NASA employee background checks can continue
POSTED: 6:28 PM WED, JANUARY 19, 2011
BY ASSOCIATED PRESS
WASHINGTON — The Supreme Court on Wednesday refused to stop federal investigations into the private lives of people who want to work at government installations — even those who don’t have security clearances and don’t work on secret projects.
The high court turned away challenges to background checks of low-risk employees at NASA’s Jet Propulsion Laboratory in California, despite claims from those federal contractors that the investigations were unconstitutional because they invaded their privacy.
“We reject the argument that the government, when it requests job-related personal information in an employment background check, has a constitutional burden to demonstrate that its questions are ‘necessary’ or the least restrictive means of furthering its interests,” Justice Samuel Alito said.
Employees said the agency was invading their privacy by requiring investigations that looked into their medical records and asked friends about their finances and sex lives. If the workers didn’t agree to the checks and fill out questionnaires on Standard Form 85 (SF-85) and Form 42, they were to be fired.
The Jet Propulsion Laboratory is NASA’s premier robotics lab, famous for sending unmanned spacecraft to Mars and the outer solar system. Unlike other NASA research centers, it’s run by the California Institute of Technology.
Lab scientists, engineers and staff are Caltech employees, but the campus and its buildings are owned by NASA.
A federal judge originally refused to stop NASA’s background checks while the lawsuit made its way through the courts. He was overturned by the 9th U.S. Circuit Court of Appeals in San Francisco.
Alito wrote, in a unanimous judgment for the Supreme Court, that the justices were not ruling on whether there was a constitutional right to “informational privacy.”
“We hold, however, that whatever the scope of this interest, it does not prevent the government from asking reasonable questions of the sort included on SF-85 and Form 42 in an employment background investigation that is subject to the Privacy Act’s safeguards against public disclosure,” Alito said.
None of the workers who sued work on classified projects or have security clearances, though several are involved in high-profile missions, including the twin Mars rovers and the Cassini spacecraft studying Saturn and its moons.
The government has been doing background checks on all civil service employees since 1953.
In 2007, NASA extended background checks for federal employees to its contract workers in response to a presidential directive that ordered government agencies to tighten security at facilities and computer systems by issuing new identification badges for millions of civil servants and contractors. The directive came in response to the terrorist attacks on Sept. 11, 2001.
“Form 42 alone is sent out by the government over 1.8 million times annually,” Alito said.
In concurring judgments, Justices Antonin Scalia and Clarence Thomas said they had simpler reasons for deciding against the NASA contract employees. “A federal constitutional right to ‘informational privacy’ does not exist,” Scalia said.
Alito said this case was not appropriate for answering that question. “We therefore decide the case before us and leave broader issues for another day,” he said.
The case is NASA v. Nelson, 09-530.
Blog focuses on Linux, open source software, cyber security, futuring, innovation, systems engineering, Africa, and other items related to technology.
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
Sunday, January 23, 2011
Friday, December 31, 2010
10th European Conference on Information Warfare and Security
Preparing a paper for this conference. As the new year is upon us my goal is to obtain more scholarly papers and conduct more research than 2010. Please see below for more information.
The Institute of Cybernetics at the Tallinn Universityof Technology, Tallinn, Estonia 7-8 July 2011 | |||||||
| |||||||
Thursday, April 8, 2010
Securing the SDLC: A Business Perspective from (ISC)2 TV
Great video on the SDLC and why software assurance is important.
(ISC)2 Certified Secure Software Lifecycle Professional (CSSLP)
(ISC)2 has a new certification titled Certified Secure Software Lifecycle Professional (CSSLP) which covers the following domains below:
- Secure Software Concepts - security implications in software development
- Secure Software Requirements - capturing security requirements in the requirements gathering phase
- Secure Software Design - translating security requirements into application design elements
- Secure Software Implementation/Coding - unit testing for security functionality and resiliency to attack, and developing secure code and exploit mitigation
- Secure Software Testing - integrated QA testing for security functionality and resiliency to attack
- Software Acceptance - security implication in the software acceptance phase
- Software Deployment, Operations, Maintenance and Disposal - security issues around steady state operations and management of software
Tuesday, September 8, 2009
Cyber Security Engineer Career Outlook & Info
Taken directly from website:
Outlook & Growth
This career is expected to grow 27 percent—faster than average—through 2016. An increase in computer security jobs is expected as technology continues to advance and become more affordable. More businesses will add computers and will need specialists to make their networks secure.
In addition, use of the Internet by businesses should increase the demand for computer security specialists. Some specialists will work inside consulting firms dedicated exclusively to computer security issues.
