<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: develop]]></title>
    <link>http://securityratty.com/tag/develop</link>
    <description></description>
    <pubDate>Fri, 22 Aug 2008 10:33:56 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Researchers develop bug-blocking chip monitor]]></title>
      <link>http://securityratty.com/article/d99bfa4028f6d252111ba50dd0c99d26</link>
      <guid>http://securityratty.com/article/d99bfa4028f6d252111ba50dd0c99d26</guid>
      <description><![CDATA[Researchers at the University of Michigan have developed technology that can fence off microprocessor bugs and keep them from seizing up a...]]></description>
      <content:encoded><![CDATA[Researchers at the University of Michigan have developed technology that can fence off microprocessor bugs and keep them from seizing up a PC.]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/microprocessor bugs">microprocessor bugs</category>
      <category domain="http://securityratty.com/tag/researchers">researchers</category>
      <category domain="http://securityratty.com/tag/university">university</category>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <category domain="http://securityratty.com/tag/michigan">michigan</category>
      <category domain="http://securityratty.com/tag/fence">fence</category>
      <source url="http://www.networkworld.com/news/2008/093008-researchers-develop-bug-blocking-chip.html?fsrc=rss-security">Researchers develop bug-blocking chip monitor</source>
    </item>
    <item>
      <title><![CDATA[Visa to develop e-payment applications for Android, Nokia phones]]></title>
      <link>http://securityratty.com/article/539d4a1928074468d4f77d0d8c3044f5</link>
      <guid>http://securityratty.com/article/539d4a1928074468d4f77d0d8c3044f5</guid>
      <description><![CDATA[Consumers will receive what Visa calls 'near real-time' notification of purchase activity, based on parameters they set...]]></description>
      <content:encoded><![CDATA[Consumers will receive what Visa calls 'near real-time' notification of purchase activity, based on parameters they set up.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:842b87190c8495845fef7a9ce0823867:l3rBLQjNmPDfsBgMMsKYCdemrvq1WtBlKR2KcqNiGszB5fUqeWneIVcvJP%2BL9pme20wVmWxvms7e'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:d552e4d82241291e12b4f9cd46c1a82f:r72UF0jPPeJY3jCMj85fDkKTXi01R%2FUdPPePwHAqCZGqgFDJAoZVtIKsf2Sxaack1yuIQmwPmWVcAg%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:70b36a1b76bb45004de2d05665939f23:sp%2BxcCju3x5LREWr%2FfLqUY4fIJr21RmJUnJgm7FO9EYgGpmCXMSv2dc6xo1csF0DAcKoPJEsc4SwEA%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:dd9b34271d18c4fef8847cb38ff993a0:GbWoppmXu765BzxawpAUTBAB7NkDc4nVVa%2BPr1a0Qry3qlc4uoUc55hFnhtDfVjwKyP2CHCFLVK3wA%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=8bb4372e4337d31b2c5d6585a9610148" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=8bb4372e4337d31b2c5d6585a9610148" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/visa calls">visa calls</category>
      <category domain="http://securityratty.com/tag/purchase activity">purchase activity</category>
      <category domain="http://securityratty.com/tag/receive">receive</category>
      <category domain="http://securityratty.com/tag/parameters">parameters</category>
      <category domain="http://securityratty.com/tag/consumers">consumers</category>
      <category domain="http://securityratty.com/tag/real-time">real-time</category>
      <category domain="http://securityratty.com/tag/notification">notification</category>
      <category domain="http://securityratty.com/tag/set">set</category>
      <category domain="http://securityratty.com/tag/based">based</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=8bb4372e4337d31b2c5d6585a9610148">Visa to develop e-payment applications for Android, Nokia phones</source>
    </item>
    <item>
      <title><![CDATA[Hansei and the CISO]]></title>
      <link>http://securityratty.com/article/345fa11bf7640e73e9bb05e7b33128f0</link>
      <guid>http://securityratty.com/article/345fa11bf7640e73e9bb05e7b33128f0</guid>
      <description><![CDATA[Continuing our series on Hansei-Kaizen, youll recall that my thoughts are about applying the concept of relentless reflection (Hansei) and continuous improvement (Kaizen) to security management. Today...]]></description>
      <content:encoded><![CDATA[<p>Continuing our series on Hansei-Kaizen, you&#8217;ll recall that my thoughts are about applying the concept of relentless reflection (Hansei) and continuous improvement (Kaizen) to security management.  Today is a good day to talk about <em><strong>what should we be reflecting about</strong></em>, and <em><strong>what is needed for reflection</strong></em>.</p>
<p>I say today is a good day for two reasons:  1.)  BT&#8217;s CSO Jill Knesek wrote an article called &#8220;<strong><a href="http://bt-securethinking.blogspot.com/2008/09/keys-to-establishing-end-to-end.html">Keys to establishing an end-to-end security strategy</a></strong>&#8221; which begs some discussion within context, and 2.)  <strong><a href="http://twitter.com/sarapeters">Sara Peters on Twitter</a></strong> last night wanted to know why I thought &#8220;risk management&#8221; requires more than what most &#8220;best practices&#8221; around the subject suggest the effort requires.</p>
<p><strong>WHAT SHOULD WE BE REFLECTING ABOUT?</strong></p>
<p>Jill Knesek&#8217;s article gives us a rough outline of how to develop a security strategy.  It&#8217;s fairly high-level, Pragmatic CSO-ish type stuff.  It gives us a nice outline of</p>
<ul>
<li>Get a seat at the table</li>
<li>Process</li>
<li>People</li>
<li>Technology</li>
</ul>
<p>Nothing earth-shattering there.  But it is a very nice broad CISO-level taxonomy about what we have to reflect on.  The <em><strong>need</strong></em> to reflect is driven by something Jack told me long ago,</p>
