<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>The InfoSec Blog</title>
	
	<link>http://infosecblog.antonaylward.com</link>
	<description>System Integrity: Without Integrity you don't have Security</description>
	<lastBuildDate>Mon, 28 May 2012 13:12:44 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/TheInfosecBlog" /><feedburner:info uri="theinfosecblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>TheInfosecBlog</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
		<title>Why Info Sec Positions Go Unfilled</title>
		<link>http://feedproxy.google.com/~r/TheInfosecBlog/~3/nry9oCJ_vF0/</link>
		<comments>http://infosecblog.antonaylward.com/2012/05/25/why-info-sec-positions-go-unfilled/#comments</comments>
		<pubDate>Fri, 25 May 2012 14:19:48 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
				<category><![CDATA[Failures]]></category>
		<category><![CDATA[Human Factors]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Human resources]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=983</guid>
		<description>http://www.infosecleaders.com/2012/05/career-advice-tuesday-why-info-sec-position-go-unfilled/ There are many holes in this, but I think they miss some important points. First is setting IT HR to look for Infosec. That is because many people think InfoSec is a IT function as opposed to an organizational function. This goes in cycles: 20 years ago there was the debate: &amp;#8220;Should Infosec report [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=nry9oCJ_vF0:CeIHxlSSI1s:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=nry9oCJ_vF0:CeIHxlSSI1s:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=nry9oCJ_vF0:CeIHxlSSI1s:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=nry9oCJ_vF0:CeIHxlSSI1s:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=nry9oCJ_vF0:CeIHxlSSI1s:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=nry9oCJ_vF0:CeIHxlSSI1s:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=nry9oCJ_vF0:CeIHxlSSI1s:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=nry9oCJ_vF0:CeIHxlSSI1s:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=nry9oCJ_vF0:CeIHxlSSI1s:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=nry9oCJ_vF0:CeIHxlSSI1s:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2012/05/25/why-info-sec-positions-go-unfilled/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://infosecblog.antonaylward.com/2012/05/25/why-info-sec-positions-go-unfilled/</feedburner:origLink></item>
		<item>
		<title>How to get a job in security</title>
		<link>http://feedproxy.google.com/~r/TheInfosecBlog/~3/lSBQIt4mJb0/</link>
		<comments>http://infosecblog.antonaylward.com/2012/05/17/how-to-get-a-job-in-security/#comments</comments>
		<pubDate>Thu, 17 May 2012 11:06:08 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
				<category><![CDATA[Failures]]></category>
		<category><![CDATA[How-to]]></category>
		<category><![CDATA[Human Factors]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=940</guid>
		<description>http://www.wired.com/threatlevel/2012/05/airport-security-id-theft/ I often get hit on by wannabes who want to &amp;#8211; as they put it &amp;#8211; &amp;#8220;break into security&amp;#8221; and get a job as a security consultant. Perhaps the media has something to do with it, making it look glamorous when in fact it is tedious and requires a lot of study and self-discipline. [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=lSBQIt4mJb0:Nly6x_lDN_Y:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=lSBQIt4mJb0:Nly6x_lDN_Y:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=lSBQIt4mJb0:Nly6x_lDN_Y:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=lSBQIt4mJb0:Nly6x_lDN_Y:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=lSBQIt4mJb0:Nly6x_lDN_Y:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=lSBQIt4mJb0:Nly6x_lDN_Y:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=lSBQIt4mJb0:Nly6x_lDN_Y:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=lSBQIt4mJb0:Nly6x_lDN_Y:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=lSBQIt4mJb0:Nly6x_lDN_Y:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=lSBQIt4mJb0:Nly6x_lDN_Y:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2012/05/17/how-to-get-a-job-in-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecblog.antonaylward.com/2012/05/17/how-to-get-a-job-in-security/</feedburner:origLink></item>
		<item>
		<title>If Customers Ask for More Choice, Don’t Listen</title>
		<link>http://feedproxy.google.com/~r/TheInfosecBlog/~3/qsvYtbp2qQ0/</link>
		<comments>http://infosecblog.antonaylward.com/2012/05/15/if-customers-ask-for-more-choice-dont-listen/#comments</comments>
		<pubDate>Tue, 15 May 2012 15:26:33 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
				<category><![CDATA[Human Factors]]></category>
		<category><![CDATA[Social]]></category>
