SANS Institute

  • In the American Innovation and Competitiveness Act, Congress told NIST to take a deep dive into how agencies understand and use the special publications and Federal Information Processing Standards for cybersecurity that it produces.

    April 04, 2017
  • The General Services Administration’s Technology Transformation Service (TTS) released a draft solicitation asking for industry input in creating a bug bounty program.

    February 06, 2017
  • To judge the progress of cybersecurity preparedness in the federal government, you've got to take a long-term view. One person who's been tracking cybersecurity and cyber education for more than 20 years, Alan Paller, director of research at the SANS Institute joined the Federal Drive with Tom Temin.

    June 24, 2016
  • Richard Spires, CEO of Learning Tree International, joins host John Gilroy to discuss how to use continuous learning to close the "skill gap" in the federal government. May 10, 2016

    May 09, 2016
  • The Homeland Security Department launched a new type of red team effort where they break into an agencies' networks over the next 90 days and help them make long-term, sustainable fixes.

    April 25, 2016
  • COMMENTARY: Ron Gula, the CEO of Tenable Network Security, makes the case for CIOs not to get overwhelmed by all the security rules and requirements and instead to focus on a few areas that can make a big difference.

    August 18, 2015
  • The Office of Management and Budget just posted the latest data from its 30-day cyber sprint. Alan Paller of the SANS Institute and a task force of industry experts offer their insight on what are the next steps agencies should be taking to improve their cybersecurity.

    August 04, 2015
  • For agency managers responsible for cybersecurity, the last few weeks have been challenging. The data breach affecting millions might have been the direct responsibility of the Office of Personnel Management, but the response has been all-of-government - starting with the now-concluded 30-day cyber sprint. Cyber is a matter of technology, skill and people. Alan Paller, the director of research at the SANS Institute, joined Jared Serbu on the Federal Drive to offer some perspective on what CIOs and cybersecurity officers need to do next.

    August 03, 2015
  • Alan Paller and John Pescatore of the SANS Institute explain why Katherine Archuleta's departure may not be a fair nor effective means for addressing the cybersecurity problems at OPM.

    July 15, 2015
  • In the aftermath of the massive data breach suffered by the Office of Personnel Management, the Homeland Security Department issues a new alert about targeted phishing attacks against federal employees and retirees. Federal News Radio asked cyber experts for advice on what victims should be on the lookout for from these bogus emails.

    July 02, 2015
  • The Office of Personnel Management starts notifying employees today that their personal information may have been compromised. As many as 4 million current and former federal employees may be affected. Now the question is, has the government learned anything from this incident, or is it lurching from crisis to crisis? SANS Institute\'s Director of Research Alan Paller joined Tom Temin on the Federal Drive for a look ahead.

    June 08, 2015
  • A large chunk of the government IT workforce that's charged with implementing the Homeland Security Department's new continuous diagnostics and mitigation initiative still doesn't know much about it. The lack of awareness is most acute with agency inspectors general. But those that have pressed forward with CDM say their networks have already become more secure or less costly.

    August 13, 2014
  • Under the continuous diagnostics and mitigation program, DHS wants to ensure systems administrators have data on the most pressing threats and vulnerabilities first so they can fix them as soon as possible. John Streufert, DHS's director of federal network resilience, said the recently-awarded dashboard will be set up to do just that.

    May 29, 2014
  • Federal cybersecurity officials are in knots over the Heartbleed threat. The vulnerability potentially affects a common data encryption system used on internet servers. Homeland Security says federal web servers are OK. Qualys has a free online SSL Server Test that can analyze a web server. Alan Paller, director of research at the cybersecurity education firm SANS Institute, explained the threat to Federal Drive hosts Tom Temin and Emily Kopp.

    April 16, 2014