<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: word]]></title>
    <link>http://securityratty.com/tag/word</link>
    <description></description>
    <pubDate>Mon, 15 Sep 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Privacy In the Cloud: Show Me The Money]]></title>
      <link>http://securityratty.com/article/2e805d07b3a60ac9d955f1ff811f3569</link>
      <guid>http://securityratty.com/article/2e805d07b3a60ac9d955f1ff811f3569</guid>
      <description><![CDATA[Privacy is a lot like universal healthcare. Many agree its a good idea in concept, but few people want to pay for it
Richard Stallman - the man that gave us GNU - doesnt trust Cloud providers with his...]]></description>
      <content:encoded><![CDATA[<p><img class="alignright" style="float: right; border: 0; margin: 3px;" src="http://farm3.static.flickr.com/2052/2404940312_e759c4030d_m_d.jpg" alt="Locker" width="180" height="240" />Privacy is a lot like universal healthcare.  Many agree its a good idea in concept, but few people want to pay for it.</p>
<p>Richard Stallman - the man that gave us <a href="http://www.gnu.org/">GNU</a> - <a href="http://www.guardian.co.uk/technology/2008/sep/29/cloud.computing.richard.stallman">doesn&#8217;t trust Cloud providers with his data</a> and says you shouldn&#8217;t either.  Richard believes we should store our private data on our own computers using &#8216;free&#8217; (as in <a href="http://www.gnu.org/gnu/thegnuproject.html">freedom</a>) software.  The ironic part for Richard is that a significant portion of the Cloud is powered by open source software which he indirectly created (think <a href="http://gcc.gnu.org/">gcc</a>).</p>
<p>Richard sees it as a question of control.  Control is important but it isn&#8217;t the only variable.  Rather, I see it as a question of control, competence and economics.</p>
<p>The quick rebuttal to Richards&#8217; view is this: the average computer user is <a href="http://www.stallman.org/photos/rms-full-size.jpg">not as smart as you</a>.  Control is not the same as competence.  Control is about exercising choice, not about requiring everyone in the world to develop sufficient skills to protect complex hardware and software systems (aka their computer) against <a href="http://ddanchev.blogspot.com/">ever increasing threats</a>.</p>
<p>My view is that privacy is not &#8216;free&#8217;.  It comes at a cost.  Whether you run your own systems or rely on someone else to do it, there is a cost.  There is cost in designing and implementing mechanisms to support privacy.  Beyond upfront costs there are ongoing expenditures to ensure privacy is maintained e.g. maintaining access control lists, testing and applying security patches, data leakage prevention etc.  None of these things are &#8216;free&#8217;.</p>
<p>If we agree that privacy costs money then how much is your privacy worth?</p>
<p>Stop for a second - think of a number&#8230;  </p>
<p>Now did we all think of the <a href="http://pbskids.org/sesame/coloring/images/07_grover.gif">same number</a>?</p>
<p>The problem with a one size fits all approach to privacy is that we each place a different value on it.</p>
<p>Checking in on the <a href="http://epic.org/">EPIC</a> site, I saw this:  </p>
<blockquote><p>A new report from <a href="http://www.pewinternet.org/">Pew Internet and American Life Project</a> indicates that &#8220;cloud computing&#8221; applications, such as web-based email and other web apps, are raising new privacy concerns. The report <a href="http://www.pewinternet.org/press_release.asp?r=306" target="_blank">Use of Cloud Computing: Applications and Services</a> found that 69% of online Americans use webmail services, store data online, or use software programs such as word processing applications whose functionality is located on the web. At the same time, &#8220;users report high levels of concern when presented with scenarios in which companies may put their data to uses of which they may not be aware.&#8221; For example, 90% of respondents said that they &#8220;would be very concerned if the company at which their data were stored sold it to another party,&#8221; 80% say &#8220;they would be very concerned if companies used their photos or other data in marketing campaigns,&#8221; and 68% of &#8220;users of at least one of the six cloud applications say they would be very concerned if companies who provided these services analyzed their information and then displayed ads to them based on their actions.&#8221;</p></blockquote>
<p>What does that tell us?</p>
<p>The average (American) Internet user finds Cloud services convenient but has concerns about how their privacy might be affected by Cloud providers actions (duh!).  The survey identifies a lack of awareness in how private data is used in some consumer based Cloud services (consistent with web advertising awareness surveys).  </p>
<p>Unfortunately, the results of this survey are not very actionable.  The survey doesn&#8217;t mention whether these are all &#8216;free&#8217; Cloud services (we can only assume they are) or ask the respondents what their expectations of privacy are and how much they would be willing to pay for different privacy assurance levels. </p>
<p>On a sidenote, respondents were not asked if they had actually read the privacy agreement for the services they signed up to.  But the providers know if they did or not&#8230;  Or at least, they have the data to figure it out.  At sign up time they can measure the time between displaying the privacy agreement and the user clicking &#8216;I accept&#8217;.  If its just a few seconds then its pretty obvious there was more scrolling than reading going on.  But I think we can probably guess the answer without the data ;-).</p>
<p>I believe we need to be able to link expectation of privacy with cost.</p>
<ul>
<li>How much are you willing to pay for privacy?  What level of privacy assurance do you need?</li>
<li>How much is your Cloud Provider paying to protect your privacy today?  What privacy services could they reasonably offer if they had customers willing to pay?  How might this compare with how you manage your private data on your home computer today?</li>
</ul>
<p>The cynical view is that we expect privacy but don&#8217;t want to pay for it.  Its a bit like uptime - there is a parallel universe out there, where internal IT departments allegedly meet their 99.999% uptime SLAs, but when Gmail goes down, the Sergey Brin witchcraft dolls come out.</p>
<p>From a provider perspective, the &#8220;cost&#8221; of privacy invariably gets bundled under that line item called &#8216;Information Security&#8217;.  And don&#8217;t be fooled, the cost of privacy in reality is more than the salary of the person employed to be the privacy advocate (if there is one).  If we can&#8217;t see how much our providers are spending on our privacy then how can we judge if they are spending enough?  And what is enough?  And what can I get if I&#8217;m willing to pay a little extra?</p>
<p>Personally, I would rather we get some transparency around privacy costs and assessment of offerings.  However, without a sufficiently sized market of customers willing to pay for privacy assurance and Cloud Providers willing to be more open, I won&#8217;t hold my breath.</p>
<p>What about you?  Would you be prepared to pay for privacy?  Should providers be more transparent about what they do and don&#8217;t do and how they do it?<br />
 <br />
 </p>
<p> </p>
<img src="http://feeds.feedburner.com/~r/CloudSecurity/~4/419000947" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 12 Oct 2008 19:49:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/cloud providers">cloud providers</category>
      <category domain="http://securityratty.com/tag/trust cloud providers">trust cloud providers</category>
      <category domain="http://securityratty.com/tag/privacy">privacy</category>
      <category domain="http://securityratty.com/tag/cloud providers actions">cloud providers actions</category>
      <category domain="http://securityratty.com/tag/cloud applications">cloud applications</category>
      <category domain="http://securityratty.com/tag/privacy costs money">privacy costs money</category>
      <category domain="http://securityratty.com/tag/privacy assurance levels">privacy assurance levels</category>
      <category domain="http://securityratty.com/tag/privacy assurance">privacy assurance</category>
      <source url="http://feeds.feedburner.com/~r/CloudSecurity/~3/419000947/">Privacy In the Cloud: Show Me The Money</source>
    </item>
    <item>
      <title><![CDATA[Hand Grenades as Weapons of Mass Destruction]]></title>
      <link>http://securityratty.com/article/e03129712b52a9ce93ee85bc9633c091</link>
      <guid>http://securityratty.com/article/e03129712b52a9ce93ee85bc9633c091</guid>
      <description><![CDATA[I get that this is terrorism: A 24-year-old convert to Islam has been sentenced to 35 years in prison for plotting to set off hand grenades in a crowded shopping mall during the Christmas season
But I...]]></description>
      <content:encoded><![CDATA[<p>I get that <a href="http://news.yahoo.com/s/ap/20080930/ap_on_re_us/terror_sentence;_ylt=AttmTC5Ji0gidcvcR8JejpnZa7gF">this</a> is terrorism:</p>

