<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: belts]]></title>
    <link>http://securityratty.com/tag/belts</link>
    <description></description>
    <pubDate>Wed, 13 Feb 2008 07:58:30 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Almost too sad to read]]></title>
      <link>http://securityratty.com/article/82deade805e53c223916a95cc44218da</link>
      <guid>http://securityratty.com/article/82deade805e53c223916a95cc44218da</guid>
      <description><![CDATA[I dont think I have any words to say for this comment


clipped from apnews.myway.com
Veterans burials nonstop at national cemeteries



An average of 1,800 veterans die each day, and 10 percent of...]]></description>
      <content:encoded><![CDATA[<div > I dont think I have any words to say for this comment. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/E572980C-22D5-4E35-9BC7-0C405ADD5B8E/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/eb442b44-952d-40c8-bff4-a6248be04d74/E572980C-22D5-4E35-9BC7-0C405ADD5B8E/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://apnews.myway.com/article/20080525/D90SFO280.html" href="http://apnews.myway.com/article/20080525/D90SFO280.html" style="font-size: 11px;">apnews.myway.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://apnews.myway.com/article/20080525/D90SFO280.html --><B>Veterans&#8217; burials nonstop at national cemeteries</B></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://apnews.myway.com/article/20080525/D90SFO280.html --><P><br />
An average of 1,800 veterans die each day, and 10 percent of them are buried in the country&#8217;s 125 national cemeteries, which are expected to set a record with 107,000 interments, including dependents, this year. And more national cemeteries are being built.</P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://apnews.myway.com/article/20080525/D90SFO280.html --><P><br />
Thirty-four veterans groups volunteer for services. Every seventh Thursday members of American Legion Post 548 from Louisville, Ohio, dressed in black coats, ties and pants with white belts, gloves and shoulder cords, come to pay tribute to fellow veterans.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/E572980C-22D5-4E35-9BC7-0C405ADD5B8E/blog/" title="blog or email this clip"><img src="http://content7.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Mon, 26 May 2008 13:22:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/national cemeteries">national cemeteries</category>
      <category domain="http://securityratty.com/tag/american legion post">american legion post</category>
      <category domain="http://securityratty.com/tag/veterans burials nonstop">veterans burials nonstop</category>
      <category domain="http://securityratty.com/tag/fellow veterans">fellow veterans</category>
      <category domain="http://securityratty.com/tag/white belts">white belts</category>
      <category domain="http://securityratty.com/tag/shoulder cords">shoulder cords</category>
      <category domain="http://securityratty.com/tag/seventh thursday">seventh thursday</category>
      <category domain="http://securityratty.com/tag/veterans die">veterans die</category>
      <category domain="http://securityratty.com/tag/black coats">black coats</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=464">Almost too sad to read</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-04-03 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/267178aadef12876bdbbc5bdc97a1501</link>
      <guid>http://securityratty.com/article/267178aadef12876bdbbc5bdc97a1501</guid>
      <description><![CDATA[Information Security as Insurance
Security Thoughts: Information Security, Governance, Compliance and Safety Belts I have seen a lot of complaints about PCI and SOX etc etc in the same way that people...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://dmiessler.com/blog/information-security-as-insurance">Information Security as Insurance</a></li>
<li><a href="http://securethink.blogspot.com/2008/03/information-security-governance.html">Security Thoughts: Information Security, Governance, Compliance and Safety Belts</a><br/>
I have seen a lot of complaints about PCI and SOX etc etc in the same way that people complain about &quot;self protection&quot; laws like safety belt laws.</li>
<li><a href="http://www.itbusinessedge.com/blogs/ssg/?p=283">The Evolution of Compliance Technology - Sarbox Survival Guide</a></li>
<li><a href="http://stage.vambenepe.com/archives/178">William Vambenepe&rsquo;s blog &raquo; Blog Archive &raquo; Another IT event standard? I&rsquo;ll believe it when I CEE it.</a></li>
<li><a href="http://searchsecurity.techtarget.com/tip/0,289483,sid14_gci1307430,00.html?track=NL-430&ad=632806USCA&asrc=EM_NLT_3408753&uid=832109">Worst practices: Recognizing the biggest compliance mistakes</a></li>
<li><a href="http://blog.tenablesecurity.com/2008/03/cybercrime-cybe.html">Tenable Network Security: CyberCrime, CyberTerror, CyberEspionage, and CyberWar</a><br/>
The final point I'd like to make on cybercrime is that the current set of problems show us nothing about how bad it can possibly get.

