Showing posts with label standards. Show all posts
Showing posts with label standards. Show all posts

Tuesday, April 23, 2013

NIEM 3.0 Public Review

The National Information Exchange Model (the data model used by law enforcement and first responders) has made NIEM 3.0 available for public review from today until May 6, 2013. NIEM is looking for both technical and non-technical comments. If you have an opinion about this now is the time to comment

Wednesday, April 10, 2013

Cyber Security Framework Workshop, April 3, 2013

The April 3 workshop was mobbed, the Department of Commerce auditorium was filled to capicity. I assumed that it would be thinly attended like the meetings of the Federal XML work group; but there must have been something like 500 people there. Clearly people are interested and are planning on following the process very closely. I hope that means that we will build a better standard that gains broad compliance.

This workshop was designed to gain industry's perspective. The first panel had Russell Schrader of VISA, Terry Rice of Merck, Michael Paypay of Northrop Grumman, and Reid Stephan of St. Lukes Health System.

Russell Schrader of VISA described the Executive Order as sensible, and was pleased with the request for private sector feedback. He also expressed the need for international cooperation, and that there is so much more to be done.

Schrader described security as being core to VISA's brand promise. He reminded that audience that VISA as one of the founding members of the Payment Card Industry Council, and suggested that PCI offers a template for cyber security coopoeration. He described the PCI system as scalable from the small merchant to the large.

Schrader described cyber security as a continuing process, that there is no box to be checked. He described VISA's approach as Prevent, Protect, and Respond, saying that, "we try to stop trouble before it begins."

Schrader called on NIST to build on what already exists and aim for global scalability. He was especially concerned that NIST not create contradictory procedures.

He stressed the need for information sharing, and that it was necessary to create a legal framework for law enforcement. (I assume that he meant over and above the work of NEIM.)

Michael Paypay, Chief Information Security Officer for Northrup Grumman, described his work as "where the rubber meets the road". He said that it was extremely important to Northrup protect the information that the government has entrusted to them.

Paypay described the defense industry as having a collaborative approach, going on to describe himself as "representing all my aerospace brothers." He said that cyber security not an area where aerospace competes, but rather they cooperate.

Paypay observed that there is no common lexicon of roles and responsibilities in cyber security. He also said that bench-marking against other people can be a problem. He described government "best practices" as very helpful, in particular NIST 800-53.

He said that it was important to identify what is appropriate for your business, going on to say that you cannot simply protect protect your perimeter; but that it was necessary to build a layered defense, and go through each layer in order to identify risk.

Reid Stephan said that it had been an eye opening experience to join health care industry, we are catching up to other industries. He said that the National Health ISAC looks to existing standards such as the 800-30 guide to risk assessment. He suggested that it was better to integrate existing standards and best practices rather than building something from scratch. Stephan pointed out that cyber security risk management had to be balanced with business risk management, going on to say a risk based approach rather the control based approach would be more practical.

Stephan lamented the lack of robust intra and inter industry collaboration, and that the framework needs to address this sort of collaboration. He went on to observe that the cyber security framework will will never be finished, but become a dynamic standard.

Terry Rice of Merck thanked Commerce and NIST for hosting the workshop. Rice pointed out that life sciences, including pharmaceuticals, has been identified as critical infrastructure. The pharmaceutical industry is already working with DHS to protect their information.

Rice reiterated the point others had made, that cyber security is not binary - as in one is not either secure or insecure. He lamented lack of metrics for risk assessments and said that NIST is in a good position to help with this. Rice said that in 2005 the pharmaceutical industry established a not for profit organization to establish digital standard standard for a bio-pharma digital signature. He said that security required authenticity, that is non-repudiable information. He described the NIST-800-63 guidelines as useful.

He reminded the audience that the DEA has established a standard for doctors' digital signature for controlled substances. Rice also spoke about the need for anonymity for persons searching for information about sensitive medical conditions.

Rice pointed out the need for skilled workers, lamenting that computer security is not a required for computer college students.

Rice echoed others call for an international approach, for example, how would the cyber security framework apply to a foreign owner of critical infrastructure?

He said that we have to include privacy as part of the framework. In this he underscored the Executive Order's inclusion of the federal government existing privacy guidelines.

At this point Patrick Gallagher opened it up for a general discussion asking, "How do we support adoption? How should the framework think about supporting adoption?

