<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[Speaking of Security, the RSA Blog and Podcast]]></title>
    <link>http://securityratty.com/feed/73a24756d7d098fdcb3f142f0c1f240f</link>
    <description></description>
    <pubDate>Tue, 12 Aug 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[What's Going on Between Asprox and Rock Phish? ]]></title>
      <link>http://securityratty.com/article/fc95ce7833adc3cdfb7b5c321e80348a</link>
      <guid>http://securityratty.com/article/fc95ce7833adc3cdfb7b5c321e80348a</guid>
      <description><![CDATA[When a small phishing gang decides to upgrade its infrastructure, it is often done in a quick and dirty fashion. The transition is almost immediate, and often buggy and unprofessional. But what...]]></description>
      <content:encoded><![CDATA[When a small phishing gang decides to upgrade its infrastructure, it is often done in a quick and dirty fashion. The transition is almost immediate, and often buggy and unprofessional. But what happens when a gang on the scale of the Rock Phish group decides to abandon its old methods and upgrade its botnet infrastructure? It is done slowly, smoothly but most importantly -- professionally. 

The RSA FraudAction Research Labs recently gathered information that indicates major changes in the tactics employed by the Rock Phish gang. We have reason to believe that the gang is replacing its phishing infrastructure, and upgrading it to an advanced <a href="http://www.honeynet.org/papers/ff/fast-flux.html">Fast-Flux</a> botnet. <B>We also believe that this new infrastructure belongs to none other than the infamous Asprox Botnet, which has recently been spreading itself using surges of SQL injection attacks...</b>
]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/rock phish">rock phish</category>
      <category domain="http://securityratty.com/tag/gang">gang</category>
      <category domain="http://securityratty.com/tag/gang decides">gang decides</category>
      <category domain="http://securityratty.com/tag/rock phish gang">rock phish gang</category>
      <category domain="http://securityratty.com/tag/infrastructure">infrastructure</category>
      <category domain="http://securityratty.com/tag/botnet infrastructure">botnet infrastructure</category>
      <category domain="http://securityratty.com/tag/infrastructure belongs">infrastructure belongs</category>
      <category domain="http://securityratty.com/tag/infamous asprox botnet">infamous asprox botnet</category>
      <category domain="http://securityratty.com/tag/decides">decides</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1338">What's Going on Between Asprox and Rock Phish? </source>
    </item>
    <item>
      <title><![CDATA[Southeast Asia: Perspectives on Compliance]]></title>
      <link>http://securityratty.com/article/1d2c3bbf31f4585ba5c55859718231a5</link>
      <guid>http://securityratty.com/article/1d2c3bbf31f4585ba5c55859718231a5</guid>
      <description><![CDATA[This past weekend, I left Southeast Asia after a week-long trip to Bangkok, Singapore and Manila. The week was spent in back-to-back meetings with customers and our local sales teams, and the majority...]]></description>
      <content:encoded><![CDATA[This past weekend, I left Southeast Asia after a week-long trip to Bangkok, Singapore and Manila. The week was spent in back-to-back meetings with customers and our local sales teams, and the majority of our discussions centered on PCI DSS and compliance in general. One clear takeaway:  Compliance is one of THE growing areas of concern for businesses in the region. 
<P>
I found the degree to which customers in the region were concerned about compliance to be a bit of a surprise. I say 'surprise' because I often hear that compliance isn't as much of an issue outside of the U.S.  <B>From what we're seeing, though, the regulatory environment in non-U.S. geos, including Southeast Asia, is becoming more complicated...</b>]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/southeast asia">southeast asia</category>
      <category domain="http://securityratty.com/tag/local sales teams">local sales teams</category>
      <category domain="http://securityratty.com/tag/week-long trip">week-long trip</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/past weekend">past weekend</category>
      <category domain="http://securityratty.com/tag/surprise">surprise</category>
      <category domain="http://securityratty.com/tag/back-to-back meetings">back-to-back meetings</category>
      <category domain="http://securityratty.com/tag/region">region</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1336">Southeast Asia: Perspectives on Compliance</source>
    </item>
    <item>
      <title><![CDATA[Planning for a new year]]></title>
      <link>http://securityratty.com/article/53eb51a004ab3e2477c2c3559dd8fb20</link>
      <guid>http://securityratty.com/article/53eb51a004ab3e2477c2c3559dd8fb20</guid>
