<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: opposite]]></title>
    <link>http://securityratty.com/tag/opposite</link>
    <description></description>
    <pubDate>Tue, 22 Jul 2008 15:01:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Chairman Tata Surprised by Tricky Terrorists]]></title>
      <link>http://securityratty.com/article/7b4520b092d5aedad18be187c5cd3069</link>
      <guid>http://securityratty.com/article/7b4520b092d5aedad18be187c5cd3069</guid>
      <description><![CDATA[Chairman Rata Tata, whose company owns the Taj hotel in Mumbai, gave a frank and honest interview to CNN. I would imagine that the Tata Group's PR people and General Counsel are scrambling at the...]]></description>
      <content:encoded><![CDATA[Chairman Rata Tata, whose company owns the Taj hotel in Mumbai, gave a frank and honest interview to CNN.  I would imagine that the Tata Group's PR people and General Counsel are scrambling at the moment trying to do as much damage control as possible. <br /><span id="fullpost"><br />The sad part of this unfolding story is the feeling one gets that the terrible loss of life at the hotel may have been prevented or at least mitigated had proper security measures been implemented and if the security that had been in place prior to the attack had not been removed.  <br /></span><br />One eye witness who stayed at the hotel a week before the terrorist assault spoke about metal detectors and baggage being checked.  The same witness then went on to say that those security measures had been removed within the last week, allowing people to enter without being checked.<br /><br />The most surprising news to surface must be the Chairman's comments regarding the terrible event. Unbelievably, he actually said; "They knew what they were doing and they did not go through the front.  All of our arrangements were on the front entrance".<br /><br />Who is Tata's security advisor, a kitchen worker?  Actually, he might have been better off if that were the case since the terrorists entered the hotel through the rear kitchen door.  ANNOUNCEMENT TO ALL CHAIRMEN AND CEO's; Terrorists are Tricky.  That is their job.  They are watching your businesses and will do the opposite to what you expect.  <br /><br />In the case of the TAJ HOTEL, you made it easy for them.  Did nobody in Mumbai ever stop to think that a bad person can go through the back door?  It is one thing for a cafe in a pedestrian area to be attacked as anyone can walk right by or walk through the front and open fire, but how can a major landmark that attracts Western vistors drop their security measures AFTER they have received terrorist alert warnings that the hotel may be the target of terrorsit attacks?  <br /><br />I don't know if it was the case with the Taj Hotel, but cutting corners where security is concerned is common place in corporate culture.  Security is often seen as a necessary evil and usually the first department to experience budgetary cutbacks.  It is very difficult to convince some clients that nothing happening is really a good thing and that by cutting out security may open the door to evil.<br /><br />This appears to have been the case with the Taj.  There is no doubt that the terrorists had conducted hundreds of hours of surveillance in and around Mumbai.  Was it a coincidence that the attack occurred the week after security measures had been removed?  What might have been the result if security had remained tight (if you could call watching the front entrance and disregarding the back as "tight security")?  Maybe the terrorists would have held back another month or two...maybe in that time they would have been detected...<br /><br />One thing is for certain, places like the Taj Hotel have to get serious about security.  Mr. Tata's claim that; "If I look at what we had...it could not have stopped what took place", must be replaced by more progressive, proactive thinking.  If the Tata Group had spent an adequate amount of funding on ensuring that a strict security policy was in force - if only for the period in question - then they might not now be facing a 5 Billion Rupee reconstruction bill.  Who knows how high the civil suits against the Taj will run when compensation and punitive costs are calculated.         <br /><br />Kudos though to Chairman Tata for at least recognizing that the Indian authorities may not be able to handle the situation on their own.  "These attacks underscore the need for Law Enforcement to seek outside expertise for training, equipment and strategic operations", he said.<br /><br />We agree Mr. Tata.  We also hope that you will recognize the need for the Tata Group to seek similar outside expertise to assist you with your security planning and training.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sun, 30 Nov 2008 22:29:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security measures">security measures</category>
      <category domain="http://securityratty.com/tag/proper security measures">proper security measures</category>
      <category domain="http://securityratty.com/tag/tata">tata</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security advisor">security advisor</category>
      <category domain="http://securityratty.com/tag/chairman tata">chairman tata</category>
      <category domain="http://securityratty.com/tag/chairman rata tata">chairman rata tata</category>
      <category domain="http://securityratty.com/tag/taj">taj</category>
      <category domain="http://securityratty.com/tag/taj hotel">taj hotel</category>
      <source url="http://www.thebulletproofblog.com/2008/11/chairman-tata-surprised-by-tricky.html">Chairman Tata Surprised by Tricky Terrorists</source>
    </item>
    <item>
      <title><![CDATA[Not Your Father's Data Breach]]></title>
      <link>http://securityratty.com/article/6e6dd929bba96e08b0dee7eee16ea946</link>
      <guid>http://securityratty.com/article/6e6dd929bba96e08b0dee7eee16ea946</guid>
      <description><![CDATA[I am surprised this doesn't happen more often, or become public when it does happen, and I suspect it will