<blockquote>A 24-year-old convert to Islam has been sentenced to 35 years in prison for plotting to set off hand grenades in a crowded shopping mall during the Christmas season.</blockquote>

<p>But I thought "weapons of mass destruction" was reserved for nuclear, chemical, and biological weapons.</p>

<blockquote>He was arrested in 2006 on charges of scheming to use weapons of mass destruction at the Cherryvale Mall in the northern Illinois city of Rockford.</blockquote>

<p>Like the <a href="http://www.schneier.com/blog/archives/2008/08/the_continuing_1.html">continuing cheapening of the word "terrorism</a>," we are now cheapening the term "weapons of mass destruction."</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=rEwFM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=rEwFM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=RGl4M"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=RGl4M" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 02:37:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mass destruction">mass destruction</category>
      <category domain="http://securityratty.com/tag/weapons">weapons</category>
      <category domain="http://securityratty.com/tag/biological weapons">biological weapons</category>
      <category domain="http://securityratty.com/tag/hand grenades">hand grenades</category>
      <category domain="http://securityratty.com/tag/mall">mall</category>
      <category domain="http://securityratty.com/tag/northern illinois city">northern illinois city</category>
      <category domain="http://securityratty.com/tag/cherryvale mall">cherryvale mall</category>
      <category domain="http://securityratty.com/tag/terrorism">terrorism</category>
      <category domain="http://securityratty.com/tag/christmas season">christmas season</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/hand_grenades_a.html">Hand Grenades as Weapons of Mass Destruction</source>
    </item>
    <item>
      <title><![CDATA[Can You Believe It? With the Financial Markets in Turmoil, the Hosting Industry Continues to Thrive!]]></title>
      <link>http://securityratty.com/article/b7bfb8c522ce436676068950e32e11a9</link>
      <guid>http://securityratty.com/article/b7bfb8c522ce436676068950e32e11a9</guid>
      <description><![CDATA[I am participating in the 4th annual Hosting Transformation Summit in sunny Las Vegas today and have just listened to some heartwarming news from Dan Golding the head of Tier1 Research . Dan kicked...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/datacenter-ani-optimized.gif" border="0" alt="Datacenter_ani_optimized" width="242" height="249" align="left" /> I am participating in the <a href="http://www.hostingtransformation.com/na/2008/" target="_blank">4th annual Hosting Transformation Summit</a> in sunny Las Vegas today and have just listened to some heartwarming news from <a href="http://www.hostingtransformation.com/na/2008/panelists.php" target="_blank">Dan Golding</a> the head of <a href="http://www.t1r.com/" target="_blank">Tier1 Research</a>. Dan kicked off the morning with his Keynote “Managed Hosting and Colocation in 2009 and beyond.” As you may know, ScienceLogic has maintained a large group of customers in the Managed Service Provider industry so we love to keep our ears to the pavement regarding industry trends. (<em><a href="http://www2.sea.siemens.com/NR/rdonlyres/4866BFD6-9181-41BD-90EA-D8380255E826/0/Datacenter_ani_optimized.gif" target="_blank">image from: Siemens</a>)</em></p>
<p>Dan described the Managed Hosting and colocation sector as “on fire” The sector is humming – incredible growth, outstanding execution, blowing away expectations. I must say, looking back 5 years ago after the tech bubble collapse, I can’t believe how strong the <a href="http://blog.wired.com/business/2008/09/why-the-tech-in.html" target="_blank">sector bounced back</a> from those very difficult times.</p>
<p>His presentation was focused on a future, and a longer view for the industry. The HTS conference is packed this year with the largest attendance of Datacenter owners, Managed hosting and colocation companies ever to attend this conference.</p>
<ul>
<li>Demand steady or increasing in all markets, driven largely by capex constraints and greater awareness and choices.</li>
<li>Supply is growing more slowly in the past 18 months as the credit crunch has hurt the ability of providers to expand ( it is very hard to get mortgages, loans only on new datacenter projects). Expansion build-out of existing shells is occurring, but very little on spec.</li>
<li>Demand Growth of 15% in 2008. (Steady and increasing in the out years) However after supply growth peaked at 7.5% in 2007 supply growth now has slowed to 5%</li>
<li>Dan believes that supply growth will pick back up again in 2011</li>
</ul>
<p>Conclusions – supply is tight, demand is high and growing…this very good news for the industry.</p>
<ul>
<li>Some other trends:
<ul>
<li>The <a href="http://royal.pingdom.com/?p=327" target="_blank">green initiatives</a> are more than just a <a href="http://www.greenm3.com/2008/09/cisco-and-ibm-s.html" target="_blank">trend as datacenter owners</a> who don’t figure out how to <a href="http://www.greenm3.com/2008/08/modeling-for-gr.html" target="_blank">maximize power efficiency</a> will be painted as villains.</li>
<li><a href="http://www.webpronews.com/topnews/2008/09/02/us-getting-dominated-in-internet-traffic" target="_blank">Internet traffic</a> and services consumption are linked as Internet traffic growth has been doubling every year (2005-2007)</li>
