DRAFT (Second Draft) Trusted Geolocation in the Cloud: Proof of Concept Implementation
Please submit comments by August 24, 2015 to ir7904-comments@nist.gov, with "IR 7904 Comments" in the subject line.
Comment Template Form for NISTIR 7904
An Educational Not for Profit focused on Federal Internet and Telecommunications Policy
| ||||
| ||||
|
Secure and Trustworthy Cyberspace (SaTC)
Synopsis of Program:
Cyberspace has transformed the daily lives of people for the better. The rush to adopt cyberspace, however, has exposed its fragility and vulnerabilities: corporations, agencies, national infrastructure and individuals have been victims of cyber-attacks. In December 2011, the National Science and Technology Council (NSTC) with the cooperation of NSF issued a broad, coordinated Federal strategic plan for cybersecurity research and development to "change the game," minimize the misuses of cyber technology, bolster education and training in cybersecurity, establish a science of cybersecurity, and transition promising cybersecurity research into practice. This challenge requires a dedicated approach to research, development, and education that leverages the disciplines of mathematics and statistics, the social sciences, and engineering together with the computing, communications and information sciences.
The Secure and Trustworthy Cyberspace (SaTC) program welcomes proposals that address cybersecurity from:
- a Trustworthy Computing Systems (TWC) perspective and/or a Social, Behavioral and Economic Sciences (SBE) perspective;
- the Secure, Trustworthy, Assured and Resilient Semiconductors and Systems (STARSS) perspective; or
- the Transition to Practice (TTP) perspective.
In addition, we welcome proposals that integrate research addressing all of these perspectives (see the Program Description below). Proposals may be submitted in one of the following three project classes (plus Cybersecurity Education; see below):
- Small projects: up to $500,000 in total budget, with durations of up to three years;
- Medium projects: $500,001 to $1,200,000 in total budget, with durations of up to four years; or
- Large projects: $1,200,001 to $3,000,000 in total budget, with durations of up to five years.
For Small hardware security proposals, the Secure, Trustworthy, Assured and Resilient Semiconductors and Systems (STARSS) perspective is focused specifically on hardware research innovation that addresses SaTC goals, and includes the opportunity to collaborate closely with industry. STARSS proposals may not include the TWC, SBE, or TTP perspectives. The STARSS perspective may not be used for Medium or Large proposals.
The Transition to Practice (TTP) perspective is focused exclusively on transitioning existing research to practice. TTP proposals may not include the TWC, SBE, or STARSS perspective. The TTP perspective may be used for Small and Medium proposals, but may not be used for Large proposals.
In addition, the SaTC program seeks proposals focusing entirely on Cybersecurity Education with total budgets limited to $300,000 and durations of up to two years. These cybersecurity education projects may not include any of the perspectives named above.
http://www.nsf.gov/pubs/2015/nsf15575/nsf15575.htm?WT.mc_id=USNSF_25&WT.mc_ev=click
The Department of Commerce Internet Policy Task Force (IPTF) is requesting comment to identify substantive cybersecurity issues that affect the digital ecosystem and digital economic growth where broad consensus, coordinated action, and the development of best practices could substantially improve security for organizations and consumers. The IPTF invites public comment on these issues from all stakeholders with an interest in cybersecurity, including the commercial, academic and civil society sectors, and from relevant federal, state, local, and tribal entities.
UPDATE: Comments are now due on or before 5 p.m. Eastern Time, May 27, 2015.
May 28, 2015
NIST IR 8062
DRAFT Privacy Risk Management for Federal Information Systems
NIST requests comments on the draft report NISTIR 8062, Privacy Risk Management for Federal Information Systems, which describes a privacy risk management framework for federal information systems. The framework provides the basis for establishing a common vocabulary to facilitate better understanding of - and communication about - privacy risks and the effective implementation of privacy principles in federal information systems.
Please send comments to privacyeng@nist.gov by July 13, 2015 at 5:00pm EDT using the comment matrix provided (link provided below).
Background:
Expanding opportunities in cloud computing, big data, and cyber-physical systems are bringing dramatic changes to how we use information technology. While these technologies bring advancements to U.S. national and economic security and our quality of life, they also pose risks to individuals' privacy.
Privacy Risk Management for Federal Information Systems (NISTIR 8062) introduces a privacy risk management framework for anticipating and addressing risks to individuals' privacy. In particular, it focuses on three privacy engineering objectives and a privacy risk model. To develop this document, NIST conducted significant public outreach and research. We are soliciting public comments on this draft to obtain further input on the proposed privacy risk management framework, and we expect to publish a final report based on this additional feedback.
Note to Reviewers:
To facilitate public review, we have compiled a number of topics of interest to which we would like reviewers to respond. Please keep in mind that it is not necessary to respond to all topics listed below, Reviewers should also feel free to suggest other areas of revision or enhancement to the document.
• Privacy Risk Management Framework: Does the framework provide a process that will help organizations make more informed system development decisions with respect to privacy? Does the framework seem likely to help bridge the communication gap between technical and non-technical personnel? Are there any gaps in the framework?
• Privacy Engineering Objectives: Do these objectives seem likely to assist system designers and engineers in building information systems that are capable of supporting agencies' privacy goals and requirements? Are there properties or capabilities that systems should have that these objectives do not cover?
