<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: incite]]></title>
    <link>http://securityratty.com/tag/incite</link>
    <description></description>
    <pubDate>Tue, 22 Jul 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Links for 2008-10-08 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/d45a6a86a62f0327b9849ed06c8c9316</link>
      <guid>http://securityratty.com/article/d45a6a86a62f0327b9849ed06c8c9316</guid>
      <description><![CDATA[Job Security Is a Dumb Goal (And a Survey with Some Cool Prizes) | Employee Evolution
Symantec Buys MessageLabs | securosis.com
Career Advice from the POPE | Security Incite: Analysis on Information...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://www.employeeevolution.com/archives/2008/10/07/job-security-is-a-dumb-goal-and-a-survey-with-some-cool-prizes/">Job Security Is a Dumb Goal (And a Survey with Some Cool Prizes) | Employee Evolution</a></li>
<li><a href="http://securosis.com/2008/10/08/symantec-buys-messagelabs/">Symantec Buys MessageLabs | securosis.com</a></li>
<li><a href="http://securityincite.com/blog/mike-rothman/career-advice-from-the-pope">Career Advice from the POPE | Security Incite: Analysis on Information Security</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/415449483" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/symantec buys messagelabs">symantec buys messagelabs</category>
      <category domain="http://securityratty.com/tag/security incite">security incite</category>
      <category domain="http://securityratty.com/tag/career advice">career advice</category>
      <category domain="http://securityratty.com/tag/job security">job security</category>
      <category domain="http://securityratty.com/tag/dumb goal">dumb goal</category>
      <category domain="http://securityratty.com/tag/employee evolution">employee evolution</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/cool">cool</category>
      <category domain="http://securityratty.com/tag/analysis">analysis</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/415449483/anton18">Links for 2008-10-08 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[POPE Rules!]]></title>
      <link>http://securityratty.com/article/0efd3abe24c9f19a5b177dfb1c91d227</link>
      <guid>http://securityratty.com/article/0efd3abe24c9f19a5b177dfb1c91d227</guid>
      <description><![CDATA[OMFG, this sooo made my day today. Mike Rothman &quot;communicates&quot; with P.O.P.E . and produces deep, lasting, impacting insight (&quot;incite?&quot;) on career, skills, etc

My fave piece: &quot;But ultimately I fancy...]]></description>
      <content:encoded><![CDATA[OMFG, <a href="http://securityincite.com/blog/mike-rothman/career-advice-from-the-pope">this </a>sooo made my day today. Mike Rothman <a href="http://securityincite.com/blog/mike-rothman/career-advice-from-the-pope">"communicates" with P.O.P.E</a>. and produces deep, lasting, impacting insight ("incite?") on career, skills, etc.<br /><br />My fave piece: "But ultimately I fancy myself to be a builder and [his new job] gives me the opportunity to build a strong strategy and marketing function." Amen to that! Even though Mike can be a "talker" too, not only a "builder."<br /><br /><a href="http://securityincite.com/blog/mike-rothman/career-advice-from-the-pope">Read it!</a><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=g8nyM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=g8nyM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=h7slM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=h7slM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=6u8kM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=6u8kM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/415211313" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 11:09:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mike">mike</category>
      <category domain="http://securityratty.com/tag/mike rothman">mike rothman</category>
      <category domain="http://securityratty.com/tag/produces deep">produces deep</category>
      <category domain="http://securityratty.com/tag/strong strategy">strong strategy</category>
      <category domain="http://securityratty.com/tag/fave piece">fave piece</category>
      <category domain="http://securityratty.com/tag/builder">builder</category>
      <category domain="http://securityratty.com/tag/function">function</category>
      <category domain="http://securityratty.com/tag/skills">skills</category>
      <category domain="http://securityratty.com/tag/opportunity">opportunity</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/415211313/pope-rules.html">POPE Rules!</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-10-02 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/4672413537d5aeb1bb2e7df4cb958805</link>
