<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>InfoSecAlways.com</title>
	<atom:link href="http://infosecalways.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosecalways.com</link>
	<description>Information Security Always by Jason Bevis</description>
	<lastBuildDate>Thu, 12 Jan 2012 18:27:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='infosecalways.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>InfoSecAlways.com</title>
		<link>http://infosecalways.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://infosecalways.com/osd.xml" title="InfoSecAlways.com" />
	<atom:link rel='hub' href='http://infosecalways.com/?pushpress=hub'/>
		<item>
		<title>Security Conference List &#8211; Wikipedia Rocks</title>
		<link>http://infosecalways.com/2011/11/01/security-conference-list-wikipedia-rocks/</link>
		<comments>http://infosecalways.com/2011/11/01/security-conference-list-wikipedia-rocks/#comments</comments>
		<pubDate>Tue, 01 Nov 2011 15:35:46 +0000</pubDate>
		<dc:creator>jtbevis</dc:creator>
				<category><![CDATA[Prevention]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security Awareness]]></category>
		<category><![CDATA[Security Governance]]></category>
		<category><![CDATA[Security Program Development]]></category>
		<category><![CDATA[Software Security]]></category>

		<guid isPermaLink="false">http://infosecalways.com/?p=211</guid>
		<description><![CDATA[Wikipedia truly is amazing.  Check out the list of worldwide security conferences.  This is a great place to look for any professionals wanting to speak or attend a high profile conferences.  Definitely a good site to add to my links page.  http://en.wikipedia.org/wiki/Computer_security_conference<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecalways.com&amp;blog=168717&amp;post=211&amp;subd=jtbevis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:small;"><span style="font-family:Calibri;">Wikipedia truly is amazing.  Check out the list of worldwide security conferences.  This is a great place to look for any professionals wanting to speak or attend a high profile conferences.  Definitely a good site to add to my links page.</span></span></p>
<p><span style="font-size:small;font-family:Calibri;"> </span><span style="font-size:small;"><span style="font-family:Calibri;"><a href="http://en.wikipedia.org/wiki/Computer_security_conference">http://en.wikipedia.org/wiki/Computer_security_conference</a></span></span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jtbevis.wordpress.com/211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jtbevis.wordpress.com/211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jtbevis.wordpress.com/211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jtbevis.wordpress.com/211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jtbevis.wordpress.com/211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jtbevis.wordpress.com/211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jtbevis.wordpress.com/211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jtbevis.wordpress.com/211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jtbevis.wordpress.com/211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jtbevis.wordpress.com/211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jtbevis.wordpress.com/211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jtbevis.wordpress.com/211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jtbevis.wordpress.com/211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jtbevis.wordpress.com/211/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecalways.com&amp;blog=168717&amp;post=211&amp;subd=jtbevis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://infosecalways.com/2011/11/01/security-conference-list-wikipedia-rocks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2cc550be1da522f5450a013056ae0ad9?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jtbevis</media:title>
		</media:content>
	</item>
		<item>
		<title>Is Your 3rd Party Provider Secure?</title>
		<link>http://infosecalways.com/2011/10/30/is-your-3rd-party-provider-secure/</link>
		<comments>http://infosecalways.com/2011/10/30/is-your-3rd-party-provider-secure/#comments</comments>
		<pubDate>Sun, 30 Oct 2011 19:48:46 +0000</pubDate>
		<dc:creator>jtbevis</dc:creator>
				<category><![CDATA[Prevention]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security Governance]]></category>
		<category><![CDATA[Security Program Development]]></category>

		<guid isPermaLink="false">http://infosecalways.com/?p=202</guid>
		<description><![CDATA[Rogue Russian entities in the advertising industry take millions and the entire company disappears. Poor security programming techniques from offshore entities expose cross site scripting flaws in 50% of the companies websites. In any event more and more security weakness is exposed by the poor practices associated with a vendor, partner, or other third party [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecalways.com&amp;blog=168717&amp;post=202&amp;subd=jtbevis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Rogue Russian entities in the advertising industry take millions and the entire company disappears. Poor security programming techniques from offshore entities expose cross site scripting flaws in 50% of the companies websites. In any event more and more security weakness is exposed by the poor practices associated with a vendor, partner, or other third party business entity. These third party entities and the services they provide can cause great exposure resulting in large scale financial problems to the host organization.</p>
<p> <br />
<strong>What can be done?</strong></p>
