<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: compliance]]></title>
    <link>http://securityratty.com/tag/compliance</link>
    <description></description>
    <pubDate>Mon, 22 Sep 2008 11:43:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[New health-care privacy laws heighten need for HIPAA compliance in California]]></title>
      <link>http://securityratty.com/article/7a8600babb9dd9b8d92cc0b40aa087f2</link>
      <guid>http://securityratty.com/article/7a8600babb9dd9b8d92cc0b40aa087f2</guid>
      <description><![CDATA[California Gov. Arnold Schwarzenegger has signed two HIPAA-like bills that set new security requirements, breach-disclosure rules and fines for health care organizations operating in that...]]></description>
      <content:encoded><![CDATA[California Gov. Arnold Schwarzenegger has signed two HIPAA-like bills that set new security requirements, breach-disclosure rules and fines for health care organizations operating in that state.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:27851d20edf51ed1f2fc8f055ce21f67:0SW2KVUaWdvHkCEoDwDPMA%2BGydWxqG8dg2ls0459p%2FE9kgoreOyCD3hHG%2FWzJTrRjxesYdL1s0kg'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:d8758858dffc1d6f975f7c3788ee4e1b:%2FtqY%2B1ZnVxGu470W02C0mgGGv%2FjHzk%2Fav%2FWn5dUXZPhlaUe2adPPN0Q7aJAjOVaC%2FpWPb93%2F9GI2Sw%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:c170ba29c884f45390fe05ae2707af20:p12V8yfNnf8%2BFxr07ncC5jLYLTTZsw5B33IsJ2oBvPvqLH66Qm98bdstUr2eC%2FQRvnI8li%2FjKwrRTQ%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:7cb195cc47aedb2f066ce49137af45bf:hEY9BPF0VZcXqXGVp7Zzvhci%2FC8ywfDY8WyYxB5foNWLNbumdvR8IFOeZDp2DGX12g168Yo4IUGb5g%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=11ba3706e6254b3ee7288884af3a298c" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=11ba3706e6254b3ee7288884af3a298c" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/health care organizations">health care organizations</category>
      <category domain="http://securityratty.com/tag/california gov">california gov</category>
      <category domain="http://securityratty.com/tag/hipaa-like bills">hipaa-like bills</category>
      <category domain="http://securityratty.com/tag/arnold schwarzenegger">arnold schwarzenegger</category>
      <category domain="http://securityratty.com/tag/security requirements">security requirements</category>
      <category domain="http://securityratty.com/tag/fines">fines</category>
      <category domain="http://securityratty.com/tag/rules">rules</category>
      <category domain="http://securityratty.com/tag/set">set</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=11ba3706e6254b3ee7288884af3a298c">New health-care privacy laws heighten need for HIPAA compliance in California</source>
    </item>
    <item>
      <title><![CDATA[Just A Thought on Compliance]]></title>
      <link>http://securityratty.com/article/0ae476d5942aec813ca6f6b8f73276d0</link>
      <guid>http://securityratty.com/article/0ae476d5942aec813ca6f6b8f73276d0</guid>
      <description><![CDATA[Do you know the difference between a solution &quot; sold as compliance &quot; and a solution that &quot; helps with compliance? &quot; In other words, are you &quot;a checkmark&quot; in a compliance checkbox OR do you help people...]]></description>
      <content:encoded><![CDATA[Do you know the difference between a solution "<span style="font-weight: bold;"><span style="font-style: italic;">sold </span>as compliance</span>" and a solution that "<span style="font-weight: bold;"><span style="font-style: italic;">helps</span> with compliance?</span>" In other words, are you "a checkmark" in a compliance checkbox OR do you help people with their compliance challenges?<br /><br />Get it?<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=wqVgM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=wqVgM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Iac7M"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Iac7M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=G872M"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=G872M" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/410668995" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 11:49:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/compliance challenges">compliance challenges</category>
      <category domain="http://securityratty.com/tag/compliance checkbox">compliance checkbox</category>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <category domain="http://securityratty.com/tag/difference">difference</category>
      <category domain="http://securityratty.com/tag/checkmark">checkmark</category>
      <category domain="http://securityratty.com/tag/words">words</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/410668995/just-thought-on-compliance.html">Just A Thought on Compliance</source>
    </item>
    <item>
      <title><![CDATA[A Few Fun Bits, While I Am Preparing for My Speech at SANS]]></title>
      <link>http://securityratty.com/article/95afa537556e21e9766eb67ee13152a8</link>
      <guid>http://securityratty.com/article/95afa537556e21e9766eb67ee13152a8</guid>
      <description><![CDATA[A few more things, that qualify as fun reads, with - hopefully just as fun! - comments

Love, love, love this piece :-) Remember the &quot;robotic gun rampage&quot; stories from last year? How does this sound:...]]></description>
