<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] category: Podcast]]></title>
    <link>http://securityratty.com/category/Podcast</link>
    <description></description>
    <pubDate>Mon, 05 May 2008 15:25:56 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Show 026 - An Interview with Adam Shostack]]></title>
      <link>http://securityratty.com/article/c33fabcf5dc8851811ed58bff76a27ea</link>
      <guid>http://securityratty.com/article/c33fabcf5dc8851811ed58bff76a27ea</guid>
      <description><![CDATA[The 26th episode of The Silver Bullet Security Podcast features Adam Shostack, a security expert on Microsofts Secure Development Lifecycle team who has also worked for Zero Knowledge and Reflective....]]></description>
      <content:encoded><![CDATA[<p><img align="right" alt="Adam Shostack" title="Adam Shostack" src="http://www.cigital.com/silverbullet/ashostack-125.gif" style="padding-left: 7px;" /></p>
<p>The 26th episode of <em>The Silver Bullet Security Podcast</em> features Adam Shostack, a security expert on Microsoft&#8217;s Secure Development Lifecycle team who has also worked for Zero Knowledge and Reflective.  Gary and Adam discuss how Adam got started in computer security, how art/literature informs Adam’s current work, and the main ideas behind Adam’s new book <em>The New School of Information Security</em>.  They go on to chat about Adam&#8217;s aversion to the term &#8220;best practices,&#8221; the role IEEE Security &#038; Privacy magazine plays in bringing the science of security to a practical level, and whether the biggest problem of the CardSystems breach was the following the letter, rather than the spirit, of PCI.  Also on the agenda, duck-billed platypuses, Kandinski, and books by Pynchon.</p>
<p>(Beginning with this episode, Silver Bullet will be available as a 192k MP3.)</p>
<ul>
<li><a href="http://www.emergentchaos.com/">Emergent Chaos blog</a></li>
<li><a href="http://www.amazon.com/New-School-Information-Security/dp/0321502787/"><em>The New School of Information Security</em></a></li>
<li><a href="http://msdn.microsoft.com/en-us/library/ms995349.aspx">Microsoft&#8217;s SDL</a></li>
<li><a href="http://www.cigital.com/justiceleague/category/software-security-touchpoints/">Cigital’s Touchpoints</a></li>
<li><a href="http://www.computer.org/portal/site/security"><em>IEEE Security &#038; Privacy magazine</em></a></li>
<li><a href="http://en.wikipedia.org/wiki/Wassily_Kandinsky">Wassily Kandinsky</a></li>
<li><a href="http://money.cnn.com/2005/06/17/news/master_card/index.htm">The CardSystems breach</a> (2005)</li>
<li><a href="http://en.wikipedia.org/wiki/Thomas_Pynchon">Thomas Pynchon</a>
</ul>
]]></content:encoded>
      <pubDate>Thu, 15 May 2008 15:17:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/role ieee security">role ieee security</category>
      <category domain="http://securityratty.com/tag/ieee security">ieee security</category>
      <category domain="http://securityratty.com/tag/security expert">security expert</category>
      <category domain="http://securityratty.com/tag/computer security">computer security</category>
      <category domain="http://securityratty.com/tag/adam">adam</category>
      <category domain="http://securityratty.com/tag/privacy magazine">privacy magazine</category>
      <category domain="http://securityratty.com/tag/privacy magazine plays">privacy magazine plays</category>
      <source url="http://www.cigital.com/silverbullet/show-026/">Show 026 - An Interview with Adam Shostack</source>
    </item>
    <item>
      <title><![CDATA[Is Virtual Security Technology A Prime Target For Acquisition?]]></title>
      <link>http://securityratty.com/article/41561c470975cace7974e729ad4f4310</link>
      <guid>http://securityratty.com/article/41561c470975cace7974e729ad4f4310</guid>
      <description><![CDATA[This week has been an interesting week in the virtual security blog world! Simon Crosby of Citrix/XenSource stated in his podcast that he felt the virtualization vendors like VMWare and Citrix didn't...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>This week has been an interesting week in the virtual security blog world!&nbsp; Simon Crosby of Citrix/XenSource <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1312793,00.html?track=sy160&amp;asrc=RSS_RSS-10_160">stated in his podcast</a> that he felt the virtualization vendors like VMWare and Citrix didn't have the competence to address the security challenges of virtualization and <a href="http://rationalsecurity.typepad.com/blog/2008/05/citrixs-crosby.html">Chris Hoff blogged</a> about it saying that the statement is a cop-out and that they should do more in securing their platforms. <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/05/render-unto-cea.html"> Alan Shimel also blogged</a> on the topic and agreed with Hoff and <a href="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/2008/05/virtualization.html">I blogged</a> about it agreeing with both Simon and Hoff.&nbsp; </p>

