<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>adventuresinsecurity.com Blog</title>
	<atom:link href="http://adventuresinsecurity.com/blog/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://adventuresinsecurity.com/blog</link>
	<description>Information Security Management for Business Managers</description>
	<lastBuildDate>Mon, 19 Feb 2007 16:08:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Use risk management for reasonable information asset protection</title>
		<link>http://adventuresinsecurity.com/blog/2007/02/19/use-risk-management-for-reasonable-information-asset-protection/</link>
		<comments>http://adventuresinsecurity.com/blog/2007/02/19/use-risk-management-for-reasonable-information-asset-protection/#comments</comments>
		<pubDate>Mon, 19 Feb 2007 16:08:58 +0000</pubDate>
		<dc:creator>Tom Olzak</dc:creator>
				<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Security Management Tips]]></category>

		<guid isPermaLink="false">http://adventuresinsecurity.com/blog/?p=118</guid>
		<description><![CDATA[Selecting the right security controls can be a daunting task.  By applying the principles of risk management, however, security managers can meet the challenge with confidence.
 Read the article
]]></description>
			<content:encoded><![CDATA[<p align="left">Selecting the right security controls can be a daunting task.  By applying the principles of risk management, however, security managers can meet the challenge with confidence.</p>
<p align="left"> <a href="http://blogs.techrepublic.com.com/security/?p=158" target="_blank">Read the article</a></p>
]]></content:encoded>
			<wfw:commentRss>http://adventuresinsecurity.com/blog/2007/02/19/use-risk-management-for-reasonable-information-asset-protection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Holy Toledo! The iPod did it!</title>
		<link>http://adventuresinsecurity.com/blog/2007/02/17/holy-toledo-the-ipod-did-it/</link>
		<comments>http://adventuresinsecurity.com/blog/2007/02/17/holy-toledo-the-ipod-did-it/#comments</comments>
		<pubDate>Sat, 17 Feb 2007 19:43:40 +0000</pubDate>
		<dc:creator>Tom Olzak</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[Security Management Tips]]></category>

		<guid isPermaLink="false">http://adventuresinsecurity.com/blog/?p=117</guid>
		<description><![CDATA[Unbelievable.  It&#8217;s even more unbelievable because I live near the community of Oregon, Ohio where a police detective called a student&#8217;s iPod a &#8220;criminal tool&#8221;. 
In an article in the Toledo Blade,  Robin Erb describes an incident in which a former Clay High School student was charged with a felony for accessing school employee and student records.  [...]]]></description>
			<content:encoded><![CDATA[<p>Unbelievable.  It&#8217;s even more unbelievable because I live near the community of Oregon, Ohio where a police detective called a student&#8217;s iPod a &#8220;criminal tool&#8221;. </p>
<p>In <a href="http://toledoblade.com/apps/pbcs.dll/article?AID=/20070214/NEWS03/702140355">an article in the Toledo Blade</a>,  Robin Erb describes an incident in which a former Clay High School student was charged with a felony for accessing school employee and student records.  Not only did he access them, he downloaded them to his iPod.  In addition to being charged with unauthorized use of a computer, he was also charged with possessing a criminal tool&#8211;i.e. the iPod.  Nice police work, Oregon.  Will I still be able to carry my iPod concealed when I cross the city line?</p>
<p>Although the former student used a school computer lab to access the sensitve records, no mention was made in the article about how this was even possible.  It probably didn&#8217;t take much cracking of system security if access was gained in a classroom with High School staff supervision.   Instead of vilifying the venerable iPod&#8211;or any other mobile storage device for that matter&#8211;it might be better to ask serious questions about how this was even possible.  What steps is the school system taking to ensure this doesn&#8217;t happen again?  Or will the school board simply add mobile storage devices to the list of criminal tools so it can assure parents and teachers that their information is now secure?<br />
 </p>
]]></content:encoded>
			<wfw:commentRss>http://adventuresinsecurity.com/blog/2007/02/17/holy-toledo-the-ipod-did-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Calling endusers stupid isn&#8217;t helpful</title>
		<link>http://adventuresinsecurity.com/blog/2007/02/17/calling-endusers-stupid-isnt-helpful/</link>
		<comments>http://adventuresinsecurity.com/blog/2007/02/17/calling-endusers-stupid-isnt-helpful/#comments</comments>
		<pubDate>Sat, 17 Feb 2007 19:00:01 +0000</pubDate>
		<dc:creator>Tom Olzak</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[Endusers]]></category>
		<category><![CDATA[Security Management Tips]]></category>

