<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: pms]]></title>
    <link>http://securityratty.com/tag/pms</link>
    <description></description>
    <pubDate>Tue, 11 Sep 2007 19:18:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[On Inspiration and Security]]></title>
      <link>http://securityratty.com/article/af4d15d6025dceda15351079f12284de</link>
      <guid>http://securityratty.com/article/af4d15d6025dceda15351079f12284de</guid>
      <description><![CDATA[First, I have a horrible revelation to make: I never held CEOs in much regard. For example, if you go to a CEO keynote at a security conference (RSA comes to mind ), you can be pretty much assured...]]></description>
      <content:encoded><![CDATA[<p>First, I have a horrible revelation to make: I never held CEOs in much regard. For example, if you go to “a CEO keynote” at a security conference (RSA <a href="http://chuvakin.blogspot.com/2008/04/rsa-2008-summary-and-reflections.html">comes to mind</a>), you can be&#160; pretty much assured that you’d get a boring, bland and “content-free” speech which summarizes to 1 word: nothing. Actually, it is 0 words :-)&#160; Similarly, even though I knew what CEOs did (tell people what to do, give speeches so that employees work better, help sales sell, interfere with engineers’ engineering :-), etc), but always regarded them as people regarded <a href="http://en.wikipedia.org/wiki/Political_commissar">“party commissars” back in the Soviet Union days</a>: as folks who give rosy speeches hardly anybody believes in and who show charts with upward trending curves (e.g. “Bullshit volume per employee per quarter is UP 34.6%!!!” :-)) To better understand this point read the famous book “<a href="http://www.amazon.com/Business-People-Speak-Like-Idiots/dp/0743269098">Why Business People Speak Like Idiots: A Bullfighter's Guide</a>” :-)</p>  <p>So, my dear readers, imagine how amazed I was to find myself being truly inspired by my CEO,&#160; for the first time in my working life! Philippe’s “no-B.S.” approach definitely works for me. I listened to his speech at a company meeting last week and – I am serious! – that was the most interesting, visionary AND inspiring speech that I’ve heard in a long time. It was clear what we’ve been doing, what worked, what didn’t and what we need to be doing and why it will work.</p>  <p>I already learned more than a few things from him just by listening to him&#160; speak or conduct a meeting (or by watching him beat up a job candidate…). For example,&#160; one CAN be “positive, but not marketing-ish,” even if situation is difficult. If one has an issue, one has to face it with no sugarcoating rather than ’play’ positive and pretend the issue is not there. One can have BOTH a driving vision AND be attentive to customers. One CAN release something when it is ready, not a year before :-) Etc, etc.</p>  <p>Finally, while <em>some</em> choose to lay people off, we at <a href="http://www.qualys.com">Qualys</a>&#160; <a href="http://www.qualys.com/company/careers/">ARE HIRING</a>!&#160; <a href="http://www.qualys.com/company/careers/">Come join us</a> and help build the SaaS security platform that actually works! Specifically, we are looking for <a href="http://www.qualys.com/company/careers/sales/">TAMs</a> (kind like an SE, but better :-)), <a href="http://www.qualys.com/company/careers/marketing/">PMs</a> and <a href="http://www.qualys.com/company/careers/engineering/">a lot of engineers</a>.</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=kFQCN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=kFQCN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=makoN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=makoN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=xnyHN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=xnyHN" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/456479091" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 11:07:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/business people">business people</category>
      <category domain="http://securityratty.com/tag/speech">speech</category>
      <category domain="http://securityratty.com/tag/content-free speech">content-free speech</category>
      <category domain="http://securityratty.com/tag/ceo keynote">ceo keynote</category>
      <category domain="http://securityratty.com/tag/speeches">speeches</category>
      <category domain="http://securityratty.com/tag/ceos">ceos</category>
      <category domain="http://securityratty.com/tag/positive">positive</category>
      <category domain="http://securityratty.com/tag/held ceos">held ceos</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/456479091/on-inspiration-and-security.html">On Inspiration and Security</source>
    </item>
    <item>
      <title><![CDATA[Dedicated to All PMs Out There]]></title>
      <link>http://securityratty.com/article/739788c64f71326b08b839e5515ee124</link>
      <guid>http://securityratty.com/article/739788c64f71326b08b839e5515ee124</guid>
      <description><![CDATA[A must read on product management... funny as life

You Might be a PM if
someone asks about your weekend plans and your answer consists of a list of Pri ones, twos, and threes
youve ever ended a...]]></description>
      <content:encoded><![CDATA[<a href="http://securitybuddha.com/2008/09/30/you-might-be-a-pm-if/">A must read</a> on product management... funny as life :-)<br /><br />"<a href="http://securitybuddha.com/2008/09/30/you-might-be-a-pm-if/" rel="bookmark" title="Permanent Link: You Might be a PM if…">You Might be a PM if…</a>    <!-- IF YOU'RE GOING TO USE GOOGLE ADS, THIS IS A GOOD PLACE TO PUT THEM -->           <p>  · … someone asks about your weekend plans and your answer consists of a list of Pri ones, twos, and threes.</p><p>· … you’ve ever ended a relationship using a PowerPoint presentation."</p><p>(<a href="http://securitybuddha.com/2008/09/30/you-might-be-a-pm-if/">more</a>)<br /></p><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=6SFfM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=6SFfM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=xuaQM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=xuaQM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=tFgDM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=tFgDM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/408639873" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 10:54:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/product management">product management</category>