      <description><![CDATA[October is creeping up on us, and for most of us that means the beginning of the end of 2008, along with the nagging feeling that we should be doing some planning for 2009. This is the perfect...]]></description>
      <content:encoded><![CDATA[October is creeping up on us, and for most of us that means the beginning of the end of 2008, along with the nagging feeling that we should be doing some planning for 2009. This is the perfect opportunity to take stock of your security and compliance programs, and to develop a plan for improving things next year. If you've been following our various blogs here at RSA you probably realize by now that we espouse a security and compliance program based on three core pillars: it's information-centric, risk-driven and framework-based. Our compliance team has spoken with hundreds of customers from all over the world and in every industry segment this year, and we're finding that this approach is gaining acceptance at an ever-increasing rate. <B>Organizations are realizing that they need to discover, manage and control their information assets in order to protect them...</b>]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/compliance program based">compliance program based</category>
      <category domain="http://securityratty.com/tag/compliance team">compliance team</category>
      <category domain="http://securityratty.com/tag/industry segment">industry segment</category>
      <category domain="http://securityratty.com/tag/compliance programs">compliance programs</category>
      <category domain="http://securityratty.com/tag/information assets">information assets</category>
      <category domain="http://securityratty.com/tag/core pillars">core pillars</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/perfect opportunity">perfect opportunity</category>
      <category domain="http://securityratty.com/tag/october">october</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1337">Planning for a new year</source>
    </item>
    <item>
      <title><![CDATA[ISO 27001 Adoption Poll Results are In]]></title>
      <link>http://securityratty.com/article/fc09764886f19fc2d529d52d8b214dbe</link>
      <guid>http://securityratty.com/article/fc09764886f19fc2d529d52d8b214dbe</guid>
      <description><![CDATA[So, several weeks ago I wrote a piece discussing the &quot;long road to ISO 27001&quot; adoption. A question posed to readers at the end of the piece: &quot;How far off are we from the point at which ISO 27001...]]></description>
      <content:encoded><![CDATA[So, several weeks ago I wrote <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1313">a piece</a> discussing the "long road to ISO 27001" adoption.  A question posed to readers at the end of the piece:  "How far off are we from the point at which ISO 27001 certifications in the U.S. are standard operating procedure for businesses -- the exception, rather than the rule?"
<P>
Well, the results are in!  Our servers nearly crashed thanks to the influx of responses, but, fortunately, that wasn't the case.  <B>Here are the results...</b>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 05:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/iso">iso</category>
      <category domain="http://securityratty.com/tag/results">results</category>
      <category domain="http://securityratty.com/tag/piece">piece</category>
      <category domain="http://securityratty.com/tag/question posed">question posed</category>
      <category domain="http://securityratty.com/tag/adoption">adoption</category>
      <category domain="http://securityratty.com/tag/weeks ago">weeks ago</category>
      <category domain="http://securityratty.com/tag/standard">standard</category>
      <category domain="http://securityratty.com/tag/rule">rule</category>
      <category domain="http://securityratty.com/tag/influx">influx</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1335">ISO 27001 Adoption Poll Results are In</source>
    </item>
    <item>
      <title><![CDATA[If there were gold medals for Data Leakage...]]></title>
      <link>http://securityratty.com/article/9ec180dabd953b9e40bf780ac4cd7485</link>
      <guid>http://securityratty.com/article/9ec180dabd953b9e40bf780ac4cd7485</guid>
      <description><![CDATA[I've just returned from my summer vacation, somewhat foolishly deciding to spend it under canvas in the south-west of the UK and expecting to get good weather. If my tent had leaked as badly in the...]]></description>
      <content:encoded><![CDATA[I've just returned from my summer vacation, somewhat foolishly deciding to spend it under canvas in the south-west of the UK and expecting to get good weather. If my tent had leaked as badly in the last couple of weeks as data seems to have been leaking in the UK during the same period, I'd be in need of an <a href="http://en.wikipedia.org/wiki/Aqua_Lung">aqualung</a> by now! If it were an Olympic sport, Britain would have beaten China for pole position in the <a href="http://news.bbc.co.uk/sport2/hi/olympics/medals_table/default.stm">medals table</a>!