<li>Prediction: 2011 -2012 - <a href="http://mashable.com/2008/08/31/is-the-us-becoming-a-part-of-the-internet-backwater/" target="_blank">internet traffic</a> will get an exaflood – it is coming with a new breed of applications (set to boxes HD Video, games, etc.) that will drive new traffic patterns. <a href="http://www.nytimes.com/2008/08/30/business/30pipes.html?_r=1&amp;ref=technology&amp;oref=slogin" target="_blank">Growth driven by consumer broadband</a> + applications (HD video) applications, which in turn will drive demand for Managed Hosting / Colocation Services…</li>
</ul>
</li>
</ul>
<p>Managed Hosting Services Highlights</p>
<ul>
<li>Incredibly fast growth 30%+</li>
<li>$10 Billion worldwide revenue by end of 2008</li>
<li>We’ll keep growth pace until at least 2011</li>
<li>Good news, Dan believes that fears about slowdown in growth are wildly overblown.</li>
</ul>
<p>Why is managed hosting growing so fast?</p>
<ul>
<li>Demographic shifts – new breed of IT employees that <a href="http://www.crcexchange.com/outsource-your-it" target="_blank">embrace outsourcing</a></li>
<li>Growth in internet applications <a href="http://www.infoworld.com/article/08/07/30/Clear_strategy_key_for_SaaS_ecommerce_success_1.html?source=rss&amp;url=http://www.infoworld.com/article/08/07/30/Clear_strategy_key_for_SaaS_ecommerce_success_1.html" target="_blank">(SaaS)</a> The acceptance and growth of browser based applications has been enormous!</li>
<li>Ambiguity between web hosting and managed hosting has turned positive</li>
</ul>
<p>Dan’s Key success factors <a href="http://blog.adspotlive.com/managed-hosting-and-related-things-to-be-considered/" target="_blank">managed hosting and services</a></p>
<ul>
<li>High margin services – and not too many – it is so tempting in our day to day business when a customer comes along and wants to come and give us money for a unique on-off service… at this point the answer has to be no – or do it through a partner.</li>
<li>High level of support delivery is critical – don’t cut pay in support people or outsource support to save a nickel… what you are selling is support. Keep doing this well or you will head into a bad place… just as examples in retail like Home Depot and others who have struggled with customer service challenges – the whole business starts to slide into the toilet… High levels of support delivers a strong word of mouth buying cycle</li>
</ul>
<p>Final thoughts, the industry is healthy and will continue to thrive. Customers are looking for the one stop shop, one company that is a trusted advisor to the customer. As customers place more eggs in the Managed Service bucket, the industry will need to tighten-up those SLA’s. Today some parts of the industry have been getting away with loose SLA’s… as customers get more sophisticated and have more on the line, they will become more demanding and require robust multi-component SLAs and back-it –up.</p>
]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 11:00:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fast">fast</category>
      <category domain="http://securityratty.com/tag/demand steady">demand steady</category>
      <category domain="http://securityratty.com/tag/demand">demand</category>
      <category domain="http://securityratty.com/tag/incredibly fast growth">incredibly fast growth</category>
      <category domain="http://securityratty.com/tag/growth">growth</category>
      <category domain="http://securityratty.com/tag/drive demand">drive demand</category>
      <category domain="http://securityratty.com/tag/drive">drive</category>
      <category domain="http://securityratty.com/tag/internet traffic growth">internet traffic growth</category>
      <category domain="http://securityratty.com/tag/industry">industry</category>
      <source url="http://blog.sciencelogic.com/can-you-believe-it-with-the-financial-markets-in-turmoil-the-hosting-industry-continues-to-thrive/09/2008">Can You Believe It? With the Financial Markets in Turmoil, the Hosting Industry Continues to Thrive!</source>
    </item>
    <item>
      <title><![CDATA[Sorry, Qantas, No Unfettered Broadband]]></title>
      <link>http://securityratty.com/article/e46bb700b1a972d41bfd64aba65817f9</link>
      <guid>http://securityratty.com/article/e46bb700b1a972d41bfd64aba65817f9</guid>
      <description><![CDATA[Qantas backs off from earlier plans, changes provider for in-flight broadband: The Sydney Morning Herald somewhat erratically and incompletely reports that Qantas has delayed and modified its...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/plane.jpg" align="right" border="0" hspace="5" /><a href="http://www.smh.com.au/news/travel/qantas-limits-access-to-web/2008/09/17/1221330929870.html"><strong>Qantas backs off from earlier plans, changes provider for in-flight broadband:</strong></a> The Sydney Morning Herald somewhat erratically and incompletely reports that Qantas has delayed and modified its in-flight broadband plans. Aeromobile was the provider when the service <a href="http://www.breakingtravelnews.com/article.php?story=2007081609481129&query=qantas"><strong>was tested in second quarter 2007</strong></a>, but OnAir is now described as the airline's partner. This was noted by colleague Fabio Zambelli, who emailed me the news, and <a href="http://www.setteb.it/content/view/4742"><strong>has his own account</strong></a> at 7BIT (in Italian).</p>

