<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] category: Compliance]]></title>
    <link>http://www.securityratty.com/category/Compliance</link>
    <description></description>
    <pubDate>Mon, 18 Aug 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[ROI Jokes?]]></title>
      <link>http://www.securityratty.com/article/e5304cb35c9fb6ece1336fb6b4d3b5f1</link>
      <guid>http://www.securityratty.com/article/e5304cb35c9fb6ece1336fb6b4d3b5f1</guid>
      <description><![CDATA[Yes, they ARE possible

This also remind me of &quot; ROI for compliance&quot; stuff
About me:...]]></description>
      <content:encoded><![CDATA[Yes, they <a href="http://www.datagovernance.com/cartoon_2.html">ARE </a>possible.<br /><br />This also remind me of "<a href="http://chuvakin.blogspot.com/2007/01/roi-on-not-getting-your-ass-whooped.html">ROI for compliance" stuff.</a><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=rwdMsK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=rwdMsK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=asvdfK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=asvdfK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=3d9ipK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=3d9ipK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/376537467" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 10:24:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/roi">roi</category>
      <category domain="http://www.securityratty.com/tag/compliance">compliance</category>
      <category domain="http://www.securityratty.com/tag/org">org</category>
      <category domain="http://www.securityratty.com/tag/stuff">stuff</category>
      <category domain="http://www.securityratty.com/tag/remind">remind</category>
      <category domain="http://www.securityratty.com/tag/chuvakin">chuvakin</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/376537467/roi-jokes.html">ROI Jokes?</source>
    </item>
    <item>
      <title><![CDATA[Fun Reading on Security - 7]]></title>
      <link>http://www.securityratty.com/article/c474f15d19ef80949f385cbe7b510b79</link>
      <guid>http://www.securityratty.com/article/c474f15d19ef80949f385cbe7b510b79</guid>
      <description><![CDATA[Instead of my usual &quot;blogging frenzy&quot; machine gun blast of short posts, I will just combine them into my new blog series &quot; Fun Reading on Security .&quot; Here is an issue #7, dated August 27th, 2008
Sad,...]]></description>
      <content:encoded><![CDATA[<p>Instead of my usual &quot;blogging frenzy&quot; machine gun blast of short posts, I will just combine them into my new blog series &quot;<a href="http://chuvakin.blogspot.com/search/label/reading">Fun Reading on Security</a>.&quot; Here is an issue #7, dated August 27th, 2008.</p>  <ol>   <li>Sad, but VERY insightful story of Alan Shimmel getting 0wned (<a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/08/im-back.html">1</a>,<a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/08/more-frustratio.html">2</a>,<a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/08/our-web-infrast.html">3</a>,<a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/08/why-google-is-n.html">4</a>, others on his blog) </li>    <li>A very good essay on security industry/market/community &quot;<a href="http://blog.trailofbits.com/2008/07/24/evolution-is-punctuated-equilibria/">Evolution is Punctuated Equilibria</a>&quot; <em>(&quot;Right now, Internet security is due for another period of rapid change.&quot;)</em> </li>    <li>As I like to say, most everybody in out industry is confused about risk (myself included, in fact) - here is some nice reading about the subject: &quot;<a href="http://layer8.itsecuritygeek.com/layer8/quant-love/">Quant love&quot;</a>, &quot;<a href="http://risktical.com/2008/07/31/what-is-risk/">What is Risk?</a>&quot; (&quot;<em>The probability of a threat overcoming security controls resistance to exploit a vulnerability that results in a loss.</em>&quot;) While you are at it, check <a href="http://risktical.com/2008/08/24/risk-and-cvss-post-1/">this blurb</a> about risk and <a href="http://www.first.org/cvss/">CVSS</a> (BTW, <a href="http://www.first.org/cvss/">CVSS</a> is about &quot;V&quot; - vulnerability, not &quot;R&quot; for risk!)