<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" gd:etag="W/&quot;A0QHSXw9eCp7ImA9WhVXFU8.&quot;"><id>tag:blogger.com,1999:blog-3872102380305691396</id><updated>2012-04-15T18:35:38.260-04:00</updated><category term="control system security" /><category term="SCADA" /><category term="risk analysis" /><category term="lightning" /><category term="scary" /><title>Real-time Information Security Analysis</title><subtitle type="html">A blog about Information Security, Emerging Technology, Collaboration, What's next?, and their effects on each other</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://infoseccollaboration.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://infoseccollaboration.blogspot.com/" /><author><name>RealtimeInfosec</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>11</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/Real-timeInformationSecurityAnalysis" /><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="real-timeinformationsecurityanalysis" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">Real-timeInformationSecurityAnalysis</feedburner:emailServiceId><feedburner:feedburnerHostname xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">http://feedburner.google.com</feedburner:feedburnerHostname><entry gd:etag="W/&quot;DkMFSH4zfyp7ImA9WhZQFkg.&quot;"><id>tag:blogger.com,1999:blog-3872102380305691396.post-404657766215519268</id><published>2011-04-24T10:13:00.002-04:00</published><updated>2011-04-24T10:13:39.087-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-04-24T10:13:39.087-04:00</app:edited><title>Advanced Leaders</title><content type="html">&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;o:OfficeDocumentSettings&gt;   &lt;o:RelyOnVML/&gt;   &lt;o:AllowPNG/&gt;  &lt;/o:OfficeDocumentSettings&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:WordDocument&gt;   &lt;w:View&gt;Normal&lt;/w:View&gt;   &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:TrackMoves/&gt;   &lt;w:TrackFormatting/&gt;   &lt;w:PunctuationKerning/&gt;   &lt;w:ValidateAgainstSchemas/&gt;   &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:DoNotPromoteQF/&gt;   &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:Compatibility&gt;    &lt;w:BreakWrappedTables/&gt;    &lt;w:SnapToGridInCell/&gt;    &lt;w:WrapTextWithPunct/&gt;    &lt;w:UseAsianBreakRules/&gt;    &lt;w:DontGrowAutofit/&gt;    &lt;w:SplitPgBreakAndParaMark/&gt;    &lt;w:EnableOpenTypeKerning/&gt;    &lt;w:DontFlipMirrorIndents/&gt;    &lt;w:OverrideTableStyleHps/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathPr&gt;    &lt;m:mathFont m:val="Cambria Math"/&gt;    &lt;m:brkBin m:val="before"/&gt;    &lt;m:brkBinSub m:val="&amp;#45;-"/&gt;    &lt;m:smallFrac m:val="off"/&gt;    &lt;m:dispDef/&gt;    &lt;m:lMargin m:val="0"/&gt;    &lt;m:rMargin m:val="0"/&gt;    &lt;m:defJc m:val="centerGroup"/&gt;    &lt;m:wrapIndent m:val="1440"/&gt;    &lt;m:intLim m:val="subSup"/&gt;    &lt;m:naryLim m:val="undOvr"/&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"
  DefSemiHidden="true" DefQFormat="false" DefPriority="99"
  LatentStyleCount="267"&gt;   &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;   &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;   &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;   &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;   &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;   &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;   &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;   &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"
   UnhideWhenUsed="false" Name="Table Grid"/&gt;   &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;   &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;   &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;   &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;   &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;   &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;   &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;   &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;   &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
 {mso-style-name:"Table Normal";
 mso-tstyle-rowband-size:0;
 mso-tstyle-colband-size:0;
 mso-style-noshow:yes;
 mso-style-priority:99;
 mso-style-parent:"";
 mso-padding-alt:0in 5.4pt 0in 5.4pt;
 mso-para-margin-top:0in;
 mso-para-margin-right:0in;
 mso-para-margin-bottom:10.0pt;
 mso-para-margin-left:0in;
 line-height:115%;
 mso-pagination:widow-orphan;
 font-size:11.0pt;
 font-family:"Calibri","sans-serif";
 mso-ascii-font-family:Calibri;
 mso-ascii-theme-font:minor-latin;
 mso-hansi-font-family:Calibri;
 mso-hansi-theme-font:minor-latin;
 mso-bidi-font-family:"Times New Roman";
 mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt; &lt;![endif]--&gt;  &lt;br /&gt;
&lt;div class="MsoNormal"&gt;Increasingly, leaders want:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in;"&gt;&lt;span&gt;&lt;span&gt;1.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Not just to run an organization effectively, but to change the surrounding system as well. &lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in;"&gt;&lt;span&gt;&lt;span&gt;2.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Not just improve hospital performance, but improve overall health. &lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in;"&gt;&lt;span&gt;&lt;span&gt;3.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Not just fix troubled schools, but change patterns in communities that lead children to under-perform. &lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="text-indent: -0.25in;"&gt;&lt;span&gt;&lt;span&gt;4.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Not just fix a problem, like a broken financial system, but change the culture.&lt;/div&gt;&lt;div class="MsoNormal"&gt;Still, advanced leaders dance to their own tune. &lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in;"&gt;&lt;span&gt;&lt;span&gt;1.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;They find opportunities for change in the cracks in the system, in the white space where nothing is written.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in;"&gt;&lt;span&gt;&lt;span&gt;2.