<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
<channel>
<title>Secure Value</title>
<link>http://www.secure-value.com/douglasdavidson/</link>
<description>Secure Value focuses on information security issues that impact the value of start up and growth oriented small and medium businesses.</description>
<language>en-US</language>
<lastBuildDate>Thu, 19 Jan 2012 15:13:03 -0500</lastBuildDate>
<generator>http://www.typepad.com/</generator>

<docs>http://www.rssboard.org/rss-specification</docs>
<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/SecureValue" /><feedburner:info uri="securevalue" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>SecureValue</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
<title>Will Information Security &amp; Privacy Compliance Come to This?</title>
<link>http://feedproxy.google.com/~r/SecureValue/~3/5g2zEWXKXjI/will-information-security-privacy-compliance-come-to-this.html</link>
<guid isPermaLink="false">http://www.secure-value.com/douglasdavidson/2012/01/will-information-security-privacy-compliance-come-to-this.html</guid>
<description>Image via Wikipedia Yesterday a client rescheduled a meeting because "the State" showed up to audit their medical operations. The State of Ohio regulators conducts spot visits in this industry on a spontaneous basis. When they come in, typically unannounced, everything stops so that they can conduct their spot audit. "Hi, I'm from the &lt;FTC/HHS/DHS/ETC&gt; and I need to see your log files and your patch management reports ... " Do you think information security and privacy compliance will ever get to that point?</description>
<content:encoded><![CDATA[<p class="zemanta-img" style="margin: 1em; float: right; display: block; width: 161px;"><a href="http://commons.wikipedia.org/wiki/File:Seal_of_Ohio.svg"><img alt="Commonly-displayed artist&#39;s rendering of the 1..." height="151" src="http://upload.wikimedia.org/wikipedia/commons/thumb/f/f3/Seal_of_Ohio.svg/300px-Seal_of_Ohio.svg.png" style="border: medium none; display: block;" width="151" /></a><span class="zemanta-img-attribution">Image via <a href="http://commons.wikipedia.org/wiki/File:Seal_of_Ohio.svg">Wikipedia</a></span></p>
<p>Yesterday a client rescheduled a meeting because &quot;the State&quot; showed up to audit their medical operations.&#0160; The State of Ohio regulators conducts spot visits in this industry on a spontaneous basis.&#0160; When they come in, typically unannounced, everything stops so that they can conduct their spot audit.</p>
<p>&quot;Hi, I&#39;m from the &lt;FTC/HHS/DHS/ETC&gt; and I need to see your log files and your patch management reports ... &quot;</p>
<p>Do you think information security and privacy compliance will ever get to that point?</p>
<p>&#0160;</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" href="http://www.zemanta.com/" title="Enhanced by Zemanta"><img alt="Enhanced by Zemanta" class="zemanta-pixie-img" src="http://img.zemanta.com/zemified_e.png?x-id=95b081ce-b39d-489b-8909-5970bbbdbe2d" style="border: medium none; float: right;" /></a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SecureValue?a=5g2zEWXKXjI:tflGObhos_w:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SecureValue?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SecureValue/~4/5g2zEWXKXjI" height="1" width="1"/>]]></content:encoded>


<category>Secure Value</category>

<dc:creator>Douglas Davidson</dc:creator>
<pubDate>Thu, 19 Jan 2012 15:13:03 -0500</pubDate>

