<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/1.5.2" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
>

<channel>
	<title>Apex Assurance Group</title>
	<link>http://www.apexassurance.com/blog</link>
	<description>... the first Weblog for security certifications in the government and commercial industries</description>
	<pubDate>Wed, 02 Jan 2008 04:41:28 +0000</pubDate>
	<generator>http://wordpress.org/?v=1.5.2</generator>
	<language>en</language>

		<item>
		<title>A quick look at 2007</title>
		<link>http://www.apexassurance.com/blog/2008/01/02/a-quick-look-at-2007/</link>
		<comments>http://www.apexassurance.com/blog/2008/01/02/a-quick-look-at-2007/#comments</comments>
		<pubDate>Wed, 02 Jan 2008 04:41:28 +0000</pubDate>
		<dc:creator>Ray Potter</dc:creator>
		
	<category>Apex Assurance Group</category>
		<guid>http://www.apexassurance.com/blog/2008/01/02/a-quick-look-at-2007/</guid>
		<description><![CDATA[	2007 can be summarized in one word: busy.  Thank you to our customers, employees, and partners who helped make this year better than even my high expectations. 
	The first year of the blog saw just over 100 posts. The second saw just under 25. And given the current forecast, the posts will continue to [...]]]></description>
			<content:encoded><![CDATA[	<p>2007 can be summarized in one word: <em>busy</em>.  Thank you to our customers, employees, and partners who helped make this year better than even my high expectations. </p>
	<p>The first year of the blog saw just over 100 posts. The second saw just under 25. And given the current forecast, the posts will continue to be a bit light in 2008. </p>
]]></content:encoded>
			<wfw:commentRSS>http://www.apexassurance.com/blog/2008/01/02/a-quick-look-at-2007/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>In the Same Boat</title>
		<link>http://www.apexassurance.com/blog/2007/10/14/in-the-same-boat/</link>
		<comments>http://www.apexassurance.com/blog/2007/10/14/in-the-same-boat/#comments</comments>
		<pubDate>Mon, 15 Oct 2007 02:15:05 +0000</pubDate>
		<dc:creator>Ray Potter</dc:creator>
		
	<category>Apex Assurance Group</category>
		<guid>http://www.apexassurance.com/blog/2007/10/14/in-the-same-boat/</guid>
		<description><![CDATA[	I was just catching up on some blogs, and I saw this post from Thomas Ptacek. 
	We’re still alive… but holy crap are we slammed. 
	Funny&#8230; I was going to submit a similar post this week. Apex is in the same boat. 
	I like Thomas&#8217; brevity. Though, unlike the Matasano folks, you probably won&#8217;t see [...]]]></description>
			<content:encoded><![CDATA[	<p>I was just catching up on some blogs, and I saw <a href="http://www.matasano.com/log/970/were-still-alive/" target="_new">this post</a> from Thomas Ptacek. </p>
	<blockquote><p>We’re still alive… but holy crap are we slammed. </p></blockquote>
	<p>Funny&#8230; I was going to submit a similar post this week. Apex is in the same boat. </p>
	<p>I like Thomas&#8217; brevity. Though, unlike the Matasano folks, you probably won&#8217;t see us resume to our normal posting schedule early next week&#8230; probabably more like middle/late next month! Things are really hot here.
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.apexassurance.com/blog/2007/10/14/in-the-same-boat/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>NIAP CCEVS Gates Opening (Slightly)</title>
		<link>http://www.apexassurance.com/blog/2007/09/12/niap-ccevs-gates-opening-slightly/</link>
		<comments>http://www.apexassurance.com/blog/2007/09/12/niap-ccevs-gates-opening-slightly/#comments</comments>
		<pubDate>Wed, 12 Sep 2007 13:39:04 +0000</pubDate>
		<dc:creator>Ray Potter</dc:creator>
		
