<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: dana]]></title>
    <link>http://securityratty.com/tag/dana</link>
    <description></description>
    <pubDate>Mon, 31 Jul 2006 17:30:23 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Links for 2008-10-01 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/2e61bbf8f65cea7668e676362729b6b6</link>
      <guid>http://securityratty.com/article/2e61bbf8f65cea7668e676362729b6b6</guid>
      <description><![CDATA[Behavioral Monitoring | securosis.com
Dana Gardner's BriefingsDirect: Improved insights and analysis from IT systems logs helps reduce complexity risks from virtualization
E-Commerce News: ID...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://securosis.com/2008/09/23/behavioral-monitoring/">Behavioral Monitoring | securosis.com</a></li>
<li><a href="http://briefingsdirectblog.blogspot.com/2008/09/improved-insights-and-analysis-from-it.html">Dana Gardner's BriefingsDirect: Improved insights and analysis from IT systems logs helps reduce complexity risks from virtualization</a></li>
<li><a href="http://www.ecommercetimes.com/story/64598.html">E-Commerce News: ID Security: New PCI Security Standard Falls Short</a></li>
<li><a href="http://duckdown.blogspot.com/2008/09/how-many-fingers-are-required-to-count.html">Enterprise Architecture: From Incite comes Insight...: How many fingers are required to count the number of clueless IT Security Professionals?</a></li>
<li><a href="http://www.csoonline.com/article/print/450190">IT Security: Can We Be Compliant and Yet Insecure?</a></li>
<li><a href="http://blogs.gartner.com/greg_young/2008/09/30/get-rich-quick-with-network-security/">Get Rich Quick With Network Security</a></li>
<li><a href="http://rationalsecurity.typepad.com/blog/2008/09/ids-vitamins-or-prophylactic.html">Rational Survivability: IDS: Vitamins Or Prophylactic?</a></li>
<li><a href="http://treasuryinstitute.org/blog/index.php?itemid=174">PCI DSS News and Information &raquo; Great Expectations?</a></li>
<li><a href="http://www.estoregfoa.org/StaticContent/staticpages/TM0508.htm#1c">GFOA Treasury Management</a></li>
<li><a href="http://forensics.sans.org/community/top7_forensic_trends.php">SANS - Computer Forensics - Top 7 New IR/Forensic Trends In 2008</a><br/>
SANS Top 7 New IR/Forensic Trends In 2008</li>
<li><a href="http://securitybuddha.com/2008/09/30/you-might-be-a-pm-if/">You Might be a PM if&hellip; &laquo; Mark Curphey - SecurityBuddha.com</a></li>
<li><a href="http://blogs.computerworld.com/security_is_not_a_solution">Security is not a solution | Computerworld Blogs</a><br/>
Security is not a solution</li>
<li><a href="http://www.andrewhay.ca/archives/385">Andrew Hay &raquo; Blog Archive &raquo; Secure Life Ep 3</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/408931097" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security professionals">security professionals</category>
      <category domain="http://securityratty.com/tag/computerworld blogs security">computerworld blogs security</category>
      <category domain="http://securityratty.com/tag/network security">network security</category>
      <category domain="http://securityratty.com/tag/sans top">sans top</category>
      <category domain="http://securityratty.com/tag/irforensic trends">irforensic trends</category>
      <category domain="http://securityratty.com/tag/sans">sans</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <category domain="http://securityratty.com/tag/pci dss news">pci dss news</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/408931097/anton18">Links for 2008-10-01 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Security + Logging + Virtualization Podcast]]></title>
      <link>http://securityratty.com/article/3ef5ee6b581fa908366fdbdec8f17d6a</link>
      <guid>http://securityratty.com/article/3ef5ee6b581fa908366fdbdec8f17d6a</guid>
      <description><![CDATA[Here is a fun podcast a bunch of us (yes, including Chris , of course! ) did on security, logging and virtualization ( audio , full transcript

It is actually a fun read / listen , if you are into...]]></description>