<feedburner:origLink>http://www.secure-value.com/douglasdavidson/2012/01/will-information-security-privacy-compliance-come-to-this.html</feedburner:origLink></item>
<item>
<title>Why should senior management be involved in security decisions? </title>
<link>http://feedproxy.google.com/~r/SecureValue/~3/5yaAT3kEoBs/why-should-senior-management-be-involved-in-security-decisions-.html</link>
<guid isPermaLink="false">http://www.secure-value.com/douglasdavidson/2012/01/why-should-senior-management-be-involved-in-security-decisions-.html</guid>
<description>I am putting the finishing touches on an executive presention for a client. Our finding, after a series of technical tests, a review of their policies and their security administrative compents was that they are generally proactive on securty from a technical perspective but any additional maturation or improvement of their program requires management involvement. I am going to present this to senior management team that has already informed me they don't want to hear that message. This isn't the first time Jacadis has encountered such a situation. Why should senior management be involved in security decisions? At some level...</description>
<content:encoded><![CDATA[<p>I am putting the finishing touches on an executive presention for a client.&#0160; Our finding, after a series of technical tests, a review of their policies and their security administrative compents was that they are generally proactive on securty from a technical perspective but any additional maturation or improvement of their program requires management involvement.</p>
<p>I am going to present this to senior management team that has already informed me they don&#39;t want to hear that message.</p>
<p>This isn&#39;t the first time Jacadis has encountered such a situation.</p>
<p>Why should senior management be involved in security decisions?</p>
<p>At some level security decisions are really risk management decisions and not just technical, information security decisions.&#0160; Even the strongest technical team can&#39;t know the risks, obligations, contracts and mission priorities that senior management brings to the table.&#0160;</p>
<p>Sorry, managers but this isn&#39;t just geeky stuff.</p>
<p>Here is a quick list of five questions that my client&#39;s technical team needs senior management input, involvement and or leadership on:</p>
<ol>
<li>Are we obligated by law or contract to HIPAA?</li>
<li>Are we obligated to PCI?&#0160; Are we exposed in the way we handle crtedit card data? </li>
<li>How long can your business operate with reduced computer facilities?&#0160; Which facilities are most important to the mission? </li>
<li>How will we respond to illegal activity on our network? Attacks from outside? In the event of a breach?</li>
<li>What are our employees permitted to do with social media outside of work hours on their own computers?</li>
</ol>
<p>Are you putting your technical team in a spot where you expect them to protect your business but don&#39;t share with them critical information or involve yourself in their decision making process?&#0160; If you are in a business that is data driven (and which business today isn&#39;t) your lack of involvement will likely ensure a high technical team turnover, raise the possibility that you will have security issues interfere with your business, decrease the resiliency of your business and potentially put at risk vendor and client relationship while also opening your business (and perhaps yourself personally) to legal and regulatory liability.</p>
<p>&#0160;</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" href="http://www.zemanta.com/" title="Enhanced by Zemanta"><img alt="Enhanced by Zemanta" class="zemanta-pixie-img" src="http://img.zemanta.com/zemified_e.png?x-id=610a1199-ad82-49b1-9882-9884bfcda34f" style="border: medium none; float: right;" /></a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SecureValue?a=5yaAT3kEoBs:Qoaz2uVuunU:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SecureValue?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SecureValue/~4/5yaAT3kEoBs" height="1" width="1"/>]]></content:encoded>


<category>Committee Action</category>
<category>Compliance</category>
<category>Continuity Planning</category>
<category>Information Security Basics</category>
<category>Leadership</category>
<category>Risk Management</category>
<category>Secure Value</category>

<dc:creator>Douglas Davidson</dc:creator>
<pubDate>Wed, 18 Jan 2012 11:14:19 -0500</pubDate>

<feedburner:origLink>http://www.secure-value.com/douglasdavidson/2012/01/why-should-senior-management-be-involved-in-security-decisions-.html</feedburner:origLink></item>
<item>
<title> Gap between what employees think and do versus what employers think and do</title>
<link>http://feedproxy.google.com/~r/SecureValue/~3/imZkqwLf5LY/-gap-between-what-employees-think-and-do-versus-what-employers-think-and-do.html</link>
<guid isPermaLink="false">http://www.secure-value.com/douglasdavidson/2011/12/-gap-between-what-employees-think-and-do-versus-what-employers-think-and-do.html</guid>
<description>Last week I gave a Lunch and Learn Presentation to a group of business people and enterpreneurs at the Dublin Chamber of Commerce on Living Securly in a Digital World. Researching the topic for fresh material I tripped across a Unisys study that shows a disturbing gap between what employees and what employers think about data use in the enterprise: While 67% can access non-work-related websites only 44% of employers agree. While 52% of workers say they can store personal data on the company network only 37% of employers agree. Do you have that same perception gap in your company?...</description>
<content:encoded><![CDATA[<p>Last week I gave a Lunch and Learn Presentation to a group of business people and enterpreneurs at the <a class="zem_slink" href="http://en.wikipedia.org/wiki/Dublin_Chamber_of_Commerce" rel="wikipedia" title="Dublin Chamber of Commerce">Dublin Chamber of Commerce</a> on Living Securly in a Digital World.&#0160; <br /><br />Researching the topic for fresh material I tripped across a Unisys study that shows a disturbing gap between what employees and what employers think about data use in the&#0160; enterprise:<br /><br /></p>
<ul>
<li>While 67% can access non-work-related websites only 44% of employers agree.</li>
<li>While 52% of workers say they can store personal data on the company network only 37% of employers agree.</li>
</ul>
<p><strong>Do you have that same perception gap in your company?</strong><br /><br />As an employer it may mean behaviors you don&#39;t want, non-productive sites visited during work time or worse, malware introduced into the company network. As an employer, it may also mean extra storage costs or extremely awkward moments during terminations (can I have my data back?!).<br /><br />As an employee, it may mean a disciplinary action for what you think is approved or allowed behavior.&#0160; And more importantly it might mean loss of personal data an information if you lose or leave your job (or the company closes). <br /><br />It is in the best interests of both sides of this divide to close the gap.</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" href="http://www.zemanta.com/" title="Enhanced by Zemanta"><img alt="Enhanced by Zemanta" class="zemanta-pixie-img" src="http://img.zemanta.com/zemified_e.png?x-id=f2445016-a9e3-4f25-82c2-7c8e6f25e4e9" style="border: medium none; float: right;" /></a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SecureValue?a=imZkqwLf5LY:B-I5LXowLIw:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SecureValue?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SecureValue/~4/imZkqwLf5LY" height="1" width="1"/>]]></content:encoded>