	<category>Apex Assurance Group</category>
	<category>Common Criteria</category>
		<guid>http://www.apexassurance.com/blog/2007/09/12/niap-ccevs-gates-opening-slightly/</guid>
		<description><![CDATA[	According to NIAP CCEVS:
	Beginning 1 October 2007, for FY08, the NIAP CCEVS office will begin accepting US Government PP compliant (basic, medium or high) and EAL 4 or above products in support of National Security customers. Product submissions meeting the above criteria will be queued and validation resources allocated as they become available. Detailed letters [...]]]></description>
			<content:encoded><![CDATA[	<p>According to <a href="http://www.niap-ccevs.org/" target="_new">NIAP CCEVS</a>:</p>
	<blockquote><p>Beginning 1 October 2007, for FY08, the NIAP CCEVS office will begin accepting US Government PP compliant (basic, medium or high) and EAL 4 or above products in support of National Security customers. Product submissions meeting the above criteria will be queued and validation resources allocated as they become available. Detailed letters of intent identifying DoD or IC customers will continue to be required. </p></blockquote>
	<p>There is still a bit of <a href="http://www.regulations.gov/fdmspublic/component/main?main=DocketDetail&#038;d=DOD-2007-OS-0066" target="_new">discussion and concern</a> around the Fee for Service validation plan, so things will certainly be interesting. </p>
	<p>September is a busy month (even by our standards!). </p>
]]></content:encoded>
			<wfw:commentRSS>http://www.apexassurance.com/blog/2007/09/12/niap-ccevs-gates-opening-slightly/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>Got Rails?</title>
		<link>http://www.apexassurance.com/blog/2007/08/01/got-rails/</link>
		<comments>http://www.apexassurance.com/blog/2007/08/01/got-rails/#comments</comments>
		<pubDate>Wed, 01 Aug 2007 19:56:13 +0000</pubDate>
		<dc:creator>Ray Potter</dc:creator>
		
	<category>Apex Assurance Group</category>
		<guid>http://www.apexassurance.com/blog/2007/08/01/got-rails/</guid>
		<description><![CDATA[	It&#8217;s time for the semi-annual (or so it seems!) posting on the Apex Assurance blog. 
	We&#8217;re looking for a Ruby on Rails developer, either part-time or full time. If you&#8217;re interested or know someone who is, please send an email to careers@apexassurance.com.
	I&#8217;ll save all the HR/marketing spiel. That&#8217;s not my specialty.

]]></description>
			<content:encoded><![CDATA[	<p>It&#8217;s time for the semi-annual (or so it seems!) posting on the Apex Assurance blog. </p>
	<p>We&#8217;re looking for a Ruby on Rails developer, either part-time or full time. If you&#8217;re interested or know someone who is, please send an email to <em>careers@apexassurance.com</em>.</p>
	<p>I&#8217;ll save all the HR/marketing spiel. That&#8217;s not my specialty.
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.apexassurance.com/blog/2007/08/01/got-rails/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>Update on FIPS 140-3</title>
		<link>http://www.apexassurance.com/blog/2007/07/17/update-on-fips-140-3/</link>
		<comments>http://www.apexassurance.com/blog/2007/07/17/update-on-fips-140-3/#comments</comments>
		<pubDate>Wed, 18 Jul 2007 00:39:11 +0000</pubDate>
		<dc:creator>Ray Potter</dc:creator>
		
	<category>FIPS 140</category>
		<guid>http://www.apexassurance.com/blog/2007/07/17/update-on-fips-140-3/</guid>
		<description><![CDATA[	NIST is now accepting comments on the latest draft of FIPS 140-3. 
	From the website: 
	Electronic comments may also be sent to:  FIPS140-3@nist.gov with &#8220;Comments on Draft 140-3&#8243; in the subject line.
	I saw this article a few days ago but didn&#8217;t have the time to post a link. Thank you to the good folks [...]]]></description>
			<content:encoded><![CDATA[	<p>NIST is <a href="http://csrc.nist.gov/cryptval/140-3.htm" target="_new">now accepting comments</a> on the latest draft of FIPS 140-3. </p>
	<p>From the website: </p>
	<blockquote><p>Electronic comments may also be sent to:  FIPS140-3@nist.gov with &#8220;Comments on Draft 140-3&#8243; in the subject line.</p></blockquote>
	<p>I saw <a href="http://www.gcn.com/online/vol1_no1/44667-1.html" target="_new">this article</a> a few days ago but didn&#8217;t have the time to post a link. Thank you to the good folks at <a href="http://www.ewa-canada.com/" target="_new">EWA-Canada</a> for the reminder. </p>
]]></content:encoded>
			<wfw:commentRSS>http://www.apexassurance.com/blog/2007/07/17/update-on-fips-140-3/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>NIAP CCEVS - Fee for Service Comment Solicitation</title>
		<link>http://www.apexassurance.com/blog/2007/07/10/niap-ccevs-fee-for-service-comment-solicitation/</link>
		<comments>http://www.apexassurance.com/blog/2007/07/10/niap-ccevs-fee-for-service-comment-solicitation/#comments</comments>
		<pubDate>Wed, 11 Jul 2007 01:48:22 +0000</pubDate>
		<dc:creator>Ray Potter</dc:creator>
		
