<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Ken Yerrid's Information Technology Musings</title>
	
	<link>http://kenyerrid.com</link>
	<description>Incredibly Shallow Thoughts From an Otherwise Deep Thinker</description>
	<lastBuildDate>Wed, 11 Apr 2012 13:59:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
<!-- podcast_generator="Blubrry PowerPress/2.0.4" -->
	<itunes:summary>Incredibly Shallow Thoughts From an Otherwise Deep Thinker</itunes:summary>
	<itunes:author>Ken Yerrid's Information Technology Musings</itunes:author>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://kenyerrid.com/wp-content/plugins/powerpress/itunes_default.jpg" />
	<itunes:subtitle>Incredibly Shallow Thoughts From an Otherwise Deep Thinker</itunes:subtitle>
	<image>
		<title>Ken Yerrid's Information Technology Musings</title>
		<url>http://kenyerrid.com/wp-content/plugins/powerpress/rss_default.jpg</url>
		<link>http://kenyerrid.com</link>
	</image>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/KenYerrid" /><feedburner:info uri="kenyerrid" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>This website will be going into hibernation…</title>
		<link>http://feedproxy.google.com/~r/KenYerrid/~3/v1jbQFN4l5A/</link>
		<comments>http://kenyerrid.com/index.php/2012/04/11/this-website-will-be-going-into-hibernation/#comments</comments>
		<pubDate>Wed, 11 Apr 2012 13:59:30 +0000</pubDate>
		<dc:creator>K0nsp1racy</dc:creator>
				<category><![CDATA[Featured Articles]]></category>

		<guid isPermaLink="false">http://kenyerrid.com/?p=319</guid>
		<description><![CDATA[I am going to be shutting this website down for a bit and moving it to a different hosting provider.  Hopefully this will bring welcome improvements.  In the interim, feel free to visit my other website at http://www.k0nsp1racy.com&#8230; &#160; K.C.]]></description>
			<content:encoded><![CDATA[<p>I am going to be shutting this website down for a bit and moving it to a different hosting provider.  Hopefully this will bring welcome improvements.  In the interim, feel free to visit my other website at http://www.k0nsp1racy.com&#8230;</p>
<p>&nbsp;</p>
<p>K.C.</p>
<img src="http://feeds.feedburner.com/~r/KenYerrid/~4/v1jbQFN4l5A" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://kenyerrid.com/index.php/2012/04/11/this-website-will-be-going-into-hibernation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://kenyerrid.com/index.php/2012/04/11/this-website-will-be-going-into-hibernation/</feedburner:origLink></item>
		<item>
		<title>The Changing of the Guard for Information Security Executives?</title>
		<link>http://feedproxy.google.com/~r/KenYerrid/~3/EwGjxn9Tf4Q/</link>
		<comments>http://kenyerrid.com/index.php/2011/11/01/the-changing-of-the-guard-for-information-security-executives/#comments</comments>
		<pubDate>Tue, 01 Nov 2011 14:41:59 +0000</pubDate>
		<dc:creator>K0nsp1racy</dc:creator>
				<category><![CDATA[Featured Articles]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Organizational Management]]></category>
		<category><![CDATA[Original Musings]]></category>
		<category><![CDATA[BSIdes]]></category>
		<category><![CDATA[career progression]]></category>
		<category><![CDATA[CISO]]></category>
		<category><![CDATA[Security BSides]]></category>

		<guid isPermaLink="false">http://kenyerrid.com/?p=293</guid>
		<description><![CDATA[(Full disclosure: This article firmly plays to my personal skill sets and career progression. Wherever possible, I have attempted to correct for my own bias) There has been a great deal of swirl lately regarding the topic of Chief Information Security Officers and what skills <a style="text-decoration:none;" href="http://kenyerrid.com/index.php/2011/11/01/the-changing-of-the-guard-for-information-security-executives/" rel="nofollow">[...]</a>]]></description>
			<content:encoded><![CDATA[<p><em>(Full disclosure:  This article firmly plays to my personal skill sets and career progression.  Wherever possible, I have attempted to correct for my own bias)</em></p>
<p>There has been a great deal of swirl lately regarding the topic of Chief Information Security Officers and what skills and/or qualifications are needed to position the organization for the best chance of success.  On one end of the continuum, the existing pool of executives is brought in with highly-attuned business acumen.  Perhaps the person has a Big4 consulting pedigree, an MBA from a well-respected university, and has forged relationships with other executives throughout social functions and other work arrangements.  </p>
<p>On the other end of the continuum, an emerging trend suggests that when it comes to protecting assets, forging relationships, and establishing trust among stakeholders and board members, that the appropriate candidate should be well-versed in technology concepts and actually rise up through the information security ranks.  The popular justification is that without understanding the threat landscape and actually having “dirt under the fingernails”, how can one fully anticipate and connect with the people that are the front lines in protection.  I find it difficult to argue this justification; this suggests to me that business is in the midst of discovering that the proper approach is to seek balance and resist the temptation of moving the slider too far to the business-end of the continuum.</p>
<p>On Friday, November 4th, <a href="http://www.securitybsides.com/w/page/44893559/BSidesATL-2011" target="_blank">Security B-Sides Atlanta</a> will be holding a panel discussion on this very topic.  Participants include Dave Kennedy, CISO for Diebold, a Fortune 1000 company, as well as Rafal Los, Enterprise Cloud Security Strategist at HP.  Those people within the community that have been observing from a distance would suggest that these two are on opposite ends of the spectrum on this topic.  However, I am going to go out on a limb here and suggest that their philosophies are actually closer to converging than diverging.</p>