      <content:encoded><![CDATA[<a href="http://briefingsdirect.blogspot.com/2008/09/virtualization-use-requires-improved.html">Here</a> is a fun podcast a bunch of us (yes, including <a href="http://rationalsecurity.typepad.com/blog/">Chris</a>, <span style="font-style: italic;">of course!</span>)  did on security, logging and virtualization (<a href="http://media.libsyn.com/media/interarbor/BriefingsDirect_LogLogic_Podcast_2.mp3">audio</a>,<a href="http://briefingsdirect.blogspot.com/2008/09/virtualization-use-requires-improved.html"> full transcript</a>).<br /><br />It is actually a fun <a href="http://briefingsdirect.blogspot.com/2008/09/virtualization-use-requires-improved.html">read </a>/ <a href="http://media.libsyn.com/media/interarbor/BriefingsDirect_LogLogic_Podcast_2.mp3">listen</a>, if you are into either/all of these three :-)<br /><br />Here is the brief blurb on that from the<a href="http://briefingsdirect.blogspot.com"> podcaster site</a>: "To help learn about new ways that systems log tools and analysis are aiding the ramp-up to virtualization use, I [<a href="http://briefingsdirectblog.blogspot.com/2008/09/improved-insights-and-analysis-from-it.html">Dana Gardner</a>] recently spoke with <a href="http://www.linkedin.com/in/charu">Charu Chaubal</a>, senior architect for technical marketing, at <a href="http://www.vmware.com/">VMware</a>; <a href="http://www.linkedin.com/in/choff">Chris Hoff</a>, chief security architect at <a href="http://www.unisys.com/">Unisys</a>, and <a href="http://www.chuvakin.org/">Dr. Anton Chuvakin</a>, chief logging evangelist and a <a href="http://en.wikipedia.org/wiki/Anton_Chuvakin">security expert</a> at <a href="http://www.loglogic.com/">LogLogic</a>."<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=n88xM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=n88xM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=OlK9M"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=OlK9M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=tCDWM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=tCDWM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/408598332" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 09:36:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security expert">security expert</category>
      <category domain="http://securityratty.com/tag/chief security architect">chief security architect</category>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/chief">chief</category>
      <category domain="http://securityratty.com/tag/anton chuvakin">anton chuvakin</category>
      <category domain="http://securityratty.com/tag/fun">fun</category>
      <category domain="http://securityratty.com/tag/chris hoff">chris hoff</category>
      <category domain="http://securityratty.com/tag/chuvakin">chuvakin</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/408598332/security-logging-virtualization-podcast.html">Security + Logging + Virtualization Podcast</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-09-15 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/76641371b3a7f5060624cdd792c7e9cb</link>
      <guid>http://securityratty.com/article/76641371b3a7f5060624cdd792c7e9cb</guid>
      <description><![CDATA[Quest grabs NetPro to strengthen Windows management wares - Network World NetPros lineup includes tools focused on security/compliance, infrastructure administration and identity/access. Those tools...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://www.networkworld.com/news/2008/091208-quest.html">Quest grabs NetPro to strengthen Windows management wares - Network World</a><br/>
NetPro’s lineup includes tools focused on security/compliance, infrastructure administration and identity/access.

Those tools include auditing, backup/recovery, policy enforcement, event log management, Exchange migration, group policy management, health/performance and user self-service password management</li>
<li><a href="http://searchsecurity.techtarget.com.au/articles/26900-Are-common-logging-and-audit-standards-emerging-">Are common logging and audit standards emerging? :: SearchSecurity.com.au</a></li>
<li><a href="http://news.zdnet.com/2424-9595_22-218408.html">SaaS market will 'collapse' in two years | Tech News on ZDNet</a><br/>
Q: Won&#039;t people avoid the mistakes of &quot;previous&quot; SaaS incarnations, as you mentioned?

