<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: benefit]]></title>
    <link>http://securityratty.com/tag/benefit</link>
    <description></description>
    <pubDate>Thu, 07 Aug 2008 12:12:55 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Magic Quadrant for Application Delivery Controllers]]></title>
      <link>http://securityratty.com/article/224089e5d76323e4bbe5b8297445e9f4</link>
      <guid>http://securityratty.com/article/224089e5d76323e4bbe5b8297445e9f4</guid>
      <description><![CDATA[Source: Citrix) Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses of solutions, and provides Magic Quadrant reporting for a quick comparison across...]]></description>
      <content:encoded><![CDATA[<b>(Source: Citrix)</b> Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses of solutions, and provides Magic Quadrant reporting for a quick comparison across all vendors.  Learn from Gartner how you can benefit from an all-in-one device like Citrix NetScaler that delivers the highest levels of availability, performance and security.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=71TQZs"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=71TQZs" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/378143212" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 29 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/application delivery controllers">application delivery controllers</category>
      <category domain="http://securityratty.com/tag/magic quadrant">magic quadrant</category>
      <category domain="http://securityratty.com/tag/citrix">citrix</category>
      <category domain="http://securityratty.com/tag/citrix netscaler">citrix netscaler</category>
      <category domain="http://securityratty.com/tag/gartner">gartner</category>
      <category domain="http://securityratty.com/tag/quick comparison">quick comparison</category>
      <category domain="http://securityratty.com/tag/all-in-one device">all-in-one device</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/solutions">solutions</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/378143212/whitepapers.do">Magic Quadrant for Application Delivery Controllers</source>
    </item>
    <item>
      <title><![CDATA[Gemba & The Journey]]></title>
      <link>http://securityratty.com/article/e207879f33e6a822f639d8ac96c2c6e7</link>
      <guid>http://securityratty.com/article/e207879f33e6a822f639d8ac96c2c6e7</guid>
      <description><![CDATA[Couple of things first before we get to the next post in the Hansei series. First, Jon Robinson was thinking about reputation damage and stock price and wrote a very lucid and smart post on the...]]></description>
      <content:encoded><![CDATA[<p>Couple of things first before we get to the next post in the Hansei series.  First, <a href="http://jonrobinson.tumblr.com/post/47570999/alexs-post-got-me-thinking-about-reputation">Jon Robinson was thinking about reputation damage and stock price</a> and wrote a very lucid and smart post on the subject:</p>
<blockquote><p>Companies think they own their reputation, but in reality they don’t. A reputation is the aggregate of the popular opinion about you. Opinions, or thoughts, belong to an individual, true or not, and a company doesn’t own a person’s thoughts, therefore a company doesn’t own its reputation. QED.</p></blockquote>
<p><em><strong>Yes</strong></em>.  Absolutely.  In fact, there are already changes in the works to the FAIR model that reflect this line of thinking that will allow us to approach reputation damage in a much more rational manner that anything else I&#8217;ve seen to date.</p>
<p><span style="color: #008000;"><strong>Second</strong></span>, RE:  Hansei &amp; Kaizen, Richard left the following comment.</p>
<blockquote><p>I don’t agree with your view on Gemba even if we live in a virtual world. Look into any company’s wiring closet and you’ll immediately see a reflection in its maturity from the state of the equipment, the labeling / documentation and overall neatness. “Man with messy wiring closet, will have messy virtual servers.”</p>
<p>However, the true benefit in Gemba is not in the actual visual inspection. It is in in the journey from your desk to the data center / wiring closet.</p></blockquote>
<p>I agree that the benefit is in the journey.  I can&#8217;t see the wiring closet as the main destination (I just don&#8217;t see it as a useful prior).  Maybe I wasn&#8217;t clear, or was taking for granted that you guys have been reading the blog for the past 2 years, but the journey needs to be to the LOB that owns the application.  The example most given when describing Gemba is going to the production line to look at the issue that causes a problem in the ability to create and sell a car.  The &#8220;security&#8221; journey is not to the wiring closet, but to the system itself and the logs that we have for the system and whatever network-based controls might be applicable.  And we, as an industry, are just starting to understand that this &#8220;security&#8221; is only part of the picture.  The whole picture is represented by the factors that create risk.</p>
<p>And for our &#8220;risk journey&#8221; that security journey is only a one of serveral useful pieces of prior information for use in analysis.  For risk we have to also journey back to the &#8220;production line&#8221;, or, in our case, to the application/LOB owner.  It may also be to corporate counsel, to marketing, to all sorts of other places in the enterprise because probable losses (a necessary measurement we need in order to understand risk) may come from many different sources in the organization.  For those with FAIR knowledge, think of the six forms of loss to get an idea of what sorts of journeys we need to make.</p>
<p>This is why tomorrow&#8217;s post is designed to look at<em><strong> what should we be reflecting about</strong></em>, and <em><strong>what is needed for reflection</strong></em>.</p>
<p><span style="color: #808080;"><em>Hint:  our models for risk &amp; risk management can give us an idea of how to create structure around Hansei for the IRM program.</em></span></p>
]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 13:27:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/journey">journey</category>
      <category domain="http://securityratty.com/tag/risk journey">risk journey</category>
      <category domain="http://securityratty.com/tag/approach reputation damage">approach reputation damage</category>
      <category domain="http://securityratty.com/tag/reputation">reputation</category>
      <category domain="http://securityratty.com/tag/security journey">security journey</category>
      <category domain="http://securityratty.com/tag/reputation damage">reputation damage</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/gemba">gemba</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=404">Gemba &amp; The Journey</source>
    </item>
    <item>
      <title><![CDATA[Red Light Cameras Don't Work]]></title>
      <link>http://securityratty.com/article/8352bdbeaa301a76267200c64791415d</link>
      <guid>http://securityratty.com/article/8352bdbeaa301a76267200c64791415d</guid>
      <description><![CDATA[Interesting : the solution to one problem causes another. &quot;The rigorous studies clearly show red-light cameras don't work,&quot; said lead author Barbara Langland-Orban, professor and chair of health...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.ridelust.com/red-light-cameras-just-dont-work/">Interesting</a>: the solution to one problem causes another.</p>