Michael Paypay said that everyone in the company has to be trained in security. He said that Northrup Grumman's spear phishes their own employees, providing remedial training for people who get it wrong. 

Both Stephan and Rice pointed out that good compliance does not equal security. It is necessary to make sure that people understand, and you have to tread carefully when dealing with doctors.

Schrader said that you have to make sure people understand the need for security procedures.

Gallagher asked Schrader how VISA persuades its service centers and merchants be compliant. Schrader replied that VISA merchants are looking for something to implement that makes sense for their situation. 

Panelists agreed that we need safe guards around data, whether in storage and transit.

Paypay observed that not all threats are the same. DDoS not affect business like Northrup Grumman as "we don't do business through the website."

Panelists agreed on the need to establish common vulnerabilities and not create new standards where there is an existing one.

Terry Rice talked about the need for metrics to measure and manage risk.

Gallagher asked the panelists how they talked about risk, and their bosses role in risk management, "how do you make cyber secuirty relavent to the C Suite? Schrader replied, "look at the daily paper, you can't run a company without knowing about these incidents, education not necessary at VISA."

Reid Stephan said that one "can't take a fear approach." It is necessary to have a consistent process to measure risk, and establish a relationship and seen as a partner, that gets you a "seat at the table."

Michael Paypay said that at Northrup-Grumman "we are lucky because our executives understand this. Also, our customers are highly educated about cyber security- they don't have a cut and dry practice for security."

Gallagher pointed out that in the US the government does not establish cyber security standards - "how can we exploit the fact that we work together?"

Schrader said that "you don't want to codify standards" because of the continuing changes in IT.

The next Cyber Security Framework Workshop will take place in Pittsburgh from May 29 through 31

Cyber Security Framework website

Grant Gross: US NIST: Industry should lead creation of cybersecurity framework

Brian Browdie: Cybersecurity Framework Demands Input from Industry, Official Says

J. Nicholas Hoover: No Bold Moves On U.S. Cybersecurity Framework

Jason Miller: NIST, industry begin journey to develop cyber framework

Molly Bernhart Walker: NIST sorting comments on cybersecurity framework

Thursday, February 14, 2013

NIST issues RIF for Cybersecurity Framework

NIST has issued a RIF for Cybersecurity Framework (PDF), which will soon be published in the Federal Register. The Information Technology Laboratory of NIST has created a web site for Cybersecurity Framework.

Interested parties need to study the Request for Information, and make whatever response they deem appropriate. Those with questions and concerns should contact  cyberframework@nist.gov.

Most of us can content ourselves with watching the Cybersecurity Framework website. I am hoping to attend the local events.

The Cybersecurity Framework

I suggest that everyone who is interested read the Executive Order -- Improving Critical Infrastructure Cybersecurity before you read the news coverage. It is not long and is reasonably clear.

Clearly, much depends upon how this is implemented. I would encourage all those who are interested to participate in the process. Now is the time to speak out, before the Executive Order is implemented.

I would draw particular attention to Section 7:

Sec. 7. Baseline Framework to Reduce Cyber Risk to Critical Infrastructure. (a) The Secretary of Commerce shall direct the Director of the National Institute of Standards and Technology (the "Director") to lead the development of a framework to reduce cyber risks to critical infrastructure (the "Cybersecurity Framework"). The Cybersecurity Framework shall include a set of standards, methodologies, procedures, and processes that align policy, business, and technological approaches to address cyber risks. The Cybersecurity Framework shall incorporate voluntary consensus standards and industry best practices to the fullest extent possible. The Cybersecurity Framework shall be consistent with voluntary international standards when such international standards will advance the objectives of this order, and shall meet the requirements of the National Institute of Standards and Technology Act, as amended (15 U.S.C. 271 et seq.), the National Technology Transfer and Advancement Act of 1995 (Public Law 104-113), and OMB Circular A-119, as revised.

What goes into the frame work and what is left out will determine what sort of cyber culture we will live with. And by "we" I don't merely mean Americans, this framework is sure to affect the entire industry.

The Executive Order clearly  requires a consultative process that will include a public comment process. Section 5 sets for the privacy and civil liberties protections that are to be based on the Fair Information Practice Principles. Privacy and civil liberties advocates would be well advised to familiarize themselves with these principles.