<p>To restate my position on it I think that Simon is correct in that virtualization vendors like VMWare and Citrix do not have the expertise today to address all of the security challenges.&nbsp; I also agree with Hoff that they should address more of the security challenges.&nbsp; So this leads me to my own opinion that some of the virtualization vendors will acquire security technologies to differentiate&nbsp; themselves from others and acquire the expertise.&nbsp; Many say that the virtualization market will become commoditized and&nbsp; that security can help protect its value.&nbsp; </p>

<p>Think about it.&nbsp; Would you rather buy a Virtual Environment or a Secure Virtual Environment?!</p>

<p>So.. Onto the topic of this blog!&nbsp; Is Virtual Security Technology A Prime Target For Acquisition?</p>

<p>I'd love your opinion so please comment!!</p>

<p>What triggered my blog on this topic was this rumor I heard today.&nbsp; Some buzz started today that one of the virtual security startups just agreed behind closed doors to be acquired by one of the big guys.&nbsp; But, who could it be?&nbsp; Reflex Security, Catbird, Blue Lane, Altor Networks, VMSight, Embotics, etc.</p>

<p>I have an idea of who it could be but don't want to spread rumors that could be false.&nbsp; The other question is whether or not there is an atmosphere of acquisition frenzy brewing in the virtualization market.&nbsp; </p>