<blockquote>"The rigorous studies clearly show red-light cameras don't work," said lead author Barbara Langland-Orban, professor and chair of health policy and management at the USF College of Public Health. "Instead, they increase crashes and injuries as drivers attempt to abruptly stop at camera intersections."

<p>Comprehensive studies from North Carolina, Virginia, and Ontario have all reported cameras are associated with increases in crashes. The study by the Virginia Transportation Research Council also found that cameras were linked to increased crash costs. The only studies that conclude cameras reduced crashes or injuries contained "major research design flaws," such as incomplete data or inadequate analyses, and were always conducted by researchers with links to the Insurance Institute for Highway Safety. The IIHS, funded by automobile insurance companies, is the leading advocate for red-light cameras since insurance companies can profit from red-light cameras by way of higher premiums due to increased crashes and citations.</blockquote></p>

<p>And, of course, the agenda of the government is to increase revenue due to fines:</p>

<blockquote>A 2001 paper by the Office of the Majority Leader of the U.S. House of Representatives reported that red-light cameras are "a hidden tax levied on motorists." The report came to the same conclusions that all of the other valid studies have, that red-light cameras are associated with increased crashes and that the timings at yellow lights are often set too short to increase tickets for red-light running. That's right, the state actually tampers with the yellow light settings to make them shorter, and more likely to turn red as you're driving through them.

<p>In fact, six U.S. cities have been found guilty of shortening the yellow light cycles below what is allowed by law on intersections equipped with cameras meant to catch red-light runners. Those local governments have completely ignored the safety benefit of increasing the yellow light time and decided to install red-light cameras, shorten the yellow light duration, and collect the profits instead.</p>