<p>Security of third party entities can be accomplished in many ways, but it has to start with the relationship and contracts in place. Once there is a contract then each practice can be broken down. Third party security assessments typically include two main practices. These are:</p>
<ol>
<li>Technical Security Testing</li>
<li>Checklist Validation Assessments</li>
</ol>
<p>Technical Security Testing usually involves network vulnerability scanning, penetration testing, application testing, and sometimes security configuration reviews. This approach occurs when a third party is contracted to assess the host organization. This is a third party assessment however this situation addresses contracting a third party to perform the assessment. The other focuses on assessing the host organizations third party service providers, not contracting a third party to perform an assessment.</p>
<p>Checklist validation assessments are commonly used for assessing ones service providers. One of the most common used tools for this practice is supplied online by Shared Assessments. The Shared assessments questionnaire and agreed upon procedures guides are used in many different countries around the world. They are very comprehensive and allow for customization if required. The core components that make this tool fantastic for third party risk assessments are:</p>
<ol>
<li>Excel based checklist format which can be auto compared against a configured baseline</li>
<li>Comprehensive list of standard questions that map to some different compliance regulations</li>
</ol>
<p>The Shared Assessments program has done a good job explaining the tool use and to avoid repeating the information that is clearly explained online the focus will be to explain leveraging the tool to build a third party assessment function in the organization. Building the third party assessment requires some dedicated resource time for the following responsibilities.</p>
<ul>
<li>Determining the assessment schedule and prioritization</li>
<li>Customizing the questionnaires</li>
<li>Phone and email follow up to third parties</li>
<li>Onsite review and validation (if applicable based on the assessment type)</li>
<li>Providing reports to management and third party entities</li>
<li>Follow up on remediation efforts</li>
</ul>
<p><strong></strong> </p>
<p><strong>Shared Assessments &#8211; Useful</strong></p>
<p>Back in 2009 my blog entry was titled “BITS Shared Assessments – Useful or Not”. After several more years and reviewing hundreds of clients it appears this is now the predominantly used assessment practice. Organizations have used the main content and questions then customized and integrated them into formal programs. I still find the validation component one of the weakest links, but in some cases that also falls on the assessor. To help mitigate the risk organizations should be looking at some kind of technical and checklist testing of their entities. Using both of these will help make up for deficiencies in the checklist based approaches.</p>
<p>I encourage others to comment if they have seen different standards for third party assessment especially those around the checklist and validation approach. As today the Shared Assessments appears to still be the number one choice implemented and used based on my experience with other companies.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jtbevis.wordpress.com/202/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jtbevis.wordpress.com/202/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jtbevis.wordpress.com/202/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jtbevis.wordpress.com/202/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jtbevis.wordpress.com/202/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jtbevis.wordpress.com/202/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jtbevis.wordpress.com/202/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jtbevis.wordpress.com/202/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jtbevis.wordpress.com/202/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jtbevis.wordpress.com/202/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jtbevis.wordpress.com/202/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jtbevis.wordpress.com/202/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jtbevis.wordpress.com/202/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jtbevis.wordpress.com/202/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecalways.com&amp;blog=168717&amp;post=202&amp;subd=jtbevis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://infosecalways.com/2011/10/30/is-your-3rd-party-provider-secure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2cc550be1da522f5450a013056ae0ad9?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jtbevis</media:title>
		</media:content>
	</item>
		<item>
		<title>Crypto, Encryption, DLP, and Privacy Laws</title>
		<link>http://infosecalways.com/2011/04/19/crypto-encryption-dlp-and-privacy-laws/</link>
		<comments>http://infosecalways.com/2011/04/19/crypto-encryption-dlp-and-privacy-laws/#comments</comments>
		<pubDate>Tue, 19 Apr 2011 20:26:04 +0000</pubDate>
		<dc:creator>jtbevis</dc:creator>
				<category><![CDATA[Policy and Compliance]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security Governance]]></category>

		<guid isPermaLink="false">http://infosecalways.com/?p=183</guid>