I would also note the deadlines the Executive Order establishes (listed in order of the deadlines):
Within 90 days of the publication of the preliminary Framework, these agencies shall submit a report to the President, through the Assistant to the President for Homeland Security and Counterterrorism, the Director of OMB, and the Assistant to the President for Economic Affairs, that states whether or not the agency has clear authority to establish requirements based upon the Cybersecurity Framework to sufficiently address current and projected cyber risks to critical infrastructure, the existing authorities identified, and any additional authority required.
(b) If current regulatory requirements are deemed to be insufficient, within 90 days of publication of the final Framework, agencies identified in subsection (a) of this section shall propose prioritized, risk-based, efficient, and coordinated actions, consistent with Executive Order 12866 of September 30, 1993 (Regulatory Planning and Review), Executive Order 13563 of January 18, 2011 (Improving Regulation and Regulatory Review), and Executive Order 13609 of May 1, 2012 (Promoting International Regulatory Cooperation), to mitigate cyber risk. The Secretary shall coordinate establishment of a set of incentives designed to promote participation in the Program. 
Within 120 days of the date of this order, the Attorney General, the Secretary of Homeland Security (the "Secretary"), and the Director of National Intelligence shall each issue instructions consistent with their authorities and with the requirements of section 12(c) of this order to ensure the timely production of unclassified reports of cyber threats to the U.S. homeland that identify a specific targeted entity.
(c) To assist the owners and operators of critical infrastructure in protecting their systems from unauthorized access, exploitation, or harm, the Secretary, consistent with 6 U.S.C. 143 and in collaboration with the Secretary of Defense, shall, within 120 days of the date of this order, establish procedures to expand the Enhanced Cybersecurity Services program to all critical infrastructure sectors.
Within 120 days of the date of this order, the Secretary and the Secretaries of the Treasury and Commerce each shall make recommendations separately to the President, through the Assistant to the President for Homeland Security and Counterterrorism and the Assistant to the President for Economic Affairs, that shall include analysis of the benefits and relative effectiveness of such incentives, and whether the incentives would require legislation or can be provided under existing law and authorities to participants in the Program.
(e) Within 120 days of the date of this order, the Secretary of Defense and the Administrator of General Services, in consultation with the Secretary and the Federal Acquisition Regulatory Council, shall make recommendations to the President, through the Assistant to the President for Homeland Security and Counterterrorism and the Assistant to the President for Economic Affairs, on the feasibility, security benefits, and relative merits of incorporating security standards into acquisition planning and contract administration. The report shall address what steps can be taken to harmonize and make consistent existing procurement requirements related to cybersecurity.

Sec. 9. Identification of Critical Infrastructure at Greatest Risk. (a) Within 150 days of the date of this order, the Secretary shall use a risk-based approach to identify critical infrastructure where a cybersecurity incident could reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security. In identifying critical infrastructure for this purpose, the Secretary shall use the consultative process established in section 6 of this order and draw upon the expertise of Sector-Specific Agencies.

(e) Within 240 days of the date of this order, the Director shall publish a preliminary version of the Cybersecurity Framework (the "preliminary Framework"). Within 1 year of the date of this order, and after coordination with the Secretary to ensure suitability under section 8 of this order, the Director shall publish a final version of the Cybersecurity Framework (the "final Framework").
(c) Within 2 years after publication of the final Framework, consistent with Executive Order 13563 and Executive Order 13610 of May 10, 2012 (Identifying and Reducing Regulatory Burdens), agencies identified in subsection (a) of this section shall, in consultation with owners and operators of critical infrastructure, report to OMB on any critical infrastructure subject to ineffective, conflicting, or excessively burdensome cybersecurity requirements.
I trust that those tasked with creating the Framework will follow the excellent example of the Federal XML Work Group by setting up a website where the rest of us can follow their work. It is particularly important that the minutes of their meetings be posted in a timely manner and that their email discussion groups be publicly posted. This will build trust and increase the chances of a smooth adoption and implementation of whatever Framework is established.

Monday, September 07, 2009

The Organization of Legal Professionals

Via Gabe and David, we learn about the Organization for Legal Professionals.

We had naively assumed that there was already an organization that certified legal support standards. Not so it seems. This then is a welcome development.

Thursday, February 26, 2009

Why open standards are good for your health

Are we going to single payer anyway?
From an IT perspective this may actually be a benefit. If more people are moving toward plans funded by the federal government, then the government’s IT procurement decisions should be definitive in terms of standards and protocols.