		<category><![CDATA[BMW]]></category>
		<category><![CDATA[Citroën]]></category>
		<category><![CDATA[Magic (illusion)]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=916</guid>
		<description>http://blogs.hbr.org/cs/2012/05/customers_arent_as_savvy_as_yo.html Perhaps the reason that Apple is ahead with the iPod, iPhone and iPad is that the competitors are offering too much choice. That being said, &amp;#8216;competitive advantage&amp;#8217; can lead to paralysis. In the auto world, each badge, each product line has an &amp;#8216;advantage&amp;#8217;. But what many customers want is a blend. Suppose you had [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=qsvYtbp2qQ0:7U8qEW3hEUY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=qsvYtbp2qQ0:7U8qEW3hEUY:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=qsvYtbp2qQ0:7U8qEW3hEUY:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=qsvYtbp2qQ0:7U8qEW3hEUY:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=qsvYtbp2qQ0:7U8qEW3hEUY:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=qsvYtbp2qQ0:7U8qEW3hEUY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=qsvYtbp2qQ0:7U8qEW3hEUY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=qsvYtbp2qQ0:7U8qEW3hEUY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=qsvYtbp2qQ0:7U8qEW3hEUY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=qsvYtbp2qQ0:7U8qEW3hEUY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2012/05/15/if-customers-ask-for-more-choice-dont-listen/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecblog.antonaylward.com/2012/05/15/if-customers-ask-for-more-choice-dont-listen/</feedburner:origLink></item>
		<item>
		<title>An OP-ED by Richard Clarke on China</title>
		<link>http://feedproxy.google.com/~r/TheInfosecBlog/~3/6vi8G6Nqyfo/</link>
		<comments>http://infosecblog.antonaylward.com/2012/04/05/an-op-ed-by-richard-clarke-on-china/#comments</comments>
		<pubDate>Thu, 05 Apr 2012 12:24:03 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Politics & Economics]]></category>
		<category><![CDATA[Rants and Raves]]></category>
		<category><![CDATA[Social]]></category>
		<category><![CDATA[Asia]]></category>
		<category><![CDATA[canada]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[Espionage]]></category>
		<category><![CDATA[France]]></category>
		<category><![CDATA[Industrial Espionage]]></category>
		<category><![CDATA[Robert Fortune]]></category>
		<category><![CDATA[United States]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=915</guid>
		<description>http://www.nytimes.com/2012/04/03/opinion/how-china-steals-our-secrets.html This is better written than most &amp;#8216;chicken little&amp;#8217; pieces, but please can we have &amp;#8216;history&amp;#8217; of how most nations, including the USA, have engages in &amp;#8216;industrial espionage&amp;#8216;. I recall a presentation by CSIS that was making the point that Canada&amp;#8217;s greatest threat on the Industrial Espionage scene was France, and France had been practising [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=6vi8G6Nqyfo:-kF0HzbNRFQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=6vi8G6Nqyfo:-kF0HzbNRFQ:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=6vi8G6Nqyfo:-kF0HzbNRFQ:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=6vi8G6Nqyfo:-kF0HzbNRFQ:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=6vi8G6Nqyfo:-kF0HzbNRFQ:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=6vi8G6Nqyfo:-kF0HzbNRFQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=6vi8G6Nqyfo:-kF0HzbNRFQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=6vi8G6Nqyfo:-kF0HzbNRFQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=6vi8G6Nqyfo:-kF0HzbNRFQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=6vi8G6Nqyfo:-kF0HzbNRFQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2012/04/05/an-op-ed-by-richard-clarke-on-china/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecblog.antonaylward.com/2012/04/05/an-op-ed-by-richard-clarke-on-china/</feedburner:origLink></item>
		<item>
		<title>Managing Software</title>
		<link>http://feedproxy.google.com/~r/TheInfosecBlog/~3/R3Gs3haSZk8/</link>
		<comments>http://infosecblog.antonaylward.com/2012/04/01/managing-software/#comments</comments>
		<pubDate>Sun, 01 Apr 2012 12:33:05 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
				<category><![CDATA[Failures]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Rants and Raves]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Open source]]></category>
		<category><![CDATA[Revision Control System]]></category>
		<category><![CDATA[Test harness]]></category>
		<category><![CDATA[Test plan]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=914</guid>