</li>    <li>Solid gold on &quot;running IT as business&quot; (and where it hits the wall) - <a href="http://taosecurity.blogspot.com/2008/08/limits-of-running-it-like-business.html">Richard</a>, <a href="http://www.cio.com/article/print/335813">the original CIO.com piece</a>&#160;<em>(&quot;If you've tried managing an internal IT department as a bona fide business you already know that you can't take that very far, for the obvious reason that your IT department isn't a business.&quot;)</em> </li>    <li>More fun stuff from Richard <a href="http://taosecurity.blogspot.com/2008/07/counterintelligence-worse-than-security.html">on insiders and why NOT look for them</a> (sadly, same logic applies to not looking for owned boxes in your environment...). </li>    <li>Analyst firms <a href="http://www.forrester.com/Research/Document/Excerpt/0,7211,46811,00.html">shocking discovery</a>: wireless MAY have security issues (I guess count it as humor...)</li>    <li>Fun read: &quot;<a href="http://onsaas.net/2008/08/23/challenges-of-enterprise-cloud-computing/">Challenges of Enterprise Cloud Computing</a>&quot; (<em>&quot;By moving the data into the cloud, enterprise, for now, will lose some capabilities to govern their own data set.&quot;</em>) </li>    <li><a href="http://searchnetworking.techtarget.com/news/article/0,289142,sid7_gci1326271,00.html">Raffy on visualization</a>. (<em>&quot;One of the dangerous things is if you don't understand the log file itself, don't assume you'll understand the visualization of it or even generate a visualization that makes sense&quot;</em>) Amen to that! BTW, Raffy's book is finally <a href="http://www.amazon.com/gp/product/0321510100/ref=cm_cr_pr_product_top">out.</a> </li>    <li>Compliance and checkbox mentality: fun pickup from <a href="http://chuvakin.blogspot.com/2008/08/few-more-words-on-dlp-and-compliance.html">my original &quot;DLP and Compliance&quot; post</a> - <a href="http://securosis.com/2008/08/18/dont-sell-compliance-if-it-isnt-a-checkbox/">Rich</a> and <a href="http://channelmarker.blogs.techtarget.com/2008/08/19/794/">TechTarget</a>. Good stuff! (&quot;<a href="http://securosis.com/2008/08/18/dont-sell-compliance-if-it-isnt-a-checkbox/"><em>Don&#8217;t Sell &#8216;Compliance&#8217; If It Isn&#8217;t A Checkbox </em></a>&quot;) </li>    <li>RedHat is <a href="http://www.redhat.com/archives/fedora-announce-list/2008-August/msg00012.html">nicely 0wned</a> (<a href="http://isc.sans.org/diary.html?storyid=4921">more info</a>)</li>    <li><a href="http://blog.wired.com/27bstroke6/2008/08/revealed-the-in.html">BGP hole</a> to dwarf the DNS hole?</li>    <li>Chris continues the virtualization and PCI DSS theme <a href="http://rationalsecurity.typepad.com/blog/2008/08/virtualized-inf.html">here</a>. The jury is still out on this one, even though the common sense approach (that virtualization is OK in regards to PCI) will probably win.</li>    <li>NEWS FLASH! <a href="http://blog.modernmechanix.com/2008/03/31/the-national-data-center-and-personal-privacy/">Privacy dies</a>. The date of death? 1967. While <a href="http://blog.modernmechanix.com/2008/03/31/the-national-data-center-and-personal-privacy/">reading it</a>, think just how visionary some folks are...</li>    <li>Finally, just for laughs: <a href="http://www.wikihow.com/Spin-Bad-News">How to Spin Bad News</a> </li> </ol>  <p>Enjoy!</p>  <p>BTW, I am saving some fun reading for dedicated posts soon :-)</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=jdwxUK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=jdwxUK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=PB8ogK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=PB8ogK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=YLH24K"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=YLH24K" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/376393795" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 06:56:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/security">security</category>
      <category domain="http://www.securityratty.com/tag/fun">fun</category>
      <category domain="http://www.securityratty.com/tag/security controls resistance">security controls resistance</category>
      <category domain="http://www.securityratty.com/tag/stuff">stuff</category>
      <category domain="http://www.securityratty.com/tag/fun stuff">fun stuff</category>
      <category domain="http://www.securityratty.com/tag/security issues">security issues</category>
      <category domain="http://www.securityratty.com/tag/business">business</category>
