<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: spire]]></title>
    <link>http://securityratty.com/tag/spire</link>
    <description></description>
    <pubDate>Sun, 03 Feb 2008 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Links for 2008-07-01 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/8f3c8a363be11b86e054f8bbcb357630</link>
      <guid>http://securityratty.com/article/8f3c8a363be11b86e054f8bbcb357630</guid>
      <description><![CDATA[The Forrester Blog For Security &amp; Risk Professionals
GRC - Why Its of LIMITED Interest to Me Mark Curphey - SecurityBuddha.com
Spire Security Viewpoint: Top Ten Strategic Security Metrics
Log...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://blogs.forrester.com/srm/2008/06/it-grc-who-is-a.html">The Forrester Blog For Security &amp; Risk Professionals</a></li>
<li><a href="http://securitybuddha.com/2008/06/10/grc-why-its-of-limited-interest-to-me/">GRC - Why It&rsquo;s of LIMITED Interest to Me &laquo; Mark Curphey - SecurityBuddha.com</a></li>
<li><a href="http://spiresecurity.typepad.com/spire_security_viewpoint/2008/07/top-ten-strategic-security-metrics.html">Spire Security Viewpoint: Top Ten Strategic Security Metrics</a></li>
<li><a href="http://technology.inc.com/managing/articles/200806/logs.html?partner=rss-alert">Log Management: What's in Your Log Files? -- log management -- LogLogic -- log maintenance</a></li>
<li><a href="http://bgidps.typepad.com/bgidps/2008/06/identity-manage.html">Burton Group Identity Blog: Identity Management in Retrograde Motion: Thoughts from Burton Group Catalyst North America 2008</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/324598654" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spire security viewpoint">spire security viewpoint</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/strategic security metrics">strategic security metrics</category>
      <category domain="http://securityratty.com/tag/catalyst north america">catalyst north america</category>
      <category domain="http://securityratty.com/tag/burton">burton</category>
      <category domain="http://securityratty.com/tag/retrograde motion">retrograde motion</category>
      <category domain="http://securityratty.com/tag/log maintenance">log maintenance</category>
      <category domain="http://securityratty.com/tag/mark curphey">mark curphey</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/324598654/anton18">Links for 2008-07-01 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-05-12 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/49c9a25cc0ab8842198665f6ed7eb929</link>
      <guid>http://securityratty.com/article/49c9a25cc0ab8842198665f6ed7eb929</guid>
      <description><![CDATA[Senate Votes to Prevent Genetic Discrimination in the Workplace | Privacy Digest
Spire Security Viewpoint: The Best Virtualization Joke Ever
The Forrester Blog For Security &amp; Risk Professionals...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://www.privacydigest.com/2008/05/12/senate+votes+prevent+genetic+discrimination+workplace">Senate Votes to Prevent Genetic Discrimination in the Workplace | Privacy Digest</a></li>
<li><a href="http://spiresecurity.typepad.com/spire_security_viewpoint/2008/05/the-best-virtua.html">Spire Security Viewpoint: The Best Virtualization Joke Ever...</a></li>
<li><a href="http://blogs.forrester.com/srm/2008/04/infosec-2008-se.html">The Forrester Blog For Security &amp; Risk Professionals</a><br/>
Visionary folks see this promised land of information security and risk management being in the green valley of business-driven risk management, where data, identity, policy, and compliance are crucial cities (elements).</li>
<li><a href="http://www.secureconsulting.net/2008/05/reflections_on_the_2008_rsa_co.html">Reflections on the 2008 RSA Conference (The Falcon's View)</a></li>
<li><a href="http://riskmanagementinsight.com/riskanalysis/?p=351">Communicating about risk - part 1 | RiskAnalys.is</a></li>
<li><a href="http://www.schneier.com/blog/archives/2008/05/third_annual_mo_2.html">Schneier on Security: Third Annual Movie-Plot Threat Contest Semi-Finalists</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/289183764" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 12 May 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/spire security viewpoint">spire security viewpoint</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/prevent genetic discrimination">prevent genetic discrimination</category>
      <category domain="http://securityratty.com/tag/annual movie-plot threat">annual movie-plot threat</category>
      <category domain="http://securityratty.com/tag/rsa conference">rsa conference</category>
      <category domain="http://securityratty.com/tag/forrester blog">forrester blog</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/289183764/anton18">Links for 2008-05-12 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-02-25 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/75fa782b9dd4787b807e14ade0da9292</link>
      <guid>http://securityratty.com/article/75fa782b9dd4787b807e14ade0da9292</guid>
      <description><![CDATA[Security and Risk Management Strategies Blog: Prospects Brightening for a Common Event Standard
You want a platform? We got your platform right here, buddy. - Splunk Dev
Category:OWASP XML Security...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://srmsblog.burtongroup.com/2008/02/prospects-brigh.html">Security and Risk Management Strategies Blog: Prospects Brightening for a Common Event Standard</a></li>
<li><a href="http://dev.splunk.com/2008/02/22/you-want-a-platform-we-got-your-platform-right-here-buddy/">You want a platform? We got your platform right here, buddy. - Splunk Dev</a></li>
<li><a href="http://www.owasp.org/index.php/Category:OWASP_XML_Security_Gateway_Evaluation_Criteria_Project_Latest">Category:OWASP XML Security Gateway Evaluation Criteria Project Latest - OWASP</a><br/>
Section 3 - Audit Logging