		<guid isPermaLink="false">http://adventuresinsecurity.com/blog/?p=116</guid>
		<description><![CDATA[I was reading a Tim Wilson article at Dark Reading this morning in which he asked the question, &#8220;So are users hopeless?  Are they inherently brainless and/or evil?&#8221;  My first reaction to the question was raucous laughter.  When I finally regained my senses, I read the rest of the article in which Wilson makes a lot [...]]]></description>
			<content:encoded><![CDATA[<p>I was reading <a href="http://www.darkreading.com/document.asp?doc_id=117639&#038;f_src=darkreading_node_1946" target="_blank">a Tim Wilson article</a> at Dark Reading this morning in which he asked the question, &#8220;So are users hopeless?  Are they inherently brainless and/or evil?&#8221;  My first reaction to the question was raucous laughter.  When I finally regained my senses, I read the rest of the article in which Wilson makes a lot of sense.</p>
<p>As a security director, I have days when I believe the users are all out to violate as many security policies as they can, either intentionally or because they are brain dead.  But this attitude isn&#8217;t helpful.  I agree with Wilson that most end users are intelligent individuals who want to do the right thing.  Keeping that in mind, helping users help themselves is a key element in any security program.</p>
<p>For years I&#8217;ve been a proponent of user education as a first step.  If there is chaos in the halls of security compliance, then part of the blame usually lies with the lack of effectiveness of an organization&#8217;s security awareness efforts.   This is always the first step, but it isn&#8217;t enough.</p>
<p>Employees will always make mistakes.  Yes, they&#8217;re human beings not robots.  So there are steps security professionals must take to mitigate the impact of those mistakes.  Content monitoring for data transfers, locking down the desktop, and Internet access controls are three good places to start.  Not only will this help stop the bleeding from an accidental incident, it will also help minimize the probability of malicious activities.</p>
<p>Wilson does finish his article with the assertion that end users <em>are</em> hopeless.  OK.  Maybe.  But IT security shouldn&#8217;t be. </p>
<p> </p>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://adventuresinsecurity.com/blog/2007/02/17/calling-endusers-stupid-isnt-helpful/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DO NOT USE TELNET OVER THE INTERNET</title>
		<link>http://adventuresinsecurity.com/blog/2007/02/16/do-not-use-telnet-over-the-internet/</link>
		<comments>http://adventuresinsecurity.com/blog/2007/02/16/do-not-use-telnet-over-the-internet/#comments</comments>
		<pubDate>Fri, 16 Feb 2007 16:03:21 +0000</pubDate>
		<dc:creator>Tom Olzak</dc:creator>
				<category><![CDATA[Security Management Tips]]></category>

		<guid isPermaLink="false">http://adventuresinsecurity.com/blog/?p=115</guid>
		<description><![CDATA[Yes, the title is in all caps.  Yes, I&#8217;ll yelling as loudly as I can.  In a recent column at seearchsecurity.com, Bill Brenner reiterates the dangers of using Telnet over connections that are not secure.  The principle problem is that Telnet communicates user IDs and passwords in clear text between workstation and server.  Secure Shell [...]]]></description>
			<content:encoded><![CDATA[<p>Yes, the title is in all caps.  Yes, I&#8217;ll yelling as loudly as I can.  <a href="http://searchsecurity.techtarget.com/columnItem/0,294698,sid14_gci1244019,00.html?track=sy160" target="_blank">In a recent column at seearchsecurity.com</a>, Bill Brenner reiterates the dangers of using Telnet over connections that are not secure.  The principle problem is that Telnet communicates user IDs and passwords in clear text between workstation and server.  Secure Shell (SSH) is a much better choice.</p>
]]></content:encoded>
			<wfw:commentRss>http://adventuresinsecurity.com/blog/2007/02/16/do-not-use-telnet-over-the-internet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Reflections on Vista security</title>
		<link>http://adventuresinsecurity.com/blog/2007/02/16/reflections-on-vista-security/</link>
		<comments>http://adventuresinsecurity.com/blog/2007/02/16/reflections-on-vista-security/#comments</comments>
		<pubDate>Fri, 16 Feb 2007 15:54:07 +0000</pubDate>
		<dc:creator>Tom Olzak</dc:creator>
				<category><![CDATA[Security Management Tips]]></category>