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Rather than try to change the establishment all at once, they fill gaps, create new alliances, and forge new pathways. For example, Advanced leaders:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in;"&gt;&lt;span&gt;&lt;span&gt;3.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Work in complex systems where authority is diffuse or divided.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in;"&gt;&lt;span&gt;&lt;span&gt;4.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Break mental boundaries and challenge established patterns.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in;"&gt;&lt;span&gt;&lt;span&gt;5.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;They think not just outside the box but outside the building. &lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in;"&gt;&lt;span&gt;&lt;span&gt;6.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;They know that cities are not City Hall, health takes more than hospitals, and education is more than schools.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in;"&gt;&lt;span&gt;&lt;span&gt;7.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Advanced leaders use the tools of the future. They don't want society's leftovers, or what I call spare change; they want the best and latest ideas and technology to make real change. &lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast"&gt;The surface has barely been scratched for the use of technology to improve society. Consider the potential for data analytics to spot disease outbreaks, mobile phones to monitor health, or interactive websites to bring personalized learning to disadvantaged areas.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3872102380305691396-404657766215519268?l=infoseccollaboration.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="related" href="http://blogs.hbr.org/innovations-in-health-care/2011/02/the-traits-of-advanced-leaders.html" title="Advanced Leaders" /><link rel="replies" type="application/atom+xml" href="http://infoseccollaboration.blogspot.com/feeds/404657766215519268/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3872102380305691396&amp;postID=404657766215519268" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/404657766215519268?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/404657766215519268?v=2" /><link rel="alternate" type="text/html" href="http://infoseccollaboration.blogspot.com/2011/04/advanced-leaders.html" title="Advanced Leaders" /><author><name>RealtimeInfosec</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;DEABRXc7eCp7ImA9Wx9WGE8.&quot;"><id>tag:blogger.com,1999:blog-3872102380305691396.post-3656739110494778796</id><published>2011-01-23T18:52:00.000-05:00</published><updated>2011-01-23T18:52:34.900-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-01-23T18:52:34.900-05:00</app:edited><title>The Most Terrifying Video You'll Ever See - Power Grid Cyber Security Edition</title><content type="html">If you have ever seen this video: &lt;a bitly="BITLY_PROCESSED" href="http://www.youtube.com/watch?v=zORv8wwiadQ"&gt;The Most Terrifying Video You'll  Ever See&lt;/a&gt;, it definitely has a catchy title that makes you want to click and watch. Regardless of your views on the topic it's covering (global climate change), it's an interesting topic and stimulates debate from all sides.&lt;br /&gt;
&lt;br /&gt;
I could not help but notice the similarities between that topic and the increasingly popular power grid cyber attack scenario argument. With the discovery of Stuxnet in 2010 and it's "game changing" functionality and components, that which was previously theoretically possible is now a reality.&lt;br /&gt;
&lt;br /&gt;
Using the same diagram as the author (Wonderingmind42, Greg)&amp;nbsp; in this video, I constructed a similar diagram for a Grid Cyber Attack (GCA).&amp;nbsp; The other acronym in the diagram is BES (Bulk Electric System).&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a bitly="BITLY_PROCESSED" href="http://2.bp.blogspot.com/_6x7-mu69saY/TTyziogjrHI/AAAAAAAAAD4/VE8ueQlSIx0/s1600/photo.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="239" src="http://2.bp.blogspot.com/_6x7-mu69saY/TTyziogjrHI/AAAAAAAAAD4/VE8ueQlSIx0/s320/photo.JPG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
First, a GCA is defined as a Stuxnet-like sophisticated piece of malware that infiltrates the US power grid at multiple locations, through multiple Utilities and is designed to have very specific impacts. Hypothetically, this scenario includes impacts such as wide spread cascading power outages in various parts of the country and many prolonged outages lasting weeks or months.&lt;br /&gt;
&lt;br /&gt;
So let's define the diagrams components for clarity:&lt;br /&gt;
&lt;br /&gt;
&lt;ol&gt;&lt;li&gt;On the left hand side is a false/true. This is whether or not you believe the above type of scenario happening is likely to be false or likely to be true. &lt;/li&gt;
&lt;li&gt;Across the top, the columns represent action taken. Either we take action "yes" or we do not take action "no" to do all that we can to prevent this type of cyber attack scenario from occurring.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;The 4 boxes in the middle represent the consequences of taking the actions (and depend on the false and true rows).&amp;nbsp;&lt;/li&gt;
&lt;/ol&gt;Now let's define the consequences of taking action in more detail:&lt;br /&gt;
&lt;br /&gt;
Box 1 (upper left corner) represents taking an action (yes) and this sort of grid cyber attack occurring being false. The consequences of this action would likely result (using a worst case scenario) in a lot of unnecessary costs to all Utilities that chose to do all they can to defend against this scenario. "All that they can" is hard to define and left up to the decision makers of each participating Utility. This would likely translate into decreased profits which would translate into things like layoffs and a sector wide decline in profitability. - We spent a whole lot of money for nothing and now we might look a little silly and impact the lives of people we are forced to lay off.&lt;br /&gt;
&lt;br /&gt;