A: People are stupid. History has shown it repeats itself, and people make the same mistakes.</li>
<li><a href="http://www.crmoutsiders.com/2008/08/28/lawson-ceo-saas-will-collapse-in-two-years/">CRM Outsiders &raquo; Blog Archive &raquo; Lawson CEO: SaaS Will &ldquo;Collapse&rdquo; In Two Years</a><br/>
I couldn’t disagree more, but than again it was also Harry Debes that predicted that many of today’s Web 2.0, cell phone gadgets would never catch on either. SaaS is certainly here to say. I</li>
<li><a href="http://www.dimitrimckay.com/Loglogic/Blog/Entries/2008/7/20_How_to_convert_windows_logs_to_syslog:.html">Nerd News: Eventlog to Syslog</a></li>
<li><a href="http://blog.isc2.org/isc2_blog/2008/09/event-correlati.html">(ISC)2 Blog: Event Correlation</a></li>
<li><a href="http://www.rsa.com/blog/blog_entry.aspx?id=1301">Speaking of Security... | Blog Entry: Paul Stamp | Correlation is no silver bullet: 1301</a><br/>
So, when deploying SIEM to improve your security operations, remember that correlation only really works when backed up by real data about what is the biggest problem in your environment, and how that problem manifests itself in the event logs. I call it &quot;working out what type of needles you&#039;ll find in your haystack.&quot;</li>
<li><a href="http://blogs.zdnet.com/Gardner/?p=2723">Systems log analytics offers operators performance insights that set stage for IT transformation | Dana Gardner&rsquo;s BriefingsDirect | ZDNet.com</a></li>
<li><a href="http://www.nemertes.com/analyst_blogs/sharpening_stones_and_walking_coals">Sharpening Stones and Walking on Coals | Nemertes Research</a><br/>
When hunting for a needle in a haystack, after all, making the haystack larger is not an obviously productive course; getting a tool that can assist in the hunt - a magnet, or a metal detector - makes more sense!</li>
<li><a href="http://www.nemertes.com/analyst_blogs/search_or_destroy">Search or Destroy | Nemertes Research</a><br/>
It&#039;s not all about security, it&#039;s not all about events, it&#039;s not all about compliance. All those things are critically important to IT, of course, but even more fundamental is the task of keeping things running.</li>
<li><a href="http://jdm-tech.blogspot.com/2008/07/how-worthwhile-is-logging.html">jdm's Blog: How worthwhile is logging?</a><br/>
Logs are like a warm blanket; verbose logging means you can know what&#039;s happening on your systems if you keep up with the logs.  At the same time, logs become a burden very very easily, and they are easy to ignore.</li>
<li><a href="http://blog.gerhards.net/2008/07/what-is-event-and-what-event-log.html">Rainer's Blog: What is an Event? And what an Event Log?</a></li>
<li><a href="http://duckdown.blogspot.com/2008/07/taming-documentum-audit-trail.html">Enterprise Architecture: From Incite comes Insight...: Taming the Documentum Audit Trail</a><br/>
First and foremost, it is a good security principle to separate log data from the system.</li>
<li><a href="http://thomasnicholson.com/2008/07/02/log-management-is-a-pain/">Log management is a pain | Thomas Nicholson</a><br/>
So for an administrator to not care about logs was a shock.</li>
<li><a href="http://blogs.splunk.com/thebaum/2008/09/03/situational-awareness/">thebaumblog &raquo; Blog Archive &raquo; Life after SIEM. Situational Awareness is next.</a><br/>
Life after SIEM. Situational Awareness is next.</li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/393875149" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/event logs">event logs</category>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/event log management">event log management</category>
      <category domain="http://securityratty.com/tag/event log">event log</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/saas market">saas market</category>
      <category domain="http://securityratty.com/tag/saas">saas</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/393875149/anton18">Links for 2008-09-15 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-09-11 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/5fc8d88b3db9b7e7ca09f8f03b4c3cd0</link>
      <guid>http://securityratty.com/article/5fc8d88b3db9b7e7ca09f8f03b4c3cd0</guid>
      <description><![CDATA[OPEN Forum by American Express OPEN Blog Archive How to Save a Billion Dollars
The Daily Incite - September 11, 2008 | Security Incite: Analysis on Information Security But I think many security...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://blogs.openforum.com/2008/09/10/how-to-save-a-billion-dollars/">OPEN Forum by American Express OPEN &raquo; Blog Archive How to Save a Billion Dollars</a></li>
<li><a href="http://securityincite.com/blog/mike-rothman/the-daily-incite-september-11-2008">The Daily Incite - September 11, 2008 | Security Incite: Analysis on Information Security</a><br/>
But I think many security managers are missing the point of what a security management platform is supposed to do. It&#039;s about control and automation. The reality is no human can wade through the morass of data that comes out of our security devices.</li>
<li><a href="http://www.darkreading.com/document.asp?doc_id=162936">Security Management: A Chicken &amp; Egg Problem - Discovery and management - Dark Reading</a><br/>
Most enterprises are looking for a product that will solve all of their problems in some sort of off-the-shelf miracle, and when they find out that the currently available tools can&#039;t do it, they either postpone their deployment or put them on the back burner.</li>
<li><a href="http://biz.yahoo.com/bw/080908/20080908005257.html?.v=1">Trusted Computer Solutions Acquires CounterStorm to Broaden Portfolio of Security Solutions: Financial News - Yahoo! Finance</a></li>
<li><a href="http://briefingsdirectblog.blogspot.com/2008/09/systems-log-analytics-offers-operators.html">Dana Gardner's BriefingsDirect: Systems log analytics offers operators performance insights that set stage for IT transformation</a></li>
<li><a href="http://financialcryptography.com/mt/archives/001091.html">Financial Cryptography: Yet more evidence: your CISO needs an MBA</a><br/>
Yet more evidence: your CISO needs an MBA</li>
<li><a href="http://www.webadminblog.com/index.php/2008/06/23/the-velocity-2008-conference-experience-part-iii/">The Velocity 2008 Conference Experience - Part III - Web Admin Blog</a><br/>
Logging should be actionable - concise, express symptoms. Anything logged is something fixable. It should be giving you less downtime - shorter time to resolution. Logging takes resources, so make it worth it.

