<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: donna]]></title>
    <link>http://securityratty.com/tag/donna</link>
    <description></description>
    <pubDate>Mon, 23 Jun 2008 11:09:22 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Random Killing on a Canadian Greyhound Bus]]></title>
      <link>http://securityratty.com/article/bc4696b6a26761ebc94ae2e2e488c3b0</link>
      <guid>http://securityratty.com/article/bc4696b6a26761ebc94ae2e2e488c3b0</guid>
      <description><![CDATA[After a random and horrific knife decapitation on a Greyhound bus last week
does this surprise anyone
A grisly slaying on a Greyhound bus has prompted calls for tighter security on Canadian bus lines,...]]></description>
      <content:encoded><![CDATA[<p>After a <a href="http://www.saskatoonhomepage.ca/index.php?option=com_content&task=view&id=13065&Itemid=374">random and horrific knife decapitation</a> on a Greyhound bus last week, <blockquote><br />
does <a href="http://www.cbc.ca/canada/story/2008/08/01/bus-slaying-security.html">this</a> surprise anyone:</p>

<p><bockquote>A grisly slaying on a Greyhound bus has prompted calls for tighter security on Canadian bus lines, despite the company and Canada's transport agency calling the stabbing death a tragic but isolated incident.</p>

<p>Greyhound spokeswoman Abby Wambaugh said bus travel is the safest mode of transportation, even though bus stations do not have metal detectors and other security measures used at airports.</blockquote></p>

<p>Despite editorials telling people <a href="http://lfpress.ca/newsstand/Opinion/Editorials/2008/08/02/6337056-sun.html">not to overreact</a>, it's <a href="http://thechronicleherald.ca/Canada/1070711.html">easy to</a>:</p>

<blockquote>"Hearing about this incident really worries me," said Donna Ryder, 56, who was waiting Thursday at the bus depot in Toronto.

<p>"I’m in a wheelchair and what would I be able to do to defend myself? Probably nothing. So that’s really scary."</p>

<p>Ryder, who was heading to Kitchener, Ont., said buses are essentially the only way she can get around the province, as her wheelchair won’t fit on Via Rail trains. As it is her main option for travel, a lack of security is troubling, she said.</p>

<p>"I guess we’re going to have to go the airline way, maybe have a search and baggage check, X-ray maybe," she said.</p>

<p>"Really, I don’t know what you can do about security anymore."</blockquote></p>

<p>Of course, airplane security <a href="http://www.sindark.com/2008/08/01/greyhound-bus-security/">won't work on busses</a>.</p>

<p>But -- more to the point -- <a href="http://www.schneier.com/blog/archives/2007/05/rare_risk_and_o_1.html">this essay</a> I wrote on overreacting to rare risks applies here:</p>

<blockquote>People tend to base risk analysis more on personal story than on data, despite the old joke that "the plural of anecdote is not data." If a friend gets mugged in a foreign country, that story is more likely to affect how safe you feel traveling to that country than abstract crime statistics. 

<p>We give storytellers we have a relationship with more credibility than strangers, and stories that are close to us more weight than stories from foreign lands. In other words, proximity of relationship affects our risk assessment. And who is everyone's major storyteller these days? Television.</blockquote></p>