		<guid isPermaLink="false">http://adventuresinsecurity.com/blog/?p=114</guid>
		<description><![CDATA[In a recent blog entry at invisiblethings.com, Joanna posted her comments on Vista UAC and integrity levels after having used the OS for more than a month.  Interesting reading.
]]></description>
			<content:encoded><![CDATA[<p>In <a href="http://theinvisiblethings.blogspot.com/2007/02/running-vista-every-day.html" target="_blank">a recent blog entry</a> at invisiblethings.com, Joanna posted her comments on Vista UAC and integrity levels after having used the OS for more than a month.  Interesting reading.</p>
]]></content:encoded>
			<wfw:commentRss>http://adventuresinsecurity.com/blog/2007/02/16/reflections-on-vista-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scan AJAX for XSS entry points</title>
		<link>http://adventuresinsecurity.com/blog/2007/02/16/scan-ajax-for-xss-entry-points/</link>
		<comments>http://adventuresinsecurity.com/blog/2007/02/16/scan-ajax-for-xss-entry-points/#comments</comments>
		<pubDate>Fri, 16 Feb 2007 15:28:49 +0000</pubDate>
		<dc:creator>Tom Olzak</dc:creator>
				<category><![CDATA[Security Management Tips]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://adventuresinsecurity.com/blog/?p=113</guid>
		<description><![CDATA[Cross site scripting (XSS) is a big problem in web application environments.  In fact, the 2007 OWASP Top Ten list of web application vulnerabilities has XSS at #1.  In a recent paper, Shreeraj Shah, founder of Net Square, describes in detail the process for protecting applications developed using the AJAX framework.  It also includes scripts [...]]]></description>
			<content:encoded><![CDATA[<p>Cross site scripting (XSS) is a big problem in web application environments.  In fact, the 2007 OWASP Top Ten list of web application vulnerabilities has XSS at #1.  In a recent paper, Shreeraj Shah, founder of Net Square, describes in detail the process for protecting applications developed using the AJAX framework.  It also includes scripts to automatically scan code for XSS vulnerabilities.  <a href="http://www.net-security.org/dl/articles/Scanning_Ajax_for_XSS_entry_points.pdf" target="_blank">The paper can be found here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://adventuresinsecurity.com/blog/2007/02/16/scan-ajax-for-xss-entry-points/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Transfer risk when mitigation costs are too high</title>
		<link>http://adventuresinsecurity.com/blog/2007/02/16/transfer-risk-when-mitigation-costs-are-too-high/</link>
		<comments>http://adventuresinsecurity.com/blog/2007/02/16/transfer-risk-when-mitigation-costs-are-too-high/#comments</comments>
		<pubDate>Fri, 16 Feb 2007 15:15:19 +0000</pubDate>
		<dc:creator>Tom Olzak</dc:creator>
				<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Security Management Tips]]></category>

		<guid isPermaLink="false">http://adventuresinsecurity.com/blog/?p=112</guid>
		<description><![CDATA[According to security best practices, there are four things you can do when risk to an information asset is identified and business impact assessed.  You can reject/ignore the risk.  This is not a smart move in most cases.  You can mitigate the risk to an acceptable level.  You can accept the risk.  And finally, you [...]]]></description>
			<content:encoded><![CDATA[<p>According to security best practices, there are four things you can do when risk to an information asset is identified and business impact assessed.  You can reject/ignore the risk.  This is not a smart move in most cases.  You can mitigate the risk to an acceptable level.  You can accept the risk.  And finally, you can transfer the risk.  Transferring risk usually takes the form of purchasing insurance to soften the impact of a security incident.  It&#8217;s occasionally less expensive to purchase insurance than it is to implement controls to significantly reduce risk.</p>
<p>In <a href="http://www.darkreading.com/document.asp?doc_id=117536&#038;f_src=darkreading_node_1946" target="_blank">a February 15 Dark Reading article</a>, Tim Wilson looks at the benefits and opportunities for security breach protection through the purchase of insurance.</p>
]]></content:encoded>
			<wfw:commentRss>http://adventuresinsecurity.com/blog/2007/02/16/transfer-risk-when-mitigation-costs-are-too-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lock it down: Use the revised OWASP Top Ten to secure your Web applications &#8212; Part 1</title>
		<link>http://adventuresinsecurity.com/blog/2007/02/15/lock-it-down-use-the-revised-owasp-top-ten-to-secure-your-web-applications-part-1/</link>
		<comments>http://adventuresinsecurity.com/blog/2007/02/15/lock-it-down-use-the-revised-owasp-top-ten-to-secure-your-web-applications-part-1/#comments</comments>
		<pubDate>Thu, 15 Feb 2007 20:06:21 +0000</pubDate>
		<dc:creator>Tom Olzak</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[OWASP Top Ten]]></category>
		<category><![CDATA[Security Management Tips]]></category>

