<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: topics]]></title>
    <link>http://securityratty.com/tag/topics</link>
    <description></description>
    <pubDate>Tue, 29 Jul 2008 13:56:58 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Monthly Blog Round-Up - August 2008]]></title>
      <link>http://securityratty.com/article/da35c1254d3a39679f5bed9406a6aded</link>
      <guid>http://securityratty.com/article/da35c1254d3a39679f5bed9406a6aded</guid>
      <description><![CDATA[I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see...]]></description>
      <content:encoded><![CDATA[<p>I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. This is an attempt to remind people of useful content!</p>  <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">&quot;Security Warrior&quot; blog</a> </strong>round-up of top 5 popular posts and topics.</p>  <ol>   <li>In a bizarre twist of fate (maybe driven by <a href="http://chuvakin.blogspot.com/2008/08/poll-9-how-much-log-security-do-you.html">my latest poll</a>), the &quot;<a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Your Logs</a>&quot; came up as #1 most popular post in August.&#160; The analysis of said <a href="http://chuvakin.blogspot.com/2008/08/poll-9-how-much-log-security-do-you.html">log security poll</a> is coming up tomorrow. BTW, see <a href="http://chuvakin.blogspot.com/search/label/poll">my other logging polls</a>:&#160; <a href="http://chuvakin.blogspot.com/2008/05/poll-8-log-analysis-context.html">poll #8</a> that covered context data for log analysis <a href="http://chuvakin.blogspot.com/2008/06/logging-poll-8-analysis-needed-log.html">is analyzed here</a> and a controversial <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">Windows Log Collection Poll</a></u> (which is <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">a poll #7</a></u>)&#160; and <u><a href="http://chuvakin.blogspot.com/2008/03/logging-poll-6-logs-do-you-look-at.html">poll #6</a></u> about logs that people actually review and <a href="http://chuvakin.blogspot.com/2008/02/logging-poll-5-logging-challenges.html">poll #5</a> about logging challenges. </li>    <li>Next up is my post &quot;<a href="http://chuvakin.blogspot.com/2008/07/log-management-day-1.html">Log Management - Day 1</a>,&quot; which talks about the very first thing you do when embarking on a journey to <a href="http://www.loglogic.com">log management</a>. </li>    <li>Still burning hot is a post with my irreverent comments on a Terry Childs saga. Namely, &quot;<a href="http://chuvakin.blogspot.com/2008/07/on-doomsaying-terry-childs-case.html">On Doomsaying (Terry Childs case)</a>&quot;, &quot;<a href="http://chuvakin.blogspot.com/2008/07/on-doomsaying-terry-childs-case.html">So ... Am I? Maybe I Am!</a>&quot; and &quot;<a href="http://chuvakin.blogspot.com/2008/07/admins-good-guys-or-am-not-idiot.html">Admins , Good Guys or &quot;I am NOT an Idiot!&quot;</a>&quot; </li>    <li>Somewhat predictably, PCI compliance is all the rage again with <a href="http://chuvakin.blogspot.com/2008/08/run-through-pci-dss-12-changes.html">1.2 coming out soon</a>. So, <a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">MUST-DO Logging for PCI?</a> post was again propelled to a place in my monthly Top5 list. It discusses the fact that there is no &quot;easy list&quot; of what you MUST do to comply.</li>    <li>Finally, my post &quot;<a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or &quot;Raffy, You Killed SIM!&quot;</a>&quot;. It is both humorous and sadly true (and <a href="http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/export/home/httpd/htdocs/reviews/2008/063008-test-siem.html&amp;pagename=/reviews/2008/063008-test-siem.html&amp;pageurl=http://www.networkworld.com/reviews/2008/063008-test-siem.html&amp;site=security">backed up by other sources</a>)</li> </ol>  <p>See you in September,&#160; when .... ah, come on! I will tell you later :-)</p>  <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/08/monthly-blog-round-up-july-2008.html">Monthly Blog Round-Up - July 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/07/monthly-blog-round-up-june-2008.html">Monthly Blog Round-Up - June 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a> </li>    <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a> </li> </ul>  <p>&#160;</p>  <p></p>  <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7192e29b-e335-4630-8b0b-dc37806d54ee" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>,<a href="http://technorati.com/tags/security" rel="tag">security</a>,<a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>,<a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=uVPfyL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=uVPfyL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=NrADzL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=NrADzL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=njcwZL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=njcwZL" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/383511875" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 08:22:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/log security poll">log security poll</category>
      <category domain="http://securityratty.com/tag/poll">poll</category>
      <category domain="http://securityratty.com/tag/popular post">popular post</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/383511875/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - August 2008</source>
    </item>
    <item>
      <title><![CDATA[Quick Notes On Getting Bart's PE/Ultimate Boot CD For Windows To Boot From A Thumb Drive]]></title>
      <link>http://securityratty.com/article/e2b301a3599ff6a5e09d0b6b7c537bcc</link>
      <guid>http://securityratty.com/article/e2b301a3599ff6a5e09d0b6b7c537bcc</guid>
      <description><![CDATA[Just what the title says, it's just a lot easier to carry around a UFD on you keychain than it is a CD. I use mine for password resets, removing spyware and other odds and ends
Also, on other security...]]></description>
      <content:encoded><![CDATA[Just what the title says, it's just a lot easier to carry around a UFD on 
you keychain than it is a CD. I use mine for password resets, removing 
spyware and other odds and ends.<p>Also, on other security topics check out 
my buddy <a href="http://leebaird.com/Me/iPhone.html">Lee's page on hacking 
apps for the iPhone / iPod Touch</a>.