If the VA, the military, Medicare and Medicaid build and re-build their IT infrastructure based on the same open standards, in other words, those become the standards the private insurance market will follow.

Assuming, of course, that the U.S. government builds to a single standard.

Sunday, January 11, 2009

Jan NCC AIIM meeting: Stephen Levenson, Administrative Office of the US Courts talks about PDF/A

Thursday, January 15, 2009
Dinner Event
Westin Arlington Gateway



PDF/A What is it and why do I want it? Get an update on the First International Conference for PDF/A held in Europe last year! You can come learn how PDF/A is being used throughout government and industry, how to lower costs, and how to exchange content. Stephen Levenson who is the international convener for this standard and Chair of the AIIM Standards Board will discuss this standard and how it fits into other standards under development through AIIM. This presentation should interest practitioners of records management, CIOs’ and General Counsels of organizations.

We will also explore:

* What is PDF/A
* Why do I want or need it?
* When does document preservation start?
* How to keep long term costs under control.
* How does this fit into and effect ECM program.

About our speaker:

Stephen Levenson is the IT Specialist for Policy and Planning for the Administrative Office of the US Courts in Washington, DC.

Wednesday, November 26, 2008

Owen Ambur talks about his work for the federal government, XML, and standards

This is the second of an occasional series of interviews with local tech leaders.

Owen Ambur recently retired from the Fish and Wildlife Service. He talks about the Federal XML Work Group, and his current work with AIIM's StratML Committee.

How did you come to work at the Fish & Wildlife Service?

After a 14-year stint on Capitol Hill with Congressman/Senator Abdnor, our election defeat became an opportunity for me to serve for 7 1/2 years as the Congressional liaison for an agency in whose mission I strongly believe.  As chief of the Office of Legislative Services, I implemented an electronic document management system and the Director of the agency asked me to take a special assignment in the Office of Information Resources Management (IRM) to expand the system agency-wide.  After spending the first two-thirds of my career in Congressional affairs, that's how I ended up in a more technical line of work -- not because of a fascination with technology but because I needed it to do my job efficiently and effectively


How did you get interested in XML?

My involvement in XML stems from my long-standing interest in document/records management and forms automation.


How was the xmlCoP formed?

Early in 2000 I sent a message to George Brundage of GSA highlighting two opportunities for the government to leverage the potential of XML.  He posted my message on a listserv he was maintaining relating to information technology architecture.  Martin Smith, who was then with the U.S. International Trade Commission (ITC), and more recently has worked at the Department of Homeland Security (DHS), suggested that I bring those ideas to the attention of the CIO Council (CIOC).  I did so and Lee Holcomb, who was then CIO at National Aeronautics and Space Administration (NASA) and co-chaired what is now the CIOC's Architecture and Infrastructure Committee (AIC), commissioned Martin and me to form an ad hoc group and come back to his committee with a recommendation.  That group recommended that a more formal working group be chartered under the auspices of the CIOC, and our first charter was approved in the fall of 2000.

The original message thread that led to formation of the XML Working Group (XML WG) is available at http://xml.gov/documents/completed/genesis.htm In September 2004, the XML WG was re-chartered as the XML Community of Practice (xmlCoP) and the history of the group is available at http://xml.gov/documents/completed/history.htm  Coincidentally, our current charter expires on November 30: http://xml.gov/documents/completed/charter.htm


How did you come to co-chair the Federal XML Work Group?

In the ad hoc group that met prior to chartering of the XML WG, I was pushing for GSA and NIST to co-chair the group, in light of their missions, and Marion Royal of GSA was subsequently assigned to serve as co-chair. However, Martin and others pressed for me to accept the other slot and it was an offer I could not refuse to do something in which I truly believe.


What do you think the Federal XML Work Group achieved?

As I told Lee and others in the CIOC, XML was going to happen regardless of whether the CIOC did anything about it or not.  It has taken longer than I had hoped and we still have a long way to go to fully capitalize on the potential in an effective and well-coordinated manner on a government-wide basis.  However, I do believe the fact that the xmlWG/CoP was formally recognized by the CIOC, met virtually every month for six years straight, and still maintains the xml.gov site has fostered awareness, education, and sharing of experiences and expertise. Hopefully, that has brought greater credibility to what is to most people a pretty esoteric subject and, in turn, has encouraged agencies to act more rapidly than might have otherwise been the case.