Filter down your logs to be concise and actionable. Production logging has different goals from dev/QA logging. You’re looking for problem diagnosis and recovery, and then statistics and monitoring. Insight into what the app’s doing.</li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/390342450" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 11 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security management platform">security management platform</category>
      <category domain="http://securityratty.com/tag/security management">security management</category>
      <category domain="http://securityratty.com/tag/management">management</category>
      <category domain="http://securityratty.com/tag/web admin blog">web admin blog</category>
      <category domain="http://securityratty.com/tag/conference experience">conference experience</category>
      <category domain="http://securityratty.com/tag/american express">american express</category>
      <category domain="http://securityratty.com/tag/ciso">ciso</category>
      <category domain="http://securityratty.com/tag/concise">concise</category>
      <category domain="http://securityratty.com/tag/mba">mba</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/390342450/anton18">Links for 2008-09-11 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Links List 6.20.08]]></title>
      <link>http://securityratty.com/article/f63a51e258d42ece74939596e871ddcf</link>
      <guid>http://securityratty.com/article/f63a51e258d42ece74939596e871ddcf</guid>
      <description><![CDATA[Dana Gardner discusses the recently announced partnership of VMWare and HP . They seek to offer enterprises and service providers a single management and control approach to both physical and virtual...]]></description>
      <content:encoded><![CDATA[<p>Dana Gardner discusses the <a href="http://briefingsdirectblog.blogspot.com/2008/06/vmware-and-hp-align-products-to-bring.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/briefingsdirectblog.blogspot.com');" target="_blank">recently announced partnership of VMWare and HP</a>. They seek to offer enterprises and service providers a single management and control approach to both physical and virtual software infrastructure stacks. A fun little game: count the number of HP modules you have to buy for a “complete” virtualization management solution.
<p>John Willis talks about customers that use a hybrid approach of priority and <a href="http://www.johnmwillis.com/opensource/the-art-of-war/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.johnmwillis.com');" target="_blank">open source monitoring</a> tools depending on how important what’s being monitored actually is to the business. He says,”a running joke that was going around in the early 2000’s is that BMC and Tivoli created Mercury (now HP) Sitescope because they, BMC and Tivoli, would not budge on their per server pricing. In fact many of the enterprise proprietary monitoring vendors still don’t deal with the not-so-important-server issue.”
<p>One of our favorite writers, <a href="http://blogs.eweek.com/masked_intentions/content/systems_management/virtualization_management_war_begins_in_earnest.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/blogs.eweek.com');" target="_blank">Michael Vizard, examines the virtualization market</a> and more at Masked Intentions. He says that, “Virtualization continues to evolve, and companies such as IBM, CA, <a href="http://www.eweek.com/c/a/Virtualization/Making-Virtualization-Work-for-You/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.eweek.com');" target="_blank">BladeLogic</a> and <a href="http://www.eweek.com/c/a/Infrastructure/Making-the-Most-Out-of-IT-Automation/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.eweek.com');" target="_blank">Hewlett-Packard</a> have all made specific commitments to extend their tools for managing physical servers to virtual machine environments.” We would add ScienceLogic to that list of course. But what’s more interesting is the statement that newbies focused on point solutions around virtualization management are saying that virtual machines represent a paradigm shift that will make existing management tools obsolete. Am I missing something here? All management vendors need to keep up with technology changes – hence the move to support virtualization. The market needs change; the management tools change, hopefully apace.