<blockquote><p>&#8220;The amount of risk we have is a function of the decisions we made and our ability to execute on them from some point in the past&#8221;.</p></blockquote>
<p style="padding-left: 30px;"><em>As an Aside:  So Sarah if you&#8217;re reading, this quote does much to explain why I said I disagree with much of what our industry calls &#8220;risk management&#8221;.  We tend to define the process of risk management as essentially a tactical &#8220;issue whack-a-mole&#8221; exercise. </em><em><strong>Find the issue.  Analyze the &#8220;risk&#8221; around the issue.  Fix the issue.  Repeat. </strong> This hamster-wheel-of-pain, while sometimes an effective tool for the CISO, is incongruous with addressing root causes (the ability to match a tactical issue to the strategic shortcoming that created the issue is up to the expertise of the analyst or consultant).  It is only Kaizen without (good) Hansei, if you will.</em></p>
<p>Back to what Jill is writing - the sorts of things we should be reflecting about can be thought of in context of her outline.  Namely:</p>
<ol>
<li>Once you have a seat at the table, what is the nature of that relationship?  Who are you reporting to and what are their concerns? What and how are you reporting and how might that be addressing their concerns?</li>
<li>What processes are in place?, How do you know that those are the processes that should be in place? If they are, what kind of job am I doing at those processes?</li>
<li>What is the quality of the skills and resources I have from a people perspective, and how do I know if they are adequate?  How do I know that the training they petition me for will effectively reduce organizational risk?</li>
<li>Are the Technology solutions I have in place effective, are we managing them effectively, and what sort of States of Knowledge could they provide me with (to make good decisions and execute upon them, from above)?</li>
</ol>
<p>This, for the CISO, is Hansei.  The continuous management of it is Kaizen.  Not to particularly pick on Jill&#8217;s article, but creating a &#8220;risk register expressed in ALE&#8221; might be fine if you&#8217;re trying to explain to the board what your &#8220;first 100 days in office&#8221; will be like - but these sorts of lists are usually not very strategic in nature, and as such, depending on the outcome of that risk register (and the models used to create it) <em><strong>it might not actually be useful.</strong></em></p>
<p><strong>WHAT IS NEEDED FOR REFLECTION?</strong></p>
<p>So what is needed for this sort of CISO-level Hansei?</p>
<p>The CISO must understand the</p>
<ul>
<li>Current State of Nature</li>
</ul>
<p>turn that into a</p>
<ul>
<li>State of Knowledge</li>
</ul>
<p>and use that to create a</p>
<ul>
<li>State of Wisdom.</li>
</ul>
<p><strong>CREATING A STATE OF NATURE FOR THE IRM PROGRAM<br />
</strong></p>
<p>This Current State of Nature determination be done by applying analytical methods to a program audit.  We must understand questions like,  &#8220;What is in that program and how is it structured?&#8221;  before we can answer questions about &#8220;how (good/bad) are we at managing risk?&#8221;</p>
<p>There are many ways to structure an IRM program, but as an example - below is a graphic shared with me by Adrian Seccombe.  For those who know Adrian and the Trust Model - this is classified as &#8220;white&#8221; so it&#8217;s OK for public display and consumption.  But here&#8217;s what Adrian is trying to build at a high level:</p>
<p style="text-align: center;"><img class="aligncenter" src="http://www.riskmanagementinsight.com/media/images/weblog/Program.jpg" alt="" width="283" height="356" /></p>
<p>So regarding Adrian&#8217;s program diagram:</p>
<ol>
<li>Is a governance framework.  Think ITIL.</li>
<li>Is a risk framework.  Think ISO 27002 using FAIR as an analytical engine.  To be fair (pun) I believe this is really issue management, and it&#8217;s a process, but that&#8217;s OK.</li>
<li>Reg compliance should be self explanatory.  That&#8217;s essentially what GRC products do for you.</li>
<li>With architecture, I think Adrian is inclined towards TOGAF.</li>
<li>Security is the ISMS in place (27001, ISM^3, PCI, whatever&#8230;)</li>
<li>Are the processes that drive execution</li>
<li><strong>M</strong><strong>onitor</strong> (audit) is creating a State of Nature and <strong>Evaluate</strong> is creating a State of Knowledge from that State of Nature around items 1-6.</li>
</ol>
<p><strong>EVALUATE - CREATING A STATE OF KNOWLEDGE ABOUT THE IRM PROGRAM</strong></p>
<p>That evaluate is Hansei/Kaizen.  Evaluation, done effectively, will drive actual organizational risk exposure.  Evaluate will even answer those four questions we raised in the &#8220;What Should We Be Reflecting About&#8221; section above:</p>
<ol>
<li>Once you have a seat at the table, what is the nature of that relationship?  Who are you reporting to and what are their concerns? What and how are you reporting and how might that be addressing their concerns?</li>
<li>What processes are in place?, How do you know that those are the processes that should be in place? If they are, what kind of job am I doing at those processes?</li>
<li>What is the quality of the skills and resources I have from a people perspective, and how do I know if they are adequate?</li>
<li>Are the Technology solutions I have in place effective, are we managing them effectively, and what sort of States of Wisdom do they provide me with (to make good decisions and execute upon them, from above)?</li>
</ol>
<p>If we could have a nice metric (or set of metrics) that answers these questions, we might call it something like &#8220;My Ability To Manage Risk&#8221; or MATMR for short.</p>