<P>
It all started with the loss of a <a href="http://news.bbc.co.uk/1/hi/uk_politics/7575989.stm">memory stick</a> by a UK Government contractor which contained somewhere around 120,000 records, including the details of 10,000 of our nation's most serious criminals. <B>We then heard about a compromise at global hotel chain Best Western...</b>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/global hotel chain">global hotel chain</category>
      <category domain="http://securityratty.com/tag/olympic sport">olympic sport</category>
      <category domain="http://securityratty.com/tag/summer vacation">summer vacation</category>
      <category domain="http://securityratty.com/tag/pole position">pole position</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/government contractor">government contractor</category>
      <category domain="http://securityratty.com/tag/medals table">medals table</category>
      <category domain="http://securityratty.com/tag/memory stick">memory stick</category>
      <category domain="http://securityratty.com/tag/nation">nation</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1334">If there were gold medals for Data Leakage...</source>
    </item>
    <item>
      <title><![CDATA[Speaking of Security Podcast #119]]></title>
      <link>http://securityratty.com/article/9889880c87bd6f2858883a0c1c40e50b</link>
      <guid>http://securityratty.com/article/9889880c87bd6f2858883a0c1c40e50b</guid>
      <description><![CDATA[Click to Download/Listen (06:46

Paul Davilman from RSAs Compliance and Solutions team sits down with Amanda Van Veen to talk about the North American Electric Reliability Corporation (NERC) Cyber...]]></description>
      <content:encoded><![CDATA[<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1333">Click to Download/Listen</a> (06:46)<br><br />Paul Davilman from RSA&rsquo;s Compliance and Solutions  team sits down with Amanda Van Veen to talk about  the <a href="http://www.nerc.com/" target="_blank">North American Electric Reliability Corporation</a> (NERC) <a href="http://www.nerc.com/filez/standards/Project_2008-06_Cyber_Security.html">Cyber Security Standards</a> and how  these standards will impact IT security in the utility industries. Please note that due to the U.S. Labor Day holiday, we'll be back in two weeks (on September 8) with a new show.<br /><br /><br />]]></content:encoded>
      <pubDate>Sun, 24 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/cyber security standards">cyber security standards</category>
      <category domain="http://securityratty.com/tag/standards">standards</category>
      <category domain="http://securityratty.com/tag/labor day holiday">labor day holiday</category>
      <category domain="http://securityratty.com/tag/solutions team sits">solutions team sits</category>
      <category domain="http://securityratty.com/tag/utility industries">utility industries</category>
      <category domain="http://securityratty.com/tag/amanda van">amanda van</category>
      <category domain="http://securityratty.com/tag/rsas compliance">rsas compliance</category>
      <category domain="http://securityratty.com/tag/paul davilman">paul davilman</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1333">Speaking of Security Podcast #119</source>
    </item>
    <item>
      <title><![CDATA[PCI Compliance: Reaction to the Summary of Changes]]></title>
      <link>http://securityratty.com/article/ddeefb896f6d234b28dddac20a55a9c5</link>
      <guid>http://securityratty.com/article/ddeefb896f6d234b28dddac20a55a9c5</guid>
      <description><![CDATA[On August 18 the PCI Security Standards Council formally announced ( http://www.pcisecuritystandards.org/pdfs/08-18-08 2.pdf ) forthcoming changes to the Payment Card Industry's Data Security Standard...]]></description>
      <content:encoded><![CDATA[On August 18 the PCI Security Standards Council formally announced (<a href="http://www.pcisecuritystandards.org/pdfs/08-18-08_2.pdf" target=_blank>http://www.pcisecuritystandards.org/pdfs/08-18-08_2.pdf</a>) forthcoming changes to the Payment Card Industry's Data Security Standard (PCI DSS) as it moves from version 1.1 to version 1.2 in October 2008.  The release represents the first major update since September 2006.
<P>
What's my take on the summary of changes? <B>Most merchants will be pleased to see that these are relatively minor changes...</b>]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/payment card industry">payment card industry</category>
      <category domain="http://securityratty.com/tag/data security standard">data security standard</category>
      <category domain="http://securityratty.com/tag/release represents">release represents</category>
      <category domain="http://securityratty.com/tag/version">version</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/summary">summary</category>
      <category domain="http://securityratty.com/tag/october">october</category>
      <category domain="http://securityratty.com/tag/pdf">pdf</category>
      <category domain="http://securityratty.com/tag/minor">minor</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1330">PCI Compliance: Reaction to the Summary of Changes</source>
    </item>
    <item>
      <title><![CDATA[Information risk management, and lessons-learned in the financial industry]]></title>
      <link>http://securityratty.com/article/b9c42d81e576cf16cdd8e7f1696edbc9</link>
      <guid>http://securityratty.com/article/b9c42d81e576cf16cdd8e7f1696edbc9</guid>
      <description><![CDATA[Information risk management, and lessons-learned in the financial industry Last week's Economist had a good article entitled &quot;Confessions of a Risk Manager&quot;, in which a risk manager from a global bank...]]></description>
      <content:encoded><![CDATA[Information risk management, and lessons-learned in the financial industry

Last week's <a href="http://www.economist.com/finance/displaystory.cfm?story_id=11897037">Economist</a> had a good article entitled "Confessions of a Risk Manager", in which a risk manager from a global bank uses 20-20 hindsight to look at "what went wrong" in the lead-up to the credit crunch and the ensuing fallout.