If you're part of an organzation that does business online, cybercrime is going to be part of your personal future, fo</li>
<li><a href="http://www.security-works.com/blog/2008/03/nice-grc-write-up-and-how-it-relates-to.html">practical risk management: Nice GRC write-up and how it relates to log management initiatives</a></li>
<li><a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/03/securitymatters_0320">Commentary: Inside the Twisted Mind of the Security Professional</a></li>
<li><a href="http://briefingsdirectblog.blogspot.com/2008/03/splunk-goes-platform-to-extend-it.html">Dana Gardner's BriefingsDirect: Splunk goes 'platform' to extend IT search benefits across more IT management functions</a></li>
<li><a href="http://www.sans.edu/resources/securitylab/hoelzer_david_dad.php">SANS Technology Institute: An Interview with David Hoelzer, author of DAD, a log aggregator</a></li>
<li><a href="http://paranoidmike.blogspot.com/2008/02/which-security-event-log-audit_12.html">ParanoidMike: Which Security Event Log audit categories are most useful on a Windows client?</a></li>
<li><a href="http://www2.csoonline.com/exclusives/column.html?CID=33575">Do Your Vendors Have Information Security That's Aaa Good? - Web Exclusives - Online Column - CSO Magazine</a></li>
<li><a href="http://www.s-ox.com/dsp_getNewsDetails.cfm?CID=2220">Sarbanes-Oxley: Growing Dependence on Log Data for Compliance and Threat Response</a><br/>
Results of note from the SenSage survey respondents include:

    *  Eighty-eight percent collect log data for compliance reasons, while 42 percent do so as part of best practices/industry standards initiatives such as ITIL.

    * Seventy-eight perce</li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/263759259" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 03 Apr 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security professional">security professional</category>
      <category domain="http://securityratty.com/tag/tenable network security">tenable network security</category>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/compliance reasons">compliance reasons</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/compliance mistakes">compliance mistakes</category>
      <category domain="http://securityratty.com/tag/compliance technology">compliance technology</category>
      <category domain="http://securityratty.com/tag/safety belt laws">safety belt laws</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/263759259/anton18">Links for 2008-04-03 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[$50 > life. WHYYYYYYY?]]></title>
      <link>http://securityratty.com/article/78bf1d88a77755dbc02fd795ad686d30</link>
      <guid>http://securityratty.com/article/78bf1d88a77755dbc02fd795ad686d30</guid>
      <description><![CDATA[If you flipped thru my slides from the CSO Summit , you noticed slide #4 with a picture of a seatbelt. Why is it there

That is why. This post really tied (for me) everything that happens in security...]]></description>
      <content:encoded><![CDATA[If you flipped thru <a href="http://www.slideshare.net/anton_chuvakin/1st-russian-cso-summit-trends-2008">my slides from the CSO Summit</a>, you noticed slide #4 with a picture of a seatbelt. Why is it there?<br /><br /><a href="http://securethink.blogspot.com/2008/03/information-security-governance.html">That </a>is why. <a href="http://securethink.blogspot.com/2008/03/information-security-governance.html">This post</a> really tied (for me) everything that happens in security today; and its essence is this quote:<br /><br />"The state of Victoria in Australia made wearing safety belts compulsory in 1970. This is now almost universal practice.  I don't know the exact statistics but a study done in South Africa found that more people used safety belts after it was made illegal to not use them than when it was left up to the driver.<br /><br /><span style="font-weight: bold;">The conclusion really is that people are more likely to obey a rule because <span style="font-style: italic;">it is law than</span> because it may just <span style="font-style: italic;">save their life</span>."<br /><br /></span>and even<br /><br />"I have seen a lot of complaints about PCI and SOX etc etc in the same way that <span style="font-weight: bold;">people complain about "self protection" laws like safety belt laws.</span>"<span style="font-weight: bold;"><br /><br /></span>If you<span style="font-weight: bold;"></span> see <span style="font-style: italic;">anything </span>weird in today's "compliance-heavy" security industry, it is probably explained by this phenomenon.<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=ld7QXpG"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=ld7QXpG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=JxUq1hG"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=JxUq1hG" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/263538249" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 03 Apr 2008 08:49:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/safety belts">safety belts</category>
      <category domain="http://securityratty.com/tag/safety belts compulsory">safety belts compulsory</category>
      <category domain="http://securityratty.com/tag/people complain">people complain</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/safety belt laws">safety belt laws</category>
      <category domain="http://securityratty.com/tag/laws">laws</category>
      <category domain="http://securityratty.com/tag/security industry">security industry</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/cso summit">cso summit</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/263538249/50-life-whyyyyyyy.html">$50 &gt; life. WHYYYYYYY?</source>
    </item>
    <item>
      <title><![CDATA[Information Security, Governance, Compliance and Safety Belts]]></title>
      <link>http://securityratty.com/article/fe8c1be479921f36e2ea9c0f29b9b2bb</link>
      <guid>http://securityratty.com/article/fe8c1be479921f36e2ea9c0f29b9b2bb</guid>
      <description><![CDATA[The state of Victoria in Australia made wearing safety belts compulsory in 1970. This is now almost universal practice

