<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: grows]]></title>
    <link>http://securityratty.com/tag/grows</link>
    <description></description>
    <pubDate>Tue, 13 May 2008 06:21:54 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Show 029 - An Interview with Dennis Fisher]]></title>
      <link>http://securityratty.com/article/ed23afa251e7ed42c51726c5d78957a6</link>
      <guid>http://securityratty.com/article/ed23afa251e7ed42c51726c5d78957a6</guid>
      <description><![CDATA[On the 29th episode of The Silver Bullet Security Podcast, Gary talks with Dennis Fisher, executive editor of The Security Media Group at TechTarget. Dennis helps run SearchSecurity.com and...]]></description>
      <content:encoded><![CDATA[<p><img align="right" alt="Dennis Fisher" title="Dennis Fisher" src="http://www.cigital.com/silverbullet/dfisher-108.png" style="padding-left: 7px;" /></p>
<p>On the 29th episode of The Silver Bullet Security Podcast, Gary talks with Dennis Fisher, executive editor of The Security Media Group at TechTarget.  Dennis helps run SearchSecurity.com and <em>Information Security Magazine</em>.  Gary and Dennis discuss the current &#8220;BS factor&#8221; in security journalism, shopping at TJ Maxx right after the TJX privacy breach, the state of software security, and which is harder: being a fry cook at Hardees or working as a PR flack.</p>
<ul>
<li><a href="http://security.blogs.techtarget.com/author/security/">Dennis&#8217; blog</a></li>
<li><a href="http://searchsecurity.techtarget.com/news/column/0,294698,sid14_gci1239802,00.html">TJX</a></li>
<li><a href="http://music.aol.com/video/dirty-laundry/the-eagles/tag/joe-walsh/1354381">Joe Walsh plays dirty laundry</a></li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1237978">Software Security Grows</a></li>
<li><a href="http://securitywireweekly.blogs.techtarget.com/2008/07/31/the-state-of-software-security">Dennis&#8217; un-named podcast</a></li>
<li><a href="http://www.youtube.com/watch?v=f99PcP0aFNE">Series of Tubes</a></li>
<li><a href="http://www.hardees.com/">Hardees</a></li>
<li><a href="http://www.cs.washington.edu/research/systems/privacy.htm">Nike/iPod</a></li>
</ul>
]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 11:05:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dennis">dennis</category>
      <category domain="http://securityratty.com/tag/dennis fisher">dennis fisher</category>
      <category domain="http://securityratty.com/tag/dennis discuss">dennis discuss</category>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <category domain="http://securityratty.com/tag/software security grows">software security grows</category>
      <category domain="http://securityratty.com/tag/dennis helps">dennis helps</category>
      <category domain="http://securityratty.com/tag/tjx privacy breach">tjx privacy breach</category>
      <category domain="http://securityratty.com/tag/tjx">tjx</category>
      <category domain="http://securityratty.com/tag/gary talks">gary talks</category>
      <source url="http://www.cigital.com/silverbullet/show-029/">Show 029 - An Interview with Dennis Fisher</source>
    </item>
    <item>
      <title><![CDATA["Walking" with the SDL - Part 3]]></title>
      <link>http://securityratty.com/article/32d81dd05e4ad116720be1d3cc3ea0bd</link>
      <guid>http://securityratty.com/article/32d81dd05e4ad116720be1d3cc3ea0bd</guid>
      <description><![CDATA[Jeremy Dallman here. This is Part Three in my multi-part series on Walking with the Security Development Lifecycle (SDL) [ Part 1 , Part 2 ]. So far I have discussed getting management approval and...]]></description>
      <content:encoded><![CDATA[<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3 face=Calibri>Jeremy Dallman here. This is Part Three in my multi-part series on “Walking” with the Security Development Lifecycle (SDL) [</FONT><A href="http://blogs.msdn.com/sdl/archive/2008/07/18/walking-with-the-sdl-part-1.aspx"><FONT size=3 face=Calibri>Part 1</FONT></A><FONT size=3 face=Calibri>, </FONT><A href="http://blogs.msdn.com/sdl/archive/2008/07/21/walking-with-the-sdl-part-2.aspx"><FONT size=3 face=Calibri>Part 2</FONT></A><FONT size=3><FONT face=Calibri>]. So far I have discussed getting management approval and expanding security training. In this post I will discuss formalizing requirements and effective ways to reuse your threat model and attack surface review data. I’ll wrap up with a look into final security reviews and managing post-release documentation.<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p></o:p></FONT></FONT></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><B style="mso-bidi-font-weight: normal"><FONT size=3><FONT face=Calibri>Formalize Requirements for long-term use<o:p></o:p></FONT></FONT></B></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3><FONT face=Calibri>Now that you are making security development a lifecycle, it is time to lock down and formalize your security requirements. At this point, you need to take what you’ve learned and begin translating your security principles into something that can apply to multiple releases and multiple levels of your development process. <o:p></o:p></FONT></FONT></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3><FONT face=Calibri>At a product level, you need to use the security rules created in prior projects to define long-term security requirements. Those requirements will become your core security policies. <SPAN style="mso-spacerun: yes">&nbsp;</SPAN>Then, at the version level, you should create security requirements that are version-specific and are defined by the security objectives and features you want to address in that version. <o:p></o:p></FONT></FONT></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3><FONT face=Calibri>Both of these sets of requirements can be formalized in a way that makes them easier to transfer across future product cycles and to modify based on the unique features or security issues of each version.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Making these a staple of your development lifecycle will also ease adoption of these requirements as team become familiar with them over multiple releases.