      <category domain="http://www.securityratty.com/tag/bona fide business">bona fide business</category>
      <category domain="http://www.securityratty.com/tag/fun pickup">fun pickup</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/376393795/fun-reading-on-security-7.html">Fun Reading on Security - 7</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-08-26 [del.icio.us]]]></title>
      <link>http://www.securityratty.com/article/b3feb4d860dfa18b442fbd6aabc5a61d</link>
      <guid>http://www.securityratty.com/article/b3feb4d860dfa18b442fbd6aabc5a61d</guid>
      <description><![CDATA[Layer 8
The Limits of Running IT Like a Business If you've tried managing an internal IT department as a bona fide business you already know that you can't take that very far, for the obvious reason...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://layer8.itsecuritygeek.com/layer8/quant-love">Layer 8</a></li>
<li><a href="http://www.cio.com/article/print/335813">The Limits of Running IT Like a Business</a><br/>
If you&#039;ve tried managing an internal IT department as a bona fide business you already know that you can&#039;t take that very far, for the obvious reason that your IT department isn&#039;t a business. It is, after all, a part of a business: a significant contributor to a value chain, not a self-contained value chain of its own.</li>
<li><a href="http://taosecurity.blogspot.com/2008/08/limits-of-running-it-like-business.html">TaoSecurity: The Limits of Running IT Like a Business</a><br/>
The Limits of Running IT Like a Business</li>
<li><a href="http://risktical.com/2008/07/31/what-is-risk/">What is Risk? &laquo; Risktical Ramblings</a></li>
<li><a href="http://searchnetworking.techtarget.com/news/article/0,289142,sid7_gci1326271,00.html">Networking data visualization not just for pointy-headed bosses</a></li>
<li><a href="http://onsaas.net/2008/08/23/challenges-of-enterprise-cloud-computing/">OnSaaS &raquo; Blog Archive &raquo; Challenges of Enterprise Cloud Computing</a></li>
<li><a href="http://channelmarker.blogs.techtarget.com/2008/08/19/794/">Regulatory compliance: Getting customers to look at the big picture &mdash; Channel Marker</a></li>
<li><a href="http://andyitguy.blogspot.com/2008/08/im-not-expert-in-all-things-security.html">Andy, ITGuy: I'm not an expert in all things security, but I am a thinker</a></li>
<li><a href="http://chuvakin.blogspot.com/2008/08/anton-security-tip-of-day-16-virtually.html">Anton Chuvakin Blog - &quot;Security Warrior&quot;: Anton Security Tip of the Day #16: Virtually There - Journey Into VMWare ESX Log Analysis</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/375866715" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/business">business</category>
      <category domain="http://www.securityratty.com/tag/bona fide business">bona fide business</category>
      <category domain="http://www.securityratty.com/tag/security">security</category>
      <category domain="http://www.securityratty.com/tag/anton security tip">anton security tip</category>
      <category domain="http://www.securityratty.com/tag/limits">limits</category>
      <category domain="http://www.securityratty.com/tag/security warrior">security warrior</category>
      <category domain="http://www.securityratty.com/tag/anton chuvakin blog">anton chuvakin blog</category>
      <category domain="http://www.securityratty.com/tag/picture channel marker">picture channel marker</category>
      <category domain="http://www.securityratty.com/tag/department">department</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/375866715/anton18">Links for 2008-08-26 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Relentless Reflection - What it Means in Risk Management]]></title>
      <link>http://www.securityratty.com/article/cb97e56e5e1097f1a11d050fe2f8d396</link>
      <guid>http://www.securityratty.com/article/cb97e56e5e1097f1a11d050fe2f8d396</guid>
      <description><![CDATA[Picking up from yesterday, Today Id like to talk about
HANSEI - WHAT IS RELENTLESS REFLECTION? - And why were talking about it in the context of Risk Analysis
Recall from yesterdays post about how I...]]></description>
      <content:encoded><![CDATA[<p>Picking up from yesterday, Today I&#8217;d like to talk about:</p>
<p><strong>HANSEI - WHAT IS &#8220;RELENTLESS REFLECTION?&#8221;</strong> - And why we&#8217;re talking about it in the context of Risk Analysis.</p>
