<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SecurityCurve &#187; Diana</title>
	<atom:link href="http://www.securitycurve.com/wordpress/archives/author/diana/feed" rel="self" type="application/rss+xml" />
	<link>http://www.securitycurve.com/wordpress</link>
	<description></description>
	<lastBuildDate>Mon, 06 Feb 2012 17:05:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Post Virtualization Security</title>
		<link>http://www.securitycurve.com/wordpress/archives/5140?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=5140</link>
		<comments>http://www.securitycurve.com/wordpress/archives/5140#comments</comments>
		<pubDate>Tue, 24 Jan 2012 13:44:20 +0000</pubDate>
		<dc:creator>Diana</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[SC in the news]]></category>
		<category><![CDATA[Cloud security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Virtualization]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=5140</guid>
		<description><![CDATA[As the second law of thermodynamics tells us, all things trend toward chaos and this is no less true with a virtual environment. Sprawl can have a real security impact, and it takes discipline and planning to control sprawl &#8212; discipline and planning that won&#8217;t occur without someone from the security team actively monitoring the [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><blockquote><p>As the second law of thermodynamics tells us, all things trend toward chaos and this is no less true with a virtual environment. Sprawl can have a real security impact, and it takes discipline and planning to control sprawl &#8212; discipline and planning that won&#8217;t occur without someone from the security team actively monitoring the problem and formulating strategies for how to address the issue.</p>
<p>VVirtualization has been one of the most rapidly and widely adopted technologies in recent memory. It&#8217;s huge, and it&#8217;s here to stay.</p>
<p>And as security professionals know, setting up a virtual environment securely isn&#8217;t easy. Significant effort goes into tasks like evaluating off-premise service providers, ensuring regulatory compliance, and standing up technical controls like monitoring and encryption. But in the excitement to stand up the new environment and get security to an acceptable &#8220;target state,&#8221; organizations sometimes don&#8217;t address security hygiene long-term. In other words, security is in high gear while the environment spins up, but it doesn&#8217;t lay the groundwork for what happens once things are chugging along.</p></blockquote>
<p>Read the rest of Ed&#8217;s article over at <a href="http://www.ecommercetimes.com/story/74250.html" target="_blank">E-Commerce Times</a>.</p>
<div class="shr-publisher-5140"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F5140' data-shr_title='Post+Virtualization+Security'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F5140' data-shr_title='Post+Virtualization+Security'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/5140/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Using HIPAA To Advance Your Security Initiative</title>
		<link>http://www.securitycurve.com/wordpress/archives/5133?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=using-hipaa-to-advance-your-security-initiative</link>
		<comments>http://www.securitycurve.com/wordpress/archives/5133#comments</comments>
		<pubDate>Mon, 16 Jan 2012 14:06:12 +0000</pubDate>
		<dc:creator>Diana</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[SC in the news]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=5133</guid>
		<description><![CDATA[[Excerpted from "Security Via HIPAA Compliance," a new report By Diana Kelley and Ed Moyle, posted on Dark Reading's Compliance Tech Center.] Healthcare compliance requirements can be a driver to improve your organization&#8217;s overall security. Here&#8217;s how: If your security organization is in the healthcare space, you inevitably are wrestling with the Healthcare Information Portability [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p><em>[Excerpted from "Security Via HIPAA Compliance," a new report By Diana Kelley and Ed Moyle, posted on Dark Reading's Compliance Tech Center.]</em></p>
<p>Healthcare compliance requirements can be a driver to improve your organization&#8217;s overall security. Here&#8217;s how:    </p>
<blockquote><p>
If your security organization is in the healthcare space, you inevitably are wrestling with the Healthcare Information Portability and Accountability Act (HIPAA). HIPAA compliance is one of the biggest challenges healthcare IT organizations face &#8212; but it also could be an opportunity to advance your security agenda.</p>