Salary & Wages
Those in executive roles—with titles such as chief information security officer, chief security officer or security manager—earned $106,326 on average. Those in more technical roles (security engineer, security penetration tester or web security manager) earned an average of $75,275.
What is a Cybersecurity Specialist?
Computer security specialists work with companies to build secure computer systems. They question managers and staff about their current security methods. They find out what information the company wants to protect. Specialists also learn what information employees should be able to access. Computer security specialists use their findings to plan the security system. They regularly train staff on how to use security software and properly use computers to prevent any problems.
Some computer security specialists write rules and procedures for employees to follow. In some companies, specialists coordinate security for vendors and customers in addition to employees. Specialists evaluate security breaks and determine if there are problems or errors. If there is a problem, specialists track where the break came from and shut off the access point.
Education & Degree Path
There are many ways to become a computer security specialist. Many employers prefer to hire people with some formal college education. A bachelor’s degree in computer science or information systems is excellent preparation for this occupation. Another route is to major in your area of interest and minor in computer science.
Bachelor’s degrees in computer security—also called information assurance—are available online.
An important part of preparing for this field is learning the latest technology. Some people learn through classes and others teach themselves.
Certification: As with other computer specialties, you can receive certification in certain products or groups of products, which can increase your appeal to employers.
Entering the Field: Many security specialists learn their skills on the job. They are paired with an experienced specialist who teaches them the job. This type of training can take between one and two years. The military has become a leading trainer in this specialty area. If you have skills and employment in any technical aspect of computers—repair, database and office systems—you can retrain to specialize in cybersecurity.
Career Changers: Many enter this field after working at a related computer specialty, such as programming or web mastering or network administration. You can re-tool quickly by earning a certificate or taking courses in cybersecurity or information assurance.
Career Links
ISC)2 (professional information security certifications)
The SANS 2005 Information Security Salary and Career Advancement Survey
Datamation magazine
CIO Insight magazine
Outlook & Growth
This career is expected to grow 27 percent—faster than average—through 2016. An increase in computer security jobs is expected as technology continues to advance and become more affordable. More businesses will add computers and will need specialists to make their networks secure.
In addition, use of the Internet by businesses should increase the demand for computer security specialists. Some specialists will work inside consulting firms dedicated exclusively to computer security issues.
Salary & Wages
Those in executive roles—with titles such as chief information security officer, chief security officer or security manager—earned $106,326 on average. Those in more technical roles (security engineer, security penetration tester or web security manager) earned an average of $75,275.
What is a Cybersecurity Specialist?
Computer security specialists work with companies to build secure computer systems. They question managers and staff about their current security methods. They find out what information the company wants to protect. Specialists also learn what information employees should be able to access. Computer security specialists use their findings to plan the security system. They regularly train staff on how to use security software and properly use computers to prevent any problems.
Some computer security specialists write rules and procedures for employees to follow. In some companies, specialists coordinate security for vendors and customers in addition to employees. Specialists evaluate security breaks and determine if there are problems or errors. If there is a problem, specialists track where the break came from and shut off the access point.
Education & Degree Path
There are many ways to become a computer security specialist. Many employers prefer to hire people with some formal college education. A bachelor’s degree in computer science or information systems is excellent preparation for this occupation. Another route is to major in your area of interest and minor in computer science.
Bachelor’s degrees in computer security—also called information assurance—are available online.
An important part of preparing for this field is learning the latest technology. Some people learn through classes and others teach themselves.
Certification: As with other computer specialties, you can receive certification in certain products or groups of products, which can increase your appeal to employers.
Entering the Field: Many security specialists learn their skills on the job. They are paired with an experienced specialist who teaches them the job. This type of training can take between one and two years. The military has become a leading trainer in this specialty area. If you have skills and employment in any technical aspect of computers—repair, database and office systems—you can retrain to specialize in cybersecurity.
Career Changers: Many enter this field after working at a related computer specialty, such as programming or web mastering or network administration. You can re-tool quickly by earning a certificate or taking courses in cybersecurity or information assurance.
Average pay for average Cyber Security Engineer were in Chantilly, VA was $116,000 In USD as of Sep 8, 2009
Career Links
ISC)2 (professional information security certifications)
The SANS 2005 Information Security Salary and Career Advancement Survey
Datamation magazine
CIO Insight magazine
Thursday, August 20, 2009
Google DC Talks: "Developing a Natl Cybersecurity Strategy"
Google talks about the national security threats we are facing today and potential threats in the future. In this they talk about the Pentagon's new establishment of a Cyber Security Command which is directly tied to President Obama's Cyber Security Act of 2009. Also note there is already a DoD 8570 Manadate for Security Professionals requiring certain certifications to be employeed on a DoD contract which impacts contractors, military, and DoD Civilians.
Subscribe to:
Posts (Atom)