Box 2 (lower left corner) represents taking an action (yes) and this sort of grid cyber attack scenario occurring turning out to be true. The consequences of this action would result in the same costs as listed above but the Utilities being able to either stop outright or retain reliability and integrity of the power grid against the described cyber attack. - We paid for it, but we stopped it. yay! :)&lt;br /&gt;
&lt;br /&gt;
Box 3 (upper right corner) represents not taking any action (no) and this sort of grid cyber attack scenario not occurring. The consequences of this inaction are "business as usual" and everyone is happy yay! :)&lt;br /&gt;
&lt;br /&gt;
Box 4 (lower right corner) represents not taking any action (no) and this sort of grid cyber attack scenario turning out to be true. The consequences&amp;nbsp; of this inaction are the "worst case scenario" coming true. Significant human impacts. Loss of hundreds of millions of dollars but more than likely, hundreds of billions of dollars due to wide spread cascading power outages lasting weeks to months across the U.S. Major impacts include public safety, health, operational, economic, and political. Widespread panic and chaos not unlikely.&lt;br /&gt;
&lt;br /&gt;
So like the author of&amp;nbsp; "The Most Terrifying Video You'll Ever See", one must ask the question, is it worth it? Are we doing enough, fast enough?&amp;nbsp; These are no doubt, difficult questions with difficult, complex answers. &lt;br /&gt;
&lt;br /&gt;
Should these decisions be a cost/benefit analysis and financially motivated when they deal with such high impact consequences?&lt;br /&gt;
&lt;br /&gt;
Some other interesting related topics include the precautionary principle: &lt;a bitly="BITLY_PROCESSED" href="http://en.wikipedia.org/wiki/Precautionary_principle"&gt;The Precautionary Principle&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
What do you think?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;h1 id="watch-headline-title" style="padding-bottom: 8px;"&gt;&lt;span class="" dir="ltr" id="eow-title" style="vertical-align: top;" title="The Most Terrifying Video You'll Ever See"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/h1&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3872102380305691396-3656739110494778796?l=infoseccollaboration.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://infoseccollaboration.blogspot.com/feeds/3656739110494778796/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3872102380305691396&amp;postID=3656739110494778796" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/3656739110494778796?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/3656739110494778796?v=2" /><link rel="alternate" type="text/html" href="http://infoseccollaboration.blogspot.com/2011/01/most-terrifying-video-youll-ever-see.html" title="The Most Terrifying Video You'll Ever See - Power Grid Cyber Security Edition" /><author><name>RealtimeInfosec</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_6x7-mu69saY/TTyziogjrHI/AAAAAAAAAD4/VE8ueQlSIx0/s72-c/photo.JPG" height="72" width="72" /><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;DUAGSHc5fip7ImA9Wx9QGE4.&quot;"><id>tag:blogger.com,1999:blog-3872102380305691396.post-8955692578241884680</id><published>2010-12-31T18:22:00.000-05:00</published><updated>2010-12-31T18:22:09.926-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-12-31T18:22:09.926-05:00</app:edited><title>A Briefly Scoped Look at 2010, Risk Management and Cyber Security Strategy</title><content type="html">&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:WordDocument&gt;   &lt;w:View&gt;Normal&lt;/w:View&gt;   &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:TrackMoves/&gt;   &lt;w:TrackFormatting/&gt;   &lt;w:PunctuationKerning/&gt;   &lt;w:ValidateAgainstSchemas/&gt;   &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:DoNotPromoteQF/&gt;   &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:Compatibility&gt;    &lt;w:BreakWrappedTables/&gt;    &lt;w:SnapToGridInCell/&gt;    &lt;w:WrapTextWithPunct/&gt;    &lt;w:UseAsianBreakRules/&gt;    &lt;w:DontGrowAutofit/&gt;    &lt;w:SplitPgBreakAndParaMark/&gt;    &lt;w:EnableOpenTypeKerning/&gt;    &lt;w:DontFlipMirrorIndents/&gt;    &lt;w:OverrideTableStyleHps/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathPr&gt;    &lt;m:mathFont m:val="Cambria Math"/&gt;    &lt;m:brkBin m:val="before"/&gt;    &lt;m:brkBinSub m:val="&amp;#45;-"/&gt;    &lt;m:smallFrac m:val="off"/&gt;    &lt;m:dispDef/&gt;    &lt;m:lMargin m:val="0"/&gt;    &lt;m:rMargin m:val="0"/&gt;    &lt;m:defJc m:val="centerGroup"/&gt;    &lt;m:wrapIndent m:val="1440"/&gt;    &lt;m:intLim m:val="subSup"/&gt;    &lt;m:naryLim m:val="undOvr"/&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"
  DefSemiHidden="true" DefQFormat="false" DefPriority="99"
  LatentStyleCount="267"&gt;   &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;   &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;   &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;   &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;   &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;   &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;   &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;   &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"
   UnhideWhenUsed="false" Name="Table Grid"/&gt;   &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;   &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;   &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;   &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;   &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;   &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;   &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;   &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;   &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
 {mso-style-name:"Table Normal";
 mso-tstyle-rowband-size:0;
 mso-tstyle-colband-size:0;
 mso-style-noshow:yes;
 mso-style-priority:99;
 mso-style-parent:"";
 mso-padding-alt:0in 5.4pt 0in 5.4pt;
 mso-para-margin-top:0in;
 mso-para-margin-right:0in;
 mso-para-margin-bottom:10.0pt;
 mso-para-margin-left:0in;
 line-height:115%;
 mso-pagination:widow-orphan;
 font-size:11.0pt;
 font-family:"Calibri","sans-serif";
 mso-ascii-font-family:Calibri;
 mso-ascii-theme-font:minor-latin;
 mso-hansi-font-family:Calibri;