<category>Leadership</category>
<category>Living Securely</category>
<category>Policy</category>
<category>Secure Value</category>
<category>Speaking Engagement</category>

<dc:creator>Douglas Davidson</dc:creator>
<pubDate>Sun, 18 Dec 2011 10:07:41 -0500</pubDate>

<feedburner:origLink>http://www.secure-value.com/douglasdavidson/2011/12/-gap-between-what-employees-think-and-do-versus-what-employers-think-and-do.html</feedburner:origLink></item>
<item>
<title>What life tasks do you do online?</title>
<link>http://feedproxy.google.com/~r/SecureValue/~3/uY0JQAQMOUY/what-life-tasks-do-you-do-online.html</link>
<guid isPermaLink="false">http://www.secure-value.com/douglasdavidson/2011/12/what-life-tasks-do-you-do-online.html</guid>
<description>I am giving a talk to the Dublin Chamber of Commerce this Thursday on Living Securely in a Digital World. As I've started preparing my presentation I've come to realize that almost everything we do or have done in the analog (fancy name for "real world") we can now do in the digital world. I'm going to talk from frmy experience, but I'd like yours as well. Here are some things I do online that used to be real world things for me ... would you share your list? Communicate with friends Search for employees Plan and record my workouts...</description>
<content:encoded><![CDATA[<p>I am giving a talk to the<a href="http://www.nextgendublin.com/index.php?src=events&amp;srctype=detail&amp;category=Upcoming%20Events&amp;refno=183" target="_self"> Dublin Chamber of Commerce this Thursday on Living Securely in a Digital World</a>.&#0160; As I&#39;ve started preparing my presentation I&#39;ve come to realize that almost everything we do or have done in the analog (fancy name for &quot;real world&quot;) we can now do in the digital world.&#0160; I&#39;m going to talk from&#0160; frmy experience, but I&#39;d like yours as well.&#0160; Here are some things I do online that used to be real world things for me ... would you share your list?</p>
<ul>
<li>Communicate with friends</li>
<li>Search for employees</li>
<li>Plan and record my workouts</li>
<li>Plan travel</li>
<li>Maps</li>
<li>Look up recipes</li>
<li>Bank</li>
<li>Invest</li>
<li>Pay bills</li>
<li>Stay informed</li>
<li>Monitor boys homework</li>
<li>Write and publish</li>
</ul><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SecureValue?a=uY0JQAQMOUY:-OdJhBZdBkk:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SecureValue?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SecureValue/~4/uY0JQAQMOUY" height="1" width="1"/>]]></content:encoded>


<category>Living Securely</category>
<category>Secure Value</category>
<category>Speaking Engagement</category>

<dc:creator>Douglas Davidson</dc:creator>
<pubDate>Tue, 13 Dec 2011 11:50:14 -0500</pubDate>

