Showing posts with label government. Show all posts
Showing posts with label government. Show all posts

Thursday, December 19, 2019

Red Hat JBoss EAP 7.2 secures Common Criteria Certification to deliver solutions for regulated industries

Red Hat, provider of open source solutions, announced Red Hat JBoss Enterprise Application Platform (JBoss EAP) 7.2 has been awarded Common Criteria Certification at Evaluation Assurance Level (EAL) 4+ by the Italian Common Criteria scheme Organismo di Certificazione della Sicurezza Informatica (OCSI). 

The certification provides government agencies, financial institutions, and customers in other security-sensitive and regulated environments the assurance and confidence that JBoss EAP 7.2 meets government security standards.


This achievement demonstrates Red Hat’s position in technology and security. This is the third time JBoss EAP has achieved Common Criteria certification. 

JBoss EAP 7 is built to provide simplified deployment and full Java EE performance for applications in any environment. Whether on-premise or in virtual, private, public and hybrid clouds, JBoss EAP features a modular architecture that starts services only as they are required. JBoss EAP 7 is built for performance and flexibility in modern application environments. Its modular architecture and services-driven set of components reduces scale-out times and provides flexibility for applications deployed in different environments.

In 2015, JBoss EAP 6.2 also achieved recognition at the EAL4+ assurance level. Red Hat’s latest certification will be recognized by all countries under the Common Criteria Recognition Arrangement (CCRA) at Evaluation Assurance Level 2 since there is no generally agreed criteria for higher assurance levels.


The Common Criteria is an internationally recognized set of standards used by the federal government and organizations to assess the security and assurance of technology offerings. EAL categorizes the depth and rigor of the evaluation, and EAL4+ assures consumers that the software has been methodically designed, tested, and reviewed to meet the evaluation criteria.

Red Hat worked with atsec information security, a government accredited laboratory in the United States, Germany, Sweden, Singapore and Italy to complete the certification. atsec tested and validated the security, performance and reliability of the solution against the Common Criteria Standard for Information Security Evaluation (ISO/IEC 15408) at EAL4+.

"We're exceptionally proud that Red Hat JBoss Enterprise Application Platform again has achieved the Common Criteria Certification. It is important that our customers know they are getting the highest standard of security when they use JBoss EAP,  especially those in highly regulated industries,” said Paul Smith, senior vice president and general manager, Public Sector, Red Hat. “Common Criteria accreditation is a rigorous security standard and means customers can confidently trust Red Hat with sensitive applications, services and data. Repeatedly achieving this accreditation is a key value of the Red Hat subscription, and one that differentiates enterprise-class open source, and proves our on-going dedication to providing top solutions to security-conscious customers." 

Thursday, December 12, 2019

SolarWinds Orion Suite v4.0 experiences Common Criteria Evaluation that includes Server Configuration Monitor, Log Analyzer

SolarWinds announced that the SolarWinds Orion Suite for Federal Government v4.0 is undergoing evaluation for Common Criteria to Evaluation Assurance Level (EAL) 2+ under the Netherlands Scheme for Certification in the Area of IT Security (NSCIB). 


The Common Criteria is an international set of guidelines and specifications designed to ensure information security products meet agreed-upon security standards for government deployments in 30 nations. Conformance is verified through laboratory evaluation and scheme certification.


SolarWinds SCM is designed to detect, track, and compare system and application changes. SolarWinds Log Analyzer allows IT professionals to collect, consolidate and manage logs. Both products are built on the SolarWinds Orion Platform, which provides a unified view and full visibility into the performance and availability of an IT environment.


“SolarWinds continues to invest in both the security of its IT products and new product development to better meet the needs of IT professionals in the public sector,” said Sandy Orlando, senior vice president of product, SolarWinds. “This year, two new products that are part of the Orion Suite, Server Configuration Monitor (SCM) and Log Analyzer, are undergoing Common Criteria evaluation for the first time.”

Intel Research recognizes digital skills gap slowing Industry 4.0 in the manufacturing sector

Intel released Thursday results of a new study “Accelerate Industrial,” which represents comprehensive view of Industry 4.0, the digital transformation of the manufacturing sector. The research uncovered a serious skills gap that most Western industrial production training programs and government investment initiatives fail to address.

The study found that current leaders need to create tomorrow’s future-ready workforce. This requires the collaboration of universities, government and industry – including initiatives that focus on worker training for the transforming manufacturing sector.



