<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Dr Anton Chuvakin Blog PERSONAL Blog</title><link>http://chuvakin.blogspot.com/</link><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/AntonChuvakinPersonalBlog" /><description>This is my PERSONAL blog, as as of August 1, 2011, it focuses on personal matters and various things I find to be fun.</description><language>en</language><managingEditor>noreply@blogger.com (Anton Chuvakin)</managingEditor><lastBuildDate>Wed, 01 May 2013 07:07:00 PDT</lastBuildDate><generator>Blogger http://www.blogger.com</generator><openSearch:totalResults xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">1622</openSearch:totalResults><openSearch:startIndex xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">1</openSearch:startIndex><openSearch:itemsPerPage xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">25</openSearch:itemsPerPage><feedburner:info uri="antonchuvakinpersonalblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><media:copyright>(C) Anton Chuvakin and Andrew Hay</media:copyright><media:thumbnail url="http://www.chuvakin.org/images/lovelogs.jpg" /><media:keywords>logs,log,management,log,analysis,SIEM,SEM,SIM,security,information,security,infosec</media:keywords><media:category scheme="http://www.itunes.com/dtds/podcast-1.0.dtd">Technology</media:category><itunes:owner><itunes:email>anton@chuvakin.org</itunes:email><itunes:name>Anton Chuvakin</itunes:name></itunes:owner><itunes:author>Anton Chuvakin</itunes:author><itunes:explicit>no</itunes:explicit><itunes:image href="http://www.chuvakin.org/images/lovelogs.jpg" /><itunes:keywords>logs,log,management,log,analysis,SIEM,SEM,SIM,security,information,security,infosec</itunes:keywords><itunes:subtitle>LogChat: Andrew Hay and Anton Chuvakin talk about logging, log management and related topics</itunes:subtitle><itunes:summary>LogChat: Andrew Hay and Anton Chuvakin talk about system logging, log management, SIEM and related topics</itunes:summary><itunes:category text="Technology" /><feedburner:emailServiceId>AntonChuvakinPersonalBlog</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item><title>Monthly Blog Round-Up – April 2013</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/A1sS66WAk2Q/monthly-blog-round-up-april-2013.html</link><category>blogging</category><category>security</category><category>Monthly</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Wed, 01 May 2013 07:07:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-5311582652999508743</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
Here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;/div&gt;
&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;ol&gt;
&lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top of this list – the checklist is still a very useful tool for many people. “&lt;a href="http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html"&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a href="http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html"&gt;updated version&lt;/a&gt;) &lt;/li&gt;
&lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011. &lt;/li&gt;
&lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” is another old classic (from 2010) that often shows up on my top list; it covers some tips on choosing SIEM tools.  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/11/siem-bloggables.html"&gt;“SIEM Bloggables”&lt;/a&gt; covers a few high-level SIEM use cases and my view (at the time) of key SIEM functions. &lt;/li&gt;
&lt;li&gt;My classic &lt;a href="http://chuvakin.blogspot.com/2012/07/chuvakin.blogspot.com/search/label/PCI_Log_Review"&gt;PCI DSS Log Review series&lt;/a&gt; is popular as well. The outlined log review approach is useful for building other types of log review processes and procedures, whether regulatory or not.&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
In addition, I’d like to draw your attention to a few recent posts from &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;my Gartner blog&lt;/a&gt;: &lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Current network forensics research:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/03/08/on-futility-of-dead-packet-storage/"&gt;On Futility of Dead Packet Storage&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/02/15/processes-for-network-forensics/"&gt;Processes for Network Forensics&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/02/05/use-cases-for-network-forensics-tools/"&gt;Use Cases for Network Forensics Tools&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/01/29/network-forensics-defined/"&gt;Network Forensics Defined?&lt;/a&gt; &lt;/li&gt;
&lt;/ul&gt;
&lt;strong&gt;Current security data sharing research:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/04/04/from-ips-to-ttps/"&gt;From IPs to TTPs&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/03/22/consumption-of-shared-security-data/"&gt;Consumption of Shared Security Data&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/02/20/on-trust-in-security-data-sharing/"&gt;On Trust in Security Data Sharing&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/02/10/on-security-data-sharing-research/"&gt;On Security Data Sharing Research&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/05/09/on-security-data-sharing/"&gt;On Security Data Sharing&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/05/29/more-on-dos-and-shared-security/"&gt;More on DoS and Shared Security&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;strong&gt;Miscellaneous fun posts:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/04/10/my-coverage-areas-reminder/"&gt;My Coverage Areas Reminder&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/04/12/bye-bye-compliance-thinking-welcome-military-thinking/"&gt;Bye-bye, Compliance Thinking. Welcome, Military Thinking!&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/04/15/9-reasons-why-building-a-big-data-security-analytics-tool-is-like-building-a-flying-car/"&gt;9 Reasons Why Building A Big Data Security Analytics Tool Is Like Building a Flying Car&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/04/17/on-being-an-analyst-or-who-are-we-hiring/"&gt;On Being An Analyst or WHO Are We Hiring?&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/04/29/verizon-dbir-2013-highlights-and-favorites/"&gt;Verizon DBIR 2013 Highlights and Favorites&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
(see my published Gartner research &lt;a href="http://www.gartner.com/AnalystBiography?authorId=40636"&gt;here&lt;/a&gt;)&lt;br /&gt;
Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual&lt;/a&gt; “Top Popular Blog Posts” – &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html"&gt;2011&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2013/01/annual-blog-round-up-2012.html"&gt;2012&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all content at &lt;a href="http://www.securitywarrior.org/"&gt;SecurityWarrior blog&lt;/a&gt; was written before I &lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;strong&gt;Previous post in this endless series:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2013/04/monthly-blog-round-up-march-2013.html"&gt;Monthly Blog Round-Up – March 2013&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;All posts tagged &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=A1sS66WAk2Q:ZVcIFLzNyQc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=A1sS66WAk2Q:ZVcIFLzNyQc:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=A1sS66WAk2Q:ZVcIFLzNyQc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/A1sS66WAk2Q" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-05-01T07:07:00.166-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2013/05/monthly-blog-round-up-april-2013.html</feedburner:origLink></item><item><title>Monthly Blog Round-Up – March 2013</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/AZre3KKYIYc/monthly-blog-round-up-march-2013.html</link><category>blogging</category><category>security</category><category>Monthly</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Mon, 01 Apr 2013 09:35:45 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-7278940753117566192</guid><description>&lt;div style="text-align: left" dir="ltr" trbidi="on"&gt;Here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt;&lt;/div&gt; &lt;div style="text-align: left" dir="ltr" trbidi="on"&gt; &lt;ol&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top of this list – the checklist is still a very useful tool for many people. “&lt;a href="http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html"&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a href="http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html"&gt;updated version&lt;/a&gt;, and, yes, I know it really needs another update)  &lt;li&gt;My classic &lt;a href="http://chuvakin.blogspot.com/2012/07/chuvakin.blogspot.com/search/label/PCI_Log_Review"&gt;PCI DSS Log Review series&lt;/a&gt; is popular as well. The outlined log review approach is useful for building other types of log review processes and procedures, whether regulatory or not.  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011.  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” is another old classic (from 2010) that often shows up on my top list; it covers some tips on choosing SIEM tools.  &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/11/siem-bloggables.html"&gt;“SIEM Bloggables”&lt;/a&gt; covers a few high-level SIEM use cases and my view (at the time) of key SIEM functions.&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt; &lt;p&gt;In addition, I’d like to draw your attention to a few recent posts from &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;my Gartner blog&lt;/a&gt;: &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Current network forensics research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/03/08/on-futility-of-dead-packet-storage/"&gt;On Futility of Dead Packet Storage&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/02/15/processes-for-network-forensics/"&gt;Processes for Network Forensics&lt;/a&gt; &lt;/li&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/02/05/use-cases-for-network-forensics-tools/"&gt;Use Cases for Network Forensics Tools&lt;/a&gt; &lt;/li&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/01/29/network-forensics-defined/"&gt;Network Forensics Defined?&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Current security data sharing research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/03/22/consumption-of-shared-security-data/"&gt;Consumption of Shared Security Data&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/02/20/on-trust-in-security-data-sharing/"&gt;On Trust in Security Data Sharing&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/02/10/on-security-data-sharing-research/"&gt;On Security Data Sharing Research&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/05/09/on-security-data-sharing/"&gt;On Security Data Sharing&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/12/11/our-log-standards-paper-publishes/"&gt;Our Log Standards Paper Publishes&lt;/a&gt; (mentions select data sharing standards)  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/05/29/more-on-dos-and-shared-security/"&gt;More on DoS and Shared Security&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Miscellaneous fun posts:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/03/04/a-quiet-assumption/"&gt;A Quiet Assumption&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/03/27/too-late-to-fight-cyber/"&gt;Too Late to Fight “Cyber”&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual&lt;/a&gt; “Top Popular Blog Posts” – &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html"&gt;2011&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2013/01/annual-blog-round-up-2012.html"&gt;2012&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all content at &lt;a href="http://www.securitywarrior.org"&gt;SecurityWarrior blog&lt;/a&gt; was written before I &lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Previous post in this endless series:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2013/03/monthly-blog-round-up-february-2013.html"&gt;Monthly Blog Round-Up – February 2013&lt;/a&gt; &lt;li&gt;All posts tagged &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=AZre3KKYIYc:6Vw2cT-ge54:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=AZre3KKYIYc:6Vw2cT-ge54:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=AZre3KKYIYc:6Vw2cT-ge54:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/AZre3KKYIYc" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-01T09:35:45.449-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2013/04/monthly-blog-round-up-march-2013.html</feedburner:origLink></item><item><title>Monthly Blog Round-Up – February 2013</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/Ovsz_vfUeEU/monthly-blog-round-up-february-2013.html</link><category>blogging</category><category>security</category><category>Monthly</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Mon, 04 Mar 2013 07:21:50 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-8908816474937082251</guid><description>&lt;div style="text-align: left" dir="ltr" trbidi="on"&gt;Here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt;&lt;/div&gt; &lt;div style="text-align: left" dir="ltr" trbidi="on"&gt; &lt;ol&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top of this list – the checklist is still a very useful tool for many people. “&lt;a href="http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html"&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a href="http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html"&gt;updated version&lt;/a&gt;, and, yes, I know it really needs another update)  &lt;li&gt;My classic &lt;a href="http://chuvakin.blogspot.com/2012/07/chuvakin.blogspot.com/search/label/PCI_Log_Review"&gt;PCI DSS Log Review series&lt;/a&gt; is popular as well. The outlined log review approach is useful for building other types of log review processes and procedures, whether regulatory or not.  