<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: college]]></title>
    <link>http://securityratty.com/tag/college</link>
    <description></description>
    <pubDate>Mon, 29 Sep 2008 11:08:38 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Judge delays trial of accused Palin e-mail hacker]]></title>
      <link>http://securityratty.com/article/d52677b2a4442562984a1693d81f32f3</link>
      <guid>http://securityratty.com/article/d52677b2a4442562984a1693d81f32f3</guid>
      <description><![CDATA[David Kernell, the Tennessee college student indicted a month ago for allegedly breaking into the e-mail account of former Republican vice presidential candidate Sarah Palin, will face trial next May,...]]></description>
      <content:encoded><![CDATA[David Kernell, the Tennessee college student indicted a month ago for allegedly breaking into the e-mail account of former Republican vice presidential candidate Sarah Palin, will face trial next May, according to court documents.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:75ca0e1b2679abdc8e80e5c04af6a7c1:FEsT5%2Bl42HIIOpJv5TLGUGh418ngBUPLgQUGqDI56ivRF5Dedt8X5fQDn5nGFOLrZ7ztkCiHHKFn'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:912d0323f156b79dc504eb94eec41651:y49LZU3y03lRUchaYpONNawBrfptSu8ql94QVUO20MSKQ3jqdJj2na4yScmu2MNXeRW2O%2BhauSw8Tw%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:02624b5cc90a1c55fe9ba385f37ede12:Y6I2m0f3BQAdR73O1zTHa98zFJ5pnTrmrySEtfdB1mLH8a1ubp396tupsMPonfYq%2BsaOL2INFw8lew%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:f69c9add5cb853b5d220d8bc79a9c74c:schohYltx26WnFfsYtvXfEeUKBL8E3S3thp2bH4CydbInBgGC4tBBjzy5Ij3sBMCAtYC94EBIWGhnQ%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=58c56c44f9aecaeb7e89af14b6ac5853" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=58c56c44f9aecaeb7e89af14b6ac5853" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tennessee college student">tennessee college student</category>
      <category domain="http://securityratty.com/tag/republican vice presidential">republican vice presidential</category>
      <category domain="http://securityratty.com/tag/trial">trial</category>
      <category domain="http://securityratty.com/tag/e-mail account">e-mail account</category>
      <category domain="http://securityratty.com/tag/david kernell">david kernell</category>
      <category domain="http://securityratty.com/tag/sarah palin">sarah palin</category>
      <category domain="http://securityratty.com/tag/month ago">month ago</category>
      <category domain="http://securityratty.com/tag/court documents">court documents</category>
      <category domain="http://securityratty.com/tag/allegedly">allegedly</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=58c56c44f9aecaeb7e89af14b6ac5853">Judge delays trial of accused Palin e-mail hacker</source>
    </item>
    <item>
      <title><![CDATA[Judge delays trial of accused Palin e-mail hacker]]></title>
      <link>http://securityratty.com/article/e75c336d986a975f6543b085214939aa</link>
      <guid>http://securityratty.com/article/e75c336d986a975f6543b085214939aa</guid>
      <description><![CDATA[The Tennessee college student indicted a month ago for allegedly breaking into the e-mail account of then-Republican vice presidential candidate Sarah Palin will face trial in May 2009, not next month...]]></description>
      <content:encoded><![CDATA[The Tennessee college student indicted a month ago for allegedly breaking into the e-mail account of then-Republican vice presidential candidate Sarah Palin will face trial in May 2009, not next month as originally scheduled, according to recent court documents.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=24395?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=24395?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Sun, 16 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/month">month</category>
      <category domain="http://securityratty.com/tag/recent court documents">recent court documents</category>
      <category domain="http://securityratty.com/tag/then-republican vice presidential">then-republican vice presidential</category>
      <category domain="http://securityratty.com/tag/tennessee college student">tennessee college student</category>
      <category domain="http://securityratty.com/tag/month ago">month ago</category>
      <category domain="http://securityratty.com/tag/trial">trial</category>
      <category domain="http://securityratty.com/tag/e-mail account">e-mail account</category>
      <category domain="http://securityratty.com/tag/sarah palin">sarah palin</category>