<p>Other professions have had this debate before, and we can draw parallels from the military as to whom makes the best general, or from the football field as to whom makes the best coach.  As information security continues to maturate, it will be the practitioners—not the other executives—that determine the right combination of skill sets needed to be successful in an executive role.  In other words, I am suggesting that currently, the business-pedigreed CISO is the safer perceived choice, not necessarily the better one.  You see, the statistics are beginning to bore out a frightening pattern when it comes to protecting information assets:  the trend is getting worse!  More and more companies are getting breached under the watch of the business-focused CISO, suggesting a disconnect between theory and reality.</p>
<p>Sooner or later, information security practitioners will begin to realize that the effort required to move the continuum from the hardcore technical to business is not as great as once perceived.  Simultaneously, those business-focused executives that are forced to become more technical will find the path much more difficult than anticipated.  This will present some interesting discussions for businesses, as they struggle to determine the appropriate combinations for their respective needs.  As anticipated, it appears that the optimal combination is not black or white.  I think what can be agreed is that the role of the information security executive in today’s challenging climate should be reevaluated.  </p>
<p>What do you think?  </p>
<img src="http://feeds.feedburner.com/~r/KenYerrid/~4/EwGjxn9Tf4Q" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://kenyerrid.com/index.php/2011/11/01/the-changing-of-the-guard-for-information-security-executives/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://kenyerrid.com/index.php/2011/11/01/the-changing-of-the-guard-for-information-security-executives/</feedburner:origLink></item>
		<item>
		<title>Correcting Cognitive Dissonance in Reactions to Information Security Presentations</title>
		<link>http://feedproxy.google.com/~r/KenYerrid/~3/BUIZuUCOS90/</link>
		<comments>http://kenyerrid.com/index.php/2011/10/26/correcting-cognitive-dissonance-in-reactions-to-information-security-presentations/#comments</comments>
		<pubDate>Wed, 26 Oct 2011 14:51:25 +0000</pubDate>
		<dc:creator>K0nsp1racy</dc:creator>
				<category><![CDATA[Conferences and Events]]></category>
		<category><![CDATA[Featured Articles]]></category>
		<category><![CDATA[Original Musings]]></category>
		<category><![CDATA[cognitive dissonance]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[Grecs]]></category>
		<category><![CDATA[Hack3rcon]]></category>
		<category><![CDATA[Johnny Long]]></category>

		<guid isPermaLink="false">http://kenyerrid.com/?p=288</guid>
		<description><![CDATA[I have recently attended a number of information security presentations. I honestly admire a presenter’s willingness to state a position in a public construct, regardless of whether I agree or disagree with the position or contents of the presentation. I will be honest… I have <a style="text-decoration:none;" href="http://kenyerrid.com/index.php/2011/10/26/correcting-cognitive-dissonance-in-reactions-to-information-security-presentations/" rel="nofollow">[...]</a>]]></description>
			<content:encoded><![CDATA[<p>I have recently attended a number of information security presentations.  I honestly admire a presenter’s willingness to state a position in a public construct, regardless of whether I agree or disagree with the position or contents of the presentation.  I will be honest…  I have seen good presentations (watch <a href="http://www.irongeek.com/i.php?page=videos/derbycon1/johnny-long-hackers-for-charity-update" target="_blank">Johnny Long’s Hackers for Charity Update at Derbycon </a>for an example), and I have seen total train wrecks.  At the end of each of them, the initial reaction is the same:  applause from the audience.  What does the applause signify in the mind of the presenter?  Chances are, the gut response is that the presenter thought he or she did very well.  But is that the right message we, as presenters, are really receiving?  Applause is good, booing is bad.  Is there a distortion, or cognitive dissonance between the intrinsic feelings and the extrinsic response?  </p>
<p>Coming off of <a href="http://www.hack3rcon.org" target="_blank">Hack3rcon II</a>, a question was posed to a mailing list about the presentations at the conference.  I found the wording of the question to be a little awkward, as the person stated that “all presentations are equal, but which ones are more equal?” I interpreted that wording as a socially awkward way of asking the question, “which ones are worth his time”, and implicitly, “which ones sucked out loud?”  In my view, I clearly thought there was a distinction, and shared my opinion.  I was not trying to throw anyone under the bus; at the same time, I did not want to tiptoe around the feelings.  The feedback I gave was not based on emotion.  Now, at what point does the presenter get to hear that candid feedback?  What are the chances that somebody like Grecs would be reading my response, absorb my feedback, and make a conscious decision to gear his presentation more towards a technical, information security audience?  </p>
<p>I am not suggesting that we should be booing people off of the stage or throwing tomatoes if the presentation misses the mark.  What I am suggesting is that—as presenters—we should be seeking candid and honest feedback from the audience members.  We spend countless hours searching for that perfect cat picture and constructing our presentations for maximum effect.  Maybe the key to improving presentations at an individual and societal level is to open that feedback loop in a non-threatening or demeaning way.  </p>