<feedburner:origLink>http://www.secure-value.com/douglasdavidson/2011/12/what-life-tasks-do-you-do-online.html</feedburner:origLink></item>
<item>
<title>When the snow flies &amp; the power dies will the generator do its thing? You sure?</title>
<link>http://feedproxy.google.com/~r/SecureValue/~3/5vG7A7_u_6A/when-the-snow-flies-the-power-dies-will-the-generate-do-its-thing-you-sure.html</link>
<guid isPermaLink="false">http://www.secure-value.com/douglasdavidson/2011/11/when-the-snow-flies-the-power-dies-will-the-generate-do-its-thing-you-sure.html</guid>
<description>Forecast is for some snow tomorrow here in Columbus. One of my clients just last week shared it had taken a couple of months to get maintenance to test the back up generator. They finally went to fire it up to test that it worked and .... nothing. Tried again. Nothing. Their hardware vendor responded quickly. Turns out that the broken part was under warranty but was 48 hours away. The test was conducted on one of those warm sunny days we had before Thanksgiving. We aren't supposed to get much snow tomorrow but you never know here in Ohio....</description>
<content:encoded><![CDATA[<p>Forecast is for some snow tomorrow here in Columbus.&#0160; One of my clients just last week shared it had taken a couple of months to get maintenance to test the back up generator.&#0160; They finally went to fire it up to test that it worked and .... nothing.&#0160; Tried again.&#0160; Nothing.&#0160; Their hardware vendor responded quickly. Turns out that the broken part was under warranty but was 48 hours away.</p>
<p>The test was conducted on one of those warm sunny days we had before Thanksgiving.&#0160; We aren&#39;t supposed to get much snow tomorrow but you never know here in Ohio.&#0160; Had the part failure not been found until it was actually needed the 48 hour shipping wait could have been catastrophic.</p>
<p>Our client did two things right:</p>
<p>1.&#0160; They created a policy calendar.&#0160; Policies should be formal statements of value supported by the routines&#0160; (processes) that must be followed to meet the stated value. Most of the time though policies are dead documents that state something a client would like to do but doesn&#39;t get around to doing.&#0160; My client&#39;s policy calendar lets them manage the normal routines of their &quot;HIPAA year&quot; which operationalizes their compliance.</p>
<p>2.&#0160;&#0160; They actually tested the process.&#0160; The IT Director didn&#39;t take no for an answer as maintenance continued to put his test request off.&#0160;</p>
<p>How are you doing?</p>
<p>Have you operationalized your HIPAA program?</p>
<p>Have you tested your generator, your back up processes and your contingency operations plan?</p>
<p>&#0160;</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SecureValue?a=5vG7A7_u_6A:wXHSCeRZlKU:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SecureValue?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SecureValue/~4/5vG7A7_u_6A" height="1" width="1"/>]]></content:encoded>


<category>Assessments and Tests</category>
<category>Committee Action</category>
<category>Compliance</category>
<category>Continuity Planning</category>
<category>HIPAA</category>
<category>HITECH</category>
<category>Secure Value</category>

<dc:creator>Douglas Davidson</dc:creator>
<pubDate>Tue, 29 Nov 2011 16:36:06 -0500</pubDate>