 mso-hansi-theme-font:minor-latin;
 mso-bidi-font-family:"Times New Roman";
 mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt; &lt;![endif]--&gt;  &lt;br /&gt;
&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Risk Management&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;2010 has been a banner year for highly publicized, yet real-world proof of concepts for a number of threats. Some of which we have known about for years.’&lt;/div&gt;&lt;div class="MsoListParagraph"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;&lt;span&gt;o&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;We started the year in January with the Google “Aurora” APT hack.See: &lt;a bitly="BITLY_PROCESSED" href="http://en.wikipedia.org/wiki/Operation_Aurora"&gt;Operation Aurora&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;&lt;span&gt;o&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Then in June we had Stuxnet which was as one author put it “malware beamed back from 5 years in the future” to raise the bar on any previously known APT. See: &lt;a bitly="BITLY_PROCESSED" href="http://www.symantec.com/connect/blogs/w32stuxnet-dossier"&gt;Symantec Stuxnet Dossier&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;&lt;span&gt;o&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Also in June, but progressively coming to light for the rest of the year we had Wikileaks. A classic case of the insider threat and data loss. See: &lt;a bitly="BITLY_PROCESSED" href="http://www.wired.com/threatlevel/2010/06/leak/"&gt;Wired.com Wikileaks Story (Original)&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoListParagraph"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;Some questions, without the answers for now…&lt;/div&gt;&lt;div class="MsoListParagraph"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Are we as industries doing enough, in a timely manner, to keep up with the pace of the myriad of threats? The threat landscape seems to be evolving faster now than anytime in recent history. Isn’t it our job to make sure that company Executives are aware of the risks associated with these threats in a timely manner so we as cyber/information/risk Analysts can have the tools to make the right decisions to best defend our sensitive information and networks in an equally timely manner? I realize the time component is an important concept here. When is it timely enough? Is being proactive in identifying the threat before we see a proof of concept in the real-world an unrealistic business goal?&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 1in;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Are we (as industries) really proactive with regards to our overall information/cyber security strategies? Or are we reactive? I realize these are loaded questions and can be looked at from a number of perspectives. For example, compared to industry peers, to cyber security budgets from years past, to other industries etc. Most organizations are in business to provide shareholder value and good returns, as well as provide quality products/services to customers and thus the business case for (increased) cyber security is sometimes a tough one to make. But of all years, 2010 certainly made this an easier case to make, I think you would agree.&lt;/div&gt;&lt;div class="MsoListParagraph"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;In 2011 will industry be implementing controls to help us defend against threats that came to light in 2010 that were no doubt occurring in 2009 and before? Yes.&lt;/div&gt;&lt;div class="MsoListParagraph"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;In 2011 I suspect industry will have a “heightened interest” in analyzing controls to prevent insider threats &amp;amp; data loss prevention (e.g. Wikileaks), and super-APT’s&lt;span&gt;&amp;nbsp; &lt;/span&gt;(e.g. Stuxnet) with 2012 business cases, while the bad guys are moving on to new techniques.&lt;/div&gt;&lt;div class="MsoListParagraph"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;I realize to a certain extent this is a perpetual game of catch-up. Is this a fact of life or something we can control? I think a little of both.&lt;span&gt;&amp;nbsp; &lt;/span&gt;I know we don’t live in an ideal world or business environment for that matter, so my point is not that we need to do everything “now” or be able predict the future, but I do think industry should strive to continually perform threat and risk analysis/management in as close to a real-time (preferably proactive) way as possible within known constraints. I pose another question; do we really think we are doing “enough” now, fast enough?&lt;b&gt; &lt;/b&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;How much more would your 2011 cyber security budgets be if your organization had an APT, Stuxnet, or Wikileaks type incident this past year? &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;I can’t state it any better than Gartner Analyst John Pescatore from the recently released Gartner document titled “The Gartner 2011 Information Security Scenario”:&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Key Issue: How should information security programs evolve to deal with changes in business processes, information technology and threats?&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;We are at a cusp very similar to what we faced 20 years ago as mainframe and departmental computing were attacked by personal computing. Consumerization and cloud are breaking IT processes, and by extension IT security processes, in a very similar manner. At the same time, cybercrime (financially motivated, targeted threats) are moving even more quickly to exploit this breakage. Similarly, legislators are moving more rapidly to "help" by introducing new laws requiring new forms of reporting. The movement toward consumerization and cloud computing has a lot of promise to both increase user productivity and decrease the cost of IT delivery. &lt;b&gt;However, if some of those savings aren't used to &lt;u&gt;keep security ahead of the threat&lt;/u&gt;, many businesses will face financially significant security incidents that more than consume the benefits.&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3872102380305691396-8955692578241884680?l=infoseccollaboration.