Homepage

Free resources for programming, hacking & cyber security help
Welcome to Hacker Hours!
This is a community for young programmers all over the world to share experiences, cooperate and have fun. As a wiki, this site allows anyone to join and contribute content. All are welcome! Before you post anything, be sure to read about our licensing.
You may want to start by checking this list of our members’ projects.
If you’re still learning about programming, check our programming language articles, with advice and links. Or perhaps you’d rather read about our thoughts on Good or Bad programming style?
A returning member, or just curious by nature? There is a Resources page with more …resources.
Feeling lost? Check our latest articles.
FISMA Law vs. Home Email Server
Working for a federal agency that has IT functions regulated by public law and running an email server from home to use for agency business…
APT vs. OODA Security Controls
Advanced Persistent Threat (APT) is a kind of attack comes from a team with advanced skills, deep resources, and specific targets. They use advanced tools…
Simple Secure Configuration Management
Configuration Management (CM) has some key controls and processes concentrated in the middle of the SDLC where configuration settings and the configuration baseline are recorded,…
Continuous Monitoring Misunderstood
Network security monitoring includes intrusion detection, audit log correlation and analysis and other methods of detecting failures of our network protections. Continuous monitoring is not…
Wireless Restrictions
AC-18 WIRELESS RESTRICTIONS (NIST SP 800-53) The organization: (i) establishes usage restrictions and implementation guidance for wireless technologies; and (ii) authorizes, monitors, controls wireless access…
Contingency Plan
Policy Business Impact Assessment (BIA) The BIA is a critical piece of the CP that establishes requirements for the strategy and procedures in the rest…
Incident Response
Federal agencies are required by law to report incidents to the US Computer Readiness Team (CERT) office in DHS and must have a formal incident…
Plan of Action and Milestones POAMs
A POAM is a plan that describes specific measures to be taken to correct deficiencies found during a security control assessment. The POAM should identify:…
Rules of Behavior
Any information security policy and Site Security Plan (SSP) should contain a section known as “Rules of Behavior” that establishes appropriate use and behavior of…
Policy and Procedure
Each of the seventeen families of security controls found in 800-53 contain a first control that requires the development of policy and procedures for that…