<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Blog Archives - Corsec Security, Inc.®</title>
	<atom:link href="https://sitdev.corsec.com/category/blog/feed/" rel="self" type="application/rss+xml" />
	<link>https://sitdev.corsec.com/category/blog/</link>
	<description>Corsec helps companies complete security certifications and validations like FIPS 140-2, Common Criteria, and listing on the DoDIN APL / UC APL.</description>
	<lastBuildDate>Tue, 04 Feb 2020 18:27:32 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>

<image>
	<url>https://sitdev.corsec.com/wp-content/uploads/cropped-Corsec-Logo-SiteMap-32x32.png</url>
	<title>Blog Archives - Corsec Security, Inc.®</title>
	<link>https://sitdev.corsec.com/category/blog/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>DoD Changes UC APL name to DoDIN APL</title>
		<link>https://sitdev.corsec.com/uc-apl-now-dodin/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Tue, 01 Aug 2017 15:45:04 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[UC APL]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=10384</guid>

					<description><![CDATA[The Department of Defense has changed the name of the list it uses for the procurement of IT products to be used over the DoD network infrastructures. Previously names the Unified Capabilities Approved Products List (UC APL), ... <p class="read-more-container"><a title="DoD Changes UC APL name to DoDIN APL" class="read-more button" href="https://sitdev.corsec.com/uc-apl-now-dodin/#more-10384" aria-label="More on DoD Changes UC APL name to DoDIN APL">Read more</a></p>]]></description>
										<content:encoded><![CDATA[<p>The Department of Defense has changed the name of the list it uses for the procurement of IT products to be used over the DoD network infrastructures. Previously names the Unified Capabilities Approved Products List (UC APL), the new list is henceforth the Department of Defense Information Network Approved Products List (DoDIN APL).</p>
<p>&#8220;The <span style="color: #3366ff;"><a style="color: #3366ff;" href="https://aplits.disa.mil/apl/" target="_blank" rel="noopener noreferrer">Department of Defense Information Network Approved Products List (DODIN APL)</a></span> is established in accordance with the UC Requirements (<a href="http://www.disa.mil/Network-Services/UCCO/Policies-and-Procedures">UCR 2013</a>) document and mandated by the DOD Instruction (DODI) <a href="http://www.dtic.mil/whs/directives/corres/pdf/810004p.pdf">8100.04</a>. Its purpose is to maintain a single consolidated list of products that have completed Interoperability (IO) and Cybersecurity certification.&#8221;</p>
<p>Notable other changes to the program include:</p>
<ul>
<li>The Unified Capabilities Certification Office (UCCO), which managed the UC APL process is now the Approved Products Certification Office (APCO) and will continue to operate as a staff element to oversee the DoDIN APL. &#8220;The APCO provides process guidance, coordination, information and support to vendors and government sponsors throughout the entire process, from the registration phase to the attainment of DODIN APL status. Additionally, the APCO manages the <a href="http://www.disa.mil/Network-Services/UCCO/APL-Removal-List">DODIN APL Removal List</a>, which consists of products that have been removed from the <a href="https://aplits.disa.mil/apl/" target="_blank" rel="noopener noreferrer">DODIN APL</a>.&#8221;</li>
<li>Information Assurance (IA) Testing is now Cybersecurity (CS) Testing. There is no change to the process, the same STIG requirements are being tested.</li>
<li>The findings report that the test center puts out at the completion of testing which was previously called the IA Report is now to be called a Cybersecurity Assessment Report (CAR). Again, the same information will be presented, the change is in name only.</li>
<li>In suite, the meeting that takes place after the Testing AO receives the vendor&#8217;s cybersecurity mitigations is no longer an IA Out-brief, it is now a CS Out-brief. Attendees will remain the same.</li>
</ul>
<header><a href="https://sitdev.corsec.com/company/contact-us/"><strong>Connect With Us:</strong></a></header>
<header>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <span style="color: #000080;"><strong><a style="color: #000080;" href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></strong></span></header>
<header></header>
<header><a href="https://sitdev.linkedin.com/company/corsec-security"><img decoding="async" class="alignleft wp-image-7805" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a><a href="https://twitter.com/CorsecSecurity"><img decoding="async" class="alignleft wp-image-7807" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img decoding="async" class="alignleft wp-image-7804" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></header>