		<description>Last month, this question came up in a discussion forum I&amp;#8217;m involved with: Another challenge to which i want to get an answer to is, do developers always need Admin rights to perform their testing? Is there not a way to give them privilege access and yet have them get their work done. I am [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=R3Gs3haSZk8:EPbXALELjhg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=R3Gs3haSZk8:EPbXALELjhg:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=R3Gs3haSZk8:EPbXALELjhg:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=R3Gs3haSZk8:EPbXALELjhg:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=R3Gs3haSZk8:EPbXALELjhg:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=R3Gs3haSZk8:EPbXALELjhg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=R3Gs3haSZk8:EPbXALELjhg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=R3Gs3haSZk8:EPbXALELjhg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=R3Gs3haSZk8:EPbXALELjhg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=R3Gs3haSZk8:EPbXALELjhg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2012/04/01/managing-software/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecblog.antonaylward.com/2012/04/01/managing-software/</feedburner:origLink></item>
		<item>
		<title>Surely compliance is binary?</title>
		<link>http://feedproxy.google.com/~r/TheInfosecBlog/~3/cm6o4_XxsCI/</link>
		<comments>http://infosecblog.antonaylward.com/2012/03/24/surely-compliance-is-binary/#comments</comments>
		<pubDate>Sat, 24 Mar 2012 15:05:09 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
				<category><![CDATA[Human Factors]]></category>
		<category><![CDATA[ISO27K]]></category>
		<category><![CDATA[Rants and Raves]]></category>
		<category><![CDATA[Standards]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[rumsfeld]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=911</guid>
		<description>Call me a dinosaur (that&amp;#8217;s OK, since its the weekend and dressed down to work in the garden) but &amp;#8230; Surely COMPLIANCE is a binary measure, not a &amp;#8220;level of&amp;#8221; issue. You are either in compliance or you are not. As in you are either deal or alive. Now it may be that some &amp;#8220;standard&amp;#8221; [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=cm6o4_XxsCI:t8fgoYBV5is:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=cm6o4_XxsCI:t8fgoYBV5is:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=cm6o4_XxsCI:t8fgoYBV5is:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=cm6o4_XxsCI:t8fgoYBV5is:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=cm6o4_XxsCI:t8fgoYBV5is:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=cm6o4_XxsCI:t8fgoYBV5is:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=cm6o4_XxsCI:t8fgoYBV5is:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=cm6o4_XxsCI:t8fgoYBV5is:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=cm6o4_XxsCI:t8fgoYBV5is:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=cm6o4_XxsCI:t8fgoYBV5is:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2012/03/24/surely-compliance-is-binary/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		<feedburner:origLink>http://infosecblog.antonaylward.com/2012/03/24/surely-compliance-is-binary/</feedburner:origLink></item>
		<item>
		<title>Social Engineering and sufficency of awareness training</title>
		<link>http://feedproxy.google.com/~r/TheInfosecBlog/~3/qSLb7065VDw/</link>
		<comments>http://infosecblog.antonaylward.com/2012/03/23/social-engineering-and-sufficency-of-awareness-training/#comments</comments>
		<pubDate>Fri, 23 Mar 2012 11:10:02 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
				<category><![CDATA[11th Domain]]></category>
		<category><![CDATA[Failures]]></category>
		<category><![CDATA[Human Factors]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Social]]></category>
		<category><![CDATA[Standards]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[Spanish Prisoner]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=910</guid>
		<description>Someone asked: If you have a good information security awareness amongst the employees then it should not a problem what kind of attempts are made by the social engineers and to glean information from your employees. Yes but as RSA demonstrated, it is a moving target. You need to have it as a continuous process, [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=qSLb7065VDw:ZU9xUGLbm10:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=qSLb7065VDw:ZU9xUGLbm10:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=qSLb7065VDw:ZU9xUGLbm10:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=qSLb7065VDw:ZU9xUGLbm10:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=qSLb7065VDw:ZU9xUGLbm10:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=qSLb7065VDw:ZU9xUGLbm10:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=qSLb7065VDw:ZU9xUGLbm10:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=qSLb7065VDw:ZU9xUGLbm10:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=qSLb7065VDw:ZU9xUGLbm10:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=qSLb7065VDw:ZU9xUGLbm10:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2012/03/23/social-engineering-and-sufficency-of-awareness-training/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://infosecblog.antonaylward.com/2012/03/23/social-engineering-and-sufficency-of-awareness-training/</feedburner:origLink></item>