For example, it is somewhat ironic that the first time the xmlCoP was briefed on the Global Justice XML Data Model (GJXDM) was when Pat McCreary and Bob Greeves of the Department of Justice (DOJ) filled in at the last minute when our scheduled speaker was unable to appear due to the events of 9/11.  The agenda and minutes from that meeting are available, respectively, at http://xml.gov/agenda/20010919.htm and
http://www.xml.gov/minutes/20010919.htm  Subsequently, the GJXDM morphed into the National Information Exchange Model (NIEM), which may be the single, best success story for XML in government.

However, I cannot leave this topic without addressing what I consider to be
our greatest failure, which was the failure of Congress to approve the President's budget request for $2.1 million for the XML registry -- despite a projected return on investment (ROI) in the range of 500 - 1400 percent.
http://xml.gov/documents/completed/bah/registryBusinessCase.htm#_Toc19694635
The history of that failure is documented at http://xml.gov/registries.asp As a result, it remains far more difficult than it should be for agencies to discover and reuse XML data elements, rather than reinventing them, needlessly and perhaps inconsistently.


What is the importance of the Federal Enterprise Architecture  
Technical Reference Model
? What is its influence on the technology  
industry as a whole?


While most of the focus of the FEA has been placed on the Business Reference Model (BRM), on the theory that it is the "business" that is most important, I contend that it is impossible to truly understand our "business" without understanding the data (records) required to conduct it.  Thus, I believe there is a reason the Data Reference Model (DRM) was the last of the FEA "models" to be drafted ... because it is the only one that truly matters.

However, from my perspective, the Technical Reference Model (TRM) is the second most important -- because unless and until the relevant technical specifications are fully supported in the IT products, components, and services used to conduct We the People's business, all the talk about "interoperability" is just that ... talk.  It would be nice to think that IT vendors would "do the right thing" by coalescing around and implementing those standards.  However, the reality is that they have every incentive to continue selling us proprietary stovepipe systems as long as we are stupid enough to keep wasting the taxpayers' money on them.


Can you tell us about ET.gov? Has it been a success? Do civil servants use it?

The history of the ET.gov site/process is documented at http://et.gov/history.htm  It was commissioned by the former co-chairs of the CIOC's AIC, John Gilligan, CIO of the Air Force, and Norm Lorentz, CTO at OMB.  It was declared a "success story" in the CIOC's strategic plan for FY2007-2009.  See pages 13 & 14 (PDF pages 15 & 16) at
http://xml.gov/documents/completed/cioc/StratPlan2007-2009.pdf

The ET.gov site has been up and running for several years.  More than 100 components and specifications have been registered and are discoverable at http://et.gov/component_search.aspx as well as via IntelligenX's search service at http://etgov.i411.com/etgov/websearchservlet?toplevel=true&
About 15 of them have progressed to Stage 2 of the ET.gov process --
http://et.gov/stage2.htm#CoPs Five have reached Stage 3 --
http://et.gov/stage3.htm#CoPs -- and three have "graduated":
http://et.gov/stage4.htm  Two of those -- PDF/A and X3D -- have been incorporated into the FEA TRM.

Considering the relatively small amount of money originally allocated by EPA (when Mark Day, EPA's Deputy CIO co-chaired the CIOC/AIC's ET Subcommittee) for development of the site and the fact that no additional funding has been provided since then, it might be fair to suggest the ET.gov site/process has been a success.  However, in truth, the jury is still very much out on the questions of whether:

a) Federal agencies really do want to collaborate more efficiently and effectively together to evaluate, demonstrate, prove and implement emerging technologies, and if so,

b) they want to use the ET.gov site/process or some other as-yet-undetermined means to do so.


You once quoted one of your fellow civil servants as saying "We can't deal with vendors coming at us with intergalactic solutions." What should vendors know about approaching the federal government with an "intergalactic solution?"

Norm Lorentz, CTO at OMB, is the one who made that statement, when he and John Gilligan, asked the ET Subcommittee to develop the ET.gov site and process.  Now that he has gone over to the "dark side" again, Norm might be better qualified to answer your question than I.  However, for my part, I must confess that it still seems to me that too many folks are too easily impressed with large, slick, fancy, so-called "solutions" that are too complex for anyone, including their proprietors to fully understand, much less effectively support.