		<description><![CDATA[Doing a project that requires knowledge of international crypto laws.  Here is a great resource that has captured information from several sources and put it on a Google map.  http://mcaf.ee/cryptolaw How about trying to figure out all those privacy laws for DLP?  Here is another map by Simon Hunt for detailing the major international DLP [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecalways.com&amp;blog=168717&amp;post=183&amp;subd=jtbevis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:left;">Doing a project that requires knowledge of international crypto laws.  Here is a great resource that has captured information from several sources and put it on a Google map. </p>
<p><a href="http://mcaf.ee/cryptolaw">http://mcaf.ee/cryptolaw</a></p>
<p>How about trying to figure out all those privacy laws for DLP?  Here is another map by Simon Hunt for detailing the major international DLP related privacy laws.</p>
<p><a href="http://mcaf.ee/dlplaws">http://mcaf.ee/dlplaws</a></p>
<p>Take a look at the DLP map below.</p>
<p><a href="http://jtbevis.files.wordpress.com/2011/04/dlp-map.jpg"><img class="size-medium wp-image-185 alignleft" title="DLP Map" src="http://jtbevis.files.wordpress.com/2011/04/dlp-map.jpg?w=300&#038;h=158" alt="" width="300" height="158" /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jtbevis.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jtbevis.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jtbevis.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jtbevis.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jtbevis.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jtbevis.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jtbevis.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jtbevis.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jtbevis.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jtbevis.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jtbevis.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jtbevis.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jtbevis.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jtbevis.wordpress.com/183/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecalways.com&amp;blog=168717&amp;post=183&amp;subd=jtbevis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://infosecalways.com/2011/04/19/crypto-encryption-dlp-and-privacy-laws/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2cc550be1da522f5450a013056ae0ad9?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jtbevis</media:title>
		</media:content>

		<media:content url="http://jtbevis.files.wordpress.com/2011/04/dlp-map.jpg?w=300" medium="image">
			<media:title type="html">DLP Map</media:title>
		</media:content>
	</item>
		<item>
		<title>Penetration Testing Risks</title>
		<link>http://infosecalways.com/2010/08/24/penetration-testing-risks/</link>
		<comments>http://infosecalways.com/2010/08/24/penetration-testing-risks/#comments</comments>
		<pubDate>Tue, 24 Aug 2010 22:05:00 +0000</pubDate>
		<dc:creator>jtbevis</dc:creator>
				<category><![CDATA[Prevention]]></category>
		<category><![CDATA[Security Governance]]></category>

		<guid isPermaLink="false">http://infosecalways.com/?p=174</guid>
		<description><![CDATA[What are the risks to someone performing a penetration test? It seems  this question has been asked a 100 times yet the other day I was typing up the same answers again because for some reason there was no write up. This is generic, but hopefully it saves us all time in the future.  Risks: Basically there [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecalways.com&amp;blog=168717&amp;post=174&amp;subd=jtbevis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>What are the risks to someone performing a penetration test?</p>
<p>It seems  this question has been asked a 100 times yet the other day I was typing up the same answers again because for some reason there was no write up.</p>
<p>This is generic, but hopefully it saves us all time in the future. </p>
<p><strong>Risks:</strong></p>
<p>Basically there are two key risks.</p>
<ol>
<li>There is no guarantee systems won&#8217;t have some type of denial of service.</li>
</ol>
<p>This is typically a result of having older legacy systems or custom applications, which are taken offline by an automated vulnerability scanner or over abuse by the attacker.</p>
<p> 2. Bandwidth or system utilization may be increased thus resulting in performance loss.</p>
<p>Based on the amount of the automated scanning, the size of the network pipes (both scanning and target), and the number of open ports on a particular system it is possible to overwhelm a service or medium resulting in a performance loss.</p>
<p><strong>Mitigating Risks:</strong></p>
<p>To help prevent a denial of service many approaches can be taken.  Here are some examples.</p>
<p>1. Exclude legacy systems from automated testing. To ensure security perform manual testing of excluded items.</p>
<p>2. Exclude custom applications from automated testing. To ensure security perform manual testing of excluded applications.</p>
<p>3. Perform testing of critical systems during off hours.  Critical systems can be scheduled for testing during low volume business or off business hours.</p>
<p>4. Perform testing in a phased manner starting with user acceptance testing (UAT) environments to ensure the actual tests do not affect particular systems or networks.  Once UAT is complete then begin testing on production environments.</p>
<p>5. Setup monitoring and escalation procedures prior to testing.  Ensure fault management is in place to ensure systems send alerts when they go down.  Ensure proper phone numbers and other contact information is defined to immediately investigate and restore services in the event of a problem.  Escalation procedures should include contact information for the person performing the testing to immediately stop all testing if required.</p>