<p>For security professionals to leverage compliance investment and activities for broader benefit, they must understand what’s driving current compliance investment.</p>
<p>First, it bears saying that the standards outlined in the HIPAA Security Rule are designed to address broad swaths of industry—from small clinics and physician offices to the largest institutional care providers and insurance companies. Because of this, the high-level security control objectives outlined in the Security Rule (standards) as well as the supporting controls are extremely broad and lacking in technical specificity.</p>
<p>How can security organizations make use of compliance activities?</p></blockquote>
<p>Check out the rest of the excerpt at <a href="http://www.darkreading.com/compliance/167901112/security/security-management/232400364/using-hipaa-to-advance-your-security-initiative.html" target="_blank">Dark Reading</a> or download the entire report at the <a href="http://www.darkreading.com/tech-center/10/Compliance.html" target="_blank">DR Compliance Tech Center</a>. </p>
<div class="shr-publisher-5133"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F5133' data-shr_title='Using+HIPAA+To+Advance+Your+Security+Initiative'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F5133' data-shr_title='Using+HIPAA+To+Advance+Your+Security+Initiative'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/5133/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The False Economies of the Info Security World</title>
		<link>http://www.securitycurve.com/wordpress/archives/4748?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=the-false-economies-of-the-info-security-world</link>
		<comments>http://www.securitycurve.com/wordpress/archives/4748#comments</comments>
		<pubDate>Wed, 19 Oct 2011 12:18:44 +0000</pubDate>
		<dc:creator>Diana</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[SC in the news]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Cost benefit analysis]]></category>
		<category><![CDATA[Hidden Costs]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=4748</guid>
		<description><![CDATA[Ed&#8217;s October article for TechNewsWorld takes a look at why it&#8217;s so hard for companies to determine the true cost of security initiatives and controls. Organizations love false economies. It may not be an entirely conscious act on their part, but it&#8217;s certainly the truth: Hang around any organization long enough and you&#8217;ll find at [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>Ed&#8217;s October article for TechNewsWorld takes a look at why it&#8217;s so hard for companies to determine the true cost of security initiatives and controls.</p>
<blockquote><p>Organizations love false economies. It may not be an entirely conscious act on their part, but it&#8217;s certainly the truth: Hang around any organization long enough and you&#8217;ll find at least one instance where it tries to save on doing A but winds up spending more on doing B in the process.</p>
<p>Consider, for example, expense policies that require employees to stay one or more extra nights when traveling. Because airfare is lower when weekend travel is involved, organizations might be tempted to ask employees to do this to keep air costs down; however, very seldom do recouped airfare dollars come even close to combined dollars lost in extra hotel stays, extra meal expenses, lost productivity and reduced employee morale. The combination of hard and soft costs far outweighs possible savings in the area of airfare.</p></blockquote>
<p>For the rest of Ed&#8217;s article, please click <a href="http://www.technewsworld.com/story/The-False-Economies-of-the-Info-Security-World-73535.html" target="_blank">here</a>.</p>
<div class="shr-publisher-4748"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4748' data-shr_title='The+False+Economies+of+the+Info+Security+World'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4748' data-shr_title='The+False+Economies+of+the+Info+Security+World'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/4748/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wrapping Personal Devices and Critical Data in Stale Policies</title>
		<link>http://www.securitycurve.com/wordpress/archives/4675?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=wrapping-personal-devices-and-critical-data-in-stale-policies</link>
		<comments>http://www.securitycurve.com/wordpress/archives/4675#comments</comments>
		<pubDate>Thu, 22 Sep 2011 18:06:29 +0000</pubDate>
		<dc:creator>Diana</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[SC in the news]]></category>