      <guid>http://securityratty.com/article/4672413537d5aeb1bb2e7df4cb958805</guid>
      <description><![CDATA[Crazy Consolidation Will Continue | Security Incite: Analysis on Information...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://securityincite.com/blog/mike-rothman/crazy-consolidation-will-continue">Crazy Consolidation Will Continue | Security Incite: Analysis on Information Security</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/409939547" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security incite">security incite</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/crazy consolidation">crazy consolidation</category>
      <category domain="http://securityratty.com/tag/continue">continue</category>
      <category domain="http://securityratty.com/tag/analysis">analysis</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/409939547/anton18">Links for 2008-10-02 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-10-01 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/2e61bbf8f65cea7668e676362729b6b6</link>
      <guid>http://securityratty.com/article/2e61bbf8f65cea7668e676362729b6b6</guid>
      <description><![CDATA[Behavioral Monitoring | securosis.com
Dana Gardner's BriefingsDirect: Improved insights and analysis from IT systems logs helps reduce complexity risks from virtualization
E-Commerce News: ID...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://securosis.com/2008/09/23/behavioral-monitoring/">Behavioral Monitoring | securosis.com</a></li>
<li><a href="http://briefingsdirectblog.blogspot.com/2008/09/improved-insights-and-analysis-from-it.html">Dana Gardner's BriefingsDirect: Improved insights and analysis from IT systems logs helps reduce complexity risks from virtualization</a></li>
<li><a href="http://www.ecommercetimes.com/story/64598.html">E-Commerce News: ID Security: New PCI Security Standard Falls Short</a></li>
<li><a href="http://duckdown.blogspot.com/2008/09/how-many-fingers-are-required-to-count.html">Enterprise Architecture: From Incite comes Insight...: How many fingers are required to count the number of clueless IT Security Professionals?</a></li>
<li><a href="http://www.csoonline.com/article/print/450190">IT Security: Can We Be Compliant and Yet Insecure?</a></li>
<li><a href="http://blogs.gartner.com/greg_young/2008/09/30/get-rich-quick-with-network-security/">Get Rich Quick With Network Security</a></li>
<li><a href="http://rationalsecurity.typepad.com/blog/2008/09/ids-vitamins-or-prophylactic.html">Rational Survivability: IDS: Vitamins Or Prophylactic?</a></li>
<li><a href="http://treasuryinstitute.org/blog/index.php?itemid=174">PCI DSS News and Information &raquo; Great Expectations?</a></li>
<li><a href="http://www.estoregfoa.org/StaticContent/staticpages/TM0508.htm#1c">GFOA Treasury Management</a></li>
<li><a href="http://forensics.sans.org/community/top7_forensic_trends.php">SANS - Computer Forensics - Top 7 New IR/Forensic Trends In 2008</a><br/>
SANS Top 7 New IR/Forensic Trends In 2008</li>
<li><a href="http://securitybuddha.com/2008/09/30/you-might-be-a-pm-if/">You Might be a PM if&hellip; &laquo; Mark Curphey - SecurityBuddha.com</a></li>
<li><a href="http://blogs.computerworld.com/security_is_not_a_solution">Security is not a solution | Computerworld Blogs</a><br/>
Security is not a solution</li>
<li><a href="http://www.andrewhay.ca/archives/385">Andrew Hay &raquo; Blog Archive &raquo; Secure Life Ep 3</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/408931097" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security professionals">security professionals</category>
      <category domain="http://securityratty.com/tag/computerworld blogs security">computerworld blogs security</category>
      <category domain="http://securityratty.com/tag/network security">network security</category>
      <category domain="http://securityratty.com/tag/sans top">sans top</category>
      <category domain="http://securityratty.com/tag/irforensic trends">irforensic trends</category>
      <category domain="http://securityratty.com/tag/sans">sans</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <category domain="http://securityratty.com/tag/pci dss news">pci dss news</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/408931097/anton18">Links for 2008-10-01 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-09-18 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/86e32073c65f0bfabc65cd7f102d81b2</link>
      <guid>http://securityratty.com/article/86e32073c65f0bfabc65cd7f102d81b2</guid>