<p><a href="http://www.onair.aero/index.php?pid=123"><strong>OnAir</strong></a> has so far tested their calling/texting-only service on two aircraft--one operated by Air France, one by TAP Portugal--even though RyanAir announced plans that its planes would started being unwired with the service by late 2007. Still no word on that fleet progress.</p>

<p>Qantas will apparently launch cached Web browsing and limited Web email (probably through a proxy) along with instant messaging, with full Internet service coming "later in 2009." This is clearly due to a lack of satellite coverage that was just remediated a few weeks ago (see below). The first plane with limited service, a new A380, should be in flight 20-October-2008.</p>

<div style="float:right; margin:0px; padding-left: 10px; padding-bottom: 0px;"><p><img src="http://wifinetnews.com//images/2008/SorryQantas.jpg" alt="SorryQantas.jpg" border="0" width="100" height="152"></p><p style="font-size: 10px">I hate in-flight<br/>broadband</p></div>To Qantas' credit, note that each seat on the plane will have a laptop opower socket, a USB port, and a multimedia system that can show 100 movies and 500 TV show episodes, play the contents of 1,000 CDs and 20 radio stations, and offer 80 games. 

<p>The Morning Herald seems to overstate the importance and scope of a complaint filed by the union representing American Airlines' flight attendants. The detailed coverage in the U.S. had more to do with the potential for issues, and likely attendants lack of interest in policing yet another media on the plane. Filtering doesn't work, the attendants probably already know, and this may just be a negotiating point with the airline.</p>

<p>On why Qantas is waiting until late 2009? This requires unwinding how OnAir gets its signal.</p>

<p>Aeromobile and OnAir both rely on Inmarsat satellites for their service. Both companies had several years ago staked their futures on the fourth-generation network Inmarsat was to inaugurate with three satellites that would use beamforming to allow precise delivery of nearly 500 Kbps per receiver, with hundreds or thousands of regions being able to be targeted from a single satellite. Inmarsat's third-gen network--don't confuse this with 3G cellular ground-based networks--can deliver about 64 Kbps per channel.</p>

<p>Now, unfortunately, Inmarsat was three years late on launching its trans-Pacific bird. While the company <a href="http://www.inmarsat.com/About/Newsroom/Press/00021465.aspx?language=EN&textonly=False"><strong>claims 85 percent coverage of the earth</strong></a> and 98 percent coverage of population, there's a big gap over the Pacific that also prevents them from having good overlap between the U.S. and Japan/China/Korea, as well as the southern Pacific, covering Australia. Since the biggest market for long-haul flights would likely be Australia, Japan, and China, traveling trans-Pacific or trans-hemispheric routes, that gap is rather large.</p>

<p>Aeromobile opted to build out a service, deployed only by Emirates airline as far as I can tell, that uses the 3G service since it was available, and most necessary equipment is already installed on most over-water planes. OnAir was waiting for 4G, which has necessitated a long wait, but allowed them to launch in Europe with a seemingly next-generation service. Given that OnAir is controlled by an airline-owned integration firm, SITA, and by Airbus, they're not going anywhere.</p>

<p>Inmarsat finally <a href="http://spaceflightnow.com/proton/i4f3/"><strong>lofted its third satellite on Baikonur Cosmodrome in Kazakhstan</strong></a> on 19-August-2008, and the launch and separation was reported as successful. Previously, the company has needed up to a year to verify and deploy its 4G satellites. (You can <a href="http://forum.nasaspaceflight.com/index.php?topic=12380.105"><strong>read extremely close coverage of the launch</strong></a> at a Web site devoted to space enthusiasm.)</p>

<p>However, the dirty little secret about Inmarsat's BGAN is that it costs a fortune to heft bandwidth across it. Thus, in-flight broadband over BGAN, if it's ever available, is going to be changed on an extremely high per-MB rate. None of the providers want to say this. This is in contrast to Row 44 (and, once, Connexion by Boeing), which relies on leased Ku-band transponders where they can fix costs and they require high volumes to keep per-bit costs efffectively low.</p>