<o:p></o:p></FONT></FONT></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3><FONT face=Calibri>I would like to touch on one topic before moving on – enforcing requirements. As your team grows and your SDL matures, there is an inherent complexity that comes with managing and enforcing your requirements. In our experience, we’ve found that it is critical to identify a security advisor. Up until now, your company has probably had someone championing security and best practices – either as a formal role or simply as a informal advocate. However, making it a feature of your lifecycle requires dedicated effort to enforce and sustain the requirements as well as monitoring the security ecosystem for changes that may add requirements to your process. The security advisor(s) are the people who will help guide the creation of the security requirements both broadly and for each product cycle; for a smaller team, this may be a single individual. For a larger organization, a team of people may be needed. The security advisor should also evaluate your security policy and apply changes where needed, ensure the product bug database is tracking security issues that can be reviewed later (I’ll get to the Final Security Review in our next post), and guide the definition and enforcement of a security “bug bar”. <o:p></o:p></FONT></FONT></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3><FONT face=Calibri>Security requirements serve as the backbone of your SDL. The amount of effort you put in defining and enforcing requirements, and keeping them up to date with the current threat landscape will have a direct return on investment in the security and privacy of the product you create. Be careful to document and clearly communicate your requirements to your team, and use them as evidence when talking to your customers about how you ensure the security and privacy of your product. <o:p></o:p></FONT></FONT></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><B style="mso-bidi-font-weight: normal"><FONT size=3><FONT face=Calibri>Reference &amp; Reuse Threat Modeling results &amp; Attack Surface Reviews<o:p></o:p></FONT></FONT></B></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3><FONT face=Calibri>Your developers and testers should have access to and be familiar with the attack surface analysis or threat model documents you have created. These documents are invaluable reference tools. Use them to perform evaluate your security from multiple angles: <o:p></o:p></FONT></FONT></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 37.5pt; mso-list: l0 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpFirst><SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore"><FONT size=3>·</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><FONT size=3><FONT face=Calibri>Think about component-level architecture <o:p></o:p></FONT></FONT></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 37.5pt; mso-list: l0 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpMiddle><SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore"><FONT size=3>·</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><FONT size=3><FONT face=Calibri>List common pitfalls in writing code, or begin defining and building test cases. <o:p></o:p></FONT></FONT></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 37.5pt; mso-list: l0 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpMiddle><SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore"><FONT size=3>·</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><FONT size=3><FONT face=Calibri>Code reviewers can reference threat models and attack surface documents to verify specific attacks were addressed in the code. <o:p></o:p></FONT></FONT></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 37.5pt; mso-list: l0 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpMiddle><SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore"><FONT size=3>·</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><FONT size=3><FONT face=Calibri>Architects can use them to identify new areas of potential attack surface based on how new code is written or interacts with existing code. <o:p></o:p></FONT></FONT></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 37.5pt; mso-list: l0 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpLast><SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore"><FONT size=3>·</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><FONT size=3><FONT face=Calibri>Project leadership can reference threat models or attack surface documents to ensure the completed project meets all security goals.<o:p></o:p></FONT></FONT></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3><FONT face=Calibri>Building a “live” library of threat models that is accessible by everyone and is designed to be easily maintained or updated is a big undertaking. Based on experience, I would strongly encourage doing this early in the evolution of your security lifecycle to avoid losing valuable data and to prevent the sheer volume of data from becoming unusable. I have heard of some companies using wiki technology as their library for threat modeling while others may use searchable documents, spreadsheets, or websites to store/sort/share the information. Whatever method you use, it is important to anticipate the accumulation of a large set of information that should be easily used and shared across the organization.<o:p></o:p></FONT></FONT></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3 face=Calibri>I would like to do a deeper dive on the importance of security code reviews as part of your “walk” evolution. Security code reviews focus on identifying insecure coding techniques and vulnerabilities that could lead to security issues. The goal of a review is to identify as many potential security vulnerabilities as possible before the code is deployed. The cost and effort of fixing security flaws at development time is far less than fixing them later in the product deployment cycle [from </FONT><A href="http://msdn.microsoft.com/en-us/library/aa302437.aspx"><FONT size=3 face=Calibri>Improving Web Application Security</FONT></A><FONT size=3><FONT face=Calibri>]. You should create a process where top security developers actively review code within the context of known threats prior to deploying your code. Leveraging the existing documentation about feature design is a vital reference piece to make those security reviews successful.<o:p></o:p></FONT></FONT></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3><FONT face=Calibri>Later this week, I’ll close the series with a look at final security reviews (FSRs) and how to document your work for post-release and next-release reference. <o:p></o:p></FONT></FONT></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><FONT size=3><FONT face=Calibri>In the meantime, we’d like to hear from you:<o:p></o:p></FONT></FONT></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoNoSpacing><SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore"><FONT size=3>?