<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;CkICQ349eyp7ImA9WhVREk8.&quot;"><id>tag:blogger.com,1999:blog-6597927639547949386</id><updated>2012-03-19T22:16:02.063-07:00</updated><category term="Novo Mercado" /><category term="Governança" /><category term="Risco" /><category term="Nota" /><title>Inter caetera</title><subtitle type="html">Governança, Risco e Compliance entre outras coisas</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://www.gustavobittencourt.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://www.gustavobittencourt.com/" /><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/InterCaetera" /><feedburner:info uri="intercaetera" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;A0AGRHwzcCp7ImA9WhRaEkg.&quot;"><id>tag:blogger.com,1999:blog-6597927639547949386.post-7326822498820383528</id><published>2012-02-14T14:46:00.002-08:00</published><updated>2012-02-14T14:48:45.288-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-02-14T14:48:45.288-08:00</app:edited><title>Como você define segurança?</title><content type="html">Excelente &lt;a href="https://plus.google.com/105015082178818522140/posts/eeqx2XzggYJ"&gt;pergunta do Michael Santarcangelo&lt;/a&gt; que poucos profissionais de segurança se fazem. Minha definição é um tanto conceitual mas que gosto pois rompe com alguns mitos:&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;&lt;b&gt;Segurança é a percepção de conforto frente a um cenário de incertezas&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;E qual é a sua definição?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6597927639547949386-7326822498820383528?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.gustavobittencourt.com/feeds/7326822498820383528/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.gustavobittencourt.com/2012/02/como-voce-define-seguranca.html#comment-form" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6597927639547949386/posts/default/7326822498820383528?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6597927639547949386/posts/default/7326822498820383528?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InterCaetera/~3/4alypZTGFdA/como-voce-define-seguranca.html" title="Como você define segurança?" /><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.gustavobittencourt.com/2012/02/como-voce-define-seguranca.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkIDQ3c-cCp7ImA9WhRbFkw.&quot;"><id>tag:blogger.com,1999:blog-6597927639547949386.post-5148734381885278104</id><published>2012-02-07T02:04:00.000-08:00</published><updated>2012-02-07T02:29:32.958-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-02-07T02:29:32.958-08:00</app:edited><title>Por que o negócio não é o principal motivador de um controle</title><content type="html">&lt;div&gt;&lt;a href="https://plus.google.com/103834334185089412536/posts/4f3rgkmpMPF"&gt;Artigo interessante do Richard Bejtlich&lt;/a&gt; sobre como é difícil mensurar o impacto de um incidente de segurança. O artigo foca em um cenário de guerra cibernética, em particular no &lt;a href="http://online.wsj.com/article/SB124027491029837401.html"&gt;"furto" de informação confidencial do jato F-35&lt;/a&gt;. Mas este problema é recorrente em incidentes de segurança da informação nos mais diversos cenários.&lt;br /&gt;
&lt;br /&gt;
Em um incidente que envolve uma negação de um serviço, é mais simples calcular o impacto, como no caso da &lt;a href="http://www.pcmag.com/article2/0,2817,2385790,00.asp"&gt;paralisação da PSN&lt;/a&gt;. Contudo, se o incidente envolve o "furto" de informação confidencial, qualquer cálculo de impacto é subjetivo. Mas como essa característica afeta o processo de SI? &lt;br /&gt;
&lt;br /&gt;
O fundamental em processo de SI está na escolha, na implementação e na operação dos &lt;b&gt;controles de SI&lt;/b&gt;, o resto é resto. E sob o aspecto dos controles de SI, eu os classifico em 3 tipos:&lt;br /&gt;
&lt;ol&gt;&lt;li&gt;Controles puramente de disponibilidade (cluster, SGCN)&lt;/li&gt;
&lt;li&gt;Controles puramente de confidencialidade (Criptografia, DLP)&lt;/li&gt;
&lt;li&gt;Controles de disponibilidade e de confidencialidade (a grande maioria)&lt;/li&gt;
&lt;/ol&gt;&lt;div style="text-align: right;"&gt;&lt;span style="font-size: x-small;"&gt;Nota: Para os que se perguntam "Cadê a integridade?", se eu tiver tempo, isso será um assunto para um outro post.&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
Voltando ao assunto, reside aí o grande dilema de SI quando tenta seguir o mantra que &lt;b&gt;devemos estar alinhado com o negócio&lt;/b&gt;. Pois é relativamente simples demonstrar o alinhamento com o negócio nos controles puramente relacionados a disponibilidade. Mas para os demais controles, qualquer relacionamento com o negócio é subjetivo. Por isso também, é mais simples justificar investimentos em disponibilidade do que em confidencialidade.&lt;br /&gt;
&lt;br /&gt;