		<item>
		<title>Orwell: a quarter of a century late</title>
		<link>http://feedproxy.google.com/~r/TheInfosecBlog/~3/bysTNEkp8kU/</link>
		<comments>http://infosecblog.antonaylward.com/2012/03/22/orwell-a-quarter-of-a-century-late/#comments</comments>
		<pubDate>Fri, 23 Mar 2012 01:34:28 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
				<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Human Factors]]></category>
		<category><![CDATA[Social]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=909</guid>
		<description>http://hdguru.com/is-your-new-hdtv-watching-you/7643/ well 28 years actually &amp;#8230; So, the two-way tv sets of Orwell&amp;#8217;s novel have arrived, over a quarter of a century late! It just goes to show. Science fiction things like the Star Trek communicator (Motorola flip phones) or the tricorder (some of the enhanced versions of the Newton) or the data Pad (the [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=bysTNEkp8kU:WKwHhQAkLtE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=bysTNEkp8kU:WKwHhQAkLtE:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=bysTNEkp8kU:WKwHhQAkLtE:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=bysTNEkp8kU:WKwHhQAkLtE:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=bysTNEkp8kU:WKwHhQAkLtE:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=bysTNEkp8kU:WKwHhQAkLtE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=bysTNEkp8kU:WKwHhQAkLtE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=bysTNEkp8kU:WKwHhQAkLtE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=bysTNEkp8kU:WKwHhQAkLtE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=bysTNEkp8kU:WKwHhQAkLtE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2012/03/22/orwell-a-quarter-of-a-century-late/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecblog.antonaylward.com/2012/03/22/orwell-a-quarter-of-a-century-late/</feedburner:origLink></item>
		<item>
		<title>About ISO 27001 Risk Statement and Controls</title>
		<link>http://feedproxy.google.com/~r/TheInfosecBlog/~3/RnGcvwH1-Bc/</link>
		<comments>http://infosecblog.antonaylward.com/2012/03/18/about-iso-27001-security-risk-statement-and-controls/#comments</comments>
		<pubDate>Sun, 18 Mar 2012 18:36:33 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
				<category><![CDATA[ISO27K]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Information security management system]]></category>
		<category><![CDATA[Internal control]]></category>
		<category><![CDATA[International Organization for Standardization]]></category>
		<category><![CDATA[ISO/IEC 27001]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Security controls]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=908</guid>
		<description>On the ISO27000 Forum list, someone asked: I&amp;#8217;m looking for Risk statement for each ISO 27k control; meaning &amp;#8220;what is the risk of not implementing a control&amp;#8221;. That&amp;#8217;s a very ingenious way of looking at it! One way of formulating the risk statement is from the control objective mentioned in the standard. Is there any [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=RnGcvwH1-Bc:Gz9HeHqONkI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=RnGcvwH1-Bc:Gz9HeHqONkI:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=RnGcvwH1-Bc:Gz9HeHqONkI:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=RnGcvwH1-Bc:Gz9HeHqONkI:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=RnGcvwH1-Bc:Gz9HeHqONkI:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=RnGcvwH1-Bc:Gz9HeHqONkI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=RnGcvwH1-Bc:Gz9HeHqONkI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=RnGcvwH1-Bc:Gz9HeHqONkI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=RnGcvwH1-Bc:Gz9HeHqONkI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=RnGcvwH1-Bc:Gz9HeHqONkI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2012/03/18/about-iso-27001-security-risk-statement-and-controls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecblog.antonaylward.com/2012/03/18/about-iso-27001-security-risk-statement-and-controls/</feedburner:origLink></item>
		<item>
		<title>The 19 most maddening security questions | Security – InfoWorld</title>
		<link>http://feedproxy.google.com/~r/TheInfosecBlog/~3/gcg_vLtxBuE/</link>