</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><FONT size=3><FONT face=Calibri>How do you express your security requirements? Do you use a checklist, a whitepaper, or something else?<o:p></o:p></FONT></FONT></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoNoSpacing><SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore"><FONT size=3>?</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><FONT size=3><FONT face=Calibri>What challenges have you faced in enforcing requirements across your teams? <o:p></o:p></FONT></FONT></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoNoSpacing><SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore"><FONT size=3>?</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><FONT size=3><FONT face=Calibri>How have you implemented threat models or attack surface reviews? <o:p></o:p></FONT></FONT></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=8767328" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 23 Jul 2008 12:43:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security requirements serve">security requirements serve</category>
      <category domain="http://securityratty.com/tag/security requirements">security requirements</category>
      <category domain="http://securityratty.com/tag/security development lifecycle">security development lifecycle</category>
      <category domain="http://securityratty.com/tag/security development">security development</category>
      <category domain="http://securityratty.com/tag/requirements">requirements</category>
      <category domain="http://securityratty.com/tag/lifecycle">lifecycle</category>
      <category domain="http://securityratty.com/tag/security lifecycle">security lifecycle</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security ecosystem">security ecosystem</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/07/23/walking-with-the-sdl-part-3.aspx">"Walking" with the SDL - Part 3</source>
    </item>
    <item>
      <title><![CDATA[Learning GovieSpeak: The Plum Book]]></title>
      <link>http://securityratty.com/article/00ebddb106bd9d06b0ced5791155ab3c</link>
      <guid>http://securityratty.com/article/00ebddb106bd9d06b0ced5791155ab3c</guid>
      <description><![CDATA[You were thinking this was part of the rainbow series, along with the orange book, the red book, and the fuchsia book, werent you
Well, no, security dweebs, were on a public policy kick, probably will...]]></description>
      <content:encoded><![CDATA[<p>You were thinking this was part of the rainbow series, along with the orange book, the red book, and the fuchsia book, weren&#8217;t you?</p>
<p>Well, no, security dweebs, we&#8217;re on a public policy kick, probably will be until the end of the year (more on that to follow, stay tuned), so you wouldn&#8217;t be so lucky.</p>
<p>The Plum Book&#8217;s official title is Government Policy and Supporting Positions and basically it&#8217;s a huge staffing chart for the Senior Executive Service&#8211;the political appointees.  Congress publishes the Plum Book after each presidential election, so for those of us who remember our civics lessons in high school, that would be every 4 years, and the last one was published in 2004.</p>
<p>In fact, you can see the <a href="http://www.gpoaccess.gov/plumbook/2004/index.html" target="_blank">last edition here</a>.  Caveat:  it&#8217;s dry, like the uber-trocken Franken white wine that grows in the fields around where I used to live in Germany&#8211;so dry that it sucks the moisture right out of you.</p>
<p style="text-align: center;"><em><img src="http://farm1.static.flickr.com/78/168193936_5653574f7c.jpg?v=0" alt="Plum Pickin" width="500" height="329" /></em></p>
<p style="text-align: center;"><em>Plum Pickin photo by <a href="http://www.flickr.com/photos/tenerife/" target="_blank">Secret Tenerife</a></em></p>
<p>Now why do we care about the Plum Book?  Well, that&#8217;s a good question.  Have a look at some of the staffing plans in the plum book, and you&#8217;ll see something missing:  Agency CISOs.</p>
<p>Now, I&#8217;m not a rocket scientist on org charts, but it seems to me that unless you put CISOs up to where they&#8217;re answerable to the agency head, they&#8217;re just a cost center inside the IT department with no visibility to the decision-makers.  Once again, we&#8217;ve crippled our security staffs like the old-school way of doing things.</p>
<p>On another note, taking a quick straw poll of the agency CISOs that I know, I think about half of them are political appointees, and half of them are GS-15s.  So what&#8217;s the difference?</p>
<p>Well, political appointees (SES) are appointed by the President.  They make a better target because they have much more visibility from the higher-ups they are more political in nature.</p>
<p>GS-scale employees are civil service careerists.  Usually these are the guys who have moved up the ranks in the various agencies and know quite a bit of things.</p>
<p>Which is better?  Well, if you want survivability, then GS-scale is the way to go.  If you want to make the most difference, SES is the ticket.</p>
<p>Most of us will never get the choice. =)</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/426&amp;title=Learning+GovieSpeak%3A++The+Plum+Book" title="Add 'Learning GovieSpeak:  The Plum Book' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'Learning GovieSpeak:  The Plum Book' to Del.icio.us" alt="Add 'Learning GovieSpeak:  The Plum Book' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/426&amp;title=Learning+GovieSpeak%3A++The+Plum+Book" title="Add 'Learning GovieSpeak:  The Plum Book' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'Learning GovieSpeak:  The Plum Book' to digg" alt="Add 'Learning GovieSpeak:  The Plum Book' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/426&amp;title=Learning+GovieSpeak%3A++The+Plum+Book" title="Add 'Learning GovieSpeak:  The Plum Book' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'Learning GovieSpeak:  The Plum Book' to reddit" alt="Add 'Learning GovieSpeak:  The Plum Book' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Learning+GovieSpeak%3A++The+Plum+Book&amp;url=http://www.guerilla-ciso.com/archives/426&amp;version=0.7" title="Add 'Learning GovieSpeak:  The Plum Book' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'Learning GovieSpeak:  The Plum Book' to Feed Me Links" alt="Add 