<div class="wp-post-navigation"></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>MONTHLY FED ROUNDUP – JUNE 2017</title>
		<link>https://sitdev.corsec.com/fed-june17/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Thu, 29 Jun 2017 16:52:09 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=10462</guid>

					<description><![CDATA[DISA’s June News Assured Compliance Assessment Solution (ACAS) training courses offered globally from July through December DISA moves forward with milCloud 2.0 through IDIQ award to connect DoD networks for use by the community and ... <p class="read-more-container"><a title="MONTHLY FED ROUNDUP – JUNE 2017" class="read-more button" href="https://sitdev.corsec.com/fed-june17/#more-10462" aria-label="More on MONTHLY FED ROUNDUP – JUNE 2017">Read more</a></p>]]></description>
										<content:encoded><![CDATA[<header></header>
<header></header>
<h3><span style="color: #800000;"><strong><a style="color: #800000;" href="http://sitdev.disa.mil/newsandevents">DISA’s June News</a></strong></span></h3>
<ul>
<li>
<h5>Assured Compliance Assessment Solution (ACAS) training courses offered globally from July through December</h5>
</li>
<li>
<h5>DISA moves forward with milCloud 2.0 through IDIQ award to connect DoD networks for use by the community and partners</h5>
</li>
<li>
<h5>DISA and DMA partner to host Federal Knowledge Management Working Group</h5>
</li>
<li>
<h5>DISA Executive Deputy Director Tony Montemarano gives annual talk on 4 things mission and industry partners need to know about DISA</h5>
</li>
<li>
<h5>DOD Information Networks commander Army Lt. Gen. Alan R. Lynn discusses how DISA is reimagining the workplace</h5>
</li>
</ul>
<h5></h5>
<h3><span style="color: #800000;"><strong><a style="color: #800000;" href="http://csrc.nist.gov/news_events/index.html">NIST’s June News</a></strong></span></h3>
<h5>New PUBs:</h5>
<header>
<ul>
<li>
<h5>Special Publication 800-192, Verification and Test Methods for Access Control Policies/Models</h5>
</li>
<li>
<h5>Special Publication 800-12 Revision 1, An Introduction to Information Security</h5>
</li>
<li>
<h5>Special Publication 800-63-3, Digital Identity Guidelines</h5>
</li>
</ul>
<h5>New Releases:</h5>
<ul>
<li>
<h5>Release of NIST SP 800-12, Revision 1</h5>
</li>
<li>
<h5>Release NIST Interagency Report (NISTIR) 8011, Automation Support for Security Control Assessments (volume 1 and 2)</h5>
</li>
</ul>
<h5></h5>
<h3><span style="color: #800000;"><strong><a style="color: #800000;" href="https://sitdev.niap-ccevs.org/Announcements/Announcements.cfm">NIAP’s June News</a></strong></span></h3>
<h5>Protection Profile Updates:</h5>
<ul>
<li>
<h5>VPN Client EP v2.0</h5>
</li>
<li>
<h5>Mobile Device Fundamentals PP v3.1</h5>
</li>
</ul>
<h5></h5>
<h3><span style="color: #800000;"><strong><a style="color: #800000;" href="https://sitdev.corsec.com/company/contact-us/">Connect With Us:</a></strong></span></h3>
<h5>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="http://na-ab05.marketo.com/lp/190-TPZ-812/Subscribe-Page.html">Subscribe</a></h5>
<h5><a href="https://sitdev.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></h5>
</header>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Protecting Your Brand</title>
		<link>https://sitdev.corsec.com/protecting-your-brand/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Wed, 21 Jun 2017 20:01:36 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=8050</guid>

					<description><![CDATA[The financial losses associated with damage to your brand can be devastating, sometimes in the millions of dollars. According to an IBM study, 66% of threats impacting brand damage can be attributed to IT system failures ... <p class="read-more-container"><a title="Protecting Your Brand" class="read-more button" href="https://sitdev.corsec.com/protecting-your-brand/#more-8050" aria-label="More on Protecting Your Brand">Read more</a></p>]]></description>
										<content:encoded><![CDATA[<h5>The financial losses associated with damage to your brand can be devastating, sometimes in the millions of dollars. According to an IBM study, 66% of threats impacting brand damage can be attributed to IT system failures and 46% can be attributed to cyber security breaches.</h5>