      <category domain="http://securityratty.com/tag/allegedly">allegedly</category>
      <source url="http://www.networkworld.com/news/2008/111708-judge-delays-trial-of-accused.html?fsrc=rss-security">Judge delays trial of accused Palin e-mail hacker</source>
    </item>
    <item>
      <title><![CDATA[Data pain: University of Florida warns 333,000 dental school patients of breach]]></title>
      <link>http://securityratty.com/article/d904473800161faddb055d40b9488852</link>
      <guid>http://securityratty.com/article/d904473800161faddb055d40b9488852</guid>
      <description><![CDATA[Reinforcing the image that college networks are highly insecure, the University of Florida is warning more than 330,000 patients of its dental school about a data breach discovered in...]]></description>
      <content:encoded><![CDATA[Reinforcing the image that college networks are highly insecure, the University of Florida is warning more than 330,000 patients of its dental school about a data breach discovered in October.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:c7e4f7d2f7190aa768c0af20fb368a4f:nTUrW2Nh5SUJeCyDofwjl89%2BtBfhX5tWnmV9LCzZekU7iAn%2BTdLkZIkXb1i16jW8OaB8o%2FYhL8sU'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:33db6e5ff4601c9aa8958221a431d571:1HPSuilYEmuKJT15%2BmZ%2FtwDN5vHhxbx2ppPJF1JTH0UJFlqvJXKkpJU1kjxQlXfeuo%2Fxu5K9ukIZ0A%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:eab4f2bd12c4da1c104bdec94d4fac36:Elchp4Tk7owlz%2Fwk9OHjbEwZ%2FQeFJDrSaxiFXACuOFsGbrcpxy84jLidUvnqokb9fwbnI8wxwUoFfQ%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:87d467e0f2ebcf6a16e808aead9744d1:OU9EPwXrVWIoCTCwfvZ7MraPhaw0nnfSimV2m1H9AJMimIJot1SfMet0yaSbC6Up2LEr0I1NCRYlXg%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/feeds/ht.php?t=c&amp;i=20e0491864fd2f8ac88c32d5624a8ad3"><img src="http://www.pheedo.com/feeds/ht.php?t=v&amp;i=20e0491864fd2f8ac88c32d5624a8ad3" border="0" /></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=20e0491864fd2f8ac88c32d5624a8ad3" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dental school">dental school</category>
      <category domain="http://securityratty.com/tag/university">university</category>
      <category domain="http://securityratty.com/tag/highly insecure">highly insecure</category>
      <category domain="http://securityratty.com/tag/college networks">college networks</category>
      <category domain="http://securityratty.com/tag/florida">florida</category>
      <category domain="http://securityratty.com/tag/patients">patients</category>
      <category domain="http://securityratty.com/tag/data breach">data breach</category>
      <category domain="http://securityratty.com/tag/october">october</category>
      <category domain="http://securityratty.com/tag/image">image</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=20e0491864fd2f8ac88c32d5624a8ad3">Data pain: University of Florida warns 333,000 dental school patients of breach</source>
    </item>
    <item>
      <title><![CDATA[University of Florida discloses patient-record data breach]]></title>
      <link>http://securityratty.com/article/2878d5a7d43399af2134ffb2721bb90f</link>
      <guid>http://securityratty.com/article/2878d5a7d43399af2134ffb2721bb90f</guid>
      <description><![CDATA[The University of Florida today disclosed that an attacker gained access to a server in its College of Dentistry where records and other personal information of 330,000 current or former dental...]]></description>
      <content:encoded><![CDATA[The University of Florida today disclosed that an attacker gained access to a server in its College of Dentistry where records and other personal information of 330,000 current or former dental patients were stored.]]></content:encoded>
      <pubDate>Tue, 11 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/university">university</category>
      <category domain="http://securityratty.com/tag/dental patients">dental patients</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/florida">florida</category>
      <category domain="http://securityratty.com/tag/records">records</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/college">college</category>
      <category domain="http://securityratty.com/tag/current">current</category>
      <category domain="http://securityratty.com/tag/server">server</category>
      <source url="http://www.networkworld.com/news/2008/111208-ufla.html?fsrc=rss-security">University of Florida discloses patient-record data breach</source>
    </item>
    <item>
      <title><![CDATA[On Being Informative, or Seeing Through The Fog]]></title>