<p>To help prevent bandwidth issues automated testing can be throttled back to use less bandwidth.  Also the number of ports can be reduced if there is a concern for overloading a particular group of systems.  Usually it is recommended to test the UAT environment instead of reducing the number of ports because certain vulnerabilities may be missed.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jtbevis.wordpress.com/174/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jtbevis.wordpress.com/174/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jtbevis.wordpress.com/174/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jtbevis.wordpress.com/174/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jtbevis.wordpress.com/174/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jtbevis.wordpress.com/174/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jtbevis.wordpress.com/174/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jtbevis.wordpress.com/174/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jtbevis.wordpress.com/174/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jtbevis.wordpress.com/174/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jtbevis.wordpress.com/174/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jtbevis.wordpress.com/174/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jtbevis.wordpress.com/174/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jtbevis.wordpress.com/174/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecalways.com&amp;blog=168717&amp;post=174&amp;subd=jtbevis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://infosecalways.com/2010/08/24/penetration-testing-risks/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2cc550be1da522f5450a013056ae0ad9?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jtbevis</media:title>
		</media:content>
	</item>
		<item>
		<title>What is the best starting point to embrace risk management?</title>
		<link>http://infosecalways.com/2010/02/04/what-is-the-best-starting-point-to-embrace-risk-management/</link>
		<comments>http://infosecalways.com/2010/02/04/what-is-the-best-starting-point-to-embrace-risk-management/#comments</comments>
		<pubDate>Thu, 04 Feb 2010 03:19:03 +0000</pubDate>
		<dc:creator>jtbevis</dc:creator>
				<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security Governance]]></category>
		<category><![CDATA[Security Program Development]]></category>

		<guid isPermaLink="false">http://infosecalways.com/?p=165</guid>
		<description><![CDATA[This is a topic that has generated a great deal of traffic on the Linkedin “Governance, Risk and Compliance Management (GRC) site.  If you are a member I recommend you read through the comments, if not you should consider joining.  This is a cross post, slightly modified, of my answer to this question, so forgive [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecalways.com&amp;blog=168717&amp;post=165&amp;subd=jtbevis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This is a topic that has generated a great deal of traffic on the Linkedin “Governance, Risk and Compliance Management (GRC) site.  If you are a member I recommend you read through the comments, if not you should consider joining.  This is a cross post, slightly modified, of my answer to this question, so forgive the double traffic if you are a member. </p>
<p>I was shocked that no one had mentioned the size and financial ability of the company.  So this addresses both small and large corporations with and without financial money allocated to security.</p>
<p>If the company is 300 people and has very little money then usually the starting point is convincing management why money needs to be directed towards an assessment versus actually doing something tangible. Therefore, obtaining management support through some shock and awe factor will help get buy in and then you can do a risk assessment. That assessment should provide a roadmap and serve as the strategic plan.</p>
<p>Now if the company is more mature and financially stable, I agree with several of the current comments, which stated some type of RA framework or COSO control framework. Anyway, the typical starting point is conducting some type of strategic risk assessment. Something reviews all of the organizations assets, the threats, and vulnerabilities. This assessment should help start the program by prioritizing based on risk each security effort. From this assessment one of action items, if it doesn&#8217;t already exist, should be to put in a control (ISMS) type framework in place.</p>
<p>Once the prioritized roadmap is created and a control structure is in place then these two items can be baselined and measured over time. Also each control area can have individual metrics. As the risk management program grows the next step will be to build a project or application based risk approach in addition to the strategic risk assessment. This focus of this secondary assessment approach is to rapidly assess projects and determine the level of security review required at the project level. Some projects will require more based on their risk (i.e. type of data, etc.).</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jtbevis.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jtbevis.wordpress.com/165/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jtbevis.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jtbevis.wordpress.com/165/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jtbevis.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jtbevis.wordpress.com/165/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jtbevis.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jtbevis.wordpress.com/165/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jtbevis.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jtbevis.wordpress.com/165/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jtbevis.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jtbevis.wordpress.com/165/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jtbevis.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jtbevis.wordpress.com/165/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecalways.com&amp;blog=168717&amp;post=165&amp;subd=jtbevis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://infosecalways.com/2010/02/04/what-is-the-best-starting-point-to-embrace-risk-management/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2cc550be1da522f5450a013056ae0ad9?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jtbevis</media:title>