		<comments>http://infosecblog.antonaylward.com/2012/03/07/the-19-most-maddening-security-questions-security/#comments</comments>
		<pubDate>Wed, 07 Mar 2012 12:46:30 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
				<category><![CDATA[Human Factors]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=905</guid>
		<description>http://www.infoworld.com/d/security/the-19-most-maddening-security-questions-187983 An interesting list, since it covers issues of public structural security. I recall reading that the greatest contribution to the health of individuals came about from good public sanitation and clean water, that is civic changes (presumably enabled by legislation) that affected the public in a structural manner. What would be on your list? [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=gcg_vLtxBuE:y3SY0FDANXo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=gcg_vLtxBuE:y3SY0FDANXo:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=gcg_vLtxBuE:y3SY0FDANXo:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=gcg_vLtxBuE:y3SY0FDANXo:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=gcg_vLtxBuE:y3SY0FDANXo:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=gcg_vLtxBuE:y3SY0FDANXo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=gcg_vLtxBuE:y3SY0FDANXo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=gcg_vLtxBuE:y3SY0FDANXo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=gcg_vLtxBuE:y3SY0FDANXo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=gcg_vLtxBuE:y3SY0FDANXo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2012/03/07/the-19-most-maddening-security-questions-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecblog.antonaylward.com/2012/03/07/the-19-most-maddening-security-questions-security/</feedburner:origLink></item>
		<item>
		<title>Naval War College uses Russian software for iPad course material</title>
		<link>http://feedproxy.google.com/~r/TheInfosecBlog/~3/y8nyTHMpBSo/</link>
		<comments>http://infosecblog.antonaylward.com/2012/03/06/naval-war-college-uses-russian-software-for-ipad-course-material/#comments</comments>
		<pubDate>Tue, 06 Mar 2012 13:38:17 +0000</pubDate>
		<dc:creator>antonaylward</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Politics & Economics]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Standards]]></category>
		<category><![CDATA[GoodReader]]></category>
		<category><![CDATA[IPad]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=904</guid>
		<description>http://www.nextgov.com/nextgov/ng_20120305_6368.php The Navy&amp;#8217;s premier institution for developing senior strategic and operational leaders started issuing students Apple iPad tablet computers equipped with GoodReader software in August 2010, unaware that the mobile app was developed and maintained by a Russian company, Good.iWare, until Nextgov reported it in February. OK so its not news and OK I&amp;#8217;ve posted [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=y8nyTHMpBSo:KK_N0_2z1XA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=y8nyTHMpBSo:KK_N0_2z1XA:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=y8nyTHMpBSo:KK_N0_2z1XA:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=y8nyTHMpBSo:KK_N0_2z1XA:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=y8nyTHMpBSo:KK_N0_2z1XA:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=y8nyTHMpBSo:KK_N0_2z1XA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=y8nyTHMpBSo:KK_N0_2z1XA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=y8nyTHMpBSo:KK_N0_2z1XA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=y8nyTHMpBSo:KK_N0_2z1XA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=y8nyTHMpBSo:KK_N0_2z1XA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2012/03/06/naval-war-college-uses-russian-software-for-ipad-course-material/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecblog.antonaylward.com/2012/03/06/naval-war-college-uses-russian-software-for-ipad-course-material/</feedburner:origLink></item>
		<item>
		<title>Please Realize That Piracy is a Service Problem.</title>
		<link>http://feedproxy.google.com/~r/TheInfosecBlog/~3/S179AxFl_EY/</link>
		<comments>http://infosecblog.antonaylward.com/2012/02/10/please-realize-piracy-is-a-service-problem/#comments</comments>
		<pubDate>Fri, 10 Feb 2012 13:50:26 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Failures]]></category>
		<category><![CDATA[Politics & Economics]]></category>
		<category><![CDATA[Rants and Raves]]></category>
		<category><![CDATA[Social]]></category>
		<category><![CDATA[Amazon]]></category>
		<category><![CDATA[Copyright infringement]]></category>
		<category><![CDATA[Piracy]]></category>
		<category><![CDATA[Recording Industry Association of America]]></category>
		<category><![CDATA[RIAA]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=903</guid>