<p>Please comment on your thoughts - Just click the comments link bellow.</p></div>
]]></content:encoded>
      <pubDate>Wed, 14 May 2008 22:12:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security challenges">security challenges</category>
      <category domain="http://securityratty.com/tag/virtual security startups">virtual security startups</category>
      <category domain="http://securityratty.com/tag/virtualization vendors">virtualization vendors</category>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/acquire security technologies">acquire security technologies</category>
      <category domain="http://securityratty.com/tag/virtual security technology">virtual security technology</category>
      <category domain="http://securityratty.com/tag/reflex security">reflex security</category>
      <category domain="http://securityratty.com/tag/acquisition">acquisition</category>
      <source url="http://feeds.feedburner.com/~r/SecurityInTheVirtualWorld/~3/290648351/is-virtual-secu.html">Is Virtual Security Technology A Prime Target For Acquisition?</source>
    </item>
    <item>
      <title><![CDATA[Network Security Podcast, Episode 104]]></title>
      <link>http://securityratty.com/article/5d3d79136e66b8a2348cea93876fcff1</link>
      <guid>http://securityratty.com/article/5d3d79136e66b8a2348cea93876fcff1</guid>
      <description><![CDATA[Martin and I were all over the map this week, but still managed to keep things under 30 minutes. We talk about the Dave and Busters hack, data exposure in Chile, and browser virtualization, among...]]></description>
      <content:encoded><![CDATA[<p>Martin and I were all over the map this week, but still managed to keep things under 30 minutes. We talk about the Dave and Buster&#8217;s hack, data exposure in Chile, and browser virtualization, among other things. The show is up over at <a href="http://netsecpodcast.com/?p=40">netsecpodcast.com</a>.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/securosis?a=spgbRH"><img src="http://feeds.feedburner.com/~f/securosis?i=spgbRH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/securosis?a=X3RW5h"><img src="http://feeds.feedburner.com/~f/securosis?i=X3RW5h" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/securosis?a=tXGe3h"><img src="http://feeds.feedburner.com/~f/securosis?i=tXGe3h" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/securosis/~4/290496883" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 14 May 2008 18:18:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data exposure">data exposure</category>
      <category domain="http://securityratty.com/tag/busters hack">busters hack</category>
      <category domain="http://securityratty.com/tag/browser virtualization">browser virtualization</category>
      <category domain="http://securityratty.com/tag/chile">chile</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/minutes">minutes</category>
      <category domain="http://securityratty.com/tag/martin">martin</category>
      <category domain="http://securityratty.com/tag/map">map</category>
      <category domain="http://securityratty.com/tag/talk">talk</category>
      <source url="http://feeds.feedburner.com/~r/securosis/~3/290496883/">Network Security Podcast, Episode 104</source>
    </item>
    <item>
      <title><![CDATA[Pragmatic CSO Podcast #13 - Digging deeper into the business plan]]></title>
      <link>http://securityratty.com/article/2795a7748d62850ba6a86f93bc6c4eb1</link>
      <guid>http://securityratty.com/article/2795a7748d62850ba6a86f93bc6c4eb1</guid>
      <description><![CDATA[This week we are going to dig a bit deeper into the business plan and deal with the first two sections of the plan. Initially we need to POSITION our securirty organization. What are we doing and why...]]></description>
      <content:encoded><![CDATA[<p>
<img src="http://www.pragmaticcso.com/Images/deep-hole.jpg" style="width: 240px; height: 180px; float: right" alt="Deep Hole" hspace="10" vspace="10" />This
week we are going to dig a bit deeper into the business plan and deal
with the first two sections of the plan. Initially we need to POSITION
our securirty organization. What are we doing and why is it important?
Then we need to make our PRIORITIES very clear. What do we focus on
first and why? 
</p>
<p>
The business plan is as much for them (meaning your senior
executives and the like) as it is for you. So you need to start the
plan off with a bunch of information about them, before you get back to
what you are going to do.<br />
</p>
<p>
Running time: 6:45<br />
<br />
Intro music is Jungle and we end with Ben Folds' &quot;Don't Change Your
Plans.&quot; Obviously the plan must adapt given the dynamic nature of our