		</media:content>
	</item>
		<item>
		<title>BITS Shared Assessments &#8211; Useful or Not</title>
		<link>http://infosecalways.com/2009/08/07/bits-shared-assessments-useful-or-not/</link>
		<comments>http://infosecalways.com/2009/08/07/bits-shared-assessments-useful-or-not/#comments</comments>
		<pubDate>Fri, 07 Aug 2009 21:47:23 +0000</pubDate>
		<dc:creator>jtbevis</dc:creator>
				<category><![CDATA[Policy and Compliance]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security Governance]]></category>
		<category><![CDATA[Security Program Development]]></category>

		<guid isPermaLink="false">http://infosecalways.com/?p=160</guid>
		<description><![CDATA[What do you think? Is this another useless assessment methodology, great idea, or a platform for vendors to sell products? I recently went to the 2nd Annual BITs Shared Assessments in Chicago. http://www.sharedassessments.org/ I found the event driven mostly by product vendors, a few assessment firms, and some footprint from the banking industry. During the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecalways.com&amp;blog=168717&amp;post=160&amp;subd=jtbevis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>What do you think? Is this another useless assessment methodology, great idea, or a platform for vendors to sell products?</p>
<p>I recently went to the 2nd Annual BITs Shared Assessments in Chicago. <a href="http://www.sharedassessments.org/">http://www.sharedassessments.org/</a></p>
<p>I found the event driven mostly by product vendors, a few assessment firms, and some footprint from the banking industry. During the time of the event and now I was able to deliver an engagement and as a result of the conference and this delivery I have the following comments.</p>
<ol>
<li>Many assessors are using older versions of the SIG and still have not adopted 4.2.</li>
<li>Product vendors have incorporated many of the features and appear to be pushing the solution the most.</li>
<li>The current AUP and SIG are fairly decent, but the overall solution still needs to mature greatly. I found that several of the AUPs were incorrect or missing. I have yet to consolidate all my comments; however I emailed the main contact number on the site. Currently comments are submitted one by one. I don’t want to enter them one by one, thus, I haven’t submitted as I’m still waiting for a response after several weeks.</li>
<li>The current scoping and process for delivery is underestimated. My experience shows that you will have to set strict guidelines with the number of follow up conversations and have a cut off for evidence. Otherwise the entity that is assessed will continue to try and justify they have the appropriate controls in place.</li>
<li>There are plans for mapping to other compliance regulations. There are many more comments I have about this solution, but mostly I’m seeing customers use only the SIG Light or SIG level 2.</li>
</ol>
<p>I see this as holding a place in the 3rd party assessment realm for an organization. I’m wondering! Is anyone else using the Shared Assessments? What are your thoughts? Will this solution grow and be used like PCI even though it doesn’t have the formal backing like PCI?</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jtbevis.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jtbevis.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jtbevis.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jtbevis.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jtbevis.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jtbevis.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jtbevis.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jtbevis.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jtbevis.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jtbevis.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jtbevis.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jtbevis.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jtbevis.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jtbevis.wordpress.com/160/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecalways.com&amp;blog=168717&amp;post=160&amp;subd=jtbevis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://infosecalways.com/2009/08/07/bits-shared-assessments-useful-or-not/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2cc550be1da522f5450a013056ae0ad9?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jtbevis</media:title>
		</media:content>
	</item>
		<item>
		<title>More on Staffing and Governance</title>
		<link>http://infosecalways.com/2009/05/19/more-on-staffing-and-governance/</link>
		<comments>http://infosecalways.com/2009/05/19/more-on-staffing-and-governance/#comments</comments>
		<pubDate>Tue, 19 May 2009 03:26:47 +0000</pubDate>
		<dc:creator>jtbevis</dc:creator>
				<category><![CDATA[Security Governance]]></category>