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011.  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” is another old classic (from 2010) that shows up on my top list; it covers some tips on&amp;nbsp; choosing SIEM tools.  &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/11/siem-bloggables.html"&gt;“SIEM Bloggables”&lt;/a&gt; covers a few high-level SIEM use cases and my view (at the time) of key SIEM functions.&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt; &lt;p&gt;In addition, I’d like to draw your attention to a few recent posts from &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;my Gartner blog&lt;/a&gt;: &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Current network forensics research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt; &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/02/15/processes-for-network-forensics/"&gt;Processes for Network Forensics&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/02/05/use-cases-for-network-forensics-tools/"&gt;Use Cases for Network Forensics Tools&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/01/29/network-forensics-defined/"&gt;Network Forensics Defined?&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Current security data sharing research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/02/20/on-trust-in-security-data-sharing/"&gt;On Trust in Security Data Sharing&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/02/10/on-security-data-sharing-research/"&gt;On Security Data Sharing Research&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/05/09/on-security-data-sharing/"&gt;On Security Data Sharing&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/12/11/our-log-standards-paper-publishes/"&gt;Our Log Standards Paper Publishes&lt;/a&gt; (mentions select data sharing standards)  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/05/29/more-on-dos-and-shared-security/"&gt;More on DoS and Shared Security&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Previous DLP research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/01/04/dlp-education-andor-automation/"&gt;DLP: Education and/or Automation?&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/12/31/more-on-internal-data-loss-incidents/"&gt;More On Internal Data Loss Incidents&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/12/27/on-internally-lost-data-and-dlp-discovery/"&gt;On “Internally Lost Data” and DLP Discovery&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/12/17/on-risks-of-dlp/"&gt;On Risks of DLP&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/12/12/dlp-and-data-classification/"&gt;DLP and Data Classification&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/12/07/dlp-discover-first-or-monitor-first/"&gt;DLP: Discover First or Monitor First?&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/11/30/on-dlp-and-pci-dss/"&gt;On DLP and PCI DSS&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/11/09/on-dlp-and-ip-theft/"&gt;On DLP and IP Theft&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/11/01/dlp-andorforvs-data-security/"&gt;DLP and/or/for/vs Data Security&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/10/25/on-dlp-processes-or-no-dlp-for-dummies/"&gt;On DLP Processes or “No DLP For Dummies”&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/10/19/on-dlp-research/"&gt;On DLP Research&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual&lt;/a&gt; “Top Popular Blog Posts” – &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html"&gt;2011&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2013/01/annual-blog-round-up-2012.html"&gt;2012&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all content at &lt;a href="http://www.securitywarrior.org"&gt;SecurityWarrior blog&lt;/a&gt; was written before I &lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Previous post in this endless series:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2013/02/monthly-blog-round-up-january-2013.html"&gt;Monthly Blog Round-Up – January 2013&lt;/a&gt;  &lt;li&gt;All posts tagged &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=Ovsz_vfUeEU:aBJ5-YKNOVs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=Ovsz_vfUeEU:aBJ5-YKNOVs:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=Ovsz_vfUeEU:aBJ5-YKNOVs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/Ovsz_vfUeEU" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-04T07:21:50.144-08:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2013/03/monthly-blog-round-up-february-2013.html</feedburner:origLink></item><item><title>Monthly Blog Round-Up – January 2013</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/0WmRiHZvVts/monthly-blog-round-up-january-2013.html</link><category>Monthly</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Fri, 01 Feb 2013 08:47:05 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-7529956352160494976</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
Here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;/div&gt;
&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;ol&gt;
&lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top of this list – the checklist is still a very useful tool for many people. “&lt;a href="http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html"&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a href="http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html"&gt;updated version&lt;/a&gt;, and, yes, I know it really needs another update)  &lt;/li&gt;
&lt;li&gt;My classic &lt;a href="http://chuvakin.blogspot.com/search/label/PCI_Log_Review"&gt;PCI DSS Log Review&lt;/a&gt; series is popular as well. The outlined log review approach is useful for building other types of log review processes and procedures, whether regulatory or not.  &lt;/li&gt;
&lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” is another old classic (from 2010) that shows up on my top list; it covers some tips on&amp;nbsp; choosing SIEM tools.  &lt;/li&gt;
&lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011.  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/11/siem-bloggables.html"&gt;“SIEM Bloggables”&lt;/a&gt; covers a few high-level SIEM use cases and my view (at the time) of key SIEM functions.&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
In addition, I’d like to draw your attention to a few posts from &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;my Gartner blog&lt;/a&gt;: &lt;br /&gt;
&lt;strong&gt;Current network forensics research:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/01/29/network-forensics-defined/"&gt;Network Forensics Defined?&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;strong&gt;Previous SIEM research:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/01/07/my-siem-papers-are-out/"&gt;My SIEM Papers Are Out&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;strong&gt;Previous DLP research:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2013/01/04/dlp-education-andor-automation/"&gt;DLP: Education and/or Automation?&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/12/31/more-on-internal-data-loss-incidents/"&gt;More On Internal Data Loss Incidents&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/12/27/on-internally-lost-data-and-dlp-discovery/"&gt;On “Internally Lost Data” and DLP Discovery&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/12/17/on-risks-of-dlp/"&gt;On Risks of DLP&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/12/12/dlp-and-data-classification/"&gt;DLP and Data Classification&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/12/07/dlp-discover-first-or-monitor-first/"&gt;DLP: Discover First or Monitor First?&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/11/30/on-dlp-and-pci-dss/"&gt;On DLP and PCI DSS&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/11/09/on-dlp-and-ip-theft/"&gt;On DLP and IP Theft&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/11/01/dlp-andorforvs-data-security/"&gt;DLP and/or/for/vs Data Security&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/10/25/on-dlp-processes-or-no-dlp-for-dummies/"&gt;On DLP Processes or “No DLP For Dummies”&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/10/19/on-dlp-research/"&gt;On DLP Research&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual&lt;/a&gt; “Top Popular Blog Posts” – &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html"&gt;2011&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2013/01/annual-blog-round-up-2012.html"&gt;2012&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all content at &lt;a href="http://www.securitywarrior.org/"&gt;SecurityWarrior blog&lt;/a&gt; was written before I &lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;strong&gt;Previous post in this endless series:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2013/01/monthly-blog-round-up-december-2012.html"&gt;Monthly Blog Round-Up – December 2012&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;All posts tagged &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=0WmRiHZvVts:Y-bJ0hYtb0U:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=0WmRiHZvVts:Y-bJ0hYtb0U:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=0WmRiHZvVts:Y-bJ0hYtb0U:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/0WmRiHZvVts" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-02-01T08:47:05.518-08:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2013/02/monthly-blog-round-up-january-2013.html</feedburner:origLink></item><item><title>Annual Blog Round-Up – 2012</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/IPG4Y6MOKxU/annual-blog-round-up-2012.html</link><category>2012</category><category>Annual</category><category>blogging</category><category>security</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Fri, 01 Feb 2013 08:47:31 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-5961219046491024254</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
Here is my &lt;strong&gt;annual &lt;a href="http://chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 10 popular posts/topics in 2012.  &lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” was again the most popular this year. The checklist, a list of critical things to look for while reviewing&amp;nbsp; system, network and security logs when responding to a security incident  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/search/label/PCI_Log_Review"&gt;PCI DSS Log Review&lt;/a&gt; series of posts take the #2 spot; they are about planning and executing PCI DSS-driven log review at an organization  &lt;/li&gt;
&lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” is about &lt;em&gt;the least wrong way&lt;/em&gt; of choosing a SIEM tool – as well as why the right way is so unpopular.  &lt;/li&gt;
&lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html"&gt;On Free Log Management Tools&lt;/a&gt;” is another &lt;em&gt;perma-popular&lt;/em&gt; post, presenting a companion resource to the log checklist above  &lt;/li&gt;
&lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” is an &lt;em&gt;EXAMPLE&lt;/em&gt; criteria list for choosing a SIEM.  &lt;/li&gt;
&lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/log-management-at-0-and-1hrweek.html"&gt;Log Management at $0 and 1hr/week?&lt;/a&gt;” is pretty much what it is. How to do log management under extreme budget AND time constraints?  &lt;/li&gt;
&lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/08/updated-with-community-feedback-sans_06.html"&gt;Updated With Community Feedback SANS Top 7 Essential Log Reports&lt;/a&gt;” and an older “&lt;a href="http://chuvakin.blogspot.com/2010/07/sans-top-5-essential-log-reports-update.html"&gt;SANS Top 5 Essential Log Reports Update!&lt;/a&gt;” &lt;/li&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/11/siem-bloggables.html"&gt;“SIEM Bloggables”&lt;/a&gt; has one possible view on higher-level SIEM use cases and basic functionality, and a quick discussion of SIEM user types. &lt;/li&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2010/06/how-do-i-get-best-siem.html"&gt;“How Do I Get The Best SIEM?”&lt;/a&gt; is a discussion (circa 2010) about approaches to choosing SIEM tools and matching functionality to requirements. &lt;/li&gt;
&lt;li&gt;2009 post called “&lt;a href="http://chuvakin.blogspot.com/2009/12/log-management-siem.html"&gt;Log Management + SIEM = ?&lt;/a&gt;” gives some quick architecture advice on combining SIEM and log management &lt;/li&gt;
&lt;/ol&gt;
&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content was written before I &lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;here&lt;/a&gt;. &lt;br /&gt;
Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual&lt;/a&gt; “Top Posts” – &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html"&gt;2011&lt;/a&gt;.&lt;br /&gt;
  &lt;br /&gt;
&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=IPG4Y6MOKxU:JRkmOfAVsYM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=IPG4Y6MOKxU:JRkmOfAVsYM:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=IPG4Y6MOKxU:JRkmOfAVsYM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/IPG4Y6MOKxU" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-02-01T08:47:31.676-08:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2013/01/annual-blog-round-up-2012.html</feedburner:origLink></item><item><title>Monthly Blog Round-Up – December 2012</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/gSoJ8j5eFww/monthly-blog-round-up-december-2012.html</link><category>Monthly</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Fri, 01 Feb 2013 08:47:54 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-6302121057368583120</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
Here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;/div&gt;
&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;ol&gt;
&lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top of this list – the checklist is still a very useful tool for many people. “&lt;a href="http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html"&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a href="http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html"&gt;updated version&lt;/a&gt;, and, yes, I know it really needs another update)  &lt;/li&gt;
&lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011.  &lt;/li&gt;
&lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” is another old classic (from 2010) that shows up on my top list; it covers some tips on&amp;nbsp; choosing SIEM tools.  &lt;/li&gt;
&lt;li&gt;My classic &lt;a href="http://chuvakin.blogspot.com/search/label/PCI_Log_Review"&gt;PCI DSS Log Review&lt;/a&gt; series is popular as well. The approach is useful for building other types of log review processes and procedures, whether regulatory or not.  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2009/11/siem-bloggables.html"&gt;“SIEM Bloggables”&lt;/a&gt; covers a few high-level SIEM use cases and my view (at the time) of key SIEM functions.&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
In addition, I’d like to draw your attention to a few posts from &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;my Gartner blog&lt;/a&gt;: &lt;br /&gt;
&lt;strong&gt;Current DLP research:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/12/27/on-internally-lost-data-and-dlp-discovery/"&gt;On “Internally Lost Data” and DLP Discovery&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/12/17/on-risks-of-dlp/"&gt;On Risks of DLP&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/12/12/dlp-and-data-classification/"&gt;DLP and Data Classification&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/12/07/dlp-discover-first-or-monitor-first/"&gt;DLP: Discover First or Monitor First?&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/11/30/on-dlp-and-pci-dss/"&gt;On DLP and PCI DSS&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/11/09/on-dlp-and-ip-theft/"&gt;On DLP and IP Theft&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/11/01/dlp-andorforvs-data-security/"&gt;DLP and/or/for/vs Data Security&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/10/25/on-dlp-processes-or-no-dlp-for-dummies/"&gt;On DLP Processes or “No DLP For Dummies”&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/10/19/on-dlp-research/"&gt;On DLP Research&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual&lt;/a&gt; “Top Posts” – &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html"&gt;2011&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all content at &lt;a href="http://www.securitywarrior.org/"&gt;SecurityWarrior blog&lt;/a&gt; was written before I &lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;strong&gt;Previous post in this endless series:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2012/12/monthly-blog-round-up-november-2012.html"&gt;Monthly Blog Round-Up – November 2012&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;All posts tagged &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=gSoJ8j5eFww:wY4-lfqPRmQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=gSoJ8j5eFww:wY4-lfqPRmQ:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=gSoJ8j5eFww:wY4-lfqPRmQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/gSoJ8j5eFww" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-02-01T08:47:54.079-08:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2013/01/monthly-blog-round-up-december-2012.html</feedburner:origLink></item><item><title>Links for 2013-01-10 [del.icio.us]</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/OfNLHW6LoYc/anton18</link><pubDate>Fri, 11 Jan 2013 00:00:00 PST</pubDate><guid isPermaLink="false">http://del.icio.us/anton18#2013-01-10</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.nbcnews.com/technology/technolog/year-didnt-happen-2012s-incorrect-security-predictions-1B7821218"&gt;The year that didn't happen: 2012's incorrect security predictions - Technology on NBCNews.com&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://communities.intel.com/community/openportit/blog/2013/01/03/top-10-security-predictions-for-2013-and-beyond"&gt;Top 10 Security Predictions for 2013 and Beyond&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.netspi.com/blog/2012/12/12/2013-cyber-threat-forecast-released/"&gt;2013 Cyber Threat Forecast Released | NetSPI Blog&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.veracode.com/blog/2012/12/2013-prediction-its-a-mad-mad-mobile-world/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+SourceConference+%28SOURCE+Conference%29"&gt;2013 Prediction &amp;ndash; It&amp;rsquo;s a Mad, Mad, Mobile World&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/OfNLHW6LoYc" height="1" width="1"/&gt;</description><feedburner:origLink>http://del.icio.us/anton18#2013-01-10</feedburner:origLink></item><item><title>Links for 2013-01-07 [del.icio.us]</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/KK0f15KGe1U/anton18</link><pubDate>Tue, 08 Jan 2013 00:00:00 PST</pubDate><guid isPermaLink="false">http://del.icio.us/anton18#2013-01-07</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://instituteforadvancedsecurity.com/ias-blogs/community-blogs/b/institute_for_advanced_security/archive/2012/12/17/predictions-for-a-secure-planet.aspx"&gt;Predictions for a Secure Planet - Institute for Advanced Security - Expert Blogs - IBM Institute for Advanced Security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.securityweek.com/now-world-didnt-end-whats-next-it-security-2013"&gt;Now That The World Didn't End, What's Next for IT Security in 2013? | SecurityWeek.Com&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/KK0f15KGe1U" height="1" width="1"/&gt;</description><feedburner:origLink>http://del.icio.us/anton18#2013-01-07</feedburner:origLink></item><item><title>Links for 2013-01-06 [del.icio.us]</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/oEbO3ZJQLqQ/anton18</link><pubDate>Mon, 07 Jan 2013 00:00:00 PST</pubDate><guid isPermaLink="false">http://del.icio.us/anton18#2013-01-06</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.veracode.com/blog/2012/12/2013-prediction-its-a-mad-mad-mobile-world/"&gt;2013 Prediction &amp;ndash; It&amp;rsquo;s a Mad, Mad, Mobile World&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/oEbO3ZJQLqQ" height="1" width="1"/&gt;</description><feedburner:origLink>http://del.icio.us/anton18#2013-01-06</feedburner:origLink></item><item><title>Links for 2013-01-03 [del.icio.us]</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/ruE_jFvw14s/anton18</link><pubDate>Fri, 04 Jan 2013 00:00:00 PST</pubDate><guid isPermaLink="false">http://del.icio.us/anton18#2013-01-03</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blog.opengroup.org/2013/01/02/2013-open-group-predictions-vol-1/"&gt;2013 Open Group Predictions, Vol. 1 | The Open Group Blog&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/ruE_jFvw14s" height="1" width="1"/&gt;</description><feedburner:origLink>http://del.icio.us/anton18#2013-01-03</feedburner:origLink></item><item><title>Links for 2012-12-27 [del.icio.us]</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/n4n7h_T3ZK0/anton18</link><pubDate>Fri, 28 Dec 2012 00:00:00 PST</pubDate><guid isPermaLink="false">http://del.icio.us/anton18#2012-12-27</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://hackmageddon.com/2012/12/26/browsing-security-predictions-for-2013/"&gt;Browsing Security Predictions for 2013 &amp;laquo; Hackmageddon.com&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/n4n7h_T3ZK0" height="1" width="1"/&gt;</description><feedburner:origLink>http://del.icio.us/anton18#2012-12-27</feedburner:origLink></item><item><title>Links for 2012-12-26 [del.icio.us]</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/7TxkrSCxtlM/anton18</link><pubDate>Thu, 27 Dec 2012 00:00:00 PST</pubDate><guid isPermaLink="false">http://del.icio.us/anton18#2012-12-26</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.computerweekly.com/blogs/david_lacey/2012/12/predictions_for_2013.html"&gt;Predictions for 2013 - David Lacey's IT Security Blog&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://blog.lookout.com/blog/2012/12/13/2013-mobile-threat-predictions/"&gt;2013 Mobile Threat Predictions | The Official Lookout Blog&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/7TxkrSCxtlM" height="1" width="1"/&gt;</description><feedburner:origLink>http://del.icio.us/anton18#2012-12-26</feedburner:origLink></item><item><title>Links for 2012-12-22 [del.icio.us]</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/tv7pehPN-jg/anton18</link><pubDate>Sun, 23 Dec 2012 00:00:00 PST</pubDate><guid isPermaLink="false">http://del.icio.us/anton18#2012-12-22</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.sans.edu/research/security-laboratory/article/2140"&gt;Security Predictions 2013-2014: Emerging Trends in IT and Security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.symantec.com/connect/blogs/top-5-security-predictions-2013-symantec-0"&gt;Top 5 Security Predictions for 2013 from Symantec | Symantec Connect Community&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://community.spiceworks.com/topic/283695-2013-security-predictions"&gt;2013 Security Predictions - Spiceworks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.csoonline.com/security-leadership/2447/infosec-predictions-2013-shoot-me-please"&gt;Infosec predictions for 2013? Shoot me, please | CSO Blogs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://vmblog.com/archive/2012/11/13/bromium-security-predictions-2013-malware-cross-pollination-and-next-generation-virtualization.aspx"&gt;Bromium: Security Predictions 2013 - Malware Cross-Pollination and Next-Generation Virtualization : VMblog.com - Virtualization Technology News and Information for Everyone&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.technet.com/b/security/archive/2012/12/13/using-the-past-to-predict-the-future-top-5-threat-predictions-for-2013.aspx"&gt;Using the Past to Predict the Future: Top 5 Threat Predictions for 2013 - Microsoft Security Blog - Site Home - TechNet Blogs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.f-secure.com/weblog/archives/00002472.html"&gt;Seven Predictions for 2013 - F-Secure Weblog : News from the Lab&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://research.zscaler.com/2012/12/2013-security-predictions.html"&gt;Zscaler Research: 2013 Security Predictions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://news.softpedia.com/news/Top-5-Security-Predictions-for-2013-from-ISF-310455.shtml"&gt;Top 5 Security Predictions for 2013 from ISF - Softpedia&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.govinfosecurity.com/blogs/5-predictions-on-govt-infosec-in-2013-p-1396"&gt;5 Predictions on Gov't Infosec in 2013&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/tv7pehPN-jg" height="1" width="1"/&gt;</description><feedburner:origLink>http://del.icio.us/anton18#2012-12-22</feedburner:origLink></item><item><title>PCI Compliance Book Giveaway #2</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/11hUcb5lT3g/pci-compliance-book-giveaway-2.html</link><category>compliance</category><category>PCI</category><category>book</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Thu, 13 Dec 2012 16:09:40 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-8589986653861326427</guid><description>&lt;p&gt;OK folks, &lt;a href="http://www.pcicompliancebook.info"&gt;our PCI Compliance book&lt;/a&gt; has been out for a few months now, and &lt;a href="https://www.brandenwilliams.com/blog/"&gt;Branden&lt;/a&gt; &amp;amp; I thought it would be fun to give away a copy with &lt;a href="http://chuvakin.blogspot.com/2012/11/pci-compliance-book-giveaway.html"&gt;another&lt;/a&gt; contest! We have assembled a group of three independent judges who will look at the submissions and pick winners for each competition. The winner will receive a &lt;a href="http://www.pcicompliancebook.info/"&gt;free, signed copy of the book&lt;/a&gt;! In fact, it would be one of those rare “dual-signed” copies with both of our signatures (and the book will have to travel from TX to CA – or from CA to TX – for this &lt;img style="border-bottom-style: none; border-right-style: none; border-top-style: none; border-left-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://lh6.ggpht.com/-IRrZLfzdg-8/UMpuRFwTeaI/AAAAAAAAWjU/S6H6DGvDEDA/wlEmoticon-smile2.png?imgmax=800"&gt;)&lt;/p&gt; &lt;p&gt;&lt;a href="https://www.brandenwilliams.com/wp-content/uploads/2009/08/41YwOvKjZCL._SL500_AA240_.jpg"&gt;&lt;img style="display: inline; float: right; margin-left: 0px; margin-right: 0px" title="PCI Compliance" alt="" align="right" src="https://www.brandenwilliams.com/wp-content/uploads/2009/08/41YwOvKjZCL._SL500_AA240_.jpg" width="240" height="240"&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;So, on to the second contest (&lt;a href="http://chuvakin.blogspot.com/2012/11/pci-compliance-book-giveaway.html"&gt;first one&lt;/a&gt;).  &lt;p&gt;Our book attempts to draw a middle line between the black &amp;amp; white “audit” style of looking at PCI DSS and the loosey-goosey “anything goes” view. We want to take a compliance-friendly and security-friendly, practitioners line. However, sometimes even a compliance guy has to be CREATIVE!  &lt;p&gt;&lt;strong&gt;So our second challenge to you, in the comments below, please tell us about your &lt;em&gt;MOST CREATIVE PCI DSS CONTROL&lt;/em&gt; you implemented, assessed or even witnessed. &lt;/strong&gt; &lt;p&gt;&lt;strong&gt;HOWEVER, it will help your submission if such control was also ACCEPTED by a QSA. We will absolutely reject the creative control submissions that have no chance of making your environment PCI DSS compliant…&lt;/strong&gt; &lt;p&gt;You’ve got about a week (until the end of December 21st), and we will announce the winners after the holidays!  &lt;p&gt;It doesn’t matter if you comment here or on &lt;a href="https://www.brandenwilliams.com/blog/2012/11/14/pci-compliance-book-giveaway/"&gt;Branden’s blog&lt;/a&gt;, we will capture all of them.