      <link>http://securityratty.com/article/525775c15c5a11217da6325a35c96ec8</link>
      <guid>http://securityratty.com/article/525775c15c5a11217da6325a35c96ec8</guid>
      <description><![CDATA[UPDATE: @MYRCURIAL from the great site Liquidmatrix says that I need to post the following warning
YOU MAY NOT WANT TO PROCESS THIS PRIOR TO YOUR 11TH CUP OF COFFEE

Carrying on from yesterdays post a...]]></description>
      <content:encoded><![CDATA[<p>==================================</p>
<p>UPDATE:  @MYRCURIAL from the great site <strong><a href="http://www.liquidmatrix.org/blog/">Liquidmatrix</a></strong> says that<strong> <a href="http://twitter.com/myrcurial/status/980493800">I need to post the following warning</a></strong>:</p>
<p><span class="entry-content"> YOU MAY NOT WANT TO PROCESS THIS PRIOR TO YOUR 11TH CUP OF COFFEE</span></p>
<p>==================================</p>
<p>Carrying on from yesterday&#8217;s post a bit, I&#8217;m happy to admit that Chris&#8217; poem is right: we don&#8217;t have nearly the information we need now when we&#8217;re supposed to have &#8220;control&#8221; over our assets, putting things in a hosted/asp/cloud/buzzword model ain&#8217;t going to help our quest for visibility. My intention was/is to show that you need visibility (in part one) and then today explain that unfortunately, that&#8217;s only half the picture.</p>
<p>Today&#8217;s follow-on is about the fact that whatever visibility we can contractually enforce (be it in the &#8220;cloud&#8221; or in our own perimeter) has to be informative (Amrit, this is why I was plugging you with those variance questions on Twitter yesterday).  That is, we can ask whatever IT department (ours, theirs, whomever) for all sorts of information, and maybe they&#8217;ll even give it to us.  But we&#8217;re not really ready to:</p>
<ul>
<li>Know what to ask for</li>
<li>Use it to create wisdom</li>
</ul>
<p>A really salient example of this from outside IT hit my browser this morning.  Now it&#8217;s not at all my intention to be political or endorse one candidate over another.  Those who know me know I&#8217;m fiercely independent.  But this morning there&#8217;s a headline on a well-read news website about how one candidate is now &#8220;+2&#8243; over another in a Gallup poll of &#8220;likely voters&#8221;. The source is <a href="http://www.gallup.com/poll/111124/Gallup-Daily-Likely-Voters-Traditional.aspx"><strong>here</strong></a>.</p>
<p><a href="http://www.gallup.com/poll/111124/Gallup-Daily-Likely-Voters-Traditional.aspx"><img class="alignnone" title="Gallup +2" src="http://www.riskmanagementinsight.com/media/images/weblog/gallup.jpg" alt="" width="597" height="452" /></a></p>
<p>That is a screen grab from Gallup&#8217;s website that shows the &#8220;+2&#8243;.   I have to ask - how informative is this information?  Part of the problem is that Gallup&#8217;s methods are hidden as some sort of &#8220;secret sauce&#8221; (their <strong><a href="http://www.gallup.com/poll/111268/How-Gallups-likely-voter-models-work.aspx">FAQ section</a></strong> doesn&#8217;t help much, either).  But regardless of the quality of the measurement, this &#8220;+2&#8243; has no context - we don&#8217;t really know what this information means with regards to an actual election.  Nor is there any predictive element (I hate the using the word predictive, but it&#8217;s common nomenclature - so there you go).  We don&#8217;t have what we need from this Gallup poll to create wisdom about the ability of either candidate to be elected.</p>
<p>Allow me show you what I mean by way of contrast.  Take a look at Nate Silver&#8217;s work at <strong><a href="http://www.fivethirtyeight.com/">http://www.fivethirtyeight.com/</a></strong>.  Now I&#8217;ve been long familiar with Nate due to his work in baseball.  He&#8217;s been at these sorts of &#8216;predictive&#8217; analytics around our shared passion: creating wisdom from baseball statistics.</p>
<p>What Nate is doing at 538 is applying that acumen from his baseball work to the political process.  He&#8217;s breaking down the vote not just on popularity among likely voters, but in the context of the electoral college, accounting for variance and uncertainty, running Monte Carlo simulations and taking into account all sorts of polling information.  The result is really quite amazing. Here&#8217;s just one graph he presents - it&#8217;s the most similar to the Gallup one above, but you should really visit the site to understand the difference in quality of information and to check out the predictive elements he creates.</p>