<p>The cities in question include Union City, CA, Dallas and Lubbock, TX, Nashville and Chattanooga, TN, and Springfield, MO, according to Motorists.org, which collected information from reports from around the country.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=GkyduK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=GkyduK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=gARYoK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=gARYoK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 08:19:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/red">red</category>
      <category domain="http://securityratty.com/tag/red-light">red-light</category>
      <category domain="http://securityratty.com/tag/red-light runners">red-light runners</category>
      <category domain="http://securityratty.com/tag/install red-light cameras">install red-light cameras</category>
      <category domain="http://securityratty.com/tag/cameras">cameras</category>
      <category domain="http://securityratty.com/tag/red-light cameras">red-light cameras</category>
      <category domain="http://securityratty.com/tag/conclude cameras">conclude cameras</category>
      <category domain="http://securityratty.com/tag/studies">studies</category>
      <category domain="http://securityratty.com/tag/rigorous studies">rigorous studies</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/red_light_camer.html">Red Light Cameras Don't Work</source>
    </item>
    <item>
      <title><![CDATA[ScienceLogics 5-Year Anniversary]]></title>
      <link>http://securityratty.com/article/1287b8dac0ea60512bed5f303d15fe55</link>
      <guid>http://securityratty.com/article/1287b8dac0ea60512bed5f303d15fe55</guid>
      <description><![CDATA[August 2003. The largest blackout in U.S. history darkens the Northeast and Midwest, the Blaster worm has been unleashed and Madonna and Britney create a stir at the 2003 MTV Music Video Awards . In...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="164" alt="B-day Cake" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/b-day-cake1.jpg" width="244" align="left" border="0"> August 2003. The largest <a href="http://blogs.wsj.com/biztech/2008/08/13/celebrating-the-anniversary-of-the-big-blackout/?mod=djemTECH" target="_blank">blackout</a> in U.S. history darkens the Northeast and Midwest, the <a href="http://news.cnet.com/2010-1001-5117862.html" target="_blank">Blaster worm</a> has been unleashed and Madonna and Britney create a stir at the <a href="http://en.wikipedia.org/wiki/2003_MTV_Video_Music_Awards" target="_blank">2003 MTV Music Video Awards</a>. In the midst of this <a href="http://www.grid.unep.ch/product/publication/download/ew_heat_wave.en.pdf" target="_blank">hot summer</a> madness, ScienceLogic was founded.
<p>To kick off our celebration of our first five years, we asked <a href="http://www.sciencelogic.com/leadership.htm" target="_blank">ScienceLogic founders</a> Dave Link, Richard Chart and Chris Cordray for their thoughts and memories on events leading to today’s milestone. How and why did they set out on this venture? What happened along the way – expected and unexpected? Why were they successful in times when other new (and established) businesses have come and <a href="http://en.wikipedia.org/wiki/Category:2003_disestablishments" target="_blank">gone</a>?
<p><b>How did you three put together this team?</b>
<p>We all worked together at a large Managed Service Provider for a couple of years before leaving to start ScienceLogic, so we all knew each other and knew our collective strengths. More importantly, each of us had worked with network management tools on some level (sales and marketing, engineering and product development), and knew first-hand all of the customer pain points, from every perspective. So we left and began rapidly figuring out how to build a better network management solution based upon our real world operational experience..
<p><strong>Dave:</strong> One interesting aspect is that our areas of expertise don’t overlap, which has contributed to our success. Chris is excellent with developing the product front-end and interface, Richard handled the backend architecture and engineering and I focused on the technical business side of sales and marketing. Our roles have been to build a product that works well and that provides real value to operations teams that experience the same day to day frustrations that we felt.<b></b>
<p><b>Whose idea was it to start the company?</b>
<p><strong>Dave:</strong> It was really a collective effort. We were all passionate about “getting it right” and not just starting a company. We knew the industry need and between us, we had the knowledge and skill sets to address all of the right aspects of developing a product and a building a business around it.
<p><b>What process did you go through to get started?</b>
<p><strong>Richard:</strong> From the beginning we knew the type of solution the market needed and we knew that we wanted to build it as an appliance. From different vantage points, we had each experienced the effects of long, difficult and expensive installations that still exist with traditional network tools. Every install has unique variations: there are always different server types, varying hardware and software versions, different patches installed, and on and on. Every installation was time consuming and unpredictable. We knew that an appliance model would address all of these variables and save a lot of time on how quickly customers could achieve immediate value.
<p>The harder decisions were around actually starting the business, assessing the market and of course determining the product pricing.
<p><b>EM7 completely flips the traditional model of complex, lengthy and expensive deployments. How did you convince others that the EM7 Meta-Appliance product was valid?</b>
<p><strong>Dave:</strong> Yes, EM7 totally disrupts the traditional model for network management. While others take a narrow approach, we intentionally designed EM7 to focus on the broad problem – managing the data center. How do you cover a variety of technologies and make sure they work seamlessly together? The vision was to make it easier, not harder, for customers.