<p>OnAir's launch of calling on Air France's service involves paying a few euros per minute for calls, which might help you understand what data costs could ultimately run.</p>]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 06:33:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/satellite coverage">satellite coverage</category>
      <category domain="http://securityratty.com/tag/coverage">coverage</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/service involves">service involves</category>
      <category domain="http://securityratty.com/tag/internet service">internet service</category>
      <category domain="http://securityratty.com/tag/in-flight broadband plans">in-flight broadband plans</category>
      <category domain="http://securityratty.com/tag/plans">plans</category>
      <category domain="http://securityratty.com/tag/inmarsat satellites">inmarsat satellites</category>
      <category domain="http://securityratty.com/tag/inmarsat">inmarsat</category>
      <source url="http://wifinetnews.com/archives/008448.html">Sorry, Qantas, No Unfettered Broadband</source>
    </item>
    <item>
      <title><![CDATA[Dumb Luck IS a Strategy!]]></title>
      <link>http://securityratty.com/article/16ab612b9342a48155481fcdd1dcf4fd</link>
      <guid>http://securityratty.com/article/16ab612b9342a48155481fcdd1dcf4fd</guid>
      <description><![CDATA[While still at GOVCERT.NL , I've attended a fun little presentation, describing a penetration test (I cannot provide any more details as it was a &quot;No Press&quot; presentation - this post is not about it,...]]></description>
      <content:encoded><![CDATA[<p>While still at <a href="http://www.govcert.nl/symposium/index.html">GOVCERT.NL</a>, I've attended a fun little presentation, describing a penetration test (I cannot provide any more details as it was a &quot;No Press&quot; presentation - this post is not about it, but rather was inspired by it!)</p>  <p>In any case, if you do pentests, think about all the RECENT cases where you break in to a major corporation through:</p>  <ul>   <li>a Solaris system with Internet-exposed telnet with a guessable password OR a telnet vulnerability (circa 1994!) </li>    <li>an exposed VPN appliance with a manufacturer's administrator password </li>    <li>a router with default &quot;enable&quot; password </li>    <li>or, something else entirely - but something that rivals the above example in its <strong>unparalleled, unbelievable, abysmal, deep idiocy.</strong> </li> </ul>  <p>Indeed, many of my pentesting friends still report plenty of such cases (one was also featured in the presentation mentioned above). Whenever I hear about it from a pentester, I always ask:</p>  <p><strong><font size="4">Do you think &quot;somebody bad&quot; had already passed through the hole you just discovered?</font></strong></p>  <p>Maybe an hour ago, a day ago - or a year ago?!</p>  <p><strong>I cannot see how the answer can be &quot;no.&quot; </strong></p>  <p>Even though pentesters usually don't focus on forensics (no time for this), it is not uncommon to notice &quot;your predecessor's&quot; intrusion traces while you break through systems, &quot;plant flags&quot;, change screen backgrounds [for the admins to notice that you've been there...], etc. </p>  <p>Let's think what this situation really means? Here are the choices I see:</p>  <ol>   <li><strong>Nobody discovered the hole</strong> - a law of large&#160; numbers (aka &quot;dumb luck&quot;) have &quot;shielded&quot; the company from an incident. Yes, Virginia, dumb luck IS a security strategy for some companies... AND it works for them. </li>    <li><strong>It was discovered, but not used/abused by the attacker</strong> - maybe he was busy hacking other systems, or saved this for later and never came back due to his ADD. Congratulation, you win! The immense power of dumb luck wrapped you in a protective &quot;security&quot; blanket ... again :-) </li>    <li><strong>It was discovered; the attacker went in, looked around and compromised a few others systems</strong>, but found nothing of interest (no low hanging fruits)&#160; - and he was not a bot herder. Again, you win. Next time you are in Vegas, bet on &quot;00.&quot; </li>    <li><strong>It was discovered; the attacker went in and deployed a bot on &quot;your&quot; system </strong>- given how many botnets are there, this situation is clearly <em>acceptable</em> to many organizations. In this case, dumb luck strategy, apparently, still work: so they use your box to spam and phish somebody else ... big deal!</li>    <li><strong>It was discovered; the attacker went in and stole all your credit card information (it is now for sale) </strong>- even in this case, the user of &quot;the dumb luck strategy&quot; still &quot;wins&quot; (in some perverse sense)! Unless and until the stolen information IS tracked back to you OR a friendly neighborhood PCI auditor come and jams a broomstick up your ..., you can still continue to be stupid at your leisure and ignore basic security practices. </li>    <li><strong>It was discovered; the attacker went in and stole your CEO's Inbox, including the email related to his affair (it is now on CNN) - </strong>now, in this case, you lose AND it is time to stop being stupid! Welcome to the &quot;0wned world.&quot; Time to launch (relaunch?) your security program and get serious. </li> </ol>  <p>What does this teach us about RISK? The lesson here is important:</p>  <ul>   <li>For a security professional, an Internet-exposed system with &quot;root/root&quot; is an obvious <strong>HUGE</strong> risk! </li>    <li>For your boss's boss's boss, it is <strong>NOT</strong>! </li> </ul>  <p>This is exactly why I think that <strong>the most critical problem in security today is METRICS</strong>. Metrics that <strong>a) work AND mean something to decision makers</strong> and <strong>b) can be clearly communicated to said decision makers [</strong>BTW, a) and b) are two separate problems.] Metrics that cover not only threats and vulnerabilities we face, but also the effectiveness of security countermeasures we deploy. Metrics you can act on - and ones your boss (and his boss) will act on. Metrics that lead to correct decisions about which risks to accept, which to&#160; mitigate (all while knowing with what efficiency such mitigation occurs) and which to transfer.</p>  <p>Until that time, the dreaded &quot;C-word&quot; (<strong>c</strong>ompliance) will trump &quot;the other C-word&quot; (<strong>c</strong>ommon sense) as a driver for security ... and we will continue to live in the &quot;0wned world.&quot;</p>  <p><strong>Possibly related posts:</strong></p>  <ul>   <li><u><a href="http://chuvakin.blogspot.com/2007/11/risk-vs-risk.htmll">Risk vs Risk</a></u>&#160;</li> </ul>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=AdXkL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=AdXkL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=SqYRL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=SqYRL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=UGPML"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=UGPML" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/396385129" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 05:38:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dumb luck">dumb luck</category>
      <category domain="http://securityratty.com/tag/dumb luck strategy">dumb luck strategy</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security countermeasures">security countermeasures</category>