<p><a href="http://feeds.feedburner.com/~a/IrongeeksSecuritySite?a=IJzmDB"><img src="http://feeds.feedburner.com/~a/IrongeeksSecuritySite?i=IJzmDB" border="0"></img></a></p><img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/382813560" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 17:07:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security topics check">security topics check</category>
      <category domain="http://securityratty.com/tag/ipod touch">ipod touch</category>
      <category domain="http://securityratty.com/tag/lot easier">lot easier</category>
      <category domain="http://securityratty.com/tag/cd">cd</category>
      <category domain="http://securityratty.com/tag/buddy lee">buddy lee</category>
      <category domain="http://securityratty.com/tag/password resets">password resets</category>
      <category domain="http://securityratty.com/tag/page">page</category>
      <category domain="http://securityratty.com/tag/spyware">spyware</category>
      <category domain="http://securityratty.com/tag/apps">apps</category>
      <source url="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~3/382813560/i.php">Quick Notes On Getting Bart's PE/Ultimate Boot CD For Windows To Boot From A Thumb Drive</source>
    </item>
    <item>
      <title><![CDATA[PCI V1.2, a good start but still not enough]]></title>
      <link>http://securityratty.com/article/b3d495f448e9ce368683c921d97b7c28</link>
      <guid>http://securityratty.com/article/b3d495f448e9ce368683c921d97b7c28</guid>
      <description><![CDATA[Blogger: Randall Gamby
Two weeks ago the PCI Security Standards Council released the preliminary details of the PCI Data Security Standard (DSS) V1.2 thats due out in October. While many Analysts and...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Randall Gamby</p>

<p>Two weeks ago the PCI Security Standards Council released the preliminary details of the <a href="https://www.pcisecuritystandards.org/pdfs/pci_dss_summary_of_changes_v1-2.pdf">PCI Data Security Standard (DSS) V1.2</a> that’s due out in October.&nbsp; While many Analysts and Reporters have already written on the topic (I’ll be releasing an extensive update on Burton Group’s PCI coverage around the October release date), they really haven’t commented on what’s still not been addressed by the standard for enterprises still working on attaining compliance.</p>

<p>While I applaud the PCI Security Standards Council in further clarifying and adjusting the standard, a lot of work still needs to be done.&nbsp; I receive about one or two PCI questions a week from our clients and they seem to revolve around a couple of topics I’ve yet to see addressed:</p>

<ul><li><strong>Guidelines for selecting a Qualified Security Assessor (QSA)</strong> – while there are a large number of QSA organizations listed on the PCI Security Standards Council web site; they can’t really recommend a particular QSA for an individual organization.&nbsp; This leads a lot of organizations to struggle with determining what criteria they should use in selecting a QSA for their certification.</li>

<li><strong>The role of the QSA</strong> – organizations are also still trying to understand the role of a QSA.&nbsp; Should they get a QSA involved in the gap and remediation process in advance of certification?&nbsp; If so, should it be the same QSA that will do their certification (knowing there’s a risk that the QSA will be pre-disposed to only care about certain vulnerabilities)?</li>

<li><strong>Industry-specific best practices</strong> – while each organization may have different infrastructures, in general, most industries try to be consistent with the major functions they perform.&nbsp; So are credit card transactions handled differently between say, a major retailer with 10,000 POS systems and an insurance company that has hundreds of independent agents receiving remittances? Probably, so what are best practices around these industry-specific configurations?</li>

<li><strong>Virtualized environments</strong> – while the PCI Security Standards Council recognizes that some organizations have moved to virtual services for consolidation and management, the DSS really doesn’t provide guidelines for QSAs to evaluate and certify these environments.</li>

<li><strong>Monitoring and audit</strong> – while the PCI DSS recommends minimum timeframes for scanning, doing pen tests, etc. what are the real levels of monitoring and audit needed for ensuring security?&nbsp; With the Hannaford and Okemo breaches that occurred (both where PCI compliant), neither discovered the problem until months after the breaches had happened.&nbsp; So identifying what should be scanned and tested and if some of this should be on a continuous basis still requires refinement.</li>

<li><strong>PCI as part of an overall security model</strong> – what are the best practices around merging PCI security requirements into an enterprise’s overall security model?&nbsp; Should it be maintained separately? Should some components be integrated with similar security mechanisms?&nbsp; Should PCI be at the top of the security model and other configurations be based upon its requirements?&nbsp; There are really no answers coming forth on this topic and the other question is where will they come from? Surely enterprises won’t expect the PCI Security Standards Council to tell them how to run their security services.</li></ul>

<p>I will be providing Burton Group’s perspective on most of these questions in my upcoming report, but rather than relying on third parties to resolve these, I’d hope that the PCI Security Standards Council will be able to continue to provide answers to the questions they can in future updates, and releases, of the PCI DSS.</p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/382655858" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 12:56:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security assessor">security assessor</category>
      <category domain="http://securityratty.com/tag/security model">security model</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/dss">dss</category>
      <category domain="http://securityratty.com/tag/pci security requirements">pci security requirements</category>
      <category domain="http://securityratty.com/tag/requirements">requirements</category>
      <category domain="http://securityratty.com/tag/qsa">qsa</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/382655858/pci-v12-a-good.html">PCI V1.2, a good start but still not enough</source>
    </item>
    <item>
      <title><![CDATA[inNOvation]]></title>