“Accelerate Industrial” was conducted and authored by Dr. Faith McCreary, a principal engineer, experience architect and researcher at Intel, in tandem with Dr. Irene Petrick, senior director of Industrial Innovation for Intel’s Industrial Solutions Division. The study encompasses mobile ethnographies and interviews with over 400 manufacturers and the ecosystem technologists that support them. The work is being released as a series of reports.

A recent Deloitte/Manufacturing Institute study suggests that industries are entering a period of acute long-term labor shortages, with a shortfall in manufacturing expected to be 2.4 million job openings unfilled by 2028, resulting in a $2.5 trillion negative impact on the U.S. economy. Germany and Japan, two other developed economies, are expected to fare even worse in terms of this projected labor shortage.


With the increasing proliferation of data, connectivity and processing power at the edge, the industrial internet of things is becoming more accessible. However, successful adoption remains out of reach for many: two of three companies piloting digital manufacturing solutions fail to move into large-scale rollout.

The study uncovered the top five challenges cited by respondents that have the potential to derail investments in smart solutions in the future, with 36 percent citing “technical skill gaps” that prevent them from benefiting from their investment; 27 percent expect “data sensitivity” from increasing concerns over data and IP privacy, ownership and management; 23 percent found that they lack interoperability between protocols, components, products and systems; 22 percent citing security threats, both in terms of current and emerging vulnerabilities in the factory; and 18 percent reference handling data growth in amount and velocity, as well as sense-making.


“Accelerate Industrial” points to the rising importance of the digital skills required to navigate and succeed in this new landscape.

The research found that while there is a big appetite for digital transformation – 83 percent of companies plan to make investments in smart factory technologies – the most important skills and characteristics cited for that transformation are not ones that are typically emphasized by most industry job training programs or relevant policymakers.

Future skills cited by respondents point to the need to go beyond the basics of programming to embrace a deep understanding of digital tools, from data collection to analytics and real-time feedback directly to the operating environment. 

The top five future skills required to support digital transformation in manufacturing are “Deep understanding” of modern programming or software engineering techniques; “digital dexterity,” or the ability to leverage existing and emerging technologies for practical business outcomes; data science; connectivity, and cybersecurity.

Sunday, December 8, 2019

Abside Networks debuts new private LTE user device powered by Sequans’ Cassiopeia LTE-advanced chip platform

Sequans Communications announced that Abside Networks has introduced its second end user device based on Sequans’ Cassiopeia LTE-advanced technology.  The Ravelin Gen3 uE is a Class 1 FR1 uE designed to operate in specialized, non-3GPP frequency LTE networks and Sequans modified its Cassiopeia technology to allow operation on non-standard frequencies. 


The rugged design of the Ravelin Gen3 uE combined with the customizations of Sequans have resulted in a high-performance solution that is now available to Abside’s private LTE customers. The Ravelin Gen3 uE is a highly integrated, multi-band product designed to replace the non-homogenous technologies currently used in defense, PMR, and private network ecosystems.

The Abside Networks’ Ravelin Gen3 uE is the second device to come to mass market via the Abside/Sequans collaboration. The Ravelin Gen3 a high power (+1Watt / +30 dBm) ruggedized IP54, extended temperature (70℃) uE operating across multiple non-3GPP bands in either FDD or TDD modes and supporting LTE standard bandwidths of 1.4, 3, 5, 10, 15, and 20 MHz. Ravelin Gen3 is also designed to counter interferences from challenging radio environments. 

In addition, Ravelin Gen3 is fully interoperable with Bastion, the Abside eNodeB infrastructure that also supports non-3GPP LTE frequency ranges of 1780 to 1850 MHz, 2200 to 2300 MHz, and 4400 to 5000 MHz for a combination of more than 760 MHz of total addressable spectrum across 16 LTE bands. 


The Ravelin Gen3 peak data rates are DL 150 Mbps with 2X2 MIMO, and UL 50 Mbps with 1X2 MIMO. The Ravelin Gen3 is 73mm x 34mm x 148mm and ~750 gr.

The Ravelin-G is based on Sequans’ Cassiopeia LTE Cat 6 Platform, a member of Sequans’ StreamrichLTE product family for high performance devices. The work with Abside is one of the development Sequans has undertaken as part of its Custom Technology Solutions initiative where Sequans experts have addressed some difficult communications challenges. 