      <category domain="http://securityratty.com/tag/security professional">security professional</category>
      <category domain="http://securityratty.com/tag/security program">security program</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/obvious huge risk">obvious huge risk</category>
      <category domain="http://securityratty.com/tag/password">password</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/396385129/dumb-luck-is-strategy.html">Dumb Luck IS a Strategy!</source>
    </item>
    <item>
      <title><![CDATA[Interop NY: IT Roundtable]]></title>
      <link>http://securityratty.com/article/4137ad5ff76308605c9861b27c7d0404</link>
      <guid>http://securityratty.com/article/4137ad5ff76308605c9861b27c7d0404</guid>
      <description><![CDATA[This session is a bit different than the usual sessions at Interop. It provides insights from three CIOs in three different industries
Moderator: Jim Metzler, Vice President, Ashton, Metzler &amp;...]]></description>
      <content:encoded><![CDATA[<p>This session is a bit different than the usual sessions at Interop. It provides insights from three CIOs in three different industries.</p>
<ul>
<li>Moderator: Jim Metzler, Vice President, Ashton, Metzler &amp; Associates</li>
<li>Rowan Snyder, CIO, KPMG</li>
<li>David Michael, CIO, United Business Media Group</li>
<li>Joanna Young, Chief Information Officer, Corporate Information Systems &amp; Enterprise Services, Liberty Mutual</li>
</ul>
<p><strong>Jim: Is the CIO a technical job anymore? For example, inside Liberty there are business projects with an IT component.</strong></p>
<p><strong>Joanna:</strong> We are organized to partner with internal business clients or vendors who provide objectives and business requirements. We strive to figure out the smallest amount of an IT investment we can make to get this to work.</p>
<p><strong>Rowan:</strong> We have both. Part of the dilemma is that the thing that sells the best is fear. I don&#8217;t want to use that to get business.</p>
<p><strong>Joanna:</strong> One good example is security from an application perspective. It&#8217;s hard to talk about security investments in business terms. We put it into terms like &#8220;this is what it will cost us if we DON&#8217;T do this.&#8221; For example, a solution for spam required us to do research into what it was costing us overall. Once we put it together, the business was all for it. You have to put your business hat on and think &#8220;how can I make this important for a businessperson?&#8221; If you can&#8217;t, you may need to ask yourself why you&#8217;re pushing services on them that they may not need.</p>
<p><strong>Jim: Can you give us insight into business-IT alignment? What about governance?</strong></p>
<p><strong>Rowan:</strong> Governance is the hardest part of IT. It&#8217;s not like the technology is easy. If it&#8217;s a business project with an IT component, I don&#8217;t usually get involved. It comes down to overall budget. The infrastructure we own and let people know exactly what it will cost to do it. We are a distributed IT firm, there are multiple groups. This is the most distributed and risk-prone organization I&#8217;ve worked in. It can be difficult for the business to exert control. It demonstrates risk, in security, compliance, methodologies, etc.</p>
<p><strong>Joanna:</strong> Governance has become a word that nobody wants to use. It suddenly implies that IT is the holder of all the money and they are the ones that get to decide. We stopped using that word and position IT as a strategic business partner.</p>
<p><strong>David:</strong> We have a highly decentralized IT set-up. We have about 600 globally and around 40 in the headquarters. We have 10 CIOs for each division, and within each division it is decentralized. We try to run each unit as autonomous. This is a close alignment with IT and business. However, then the problem of how do you have commonality between divisions and collaboration?</p>
<p><strong>Jim: How can you minimize risk in distributed environment using standards and procedures?</strong></p>
<p><strong>David:</strong> The reality is it can be impractical for an organization. You end up with a patchwork of platforms and technologies. We have to accept that we&#8217;ll have multiple solutions. We can attempt to push a standard, but overall have a much more relaxed approach to manage everything. There is a lot of equality between divisions in what they can choose to purchase.</p>
<p><strong>Joanna:</strong> Standards are easier to apply the further down the staff you are. The most important thing with any of this is to understand why you are making the decisions. If there is a process and pros and cons are identified, there is a clear record of why decisions were made.</p>
<p><strong>Audience Poll: Everyone raised their hand that MORE standards were needed</strong>.</p>
<p><strong>Audience Question: Are there inefficiencies in the data center in terms of energy and green IT? What are you doing about it?</strong></p>
<p><strong>Joanna:</strong> Everyone focuses on cars for carbon footprints. But, it&#8217;s really buildings&#8230;and then data centers. The data center has the same importance as any other efficiency. They need to be running as cheaply as possible. Corporations have a responsibility to make sure they are energy efficient.</p>
<p><strong>Rowan:</strong> We recently did a carbon footprint analysis, and found that half of carbon comes from electricity, with half of that from the data center.</p>
<p><strong>David:</strong> Every company does have a responsibility to look at its carbon emission globally. Consider international travel, flying, etc. As much as possible, we are not building data centers. We are using other people&#8217;s data centers in an effort to get out of the data center business.</p>
<p><strong>Audience Question: How do you balance the good from standards with agile development and possible roadblocks?</strong></p>
<p><strong>Joanna:</strong> Luckily agile development is under the CIO&#8217;s control. You can see the lifecycle and savings that occur. When I look, I check what the standards are that I&#8217;m measuring by.</p>
<p><strong>Jim: Does web 2.0 have any business meaning in your environment? If so, what are you doing about it?</strong></p>
<p><strong>Joanna:</strong> I&#8217;ve been in IT for 20 years. It&#8217;s another component to business IT investment, and has to be presented as such. As IT professionals we have a responsibility to identify what Web 2.0 is, and then translate to see if there is anything the company should be doing with it. Monitor it based on your current portfolio, and consider its impact.</p>
<p><strong>David:</strong> It&#8217;s pretty important to our business as a media company. I don&#8217;t think it means one thing, it&#8217;s a term people use to talk about the web and what&#8217;s going on online. From mobile, to ajax, cloud computing or mashups - you can draw multiple conclusions. More and more business is being done online. We have a lot of growth opportunities online.</p>
<p><strong>Rowan:</strong> Compliance, security, and privacy issues just explode with Web 2.0.</p>
]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 15:45:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/terms">terms</category>
      <category domain="http://securityratty.com/tag/data center business">data center business</category>
      <category domain="http://securityratty.com/tag/data center">data center</category>