<p><strong>GETTING TO A STATE OF WISDOM</strong></p>
<p>What&#8217;s then missing is how you create a State of Wisdom around the State of Knowledge developed - your &#8220;MATMR&#8221; metric.  That is, given the current State of Knowledge - how can I be most effective?  This State of Wisdom requires proper models for what risk is, and what you can do to manage it applied in a probabilistic manner (because we can&#8217;t intrinsically *know* the future, we can only say with some degree of certainty what the desired course should be).</p>
<p>So the outcome of Hansei/Kaizen should be to create a State of Wisdom about Risk Management.  This is why reflection must be relentless - because your wisdom must be similarly abundant.</p>
<p>This is no small part of the reason RMI exists, why we build software and help organizations understand the things they do.</p>
]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 13:47:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management requires">risk management requires</category>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/hansei">hansei</category>
      <category domain="http://securityratty.com/tag/risk register">risk register</category>
      <category domain="http://securityratty.com/tag/program">program</category>
      <category domain="http://securityratty.com/tag/manage risk">manage risk</category>
      <category domain="http://securityratty.com/tag/manage">manage</category>
      <category domain="http://securityratty.com/tag/adrians program diagram">adrians program diagram</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=411">Hansei and the CISO</source>
    </item>
    <item>
      <title><![CDATA[SDL and the XSS Filter, Revisited]]></title>
      <link>http://securityratty.com/article/716886a1157dce9a26be34d638f2a814</link>
      <guid>http://securityratty.com/article/716886a1157dce9a26be34d638f2a814</guid>
      <description><![CDATA[Bryan here. Since Steve called me out in his post on the XSS Filter last week, I feel obligated to clarify my position. I believe that the SDL blog is mainly for development teams; after all,...]]></description>
      <content:encoded><![CDATA[<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">Bryan here. Since Steve called me out in his post on the <A class="" href="http://blogs.msdn.com/sdl/archive/2008/08/27/sdl-and-the-xss-filter.aspx" mce_href="http://blogs.msdn.com/sdl/archive/2008/08/27/sdl-and-the-xss-filter.aspx">XSS Filter</A> last week, I feel obligated to clarify my position. </SPAN><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Courier New'; mso-ascii-theme-font: minor-latin; mso-ascii-font-family: Calibri">☺</SPAN><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-bidi-font-family: Consolas; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"> I believe that the SDL blog is mainly for development teams; after all, development is the D in SDL. Now, development teams are made up of more than just developers. Development teams include everyone involved in the development process from management on down. But development teams don’t include end users. While XSS Filter is a great, innovative XSS defense technology, there’s really nothing that development teams can do to take advantage of it. Users alone make the decision as to whether they’re g</SPAN><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">oing to take advantage of XSS Filter: they either use IE8 and get it, or they use another browser and don’t get it.<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p></o:p></SPAN></P>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"><o:p>&nbsp;</o:p></SPAN></P>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">That being said, there are some interesting implications that XSS Filter and other user-specified defenses have for the SDL. Given that XSS Filter is effective in stopping many types of reflected XSS attacks, should we relax the SDL coding and testing requirements around server-side XSS defense? Of course not. For one reason, the SDL requirements are effective in preventing forms of XSS that XSS Filter does not address, like persistent XSS. For another, not everyone uses IE 8. If we were to relax server-side requirements now, we would jeopardize IE 7 users, as well as Firefox, Safari, Opera, Chrome, and all the other browsers’ users.<o:p></o:p></SPAN></P>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"><o:p>&nbsp;</o:p></SPAN></P>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">But what if these conditions change? What if David and others on the <A class="" href="http://blogs.technet.com/swi/" mce_href="http://blogs.technet.com/swi/">security science team</A> develop a new version of XSS Filter that’s effective against all forms of XSS? And what if all the browser manufacturers develop similar technology and implement it in their browsers? (Or alternatively, what if every user on the planet switches to IE 8? </SPAN><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Courier New'; mso-ascii-theme-font: minor-latin; mso-ascii-font-family: Calibri">☺</SPAN><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-bidi-font-family: Consolas; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">) Then would we relax the server-side XSS defense requirements? Yes, we probably would.</SPAN><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"><o:p></o:p></SPAN></P>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"><o:p>&nbsp;</o:p></SPAN></P>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">I’ve always been more of a security pragmatist than a security purist. While the security purist in me would want to keep the requirements around to prevent developers from falling back into bad habits, the security pragmatist in me would recognize that development teams have a limited amount of bandwidth, and making them defend against rare, obscure vulnerabilities is a poor use of their time. Unfortunately, we’re not likely to face this scenario any time in the near future, so the SDL will continue to require server-side input validation and output encoding to prevent XSS attacks.<o:p></o:p></SPAN></P>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"><o:p>&nbsp;</o:p></SPAN></P>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">We now return you to your regularly scheduled development-focused blog.<o:p></o:p></SPAN></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=8934730" width="1" height="1">]]></content:encoded>