		<category><![CDATA[Acceptable Use]]></category>
		<category><![CDATA[AUPs]]></category>
		<category><![CDATA[BYOB]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Personal Devices]]></category>
		<category><![CDATA[Policies]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=4675</guid>
		<description><![CDATA[In his monthly Opinion piece, Ed discusses why BYOB requires a fresh look at AUPs: The use of personal devices for corporate tasks is on the rise, and too many IT departments haven&#8217;t fully addressed the information security ramifications of the trend. To tackle the situation, you&#8217;ll need to first get a handle on what [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>In his monthly Opinion piece, Ed discusses why BYOB requires a fresh look at AUPs:</p>
<blockquote><p>The use of personal devices for corporate tasks is on the rise, and too many IT departments haven&#8217;t fully addressed the information security ramifications of the trend. To tackle the situation, you&#8217;ll need to first get a handle on what your current policies are as they relate to management intent as well as what policies you&#8217;re already enforcing technically.</p>
<p>It&#8217;s a myth that ostriches bury their heads when they spot danger. It sounds plausible, but in reality, they&#8217;re just like us: In the face of imminent danger, they either run or attack (&#8220;fight or flight&#8221;).</p>
<p>This makes sense when you stop to think about it. After all, one thing that seems almost painfully obvious is that ignoring signs of danger isn&#8217;t an effective defense strategy. In a high-stakes situation (like being a prey animal on the Serengeti), ignorance isn&#8217;t an evolutionarily productive strategy. Successful ostriches are more likely to live by taking evasive action; less-successful ostriches are more likely to ignore danger and perish.</p></blockquote>
<p>For the rest of Ed&#8217;s article, please click <a href="http://www.technewsworld.com/story/73325.html">here</a>.</p>
<div class="shr-publisher-4675"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4675' data-shr_title='Wrapping+Personal+Devices+and+Critical+Data+in+Stale+Policies'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4675' data-shr_title='Wrapping+Personal+Devices+and+Critical+Data+in+Stale+Policies'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/4675/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analysis: PCI Tokenization Guidelines offer Clarity, but Questions Remain</title>
		<link>http://www.securitycurve.com/wordpress/archives/4671?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=analysis-pci-tokenization-guidelines-offer-clarity-but-questions-remain</link>
		<comments>http://www.securitycurve.com/wordpress/archives/4671#comments</comments>
		<pubDate>Thu, 22 Sep 2011 17:54:52 +0000</pubDate>
		<dc:creator>Diana</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[SC in the news]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[PCI-DSS]]></category>
		<category><![CDATA[Tokenization]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=4671</guid>
		<description><![CDATA[TechTarget just published my analysis on the PCI Tokenization Guidelines: For years, security experts have touted the value of credit card tokenization for limiting PCI scope. The National Retail Federation (NRF) listed tokenization in its January 2009 “Key PCI Best Practices” document, and Gartner Inc. analysts John Pescatore and Avivah Litan explained how tokenization can [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>TechTarget just published my analysis on the PCI Tokenization Guidelines:</p>
<blockquote><p>For years, security experts have touted the value of credit card tokenization for limiting PCI scope. The National Retail Federation (NRF) listed tokenization in its January 2009 “Key PCI Best Practices” document, and Gartner Inc. analysts John Pescatore and Avivah Litan explained how tokenization can be used to reduce PCI scope in their August 2009 research note, “Using Tokenization to Reduce PCI Compliance Requirements.”</p>
<p>Now, following the long-awaited release of its PCI Tokenization Guidelines in August 2011, the PCI Security Standards Council (SSC) has made it official: tokenization can reduce scope for PCI audits. Organizations that were waiting for the council’s opinion can now forge ahead with implementations, knowing that credit card tokenization is approved for use in a PCI DSS-compliant cardholder data environment (CDE). That in itself will be welcome news to many merchants.</p></blockquote>
<p>To read the rest of my analysis, please click <a href="http://searchsecurity.techtarget.com/tip/Analysis-PCI-Tokenization-Guidelines-offer-clarity-but-questions-remain">here</a>.</p>