      <description><![CDATA[Rise up against Mediocrity | Security Incite: Analysis on Information Security
invisiblethings' blog: Microsoft executive &quot;rebuts&quot; our...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://securityincite.com/blog/mike-rothman/rise-up-against-mediocrity">Rise up against Mediocrity | Security Incite: Analysis on Information Security</a></li>
<li><a href="http://theinvisiblethings.blogspot.com/2008/09/microsoft-executive-rebuts-our-research.html">invisiblethings' blog: Microsoft executive &quot;rebuts&quot; our research!</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/396890266" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security incite">security incite</category>
      <category domain="http://securityratty.com/tag/microsoft executive">microsoft executive</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/invisiblethings">invisiblethings</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/analysis">analysis</category>
      <category domain="http://securityratty.com/tag/mediocrity">mediocrity</category>
      <category domain="http://securityratty.com/tag/rebuts">rebuts</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/396890266/anton18">Links for 2008-09-18 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-09-16 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/5a3a38b2081a3ca466ccd8cb3251f404</link>
      <guid>http://securityratty.com/article/5a3a38b2081a3ca466ccd8cb3251f404</guid>
      <description><![CDATA[Matt Flynn's Identity Management Blog: Situational Awareness in Logs &amp; Events
The Difference between Quantitative and Qualitative Risk Analysis and Why It Matters (Part 1) | BlogInfoSec.com
The Daily...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://360tek.blogspot.com/2008/09/situational-awareness-in-logs-events.html">Matt Flynn's Identity Management Blog: Situational Awareness in Logs &amp; Events</a></li>
<li><a href="http://www.bloginfosec.com/2008/09/04/the-difference-between-quantitative-and-qualitative-risk-analysis-and-why-it-matters-part-1/">The Difference between Quantitative and Qualitative Risk Analysis and Why It Matters (Part 1) | BlogInfoSec.com</a></li>
<li><a href="http://securityincite.com/blog/mike-rothman/the-daily-incite-september-16-2008">The Daily Incite - September 16, 2008 | Security Incite: Analysis on Information Security</a><br/>
I got an earful from folks in the DLP space about my thoughts on &quot;poor man&#039;s DLP,&quot; basically the capabilities that come with your email and web gateways that can check for very simple regular expressions and other content matching algorithms. I maintain that for a lot of customers, this is good enough to meet the spirit of the regulations and also to address the most common data leakages. No, this probably won&#039;t wash for a Fortune 50 class mega-enterprise. But Joey-bag-of-donuts and his PCI requirements?</li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/394871019" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/analysis">analysis</category>
      <category domain="http://securityratty.com/tag/qualitative risk analysis">qualitative risk analysis</category>
      <category domain="http://securityratty.com/tag/dlp space">dlp space</category>
      <category domain="http://securityratty.com/tag/identity management blog">identity management blog</category>
      <category domain="http://securityratty.com/tag/dlp">dlp</category>
      <category domain="http://securityratty.com/tag/simple regular expressions">simple regular expressions</category>
      <category domain="http://securityratty.com/tag/common data leakages">common data leakages</category>
      <category domain="http://securityratty.com/tag/pci requirements">pci requirements</category>
      <category domain="http://securityratty.com/tag/situational awareness">situational awareness</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/394871019/anton18">Links for 2008-09-16 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-09-15 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/76641371b3a7f5060624cdd792c7e9cb</link>
      <guid>http://securityratty.com/article/76641371b3a7f5060624cdd792c7e9cb</guid>
      <description><![CDATA[Quest grabs NetPro to strengthen Windows management wares - Network World NetPros lineup includes tools focused on security/compliance, infrastructure administration and identity/access. Those tools...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://www.networkworld.com/news/2008/091208-quest.html">Quest grabs NetPro to strengthen Windows management wares - Network World</a><br/>
NetPro’s lineup includes tools focused on security/compliance, infrastructure administration and identity/access.