		<category><![CDATA[Security Program Development]]></category>
		<category><![CDATA[Security Staffing]]></category>

		<guid isPermaLink="false">http://infosecalways.com/?p=158</guid>
		<description><![CDATA[I been tracking via this blog a good amount of search hits looking for security staffing and governance.  Unfortunately when you search there is not much out on the Internet.  If anyone is interested let me know and I will start an open source project off this blog to create a governance and staffing solution/program. For [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecalways.com&amp;blog=168717&amp;post=158&amp;subd=jtbevis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I been tracking via this blog a good amount of search hits looking for security staffing and governance.  Unfortunately when you search there is not much out on the Internet.  If anyone is interested let me know and I will start an open source project off this blog to create a governance and staffing solution/program.</p>
<p>For those that have little or no knowledge in this area I suggest you review the Security Task Force documentation and the Educause updates located here:</p>
<p><a href="http://www.educause.edu/Resources/InformationSecurityGovernanceA/160639">Educause Information Security Governance Assessment Tool</a></p>
<p>For an open source program I would like to build of the current work, but also provide a lot more emphasis on the organizational charts and the roles and responsibilities.  If your interested please let me know and we can get everyone together and create an updated model for multiple industries.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jtbevis.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jtbevis.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jtbevis.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jtbevis.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jtbevis.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jtbevis.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jtbevis.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jtbevis.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jtbevis.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jtbevis.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jtbevis.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jtbevis.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jtbevis.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jtbevis.wordpress.com/158/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecalways.com&amp;blog=168717&amp;post=158&amp;subd=jtbevis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://infosecalways.com/2009/05/19/more-on-staffing-and-governance/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2cc550be1da522f5450a013056ae0ad9?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jtbevis</media:title>
		</media:content>
	</item>
		<item>
		<title>Application Risk Assessments</title>
		<link>http://infosecalways.com/2009/04/17/application-risk-assessments/</link>
		<comments>http://infosecalways.com/2009/04/17/application-risk-assessments/#comments</comments>
		<pubDate>Fri, 17 Apr 2009 21:13:11 +0000</pubDate>
		<dc:creator>jtbevis</dc:creator>
				<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Software Security]]></category>

		<guid isPermaLink="false">http://infosecalways.com/?p=149</guid>
		<description><![CDATA[I came across an interesting blog about application risk assessment today, so I wanted to highlight some of the different approaches in response.  Blog Post: http://risktical.com/2009/03/16/application-security-risk-assessments/ In the blog Chris’s approach seems somewhat like threat modeling, which is typically used for code reviews.  In general he covers a large part of the important content but doesn’t [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecalways.com&amp;blog=168717&amp;post=149&amp;subd=jtbevis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin:0;"><span style="font-size:small;"><span style="font-family:Times New Roman;">I came across an interesting blog about application risk assessment today, so I wanted to highlight some of the different approaches in response.<span>  </span></span></span></p>
<p class="MsoNormal" style="margin:0;"><span style="font-size:small;font-family:Times New Roman;">Blog Post:</span></p>
<ul>
<li>
<div class="MsoNormal" style="margin:0;"><a href="http://risktical.com/2009/03/16/application-security-risk-assessments/">http://risktical.com/2009/03/16/application-security-risk-assessments/</a></div>
</li>
</ul>
<p class="MsoNormal" style="margin:0;"><span style="font-size:small;font-family:Times New Roman;">In the blog Chris’s approach seems somewhat like threat modeling, which is typically used for code reviews.<span>  </span>In general he covers a large part of the important content but doesn’t address the real issues of risk – Cost vs Risk.<span>  </span>Anyway I hope to address that here and explain the two major methods used extensively.<span>  </span>These are threat modeling and the NIST/OCTAVE asset based approach. </span></p>
<p class="MsoNormal" style="margin:0;"> </p>
<p class="MsoNormal" style="margin:0;"><strong>Threat Modeling Approach</strong></p>
<p class="MsoNormal" style="margin:0;">Threat Modeling is basically the ongoing risk assessment process which covers the entire Software Development Lifecycle.</p>
<ul>
<li>
<div class="MsoNormal" style="margin:0;"><span style="font-size:small;font-family:Times New Roman;"><a href="http://en.wikipedia.org/wiki/Threat_model">http://en.wikipedia.org/wiki/Threat_model</a> </span></div>
</li>
<li>