Although Frank Raines' name has been sullied in the intervening years, his name was affixed to some very good guidance given to Federal agencies more than a decade ago when he was the Director at OMB.  My favorite among the eight points that became known as "Raines' Rules" was number seven, which directed agencies to implement IT in "phased, successive chunks as narrow in scope and brief in duration as practicable, each of which solves a specific part of an overall mission problem and delivers a measurable net benefit independent of future chunks."
http://www.xml.gov/documents/completed/iea/RainesRulesRevisited_files/frame.htm

Unfortunately, it still seems to me that it is possible to fool too many of
the people too often and, thus, government agencies continue to waste far
too much of the taxpayers' money on "intergalactic solutions."  However, I
remain hopeful that such foolishness may not continue indefinitely, if for
no other reason than it is becoming clearer and clearer that "change is
coming" ... because we can no longer afford "business as usual."


Small vendors tell me all the time how they cooperated with the federal government to develop an idea, often without compensation, only to see it handed off to one of the very large well known contractors. How can they avoid that unpleasant experience?

I don't think I'm qualified to answer this question, although I will say that I do believe the Federal procurement process is badly broken. I believe the process would be vastly improved by greater openness and transparency, in contrast to the current, highly centralized and secretive process.  Perhaps the best I can suggest is that:

a) it doesn't cost anything to use the ET.gov site to identify emerging technology components, specifications, and services that may be of interest to .gov agencies, and

b) if someone uses the ET.gov process to identify something for which another vendor is subsequently paid to do work for Uncle Sam, at least the record would be clear as to who proposed it first and the government may feel some additional obligation to justify paying someone else to carry it out.


What are some of the things you would like to see the federal government do with the Web and RSS to make government more transparent and citizen centric?

First of all, as suggested in the EEIRS report, agencies should post all of their public records on their Web sites, so that they can be indexed by the search engines. http://www.cio.gov/documents/EEIRS_RFI_Response_Analysis.pdf

Second, they should specify XML schemas for all of the records, and they should post all of those schemas on their Web sites so that XML registry services can be built from the bottom up.

Third, consistent with the E-FOIA amendments, agencies should begin to create and maintain their records in XML format so that they can easily be made available in whatever formats they may be requested.
http://www.usdoj.gov/oip/foia_updates/Vol_XVII_4/page2.htm

Fourth, agencies should participate in the finalization and use of the XML schema (XSD) for the FEA DRM: http://xml.gov/draft/drm20060105.xsd  In the FEA PMO's assessment of enterprise architecture programs, agency scores on the DRM performance element should be based upon the degrees to which they have documented their data collections on their Web sites in conformance with the XSD for the DRM.

Fifth, as directed by subsection 202(b)(4) of the eGov Act, agencies should:

a) use AIIM's emerging StratML standard to explicitly identify the stakeholders for each of their strategic objectives,

b) embed in each and every one of their records a metatag(s) identifying the strategic objective(s) it supports and, thus,

c) enable the discovery of all of their records based upon the stakeholders
to which they apply.


What is StratML?

Strategy Markup Language (StratML) is an XML vocabulary and schema containing the elements that are common not only to the plans that U.S. federal agencies are required to compile and maintain under the Government Performance and Results Act (GPRA) but also to the strategic plans of all organizations.

The prospective purposes of the emerging StratML standard are outlined at
http://xml.gov/stratml/index.htm#DefinitionPurposes.  Under the auspices of AIIM, we aim to establish it as an international voluntary consensus standard for potential use by all organizations worldwide, thus enabling population of the *Strategic* Semantic Web.

In the service to the notions of citizen-centricity and the government as a single "enterprise," as well as conformance with OMB Circular A-119, it would not be unreasonable to think that OMB might require U.S. federal agencies to post their GPRA plans on their Web sites in StratML format.
http://www.whitehouse.gov/omb/circulars/a119/a119.html


How did AIIM come to be involved?

I originally approached AIIM in December 2003 because:

a) I had been a member of AIIM since 1995, and

b) AIIM was then touting itself as the "strategic content management" association and I wanted to help them make that concept real, rather than merely a marketing slogan.

The full history of StratML is documented at
http://xml.gov/stratml/index.htm#History


Why should private businesses who don't have significant federal work care about StratML?

Anyone who cares about the concept of "strategic alignment" has a stake in the success and widespread usage of StratML.  There is nothing unique or "inherently governmental" about strategic planning.  Any organization that wants to be effective must have a clear understanding about what it aims to do and how it will "align" its resources to achieve its objectives.