Corporate custodians of confidential medical data should be closely monitoring events...]]></description>
      <content:encoded><![CDATA[<p>I am surprised <a href="http://www.stltoday.com/blogzone/the-platform/published-editorials/2008/11/express-scripts-data-breach-is-bitter-medicine/"><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">this</span></a><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "> doesn&#39;t happen more often, or become public when it does happen, and I suspect it will:</span></p><div><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-size: 16px; line-height: 17px; "><strong style="font-style: normal; font-weight: bold; "><span style="font-style: normal; font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Corporate custodians</span></strong><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&#0160;of confidential medical data should be closely monitoring events connected to a nightmarish computer security breach in the St. Louis region.</span></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Express Scripts is one of the nation’s largest pharmacy benefits managers. The company, with headquarters in St. Louis County, handles approximately 500 million prescriptions per year for 50 million workers at 1,600 American companies. Early in October, it received an extortion letter, the details of which it released on Nov. 6.</span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The letter included personal information on about 75 Express Scripts clients — Social Security numbers, dates of birth and, in some cases, information about prescription medications. Whoever sent the letter demanded money from the company — the amount has not been disclosed — and threatened to use the Internet to reveal personal and medical information about millions of people if the demands were not met.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">...</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-size: 16px; line-height: 17px; "><strong style="font-style: normal; font-weight: bold; "><span style="font-style: normal; font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Beyond&#0160;</span></strong><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">the scale of the problem for Express Scripts — and the potential impact on the company is enormous — the issue extends well beyond the mounting concerns about identity theft, a phenomenon with which most people have become at least somewhat familiar.</span></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The greater problem is the unique nature of personal medical records, the importance of moving to computerization of such records to improve health safety and reduce costs and the irreversibility of the damage people can suffer if confidential medical information becomes public. The stakes are so high that a federal law establishes strict standards for maintaining the privacy of medical information and stiff fines for failing to do so.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Medical records of all kinds — paper and, especially, electronic — must be protected with the most sophisticated kinds of security systems available, including backup protections and automatic alerts of security violations. Yet Express Scripts learned of this breach in the “worst way,” as InformationWeek.com security correspondent George Hulme put it in an online report: “via an extortion letter.”</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; font-size: 16px; line-height: 17px; "><strong style="font-style: normal; font-weight: bold; "><span style="font-style: normal; font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The Express Scripts</span></strong><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&#0160;breach raises many questions for all elements of the health industry: hospitals, clinics and doctors’ practices, benefits management firms, insurance companies, pharmacies, employers and government agencies:</span></span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Are they using the most advanced information security technology possible? Do they minimize the amount of data they collect and keep it only as long as necessary? Do they have strict protocols governing access to personal and medical data — and systems to enforce those protocols? If criminals were to hack into their systems, how would the companies know? How soon? And are the systems capable of instantly cutting off illegal access as soon as a breach is discovered?</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; font-size: 16px; line-height: 17px; "><strong style="font-style: normal; font-weight: bold; "><span style="font-style: normal; font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Confronted</span></strong><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&#0160;with a grave breach of electronic security, Express Scripts has responded by contacting law enforcement, establishing an informational website, offering a substantial reward and hiring a private consulting firm to help clients who have privacy concerns and investigate situations that “appear to be tied to identity theft” and provide “identity restoration services.” There is no question that the company is taking the situation extremely seriously.</span></span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Given the ongoing criminal situation, information about how Express Scripts’ data systems were compromised — and whether it could have been avoided — has yet to be disclosed. But the American people have the right to expect that their sensitive personal and medical information is zealously protected and kept secure — not only by Express Scripts but also by every person or company entrusted with it.</span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><p><span style="color: #333333; font-size: 16px; line-height: 17px; "><div><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The reason I am surprised this doesn&#39;t happen more often is that many Fortune 500 companies have oceans and oceans of personal data. Almost the only companies that have even tried to get to a medium level assurance are financial companies, yet many of the other companies have as much or even more data, with lower assurance. All that was lacking in the mix was an incentive and a bit of creativity and risk taking by the bad guys.</span></span></p><div><span style="color: #333333; line-height: 17px;"><br /></span></div><div><span style="color: #333333; line-height: 17px;">I posted this to the security metrics list and Andy Jaquith quoted it in his great book S<a href="http://1raindrop.typepad.com/1_raindrop/2007/08/chicken-soup-fo.html">ecurity Metrics</a>:</span></div><div><span style="color: #333333; line-height: 17px;"><br /></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; ">&quot;Customers and customer relationships...have tangible measurable value to businesses, and their value is much easier to communicate to those who fund projects. So in an enterprise risk management scenartio, their vlaue informs the risk management process...