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Related posts:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2012/11/pci-compliance-book-giveaway.html"&gt;PCI Compliance Book Giveaway #1&lt;/a&gt;  &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2012/12/pci-compliance-book-giveawayresults.html"&gt;PCI Compliance Book Giveaway #1 –Results&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=11hUcb5lT3g:GbX6IxmHHGA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=11hUcb5lT3g:GbX6IxmHHGA:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=11hUcb5lT3g:GbX6IxmHHGA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/11hUcb5lT3g" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-12-13T16:09:40.991-08:00</app:edited><media:thumbnail url="http://lh6.ggpht.com/-IRrZLfzdg-8/UMpuRFwTeaI/AAAAAAAAWjU/S6H6DGvDEDA/s72-c/wlEmoticon-smile2.png?imgmax=800" height="72" width="72" /><feedburner:origLink>http://chuvakin.blogspot.com/2012/12/pci-compliance-book-giveaway-2.html</feedburner:origLink></item><item><title>PCI Compliance Book Giveaway–Results</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/zHBCqtbIPYs/pci-compliance-book-giveawayresults.html</link><category>compliance</category><category>PCI</category><category>book</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Tue, 04 Dec 2012 14:32:59 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-7784640038738267568</guid><description>&lt;p&gt;Our &lt;a href="http://chuvakin.blogspot.com/2012/11/pci-compliance-book-giveaway.html"&gt;PCI Compliance Book Giveaway&lt;/a&gt; has ended – with a bang!&amp;nbsp; The winning entry (&lt;a href="http://chuvakin.blogspot.com/2012/11/pci-compliance-book-giveaway.html"&gt;submitted here&lt;/a&gt;) is below:&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;"Hilarious in a sad way, the worst PCI fail I ever had was getting&lt;br&gt;solicited by a Wedding / Bridal catalog company to assist them in&lt;br&gt;improving their online ordering and bridal catalog subscription&lt;br&gt;service. I had no contract with them, this was just a preliminary&lt;br&gt;"Let's see what we can do for you." They sent us their website, and&lt;br&gt;also e-mailed me a copy of their site's source code.&lt;br&gt;In the source code was an SQL dump of over 7 years of brides personal&lt;br&gt;information including names, addresses, birthdays, and FULL credit&lt;br&gt;card numbers, expiration dates, CCVs, card type, phone numbers, email&lt;br&gt;addresses, and unencrypted passwords.&lt;br&gt;In shock of seeing this, I called the potential client, said we&lt;br&gt;couldn't help them and deleted the data as completely as I could.&lt;br&gt;Eek!"&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;The winner, “James P”, please mail your address to &lt;a href="mailto:authors@pcicompliancebook.info"&gt;authors@pcicompliancebook.info&lt;/a&gt; and we will mail you your signed copy of &lt;a href="http://www.pcicompliancebook.info"&gt;The PCI Book&lt;/a&gt;, 3rd edition. And, no, we won’t charge your credit card for that &lt;img style="border-bottom-style: none; border-right-style: none; border-top-style: none; border-left-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://lh5.ggpht.com/-xR3A56TARYk/UL56Gneg6NI/AAAAAAAAWeA/1d30qNvEP1A/wlEmoticon-smile%25255B2%25255D.png?imgmax=800"&gt; &lt;p&gt;The runner-up entries were: &lt;p&gt;“A very large retailer decides to reorganize their IT department to be more responsive and reactive. As part of that reorganization, they create a group titled 'Enterprise Monitoring' that is responsible for the care/feeding of the log management and analysis solutions. Centralized personnel that actually do the monitoring are pushed out to the business units where, according to IT management, the actual monitoring belongs. Everyone at the meeting announcing this decision says that the name. Enterprise Monitoring, needs to be changed because it gives the impression that the group does the monitoring, but they are over ruled.&lt;br&gt;Spin ahead almost a year later to their PCI assessment. The monitoring personnel that were pushed out to the business units were, surprise/surprise, were seen as new bodies that could be used for everything BUT monitoring. So, we have great log management and analysis solutions running, but no one has been monitoring anything for almost a year! When asked, the business units point to the Enterprise Monitoring group and say that it is their responsibility because they are 'Enterprise Monitoring'. DUH!﻿” (&lt;a href="https://plus.google.com/104051623244958334514/posts/g2rfKAXwU7Q"&gt;source&lt;/a&gt;) &lt;p&gt;and &lt;p&gt;“I work with a stadium and arena concessions operation that once told me they were compliant because they put their card swipe readers on the counter and turned them around to face the customer. They no longer touched the cards so this made them compliant. True story.” (&lt;a href="https://www.brandenwilliams.com/blog/2012/11/14/pci-compliance-book-giveaway/"&gt;source&lt;/a&gt;) &lt;p&gt;and &lt;p&gt;“It’s a not a fail, but I certainly found humor in this. When enrolling in training with the PCI Security Standards Council, if you would like pay by credit card they ask that you write your CC#, CVV, Expiration, etc on the invoice and fax it or mail it to them. They note, it is a secure and password protected fax. I expected something a little more from the people who create the standards, but hey that’s one way to reduce your scope. Upon receiving the invoice, it was an LOL moment. ” (&lt;a href="https://www.brandenwilliams.com/blog/2012/11/14/pci-compliance-book-giveaway/"&gt;source&lt;/a&gt;) &lt;p&gt;MORE PCI Book CONTESTS ARE COMING!! Stand by….&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=zHBCqtbIPYs:WM8rbhcB9KI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=zHBCqtbIPYs:WM8rbhcB9KI:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=zHBCqtbIPYs:WM8rbhcB9KI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/zHBCqtbIPYs" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-12-04T14:32:59.534-08:00</app:edited><media:thumbnail url="http://lh5.ggpht.com/-xR3A56TARYk/UL56Gneg6NI/AAAAAAAAWeA/1d30qNvEP1A/s72-c/wlEmoticon-smile%25255B2%25255D.png?imgmax=800" height="72" width="72" /><feedburner:origLink>http://chuvakin.blogspot.com/2012/12/pci-compliance-book-giveawayresults.html</feedburner:origLink></item><item><title>Monthly Blog Round-Up – November 2012</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/tf_MnRwfUwM/monthly-blog-round-up-november-2012.html</link><category>Monthly</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Mon, 03 Dec 2012 07:43:12 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-6747014106434522321</guid><description>&lt;div style="text-align: left" dir="ltr" trbidi="on"&gt;Here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt;&lt;/div&gt; &lt;div style="text-align: left" dir="ltr" trbidi="on"&gt; &lt;ol&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top of this list – the checklist is still a very useful tool for many people. “&lt;a href="http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html"&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a href="http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html"&gt;updated version&lt;/a&gt;, and, yes, I know it really needs another update)  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2012/11/pci-compliance-book-giveaway.html"&gt;PCI Compliance Book Giveaway!&lt;/a&gt;” announces &lt;a href="https://www.brandenwilliams.com/blog/"&gt;our&lt;/a&gt; new contest and its prize – &lt;a href="http://www.pcicompliancebook.info"&gt;The PCI Compliance book&lt;/a&gt;. We will announce the winner any day now. &lt;li&gt;My classic &lt;a href="http://chuvakin.blogspot.com/2012/07/chuvakin.blogspot.com/search/label/PCI_Log_Review"&gt;PCI DSS Log Review series&lt;/a&gt; is popular as well. The approach is useful for building other types of log review processes and procedures, whether regulatory or not. &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” is another old classic (from 2010) that shows up on my top list; it covers some tips on&amp;nbsp; choosing SIEM tools.  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011. &lt;/li&gt;&lt;/ol&gt;&lt;/div&gt; &lt;p&gt;In addition, I’d like to draw your attention to a few posts from &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;my Gartner blog&lt;/a&gt;: &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Current DLP research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/11/30/on-dlp-and-pci-dss/"&gt;On DLP and PCI DSS&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/11/09/on-dlp-and-ip-theft/"&gt;On DLP and IP Theft&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/11/01/dlp-andorforvs-data-security/"&gt;DLP and/or/for/vs Data Security&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/10/25/on-dlp-processes-or-no-dlp-for-dummies/"&gt;On DLP Processes or “No DLP For Dummies”&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/10/19/on-dlp-research/"&gt;On DLP Research&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual&lt;/a&gt; “Top Posts” – &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html"&gt;2011&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all content at &lt;a href="http://www.securitywarrior.org"&gt;SecurityWarrior blog&lt;/a&gt; was written before I &lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Previous post in this endless series:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2012/11/monthly-blog-round-up-october-2012.html"&gt;Monthly Blog Round-Up – October 2012&lt;/a&gt; &lt;li&gt;All posts tagged &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=tf_MnRwfUwM:amqbDXl5ASA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=tf_MnRwfUwM:amqbDXl5ASA:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=tf_MnRwfUwM:amqbDXl5ASA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/tf_MnRwfUwM" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-12-03T07:43:12.563-08:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2012/12/monthly-blog-round-up-november-2012.html</feedburner:origLink></item><item><title>PCI Compliance Book Giveaway!</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/SgaQUOT0nec/pci-compliance-book-giveaway.html</link><category>PCI</category><category>book</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Thu, 15 Nov 2012 15:51:35 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-4033420457311775457</guid><description>&lt;p&gt;OK folks, &lt;a href="http://www.pcicompliancebook.info"&gt;our PCI Compliance book&lt;/a&gt; has been out for a couple of months now, and Branden &amp;amp; I thought it would be fun to give a way a couple of copies with a contest! We have assembled a group of three independent judges that will take a whittled down list and pick winners for each competition. The winner will receive a &lt;a href="http://www.pcicompliancebook.info/"&gt;free, signed copy of the book&lt;/a&gt;!&lt;/p&gt; &lt;p&gt;&lt;a href="https://www.brandenwilliams.com/wp-content/uploads/2009/08/41YwOvKjZCL._SL500_AA240_.jpg"&gt;&lt;img title="PCI Compliance" alt="" src="https://www.brandenwilliams.com/wp-content/uploads/2009/08/41YwOvKjZCL._SL500_AA240_.jpg" width="240" height="240"&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;So, on to the first contest.  &lt;p&gt;Our book attempts to draw a middle line between the black &amp;amp; white “audit” style of looking at PCI DSS and the loosey-goosey anything goes view. We want to take a compliance-friendly, practitioners line. But we’ve all been in those meetings when you look at a particular defense of a control (or lack thereof) and you can’t help but laugh a little bit on the ridiculous nature of what was presented.  &lt;p&gt;&lt;strong&gt;So our first challenge to you, in the comments below, please tell us about your MOST HILARIOUS PCI FAIL. &lt;/strong&gt; &lt;p&gt;You’ve got a week (until the end of Wednesday, November 21st), and we will announce the winners after the US Thanksgiving holiday! &lt;p&gt;It doesn’t matter if you comment here or on &lt;a href="https://www.brandenwilliams.com/blog/2012/11/14/pci-compliance-book-giveaway/"&gt;Branden’s blog&lt;/a&gt;, we will capture all of them.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=SgaQUOT0nec:EyW7GW6gpYc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=SgaQUOT0nec:EyW7GW6gpYc:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=SgaQUOT0nec:EyW7GW6gpYc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/SgaQUOT0nec" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-11-15T15:51:35.638-08:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2012/11/pci-compliance-book-giveaway.html</feedburner:origLink></item><item><title>Monthly Blog Round-Up – October 2012</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/ZT_qP-R-pvM/monthly-blog-round-up-october-2012.html</link><category>Monthly</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Thu, 01 Nov 2012 10:48:20 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-6009497223280902365</guid><description>&lt;div style="text-align: left" dir="ltr" trbidi="on"&gt;Here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt;&lt;/div&gt; &lt;div style="text-align: left" dir="ltr" trbidi="on"&gt; &lt;ol&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top of this list – the checklist is still a very useful tool for many people. “&lt;a href="http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html"&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a href="http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html"&gt;updated version&lt;/a&gt;, and, yes, I know it needs another update)  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” is another old classic (from 2010) that shows up on my top list; it covers some tips on&amp;nbsp; choosing SIEM tools.  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011.  &lt;li&gt;My &lt;a href="http://chuvakin.blogspot.com/2012/07/chuvakin.blogspot.com/search/label/PCI_Log_Review"&gt;PCI DSS Log Review series&lt;/a&gt; is popular as well. It actually needs no introduction.  &lt;li&gt;SIEM use cases (however they are defined) seem to be on a lot of minds and so &lt;a href="http://chuvakin.blogspot.com/2009/11/siem-bloggables.html"&gt;“SIEM Bloggables”&lt;/a&gt; post (and &lt;a href="http://chuvakin.blogspot.com/2009/12/log-management-siem.html"&gt;this one&lt;/a&gt; too) is on my top list.&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt; &lt;p&gt;In addition, I’d like to draw your attention to a few posts from &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;my Gartner blog&lt;/a&gt;: &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Current DLP research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/11/01/dlp-andorforvs-data-security/"&gt;DLP and/or/for/vs Data Security&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/10/25/on-dlp-processes-or-no-dlp-for-dummies/"&gt;On DLP Processes or “No DLP For Dummies”&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/10/19/on-dlp-research/"&gt;On DLP Research&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Recent SIEM research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/09/24/on-output-driven-siem/"&gt;On “Output-driven” SIEM&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/09/17/on-siem-maturity-scale-and-maybe-on-cmm-too/"&gt;On SIEM Maturity Scale and Maybe On CMM Too&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/09/14/my-siem-workshop-sas-day/"&gt;My SIEM Workshop / SAS Day&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/08/24/on-siem-deployment-evolution/"&gt;On SIEM Deployment Evolution&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/08/09/on-people-running-siem/"&gt;On People Running SIEM&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/09/14/my-siem-workshop-sas-day/"&gt;My SIEM Workshop / SAS Day&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/07/30/on-siem-processespractices/"&gt;On SIEM Processes/Practices&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/07/25/on-large-scale-siem-architecture/"&gt;On Large-scale SIEM Architecture&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/07/18/some-of-the-big-siem-questions/"&gt;Some of the Big SIEM Questions&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/07/13/my-upcoming-siem-research/"&gt;My Upcoming SIEM Research&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual&lt;/a&gt; “Top Posts” – &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html"&gt;2011&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all content at &lt;a href="http://www.securitywarrior.org"&gt;SecurityWarrior blog&lt;/a&gt; was written before I &lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Previous post in this endless series:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2012/10/monthly-blog-round-up-september-2012.html"&gt;Monthly Blog Round-Up – September 2012&lt;/a&gt;  &lt;li&gt;All posts tagged &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=ZT_qP-R-pvM:YYlGBA4LWVc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=ZT_qP-R-pvM:YYlGBA4LWVc:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=ZT_qP-R-pvM:YYlGBA4LWVc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/ZT_qP-R-pvM" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-11-01T10:48:20.696-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2012/11/monthly-blog-round-up-october-2012.html</feedburner:origLink></item><item><title>Monthly Blog Round-Up – September 2012</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/cTMnDO900Mo/monthly-blog-round-up-september-2012.html</link><category>Monthly</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Mon, 01 Oct 2012 09:14:09 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-4824438890776312517</guid><description>&lt;div style="text-align: left" dir="ltr" trbidi="on"&gt;Here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt;&lt;/div&gt; &lt;div style="text-align: left" dir="ltr" trbidi="on"&gt; &lt;ol&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top of this list – the checklist is still a very useful tool for many people. “&lt;a href="http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html"&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a href="http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html"&gt;updated version&lt;/a&gt;, and, yes, I know it needs another update…)  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011.  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” is another old classic (from 2010) that shows up on my top list; it covers some tips on&amp;nbsp; choosing SIEM tools.  &lt;li&gt;My &lt;a href="http://chuvakin.blogspot.com/2012/07/chuvakin.blogspot.com/search/label/PCI_Log_Review"&gt;PCI DSS Log Review series&lt;/a&gt; is popular as well. It actually needs no introduction &lt;img style="border-bottom-style: none; border-right-style: none; border-top-style: none; border-left-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://lh3.ggpht.com/-DlqMUuKbLp4/UGnBUKP1qjI/AAAAAAAAV_I/NkAZrPhlKLk/wlEmoticon-smile%25255B2%25255D.png?imgmax=800"&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/myth-of-siem-as-analyst-in-box-or-how.html"&gt;The Myth of SIEM as “An Analyst-in-the-box” or How NOT to Pick a SIEM-II?&lt;/a&gt;” is about how some organizations want to buy a SIEM and pretend they now have security monitoring&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;In addition, I’d like to draw your attention to a few posts from &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;my Gartner blog&lt;/a&gt;:  &lt;p&gt;&lt;strong&gt;Current SIEM research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/09/24/on-output-driven-siem/"&gt;On “Output-driven” SIEM&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/09/17/on-siem-maturity-scale-and-maybe-on-cmm-too/"&gt;On SIEM Maturity Scale and Maybe On CMM Too&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/09/14/my-siem-workshop-sas-day/"&gt;My SIEM Workshop / SAS Day&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/08/24/on-siem-deployment-evolution/"&gt;On SIEM Deployment Evolution&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/08/09/on-people-running-siem/"&gt;On People Running SIEM&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/09/14/my-siem-workshop-sas-day/"&gt;My SIEM Workshop / SAS Day&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/07/30/on-siem-processespractices/"&gt;On SIEM Processes/Practices&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/07/25/on-large-scale-siem-architecture/"&gt;On Large-scale SIEM Architecture&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/07/18/some-of-the-big-siem-questions/"&gt;Some of the Big SIEM Questions&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/07/13/my-upcoming-siem-research/"&gt;My Upcoming SIEM Research&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Other fun Gartner blog posts:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/08/29/on-nebulous-security-policies/"&gt;On Nebulous Security Policies&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/06/29/how-are-we-doing-compared-to-peers/"&gt;How Are We Doing Compared To Peers?&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual&lt;/a&gt; “Top Posts” – &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html"&gt;2011&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content at SecurityWarrior blog was written before I &lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Previous post in this endless series:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2012/09/monthly-blog-round-up-august-2012.html"&gt;Monthly Blog Round-Up – August 2012&lt;/a&gt;  &lt;li&gt;All posts tagged &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=cTMnDO900Mo:VUZPpiJ1bdM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=cTMnDO900Mo:VUZPpiJ1bdM:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=cTMnDO900Mo:VUZPpiJ1bdM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/cTMnDO900Mo" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-10-01T09:14:09.214-07:00</app:edited><media:thumbnail url="http://lh3.ggpht.com/-DlqMUuKbLp4/UGnBUKP1qjI/AAAAAAAAV_I/NkAZrPhlKLk/s72-c/wlEmoticon-smile%25255B2%25255D.png?imgmax=800" height="72" width="72" /><feedburner:origLink>http://chuvakin.blogspot.com/2012/10/monthly-blog-round-up-september-2012.html</feedburner:origLink></item><item><title>Monthly Blog Round-Up – August 2012</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/bYeJLuLN4lA/monthly-blog-round-up-august-2012.html</link><category>Monthly</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Mon, 10 Sep 2012 07:46:57 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-6497991929657086093</guid><description>&lt;div style="text-align: left" dir="ltr" trbidi="on"&gt;Here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt;&lt;/div&gt; &lt;div style="text-align: left" dir="ltr" trbidi="on"&gt; &lt;ol&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top of this list – the checklist is still a very useful tool for many people. “&lt;a href="http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html"&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a href="http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html"&gt;updated version&lt;/a&gt;, and, yes, I know it needs another update…)  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011.  &lt;li&gt;My &lt;a href="http://chuvakin.blogspot.com/2012/07/chuvakin.blogspot.com/search/label/PCI_Log_Review"&gt;PCI DSS Log Review series&lt;/a&gt; is popular as well. &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” is another old classic (from 2010) that shows up on my top list. &lt;li&gt;Next is “&lt;a href="http://chuvakin.blogspot.com/2011/03/siem-resourcing-or-how-much-friggin.html"&gt;SIEM Resourcing or How Much the Friggin’ Thing Would REALLY Cost Me?&lt;/a&gt;” While reading this, also check &lt;a href="http://www.slideshare.net/anton_chuvakin/something-fun-about-using-siem-by-dr-anton-chuvakin"&gt;this presentation&lt;/a&gt;. &lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;In addition, I’d like to draw your attention to a few posts from &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;my Gartner blog&lt;/a&gt;:  &lt;p&gt;&lt;strong&gt;Current SIEM research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/08/24/on-siem-deployment-evolution/"&gt;On SIEM Deployment Evolution&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/08/09/on-people-running-siem/"&gt;On People Running SIEM&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/07/30/on-siem-processespractices/"&gt;On SIEM Processes/Practices&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/07/25/on-large-scale-siem-architecture/"&gt;On Large-scale SIEM Architecture&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/07/18/some-of-the-big-siem-questions/"&gt;Some of the Big SIEM Questions&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/07/13/my-upcoming-siem-research/"&gt;My Upcoming SIEM Research&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Other fun posts:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/08/29/on-nebulous-security-policies/"&gt;On Nebulous Security Policies&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/06/29/how-are-we-doing-compared-to-peers/"&gt;How Are We Doing Compared To Peers?&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual&lt;/a&gt; “Top Posts” – &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html"&gt;2011&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content at SecurityWarrior blog was written before I &lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Previous post in this endless series:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2012/08/monthly-blog-round-up-july-2012.html"&gt;Monthly Blog Round-Up – July 2012&lt;/a&gt; &lt;li&gt;All posts tagged &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=bYeJLuLN4lA:CeqTKtrJ2tQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=bYeJLuLN4lA:CeqTKtrJ2tQ:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=bYeJLuLN4lA:CeqTKtrJ2tQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/bYeJLuLN4lA" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-09-10T07:46:57.860-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2012/09/monthly-blog-round-up-august-2012.html</feedburner:origLink></item><item><title>One Year at Gartner!</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/norND4pTUdY/one-year-at-gartner.html</link><category>personal</category><category>jobs</category><category>career</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Thu, 02 Aug 2012 10:28:52 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-7126207522515143014</guid><description>&lt;p&gt;Believe it or not, but I've been at Gartner for a year. One whole year has passed since &lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;that infamous blog post&lt;/a&gt;. I don't feel like diving into deep reflections and long contemplations about it, but I wanted to share how it was. During this year, I …&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;strong&gt;learned a lot&lt;/strong&gt;, and expanded my security knowledge into new areas such as &lt;a href="http://blogs.gartner.com/anton-chuvakin/category/denial-of-service/"&gt;denial of service defense&lt;/a&gt;&amp;nbsp; &lt;li&gt;found out that &lt;strong&gt;being an analyst is a lot of fun&lt;/strong&gt;  &lt;li&gt;realized that there are &lt;strong&gt;many levels of writing excellence&lt;/strong&gt; beyond the level that I thought I had …  &lt;li&gt;interacted with &lt;strong&gt;a lot of smart people&lt;/strong&gt; both within and outside Gartner  &lt;li&gt;&lt;strong&gt;helped&lt;/strong&gt; dozens of our clients – both security vendors and large enterprises - with their security challenges, some simple and some pretty esoteric  &lt;li&gt;&lt;strong&gt;discovered&lt;/strong&gt; that a lot of companies are not where our industry pundits and "thought leaders" say they are (“what is more common&amp;nbsp; today at large organizations, cloud or Windows 2000?”) &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;That's about it - I am really looking forward to my second year!