<div class="shr-publisher-4671"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4671' data-shr_title='Analysis%3A+PCI+Tokenization+Guidelines+offer+Clarity%2C+but+Questions+Remain'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4671' data-shr_title='Analysis%3A+PCI+Tokenization+Guidelines+offer+Clarity%2C+but+Questions+Remain'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/4671/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is InfoSec Ready for Big Data?</title>
		<link>http://www.securitycurve.com/wordpress/archives/4557?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=is-infosec-ready-for-big-data</link>
		<comments>http://www.securitycurve.com/wordpress/archives/4557#comments</comments>
		<pubDate>Mon, 15 Aug 2011 13:10:32 +0000</pubDate>
		<dc:creator>Diana</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[SC in the news]]></category>
		<category><![CDATA[big data]]></category>
		<category><![CDATA[Buzzwords]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=4557</guid>
		<description><![CDATA[Ed&#8217;s column in TechNewsWorld this month takes a look at &#8220;Big Data&#8221; - Over the past few decades, most IT shops have followed a somewhat similar trajectory: Starting from a centralized model (i.e., the mainframe days), computing resources, much like the cosmological Big Bang, have exploded outwards to become ever-more-distributed and decentralized. This makes sense [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p><a href="http://www.securitycurve.com/wordpress/wp-content/uploads/2010/07/Ed.jpg" rel="lightbox[4557]"><img src="http://www.securitycurve.com/wordpress/wp-content/uploads/2010/07/Ed.jpg" alt="" title="Ed" width="172" height="124" class="alignleft size-full wp-image-2127" /></a>Ed&#8217;s column in TechNewsWorld this month takes a look at &#8220;Big Data&#8221; -</p>
<blockquote><p>Over the past few decades, most IT shops have followed a somewhat similar trajectory: Starting from a centralized model (i.e., the mainframe days), computing resources, much like the cosmological Big Bang, have exploded outwards to become ever-more-distributed and decentralized. This makes sense given market dynamics. Computing platforms evolve quickly, so monolithic computing platforms that require heavy up-front investment are less efficient from a depreciation standpoint (i.e., from a MIPS per dollar per year point of view) than numerous, incremental investments in lower-powered devices.</p>
<p>So it&#8217;s natural that processing would decentralize. And in fact, there have been numerous technologies invented over the years to support exactly this paradigm.</p>
<p>By virtue of ever-more decentralized processing, it logically follows that storage would be (in general) decentralized as well. In fact, storage becomes a balancing act. Data is placed in such a way as to be centralized enough to be manageable, while still being distributed enough to be efficiently used by consumers of that data. That&#8217;s the paradigm of recent history. But this paradigm is changing &#8212; changing in a way that impacts how we manage IT overall from a security perspective. And that change is &#8220;big data.&#8221;</p></blockquote>
<p>To read the rest of the article please click <a href="http://www.technewsworld.com/story/Is-InfoSec-Ready-for-Big-Data-73070.html" target="_blank">here</a>.</p>
<div class="shr-publisher-4557"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4557' data-shr_title='Is+InfoSec+Ready+for+Big+Data%3F'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4557' data-shr_title='Is+InfoSec+Ready+for+Big+Data%3F'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/4557/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>5 Things You Can Do Right Now to Boost Your Social Engineering Immunity</title>
		<link>http://www.securitycurve.com/wordpress/archives/4441?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=5-things-you-can-do-right-now-to-boost-your-social-engineering-immunity</link>
		<comments>http://www.securitycurve.com/wordpress/archives/4441#comments</comments>
		<pubDate>Tue, 19 Jul 2011 13:06:44 +0000</pubDate>
		<dc:creator>Diana</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[SC in the news]]></category>
		<category><![CDATA[Social Engineering]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=4441</guid>