<h5>Depending on your industry and markets, protecting your brand identity can be as simple as a solid and responsive social media presence or as complex as a series of security measures that will keep your product’s integrity intact. In many industries, specifically those that deal directly with government or regulated industries, brand integrity is a big deal. The same is true for other consumer driven areas, like the automotive and health care industries, in which advances in technology leave organizations open to new threats that can leave consumers questioning their credibility.</h5>
<h3><strong>Third Party Solutions and the Risk to Your Brand</strong></h3>
<h5>Since 2013, there have been significant security breaches that impacted companies of various backgrounds, exposing sensitive consumer information and breaking valuable bonds of trust. Healthcare (Anthem, Premera Blue Cross), finance (JP Morgan), retailers (Target), and online entities (Google, Linkedin), as well as their users/customers, have all been the victims of vicious cyber-attacks, and there is no sign that these attacks will stop in the near future.</h5>
<h5>Perhaps, most notably is the 2014 Heartbleed Bug, which was a catastrophic vulnerability found in the OpenSSL implementation of SSL and TLS. This vulnerability made it possible for anyone on the internet to steal information that was typically protected by encryption.</h5>
<h5>Since OpenSSL is an open source library, nearly 17% of all secure websites that implemented it became vulnerable. In a “heartbeat”, all companies that utilized OpenSSL became victims, in their own right, and though the Heartbleed Bug became widely known in 2014, it was actually committed to two OpenSSL versions 2 years earlier. For brands that relied on OpenSSL, this represented 2 years where consumer information was in jeopardy.</h5>
<h5>These brands were left vulnerable at a single fail point that existed for two whole years &#8212; one that no one anticipated.</h5>
<h3><strong>Certification &amp; Validation: The Path to Brand Security</strong></h3>
<h5>When a client comes to Corsec to begin their journey towards obtaining a Common Criteria certification, a FIPS 140-2 validation, or listing on the DoDIN APL, their reasons may vary, but typically clients want to achieve certification so that they can expand within or access markets that were previously out of reach. And while getting that box checked is a driving reason for many certifications, there is a hidden yet powerful benefit to security certifications – they make your product, and therefore your brand, more secure. When it comes to the relationship between security certifications and brand reputation, it’s important to keep the following points in mind:</h5>
<ul>
<li>
<h5>Certifications assure that your product meets rigid security requirements that mitigate the threat of breaches and other security based risks that could cost your brand long term, irreparable damage.</h5>
</li>
</ul>
<h5>As we guide clients through the certification process, we make sure that their products, and the company as a whole, are meeting or exceeding these requirements. Corsec works with clients to implement changes and updates to secure a product at various entry points, including everything from supply chain management to source code and encryption.</h5>
<ul>
<li>
<h5>A fully validated product means your organization is in full control of your brand. As was pointed out above, in the case of Heartbleed, organizations tethered to a single threat outside their means to fix or control could face disastrous circumstances.</h5>
</li>
</ul>
<h5>When an organization chooses to rely on their own fully validated product, they are securing every single point of entry within their product. This measure mitigates risk more effectively and keeps a product above the curve.</h5>
<ul>
<li>
<h5>Security validations require compliance maintenance (learn more <span style="color: #333399;"><a style="color: #333399;" href="https://sitdev.corsec.com/is-there-value-in-maintaining-your-security-validation/">here</a></span>). However, failure to do so can mean your product is no longer up to date and even worse, could be removed from government approved product purchasing lists. This was the case for many products that had gone through FIPS validation but used outdated Random Number Generators (RNG).</h5>
</li>
</ul>
<h5>At Corsec, we recognize the importance of certification maintenance and make it our goal to care of our clients long after certifications and validations are achieved. We can work with your organization to make sure your product continues to stay market ready and assist you as you determine which path will keep your product, your consumers, confidence, and your brand secure.</h5>
<h5>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <span style="color: #333399;"><a style="color: #333399;" href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></span></h5>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Monthly Fed Roundup – March 2017</title>