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://infoseccollaboration.blogspot.com/feeds/8955692578241884680/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3872102380305691396&amp;postID=8955692578241884680" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/8955692578241884680?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/8955692578241884680?v=2" /><link rel="alternate" type="text/html" href="http://infoseccollaboration.blogspot.com/2010/12/briefly-scoped-look-at-2010-risk.html" title="A Briefly Scoped Look at 2010, Risk Management and Cyber Security Strategy" /><author><name>RealtimeInfosec</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;CEIFQX04cCp7ImA9Wx9QFE0.&quot;"><id>tag:blogger.com,1999:blog-3872102380305691396.post-2320542869231105434</id><published>2010-12-26T17:28:00.000-05:00</published><updated>2010-12-26T17:28:30.338-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-12-26T17:28:30.338-05:00</app:edited><title>Book Review/Notes: Psychology of Intelligence Analysis</title><content type="html">&lt;a bitly="BITLY_PROCESSED" href="https://docs.google.com/viewer?a=v&amp;amp;pid=explorer&amp;amp;chrome=true&amp;amp;srcid=0B6CzJyF3D4gFY2I0MTcxYTItNmExMy00YjRhLTkzMTgtN2VjNWU1ZDJjN2Zl&amp;amp;hl=en&amp;amp;authkey=CP_er4EP"&gt;Psychology of Intelligence Analysis Book notes on Google Docs&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a bitly="BITLY_PROCESSED" href="http://www.amazon.com/Psychology-Intelligence-Analysis-Richards-Heuer/dp/0160590353"&gt;Amazon&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a bitly="BITLY_PROCESSED" href="https://www.cia.gov/library/center-for-the-study-of-intelligence/csi-publications/books-and-monographs/psychology-of-intelligence-analysis/index.html"&gt;CIA&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3872102380305691396-2320542869231105434?l=infoseccollaboration.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://infoseccollaboration.blogspot.com/feeds/2320542869231105434/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3872102380305691396&amp;postID=2320542869231105434" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/2320542869231105434?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/2320542869231105434?v=2" /><link rel="alternate" type="text/html" href="http://infoseccollaboration.blogspot.com/2010/12/book-reviewnotes-psychology-of.html" title="Book Review/Notes: Psychology of Intelligence Analysis" /><author><name>RealtimeInfosec</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;CkYNRnszfyp7ImA9WxBXE00.&quot;"><id>tag:blogger.com,1999:blog-3872102380305691396.post-2130696171254287526</id><published>2010-01-23T21:29:00.000-05:00</published><updated>2010-01-23T21:29:57.587-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-23T21:29:57.587-05:00</app:edited><title>Project Grey Goose Report on Critical Infrastructure: Attacks, Actors, and Emerging Threats</title><content type="html">Fascinating, informative new report from GreyLogic examining the state of Cyber Security on the US critical infrastructure. Attacks, Actors, and Emerging Threats&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3872102380305691396-2130696171254287526?l=infoseccollaboration.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="related" href="http://www.scribd.com/doc/25550091/Proj-Grey-Goose-report-on-Critical-Infrastructure-Attacks-Actors-and-Emerging-Threats" title="Project Grey Goose Report on Critical Infrastructure: Attacks, Actors, and Emerging Threats" /><link rel="replies" type="application/atom+xml" href="http://infoseccollaboration.blogspot.com/feeds/2130696171254287526/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3872102380305691396&amp;postID=2130696171254287526" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/2130696171254287526?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/2130696171254287526?v=2" /><link rel="alternate" type="text/html" href="http://infoseccollaboration.blogspot.com/2010/01/project-grey-goose-report-on-critical.html" title="Project Grey Goose Report on Critical Infrastructure: Attacks, Actors, and Emerging Threats" /><author><name>RealtimeInfosec</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;CE4DQX47fSp7ImA9WxBXEE4.&quot;"><id>tag:blogger.com,1999:blog-3872102380305691396.post-5869129824425270240</id><published>2010-01-20T19:16:00.000-05:00</published><updated>2010-01-20T19:16:10.005-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-20T19:16:10.005-05:00</app:edited><title>Google Hack Attack Was Ultra Sophisticated, New Details Show</title><content type="html">&lt;div class="MsoNormal" style="margin-bottom: 12pt;"&gt;&lt;b&gt;&lt;span style="color: #1f497d;"&gt;Google Hack Attack Was Ultra Sophisticated, New Details  Show&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="color: #1f497d;"&gt;&lt;a href="http://www.blogger.com/redir.aspx?C=7c49cf8ba4744ef1b87ba877aa4f832a&amp;amp;URL=http%3a%2f%2fwww.wired.com%2fthreatlevel%2f2010%2f01%2foperation-aurora%2f" target="_blank"&gt;http://www.wired.com/threatlevel/2010/01/operation-aurora/&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;span style="color: #1f497d; font-family: Symbol;"&gt;&lt;span&gt;·&lt;span style="font-family: 'Times New Roman'; font-size-adjust: none; font-size: 7pt; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color: #1f497d;"&gt;Although the initial attack occurred when company  employees visited a &lt;b&gt;malicious website&lt;/b&gt;, researchers are still trying to  determine if this occurred through a URL sent to employees by e-mail, instant  messaging or through some other method, such as Facebook or other social  networking sites.&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;span style="color: #1f497d; font-family: Symbol;"&gt;&lt;span&gt;·&lt;span style="font-family: 'Times New Roman'; font-size-adjust: none; font-size: 7pt; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color: #1f497d;"&gt;Once the user visited the malicious site, &lt;b&gt;their  Internet Explorer browser was exploited to download an array of malware&lt;/b&gt; to  their computer automatically and transparently. The programs unloaded seamlessly  and silently onto the system&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;span style="color: #1f497d; font-family: Symbol;"&gt;&lt;span&gt;·&lt;span style="font-family: 'Times New Roman'; font-size-adjust: none; font-size: 7pt; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color: #1f497d;"&gt;“The &lt;b&gt;initial piece of code was shell code encrypted  three times and that activated the exploit&lt;/b&gt;, Then it &lt;b&gt;executed downloads  from an external machine that dropped the first piece of binary on the host.