﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>I-Assure Forums / Information Assurance / Security Testing </title><generator>InstantForum.NET v4.1.4</generator><description>I-Assure Forums</description><link>http://www.i-assure.com/forums/</link><webMaster>forums@i-assure.com</webMaster><lastBuildDate>Sat, 31 Jul 2010 20:27:14 GMT</lastBuildDate><ttl>20</ttl><item><title>COTS Audit reduction tool/software</title><link>http://www.i-assure.com/forums/Topic944-7-1.aspx</link><description>Anyone out there using a COTS audit tool or software that assists with performing weekly system audits?  I came from a place where they had build custom scripts to do this but I'm at place now where they just view them manually and I'm triying to find a better solution.  Thanks</description><pubDate>Mon, 29 Mar 2010 16:10:00 GMT</pubDate><dc:creator>murphybe</dc:creator></item><item><title>Assigning DIACAP Severity Codes and risk assessments</title><link>http://www.i-assure.com/forums/Topic927-7-1.aspx</link><description>Good evening,&lt;P&gt;In my current position, I routinely see 'risk assessment' reports that consist of no more than DISA Gold Disk findings assigned to an DoDD 8500.2 IA control. I've been assurred by the 'experts' who conducted an ST&amp;amp;E that the report does not contain false positives.  When asked, "how do you know it doesn't contain false positives," I was promptly told "it doesn't!"  &lt;/P&gt;&lt;P&gt;In my opinion, a report with nothing more than cut and paste from a DISA Gold report isn't all that useful and could contain false positives.  Isn't some level of analysis is needed to ensure what makes your final report is an actual finding? &lt;/P&gt;&lt;P&gt;My question:  How in the heck can you assess a severity code I to an IA control based on DISA Gold/STIG/checklist findings that may or may not be true?  Essentially, where is the analysis????&lt;/P&gt;&lt;P&gt;If I were a Cert Authority (CA), I wouldn't make a recommendation to my DAA based data that hasn't been analyzed.  It seems that some organizations rely solely on DISA gold/SRR/Checklist and if it's a STIG CAT I, by god, it's going to make the IA Control a CAT I.  Grrrr ... very frustrating!  I've seen several STIG PDIs that make reference to the wrong IA control.&lt;/P&gt;&lt;P&gt;Sorry to vent, but the IA business really sucks at times! </description><pubDate>Mon, 15 Feb 2010 21:36:02 GMT</pubDate><dc:creator>07caddy</dc:creator></item><item><title>Retina Scan Settings</title><link>http://www.i-assure.com/forums/Topic859-7-1.aspx</link><description>What are the best scan settings to use for Retina for DIACAP preparation?</description><pubDate>Mon, 14 Sep 2009 14:29:58 GMT</pubDate><dc:creator>tcornelius</dc:creator></item><item><title>8500 IA Controls SRTM</title><link>http://www.i-assure.com/forums/Topic885-7-1.aspx</link><description>Does anyone have a SRTM in excel format for evaluating the 8500 IA controls?  If so could you forward it to me in an email.</description><pubDate>Wed, 21 Oct 2009 12:07:13 GMT</pubDate><dc:creator>bzhz79</dc:creator></item><item><title>VMS to RTM</title><link>http://www.i-assure.com/forums/Topic108-7-1.aspx</link><description>I'm looking for a tool that can convert the VMS numbers from DISA Gold Disk to RTM / IA Controls.&lt;P&gt;If there's such a thing. please let me know.&lt;/P&gt;&lt;P&gt;Thanks</description><pubDate>Mon, 22 Jan 2007 13:32:41 GMT</pubDate><dc:creator>Dhruvo</dc:creator></item><item><title>Auto RTM download location</title><link>http://www.i-assure.com/forums/Topic606-7-1.aspx</link><description>Hello,&lt;br&gt;&lt;br&gt;I can't seem to find the download link for AutoRTM.  I downloaded the toolset, just fine. Can someone send me a link?</description><pubDate>Tue, 20 May 2008 14:50:59 GMT</pubDate><dc:creator>wshutter</dc:creator></item><item><title>AutoRTM License</title><link>http://www.i-assure.com/forums/Topic685-7-1.aspx</link><description>Is there a requirement to have a license to use AutoRTM?  When I clicked execute I was told that there wasn't a license.  When I left the block blank it shutdown.</description><pubDate>Tue, 23 Sep 2008 10:13:42 GMT</pubDate><dc:creator>vsmith51</dc:creator></item><item><title>AutoRTM no IAVA listing?</title><link>http://www.i-assure.com/forums/Topic358-7-1.aspx</link><description>I noticed that the UNIX RTM does not list the IAVA.  Running the Unix SRR IAVA is listed in the report.  Will AutoRTM support listing IAVA?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;-ln</description><pubDate>Tue, 13 Nov 2007 14:11:10 GMT</pubDate><dc:creator>lnunez</dc:creator></item><item><title>AUTORTM</title><link>http://www.i-assure.com/forums/Topic609-7-1.aspx</link><description>Can you provide an update to the autortm for CJCSI6510D to CJCSI6510E</description><pubDate>Fri, 23 May 2008 10:15:02 GMT</pubDate><dc:creator>doriangray</dc:creator></item><item><title>AUTORTM</title><link>http://www.i-assure.com/forums/Topic599-7-1.aspx</link><description>Is there anyway to integrate the Windows STIGS (NSA) into the AutoRTM? The tool is great by the way!!!!!</description><pubDate>Tue, 13 May 2008 14:58:33 GMT</pubDate><dc:creator>doriangray</dc:creator></item><item><title>AutoRTM questions</title><link>http://www.i-assure.com/forums/Topic460-7-1.aspx</link><description>Hi,&lt;/P&gt;&lt;P&gt;I like the AutoRTM tool, but have a few questions:&lt;/P&gt;&lt;P&gt;- I'd like to be able to see the version # or date of the source requirements documents, but the only time I see that information is when I created the project using the wizard. Is this information saved somewhere in the project where I can refer to it when needed, rather than going back through the wizard?&lt;/P&gt;&lt;P&gt;- I'd be interested to know how updates to requirements will be handled for existing projects. Will the entire list of requirements be completely replaced for a project, or will individual requirements that are added, deleted or changed be highlighted in some way?&lt;/P&gt;&lt;P&gt;- After creating a project using the wizard, is there a way to add a set of requirements without recreating the project?  For example, I may want to add another DISA STIG to my project later on.&lt;/P&gt;&lt;P&gt;Thanks for your help. Great tool!</description><pubDate>Wed, 23 Jan 2008 10:35:39 GMT</pubDate><dc:creator>hsconnor</dc:creator></item></channel></rss>