In times like these, it is more important than ever not only to use our own resources wisely but also to partner more efficiently and effectively with others with whom we share common objectives.  That is the essence of StratML, whose purposes are more fully outlined at
http://xml.gov/stratml/index.htm#DefinitionPurposes


Where do you see the XML industry going in the near future? Are we close to the semantic web?

There is little doubt that innovation will continue apace in the XML community.  Just as the simplicity of HTML, HTTP, and IP enabled the explosion of the Web, the relative ease with which XML enables the sharing of data means that we haven't seen anything yet by comparison to what we will soon experience.  Although the financial realities that have recently become too compelling to ignore any longer will place increasing pressure on IT budgets, those same realities increase the need to apply IT more
efficiently and effectively.  Indeed, more and better usage of technology --
particularly information technology -- is the *only* way that we can hope to avoid reliving the mistakes of the past, much less continuing progress into the future.

Regarding the semantic web, I'm not sure that the business case has been sufficiently well-established, much less that most people have any idea yet as to how they might contribute to and benefit from it.  However, I do hope that the emerging StratML standard will foster the development of a worldwide Web of organizations and individuals who choose to lead mission/goal-directed lives and seek to pursue those goals in collaboration with others who share their objectives.

Friday, November 07, 2008

SEC completes taxonomies for XBRL

Investment News

The SEC is encouraging users and creators of investment company information to review the taxonomies (see the link below).

Any comments received by Nov. 24 might be included in the final taxonomies that are to be used in mutual fund filings, starting in 2009.

Visit the SEC website to read the rule proposal on mutual fund risk-return summaries. To review and comment on the taxonomies, visit XBRL US. Visit the story “Advisers may benefit from XBRL shift” for more on how the standards will ultimately help advisers.



If you have an opinion about taxonomies for XBRL, the time to express it would be before November 24.

Friday, July 25, 2008

The Open Web Foundation

Community-Driven Specifications
At OSCON yesterday Dave Recordon, of Movable Type, announced a new nonprofit organization. The Open Web Foundation has been created to support the development and protection of non-proprietary specifications for Web technologies.

Standards for mobile banking

FSTC Establishes Mobile Standards Group
The Financial Services Technology Consortium (FSTC) has created a working group to establish mobile banking standards and best practices. The goal is to facilitate a model that allows for interoperability of a mobile payments infrastructure, according to the New York-based industry group.


If you have an opinion about this, now is the time to get involved.

Friday, April 18, 2008

Open Office XML, a Potemkin standard?

At last night’s meeting of the DC XML Users group I asked what they thought of the controversy surrounding the International Standards Organization adoption of OOXML. There was general agreement that the ISO had not covered itself in glory and that its reputation has taken a major hit. Someone mentioned this post by Tim Bray -
The important thing is this: The ISO Delta is completely irrelevant to the marketplace. It is not implemented in the shipping Microsoft products. Microsoft may choose to implement some portion of it in some future release of some product, or they may not. Given Office’s release and adoption cycle, it’s very unlikely that any pieces of the delta they decide to implement will be widely deployed in anything less than five years.

Thus, if you write OOXML software and you generate ISO-Delta markup, it won’t be usable by the deployed base of software. In fact, we have no information as to how gracefully Office will react; will it bypass such markup or explode messily? I’m not optimistic. So, implementors should not generate ISO-Delta markup.


If Bray is correct, the whole purpose of a standards organization has been defeated. It is a shame, a real shame.

Thursday, April 10, 2008

OpenTheGovernment

OpenTheGovernment.org
OpenTheGovernment.org is a coalition of journalists, consumer and good government groups, environmentalists, library groups, labor and others united to make the federal government a more open place in order to make us safer, strengthen public trust in government, and support our democratic principles.

Governance: OpenTheGovernment.org is guided by a Steering Committee (members listed below). A subset - the two co-chairs and three steering committee members - are appointed to the Executive Committee which provides day-to-day guidance, as needed, to the Directorhttp://www.blogger.com/img/gl.link.gif and assists in the development of an annual budget which is brought before the full committee for approval. Subcommittees include a nominations committee and ad hoc committees and working groups as needed.


They are participating in the StratML committee.

Wednesday, April 09, 2008

Why standards are newsworthy

There is a demonstration in Oslo against Microsoft's Open Office XML format. A demonstration for crying out loud!