'Learning GovieSpeak:  The Plum Book' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/426" title="Add 'Learning GovieSpeak:  The Plum Book' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'Learning GovieSpeak:  The Plum Book' to Technorati" alt="Add 'Learning GovieSpeak:  The Plum Book' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/426&amp;t=Learning+GovieSpeak%3A++The+Plum+Book" title="Add 'Learning GovieSpeak:  The Plum Book' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'Learning GovieSpeak:  The Plum Book' to Yahoo My Web" alt="Add 'Learning GovieSpeak:  The Plum Book' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/426&amp;title=Learning+GovieSpeak%3A++The+Plum+Book" title="Add 'Learning GovieSpeak:  The Plum Book' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'Learning GovieSpeak:  The Plum Book' to Stumble Upon" alt="Add 'Learning GovieSpeak:  The Plum Book' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/426&amp;title=Learning+GovieSpeak%3A++The+Plum+Book" title="Add 'Learning GovieSpeak:  The Plum Book' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'Learning GovieSpeak:  The Plum Book' to Google Bookmarks" alt="Add 'Learning GovieSpeak:  The Plum Book' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/426" title="Add 'Learning GovieSpeak:  The Plum Book' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'Learning GovieSpeak:  The Plum Book' to Squidoo" alt="Add 'Learning GovieSpeak:  The Plum Book' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/426" title="Add 'Learning GovieSpeak:  The Plum Book' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'Learning GovieSpeak:  The Plum Book' to Bloglines" alt="Add 'Learning GovieSpeak:  The Plum Book' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=crtENJ"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=crtENJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=LCQUPj"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=LCQUPj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/338011282" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 17 Jul 2008 08:53:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/plum book">plum book</category>
      <category domain="http://securityratty.com/tag/agency cisos">agency cisos</category>
      <category domain="http://securityratty.com/tag/political">political</category>
      <category domain="http://securityratty.com/tag/political appointees">political appointees</category>
      <category domain="http://securityratty.com/tag/cisos">cisos</category>
      <category domain="http://securityratty.com/tag/cost center inside">cost center inside</category>
      <category domain="http://securityratty.com/tag/public policy kick">public policy kick</category>
      <category domain="http://securityratty.com/tag/gs-scale">gs-scale</category>
      <category domain="http://securityratty.com/tag/germanyso dry">germanyso dry</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/338011282/426">Learning GovieSpeak: The Plum Book</source>
    </item>
    <item>
      <title><![CDATA[Taming of the Information Security]]></title>
      <link>http://securityratty.com/article/d22f10755f4bc01c24a23a86362200d0</link>
      <guid>http://securityratty.com/article/d22f10755f4bc01c24a23a86362200d0</guid>
      <description><![CDATA[In many mid-size to large organizations, information security grows up to become an unmanageable complex beast. In some cases, this happens consciously where information security goes out of control,...]]></description>
      <content:encoded><![CDATA[<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face="Times New Roman,Times,serif"><FONT size=3><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">In many mid-size to large organizations, information security grows up to become an unmanageable complex beast.&nbsp; </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">In some cases, this happens consciously where information security goes out of control, but in other cases this&nbsp;</SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">happens unconsciously where there is a slow but incremental increase in the complexity of information security </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">which leads to chaos. </SPAN></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond"><?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p><FONT face="Times New Roman,Times,serif" size=3>&nbsp;</FONT></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face="Times New Roman,Times,serif"><FONT size=3><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">The information security field is not yet fully mature; there is a lack of cohesive interoperable framework.<SPAN style="mso-spacerun: yes">&nbsp;&nbsp; </SPAN></SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">The rapidly evolving landscape adds to the existing problem. There are several examples: Intrusion Detection System </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">(IDS) was quickly overtaken by Intrusion Prevention System (IPS).<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>On the Firewall arena: the focus has moved </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">from perimeter security to end point security.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>There are some security visionaries who are preaching inside-out </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">security approach i.e. building products with information security in mind from the beginning. </SPAN></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face="Times New Roman,Times,serif"><FONT size=3><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">Threats are </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">moving higher up in the OSI stack making it harder to detect. Hackers are becoming more sophisticated – there </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">are powerful free open source hacking tools available at their disposal. </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">Security managers driving security initiatives without co-ordination can result in pieces of puzzle that don't </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">fit well. Agency problem i.e. security managers thinking more about their personal advancement rather than security </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">of the company is bad for the company’s security initiative. Security leaders who do not have a clear vision of </SPAN></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face="Times New Roman,Times,serif"><FONT size=3><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">security at the component level, the administration level and the strategy level can only make information </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">security even more convoluted. The CISO and acting CIO of US Dept of Veteran affairs resigned after the breach</SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond"><SPAN style="mso-spacerun: yes">&nbsp;</SPAN>in May, 2006 where personal data of 26 million veterans and more than 2 million service members was stolen. </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">This clearly demonstrates the accountability and visibility of security leadership.