<p>I propose some simplistic steps to improve the quality of presentations:<br />
•	Conference Organizers should provide feedback mechanisms for attendees.  A brief, yet useful survey during the transitions between presenters could provide a wealth of feedback.  This could be as low-tech as index cards, or as simple as an online survey accessible by electronic gadgets.</p>
<p>•	Presenters should stick around after the presentation and actively seek feedback.  In all likelihood, if a presenter asks an attendee a closed question, such as “how did you like the presentation”, the answer will be skewed on politeness.  However, if you ask open questions, such as what would the attendee change about the presentation, there is a far greater chance for useful feedback. </p>
<p>•	Attendees need to vocalize their disappointment in a tactful manner.  Like I said above, this is not the time to throw tomatoes.  The presenter did the best he or she could; if constructive criticism is not provided, there is a very good chance that you may come across the exact same presentation at the next conference.</p>
<p>What do you think?  Hit me up at @K0nsp1racy.</p>
<img src="http://feeds.feedburner.com/~r/KenYerrid/~4/BUIZuUCOS90" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://kenyerrid.com/index.php/2011/10/26/correcting-cognitive-dissonance-in-reactions-to-information-security-presentations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://kenyerrid.com/index.php/2011/10/26/correcting-cognitive-dissonance-in-reactions-to-information-security-presentations/</feedburner:origLink></item>
		<item>
		<title>Hack3rcon II – Charleston, West Virginia – Oct. 21 – 23</title>
		<link>http://feedproxy.google.com/~r/KenYerrid/~3/snEZO3Bxg38/</link>
		<comments>http://kenyerrid.com/index.php/2011/10/05/hack3rcon-ii-charleston-west-virginia-oct-21-23/#comments</comments>
		<pubDate>Wed, 05 Oct 2011 21:01:16 +0000</pubDate>
		<dc:creator>K0nsp1racy</dc:creator>
				<category><![CDATA[Conferences and Events]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Original Musings]]></category>

		<guid isPermaLink="false">http://kenyerrid.com/?p=284</guid>
		<description><![CDATA[I was at the inaugural Hack3rcon last year, and had an absolute blast. The quality of the speakers was fantastic, and this year they are raising the bar again. Dave Kennedy (R3L1k), Martin Bos (purehate), Adrian Crenshaw (Irongeek), Keith Pachulski (Sec0ps), and Boris Sverdlik (JadedSecurity), <a style="text-decoration:none;" href="http://kenyerrid.com/index.php/2011/10/05/hack3rcon-ii-charleston-west-virginia-oct-21-23/" rel="nofollow">[...]</a>]]></description>
			<content:encoded><![CDATA[<p>I was at the inaugural Hack3rcon last year, and had an absolute blast.  The quality of the speakers was fantastic, and this year they are raising the bar again.  Dave Kennedy (R3L1k), Martin Bos (purehate), Adrian Crenshaw (Irongeek), Keith Pachulski (Sec0ps), and Boris Sverdlik (JadedSecurity), as well as a number of other established security professionals are scheduled to speak.</p>
<p>The price is incredibly reasonable (it is Charleston, West Virginia), and a portion of the proceeds will be going to Hackersforcharity.org.  Come see what I am fussing about, and while you are there, check out DualCore in concert!</p>
<p>Thanks to the 304Geeks and Hackers For Charity for putting on this awesome regional conference!  For more information, visit http://www.hack3rcon.org.</p>
<img src="http://feeds.feedburner.com/~r/KenYerrid/~4/snEZO3Bxg38" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://kenyerrid.com/index.php/2011/10/05/hack3rcon-ii-charleston-west-virginia-oct-21-23/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://kenyerrid.com/index.php/2011/10/05/hack3rcon-ii-charleston-west-virginia-oct-21-23/</feedburner:origLink></item>
		<item>
		<title>Why do we continually blame the “user” for a lack of security awareness? – A Polite Rant</title>
		<link>http://feedproxy.google.com/~r/KenYerrid/~3/fLffbAhPiiE/</link>
		<comments>http://kenyerrid.com/index.php/2011/10/05/why-do-we-continually-blame-the-user-for-a-lack-of-security-awareness-a-polite-rant/#comments</comments>
		<pubDate>Wed, 05 Oct 2011 20:39:32 +0000</pubDate>
		<dc:creator>K0nsp1racy</dc:creator>
				<category><![CDATA[Featured Articles]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Original Musings]]></category>
		<category><![CDATA[Security Governance]]></category>

		<guid isPermaLink="false">http://kenyerrid.com/?p=272</guid>
		<description><![CDATA[Why do we continually blame the “user” for a lack of security awareness? Coming back from one of the most successful information security conferences in quite some time, it was difficult (but not impossible) to find something that needed improvement. I was confused and disappointed <a style="text-decoration:none;" href="http://kenyerrid.com/index.php/2011/10/05/why-do-we-continually-blame-the-user-for-a-lack-of-security-awareness-a-polite-rant/" rel="nofollow">[...]</a>]]></description>
			<content:encoded><![CDATA[<p>Why do we continually blame the “user” for a lack of security awareness?<br />
Coming back from one of the most successful information security conferences in quite some time, it was difficult (but not impossible) to find something that needed improvement.  I was confused and disappointed in the number of presentations that I attended that made statements to the effect of:</p>
<p>•	Users are dumb!<br />
•	We need to tell our users to stop clicking <expletive>!<br />
•	There is no patch for user stupidity!</p>
<p>All of this talk got me to thinking.  Who is really failing here?  Who are the ones that are truly the dumb ones?  As an information security professional, I am disappointed in the percentage of mouthpieces and/or practitioners that fail to grasp the basic tenets of how communication works.  You see, like so many things, many of us suffer from the failure to effectively communicate the problem statement, accept criticism as an opportunity to improve, and –most of all—the failure to communicate.  It is driving me nuts!  </p>