      <link>http://securityratty.com/article/1cd8dbd3a11c8ad7a25d72724c2bece8</link>
      <guid>http://securityratty.com/article/1cd8dbd3a11c8ad7a25d72724c2bece8</guid>
      <description><![CDATA[It is amazing to me that in a seemingly tight Presidential race that NEITHER candidate has made innovation an issue, this article from the NYT on former Cisco CTO Judy Estrin

I am generally not an...]]></description>
      <content:encoded><![CDATA[<p>It is amazing to me that in a seemingly tight Presidential race that NEITHER candidate has made innovation an issue, this <a href="http://www.nytimes.com/2008/09/01/technology/01estrin.html">article</a> from the NYT on former Cisco CTO Judy Estrin:</p><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Georgia; font-size: 15px; line-height: 22px; ">“I am generally not an alarmist, but I have become more and more concerned about the state of our country and its innovation,” she said last week, explaining why she wrote her book, “Closing the Innovation Gap,” which arrives in bookstores Tuesday. “We have a national innovation deficit.”</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Georgia; font-size: 15px; line-height: 22px;"><br /></span><span style="font-family: Georgia; font-size: 15px; line-height: 22px; ">Ms. Estrin’s book is the latest call to action during the last several years by scientists, technologists and political leaders worried about the country’s future competitiveness in technology.</span><br /><span style="font-family: Georgia; font-size: 15px; line-height: 22px; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Georgia; font-size: 15px; line-height: 22px; ">In 2005, the National Academies published “Rising Above the Gathering Storm,” a report requested by Congress, which found that federal financing of research in the physical sciences was 45 percent less in 2004 than in 1976 and that 93 percent of students in grades five through eight learn science from teachers who do not hold degrees or certifications in the topics.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Georgia; font-size: 15px; line-height: 22px;">...</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Georgia; font-size: 15px; line-height: 22px;">“There is a remarkable telescoping in of vision and an unwillingness to make long-term bets,” said Vinton G. Cerf, the chief Internet evangelist at&#160;<a href="http://topics.nytimes.com/top/news/business/companies/google_inc/index.html?inline=nyt-org" style="color: #004276; text-decoration: underline; " title="More information about Google Inc">Google</a>.<br /></span></p></blockquote><p><span style="font-family: Georgia; font-size: 15px; line-height: 22px;"><br />Geez, its like no one ever read </span><a href="http://www.edgeperspectives.com/index3.shtml">&quot;The Only Sustainable Edge&quot;</a><span style="font-family: Georgia; font-size: 15px; line-height: 22px;"> or something...<br /></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Georgia; font-size: 15px; line-height: 22px;"><br /></span></p></blockquote>]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 10:20:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/innovation">innovation</category>
      <category domain="http://securityratty.com/tag/national innovation deficit">national innovation deficit</category>
      <category domain="http://securityratty.com/tag/innovation gap">innovation gap</category>
      <category domain="http://securityratty.com/tag/chief internet evangelist">chief internet evangelist</category>
      <category domain="http://securityratty.com/tag/estrins book">estrins book</category>
      <category domain="http://securityratty.com/tag/book">book</category>
      <category domain="http://securityratty.com/tag/countrys future competitiveness">countrys future competitiveness</category>
      <category domain="http://securityratty.com/tag/percent">percent</category>
      <category domain="http://securityratty.com/tag/long-term bets">long-term bets</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/innovation.html">inNOvation</source>
    </item>
    <item>
      <title><![CDATA[Web Services and XML Security Training at OWASP]]></title>
      <link>http://securityratty.com/article/6d12835067b0b2251fdc4b658b6928cc</link>
      <guid>http://securityratty.com/article/6d12835067b0b2251fdc4b658b6928cc</guid>
      <description><![CDATA[I am teaching Web Services and XML Security training at OWASP's AppSec conference in NYC, Sept 22-23. Web services provide the backbone that integrates many things in the enterprise from application...]]></description>
      <content:encoded><![CDATA[<p>I am teaching <a href="http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference_Training#T3._Web_Services_and_XML_Security_-_2-Day_Course_-_Sep_22-23.2C_2008">Web Services and XML Security training</a> at OWASP&#39;s AppSec conference in NYC, Sept 22-23. Web services provide the backbone that integrates many things in the enterprise from application servers, databases, ERP, and CRM. &#160;Increasingly we are seeing Web services in more B2C roles with Rest, Federation and other technologies. The class looks at how Web services applications are built, what are common threats and vulnerabilities in Web services, and how to build your Web services application to defend against them.</p><br /><div>I have often said that OWASP conferences are my favorite ones because they are in depth technically and very practical. I always look forward to teaching at OWASP and the speaker lineup for this conference looks excellent.</div><br /><div>Here is a quick list of tools we have used in past classes<br /></div><br /><div><span style="color: #333333; line-height: 19px; "><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Web Services frameworks</strong><br /><a href="http://incubator.apache.org/cxf/" style="text-decoration: underline; color: #003366; ">Apache CXF</a>&#160;- very interesting open source Web services framework with support for JMS, SOAP, and Rest<br />Apache&#160;<a href="http://ws.apache.org/axis/" style="text-decoration: underline; color: #003366; ">Axis</a>&#160;&amp;&#160;<a href="http://ws.apache.org/axis2/" style="text-decoration: underline; color: #003366; ">Axis2</a><br /><a href="http://en.wikipedia.org/wiki/Windows_Communication_Foundation" style="text-decoration: underline; color: #003366; ">.Net</a><br /><a href="https://metro.dev.java.net/" style="text-decoration: underline; color: #003366; ">Metro</a>&#160;- interesting framework from Sun for interop with WCF</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Identity</strong>&#160;<br /><a href="http://www.pingidentity.com/products/pingfederate.cfm" style="text-decoration: underline; color: #003366; ">PingFederate</a>&#160;- leading federation tool, we&#39;ll look at browser based SSO with SAML<br /><a href="http://www.pingidentity.com/products/web-services.cfm" style="text-decoration: underline; color: #003366; ">PingFederate Web Services</a>&#160;- we&#39;ll look at how to implement a STS in Web services<br /><a href="http://www.bandit-project.org/index.php/Welcome_to_Bandit" style="text-decoration: underline; color: #003366; ">Bandit</a>&#160;-&#160;<a href="http://en.wikipedia.org/wiki/Windows_CardSpace" style="text-decoration: underline; color: #003366; ">Cardspace</a>, authorization, and auditing</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Security Services</strong><br /><a href="http://www.vordel.com/products/vx_gateway/" style="text-decoration: underline; color: #003366; ">VordelSecure</a>&#160;- XML gateway, comprehensive web services security policy creation and enforcement, deploying decentralized security services<br /><a href="http://ws.apache.org/axis2/modules/rampart/1_0/security-module.html" style="text-decoration: underline; color: #003366; ">Apache Ramparts</a><br /><a href="http://www.modsecurity.org/" style="text-decoration: underline; color: #003366; ">modecurity</a></p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Testing</strong><br /><a href="http://www.vordel.com/products/soapbox/" style="text-decoration: underline; color: #003366; ">Soapbox</a>&#160;- web services security testing<br /><a href="http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project" style="text-decoration: underline; color: #003366; ">WebScarab</a>&#160;- web services fuzzing</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Static Analysis</strong><br /><a href="http://www.fortifysoftware.com/products/sca/" style="text-decoration: underline; color: #003366; ">Fortify SC</a>A - how to scan your web services code for security bugs *before* you deploy</p></span><br /><div><span style="color: #333333; line-height: 19px; ">This is just a quick list, new tools are added periodically. If you are using tools of these types in your company you may find it interesting <a href="http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference_Training#T3._Web_Services_and_XML_Security_-_2-Day_Course_-_Sep_22-23.2C_2008">to attend</a>.</span><br /></div><br /><div>Testimontials on past classes<br /><br /><div><span style="font-family: Times; font-size: 16px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; ">&quot;High quality detailed overview of SOA security standards and approaches. Well thought-out and structured presentation.&quot;<br />- Sr. IT Architect, Fortune 10 enterprise<p>&quot;The knowledge and transfer was a great baseline and with the additional resources Gunnar made available, made this one of the best one day classes I&#39;ve taken.&quot;<br />- IT Security Lead, Fortune 10 enterprise</p><p>&quot;This class was a thorough and well-organized trek through the current Web Services Security landscape. Going beyond just describing the standards and the options available in the Web Services Security world, this class discusses real-world use cases and offers implementable solutions, best practices, even vendor choices in several key areas. &#160;This class provided me with actionable tasks that I took back to my project teams the very next day!&quot;<br />-Jesse Aalberg, Sr. Enterprise Application Architect, United Healthcare</p><p>&quot;The class was distinctly focused on Security requirements and the strength and weaknesses of the various solution approaches we could consider. The result of the course was actionable approaches to providing security in our SOA environment.&quot;<br />-Brad Sillman, Director IT Security, Deluxe Corp.</p><p>&quot;Anyone who wants up-to-date information on SOA Security, security standards and best practices should take this class.&quot;<br />-Kevin Beam, Senior Systems Engineer, Union Pacific Railroad</p><p>&quot;Good comprehensive overview of subject, standards, and threats&quot;&#160;<br />- Sr.Security Consultant, Ubizen</p><p>&quot;The class helped me get my head around what &quot;SOA&quot; and WS-Security is really all about&quot;<br />- Mike Zusman, Independent consultant</p><p>&quot;Topics addressed are timely and relevant. Labs are hands-on and help see concepts in action&quot;<br />- Jerry Tan, Systems Analyst, DTCC</p><p>&quot;This class was concise and covered a majority of the problem set my company is looking at and dealing with.&quot;&#160;<br />- Steve Reilley, Technical consultant, Commerce Insurance</p><p>&quot;Excellent two day overview of security topics as related to Web Services.&quot;<br />- Daniel Reznick, Information Security, ADP</p><p>&quot;Issue affecting&#160;<span style="text-decoration: underline;">most</span>&#160;of us today &amp; for those that don&#39;t - will soon. Very necessary education and technology.&quot;<br />Aaron Delashmutt</p><p>&quot;Great class! Effective and relevant teaching in an area without much guidance.&quot;<br />- Mark DiSabato, Senior Information Security Architect, Roche</p><p>&quot;The class cut through jargon to communicate concepts and implementation details.&quot;<br />- Developer, Fortune 100 insurance company</p><p>&quot;Good overview regarding SOA Security. Contains new technology like AMQP and REST&quot;&#160;<br />- Lars Loland, Statoil</p><p>&quot;The course covered what I had to learn about Web services&quot;<br />- Sven Vetsch, Dreamlab Technologies</p><p>&quot;Very good, eye opening especially for websecurity noob.&quot;<br />-Michael Brandon</p><p>&quot;Presenter has very broad and deep technical knowledge on subject. Content: good overview and comparison of SAML and WS-*&quot;<br />- Security consultant, ING</p><p>&quot;Good to learn where our application is vulnerable to attacks and how we can avoid them.&quot;<br />- Application Development Programmer Lead, Fortune 100 Insurance company</p><p>&quot;Entirely thorough overview of technology surrounding the use of web services with a 1 day presentation&quot;<br />- Technical consultant Contextis</p><p>&quot;Gave a good overview of the Web services security environment&quot;<br />- Francesco Degrassi, Emaze Networks</p><p>&quot;A great entry point for securing your web services&quot;<br />- Stig Kluver</p><p>&quot;Lots of good technical information about an emerging area that&#39;s very useful&quot;<br />- Rory McClune, HBOS PLC</p><p>&quot;This class reinforced the importance of software security assurance to me as it lucidly demonstrated why being &#39;behind the firewall&#39; is an outdated concept.