<p>Recall from yesterday&#8217;s post about how I got to thinking about the concept of Hansei-Kaizen, &#8220;relentless reflection&#8221; and &#8220;continuous improvement&#8221; and how we might apply that to risk management.  It&#8217;s a concept born of Toyota and is, in some way, the foundation for &#8220;Lean&#8221; production.</p>
<p>Call me biased, but I think that Hansei - the act of &#8216;relentless reflection&#8217; made structured is the <em>analytical function</em>.  And I hate to debate (post-mortem) the father of Toyota quality success when he says that Hansei is the &#8220;check&#8221; in Plan/Do/Check/Act, but I think that Hansei also applies to the &#8220;Plan&#8221; of the P/D/C/A or Deming cycle.</p>
<p>You&#8217;ll recall the P/D/C/A cycle can be thought of even as an implementation of Scientific Method, in that it is Observation &amp; Hypothesis Creation (P), Experiment (D), Analysis (Check), and Act (Revise/New Hypothesis, etc&#8230;).  Well then as such, the Hypothesis creation involves creating a model or creating an expected outcome for data using the currently accepted model.</p>
<p>So in our industry there is an opportunity for Relentless Reflection in both the Observation and Hypothesis (Plan) creation steps, and the Check step.  We create an estimate for control strength, or probable losses in the context of risk- then we go to Experiment step.  That hypothesis can be put it into production, have an audit, have a penetration test, whatever, in the context of the Do step.  BTW - using Hansei/Analytics in Plan is one way that strong analytical functions can really make penetration testing more useful - as a means to test the estimates and inputs into a model.  It&#8217;s <strong>Penetration Testing 2.0</strong>!  (&lt;- tongue fully in cheek, yes)</p>
<p><em><br />
Those who are versed in the reasons to merge Six Sigma and Lean together are probably already seeing where I&#8217;m going with this today.  But before you think that a simple DMAIC function is all that is needed to create proper &#8220;Hansei&#8221;, let me encourage you to keep reading.</em></p>
<p><span style="color: #008000;"><strong><br />
Now if the analytical function can said to be &#8220;reflection&#8221;, why must it be relentless?</strong></span></p>
<p>One word.  <em><strong>Change.</strong></em> There are essentially four separate &#8220;landscapes&#8221; or sources of change that we face (more on those tomorrow).  But anyone who has tried to manage system compliance, log management or policy exceptions knows that change is possibly the most difficult thing we security professionals must manage.  And when you think about it, there aren&#8217;t too many other business functions like information security where significant visibility and insight about the environment is needed for &#8220;complete&#8221; information (get bullish on Log Management is my recommendation).</p>
<p><strong>HANSEI STEPS ADAPTED TO INFORMATION SECURITY</strong></p>
<p>This is one of those quality control concepts that we can <span style="text-decoration: line-through;">mangle</span> adopt.  At Toyota, Hansei-Kaizen includes the following basic steps:</p>
<p>1. Initial problem perception<br />
2. Clarify the problem<br />
3. Locate area/point of cause<br />
4. Investigate root cause (using an ask why 5 times approach)<br />
5. Countermeasure<br />
6. Evaluate<br />
7. Standardize</p>
<p>Now it&#8217;s important to note that part of this includes the concept of Go See For Yourself, called &#8220;<em><strong>Gemba</strong></em>&#8220;.  Gemba can be translated as “the actual place” or “the place where virtue or truth is found.” At Toyota this might mean going to the shop floor to see the issue at hand in the production line.  But for us, that&#8217;s a problem because we live in the virtual world.  There&#8217;s usually not much use in hanging out in the wiring closets to try to see the problems.</p>
<p>But if you combine the concept of Gemba with the concept of <em><strong>&#8220;Nemawashi</strong></em>&#8221; –the process of discussing problems and potential solutions with all those affected- we can forge a similar concept using risk analysis.  That is discussing the issue and the risk associated with an issue (what some people would call &#8220;risk management&#8221;) with the business/LOB/data owner and let them accept authority and the risk decision.  We, the risk analyst, our goal is simply to perform items 1-5 (presenting countermeasure options that include transferring or accepting risk).  By going to the line of business and involving them, responsibility is shared.  Also, if you structure organizational behavior right, <em>personal </em>risk is transferred!</p>