      <content:encoded><![CDATA[A few more things, that qualify as fun reads, with - hopefully just as fun! - comments.<br /><ul><li>Love, love, love <a href="http://www.defensetech.org/archives/004449.html">this piece</a> :-) Remember the <a href="http://chuvakin.blogspot.com/search/label/warfare">"robotic gun rampage" stories</a> from last year? How does this sound: "The gun can track 360 degress, but there is <span style="font-weight: bold;">a software-driven safety zone that makes sure rounds don't blow the rotors off.</span> If the Osprey has to maneuver away from the target and the crew chief can't hold the gun on the bad guys manually, the system slaves the gun to the point of the last shot, slewing it as the plane moves." (watch the fun video there too)<br /></li><li>"Security idiot" meme lives on - go <a href="http://duckdown.blogspot.com/2008/09/are-you-it-security-idiot.html">here</a>. BTW, the post is a follow-up to <a href="http://duckdown.blogspot.com/2008/09/how-many-fingers-are-required-to-count.html">this </a></li><li><a href="http://www.securitybalance.com/2008/09/which-compliance-pill-to-take/">A fun follow-up</a> to my post on compliance approaches titled <a href="http://chuvakin.blogspot.com/2008/09/is-pci-dss-prescriptive.html">Is PCI DSS "Too Prescriptive"?</a> </li><li>Finally, my fave post: "<a href="http://www.cutawaysecurity.com/blog/archives/342" rel="bookmark" title="Permanent Link: Increase Your Logging">Increase Your Logging</a>." I am sooooo happy that logging evangelism is spreading  far and wide! A quote from<a href="http://www.cutawaysecurity.com/blog/archives/342"> the paper</a>: ”<em>Logs are interesting, logs are fun, logs should be done by EVERYONE…..get to logging!!!</em>” (I promise that specific case was not my quote, even though I do say that very thing all the time!)<br /></li></ul>Enjoy! Time for me to run and do my preso ... about logs of course!<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=dEUWM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=dEUWM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Jdl7M"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Jdl7M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=7k1zM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=7k1zM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/410521073" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 08:04:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fun">fun</category>
      <category domain="http://securityratty.com/tag/fun video">fun video</category>
      <category domain="http://securityratty.com/tag/fun follow-up">fun follow-up</category>
      <category domain="http://securityratty.com/tag/follow-up">follow-up</category>
      <category domain="http://securityratty.com/tag/gun">gun</category>
      <category domain="http://securityratty.com/tag/robotic gun rampage">robotic gun rampage</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/fun reads">fun reads</category>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/410521073/few-fun-bits-while-i-am-preparing-for.html">A Few Fun Bits, While I Am Preparing for My Speech at SANS</source>
    </item>
    <item>
      <title><![CDATA[Fun Reading on Security - 8]]></title>
      <link>http://securityratty.com/article/d60cc90ef226fd7624953a3c03f282d4</link>
      <guid>http://securityratty.com/article/d60cc90ef226fd7624953a3c03f282d4</guid>
      <description><![CDATA[Instead of my usual &quot;blogging frenzy&quot; machine gun blast of short posts, I will just combine them into my new blog series &quot; Fun Reading on Security .&quot; Here is an issue #7, dated October 2nd, 2008
Great...]]></description>
      <content:encoded><![CDATA[<p>Instead of my usual &quot;blogging frenzy&quot; machine gun blast of short posts, I will just combine them into my new blog series &quot;<a href="http://chuvakin.blogspot.com/search/label/reading">Fun Reading on Security</a>.&quot; Here is an issue #7, dated October 2nd, 2008.</p>  <ol>   <li><a href="http://www.darkreading.com/document.asp?doc_id=162936">Great paper</a> that complements the whole &quot;SIEM is dead?&quot; saga - &quot;Most enterprises are looking for a product that <em>will solve all of their problems in some sort of off-the-shelf miracle</em>, and when they find out that the currently available tools can't do it, they either postpone their deployment or put them on the back burner. &quot; </li>    <li>&quot;<a href="http://financialcryptography.com/mt/archives/001093.html">The Mess: looking for someone to blame?</a>&quot; is an awesome piece on Internet security and its architecture - and so is Gunnar's follow-up (&quot;<a href="http://1raindrop.typepad.com/1_raindrop/2008/09/if-a-tree-falls-in-someone-elses-silo.html">If a tree falls in someone else's silo...</a>&quot;) </li>    <li>Mike call to &quot;<a href="http://securityincite.com/blog/mike-rothman/rise-up-against-mediocrity">Rise up against Mediocrity</a>.&quot;&#160; - &quot;Dilbert makes the risk of the lowest common denominator approach abundantly clear.&quot;; in other words, you say 'best practices', I say 'mediocrity!' Mike also remind us, in vain, to do &quot;Security FIRST!