	<category>Common Criteria</category>
		<guid>http://www.apexassurance.com/blog/2007/07/10/niap-ccevs-fee-for-service-comment-solicitation/</guid>
		<description><![CDATA[	In case you missed it, there is a draft policy for the fee-for-service validation model from NIAP CCEVS. Details can be found at the NIAP CCEVS website.

]]></description>
			<content:encoded><![CDATA[	<p>In case you missed it, there is a draft policy for the fee-for-service validation model from NIAP CCEVS. Details can be found at the <a href="http://www.niap-ccevs.org/cc-scheme/" target="_new">NIAP CCEVS website</a>.
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.apexassurance.com/blog/2007/07/10/niap-ccevs-fee-for-service-comment-solicitation/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>Breaking the silence&#8230; sort of</title>
		<link>http://www.apexassurance.com/blog/2007/06/13/breaking-the-silence-sort-of/</link>
		<comments>http://www.apexassurance.com/blog/2007/06/13/breaking-the-silence-sort-of/#comments</comments>
		<pubDate>Thu, 14 Jun 2007 02:59:51 +0000</pubDate>
		<dc:creator>Ray Potter</dc:creator>
		
	<category>Apex Assurance Group</category>
		<guid>http://www.apexassurance.com/blog/2007/06/13/breaking-the-silence-sort-of/</guid>
		<description><![CDATA[	Has it really been almost two months since the last post? Wow. I&#8217;m sure your RSS reader is freaking out&#8230; and no, it doesn&#8217;t have a bug. 
	Anyway, things have been extremely busy lately, and I&#8217;ve been thinking about the blog. Just not writing. Customers come first, then the company, then the blog. The first [...]]]></description>
			<content:encoded><![CDATA[	<p>Has it really been almost two months since the last post? Wow. I&#8217;m sure your RSS reader is freaking out&#8230; and no, it doesn&#8217;t have a bug. </p>
	<p>Anyway, things have been extremely busy lately, and I&#8217;ve been thinking about the blog. Just not writing. Customers come first, then the company, then the blog. The first two are completely consuming us. </p>
	<p>And believe me, there are many interesting things going, and I&#8217;m hoping you&#8217;ll see several big announcements soon. </p>
]]></content:encoded>
			<wfw:commentRSS>http://www.apexassurance.com/blog/2007/06/13/breaking-the-silence-sort-of/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>Security at Airline Kiosks</title>
		<link>http://www.apexassurance.com/blog/2007/04/20/security-at-airline-kiosks/</link>
		<comments>http://www.apexassurance.com/blog/2007/04/20/security-at-airline-kiosks/#comments</comments>
		<pubDate>Fri, 20 Apr 2007 17:30:15 +0000</pubDate>
		<dc:creator>Ray Potter</dc:creator>
		
	<category>Security</category>
		<guid>http://www.apexassurance.com/blog/2007/04/20/security-at-airline-kiosks/</guid>
		<description><![CDATA[	I was traveling this week and had an interesting encounter. 
	The first leg of my flight was delayed, and I was going to miss my connection. I was rebooked on another airline, and I went to the desk to get my boarding pass. Since the booking was just made, I wasn&#8217;t able to self-check-in at [...]]]></description>
			<content:encoded><![CDATA[	<p>I was traveling this week and had an interesting encounter. </p>
	<p>The first leg of my flight was delayed, and I was going to miss my connection. I was rebooked on another airline, and I went to the desk to get my boarding pass. Since the booking was just made, I wasn&#8217;t able to self-check-in at the kiosk. The terminals behind the desk were all being used, and an airline representative was kind enough to step out and offer some help. </p>
	<p>So get this&#8230; she taps three times on the touchscreen near this particular airline&#8217;s logo. She is presented with a login prompt, and the kiosk displays a full touchscreen keyboard. She enters a 4 digit number (which wasn&#8217;t masked). Then she&#8217;s prompted for the password. She types in a 6 character password that was quite easy to &#8220;shoulder surf&#8221; given the size of the keyboard and the fact that the letters are animated when touched. </p>
	<p>And I think I know the name of one of her pets. Or the street she lives on. </p>
	<p>Anyway, on the screen, a full-featured GUI is presented. She mentioned that she is able to do all the things that they normally do behind the desk via this interface. Rebookings, upgrades&#8230; it was all there. Amazing! Of course, I joked with her about putting me in for an upgrade, but considering it was a 50 minute flight, it really wouldn&#8217;t be worth it. </p>
	<p>Anyway&#8230;. very interesting stuff. Who, besides Johnny Long, would have thought?!?
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.apexassurance.com/blog/2007/04/20/security-at-airline-kiosks/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>New FIPS 140-2 Lab</title>
		<link>http://www.apexassurance.com/blog/2007/04/16/new-fips-140-2-lab/</link>
		<comments>http://www.apexassurance.com/blog/2007/04/16/new-fips-140-2-lab/#comments</comments>
		<pubDate>Mon, 16 Apr 2007 13:38:32 +0000</pubDate>
		<dc:creator>Ray Potter</dc:creator>
		