<p><a href="http://www.packettrap.com/blog/index.php/june-16th-2008-commercial-open-source-debate/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.packettrap.com');" target="_blank">PacketTrap thinks that commercial open source is dying</a>. So does that mean they think only commercial open source is their competitor and not just open source monitoring software?
<p>So their value proposition is not that their feature set and value are better, but that they’ll probably be around longer than any open source products dabbling in trying to drum up revenue.
<p>Want to work inside the Interop NOC? We’re <a href="http://www.interop.com/blog/?p=408" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.interop.com');" target="_blank">looking for some great people to join the volunteer team at Interop</a>.
<p>And finally, snicker, snicker. Here’s a truly funny post on the <a href="http://weblog.infoworld.com/openresource/archives/2008/06/memo_to_broadco.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/weblog.infoworld.com');" target="_blank">Broadcom debacle</a>. </p>
<p><a href="http://sharethis.com/item?&wp=2.5.1&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Links+List+6.20.08&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Flinks-list-62008%2F06%2F2008" onclick="javascript:pageTracker._trackPageview('/outbound/article/sharethis.com');">ShareThis</a></p>]]></content:encoded>
      <pubDate>Fri, 20 Jun 2008 17:26:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/management tools change">management tools change</category>
      <category domain="http://securityratty.com/tag/source products">source products</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/management tools obsolete">management tools obsolete</category>
      <category domain="http://securityratty.com/tag/change">change</category>
      <category domain="http://securityratty.com/tag/market">market</category>
      <category domain="http://securityratty.com/tag/virtualization market">virtualization market</category>
      <category domain="http://securityratty.com/tag/interop">interop</category>
      <source url="http://blog.sciencelogic.com/links-list-62008/06/2008">Links List 6.20.08</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-04-03 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/267178aadef12876bdbbc5bdc97a1501</link>
      <guid>http://securityratty.com/article/267178aadef12876bdbbc5bdc97a1501</guid>
      <description><![CDATA[Information Security as Insurance
Security Thoughts: Information Security, Governance, Compliance and Safety Belts I have seen a lot of complaints about PCI and SOX etc etc in the same way that people...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://dmiessler.com/blog/information-security-as-insurance">Information Security as Insurance</a></li>
<li><a href="http://securethink.blogspot.com/2008/03/information-security-governance.html">Security Thoughts: Information Security, Governance, Compliance and Safety Belts</a><br/>
I have seen a lot of complaints about PCI and SOX etc etc in the same way that people complain about &quot;self protection&quot; laws like safety belt laws.</li>
<li><a href="http://www.itbusinessedge.com/blogs/ssg/?p=283">The Evolution of Compliance Technology - Sarbox Survival Guide</a></li>
<li><a href="http://stage.vambenepe.com/archives/178">William Vambenepe&rsquo;s blog &raquo; Blog Archive &raquo; Another IT event standard? I&rsquo;ll believe it when I CEE it.</a></li>
<li><a href="http://searchsecurity.techtarget.com/tip/0,289483,sid14_gci1307430,00.html?track=NL-430&ad=632806USCA&asrc=EM_NLT_3408753&uid=832109">Worst practices: Recognizing the biggest compliance mistakes</a></li>
<li><a href="http://blog.tenablesecurity.com/2008/03/cybercrime-cybe.html">Tenable Network Security: CyberCrime, CyberTerror, CyberEspionage, and CyberWar</a><br/>
The final point I'd like to make on cybercrime is that the current set of problems show us nothing about how bad it can possibly get.

If you're part of an organzation that does business online, cybercrime is going to be part of your personal future, fo</li>
<li><a href="http://www.security-works.com/blog/2008/03/nice-grc-write-up-and-how-it-relates-to.html">practical risk management: Nice GRC write-up and how it relates to log management initiatives</a></li>
<li><a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/03/securitymatters_0320">Commentary: Inside the Twisted Mind of the Security Professional</a></li>
<li><a href="http://briefingsdirectblog.blogspot.com/2008/03/splunk-goes-platform-to-extend-it.html">Dana Gardner's BriefingsDirect: Splunk goes 'platform' to extend IT search benefits across more IT management functions</a></li>
<li><a href="http://www.sans.edu/resources/securitylab/hoelzer_david_dad.php">SANS Technology Institute: An Interview with David Hoelzer, author of DAD, a log aggregator</a></li>
<li><a href="http://paranoidmike.blogspot.com/2008/02/which-security-event-log-audit_12.html">ParanoidMike: Which Security Event Log audit categories are most useful on a Windows client?</a></li>
<li><a href="http://www2.csoonline.com/exclusives/column.html?CID=33575">Do Your Vendors Have Information Security That's Aaa Good? - Web Exclusives - Online Column - CSO Magazine</a></li>
<li><a href="http://www.s-ox.com/dsp_getNewsDetails.cfm?CID=2220">Sarbanes-Oxley: Growing Dependence on Log Data for Compliance and Threat Response</a><br/>
Results of note from the SenSage survey respondents include:

    *  Eighty-eight percent collect log data for compliance reasons, while 42 percent do so as part of best practices/industry standards initiatives such as ITIL.

