<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Information and Technology Security</title>
	<atom:link href="https://awrobinson.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://awrobinson.wordpress.com</link>
	<description>News, resources and discussion on Information Security and Technology with an Australian focus.</description>
	<lastBuildDate>Thu, 01 Oct 2009 02:42:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='awrobinson.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>https://s0.wp.com/i/buttonw-com.png</url>
		<title>Information and Technology Security</title>
		<link>https://awrobinson.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="https://awrobinson.wordpress.com/osd.xml" title="Information and Technology Security" />
	<atom:link rel='hub' href='https://awrobinson.wordpress.com/?pushpress=hub'/>
	<item>
		<title>Brake Theory and Jet Theory</title>
		<link>https://awrobinson.wordpress.com/2009/10/01/brake-theory-and-jet-theory/</link>
					<comments>https://awrobinson.wordpress.com/2009/10/01/brake-theory-and-jet-theory/#respond</comments>
		
		<dc:creator><![CDATA[awrobinson]]></dc:creator>
		<pubDate>Thu, 01 Oct 2009 00:01:10 +0000</pubDate>
				<category><![CDATA[Security Awareness]]></category>
		<guid isPermaLink="false">http://awrobinson.wordpress.com/?p=689</guid>

					<description><![CDATA[Explaining security to those in the security industry can be hard enough at the best of times without having to try and convince a board to spend on security during harder times.  Traditional Brake Theory is sometimes deployed by security managers at this point but I&#8217;m going to introduce a new and improved theory that [&#8230;]]]></description>
		
					<wfw:commentRss>https://awrobinson.wordpress.com/2009/10/01/brake-theory-and-jet-theory/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		
		<media:content url="https://2.gravatar.com/avatar/8413b8b52c7759c83835c1c61fd83e76888041eaf98f50be831fb43b9d3d92d7?s=96&#38;d=https%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">awrobinson</media:title>
		</media:content>

		<media:content url="https://awrobinson.wordpress.com/wp-content/uploads/2009/10/afterburner.jpg?w=150" medium="image">
			<media:title type="html">afterburner</media:title>
		</media:content>
	</item>
		<item>
		<title>Calculating Overall Risk</title>
		<link>https://awrobinson.wordpress.com/2009/06/02/calculating-overall-risk/</link>
					<comments>https://awrobinson.wordpress.com/2009/06/02/calculating-overall-risk/#comments</comments>
		
		<dc:creator><![CDATA[awrobinson]]></dc:creator>
		<pubDate>Tue, 02 Jun 2009 00:42:09 +0000</pubDate>
				<category><![CDATA[Management System]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://awrobinson.wordpress.com/?p=651</guid>

					<description><![CDATA[An Overall risk exposure value should be calculated for each server or each application to provide a means for comparison with other servers or applications.  Enough polarisation should exist that the management of servers and applications &#8212; i.e. prioritising of changes or compliance efforts &#8212; may be controlled more granularly based on both technical and [&#8230;]]]></description>
		
					<wfw:commentRss>https://awrobinson.wordpress.com/2009/06/02/calculating-overall-risk/feed/</wfw:commentRss>
			<slash:comments>4</slash:comments>
		
		
		
		<media:content url="https://2.gravatar.com/avatar/8413b8b52c7759c83835c1c61fd83e76888041eaf98f50be831fb43b9d3d92d7?s=96&#38;d=https%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">awrobinson</media:title>
		</media:content>
	</item>
		<item>
		<title>Assessing Business Risk</title>
		<link>https://awrobinson.wordpress.com/2009/06/02/assessing-business-risk/</link>
					<comments>https://awrobinson.wordpress.com/2009/06/02/assessing-business-risk/#comments</comments>
		
		<dc:creator><![CDATA[awrobinson]]></dc:creator>
		<pubDate>Tue, 02 Jun 2009 00:41:45 +0000</pubDate>
				<category><![CDATA[Management System]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://awrobinson.wordpress.com/?p=600</guid>

					<description><![CDATA[Business risk for the purposes of A Simple Security Risk Assessment is the input provided by Business Unit which incorporates the value and criticality of the Information Assets to business operations.  A Business risk value is usually assigned to each application and not to each server or configuration item (unlike Technical risk which is assigned [&#8230;]]]></description>
		
					<wfw:commentRss>https://awrobinson.wordpress.com/2009/06/02/assessing-business-risk/feed/</wfw:commentRss>
			<slash:comments>4</slash:comments>
		
		
		
		<media:content url="https://2.gravatar.com/avatar/8413b8b52c7759c83835c1c61fd83e76888041eaf98f50be831fb43b9d3d92d7?s=96&#38;d=https%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">awrobinson</media:title>
		</media:content>

		<media:content url="https://awrobinson.wordpress.com/wp-content/uploads/2009/06/business_risk_chat.gif" medium="image">
			<media:title type="html">Business_Risk_Chat</media:title>
		</media:content>
	</item>
		<item>
		<title>Assessing Technical Risk</title>
		<link>https://awrobinson.wordpress.com/2009/06/02/assessing-technical-risk/</link>
					<comments>https://awrobinson.wordpress.com/2009/06/02/assessing-technical-risk/#comments</comments>
		