&lt;/b&gt;  That download was also &lt;b&gt;encrypted&lt;/b&gt;. The &lt;b&gt;encrypted binary packed itself  into a couple of executables that were also encrypted&lt;/b&gt;.”&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;span style="color: #1f497d; font-family: Symbol;"&gt;&lt;span&gt;·&lt;span style="font-family: 'Times New Roman'; font-size-adjust: none; font-size: 7pt; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color: #1f497d;"&gt;One of the &lt;b&gt;malicious programs opened a remote backdoor  to the computer, establishing an encrypted covert channel that masqueraded as an  SSL connection to avoid detection&lt;/b&gt;. &lt;b&gt;This allowed the attackers ongoing  access to the computer and to use it as a “beachhead” into other parts of the  network to search for login credentials, intellectual property and whatever else  they were seeking.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;span style="color: #1f497d; font-family: Symbol;"&gt;&lt;span&gt;·&lt;span style="font-family: 'Times New Roman'; font-size-adjust: none; font-size: 7pt; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color: #1f497d;"&gt;Although security firm iDefense told Threat Level on  Tuesday that the &lt;a href="http://www.blogger.com/redir.aspx?C=7c49cf8ba4744ef1b87ba877aa4f832a&amp;amp;URL=http%3a%2f%2fwww.wired.com%2fthreatlevel%2f2010%2f01%2fgoogle-hack-attack%2f" target="_blank"&gt;&lt;span style="color: #1f497d; text-decoration: none;"&gt;Trojan used in  some of the attacks&lt;/span&gt;&lt;/a&gt; was the Trojan.Hydraq, Alperovitch &lt;b&gt;says the  malware he examined was not previously known by any anti-virus  vendors.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;span style="color: #1f497d; font-family: Symbol;"&gt;&lt;span&gt;·&lt;span style="font-family: 'Times New Roman'; font-size-adjust: none; font-size: 7pt; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color: #1f497d;"&gt;iDefense also said that a vulnerability in Adobe’s Reader  and Acrobat applications was used to gain access to some of the 34 breached  companies. &lt;b&gt;The hackers sent e-mail to targets that carried malicious PDF  attachments.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span style="color: #1f497d;"&gt;Aurora and  Botnets&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="color: #1f497d;"&gt;McAfee Worldwide Chief  Technology Officer, George Kurtz, McAfee Senior Vice President, Stuart McClure,  and McAfee Senior Director, Greg Brown, will team up to share everything you  need to know about two white-hot security topics: Botnets and Aurora - the day-0  vulnerability that impacted Google and several other companies last week. Jan  21st at 2:pm EST &lt;/span&gt;&lt;span class="MsoHyperlink"&gt;&lt;a href="http://www.blogger.com/redir.aspx?C=7c49cf8ba4744ef1b87ba877aa4f832a&amp;amp;URL=http%3a%2f%2fwww.linkedin.com%2fredirect%3furl%3dhttps%253A%252F%252Fwww1%252Egotomeeting%252Ecom%252Fregister%252F541112360%26urlhash%3d0eb0" target="_blank" title="New window will open"&gt;https://www1.gotomeeting.com/register/541112360&lt;/a&gt;&lt;/span&gt;&lt;span style="color: #1f497d;"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3872102380305691396-5869129824425270240?l=infoseccollaboration.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="related" href="http://www.wired.com/threatlevel/2010/01/operation-aurora/" title="Google Hack Attack Was Ultra Sophisticated, New Details Show" /><link rel="replies" type="application/atom+xml" href="http://infoseccollaboration.blogspot.com/feeds/5869129824425270240/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3872102380305691396&amp;postID=5869129824425270240" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/5869129824425270240?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/5869129824425270240?v=2" /><link rel="alternate" type="text/html" href="http://infoseccollaboration.blogspot.com/2010/01/google-hack-attack-was-ultra.html" title="Google Hack Attack Was Ultra Sophisticated, New Details Show" /><author><name>RealtimeInfosec</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;A0cGRXs6fip7ImA9WxdVE04.&quot;"><id>tag:blogger.com,1999:blog-3872102380305691396.post-85034528850758346</id><published>2008-07-16T22:15:00.002-04:00</published><updated>2008-07-17T19:57:04.516-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-07-17T19:57:04.516-04:00</app:edited><title>Cool Infosec link</title><content type="html">This  &lt;a href="http://www.netvibes.com/mailforlen#virus"&gt;Infosecportal&lt;/a&gt; is a great idea, a portal for relevant Information Security, threats, and risks data from a wealth of reputable sources. Enjoy.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3872102380305691396-85034528850758346?l=infoseccollaboration.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://infoseccollaboration.blogspot.com/feeds/85034528850758346/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3872102380305691396&amp;postID=85034528850758346" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/85034528850758346?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/85034528850758346?v=2" /><link rel="alternate" type="text/html" href="http://infoseccollaboration.blogspot.com/2008/07/cool-infosec-link.html" title="Cool Infosec link" /><author><name>RealtimeInfosec</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;D0ABRHs4cCp7ImA9WxdVE0Q.