I won't pretend to understand all the ins and outs of financial derivatives, <B>but there were some points raised that anyone in the IT security space can identify with...</b>]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information risk management">information risk management</category>
      <category domain="http://securityratty.com/tag/financial industry">financial industry</category>
      <category domain="http://securityratty.com/tag/risk manager">risk manager</category>
      <category domain="http://securityratty.com/tag/financial derivatives">financial derivatives</category>
      <category domain="http://securityratty.com/tag/credit crunch">credit crunch</category>
      <category domain="http://securityratty.com/tag/security space">security space</category>
      <category domain="http://securityratty.com/tag/global bank">global bank</category>
      <category domain="http://securityratty.com/tag/pretend">pretend</category>
      <category domain="http://securityratty.com/tag/lead-up">lead-up</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1331">Information risk management, and lessons-learned in the financial industry</source>
    </item>
    <item>
      <title><![CDATA[Speaking of Security Podcast #118]]></title>
      <link>http://securityratty.com/article/fb67ff3ce1f2b335b3f648a50bd31bd9</link>
      <guid>http://securityratty.com/article/fb67ff3ce1f2b335b3f648a50bd31bd9</guid>
      <description><![CDATA[Click to Download/Listen (11:27

This week, Amanda Van Veen speaks with analyst Rod Nelsestuen from the TowerGroup . Rod covers key issues affecting several financial industry segments including...]]></description>
      <content:encoded><![CDATA[<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1332">Click to Download/Listen</a> (11:27)<br><br />This week, Amanda Van Veen speaks with analyst Rod Nelsestuen from the <a href="http://www.towergroup.com/research/home/index.htm" target="_blank">TowerGroup</a>.  Rod covers key issues affecting several financial  industry segments including emerging markets and trend, security, and risk management  matters and in this segment, talks with Amanda about the evolution of business  continuity planning and security&rsquo;s increasing role.<br /><br /><br />]]></content:encoded>
      <pubDate>Sun, 17 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management matters">risk management matters</category>
      <category domain="http://securityratty.com/tag/financial industry segments">financial industry segments</category>
      <category domain="http://securityratty.com/tag/amanda van">amanda van</category>
      <category domain="http://securityratty.com/tag/amanda">amanda</category>
      <category domain="http://securityratty.com/tag/analyst rod">analyst rod</category>
      <category domain="http://securityratty.com/tag/business continuity">business continuity</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/markets">markets</category>
      <category domain="http://securityratty.com/tag/talks">talks</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1332">Speaking of Security Podcast #118</source>
    </item>
    <item>
      <title><![CDATA[Addressing NERC Cyber Security Standards Using a Frameworks-Based Approach]]></title>
      <link>http://securityratty.com/article/adf577a5e402094355f94e59576db638</link>
      <guid>http://securityratty.com/article/adf577a5e402094355f94e59576db638</guid>
      <description><![CDATA[Although the NERC Cyber-Security Standards ( http://www.nerc.com/files/CIP-002-1.pdf ) are applicable only in the US, I think there's no doubt that cyber security is fast becoming a major concern of...]]></description>
      <content:encoded><![CDATA[Although the NERC Cyber-Security Standards (<a href="http://www.nerc.com/files/CIP-002-1.pdf" target=_blank>http://www.nerc.com/files/CIP-002-1.pdf</a>) are applicable only in the US, I think there's no doubt that cyber security is fast becoming a major concern of electric utility companies worldwide.  In addition, other US critical infrastructure industry segments, such as water and chemical companies are also coming under increasing federal pressure to improve their own cyber-security efforts.  Still, the NERC Cyber-Security standards have been criticized for being too ambiguous, providing little in the way of guidance, <B>as well as for leaving loopholes for utility companies to beat the rules...</b> ]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nerc">nerc</category>
      <category domain="http://securityratty.com/tag/nerc cyber-security standards">nerc cyber-security standards</category>
      <category domain="http://securityratty.com/tag/cyber security">cyber security</category>
      <category domain="http://securityratty.com/tag/utility companies">utility companies</category>
      <category domain="http://securityratty.com/tag/federal pressure">federal pressure</category>
      <category domain="http://securityratty.com/tag/chemical companies">chemical companies</category>
      <category domain="http://securityratty.com/tag/major concern">major concern</category>
      <category domain="http://securityratty.com/tag/cyber-security efforts">cyber-security efforts</category>
      <category domain="http://securityratty.com/tag/guidance">guidance</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1329">Addressing NERC Cyber Security Standards Using a Frameworks-Based Approach</source>
    </item>
  </channel>
</rss>