&quot;<br />-Senior Support Engineer, Software Security vendor</p><p>&quot;The area of SOA Security is complicated and youg. A course such as this helps bring it into focus.&quot;<br />-Jayme Frye, System Engineer, Union Pacific Railroad</p><p>&quot;Web services security class provided application security concepts valuable for applications audits.&quot;<br />- Mary Ma, IT Auditor, DTCC</p><p>&quot;Very knowledgeable coverage of security requirements for Web services.&quot;<br />- David Libershal, Network Security Engineer, Johns Hopkins University Applied Physics Laboratory</p><p>&quot;WS/XML security is not a &quot;black art&quot;, but you do need to know about it to be able to take it into consideration.&quot;<br />- Applications Specialist, Global 500 manufacturer</p><p>&quot;Good overview of techniques worth considering when planning secure apps&quot;<br />- EAI Specialist, Leading Mobility company</p><p>&quot;Brought concepts in very easily understood terms.&quot;<br />-Glenn Bernard, Systems Engineer</p><p>&quot;Gives ideas about the latest Web services security standards in the industry&quot;<br />- Security Coordinator, Global 500 manufacturer</p><p>&quot;Class cleared up various WS-* standards and gave great concrete examples of how to build a message using each standard. Very good general thoughts on security groups&#39; role in IT.&quot;<br />- Matt Kasselman, UP Systems Engineering</p><p>&quot;I found this very useful as an IT architect in a &quot;security critical environment&quot;.&quot;<br />- Mika Pullinen, IT Architect, Finnish Defense Forces</p><p>&quot;Lots of useful information packed in a small amount of time. Good overall picture.&quot;<br />- Jari Pirhonen, Security Director, Samlink</p><p>&quot;Gunnar is very knowledgeable about security topics and has a great ability to explain complex ideas using simple, appropriate, and amusing language and analogies.&quot;<br />- Scott Redd, Sr. Project Engineer, Union Pacific</p><p>&quot;Excellent instructor who had a good pace to go through the presentation&quot;&#160;<br />- Anna Vaahtokan, Specialist, Nordea</p><p>&quot;Good application security principles.&quot;<br />- Tuomas Kivinen, IT Security Specialist, Nordea</p><p>&quot;I liked the class quite a bit. I took it in a &quot;survey mode&quot; where I wanted to learn about topics at a high level, and this was accomplished. It was good to listen to those in the class that were much more familiar with SAO than I.&quot;<br />- John Glazeski, Senior Systems Engineer</p></span></div></div></div>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 04:55:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/soa security standards">soa security standards</category>
      <category domain="http://securityratty.com/tag/security standards">security standards</category>
      <category domain="http://securityratty.com/tag/soa security">soa security</category>
      <category domain="http://securityratty.com/tag/soa">soa</category>
      <category domain="http://securityratty.com/tag/security critical environment">security critical environment</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/application security principles">application security principles</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/web-services-and-xml-security-training-at-owasp.html">Web Services and XML Security Training at OWASP</source>
    </item>
    <item>
      <title><![CDATA[This Generations ApathyThe Age of Specialization and ADD]]></title>
      <link>http://securityratty.com/article/de3980adf7c1fb760b23b64836636412</link>
      <guid>http://securityratty.com/article/de3980adf7c1fb760b23b64836636412</guid>
      <description><![CDATA[Robert Scoble has some interesting commentary this morning about the number of photojournalists with expensive gear covering the Olympics
Hes a bit indignant that so much energy goes to sporting...]]></description>
      <content:encoded><![CDATA[<p>Robert Scoble has some interesting <a rel="nofollow" target="_blank" href="http://scobleizer.com/">commentary</a> this morning about the number of photojournalists with expensive gear covering the Olympics.</p>
<p>He&#8217;s a bit indignant that so much energy goes to sporting events like the Olympics rather than more important news that isn&#8217;t getting reported around the world.</p>
<blockquote><p>This is in a year when tons of journalists are getting laid off.</p>
<p>This is in a year when there are tons of stories around the world that aren’t getting reported on.</p>
<p>Could we take half of those photographers and send them to Russia, for instance</p></blockquote>
<p>Reminds me of a feeling I had back in college as an undergrad student studying social sciences and humanities, about the way my friends who were physicists interacted with the world. They were so awed by the stars, Mars, astrophysics, and it seemed to me interesting but altogether unimportant. They argued they may find something outside our planet that could help solve Earth-bound problems like disease, or find the origins of earth and humanity &#8212; but really they were doing it because they loved it. One of my friends had a good argument, though &#8212; there are enough people right now that we can specialize in what we care about, and there will still be others covering other topics. He could be a physicist and look into the universe&#8217;s origin, while I studied social interaction and writing, and our other friends looked into solving cancer or eradicating invasive plants in the native wetlands. We have to specialize, and there are enough of us to do it too.</p>
<p>I think it&#8217;s the same way in journalism &#8212; whether it&#8217;s sports, celebrity journalism, or coverage of politics and war, there are a lot of opportunities right now for journalists. Of course the business model is changing, and some old-schoolers won&#8217;t know how to roll with that, but generations change slowly; we&#8217;re learning.</p>
<p>Also, the Olympics is seen as more than a sporting event, it&#8217;s also a symbol of world competition and cooperation too &#8212; a way for countries to come together and share entertainment globally. I think that&#8217;s worth covering.</p>
