<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: tough]]></title>
    <link>http://securityratty.com/tag/tough</link>
    <description></description>
    <pubDate>Sun, 26 Oct 2008 16:37:40 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Tough times and risk management, Part 2]]></title>
      <link>http://securityratty.com/article/5de1bd4c883ea9408ddecd977472b5ff</link>
      <guid>http://securityratty.com/article/5de1bd4c883ea9408ddecd977472b5ff</guid>
      <description><![CDATA[Gibbs discussed the concept of risk management in IT a couple of weeks ago, and vowed to continue with a discussion of the consequent politics. True to his word, here...]]></description>
      <content:encoded><![CDATA[Gibbs discussed the concept of risk management in IT a couple of weeks ago, and vowed to continue with a discussion of the consequent politics. True to his word, here 'tis . . .]]></content:encoded>
      <pubDate>Sun, 30 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/weeks ago">weeks ago</category>
      <category domain="http://securityratty.com/tag/consequent politics">consequent politics</category>
      <category domain="http://securityratty.com/tag/gibbs">gibbs</category>
      <category domain="http://securityratty.com/tag/true">true</category>
      <category domain="http://securityratty.com/tag/tis">tis</category>
      <category domain="http://securityratty.com/tag/couple">couple</category>
      <category domain="http://securityratty.com/tag/word">word</category>
      <category domain="http://securityratty.com/tag/vowed">vowed</category>
      <source url="http://www.networkworld.com/columnists/2008/120108backspin.html?fsrc=rss-security">Tough times and risk management, Part 2</source>
    </item>
    <item>
      <title><![CDATA[Massachusetts extends compliance deadline on new data encryption rules]]></title>
      <link>http://securityratty.com/article/dcf375161bf04b2242011004444e86e4</link>
      <guid>http://securityratty.com/article/dcf375161bf04b2242011004444e86e4</guid>
      <description><![CDATA[Citing the economic downturn, the Massachusetts state government is giving companies more time to comply with tough new regulations on securing the personal data of state...]]></description>
      <content:encoded><![CDATA[Citing the economic downturn, the Massachusetts state government is giving companies more time to comply with tough new regulations on securing the personal data of state residents.<br style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:80743a3e4efe19999f34c801fd7bd92f:WiPkSeOVsv3zl50P4GV5zQmroNP2o5Te8mRtn%2BzYUM4XoQmEbKi8rb0rkfp6duhLutZZIuRy%2FN5m'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:68018f73d7c15f88a6e72c6f4737f8f7:uec05RcU%2F5uhVq%2FdAc38z9rRvmr%2BzUPDwVM0JpguiSc1fhX8zZ%2Bsve%2BFCIfedKKz%2F%2FCNLMuzlATB8Q%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:a2b2db43506a71e62a00fd2b5dc8729e:5zCbYVOa38S47PUY7b7MI0TQJQV8flZsdfXDcqns1p%2FKLqqVVZ32LUf58KlzhBTVWQ5%2BbRzuLXqowg%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:72455376969fc933a9b22db59e3690b5:UChAzeWgtCBdgCp3Lzbz%2BuAjGRUowiav1ERwhjnfNLpUKs066y1teL182WK8YB89RdnzMyE7GS%2FRfg%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>
<a href="http://www.pheedo.com/click.phdo?s=447649038b0f932781657963f56faa7b&p=1"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=447649038b0f932781657963f56faa7b&p=1"/></a>
<img src="http://www.pheedo.com/feeds/tracker.php?i=447649038b0f932781657963f56faa7b" style="display: none;" border="0" height="1" width="1" alt=""/>
]]></content:encoded>
      <pubDate>Thu, 20 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/economic downturn">economic downturn</category>
      <category domain="http://securityratty.com/tag/personal data">personal data</category>
      <category domain="http://securityratty.com/tag/massachusetts">massachusetts</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/regulations">regulations</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/comply">comply</category>
      <category domain="http://securityratty.com/tag/tough">tough</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=447649038b0f932781657963f56faa7b">Massachusetts extends compliance deadline on new data encryption rules</source>
    </item>
    <item>
      <title><![CDATA[Talking Engagement]]></title>
      <link>http://securityratty.com/article/b1376fcaf83b962af2522fd39ae76937</link>
      <guid>http://securityratty.com/article/b1376fcaf83b962af2522fd39ae76937</guid>
      <description><![CDATA[So, it finally happened. I was invited to talk at an Information Security Conference and I went and talked

My talk was about the risks of information leaving the organisation but I decided to add in...]]></description>