<p>This sort of approach is also in harmony with concepts like “mutual ownership of problems,” or “<em><a title="Genchi Genbutsu" href="http://en.wikipedia.org/wiki/Genchi_Genbutsu">genchi genbutsu</a>,</em>” (solving problems at the source instead of behind desks), and the “<em><a title="Kaizen" href="http://en.wikipedia.org/wiki/Kaizen">kaizen</a> mind,</em>” (an unending sense of crisis behind the company’s constant drive to improve).</p>
<p>One of the criticisms I have with the way most people try to implement DMAIC into &#8220;Lean&#8221;</p>
<p><strong>REQUIREMENTS</strong></p>
<p>Now to get this done, I really see three significant requirements.</p>
<p>1.)  A change in political structure.</p>
<p>2.)  Models that provide consistent, defensible analysis.</p>
<p>3.)  A Quantitative approach.  This means using actual units of measurement (not just amorphous percents, ordinal scales, etc.)  for risk and it&#8217;s subsequent factors.  Sure there are times when Q&amp;D qualitative approaches are acceptable, but policy should be to have quantitative analysis whenever and wherever possible.</p>
<p>That last item - the quantitative approach - is really quite important.  And the reasons why will be discussed further in tomorrow&#8217;s post:</p>
<p style="text-align: center;"><strong>&#8220;What should we be reflecting about? &amp; What is needed for reflection?&#8221;</strong></p>
<p><em>P.S.  Your comments and suggestions, as always, are welcome.</em></p>
<p><em>P.P.S  Those who may be familiar with Lean/SixSigma/Kaizen sorts of mashups may be thinking - &#8220;hey, an Analytical step is built into SixSigma&#8221;.  Well, yes there is some prevision for analytical functions based on statistics, but I find SixSigma geared towards creating a State of Knowledge about operational processes, not towards creating a State of Wisdom for CISO&#8217;s around security &amp; risks &#8220;big questions&#8221;.  In otherwords, the analytical function in DMAIC is in the context of Kaizen, and a different step than &#8220;reflective&#8221; analytics. </em></p>
]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 13:55:40 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/risk management">risk management</category>
      <category domain="http://www.securityratty.com/tag/risk">risk</category>
      <category domain="http://www.securityratty.com/tag/call risk management">call risk management</category>
      <category domain="http://www.securityratty.com/tag/call">call</category>
      <category domain="http://www.securityratty.com/tag/relentless reflection">relentless reflection</category>
      <category domain="http://www.securityratty.com/tag/relentless">relentless</category>
      <category domain="http://www.securityratty.com/tag/reflection">reflection</category>
      <category domain="http://www.securityratty.com/tag/risk analyst">risk analyst</category>
      <category domain="http://www.securityratty.com/tag/risk decision">risk decision</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=393">Relentless Reflection - What it Means in Risk Management</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-08-25 [del.icio.us]]]></title>
      <link>http://www.securityratty.com/article/971b61f5d2ba103bfbf9e50241696a4d</link>
      <guid>http://www.securityratty.com/article/971b61f5d2ba103bfbf9e50241696a4d</guid>
      <description><![CDATA[InternetNews Realtime IT News - Motorola Buys AirDefense
Virtualization Monitoring | Virtualization Information Q: Often Splunk is associated with being just security tool. Why do IT server...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://www.internetnews.com/security/article.php/3762106/Motorola+Buys+AirDefense.htm">InternetNews Realtime IT News - Motorola Buys AirDefense</a></li>
<li><a href="http://virtualizationinformation.com/?page_id=207">Virtualization Monitoring | Virtualization Information</a><br/>
Q: Often Splunk is associated with being just security tool. Why do IT server administrators want this for their virtualization platform?