<p><strong>Chris:</strong> I have to give it to Dave – very early on, he realized the power of a demo. If Dave could get in front of someone, he’d make them a believer. He’d use the Peter Falk/Columbo technique of “let me show you one more thing.” It was very effective. It’s getting easier, but even today people sometimes have to see EM7 in action before they become believers.
<p><b>Can you describe the early days of running a new business?</b>
<p><strong>Dave:</strong> ScienceLogic is a classic case of entrepreneurship. For the first year we worked out of our basements. We kept the costs low in every conceivable way and spent the first year developing the product before we even made a sale.
<p><strong>Chris:</strong> We stayed at lots of odd places when we were on the road, took cheap flights with multiple layovers and purchased lots of our first test equipment on eBay. This was during the dot-com bust so there was lots of equipment for sale on eBay, really cheap!
<p><strong>Richard:</strong> The amount of equipment I had in my house was absolutely crazy. Back then, servers were huge – I had a Cisco 6509 Catalyst, a Compaq Proliant DL380, Brocade switch, IBM Netfinity 4500R, and tons of other machines.
<p><strong>Chris:</strong> I had to install a new circuit box at home because I was blowing breakers. I remember when that 6509 crashed, we revived it and it died again. The second death was final.
<p><b>So you started in your houses – what was your first office space?</b>
<p><strong>Dave:</strong> My friend, the CEO at Ernst &amp; Young Technology had a few extra cubes and a data center in their office that they graciously allowed us to use. Their help was an important step in helping us really formalize the business. We started doing well and adding people, but ironically, their company was downsizing. Before long, many of their original YET people were gone and the ScienceLogic team kept growing in to the open cubes.
<p>Our first leased space was converted warehouse space in Chantilly, VA that once housed an internet radio station. It was cool – it had a large salt water fish tank, a loft, a spiral staircase and a Star Trek door that retracted into the walls with the customary lights and “whooshing” sound.
<p>We outgrew the Chantilly space, leading to our current office in Reston, VA.
<p><b>Who was the first ScienceLogic customer?</b>
<p>Our first paying customer was <a href="http://martinspoint.com/" target="_blank">Martins Point Health Care</a>. We deployed there in July 2004 and are pleased to say they continue to be a ScienceLogic customer. Other early (and still) EM7 <a href="http://www.sciencelogic.com/customers.htm" target="_blank">customers</a> include Navy Knowledge Online and the Department of Transportation. Nearly all of our customers are still actively using EM7 and renewing their maintenance.
<p><b>Where do you see the company in the next 5, 10 or 15 years?</b>
<p>Well, our revenue has doubled year-over-year in each of the last three years, so of course we’d like to continue to grow like that or even faster. In five years we’ve gone from three founders to the point where Dave does not know everyone’s fondest childhood memory. We’ll continue to scale our growth to cover the demands of our growing customer base.
<p><b>Where do you see the industry going over the coming years?</b>
<p><strong>Chris:</strong> IT is always moving and gaining in complexity, so network management is also becoming more complicated. There’s increasing diversity, new standards, virtualization and cloud computing. All of these are today’s technologies. Customers have a mix of the old and the new, so EM7 has to accommodate and support both.
<p><strong>Richard:</strong> Each generation of products has a new set of ways to monitor, but the “old” doesn’t go away. Even when a new, hot technology comes along, the old technologies still need to be supported. We work to ensure EM7 keeps up with both.
<p><strong>Dave:</strong> After five years we’re just hitting our stride and we’re just now reaching the tipping point in awareness of ScienceLogic and EM7. We’re all still passionate about the product and as Chris and Rich said, there’s still a lot do. We’ll continue disrupting the market with EM7. Our vision hasn’t changed, and with the increasing levels of automation that customers demand, the market needs are greater than ever. Our future is as bright, or brighter, than ever and we’ll continue to be looking for smart ways to automate traditionally manual IT Operations processes.
<p><b>What’s your advice for someone interested in starting their own business?</b>
<p><strong>Chris:</strong> Be passionate. That’s what has gotten me through the tough times. I didn’t really appreciate this thought when I heard others say it before. But it’s very true.
<p><strong>Richard:</strong> I agree. We met and talked with lots of people who told us, “That’s been done before.” But we kept going because we truly believed in what we were doing and we knew that while our approach was different, that it would be successful.
<p><strong>Richard:</strong> Be fearless. You can’t be too nervous and you need to be able to expect and handle the stress because it will be there. You have to learn to accept the stressful times as a necessary part of the process of starting out on your own.
<p><strong>Dave:</strong> Know your niche from the beginning and give potential customers a compelling reason to trust you and really benefit from your solution. You have to know the problem, see the gap and have a clear and consistent vision of how to solve the problem. Then you have to execute. If you don’t build your team with “doers” you won’t make it.
<p><strong>Chris:</strong> It helps to have friends. ScienceLogic was built on friendships and relationships, starting with the three of us. If you look at our team, most of our hires are referrals – people who developed and maintained great connections with other great people throughout their careers. Maintain your connections and keep in touch with your network of friends.</p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 18:39:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/em7 completely flips">em7 completely flips</category>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/network management">network management</category>
      <category domain="http://securityratty.com/tag/network management tools">network management tools</category>