</SPAN></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond"><o:p><FONT face="Times New Roman,Times,serif" size=3>&nbsp;</FONT></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face="Times New Roman,Times,serif"><FONT size=3><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">The attitude of IT security leaders and security team members has a significant impact on security.<SPAN style="mso-spacerun: yes">&nbsp;&nbsp;Reckless buying of information security technology can result in wasteful expenditure&nbsp;and very little gain in efficiency</SPAN></SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">. Not understanding </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">the business perspective of security issues or security perspective of business issues can lead to poor security </SPAN></FONT></FONT><FONT face="Times New Roman,Times,serif"><FONT size=3><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">decisions. Using security as a mechanism to gain control rather than using it as a tool to reduce risk can only&nbsp;</SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">diminish the perceived value of security initiative. Implementing security as an afterthought rather than building </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">it into the framework not only result in poor architectural decision. Security investment is more like buying insurance.&nbsp;</SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">Thinking security as a vehicle providing an ROI can result in wrong expectation and lead poor decision. The business i</SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">n which a company operates contributes largely to the perceived importance to security. Financial institutions </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">usually have a higher bar on security because of the very nature of their business and their exposure legal liability. </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">It is a good idea for many technology companies to emulate&nbsp;financial institutions to raise their information security bar</SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">.</SPAN></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond"><o:p><FONT face="Times New Roman,Times,serif" size=3>&nbsp;</FONT></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face="Times New Roman,Times,serif"><FONT size=3><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">It could be a pipedream to accomplish complete<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>information security but accomplishing a well managed information </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">security program is an attainable possibility.</SPAN></FONT></FONT></P><PRE>&nbsp;</PRE>]]></content:encoded>
      <pubDate>Wed, 09 Jul 2008 02:33:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/information security field">information security field</category>
      <category domain="http://securityratty.com/tag/information security bar">information security bar</category>
      <category domain="http://securityratty.com/tag/information security program">information security program</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/information security technology">information security technology</category>
      <category domain="http://securityratty.com/tag/poor security decisions">poor security decisions</category>
      <category domain="http://securityratty.com/tag/information security grows">information security grows</category>
      <category domain="http://securityratty.com/tag/companys security initiative">companys security initiative</category>
      <source url="http://ravichar.blogharbor.com/blog/_archives/2008/7/9/3785025.html">Taming of the Information Security</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up - June 2008]]></title>
      <link>http://securityratty.com/article/6bb7f76a5056f7584446e3423f3defba</link>
      <guid>http://securityratty.com/article/6bb7f76a5056f7584446e3423f3defba</guid>
      <description><![CDATA[I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see...]]></description>
      <content:encoded><![CDATA[<p>I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit "stateless" and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. This is what is driving an idiotic campaign of such "news" as "hackers increase hacking", "compliance is hard/easy/matters/doesn't" or "awareness of virtualization/SaaS/hacking/compliance grows."</p> <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">"Security Warrior" blog</a> </strong>round-up of top 5 popular posts and topics.</p> <ol> <li>Again this month, <a href="http://chuvakin.blogspot.com/search/label/poll">my logging polls</a> took the #1 spot!&nbsp; <a href="http://chuvakin.blogspot.com/2008/05/poll-8-log-analysis-context.html">Poll #8</a> that covered context data for log analysis <a href="http://chuvakin.blogspot.com/2008/06/logging-poll-8-analysis-needed-log.html">is analyzed here</a>. Other popular polls include a controversial <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">Windows Log Collection Poll</a></u> (which is <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">a poll #7</a></u>)&nbsp; and <u><a href="http://chuvakin.blogspot.com/2008/03/logging-poll-6-logs-do-you-look-at.html">poll #6</a></u> about logs that people actually look and <a href="http://chuvakin.blogspot.com/2008/02/logging-poll-5-logging-challenges.html">poll #5</a> about logging challenges. Next poll is coming soon. <li>Not entirely surprising, my post/rant called "<a href="http://chuvakin.blogspot.com/2008/06/you-are-security-idiot-if.html">You Are "A Security Idiot" If ...