&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=norND4pTUdY:eJvlpvrb8bs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=norND4pTUdY:eJvlpvrb8bs:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=norND4pTUdY:eJvlpvrb8bs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/norND4pTUdY" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-08-02T10:28:52.128-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2012/08/one-year-at-gartner.html</feedburner:origLink></item><item><title>Monthly Blog Round-Up – July 2012</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/h6XD4UYmMLg/monthly-blog-round-up-july-2012.html</link><category>Monthly</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Wed, 01 Aug 2012 08:05:23 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-4728736385312907599</guid><description>&lt;div style="text-align: left" dir="ltr" trbidi="on"&gt;Here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt;&lt;/div&gt; &lt;div style="text-align: left" dir="ltr" trbidi="on"&gt; &lt;ol&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top – the checklist is still a very useful tool for many people. “&lt;a href="http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html"&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a href="http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html"&gt;updated version&lt;/a&gt;)  &lt;li&gt;Next is “&lt;a href="http://chuvakin.blogspot.com/2011/03/siem-resourcing-or-how-much-friggin.html"&gt;SIEM Resourcing or How Much the Friggin’ Thing Would REALLY Cost Me?&lt;/a&gt;” While reading this, also check &lt;a href="http://www.slideshare.net/anton_chuvakin/something-fun-about-using-siem-by-dr-anton-chuvakin"&gt;this presentation&lt;/a&gt;. &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/on-siem-services.html"&gt;On SIEM Services&lt;/a&gt;” appearance on this list reminds me that the Internet has a mind of its own as this post is closely related to what I am working on right now &lt;img style="border-bottom-style: none; border-right-style: none; border-top-style: none; border-left-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://lh4.ggpht.com/-DF2Ps8MnATc/UBlFsji89AI/AAAAAAAAVYs/JfiejerKIrE/wlEmoticon-smile%25255B2%25255D.png?imgmax=800"&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011.  &lt;li&gt;Finally, “&lt;a href="http://chuvakin.blogspot.com/2012/07/book-review-up-and-to-right-strategy.html"&gt;Book Review: “UP and to the RIGHT: Strategy and Tactics of Analyst Influence: A complete guide to analyst influence” by Richard Stiennon&lt;/a&gt;” made it to the top 5 as well.&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;In addition, I’d like to draw your attention to a few posts from &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;my Gartner blog&lt;/a&gt;:  &lt;p&gt;&lt;strong&gt;Current SIEM research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/07/30/on-siem-processespractices/"&gt;On SIEM Processes/Practices&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/07/25/on-large-scale-siem-architecture/"&gt;On Large-scale SIEM Architecture&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/07/18/some-of-the-big-siem-questions/"&gt;Some of the Big SIEM Questions&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/07/13/my-upcoming-siem-research/"&gt;My Upcoming SIEM Research&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Other fun posts:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/06/29/how-are-we-doing-compared-to-peers/"&gt;How Are We Doing Compared To Peers?&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual&lt;/a&gt; “Top Posts” – &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html"&gt;2011&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content was written before I &lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Previous post in this endless series:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2012/07/monthly-blog-round-up-june-2012.html"&gt;Monthly Blog Round-Up – June 2012&lt;/a&gt;&lt;/li&gt; &lt;li&gt;All posts tagged &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=h6XD4UYmMLg:gyUAa1e1IUA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=h6XD4UYmMLg:gyUAa1e1IUA:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=h6XD4UYmMLg:gyUAa1e1IUA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/h6XD4UYmMLg" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-08-01T08:05:23.658-07:00</app:edited><media:thumbnail url="http://lh4.ggpht.com/-DF2Ps8MnATc/UBlFsji89AI/AAAAAAAAVYs/JfiejerKIrE/s72-c/wlEmoticon-smile%25255B2%25255D.png?imgmax=800" height="72" width="72" /><feedburner:origLink>http://chuvakin.blogspot.com/2012/08/monthly-blog-round-up-july-2012.html</feedburner:origLink></item><item><title>Metricon 7 Workshop Reminder</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/XMrHuA1PLU8/metricon-7-workshop-reminder.html</link><category>conference</category><category>metrics</category><category>news</category><category>security</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Thu, 19 Jul 2012 17:20:39 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-5110081205355225635</guid><description>&lt;p&gt;Just a quick reminder about the Metricon 7 workshop on security metrics.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Date&lt;/strong&gt;: August 7, 2012&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Location&lt;/strong&gt;: Bellevue, WA (&lt;a href="https://www.usenix.org/conference/usenixsecurity12/hotel-and-travel-information"&gt;co-located with USENIX 12&lt;/a&gt;)&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Registration&lt;/strong&gt;:&lt;a href="https://www.usenix.org/conference/usenixsecurity12/registration-information"&gt;https://www.usenix.org/conference/usenixsecurity12/registration-information&lt;/a&gt;&amp;nbsp; (pick just the metrics workshop or the entire event)&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Agenda&lt;/strong&gt;:&lt;/p&gt; &lt;p&gt;1. Introduction to Metricon, security metrics and workshop goals by Anton Chuvakin (9:00-9:30) &lt;p&gt;2. “Even Giant Metrics Programs Start Small” by David Severski (9:30-10:30) &lt;p&gt;3. Break (10:30-10:45) &lt;p&gt;4. PANEL: “Rules of the Road for Useful Security Metrics” (10:45-11:30) &lt;p&gt;5. Mini-talk 1 and 2 – &lt;strong&gt;TBD&lt;/strong&gt; (11:30-12:00) &lt;p&gt;6. Lunch break (12:00-1:00)  &lt;p&gt;7. “What We Want to See in Security Metrics” by Christopher Carlson (1:00-2:00) &lt;p&gt;8. PANEL: “What We Know to Work in Security Metrics” (2:00-2:30) &lt;p&gt;9. “Application Security Metrics We Use” Steve Mckinney (2:30-3:00) &lt;p&gt;10. Break (3:00 – 3:15) &lt;p&gt;11. "Threat Genomics and Threat Modeling” by Jon Espenschied (3:15-4:15) &lt;p&gt;12. Discussion time, everybody shares lessons, highlights, etc (4:15-5:00) &lt;p&gt;13. Conclusions, results and action items by Anton Chuvakin (5:00-5:15) &lt;p&gt;&lt;strong&gt;Additional details: &lt;/strong&gt;&lt;a href="http://www.securitymetrics.org/content/Wiki.jsp?page=Metricon7.0"&gt;here&lt;/a&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;See you there!&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=XMrHuA1PLU8:OWpgYVVcK10:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=XMrHuA1PLU8:OWpgYVVcK10:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=XMrHuA1PLU8:OWpgYVVcK10:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/XMrHuA1PLU8" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-07-19T17:20:39.528-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2012/07/metricon-7-workshop-reminder.html</feedburner:origLink></item><item><title>Book Review: “UP and to the RIGHT: Strategy and Tactics of Analyst Influence: A complete guide to analyst influence” by Richard Stiennon</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/q8LAjqM9Ru8/book-review-up-and-to-right-strategy.html</link><category>book review</category><category>security</category><category>review</category><category>reading</category><category>book</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Tue, 17 Jul 2012 10:09:01 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-3366973795501676766</guid><description>&lt;p&gt;This is not a book for everybody (and your grandmother probably does not need to read it; neither does an average IT professional). However, I think that &lt;a href="http://www.amazon.com/UP-RIGHT-Strategy-Influence-influence/dp/0985460709/"&gt;this book&lt;/a&gt; is pure gold for those tasked with interacting with analyst firms.&lt;br&gt;&lt;iframe style="width: 120px; height: 240px" marginheight="0" src="http://rcm.amazon.com/e/cm?t=antonchuvakin-20&amp;amp;o=1&amp;amp;p=8&amp;amp;l=as1&amp;amp;asins=0985460709&amp;amp;ref=qf_sp_asin_til&amp;amp;fc1=000000&amp;amp;IS2=1&amp;amp;lt1=_blank&amp;amp;m=amazon&amp;amp;lc1=0000FF&amp;amp;bc1=000000&amp;amp;bg1=FFFFFF&amp;amp;f=ifr" frameborder="0" marginwidth="0" scrolling="no"&gt;&lt;/iframe&gt;&lt;br&gt;I am an analyst, and I wish every vendor client read this book and followed some of the advice given there. It would reduce pain on both sides of the conversation, as well as make the interactions more valuable for – again! - both sides.  &lt;p&gt;Obviously, this is not a book to guarantee your IT product a favorable placement in analyst research. It is also not a book on how to bamboozle the analysts, despite its focus on analyst influence. However, it is definitely a book to make sure that well deserving products, developed and marketed by good teams of people, don't get sidelined.  &lt;p&gt;Some of the specifics that I liked include the influence pyramid concept, social media techniques, a careful approach to managing corporate Wikipedia entries, specific approaches to various analyst activities (such as calls, reports, advisory days and conferences), etc. My favorite sections (both fun to read as well as insightful!) are the one on “guerrilla tactics” and the obligatory “what not to do” chapter (the latter has a few sad case studies of IT vendors who screwed themselves up). Another great chapter covers the role of a vendor sales team in both helping the interaction with the analyst firm and avoiding some embarrassing mistakes.  &lt;p&gt;In fact, this book makes me proud to be an analyst. Then again, maybe it is my ego talking as the book seems to project an impression that “an analyst is the most important person in the world“, at least as far as IT vendors are concerned. &lt;p&gt;Finally, if you are a IT vendor marketer, remember: when you say “holistic," some analysts think “imaginary.” &lt;a href="http://www.linkedin.com/in/stiennon"&gt;Richard&lt;/a&gt; suggests to scrub your presentations of silly meaningless words like “synergy” and “holistic.” &lt;ul&gt; &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/search/label/book%20review"&gt;All book reviews.&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=q8LAjqM9Ru8:ZcD_IPxrFyg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=q8LAjqM9Ru8:ZcD_IPxrFyg:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=q8LAjqM9Ru8:ZcD_IPxrFyg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/q8LAjqM9Ru8" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-07-17T10:09:01.670-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2012/07/book-review-up-and-to-right-strategy.html</feedburner:origLink></item><item><title>Monthly Blog Round-Up – June 2012</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/-6SKkQLflAk/monthly-blog-round-up-june-2012.html</link><category>Monthly</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Mon, 09 Jul 2012 15:10:25 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-432918764277939940</guid><description>&lt;div style="text-align: left" dir="ltr" trbidi="on"&gt;Here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt;&lt;/div&gt; &lt;div style="text-align: left" dir="ltr" trbidi="on"&gt; &lt;ol&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top – the checklist is still a very useful tool for many people. “&lt;a href="http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html"&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a href="http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html"&gt;updated version&lt;/a&gt;)  &lt;li&gt;My &lt;a href="chuvakin.blogspot.com/search/label/PCI_Log_Review"&gt;PCI DSS Log Review series&lt;/a&gt; is popular as well. &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” is about &lt;em&gt;the least wrong way&lt;/em&gt; of choosing a SIEM tool – as well as why the right way is so unpopular.  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm.  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/log-management-at-0-and-1hrweek.html"&gt;Log Management at $0 and 1hr/week?&lt;/a&gt;” is where a lot of companies still are, thus this post became popular again.&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;In addition, I’d like to draw your attention to a few posts from &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;my Gartner blog&lt;/a&gt;:  &lt;p&gt;&lt;strong&gt;Denial of Service research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/05/29/more-on-dos-and-shared-security/"&gt;More on DoS and Shared Security&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/05/15/on-dos-detection/"&gt;On DoS Detection&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/05/03/wanted-dead-or-alive-application-dos-attack/"&gt;Wanted Dead or Alive: Application DoS Attack&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/04/26/availability-security-and-why-is-dos-fun/"&gt;Availability, Security and Why is DoS Fun?&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/06/06/quick-dos-attack-taxonomy/"&gt;Quick DoS Attack Taxonomy&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/05/29/more-on-dos-and-shared-security/"&gt;More on DoS and Shared Security&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Other fun posts:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/06/29/how-are-we-doing-compared-to-peers/"&gt;How Are We Doing Compared To Peers?&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/06/04/on-stuxnet-revelations/"&gt;On Stuxnet Revelations&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual&lt;/a&gt; “Top Posts” – &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html"&gt;2011&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content was written before I &lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2012/06/monthly-blog-round-up-may-2012.html"&gt;Monthly Blog Round-Up – May 2012&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=-6SKkQLflAk:JiSDAcL7GNU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=-6SKkQLflAk:JiSDAcL7GNU:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=-6SKkQLflAk:JiSDAcL7GNU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/-6SKkQLflAk" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-07-09T15:10:25.748-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2012/07/monthly-blog-round-up-june-2012.html</feedburner:origLink></item><item><title>"PCI Compliance", 3rd edition - Out On August 6, 2012</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/fcmlQsy1org/pci-compliance-3rd-edition-out-on.html</link><category>compliance</category><category>news</category><category>security</category><category>PCI</category><category>book</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Tue, 12 Jun 2012 23:05:07 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-4551134351136414561</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