[For example, consider] a farmer deciding which crop to grow. A farmer interested in short term profits may grow the same high yield crop every year, but over time this would burn the fields out. The long term focused farmer would rotate the crops and invest in things that build the value of the farm and soil over time. Investing in security on behalf of your customers is like this. The investment made in securing your customer&#39;s data build current and future value for them. Measuring the value of the customer and relationships helps to target where to allocate security resources.&quot;</span></p></blockquote><div><span style="color: #333333; line-height: 17px;"><br /></span></div><div><span style="color: #333333; line-height: 17px;">Of course this is the opposite of how most organizations do risk management and security architecture, and now, the fields have turned brown.<br /></span><div><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><div><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">(Thanks to Chris for pointing me to this story)</span></div></div></div>]]></content:encoded>
      <pubDate>Thu, 20 Nov 2008 06:37:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/medical information">medical information</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/personal">personal</category>
      <category domain="http://securityratty.com/tag/personal medical records">personal medical records</category>
      <category domain="http://securityratty.com/tag/medical records">medical records</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/security systems">security systems</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/11/not-your-fathers-data-breach.html">Not Your Father's Data Breach</source>
    </item>
    <item>
      <title><![CDATA[So Logically, If She Weighs The Same As A DuckShes A Witch!]]></title>
      <link>http://securityratty.com/article/3fa3a2c5641e284f4fc5fc76430d2faa</link>
      <guid>http://securityratty.com/article/3fa3a2c5641e284f4fc5fc76430d2faa</guid>
      <description><![CDATA[I usually try to stay far away from politics and current events, but my friend Rich has put up a blog post blaming the credit crisis on quantitative analysis, and then positing that because the...]]></description>
      <content:encoded><![CDATA[<p>I usually try to stay far away from politics and current events, but my friend <strong><a href="http://securosis.com/2008/09/17/the-fallacy-of-complete-and-accurate-risk-quantification/">Rich has put up a blog post</a></strong> blaming the credit crisis on quantitative analysis, and then positing that because the economy sucks, Information Security should be only qualitative.</p>
<p>Now I&#8217;ve been &#8220;accused&#8221; of being a quant in the past (hi rybolov!) but in reality the only dogs I have in this fight are the model and the application of scientific method - and really, ethically speaking, I have to be tied to the latter while applying the former.</p>
<p>And I see a false dichotomy in this whole Quant vs. Qual thing.  We, as a profession, tend to create a political divide between the two which, if it even exists, I&#8217;d say is based more on our ignorance rather than our expertise.  After all, we are the profession that regularly multiplies across ordinal scales and uses wonderful models like R=VxTxI.   As someone  learning to deal in probabilities and rationalism, I have to recognize that this discussion is really just about the act of observation using different metrics of measurement.</p>
<p>But how we&#8217;re going about observing does not change the fact that there is measurement based on observation.  So if I&#8217;m working with you I can easily turn your qualitative scale into a quantitative one, and vice-versa.  Yes, Shrdlu, if we had the time, even your most seemingly Qual things could be Quant! (This flexible world view, btw, is an outcome of that new-fangled Bayesian thing).</p>
<p><strong>COGNITIVE BIAS A-PLENTY</strong></p>
<p>But back to what Rich is saying there about information security and risk - and he isn&#8217;t/won&#8217;t be the only one saying these sorts of things - we should try to understand what&#8217;s really going on rather than get caught up in the emotional hurricane.  Our profession suffers several forms of cognitive bias.  The nature of our jobs and what we do can cause us to be focused on the outcome and not the quality of the decision at the time it was made.  We want to bring in things from other professions that are useful, but at times we do view things outside our profession with false correlation to our own (unfortunately for those who write these sorts of articles, financial risk is <em><strong>completely different</strong></em> than operational risk).  We also have the tendency to focus on negative outcomes without acknowledging the positive outcomes (For example, I hear that Alan Greenspan&#8217;s new firm is up a couple of $billion in all this mess since he joined them, short sellers are doing quite well - must be because they have qualitative models or something <em>-grin-</em>).  The effect of these biases are compounded by the facts that proper correlation takes more work than we usually give it, and rational thought is not that easy when there&#8217;s a witch-hunt mentality.</p>
<div class="wp-caption alignnone" style="width: 257px"><a href="http://www.youtube.com/watch?v=zrzMhU_4m-g"><img src="http://www.riskmanagementinsight.com/media/images/weblog/peasants.png" alt="Burn her anyway!" width="247" height="219" /></a><p class="wp-caption-text">What also floats in water? (link to Youtube)</p></div>
<p><strong>WHAT SHOULD WE BE THINKING ABOUT?</strong></p>
<p>So as you and I read opinions that seem to be the polar opposite of irrational exuberance (and there will be plenty between now and the election) we&#8217;ll have to ask ourselves, &#8220;what really failed here?&#8221;  At the risk (pun) of over-simplification:</p>
<ul>
<li>Was There an Error on the part of Probability Theory?</li>
</ul>
<p>After all, Probability Science like all other fields of knowledge is always &#8220;advancing&#8221; as they say.  So perhaps probability theory is wrong somehow?</p>
<p>I&#8217;m personally disinclined to put the blame here, primarily because I would think that there would be evidence from other fields (like Quantum Mechanics) that something is amiss waaaaay before it hit a field like economics.</p>
<ul>
<li>Was There Error In The Model Used to Determine Risk?</li>
</ul>
<p>Some people who understand real estate valuation and complex derivatives and financial risk want to put the blame here.  It&#8217;s a little too early to tell, but one thing is for sure - Financial risk is so different from operational risk I couldn&#8217;t begin to hazard an opinion on the subject.   But it would seem that this is really somewhere we might look.</p>