      <category domain="http://securityratty.com/tag/business terms">business terms</category>
      <category domain="http://securityratty.com/tag/business projects">business projects</category>
      <category domain="http://securityratty.com/tag/business-it alignment">business-it alignment</category>
      <category domain="http://securityratty.com/tag/internal business clients">internal business clients</category>
      <category domain="http://securityratty.com/tag/business hat">business hat</category>
      <source url="http://blog.sciencelogic.com/interop-ny-it-roundtable/09/2008">Interop NY: IT Roundtable</source>
    </item>
    <item>
      <title><![CDATA[Interop NY Keynotes: Cisco]]></title>
      <link>http://securityratty.com/article/c55a3293fe594f4363a5830f6da4d48c</link>
      <guid>http://securityratty.com/article/c55a3293fe594f4363a5830f6da4d48c</guid>
      <description><![CDATA[After some rousing introduction music, Marie Hatter , Vice President, Network Systems and Security Solutions Marketing / CMO of Cisco began her presentation on virtualization
Introduction...]]></description>
      <content:encoded><![CDATA[<p>After some rousing introduction music, <a href="http://blogs.cisco.com/authors/bio/83" target="_blank">Marie Hatter</a>, Vice President, Network Systems and Security Solutions Marketing / CMO of Cisco began her presentation on virtualization.</p>
<p><strong>Introduction</strong></p>
<p>Virtualization is a word used by consumers and also by IT. But, do we all mean the same thing?</p>
<p>A very cool video from Cisco provided answers to &#8220;what is virtualization&#8221; from an  engineering perspective, data center perspective, IT perspective and the user perspective (virtual world).</p>
<p>Virtualization is about breaking the bonds between applications and server hardware, nodes and networks, applications and operating systems.</p>
<p>Why is this interesting? Virtualization holds the promise to transform the way we work, live, learn and play.</p>
<p><strong>Why virtualize?</strong></p>
<p>The real estate boom over the last 30 years has driven people to the suburbs. People didn&#8217;t mind commuting for an hour with lower gas prices. Today, we have a weak economy and gas prices are high. Something has to change.</p>
<p>Many are opting to stay at home. Businesses are trying out telecommuting, some (like Cisco) are even offering telepresence. This helps by reducing carbon footprint. Corporations are breaking free from physical requirements. The global workforce is also having an impact on the network. These changes are having a huge impact on the network.</p>
<p>We are on the cusp of transitioning from virtualization to VIRTUALIZATION.</p>
<p><strong>&#8220;One to many&#8230;.many to one.&#8221;</strong></p>
<p>This is Cisco&#8217;s idea of virtualization.</p>
<p>Consider the different roles we play in life - one to many. Spouse, executive, friend, parent, gym rat. This would be &#8220;one to many&#8221;. This is exactly what virtualization does. It allows you to partition resources off that you can use on the fly.</p>
<p><strong>Where do I start?</strong></p>
<p>Virtualization starts with server and storage. But, it&#8217;s the network that touches everything - it spans the physical, the virtual, and the cloud. This provides the connectivity to all these resources. The network brings transparency to the picture. It allows you to better monitor performance and better implement security - great benefits!</p>
<p><strong>Why do I need this?</strong></p>
<p>At Cisco, we saw that we were only using 20% of our storage utilization. We wanted to virtualize our datacenters. When we did that, we were able to get 68% storage utilization. For each year that we were able to defer buildup, we saved $40 million.</p>
<p>From a business standpoint, virtualization helps you differentiate and work faster. Provisioning in minutes, improved productivity and competitive differentiation, using less power (environmental impact), and up the ante of business continuity. If VMWare fails? It&#8217;s OK. You can reprovision it on the fly.</p>
<p><strong>Is it for everyone?</strong></p>
<p>IT organizations tend to be siloed. You have the IT side and the Operations side. Each has responsibility. For virtualization to work, these walls have to come down. The concept of virtualization depends on shared resources.</p>
<p><strong><a href="http://en.wikipedia.org/wiki/Metcalfe%27s_law" target="_blank">Metcalfe&#8217;s Law of the Network</a> Effect</strong></p>
<p>Everytime you add a node to the network, you increase the value. This is what happens with virtualization. Every device you virtualize increases the power of each device. More control of environment and more efficiency.</p>
<p>This leads to&#8230;</p>
<p><strong>Cloud computing.</strong></p>
<p>Wow, show of hands from the audience when Marie asked &#8220;how many are using cloud computing?&#8221; and &#8220;how many are using your own clouds?&#8221; - not a lot of hands were raised. Interesting considering the coverage cloud computing has and the focus of it.</p>
<p>Cloud computing has three possibilities at Cisco:</p>
<ul>
<li>Flexible infrastructure (hosting)</li>
<li>Abstract services (APIs)</li>
<li>Application services (SaaS)</li>
</ul>
<p>Automation is going to be key, and will need to integrate virtualization-aware elements.</p>
<p>Can you imagine if you wanted interoperability in the cloud? People haven&#8217;t even begun thinking about it.</p>
<p><strong>Conclusion</strong></p>
<p>As you virtualize, your role will change. You will think more about strategy. But keep in mind these &#8220;minefields&#8221; of virtualization:</p>
<ul>
<li>Insufficient planning</li>
<li>Lack of standards</li>
<li>Weak security</li>
</ul>
<p>Security cannot be an afterthought. It has to be planned. We&#8217;ve seen new forms of malware, hypervisor attacks, and root kit infections.</p>
<p>As higher expectations from end users evolve, we&#8217;re becoming not server oriented, but SERVICE oriented.</p>
<p><strong>Tips:</strong></p>
<ul>
<li>Think holistically</li>
<li>Consider IT culture - equipment and people</li>
</ul>
]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 10:11:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/virtualization starts">virtualization starts</category>
      <category domain="http://securityratty.com/tag/virtualization helps">virtualization helps</category>
      <category domain="http://securityratty.com/tag/helps">helps</category>
      <category domain="http://securityratty.com/tag/virtualization depends">virtualization depends</category>
      <category domain="http://securityratty.com/tag/virtualization holds">virtualization holds</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/network brings transparency">network brings transparency</category>
      <category domain="http://securityratty.com/tag/cisco">cisco</category>
      <source url="http://blog.sciencelogic.com/interop-ny-keynotes-cisco/09/2008">Interop NY Keynotes: Cisco</source>
    </item>
    <item>
      <title><![CDATA[Risk Management at Catalyst: Learning from the Past]]></title>
      <link>http://securityratty.com/article/cdcc6abd33d2bca90707ee704a736fd7</link>
      <guid>http://securityratty.com/article/cdcc6abd33d2bca90707ee704a736fd7</guid>
      <description><![CDATA[Blogger: Trent Henry
Burton Groups Catalyst Europe conference is just around the corner. With financial services industry failures at the top of everyones mind, nows a great time to revisit how risk...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Trent Henry</p>