<p><a href="http://www.fivethirtyeight.com/"><img class="alignnone" src="http://www.riskmanagementinsight.com/media/images/weblog/538.jpg" alt="" width="376" height="377" /></a></p>
<p><strong>NOT ALL INFORMATION IS CREATED EQUAL</strong>, <em>AND NOT ALL  JUDGMENTS ARE CREATED EQUALLY</em></p>
<p>And take a look at the contrast, here:</p>
<p>On one hand you have Gallup giving us a &#8220;+2&#8243; advantage to a particular candidate.  Now Gallup themselves draws no conclusion but, as digested, how many readers do you think take this as evidence that the election is *really* close?</p>
<p>On the other hand, 538&#8217;s predictions show a 348/189 electoral college split, and one candidate winning 96% of the time in simulated elections.  That doesn&#8217;t seem close at all!</p>
<p><strong>RISK MANAGEMENT</strong></p>
<p>It is these predictive elements that we need in order to make better strategy and decisions.  I&#8217;ve been talking in the past about risk management&#8217;s inability to link current state to systemic causes, and this &#8220;context&#8221; is what predictive analytics provide.  We might have all sorts of visibility into our environment, and measurement of various amounts of variability that visibility gives us. But unless we have context to create wisdom, it&#8217;s all just, as Chris says, &#8220;machinations&#8221;.  <em><strong>We have to move beyond &#8220;+2&#8243;.<br />
</strong></em></p>
<p>So Cloud/Grid/Utility/ASP/TimeShare/Whatever you want to call it - security will have to clean up our own mess first before we can do a good job with or without a perimeter.  Once we can start moving beyond &#8220;+2&#8243; statements, then we can know what sort of visibility we require into an ability to Prevent, Detect, and Respond.</p>
]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 10:18:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gallup">gallup</category>
      <category domain="http://securityratty.com/tag/gallup poll">gallup poll</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/visibility">visibility</category>
      <category domain="http://securityratty.com/tag/electoral college split">electoral college split</category>
      <category domain="http://securityratty.com/tag/predictive analytics provide">predictive analytics provide</category>
      <category domain="http://securityratty.com/tag/predictive analytics">predictive analytics</category>
      <category domain="http://securityratty.com/tag/electoral college">electoral college</category>
      <category domain="http://securityratty.com/tag/wisdom">wisdom</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=503">On Being Informative, or Seeing Through The Fog</source>
    </item>
    <item>
      <title><![CDATA[Boston College converts chapel into high security data center ]]></title>
      <link>http://securityratty.com/article/33f833af84d964164420b7eff2224f13</link>
      <guid>http://securityratty.com/article/33f833af84d964164420b7eff2224f13</guid>
      <description><![CDATA[Boston College's IT department has gotten absolutely religious about securing data three years after a big breach made. So it might seem only fitting that the school's new data center resides inside a...]]></description>
      <content:encoded><![CDATA[Boston College's IT department has gotten absolutely religious about securing data three years after a big breach made. So it might seem only fitting that the school's new data center resides inside a former chapel on land acquired from the Catholic Archdiocese.]]></content:encoded>
      <pubDate>Sun, 12 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/boston college">boston college</category>
      <category domain="http://securityratty.com/tag/chapel">chapel</category>
      <category domain="http://securityratty.com/tag/catholic archdiocese">catholic archdiocese</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/absolutely religious">absolutely religious</category>
      <category domain="http://securityratty.com/tag/land">land</category>
      <category domain="http://securityratty.com/tag/department">department</category>
      <category domain="http://securityratty.com/tag/school">school</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <source url="http://www.networkworld.com/news/2008/101308-boston-college-data-center.html?fsrc=rss-security">Boston College converts chapel into high security data center </source>
    </item>
    <item>
      <title><![CDATA[User-centric security begs for process overhaul]]></title>
      <link>http://securityratty.com/article/b9ad0209f220932489e5adf8ff48ef72</link>