<feedburner:origLink>http://www.secure-value.com/douglasdavidson/2011/11/when-the-snow-flies-the-power-dies-will-the-generate-do-its-thing-you-sure.html</feedburner:origLink></item>
<item>
<title>Tablets, tablets everywhere .... </title>
<link>http://feedproxy.google.com/~r/SecureValue/~3/qvvA-smXE3Y/tablets-tablets-everywhere.html</link>
<guid isPermaLink="false">http://www.secure-value.com/douglasdavidson/2011/11/tablets-tablets-everywhere.html</guid>
<description>I've been bombed (not spammed because I know the people sending me the emails) with this message from a number of Verizon representatives. Tablets are fast becoming a useful tool in business and our everyday lives. More and more businesses are buying tablets to help streamline workflow and bee more efficient. More and more people are buying tablets for personal use because of their small size, ease of use and their multi-functionality versus a laptop. Tablets bought in the United States: 2010 – 19.5 million 2011 – 54.8 million (proj) 2012 – 103.4 million (proj) 2013 – 154.2 million (proj)...</description>
<content:encoded><![CDATA[<p>I&#39;ve been bombed (not spammed because I know the people sending me the emails) with this message from a number of Verizon representatives.&#0160;</p>
<blockquote>
<p><br /><em>Tablets are fast becoming a useful tool in business and our everyday lives.&#0160; More and more businesses are buying tablets to help streamline workflow and bee more efficient.&#0160; More and more people are buying tablets for personal use because of their small size, ease of use and their multi-functionality versus a laptop.&#0160; </em><br /><br /><em>Tablets bought in the United States:&#0160;&#0160; </em><br />&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160; <br /><em>&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160; 2010 – 19.5 million</em><br /><em>&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160; 2011 – 54.8 million (proj)</em><br /><em>&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160; 2012 – 103.4 million (proj)</em><br /><em>&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160; 2013 – 154.2 million (proj)</em><br /><em>&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160;&#0160; 2014 -&#0160; 208.0 million (proj)</em></p>
</blockquote>
<p><br />Millions of tablets doing work once done behind walls creates a more mobile and more productive (maybe) workforce but it also creates a more vulnerable information system.</p>
<p>Are you finding tablets are a useful addition to your business and personal life?&#0160;</p>
<p>What are you doing to protect your tablet and the information on it?&#0160;</p>
<p>Make sure that is a part of your decision to move your work and personal computing to a tablet form factor.</p>
<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles</legend>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.zdnet.com/blog/mobile-news/who-really-needs-a-stinking-tablet-anyway/5563">Who really needs a stinking tablet, anyway?</a> (zdnet.com)</li>
<li class="zemanta-article-ul-li"><a href="http://mashable.com/2011/11/15/tablets-vs-laptops/">79% of Consumers Crave Tablets Over Laptops</a> (mashable.com)</li>
</ul>
</fieldset>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" href="http://www.zemanta.com/" title="Enhanced by Zemanta"><img alt="Enhanced by Zemanta" class="zemanta-pixie-img" src="http://img.zemanta.com/zemified_e.png?x-id=061dcf9a-d681-43d0-9ed4-38028838cccf" style="border: medium none; float: right;" /></a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SecureValue?a=qvvA-smXE3Y:6256OyPUTqw:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SecureValue?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SecureValue/~4/qvvA-smXE3Y" height="1" width="1"/>]]></content:encoded>


<category>Living Securely</category>
<category>Mobile Security</category>
<category>Secure Value</category>

<dc:creator>Douglas Davidson</dc:creator>
<pubDate>Sat, 19 Nov 2011 11:18:00 -0500</pubDate>

<feedburner:origLink>http://www.secure-value.com/douglasdavidson/2011/11/tablets-tablets-everywhere.html</feedburner:origLink></item>
<item>
<title>Security Job Posting: Jacadis Searching for Service Delivery Manager</title>
<link>http://feedproxy.google.com/~r/SecureValue/~3/T-prqYWdXQI/security-job-posting-jacadis-searching-for-service-delivery-manager.html</link>
<guid isPermaLink="false">http://www.secure-value.com/douglasdavidson/2011/11/security-job-posting-jacadis-searching-for-service-delivery-manager.html</guid>
<description>I have lots to say about what I’ve learned at the Gartner IT Symposia in Orlando as well as some other events relating to small business security and risk management. But I came back to a team that had further positioned Jacadis for growth. So instead of blogging I’ve been working to build out some additions to our work team. We are currently looking for a hands on IT Project Manager with the capability and motivation to grow our services team along with their career. This is the posting we'll be placing formally on Monday. Is this you? Do you...</description>
<content:encoded><![CDATA[<p style="text-align: center;"><strong><em>I have lots to say about what I’ve learned at the Gartner IT Symposia in Orlando as well as some other events relating to small business security and risk management. But I came back to a team that had further positioned Jacadis for growth.&#0160; So instead of blogging I’ve been working&#0160; to build out some additions to our work team.</em></strong></p>
<p>We are currently looking for a hands on IT Project Manager with the capability and motivation to grow our services team along with their career.&#0160; This is the posting we&#39;ll be placing formally on Monday.&#0160;</p>
<p>Is this you?</p>
<ul>
<li>Do you have a mix of IT technical knowledge combined with strong communication oand organizational skills plus a desire to move out of the day to day technical detals and into a management role?</li>
<li>Does the thought of building something alongside a high performing team excite you more than the thought of maintaining something built by others before you?</li>
<li>Are you that unique individual who can work with technology, communicate with others regardless of their IT skill, manage multiple personality types and projects and balance business performance and quality?</li>
<li>Are you PMP certified or headed down that road?</li>
<li>Does your work style embrace best &#0160;for project management processes, tools and techniques?</li>
<li>Are you driven to solve tough problems and satisfy customers at all costs?</li>
</ul>
<p>We are looking for that special person to join us as our Services Delivery Manager.&#0160; &#0160;You’ll join us as the coordinator of a 5 person services team, manage all of our project delivery and then as the company grows you’ll grow alongside it professionally as we continue to build that team.</p>
<p><span class="asset  asset-generic at-xid-6a0115705c9c4c970c015392d0a804970b"><a href="http://www.secure-value.com/files/services-delivery-manager-2011.pdf">Download Services Delivery Manager 2011</a></span></p>
<p>&#0160;</p>
<p>&#0160;</p>
<p>&#0160;</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SecureValue?a=T-prqYWdXQI:q_iYpU0tYqg:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SecureValue?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SecureValue/~4/T-prqYWdXQI" height="1" width="1"/>]]></content:encoded>


