Currently browsing tag

dod

FedRAMP for the impatient.

FedRAMP Security Assessment

FedRAMP is how clouds will be authorized for use in the Federal government. With it, the government to authorize a cloud for …

DISA releases IAVA-to-CVE mapping

A diagram of the IAVM-to-CVE workflow.

The DOD keeps its own catalog of system vulnerabilities, the IAVM. You can think about this as the computer security alerting system …

Fighting Forks

Licenses

This is the ignite presentation I gave for the Mil-OSS WG2 conference today. It’s a tremendous group of sandal-shod revolutionaries who want …

Open Source and Open Standards

Open standards are motherhood and apple pie – they ensure a level playing field in which many implementations can compete against each …