I don't know the exact statistics but a study done in South Africa found that...]]></description>
      <content:encoded><![CDATA[The state of Victoria in Australia made wearing safety belts compulsory in 1970. This is now almost universal practice.<br /><br />I don't know the exact statistics but a study done in South Africa found that more people used safety belts after it was made illegal to not use them than when it was left up to the driver.<br /><br />The conclusion really is that people are more likely to obey a rule because it is law than because it may just save their life.<br /><br />I think that the same is true with Information Security. It won't (necessarily) save your life but it is good practice. And yet companies are only doing it because it is now law.<br /><br />The problem with this is that it is not accepted by people in their hearts. I know of people who drive around without their belts on and put them half on when they see a traffic cop.<br /><br />The Information Security equivalent is jacking up your InfoSec program when the auditors come to visit and letting it slide when they are not around. Or making sure that they don't see some issues that you are well aware of.<br /><br />I have seen a lot of complaints about PCI and SOX etc etc in the same way that people complain about "self protection" laws like safety belt laws. The thing is that the government is stepping in only because people are very bad at self regulation. Really, what a number of InfoSec experts are trying to promote is - understand why you need to protect yourself, understand how and abide by it. Do it for your company, not because the government demands it.<br /><br />That way, not only will you be "compliant" and full of "good governance" but more importantly - your company will be safe.<img src="http://feeds.feedburner.com/~r/SecurityThoughts/~4/254779764" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 20 Mar 2008 04:47:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/safety belts">safety belts</category>
      <category domain="http://securityratty.com/tag/belts">belts</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/safety belts compulsory">safety belts compulsory</category>
      <category domain="http://securityratty.com/tag/people complain">people complain</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/information security equivalent">information security equivalent</category>
      <category domain="http://securityratty.com/tag/safety belt laws">safety belt laws</category>
      <category domain="http://securityratty.com/tag/laws">laws</category>
      <source url="http://feeds.feedburner.com/~r/SecurityThoughts/~3/254779764/information-security-governance.html">Information Security, Governance, Compliance and Safety Belts</source>
    </item>
    <item>
      <title><![CDATA[Recession brings a downturn in security spending and jobs]]></title>
      <link>http://securityratty.com/article/eb9e0726b1940273c6d6e383bd0b146d</link>
      <guid>http://securityratty.com/article/eb9e0726b1940273c6d6e383bd0b146d</guid>
      <description><![CDATA[Many financial indicators are pointing to a looming global recession. This means that companies will be tightening their belts and drastically cutting down on their discretionary spending. What does...]]></description>
      <content:encoded><![CDATA[<p>Many financial indicators are pointing to a looming global recession. This means that companies will be tightening their belts and drastically cutting down on their discretionary spending. What does this mean for information security industry? And what can CISOs do to recession proof their security programs? </p>

<p>This means leaner security organizations (yes that means lay offs), significantly reduced spending on security consultants and contractors, and squeezing the most out of every buck that is spent for information security. This would also mean longer sales cycles for security vendors, cost taking precedence over functionality. From a CISO perspective, it means more justification for security budgets, begging other parts of the business to fund security projects, and pushing existing vendors to provide more for the same amount of dollars. </p>

<p>Some people see a silver lining to all this. Here is what they say, “When things get tough, businesses will more likely to focus on what they do best and hand off operational tasks to an outsourcer.” Many on-shore and off-shore providers have had double digit growth in their managed security businesses in the past. But here is the dirty little secret of security outsourcing - many times it does not save you costs. A lot of times you end up spending the same, if not more, on outsourcing. You could potentially get some cost benefits by working with an off shore provider, but due to the declining dollar that proposition is also becoming pretty bleak. </p>

<p>We may be better off than other areas of IT because the demand for information security professionals is still outstripping supply, but expect a lot more organizations to pick people from other parts of their organization and move them to information security rather than hiring new people. Unfortunately, this means lesser jobs for all of us – the real security folk. </p>]]></content:encoded>
      <pubDate>Wed, 13 Feb 2008 07:58:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/information security professionals">information security professionals</category>
      <category domain="http://securityratty.com/tag/businesses">businesses</category>
      <category domain="http://securityratty.com/tag/security businesses">security businesses</category>
      <category domain="http://securityratty.com/tag/fund security projects">fund security projects</category>
      <category domain="http://securityratty.com/tag/real security folk">real security folk</category>
      <category domain="http://securityratty.com/tag/information security industry">information security industry</category>
      <category domain="http://securityratty.com/tag/security budgets">security budgets</category>
      <source url="http://blogs.forrester.com/srm/2008/02/recession-bring.html">Recession brings a downturn in security spending and jobs</source>
    </item>
  </channel>
</rss>