<p>Which is why Canadians are talking about increasing security on long-haul busses, and not Americans.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=GUhTfK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=GUhTfK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=pwQX0K"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=pwQX0K" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 04 Aug 2008 02:19:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/tighter security">tighter security</category>
      <category domain="http://securityratty.com/tag/airplane security">airplane security</category>
      <category domain="http://securityratty.com/tag/greyhound bus">greyhound bus</category>
      <category domain="http://securityratty.com/tag/security measures">security measures</category>
      <category domain="http://securityratty.com/tag/security anymore">security anymore</category>
      <category domain="http://securityratty.com/tag/abstract crime statistics">abstract crime statistics</category>
      <category domain="http://securityratty.com/tag/travel">travel</category>
      <category domain="http://securityratty.com/tag/rare risks applies">rare risks applies</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/random_killing.html">Random Killing on a Canadian Greyhound Bus</source>
    </item>
    <item>
      <title><![CDATA[Do we need a farm system in the security industry?]]></title>
      <link>http://securityratty.com/article/9bd54e0c74e4d7f5590217159a48aeec</link>
      <guid>http://securityratty.com/article/9bd54e0c74e4d7f5590217159a48aeec</guid>
      <description><![CDATA[Just read a good article by Lisa Vaas on Computerworld titles &quot;When security staffers fail up&quot;. The article talks about some of the challenges that are faced by companies trying to provide proper...]]></description>
      <content:encoded><![CDATA[<p>Just read a <a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9104599&amp;pageNumber=4">good article by Lisa Vaas</a> on Computerworld titles "When security staffers fail up". The article talks about some of the challenges that are faced by companies trying to provide proper security. While one of the issues is "bundled badness" which I will talk about later, the bigger problem that Lisa writes about is the profile of our security administrators. It is a familiar story I am afraid. Security people don't do a good job of "humanizing" themselves. Their peers don't understand what they are trying to accomplish and too often we speak in geek terms and try to dictate how people conduct business. As a result we are the "people in the way".<br><br>The next thing Lisa hits on is the obsession with certifications. Too many people think having a CISSP is the be all and end all of security. First of all, you can't hire enough of them and many of them don't have the practical business experience to take it to the next level. Than there is the security "prima donna". They just think they are smarter than everyone else and too many tasks are below them as to elementary. We have all met these types before as well. <br><br>Quickly on the "bundled badness" thing. Lisa rightfully points out that in spite of Mike Rothman's feelings to the contrary, though CIO and CFO types like to buy the bundle and get the jack of all trades suite cheaper than buying best of breeds individually, at the end of the day it is hurting our security. If you are really serious about securing the environment there is a world of difference between buying the bundle of goodness versus best in class tools.<br><br>Ultimately though, what are we to do about getting better security pros in the workplace? Do we need to change the certification process? Should companies have a different profile of who they hire for security positions. Do we need to develop some sort of farm system where security pros can cut their teeth and learn their craft, like the guilds and apprentices of yesteryear? The construction industry used to work like that. Maybe we should consider it too?</p>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=bEHJbL"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=bEHJbL" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=mx99tJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=mx99tJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=e6dpaJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=e6dpaJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=YwE32J"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=YwE32J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=Io9IaJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=Io9IaJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=qFI7Kj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=qFI7Kj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=TYeLwj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=TYeLwj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/341925149" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 12:17:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security administrators">security administrators</category>
      <category domain="http://securityratty.com/tag/security staffers fail">security staffers fail</category>
      <category domain="http://securityratty.com/tag/security positions">security positions</category>
      <category domain="http://securityratty.com/tag/security people">security people</category>