      <pubDate>Mon, 08 Sep 2008 16:18:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/xss">xss</category>
      <category domain="http://securityratty.com/tag/xss filter">xss filter</category>
      <category domain="http://securityratty.com/tag/persistent xss">persistent xss</category>
      <category domain="http://securityratty.com/tag/server-side xss defense">server-side xss defense</category>
      <category domain="http://securityratty.com/tag/development teams include">development teams include</category>
      <category domain="http://securityratty.com/tag/development teams">development teams</category>
      <category domain="http://securityratty.com/tag/development">development</category>
      <category domain="http://securityratty.com/tag/sdl">sdl</category>
      <category domain="http://securityratty.com/tag/sdl requirements">sdl requirements</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/09/08/sdl-and-the-xss-filter-revisited.aspx">SDL and the XSS Filter, Revisited</source>
    </item>
    <item>
      <title><![CDATA[Modelling Shoplifting]]></title>
      <link>http://securityratty.com/article/3943f3c70f24e801812a87cf0b0b61f8</link>
      <guid>http://securityratty.com/article/3943f3c70f24e801812a87cf0b0b61f8</guid>
      <description><![CDATA[The other day I was thinking that I should write about specific situation models and by coincident Marc Adler pens CEP and Shoplifting . In Marcs post, Marc begins to model shoplifting as if...]]></description>
      <content:encoded><![CDATA[<p>The other day I was thinking that I should write about specific situation models and by coincident Marc Adler pens <a href="http://magmasystems.blogspot.com/2008/09/cep-and-shoplifting.html" target="_blank">CEP and Shoplifting</a>.  In Marc&#8217;s post, Marc begins to model shoplifting as if shoplifting is &#8220;market data,&#8221; with Level 1 to Level 4 shoplifting &#8220;quotes&#8221; - the natural approach for a brilliant guy from Citi.   In reality, this model does not work very well, and I&#8217;ll touch on a few reasons why today.</p>
<p>Marc&#8217;s initial shoplifting model in his post is based on John <span id="SPELLING_ERROR_3" class="blsp-spelling-error">Colapinto&#8217;s concepts of matching a pattern of customer movements in the store with their estimated patterns of shoplifting behavioral patterns.    Marc&#8217;s asks how Coral8 might address this.   We are not ready to seek a vendor solution.  We do not yet have a workable detection model.</span></p>
<p><span class="blsp-spelling-error">As indicated above, I don&#8217;t think the example situation cited by John and Marc is a viable model for automated processing.    Tracking the behavior of customer&#8217;s movements, by machine, would require some very sophisticated image processing technology that would be too expensive compared to any possible loss at most retails stores.    This type of behavioral pattern recognition. in retail stores, is performed by people (security personnel), not machines, observing people.  </span></p>
<p><span class="blsp-spelling-error">To develop a machine pattern recognition application to detect retail shoplifting we need to build detection models that are economically feasible.  If we are going to use a model of shoplifting pattern recognition versus anomaly detection, we need to define the objects we must track.   </span></p>
<p><span class="blsp-spelling-error">In the most simple model, we have merchandise-objects.   Stores normally (physically) track merchandise-objects only at the exit/entry points of the store using some electromagnetic proximity detection technology.   In this model, the detection configuration is a combination of simple alerting with humans watching the store (&#8221;minding the store&#8221;).    This is not complex event processing.</span></p>
<p><span class="blsp-spelling-error">However, if we added another object to our model, the customer-object, then we start to get more &#8220;complex,&#8221; but we have not defined &#8220;complexity&#8221; yet because we have not defined the object properties, the possible states of the objects, and the relationships between the objects that are the basis for estimated situations.</span></p>
<p><span class="blsp-spelling-error">Hence, model building is constrained by available resources, simple economics and risk (cost-benefit).  If we are detecting shoplifting in Walmart the cost-benefit model for implementing an automated shoplifting detection system would be different than at a top diamond store on 5th Avenue in NYC.   Protecting loss at a weapons-grade uranium respository follows a different model than protecting loss at a handicraft shop, naturally.</span></p>
<p><span class="blsp-spelling-error">Like Marc, I find models to automatically detect shoplifting interesting, so permit me to close with a general discussion of shoplifting in the context of our <a href="http://www.thecepblog.com/what-is-complex-event-processing/" target="_blank">CEP/EP reference model</a>.</span></p>