<p>Quite simply, when your “user” clicks a hyperlink in a phishing message, we fall back on the yearly compliance tutorials, likely invented in response to the Melissa and Loveletter worms of 1999 and 2000, respectively.  We sit back in our arrogant and condescending voice and say our training was not adhered to; that ‘user’ is dumb!  Folks, it is 2011, and the problem has not gone away.  Perhaps the payload has changed, as we now have advanced persistent threats (whatever that is), trojans, and rootkits.  However, the vector remains IDENTICAL, and has for over a decade.  We need a new approach, and we need to rethink how we address our (dumb) ‘users’.</p>
<p>I do not claim to know about every person’s specific scenario; however, I am an expense to my organization.  I hemorrhage money from the company’s bottom line profits as a necessary evil to prevent the company from hemorrhaging larger amounts of money at the hands of lawyers and regulatory bodies.  To imply that we are in a position to be condescending to anyone within the organization is absolutely, positively ridiculous.  To imply, infer, or simply think that a ‘user’ as simply a ‘user’ is foolish.  They are a partner.  Their actions dictate a large portion of whether you are the pigeon or the proverbial statue.  Yes, the term ‘user’ is compact, making for perfect slang on a PowerPoint deck or tweet.  But to have to speak of being condescending to the hand that feeds you is incredibly arrogant.</p>
<p>Perhaps I am in the minority here; however, after listening to speaker after speaker talk about security as a ‘we’ versus ‘them’ scenario, I am quite certain that we cannot, and will not secure our environment through a tug of war or battle of attrition.  According to Kumaraguru, Sheng, Acquisti, Cranor, &#038; Hong (2010), our customers look to us to perform three concurrent and complementary tactics to mitigate threats (i.e. phishing message, etc.):  </p>
<p>1.	Silently and transparently remove it<br />
2.	Simplistically communicate/warn the customers of it<br />
3.	Train and communicate to the customers so that they can identify variations of it</p>
<p>So much of our focus as practitioners is on silently and transparently removing threats through automated devices such as firewalls, IDS/IPS, etc.  The vendors (also a popular target in conferences) are marketing these directly to the people in the trenches.  Vendors also have identified the opportunity to communicate/warn customers in a simplistic manner.  For evidence, look at the green address bar in the browser.  Unfortunately, the underlying protocol is broken, but hey, it is in fact simple.  Mission accomplished.</p>
<p>If you notice the last tactic, this is the one that we fall flat on our face about in my opinion.  We do yearly compliance training using canned presentations.  We simply check the box, year after year, and expect a different outcome.  While I am highly encouraged by the work of folks like Dave Kennedy’s Social Engineer’s Toolkit, providing the tools is simply not enough.  We need to use these tools in everyday work and drive these types of training and awareness to the masses.  Furthermore, we need to provide a consistent and repeatable framework on what the threats are, how they can be mitigated via awareness training, and provide support for organizations to implement the recommendations within the framework.  </p>
<p>Rather than sitting back and launching a tirade about the educational competency of our stakeholders, while the collective community continues to hemorrhage like a stuffed pig over vectors and methods that are over a decade old, a number of us are seeking to do something about this vacuum of information.  Of course this is blatant self-promotion for the Security Awareness Training Framework working group that is located at http://groups.google.com/group/SATF-workinggroup, but if you could recognize this, then why can’t we do a better job of recognizing phishing messages?  </p>
<p>References<br />
Kumaraguru, P., Sheng, S., Acquisti, A., Cranor, L. F., &#038; Hong, J. (2010). Teaching Johnny not to fall for phish. ACM Transactions on Internet Technology , 10 (2), 1-31.</p>
<img src="http://feeds.feedburner.com/~r/KenYerrid/~4/fLffbAhPiiE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://kenyerrid.com/index.php/2011/10/05/why-do-we-continually-blame-the-user-for-a-lack-of-security-awareness-a-polite-rant/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://kenyerrid.com/index.php/2011/10/05/why-do-we-continually-blame-the-user-for-a-lack-of-security-awareness-a-polite-rant/</feedburner:origLink></item>
		<item>
		<title>Is your organization overlooking the total cost of offshoring?</title>
		<link>http://feedproxy.google.com/~r/KenYerrid/~3/0tkJPhj7nXM/</link>
		<comments>http://kenyerrid.com/index.php/2011/09/18/is-your-organization-overlooking-the-total-cost-of-offshoring/#comments</comments>
		<pubDate>Sun, 18 Sep 2011 15:23:18 +0000</pubDate>
		<dc:creator>K0nsp1racy</dc:creator>
				<category><![CDATA[Featured Articles]]></category>
		<category><![CDATA[Technology in Business]]></category>
		<category><![CDATA[national security]]></category>
		<category><![CDATA[offswhoring]]></category>

		<guid isPermaLink="false">http://kenyerrid.com/?p=269</guid>
		<description><![CDATA[This morning I was reading a new report that seems to have provided additional evidence of some of my suspicions regarding the total cost of offshoring decisions for information technology initiatives. Written by the Intelligence and National Security Alliance, the new report suggests (while in <a style="text-decoration:none;" href="http://kenyerrid.com/index.php/2011/09/18/is-your-organization-overlooking-the-total-cost-of-offshoring/" rel="nofollow">[...]</a>]]></description>