		<link>https://sitdev.corsec.com/fed-march17/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Thu, 30 Mar 2017 19:47:59 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<category><![CDATA[UC APL]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=9594</guid>

					<description><![CDATA[DISA’s March News DISA holds Systems Engineering, Technology, and Innovation Pre-Proposal Conference for insights on new Engineering Contract Vehicle Training offered for individuals trying to re-certify, re-accredit, or establish connectivity to the Defense Security Information Security Network ... <p class="read-more-container"><a title="Monthly Fed Roundup – March 2017" class="read-more button" href="https://sitdev.corsec.com/fed-march17/#more-9594" aria-label="More on Monthly Fed Roundup – March 2017">Read more</a></p>]]></description>
										<content:encoded><![CDATA[<header><span style="color: #000080;"><strong><a style="color: #000080;" href="http://sitdev.disa.mil/NewsandEvents/News">DISA’s March News</a></strong></span></header>
<p>DISA holds Systems Engineering, Technology, and Innovation Pre-Proposal Conference for insights on new Engineering Contract Vehicle</p>
<p>Training offered for individuals trying to re-certify, re-accredit, or establish connectivity to the Defense Security Information Security Network (DISN)</p>
<header></header>
<header><span style="color: #000080;"><a style="color: #000080;" href="http://csrc.nist.gov/news_events/index.html"><strong>NIST’s March News</strong></a></span>NIST Final Public Draft:</p>
<ul>
<li>Cybersecurity Framework Manufacturing Profile</li>
</ul>
<p><span style="color: #000080;"><strong><a style="color: #000080;" href="https://sitdev.niap-ccevs.org/Announcements/Announcements.cfm">NIAP’s March News</a></strong></span></p>
<p>RequestedTechnical Community Participation:</p>
<ul>
<li>The update on the Peripheral Sharing Switch Protection Profile version 3.0</li>
<li>The update on the File Encryption Extended Profile (EP)</li>
</ul>
<p>NIAP has published the VPN Gateway Extended Package Version 2.1</p>
<p><span style="color: #000080;"><a style="color: #000080;" href="https://sitdev.corsec.com/company/contact-us/"><strong>Connect With Us:</strong></a></span></p>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <span style="color: #000080;"><strong><a style="color: #000080;" href="http://na-ab05.marketo.com/lp/190-TPZ-812/Subscribe-Page.html">Subscribe</a></strong></span></p>
<p><a href="https://sitdev.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" class="alignleft wp-image-7805" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" class="alignleft wp-image-7807" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" class="alignleft wp-image-7804" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></p>
<div class="wp-post-navigation"></div>
</header>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Upcoming Changes to Common Criteria and Other Security Certifications</title>
		<link>https://sitdev.corsec.com/icmc17/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Thu, 16 Mar 2017 19:07:24 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<category><![CDATA[UC APL]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=9590</guid>

					<description><![CDATA[The global encryption community will gather at the fifth annual International Cryptographic Module Conference (ICMC) in May to discuss the future of commercial cryptography and the role it plays in security of the world around ... <p class="read-more-container"><a title="Upcoming Changes to Common Criteria and Other Security Certifications" class="read-more button" href="https://sitdev.corsec.com/icmc17/#more-9590" aria-label="More on Upcoming Changes to Common Criteria and Other Security Certifications">Read more</a></p>]]></description>
										<content:encoded><![CDATA[<p>The global encryption community will gather at the fifth annual International Cryptographic Module Conference (ICMC) in May to discuss the future of commercial cryptography and the role it plays in security of the world around us. Over 20 countries will be represented, as leaders come together to collaborate on unique challenges faced by those who produce, use, and test cryptographic modules. This discussion fill focus on international standards such as FIPS 140-2, ISO/IEC 19790, and Common Criteria; including the following six tracks:</p>
<ul>
<li>Global Cryptographic Module Validation</li>
<li>Open Source Cryptography</li>
<li>Embedded Encryption and Industry-Vertical Applications</li>
<li>Common Criteria</li>
<li>Quantum Threats and Quantum-Safe Crypto</li>