      <category domain="http://securityratty.com/tag/powerpoint presentation">powerpoint presentation</category>
      <category domain="http://securityratty.com/tag/answer consists">answer consists</category>
      <category domain="http://securityratty.com/tag/weekend plans">weekend plans</category>
      <category domain="http://securityratty.com/tag/funny">funny</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <category domain="http://securityratty.com/tag/relationship">relationship</category>
      <category domain="http://securityratty.com/tag/threes">threes</category>
      <category domain="http://securityratty.com/tag/pri">pri</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/408639873/dedicated-to-all-pms-out-there.html">Dedicated to All PMs Out There</source>
    </item>
    <item>
      <title><![CDATA[STRIDE chart]]></title>
      <link>http://securityratty.com/article/96a819221c5280509ecb41c2d92d2eac</link>
      <guid>http://securityratty.com/article/96a819221c5280509ecb41c2d92d2eac</guid>
      <description><![CDATA[Adam Shostack here

I've been meaning to talk more about what I actually do, which is help the teams within Microsoft who are threat modeling (for our boxed software) to do their jobs better. Better...]]></description>
      <content:encoded><![CDATA[<P><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA">Adam Shostack here.</SPAN></P>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p><FONT face=calibri size=3>&nbsp;</FONT></o:p></P>
<P><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA">I've been meaning to talk more about what I actually do, which is help the teams within Microsoft who are threat modeling (for our boxed software) to do their jobs better.&nbsp; Better means faster, cheaper or more effectively.&nbsp; <SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA">There are good reasons to optimize for different points on that spectrum (of better/faster/cheaper) <SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA">at different times in different products.&nbsp;&nbsp; <SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA">One of the things that I've learned is that we ask a lot of developers, testers, and PMs here.&nbsp; They all have some exposure to security, but terms that I've been using for years are often new to them.</SPAN></SPAN></SPAN></SPAN></P>
<P><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA">Larry Osterman is a <A class="" title="longtime MS veteran" href="http://channel9.msdn.com/ShowPost.aspx?PostID=27667" mce_href="http://channel9.msdn.com/ShowPost.aspx?PostID=27667">longtime MS veteran</A>, currently working in Windows audio.&nbsp; He's been a threat modeling advocate for years, and <SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA">has been blogging a lot about our new processes, and describes in great detail the STRIDE per element process.&nbsp;&nbsp; His recent posts are "<A href="http://blogs.msdn.com/larryosterman/archive/2007/08/30/threat-modeling-once-again.aspx" mce_href="http://blogs.msdn.com/larryosterman/archive/2007/08/30/threat-modeling-once-again.aspx">Threat Modeling, Once Again</A>," "<A href="http://blogs.msdn.com/larryosterman/archive/2007/08/31/threat-modeling-again-drawing-the-diagram.aspx">Threat modeling again. Drawing the diagram</A>," "<A href="http://blogs.msdn.com/larryosterman/archive/2007/09/04/threat-modeling-again-stride.aspx">Threat Modeling Again: STRIDE</A>," "<A href="http://blogs.msdn.com/larryosterman/archive/2007/09/05/threat-modeling-again-stride-mitigations.aspx">Threat modeling again, STRIDE mitigations</A>," "<A href="http://blogs.msdn.com/larryosterman/archive/2007/09/07/threat-modeling-again-what-does-stride-have-to-do-with-threat-modeling.aspx">Threat modeling again, what does STRIDE have to do with threat modeling</A>," "<A href="http://blogs.msdn.com/larryosterman/archive/2007/09/10/threat-modeling-again-stride-per-element.aspx">Threat modeling again, STRIDE per element</A>," "<A href="http://blogs.msdn.com/larryosterman/archive/2007/09/11/threat-modeling-again-threat-modeling-playsound.aspx">Threat modeling again, threat modeling playsound</A>."</SPAN></SPAN></SPAN></SPAN></SPAN></P>
<P><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA">I wanted to chime in and offer up this handy chart that we use.&nbsp; It's part of how we teach people to go from a diagram to a set of threats.&nbsp; We used to ask them to brainstorm, and have discovered that that works a lot better with some structure.</SPAN></SPAN></SPAN></SPAN></SPAN></P>
<P><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><o:p><FONT face=calibri size=3></FONT></o:p>&nbsp;</P>
<P>
<TABLE class=MsoNormalTable style="BORDER-COLLAPSE: collapse; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 0in 0in 0in" cellSpacing=0 cellPadding=0 border=0 class="MsoNormalTable">
<TBODY>
<TR style="mso-yfti-irow: 0; mso-yfti-firstrow: yes">
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 0.1in; BORDER-TOP: white 1pt solid; PADDING-LEFT: 0.1in; BACKGROUND: #4f81bd; PADDING-BOTTOM: 0.05in; BORDER-LEFT: white 1pt solid; PADDING-TOP: 0.05in; BORDER-BOTTOM: white 3pt solid" vAlign=top width=189>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Property </FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 0.1in; BORDER-TOP: white 1pt solid; PADDING-LEFT: 0.1in; BACKGROUND: #4f81bd; PADDING-BOTTOM: 0.05in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.05in; BORDER-BOTTOM: white 3pt solid" vAlign=top width=147>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Threat </FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 0.1in; BORDER-TOP: white 1pt solid; PADDING-LEFT: 0.1in; BACKGROUND: #4f81bd; PADDING-BOTTOM: 0.05in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.05in; BORDER-BOTTOM: white 3pt solid" vAlign=top width=197>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Definition </FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 0.1in; BORDER-TOP: white 1pt solid; PADDING-LEFT: 0.1in; BACKGROUND: #4f81bd; PADDING-BOTTOM: 0.05in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.05in; BORDER-BOTTOM: white 3pt solid" vAlign=top width=395>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Example </FONT></P></TD></TR>