			<content:encoded><![CDATA[<p>This morning I was reading a new report that seems to have provided additional evidence of some of my suspicions regarding the total cost of offshoring decisions for information technology initiatives.  Written by the Intelligence and National Security Alliance, the <a href="https://images.magnetmail.net/images/clients/INSA/attach/INSA_CYBER_INTELLIGENCE_2011.pdf" target="_blank">new report</a> suggests (while in the context of the U.S. Government) that there may be hidden consequences of outsourcing and offshoring decisions, where “potential adversaries can easily insert themselves into our logistical chains” (Intelligence and National Security Alliance, 2011, p. 6).</p>
<p>Overlaying the backdrop of operations logistical risk of national security over the speed and proliferation of privatized offshoring decisions, I cannot help but wonder if the net result of the individual and systemic chase for higher short-term profits has resulted in the overall weakening of the corporation’s sustainability. In other words—once again—have our executives have placed greed and short term profit margin over long term growth and stability?  Of course, not every offshoring decision is a poor one; and periodicals like the Harvard Business Review and the Wall Street Journal may highlight case studies of successful offshoring and business process outsourcing initiatives.  The point I am trying to make is consistent with many others:  Perform the due diligence necessary to account for shifts in geopolitical and diplomatic climates, and include information privacy and legal perspectives into the business decision.</p>
<p>In closing the loop, the organization should feel comfortable enough in the capabilities of their information security management to include these critical resources in the earliest stages of the due diligence.  In addition, the information security management must continue to bridge the gap between their technical expertise and leadership with the needs of the business.  Therefore, the message to future information security managers and trusted advisors is one of balance between tech and true business acumen.</p>
<p>What are your thoughts?  Email me at ken at kenyerrid dawt com.</p>
<p>References<br />
Intelligence and National Security Alliance. (2011). Cyber intelligence: Setting the landscape for an emerging discipline. Arlington: Intelligence and National Security Alliance.</p>
<img src="http://feeds.feedburner.com/~r/KenYerrid/~4/0tkJPhj7nXM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://kenyerrid.com/index.php/2011/09/18/is-your-organization-overlooking-the-total-cost-of-offshoring/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://kenyerrid.com/index.php/2011/09/18/is-your-organization-overlooking-the-total-cost-of-offshoring/</feedburner:origLink></item>
		<item>
		<title>Feedback From Social-Engineer.org Podcast with Kevin Mitnick</title>
		<link>http://feedproxy.google.com/~r/KenYerrid/~3/THH3rYmPz5U/</link>
		<comments>http://kenyerrid.com/index.php/2011/09/16/feedback-from-social-engineer-org-podcast-with-kevin-mitnick/#comments</comments>
		<pubDate>Fri, 16 Sep 2011 19:54:48 +0000</pubDate>
		<dc:creator>K0nsp1racy</dc:creator>
				<category><![CDATA[Featured Articles]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Original Musings]]></category>
		<category><![CDATA[Recommended Reading]]></category>
		<category><![CDATA[Ghost in the Wires]]></category>
		<category><![CDATA[Kevin Mitnick]]></category>

		<guid isPermaLink="false">http://kenyerrid.com/?p=260</guid>
		<description><![CDATA[This morning, I was listening to the Social-Engineer.org podcast with a special interview with Kevin Mitnick. It has been suggested that I was trolling Kevin, that I had a personal problem with Kevin, or that I hated Kevin and/or was jealous of him. This is <a style="text-decoration:none;" href="http://kenyerrid.com/index.php/2011/09/16/feedback-from-social-engineer-org-podcast-with-kevin-mitnick/" rel="nofollow">[...]</a>]]></description>
			<content:encoded><![CDATA[<p>This morning, I was listening to the <a href="http://www.social-engineer.org/podcast/" target="_blank">Social-Engineer.org podcast</a> with a special interview with Kevin Mitnick.  It has been suggested that I was trolling Kevin, that I had a personal problem with Kevin, or that I hated Kevin and/or was jealous of him.  This is simply not accurate.  In my <a href="http://kenyerrid.com/index.php/2011/08/19/why-kevin-mitnick-missed-a-golden-opportunity-to-advance-the-profession-and-why-i-am-angry-about-it" target="_blank">blog post</a>, I state that, </p>
<blockquote><p>“Unfortunately, some people feel they are simply far too important to pay it forward, too busy to bother with the little fish that wants to learn, too intelligent to ever be wrong, and too self-centered to share the spotlight with the community. I can name a handful of people that fit these categories, and unfortunately, many of them have the lectern.”</p></blockquote>
<p>It is unfortunate that there were a handful of people that would jump to the conclusion that I was grouping Kevin into that group.  Trust me, the people that are in this group have earned their place, and I do not feel that Kevin Mitnick is in that place by any stretch.  As Kevin correctly noted in the interview with the SE.org crew, I have never met or interacted with Kevin directly, and would only have a limited perspective based on online interactions.</p>