<ul>
<li>Was There Error In The  Scale Used (Quantitative vs. Qualitative)?</li>
</ul>
<p>Honestly?  I find it extremely difficult to understand how this could be the source of financial ruin.</p>
<ul>
<li>Was There Error on the part of the Decision Maker?</li>
</ul>
<p>What if all of the above were just fine, and the decision maker chose short term gain over long term stability?  What if this was (to simplify the matter greatly) a choice of &#8220;heads&#8221; over &#8220;tails&#8221; and the coin landed on tails?  What if the model represented the right risk (probability of negative outcome vs. positive outcome), but the complex derivative was sold to someone else who had poor &#8220;risk management&#8221; (ability to make a good decisions)?</p>
<p>Now I have no clue about complex derivatives, and I&#8217;m oversimplifying to be sure - chances are like most things, there are several problems that helped create the primary cause. But it seems to me that as we go into incident response mode for the economy, it&#8217;s more helpful to do so in a rational, logical manner.<br />
<strong><br />
OTHER THINGS WE MIGHT WANT TO CONSIDER</strong></p>
<p><span style="color: #008000;"><strong>Consider the Source</strong></span><br />
Some authors (who I think tend to exploit outcome and hindsight bias,and then combine those with indirect ad hominem attacks in order to sell their books), are actually putting forth arguments against the use of analytics.  The source of this is a current epistemic debate between those who believe that only falsification is certain, and those who maintain that neither proof nor falsification are certain, there are only probabilities.    So before you go believing any &#8220;quadrants&#8221; of usefulness on faith - I encourage you to understand what is at the heart of the discussion.<br />
<span style="color: #008000;"><strong><br />
We All Have to Live In The Real World</strong></span><br />
The sun will rise tomorrow, and someone will try to find the source of the problem and do a better job.  Now chances are, they&#8217;ll be doing it in a quantitative manner.  Chances are also that at some point their models will fail and we&#8217;ll need to build new ones.  And this will happen whether the field is cosmology, economics, meteorology, information security, or professional baseball.<br />
<strong><br />
WHAT ABOUT YOU, ALEX?</strong></p>
<p>I&#8217;m far from certain and subject to change, but these days I lean towards <strong><a href="http://www.overcomingbias.com/2008/09/who-to-blame.html">Robin Hanson &amp; MIchael Lewis</a></strong> w/regards to placing blame.</p>
]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 10:59:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/financial risk">financial risk</category>
      <category domain="http://securityratty.com/tag/poor risk management">poor risk management</category>
      <category domain="http://securityratty.com/tag/operational risk">operational risk</category>
      <category domain="http://securityratty.com/tag/outcome">outcome</category>
      <category domain="http://securityratty.com/tag/exploit outcome">exploit outcome</category>
      <category domain="http://securityratty.com/tag/probability">probability</category>
      <category domain="http://securityratty.com/tag/qualitative models">qualitative models</category>
      <category domain="http://securityratty.com/tag/models">models</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=420">So Logically, If She Weighs The Same As A DuckShes A Witch!</source>
    </item>
    <item>
      <title><![CDATA[Null Strings in ASP.NET Declarative DataSource Updates]]></title>
      <link>http://securityratty.com/article/11f8906732a7b86831292456d642b2f5</link>
      <guid>http://securityratty.com/article/11f8906732a7b86831292456d642b2f5</guid>
      <description><![CDATA[I just spent about 15 minutes debugging a problem where a document was getting unexpected nulls where empty strings should have been. Indeed controls like the TextBox have code in them that allows you...]]></description>
      <content:encoded><![CDATA[<p>I just spent about 15 minutes debugging a problem where a document was getting unexpected nulls where empty strings should have been. Indeed controls like the TextBox have code in them that allows you to set the Text property to null and the TextBox will convert that into an empty string. So it&#39;s a bit counterintuitive that <em>the declarative data source works the opposite way by default</em>.</p> <p>When you use a declarative data source to perform a parameterized update that contains string parameters, consider setting ConvertEmptyStringToNull=&#39;false&#39; on your &lt;asp:Parameter&gt; elements, because <em>it&#39;s true by default</em>! In other words, if a text field contains an empty string, it&#39;ll be sent to your declarative data source not as string.Empty, but as null.</p> <p>Now I don&#39;t know about you, but I don&#39;t like dealing with nulls if I can avoid it. Especially strings. Unless there&#39;s a clear need to have a null state, I avoid them like the plague not only in my database designs but also in my XML schema designs. Hopefully this helps somebody out!</p><div style="clear:both;"></div><img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=52773" width="1" height="1">]]></content:encoded>
      <pubDate>Fri, 29 Aug 2008 11:42:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/strings">strings</category>
      <category domain="http://securityratty.com/tag/declarative data source">declarative data source</category>
      <category domain="http://securityratty.com/tag/empty strings">empty strings</category>
      <category domain="http://securityratty.com/tag/null">null</category>
      <category domain="http://securityratty.com/tag/empty">empty</category>
      <category domain="http://securityratty.com/tag/xml schema designs">xml schema designs</category>
      <category domain="http://securityratty.com/tag/textbox">textbox</category>
      <category domain="http://securityratty.com/tag/text property">text property</category>
      <category domain="http://securityratty.com/tag/nulls">nulls</category>
      <source url="http://www.pluralsight.com/community/blogs/keith/archive/2008/08/29/null-strings-in-asp-net-declarative-datasource-updates.aspx">Null Strings in ASP.NET Declarative DataSource Updates</source>
    </item>
    <item>
      <title><![CDATA[Economist.com - Confessions of a Risk Manager]]></title>
      <link>http://securityratty.com/article/536365450db644abfa519cdc03dc2c4c</link>
      <guid>http://securityratty.com/article/536365450db644abfa519cdc03dc2c4c</guid>
      <description><![CDATA[I was reading the Economist this week and came across an excellent article titled &quot; Confessions of a Risk Manager