<div class="MsoNormal" style="margin:0;"><span style="font-size:small;font-family:Times New Roman;"><a href="http://msdn.microsoft.com/en-us/library/ms978516.aspx">http://msdn.microsoft.com/en-us/library/ms978516.aspx</a> </span></div>
</li>
</ul>
<p class="MsoNormal" style="margin:0;"><span style="font-size:small;font-family:Times New Roman;"><strong>Strategic Approach</strong></span></p>
<p class="MsoNormal" style="margin:0;"><span style="font-size:small;font-family:Times New Roman;">From a managerial risk assessment approach I would take a different view using a strategic NIST/OCTAVE approach.</span></p>
<ol>
<li>
<div class="MsoNormal" style="margin:0;"><span style="font-size:small;font-family:Times New Roman;">What are the assets? (i.e. information, applications, hardware, etc.)</span></div>
</li>
<li>
<div class="MsoNormal" style="margin:0;"><span style="font-size:small;font-family:Times New Roman;">What are the threats? (i.e. data contamination, malicious code, equipment failure, etc.)</span></div>
</li>
<li>
<div class="MsoNormal" style="margin:0;"><span style="font-size:small;font-family:Times New Roman;">What are the vulnerabilities (i.e. no security training for developers, lack of formal SDLC, no development standards, no security requirements, no security testing, etc.)</span></div>
</li>
</ol>
<p class="MsoNormal" style="margin:0;"><span style="font-size:small;font-family:Times New Roman;">Within the vulnerabilities I would role up any identified tactical findings into strategic issues.<span>  </span>For example, software code with clear text passwords may result in a poor encryption policy, lack of standard, or a lack of proper classification policy and controls around passwords. </span></p>
<p class="MsoNormal" style="margin:0;"> </p>
<p class="MsoNormal" style="margin:0;"><span style="font-size:small;font-family:Times New Roman;">Overall using this strategic approach helps us to determine what assets in the entire application architecture/environment have the highest risk and we can mitigate accordingly.<span>  </span>In the long run this approach should save cost.<span>  </span>We really wouldn’t want to spend $40,000 dollars on a code review for each application when I know that none of the developers have security training nor do we have secure development standards.<span>  </span>This money can be strategically better spent on training since we might have 30 applications across the enterprise.<span>  </span>At that point we can then decide to perform a sample checkup and measure the progress to see how we perform both before and after the training.<span>  </span>This will be the most cost effective approach and produce metrics that can be delivered to executive management.</span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jtbevis.wordpress.com/149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jtbevis.wordpress.com/149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jtbevis.wordpress.com/149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jtbevis.wordpress.com/149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jtbevis.wordpress.com/149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jtbevis.wordpress.com/149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jtbevis.wordpress.com/149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jtbevis.wordpress.com/149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jtbevis.wordpress.com/149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jtbevis.wordpress.com/149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jtbevis.wordpress.com/149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jtbevis.wordpress.com/149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jtbevis.wordpress.com/149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jtbevis.wordpress.com/149/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecalways.com&amp;blog=168717&amp;post=149&amp;subd=jtbevis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://infosecalways.com/2009/04/17/application-risk-assessments/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2cc550be1da522f5450a013056ae0ad9?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jtbevis</media:title>
		</media:content>
	</item>
		<item>
		<title>Do QSA’s Understand PCI?</title>
		<link>http://infosecalways.com/2009/03/19/do-qsa%e2%80%99s-understand-pci/</link>
		<comments>http://infosecalways.com/2009/03/19/do-qsa%e2%80%99s-understand-pci/#comments</comments>
		<pubDate>Thu, 19 Mar 2009 21:39:24 +0000</pubDate>
		<dc:creator>jtbevis</dc:creator>
				<category><![CDATA[Policy and Compliance]]></category>
		<category><![CDATA[Security Governance]]></category>

		<guid isPermaLink="false">http://infosecalways.com/?p=141</guid>
		<description><![CDATA[I guess that title should say “Can anyone clarify PCI?” or “Can we get some PCI consistency please?.  I find myself in discussion day after day on topics around PCI.   What is required for web app test?  Is it authenticated? Is it just a scan?  Is it just my external environment?  Is it only [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecalways.com&amp;blog=168717&amp;post=141&amp;subd=jtbevis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin:0;"><span style="font-size:small;font-family:Times New Roman;">I guess that title should say “Can anyone clarify PCI?” or “Can we get some PCI consistency please?.<span>  </span>I find myself in discussion day after day on topics around PCI.</span></p>
<p class="MsoNormal" style="margin:0;"><span style="font-size:small;font-family:Times New Roman;"> </span></p>
<p class="MsoNormal" style="margin:0;"><span style="font-size:small;font-family:Times New Roman;">What is required for web app test?<span>  </span>Is it authenticated? Is it just a scan?<span>  </span>Is it just my external environment?<span>  </span>Is it only my card holder systems?</span></p>