<p><span class="blsp-spelling-error"><span class="blsp-spelling-error">One approach would be do determine what objects will be represented in our model.   For example, if we are going to track merchandise, we need to model the &#8221;merchandise-object&#8221;.  If we are going to track people, we need to define the properties of this &#8220;person object.&#8221;  If we are going to represent the store layout, we need to define all these objects (store-object, table-object, shelf-object, entry-object and so forth).  The model can get &#8220;complex&#8221; quite quickly.  </span></span></p>
<blockquote><p><span class="blsp-spelling-error"><span class="blsp-spelling-error">Editorial Note:  <em>An object-oriented approach greatly assists complex model building because we can benefit from OO properties such as encapsulation and polymorphism.  For example, we can define a basic &#8220;person object class&#8221; and then create superclasses of this object for &#8220;customer-object&#8221;, &#8220;manager-object&#8221;, &#8220;or criminal-object.&#8221;</em></span></span></p></blockquote>
<p><span class="blsp-spelling-error"><span class="blsp-spelling-error">Generally speaking, each object we define will require a state-model, for example, in Marc&#8217;s example of a customer moving around the store, we would need to model the possible states (customer at the entrance, at table 1, at table 2, at shelf 1, in the bathroom, at the cashier, etc.)  Indeed Marc, this is complex event processing if we have modelled multiple objects and defined object-object relationships that indicate situations of interest.   For example, customer-object at table2 where merchandise-object has the property of  &#8221;very expensive, high risk&#8221; and then customer-object changes state to &#8220;in bathroom&#8221;.  Of course, we need more key indicators, but you get the idea.</span></span></p>
<p><span class="blsp-spelling-error"><span class="blsp-spelling-error">Right now, I am typing from the <a href="http://www.taste4heaven.com">Taste from Heaven Vegetarian Restaurant</a> in Chiang Mai and my battery is running low.  The owner of this excellent restaurant also runs the <a href="http://www.elephantnaturefoundation.org/" target="_blank">Elephant Nature Park</a>, a non-profit organization advocating and acting on behalf of the rights of the mighty elephants in Thailand.  Would be great if we could also automatically detect the situation of &#8220;elephant abuse&#8221; by poachers and other crimes against nature.   Time to get back to my delicious mushroom salad, Northeastern Thai style.</span></span></p>
<p><span class="blsp-spelling-error"><span class="blsp-spelling-error">As always, thanks for reading, time for me to get back to eating!</span></span></p>
<p> </p>
]]></content:encoded>
      <pubDate>Sun, 07 Sep 2008 03:30:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/store">store</category>
      <category domain="http://securityratty.com/tag/store-object">store-object</category>
      <category domain="http://securityratty.com/tag/complex">complex</category>
      <category domain="http://securityratty.com/tag/model canget complex">model canget complex</category>
      <category domain="http://securityratty.com/tag/model">model</category>
      <category domain="http://securityratty.com/tag/simple">simple</category>
      <category domain="http://securityratty.com/tag/simple economics">simple economics</category>
      <category domain="http://securityratty.com/tag/simple model">simple model</category>
      <category domain="http://securityratty.com/tag/object">object</category>
      <source url="http://www.thecepblog.com/2008/09/07/modelling-shoplifting/">Modelling Shoplifting</source>
    </item>
    <item>
      <title><![CDATA[Can Chrome be read by a Keylogger?]]></title>
      <link>http://securityratty.com/article/ffd6c737d3494d5d3d0a9f12e2f3d320</link>
      <guid>http://securityratty.com/article/ffd6c737d3494d5d3d0a9f12e2f3d320</guid>
      <description><![CDATA[I dont know yet, but Im checking. This is a article that bears reading


clipped from www.tgdaily.com


Chrome is a security nightmare, indexes your bank accounts


So is this all a big deal?? Well...]]></description>
      <content:encoded><![CDATA[<div > I dont know yet, but Im checking. This is a article that bears reading.<br/> </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/F94FFD04-78C2-4FF1-B714-FCA0F390D44C/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/e1bca7ce-88f4-4574-a7c0-b319e0a3e344/F94FFD04-78C2-4FF1-B714-FCA0F390D44C/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.tgdaily.com/content/view/39176/108/" href="http://www.tgdaily.com/content/view/39176/108/" style="font-size: 11px;">www.tgdaily.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.tgdaily.com/content/view/39176/108/ --><br />
<table background="undefined" bgcolor="">
<tr><TD width="100%" class="contentheading">Chrome is a security nightmare, indexes your bank accounts									</TD></tr>
</table>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.tgdaily.com/content/view/39176/108/ --><DIV>So is this all a big deal?? Well anyone who wants to search your financial information would need local access to your machine and if a person is sitting at your <A class="iAs" classname="iAs" href="#" target="_blank" itxtdid="6579451">computer</A>, you have a lot more things to worry about than him/her using Chrome’s history search.? Conceivably a hacker could develop an app to pull the cache and index files off your computer and examine them later on another machine – these files reside in the “C:\Documents and Settings\USERNAME\Local Settings\Application Data\Google\Chrome\User Data\Default” folder.</DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/F94FFD04-78C2-4FF1-B714-FCA0F390D44C/blog/" title="blog or email this clip"><img src="http://content8.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_050908035635"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=050908035635&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=050908035635&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=050908035635&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_050908035635" /></a></P>]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 11:56:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/local access">local access</category>