In addition to private network LTE, Sequans has adapted its technology for projects in aviation, transportation, satellite, and government.

Keysight, Marvin Test Solutions come together to speed manufacturing of mmWave semiconductors

Keysight Technologies announced this week that its collaboration with Marvin Test Solutions Inc. (MTS) – a supplier of functional test solutions – has resulted in the development of a fast and accurate 5G semiconductor manufacturing test platform.

The two parties focused on advancing beamformer integrated circuit (IC) test technology to help manufacturers of semiconductors accelerate the production of high performance 5G integrated ICs. Marvin integrated Keysight’s PXIe-based Vector Network Analyzer (VNA) to achieve accurate and fast measurements in its TS-960e-5G mmWave Test System.


The Keysight M980xA PXIe Vector Network Analyzer (VNA) meets the most demanding multiport challenges with a true multiport architecture that offers exceptional performance no matter how many ports you use. Gain deeper insights into devices with the widest available line of measurement applications for PXI VNAs, including spectrum analysis and noise figure measurements.

The M980xA Series offers the performance required for testing passive components, amplifiers, mixers or frequency converters. It provides key PXI VNA specifications such as dynamic range, measurement speed, trace noise and temperature stability. 


Keysight’s recently introduced M980xA Series network analyzers offer the scalability required to test multi-port components, front end modules (FEMs) and base stations that rely on beamforming technology. Mobile operators are deploying beamforming technology to extend cellular coverage and deliver higher data rates, leading to improved mmWave 5G network reliability and efficiency. 

To ensure reliable and efficient 5G mmWave communications, the performance of critical elements that form part of the beamformer IC need to be rigorously tested under linear and nonlinear conditions across the entire workflow from design, validation to manufacturing.


“Our collaboration with Marvin Test Solutions demonstrates that scalable production testing of beamformer solutions can be achieved with Keysight’s PXI VNAs,” said Kailash Narayanan, vice president and general manager of Keysight's wireless test group. “We’re excited to help shape the future of 5G mmWave production testing with our beamformer IC test solutions using integrated component and system-level simulation tools to deliver high precision measurements at mmWave frequency bands.”

Thursday, December 5, 2019

Synack report showcases rapid growth, almost four times, in crowdsourced security testing for compliance

Synack released a new report Wednesday detailing a major cultural shift taking part among some of the world’s largest organizations and institutions. The 2020 State of Compliance and Security Testing Report reveals that a large percentage of organizations and institutions are moving toward a rigorous, continuous testing model to ensure compliance. 

As part of this shift toward continuous testing, organizations are utilizing crowdsourced security testing to achieve regulatory compliance and real security, with adoption expected to increase four-fold in 2020.

With new compliance frameworks such as GDPR and CCPA increasing the cost of a breach, organizations are racing to protect their data. In an increasingly connected, highly regulated and digital world, business leaders and decision makers are turning to outside vendors that can ramp up quickly in a cost effective manner. 


As a result, the crowdsourced security testing space--which has already gained credibility for its significantly better ROI than more traditional, less frequent, and less secure methods--has surpassed all estimates and will continue to do so in 2020 and beyond.

For the report, Synack surveyed leaders from more than 300 organizations representing a number of industries and verticals, including technology, government, healthcare, information technology, and financial services. 

In addition to helping identify a set of security and compliance best practices for a diverse set of industries, the report found security testing is becoming part of an organization’s normal routine rather than a once-a-year check of the box focused only on compliance. 


44 percent of organizations and institutions surveyed are performing security tests on a monthly or weekly basis, which suggests they are moving toward the more effective continuous model that crowdsourced solutions enable.

Other findings include 63 percent of organizations agree that the most common use case for external vendors is to identify and reduce vulnerabilities, which is encouraged by different compliance frameworks and best practice standards; 52 percent of organizations experience unwanted cost and complexity due to overlap in functionality from using multiple security vendors, which is caused by poor budget allocation and overlap in vendor capabilities; and 32 percent of compliance testing processes are expensive and difficult to scale, yet crowdsourced security testing solutions provide 147 percent higher ROI than a typical pen test and may decrease the burden of testing on organizations by reducing signal-noise ratio.