3.1 Describe the audit logging input and output options

3.2 Describe log analysis tools

3.3 Describe security event notification options

3.4 Where and how is logging integrated into XSG?

3.4.1 How are the logs secu</li>
<li><a href="http://ravichar.blogharbor.com/blog/_archives/2008/2/18/3530987.html">Musings on Information Security :: Application Due Care</a><br/>
Often I hear phrases such as &quot;if the application is truly built secure inside-out, then there is no need for other security layers&quot;. Truly secure application is a far fetched statement. 

1. What is the application made of? - Complexity.
2. How was the</li>
<li><a href="http://www.secureworks.com/research/newsletter/2008/02/?year=2008&month=02#log">Log Management Explained; Aberdeen Featured Report; Web Malicious Code; SecureFacts: Log Management and Log Retention - Research - Managed, Monitored, On-Demand Security Services Provider</a><br/>
Log Management consists of two core processes: Log Monitoring and Log Retention. The following graphic illustrates the major steps in each process:</li>
<li><a href="http://www.security-works.com/blog/2008/02/gartner-it-grc-predictions.html">practical risk management: Gartner IT GRC Predictions</a></li>
<li><a href="http://www.security-works.com/blog/2008/01/2008-year-of-it-risk-management.html">practical risk management: 2008 - The Year of IT Risk Management?</a></li>
<li><a href="http://spiresecurity.typepad.com/spire_security_viewpoint/2008/02/another-envelop.html">Spire Security Viewpoint: Another Envelope: Vulnerability Growth Rates</a><br/>
Calculations:

    * [C1] Number of new lines of code created every day -- 2m * 25 = 50 million [A1]*[A2]
    * [C2] Number of new vulnerabilities created every day -- 50m / 10k = 5,000 [C1]/[A3]
    * [C3] % of new vulnerabilities eventually found --</li>
<li><a href="http://www.esj.com/Enterprise/article.aspx?EditorialsID=2956">Enterprise Systems | IT and Compliance: 5 Big Predictions for 2008</a></li>
<li><a href="http://taosecurity.blogspot.com/2008/02/first-they-came-for-bandwidth.html">TaoSecurity: First They Came for Bandwidth...</a><br/>
Overall I see a progression like the following. (I thought I posted this before but I cannot find it!)


    * First they came for bandwidth... These are attacks on availability, executed via denial of service attacks starting in the mid 1990's and mon</li>
<li><a href="http://theresaneil.wordpress.com/2008/01/29/seek-or-show-two-design-paradigms-for-lots-of-data/">Seek or Show: Two Design Paradigms for Lots of Data &laquo; Theresaneil&rsquo;s Weblog</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/241310102" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 25 Feb 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/log">log</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/spire security viewpoint">spire security viewpoint</category>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/practical risk management">practical risk management</category>
      <category domain="http://securityratty.com/tag/application due care">application due care</category>
      <category domain="http://securityratty.com/tag/application">application</category>
      <category domain="http://securityratty.com/tag/security layers">security layers</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/241310102/anton18">Links for 2008-02-25 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-02-03 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/7f7dff8593df44531f229cf082de8d10</link>
      <guid>http://securityratty.com/article/7f7dff8593df44531f229cf082de8d10</guid>
      <description><![CDATA[Spire Security Viewpoint: The Other Side of...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://spiresecurity.typepad.com/spire_security_viewpoint/2008/02/the-other-side.html">Spire Security Viewpoint: The Other Side of Privacy</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/228723283" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 03 Feb 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spire security viewpoint">spire security viewpoint</category>
      <category domain="http://securityratty.com/tag/privacy">privacy</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/228723283/anton18">Links for 2008-02-03 [del.icio.us]</source>
    </item>
  </channel>
</rss>