Those tools include auditing, backup/recovery, policy enforcement, event log management, Exchange migration, group policy management, health/performance and user self-service password management</li>
<li><a href="http://searchsecurity.techtarget.com.au/articles/26900-Are-common-logging-and-audit-standards-emerging-">Are common logging and audit standards emerging? :: SearchSecurity.com.au</a></li>
<li><a href="http://news.zdnet.com/2424-9595_22-218408.html">SaaS market will 'collapse' in two years | Tech News on ZDNet</a><br/>
Q: Won&#039;t people avoid the mistakes of &quot;previous&quot; SaaS incarnations, as you mentioned?

A: People are stupid. History has shown it repeats itself, and people make the same mistakes.</li>
<li><a href="http://www.crmoutsiders.com/2008/08/28/lawson-ceo-saas-will-collapse-in-two-years/">CRM Outsiders &raquo; Blog Archive &raquo; Lawson CEO: SaaS Will &ldquo;Collapse&rdquo; In Two Years</a><br/>
I couldn’t disagree more, but than again it was also Harry Debes that predicted that many of today’s Web 2.0, cell phone gadgets would never catch on either. SaaS is certainly here to say. I</li>
<li><a href="http://www.dimitrimckay.com/Loglogic/Blog/Entries/2008/7/20_How_to_convert_windows_logs_to_syslog:.html">Nerd News: Eventlog to Syslog</a></li>
<li><a href="http://blog.isc2.org/isc2_blog/2008/09/event-correlati.html">(ISC)2 Blog: Event Correlation</a></li>
<li><a href="http://www.rsa.com/blog/blog_entry.aspx?id=1301">Speaking of Security... | Blog Entry: Paul Stamp | Correlation is no silver bullet: 1301</a><br/>
So, when deploying SIEM to improve your security operations, remember that correlation only really works when backed up by real data about what is the biggest problem in your environment, and how that problem manifests itself in the event logs. I call it &quot;working out what type of needles you&#039;ll find in your haystack.&quot;</li>
<li><a href="http://blogs.zdnet.com/Gardner/?p=2723">Systems log analytics offers operators performance insights that set stage for IT transformation | Dana Gardner&rsquo;s BriefingsDirect | ZDNet.com</a></li>
<li><a href="http://www.nemertes.com/analyst_blogs/sharpening_stones_and_walking_coals">Sharpening Stones and Walking on Coals | Nemertes Research</a><br/>
When hunting for a needle in a haystack, after all, making the haystack larger is not an obviously productive course; getting a tool that can assist in the hunt - a magnet, or a metal detector - makes more sense!</li>
<li><a href="http://www.nemertes.com/analyst_blogs/search_or_destroy">Search or Destroy | Nemertes Research</a><br/>
It&#039;s not all about security, it&#039;s not all about events, it&#039;s not all about compliance. All those things are critically important to IT, of course, but even more fundamental is the task of keeping things running.</li>
<li><a href="http://jdm-tech.blogspot.com/2008/07/how-worthwhile-is-logging.html">jdm's Blog: How worthwhile is logging?</a><br/>
Logs are like a warm blanket; verbose logging means you can know what&#039;s happening on your systems if you keep up with the logs.  At the same time, logs become a burden very very easily, and they are easy to ignore.</li>
<li><a href="http://blog.gerhards.net/2008/07/what-is-event-and-what-event-log.html">Rainer's Blog: What is an Event? And what an Event Log?</a></li>
<li><a href="http://duckdown.blogspot.com/2008/07/taming-documentum-audit-trail.html">Enterprise Architecture: From Incite comes Insight...: Taming the Documentum Audit Trail</a><br/>
First and foremost, it is a good security principle to separate log data from the system.</li>