<p>Burton Group’s Catalyst Europe conference is just around the corner. With financial services industry failures at the top of everyone’s mind, now’s a great time to revisit how risk management shortcomings have tremendous impact on organizations of every kind. In a reprise of his insightful Catalyst North America talk, Nick Leeson will once again detail how inadequate controls (and foolish actions on his part) brought about the fall of Barings Bank. In addition, security conversations at Catalyst will include:</p>

<p> - How large enterprises are grappling with governance, risk, and compliance (and why “GRC” is actually a four-letter word)<br />
 - What large, distributed organizations are doing to create effective “security embassies”<br />
 - The role of metrics in managing protection and communicating with Management<br />
 - How information-centric security will unfold over the next five years</p>

<p><object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/FJEDKgiCIXE&hl=en&fs=1"></param><param name="allowFullScreen" value="true"></param><embed src="http://www.youtube.com/v/FJEDKgiCIXE&hl=en&fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="425" height="344"></embed></object></p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/395263711" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 07:00:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/management">management</category>
      <category domain="http://securityratty.com/tag/catalyst">catalyst</category>
      <category domain="http://securityratty.com/tag/effective security embassies">effective security embassies</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/risk management shortcomings">risk management shortcomings</category>
      <category domain="http://securityratty.com/tag/catalyst europe conference">catalyst europe conference</category>
      <category domain="http://securityratty.com/tag/security conversations">security conversations</category>
      <category domain="http://securityratty.com/tag/nick leeson">nick leeson</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/395263711/risk-management.html">Risk Management at Catalyst: Learning from the Past</source>
    </item>
    <item>
      <title><![CDATA[The Importance of Trust]]></title>
      <link>http://securityratty.com/article/a237a38c2b93a16a5d0702327c562838</link>
      <guid>http://securityratty.com/article/a237a38c2b93a16a5d0702327c562838</guid>
      <description><![CDATA[As an instructor and trainer, I am constantly reinforcing the importance of living by one's word

Integrity, Honor, Loyalty - all of these fine characteristics are the building blocks upon which...]]></description>
      <content:encoded><![CDATA[As an instructor and trainer, I am constantly reinforcing the importance of living by one's word.  <br /><span id="fullpost"><br />Integrity, Honor, Loyalty - all of these fine characteristics are the building blocks upon which reputations are raised.  It is of the utmost importance in any walk of life to "live by your word", but in the security profession - especially where the protecting of life is concerned, it is everything. <br /></span><br />I attended National Stadium last night and watched the Washington Nationals beat the New York Mets.  I was fortunate to have been invited to enjoy the game from the president's box.  During the pre-dinner networking, I ran into a business owner whom I had met a few years previously.  He had been introduced to me at that time as his business involved him being around some area celebrity sporting stars.<br /><br />Being interested in a chance to possibly offer executive protection services to these stars, I arranged to meet with this business owner to discuss how we might be able to assist one another.  I remember it was during the winter and the roads were a little suspect in places as I drove the 25-30 miles to be closer to his location.  <br /><br />I arrived a little early, as is my custom and waited for him to arrive.  It became clear after about an hour that he was experiencing some difficulty or had some other reason for being so late.  I left a few voice mails and called it quits after around 90 minutes.  He never returned any of my calls but when I reached him about a week later he admitted that something else had come up.  Unfortunately, he did not think it worth his while to let me know this with a phone call.<br /><br />So, here I am last night and this same person is introduced to me once again.  Maybe he didn't remember back three years ago because he started to tell me about some connection that he knew that may be a "good fit" for my company.  His small talk fell on deaf ears.  He had already lost all credibility with me and eventhough I have not thought about it once in the inetrvening years, as soon as I saw him it came back as clear as day.<br /><br />In his book; "The Speed of Trust", the author Stephen M.R. Covey sums it up best - "keeping commitments is based on the principles of integrity, performance, courage and humility.  It is the perfect balance of character and competence. Particularly, it involves integrity (character) and your ability to do what you say you are going to do (competence)."<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 15:46:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/importance">importance</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/business owner">business owner</category>
      <category domain="http://securityratty.com/tag/integrity">integrity</category>
      <category domain="http://securityratty.com/tag/involves integrity">involves integrity</category>
      <category domain="http://securityratty.com/tag/utmost importance">utmost importance</category>
      <category domain="http://securityratty.com/tag/competence">competence</category>
      <category domain="http://securityratty.com/tag/security profession">security profession</category>
      <category domain="http://securityratty.com/tag/deaf ears">deaf ears</category>
      <source url="http://www.thebulletproofblog.com/2008/09/importance-of-trust.html">The Importance of Trust</source>
    </item>
    <item>
      <title><![CDATA[Breaking Down the Walls of Compliance Challenges]]></title>
      <link>http://securityratty.com/article/7c61fff825b5171c5fec0c8e8ae65de2</link>
      <guid>http://securityratty.com/article/7c61fff825b5171c5fec0c8e8ae65de2</guid>
      <description><![CDATA[Compliance, Compliance, Compliance. Its the word thats on everybodys lips in the security industry these days. Companies of all shapes &amp; sizes are spending big bucks to ensure compliance, but what are...]]></description>
      <content:encoded><![CDATA[Compliance, Compliance, Compliance.&nbsp; It&rsquo;s the word that&rsquo;s on everybody&rsquo;s lips in  the security industry these days.&nbsp; &nbsp;Companies of all shapes &amp; sizes are  spending big bucks to ensure compliance, but what are they trying to be  compliant to?&nbsp; Regulatory issues, legal issues,  internal policies &amp; procedures or all of the above???&nbsp;&nbsp;&nbsp; Unfortunately, trying to be compliant in  any of these areas brings challenges <B>but there are some ways to make it a  little easier...</b>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/ensure compliance">ensure compliance</category>
      <category domain="http://securityratty.com/tag/everybodys lips">everybodys lips</category>
      <category domain="http://securityratty.com/tag/legal issues">legal issues</category>
      <category domain="http://securityratty.com/tag/security industry">security industry</category>
      <category domain="http://securityratty.com/tag/compliant">compliant</category>
      <category domain="http://securityratty.com/tag/internal policies">internal policies</category>
      <category domain="http://securityratty.com/tag/regulatory issues">regulatory issues</category>
      <category domain="http://securityratty.com/tag/brings challenges">brings challenges</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1346">Breaking Down the Walls of Compliance Challenges</source>
    </item>
  </channel>
</rss>