businesses, but by building the plan with the customer in mind you
won't be changing it based upon the way the wind blows.  <br />
</p>
<p>
Direct Download: <a href="http://media.libsyn.com/media/pragmaticcso/12_Pragmatic_CSO_Podcast_12.mp3" target="_blank">13_Pragmatic_CSO_Podcast_13.mp3</a><br />
<br />
<img src="http://www.feedburner.com/fb/images/pub/feed-icon32x32.png" style="width: 32px; height: 32px" alt="Subscribe" /><a href="http://feeds.feedburner.com/P-CSO-Podcast" target="_blank">Subscribe
in a reader</a><br />
<br />
Photo Credit: <a href="http://www.flickr.com/photos/thebonzey/2402548202/" target="_blank">nbonzey</a>
</p>
]]></content:encoded>
      <pubDate>Wed, 14 May 2008 05:14:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/plan">plan</category>
      <category domain="http://securityratty.com/tag/business plan">business plan</category>
      <category domain="http://securityratty.com/tag/pragmatic cso podcast">pragmatic cso podcast</category>
      <category domain="http://securityratty.com/tag/photo credit">photo credit</category>
      <category domain="http://securityratty.com/tag/dynamic nature">dynamic nature</category>
      <category domain="http://securityratty.com/tag/securirty organization">securirty organization</category>
      <category domain="http://securityratty.com/tag/bit deeper">bit deeper</category>
      <category domain="http://securityratty.com/tag/direct download">direct download</category>
      <category domain="http://securityratty.com/tag/senior executives">senior executives</category>
      <source url="http://securityincite.com/blog/mike-rothman/pragmatic-cso-podcast-13-digging-deeper-into-the-business-plan">Pragmatic CSO Podcast #13 - Digging deeper into the business plan</source>
    </item>
    <item>
      <title><![CDATA[Speaking of Security Podcast #104]]></title>
      <link>http://securityratty.com/article/79cd3223604f3313d1a1d83c1d5464e9</link>
      <guid>http://securityratty.com/article/79cd3223604f3313d1a1d83c1d5464e9</guid>
      <description><![CDATA[Click to Listen/Download
Paul Joyal interview's the President of Corporate Integrity, Michael Rasmussen , about &quot;Developing a Sustainable and Cost Effective IT Compliance Program.&quot; For the companion...]]></description>
      <content:encoded><![CDATA[<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1280">Click to Listen/Download</a><br><br clear="all" />Paul Joyal interview's the President of Corporate Integrity, <a href="http://www.corp-integrity.com/about/bio_michael_rasmussen.html" target="_blank">Michael Rasmussen</a>, about &quot;Developing a Sustainable and Cost Effective  IT Compliance Program.&quot; For the companion white paper, <a href="https://www.rsa.com/go/wpt/wpindex.asp?WPID=9338" target="_blank">click  here</a>. Other RSA resources on this approach can be found at <a href="https://www.rsa.com/compliance">www.rsa.com/compliance</a>.]]></content:encoded>
      <pubDate>Sun, 11 May 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/companion white paper">companion white paper</category>
      <category domain="http://securityratty.com/tag/rsa resources">rsa resources</category>
      <category domain="http://securityratty.com/tag/rsa">rsa</category>
      <category domain="http://securityratty.com/tag/paul joyal interview">paul joyal interview</category>
      <category domain="http://securityratty.com/tag/cost effective">cost effective</category>
      <category domain="http://securityratty.com/tag/compliance program">compliance program</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/listendownload">listendownload</category>
      <category domain="http://securityratty.com/tag/michael">michael</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1280">Speaking of Security Podcast #104</source>
    </item>
    <item>
      <title><![CDATA[Virtualization Vendors Are Not In The Security Business?]]></title>
      <link>http://securityratty.com/article/306b180d27de5b1fbd7fbd6df4320857</link>
      <guid>http://securityratty.com/article/306b180d27de5b1fbd7fbd6df4320857</guid>
      <description><![CDATA[Simon Crosby, CTO of Citrix/XenSource made a pretty bold statement yesterday that has some people agreeing with his position and others disagreeing. In an interview with searchsecurity.com he publicy...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Simon Crosby, CTO of Citrix/XenSource made a pretty bold statement yesterday that has some people agreeing with his position and others disagreeing.&nbsp; In an interview with searchsecurity.com he publicy stated that virtualization vendors are not competent to try and secure virtual environments and therefore looks to 3rd party security companies to solve these concerns.&nbsp; </p>