		<description><![CDATA[In his July article for TechNews World, Ed discusses ways to make an organization more resistant to social engineering: Let&#8217;s face it: Social engineering &#8212; attacking an organization through deception by &#8220;tricking&#8221; internal users into sharing inappropriate levels of access &#8212; isn&#8217;t a topic that comes up very much in most IT shops. This isn&#8217;t [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p><a href="http://www.securitycurve.com/wordpress/wp-content/uploads/2010/07/Ed.jpg" rel="lightbox[4441]"><img src="http://www.securitycurve.com/wordpress/wp-content/uploads/2010/07/Ed.jpg" alt="" title="Ed" width="172" height="124" class="alignleft size-full wp-image-2127" /></a>In his July article for TechNews World, Ed discusses ways to make an organization more <a href="http://www.technewsworld.com/story/72891.html" target="_blank">resistant to social engineering</a>:</p>
<blockquote><p>Let&#8217;s face it: Social engineering &#8212; attacking an organization through deception by &#8220;tricking&#8221; internal users into sharing inappropriate levels of access &#8212; isn&#8217;t a topic that comes up very much in most IT shops. This isn&#8217;t because social engineering is ineffective or because organizations aren&#8217;t susceptible to it.</p>
<p>To the contrary: Although direct, quantifiable evidence about social engineering is difficult to come by, what statistics we do have (for example, the 90+ percent success rate at Defcon 18&#8242;s Social Engineering &#8220;Capture the Flag&#8221; contest) suggest that success rates for social engineering attacks are disproportionately high relative to attacks against technological components within our infrastructures.</p></blockquote>
<p>To keep reading the article, please click over to TechNews World <a href="http://www.technewsworld.com/story/72891.html" target="_blank">here</a>.</p>
<div class="shr-publisher-4441"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4441' data-shr_title='5+Things+You+Can+Do+Right+Now+to+Boost+Your+Social+Engineering+Immunity'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4441' data-shr_title='5+Things+You+Can+Do+Right+Now+to+Boost+Your+Social+Engineering+Immunity'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/4441/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IT Patch Management Webinar</title>
		<link>http://www.securitycurve.com/wordpress/archives/4418?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=it-patch-management-webinar</link>
		<comments>http://www.securitycurve.com/wordpress/archives/4418#comments</comments>
		<pubDate>Thu, 14 Jul 2011 13:44:15 +0000</pubDate>
		<dc:creator>Diana</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[patch lifecycle]]></category>
		<category><![CDATA[patch management]]></category>
		<category><![CDATA[remediation]]></category>
		<category><![CDATA[testing]]></category>
		<category><![CDATA[validation]]></category>
		<category><![CDATA[webinars]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=4418</guid>
		<description><![CDATA[SearchSecurity just posted my 45 minute webinar: IT Patch Management Best Practices: Overcoming the Challenges. With targeted attacks and zero-day vulnerabilities shrinking the window of time between vulnerability disclosure and exploit availability, it’s becoming more incumbent on security managers to understand the assets in their IT environment and the patch levels of those machines. In [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>SearchSecurity just posted my 45 minute webinar: <a href="http://searchsecurity.techtarget.com/video/IT-patch-management-best-practices-Overcoming-the-challenges" target="_blank">IT Patch Management Best Practices: Overcoming the Challenges</a>.</p>
<blockquote><p>With targeted attacks and zero-day vulnerabilities shrinking the window of time between vulnerability disclosure and exploit availability, it’s becoming more incumbent on security managers to understand the assets in their IT environment and the patch levels of those machines.</p>
<p>In this presentation on vulnerability management and IT patch management best practices, application security expert Diana Kelley explains how to improve your asset discovery processes, determine the patch level of the machines in your environment, and improve testing and deployment processes to keep pace with patch and vulnerability management.</p>
<p>In this presentation, Kelley discusses:</p>
<ul>
<li>Patching and remediation as a component of the vulnerability management lifecycle.</li>
<li>Implementing a vulnerability management program including scanning and prioritization.</li>
<li>Remediation:When and what to patch:</li>
</ul>
<ul>
<ul>
<li>Testing</li>
<li>Deployment</li>
<li>Validation</li>
</ul>
<li>Remediation alternatives</li>
<li>Keys to successful configuration and patch management lifecycle</li>
</ul>
</blockquote>