</a>" takes the #2 spot after being live for only a few days. Yes, we all like to point out other people's problems, especially when they are epically huge :-) <li>Also not surprisingly, my post "<a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or "Raffy, You Killed SIM!"</a>" is on the Top list. It is both humorous and sadly true (and <a href="http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/export/home/httpd/htdocs/reviews/2008/063008-test-siem.html&amp;pagename=/reviews/2008/063008-test-siem.html&amp;pageurl=http://www.networkworld.com/reviews/2008/063008-test-siem.html&amp;site=security">backed up by other sources</a>) <li>A curious subject of DLP or "data leak prevention" (specifically, the post called "<a href="http://chuvakin.blogspot.com/2008/06/so-can-we-have-dlp.html">So, CAN We Have DLP?</a>") also tops the charts. My previous post on data leak 'prevention' ("<a href="http://chuvakin.blogspot.com/2008/05/in-passing-on-dlp.html">In Passing on DLP</a>") is popular as well. <li>Again and again, people googling for "open source SIEM" have pushed this post (<a href="http://chuvakin.blogspot.com/2007/01/on-open-source-in-siem-and-log.html">this tiny old pathetic blurb</a>) to top5. This ancient post from years ago explains why an open source <a href="http://chuvakin.blogspot.com/search/label/SIEM">SIEM</a> will NOT emerge soon, if ever. </li></ol> <p>See you in July!</p> <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p> <ul> <li><a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a>  <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a></li></ul> <p>&nbsp;</p> <p></p> <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7192e29b-e335-4630-8b0b-dc37806d54ee" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>, <a href="http://technorati.com/tags/security" rel="tag">security</a>, <a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>, <a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=vJkYeJ"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=vJkYeJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=jCmSaJ"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=jCmSaJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=U2B0xJ"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=U2B0xJ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/324237184" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 07:10:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/posts">posts</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/ancient post">ancient post</category>
      <category domain="http://securityratty.com/tag/popular posts">popular posts</category>
      <category domain="http://securityratty.com/tag/popular">popular</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/324237184/monthly-blog-round-up-june-2008.html">Monthly Blog Round-Up - June 2008</source>
    </item>
    <item>
      <title><![CDATA[Googles Culture of Yes]]></title>
      <link>http://securityratty.com/article/e615947c2baeb07b85af246f8d822bd5</link>
      <guid>http://securityratty.com/article/e615947c2baeb07b85af246f8d822bd5</guid>
      <description><![CDATA[Recently, Eric Schmidt gave quite an inspirational speech at the Economic Club of Washington . It was so interesting; I wanted to share this with you in case you missed it. The entire speech is rather...]]></description>
      <content:encoded><![CDATA[<p>Recently, Eric Schmidt gave quite an inspirational speech at the <a href="http://www.economicclub.org/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.economicclub.org');" target="_blank">Economic Club of Washington</a>.  It was so interesting; I wanted to share this with you in case you missed it. The entire speech is rather long but here’s the <a href="http://fora.tv/2008/06/09/Eric_Schmidt_Explains_Google_s_Culture_of_Yes" onclick="javascript:pageTracker._trackPageview('/outbound/article/fora.tv');" target="_blank">section on Google’s Culture of Yes</a>.</p>
<p>After hearing his speech, I thought about how Eric and Google are impacting the digital revolution after so many others have tried unsuccessfully over the last 25 years. He has led the company through a period of explosive growth from $1 Billion to over $16 Billion in the past year, while keeping the young, fun, irreverent culture intact. Considering the meteoric rise of Google’s popularity in a reasonably short period of time, to the point that the company name is now actually a verb!</p>
<p>The point that I found enlightening was his summary, which you can scroll to at the 26 - 30 minutes timeframe in the presentation, where he shared an interesting glimpse into the culture of Google. “Creating more luck, giving yourself more at bats, being out there… to think big and inspire a culture of YES.” The culture of Yes inspires people to aim higher and be ambitious in their reach and goals.</p>
<p>That is a very interesting point in which I really believe. If there is one thing that all companies and especially small companies struggle with because of natural resource constraints, it is building a strong culture of Yes. We have tried to do this from the very inception of ScienceLogic, but it continues to get harder and harder the larger the business grows. To consistently inspire a principle of Yes, without agreeing to every idea that flows across my desk is amongst the most challenging parts of our daily jobs. However if I could create the perfect scenario, we would intuitively strive for a principle of Yes and inspire our associates and our ecosystem of partners and customers to use this simple concept to confidently go forward.</p>
<p>Eric says, “It is possible to build a culture around innovation. It is possible to build a culture around leadership, and it is possible to build a culture around optimism.” Google is a great example, but by no means the only example. I agree with Eric’s summary and hope to lead ScienceLogic according to these very basic but essential principles. “Let’s be revolutionaries. Let’s take this opportunity, this huge change that is before us with technology and let’s change our businesses, our communication and the way we interact on some new principles that reflect the very best in America.”</p>
<p><a href="http://sharethis.com/item?&wp=2.5.1&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Google%26%238217%3Bs+Culture+of+Yes&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fgoogles-culture-of-yes%2F06%2F2008" onclick="javascript:pageTracker._trackPageview('/outbound/article/sharethis.com');">ShareThis</a></p>]]></content:encoded>
      <pubDate>Mon, 23 Jun 2008 11:21:46 +0000</pubDate>