      <category domain="http://securityratty.com/tag/em7 meta-appliance product">em7 meta-appliance product</category>
      <category domain="http://securityratty.com/tag/sciencelogic team">sciencelogic team</category>
      <category domain="http://securityratty.com/tag/team">team</category>
      <category domain="http://securityratty.com/tag/front">front</category>
      <category domain="http://securityratty.com/tag/product front-end">product front-end</category>
      <source url="http://blog.sciencelogic.com/sciencelogics-5-year-anniversary/08/2008">ScienceLogics 5-Year Anniversary</source>
    </item>
    <item>
      <title><![CDATA[Virginia Tech intros another emergency notification system]]></title>
      <link>http://securityratty.com/article/1cc1a31909fa60cd278c4fc81af0b55e</link>
      <guid>http://securityratty.com/article/1cc1a31909fa60cd278c4fc81af0b55e</guid>
      <description><![CDATA[When Virginia Tech's 28,000 students return to classes for the fall on Monday, they will benefit from another emergency mass notification system added over the summer in response to the April 2007...]]></description>
      <content:encoded><![CDATA[When Virginia Tech's 28,000 students return to classes for the fall on Monday, they will benefit from another emergency mass notification system added over the summer in response to the April 2007 campus killings of 32 people by a lone gunman.]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/virginia tech">virginia tech</category>
      <category domain="http://securityratty.com/tag/students return">students return</category>
      <category domain="http://securityratty.com/tag/campus killings">campus killings</category>
      <category domain="http://securityratty.com/tag/lone gunman">lone gunman</category>
      <category domain="http://securityratty.com/tag/classes">classes</category>
      <category domain="http://securityratty.com/tag/response">response</category>
      <category domain="http://securityratty.com/tag/summer">summer</category>
      <category domain="http://securityratty.com/tag/monday">monday</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <source url="http://www.networkworld.com/news/2008/082008-virginia-tech-intros-another-emergency.html?fsrc=rss-security">Virginia Tech intros another emergency notification system</source>
    </item>
    <item>
      <title><![CDATA[No Trademark for Cloud Computing]]></title>
      <link>http://securityratty.com/article/4b9f7e842fb8a79ceb2a5ea157dab13c</link>
      <guid>http://securityratty.com/article/4b9f7e842fb8a79ceb2a5ea157dab13c</guid>
      <description><![CDATA[Just a couple of weeks ago, it was reported that Dell was in the final stages of being granted a trademark on Cloud Computing shocking and amusing pretty much everyone except for possibly Dell...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="157" alt="clouds-jwn6" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/clouds-jwn6.jpg" width="240" align="left" border="0" /> Just a couple of weeks ago, it was reported that Dell was in the final stages of being granted a trademark on &#8220;Cloud Computing&#8221; &#8211; <a href="http://languagelog.ldc.upenn.edu/nll/?p=434#more-434" target="_blank">shocking and amusing</a> pretty much everyone except for possibly Dell employees. But apparently the US Patent and Trademark Office paid attention to the flurry of negative responses and has since <a href="http://samj.net/2008/08/dells-notice-of-allowance-for-cloud.html" target="_blank">cancelled their &#8220;Notice of Allowance&#8221;</a> for the trademark. </p>
<p>I&#8217;d like to give everyone the benefit of the doubt here; perhaps Dell was using it in a much narrower sense. Perhaps the term has really only been used more commonly since the time Dell first applied for the trademark back in March 2007 and now. BUT&#8230;</p>
<p>- Dell&#8217;s definition is quite broad and certainly not Dell-specific. <a href="http://www.eweek.com/c/a/IT-Infrastructure/Dell-Attempts-to-Trademark-Cloud-Computing/" target="_blank">&#8220;The design of computer hardware for use in datacenters and mega-scale computing environments for others; customization of computer hardware for use in data centers and mega-scale computing environments for others; design and development of networks for use in data centers and mega-scale computing environments for others.&#8221;</a> Strike One.</p>
<p>- And according to the Wall Street Journal&#8217;s research, &#8220;<a href="http://blogs.wsj.com/biztech/2008/08/06/dells-tech-jargon-trademark/" target="_blank">cloud computing&#8221; has been in regular use since 2001</a>. Strike Two.</p>
<p>So now the &#8220;case&#8221; has been returned to examination and hopefully the PTO will follow up on everyone else&#8217;s research on this and decide that yes, cloud computing is one of those broad, ubiquitous terms that should NOT be trademarked by a single company. </p>
]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 16:01:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/trademark">trademark</category>
      <category domain="http://securityratty.com/tag/dell">dell</category>
      <category domain="http://securityratty.com/tag/time dell">time dell</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/dell-specific">dell-specific</category>
      <category domain="http://securityratty.com/tag/possibly dell employees">possibly dell employees</category>
      <category domain="http://securityratty.com/tag/trademark office">trademark office</category>
      <category domain="http://securityratty.com/tag/computer hardware">computer hardware</category>
      <category domain="http://securityratty.com/tag/data centers">data centers</category>
      <source url="http://blog.sciencelogic.com/no-trademark-for-cloud-computing/08/2008">No Trademark for Cloud Computing</source>
    </item>
    <item>
      <title><![CDATA[Memo to the President]]></title>
      <link>http://securityratty.com/article/f55b7cd26cfc6057b3118e4828224bba</link>
      <guid>http://securityratty.com/article/f55b7cd26cfc6057b3118e4828224bba</guid>
      <description><![CDATA[Obama has a cyber security plan
It's basically what you would expect : Appoint a national cyber security advisor, invest in math and science education, establish standards for critical infrastructure,...]]></description>
      <content:encoded><![CDATA[<p>Obama has a cyber security plan.</p>