In the article a risk manager for a major financial institution talks about managing...]]></description>
      <content:encoded><![CDATA[I was reading the <a href="http://www.economist.com/">Economist </a>this week and came across an excellent article titled "<a href="http://www.economist.com/finance/displaystory.cfm?story_id=11897037">Confessions of a Risk Manager</a>".<br /><br />In the article a risk manager for a major financial institution talks about managing risks and how the risk department was viewed as an obstacle by the rest of the business.  I'll just quote a section here so you can see that governance roles, especially those involving trade-offs of risk vs. return are difficult not just in security.<br /><blockquote>In their eyes, we were not earning money for the bank. Worse, we had the power to say no and therefore prevent business from being done. Traders saw us as obstructive and a hindrance to their ability to earn higher bonuses. They did not take kindly to this. Sometimes the relationship between the risk department and the business lines ended in arguments.   . . .<br /><br />Tactfully explaining why we said no was not our forte. Traders were often exasperated as much by how they were told as by what they were told.  <p>At the root of it all, however, was—and still is—a deeply ingrained flaw in the decision-making process. In contrast to the law, where two sides make an equal-and-opposite argument that is fairly judged, in banks there is always a bias towards one side of the argument. The business line was more focused on getting a transaction approved than on identifying the risks in what it was proposing. The risk factors were a small part of the presentation and always “mitigated”. This made it hard to discourage transactions. If a risk manager said no, he was immediately on a collision course with the business line. The risk thinking therefore leaned towards giving the benefit of the doubt to the risk-takers.<br /></p><p>Collective common sense suffered as a result. Often in meetings, our gut reactions as risk managers were negative. But it was difficult to come up with hard-and-fast arguments for why you should decline a transaction, especially when you were sitting opposite a team that had worked for weeks on a proposal, which you had received an hour before the meeting started. In the end, with pressure for earnings and a calm market environment, we reluctantly agreed to marginal transactions.</p></blockquote><br />Every time I read about decision making like this I refer back to an some excellent presentations I've come across by Reidar Bratvold.  He has done some excellent presentations on decision making in the face of risks/uncertainty.<br /><br /><ul><li><a href="www.spe.no/stavanger/doc/Bratvold%20-%20SPE%20Dist%20Lecturer.pdf">Would You Know a Good decision if You Saw One?</a></li><li><a href="http://www.reidar-bratvold.com/Decision%20Making%20Under%20Uncertainty%20-%20BadenBaden.pdf">Decision Making Under Uncertainty</a></li></ul><img src="http://feeds.feedburner.com/~r/SecurityRetentive/~4/362069047" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 04:42:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk manager">risk manager</category>
      <category domain="http://securityratty.com/tag/risk factors">risk factors</category>
      <category domain="http://securityratty.com/tag/risk-takers">risk-takers</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/business line">business line</category>
      <category domain="http://securityratty.com/tag/risk managers">risk managers</category>
      <category domain="http://securityratty.com/tag/risk department">risk department</category>
      <category domain="http://securityratty.com/tag/business lines">business lines</category>
      <source url="http://feeds.feedburner.com/~r/SecurityRetentive/~3/362069047/economistcom-confessions-of-risk.html">Economist.com - Confessions of a Risk Manager</source>
    </item>
    <item>
      <title><![CDATA[Apptis and USNS Mercy Monitoring on the High Seas]]></title>
      <link>http://securityratty.com/article/32ab3189b54d8e46b467ebbf87db32e0</link>
      <guid>http://securityratty.com/article/32ab3189b54d8e46b467ebbf87db32e0</guid>
      <description><![CDATA[Meet Mike Lawson, Pre-Sales Engineer at Apptis, a leading system integrator and ScienceLogic partner that has deployed EM7 to meet the network, systems and application management needs of several...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="244" alt="mike2 (Small)" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/mike2-small.jpg" width="204" align="left" border="0"> Meet Mike Lawson, Pre-Sales Engineer at Apptis, a leading system integrator and ScienceLogic partner that has deployed EM7 to meet the network, systems and application management needs of several customers. We thought Mike would have an interesting perspective to share on EM7, having recently come from the “customer side” and already with a few deployments under his belt.
<p><b>ScienceLogic: Mike, what’s your background working with network and management system tools?</b>
<p><b>Mike Lawson: </b>Before joining Apptis, I worked for the Air Force, mainly in satellite communications for almost nine years. I’m probably most familiar with HP OpenView and BMC Remedy. I managed a team that used them but wasn’t involved in tool selection; like many other federal IT workers, we didn’t have a choice of tools because there were existing enterprise licenses and maintenance contracts.
<p>I also saw a large systems integrator do a full Remedy/Crystal Systems/OpenView installation. It took 6 weeks to stand up and customize to meet just the basic monitoring requirements, and it cost something like half a million dollars. At the time, I thought that wasn’t bad and was a pretty typical experience.
<p><b>ScienceLogic: Coming from where you did, what’s your take on EM7?</b>
<p><strong>Mike Lawson:</strong> Honestly, I didn’t believe that EM7 could really do all that it claimed. In many ways, it was the complete opposite of what I had seen first-hand with other monitoring solutions. Could it really cover that much functionality? At relatively much lower cost to the customer and without the licensing nightmare?
<p>That quickly changed when I needed to understand the system enough to run it at a customer’s site. I went back over the training docs I received during my initial training class and jumped in; now, 6 months later, I’m the EM7 expert and can tell you that it delivers on all those promises. (But I still need to show people to get them to believe it too)