A new edition (3rd) of our book &lt;a href="http://www.amazon.com/PCI-Compliance-Third-Edition-Understand/dp/159749948X"&gt;"PCI Compliance&lt;/a&gt;" is coming out on August 6, 2012.&lt;br /&gt;
It covers PCI DSS 2.0, as requested by many of our readers. &amp;nbsp;Other new materials include Emerging Technology and Alternative Payment Schemes, PCI for the Small Business, etc. A full ToC for this new edition is &lt;a href="http://www.elsevier.com/wps/find/bookdescription.cws_home/727897/description#description"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Get the book in print or for Kindle!&lt;br /&gt;
&lt;br /&gt;
&lt;iframe frameborder="0" marginheight="0" marginwidth="0" scrolling="no" src="http://rcm.amazon.com/e/cm?t=antonchuvakin-20&amp;amp;o=1&amp;amp;p=8&amp;amp;l=as1&amp;amp;asins=159749948X&amp;amp;ref=qf_sp_asin_til&amp;amp;fc1=000000&amp;amp;IS2=1&amp;amp;lt1=_blank&amp;amp;m=amazon&amp;amp;lc1=0000FF&amp;amp;bc1=000000&amp;amp;bg1=FFFFFF&amp;amp;f=ifr" style="height: 240px; width: 120px;"&gt;&lt;/iframe&gt;

&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=fcmlQsy1org:HPsaLduKlyc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=fcmlQsy1org:HPsaLduKlyc:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=fcmlQsy1org:HPsaLduKlyc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/fcmlQsy1org" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-06-12T23:05:07.358-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2012/06/pci-compliance-3rd-edition-out-on.html</feedburner:origLink></item><item><title>Monthly Blog Round-Up – May 2012</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/hi3zteaqA60/monthly-blog-round-up-may-2012.html</link><category>blogging</category><category>security</category><category>Monthly</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Fri, 01 Jun 2012 08:37:24 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-8023703006117659175</guid><description>&lt;div style="text-align: left" dir="ltr" trbidi="on"&gt;Here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt;&lt;/div&gt; &lt;div style="text-align: left" dir="ltr" trbidi="on"&gt; &lt;ol&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/log-management-at-0-and-1hrweek.html"&gt;Log Management at $0 and 1hr/week?&lt;/a&gt;” is where a lot of companies still are, thus this post became popular again. &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top – the checklist is still a very useful tool for many people. “&lt;a href="http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html"&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a href="http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html"&gt;updated version&lt;/a&gt;)  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2009/06/why-no-open-source-siem-ever.html"&gt;Why No Open Source SIEM, EVER?&lt;/a&gt;” (and &lt;a href="http://chuvakin.blogspot.com/2010/02/short-observation-on-open-source-siem.html"&gt;this&lt;/a&gt;) is next – for some weird reason. I suspect a lot of people still crave a free open source SIEM tool.  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm. &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” is about &lt;em&gt;the least wrong way&lt;/em&gt; of choosing a SIEM tool – as well as why the right way is so unpopular. &lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;In addition, I’d like to draw your attention to a few posts from &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;my Gartner blog&lt;/a&gt;:  &lt;p&gt;&lt;strong&gt;Denial of Service research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/05/29/more-on-dos-and-shared-security/"&gt;More on DoS and Shared Security&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/05/15/on-dos-detection/"&gt;On DoS Detection&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/05/03/wanted-dead-or-alive-application-dos-attack/"&gt;Wanted Dead or Alive: Application DoS Attack&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/04/26/availability-security-and-why-is-dos-fun/"&gt;Availability, Security and Why is DoS Fun?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual&lt;/a&gt; “Top Posts” – &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html"&gt;2011&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content was written before I &lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2012/05/monthly-blog-round-up-april-2012.html"&gt;Monthly Blog Round-Up – April 2012&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=hi3zteaqA60:NezQws7nJa4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=hi3zteaqA60:NezQws7nJa4:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=hi3zteaqA60:NezQws7nJa4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/hi3zteaqA60" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-06-01T08:37:24.587-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2012/06/monthly-blog-round-up-may-2012.html</feedburner:origLink></item><item><title>Book Review: “Security De-Engineering: Solving the Problems in Information Risk Management” by Ian Tibble</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/OdaqQorHemU/book-review-security-de-engineering.html</link><category>book review</category><category>security</category><category>review</category><category>book</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Fri, 18 May 2012 15:44:56 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-2279970692188469581</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
This book is probably the most thought-provoking book on security I read in the last 5-7 years! While I'm somewhat known from my proclivity to exaggerate, I assure you this is not an exaggeration. As I was reading it, I felt like I connected to deep layers of the subconsciousness of security industry. &lt;iframe frameborder="0" marginheight="0" marginwidth="0" scrolling="no" src="http://rcm.amazon.com/e/cm?t=antonchuvakin-20&amp;amp;o=1&amp;amp;p=8&amp;amp;l=as1&amp;amp;asins=B0074MUPBQ&amp;amp;ref=qf_sp_asin_til&amp;amp;fc1=000000&amp;amp;IS2=1&amp;amp;lt1=_blank&amp;amp;m=amazon&amp;amp;lc1=0000FF&amp;amp;bc1=000000&amp;amp;bg1=FFFFFF&amp;amp;f=ifr" style="height: 240px; width: 120px;"&gt;&lt;/iframe&gt; &lt;br /&gt;
In fact, the influence this book already had on me is palpable: I found myself using some of the terms (such as author’s favorites, “intellectual capital” and “CASE”) and concepts on the next day after I started reading it.  &lt;br /&gt;
&lt;br /&gt;
As a brief summary, the book investigates the evolution of the way we do information security from the “hacker-lead” late 1990s to “compliance-heavy” late 2000s and today. The author also highlights dramatic problems with today's approach to security and suggests some of the solutions in the way people think and operate around security.  &lt;br /&gt;
&lt;br /&gt;
In fact, it might be one of the most influential books ever written in history of security industry - the one that appeared at the best possible time when it’s most needed. Along the same line, I have grown worried about the ranks of security professionals who are not hands-on with technology and who have never secured production systems. Just as the author, I've been grown frustrated with the ranks of idiots who equate compliance and security. Even author’s rant about ethics is something I've been thinking for years.  &lt;br /&gt;
&lt;br /&gt;
The author slaughters a few of the sacred cows of security industry: one that “executives are clueless” and the one that we “must have reliable actuarial data on incidents to stay relevant.” He also highlights a few categories of security products, which are notorious for not delivering value and explains the reasons for that. Most of his points are backed up by specific cases from his experience, going back to the end of 1990s when the security industry was born.  &lt;br /&gt;
&lt;br /&gt;
And, of course, as with any thought-provoking writing, I cannot say I agree with every word I read. For example, I am much less negative on the vulnerability assessment technology than the author (I don't think they give you 50% “false negatives” on common platforms today). Furthermore, I abhor the use (misuse, really) of “ROI” for justifying security spending. Style-wise, the author is a little too fond of repetitions to my taste. However, having a summary after each chapter is a great idea.  &lt;br /&gt;
&lt;br /&gt;
Finally, despite the unreasonably high price, I feel that every member of the security community MUST read this book. Literally every chapter will have insights that will make you a better security professional today.  &lt;br /&gt;
&lt;a href="http://chuvakin.blogspot.com/search/label/book%20review"&gt;All book reviews.&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=OdaqQorHemU:WBb6zagZQl0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=OdaqQorHemU:WBb6zagZQl0:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=OdaqQorHemU:WBb6zagZQl0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/OdaqQorHemU" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-18T15:44:56.817-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2012/05/book-review-security-de-engineering.html</feedburner:origLink></item><item><title>Monthly Blog Round-Up – April 2012</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/X5Ltd59xXec/monthly-blog-round-up-april-2012.html</link><category>blogging</category><category>security</category><category>Monthly</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Tue, 01 May 2012 20:11:27 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-1637433199235093766</guid><description>&lt;div style="text-align: left" dir="ltr" trbidi="on"&gt;Here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt;&lt;/div&gt; &lt;div style="text-align: left" dir="ltr" trbidi="on"&gt; &lt;ol&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top – the checklist is still a very useful tool for many people. “&lt;a href="http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html"&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a href="http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html"&gt;updated version&lt;/a&gt;)  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2009/06/why-no-open-source-siem-ever.html"&gt;Why No Open Source SIEM, EVER?&lt;/a&gt;” (and &lt;a href="http://chuvakin.blogspot.com/2010/02/short-observation-on-open-source-siem.html"&gt;this&lt;/a&gt;) is next – for some weird reason. I suspect a lot of people still crave a free open source SIEM tool. &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” is about &lt;em&gt;the least wrong way&lt;/em&gt; of choosing a SIEM tool – as well as why the right way is so unpopular.  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/log-management-at-0-and-1hrweek.html"&gt;Log Management at $0 and 1hr/week?&lt;/a&gt;” is where a lot of companies still are, thus this post became popular again. &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html"&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm.&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;In addition, I’d like to draw your attention to a few posts from &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;my Gartner blog&lt;/a&gt;: &lt;p&gt;&lt;strong&gt;Denial of Service research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/04/26/availability-security-and-why-is-dos-fun/"&gt;Availability, Security and Why is DoS Fun?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Cloud security monitoring research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/04/23/my-cloud-security-monitoring-paper-publishes/"&gt;My Cloud Security Monitoring Paper Publishes!&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/04/10/cloud-security-monitoring-the-who-question/"&gt;Cloud Security Monitoring: The “Who” Question&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/01/21/cloud-security-monitoring-for-iaas-paas-saas/"&gt;Cloud Security Monitoring for IaaS, PaaS, SaaS&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/01/14/more-on-security-monitoring-of-public-cloud-assets/"&gt;More On Security Monitoring of Public Cloud Assets&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/03/13/is-cloud-secure-wtfc/"&gt;Is Cloud Secure? WTFC!&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/01/09/cloud-security-monitoring/"&gt;Cloud Security Monitoring!