<p><a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1312793,00.html?track=sy160&amp;asrc=RSS_RSS-10_160">Listen to the podcast here</a></p>

<p>Who are these 3rd party security companies?&nbsp; Well, there are a number of startup companies such as <a href="http://www.montegonetworks.com">Montego Networks</a>, <a href="http://www.bluelane.com">Blue Lane</a>, <a href="http://www.catbird.com">Catbird</a>, <a href="http://www.altornetworks.com">Altor Networks</a> as well as some of the big guys that are working on helping the virtualization vendors with these security concerns.</p>

<p>I tend to agree with Simon that the virtualization vendors don't currently have the expertise to deliver appropriate security controls for virtual environments BUT should they?</p>

<p>Well, Chris Hoff who blogs on the topic of virtualization security a lot seems to think that they should deliver security tools and and by not delivering solutions to secure the environment they are doing their customers a disservice.</p>

<p>&quot;Further, I don't expect that the hypervisor should be the place in
which all security functionality is delivered, but simply transferring
the lack of design and architecture forethought from the hypervisor
provider to the consumer by expecting someone else to clean up the mess
is just, well, typical.&quot;&nbsp; Said Chris Hoff in <a href="http://rationalsecurity.typepad.com/blog/2008/05/citrixs-crosby.html">his blog on this topic</a></p>

<p>I've spoken with a number of research analysts, venture capitalists and customers on this topic over the last several months and whenever I tell them what Montego Networks is off building they ALL seem to ask the same questions.&nbsp; One of those questions is:&nbsp; Why isn't VMWare or Citrix/Xensource doing this?&nbsp; My response has always been that &quot;they have publicly stated they do not want to and plan on leveraging an eco-system of security vendors to provide this&quot;.&nbsp; </p>

<p>Well, Simon's public statement is right in line with what I've been saying all along.&nbsp; The other question I get when I describe how Montego has security built into a virtual switch we've created is; shouldn't this technology be in the VMWare Virtual Switch?&nbsp; And my response is &quot;absolutely!&nbsp; But it isn't!&nbsp; so, someones got to do it.&quot;</p>

<p>So, I agree with Chris Hoff and I also agree with Simon Crosby.&nbsp; The virtualization vendors don't have the expertise BUT I feel they should provide SOME security tools to ensure the environment is safe.&nbsp; </p>

<p>There are some virtualization vendors that I have spoken with that are planning on using security as a differentiator and its my prediction that one of them will acquire security technology to do this.&nbsp; &nbsp;Its often easier to acquire vs. try and built it yourself given you don't currently have the expertise.</p>

<p>So who's problem is it to solve??&nbsp; Virtualization Vendors or Security Vendors??</p>

<p>I see the finger pointing game starting!</p>

<p><a onclick="window.open(this.href, '_blank', 'width=400,height=295,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/05/09/fingerpointing.png"><img width="200" height="147" border="0" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/05/09/fingerpointing.png" title="Fingerpointing" alt="Fingerpointing" style="margin: 0px 5px 5px 0px; float: left;" /></a> </p><br /><br /><br />