	<category>FIPS 140</category>
		<guid>http://www.apexassurance.com/blog/2007/04/16/new-fips-140-2-lab/</guid>
		<description><![CDATA[	There is a new FIPS 140 Testing Laboratory: ACTL: authsec Conformance Testing Laboratory. This brings the total to 14 labs. 
	With the NIST queue for review standing at about 5 months, I do wish NIST would enlist the help of the labs to assist with the validation component. The increased timeline has been quite frustrating [...]]]></description>
			<content:encoded><![CDATA[	<p>There is a new FIPS 140 <a href="http://csrc.nist.gov/cryptval/1401labs.htm" target="_new">Testing Laboratory</a>: <a href="http://www.authsec.com/" target="_new">ACTL: authsec Conformance Testing Laboratory</a>. This brings the total to 14 labs. </p>
	<p>With the NIST queue for review standing at about 5 months, I do wish NIST would enlist the help of the labs to assist with the validation component. The increased timeline has been quite frustrating for our customers, and I&#8217;m working up a proposal for an operations plan to help NIST with this issue.
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.apexassurance.com/blog/2007/04/16/new-fips-140-2-lab/feed/</wfw:commentRSS>
	</item>
		<item>
		<title>Here&#8217;s the update</title>
		<link>http://www.apexassurance.com/blog/2007/04/10/heres-the-update/</link>
		<comments>http://www.apexassurance.com/blog/2007/04/10/heres-the-update/#comments</comments>
		<pubDate>Tue, 10 Apr 2007 17:29:01 +0000</pubDate>
		<dc:creator>Ray Potter</dc:creator>
		
	<category>Uncategorized</category>
		<guid>http://www.apexassurance.com/blog/2007/04/10/heres-the-update/</guid>
		<description><![CDATA[	A customer poked fun at me for not updating the blog as often as in the past. Of course, he was just kidding because he knows how busy we&#8217;ve been, but I did promise an update. So here goes. 
	This story requires two inputs:
	
	My two year old daughter loves Dr. Seuss&#8217; Hop on Pop, and [...]]]></description>
			<content:encoded><![CDATA[	<p>A customer poked fun at me for not updating the blog as often as in the past. Of course, he was just kidding because he knows how busy we&#8217;ve been, but I did promise an update. So here goes. </p>
	<p>This story requires two inputs:</p>
	<ol>
	<li>My two year old daughter loves Dr. Seuss&#8217; <em>Hop on Pop</em>, and we read it together about a week ago. </li>
	<li>I talk in my sleep. Weird, random, and usually coherent streams of unconsciousness pour out uncontrollably (and usually quite humorously). </li>
	</ol>
	<p>This morning my wife asked, &#8220;Do you remember what you said last night?&#8221; That question is usually followed by the most intense feeling of nervous anticipation you can imagine. </p>
	<p>Well, apparently I quoted about 1/4 of Hop on Pop. <em>Really quickly.</em> Then I followed with, &#8220;Of course, I&#8217;m not reading this. I&#8217;m just reciting it.&#8221;</p>
	<p>So what&#8217;s this have to do with security?</p>
	<p>Nothing. But it&#8217;s pretty darn funny. </p>
	<p>Consider the blog updated.
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.apexassurance.com/blog/2007/04/10/heres-the-update/feed/</wfw:commentRSS>
	</item>
	</channel>
</rss>