&quot;"><id>tag:blogger.com,1999:blog-3872102380305691396.post-2592085642847441394</id><published>2008-07-16T22:10:00.003-04:00</published><updated>2008-07-18T11:42:35.538-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-07-18T11:42:35.538-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="control system security" /><category scheme="http://www.blogger.com/atom/ns#" term="risk analysis" /><category scheme="http://www.blogger.com/atom/ns#" term="SCADA" /><title>Comment on Understanding Risk in Control System Environments</title><content type="html">&lt;div style="text-align: left;"&gt;In response to an interesting post on the Digital Bond website &lt;a href="http://www.digitalbond.com/index.php/2008/07/16/understanding-risk-in-the-dcs-enviroment/"&gt;here&lt;/a&gt;  I wrote the following:&lt;br /&gt;&lt;br /&gt;&lt;p class="commenticon"&gt; &lt;strong&gt;Comment&lt;/strong&gt; from &lt;strong&gt;chris&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;Time:&lt;/strong&gt; July 16, 2008, 9:59 pm&lt;/p&gt; &lt;p&gt;Quality post. Perhaps the concept of Corporate Social Responsibility (CSR) can be more formally inserted into the risk analysis. In CSR, the triple bottom line of social, financial, and environmental performance is tracked along with the traditional primary financial focus. For the vast majority of corporations practicing CSR today , the environmental and social metrics are then rolled up into the financial tying it all back to a $ amount. However, for purposes of this risk assessment it would appear that using all three indicators individually may assist in a more sound albeit less quantitative consequence definition. To add to that, many organizations in scope of this type of risk assessment are government run (water management districts for example) so their focus is not always tied to making a profit, or even wise use of funds i speculate. So for utility X with a financial focus, a power plant down leading to wide spread power outages may be worst case scenario from a financial (reputation + lost revenue + other impacts caused from power outage) perspective, while for water management district Y with a social (public service/ public impact) focus it is wide spread flooding from a dam malfunction. For a nuclear plant it is affect/loss of human life etc.&lt;/p&gt; &lt;p&gt;Perhaps keeping the three CSR areas of social, financial, and environmental separate is a good idea when defining consequence. Define worst case scenarios in each of the three areas and agree that there are events that you know you can’t quantify ahead of time, but you would never want to see happen in each area as well. Luckily, for those “you never want to see” events, government regulations often address but if you’re an organization you *should* do whatever is in your power to prevent them as well.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3872102380305691396-2592085642847441394?l=infoseccollaboration.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://infoseccollaboration.blogspot.com/feeds/2592085642847441394/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3872102380305691396&amp;postID=2592085642847441394" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/2592085642847441394?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/2592085642847441394?v=2" /><link rel="alternate" type="text/html" href="http://infoseccollaboration.blogspot.com/2008/07/comment-on-understanding-risk-in.html" title="Comment on Understanding Risk in Control System Environments" /><author><name>RealtimeInfosec</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;Ak4BSH0-fSp7ImA9WxdWGE8.&quot;"><id>tag:blogger.com,1999:blog-3872102380305691396.post-6279490551338760629</id><published>2008-07-11T21:53:00.005-04:00</published><updated>2008-07-11T22:15:59.355-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-07-11T22:15:59.355-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="scary" /><category scheme="http://www.blogger.com/atom/ns#" term="lightning" /><title>Watch out for lightning!</title><content type="html">from: &lt;a href="http://www.flickr.com/photos/i_love_the_slow_loris/2646424593/"&gt; http://www.flickr.com/photos/i_love_the_slow_loris/2646424593/&lt;/a&gt;&lt;br /&gt;&lt;object width="320" height="266" class="BLOG_video_class" id="BLOG_video-9079bbb4e4e0a678" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"&gt;&lt;param name="movie" value="http://www.youtube.com/get_player"&gt;
&lt;param name="bgcolor" value="#FFFFFF"&gt;
&lt;param name="allowfullscreen" value="true"&gt;
&lt;param name="flashvars" value="flvurl=http://v21.nonxt1.googlevideo.com/videoplayback?id%3D9079bbb4e4e0a678%26itag%3D5%26app%3Dblogger%26ip%3D0.0.0.0%26ipbits%3D0%26expire%3D1340118430%26sparams%3Did,itag,ip,ipbits,expire%26signature%3D5E5BD0CE833C456062766DF2B42BEB9A3EFF2E9B.2C8A6D362F9805332CC402FD844026AFDC9441E1%26key%3Dck1&amp;amp;iurl=http://video.google.com/ThumbnailServer2?app%3Dblogger%26contentid%3D9079bbb4e4e0a678%26offsetms%3D5000%26itag%3Dw160%26sigh%3DsHNpLfvwPGTv4ySLB1P5huBxlfY&amp;amp;autoplay=0&amp;amp;ps=blogger"&gt;
&lt;embed src="http://www.youtube.com/get_player" type="application/x-shockwave-flash"
width="320" height="266" bgcolor="#FFFFFF"
flashvars="flvurl=http://v21.nonxt1.googlevideo.com/videoplayback?id%3D9079bbb4e4e0a678%26itag%3D5%26app%3Dblogger%26ip%3D0.0.0.0%26ipbits%3D0%26expire%3D1340118430%26sparams%3Did,itag,ip,ipbits,expire%26signature%3D5E5BD0CE833C456062766DF2B42BEB9A3EFF2E9B.2C8A6D362F9805332CC402FD844026AFDC9441E1%26key%3Dck1&amp;iurl=http://video.google.com/ThumbnailServer2?app%3Dblogger%26contentid%3D9079bbb4e4e0a678%26offsetms%3D5000%26itag%3Dw160%26sigh%3DsHNpLfvwPGTv4ySLB1P5huBxlfY&amp;autoplay=0&amp;ps=blogger"
allowFullScreen="true" /&gt;&lt;/object&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3872102380305691396-6279490551338760629?l=infoseccollaboration.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="enclosure" type="video/mp4" href="http://www.blogger.com/video-play.mp4?contentId=9079bbb4e4e0a678&amp;type=video%2Fmp4" length="0" /><link rel="replies" type="application/atom+xml" href="http://infoseccollaboration.blogspot.com/feeds/6279490551338760629/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3872102380305691396&amp;postID=6279490551338760629" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/6279490551338760629?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/6279490551338760629?v=2" /><link rel="alternate" type="text/html" href="http://infoseccollaboration.blogspot.com/2008/07/watch-out-for-lightning.html" title="Watch out for lightning!" /><author><name>RealtimeInfosec</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;A0cFRHY_eyp7ImA9WxdWF04.