<p>I picked up <a href="http://www.amazon.com/Ghost-Wires-Adventures-Worlds-Wanted/dp/0316037702/ref=sr_1_1?s=books&#038;ie=UTF8&#038;qid=1316202400&#038;sr=1-1" target="_blank">Ghost in the Wires</a> while on vacation in Seattle last week, as I really needed a break from reading about <a href="http://www.amazon.com/Decoding-Virtual-Dragon-Evolutions-Information/dp/B001AATF5K/ref=sr_1_1?s=books&#038;ie=UTF8&#038;qid=1316202463&#038;sr=1-1" target="_blank">Chinese Information Warfare theory</a> from Tim Thomas.  I have to admit, I am absolutely hooked on the book, and Kevin deserves all of the success and exposure that he is receiving.  If you have happened to be holding back on the book thinking it was going to be strictly about whistling launch codes or at a technical level different than your own, I would strongly encourage you to reconsider.  The book is completely accessible; in fact, Kevin goes out of his way to explain things in layperson terms.  The aspect of the book that I am particularly impressed with is in his description of the emotions and the vulnerability he shares with the reader throughout the book.  Kevin is a guy who has been the statue far more than the pigeon, and for him to convey that level of openness and honesty is admirable. </p>
<p>So, to set the record straight for anyone that is still confused and cares…  I do not have a grudge against Kevin Mitnick by any stretch.  In fact, I hope I have the chance to meet him in person at <a href="http://www.derbycon.com" target="_blank">Derbycon</a> for what I hope is the beginning of a long term friendship.  Furthermore, I think that Kevin said it best in his interview with Chris, Dave, and Jim regarding people trolling that only has limited interaction with Kevin or others people in the community (rather than paraphrase the comments, listen to it here).  I can only imagine how difficult it is to manage others’ expectations, particularly strangers.  </p>
<p>Finally…  If Kevin and or others in the community felt I was trying to undermine or troll on Kevin’s success with his book, I sincerely apologize.  I can assure you that my intention with my blog post was strictly related to the opportunity to share the love and throw a bone to the entire security community.  At times, I have been critical to Kevin’s tweets and notices of book signings (even comparing the marketing strategy to *shudders* Gregory D. Evans of Ligatt Security) but completely understand Marketing 101, and do not blame him for it.  </p>
<img src="http://feeds.feedburner.com/~r/KenYerrid/~4/THH3rYmPz5U" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://kenyerrid.com/index.php/2011/09/16/feedback-from-social-engineer-org-podcast-with-kevin-mitnick/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://kenyerrid.com/index.php/2011/09/16/feedback-from-social-engineer-org-podcast-with-kevin-mitnick/</feedburner:origLink></item>
		<item>
		<title>Why Kevin Mitnick Missed a Golden Opportunity to Advance the Profession, and Why I Am Angry About It</title>
		<link>http://feedproxy.google.com/~r/KenYerrid/~3/DZp4MB4qFnw/</link>
		<comments>http://kenyerrid.com/index.php/2011/08/19/why-kevin-mitnick-missed-a-golden-opportunity-to-advance-the-profession-and-why-i-am-angry-about-it/#comments</comments>
		<pubDate>Fri, 19 Aug 2011 15:22:59 +0000</pubDate>
		<dc:creator>K0nsp1racy</dc:creator>
				<category><![CDATA[Featured Articles]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Original Musings]]></category>

		<guid isPermaLink="false">http://kenyerrid.com/?p=257</guid>
		<description><![CDATA[Today, I am a little off-center, and some have questioned why I have so much venom in my words on Twitter regarding Kevin Mitnick. Since explaining my actions in 140 character morsels is less than effective, I thought that I would take some time and <a style="text-decoration:none;" href="http://kenyerrid.com/index.php/2011/08/19/why-kevin-mitnick-missed-a-golden-opportunity-to-advance-the-profession-and-why-i-am-angry-about-it/" rel="nofollow">[...]</a>]]></description>
			<content:encoded><![CDATA[<p>Today, I am a little off-center, and some have questioned why I have so much venom in my words on Twitter regarding Kevin Mitnick.  Since explaining my actions in 140 character morsels is less than effective, I thought that I would take some time and explain my rationale.  For starters, I do not have a personal axe to grind with Kevin Mitnick or anyone else in the information security profession for that matter.  Kevin has never directed any words or actions my way in an attempt to make me feel inferior.  Secondly, my words and actions are not driven out of jealousy or spite.  As I have said on numerous occasions, I want everyone in information security to succeed.  There is plenty of room on the mountaintop for all of us, and I would encourage others to question their motives when choosing to attack someone in the community.  Of course, some people deserve to be pushed off the mountain on the basis of their actions and the shortcuts they have taken to achieve their level of notoriety.  </p>
<p>I want to believe that Kevin Mitnick is a nice person.  I have never personally met him, although I have heard of his story.   His book, Ghost in the Wires, is purportedly an expose of his life.  For months now, I have been watching tweets about the book (self promotional) being released.  I see self-promotional tweets about book signings and appearances.  Quite honestly, it reminds me of the marketing that Mr. Gregory D. Evans executes.  I do not fault the guy for wanting to make a living, and it is not my place to judge his motivation.  But last night, Kevin Mitnick was given a golden opportunity to help change perspectives on the state of information security by appearing on The Colbert Report.  Information security is an industry that still suffers from a perception of being unstructured, unprofessional outlaws and elitists.  Despite all of the wonderful things that we do for each other and others in the world, this success stories are still not being communicated effectively.  It is sad.  </p>