&quot; (and compliance second) </li>    <li>A great piece from Burton: &quot;<a href="http://srmsblog.burtongroup.com/2008/08/on-response.html">On Response</a>&quot; - I think the world needs another 10-20 million reminders that PREVENTION FAILS. <a href="http://srmsblog.burtongroup.com/2008/08/on-response.html">This</a> is definitely a good one for those still in the &quot;we'll just block the threat world&quot; - &quot;we will not win a continuing war of escalation&quot; and &quot;using response can be more cost effective than installing the latest and greatest preventative tool&quot; </li>    <li><a href="http://blog.isc2.org/isc2_blog/2008/08/security-metric.html">More on metrics</a>, including the highly-awaited ISO27004. </li>    <li><a href="http://www.ecommercetimes.com/story/64598.html">Pretty dumb paper</a> by a person confused by why PCI DSS exists (the guy needs to read <a href="http://treasuryinstitute.org/blog/index.php?itemid=174">this</a>). PCI doesn't &quot;fall short,&quot; it helps people who will otherwise not do <em>anything</em> and their systems will &quot;power&quot; those botnets of the future... </li>    <li>While we are on this subject: <a href="http://pcianswers.com/2008/10/01/pci-dss-version-12-differences-and-updates/">a really good coverage of PCI 1.2. changes</a>, released Oct 1st. More PCI fun <a href="http://pcidss.wordpress.com/2008/09/11/recap-cso-executive-seminar-on-pci-compliance-by-james-deluccia/">here.</a> And more <a href="http://www.computerweekly.com/blogs/stuart_king/2008/09/i-was-supposed-to-be.html">here</a> (&quot;<a href="http://www.computerweekly.com/blogs/stuart_king/2008/09/i-was-supposed-to-be.html">PCI Compliance - dispelling some common myths</a>&quot;). And, <a href="http://www.estoregfoa.org/StaticContent/staticpages/TM0508.htm#1c">more PCI myths</a>. And <a href="http://securityincite.com/blog/mike-rothman/the-daily-incite-september-29-2008">more good ideas</a> on PCI from Mike R. Sorry, can't stop thinking about PCI :-)&#160; - also <a href="http://pcidss.wordpress.com/2008/09/19/the-inside-story-of-pci-confessions-of-a-qsa-commentary-by-james-deluccia/">this is good.</a> </li>    <li><a href="http://securosis.com/2008/09/23/behavioral-monitoring/">Adrian on behavioral monitoring</a>; mostly in DAM, but also elsewhere in security. </li>    <li>&quot;<a href="http://www.darkreading.com/blog.asp?blog_sectionid=327&amp;doc_id=164144">Premature Chasm-Crossing</a>&quot;&#160; - a must-read for all security vendors and especially their marketing (and&#160; their easily-excitable PR teams...) - &quot;Shouldn't vendors be spending more time fighting the problems that security managers are facing today, right this minute?&quot; (Mike R <a href="http://securityincite.com/blog/mike-rothman/the-daily-incite-september-24-2008">also comments</a> on that). A related - and&#160; just as interesting point is made here: &quot;<a href="http://blogs.computerworld.com/security_is_not_a_solution">Security is not a solution</a>&quot; </li>    <li><a href="http://www.csoonline.com/article/print/450190">More</a> on compliance and security checklists, good and bad: &quot;I think this is a dangerous trend unless the &quot;checklist&quot; is all inclusive.&quot; (how can a checklist include <strong>ALL? :-)</strong>) </li>    <li><a href="http://forensics.sans.org/community/top7_forensic_trends.php">&quot;SANS Top 7 New IR/Forensic Trends In 2008&quot;</a> </li>    <li>Read &quot;<a href="http://theinvisiblethings.blogspot.com/2008/09/three-approaches-to-computer-security.html">The three approaches to computer security!</a>&quot;&#160; Why? Come on, it is from <a href="http://theinvisiblethings.blogspot.com">Joanna</a>! :-) </li>    <li><a href="http://rationalsecurity.typepad.com/blog/2008/09/ids-vitamins-or-prophylactic.html">A fun discussion</a> about a hot new technology:<em> network IDS. </em>Is IDS <em>absolutely</em> indispensable to <em>ALL</em> companies? No. Can it be incredibly useful? You bet. End of discussion. </li>    <li>On an unrelated note, are lasers the future of warfare? <a href="http://blog.wired.com/defense/2008/09/why-lasers-wont.html">Some say no.</a> </li>    <li>Finally, some security humor from Gartner (!): &quot;<a href="http://blogs.gartner.com/greg_young/2008/09/30/get-rich-quick-with-network-security/">Get Rich Quick With Network Security</a>&quot; </li> </ol>  <p>Enjoy!</p>  <p><a href="http://chuvakin.blogspot.com/search/label/reading">Previous security reading.</a></p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=pqMsM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=pqMsM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=avlNM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=avlNM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=EvcjM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=EvcjM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/409462346" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 06:31:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security managers">security managers</category>
      <category domain="http://securityratty.com/tag/previous security">previous security</category>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/pci dss exists">pci dss exists</category>
      <category domain="http://securityratty.com/tag/computer security">computer security</category>
      <category domain="http://securityratty.com/tag/pci fun">pci fun</category>
      <category domain="http://securityratty.com/tag/security checklists">security checklists</category>
      <category domain="http://securityratty.com/tag/network security">network security</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/409462346/fun-reading-on-security-8.html">Fun Reading on Security - 8</source>