      <category domain="http://securityratty.com/tag/culture">culture</category>
      <category domain="http://securityratty.com/tag/googles culture">googles culture</category>
      <category domain="http://securityratty.com/tag/strong culture">strong culture</category>
      <category domain="http://securityratty.com/tag/irreverent culture intact">irreverent culture intact</category>
      <category domain="http://securityratty.com/tag/inspirational speech">inspirational speech</category>
      <category domain="http://securityratty.com/tag/speech">speech</category>
      <category domain="http://securityratty.com/tag/inspire">inspire</category>
      <category domain="http://securityratty.com/tag/consistently inspire">consistently inspire</category>
      <category domain="http://securityratty.com/tag/eric">eric</category>
      <source url="http://blog.sciencelogic.com/googles-culture-of-yes/06/2008">Googles Culture of Yes</source>
    </item>
    <item>
      <title><![CDATA[Real ID, Real Problem]]></title>
      <link>http://securityratty.com/article/593bf18a6ee5711794b59015b60b5a25</link>
      <guid>http://securityratty.com/article/593bf18a6ee5711794b59015b60b5a25</guid>
      <description><![CDATA[The Real ID program is proving to be a veritable sumo match of epic proportions. The calls are going out to kill it before it grows
From the Baltimore Sun
No. Nope. No way
So exclaimed Democratic Gov....]]></description>
      <content:encoded><![CDATA[<p><center><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2008/06/matrix-tracer.jpg" /></center></p>
<p>The Real ID program is proving to be a veritable sumo match of epic proportions. The calls are going out to kill it before it grows.</p>
<p>From the Baltimore Sun:</p>
<blockquote><p>&#8220;No. Nope. No way.&#8221;</p>
<p>So exclaimed Democratic Gov. Brian Schweitzer of Montana when asked whether his state would participate in the federal Real ID program.</p>
<p>Frustration with this misguided, expensive and unworkable federal mandate also compelled another governor, Republican Mark Sanford of South Carolina, to call Real ID &#8220;the worst piece of legislation I have seen during the 15 years I have been engaged in the political process.&#8221; If Real ID has any friends in the states, they&#8217;re not speaking up.</p>
<p>This sentiment is now percolating through the halls of Congress. In recent hearings before the U.S. Senate Homeland Security and Governmental Affairs Committee, senators from both sides of the aisle were blistering in their criticism of Real ID.</p></blockquote>
<p>Read on.</p>
<p><a href="http://www.baltimoresun.com/news/opinion/oped/bal-op.id17jun17,0,2050136.story">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=iNLg6M"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=iNLg6M" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=oVRm9I"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=oVRm9I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=ulHI0i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=ulHI0i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=FExg4i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=FExg4i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=wCG3Ci"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=wCG3Ci" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=RPFFLi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=RPFFLi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/313725471" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 17 Jun 2008 07:19:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/real">real</category>
      <category domain="http://securityratty.com/tag/federal real">federal real</category>
      <category domain="http://securityratty.com/tag/call real">call real</category>
      <category domain="http://securityratty.com/tag/republican mark sanford">republican mark sanford</category>
      <category domain="http://securityratty.com/tag/governmental affairs committee">governmental affairs committee</category>
      <category domain="http://securityratty.com/tag/veritable sumo match">veritable sumo match</category>
      <category domain="http://securityratty.com/tag/homeland security">homeland security</category>
      <category domain="http://securityratty.com/tag/article link">article link</category>
      <category domain="http://securityratty.com/tag/program">program</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/313725471/">Real ID, Real Problem</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up - May 2008]]></title>
      <link>http://securityratty.com/article/7dbe2b9e432e7c2dd0077f7a580d13a9</link>
      <guid>http://securityratty.com/article/7dbe2b9e432e7c2dd0077f7a580d13a9</guid>
      <description><![CDATA[I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see...]]></description>
      <content:encoded><![CDATA[<p>I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit "stateless" and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. This is what is driving an idiotic campaign of such "news" as "hackers increase hacking", "compliance is hard" or "awareness of virtualization grows."</p> <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">"Security Warrior" blog</a> </strong>round-up of top 5 popular posts and topics.</p> <ol> <li>First time this month, <a href="http://chuvakin.blogspot.com/search/label/poll">my logging polls</a> took #1 spot!&nbsp; Specifically, a controversial <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">Windows Log Collection Poll</a></u> (which is <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">a poll #7</a></u>) sits highest among the Top5 posts (closely behind are <u><a href="http://chuvakin.blogspot.com/2008/03/logging-poll-6-logs-do-you-look-at.html">poll #6</a></u> about logs that people actually look at as well as <a href="http://chuvakin.blogspot.com/2008/02/logging-poll-5-logging-challenges.html">poll #5</a> about logging challenges). <a href="http://chuvakin.blogspot.com/2008/05/poll-8-log-analysis-context.html">Poll #8 analysis</a> is coming up tomorrow, BTW... <li>As expected, the post called "<a href="http://chuvakin.blogspot.com/2008/05/reverse-compliance-or-as-proof-of.html">Reverse Compliance or "Logs as Proof of Incompetence?"