<p>In the second post, Robert Scoble says there are plenty of great journalists but the public doesn&#8217;t care. In some ways I have to agree with that, but I don&#8217;t think it&#8217;s negative, necessarily. I had a conversation with someone the other day about world news reportage. He says, &#8220;I was just reading this story, but what does it matter to me if there&#8217;s a flood in some city in another country I&#8217;ll never visit and some farmer lost his sheep?&#8221; World news is only important when it&#8217;s relevant, so it&#8217;s no wonder that many people don&#8217;t care &#8212; if they don&#8217;t know much about the area, and it doesn&#8217;t affect them, they have no incentive to give it full attention. You can call that apathy, but I think it&#8217;s an important selectivity skill that humans have. We have to choose what to give priority to, so if nothing stands out as being particularly important, we just ignore it or gloss over it. Human nature&#8230;</p>
<p>Also I think the common person today just gets desensitized and doesn&#8217;t know where to turn their energy, when surrounded by so many crises. Either you focus on one specialty and do your best to work toward one cause in your life &#8212; and maybe that&#8217;s just in the course of your daily work &#8212; or you become a complete Attention-Deficit-Disorder case and bounce from one problem to the next, without knowing how to solve anything. That just causes a sense of bewilderment, despair, and either that bogs you down or eventually you get desensitized.</p>
<p>There&#8217;s a commenter on Scoble&#8217;s blog, Spencer, who talks about this generation&#8217;s apathy. There are so many people who want to blame today&#8217;s generation or the young generation for this &#8220;apathy&#8221; that they sense. But I see it as a survival mechanism that arises from the way information flows these days. We&#8217;re surrounded by crises, everyone wants us to know about them &#8212; the water shortage, global warming, death in Iraq, the national deficit. Okay, crisis, I get it. But no one gives a real clear idea on what any individual is really supposed to do to solve the problem. You can&#8217;t get involved with one global cause, without ignoring all the others, and if you do get involved it&#8217;s likely to become your life&#8217;s purpose. Most people are concerned with other things &#8212; their families, their work, personal development, their homes and futures, and really that&#8217;s enough to take up all their time.</p>
<p>I&#8217;m always amazed when I read about the early unionists. Emma Goldman for example, the activist who pushed for the 8-hr workday, and campaigned for free love in the early 1900s when women were still wearing corsets, used to work 16 hour factory days as a seamstress, then lead meetings late into the night. Today we lead cushy lives comparatively&#8211;8 hour days, plus commute and lunch, family time, dinner time, gym maybe, sleep&#8230; but it still doesn&#8217;t seem like we ever have enough energy and time.</p>
<p>What Emma had that most people today don&#8217;t, is a community living in the same conditions as herself, with clear goals about what they were campaigning for, and a cause that affected their own daily lives. Today, unionism and local activism is in much shorter supply, in part due to the many people who work fairly comfy desk jobs, and the problem that everyone has his own specialization, works in a cubicle, does his or her own thing. The problems we&#8217;re facing today in terms of global warming, global water shortage, aren&#8217;t the same kinds of problems that activists have fought for in the past, and there&#8217;s no clear road map for how to solve them. Our leaders sure aren&#8217;t leading the way.</p>
<p>What we do have, at least, is the Olympics, which is an age old symbol of international cooperation, play and competition&#8230;so, uh, go sports! As for full disclosure, I don&#8217;t actually have a TV and haven&#8217;t watched the Olympics in many years, but I do try taking short showers&#8211;does that help?</p>]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 09:46:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/world news reportage">world news reportage</category>
      <category domain="http://securityratty.com/tag/world">world</category>
      <category domain="http://securityratty.com/tag/world competition">world competition</category>
      <category domain="http://securityratty.com/tag/world news">world news</category>
      <category domain="http://securityratty.com/tag/global water shortage">global water shortage</category>
      <category domain="http://securityratty.com/tag/global">global</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/solve earth-bound">solve earth-bound</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/369359733/">This Generations ApathyThe Age of Specialization and ADD</source>
    </item>
    <item>
      <title><![CDATA[Don't put your foot in it, Mr. President]]></title>
      <link>http://securityratty.com/article/d826a8c8ac69bcbf21bb4cc5b4cdf815</link>
      <guid>http://securityratty.com/article/d826a8c8ac69bcbf21bb4cc5b4cdf815</guid>
      <description><![CDATA[Watching the beginning of the Olympics, I was surprised to see the way President Bush was sitting

The First Lady was on one side of him (thankfully) and a Chinese looking gentleman was on the other...]]></description>
      <content:encoded><![CDATA[<a href="http://1.bp.blogspot.com/_1UFxC-OgSnA/SKXxuGNxEzI/AAAAAAAAAF4/KfNUNDfyARI/s1600-h/george-w-bush.jpg"><img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_1UFxC-OgSnA/SKXxuGNxEzI/AAAAAAAAAF4/KfNUNDfyARI/s320/george-w-bush.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5234855916132700978" /></a><br />Watching the beginning of the Olympics, I was surprised to see the way President Bush was sitting.<br /><span id="fullpost"><br />The First Lady was on one side of him (thankfully) and a Chinese looking gentleman was on the other side.  The President had his right foot resting on his left knee, thereby exposing his shoe sole.  That is a huge "no no" in Asia and the Middle East. <br /></span><br />As I said, thankfully the First Lady, Laura Bush was the recipient of the President's sole-waving but it made me wonder if he changed legs at a later stage and "flashed" the Chinese official.  I figure it was a high ranking official or else he would hardly be sat next to the President of the United States.<br /><br />What has this to do with security?  It is one of the topics we teach to our budding bodyguards during our intensive Executive Protection course in the United States and abroad.  You could have a very successful business meeting or trip, either overseas or at home, but ruin it by insulting (albeit unintentionally)a foreign guest.  It is very important for those wroking around forein nationals to be aware of their customs and traditions.  <br /><br />This is not that difficult these days with all of the materials available.  One of the best books I have found is; "Kiss, Bow or Shake Hands".  This book and others like it, will advise the reader on the correct course of action to take when dealing with people from a host of different countries.  Not that I expect the President to read the book, afterall, he must have Protocol officers to keep an eye on him.  My question is, were they brought to China? <br /><br />For the rest of us who are not lucky enough to have our own Protocol officers to keep us out of trouble, we'll just have to read the book.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 16:57:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/president">president</category>