<p>I preach the “EM7 gospel” and when anyone wants to talk monitoring, I ask about the universal pain points: cost, maintenance contracts and licensing, and then I explain EM7. The cost difference is real; the solution is based on capacity, so there’s no licensing and it’s easy to use. They are shocked to learn that they can buy multiple EM7 appliances and years of maintenance for what they paid for most other tools.
<p><b>ScienceLogic: Apptis won the contract for monitoring aboard the USNS Mercy. We love that you’re using EM7 for one of the Navy’s hospital ships. Can you tell us more?</b>
<p><strong>Mike Lawson:</strong> The USNS Mercy is a Military Sealift Command hospital ship. <a href="http://www.navy.mil/navydata/fact_display.asp?cid=4400&amp;tid=400&amp;ct=4" target="_blank">Some stats</a>:
<ul>
<li>849 feet long (nearly the size of a football field)
<li>12 fully-equipped operating rooms, a 1,000 bed hospital facility, digital radiological services, a diagnostic and clinical laboratory, a pharmacy, an optometry lab, a CAT scan and two oxygen producing plants
<li>Crew: 61 civilian mariners, 956 Naval medical staff, and 259 Naval support staff</li>
</ul>
<p>The USNS recently departed on a five-month humanitarian mission in the Western Pacific and Southeast Asia in support of Pacific Partnership 2008. The partnership provides international medical, dental and engineering teams this summer to provide humanitarian support and conduct joint, combined, and cooperative Civil-Military Operations in order to improve regional stability and build partner capacity to respond to natural disasters and pandemic.
<p>For the most part, the ship’s network is self-contained, but can also use a landline when docked. The network covers 400 devices, including Windows/Exchange servers and VMware for server virtualization. Prior to using EM7, none of the monitoring was integrated; each system was independently monitored through individual vendor-specific consoles.
<p>Out of the box, EM7 provided integrated systems, application and network management for all network gear, applications and virtual machines in one solution. We didn’t have to do a lot of customization – EM7 includes best-practice based thresholds, event and monitoring templates and this covered what USNS Mercy needed to monitor.
<p><b>ScienceLogic: You’re a systems integrator with a very useful “customer point of view” when it comes to looking at tools. From that perspective, can you share what you think are the biggest benefits that EM7 provides?</b>
<p><strong>Mike Lawson:</strong> First of all, EM7 stands up right away. We’re talking days, not weeks. In contrast to the lengthy installation of OpenView and Remedy I witnessed during my military career, I was able to configure, customize, and implement the EM7 solution for the USNS Mercy in three days.
<p>Second, it’s easy to train people on and the support is outstanding. This judgment is from first-hand experience. Right before the USNS Mercy departed on its latest voyage, the system administrator I had trained on EM7 left, so I had all of a day to train some new EM7 admins. I prepared a seven-page “cheat sheet” and over a 3-hour conference call, we walked through the entire EM7 solution; I haven’t gotten a support call since.
<p>And when a problem did crop up with a device being discovered incorrectly, ScienceLogic was very responsive. We contacted ScienceLogic support on a Saturday and they created and emailed us a video to help troubleshoot the same day. Within 30 seconds of watching the video, the problem was resolved.
<p>Finally, EM7 helps us be good stewards of the government’s money. This is very important to me personally and to Apptis as a company. Because EM7 is cheaper and deploys so quickly and easily, you might think that it’s just the opposite of what a system integrator would want to use. But that’s short-term thinking. We believe in deliver the most value for customers every time. It’s what creates trust and long-term relationships with our customers. Instead of that half million spent on standing up the solution and basic setup, I’d much rather (and I know the customer would rather) spend that on fine-tuning or extending the solution to do much, much more.
<p>As a former government employee, I know what it’s like to use a tool that doesn’t fit my needs. EM7 proves that the best solution can totally break the old model of costly, lengthy installations. EM7 has the right model: the right solution and the right price delivered as an appliance that is easy to deploy, train on and use. </p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Apptis+and+USNS+Mercy+%26ndash%3B+Monitoring+on+the+High+Seas&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fapptis-and-usns-mercy-monitoring-on-the-high-seas%2F08%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 11:59:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/entire em7 solution">entire em7 solution</category>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/em7 gospel">em7 gospel</category>
      <category domain="http://securityratty.com/tag/em7 proves">em7 proves</category>
      <category domain="http://securityratty.com/tag/em7 admins">em7 admins</category>
      <category domain="http://securityratty.com/tag/multiple em7 appliances">multiple em7 appliances</category>
      <category domain="http://securityratty.com/tag/em7 solution">em7 solution</category>
      <category domain="http://securityratty.com/tag/explain em7">explain em7</category>
      <source url="http://blog.sciencelogic.com/apptis-and-usns-mercy-monitoring-on-the-high-seas/08/2008">Apptis and USNS Mercy Monitoring on the High Seas</source>
    </item>
    <item>
      <title><![CDATA[Software Liabilities and Free Software]]></title>
      <link>http://securityratty.com/article/dd4800aaf10918236391882307e39b57</link>
      <guid>http://securityratty.com/article/dd4800aaf10918236391882307e39b57</guid>
      <description><![CDATA[Whenever I write about software liabilities , many people ask about free and open source software. If people who write free software, like PasswordSafe , are forced to assume liabilities, they will...]]></description>
      <content:encoded><![CDATA[<p>Whenever I <a href="http://www.guardian.co.uk/technology/2008/jul/17/internet.security">write</a> <a href="http://www.schneier.com/blog/archives/2007/01/information_sec_1.html">about</a> <a href="http://www.schneier.com/essay-116.html">software</a> <a href="http://www.schneier.com/essay-025.html">liabilities</a>, many people ask about free and open source software.  If people who write free software, like <a href="http://www.schneier.com/passsafe.html">PasswordSafe</a>, are forced to assume liabilities, they will simply not be able to and free software would disappear.</p>