<p>It's basically what <a href="http://www.barackobama.com/2008/07/16/remarks_of_senator_barack_obam_95.php">you</a> would <a href="http://www.barackobama.com/2008/07/16/fact_sheet_obamas_new_plan_to.php">expect</a>: Appoint a national cyber security advisor, invest in math and science education, establish standards for critical infrastructure, spend money on enforcement, establish national standards for securing personal data and data-breach disclosure, and work with industry and academia to develop a bunch of needed technologies.</p>

<p>I could comment on the plan, but with security the devil is always in the details -- and, of course, at this point there are few details.  But since he brought up the topic -- McCain supposedly is "<a href="http://www.scmagazineus.com/Cybersecurity-and-the-presidential-campaign/article/112566/">working on the issues</a>" as well -- I have three pieces of policy advice for the next president, whoever he is. They're too detailed for campaign speeches or even position papers, but they're essential for improving information security in our society.  Actually, they apply to national security in general.  And they're things only government can do.</p>

<p>One, use your immense buying power to improve the security of commercial products and services. One property of technological products is that most of the cost is in the development of the product rather than the production. Think software: The first copy costs millions, but the second copy is free.</p></p>

<p>You have to secure your own government networks, military and civilian. You have to buy computers for all your government employees. Consolidate those contracts, and start putting explicit security requirements into the RFPs. You have the buying power to get your vendors to make serious security improvements in the products and services they sell to the government, and then we all benefit because they'll include those improvements in the same products and services they sell to the rest of us. We're all safer if information technology is more secure, even though the bad guys can <a href="http://www.schneier.com/blog/archives/2008/05/dualuse_technol_1.html">use it, too</a>.

<p>Two, <a href="http://www.schneier.com/essay-141.html">legislate results and not methodologies</a>. There are a lot of areas in security where you need to pass laws, where the <a href="http://www.schneier.com/blog/archives/2007/01/information_sec_1.html">security externalities</a> are such that the market fails to provide adequate security. For example, software companies who sell insecure products are exploiting an externality just as much as chemical plants that dump waste into the river. But a bad law is worse than no law. A law requiring companies to secure personal data is good; a law specifying what technologies they should use to do so is not.  <a href="http://www.guardian.co.uk/technology/2008/jul/17/internet.security"> Mandating</a> <a href="http://www.schneier.com/essay-025.html">software</a> <a href="http://www.schneier.com/blog/archives/2007/01/information_sec_1.html">liabilities</a> for software failures is <a href=http://www.schneier.com/essay-116.html">good</a>, detailing how is not. Legislate for the results you want and implement the appropriate penalties; let the market figure out how -- that's what markets are good at.  </p>

<p>Three, broadly invest in research. Basic research is risky; it doesn't always pay off. That's why companies have stopped funding it. Bell Labs is gone because nobody could afford it after the AT&T breakup, but the root cause was a desire for higher efficiency and short-term profitability -- not unreasonable in an unregulated business. Government research can be used to balance that by funding long-term research.  </p>

<p>Spread those research dollars wide. Lately, most research money has been <a href="http://query.nytimes.com/gst/fullpage.html?res=9F04E1DB113FF931A35757C0A9639C8B63">redirected</a> through DARPA to near-term military-related projects; that's not good. Keep the earmark-happy Congress from <a href="http://www.ostp.gov/pdf/1pger_earmark.pdf">dictating</a> how the money is spent. Let the NSF, NIH and other funding agencies decide how to spend the money and don't try to micromanage.  Give the national laboratories lots of freedom, too. Yes, some research will sound silly to a layman. But you can't predict what will be useful for what, and if funding is really peer-reviewed, the average results will be much better. Compared to corporate tax breaks and other subsidies, this is chump change.</p>

<p>If our research capability is to remain vibrant, we need more science and math students with decent elementary and high school preparation. The declining interest is partly from the perception that scientists don't get rich like lawyers and dentists and stockbrokers, but also because science isn't valued in a country full of creationists. One way the president can help is by trusting scientific advisers and not overruling them for political reasons.</p>

<p>Oh, and get rid of those post-9/11 restrictions on student visas that are <a href="http://www7.nationalacademies.org/visas/Statement%20on%20Visa%20Problems.pdf">causing</a> (.pdf) so many top students to do their graduate work in Canada, Europe and Asia instead of in the United States. Those restrictions will <a href="http://www.aau.edu/research/Gast.pdf">hurt us</a> immensely in the long run.</p>

<p>Those are the three big ones; the rest is in the details. And it's the details that matter. There are lots of serious issues that you're going to have to tackle: data privacy, data sharing, data mining, government eavesdropping, government databases, use of Social Security numbers as identifiers, and so on. It's not enough to get the broad policy goals right. You can have good intentions and enact a good law, and have the whole thing completely gutted by two sentences sneaked in during rulemaking by some lobbyist.</p>

<p>Security is both subtle and complex, and -- unfortunately -- it doesn't readily lend itself to normal legislative processes. You're used to finding consensus, but security by consensus rarely works. On the internet, security standards are much worse when they're developed by a consensus body, and much better when someone just does them. This doesn't always work -- a lot of crap security has come from companies that have "just done it" -- but nothing but mediocre standards come from consensus bodies.  The point is that you won't get good security without pissing someone off: The information broker industry, the voting machine industry, the telcos. The normal legislative process makes it hard to get security right, which is why I don't have much optimism about what you can get done.</p>

<p>And if you're going to appoint a cyber security czar, you have to give him actual budgetary authority -- otherwise he won't be able to get anything done, either.</p>