No final da contas, decisões objetivas funcionam fundamentalmente com os controles puramente de disponibilidade. As demais decisões de controle que SI precisa tomar são de caráter subjetivo, por isso precisamos a toda hora nos respaldar com boas práticas de mercado, padrões de segurança, regulamentações, etc. em detrimento da análise pura e simples da necessidade de segurança do negócio.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6597927639547949386-5148734381885278104?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.gustavobittencourt.com/feeds/5148734381885278104/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.gustavobittencourt.com/2012/02/por-que-o-negocio-nao-e-o-principal.html#comment-form" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6597927639547949386/posts/default/5148734381885278104?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6597927639547949386/posts/default/5148734381885278104?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InterCaetera/~3/KUg6FcHN8ls/por-que-o-negocio-nao-e-o-principal.html" title="Por que o negócio não é o principal motivador de um controle" /><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.gustavobittencourt.com/2012/02/por-que-o-negocio-nao-e-o-principal.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CE8NQ3w9eCp7ImA9WhRbFk0.&quot;"><id>tag:blogger.com,1999:blog-6597927639547949386.post-6044907284425783623</id><published>2012-02-07T00:21:00.000-08:00</published><updated>2012-02-07T00:21:32.260-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-02-07T00:21:32.260-08:00</app:edited><title>GRC Meeting</title><content type="html">Estarei no  &lt;a href="https://plus.google.com/103834334185089412536/posts/eexf8FxbQ9G"&gt;GRC Meeting&lt;/a&gt; no próximo dia 14.&lt;a href="https://plus.google.com/103834334185089412536/posts/eexf8FxbQ9G"&gt;&lt;br /&gt;
&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.grcmeeting.com.br/wp-content/themes/twentyeleven/imgs/lgGRCMeeting.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="60" src="http://www.grcmeeting.com.br/wp-content/themes/twentyeleven/imgs/lgGRCMeeting.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6597927639547949386-6044907284425783623?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.gustavobittencourt.com/feeds/6044907284425783623/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.gustavobittencourt.com/2012/02/grc-meeting.html#comment-form" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6597927639547949386/posts/default/6044907284425783623?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6597927639547949386/posts/default/6044907284425783623?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InterCaetera/~3/iDZpocWAhow/grc-meeting.html" title="GRC Meeting" /><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.gustavobittencourt.com/2012/02/grc-meeting.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0QHSH45cSp7ImA9Wx5XEU8.&quot;"><id>tag:blogger.com,1999:blog-6597927639547949386.post-325160955222241557</id><published>2010-09-08T19:32:00.000-07:00</published><updated>2010-09-10T06:28:59.029-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-09-10T06:28:59.029-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Novo Mercado" /><category scheme="http://www.blogger.com/atom/ns#" term="Risco" /><category scheme="http://www.blogger.com/atom/ns#" term="Governança" /><title>Diversos</title><content type="html">Na falta de tempo e inspiração para escrever algo próprio, seguem enlaces interessantes:&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Marcello Zillo escreveu um artigo sobre &lt;a href="http://mzillo.blogspot.com/2010/09/top-down-ou-bottom-up.html"&gt;gestão de risco top-down e bottom-up&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Termina hoje o prazo de manifestação da proposta de alteração do regulamento de listagem do Novo Mercado (&lt;a href="http://www.bmfbovespa.com.br/empresas/download/NM-Minuta-de-Regulamento-objeto-de-Audiencia-Restrita-09-Julho-2010.pdf"&gt;ver proposta aqui&lt;/a&gt;).&lt;/li&gt;
&lt;/ul&gt;&lt;b&gt;Update &lt;/b&gt;&lt;br /&gt;
(10/09/2010) Saiu o &lt;a href="http://bmfbovespa.comunique-se.com.br/bovespa/show.aspx?id_materia=28561&amp;amp;id_canal=835"&gt;resultado&lt;/a&gt; da proposta de alteração do Novo Mercado, N1 e N2.&lt;br /&gt;
&lt;ul&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6597927639547949386-325160955222241557?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.gustavobittencourt.com/feeds/325160955222241557/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.gustavobittencourt.com/2010/09/diversos.html#comment-form" title="6 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6597927639547949386/posts/default/325160955222241557?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6597927639547949386/posts/default/325160955222241557?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InterCaetera/~3/05RuJrrx6fQ/diversos.html" title="Diversos" /><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>6</thr:total><feedburner:origLink>http://www.gustavobittencourt.com/2010/09/diversos.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEMBQHc6eSp7ImA9WxBUGUw.&quot;"><id>tag:blogger.com,1999:blog-6597927639547949386.post-5477495227545965305</id><published>2010-03-06T14:33:00.000-08:00</published><updated>2010-03-06T15:00:51.911-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-03-06T15:00:51.911-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Nota" /><title>Reínicio</title><content type="html">Este &lt;i&gt;post&lt;/i&gt; marca meu reinício como blogueiro. Além de escrever sobre governança, risco e compliance, pretendo abordar aspectos como gestão, projetos, processos, pessoas e outros aspectos da cultura corporativa.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6597927639547949386-5477495227545965305?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.gustavobittencourt.com/feeds/5477495227545965305/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.gustavobittencourt.com/2010/03/reinicio.html#comment-form" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6597927639547949386/posts/default/5477495227545965305?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6597927639547949386/posts/default/5477495227545965305?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/InterCaetera/~3/QRJBkmrP3ag/reinicio.html" title="Reínicio" /><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.gustavobittencourt.com/2010/03/reinicio.html</feedburner:origLink></entry></feed>