		<description>http://www.forbes.com/sites/insertcoin/2012/02/03/you-will-never-kill-piracy-and-piracy-will-never-kill-you/ The full article is a bit wordy, and manages to avoid lecturing about how the media industry failed at &amp;#8220;service&amp;#8221; when it came to view tapes and DVDs, how they objected even those turned out to be immensely profitable. We all know that and we all know that despite the opportunity for profits that [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=S179AxFl_EY:nw9AzP5nItQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=S179AxFl_EY:nw9AzP5nItQ:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=S179AxFl_EY:nw9AzP5nItQ:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=S179AxFl_EY:nw9AzP5nItQ:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=S179AxFl_EY:nw9AzP5nItQ:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=S179AxFl_EY:nw9AzP5nItQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=S179AxFl_EY:nw9AzP5nItQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=S179AxFl_EY:nw9AzP5nItQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=S179AxFl_EY:nw9AzP5nItQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=S179AxFl_EY:nw9AzP5nItQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2012/02/10/please-realize-piracy-is-a-service-problem/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecblog.antonaylward.com/2012/02/10/please-realize-piracy-is-a-service-problem/</feedburner:origLink></item>
		<item>
		<title>Upside and downside: How I hate Journalists</title>
		<link>http://feedproxy.google.com/~r/TheInfosecBlog/~3/jaL-Fp8gD2E/</link>
		<comments>http://infosecblog.antonaylward.com/2012/02/08/upside-and-downside-how-i-hate-journalists/#comments</comments>
		<pubDate>Wed, 08 Feb 2012 23:30:28 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
				<category><![CDATA[11th Domain]]></category>
		<category><![CDATA[Human Factors]]></category>
		<category><![CDATA[Politics & Economics]]></category>
		<category><![CDATA[Rants and Raves]]></category>
		<category><![CDATA[Les Bell]]></category>
		<category><![CDATA[Political Compass]]></category>
		<category><![CDATA[Politics]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=902</guid>
		<description>http://compliancesearch.com/compliancex/insider-trading/senate-votes-to-ban-insider-trading-by-its-members/ And this doesn&amp;#8217;t actually stop them form making use of &amp;#8216;insider information&amp;#8217; they just have to declare it within 30 days. No, wait, sorry &amp;#8230; you mean that the legislators are saying that legislators shouldn&amp;#8217;t do something that is illegal anyway? Or that, if they do something that is already illegal, it is OK [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=jaL-Fp8gD2E:E-SIMe4xoxA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=jaL-Fp8gD2E:E-SIMe4xoxA:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=jaL-Fp8gD2E:E-SIMe4xoxA:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=jaL-Fp8gD2E:E-SIMe4xoxA:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=jaL-Fp8gD2E:E-SIMe4xoxA:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=jaL-Fp8gD2E:E-SIMe4xoxA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=jaL-Fp8gD2E:E-SIMe4xoxA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=jaL-Fp8gD2E:E-SIMe4xoxA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=jaL-Fp8gD2E:E-SIMe4xoxA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=jaL-Fp8gD2E:E-SIMe4xoxA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2012/02/08/upside-and-downside-how-i-hate-journalists/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecblog.antonaylward.com/2012/02/08/upside-and-downside-how-i-hate-journalists/</feedburner:origLink></item>
		<item>
		<title>“Cybercrime” is still Crime and “Cyberfraud” is still Fraud</title>
		<link>http://feedproxy.google.com/~r/TheInfosecBlog/~3/Dhhd0jHYrfo/</link>
		<comments>http://infosecblog.antonaylward.com/2012/01/25/cybercrime-is-still-crime-and-cyberfraud-is-still-fraud/#comments</comments>
		<pubDate>Wed, 25 Jan 2012 13:14:51 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Law]]></category>
		<category><![CDATA[Politics & Economics]]></category>
		<category><![CDATA[Social]]></category>
		<category><![CDATA[Computer crime]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cyberfraud]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[Organized crime]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=898</guid>