<li>End-User Experience and Crypto Policy</li>
</ul>
<p>Corsec&#8217;s team will again be leading discussions on various topics including Corsec&#8217;s Matt Keller, who will kick off the conference with an overview on the CMUF and recent changes that affect the community. Later that day, Corsec President John Morris will present on the importance of <span class="dynamic-settings-style-single-post_title ">Third-party security validations, including the role of FIPS 140-2, Common Criteria, and DoDIN APL in securing products</span>. &#8211; &#8220;When it comes to commercially-viable security assurance, there are few options that address all concerns. Traditional third-party assurance programs are slow to be defined, enforced, and are often costly for vendors to navigate. However, vendors are participating more and more frequently in several government-mandated efforts Mr. Morris will examine three of the most successful third-party assurance programs (FIPS 140-2, Common Criteria, and DoDIN APL) and the benefits and drawbacks of the programs. Mr. Morris will break down the vendor, government, and consumer experience with security accreditations and provide insight into the current and future directions of these programs.&#8221;</p>
<p>In addition to Mr. Morris and Mr. Keller, Corsec’s Shashi Karanam will speak on how to keep FIPS 140-2 validations valid, including change within the module and operational environments. &#8211; &#8220;The goal of this presentation is to help vendors to have a better understanding of the CMVP requirements of maintaining the FIPS certificates and the revalidation requirements in FIPS 140-2.&#8221;</p>
<p>Corsec&#8217;s continued participation at ICMC demonstrates the importance of global involvement in the cryptographic community. If you can not attend the conference and want to stay up to date with Corsec as we help to shape the future of validations, you can <strong><span style="color: #000080;"><a style="color: #000080;" href="https://sitdev.corsec.com/contact-us/">request your annual report</a></span></strong> after the show.</p>
<p>&nbsp;</p>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <span style="color: #000080;"><strong><a style="color: #000080;" href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></strong></span></p>
<p><strong>Corsec Social Media</strong></p>
<p><a href="https://sitdev.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" class="alignleft wp-image-7805" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" class="alignleft wp-image-7807" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" class="alignleft wp-image-7804" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></p>
<p>&nbsp;</p>
<div class="wp-post-navigation"></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Monthly Fed Roundup – February 2017</title>
		<link>https://sitdev.corsec.com/fed-feb17/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Mon, 27 Feb 2017 20:15:34 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=9507</guid>

					<description><![CDATA[DISA’s February News DISA CTO set to retire Systems Engineering, Technology and Innovation&#160;Request for Proposal released by DISA NIST’s February News NIST Draft Releases: Draft Special Publication 1800-7,&#160;Situational Awareness for Electric Utilities released for comments ... <p class="read-more-container"><a title="Monthly Fed Roundup – February 2017" class="read-more button" href="https://sitdev.corsec.com/fed-feb17/#more-9507" aria-label="More on Monthly Fed Roundup – February 2017">Read more</a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="color: #000080;"><strong><a style="color: #000080;" href="http://sitdev.disa.mil/NewsandEvents/News">DISA’s February News</a></strong></span></p>
<p>DISA CTO set to retire</p>
<p>Systems Engineering, Technology and Innovation&nbsp;Request for Proposal released by DISA</p>
<p><span style="color: #000080;"><a style="color: #000080;" href="http://csrc.nist.gov/news_events/index.html"><strong>NIST’s February News</strong></a></span></p>
<p>NIST Draft Releases:</p>
<ul>
<li>Draft Special Publication 1800-7,&nbsp;Situational Awareness for Electric Utilities released for comments</li>
</ul>
<p>SHA-1 Collision</p>
<p><span style="color: #000080;"><strong><a style="color: #000080;" href="https://sitdev.niap-ccevs.org/Announcements/Announcements.cfm">NIAP’s February News</a></strong></span></p>
<p>NIAP has announced&nbsp;an invite to join a&nbsp;technical working group in the development of a Protection Profile for TLS Inspection products</p>