<li><a href="http://thomasnicholson.com/2008/07/02/log-management-is-a-pain/">Log management is a pain | Thomas Nicholson</a><br/>
So for an administrator to not care about logs was a shock.</li>
<li><a href="http://blogs.splunk.com/thebaum/2008/09/03/situational-awareness/">thebaumblog &raquo; Blog Archive &raquo; Life after SIEM. Situational Awareness is next.</a><br/>
Life after SIEM. Situational Awareness is next.</li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/393875149" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/event logs">event logs</category>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/event log management">event log management</category>
      <category domain="http://securityratty.com/tag/event log">event log</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/saas market">saas market</category>
      <category domain="http://securityratty.com/tag/saas">saas</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/393875149/anton18">Links for 2008-09-15 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-09-11 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/5fc8d88b3db9b7e7ca09f8f03b4c3cd0</link>
      <guid>http://securityratty.com/article/5fc8d88b3db9b7e7ca09f8f03b4c3cd0</guid>
      <description><![CDATA[OPEN Forum by American Express OPEN Blog Archive How to Save a Billion Dollars
The Daily Incite - September 11, 2008 | Security Incite: Analysis on Information Security But I think many security...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://blogs.openforum.com/2008/09/10/how-to-save-a-billion-dollars/">OPEN Forum by American Express OPEN &raquo; Blog Archive How to Save a Billion Dollars</a></li>
<li><a href="http://securityincite.com/blog/mike-rothman/the-daily-incite-september-11-2008">The Daily Incite - September 11, 2008 | Security Incite: Analysis on Information Security</a><br/>
But I think many security managers are missing the point of what a security management platform is supposed to do. It&#039;s about control and automation. The reality is no human can wade through the morass of data that comes out of our security devices.</li>
<li><a href="http://www.darkreading.com/document.asp?doc_id=162936">Security Management: A Chicken &amp; Egg Problem - Discovery and management - Dark Reading</a><br/>
Most enterprises are looking for a product that will solve all of their problems in some sort of off-the-shelf miracle, and when they find out that the currently available tools can&#039;t do it, they either postpone their deployment or put them on the back burner.</li>
<li><a href="http://biz.yahoo.com/bw/080908/20080908005257.html?.v=1">Trusted Computer Solutions Acquires CounterStorm to Broaden Portfolio of Security Solutions: Financial News - Yahoo! Finance</a></li>
<li><a href="http://briefingsdirectblog.blogspot.com/2008/09/systems-log-analytics-offers-operators.html">Dana Gardner's BriefingsDirect: Systems log analytics offers operators performance insights that set stage for IT transformation</a></li>
<li><a href="http://financialcryptography.com/mt/archives/001091.html">Financial Cryptography: Yet more evidence: your CISO needs an MBA</a><br/>
Yet more evidence: your CISO needs an MBA</li>
<li><a href="http://www.webadminblog.com/index.php/2008/06/23/the-velocity-2008-conference-experience-part-iii/">The Velocity 2008 Conference Experience - Part III - Web Admin Blog</a><br/>
Logging should be actionable - concise, express symptoms. Anything logged is something fixable. It should be giving you less downtime - shorter time to resolution. Logging takes resources, so make it worth it.