<category>Jacadis</category>

<dc:creator>Douglas Davidson</dc:creator>
<pubDate>Fri, 04 Nov 2011 21:16:57 -0400</pubDate>

<feedburner:origLink>http://www.secure-value.com/douglasdavidson/2011/11/security-job-posting-jacadis-searching-for-service-delivery-manager.html</feedburner:origLink></item>
<item>
<title>Security Job Openings: Jacadis looking for Security Analysts </title>
<link>http://feedproxy.google.com/~r/SecureValue/~3/WFK3o8tIRUU/security-job-openings-jacadis-looking-for-security-analysts-.html</link>
<guid isPermaLink="false">http://www.secure-value.com/douglasdavidson/2011/10/security-job-openings-jacadis-looking-for-security-analysts-.html</guid>
<description>Jacadis is about to begin the search for a security analyst to join our team. Likewise, we also have the desire to build an ongoing relationship with 1 or 2 independent security analysts who could take project work on as it comes in. The positions we are looking to fill are all similar to the job description I've attached to this post. The employee analyst will ideally be a generalist with any alphabet soup acronyms (PCI DSS, HIPAA, GLBA, ISO, etc.) being a bonus. The independents we are looking for will ideally have some HIPAA or healthcare security in their...</description>
<content:encoded><![CDATA[<p>Jacadis is about to begin the search for a security analyst to join our team.&#0160; Likewise, we also have the desire to build an ongoing relationship with 1 or 2 independent security analysts who could take project work on as it comes in.&#0160; The positions we are looking to fill are all similar to the job description I&#39;ve attached to this post.&#0160;</p>
<p>The employee analyst will ideally be a generalist with any alphabet soup  acronyms (PCI DSS, HIPAA, GLBA, ISO, etc.) being a bonus.&#0160;</p>
<p>The independents we are looking for will ideally have some HIPAA or healthcare security in their backgrounds in addition to the security and consulting skills we list in the job description.&#0160;</p>
<p>Please email me directly with questions.&#0160; If you wish to apply send a cover letter and resume to me directly as well.&#0160;</p>
<p><span class="asset  asset-generic at-xid-6a0115705c9c4c970c0153920a02e3970b"><a href="http://www.secure-value.com/files/security-analyst-2011.pdf">Download Security Analyst  2011</a></span></p>
<p>&#0160;</p>
<p>&#0160;</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SecureValue?a=WFK3o8tIRUU:eVfa2vAvdi8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SecureValue?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SecureValue/~4/WFK3o8tIRUU" height="1" width="1"/>]]></content:encoded>


<category>Jacadis</category>

<dc:creator>Douglas Davidson</dc:creator>
<pubDate>Mon, 03 Oct 2011 11:47:52 -0400</pubDate>