      <category domain="http://securityratty.com/tag/chrome">chrome</category>
      <category domain="http://securityratty.com/tag/chromes history">chromes history</category>
      <category domain="http://securityratty.com/tag/index files">index files</category>
      <category domain="http://securityratty.com/tag/machine">machine</category>
      <category domain="http://securityratty.com/tag/security nightmare">security nightmare</category>
      <category domain="http://securityratty.com/tag/datadefault folder">datadefault folder</category>
      <category domain="http://securityratty.com/tag/financial information">financial information</category>
      <category domain="http://securityratty.com/tag/bank accounts">bank accounts</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=605">Can Chrome be read by a Keylogger?</source>
    </item>
    <item>
      <title><![CDATA[Planning for a new year]]></title>
      <link>http://securityratty.com/article/53eb51a004ab3e2477c2c3559dd8fb20</link>
      <guid>http://securityratty.com/article/53eb51a004ab3e2477c2c3559dd8fb20</guid>
      <description><![CDATA[October is creeping up on us, and for most of us that means the beginning of the end of 2008, along with the nagging feeling that we should be doing some planning for 2009. This is the perfect...]]></description>
      <content:encoded><![CDATA[October is creeping up on us, and for most of us that means the beginning of the end of 2008, along with the nagging feeling that we should be doing some planning for 2009. This is the perfect opportunity to take stock of your security and compliance programs, and to develop a plan for improving things next year. If you've been following our various blogs here at RSA you probably realize by now that we espouse a security and compliance program based on three core pillars: it's information-centric, risk-driven and framework-based. Our compliance team has spoken with hundreds of customers from all over the world and in every industry segment this year, and we're finding that this approach is gaining acceptance at an ever-increasing rate. <B>Organizations are realizing that they need to discover, manage and control their information assets in order to protect them...</b>]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/compliance program based">compliance program based</category>
      <category domain="http://securityratty.com/tag/compliance team">compliance team</category>
      <category domain="http://securityratty.com/tag/industry segment">industry segment</category>
      <category domain="http://securityratty.com/tag/compliance programs">compliance programs</category>
      <category domain="http://securityratty.com/tag/information assets">information assets</category>
      <category domain="http://securityratty.com/tag/core pillars">core pillars</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/perfect opportunity">perfect opportunity</category>
      <category domain="http://securityratty.com/tag/october">october</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1337">Planning for a new year</source>
    </item>
    <item>
      <title><![CDATA[The Stigma Enigma, Revisited]]></title>
      <link>http://securityratty.com/article/c238be0f778cce325c4423b05b36b9e3</link>
      <guid>http://securityratty.com/article/c238be0f778cce325c4423b05b36b9e3</guid>
      <description><![CDATA[Recently my pal Bill Pytlovany (of WinPatrol fame) wrote an article on his blog asking &quot;What's Wrong With Toolbars

I wrote something along similar lines way back in 2005 , and it's vaguely depressing...]]></description>
      <content:encoded><![CDATA[
        Recently my pal Bill Pytlovany (of WinPatrol fame) wrote an <a href="http://billpstudios.blogspot.com/2008/08/what-wrong-with-toolbars.html">article</a> on his blog asking "What's Wrong With Toolbars"?<br /><br />I wrote something along similar lines <a href="http://www.revenews.com/chrisboyd/the-stigma-enigma/">way back in 2005</a>, and it's vaguely depressing to see how little has apparently changed. I'm not going to quote myself, but rather compare and contrast Bills experiences (and those of his commentators) with the person who posted a comment to my entry, which I quote below in full:<br /><br /><div class="comment-content">
                                                <p><i>"Unfortunately,
the few 'honest' toolbars have indeed taken the wrath of users as a
result of the spyware, parasite, adware and other creepy applications
of an otherwise good technology.</i></p>
<p><i>What's interesting is that, as far as my own toolbar system goes,
I've had offers from clients all over the world to develop different
kinds of toolbars -- and without fail -- it is the US-based companies
that seem most willing to cross the line and request applications that
I simply refuse to develop.</i></p>
<p><i>We're talking about features like:</i></p>
<p><i>- Forced Install<br />
- Hidden Install<br />
- Report all URLs back<br />
- Report all searches back<br />
- Forcibly and hidden set home page<br />
- Forcibly and hidden set default search engine<br />
- Forcibly generate un-blockable pop-ups<br />
- Install and run hidden executables<br />
- Bypass all security and anti-virus tools<br />
- The list goes on...</i></p>
<p><i>What's sad is that I'm able to generate the most powerful and
incredibly useful toolbars imaginable. Ones that can save countless