A: It is funny that Splunk has that image!  Application and server availability is actually our predominant use case, with security and compliance a good way behind.</li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/374902986" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://www.securityratty.com/tag/virtualization platform">virtualization platform</category>
      <category domain="http://www.securityratty.com/tag/virtualization information">virtualization information</category>
      <category domain="http://www.securityratty.com/tag/motorola buys airdefense">motorola buys airdefense</category>
      <category domain="http://www.securityratty.com/tag/security tool">security tool</category>
      <category domain="http://www.securityratty.com/tag/security">security</category>
      <category domain="http://www.securityratty.com/tag/server availability">server availability</category>
      <category domain="http://www.securityratty.com/tag/splunk">splunk</category>
      <category domain="http://www.securityratty.com/tag/server administrators">server administrators</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/374902986/anton18">Links for 2008-08-25 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[File Integrity Monitoring: Secure Your Virtual and Physical IT Environments]]></title>
      <link>http://www.securityratty.com/article/f25697c6547acff1ffe2bf8a0039f459</link>
      <guid>http://www.securityratty.com/article/f25697c6547acff1ffe2bf8a0039f459</guid>
      <description><![CDATA[Source: Tripwire) Looking for a File Integrity Monitoring Solution? With the numerous servers, devices and applications organizations rely on to support their everyday business, outages and security...]]></description>
      <content:encoded><![CDATA[<b>(Source: Tripwire)</b>  Looking for a File Integrity Monitoring Solution? With the numerous servers, devices and applications organizations rely on to support their everyday business, outages and security breaches due to poor IT configurations are unacceptable. In addition, many organizations must now prove compliance with standards like PCI DSS designed to protect systems and sensitive data. File integrity monitoring solutions minimize security risk resulting from undesirable configuration change by monitoring, detecting, and reconciling changes to key files throughout the virtual and physical IT infrastructures.<p>Learn how file integrity monitoring solutions work and the capabilities you should expect your solution to have. Then review a detailed checklist you should complete before purchasing your solution. Finally, discover how Tripwire Enterprise effectively combines file integrity monitoring with configuration assessment-a single configuration control solution that proactively assesses and monitors the IT infrastructure and enables organizations to achieve and maintain compliance with standards and regulations.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=4fD2VT"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=4fD2VT" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/374621002" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/file integrity">file integrity</category>
      <category domain="http://www.securityratty.com/tag/applications organizations rely">applications organizations rely</category>
      <category domain="http://www.securityratty.com/tag/organizations">organizations</category>
      <category domain="http://www.securityratty.com/tag/enables organizations">enables organizations</category>
      <category domain="http://www.securityratty.com/tag/security breaches due">security breaches due</category>
      <category domain="http://www.securityratty.com/tag/solution">solution</category>
      <category domain="http://www.securityratty.com/tag/undesirable configuration change">undesirable configuration change</category>
      <category domain="http://www.securityratty.com/tag/maintain compliance">maintain compliance</category>
      <category domain="http://www.securityratty.com/tag/numerous servers">numerous servers</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/374621002/whitepapers.do">File Integrity Monitoring: Secure Your Virtual and Physical IT Environments</source>
    </item>
    <item>
      <title><![CDATA[Speaking of Security Podcast #119]]></title>
      <link>http://www.securityratty.com/article/9889880c87bd6f2858883a0c1c40e50b</link>
      <guid>http://www.securityratty.com/article/9889880c87bd6f2858883a0c1c40e50b</guid>
      <description><![CDATA[Click to Download/Listen (06:46

Paul Davilman from RSAs Compliance and Solutions team sits down with Amanda Van Veen to talk about the North American Electric Reliability Corporation (NERC) Cyber...]]></description>
      <content:encoded><![CDATA[<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1333">Click to Download/Listen</a> (06:46)<br><br />Paul Davilman from RSA&rsquo;s Compliance and Solutions  team sits down with Amanda Van Veen to talk about  the <a href="http://www.nerc.com/" target="_blank">North American Electric Reliability Corporation</a> (NERC) <a href="http://www.nerc.com/filez/standards/Project_2008-06_Cyber_Security.html">Cyber Security Standards</a> and how  these standards will impact IT security in the utility industries. Please note that due to the U.S. Labor Day holiday, we'll be back in two weeks (on September 8) with a new show.<br /><br /><br />]]></content:encoded>
      <pubDate>Sun, 24 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/security">security</category>
      <category domain="http://www.securityratty.com/tag/cyber security standards">cyber security standards</category>
      <category domain="http://www.securityratty.com/tag/standards">standards</category>
      <category domain="http://www.securityratty.com/tag/labor day holiday">labor day holiday</category>
      <category domain="http://www.securityratty.com/tag/solutions team sits">solutions team sits</category>
      <category domain="http://www.securityratty.com/tag/utility industries">utility industries</category>
      <category domain="http://www.securityratty.com/tag/amanda van">amanda van</category>