    </item>
    <item>
      <title><![CDATA[The Virtues and Dangers of Security and Compliance]]></title>
      <link>http://securityratty.com/article/c851d24e675867c73b9ed6b8c8f43676</link>
      <guid>http://securityratty.com/article/c851d24e675867c73b9ed6b8c8f43676</guid>
      <description><![CDATA[Last week I made a flying visit to NYC to appear on a panel at Interop with John Pironti of Getronics, Khalid Kark of Forrester, Jennifer Mack of the PCI Standards Council and Jim Routh of DTCC. The...]]></description>
      <content:encoded><![CDATA[<p>Last week I made a flying visit to NYC to appear on a panel at Interop with John Pironti of Getronics, Khalid Kark of Forrester, Jennifer Mack of the PCI Standards Council and Jim Routh of DTCC. The subject was &quot;Security By Compliance - A Discussion of Information Risk Management's Greatest Challenge&quot;.</p>
]]></content:encoded>
      <pubDate>Sun, 28 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci standards council">pci standards council</category>
      <category domain="http://securityratty.com/tag/information risk management">information risk management</category>
      <category domain="http://securityratty.com/tag/khalid kark">khalid kark</category>
      <category domain="http://securityratty.com/tag/jennifer mack">jennifer mack</category>
      <category domain="http://securityratty.com/tag/jim routh">jim routh</category>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/john pironti">john pironti</category>
      <category domain="http://securityratty.com/tag/visit">visit</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1356">The Virtues and Dangers of Security and Compliance</source>
    </item>
    <item>
      <title><![CDATA[Hype Alert: Internet Shopping Carts Are Secure]]></title>
      <link>http://securityratty.com/article/6f0706e64d78d354492017803497a079</link>
      <guid>http://securityratty.com/article/6f0706e64d78d354492017803497a079</guid>
      <description><![CDATA[My blog reader fed me a nugget today that set off my hype monitor, specifically a post entitled Internet Shopping Carts are Secure
OMG...really
To be fair, I realize the author is speaking from the...]]></description>
      <content:encoded><![CDATA[My blog reader fed me a nugget today that set off my hype monitor, specifically a post entitled <a href="http://hubpages.com/hub/Internet-Shopping-Carts-Are-Secure" taget="_blank">Internet Shopping Carts are Secure</a>. <br />OMG...really?<br />To be fair, I realize the author is speaking from the eCommerce perspective, rather than that of an information security practitioner, but here's where the trouble begins:<br /><span style="font-style:italic;">"Shopping cart service providers have developed secure ecommerce shopping cart solutions for any business owner looking to enhance their current online store, or create a new one. Some ecommerce shopping cart solution providers are even receiving PABP (Payment Application Best Practice) certification which supports PCI compliance requirements for all businesses accepting credit card payments online."</span><br />This may be true in part, but it is by no means an all-inclusive claim. Shopping carts continue to be sieve-like, even when apparently reviewed per <a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank">PCI</a> standards.<br />Allow me to elaborate.<br />We'll kick off our hype eliminating effort with a simple Google dork: <a href="http://www.google.com/search?hl=en&q=inurl%3A%22cart.cfm%22&btnG=Search" target="_blank"{>inurl:"cart.cfm"</a> (picking on ColdFusion again, but man, they make it easy)<br /><a href="http://www.gmpartsdirect.com/cart.cfm" target="_blank">GM Parts Direct: Your Shopping Cart</a> jumped right out at me for a number of reasons.<br />First, I sensed XSS vulns lurking like a Geiger counter senses radiation. Sound <a href="http://www.ringelkater.de/Sounds/2geraeusche_gegenst/geigerzaehler.wav" target="_blank">effect</a> for edification. :-)<br />Second, the page contained one of the growing number of aforementioned conversion-driving website <a href="http://sealserver.trustwave.com/cert.php?customerId=w6ordzctHpqOVGcB1cmBsViTpDGC2k&size=105x54&style=normal&language=en" target="_blank">security</a> seals. <br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_kVOWaY1TAF0/SN1tYvapkkI/AAAAAAAAADg/6k1ncKqufL4/s1600-h/GMparts.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_kVOWaY1TAF0/SN1tYvapkkI/AAAAAAAAADg/6k1ncKqufL4/s320/GMparts.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5250473012396397122" /></a><br /><br />Tick, tick, click...the Gieger counter is getting louder. <br />Trustwave claims that the site operator "is enrolled in Trustwave's Trusted Commerce™ program to validate compliance with the Payment Card Industry Data Security Standard (PCI DSS) mandated by all the major credit card associations including: American Express, Diners Club, Discover, JCB, MasterCard Worldwide, Visa, Inc. and Visa Europe."<br />Methinks that <a href="https://www.trustwave.com/" target="_blank">Trustwave's</a> Trusted Commerce program is missing a few fundamental security checks. Remember, XSS in PCI regulated sites, according to the <a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank">PCI DSS</a>, indicates that a site is not compliant (see section 6.5.4) if vulnerable to XSS.