<TR style="mso-yfti-irow: 1">
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: white 1pt solid; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=189>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Authentication</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=147>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=calibri><B>S</B>poofing</FONT></FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=197>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=calibri>Impersonating something or someone else. </FONT></FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=395>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=calibri>Pretending to be any of billg, microsoft.com or ntdll.dll </FONT></FONT></P></TD></TR>
<TR style="mso-yfti-irow: 2">
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: white 1pt solid; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=189>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Integrity</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=147>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=calibri><B>T</B>ampering</FONT></FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=197>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Modifying data or code</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=395>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Modifying a DLL on disk or DVD, or a packet as it traverses the LAN.</FONT></P></TD></TR>
<TR style="mso-yfti-irow: 3">
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: white 1pt solid; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=189>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Non-repudiation</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=147>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=calibri><B>R</B>epudiation</FONT></FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=197>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Claiming to have not performed an action.</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=395>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>“I didn’t send that email,” “I didn’t modify that file,” “I <I>certainly</I> didn’t visit that web site, dear!”</FONT></P></TD></TR>
<TR style="mso-yfti-irow: 4">
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: white 1pt solid; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=189>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Confidentiality</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=147>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=calibri><B>I</B>nformation Disclosure</FONT></FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=197>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Exposing information to someone not authorized to see it</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=395>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Allowing someone to read the Windows source code; publishing a list of customers to a web site.</FONT></P></TD></TR>
<TR style="HEIGHT: 69.8pt; mso-yfti-irow: 5">
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: white 1pt solid; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=189>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Availability</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=147>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=calibri><B>D</B>enial of Service</FONT></FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=197>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Deny or degrade service to users</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=395>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Crashing Windows or a web site, sending a packet and absorbing seconds of CPU time, or routing packets into a black hole.</FONT></P></TD></TR>
<TR style="HEIGHT: 55.45pt; mso-yfti-irow: 6; mso-yfti-lastrow: yes">
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: white 1pt solid; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=189>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Authorization</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BORDER-LEFT-COLOR: #f0f0f0; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-BOTTOM: white 1pt solid" vAlign=top width=147>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=calibri><B>E</B>levation of Privilege</FONT></FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=197>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Gain capabilities without proper authorization</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=395>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Allowing a remote internet user to run commands is the classic example, but going from a limited user to admin is also EoP.</FONT></P></TD></TR></TBODY></TABLE></P>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><o:p><FONT face=calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><o:p><FONT size=3></FONT></o:p>&nbsp;</P>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><o:p><FONT face=calibri size=3>[Update: fixed the table so it displays&nbsp;all four columns.]&nbsp;</FONT></o:p></P></SPAN></SPAN></SPAN></SPAN></SPAN>
<P><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"></SPAN></SPAN></SPAN></SPAN></SPAN><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA">&nbsp;</P></SPAN></SPAN></SPAN></SPAN></SPAN><img src="http://blogs.msdn.com/aggbug.aspx?PostID=4872732" width="1" height="1">]]></content:encoded>
      <pubDate>Tue, 11 Sep 2007 19:18:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/threat">threat</category>
      <category domain="http://securityratty.com/tag/stride">stride</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/windows source code">windows source code</category>
      <category domain="http://securityratty.com/tag/web site">web site</category>
      <category domain="http://securityratty.com/tag/stride mitigations">stride mitigations</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <category domain="http://securityratty.com/tag/user">user</category>
      <category domain="http://securityratty.com/tag/remote internet user">remote internet user</category>
      <source url="http://blogs.msdn.com/sdl/archive/2007/09/11/stride-chart.aspx">STRIDE chart</source>
    </item>
  </channel>
</rss>
