s administrative role associated with root zone management, which the groups working on the transition were not asked to address. We asked Verisign and ICANN to submit a proposal detailing how best to do this in a manner that maintains the security, stability and resiliency of the DNS. Under the current root zone management system, Verisign edits and distributes the root zone file after it has received authorization to do so from NTIA. Verisign and ICANN have developed a proposal that outlines a technical plan and testing regime for phasing out the largely clerical role NTIA currently plays in this process. The testing will occur in a parallel environment that will not disrupt the current operation of the root zone management system.
"These developments will help ensure that the IANA transition will be done in a manner that preserves the security and stability of the DNS.

:: FTC Start with Security Conference San Francisco

FTC Start with Security Conference San Francisco

UNIVERSITY OF CALIFORNIA HASTINGS COLLEGE OF THE LAWAlumni Reception Center, 200 McAllister St., San Francisco, CA 94102 | Directions & Nearby

EVENT DESCRIPTION

"The FTC's first “Start With Security” conference is scheduled for September 9, 2015, in San Francisco, and is co-sponsored by the University of California Hastings College of the Law. It is part of a business education initiative designed to provide companies with practical resources to help them implement effective data security strategies.
"Aimed at start-ups and developers, this event will bring together experts to provide information on security by design, common security vulnerabilities, strategies for secure development, and vulnerability response. "Start with Security" will run from 10:00 AM to 4:00 PM. The event is free and open to the public. No pre-registration is necessary. Lunch is provided. This event will be webcast. Check this page on the day of the event for details.
"The conference series is part of the agency’s longstanding efforts to provide businesses with guidance about how to put effective security in place.

♪ Whether Smart City engaged in prohibited Wi-Fi blocking

In re Smart City Holdings, Dkt. EB-SED-15-00018248, Order (Aug. 18, 2015)

"The Enforcement Bureau (Bureau) of the Federal Communications Commission has entered into a Consent Decree to resolve its investigation into whether Smart City Holdings, LLC, and its wholly-owned subsidiaries, Smart City Networks, LP, and Smart City Solutions LLC (collectively, Smart City) engaged in prohibited Wi-Fi blocking by interfering with and disabling Wi-Fi networks established by consumers at several conference facilities where Smart City operates or manages the facility’s Wi-Fi network. To settle this matter, Smart City (i) admits that it prevented certain Wi-Fi users at these locations from establishing or maintaining a Wi-Fi network independent of Smart City’s network, (ii) will implement a compliance plan under which it commits to not engage in Wi-Fi blocking, and (iii) agrees to pay a $750,000 civil penalty."

"On June 24, 2014, the Commission received an informal complaint from a company that provides equipment that enabled users to establish hotspots, marketing its use as an alternative to paying forWi-Fi service that may otherwise be available to consumers at a venue. The complaint charged that its customers could not connect to the Internet using the complainant’s equipment at several venues where Smart City operates or manages the Wi-Fi access.2 In response to the Bureau’s investigation, Smart City provided information revealing that it automatically blocked certain Wi-Fi users at several venues where it managed or operated the Wi-Fi access to prevent such these users from establishing or maintaining a Wi-Fi network independent of Smart City’s network. No evidence exists that the Wi-Fi blocking occurred in response to a specifically identified threat to the security of the Smart City network or the network’s users."

"After reviewing the terms of the Consent Decree and evaluating the facts before us, we find that the public interest would be served by adopting the Consent Decree and terminating the referenced investigation regarding Smart City’s compliance with Section 333 of the Communications Act of 1934, as amended (Act)."

SMART CITY HOLDINGS, LLC, AND ITS WHOLLY-OWNED SUBSIDIARIES, SMART CITY NETWORKS, LP, AND SMART CITY SOLUTIONS LLC. Adopted a Consent Decree and terminated the investigation. Action by: Chief, Enforcement Bureau. Adopted: 08/17/2015 by Order/Consent Decree. (DA No. 15-917). EB   DA-15-917A1.docx  DA-15-917A1.pdf  

IGF-USA 2015 - Keynote Conversation with Vint Cerf and Steve Crocker (Video)

Monday, August 17, 2015

RFC NTIA :: Transitioning NTIA’s IANA Stewardship Role

Date: 
August 11, 2015
This notice announces the dates of a comment period during which the public is invited to provide input on two interrelated multistakeholder community proposals. Together, the proposals set forth a plan for transitioning NTIA’s stewardship role over the Internet Assigned Numbers Authority (IANA) functions. The purpose of this notice is to encourage interested parties to comment on the two connected proposals—the IANA Stewardship Transition Plan and the Enhancements to Internet Corporation for Assigned Names and Numbers (ICANN) Accountability Related to the IANA Stewardship Transition. NTIA will utilize the input provided in making its determination of whether the proposals have received broad community support and whether the plan satisfies the criteria required to transition its stewardship role.
Comments on the IANA Stewardship Transition Plan are due on or before September 8, 2015; comments on the Enhancements to ICANN Accountability are due on or before September 12, 2015. Written comments on the IANA Stewardship Transition Proposal should be submitted at https://www.ianacg.org/calls-for-input/combined-proposal-public-comment-period/. Written comments on the proposed Enhancements to ICANN’s Accountability should be submitted athttps://www.icann.org/public-comments/ccwg-accountability-2015-08-03-en.

IGF-USA 2015 Breakout - Global Solutions for an Ethical Internet of Things (Video)