<br />Uh-oh.<br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_kVOWaY1TAF0/SN1wVI4q8FI/AAAAAAAAADo/ZzFA7u8xNCA/s1600-h/GMparts_xss_trustwave.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_kVOWaY1TAF0/SN1wVI4q8FI/AAAAAAAAADo/ZzFA7u8xNCA/s320/GMparts_xss_trustwave.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5250476249048608850" /></a><br />All it takes is a fake login page, as opposed to our friends at <a href="http://xssed.com/" target="_blank">XSSED.com</a>, and...well, you get the point.<br />Simply, this is one of an endless number of shopping cart not secure, and not PCI compliant. For shame. You need only browse the <a href="http://holisticinfosec.org/content/category/6/23/45/" target="_blank">Holisticinfosec.org Advisories</a> page to find multiple ecommerce platforms and shopping carts that are missing the mark. Trust me, these are a fraction of the <a href="http://secunia.com/advisories/search/?search=shopping+cart" target="_blank">problem</a>.<br />ecommerce<>security<br />ecommerce<><a href="http://msdn.microsoft.com/en-us/library/ms995349.aspx" target="_blank">SDL</a><br />ecommerce<>PCI<br />website security seal<>security<br />Sigh.]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 11:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ecommerce">ecommerce</category>
      <category domain="http://securityratty.com/tag/multiple ecommerce platforms">multiple ecommerce platforms</category>
      <category domain="http://securityratty.com/tag/ecommerce sdl">ecommerce sdl</category>
      <category domain="http://securityratty.com/tag/ecommerce perspective">ecommerce perspective</category>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/cart solutions">cart solutions</category>
      <category domain="http://securityratty.com/tag/cart">cart</category>
      <category domain="http://securityratty.com/tag/ecommerce security">ecommerce security</category>
      <source url="http://holisticinfosec.blogspot.com/2008/09/hype-alert-internet-shopping-carts-are.html">Hype Alert: Internet Shopping Carts Are Secure</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-09-23 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/2af80556b9f0e7dd51df3553792d655a</link>
      <guid>http://securityratty.com/article/2af80556b9f0e7dd51df3553792d655a</guid>
      <description><![CDATA[Rational Survivability: VMWare's VirtSec Vision...Virtual Validation
Security and Risk Management Strategies Blog: PCI V1.2, a good start but still not enough Monitoring and audit while the PCI DSS...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://rationalsecurity.typepad.com/blog/2008/09/vmwares-virtsec-visionvirtual-validation.html">Rational Survivability: VMWare's VirtSec Vision...Virtual Validation?</a></li>
<li><a href="http://srmsblog.burtongroup.com/2008/09/pci-v12-a-good.html">Security and Risk Management Strategies Blog: PCI V1.2, a good start but still not enough</a><br/>
Monitoring and audit – while the PCI DSS recommends minimum timeframes for scanning, doing pen tests, etc. what are the real levels of monitoring and audit needed for ensuring security?  With the Hannaford and Okemo breaches that occurred (both where PCI compliant), neither discovered the problem until months after the breaches had happened.  So identifying what should be scanned and tested and if some of this should be on a continuous basis still requires refinement.</li>
<li><a href="http://www.computerweekly.com/blogs/stuart_king/2008/09/i-was-supposed-to-be.html">PCI Compliance - dispelling some common myths (Stuart King's Security and Risk Management Blog)</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/401466847" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 23 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci compliant">pci compliant</category>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/pci compliance">pci compliance</category>
      <category domain="http://securityratty.com/tag/risk management blog">risk management blog</category>
      <category domain="http://securityratty.com/tag/breaches">breaches</category>
      <category domain="http://securityratty.com/tag/okemo breaches">okemo breaches</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/continuous basis">continuous basis</category>
      <category domain="http://securityratty.com/tag/virtsec vision">virtsec vision</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/401466847/anton18">Links for 2008-09-23 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Security issues magnified in India]]></title>
      <link>http://securityratty.com/article/140552ba289fe8016e55aa24d1e0d7f4</link>
      <guid>http://securityratty.com/article/140552ba289fe8016e55aa24d1e0d7f4</guid>
      <description><![CDATA[CTO of Bigfix, Amrit Williams feels that security, already identified as one of the top three CIO concerns, deserves even greater attention in India. As the IT industry in the country grows, it will...]]></description>
      <content:encoded><![CDATA[CTO of Bigfix, Amrit Williams feels that security, already identified as one of the top three CIO concerns, deserves even greater attention in India. As the IT industry in the country grows, it will take on even more significant proportions, especially due to international compliance regulations. He voices his concerns and insights below:]]></content:encoded>