		<dc:creator><![CDATA[awrobinson]]></dc:creator>
		<pubDate>Tue, 02 Jun 2009 00:41:22 +0000</pubDate>
				<category><![CDATA[Management System]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://awrobinson.wordpress.com/?p=599</guid>

					<description><![CDATA[Technical risk for the purposes of A Simple Security Risk Assessment refers to the probability that an attacker will exploit a vulnerability in the software related to a specific configuration item, or that a misconfiguration of the configuration item will result in the same or a similar level of Impact.  Let&#8217;s see how we can [&#8230;]]]></description>
		
					<wfw:commentRss>https://awrobinson.wordpress.com/2009/06/02/assessing-technical-risk/feed/</wfw:commentRss>
			<slash:comments>4</slash:comments>
		
		
		
		<media:content url="https://2.gravatar.com/avatar/8413b8b52c7759c83835c1c61fd83e76888041eaf98f50be831fb43b9d3d92d7?s=96&#38;d=https%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">awrobinson</media:title>
		</media:content>

		<media:content url="https://awrobinson.wordpress.com/wp-content/uploads/2009/06/technical_risk_chart.gif" medium="image">
			<media:title type="html">Technical_Risk_Chart</media:title>
		</media:content>
	</item>
		<item>
		<title>Information Asset Attributes</title>
		<link>https://awrobinson.wordpress.com/2009/06/02/information-asset-attributes/</link>
					<comments>https://awrobinson.wordpress.com/2009/06/02/information-asset-attributes/#comments</comments>
		
		<dc:creator><![CDATA[awrobinson]]></dc:creator>
		<pubDate>Tue, 02 Jun 2009 00:40:56 +0000</pubDate>
				<category><![CDATA[Management System]]></category>
		<category><![CDATA[accountability]]></category>
		<category><![CDATA[availability]]></category>
		<category><![CDATA[confidentiality]]></category>
		<category><![CDATA[Information Assets]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[integrity]]></category>
		<category><![CDATA[non-repudiation]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[STRIDE]]></category>
		<guid isPermaLink="false">http://awrobinson.wordpress.com/?p=575</guid>

					<description><![CDATA[As discussed in the previous post, it is a common approach for Industry Standard Risk Methodologies to categorise the threat type prior to assigning a value.  The threat type provides a level of context around the value that will be assigned to it and is far easier than exhaustively evaluating every possible threat (although this [&#8230;]]]></description>
		
					<wfw:commentRss>https://awrobinson.wordpress.com/2009/06/02/information-asset-attributes/feed/</wfw:commentRss>
			<slash:comments>4</slash:comments>
		
		
		
		<media:content url="https://2.gravatar.com/avatar/8413b8b52c7759c83835c1c61fd83e76888041eaf98f50be831fb43b9d3d92d7?s=96&#38;d=https%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">awrobinson</media:title>
		</media:content>
	</item>
		<item>
		<title>Industry Standard Risk Methodologies</title>
		<link>https://awrobinson.wordpress.com/2009/06/02/industry-standard-risk-methodologies/</link>
					<comments>https://awrobinson.wordpress.com/2009/06/02/industry-standard-risk-methodologies/#comments</comments>
		
		<dc:creator><![CDATA[awrobinson]]></dc:creator>
		<pubDate>Tue, 02 Jun 2009 00:40:04 +0000</pubDate>
				<category><![CDATA[Management System]]></category>
		<category><![CDATA[4360]]></category>
		<category><![CDATA[CVSS]]></category>
		<category><![CDATA[DEAD]]></category>
		<category><![CDATA[Information Risk Management]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[IRAM]]></category>
		<category><![CDATA[Octave]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SP 800-30]]></category>
		<category><![CDATA[STRIDE]]></category>
		<guid isPermaLink="false">http://awrobinson.wordpress.com/?p=573</guid>

					<description><![CDATA[Risk methodologies of various levels of complexity already exist for different purposes.  Whilst it is prudent to evaluate industry standard security risk methodologies, stringently following an industry standard may not result in a suitable outcome for your organisation.  The objective of this post is to provide an introduction to the general concepts of risk assessment [&#8230;]]]></description>
		
					<wfw:commentRss>https://awrobinson.wordpress.com/2009/06/02/industry-standard-risk-methodologies/feed/</wfw:commentRss>
			<slash:comments>4</slash:comments>
		
		
		
		<media:content url="https://2.gravatar.com/avatar/8413b8b52c7759c83835c1c61fd83e76888041eaf98f50be831fb43b9d3d92d7?s=96&#38;d=https%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">awrobinson</media:title>
		</media:content>
	</item>
		<item>
		<title>A Simple Security Risk Assessment</title>
		<link>https://awrobinson.wordpress.com/2009/06/02/a-simple-security-risk-assessment/</link>
					<comments>https://awrobinson.wordpress.com/2009/06/02/a-simple-security-risk-assessment/#comments</comments>
		