<p>Don't worry, they won't be.</p>

<p>The key to understanding this is that this sort of contractual liability is part of a contract, and with free software -- or free anything -- there's no contract.  Free software wouldn't fall under a liability regime because the writer and the user have no business relationship; they are not seller and buyer.  I would hope the courts would realize this without any prompting, but we could always pass a Good Samaritan-like law that would protect people who distribute free software.  (The opposite would be an Attractive Nuisance-like law -- that would be bad.)</p>

<p>There would be an industry of companies who provide liabilities for free software.  If Red Hat, for example, sold free Linux, they would have to provide some liability protection.  Yes, this would mean that they would charge more for Linux; that extra would go to the insurance premiums.  That same sort of insurance protection would be available to companies who use other free software packages.</p>

<p>The insurance industry is key to making this work.  Luckily, they're good at protecting people against liabilities.  There's no reason to think they won't be able to do it here.</p>

<p>I've written more about liabilities and the insurance industry <a href="http://www.schneier.com/crypto-gram-0204.html#6">here</a>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=eikXNJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=eikXNJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=znVSvJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=znVSvJ" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 28 Jul 2008 10:42:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/free software">free software</category>
      <category domain="http://securityratty.com/tag/free">free</category>
      <category domain="http://securityratty.com/tag/free software packages">free software packages</category>
      <category domain="http://securityratty.com/tag/distribute free software">distribute free software</category>
      <category domain="http://securityratty.com/tag/software liabilities">software liabilities</category>
      <category domain="http://securityratty.com/tag/liabilities">liabilities</category>
      <category domain="http://securityratty.com/tag/assume liabilities">assume liabilities</category>
      <category domain="http://securityratty.com/tag/free linux">free linux</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <source url="http://www.schneier.com/blog/archives/2008/07/software_liabil.html">Software Liabilities and Free Software</source>
    </item>
    <item>
      <title><![CDATA[Addressing Cost Issues in the Ever-Changing World of Compliance]]></title>
      <link>http://securityratty.com/article/7d0bdd3a86ffd6cbb812259c8b3b178b</link>
      <guid>http://securityratty.com/article/7d0bdd3a86ffd6cbb812259c8b3b178b</guid>
      <description><![CDATA[We keep hearing from analysts that the cost of compliance should go down each year but unfortunately our customers are telling us the exact opposite. They are continuing to get slammed by new...]]></description>
      <content:encoded><![CDATA[We keep hearing from analysts that the cost of compliance should go down each year but unfortunately our customers are telling us the exact opposite.  They are continuing to get slammed by new regulations and feel compelled to implement all types of point products & solutions in order to meet immediate needs.]]></content:encoded>
      <pubDate>Thu, 24 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/cost">cost</category>
      <category domain="http://securityratty.com/tag/exact opposite">exact opposite</category>
      <category domain="http://securityratty.com/tag/types">types</category>
      <category domain="http://securityratty.com/tag/regulations">regulations</category>
      <category domain="http://securityratty.com/tag/implement">implement</category>
      <category domain="http://securityratty.com/tag/analysts">analysts</category>
      <category domain="http://securityratty.com/tag/solutions">solutions</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1318">Addressing Cost Issues in the Ever-Changing World of Compliance</source>
    </item>
    <item>
      <title><![CDATA[Get Involved Now In Cloud Computing Discussions]]></title>
      <link>http://securityratty.com/article/a06cd0de4e69f284cadf864ed07e11a2</link>
      <guid>http://securityratty.com/article/a06cd0de4e69f284cadf864ed07e11a2</guid>
      <description><![CDATA[This week Amazons Simple Storage Service (S3) suffered a major outage that affected several websites that rely on the service. This is actually the second major outage for Amazon S3 this year. As a...]]></description>
      <content:encoded><![CDATA[<p><img border="0" title="Stephanie Balaouras" alt="Stephanie Balaouras" src="http://www.forrester.com/role_based/images/author/imported/forresterDotCom/Analyst_Photos/Silhouette/Color/Stephanie-Balaouras.gif" style="margin: 0px 5px 5px 0px; float: left;" /></p>
<p class="MsoNormal" style="margin: 0pt;"><span face="Times New Roman">This week Amazon’s Simple Storage Service (S3) suffered a major outage that affected several websites that rely on the service. This is actually the second major outage for Amazon S3 this year. As a result of these and other reported outages, some companies will come to question whether they should pursue these new cloud-based services in the future. I agree with </span><a href="http://www.roughtype.com/archives/2008/02/amazons_s3_util.php"><span face="Times New Roman">Nick Carr</span></a><span face="Times New Roman">, whether you’re a startup looking to rely on the cloud almost exclusively for computing power and storage capacity or you’re a brick and mortar company who may want to use SaaS services for CRM or an </span><a href="http://www.forrester.com/go?docid=42947"><span face="Times New Roman">online backup service</span></a><span face="Times New Roman">, these outages should not scare companies away from cloud-based services. Outages are inevitable; no one, not the most sophisticated internal IT shops on Wall Street, or the largest service providers can offer 100% availability all the time. </span><a href="http://status.aws.amazon.com/"><span face="Times New Roman">Amazon threw everything it had to fix the problem</span></a><span face="Times New Roman"> and was able to address the outage in several hours. How well would you be able to execute on your disaster recovery plan if you had a major outage?</span></p>

<p class="MsoNormal" style="margin: 0pt;"><span face="Times New Roman"><br /></span></p>

<p class="MsoNormal" style="margin: 0pt;"></p>













<p class="MsoNormal" style="margin: 0pt;"><span face="Times New Roman">Instead of avoiding cloud-based services, organizations need to be savvier about security and resiliency of the service provider. In fact, your organization may already be in pursuit of these services. Online backup is becoming a viable alternate to premise-based solutions for PC backup as well as remote office backup. Next will be a number of services related to information management such as </span><a href="/t/app/Local%20Settings/Temporary%20Internet%20Files/OLKF5/The%20Forrester%20Wave:%20Message%20Archiving%20Hosted%20Services,%20Q1%202008"><span face="Times New Roman">online archiving</span></a><span face="Times New Roman"> and online records management and more online storage offerings to support low cost storage. Further down the road, there will also be hosted, multi-tenancy Exchange solutions. Get involved in these discussions. Don’t take it for granted that the potential service provider has hardened data centers that meet Tier III or Tier IV classifications (these classifications describe data center site infrastructure and topology, Tier IV is the highest rating), that your data is replicated to another data center, that your data is encrypted in flight and at rest and that the service provider has strong security measures in place so that administrators can support the infrastructure but not access or even see your organization’s information.<span style="text-decoration: underline;">&nbsp;</span></span><a href="http://www.forrester.com/go?docid=43849"><span face="Times New Roman">Organizations should have consistent processes before, during and after the contracts have been signed. </span></a><span face="Times New Roman"><br /></span></p>

<p class="MsoNormal" style="margin: 0pt;"><span face="Times New Roman"><br /></span></p>