      <content:encoded><![CDATA[So, it finally happened. I was invited to talk at an Information Security Conference and I went and talked.<br /><br />My talk was about the risks of information leaving the organisation but I decided to add in the risks of information <span style="font-style: italic;">not</span> leaving the organisation.<br /><br />This may sound counter productive but in these though times your IT department should really be looking at using services such as GMail, your Marketing department should be looking at using Facebook, Twitter, Blogs etc. Your HR department should be looking through LinkedIn for new staff.<br /><br />If your Security Department is too tough on information leaving the organisation then you are missing out on opportunities. Of course, if you are too lax then information will make its way out and that can't be good for the company either.<br /><br />Information Classification is key. As is awareness.<br /><br />My speech was very well received, achieving over 8/10 for the different areas and I have been invited back to speak again.<br /><br />I must admit that my speech was aimed at business decision makers and not technical people and yet the people who showed up were more technical people. There are very few companies in South Africa (with my employer being a noted exception) that treat Information Security as a business issue and not (only) a technical issue.<br /><br />I'm not really one to tooth my own horn but I wrote this blog entry to thank a number of people who made my speech possible.<br /><br />Firstly thank you to the two blogs that I feel are on the forefront of Information-centric Security - <a href="http://securosis.com/">Securosis</a> and <a href="http://rationalsecurity.typepad.com/blog/">Rational Survivability</a>. I used some material from both sites and some that was sent to me by Richard Mogull from Securosis.<br /><br />I used some speaking tips that I got from <a href="http://www.presentationzen.com/presentationzen/">Presentation Zen</a> so I didn't put everyone to sleep (even though my speech was at the danger time of 3:30pm when everyone is tired and wants to go home) and I used some (free!) graphics from <a href="http://www.sxc.hu/">Stock Exchange</a>.<br /><br />When I was preparing for the speech, I revisited some of my old Blog posts which I think I need to repost as I have some more ideas about them.<img src="http://feeds.feedburner.com/~r/SecurityThoughts/~4/452816173" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 14 Nov 2008 06:46:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/treat information security">treat information security</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/information classification">information classification</category>
      <category domain="http://securityratty.com/tag/security department">security department</category>
      <category domain="http://securityratty.com/tag/information security conference">information security conference</category>
      <category domain="http://securityratty.com/tag/technical people">technical people</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/department">department</category>
      <source url="http://feeds.feedburner.com/~r/SecurityThoughts/~3/452816173/talking-engagement.html">Talking Engagement</source>
    </item>
    <item>
      <title><![CDATA[Giving Out Replacement Hotel Keys]]></title>
      <link>http://securityratty.com/article/542f16268a3db761c37b339fd48c2076</link>
      <guid>http://securityratty.com/article/542f16268a3db761c37b339fd48c2076</guid>
      <description><![CDATA[It's a tough security trade-off. Guests lose their hotel room keys, and the hotel staff needs to be accommodating. But at the same time, they can't be giving out hotel room keys to anyone claiming to...]]></description>
      <content:encoded><![CDATA[<p>It's a tough security trade-off.  Guests lose their hotel room keys, and the hotel staff needs to be accommodating.  But at the same time, they can't be giving out hotel room keys to anyone claiming to have lost one.  Generally, hotels ask to see some ID before giving out a replacement key and, if the guest doesn't have his wallet with him, have someone walk to the room with the key and check their ID.</p>

<p>This normally works pretty well, but there's a <a href="http://www.brisbanetimes.com.au/news/queensland/room-key-given-to-rapist-hotel-guest/2008/10/29/1224956099579.html">court case in Brisbane</a> right now about a hotel giving a room key to someone who ended up sexually attacking the woman who had rented the room.</p>

<blockquote>In civil action launched yesterday, the woman alleges the man was given the spare access key to her room by a hotel staffer.</blockquote>

<p>The article doesn't say what kind of authentication the hotel requested or received.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=qKbJN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=qKbJN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=I9pEN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=I9pEN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 09:12:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hotel">hotel</category>
      <category domain="http://securityratty.com/tag/hotel staff">hotel staff</category>
      <category domain="http://securityratty.com/tag/key">key</category>
      <category domain="http://securityratty.com/tag/spare access key">spare access key</category>