<feedburner:origLink>http://www.secure-value.com/douglasdavidson/2011/10/security-job-openings-jacadis-looking-for-security-analysts-.html</feedburner:origLink></item>
<item>
<title>Are you naturally inclined to protect your own business secrets? I don't think so ... </title>
<link>http://feedproxy.google.com/~r/SecureValue/~3/Jydcn_uUmh0/are-you-naturally-inclined-to-protect-your-own-business-secrets-i-dont-think-so-.html</link>
<guid isPermaLink="false">http://www.secure-value.com/douglasdavidson/2011/09/are-you-naturally-inclined-to-protect-your-own-business-secrets-i-dont-think-so-.html</guid>
<description>I am reading the Verizon 2011 PAYMENT CARD INDUSTRY COMPLIANCE REPORT to gain some insight from the perspective of the mid-sized enterprises that I typically consult with on governance and management matters related to their information security and assurance. In the forward is a statement that jumped out at me: Information security exists for two distinct purposes: to enable an entity (a person, business, or government) to protect their own secrets, and to enable an entity to protect another entity’s secrets. The former will occur naturally—one is naturally incented to protect one’s own secrets. The latter, however, does not—it is...</description>
<content:encoded><![CDATA[<p>I am reading the Verizon <a href="http://www.verizonbusiness.com/resources/reports/rp_2011-payment-card-industry-compliance-report_en_xg.pdf" target="_self"><em>2011 PAYMENT CARD INDUSTRY COMPLIANCE REPORT</em> </a>to gain some insight from the perspective of the mid-sized enterprises that I typically consult with on governance and management matters related to their information security and assurance.</p>
<p>In the forward is a statement that jumped out at me:</p>
<blockquote>
<p><span style="font-size: 8pt;"><em>Information security exists for two distinct purposes: to enable an entity (a person, business, or government) to protect their own secrets, and to enable an entity to protect another entity’s secrets. The former will occur naturally—one is naturally incented to protect one’s own secrets. The latter, however, does not—it is an externality. As such, it is sometimes necessary to create regulatory bodies to ensure that these secrets are adequately protected.</em></span></p>
</blockquote>
<p>I have to comment (and that scares me because I am two pages in to a 36 page report).</p>
<p>The assertion is that we are &quot;<em>naturally incented to protect one&#39;s own secrets</em>&quot;.&#0160;</p>
<p>I generally think that is true in the context of real life and the physical world.&#0160; I hide the Christmas gifts from my kids and the new kettlebells I purchased from my wife.&#0160; My neighbors don&#39;t know my credit card numbers, my social security number or the result of my latest physical.&#0160; We don&#39;t talk about our crazy uncle.&#0160; Everyone has those kinds of secrets and is inclined to protect them.</p>
<p>In the business world we have similar secrets.&#0160; Our new marketing campaign.&#0160; The new untapped market niche one of the sales people discovered.&#0160; Our secret sauce.&#0160; Customer lists.&#0160; Bank account information.&#0160; Sales commission agreements between the company and each salesperson.&#0160; Business people ARE inclined to protect those kinds of secrets.</p>
<p>In the personal and the business examples above the secrets are physical secrets or &quot;secrets of the mind&quot;.&#0160; The moment we digitize those secrets though I think the inclination changes.&#0160; There is a desire to protect them but the inclination to protect is twarted by a lack of awareness about how well protected these secrets are and about what might attack them or the system they are &quot;safely&quot; stored on.</p>
<p>Said differently, the unaware business owner just might be inclined to want to protect his &quot;own secrets&quot; but most likely doesn&#39;t realize they are exposed.</p>
<p>Several years ago we had a prospective client come calling.&#0160; They had been breached. It wasn&#39;t a legally reportable breach as no personally identifiable information was involved.&#0160; It was a mess, however.&#0160; No logs to allow much of an investigation.&#0160; The weakness in the soon to be our client&#39;s systems was human error.&#0160; They had simply not attended to the necessary effort needed to secure the system.&#0160; In non-technical terms they had built a building but not put a lock on it or watched the door.&#0160;&#0160; Their losses were intangibles.&#0160; Source code to a custom app was taken.&#0160; Code in production on their servers was contaminated.&#0160; Nothing was backed up so work had to be redone to get them back to a pre-breakin state.</p>
<p>Physically when I first visited their facility I entered from an outside door inta an empty locked room.&#0160; In that room, with double locked doors and a camera is a phone.&#0160; Instructions clearly stat to call your appointment from the phone and then they will come to get you.&#0160; We&#39;ve assessed the environment since we first met as a an outcome of the breach and the system, though primative works.</p>
<p>They understand the physical and lock it down pretty well.&#0160; In the physcial sense they are inclined to &quot;protect their secrets&quot; (or at least their physical property).&#0160; But until that breach occured they didn&#39;t understand that the hard work invested in their custom code, the code itself and &quot;secrets&quot; kept in databases on their servers were every bit as exposed as if a customer list or some other printed form was sitting unattended in that entry room or outside the front door.</p>
<p>When it came to their virtual goods, the electronic equivalance of that secure room, locked down and monitored, didn&#39;t exist.</p>
<p>Why? Were they not &quot;naturally incented to protect one&#39;s own secrets&#39;?&quot;&#0160;</p>
<p>I think they were inclined to protect their own secrets.&#0160; After some education they now have the electronic equivalance of that secure room.</p>
<p>The issue for them and I think for many, if not most, business owners, even in technology fields, is that there is a lack of awareness of what is at risk, where weakness lie and what might be attacking those weaknesses.</p>
<p>I believe it is an imperative for a business owner or executive to understand the context of their business. If much of their business occurs electronically then understanding the context of that environment is an imperative.&#0160; Only through that awareness and understanding can your inclination to protect your secrets be real.</p>
<p>Are you naturally inclined to protect your business secrets?</p>
<p>Are you aware of how those electronic secrets are protected?</p>
<p>Are you aware of weaknesses in your system security that would allow an attacker an entry point?</p>
<p>Are you aware of who the attacker might be? Or what they might want?</p>
<p>Have you assessed your security posture?</p>
<p>Again, are you naturally inclined to protect your business secrets?</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SecureValue?a=Jydcn_uUmh0:xD-PUpGGQpY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SecureValue?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SecureValue/~4/Jydcn_uUmh0" height="1" width="1"/>]]></content:encoded>