<p>So rather than talking about being in solitary confinement for a year, and sitting at home on Valentine’s Day—statements that further extends the stereotypes of security professionals being nerds with no life— the statements that have me fired up is the ones where he had the opportunity to pay it forward to the community.  Clearly, there was an opportunity for Kevin Mitnick to avoid bragging about hacking companies with their permission (again self-gratifying), and talk about how he had made mistakes in the past, served his time, and now spends his time along with millions in the community, in protecting companies from the bad guys.  Simple wordplay, but powerful nonetheless.  Mitnick squandered that chance. </p>
<p>The security community does so many wonderful things that do not see the light of day.  Take the mission of Hackers for Charity and Infosec without Borders, look at the response to Gattaca’s wife or BarKode, whose medical battles have brought the entire community together for a common, charitable purpose.  How about the story of Stacy Thayer and her husband in Vegas this year, getting her purse stolen, and the community giving her money and anything else she needed.  The way people came together was nothing short of awesome for the entire community.  But these stories remain guarded in the community, and trickle out at an anemic pace.  </p>
<p>We need to make a better effort of paying our successes forward and telling community success stories.  $Deity knows that the mainstream media picks up on every breach, misstep, and acronym to instill fear, uncertainty, and doubt.  The community, collectively, is impacted by each failure, either directly, or by association.  While we continue to propagate negative energy, other than the mainstream media, who do you think is laughing at us?  We are not nearly as powerful as individuals; just ask hacktivist groups and state-sponsored information warfare collectives.  For every person that thinks selfishly like Kevin Mitnick did last night, there are thousands of $country hackers that are content with standing shoulder to shoulder and fighting a collective information skirmish.  Guess what, they are winning.  </p>
<p>What is the solution?  What is the call to action?  The message I am trying to get across is one where we stop thinking like the front man of a rock band and more like the drummer.  Our profession will never be sexy in the traditional sense, so why allow personal ego to interfere with advancing the industry?  Look at the people in the community that teach others, that inspire, that actually listen to all comments and criticisms, and actually respond.  The people I respect the most in the community have their heads on straight, are content with sharing the burden and the spotlight, and learn, as well as teach.  Unfortunately, some people feel they are simply far too important to pay it forward, too busy to bother with the little fish that wants to learn, too intelligent to ever be wrong, and too self-centered to share the spotlight with the community.  I can name a handful of people that fit these categories, and unfortunately, many of them have the lectern.  The only way that our industry will advance is by transforming the people that get the opportunity and making sure that they hit the marks that are good for the community, not just for themselves.</p>
<img src="http://feeds.feedburner.com/~r/KenYerrid/~4/DZp4MB4qFnw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://kenyerrid.com/index.php/2011/08/19/why-kevin-mitnick-missed-a-golden-opportunity-to-advance-the-profession-and-why-i-am-angry-about-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://kenyerrid.com/index.php/2011/08/19/why-kevin-mitnick-missed-a-golden-opportunity-to-advance-the-profession-and-why-i-am-angry-about-it/</feedburner:origLink></item>
		<item>
		<title>What’s in a Name?   If you are Labeled a Charlatan, then it is a lot!</title>
		<link>http://feedproxy.google.com/~r/KenYerrid/~3/o4IXLbftbJE/</link>
		<comments>http://kenyerrid.com/index.php/2011/08/08/whats-in-a-name-if-you-are-labeled-a-charlatan-then-it-is-a-lot/#comments</comments>
		<pubDate>Mon, 08 Aug 2011 23:38:13 +0000</pubDate>
		<dc:creator>K0nsp1racy</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Original Musings]]></category>
		<category><![CDATA[Security Governance]]></category>
		<category><![CDATA[Attrition.org]]></category>
		<category><![CDATA[BlackHat]]></category>
		<category><![CDATA[Charlatan]]></category>
		<category><![CDATA[DEFCON]]></category>
		<category><![CDATA[Derbycon]]></category>
		<category><![CDATA[Gregory Evans]]></category>
		<category><![CDATA[Ligatt]]></category>
		<category><![CDATA[Security BSides]]></category>

		<guid isPermaLink="false">http://kenyerrid.com/?p=252</guid>
		<description><![CDATA[Information security perception is highly dependent on practitioner reputation. If a practitioner is foolish enough to plagiarize or damage the industry, sites like attrition.org are there to label the person as a charlatan. Recently, there were some rumors floating around about infamous, alleged charlatan Gregory <a style="text-decoration:none;" href="http://kenyerrid.com/index.php/2011/08/08/whats-in-a-name-if-you-are-labeled-a-charlatan-then-it-is-a-lot/" rel="nofollow">[...]</a>]]></description>
			<content:encoded><![CDATA[<p>Information security perception is highly dependent on practitioner reputation.  If a practitioner is foolish enough to plagiarize or damage the industry, sites like <a href="http://attrition.org/errata/charlatan/" target="_blank">attrition.org</a> are there to label the person as a charlatan.  Recently, there were some rumors floating around about infamous, alleged charlatan <a href="http://gregorydevans.com/" target="_blank">Gregory D. Evans</a> being unable to attend the major conferences (<a href="http://www.blackhat.com" target="_blank">Black Hat</a>, <a href="http://www.defcon.org" target="_blank">DEF CON</a> and <a href="http://www.securitybsides.com/w/page/12194156/FrontPage" target="_blank">BSides</a>) in Las Vegas, NV.  Some have suggested that there were some financial constraints that prevented this.  As I have noted in the past, I question the personal damage that the alleged actions of Evans has done to me.  One thing I have observed though is that people are passionate about their disdain for alleged charlatans like Gregory D. Evans.  </p>