      <category domain="http://www.securityratty.com/tag/rsas compliance">rsas compliance</category>
      <category domain="http://www.securityratty.com/tag/paul davilman">paul davilman</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1333">Speaking of Security Podcast #119</source>
    </item>
    <item>
      <title><![CDATA[eBook on Log Management]]></title>
      <link>http://www.securityratty.com/article/25fe809ffbf0440e98ade14d7b8dfc8f</link>
      <guid>http://www.securityratty.com/article/25fe809ffbf0440e98ade14d7b8dfc8f</guid>
      <description><![CDATA[Check out this new log-related ebook from TechTarget: &quot; eBook - Log Management: Effective Tools for Compliance Reporting and Security Event Detection
About me:...]]></description>
      <content:encoded><![CDATA[Check out this new log-related ebook from TechTarget: "<a href="http://searchsecurity.bitpipe.com/data/document.do;jsessionid=36E85293C3F76220E84563000B7EB60E?res_id=1218204055_625&amp;src=DED_ssec_08_21_08" class="textHighlite">eBook - Log Management: Effective Tools for Compliance Reporting and Security Event Detection</a>"<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=MFJnxK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=MFJnxK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=26MnOK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=26MnOK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=D1lQPK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=D1lQPK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/375480452" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 22 Aug 2008 06:19:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/log management">log management</category>
      <category domain="http://www.securityratty.com/tag/ebook">ebook</category>
      <category domain="http://www.securityratty.com/tag/security event detection">security event detection</category>
      <category domain="http://www.securityratty.com/tag/effective tools">effective tools</category>
      <category domain="http://www.securityratty.com/tag/compliance">compliance</category>
      <category domain="http://www.securityratty.com/tag/org">org</category>
      <category domain="http://www.securityratty.com/tag/check">check</category>
      <category domain="http://www.securityratty.com/tag/techtarget">techtarget</category>
      <category domain="http://www.securityratty.com/tag/chuvakin">chuvakin</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/375480452/ebook-on-log-management.html">eBook on Log Management</source>
    </item>
    <item>
      <title><![CDATA[Changes to PCI standard not expected to up ante on protecting payment card data]]></title>
      <link>http://www.securityratty.com/article/bf27c281117cda1a2c49240f942ee290</link>
      <guid>http://www.securityratty.com/article/bf27c281117cda1a2c49240f942ee290</guid>
      <description><![CDATA[An update of the Payment Card Industry Data Security Standard, or PCI, may ease some of the compliance challenges facing businesses that handle cardholder...]]></description>
      <content:encoded><![CDATA[An update of the Payment Card Industry Data Security Standard, or PCI, may ease some of the compliance challenges facing businesses that handle cardholder data.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=htckdq"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=htckdq" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/370408352" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/handle cardholder data">handle cardholder data</category>
      <category domain="http://www.securityratty.com/tag/pci">pci</category>
      <category domain="http://www.securityratty.com/tag/compliance challenges">compliance challenges</category>
      <category domain="http://www.securityratty.com/tag/businesses">businesses</category>
      <category domain="http://www.securityratty.com/tag/ease">ease</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/370408352/article.do">Changes to PCI standard not expected to up ante on protecting payment card data</source>
    </item>
    <item>
      <title><![CDATA[PCI Compliance: Reaction to the Summary of Changes]]></title>
      <link>http://www.securityratty.com/article/ddeefb896f6d234b28dddac20a55a9c5</link>
      <guid>http://www.securityratty.com/article/ddeefb896f6d234b28dddac20a55a9c5</guid>
      <description><![CDATA[On August 18 the PCI Security Standards Council formally announced ( http://www.pcisecuritystandards.org/pdfs/08-18-08 2.pdf ) forthcoming changes to the Payment Card Industry's Data Security Standard...]]></description>
      <content:encoded><![CDATA[On August 18 the PCI Security Standards Council formally announced (<a href="http://www.pcisecuritystandards.org/pdfs/08-18-08_2.pdf" target=_blank>http://www.pcisecuritystandards.org/pdfs/08-18-08_2.pdf</a>) forthcoming changes to the Payment Card Industry's Data Security Standard (PCI DSS) as it moves from version 1.1 to version 1.2 in October 2008.  The release represents the first major update since September 2006.
<P>
What's my take on the summary of changes? <B>Most merchants will be pleased to see that these are relatively minor changes...</b>]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/payment card industry">payment card industry</category>
      <category domain="http://www.securityratty.com/tag/data security standard">data security standard</category>
      <category domain="http://www.securityratty.com/tag/release represents">release represents</category>
      <category domain="http://www.securityratty.com/tag/version">version</category>
      <category domain="http://www.securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://www.securityratty.com/tag/summary">summary</category>
      <category domain="http://www.securityratty.com/tag/october">october</category>
      <category domain="http://www.securityratty.com/tag/pdf">pdf</category>
      <category domain="http://www.securityratty.com/tag/minor">minor</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1330">PCI Compliance: Reaction to the Summary of Changes</source>
    </item>
  </channel>
</rss>