      <category domain="http://securityratty.com/tag/security pros">security pros</category>
      <category domain="http://securityratty.com/tag/lisa hits">lisa hits</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/lisa">lisa</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/341925149/do-we-need-a-fa.html">Do we need a farm system in the security industry?</source>
    </item>
    <item>
      <title><![CDATA[IT Operations Management Audience Polls at the Gartner Conference]]></title>
      <link>http://securityratty.com/article/ed3926a9edd61b10b292d826e31778ec</link>
      <guid>http://securityratty.com/article/ed3926a9edd61b10b292d826e31778ec</guid>
      <description><![CDATA[Greetings from the Gartner IT Infrastucture, Operations &amp; Management Summit 2008 in warm and humid Florida
A couple of notes from the first days keynote address IT Operations Management Scenarios:...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="130" alt="Gartner IOM" src="http://blog.sciencelogic.com/wp-content/uploads/2008/06/gartner-iom.jpg" width="231" align="left" border="0"> Greetings from the <a href="http://www.gartner.com/it/page.jsp?id=603107" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.gartner.com');" target="_blank">Gartner IT Infrastucture, Operations &amp; Management Summit 2008</a> – in warm and humid Florida!
<p>A couple of notes from the first day&#8217;s&nbsp; keynote address <strong>“IT Operations Management Scenarios: Trends, Directions and Market Landscape”</strong> by <a href="http://agendabuilder.gartner.com/str24/WebPages/SessionList.aspx?Speaker=56" onclick="javascript:pageTracker._trackPageview('/outbound/article/agendabuilder.gartner.com');" target="_blank">Donna Scott – VP and Distinguished Analyst at Gartner Research</a>.
<p><strong>Donna:</strong> Today customers are looking for 100% availability for their externally facing business systems. Five 9’s are no longer enough. They expect IT to deliver the right services at the right cost with the right service levels.
<p><strong>My aside:</strong> How many of you are like me? When I listen to analysts or read the research, part of me is always asking – how applicable is this to me now? How rooted is what they are saying in the practical day-to-day operations that our customers need help with now? Well, how short-sighted of me.
<p><strong>Donna: </strong>“Best-in-class organizations manage through the day-to-day turbulence of change but also keep an eye on the long-term nirvana of IT operations management.” And that creating a continuous optimization culture is necessary to improve over time – this needs to be baked into the corporate IT culture. Food for thought for all of us.
<p>Interesting quick polls of the audience – some results were surprising; some were funny; and some were validating.
<p><strong>I. What are the Top 3 pressures on IT Infrastructure and Operations Management:</strong>
<p>1) 24 x7 availability: 82%
<p>2) Business continuity and disaster recovery: 70%
<p>3) Cost reduction and/or cost management: 67%
<p><em>On a personal note – supporting/deploying SOA came in at the bottom of this poll. Enough said.</em>
<p><strong>II. What grade would you give the IT Infrastructure and Operations Management vendors?</strong>
<p>A 1%
<p>B 14%
<p>C 49%
<p>D 17%
<p>F 4%
<p><em>Last year – the average grade ended up being C- so the grade went up slightly this year.</em>
<p><strong>III. What IT Infrastructure and Operations Management vendor are you most confident in to help achieve “ERP for IT”?</strong><em> (Dave will cover this topic later this week.)</em>
<p>HP 20%
<p>IBM 16%
<p>BMC 16%
<p>CA 4% (lingering bad rep?)
<p>Microsoft 8%
<p>Oracle 4%
<p>EMC 4%
<p>Other 5%
<p>And the winner was “NONE OF THE ABOVE” with 23% of the responses. </p>
<p><a href="http://sharethis.com/item?&wp=2.5.1&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=IT+Operations+Management+%26ndash%3B+Audience+Polls+at+the+Gartner+Conference&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fit-operations-management-audience-polls-at-the-gartner-conference%2F06%2F2008" onclick="javascript:pageTracker._trackPageview('/outbound/article/sharethis.com');">ShareThis</a></p>]]></content:encoded>
      <pubDate>Mon, 23 Jun 2008 11:09:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/operations">operations</category>
      <category domain="http://securityratty.com/tag/operations management">operations management</category>
      <category domain="http://securityratty.com/tag/operations management vendors">operations management vendors</category>
      <category domain="http://securityratty.com/tag/operations management scenarios">operations management scenarios</category>
      <category domain="http://securityratty.com/tag/operations management vendor">operations management vendor</category>
      <category domain="http://securityratty.com/tag/gartner">gartner</category>
      <category domain="http://securityratty.com/tag/donna">donna</category>
      <category domain="http://securityratty.com/tag/practical day-to-day operations">practical day-to-day operations</category>
      <category domain="http://securityratty.com/tag/gartner research">gartner research</category>
      <source url="http://blog.sciencelogic.com/it-operations-management-audience-polls-at-the-gartner-conference/06/2008">IT Operations Management Audience Polls at the Gartner Conference</source>
    </item>
  </channel>
</rss>