hours of time and effort. Ones that can be customized on a per-user
basis to make the Internet and use of ones's own computer a pleasure.</i></p>
<p><i>However, there will always be people around who's sole motivation is the almighty dollar -- and who will do ANYTHING to get it.</i></p>
<p><i>These people don't care about you, your wants, your needs, your
security or safety -- as long as they can line their pockets with your
money, or by taking advantage of actions you perform (even one lousy
click!).</i></p>
<p><i>They'll infect your machine, using whatever means necessary, and they won't stop -- EVER."</i><br /><br />The "industry" has certainly cleaned up since then, but the insistence on wanting to cram a toolbar on every PC, ever, remains. I must admit to being kind of disturbed that none of these companies seemingly want to take "No" for an answer - instead of leaving alone, they keep coming back every month or so. Of course, given the potential for mass moneymaking that's on offer I can't say I'm entirely surprised...<br /></p>
                    </div><br /> 
        
    ]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 10:58:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/toolbars imaginable">toolbars imaginable</category>
      <category domain="http://securityratty.com/tag/toolbars">toolbars</category>
      <category domain="http://securityratty.com/tag/forcibly">forcibly</category>
      <category domain="http://securityratty.com/tag/install">install</category>
      <category domain="http://securityratty.com/tag/toolbar">toolbar</category>
      <category domain="http://securityratty.com/tag/applications">applications</category>
      <category domain="http://securityratty.com/tag/contrast bills experiences">contrast bills experiences</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/toolbar system">toolbar system</category>
      <source url="http://blog.spywareguide.com/2008/08/the-stigma-enigma-revisited.html">The Stigma Enigma, Revisited</source>
    </item>
    <item>
      <title><![CDATA[Building Secure Web Applications Training in Minneapolis]]></title>
      <link>http://securityratty.com/article/425c10b73ebf6262c2b07d2a4b9edeaa</link>
      <guid>http://securityratty.com/article/425c10b73ebf6262c2b07d2a4b9edeaa</guid>
      <description><![CDATA[I am very excited to announce that I am co-teaching a public software security class with Ken van Wyk , in Minneapolis, the class runs September 30 - October 2. Ken co-wrote a great book called Secure...]]></description>
      <content:encoded><![CDATA[<div>I am very excited to announce that I am co-teaching a public software security class with <a href="http://krvw.com/about/about.html">Ken van Wyk</a>, in Minneapolis, the class runs September 30 - October 2. Ken co-wrote a great book called <a href="http://1raindrop.typepad.com/1_raindrop/2007/02/book_review_sec.html">Secure Coding</a>, and has trained folks in software security all across the globe. I am really looking forward to doing this class with Ken, I wanted to make sure we got Ken up here before the weather got too cold! The summary is below, if you would like more info please let me know. More details to follow.</div><br /><div>Building Secure Web Applications in Java/J2EE</div><br /><div>Course Description</div><div>This course teaches the students how to develop secure applications from the web front end through the middle tier and data and integration layers for today’s complex internetworked environment. &#160;Students will receive a deep and thorough understanding of the most prevalent and dangerous security defects in today’s applications, and what to do about them. &#160;Additionally, they will learn practical and actionable guidelines on how to remediate against these common defects in Java/J2EE and Web Services frameworks and how to test for them in their own applications.</div><br /><div>This class starts with a description of the security problems faced by today&#39;s software developer, as well as a detailed description of the Open Web Application Security Project’s (OWASP) “Top 10” security defects. &#160;These defects are studied in instructor-lead sessions as well as in hands-on lab exercises in which each student learns how to actually exploit the defects to “break into” a real web application. &#160;(The labs are performed in safe test environments.)</div><br /><div>Remediation techniques and strategies are then studied for each defect. Practical guidelines on how to integrate secure development practices into the software development process are then presented and discussed. Bring the concepts and hands on learning together, the class uses a case study to show how to design and architect security services for a real world application.</div><br /><div>Intended Audience</div><div>The ideal student for this tutorial is a hands-on web application developer or architect who is looking for a fundamental understanding of today&#39;s best practices in secure software development.</div>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 17:43:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security defects">security defects</category>
      <category domain="http://securityratty.com/tag/defects">defects</category>
      <category domain="http://securityratty.com/tag/applications">applications</category>
      <category domain="http://securityratty.com/tag/secure">secure</category>
      <category domain="http://securityratty.com/tag/dangerous security defects">dangerous security defects</category>
      <category domain="http://securityratty.com/tag/secure web applications">secure web applications</category>
      <category domain="http://securityratty.com/tag/develop secure applications">develop secure applications</category>