      <category domain="http://securityratty.com/tag/president bush">president bush</category>
      <category domain="http://securityratty.com/tag/chinese official">chinese official</category>
      <category domain="http://securityratty.com/tag/official">official</category>
      <category domain="http://securityratty.com/tag/protocol officers">protocol officers</category>
      <category domain="http://securityratty.com/tag/chinese">chinese</category>
      <category domain="http://securityratty.com/tag/intensive executive protection">intensive executive protection</category>
      <category domain="http://securityratty.com/tag/book">book</category>
      <category domain="http://securityratty.com/tag/shoe sole">shoe sole</category>
      <source url="http://www.thebulletproofblog.com/2008/08/dont-put-your-foot-in-it-mr-president.html">Don't put your foot in it, Mr. President</source>
    </item>
    <item>
      <title><![CDATA[Black Hat: Security Geeks Converge on Vegas]]></title>
      <link>http://securityratty.com/article/68be741df457de1bea1829af536288ea</link>
      <guid>http://securityratty.com/article/68be741df457de1bea1829af536288ea</guid>
      <description><![CDATA[More than 4,000 security professionals are in Las Vegas this week for the Black Hat Security Conference. Topics include hacking highway toll systems, security vulnerabilities in implantable wireless...]]></description>
      <content:encoded><![CDATA[More than 4,000 security professionals are in Las Vegas this week for the Black Hat Security Conference.  Topics include hacking highway toll systems, security vulnerabilities in implantable wireless medical devices and a demonstration of injecting law-enforcement Trojan horses onto target machines.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=a4d1f4972a4845cc5a8f28c6bcdd964a" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=a4d1f4972a4845cc5a8f28c6bcdd964a" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=tARxqK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=tARxqK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Sg6Vnk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Sg6Vnk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=bdh3Uk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=bdh3Uk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=BywvdK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=BywvdK" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=spNrQK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=spNrQK" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=wSaoYk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=wSaoYk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=d9o3Bk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=d9o3Bk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=QRQKpK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=QRQKpK" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/357736373" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/357736390" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 13:15:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/law-enforcement trojan horses">law-enforcement trojan horses</category>
      <category domain="http://securityratty.com/tag/highway toll systems">highway toll systems</category>
      <category domain="http://securityratty.com/tag/topics include">topics include</category>
      <category domain="http://securityratty.com/tag/target machines">target machines</category>
      <category domain="http://securityratty.com/tag/security professionals">security professionals</category>
      <category domain="http://securityratty.com/tag/las vegas">las vegas</category>
      <category domain="http://securityratty.com/tag/security vulnerabilities">security vulnerabilities</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/demonstration">demonstration</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/357736390/security-geeks.html">Black Hat: Security Geeks Converge on Vegas</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up - July 2008]]></title>
      <link>http://securityratty.com/article/ad180724e0eff95212e4a6b6f36f73c1</link>
      <guid>http://securityratty.com/article/ad180724e0eff95212e4a6b6f36f73c1</guid>
      <description><![CDATA[I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see...]]></description>
      <content:encoded><![CDATA[<p>I saw this idea of a monthly blog round-up and I liked it. In general, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. This is an attempt to remind people of useful content!</p>  <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">&quot;Security Warrior&quot; blog</a> </strong>round-up of top 5 popular posts and topics.</p>  <ol>   <li>As you can easily, easily guess, the&#160; #1 spot this month is taken by my irreverent comments on a Terry Childs saga. Namely, &quot;<a href="http://chuvakin.blogspot.com/2008/07/on-doomsaying-terry-childs-case.html">On Doomsaying (Terry Childs case)</a>&quot;, &quot;<a href="http://chuvakin.blogspot.com/2008/07/on-doomsaying-terry-childs-case.html">So ... Am I? Maybe I Am!</a>&quot; and &quot;<a href="http://chuvakin.blogspot.com/2008/07/admins-good-guys-or-am-not-idiot.html">Admins , Good Guys or &quot;I am NOT an Idiot!&quot;</a>&quot;</li>    <li>Obviously, my earlier post/rant called &quot;<a href="http://chuvakin.blogspot.com/2008/06/you-are-security-idiot-if.html">You Are &quot;A Security Idiot&quot; If ...</a>&quot; takes the #2 spot. Yes, we all like to point out other people's problems, especially when they are epically huge :-)</li>    <li>Next up is my post &quot;<a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or &quot;Raffy, You Killed SIM!