      <guid>http://securityratty.com/article/b9ad0209f220932489e5adf8ff48ef72</guid>
      <description><![CDATA[Ferrum College overhauled people and processes when it implemented user-centric access...]]></description>
      <content:encoded><![CDATA[Ferrum College overhauled people and processes when it implemented user-centric access control.]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/user-centric access control">user-centric access control</category>
      <category domain="http://securityratty.com/tag/ferrum college">ferrum college</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/processes">processes</category>
      <source url="http://www.networkworld.com/supp/2008//100908-trendwatch-access-control-ferrum-college.html?fsrc=rss-security">User-centric security begs for process overhaul</source>
    </item>
    <item>
      <title><![CDATA[Tenn. student indicted for hacking Palin's e-mail]]></title>
      <link>http://securityratty.com/article/7c2688b677117f0cc6d9c24b26f2cd38</link>
      <guid>http://securityratty.com/article/7c2688b677117f0cc6d9c24b26f2cd38</guid>
      <description><![CDATA[The Tennessee college student who came under suspicion as the hacker who broke into the e-mail account of vice presidential candidate Sarah Palin has been indicted by a federal grand...]]></description>
      <content:encoded><![CDATA[The Tennessee college student who came under suspicion as the hacker who broke into the e-mail account of vice presidential candidate Sarah Palin has been indicted by a federal grand jury.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:24a7da4fcaef57af8e5c3adccf4c01ee:lPQi71Ep5ZL2IM%2F7ngVjpVf1tOpD80wO0dLRvEB7nFTnNxAl94aJWuNe4fVtqfFLF6g5VwESQVVm'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:c8c50797519e84ee0cea0140fa7f728b:OGQGpLs76HqHTtZC3cpj6eckPrN%2FGkPjdmJ8hzepjjA7l3sKDmSo9a%2B0j%2B%2Fe7ez2W%2FmPCKpjS%2BmKSQ%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:5e7684fabee745e619f63fa26309daf1:wDUmO4of6AEBzsdJ9y7GREmH%2F1fvt5oY0hh1b0m5uDePMgPFLBrzXQh6sBu6zXv%2B95HvIEDtiy2JGQ%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:5a3d52939d24cd40fe82d50282bcada4:yo2dceotwAllcZFQcJZePMjl2jde0kCytfpxA7zSR%2B0l8%2F9Eb5MO356cgi3YJ9xJ5vV1UwM%2FyvIM8w%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/click.phdo?s=9296a669728ea3309de7ceb244294be0"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=9296a669728ea3309de7ceb244294be0"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=9296a669728ea3309de7ceb244294be0" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/federal grand jury">federal grand jury</category>
      <category domain="http://securityratty.com/tag/tennessee college student">tennessee college student</category>
      <category domain="http://securityratty.com/tag/vice presidential">vice presidential</category>
      <category domain="http://securityratty.com/tag/e-mail account">e-mail account</category>
      <category domain="http://securityratty.com/tag/sarah palin">sarah palin</category>
      <category domain="http://securityratty.com/tag/hacker">hacker</category>
      <category domain="http://securityratty.com/tag/suspicion">suspicion</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=9296a669728ea3309de7ceb244294be0">Tenn. student indicted for hacking Palin's e-mail</source>
    </item>
    <item>
      <title><![CDATA[Federal Charges Filed Against Alleged Cyber Peeping Tom]]></title>
      <link>http://securityratty.com/article/86dd1b9c05f907fcb650cb7699f2de73</link>
      <guid>http://securityratty.com/article/86dd1b9c05f907fcb650cb7699f2de73</guid>
      <description><![CDATA[A college student who allegedly rigged a woman's laptop to snap nude photos through her webcam faces federal charges this week, and tops Threat Level's roundup of cybercrime in the federal...]]></description>
      <content:encoded><![CDATA[A college student who allegedly rigged a woman's laptop to snap nude photos through her webcam faces federal charges this week, and tops Threat Level's roundup of cybercrime in the federal courts.