Sunday, November 24, 2019

Kaspersky predicts advanced persistent threats in 2020, with abuse of personal information, sophisticated attacks leading the pack

Kaspersky researchers have shared their predictions on Advanced Persistent Threats (APTs) in 2020, pointing out some of the ways the landscape of targeted attacks could change in the coming months. 

The overall trend shows that threats will grow in sophistication and become more targeted, diversifying under the influence of external factors, such as the development and propagation of machine learning, technologies for deepfake development, and tensions around trade routes between Asia and Europe.

The predictions were developed based on changes that the Global Research and Analysis Team witnessed over 2019, and are an effort to help the cybersecurity community prepare for the challenges that lie ahead in the coming year.


Other targeted threat predictions for 2020 include false flag attacks reach a whole new level. These attacks will develop further, with threat actors seeking not only to avoid attribution but also to actively lay the blame on someone else. Commodity malware, scripts, publicly available security tools and administrator software, mixed with a couple of false flags, where security researchers are hungry for any small clue, might be enough to divert suspected authorship to someone else.

Attackers will focus more on organizations that are likely to make substantial payments in order to recover their data. A potential twist might be that, instead of making files unrecoverable, threat actors will threaten to publish data that they have stolen from the victim company. As banks will be required to open their infrastructure and data to third parties who wish to provide services to bank customers, it is likely that attackers will seek to abuse these new mechanisms with new fraudulent schemes.


Determined threat actors have, for some time, been extending their toolsets beyond Windows, and even beyond PC systems. VPNFilter and Slingshot, for example, targeted networking hardware. New attacks could hit regions including Turkey, East and South Europe and East Africa. Possible scenarios include a growth in political espionage as governments seek to secure their interests at home and abroad. They could extend also to technological espionage in situations of economic crisis and instability.

With new interception capabilities and data exfiltration methods, use of supply chains will continue to be one of the most difficult delivery methods to address. It is likely that attackers will continue to expand this method through manipulated software containers, for example, and abuse of packages and libraries.

There are no good reasons to think this will stop any time soon. However, due to the increased attention given to this subject by the security community, the number of attacks being identified and analyzed in detail will also increase.

Personal information abuse grows, armed with AI. It is very similar to some of the techniques used for driving election advertisements through social media. This technology is already in use and it is just a matter of time before some attackers take advantage of it.


“The future holds so many possibilities that there are likely to be things that are not included in our predictions. The extent and complexity of the environments in which attacks play out offer so many possibilities,” said said Vicente Diaz, security researcher at Kaspersky. “In addition, no single threat research team has complete visibility of the operations of APT threat actors. We will continue to try and anticipate the activities of APT groups and understand the methods they employ, while providing insights into their campaigns and the impact they have.”

Monday, November 4, 2019

QliqSOFT post-acute visit management app offers business-enhancing delivery-data for hospice and home healthcare agencies

QliqSOFT has launched on Monday VisitPath, its home health nurse distress notification-enabled mobile care-delivery app designed to provide hospice and post-acute business administration with data that improves business and patient outcomes. Additionally, Visit Path puts safety in the hands of the home health nurse. 

The Visit Path web-based administrator’s dashboard integrates with GPS-enabled smart devices to ensure patient care delivery is optimized, on time and recorded. This, along with the ability to manage unscheduled and after-hours visits, improves patient and home health nurse satisfaction, patient outcomes, billing accuracy and a digital record that prevents ensures government reimbursements are never penalized.



As a real-time, GPS-enabled care management delivery solution, Visit Path verifies where and when a hospice or home health field nurse is on duty, begins service for a client, when they complete service and when they are off duty. This verification of service is the basis for accurate, compliant billing. The administrator's dashboard is a window into ROI.


With a focus on home health, hospice, and other post-acute verticals, QliqSOFT is excited to share the news of Visit Path to coincide with the National Hospice and Palliative Care Organization’s (NHPCO) annual Interdisciplinary Conference.

“This app is a good solution for hospice and home healthcare agencies that want more insight into their care delivery data to reduce costs and improve their business outcomes," says QliqSOFT founder and CEO Krishna Kurapati. “Additionally, the distress notification provides safety and security for nurses while visiting homes and if they should run into trouble while in transit between visits.”


“We wanted to provide hospice and home healthcare agencies with a product that gives them real-time knowledge of completed patient visits activity to help them better manage their field staff,” Krishna added. 

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...