Standards matter. Standard selection is vendor selection; which is why Microsoft has put so much money in persuading the International Standards Organization to accept OOXML.

The Potomac technology community is one of the most influential in standards issues. Even more than money, standards determine the direction of future technology. It is a pity local editors do not understand this.

Friday, February 08, 2008

New to me IT governance blog

Information Governance Engagement Area: The Information Governance Engagement Area has been established with the goal of aggregating key compliance, electronic discovery, and storage news for further review, study, and consideration by legal and corporate professionals. Welcome to the Information Governance Engagement Area.

Tuesday, February 05, 2008

Security Companies Agree To Testing Standards

IBM, Microsoft, McAfee, Symantec, Trend Micro, and Panda Security are among those in Spain this week hammering out details of the anti-malware group.
Despite their business differences, computer security companies are coming together to standardize testing for anti-malware products and services.

In Bilbao, Spain, on Monday, more than 40 security researchers and anti-malware testers convened to formalize the charter of a new Anti-Malware Testing Standards Organization.

Ultimately this is not a technical problem, it is a legal problem. We will have to do a better job of sending these crooks to jail.

Wednesday, January 30, 2008

ISO and OOXML

Microsoft: IBM masterminded OOXML failure
Microsoft executives have accused IBM of single-handedly leading an effort to block the software giant from having its Office Open XML standard approved by the International Organization for Standardization.

After initially being rejected by the International Organization for Standardization (ISO) in September 2007, Microsoft has a second chance for its next-generation document format to become an international standard in February at a ballot resolution meeting in Geneva.

While criticism of Microsoft's efforts to promote the standard have come from a variety of quarters, Microsoft senior director of XML technology, Jean Paoli, accused IBM of masterminding the attack.

"Let's be very clear," Paoli said. "It has been fostered by a single company — IBM. If it was not for IBM, it would have been business as usual for this standard."

Would business as usual be a good or bad thing?

Wednesday, January 23, 2008

AIIM StratML Committee

AIIM adopts StratML

The AIIM Standards Board has announced that it is adding Strategic Markup Language (StratML) to its standards program of work. AIIM, based in Silver Spring, Md., is an enterprise content management association.

Owen Ambur, former senior architect at the Interior Department, and Adam Schwartz, a program analyst in the Program Management Office at the Government Printing Office, oversaw development of that schema, which is designed to encapsulate strategic plans, performance plans and performance reports in a format based on Extensible Markup Language, the association said last week.


January 10th saw the first meeting of the AIIM StratML committee. It opened with Betsy Fanning describing the AIIM’s standard’s process. I learned that AIIM is the US representative on the International Standards Organization Technical Advisory Group. If you want to influence the industry standards in this area it is necessary to participate in this group.

Adam Schwartz opened his presentation with a brief explanation of what StratML is, from my notes: StratML is a mark up language and schema for strategic plans as well as performance plans.

StratML creates a system whereby an organization can track its plans and measure performance. It was created to comply with the Government Performance & Results Act of 1993. This calls for, amongst other things, a publicly searchable database of federal government strategic and performance plans and progress reports. Although private organizations would probably not want to make their plans public, such a language would have obvious value for their internal planning and review.

The should the standard created by the committee be accepted by AIIM, it would then be submitted to the International Standards Organization, so the work of this committee will have far reaching consequences for the entire industry.

One of the committee members asked if StratML could be related to XBRL, but there was some feeling that might be taking on too much.

The core schema has been created and incorporates GEFEG XML. Mark Logic has created a search prototype, a password in required.

AIIM members who are interested in participating in the work of this committee should contact Betsy Fanning, Adam Schwartz, or Owen Ambur.

StratML Wiki

Tuesday, January 22, 2008

The coming fight over privacy

EU Group Head Says IP is Personal
In a ruling that could have long term repercussions -- especially on the way in which search engines record and store data -- the Head of the European Union's Group of Data Privacy Regulators said IP (Internet Protocol) addresses that identify computers on the Internet should generally be regarded as personal information.

Peter Scharr, who is also the Data Protection Commissioner for Germany, was speaking at a hearing of the European Parliament on the subject of 'online data protection'. He expressly said that when someone is identified by an IP or Internet Protocol address, "then it has to be regarded as personal data".

Privacy is the next killer ap. The market isn't ready yet, but it will be.

Privacy/data protection regulators around the world