      <category domain="http://securityratty.com/tag/secure software development">secure software development</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/building-secure-web-applications-training-in-minneapolis.html">Building Secure Web Applications Training in Minneapolis</source>
    </item>
    <item>
      <title><![CDATA[Reputation Damage & Measurement]]></title>
      <link>http://securityratty.com/article/d9577961443ca1c3cd93223077fbca5f</link>
      <guid>http://securityratty.com/article/d9577961443ca1c3cd93223077fbca5f</guid>
      <description><![CDATA[Reputation damage can be one of the most difficult concepts to build measurements around. In fact, it can be difficult to develop the actual metrics for the measurements, as well. Damage to things...]]></description>
      <content:encoded><![CDATA[<p>Reputation damage can be one of the most difficult concepts to build measurements around.  In fact, it can be difficult to develop the actual metrics for the measurements, as well.  Damage to things like &#8220;corporate reputation&#8221; and &#8220;goodwill&#8221; and &#8220;brand equity&#8221; can be difficult to wrap even reasonable dollar estimates around (When I use FAIR, I really only care to use one metric when describing loss magnitudes - the almighty currency).</p>
<p>Complicating factors is the impact (or lack thereof) of incidents on stock price.  Many researchers who identify themselves with the <strong><a href="http://www.amazon.com/New-School-Information-Security/dp/0321502787">New School of Information Security</a></strong> (yours truly included) want to immediately look at stock price as a bell-weather metric for incident impact.  I think this stems from our days of slinging FUD, back when we could scream &#8220;Buy a firewall or we&#8217;ll have an incident and you&#8217;ll be on the front page of the paper and the stock price will go down!&#8221;  But these days notable incidents seem to suggest that the impact on stock price for an incident is short lived.  <em><strong>With qualifications, of course.</strong></em></p>
<p>So what would/should we make of this from <a href="http://www.money.co.uk/article/1001229-12-million-wiped-off-helphire-stock-after-malicious-gmail-sent-to-clients.htm">Money.co.uk</a>?</p>
<p style="text-align: center;"><strong>£12million ($24m) Wiped off Helphire Stock after Malicious Email Sent to Clients</strong></p>
<blockquote><p>Car hire firm Helphire have taken Google to court after a malicious email sent from a Gmail account saw their shares plummet £12million in a single day.</p>
<p>The Bath-based business who specialise in providing replacement cars to &#8216;no-fault&#8217; drivers involved in accidents on behalf of car insurance companies, initiated legal proceedings against the search engine giant as part of their attempt to find out who is responsible for sending the defamatory mailing.</p>
<p>Google are now known to have complied with the court order and have controversially supplied details of the email account and ISP used by the meddler.</p>
<p>Written under the psudoname Peter Franks, the 1200 word email is know to have been sent from a gmail account that was opened specifically for this purpose and closed a few minutes after the damage had been done&#8230;</p>
<p>&#8230;The misdemeanour couldn’t have come at a worse time for the struggling firm who have undergone a £45million rights issue and seen a 75% drop in the value of their stock already this year.</p></blockquote>
<p>That last paragraph, for me, explains some of the difficulty in tying reputation damage to stock decreases.  It&#8217;s like when you read the headlines from Bloomberg about why the days stocks (or commodity) prices are up or down.  You know, the &#8220;Oil closes $3 higher on news that a notable South American dictator has a rather unpleasant boil in a very uncomfortable area&#8221; type of headlines.  You really do have to question the causality and correlation.  So in the Helphire case above - is this new drop in stock really because of the email sent?  If so, should we view that $24mil number as an independent data point to describe this sort of attack on reputation, or is the magnitude aggravated due to the long-term trend of stock price?</p>
<p>Even when we have &#8220;Objective Data&#8221; (an in-joke for Adam S.) like this decline in stock price, it is really difficult to provide any sort of precise estimate or measurement - about the future, present or past.  The best we can do is use ranges, distributions, that are reasonable based on evidence and observation.</p>
<p>So it&#8217;s worth filing away this sort of datum for future use - while dutifully acknowledging the qualifiers we might place around it.</p>
<p>So the questions I ask here - what should we make of this new information, and how should we view the $24million drop - they&#8217;re not rhetorical.  I am very interested in your views and welcome your comments!</p>
]]></content:encoded>
      <pubDate>Fri, 22 Aug 2008 10:33:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/stock">stock</category>
      <category domain="http://securityratty.com/tag/helphire stock">helphire stock</category>
      <category domain="http://securityratty.com/tag/reputation damage">reputation damage</category>
      <category domain="http://securityratty.com/tag/reputation">reputation</category>
      <category domain="http://securityratty.com/tag/stock price">stock price</category>
      <category domain="http://securityratty.com/tag/damage">damage</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/email account">email account</category>
      <category domain="http://securityratty.com/tag/malicious email">malicious email</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=387">Reputation Damage &amp; Measurement</source>
    </item>
  </channel>
</rss>