<p class="MsoNormal" style="margin: 0pt;"><span face="Times New Roman">And, when you ask about SLAs regarding resiliency, keep in mind that there will be some downtime for routine maintenance and that some unplanned downtime is inevitable. Consider a service provider that might boast about 99.9% availability (8 hours/year outage for 24x7). What is the difference between the following?</span></p>

<p class="MsoNormal" style="margin: 0pt;"></p>





<p class="MsoNormal" style="margin: 0pt 0pt 0pt 90pt; text-indent: -18pt;"><span style="font-family: Symbol;">·<span style="font-family: &quot;Times New Roman&quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;">&nbsp;</span></span><span face="Times New Roman">8 AM to 4 PM on the last Friday of the quarter </span></p>

<p class="MsoNormal" style="margin: 0pt 0pt 0pt 90pt; text-indent: -18pt;"><span style="font-family: Symbol;">·<span style="font-family: &quot;Times New Roman&quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;">&nbsp;</span></span><span face="Times New Roman">Biweekly outages of 30 min at 4 AM local time</span></p>

<p class="MsoNormal" style="margin: 0pt;"></p>





<p class="MsoNormal" style="margin: 0pt;"><span face="Times New Roman">Timing and duration are more important than total downtime/outage.</span></p>

<p class="MsoNormal" style="margin: 0pt;"><span face="Times New Roman"><br /></span></p>

<p class="MsoNormal" style="margin: 0pt;"></p>





<p class="MsoNormal" style="margin: 0pt;"><span face="Times New Roman">Get involved in these discussions but be careful not to come off as the obstacle or as the doomsayer. Quite the opposite, you want to be seen as the enabler. Help the organization understand some of the potential risks but then help the organization define its resiliency requirements, security requirements, and risk tolerance. When the organization knows this, it can more confidently go out and select the right service provider, negotiate the appropriate SLAs and be prepared ahead of time with contingency plans for any potential service outages.</span></p>]]></content:encoded>
      <pubDate>Thu, 24 Jul 2008 06:55:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/online backup service">online backup service</category>
      <category domain="http://securityratty.com/tag/online">online</category>
      <category domain="http://securityratty.com/tag/potential service provider">potential service provider</category>
      <category domain="http://securityratty.com/tag/service provider">service provider</category>
      <category domain="http://securityratty.com/tag/online storage offerings">online storage offerings</category>
      <category domain="http://securityratty.com/tag/online records management">online records management</category>
      <category domain="http://securityratty.com/tag/online backup">online backup</category>
      <category domain="http://securityratty.com/tag/potential service outages">potential service outages</category>
      <source url="http://blogs.forrester.com/srm/2008/07/get-involved-no.html">Get Involved Now In Cloud Computing Discussions</source>
    </item>
    <item>
      <title><![CDATA[At SANSFIRE 2008 in Washington, DC]]></title>
      <link>http://securityratty.com/article/69b7a54c07f2833e13efa53aef2a59c8</link>
      <guid>http://securityratty.com/article/69b7a54c07f2833e13efa53aef2a59c8</guid>
      <description><![CDATA[I just landed at Washington, DC to speak at SANSFIRE tomorrow ( my Lunch and Learn on &quot;Log Management 'Worst Practices'&quot; is on Wednesday, July 23rd - come over, it will be fun
LogLogic Lunch and Learn...]]></description>
      <content:encoded><![CDATA[<p>I just landed at Washington, DC to speak at SANSFIRE tomorrow (<a href="http://www.sans.org/sansfire08/vendor.php">my Lunch and Learn on &quot;Log Management 'Worst Practices'&quot;</a> is on Wednesday, July 23rd - come over, it will be fun!)</p>  <p><em><strong>LogLogic Lunch and Learn Presentation</strong>      <br />- &quot;Worst Practices&quot; of Log Management      <br />- Speaker: Dr. Anton Chuvakin, GCIA, GCIH, GCFA      <br />- Wednesday, July 23rd, 2008 * 12:30pm - 1:15 pm</em></p>  <p><em>Want to learn all the embarrassing mistakes and pitfalls that await you on the path to log management nirvana? Attend &quot;'Worst Practices' of Log Management&quot; presentation by LogLogic's Logging Evangelist Dr Anton Chuvakin that covers all the things that can go wrong while planning, evaluating, deploying and running a log management solution. Insufficient planning, unrealistic expectations, choosing tools on price alone, lack of logging configuration guidance are among such &quot;worst practices.&quot; Each common &quot;worst practice&quot; will be accompanied by suggestions to avoid the errors and do things correctly! Everybody touts &quot;best practices&quot;, but this is the place to learn how to avoid the opposite - and have fun in the process.</em></p>  <p>if you want to meet, drop me an email/call or just show up for &quot;lunch and learn.&quot; Unfortunately, I am going back right after my presentation tomorrow...</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Ets4bJ"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Ets4bJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=WzVtJJ"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=WzVtJJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=xVtnNJ"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=xVtnNJ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/343116514" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 15:01:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/log management nirvana">log management nirvana</category>
      <category domain="http://securityratty.com/tag/log management solution">log management solution</category>
      <category domain="http://securityratty.com/tag/worst practices">worst practices</category>
      <category domain="http://securityratty.com/tag/practices">practices</category>
      <category domain="http://securityratty.com/tag/anton chuvakin">anton chuvakin</category>
      <category domain="http://securityratty.com/tag/chuvakin">chuvakin</category>
      <category domain="http://securityratty.com/tag/lunch">lunch</category>
      <category domain="http://securityratty.com/tag/loglogic lunch">loglogic lunch</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/343116514/at-sansfire-2008-in-washington-dc.html">At SANSFIRE 2008 in Washington, DC</source>
    </item>
  </channel>
</rss>