<p class="MsoNormal" style="margin:0;"><span style="font-size:small;font-family:Times New Roman;"> </span></p>
<p class="MsoNormal" style="margin:0;"><span style="font-size:small;font-family:Times New Roman;">I know the council is trying to do their best with outlining the standards but their still is a serious lack of consistency across QSA’s and organizations.<span>  </span>I found this so frustrating that I developed the cartoon below to represent my opinion.</span></p>
<p class="MsoNormal" style="margin:0;"> </p>
<p class="MsoNormal" style="margin:0;"><img class="aligncenter size-full wp-image-143" title="pci-compliance" src="http://jtbevis.files.wordpress.com/2009/03/pci-compliance.png?w=470&#038;h=214" alt="pci-compliance" width="470" height="214" /></p>
<p class="MsoNormal" style="margin:0;"><span style="font-size:small;font-family:Times New Roman;">Basically Mr. CEO here is not meeting PCI compliance and his QSA’s are all telling him something different.<span>  </span>Even better is the new standards and enforcement that all the QSA’s themselves are trying to understand?<span>  </span>Will any big enterprise be able to make compliance? </span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jtbevis.wordpress.com/141/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jtbevis.wordpress.com/141/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jtbevis.wordpress.com/141/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jtbevis.wordpress.com/141/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jtbevis.wordpress.com/141/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jtbevis.wordpress.com/141/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jtbevis.wordpress.com/141/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jtbevis.wordpress.com/141/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jtbevis.wordpress.com/141/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jtbevis.wordpress.com/141/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jtbevis.wordpress.com/141/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jtbevis.wordpress.com/141/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jtbevis.wordpress.com/141/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jtbevis.wordpress.com/141/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecalways.com&amp;blog=168717&amp;post=141&amp;subd=jtbevis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://infosecalways.com/2009/03/19/do-qsa%e2%80%99s-understand-pci/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2cc550be1da522f5450a013056ae0ad9?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jtbevis</media:title>
		</media:content>

		<media:content url="http://jtbevis.files.wordpress.com/2009/03/pci-compliance.png" medium="image">
			<media:title type="html">pci-compliance</media:title>
		</media:content>
	</item>
		<item>
		<title>Security Survey Polls Added</title>
		<link>http://infosecalways.com/2009/03/19/security-survey-polls-added/</link>
		<comments>http://infosecalways.com/2009/03/19/security-survey-polls-added/#comments</comments>
		<pubDate>Thu, 19 Mar 2009 13:39:21 +0000</pubDate>
		<dc:creator>jtbevis</dc:creator>
				<category><![CDATA[Security Governance]]></category>
		<category><![CDATA[Security Program Development]]></category>
		<category><![CDATA[Security Staffing]]></category>

		<guid isPermaLink="false">http://infosecalways.com/?p=135</guid>
		<description><![CDATA[The polls are open! While visiting this site please check out the new IS Management page and contribute to the voting polls. http://infosecalways.com/is-management-polls/ If you would like to see new or different polls added let me know.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecalways.com&amp;blog=168717&amp;post=135&amp;subd=jtbevis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The polls are open!</p>
<p>While visiting this site please check out the new IS Management page and contribute to the voting polls.</p>
<ul>
<li><a href="http://infosecalways.com/is-management-polls/">http://infosecalways.com/is-management-polls/</a></li>
</ul>
<p>If you would like to see new or different polls added let me know.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jtbevis.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jtbevis.wordpress.com/135/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jtbevis.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jtbevis.wordpress.com/135/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jtbevis.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jtbevis.wordpress.com/135/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jtbevis.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jtbevis.wordpress.com/135/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jtbevis.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jtbevis.wordpress.com/135/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jtbevis.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jtbevis.wordpress.com/135/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jtbevis.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jtbevis.wordpress.com/135/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infosecalways.com&amp;blog=168717&amp;post=135&amp;subd=jtbevis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://infosecalways.com/2009/03/19/security-survey-polls-added/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2cc550be1da522f5450a013056ae0ad9?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jtbevis</media:title>
		</media:content>
	</item>
	</channel>
</rss>