      <category domain="http://securityratty.com/tag/hotel staffer">hotel staffer</category>
      <category domain="http://securityratty.com/tag/keys">keys</category>
      <category domain="http://securityratty.com/tag/replacement key">replacement key</category>
      <category domain="http://securityratty.com/tag/woman alleges">woman alleges</category>
      <category domain="http://securityratty.com/tag/woman">woman</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/giving_out_repl.html">Giving Out Replacement Hotel Keys</source>
    </item>
    <item>
      <title><![CDATA[Investing in Your IT Security Career in Tough Times]]></title>
      <link>http://securityratty.com/article/73dfed3db4d8429f88c002b4ea28bf53</link>
      <guid>http://securityratty.com/article/73dfed3db4d8429f88c002b4ea28bf53</guid>
      <description><![CDATA[When meeting someone new and describing my background in this industry I often say &quot;I've seen the best of times, I've seen the worst of times and most of what falls in between.&quot; I've been recruiting...]]></description>
      <content:encoded><![CDATA[When meeting someone new and describing my background in this industry I often say "I've seen the best of times, I've seen the worst of times and most of what falls in between." I've been recruiting in Information Security long enough to have experienced the heady times of the dot.com boom and the dark days that followed after it all came crashing down. I've also been here as the industry has grown and evolved-sometimes as a result of and sometimes in spite of significant difficulties. This evolution leads to adaptation, and it's the ability of people to adapt and rise above one challenge after another that makes our industry so dynamic.]]></content:encoded>
      <pubDate>Mon, 03 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/times">times</category>
      <category domain="http://securityratty.com/tag/heady times">heady times</category>
      <category domain="http://securityratty.com/tag/industry">industry</category>
      <category domain="http://securityratty.com/tag/dark days">dark days</category>
      <category domain="http://securityratty.com/tag/significant difficulties">significant difficulties</category>
      <category domain="http://securityratty.com/tag/evolution leads">evolution leads</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/worst">worst</category>
      <category domain="http://securityratty.com/tag/challenge">challenge</category>
      <source url="http://www.networkworld.com/news/2008/110408-investing-in-your-it-security.html?fsrc=rss-security">Investing in Your IT Security Career in Tough Times</source>
    </item>
    <item>
      <title><![CDATA[Seeing tough times ahead, Symantec plans layoffs]]></title>
      <link>http://securityratty.com/article/d24366dbf96a3a058970def392cd1841</link>
      <guid>http://securityratty.com/article/d24366dbf96a3a058970def392cd1841</guid>
      <description><![CDATA[Anticipating a slowdown in IT spending, Symantec expects to begin laying off employees next...]]></description>
      <content:encoded><![CDATA[Anticipating a slowdown in IT spending, Symantec expects to begin laying off employees next month.]]></content:encoded>
      <pubDate>Thu, 30 Oct 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/symantec expects">symantec expects</category>
      <category domain="http://securityratty.com/tag/month">month</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <category domain="http://securityratty.com/tag/slowdown">slowdown</category>
      <source url="http://www.networkworld.com/news/2008/103108-seeing-tough-times-ahead-symantec.html?fsrc=rss-security">Seeing tough times ahead, Symantec plans layoffs</source>
    </item>
    <item>
      <title><![CDATA[Seeing tough times ahead, Symantec plans layoffs]]></title>
      <link>http://securityratty.com/article/98bc3dceaa4253574a6298730b2b23d3</link>
      <guid>http://securityratty.com/article/98bc3dceaa4253574a6298730b2b23d3</guid>
      <description><![CDATA[Anticipating a slowdown in IT spending, Symantec expects to begin laying off employees next...]]></description>
      <content:encoded><![CDATA[Anticipating a slowdown in IT spending, Symantec expects to begin laying off employees next month.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:3e9b7242358a0c9f059966b7905e4c63:71WPORpFcPKPm16Cb3oQLZPRJoAFe2GGl%2FpU0w4gmz2geliSd1Donfy1a98SwzeCPqohvEKN6WaR'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:610c6a71ef797b0a1e7737f903c86c39:xXzBq0JtAnhPudFx39YuIJaXTAtXzuzrPZFbiS1HGV533b6xP%2BO2iZti%2BMfnqQuOk9iyJMM2faiBGg%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:2a2263c37f7e7e7cd7269920c31c2e5b:PN1RBaLQ1olFJyJ0wUBNxJyyf4DSfcIsJ9cDFGPaP7d223QfGbwfgZyZj4UlcU7fglIdvtTH3EUnzQ%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:33f6db217075f8b6978db219249956f5:bbyJXYINNxegiHis6bpPAD9RlG2hravBIpa%2BF3Y8STPUvl1tlncX8d9DyR3r1hx1Wq4wvBeQpI1Tsg%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/feeds/ht.php?t=c&amp;i=dbc69f75cdb18b6289430e6a5f0056bf"><img src="http://www.pheedo.com/feeds/ht.php?t=v&amp;i=dbc69f75cdb18b6289430e6a5f0056bf" border="0" /></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=dbc69f75cdb18b6289430e6a5f0056bf" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 30 Oct 2008 01:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/symantec expects">symantec expects</category>