<p><span style="color: #000080;"><a style="color: #000080;" href="https://sitdev.corsec.com/company/contact-us/"><strong>Connect With Us:</strong></a></span></p>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements –&nbsp;<span style="color: #000080;"><strong><a style="color: #000080;" href="http://na-ab05.marketo.com/lp/190-TPZ-812/Subscribe-Page.html">Subscribe</a></strong></span></p>
<p><a href="https://sitdev.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" class="alignleft wp-image-7805" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35"></a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" class="alignleft wp-image-7807" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35"></a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" class="alignleft wp-image-7804" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35"></a></p>
<div class="wp-post-navigation">&nbsp;</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Dispelling DoDIN APL Listing Myths</title>
		<link>https://sitdev.corsec.com/ucapl-myths/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Mon, 06 Feb 2017 21:40:10 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[UC APL]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification ROI]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=9498</guid>

					<description><![CDATA[The hoops that companies must jump through in order to sell into the Federal government can be difficult to understand and sometimes misleading. As with any government process, misconceptions surrounding what is required begin to ... <p class="read-more-container"><a title="Dispelling DoDIN APL Listing Myths" class="read-more button" href="https://sitdev.corsec.com/ucapl-myths/#more-9498" aria-label="More on Dispelling DoDIN APL Listing Myths">Read more</a></p>]]></description>
										<content:encoded><![CDATA[<p>The hoops that companies must jump through in order to sell into the Federal government can be difficult to understand and sometimes misleading. As with any government process, misconceptions surrounding what is required begin to evolve and companies can potentially lose revenue as a result.</p>
<p>Here are a few of the most common myths and misconception we have encountered over the years as we helped companies navigate the DoD mandated listing process for the DoDIN APL (Department of Defense Information Network Approved Products List)<span id="__caret"></span>:</p>
<p><strong>Myth 1: “I’m already selling into the DoD, I don’t need additional product security hardening.” </strong></p>
<p>Per <span style="color: #000080;"><a style="color: #000080;" href="http://www.disa.mil/network-services/ucco">DoD guidelines</a></span>, procurements are restricted to those solutions specifically listed on the DoDIN APL. If your product is not currently on the list, or you are not actively pursuing a listing, the new restrictions will shut you out of any future procurements.</p>
<p>Although your current customers may have purchased your solution in the past, they are in fact not authorized to do so in the future, and could require you to get listed at any time moving forward without prior notice.</p>
<p><strong>Myth 2: &#8220;I already completed JITC/STIG Testing and or have a CON, I don&#8217;t need to do anything further.&#8221;</strong></p>
<p>Previously, each military branch would issue a Certificate of Net-worthiness (CON) on their own to individual contractors. A CON gave you the ability to sell into that specific agency, but that agency alone. Year after year, each branch issued their own CON until finally the DoD collectively agreed to develop one singular list to buy from &#8211; and hence the Unified Capabilities Approved Product List was created.</p>
<p>To be listed on the DoDIN APL, your product must go through Interoperability (IO) testing as well as Information Assurance (IA) testing. The Joint Interoperability Test Command (JITC) is the IO certifying authority within The DoD. Any previously certified products tested solely by JITC would need to re-list on the DoDIN APL.</p>
<p>Security Technical Implementation Guide (STIG) testing is part of the initial submission for the DoDIN APL listing process. It includes the completion of a questionnaire on product internals, secure protocols, and access. The results determine which STIGs will be applied to your product. Testing is only one portion of DoDIN APL listing requirements, and while it can help in a quick RFP/RFQ response, it is only a first step. Completing the process ensures access to the total DoD procurement engine.</p>
<p><strong>Myth 3: “The DoD only purchases from U.S. based companies.”</strong></p>
<p>Companies outside the United States that are attempting to develop solutions for the DoD may do so as long as they are listed on the DoDIN APL. In fact, companies from ten different countries outside of the United States have products currently listed on the DoDIN APL.</p>