&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/02/07/cloud-security-monitoring-iaas-conundrum-2/"&gt;Cloud Security Monitoring: IaaS Conundrum&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/02/16/cloud-is-different-so-monitoring-must-be-different/"&gt;Cloud IS Different: So Monitoring Must Be Different?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Future SIEM analytics research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/03/26/big-analytics-for-security-a-harbinger-or-an-outlier/"&gt;“Big Analytics” for Security: A Harbinger or An Outlier?&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/02/02/many-faces-of-application-security-monitoring/"&gt;Many Faces of Application Security Monitoring&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/03/15/more-on-application-security-monitoring/"&gt;More on Application Security Monitoring&lt;/a&gt; &lt;/li&gt;&lt;!--EndFragment--&gt;&lt;/ul&gt; &lt;p&gt;Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual&lt;/a&gt; “Top Posts” – &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html"&gt;2011&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content was written before I &lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2012/04/monthly-blog-round-up-march-2012.html"&gt;Monthly Blog Round-Up – March 2012&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=X5Ltd59xXec:xkD4b9qRz-U:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=X5Ltd59xXec:xkD4b9qRz-U:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=X5Ltd59xXec:xkD4b9qRz-U:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/X5Ltd59xXec" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-01T20:11:27.669-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2012/05/monthly-blog-round-up-april-2012.html</feedburner:origLink></item><item><title>Metricon 7 Call for Papers</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/hjsz_Gs21vE/metricon-7-call-for-papers.html</link><category>conference</category><category>metrics</category><category>news</category><category>security</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Mon, 30 Apr 2012 09:54:30 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-5830886756831028666</guid><description>&lt;p&gt;This is a Call for Papers (CFP) for &lt;strong&gt;Metricon 7.&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Key stats first:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;Conference date: &lt;strong&gt;August 7, 2012&lt;/strong&gt;&lt;/li&gt; &lt;li&gt;CFP deadline: &lt;strong&gt;May 31, 2012&lt;/strong&gt;&lt;/li&gt; &lt;li&gt;Conference location: &lt;strong&gt;Bellevue, WA&lt;/strong&gt;&lt;/li&gt; &lt;li&gt;Cost to attend:&lt;strong&gt; free &lt;/strong&gt;(&lt;em&gt;but you’d need to add value to discussions&lt;/em&gt;)&lt;strong&gt;.&lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;CFP follows below and can be found at &lt;a href="http://securitymetrics.org/content/Wiki.jsp?page=Metricon7.0"&gt;SecurityMetrics site&lt;/a&gt;. &lt;p&gt;&lt;strong&gt;&lt;font size="4"&gt;Metricon 7 - Security Metrics: Useful or Bust!!&lt;/font&gt;&lt;/strong&gt; &lt;p&gt;How to define, generate, and communicate security metrics you can use TODAY!  &lt;p&gt;This year, Metricon 7.0 is excited to issue a call for participation to the information security community. The event will occur &lt;strong&gt;August 7th 2012&lt;/strong&gt; collocated with USENIX in &lt;strong&gt;Bellevue, WA. &lt;/strong&gt; &lt;p&gt;Given that this is the 7th event, we think it is time to finally say it: security metrics MUST be useful NOW! Thus, the focus this year is on useful and usable metrics – not conceptual and theoretical stuff that sounds great, but cannot and will not be used in today’s organizations. Also, presentations and panels that talk about “How?” and “What?” will be strongly prioritized over “Why?”(and “whine”). Enterprises and tool vendors are both welcome to present! Academic researchers tacking the real-world problems are welcome as well.  &lt;p&gt;&lt;strong&gt;&lt;font size="3"&gt;We want to see:&lt;br&gt;&lt;/font&gt;&lt;/strong&gt;• How you achieved “quick wins” with security metrics?&lt;br&gt;• How you define useful metrics, whether risk or operational?&lt;br&gt;• What metrics you track are the most useful?&lt;br&gt;• How did you solve a particular challenge in security metrics area?&lt;br&gt;• How your tool helps (not “can help”!) with collecting and analyzing security metric data?&lt;br&gt;• Who gets the metrics you create? How do they use them?&lt;br&gt;• What metrics you use to determine that security controls are effective?&lt;br&gt;• How organization generate actionable advice from security metrics?&lt;br&gt;• How to track that your security is improving using metrics?  &lt;p&gt;&lt;font size="3"&gt;&lt;em&gt;We do not want:&lt;br&gt;&lt;/em&gt;&lt;/font&gt;• Uncollectable and unusable metrics&lt;br&gt;• Metrics philosophy&lt;br&gt;• Uncooked metrics that sound vaguely “interesting”  &lt;p&gt;Send submissions and your ideas for panels and presentations to &lt;a href="mailto:metricon7@securitymetrics.org"&gt;metricon7@securitymetrics.org&lt;/a&gt;  &lt;p&gt;Deadline for presentation and talk submissions is &lt;strong&gt;May 31st, 2012&lt;/strong&gt;. Submissions should be sent to &lt;a href="mailto:Metricon7@securitymetrics.org"&gt;Metricon7@securitymetrics.org&lt;/a&gt;.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=hjsz_Gs21vE:KLDij9bvb58:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=hjsz_Gs21vE:KLDij9bvb58:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=hjsz_Gs21vE:KLDij9bvb58:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/hjsz_Gs21vE" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-04-30T09:54:30.263-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2012/04/metricon-7-call-for-papers.html</feedburner:origLink></item><item><title>Monthly Blog Round-Up – March 2012</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/_TqRQTNJkmg/monthly-blog-round-up-march-2012.html</link><category>Monthly</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Mon, 02 Apr 2012 10:17:08 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-7590495911413651910</guid><description>&lt;div style="text-align: left" dir="ltr" trbidi="on"&gt;Here is my next &lt;strong&gt;monthly &lt;a href="http://www.blogger.com/chuvakin.blogspot.com/"&gt;"Security Warrior" blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt; &lt;ol&gt; &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html"&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top – the checklist is still a very useful tool for many people  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/08/updated-with-community-feedback-sans_06.html"&gt;Updated With Community Feedback SANS Top 7 Essential Log Reports DRAFT2&lt;/a&gt;”, “&lt;a href="http://chuvakin.blogspot.com/2010/07/sans-top-5-essential-log-reports-update.html"&gt;SANS Top 5 Essential Log Reports Update!&lt;/a&gt;” and their predecessor&amp;nbsp; &lt;a href="http://chuvakin.blogspot.com/2010/07/sans-top-5-essential-log-reports-update.html"&gt;“Top5 SANS Log Reports Update DRAFT”&lt;/a&gt; also show up close to the top. &lt;font color="#ff0000"&gt;&lt;b&gt;&lt;i&gt;IF YOU WANT TO VOLUNTEER TO FINISH THIS DOCUMENT- PLEASE EMAIL ME!&lt;/i&gt;&lt;/b&gt; &lt;/font&gt; &lt;li&gt;My classic PCI DSS log review series is still on my Top 5: “&lt;a href="http://chuvakin.blogspot.com/search/label/PCI_Log_Review"&gt;Complete PCI DSS Log Review Procedures&lt;/a&gt;”; they are also useful for other compliance or security log review and log monitoring.  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html"&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist below (&lt;a href="http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html"&gt;updated version&lt;/a&gt;)  &lt;li&gt;“&lt;a href="http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html"&gt;On Choosing SIEM&lt;/a&gt;” is about &lt;em&gt;the least wrong way&lt;/em&gt; of choosing a SIEM tool – as well as why the right way is so unpopular. &lt;/li&gt;&lt;/ol&gt;In addition, I’d like to draw your attention to a few posts from &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;my Gartner blog&lt;/a&gt;:&lt;br&gt; &lt;ol&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/03/26/big-analytics-for-security-a-harbinger-or-an-outlier/"&gt;“Big Analytics” for Security: A Harbinger or An Outlier?&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/02/02/many-faces-of-application-security-monitoring/"&gt;Many Faces of Application Security Monitoring&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/03/15/more-on-application-security-monitoring/"&gt;More on Application Security Monitoring&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/01/21/cloud-security-monitoring-for-iaas-paas-saas/"&gt;Cloud Security Monitoring for IaaS, PaaS, SaaS&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/01/14/more-on-security-monitoring-of-public-cloud-assets/"&gt;More On Security Monitoring of Public Cloud Assets&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/03/13/is-cloud-secure-wtfc/"&gt;Is Cloud Secure? WTFC!&lt;/a&gt; &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/01/09/cloud-security-monitoring/"&gt;Cloud Security Monitoring!&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/02/07/cloud-security-monitoring-iaas-conundrum-2/"&gt;Cloud Security Monitoring: IaaS Conundrum&lt;/a&gt;  &lt;li&gt;&lt;a href="http://blogs.gartner.com/anton-chuvakin/2012/02/16/cloud-is-different-so-monitoring-must-be-different/"&gt;Cloud IS Different: So Monitoring Must Be Different?&lt;/a&gt;&lt;/li&gt;&lt;/ol&gt;Also see my past &lt;a href="http://chuvakin.blogspot.com/search/label/Monthly"&gt;monthly&lt;/a&gt; and &lt;a href="http://chuvakin.blogspot.com/search/label/Annual"&gt;annual&lt;/a&gt; “Top Posts” – &lt;a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html"&gt;2007&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html"&gt;2008&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html"&gt;2009&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html"&gt;2010&lt;/a&gt;, &lt;a href="http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html"&gt;2011&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content was written before I &lt;a href="http://chuvakin.blogspot.com/2011/07/last-blog-post.html"&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a href="http://blogs.gartner.com/anton-chuvakin"&gt;here&lt;/a&gt;.&lt;br&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://chuvakin.blogspot.com/2012/03/monthly-blog-round-up-february-2012.html"&gt;Monthly Blog Round-Up – February 2012&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=_TqRQTNJkmg:9Soe0yEstXQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=_TqRQTNJkmg:9Soe0yEstXQ:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=_TqRQTNJkmg:9Soe0yEstXQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/_TqRQTNJkmg" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-04-02T10:17:08.852-07:00</app:edited><feedburner:origLink>http://chuvakin.blogspot.com/2012/04/monthly-blog-round-up-march-2012.html</feedburner:origLink></item><item><title>The Log Book Needs YOUR Help!</title><link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/JCvLLbF4W_w/log-book-needs-your-help.html</link><category>log management</category><category>logs</category><category>logging</category><category>book</category><author>anton@chuvakin.org (Anton Chuvakin)</author><pubDate>Fri, 09 Mar 2012 08:10:04 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-3965897588270285615</guid><description>&lt;p&gt;As most of you know, I’ve been working on a book about logs, logging and log management for some number of &lt;em&gt;years&lt;/em&gt;. At this point, &lt;a href="http://www.syngress.com/information-security-and-system-administrators/Logging-and-Log-Management/"&gt;the book&lt;/a&gt; is almost done, but the author team is having some &lt;em&gt;minor&lt;/em&gt; time commitment issues (aka “less time to write than originally estimated”) &lt;img style="border-bottom-style: none; border-right-style: none; border-top-style: none; border-left-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://lh3.ggpht.com/-91aU1TllJ9A/T1orWC7U35I/AAAAAAAASYI/qJLothdCEfo/wlEmoticon-smile%25255B2%25255D.png?imgmax=800"&gt;).&lt;/p&gt; &lt;p&gt;&lt;img style="display: inline; float: left" align="left" src="http://covers.elsevier.com/165_FW/9781597496353.jpg"&gt;&lt;/p&gt; &lt;p&gt;So, do any of my esteemed blog readers (those adept in the dark arts of log analysis) care to help and write a few chapters here and there, in exchange for (lots of) immortal fame and (admittedly small amount of) cash?&lt;/p&gt; &lt;p&gt;Table of contents is &lt;a href="http://www.syngress.com/information-security-and-system-administrators/Logging-and-Log-Management/"&gt;here&lt;/a&gt; – if you see any chapters you’d like to help with, please let us know. I will post a list of chapters that really need help soon.&lt;/p&gt; &lt;p&gt;At this point, we have PLENTY of reviewing help, but we sure can use some writing help!&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=JCvLLbF4W_w:67fqEq62QWw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=JCvLLbF4W_w:67fqEq62QWw:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=JCvLLbF4W_w:67fqEq62QWw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/JCvLLbF4W_w" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-03-09T08:10:04.629-08:00</app:edited><media:thumbnail url="http://lh3.ggpht.com/-91aU1TllJ9A/T1orWC7U35I/AAAAAAAASYI/qJLothdCEfo/s72-c/wlEmoticon-smile%25255B2%25255D.png?imgmax=800" height="72" width="72" /><feedburner:origLink>http://chuvakin.blogspot.com/2012/03/log-book-needs-your-help.html</feedburner:origLink></item><copyright>(C) Anton Chuvakin and Andrew Hay</copyright><media:credit role="author">Anton Chuvakin</media:credit><media:rating>nonadult</media:rating><media:description type="plain">LogChat: Andrew Hay and Anton Chuvakin talk about logging, log management and related topics</media:description></channel></rss>