      <category domain="http://securityratty.com/tag/month">month</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <category domain="http://securityratty.com/tag/slowdown">slowdown</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=dbc69f75cdb18b6289430e6a5f0056bf">Seeing tough times ahead, Symantec plans layoffs</source>
    </item>
    <item>
      <title><![CDATA[Accenture CIO Modruson is not just putting out fires]]></title>
      <link>http://securityratty.com/article/58836d9c09733dca1575325dc946aa94</link>
      <guid>http://securityratty.com/article/58836d9c09733dca1575325dc946aa94</guid>
      <description><![CDATA[Being an IT leader is tough enough at the best of times, but what do you do when your company is stacked with IT experts? 'Make the most of it' would appear to be the attitude of Frank Modruson, CIO...]]></description>
      <content:encoded><![CDATA[Being an IT leader is tough enough at the best of times, but what do you do when your company is stacked with IT experts? 'Make the most of it' would appear to be the attitude of Frank Modruson, CIO of Accenture, one of the world's biggest management consulting, technology services and outsourcing companies.]]></content:encoded>
      <pubDate>Mon, 27 Oct 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/frank modruson">frank modruson</category>
      <category domain="http://securityratty.com/tag/technology services">technology services</category>
      <category domain="http://securityratty.com/tag/cio">cio</category>
      <category domain="http://securityratty.com/tag/accenture">accenture</category>
      <category domain="http://securityratty.com/tag/leader">leader</category>
      <category domain="http://securityratty.com/tag/world">world</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/attitude">attitude</category>
      <category domain="http://securityratty.com/tag/tough">tough</category>
      <source url="http://www.networkworld.com/news/2008/102808-accenture-cio-modruson-is-not.html?fsrc=rss-security">Accenture CIO Modruson is not just putting out fires</source>
    </item>
    <item>
      <title><![CDATA[IT wary of insider attacks as economy slows down]]></title>
      <link>http://securityratty.com/article/2d5875c8323e22acbeca9e0d7dea3f2c</link>
      <guid>http://securityratty.com/article/2d5875c8323e22acbeca9e0d7dea3f2c</guid>
      <description><![CDATA[Experts warn that companies should be especially vigilant about protecting their data and networks from disgruntled employees during tough economic...]]></description>
      <content:encoded><![CDATA[Experts warn that companies should be especially vigilant about protecting their data and networks from disgruntled employees during tough economic times.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:83e4ec94f86d129868c4b2d0cc4e64c6:I%2FSn3SEghhfv83Pq4vxlqMs4wkTVi0jHd6zAOr7X3SweVS50cCg2FqNvgB155ehr%2FpUDVNUX9JOk'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:23d67e4deccaf1343c75a55fd1874fe2:X6T1adOL0IwsT0CcQgmW9clO6RHl7CETWaDJXOCPemptZ7pmwVXqG5Y9O3IKT7SuyCXmcYwYsZZ6xQ%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:231abc397222dce2b54afb0aaf0366d9:fJlYW%2BHRxfP0wooXahpYFuZmrd5xNoYasTFf6nDBVh39rOH9D5rk6Zf9ORd8kJZNEIiYv872Aq5HPw%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:947beb156698ca50f3f56e53f1569d06:JqzFq9x%2B3UM%2Fip3E50Vlj7U%2FtmP2AoY%2BFIAbqxSCj3PPhjMfXvRb%2FMvtlrvsWj8GPkBgM2BUSI3LFQ%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=00ec126a7423b5eb0b0df528604eec8d" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=00ec126a7423b5eb0b0df528604eec8d" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 27 Oct 2008 01:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tough economic times">tough economic times</category>
      <category domain="http://securityratty.com/tag/experts warn">experts warn</category>
      <category domain="http://securityratty.com/tag/vigilant">vigilant</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/networks">networks</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=00ec126a7423b5eb0b0df528604eec8d">IT wary of insider attacks as economy slows down</source>
    </item>
    <item>
      <title><![CDATA[Information security in bad economy]]></title>
      <link>http://securityratty.com/article/724237a8203417ab862d25e018912170</link>
      <guid>http://securityratty.com/article/724237a8203417ab862d25e018912170</guid>
      <description><![CDATA[Economy looks grim. The headlines are very discouraging. Capitalism does not guarantee wealth and success all the time. The talking heads on TV blame the greed in the stock market. I wish stock market...]]></description>