&quot;"><id>tag:blogger.com,1999:blog-3872102380305691396.post-3045655412357019281</id><published>2007-11-02T18:43:00.002-04:00</published><updated>2008-07-10T21:16:55.843-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-07-10T21:16:55.843-04:00</app:edited><title>Vacation - A week to reflect, relax, enjoy</title><content type="html">I had some vacation days left for 2007 so I decided to use them all together and take a week off rather than a day here and a day there for the rest of the year, besides they were use em or lose em days...I tried to coordinate getting out of Miami with some friends but it was just not possible so I stayed local and just woke up each day without a real plan (other than my To-Do list which has grown into a multi-tabbed, colored, faceted MS Excel spreadsheet ). On this list I have a plethora of thoughts, ideas, dreams, and wishes to share a few (Move to Italy, Take Golf, Tennis, Italian and Salsa lessons, test drive a new car, a book list, you get the idea..) as you can see the list has no real entrance requirements.  I also did a a lot of other little things during my vacation that I just don't have or make the time to do during a normal week like a random drive to no where just for the fun of it or sit out on my balcony and enjoy a sunny day looking at Biscayne Bay drinking a glass of fresh limeade, ok fine it was from a carton...&lt;br /&gt;&lt;br /&gt;One thing that happened to me prior to going on vacation was a request from a respected executive of a vendor my company does business with asking me if I would be interested in writing a guest blog entry on his blog. I was extremely surprised and flattered by the request. I am excited at this opportunity and have to approach it correctly. When I return back to work on 11/5 I will seek approval to follow through on this...&lt;br /&gt;&lt;br /&gt;Here are my latest fav websites:&lt;br /&gt;&lt;br /&gt;Italy&lt;br /&gt;&lt;br /&gt;http://howtoitaly.typepad.com/howtoitaly/&lt;br /&gt;&lt;br /&gt;Fitness&lt;br /&gt;&lt;br /&gt;http://exercise.about.com/cs/forprofessionals/a/personaltrainer.htm&lt;br /&gt;&lt;br /&gt;Miami Real Estate&lt;br /&gt;&lt;br /&gt;http://blog.miamicondoinvestments.com/&lt;br /&gt;&lt;br /&gt;Music&lt;br /&gt;&lt;br /&gt;http://www.bbc.co.uk/radio1/&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3872102380305691396-3045655412357019281?l=infoseccollaboration.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://infoseccollaboration.blogspot.com/feeds/3045655412357019281/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3872102380305691396&amp;postID=3045655412357019281" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/3045655412357019281?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/3045655412357019281?v=2" /><link rel="alternate" type="text/html" href="http://infoseccollaboration.blogspot.com/2007/11/vacation-week-to-reflect-relax-enjoy.html" title="Vacation - A week to reflect, relax, enjoy" /><author><name>RealtimeInfosec</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total></entry><entry gd:etag="W/&quot;AkAEQ385cCp7ImA9WB9XEk0.&quot;"><id>tag:blogger.com,1999:blog-3872102380305691396.post-3506463742153111153</id><published>2007-06-17T23:33:00.000-04:00</published><updated>2007-11-04T15:38:22.128-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-11-04T15:38:22.128-05:00</app:edited><title>Information sharing</title><content type="html">I recently started reading a book called "Wikinomics" how mass collaboration changes everything. I found the book to be extremely interesting. While reading this book, several websites are cited as examples to topics covered, this led me to a number of "social networking" sites including some social news &amp; social bookmarking websites. Social networking is as it sounds, in this example websites where people go to socialize and network. The most popular of which are Myspace.com and Facebook.com. Social bookmarking was new to me and this is basically sites that offer a downloadable plug-in for your web brwoser that allow you to 'tag' sites or save sites you find interesting to a central location for anyone else out there in the WWW world who has also inctalled the same plugin. The most popular of these sites is del.icio.us (just type that into your web browser, it works.) I have since stumbled across a whole host of websites that provide a wealth of extremely useful, interesting, sometimes fascinating and even funny information from topics across the board. I thought I would share the most interesting sites I have come across up to this point. I hope you enjoy them as well!&lt;br /&gt;&lt;br /&gt;http://del.icio.us/&lt;br /&gt;http://wikinomics.com/ &amp;amp; the blog&lt;br /&gt;http://digg.com/&lt;br /&gt;http://slashdot.org/&lt;br /&gt;http://blogs.sun.com/jonathan/&lt;br /&gt;http://technorati.com/&lt;br /&gt;http://www.thesimpledollar.com/&lt;br /&gt;http://www.lifeoptimizer.org/2007/06/06/106-tips-to-become-a-&lt;br /&gt;master-connector/&lt;br /&gt;http://www.writingcave.com/a-herd-of-buffaloes-a-pride-of-&lt;br /&gt;lions-and-a-lonely-crocodile/&lt;br /&gt;http://video.google.com/videoplay?docid=-2757699799&lt;br /&gt;528285056&lt;br /&gt;http://www.ted.com/index.php/talks/view/id/129&lt;br /&gt;http://money.cnn.com/galleries/2007/moneymag/0706/&lt;br /&gt;gallery.success_stories.moneymag/index.html&lt;br /&gt;http://www.frugallawstudent.com/2007/05/29/massive&lt;br /&gt;-personal-finance-resource-list/&lt;br /&gt;http://ocw.mit.edu/OcwWeb/web/courses/courses/index.htm&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3872102380305691396-3506463742153111153?l=infoseccollaboration.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://infoseccollaboration.blogspot.com/feeds/3506463742153111153/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3872102380305691396&amp;postID=3506463742153111153" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/3506463742153111153?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3872102380305691396/posts/default/3506463742153111153?v=2" /><link rel="alternate" type="text/html" href="http://infoseccollaboration.blogspot.com/2007/06/information-sharing.html" title="Information sharing" /><author><name>RealtimeInfosec</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total></entry></feed>