		<guid isPermaLink="false">http://adventuresinsecurity.com/blog/?p=111</guid>
		<description><![CDATA[For the first time since 2004, the Open Web Application Security Project (OWASP) is updating its Top 10 Vulnerabilities list. As a supplement to an previously published article on the 2004 OWASP Top 10, this is the second in a series of articles in which I explore the 10 vulnerabilities the OWASP believes present the [...]]]></description>
			<content:encoded><![CDATA[<p>For the first time since 2004, the Open Web Application Security Project (OWASP) is updating its Top 10 Vulnerabilities list. As a supplement to an previously published article on the 2004 OWASP Top 10, <a href="http://articles.techrepublic.com.com/5100-1009_11-6159742.html" target="_blank">this is the second in a series of articles</a> in which I explore the 10 vulnerabilities the OWASP believes present the highest risk to Web application environments.</p>
]]></content:encoded>
			<wfw:commentRss>http://adventuresinsecurity.com/blog/2007/02/15/lock-it-down-use-the-revised-owasp-top-ten-to-secure-your-web-applications-part-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Personal, gratuitous post&#8230;</title>
		<link>http://adventuresinsecurity.com/blog/2007/02/15/personal-gratuitous-post/</link>
		<comments>http://adventuresinsecurity.com/blog/2007/02/15/personal-gratuitous-post/#comments</comments>
		<pubDate>Thu, 15 Feb 2007 18:49:38 +0000</pubDate>
		<dc:creator>Tom Olzak</dc:creator>
				<category><![CDATA[Security Management Tips]]></category>

		<guid isPermaLink="false">http://adventuresinsecurity.com/blog/?p=110</guid>
		<description><![CDATA[______________________________________________________
Check out my book, Just Enough Security, at Amazon.com
Additional security management resources are available at http://adventuresinsecurity.com/.
My podcasts –> http://blastpodcast.com/viewpodcast.html?id=441
Free security training –> http://adventuresinsecurity.com/SCourses
_______________________________________________________
]]></description>
			<content:encoded><![CDATA[<p>______________________________________________________</p>
<p>Check out my book, <em>Just Enough Security</em>, at <a href="http://www.amazon.com/gp/product/141167541X/qid=1151094612/sr=1-1/ref=sr_1_1/102-0044978-8250540?s=books&#038;v=glance&#038;n=283155" target="_blank">Amazon.com</a></p>
<p>Additional security management resources are available at <a href="http://adventuresinsecurity.com/" target="_blank">http://adventuresinsecurity.com/</a>.</p>
<p>My podcasts –> <a href="http://blastpodcast.com/viewpodcast.html?id=441" target="_blank">http://blastpodcast.com/viewpodcast.html?id=441</a></p>
<p>Free security training –> <a href="http://adventuresinsecurity.com/SCourses" target="_blank">http://adventuresinsecurity.com/SCourses</a><br />
_______________________________________________________</p>
]]></content:encoded>
			<wfw:commentRss>http://adventuresinsecurity.com/blog/2007/02/15/personal-gratuitous-post/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Soft versus hard security</title>
		<link>http://adventuresinsecurity.com/blog/2007/02/15/soft-versus-hard-security/</link>
		<comments>http://adventuresinsecurity.com/blog/2007/02/15/soft-versus-hard-security/#comments</comments>
		<pubDate>Thu, 15 Feb 2007 18:44:19 +0000</pubDate>
		<dc:creator>Tom Olzak</dc:creator>
				<category><![CDATA[Security Management Tips]]></category>

		<guid isPermaLink="false">http://adventuresinsecurity.com/blog/?p=109</guid>
		<description><![CDATA[In this Geekzone article, Darryl Burling ponders the value of putting risk management on the user.  I don&#8217;t know about you, but relying on users to protect data, even their own, is typically a losing proposition.  Read the artcle and you decide.
 
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.geekzone.co.nz/content.asp?ContentId=7036" target="_blank">In this Geekzone article</a>, Darryl Burling ponders the value of putting risk management on the user.  I don&#8217;t know about you, but relying on users to protect data, even their own, is typically a losing proposition.  Read the artcle and you decide.</p>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://adventuresinsecurity.com/blog/2007/02/15/soft-versus-hard-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