    * Seventy-eight perce</li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/263759259" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 03 Apr 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security professional">security professional</category>
      <category domain="http://securityratty.com/tag/tenable network security">tenable network security</category>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/compliance reasons">compliance reasons</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/compliance mistakes">compliance mistakes</category>
      <category domain="http://securityratty.com/tag/compliance technology">compliance technology</category>
      <category domain="http://securityratty.com/tag/safety belt laws">safety belt laws</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/263759259/anton18">Links for 2008-04-03 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Show 004 - An Interview with Dana Epp]]></title>
      <link>http://securityratty.com/article/52ae9251ad51014268661d42bf188087</link>
      <guid>http://securityratty.com/article/52ae9251ad51014268661d42bf188087</guid>
      <description><![CDATA[In the fourth episode of the Silver Bullet Security Podcast, Garys guest is Dana Epp, CEO and founder of Scorpion Software . Dana also runs a popular software security blog and is a jazz trumpeter. On...]]></description>
      <content:encoded><![CDATA[<p><img align="right" alt="Dana Epp" title="Dana Epp" src="http://www.cigital.com/silverbullet/depp-125.jpg" /></p>
<p style="margin-top: 5px">In the fourth episode of the Silver Bullet Security Podcast, Gary&#8217;s guest is Dana Epp, CEO and founder of <a href="http://www.scorpionsoft.com/">Scorpion Software</a>.  Dana also runs a popular <a href="http://silverstr.ufies.org/blog/">software security blog</a> and is a jazz trumpeter.  On this show, Dana and Gary talk about past programming disasters (&#8221;code lives forever&#8221;), the security implications of systems with ever-increasing complexity, suggestions for new developers interested in learning about software security, regulation&#8217;s role in information security, and Miles Davis.</p>
<ul>
<li><a href="http://silverstr.ufies.org/blog/">SilverStr&#8217;s blog</a> - Dana&#8217;s blog</li>
<li><a href="http://snltranscripts.jt.org/90/90tpat.phtml">It&#8217;s Pat!</a></li>
<li><a href="http://www.rapro.com/">RemoteAccess BBS</a></li>
<li><a href="http://silverstr.ufies.org/blog/archives/000926.html">The 5 Rules of the Regulatory Process</a></li>
<li><a href="http://www.chrisbotti.com/">Chris Botti</a></li>
<li><a href="http://www.securecoding.org/list/">SC-L List</a></li>
<li><a href="http://www.miles-davis.com/brew.html"><em>Bitches Brew</em></a></li>
<li><a href="http://www.computer.org/security/bsisub">Subscribe to <em>IEEE Security &amp; Privacy</em></a></li>
</ul>
]]></content:encoded>
      <pubDate>Mon, 31 Jul 2006 17:30:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dana epp">dana epp</category>
      <category domain="http://securityratty.com/tag/dana">dana</category>
      <category domain="http://securityratty.com/tag/code lives forever">code lives forever</category>
      <category domain="http://securityratty.com/tag/silverstrs blog">silverstrs blog</category>
      <category domain="http://securityratty.com/tag/fourth episode">fourth episode</category>
      <category domain="http://securityratty.com/tag/regulatory process">regulatory process</category>
      <category domain="http://securityratty.com/tag/security implications">security implications</category>
      <category domain="http://securityratty.com/tag/sc-l list">sc-l list</category>
      <category domain="http://securityratty.com/tag/garys guest">garys guest</category>
      <source url="http://www.cigital.com/silverbullet/show-004/">Show 004 - An Interview with Dana Epp</source>
    </item>
  </channel>
</rss>