Filter down your logs to be concise and actionable. Production logging has different goals from dev/QA logging. You’re looking for problem diagnosis and recovery, and then statistics and monitoring. Insight into what the app’s doing.</li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/390342450" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 11 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security management platform">security management platform</category>
      <category domain="http://securityratty.com/tag/security management">security management</category>
      <category domain="http://securityratty.com/tag/management">management</category>
      <category domain="http://securityratty.com/tag/web admin blog">web admin blog</category>
      <category domain="http://securityratty.com/tag/conference experience">conference experience</category>
      <category domain="http://securityratty.com/tag/american express">american express</category>
      <category domain="http://securityratty.com/tag/ciso">ciso</category>
      <category domain="http://securityratty.com/tag/concise">concise</category>
      <category domain="http://securityratty.com/tag/mba">mba</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/390342450/anton18">Links for 2008-09-11 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-08-15 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/c3237e147aa048495488e182bb006937</link>
      <guid>http://securityratty.com/article/c3237e147aa048495488e182bb006937</guid>
      <description><![CDATA[The Daily Incite - August 15, 2008 | Security Incite: Ding dong, SIM is dead? Yeah, not so much... My opinion is that the first generation of SIM didn't do what it needed to. It was too hard, too...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://securityincite.com/blog/mike-rothman/the-daily-incite-august-15-2008">The Daily Incite - August 15, 2008 | Security Incite:    Ding dong, SIM is dead? Yeah, not so much...</a><br/>
My opinion is that the first generation of SIM didn&#039;t do what it needed to. It was too hard, too expensive, took too long to see value. There are lots of folks that are working on those issues. Of course, we still aren&#039;t there yet, but the industry is making progress. And the biggest reason I don&#039;t see the idea of SIM dying (although the implementation will clearly change and evolve) is because CUSTOMERS NEED IT.</li>
<li><a href="http://securityincite.com/TDI-2008-08-15#TBP3">Lets start the hype engine for 2009</a><br/>
For the 5th year in a row, I suspect 2009 will be very much like 2008. We are still bailing out the leaky boat with a small cup. Sure, there are new and different attack vectors. And things like &quot;the cloud&quot; are causing us to revisit our general security architectures. And compliance certainly isn&#039;t going away as a key issue for security folks everywhere. BUT, maybe in 2009 we can start actually implementing the stuff we bought in 2006 and making sure we are more effectively doing the blocking and tackling that we all know can use some improvement.</li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/366256321" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sim">sim</category>
      <category domain="http://securityratty.com/tag/folks">folks</category>
      <category domain="http://securityratty.com/tag/security folks">security folks</category>
      <category domain="http://securityratty.com/tag/attack vectors">attack vectors</category>
      <category domain="http://securityratty.com/tag/key issue">key issue</category>
      <category domain="http://securityratty.com/tag/security architectures">security architectures</category>
      <category domain="http://securityratty.com/tag/start">start</category>
      <category domain="http://securityratty.com/tag/security incite">security incite</category>
      <category domain="http://securityratty.com/tag/leaky boat">leaky boat</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/366256321/anton18">Links for 2008-08-15 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-07-22 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/6e863ea0d836fdb6013ed12bd7b5ccef</link>
      <guid>http://securityratty.com/article/6e863ea0d836fdb6013ed12bd7b5ccef</guid>
      <description><![CDATA[NitroSecuritys Acquisition of RippleTech | securosis.com
Individual Privacy vs. Business Drivers | securosis.com
What goes up... (virtualization market) | Security Incite: Analysis on Information...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://securosis.com/2008/07/21/nitrosecuritys-acquisition-of-rippletech/">NitroSecurity&rsquo;s Acquisition of RippleTech | securosis.com</a></li>
<li><a href="http://securosis.com/2008/07/21/individual-privacy-vs-business-drivers/">Individual Privacy vs. Business Drivers | securosis.com</a></li>
<li><a href="http://securityincite.com/blog/mike-rothman/what-goes-up-virtualization-market">What goes up... (virtualization market) | Security Incite: Analysis on Information Security</a></li>
<li><a href="http://securityincite.com/blog/mike-rothman/incite-redux-day-9-get-the-jumper-cables-for-dlp">Incite Redux: Day 9 - Get the jumper cables for DLP | Security Incite: Analysis on Information Security</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/343213511" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security incite">security incite</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/business drivers">business drivers</category>
      <category domain="http://securityratty.com/tag/individual privacy">individual privacy</category>
      <category domain="http://securityratty.com/tag/virtualization market">virtualization market</category>
      <category domain="http://securityratty.com/tag/nitrosecuritys acquisition">nitrosecuritys acquisition</category>
      <category domain="http://securityratty.com/tag/jumper cables">jumper cables</category>
      <category domain="http://securityratty.com/tag/analysis">analysis</category>
      <category domain="http://securityratty.com/tag/incite redux">incite redux</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/343213511/anton18">Links for 2008-07-22 [del.icio.us]</source>
    </item>
  </channel>
</rss>