&quot;</a>&quot;. It is both humorous and sadly true (and <a href="http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/export/home/httpd/htdocs/reviews/2008/063008-test-siem.html&amp;pagename=/reviews/2008/063008-test-siem.html&amp;pageurl=http://www.networkworld.com/reviews/2008/063008-test-siem.html&amp;site=security">backed up by other sources</a>) </li>    <li>Also popular is my post &quot;<a href="http://chuvakin.blogspot.com/2008/07/log-management-day-1.html">Log Management - Day 1</a>,&quot; which talks about the very first thing you do when embarking on a journey to <a href="http://www.loglogic.com">log management</a>.</li>    <li>Finally, again this month, <a href="http://chuvakin.blogspot.com/search/label/poll">my logging polls</a> took the #1 spot!&#160; <a href="http://chuvakin.blogspot.com/2008/05/poll-8-log-analysis-context.html">Poll #8</a> that covered context data for log analysis <a href="http://chuvakin.blogspot.com/2008/06/logging-poll-8-analysis-needed-log.html">is analyzed here</a>. Other popular polls include a controversial <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">Windows Log Collection Poll</a></u> (which is <u><a href="http://chuvakin.blogspot.com/2008/04/windows-log-collection-poll-analysis.html">a poll #7</a></u>)&#160; and <u><a href="http://chuvakin.blogspot.com/2008/03/logging-poll-6-logs-do-you-look-at.html">poll #6</a></u> about logs that people actually look and <a href="http://chuvakin.blogspot.com/2008/02/logging-poll-5-logging-challenges.html">poll #5</a> about logging challenges. </li>    <li>Strangely, a lot of people wanted to &quot;<a href="http://chuvakin.blogspot.com/2008/07/which-blogs-do-i-read.html">Which Blogs Do I Read?</a>&quot; - so my brief post on that made it to the top.</li> </ol>  <p>See you in August, unless you are all on vacations, that is :-)</p>  <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/07/monthly-blog-round-up-june-2008.html">Monthly Blog Round-Up - June 2008</a></li>    <li><a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a> </li>    <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a></li> </ul>  <p>&#160;</p>  <p></p>  <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7192e29b-e335-4630-8b0b-dc37806d54ee" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>,<a href="http://technorati.com/tags/security" rel="tag">security</a>,<a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>,<a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=dP6djK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=dP6djK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=ZJx4wK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=ZJx4wK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Avu9xK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Avu9xK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/353106236" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 01 Aug 2008 12:38:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/posts">posts</category>
      <category domain="http://securityratty.com/tag/popular posts">popular posts</category>
      <category domain="http://securityratty.com/tag/popular">popular</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/353106236/monthly-blog-round-up-july-2008.html">Monthly Blog Round-Up - July 2008</source>
    </item>
    <item>
      <title><![CDATA[Reminder: WebEx Seminar on Risk Analysis]]></title>
      <link>http://securityratty.com/article/967093a66c194ca86dac97183d5a6526</link>
      <guid>http://securityratty.com/article/967093a66c194ca86dac97183d5a6526</guid>
      <description><![CDATA[Hey everybody! Quick post this morning to remind you guys that Cisco has been kind enough to let us give a follow on WebEx presentation on July 31, 2008 at 11:30 a.m. EDT. The link to sign up is &gt;&gt; ....]]></description>
      <content:encoded><![CDATA[<p>Hey everybody!  Quick post this morning to remind you guys that Cisco has been kind enough to let us give a follow on WebEx presentation on  July 31, 2008 at 11:30 a.m. EDT.  The link to sign up is <a href="https://ciscosales.webex.com/ciscosales/onstage/g.php?d=929845289&amp;t=a&amp;EA=miradiga%40cisco.com&amp;ET=d5be1b551672ee32df7260c6418042ca&amp;ETR=b92381359a9255da61ca95ac83ae2f0e"><strong>&lt;&lt;&lt;here&gt;&gt;&gt;</strong></a>.  There are only about 40 slots left.  It looks like it&#8217;s going to be a good crowd.</p>
<p>We&#8217;re calling this part II - and it&#8217;s being advertised as:</p>
<p><em><strong>&#8220;How to conduct a risk analysis and produce a high impact deliverable to senior management.&#8221;</strong></em></p>
<p>With topics:</p>
<ul>
<li>The life-cycle of a quantitative risk analysis</li>
<li>Key control opportunities against targeted attacks</li>
<li>Getting senior management to understand the risk posed to the business</li>
</ul>
<p>I got to do the Q&amp;A backchannel on the last presentation, and there were great questions asked.  I think this presentation will be even more exciting, as it&#8217;ll cover both analyst and management considerations.</p>
<p>If you&#8217;re a regular reader of the blog, I don&#8217;t think you&#8217;ll have to have attended the last one for this one to be worth your while.</p>
<p><strong>REPEAT PERFORMANCES OF THE FIRST WEBEX ARE AVAILABLE</strong></p>
<p>And if you missed it the first time, the playback of the first preso is <a href="https://ciscosales.webex.com/ciscosales/lsr.php?AT=pb&amp;SP=EC&amp;rID=25693942&amp;rKey=5A9EF2E7F1B062BC"><strong>here</strong></a>, and the slides are <a href="http://www.riskmanagementinsight.com/media/documents/Risk_Evolution.pdf"><strong>here</strong></a>.</p>
]]></content:encoded>
      <pubDate>Tue, 29 Jul 2008 13:56:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk analysis">risk analysis</category>
      <category domain="http://securityratty.com/tag/webex">webex</category>
      <category domain="http://securityratty.com/tag/webex presentation">webex presentation</category>
      <category domain="http://securityratty.com/tag/quantitative risk analysis">quantitative risk analysis</category>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/senior management">senior management</category>
      <category domain="http://securityratty.com/tag/key control opportunities">key control opportunities</category>
      <category domain="http://securityratty.com/tag/risk posed">risk posed</category>
      <category domain="http://securityratty.com/tag/impact deliverable">impact deliverable</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=379">Reminder: WebEx Seminar on Risk Analysis</source>
    </item>
  </channel>
</rss>