<p>-John Peterson</p>

<p>CTO / Montego Networks</p></div>
]]></content:encoded>
      <pubDate>Fri, 09 May 2008 11:44:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security tools">security tools</category>
      <category domain="http://securityratty.com/tag/deliver security tools">deliver security tools</category>
      <category domain="http://securityratty.com/tag/virtualization vendors">virtualization vendors</category>
      <category domain="http://securityratty.com/tag/acquire">acquire</category>
      <category domain="http://securityratty.com/tag/acquire security technology">acquire security technology</category>
      <category domain="http://securityratty.com/tag/security functionality">security functionality</category>
      <category domain="http://securityratty.com/tag/security controls">security controls</category>
      <category domain="http://securityratty.com/tag/security concerns">security concerns</category>
      <source url="http://feeds.feedburner.com/~r/SecurityInTheVirtualWorld/~3/286984713/virtualization.html">Virtualization Vendors Are Not In The Security Business?</source>
    </item>
    <item>
      <title><![CDATA[Information lifecycle management for resellers]]></title>
      <link>http://securityratty.com/article/dffc7f40b95ae3764867ff35012c788f</link>
      <guid>http://securityratty.com/article/dffc7f40b95ae3764867ff35012c788f</guid>
      <description><![CDATA[Information lifecycle management is all about making storage resources more efficient. In this podcast, Paul Franco of Zibiz Data Management explains how to determine if ILM is a good fit for your...]]></description>
      <content:encoded><![CDATA[Information lifecycle management is all about making storage resources more efficient. In this podcast, Paul Franco of Zibiz Data Management explains how to determine if ILM is a good fit for your customers and how to approach an ILM project at those companies that are well-suited for the technology.<img src="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~4/286067004" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 08 May 2008 04:49:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information lifecycle management">information lifecycle management</category>
      <category domain="http://securityratty.com/tag/ilm">ilm</category>
      <category domain="http://securityratty.com/tag/ilm project">ilm project</category>
      <category domain="http://securityratty.com/tag/storage resources">storage resources</category>
      <category domain="http://securityratty.com/tag/paul franco">paul franco</category>
      <category domain="http://securityratty.com/tag/fit">fit</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/determine">determine</category>
      <category domain="http://securityratty.com/tag/efficient">efficient</category>
      <source url="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~3/286067004/0,295582,sid98_gci1309216,00.html">Information lifecycle management for resellers</source>
    </item>
    <item>
      <title><![CDATA[ebizQ with Mike Rothman]]></title>
      <link>http://securityratty.com/article/d486f2329fe29e5b54709614b88593a3</link>
      <guid>http://securityratty.com/article/d486f2329fe29e5b54709614b88593a3</guid>
      <description><![CDATA[ebizQ published a podcast that Mike Rothman invited me on dealing with vendor consolidation and &quot;big is the new small&quot;. It is always fun talking with Mike and we had a good time. I like that they also...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><img title="Rothman" alt="Rothman" src="http://www.stillsecureafteralltheseyears.com/photos/uncategorized/2008/05/07/rothman.jpg" border="0" style="FLOAT: left; MARGIN: 0px 5px 5px 0px" />ebizQ published a podcast that Mike Rothman invited me on dealing with vendor consolidation and &quot;big is the new small&quot;.&nbsp; It is always fun talking with Mike and we had a good time.&nbsp; I like that they also transcribed the podcast if you just want to read it.&nbsp; You can get it <a href="http://www.ebizq.net/blogs/mike_rothman/2008/05/post_1.php" target="_blank">here</a>.</p></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=PM04jy"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=PM04jy" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=nxDBkH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=nxDBkH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=XLE64H"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=XLE64H" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=c0Z3RH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=c0Z3RH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=gMfB4H"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=gMfB4H" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=JrKcuh"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=JrKcuh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=RDKlTh"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=RDKlTh" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/285732707" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 07 May 2008 15:41:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mike">mike</category>
      <category domain="http://securityratty.com/tag/mike rothman">mike rothman</category>
      <category domain="http://securityratty.com/tag/ebizq">ebizq</category>
      <category domain="http://securityratty.com/tag/vendor consolidation">vendor consolidation</category>