      <pubDate>Tue, 23 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cio concerns">cio concerns</category>
      <category domain="http://securityratty.com/tag/international compliance regulations">international compliance regulations</category>
      <category domain="http://securityratty.com/tag/amrit williams feels">amrit williams feels</category>
      <category domain="http://securityratty.com/tag/concerns">concerns</category>
      <category domain="http://securityratty.com/tag/india">india</category>
      <category domain="http://securityratty.com/tag/significant proportions">significant proportions</category>
      <category domain="http://securityratty.com/tag/country grows">country grows</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/due">due</category>
      <source url="http://www.networkworld.com/news/2008/092408-security-issues-magnified-in.html?fsrc=rss-security">Security issues magnified in India</source>
    </item>
    <item>
      <title><![CDATA[One Mans Frustrations With Risk Management]]></title>
      <link>http://securityratty.com/article/35f7d9bc833b43ad15689be67c2bbe31</link>
      <guid>http://securityratty.com/article/35f7d9bc833b43ad15689be67c2bbe31</guid>
      <description><![CDATA[Chris, who is a male in Government C&amp;A has a blog with a wonderful title: How is that Assurance Evidence
Id love to have another blog even more specific - Ok, that Assurance is Evidence Of What,...]]></description>
      <content:encoded><![CDATA[<p>Chris, who is a male in Government C&amp;A has a blog with a wonderful title:<a href="http://howisthatassuranceevidence.blogspot.com/"> How is that Assurance Evidence? </a></p>
<p>I&#8217;d love to have another blog even more specific - &#8220;Ok, that Assurance is Evidence <em><strong>Of What, Exactly</strong></em>?</p>
<p>Today he has a great article called:</p>
<p><a name="2599135121032652210"></a></p>
<h2 class="title"><a href="http://howisthatassuranceevidence.blogspot.com/2008/09/whats-matter-with-risk-management.html">What&#8217;s the matter with Risk Management?</a></h2>
<p><em>And &#8220;in short, it&#8217;s everything.&#8221;</em> It pretty much sums up why I had to grow to re-evaluate how our industry does risk, risk management, approaches controls &amp; vulnerability and find a new way.   A couple of things jump out at me in reading Chris&#8217; article:</p>
<p><strong>1.)  Just because that Deming cycle sucks and is full of unknowns doesn&#8217;t mean &#8220;risk&#8221; doesn&#8217;t exist, nor that it isn&#8217;t of primary importance.</strong> Nor does it mean that in the absence of model &amp; methodology, we won&#8217;t be &#8220;doing&#8221; risk analysis anyway - just in an ad hoc method and completely from &#8220;the gut&#8221;.</p>
<p>Our industry calls these unstructured risk analysis &#8220;Best Practices&#8221;, as it&#8217;s an easy and convenient way of sweeping the unknowns under the rug of bureaucracy and enforcing it via peer pressure.</p>
<p><strong>2.)  What this &#8220;suckiness&#8221; does mean is that your model and methodology aren&#8217;t helping you.</strong> As Chris intimates, there is too much uncertainty in the inputs for his model (they are, in the language of Bayesians - too subjective to be useful priors).</p>
<p>Take for example how we might be approaching the &#8220;controls&#8221; part of our analysis.  Chris writes:</p>
<blockquote><p><em>&#8220;2.  What are the controls that we have to employ?<br />
800-53, ISO 27001, PCI, etc.</em></p>
<p><em>Still kinda good, but we basically know that ISO is relatively voluntary and NIST supplies a control catalog and not policies. So here we have to take the control catalog, and mash our policies into it.&#8221;</em></p></blockquote>
<p>I wouldn&#8217;t call this &#8220;kinda good&#8221; at all :)  These control catalogs only provide a hierarchy within which to look for evidence of  our ability to resist an attacker.  They are incapable of making any claim about the effectiveness of the controls when they are operated at 100% efficiency, or more importantly, what % efficiency our specific organization operates at.</p>
<p>Let&#8217;s use <a href="http://risktical.com/initech-inc/">Chris Hayes&#8217; Initech as our fictional example</a>.</p>
<p>Initech has a control (a back door on a loading dock).  Now the locks on the door are 100% capable of locking the door.  This is different than saying that they are capable of frustrating all but the top 5% of lockpicking burgalars.  It is also diffferent than saying that in a sample of several &#8220;walk around audits&#8221; the doors are left open 20% of the time (they are not in compliance with policy 100% of the time).  Even worse, that 80% of the time the door is not propped open?  Yeah, tailgating is a known issue.</p>
<p>So we have several different variables here that we need to account for (and it&#8217;s just a door).  But the analogy stands that most &#8220;risk management&#8221; methodologies are &#8220;We have a door, yes/no?&#8221; And most GRC platforms, when asked for their &#8220;opinion&#8221; will simply say &#8220;door is needed&#8221; or, even worse, &#8220;a door policy is needed&#8221;.</p>
<p><strong>3.)  Criticality and the Source of Value is all messed up in these Risk Management models.<br />
</strong></p>
<p>Chris writes:</p>
<blockquote><p><em>Someone wants me to tell them which boxes are more critical than others. This is mainly because of budgetary or operational reasons. To which I usually say &#8220;All of them, it is a system after all&#8221;.</em></p></blockquote>