<p>No registration required! So if you&#8217;ve got some time and are interested in patch management please give a listen <a href="http://searchsecurity.techtarget.com/video/IT-patch-management-best-practices-Overcoming-the-challenges" target="_blank">here</a>.</p>
<div class="shr-publisher-4418"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4418' data-shr_title='IT+Patch+Management+Webinar'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4418' data-shr_title='IT+Patch+Management+Webinar'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/4418/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Are your Firewalls Burning Money &#8211; Part Deux</title>
		<link>http://www.securitycurve.com/wordpress/archives/4404?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=are-your-firewalls-burning-money-part-deux</link>
		<comments>http://www.securitycurve.com/wordpress/archives/4404#comments</comments>
		<pubDate>Wed, 13 Jul 2011 13:30:06 +0000</pubDate>
		<dc:creator>Diana</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[firewall policies]]></category>
		<category><![CDATA[firewalls]]></category>
		<category><![CDATA[perimeter firewalls]]></category>
		<category><![CDATA[risk mangement]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=4404</guid>
		<description><![CDATA[The second part of my two part guest blogger post for the Tufin blog is up: Think about how much your organization spends annually on firewall hardware, software licenses, and management. Now think about watching all that money washing down the drain because a single poorly implemented rule circumvented all of the other firewall-based protections. [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>The <a href="http://www.tufin.com/blog/2011/07/13/tufin-guest-blogger-diana-kelly-asks-again-are-your-firewalls-are-burning-money-part-two/" target="_blank">second part</a> of my two part guest blogger post for the Tufin blog is up:</p>
<blockquote><p>
Think about how much your organization spends annually on firewall hardware, software licenses, and management. Now think about watching all that money washing down the drain because a single poorly implemented rule circumvented all of the other firewall-based protections. Sounds a little alarming, but if you’re a firewall administrator, you know how real that possibility is.</p>
<p>In a previous post we took a look at “shadow rules” and why investing in automated tools that help eliminate them can be a solid business, not to mention security investment. But eliminating redundant, outdated and ineffective rules is only part of the problem.  For many firewall administrators, the bigger challenge is handling the day-to-day requests for firewall rule changes without introducing vulnerabilities or exposure points.</p>
<p>Firewalls aren’t static sentries that are set up once and run without change for years.
</p></blockquote>
<p>To read the full post please visit the Tufin blog <a href="http://www.tufin.com/blog/2011/07/13/tufin-guest-blogger-diana-kelly-asks-again-are-your-firewalls-are-burning-money-part-two/" target="_blank">here</a>.</p>
<div class="shr-publisher-4404"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4404' data-shr_title='Are+your+Firewalls+Burning+Money+-+Part+Deux'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4404' data-shr_title='Are+your+Firewalls+Burning+Money+-+Part+Deux'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/4404/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Happy 4th of July!</title>
		<link>http://www.securitycurve.com/wordpress/archives/4365?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=happy-4th-of-july</link>
		<comments>http://www.securitycurve.com/wordpress/archives/4365#comments</comments>
		<pubDate>Mon, 04 Jul 2011 05:44:38 +0000</pubDate>
		<dc:creator>Diana</dc:creator>
				<category><![CDATA[Useless Shizz]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=4365</guid>
		<description><![CDATA[]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p><a href="http://www.securitycurve.com/wordpress/wp-content/uploads/2011/06/Feeling-Patriotic.jpg" rel="lightbox[4365]"><img src="http://www.securitycurve.com/wordpress/wp-content/uploads/2011/06/Feeling-Patriotic-908x1024.jpg" alt="" title="Feeling Patriotic" width="454" height="512" class="aligncenter size-large wp-image-4366" /></a></p>
<div class="shr-publisher-4365"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4365' data-shr_title='Happy+4th+of+July%21'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4365' data-shr_title='Happy+4th+of+July%21'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/4365/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