<p>This essay <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/08/securitymatters_0807">originally appeared</a> on Wired.com.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=LZGCXK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=LZGCXK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=56vyIK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=56vyIK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 02:36:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security standards">security standards</category>
      <category domain="http://securityratty.com/tag/improvements">improvements</category>
      <category domain="http://securityratty.com/tag/security improvements">security improvements</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/government research">government research</category>
      <category domain="http://securityratty.com/tag/cyber security plan">cyber security plan</category>
      <category domain="http://securityratty.com/tag/national security">national security</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/memo_to_the_pre.html">Memo to the President</source>
    </item>
    <item>
      <title><![CDATA[Economist.com - Confessions of a Risk Manager]]></title>
      <link>http://securityratty.com/article/536365450db644abfa519cdc03dc2c4c</link>
      <guid>http://securityratty.com/article/536365450db644abfa519cdc03dc2c4c</guid>
      <description><![CDATA[I was reading the Economist this week and came across an excellent article titled &quot; Confessions of a Risk Manager

In the article a risk manager for a major financial institution talks about managing...]]></description>
      <content:encoded><![CDATA[I was reading the <a href="http://www.economist.com/">Economist </a>this week and came across an excellent article titled "<a href="http://www.economist.com/finance/displaystory.cfm?story_id=11897037">Confessions of a Risk Manager</a>".<br /><br />In the article a risk manager for a major financial institution talks about managing risks and how the risk department was viewed as an obstacle by the rest of the business.  I'll just quote a section here so you can see that governance roles, especially those involving trade-offs of risk vs. return are difficult not just in security.<br /><blockquote>In their eyes, we were not earning money for the bank. Worse, we had the power to say no and therefore prevent business from being done. Traders saw us as obstructive and a hindrance to their ability to earn higher bonuses. They did not take kindly to this. Sometimes the relationship between the risk department and the business lines ended in arguments.   . . .<br /><br />Tactfully explaining why we said no was not our forte. Traders were often exasperated as much by how they were told as by what they were told.  <p>At the root of it all, however, was—and still is—a deeply ingrained flaw in the decision-making process. In contrast to the law, where two sides make an equal-and-opposite argument that is fairly judged, in banks there is always a bias towards one side of the argument. The business line was more focused on getting a transaction approved than on identifying the risks in what it was proposing. The risk factors were a small part of the presentation and always “mitigated”. This made it hard to discourage transactions. If a risk manager said no, he was immediately on a collision course with the business line. The risk thinking therefore leaned towards giving the benefit of the doubt to the risk-takers.<br /></p><p>Collective common sense suffered as a result. Often in meetings, our gut reactions as risk managers were negative. But it was difficult to come up with hard-and-fast arguments for why you should decline a transaction, especially when you were sitting opposite a team that had worked for weeks on a proposal, which you had received an hour before the meeting started. In the end, with pressure for earnings and a calm market environment, we reluctantly agreed to marginal transactions.</p></blockquote><br />Every time I read about decision making like this I refer back to an some excellent presentations I've come across by Reidar Bratvold.  He has done some excellent presentations on decision making in the face of risks/uncertainty.<br /><br /><ul><li><a href="www.spe.no/stavanger/doc/Bratvold%20-%20SPE%20Dist%20Lecturer.pdf">Would You Know a Good decision if You Saw One?</a></li><li><a href="http://www.reidar-bratvold.com/Decision%20Making%20Under%20Uncertainty%20-%20BadenBaden.pdf">Decision Making Under Uncertainty</a></li></ul><img src="http://feeds.feedburner.com/~r/SecurityRetentive/~4/362069047" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 04:42:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk manager">risk manager</category>
      <category domain="http://securityratty.com/tag/risk factors">risk factors</category>
      <category domain="http://securityratty.com/tag/risk-takers">risk-takers</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/business line">business line</category>
      <category domain="http://securityratty.com/tag/risk managers">risk managers</category>
      <category domain="http://securityratty.com/tag/risk department">risk department</category>
      <category domain="http://securityratty.com/tag/business lines">business lines</category>
      <source url="http://feeds.feedburner.com/~r/SecurityRetentive/~3/362069047/economistcom-confessions-of-risk.html">Economist.com - Confessions of a Risk Manager</source>
    </item>
    <item>
      <title><![CDATA[Sun To Pick Up Java Droppings In Future]]></title>
      <link>http://securityratty.com/article/75f4432050f492630a7682f7f127e94a</link>
      <guid>http://securityratty.com/article/75f4432050f492630a7682f7f127e94a</guid>
      <description><![CDATA[Thanks to a reader for pointing out that a planned update to Sun's Java platform, at least on Windows, will address the old version problem . As I have blogged recently, the current Java versions...]]></description>
      <content:encoded><![CDATA[Thanks to a reader for pointing out that <a href="https://jdk6.dev.java.net/6u10ea.html">a planned update to Sun's Java platform, at least on Windows, will address the old version problem</a>. As I have blogged recently, <a href="http://blogs.eweek.com/cheap_hack/content/patches/java_droppings_on_my_pc.html">the current Java versions leave all the old updates in place when you install a new one</a>. Just this morning, while visiting my mother-in-law I uninstalled about a dozen old Java updates.