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=5e743031c0cace49ee8f1950873fcf31" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=5e743031c0cace49ee8f1950873fcf31" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=PgSIM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=PgSIM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=jjd9m"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=jjd9m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=pw8om"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=pw8om" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=ohwMM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=ohwMM" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=QboLM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=QboLM" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=MECHm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=MECHm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Dijbm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Dijbm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Php3M"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Php3M" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/410660103" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/410660104" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 16:30:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/federal charges">federal charges</category>
      <category domain="http://securityratty.com/tag/tops threat level">tops threat level</category>
      <category domain="http://securityratty.com/tag/snap nude photos">snap nude photos</category>
      <category domain="http://securityratty.com/tag/federal courts">federal courts</category>
      <category domain="http://securityratty.com/tag/college student">college student</category>
      <category domain="http://securityratty.com/tag/laptop">laptop</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/roundup">roundup</category>
      <category domain="http://securityratty.com/tag/cybercrime">cybercrime</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/410660104/fed-blotter-cha.html">Federal Charges Filed Against Alleged Cyber Peeping Tom</source>
    </item>
    <item>
      <title><![CDATA[(ISC)2s Newest Cash Cow: The CSSLP Certification]]></title>
      <link>http://securityratty.com/article/4d2aae6d17ac0d88114660137a62c55f</link>
      <guid>http://securityratty.com/article/4d2aae6d17ac0d88114660137a62c55f</guid>
      <description><![CDATA[Earlier this week, during the OWASP AppSec 2008 Conference , the people behind the ubiquitous CISSP certification announced their latest creation the Certified Software Security Lifecycle Professional...]]></description>
      <content:encoded><![CDATA[<p>Earlier this week, during the <a href="http://www.owasp.org/index.php?title=OWASP_NYC_AppSec_2008_Conference">OWASP AppSec 2008 Conference</a>, the people behind the ubiquitous CISSP certification announced their latest creation &#8212; the <a href="http://isc2.org/csslp">Certified Software Security Lifecycle Professional</a> (CSSLP).  In front of a captive audience waiting for a 42&#8243; plasma TV to be raffled, the <a href="http://blog.isc2.org/isc2_blog/tipton/index.html">Executive Director of (ISC)2</a> outlined this new certification designed to appeal to application security professionals.  To his credit, Mr. Tipton stated very clearly that the CSSLP is not intended to measure one&#8217;s technical skillset.  Unfortunately, it&#8217;s inevitable that employers will treat it as such.</p>
<p>You can read all the details on their website (except for the part about the certification not being a measure of practical skills).  From what I can tell, the CSSLP is just the CISSP with different CBKs, or Common Bodies of Knowledge.  As with the CISSP, they are going for broad knowledge, not depth.  Starting in June 2009, you can get certified by taking a paper exam, likely a multiple choice test similar to the CISSP.  Why June?  Because the test isn&#8217;t even written yet &#8212; I&#8217;ve heard from several sources that they are actively soliciting their existing pool of CISSPs to help write test questions.</p>
<p>Ah, but what if you can&#8217;t wait that long and want to get certified <i>right away</i>?  You&#8217;re in luck. If you act before March 31, 2009, you can get grandfathered in without even having to take the exam!  That&#8217;s right, they call it the <a href="https://www.isc2.org/cgi-bin/content.cgi?category=1691">CSSLP Experience Assessment</a>, and here are the requirements:</p>
<div style="float:right; margin-left: 15px"><a href="http://www.veracode.com/blog/wp-content/uploads/2008/09/101-hand_with_money.jpg"><img src="http://www.veracode.com/blog/wp-content/uploads/2008/09/101-hand_with_money-191x300.jpg" alt="" title="101-hand_with_money" width="191" height="300" class="alignright size-medium wp-image-372 photoborder" /></a></div>
<ul>
<li>Upload a resume showing three years of experience related to software security, or four years if you don&#8217;t have a college degree</li>
<li>Write short essays (500 words maximum) discussing four CBKs of your choice</li>