		<dc:creator><![CDATA[awrobinson]]></dc:creator>
		<pubDate>Tue, 02 Jun 2009 00:38:46 +0000</pubDate>
				<category><![CDATA[Management System]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://awrobinson.wordpress.com/?p=568</guid>

					<description><![CDATA[Many security practitioners (and others) struggle to understand the environment they are working in and find it difficult to prioritise what needs to be done.  To help, I&#8217;m going to share a series of articles that demonstrate an approach to completing A Simple Security Risk Assessment, an approach that takes into consideration both technical and [&#8230;]]]></description>
		
					<wfw:commentRss>https://awrobinson.wordpress.com/2009/06/02/a-simple-security-risk-assessment/feed/</wfw:commentRss>
			<slash:comments>4</slash:comments>
		
		
		
		<media:content url="https://2.gravatar.com/avatar/8413b8b52c7759c83835c1c61fd83e76888041eaf98f50be831fb43b9d3d92d7?s=96&#38;d=https%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">awrobinson</media:title>
		</media:content>
	</item>
		<item>
		<title>Top 10 Blog Posts</title>
		<link>https://awrobinson.wordpress.com/2009/01/13/top-10-blog-posts/</link>
					<comments>https://awrobinson.wordpress.com/2009/01/13/top-10-blog-posts/#respond</comments>
		
		<dc:creator><![CDATA[awrobinson]]></dc:creator>
		<pubDate>Tue, 13 Jan 2009 23:16:27 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[top 10]]></category>
		<guid isPermaLink="false">http://awrobinson.wordpress.com/?p=549</guid>

					<description><![CDATA[I no longer post regularly as I find the time is better spent on my own security research and with my family and friends.  The existing content will remain available and to focus on this I have provided a list of the Top 10 Blog Posts. 1. A Simple Scorecard for Information Security 2. The [&#8230;]]]></description>
		
					<wfw:commentRss>https://awrobinson.wordpress.com/2009/01/13/top-10-blog-posts/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		
		<media:content url="https://2.gravatar.com/avatar/8413b8b52c7759c83835c1c61fd83e76888041eaf98f50be831fb43b9d3d92d7?s=96&#38;d=https%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">awrobinson</media:title>
		</media:content>
	</item>
		<item>
		<title>Forecasting Vulnerabilities for 2009</title>
		<link>https://awrobinson.wordpress.com/2009/01/04/forecasting-vulnerabilities-for-2009/</link>
					<comments>https://awrobinson.wordpress.com/2009/01/04/forecasting-vulnerabilities-for-2009/#respond</comments>
		
		<dc:creator><![CDATA[awrobinson]]></dc:creator>
		<pubDate>Sun, 04 Jan 2009 01:24:37 +0000</pubDate>
				<category><![CDATA[Vulnerability Management]]></category>
		<category><![CDATA[2009]]></category>
		<category><![CDATA[forecast]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://awrobinson.wordpress.com/?p=538</guid>

					<description><![CDATA[As we start 2009 it is prudent to think about what we may need to plan for in the year ahead.  Many organisations will pursue existing projects and (hopefully) continue to mature their security capabilities.  It is also necessary to be mindful of the current business environment and technology trends. DarkReading has a somewhat fearsome [&#8230;]]]></description>
		
					<wfw:commentRss>https://awrobinson.wordpress.com/2009/01/04/forecasting-vulnerabilities-for-2009/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		
		<media:content url="https://2.gravatar.com/avatar/8413b8b52c7759c83835c1c61fd83e76888041eaf98f50be831fb43b9d3d92d7?s=96&#38;d=https%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">awrobinson</media:title>
		</media:content>
	</item>
		<item>
		<title>Child porn ring busted using P2P</title>
		<link>https://awrobinson.wordpress.com/2008/12/12/child-porn-ring-using-p2p/</link>
					<comments>https://awrobinson.wordpress.com/2008/12/12/child-porn-ring-using-p2p/#respond</comments>
		
		<dc:creator><![CDATA[awrobinson]]></dc:creator>
		<pubDate>Fri, 12 Dec 2008 02:53:49 +0000</pubDate>
				<category><![CDATA[Security Incidents]]></category>
		<category><![CDATA[AFP]]></category>
		<category><![CDATA[child porn]]></category>
		<category><![CDATA[dynDNS]]></category>
		<category><![CDATA[fast flux]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[internet filter]]></category>
		<category><![CDATA[p2p]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://awrobinson.wordpress.com/?p=527</guid>

					<description><![CDATA[In a recent article on the politics of an Australian Internet filter, I shared some of the concerns being raised about the proposed legislation.  One of those concerns was that the filter would be unable to handle the ever changing IP addresses used by peer-to-peer network and dynamic websites (see DynDNS and Fast Flux). Having [&#8230;]]]></description>
		
					<wfw:commentRss>https://awrobinson.wordpress.com/2008/12/12/child-porn-ring-using-p2p/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		
		<media:content url="https://2.gravatar.com/avatar/8413b8b52c7759c83835c1c61fd83e76888041eaf98f50be831fb43b9d3d92d7?s=96&#38;d=https%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">awrobinson</media:title>
		</media:content>
	</item>
	</channel>
</rss>