<p>I suppose I am being less critical, maybe I am being more open-minded.  The fact of the matter is that until I hear something from the horse’s mouth, I am willing to allow my own opinions to remain my own, and not let other’s influence them.  In other words, I believe people that are labeled as charlatans should have their day in court, among a jury of their peers (parallels to Mr. Evans litigious history is intended).  I thought the industry had made some real progress by having an open dialog with Mr. Evans and some of his most vocal critics on the <a href="http://www.isdpodcast.com" target="_blank">ISDPodcast</a>.  Unfortunately, much of the banter was circular and defensive, and very little was tangibly accomplished.  However, the fact that Evans appeared on his own volition was a huge step for him and the industry at large.  I agree that ‘distractions’ such as the accusations levied against Evans and others cast a certain aura of uncertainty within the industry.  I believe that more of these discussions should occur and the “defendant” should have a chance to clear his or her name.  Lastly, I would hate to see financial considerations serve as a deterrent from a labeled charlatan.</p>
<p>What I am proposing, beginning with my own offer of donation to <a href="http://www.derbycon.com" target="_blank">Derbycon</a>, is to remove finances from the ability to have an opportunity to have an alleged charlatan clear his or her name.  Maybe we can call it Charlatan’s Purse (tongue in cheek).  The idea would be to allow members of the information security community an opportunity to contribute money to a fund to allow the alleged charlatan to defend him or herself in a public forum.  Think of it as a public defender’s office for alleged charlatans.  Let’s remove the barriers to cleaning up the industry and push through the stalemate!</p>
<p>Let’s take Gregory D. Evans as an example.  As of 8/8/2011, a roundtrip, 1st class ticket from Atlanta, Georgia to Louisville, Kentucky would cost under $900.  Under my philosophy, a communal donation of less than $2,000 would get Evans a room, food (or Cristal), and a flight.  The community would have the opportunity to interact with Mr. Evans.  Fair trade?  I think so.</p>
<p>Of course, certain logistical parameters would need to be established.  I propose that an alleged charlatan should be treated respectfully, yet critically.  I am not opposed to pre-formulating interview questions.  The important thing in my mind is to free the alleged named charlatan from any barriers to help clear his or her name.  </p>
<p>If you have any comments or ideas, please mention something on Twitter using hashtag #charlatanspurse</p>
<img src="http://feeds.feedburner.com/~r/KenYerrid/~4/o4IXLbftbJE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://kenyerrid.com/index.php/2011/08/08/whats-in-a-name-if-you-are-labeled-a-charlatan-then-it-is-a-lot/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://kenyerrid.com/index.php/2011/08/08/whats-in-a-name-if-you-are-labeled-a-charlatan-then-it-is-a-lot/</feedburner:origLink></item>
		<item>
		<title>DerbyCon – Louisville, Kentucky:  September 30th – October 2nd, 2011</title>
		<link>http://feedproxy.google.com/~r/KenYerrid/~3/qjPMnjvA6Hw/</link>
		<comments>http://kenyerrid.com/index.php/2011/08/03/derbycon-louisville-kentucky-september-30th-october-2nd-2011/#comments</comments>
		<pubDate>Wed, 03 Aug 2011 15:09:23 +0000</pubDate>
		<dc:creator>K0nsp1racy</dc:creator>
				<category><![CDATA[Conferences and Events]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Bourbon]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[Derbycon]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Irongeek]]></category>
		<category><![CDATA[Purehate]]></category>
		<category><![CDATA[ReL1K]]></category>

		<guid isPermaLink="false">http://kenyerrid.com/?p=248</guid>
		<description><![CDATA[I am getting excited about this conference. Even though it is in its first year of existance, DerbyCon has the potential to be the premier conference East of the Mississippi River this fall. Organized by my friends Dave Kennedy (ReL1K), Martin Bos (PureHate), Adrian Crenshaw <a style="text-decoration:none;" href="http://kenyerrid.com/index.php/2011/08/03/derbycon-louisville-kentucky-september-30th-october-2nd-2011/" rel="nofollow">[...]</a>]]></description>
			<content:encoded><![CDATA[<p>I am getting excited about this conference.  Even though it is in its first year of existance, <a href="http://www.derbycon.com" target="_blank">DerbyCon</a> has the potential to be the premier conference East of the Mississippi River this fall.  Organized by my friends Dave Kennedy (ReL1K), Martin Bos (PureHate), Adrian Crenshaw (IronGeek), and Nick Hitchcock (nick8ch), the event has lined up some of the industry&#8217;s best and brightest.  For a full list, check their <a href="http://www.derbycon.com/speakers/" target="_blank">speaker page</a>.</p>
<p>The event will feature some intense training opportunities at a very reasonable rate by some of the core people in the community.  Last I checked, there were some slots open in a handful of the courses.  After hours, the nerdcore rap group DualCore will be performing at the DerbyCon after party.  The bottom line, you should defintely check this conference out if you have the hall pass.  </p>
<img src="http://feeds.feedburner.com/~r/KenYerrid/~4/qjPMnjvA6Hw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://kenyerrid.com/index.php/2011/08/03/derbycon-louisville-kentucky-september-30th-october-2nd-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://kenyerrid.com/index.php/2011/08/03/derbycon-louisville-kentucky-september-30th-october-2nd-2011/</feedburner:origLink></item>
	</channel>
</rss>