<p>This literally made me laugh out loud.  And <strong><a href="http://riskmanagementinsight.com/riskanalysis/?p=383">this sort of &#8220;rate the firewall as Risk = 500 but rate the actual business application as Risk = 157&#8243; thing is</a></strong> also endemic.  Now Chris is very smart here.  He correctly identifies that the value is tied to the business process the systems support, and not to a specific box.  Oh, we scan at the specific box level - but because of the nature of systemic failures - all the boxes in the process are inexorably interrelated.</p>
<p>One of the reasons I really like FAIR is that the losses are quantified (or qualified) based not on some amorphous value of the box or the process itself, but<strong> losses are linked to the actions that the threat will take. </strong> Take systems in a highly regulated industries as an example.  Usually the most probable losses aren&#8217;t due to system compromise per se, but in the disclosure the compromise causes (regulators are a threat source, after all).  But many &#8220;risk management&#8221; methodologies will say &#8220;online banking is worth $2 billion, the value of the systems is therefore $2 billion&#8221;.  And suddenly we&#8217;re telling executive management that there&#8217;s a 60% probability that they&#8217;ll lose $2 billion.</p>
<p><strong>4.)  If the primary source of prior information for your &#8220;risk management&#8221; methodology is a vulnerability scanner</strong> - <em><strong>you&#8217;re doing it wrong</strong></em>.  Chris writes:</p>
<blockquote><p><em>So we ran a scan and now we have a report. A snapshot in time to make all decisions. Where did these vulnerability ratings come from? Do I even know if my system is at risk? What if I spend my time on vulnerabilities that have no threat?</em></p></blockquote>
<p>So first, my thoughts are that actual &#8220;vulnerability&#8221; must be a comparison of the force a threat can apply, and our ability to resist that force (this is a probability statement, btw).</p>
<p>Changing your thinking about vulnerability now helps us understand the problem in several new ways.  First, you can start to divorce yourself from the scanner.  After all, the scanner is simply providing you with current state information that is usually just relevant variance from policy. It doesn&#8217;t really tell you about real &#8220;weakness in a system&#8221; because the system is an interrelated mess of people, processes and IT assets.</p>
<p><strong>5.)  Finally, most &#8220;risk management&#8221; approaches just *don&#8217;t* do a good job of helping us understand the how&#8217;s and why&#8217;s of <em>managing</em> <em>risk</em>.</strong> In the past, I&#8217;ve referred to these standards as really being &#8220;issue management&#8221; because they are at their heart, an act of discovery - a formal process around gathering prior information.  They are not, in and of themselves, capable of linking the issues discovered to the root cause.  And these root causes?  Yeah, they&#8217;re the things that create &#8220;risk&#8221;.  Not a threat, not a vulnerability, not the existence of an asset - the amount of risk that we have stems from our capability to manage it.</p>
<p>So Chris, I completely agree - but I wouldn&#8217;t give up yet.  There actually are a few of us who are focused on what you suggest:</p>
<blockquote><p>Where to go from here: A fundamental revamp of how to deal with Risk. Where risk professionals focus on the treating the sickness and not the symptoms, and come up with some new success/actionable metrics.</p></blockquote>
<p>Chris, there&#8217;s nothing I want to do more than that.</p>
]]></content:encoded>
      <pubDate>Tue, 23 Sep 2008 14:05:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/risk management methodologies">risk management methodologies</category>
      <category domain="http://securityratty.com/tag/risk management approaches">risk management approaches</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk management methodology">risk management methodology</category>
      <category domain="http://securityratty.com/tag/risk management models">risk management models</category>
      <category domain="http://securityratty.com/tag/risk professionals focus">risk professionals focus</category>
      <category domain="http://securityratty.com/tag/risk analysis">risk analysis</category>
      <category domain="http://securityratty.com/tag/specific">specific</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=447">One Mans Frustrations With Risk Management</source>
    </item>
    <item>
      <title><![CDATA[Is PCI DSS "Too Prescriptive"?]]></title>
      <link>http://securityratty.com/article/3dfc59dd4876349ed35372715a67d3d7</link>
      <guid>http://securityratty.com/article/3dfc59dd4876349ed35372715a67d3d7</guid>
      <description><![CDATA[I did this fun panel on PCI compliance at SecureWorld Bay Area the other week. What is interesting is that almost every time there is a discussion about PCI DSS, somebody crawls out of the woodwork...]]></description>