</a>" tops the charts as well. It is about, <strong>"r</strong>everse compliance", which is a motivation to <em>purposefully</em> avoid technologies that have a chance of telling you that you are NOT in compliance. <li>My quick post on data leak 'prevention' ("<a href="http://chuvakin.blogspot.com/2008/05/in-passing-on-dlp.html">In Passing on DLP</a>") is popular as well. Indeed, DLP is a very interesting segment of security market and there is plenty of innovation happening there. <li>ISO17799/27002 might not be hot in the US, but discussing why it is not IS indeed hot. WTH? Well, <a href="http://chuvakin.blogspot.com/2008/05/why-is-iso2700x-hot-in-uk-but-not-in-us.html">"Why Is ISO2700x Hot in UK, but Not in US?"</a> is in Top5. <li>Again, people googling for "open source SIEM" have pushed this post (<a href="http://chuvakin.blogspot.com/2007/01/on-open-source-in-siem-and-log.html">this tiny blurb</a>) to top5. This ancient post from 2 years ago (!) years ago explains why an open source <a href="http://chuvakin.blogspot.com/search/label/SIEM">SIEM</a> will NOT emerge soon, if ever. </li></ol> <p>See you in June!</p> <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p> <ul> <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&nbsp;&nbsp; <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a>  <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a></li></ul> <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:d616d4cf-aabb-415e-afd0-332828a25e0b" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>, <a href="http://technorati.com/tags/security" rel="tag">security</a>, <a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>, <a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=lMueeI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=lMueeI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=61w2QI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=61w2QI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=xCNdUI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=xCNdUI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/303434819" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 02 Jun 2008 16:54:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/posts">posts</category>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/everse compliance">everse compliance</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/ancient post">ancient post</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/303434819/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</source>
    </item>
    <item>
      <title><![CDATA[Learn by Analogy or Die Trying]]></title>
      <link>http://securityratty.com/article/72ac1e66cff28f0312035531210d2100</link>
      <guid>http://securityratty.com/article/72ac1e66cff28f0312035531210d2100</guid>
      <description><![CDATA[The security field, as we mean it here in IEEE S&amp;P, is both new and old. It is new in the spectacular sense of a positive feedback loop; everything in the computer world is itself designed by...]]></description>
      <content:encoded><![CDATA[The security field, as we mean it here in IEEE S&amp;P, is both new and old. It is new in the spectacular sense of a positive feedback loop; everything in the computer world is itself designed by computers and thus everything grows geometrically, not just chip density by way of Moore's Law. The best technology transfer is a human brain on legs. When a new field coalesces out of varied practitioners from other fields, the sum of that technology transfer reaches a maximum. Such is happening with the security field.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=e48fdb469497e1a87408dcc7ca82c820" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=e48fdb469497e1a87408dcc7ca82c820" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 22 May 2008 10:32:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/technology transfer reaches">technology transfer reaches</category>
      <category domain="http://securityratty.com/tag/technology transfer">technology transfer</category>
      <category domain="http://securityratty.com/tag/security field">security field</category>
      <category domain="http://securityratty.com/tag/positive feedback loop">positive feedback loop</category>
      <category domain="http://securityratty.com/tag/spectacular sense">spectacular sense</category>
      <category domain="http://securityratty.com/tag/chip density">chip density</category>
      <category domain="http://securityratty.com/tag/human brain">human brain</category>
      <category domain="http://securityratty.com/tag/computer world">computer world</category>
      <category domain="http://securityratty.com/tag/field coalesces">field coalesces</category>
      <source url="http://www.pheedo.com/click.phdo?i=e48fdb469497e1a87408dcc7ca82c820">Learn by Analogy or Die Trying</source>
    </item>
    <item>
      <title><![CDATA[Srizbi grows into world's largest botnet]]></title>
      <link>http://securityratty.com/article/c4ca11807483dd76c1bac66f6d961e2e</link>
      <guid>http://securityratty.com/article/c4ca11807483dd76c1bac66f6d961e2e</guid>
      <description><![CDATA[The Storm botnet hasn't completely blown over, but already there's a new big threat in town: the rampaging Srizbi botnet. (Nostalgic yet for the days when you could pronounce the name of the thing...]]></description>
      <content:encoded><![CDATA[The Storm botnet hasn't completely blown over, but already there's a new big threat in town: the rampaging Srizbi botnet. (Nostalgic yet for the days when you could pronounce the name of the thing that tormented you?) A disturbing new feature makes Sribzi especially pernicious.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=fXi2hP"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=fXi2hP" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/289301015" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 13 May 2008 06:21:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/completely blown">completely blown</category>
      <category domain="http://securityratty.com/tag/storm botnet">storm botnet</category>
      <category domain="http://securityratty.com/tag/srizbi botnet">srizbi botnet</category>
      <category domain="http://securityratty.com/tag/pronounce">pronounce</category>
      <category domain="http://securityratty.com/tag/threat">threat</category>
      <category domain="http://securityratty.com/tag/pernicious">pernicious</category>
      <category domain="http://securityratty.com/tag/town">town</category>
      <category domain="http://securityratty.com/tag/days">days</category>
      <category domain="http://securityratty.com/tag/feature">feature</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/289301015/article.do">Srizbi grows into world's largest botnet</source>
    </item>
  </channel>
</rss>