<p><span style="color: #000080;"><strong><a style="color: #000080;" href="https://sitdev.corsec.com/dodin-apl/">LEARN MORE</a></strong> </span>about inclusion on the DoDIN APL and how to get started.</p>
<p>Corsec brings you all the most recent updates to the standards, certifications, and requirements – <span style="color: #000080;"><strong><a style="color: #000080;" href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></strong></span></p>
<p><a href="https://sitdev.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" class="alignleft wp-image-7805" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" class="alignleft wp-image-7807" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" class="alignleft wp-image-7804" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Monthly Fed Roundup – January 2017</title>
		<link>https://sitdev.corsec.com/fed-jan17/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Mon, 30 Jan 2017 16:48:49 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<category><![CDATA[UC APL]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=9479</guid>

					<description><![CDATA[DISA’s January News DISA focuses on Innovation during the Armed Forces Communications and Electronics Association panel NIST’s January News NIST Draft Releases: Draft Special Publication&#160;800-12, Revision 1, An Introduction to Information Security NIST Interagency Reports: ... <p class="read-more-container"><a title="Monthly Fed Roundup – January 2017" class="read-more button" href="https://sitdev.corsec.com/fed-jan17/#more-9479" aria-label="More on Monthly Fed Roundup – January 2017">Read more</a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="color: #000080;"><strong><a style="color: #000080;" href="http://sitdev.disa.mil/NewsandEvents/News">DISA’s January News</a></strong></span></p>
<p>DISA focuses on Innovation during the Armed Forces Communications and Electronics Association panel</p>
<p><span style="color: #000080;"><a style="color: #000080;" href="http://csrc.nist.gov/news_events/index.html"><strong>NIST’s January News</strong></a></span></p>
<p>NIST Draft Releases:</p>
<ul>
<li>Draft Special Publication&nbsp;800-12, Revision 1, An Introduction to Information Security</li>
</ul>
<p>NIST Interagency Reports:</p>
<ul>
<li>An Introduction to Privacy Engineering and Risk Management in Federal Systems</li>
</ul>
<p><span style="color: #000080;"><strong><a style="color: #000080;" href="https://sitdev.niap-ccevs.org/Announcements/Announcements.cfm">NIAP’s January News</a></strong></span></p>
<p>The <span style="color: #800000;"><a style="color: #800000;" href="https://sitdev.niap-ccevs.org/Ref/Progress_Report_2016.pdf">2016 NIAP Progress Report</a></span> Has Been Released, Outlining Changes To:</p>
<ul>
<li>Protection Profiles</li>
<li>Evaluated Products</li>
<li>The CCRA</li>
<li>CSfC</li>
<li>Interagency Collaboration &#8211; NIST</li>
<li>Process Improvements and Outreach</li>
</ul>
<p><span style="color: #000080;"><a style="color: #000080;" href="https://sitdev.corsec.com/company/contact-us/"><strong>Connect With Us:</strong></a></span></p>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements –&nbsp;<span style="color: #000080;"><strong><a style="color: #000080;" href="http://na-ab05.marketo.com/lp/190-TPZ-812/Subscribe-Page.html">Subscribe</a></strong></span></p>
<p><a href="https://sitdev.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" class="alignleft wp-image-7805" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35"></a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" class="alignleft wp-image-7807" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35"></a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" class="alignleft wp-image-7804" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35"></a></p>
<p>&nbsp;</p>
<div class="wp-post-navigation">&nbsp;</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Monthly Fed Roundup – December 2016</title>
		<link>https://sitdev.corsec.com/fed-dec16/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Thu, 05 Jan 2017 17:22:04 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=9451</guid>

					<description><![CDATA[DISA’s December News No December&#160;Updates NIST’s December News NIST Draft Releases: Draft Special Publication&#160;800-188, De-Identification of Government Datasets Special Publications: SP 800-179 Guide to Securing Apple OS X 10.10 Systems for IT Professionals: A NIST ... <p class="read-more-container"><a title="Monthly Fed Roundup – December 2016" class="read-more button" href="https://sitdev.corsec.com/fed-dec16/#more-9451" aria-label="More on Monthly Fed Roundup – December 2016">Read more</a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="color: #000080;"><strong><a style="color: #000080;" href="http://sitdev.disa.mil/NewsandEvents/News">DISA’s December News</a></strong></span></p>