      <content:encoded><![CDATA[<P>Economy looks grim. The headlines are very discouraging. Capitalism does not guarantee wealth and success all the time. The talking heads on TV blame the&nbsp;greed in the stock market. I wish stock market is made of just computers that are not greedy human beings. These are bound to happen when there are human beings that participate! Money flows will eventually correct itself&nbsp; I hope, capitalism will be healthy again. This will take time. I am not an economist, but I do understand that people part with money for a period of time to collect higher return in the horizon based on their aptitude for risk.&nbsp; Simple is it not! But, all these complex financial instruments and its machinations seem to blur the reality and make even the brainiest act dumb - or are they just plain greedy?</P>
<P>Setting the context for this post, it is a tough economic situation all over the world. IT spending has reduced and will reduce significantly. In one of earlier posts, I&nbsp;had referred&nbsp;to information security as an overhead of an overhead (IT).&nbsp;What is a good approach for&nbsp;security practice in this type of economy? </P>
<P>I don't have a magic wand to pull a rabbit out of a hat. I have always been told&nbsp;that: tough economy is the time for&nbsp;real smart people to&nbsp;make money. Coming back to information security topic,&nbsp;with a bit of common sense, it is wise for&nbsp;information security professionals to offer services in&nbsp;those&nbsp;areas&nbsp;that does not involve capital expenditure. As a Security Manager, you may be already aware that your people are willing to&nbsp;go&nbsp;an extra mile in the current economic times.</P>
<P>- No budget or lack of budget,&nbsp;means no&nbsp;new capital expenditure. Spend time wisely in building a future technology strategy and keep it in the back pocket when the economy turns around.</P>
<P>- This is a good time to create roles/responsibilities and ownership for various areas. Create operating procedures.&nbsp;Make your team to automate tasks. This will help your operations become more efficient.</P>
<P>- This is time for security awareness&nbsp; education. Create pamphlets/brochures/presentations for an online or classroom training. Engage your and your team's time to impart training.</P>
<P>- Leverage already invested&nbsp;technology platforms. Leverage utilized features that reduce costs. If you have already invested in technology such as VMware, this is the time to get the best out of it. You can use VMware's toolkit to build your lab and staging&nbsp;environment and optimize on hardware cost.</P>
<P>- Off shoring has been the mantra of senior executives, this is the time to revisit those services and measure their performance closely&nbsp;and assess&nbsp;your satisfaction level. This is a good time to build a case for not off shoring if it makes sense.</P>
<P>- Companies are more vulnerable in bad economic times. You are in a better position&nbsp;to&nbsp;influence senior management about information security risks under these circumstances and drive home the value of protecting your intellectual property under these kinds of circumstances. management will be all ears&nbsp;for such a pitch.</P>
<P>- Time to engage your architect to optimize your security architecture, revisit standards and optimize design for cost efficiency.</P>
<P>- Revisit various controls and see if there are some risks that you could optimize spending on.</P>
<P>- Training budget&nbsp;is an unfortunate victim of&nbsp;this type of economy. Encourage employees to take free webinars offered by various security vendors and encourage them to share the summary across the team. This will put your employees in touch with latest happenings in security at the same time there is some learning that is imparted&nbsp;despite&nbsp;zero training budget.</P>
<P>- Since there are very few projects in action, this is a good time to have conversations with cross functional teams and educate them about your services and solicit feedback on how to do better.</P>
<P>- Revisit your vendor logistics and identify whether you can renegotiate some of your already existing contracts.</P>
<P>The above are some good&nbsp;ways by which you can optimize costs, this will also enhance&nbsp;your team's competence level in the long run. And this approach is better than letting people go, if you can pull this.</P>
<P>&nbsp;</P>]]></content:encoded>
      <pubDate>Sun, 26 Oct 2008 16:37:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/information security risks">information security risks</category>
      <category domain="http://securityratty.com/tag/risks">risks</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/information security professionals">information security professionals</category>
      <category domain="http://securityratty.com/tag/security manager">security manager</category>
      <category domain="http://securityratty.com/tag/information security topic">information security topic</category>
      <category domain="http://securityratty.com/tag/security architecture">security architecture</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <source url="http://ravichar.blogharbor.com/blog/_archives/2008/10/26/3948897.html">Information security in bad economy</source>
    </item>
  </channel>
</rss>