• Privacy Risk Model:
o Does the equation seem likely to be effective in helping agencies to distinguish between cybersecurity and privacy risks?
o Can data actions be evaluated as the document proposes? Is the approach of identifying and assessing problematic data actions usable and actionable?
o Should context be a key input to the privacy risk model? If not, why not? If so, does this model incorporate context appropriately? Would more guidance on the consideration of context be helpful?
o The NISTIR describes the difficulty of assessing the impact of problematic data actions on individuals alone, and incorporates organizational impact into the risk assessment. Is this appropriate or should impact be assessed for individuals alone? If so, what would be the factors in such an assessment
FCC Chairman Tom Wheeler issued the following statement today after Comcast announced its decision to abandon its $45 billion dollar bid to acquire Time Warner Cable. Comcast's announcement comes after the Federal Communications Commission staff informed the companies of their serious concerns that the merger risks outweighed the benefits to the public interest.
"Comcast and Time Warner Cable’s decision to end Comcast’s proposed acquisition of Time Warner Cable is in the best interests of consumers. The proposed transaction would have created a company with the most broadband and video subscribers in the nation alongside the ownership of significant programming interests.
"Today, an online video market is emerging that offers new business models and greater consumer choice. The proposed merger would have posed an unacceptable risk to competition and innovation especially given the growing importance of high-speed broadband to online video and innovative new services.
I am proud of our close working relationship throughout the review process with the Antitrust Division of the Department of Justice. Our collaboration provided both agencies with a deeper understanding of the important issues of innovation and competition that the proposed transaction raised.”
Position Summary: The Policy Advocate will play a key role in the development of Public Knowledge's approach to promoting innovation, consumer rights, and the free flow of information. The Policy Advocate position presents a rare opportunity for a hard-working, creative advocate to work in a cutting-edge issue area and to become a public figure in the field.
Position Status: Full-time
Location: Washington, D.C.
Reports to: Public Knowledge President and Vice President
Application Deadline: January 16th, 2015
Essential Duties:
Qualifications:
Compensation: Public Knowledge provides competitive compensation, excellent benefits and opportunities for professional growth.
To Apply: Send a resume including salary history; cover letter stating your interest in Public Knowledge, and two writing samples (max. 5 pages each) to: jobs@publicknowledge.org, with the subject line "Policy Advocate." Applications will be accepted on a rolling basis beginning December 4, 2014; open until filled.
Job Title:Attorney Advisor
Department:Department Of Homeland Security
Agency:DHS Headquarters
Job Announcement Number:DHSHQ15-1261359-OGC
SALARY RANGE: | $106,263.00 to $138,136.00 / Per Year |
OPEN PERIOD: | Friday, December 5, 2014 to Thursday, December 25, 2014 |
SERIES & GRADE: | GS-0905-14 |
POSITION INFORMATION: | Full Time - Excepted Service Permanent |
PROMOTION POTENTIAL:15 | |
DUTY LOCATIONS: | 1 vacancy in the following location: Washington DC, DC View Map |
WHO MAY APPLY: | United States Citizens |
SECURITY CLEARANCE: | Secret |
SUPERVISORY STATUS: | No |
Do you desire to protect American interests and secure our Nation while building a meaningful and rewarding career? If so, the Department of Homeland Security (DHS) is calling. DHS components work collectively to prevent terrorism, secure borders, enforce and administer immigration laws, safeguard cyberspace and ensure resilience to disasters. The vitality and magnitude of this mission is achieved by a diverse workforce spanning hundreds of occupations. Make an impact; join DHS.
The primary purpose of this position is to serve the Office of the General Counsel as a legal advisor. The individual selected for this position will be responsible for providing legal advice for government contracts, inter-agency agreements, licensing agreements, and international agreements entered into by DHS's Science and Technology Directorate ("S&T") in the areas of research, development, test, and evaluation. S&T's contracts are issued in accordance with the Federal Acquisition Regulation ("FAR") or DHS's Other Transaction Agreement authority and relate to a broad portfolio of S&T programs, including cyber security and biosecurity. The individual selected for this position will also be responsible for providing legal advice for intellectual property issues related to S&T's programs, including intellectual property issues in government contracts, international agreements, and licenses.
S&T is the primary research, development, test, and evaluation component of the Department. The work carried out in S&T, in partnership with the private sector, national laboratories, universities, international partners, and other government agencies, helps push the innovation envelope and drives development and use of high technology in support of the Department's operational units.
This position is located in the Department of Homeland Security (DHS), Office of the General Counsel (OGC), Technology Programs Law Division.
This is a permanent appointment in the excepted service and will be filled on a full-time permanent basis. Employees hired under an Excepted Service appointment are required to serve a two (2) year trial period. Upon successful completion of the required trial period, this position will be permanent.
As an Attorney Advisor you will:
The Office of the General Counsel (OGC) will evaluate eligible candidates based on the following criteria:
OGC will rate qualified applicants by comparing each candidate's qualifications to those pertinent to the position. OGC will consider relevant skills and experience, education and training, performance, and awards. The skills and experience listed immediately below are of particular importance to the position, and applicants should provide specific detailed information in these areas, where applicable, as part of their application.
For this position, specialized experience is providing legal advice and support on matters related to government contracts and intellectual property law issues in the Federal Government.
At least three years of experience as a practicing attorney is desired.
Applicants with less than five years of practice experience must submit a law school transcript and grade point average or class ranking with the application materials.
Please visit OPM's web site at https://www.opm.gov/qualifications/SEC-II/s2-e4.htm#e4a for additional information on this topic.
Application of Veterans' Preference: There is no formal rating system for applying veterans' preference to attorney appointments in the excepted service; however, the Department of Homeland Security considers veterans' preference eligibility as a positive factor in attorney hiring. Applicants eligible for veterans' preference are encouraged to include that information in their cover letter or resume and attach supporting documentation (e.g., DD form 214 or other substantiating documents) to their submissions.