<p>No December&nbsp;Updates</p>
<p><span style="color: #000080;"><a style="color: #000080;" href="http://csrc.nist.gov/news_events/index.html"><strong>NIST’s December News</strong></a></span></p>
<p>NIST Draft Releases:</p>
<ul>
<li>Draft Special Publication&nbsp;800-188, De-Identification of Government Datasets</li>
</ul>
<p>Special Publications:</p>
<ul>
<li>SP 800-179 Guide to Securing Apple OS X 10.10 Systems for IT Professionals: A NIST Security Configuration Checklist</li>
<li>Special Publication 800-171, Revision 1, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations</li>
<li>Special Publication 800-184, Guide for Cybersecurity Event Recovery</li>
<li>Special Publication (SP) 800-185, SHA-3 Derived Functions: cSHAKE, KMAC, TupleHash, and ParallelHash</li>
</ul>
<p><span style="color: #000080;"><strong><a style="color: #000080;" href="https://sitdev.niap-ccevs.org/Announcements/Announcements.cfm">NIAP’s December News</a>:</strong></span></p>
<p>Protection Profile Updates:</p>
<ul>
<li>Mobile Device Management Protection Profile v3.0</li>
<li>Mobile Device Management Agents Extended Package v3.0</li>
</ul>
<p><span style="color: #000080;"><a style="color: #000080;" href="https://sitdev.corsec.com/company/contact-us/"><strong>Connect With Us:</strong></a></span></p>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements –&nbsp;<span style="color: #000080;"><strong><a style="color: #000080;" href="http://na-ab05.marketo.com/lp/190-TPZ-812/Subscribe-Page.html">Subscribe</a></strong></span></p>
<p><a href="https://sitdev.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" class="alignleft wp-image-7805" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35"></a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" class="alignleft wp-image-7807" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35"></a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" class="alignleft wp-image-7804" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35"></a></p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Corsec Named Owler ‘HOT in 2016’ Winner</title>
		<link>https://sitdev.corsec.com/owler-2016-winner/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Mon, 19 Dec 2016 20:32:33 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=9447</guid>

					<description><![CDATA[Owler (a Crowdsourced Competitive Intelligence Platform) recognizes the top trending companies in cities around the world. They filtered through more than 15 million companies and picked 4,500 award winners across 600 cities worldwide. Recipients were ... <p class="read-more-container"><a title="Corsec Named Owler ‘HOT in 2016’ Winner" class="read-more button" href="https://sitdev.corsec.com/owler-2016-winner/#more-9447" aria-label="More on Corsec Named Owler ‘HOT in 2016’ Winner">Read more</a></p>]]></description>
										<content:encoded><![CDATA[<p>Owler (a Crowdsourced Competitive Intelligence Platform) recognizes the top trending companies in cities around the world. They filtered through more than 15 million companies and picked 4,500 award winners across 600 cities worldwide. Recipients were chosen based on several different metrics, including number of followers on Owler, insights collected from our community, social media followers, and blog posts over the past year.</p>
<p>This year Owler selected Corsec Security, Inc. in Herndon, VA as one of their &#8220;Hot In 2016&#8221; winners. “We’ve sorted through database of millions of contributions from our community and landed on the top trending companies from around the world,” said Jim Fowler, CEO at Owler.</p>
<p>For 18 years Corsec has assisted companies through the security certification and validation process. We are a privately-owned company that partners with organizations worldwide to strengthen product security, improve brand reputation, and increase financial returns. Our turnkey solution helps our partners complete security certifications the first time through. This approach has helped secure products in all industries, from storage devices to satellites. Our broad knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast and flexible information on security and industry knowledge.</p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Content Delivery Network via cdn.corsec.com

Served from: sitdev.corsec.com @ 2026-05-30 22:29:09 by W3 Total Cache
-->