      <content:encoded><![CDATA[<p>I did this <u><a href="http://secureworldexpo.com/events/index.php?id=255">fun panel on PCI compliance at SecureWorld Bay Area</a></u> the other week. What is interesting is that almost every time there is a discussion about PCI DSS, somebody crawls out of the woodwork and utters the following: &quot;<strong>PCI is too prescriptive!</strong>&quot;, as if it is a bad thing (e.g. I mentioned it before <a href="http://chuvakin.blogspot.com/2008/04/rsa-impressions-2-compliance.html">here</a>)</p>  <p>I used to react to this with &quot;<em>Are you stupid?!</em> PCI being prescriptive is the best thing since sliced cake :-) Finally, there is some specific guidance for people to follow and be more secure!&quot; BTW, in many cases end users who have to comply with PCI DSS <strong>still</strong> think it is &quot;too fuzzy&quot; and &quot;not specific enough&quot; (e.g. see <u><a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">&quot;MUST-DO Logging for PCI&quot;</a></u>); and they basically ask for&#160; &quot;<strong>a compliance TODO list</strong>.&quot; (also see <a href="http://chuvakin.blogspot.com/2008/08/few-more-words-on-dlp-and-compliance.html">this</a> and especially <a href="http://securosis.com/2008/08/18/dont-sell-compliance-if-it-isnt-a-checkbox/">this</a> on compliance checklists)</p>  <p>But every time it happens, I can't stop but think - why do people even utter such utter heresy? :-) And you know what?&#160; I think I got it!</p>  <p>When people say &quot;PCI is too prescriptive,&quot; they actually mean that it engenders &quot;<u><a href="http://chuvakin.blogspot.com/2008/04/rsa-impressions-2-compliance.html">checklist mentality</a></u>&quot; and leads to following the letter of the mandate blindly, without thinking about WHY it was put in place (to protect cardholder data, share risk/responsibility, etc). For example, it says &quot;use a firewall&quot; and so they deploy a shiny firewall with a simple &quot;ALLOW ALL&lt;-&gt;ALL&quot; rule (an obvious exaggeration - but you get the point!) Or they have <u><a href="http://chuvakin.blogspot.com/2008/09/dumb-luck-is-strategy.html">a firewall with a default password unchanged</a></u>... In addition, the proponents of &quot;PCI is too prescriptive&quot; tend to think that fuzzier guidance (and, especially, prescribing the desired end state AND not the tools to be installed) will lead to people actually thinking about the best way to do it.</p>  <p>So the choices are:</p>  <ol>   <li><strong>Mandate the tools</strong> (e.g. &quot;must use a firewall&quot;) - <strong>and risk</strong> &quot;checklist mentality&quot;, resulting in BOTH insecurity and &quot;false sense&quot; of security. </li>    <li><strong>Mandate the results</strong> (e.g. &quot;must be secure&quot;) -&#160; <strong>and risk</strong> people saying &quot;eh, but I dunno how&quot; - and then not acting at all, again leading to insecurity. </li> </ol>  <p>Take your poison now?! Isn't compliance fun? What is the practical solution to this? I personally would take the pill #1 over pill #2 (and that is why I like PCI <a href="http://chuvakin.blogspot.com/2007/08/free-pci-compliance-book-chapter-on.html">that much</a>), but with some pause to think, for sure.&#160; I think organizations with less mature security programs will benefit at least a bit from #1, while those with more mature programs might &quot;enjoy&quot; #2 more...</p>  <p>BTW, this post was originally called &quot;Isn't Compliance Fun?!&quot;&#160; I had a few fierce debates with some friends and all of them&#160; piled on me to convince me that &quot;compliance is boring, while security is fun!&quot; The above does illustrate that there are worthy and exciting intellectual challenges in the domain of regulatory compliance. It is not [only] a domain of minimalists (who just &quot;want the auditor to go away&quot;) and <u><a href="http://securityincite.com/blog/mike-rothman/rise-up-against-mediocrity">mediocrity</a></u>, as some think. What makes security fun - the people aspect, the ever-changing threat landscape, cool technology, high uncertainty, even risk - also apply to compliance ...</p>  <p>So, need a cool marketing slogan BUT <u></u><a href="http://securityincite.com/blog/mike-rothman/pragmatic-cso-podcast-10-its-so-easy">hate &quot;making compliance easy&quot;</a>?&#160; Go for &quot;Making Compliance Fun!&quot; :-)</p>  <p><u><a href="http://chuvakin.blogspot.com/search/label/PCI">All posts on PCI</a></u> - some are fun:-)</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=eFI6L"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=eFI6L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=dQYpL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=dQYpL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=GGp5L"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=GGp5L" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/400214601" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 22 Sep 2008 11:43:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/compliance fun">compliance fun</category>
      <category domain="http://securityratty.com/tag/pci compliance">pci compliance</category>
      <category domain="http://securityratty.com/tag/compliance checklists">compliance checklists</category>
      <category domain="http://securityratty.com/tag/fun">fun</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/regulatory compliance">regulatory compliance</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/400214601/is-pci-dss-prescriptive.html">Is PCI DSS "Too Prescriptive"?</source>
    </item>
  </channel>
</rss>