Scheduled for release this summer or fall, Java 6 Update 10 (the current version is Update 7; I'm not sure 10 is really going to be the number) will address the problem, at least partly. According to Sun: <blockquote>For current users of Java SE, the JRE update mechanism has also been improved, using a patch-in-place mechanism that translates in a faster and more reliable update process (the patch in place mechanism will take effect for end users who upgrade from this update release or later to a new update release). As an added benefit, follow-on update releases will no longer be listed as separate items in the Windows "Add or Remove Programs" dialog. </blockquote> 

It sounds to me from that description as if currently old versions will still be there, but going forward new versions will overwrite the most recent one instead of leaving it in place and installing a new one.

As I said, timing cues in the docs are a little confusing; Can it really be 3 updates from now (Java 6 Update 7 is very recent), yet still come out this fall? The sooner the better if you ask me.<img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/ZdVMy8-i2WA" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 10 Aug 2008 17:27:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/java">java</category>
      <category domain="http://securityratty.com/tag/java platform">java platform</category>
      <category domain="http://securityratty.com/tag/current java versions">current java versions</category>
      <category domain="http://securityratty.com/tag/patch-in-place mechanism">patch-in-place mechanism</category>
      <category domain="http://securityratty.com/tag/mechanism">mechanism</category>
      <category domain="http://securityratty.com/tag/versions">versions</category>
      <category domain="http://securityratty.com/tag/sun">sun</category>
      <category domain="http://securityratty.com/tag/current users">current users</category>
      <category domain="http://securityratty.com/tag/patch">patch</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/ZdVMy8-i2WA/sun_to_pick_up_java_droppings_in_future.html">Sun To Pick Up Java Droppings In Future</source>
    </item>
    <item>
      <title><![CDATA[Microsoft and BearingPoint see space to play in the Enterprise GRC market]]></title>
      <link>http://securityratty.com/article/36af1d0bb845709d797550944d74b9e3</link>
      <guid>http://securityratty.com/article/36af1d0bb845709d797550944d74b9e3</guid>
      <description><![CDATA[Earlier this week in a joint press release, Microsoft and BearingPoint announced the new BearingPoint Enterprise Governance, Risk, and Compliance product offering. Ok... it will be a while before the...]]></description>
      <content:encoded><![CDATA[<p><img border="0" src="http://www.forrester.com/role_based/images/author/imported/forresterDotCom/Analyst_Photos/Silhouette/Color/Chris-McClean.gif" alt="Chris McClean" title="Chris McClean" style="margin: 0px 5px 5px 0px; float: left;" /></p>

<p>Earlier this week in a joint press release, Microsoft and BearingPoint announced the new <a href="http://www.businesswire.com/portal/site/google/?ndmViewId=news_view&amp;newsId=20080805005278&amp;newsLang=en">BearingPoint Enterprise Governance, Risk, and Compliance</a> product offering. Ok... it will be a while before the more veteran enterprise GRC vendors start really losing sleep over this deal. But BearingPoint continues to be a <a href="http://www.forrester.com/Research/Document/0,,40476,00.html">top risk consulting firm</a>, and Microsoft’s reach through the business user community will be an attractive benefit for compliance and risk professionals trying to get hundreds or thousands of staff members to contribute to the GRC program. There’s potential here for sure.</p>

<p>With software giants IBM, Oracle, SAP, and now Microsoft increasing their level of commitment in the enterprise GRC space, the 2-3 year market outlook continues to change. The risk and regulatory landscape is only going to get tougher to handle, and the more GRC programs can run seamlessly with existing business processes and applications, the better. The vendors focused solely on GRC still have the advantage for now, but market consolidation is on its way... and it’s coming maybe just a tiny bit faster than it was at the start of this week.</p>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 12:12:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/grc">grc</category>
      <category domain="http://securityratty.com/tag/bearingpoint">bearingpoint</category>
      <category domain="http://securityratty.com/tag/grc programs">grc programs</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/bearingpoint continues">bearingpoint continues</category>
      <category domain="http://securityratty.com/tag/grc program">grc program</category>
      <category domain="http://securityratty.com/tag/top risk">top risk</category>
      <category domain="http://securityratty.com/tag/bearingpoint enterprise governance">bearingpoint enterprise governance</category>
      <category domain="http://securityratty.com/tag/enterprise grc space">enterprise grc space</category>
      <source url="http://blogs.forrester.com/srm/2008/08/microsoft-and-b.html">Microsoft and BearingPoint see space to play in the Enterprise GRC market</source>
    </item>
  </channel>
</rss>