<li>Get a CISSP to vouch for you</li>
<li>Pay $650</li>
<p>
</ul>
<p>Let&#8217;s examine these requirements one at a time.</p>
<p><b>Three years of experience</b>.  (ISC)2 doesn&#8217;t provide any requirements on depth of experience, other than citing the broadly-defined CBKs.  Considering they are targeting everyone from software developers to security assessors to business analysts (yes, really), chances are they are going to accept any experience that is even tangential to the SDLC or software security.</p>
<p><b>Short essays on four of the CBKs</b>.  I asked the (ISC)2 exhibitors specifically what they are looking for to satisfy this requirement, and they said the essays should be a general discussion of the CBK topic, <i>optionally</i> citing your personal experience in that area if you have any.  This messaging is not quite aligned with the website guidance, which states that the essays should be &#8220;Accomplishment Records&#8221; which are self-reported descriptions of experience.  Either way, with a maximum essay length of 500 words, it&#8217;s pretty obvious that substance is not (ISC)2&#8217;s first priority.  Here&#8217;s one data point for you: I spoke to someone who has already submitted the CSSLP Experience Assessment, and he said it took about an hour to write the essays.</p>
<p><b>Get a CISSP to vouch for you</b>.  Actually this can be any (ISC)2 certified person, not just CISSPs.  Contrary to what you&#8217;d expect, though, the person isn&#8217;t vouching for your skillset so much as they are confirming that the attestations on your resume are accurate.</p>
<p><b>Pay $650</b>.  You knew it was coming.  After all, there is money to be made.  How is it that qualifying for the CSSLP through professional experience should cost $650?  If you&#8217;re taking the written exam, fair enough, (ISC)2 does incur the cost of administering and grading that exam (even though the <a href="http://www.scantron.com/datacollection/scanners.aspx">Scantron machine</a> is probably paid off by now).  But $650 for the submitted-online Experience Assessment?  If we assume that the person reading these essay submissions makes a rather generous $100k per year, then $650 accounts for roughly a day and a half.  Will it really take that long to read a <i>maximum</i> of 2,000 words and pass judgment?  Of course not.  (ISC)2 wants to get as many people as possible to qualify based on &#8220;experience&#8221;, seeding the initial pool of CSSLPs and netting them $650 per head for doing next to nothing.</p>
<p>As <a href="http://www.ljkushner.com/about_mstr.html">Lee Kushner</a> stated during his OWASP AppSec presentation (<i>7 Habits of Highly Effective Career Managers</i>), &#8220;the more people who own a cert, the less relevant it becomes.&#8221;  Irrelevant &#8212; that&#8217;s exactly what the CISSP has become, and it&#8217;s exactly where the CSSLP is headed.  Meanwhile, (ISC)2 will sit back and watch while you and your employers continue to fill their coffers.</p>
<p>In closing, let me acknowledge that this blog entry probably comes across as judgmental.  I accept that.  I&#8217;m not ranting against the idea of certifications, though admittedly <a href="http://www.veracode.com/blog/2008/04/not-a-cissp/">I&#8217;m not a fan of them either</a>.  I am disappointed that (ISC)2, an organization with tremendous influence, could have created something more meaningful but chose not to. Why bother when people will just fork over the cash anyway?</p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 11:08:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/csslp">csslp</category>
      <category domain="http://securityratty.com/tag/csslp experience assessment">csslp experience assessment</category>
      <category domain="http://securityratty.com/tag/experience assessment">experience assessment</category>
      <category domain="http://securityratty.com/tag/certification">certification</category>
      <category domain="http://securityratty.com/tag/experience">experience</category>
      <category domain="http://securityratty.com/tag/isc">isc</category>
      <category domain="http://securityratty.com/tag/personal experience">personal experience</category>
      <category domain="http://securityratty.com/tag/ubiquitous cissp certification">ubiquitous cissp certification</category>
      <category domain="http://securityratty.com/tag/cissp">cissp</category>
      <source url="http://www.veracode.com/blog/2008/09/isc2s-newest-cash-cow-csslp/">(ISC)2s Newest Cash Cow: The CSSLP Certification</source>
    </item>
  </channel>
</rss>