<dc:creator>Douglas Davidson</dc:creator>
<pubDate>Fri, 30 Sep 2011 10:57:40 -0400</pubDate>

<feedburner:origLink>http://www.secure-value.com/douglasdavidson/2011/09/are-you-naturally-inclined-to-protect-your-own-business-secrets-i-dont-think-so-.html</feedburner:origLink></item>
<item>
<title>In today's fluid world your information assets are many places ... do you know them all?</title>
<link>http://feedproxy.google.com/~r/SecureValue/~3/LtAQfnUZ6DY/in-todays-fluid-world-your-information-assets-are-many-places-do-you-know-them-all.html</link>
<guid isPermaLink="false">http://www.secure-value.com/douglasdavidson/2011/09/in-todays-fluid-world-your-information-assets-are-many-places-do-you-know-them-all.html</guid>
<description>Information security focuses on maintaining the confidentiality, integrity and availability of your information. Conventionally, information security activities in most businesses focus on maintaining confidentiality, integrity and availability for information on the company network and company owned computing devices such as laptops, cell phones, smart phones, etc. But in today's fluid world your information assets are many other places. Do you know where your data flows? As you work with your IT department use this quick check list to make sure you are talking about all the places your company information is located and make certain you have plans in place...</description>
<content:encoded><![CDATA[<p>Information security focuses on maintaining the confidentiality, integrity and availability of your information.&#0160; Conventionally, information security activities in most businesses focus on maintaining confidentiality, integrity and availability for information on the company network and company owned computing devices such as laptops, cell phones, smart phones, etc.</p>
<p>But in today&#39;s fluid world your information assets are many other places.&#0160; Do you know where your data flows?</p>
<p>As you work with your IT department use this quick check list to make sure you are talking about all the places your company information is located and make certain you have plans in place to maintain confidentiality, integrity and availabilty of that information as well as the information on your company network.</p>
<p>Do you allow employee&#39;s personal devices such as cell phones, smart phones, tablets, USB drives and other devices to connect to your company computers?&#0160; Do employees work with company information on those personal tools?&#0160; Do they receive voice mails on them? Email? Other information?</p>
<p>Do employees that telecommute work from home on company laptops? or do they use their home computer? home fax? home printer?</p>
<p>Are you sharing or storing information through online services such as Sharefile or Dropbox?&#0160;</p>
<p>Are employees taking paper files home?</p>
<p>Are you sharing data and information with service providers in your suppply chain?</p>
<p>Where else might your information and data flow?</p>
<p>&#0160;</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SecureValue?a=LtAQfnUZ6DY:ILvtYVP1RjU:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SecureValue?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SecureValue/~4/LtAQfnUZ6DY" height="1" width="1"/>]]></content:encoded>


<category>Secure Value</category>

<dc:creator>Douglas Davidson</dc:creator>
<pubDate>Mon, 12 Sep 2011 10:38:19 -0400</pubDate>

<feedburner:origLink>http://www.secure-value.com/douglasdavidson/2011/09/in-todays-fluid-world-your-information-assets-are-many-places-do-you-know-them-all.html</feedburner:origLink></item>

</channel>
</rss><!-- ph=1 -->