      <category domain="http://securityratty.com/tag/podcast">podcast</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/fun">fun</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/285732707/ebizq-with-mike.html">ebizQ with Mike Rothman</source>
    </item>
    <item>
      <title><![CDATA[Pragmatic CSO Podcast #12 - The Business Plan]]></title>
      <link>http://securityratty.com/article/ce50430e048dca2d7bff4eb43b51356b</link>
      <guid>http://securityratty.com/article/ce50430e048dca2d7bff4eb43b51356b</guid>
      <description><![CDATA[This week we get back into the Pragmatic CSO methodology, and jump into Section 2: Building Your Pragmatic Security Environment. The first step in S2 is Step 4 or Building Your Security Business Plan....]]></description>
      <content:encoded><![CDATA[<p>
<img src="http://www.pragmaticcso.com/Images/business-plan.jpg" style="width: 180px; height: 240px; float: right" alt="This shouldn't be your business plan" hspace="10" vspace="10" />
</p>
<p>
This
week we get back into the Pragmatic CSO methodology, and jump into
Section 2: Building Your Pragmatic Security Environment. The first step
in S2 is Step 4 or Building Your Security Business Plan. Why do we need
a business plan anyway? What's the point?
</p>
<p>
All is revealed in podcast #12. Well OK, not all - but I lay
the
groundwork on why the business plan is probably the most important of
the 12 steps and what goes into building it. Over the next 2 months or
so, we'll be delving deeply into the business plan and the associated
efforts to &quot;sell&quot; the strategy to the senior team.
</p>
<p>
So, buckle up as we take off for the next leg of the P-CSO
journey. 
</p>
<p>
Running time: 5:52<br />
<br />
Intro music is Jungle and I sign off with Acquiese from Oasis'
Masterplan album. Since the security business plan is YOUR Masterplan,
I thought that was appropriate. <br />
</p>
<p>
Direct Download: <a href="http://media.libsyn.com/media/pragmaticcso/12_Pragmatic_CSO_Podcast_12.mp3" target="_blank">12_Pragmatic_CSO_Podcast_12.mp3</a><br />
<br />
<img src="http://www.feedburner.com/fb/images/pub/feed-icon32x32.png" style="width: 32px; height: 32px" alt="Subscribe" /><a href="http://feeds.feedburner.com/P-CSO-Podcast" target="_blank">Subscribe
in a reader</a><br />
<br />
Photo Credit: <a href="http://www.flickr.com/photos/bury_irc/196409308/" target="_blank">Peter J. Bury - IRC</a>
</p>
<p>
&nbsp;
</p>
]]></content:encoded>
      <pubDate>Wed, 07 May 2008 06:24:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/business plan">business plan</category>
      <category domain="http://securityratty.com/tag/security business plan">security business plan</category>
      <category domain="http://securityratty.com/tag/podcast">podcast</category>
      <category domain="http://securityratty.com/tag/pragmatic cso podcast">pragmatic cso podcast</category>
      <category domain="http://securityratty.com/tag/masterplan">masterplan</category>
      <category domain="http://securityratty.com/tag/pragmatic security environment">pragmatic security environment</category>
      <category domain="http://securityratty.com/tag/masterplan album">masterplan album</category>
      <category domain="http://securityratty.com/tag/pragmatic cso methodology">pragmatic cso methodology</category>
      <category domain="http://securityratty.com/tag/step">step</category>
      <source url="http://securityincite.com/blog/mike-rothman/pragmatic-cso-podcast-12-the-business-plan">Pragmatic CSO Podcast #12 - The Business Plan</source>
    </item>
    <item>
      <title><![CDATA[HNS Podcast: Jeremiah Grossman's top security conferences]]></title>
      <link>http://securityratty.com/article/8753b59d1142f31236e4a900ef029488</link>
      <guid>http://securityratty.com/article/8753b59d1142f31236e4a900ef029488</guid>
      <description><![CDATA[Jeremiah Grossman, the founder and Chief Technology Officer of WhiteHat Security attends quite a number of security conferences around the globe. A couple of weeks ago we had a chat with him and in...]]></description>
      <content:encoded><![CDATA[Jeremiah Grossman, the founder and Chief Technology Officer of WhiteHat Security attends quite a number of security conferences around the globe. A couple of weeks ago we had a chat with him and in th...]]></content:encoded>
      <pubDate>Mon, 05 May 2008 15:25:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security conferences">security conferences</category>
      <category domain="http://securityratty.com/tag/jeremiah grossman">jeremiah grossman</category>
      <category domain="http://securityratty.com/tag/chief technology officer">chief technology officer</category>
      <category domain="http://securityratty.com/tag/whitehat security attends">whitehat security attends</category>
      <category domain="http://securityratty.com/tag/weeks ago">weeks ago</category>
      <category domain="http://securityratty.com/tag/chat">chat</category>
      <category domain="http://securityratty.com/tag/couple">couple</category>
      <category domain="http://securityratty.com/tag/founder">founder</category>
      <category domain="http://securityratty.com/tag/globe">globe</category>
      <source url="http://www.net-security.org/article.php?id=1131">HNS Podcast: Jeremiah Grossman's top security conferences</source>
    </item>
  </channel>
</rss>