		<description>http://www.techsecuritytoday.com/index.php/our-contributors/michael-vizard/entry/lifting-the-veil-on-cybercrime This says it all: At the end of the day, cybercriminal activity is not all that different from more traditional forms of organized crime. Obviously, the way the crime is perpetrated is new, but the ways in which cybercriminals operate is not all that different from anything that has gone on before. Heck, once [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=Dhhd0jHYrfo:HbEH0mP8bow:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=Dhhd0jHYrfo:HbEH0mP8bow:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=Dhhd0jHYrfo:HbEH0mP8bow:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=Dhhd0jHYrfo:HbEH0mP8bow:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=Dhhd0jHYrfo:HbEH0mP8bow:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=Dhhd0jHYrfo:HbEH0mP8bow:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=Dhhd0jHYrfo:HbEH0mP8bow:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=Dhhd0jHYrfo:HbEH0mP8bow:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=Dhhd0jHYrfo:HbEH0mP8bow:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=Dhhd0jHYrfo:HbEH0mP8bow:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2012/01/25/cybercrime-is-still-crime-and-cyberfraud-is-still-fraud/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecblog.antonaylward.com/2012/01/25/cybercrime-is-still-crime-and-cyberfraud-is-still-fraud/</feedburner:origLink></item>
		<item>
		<title>The Death of Antivirus Software</title>
		<link>http://feedproxy.google.com/~r/TheInfosecBlog/~3/pZf1T9ZEqbw/</link>
		<comments>http://infosecblog.antonaylward.com/2012/01/24/the-death-of-antivirus-software/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 15:27:09 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
				<category><![CDATA[Failures]]></category>
		<category><![CDATA[Human Factors]]></category>
		<category><![CDATA[Rants and Raves]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Digital signature]]></category>
		<category><![CDATA[John McAfee]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[PGP]]></category>
		<category><![CDATA[Pretty Good Privacy]]></category>
		<category><![CDATA[Public key infrastructure]]></category>
		<category><![CDATA[SSL]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=897</guid>
		<description>http://www.infosecisland.com/blogview/19386-The-Death-of-Antivirus-Software.html The real issue here isn&amp;#8217;t Ubuntu, or any other form of Linux. Its that AV software doesn&amp;#8217;t work. PERIOD. There are over 50,000 new piece of malware developed and released daily. The very nature of the AV software models that John McAfee foisted on the industry simply can&amp;#8217;t cope. This isn&amp;#8217;t news. Signature-based (and [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=pZf1T9ZEqbw:MmbpZyQF5OU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=pZf1T9ZEqbw:MmbpZyQF5OU:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=pZf1T9ZEqbw:MmbpZyQF5OU:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=pZf1T9ZEqbw:MmbpZyQF5OU:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=pZf1T9ZEqbw:MmbpZyQF5OU:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=pZf1T9ZEqbw:MmbpZyQF5OU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=pZf1T9ZEqbw:MmbpZyQF5OU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=pZf1T9ZEqbw:MmbpZyQF5OU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=pZf1T9ZEqbw:MmbpZyQF5OU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=pZf1T9ZEqbw:MmbpZyQF5OU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2012/01/24/the-death-of-antivirus-software/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecblog.antonaylward.com/2012/01/24/the-death-of-antivirus-software/</feedburner:origLink></item>
		<item>
		<title>”My dog knows you don’t look like me”</title>
		<link>http://feedproxy.google.com/~r/TheInfosecBlog/~3/Q6rprTmmn6Q/</link>
		<comments>http://infosecblog.antonaylward.com/2012/01/19/my-dog-knows-you-don%e2%80%99t-look-like-me/#comments</comments>
		<pubDate>Thu, 19 Jan 2012 12:49:14 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
				<category><![CDATA[Failures]]></category>
		<category><![CDATA[Human Factors]]></category>
		<category><![CDATA[Privay]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=896</guid>
		<description>http://www.zdnet.com/blog/identity/darpa-authentication-project-focuses-on-humans-as-secrets/157 So do my cats. But so what? Does this mean that DARPA/USGov will finance the supply of advanced biometrics with every PC from Microsoft or Apples and every Tablet and smartphone? Perhaps eyeball recognition like in &amp;#8220;Minority Report&amp;#8220;. And I&amp;#8217;m sure there are _other_ ways to hack that than the one mentioned in the [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=Q6rprTmmn6Q:EnGWzBOlW6U:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=Q6rprTmmn6Q:EnGWzBOlW6U:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=Q6rprTmmn6Q:EnGWzBOlW6U:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=Q6rprTmmn6Q:EnGWzBOlW6U:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=Q6rprTmmn6Q:EnGWzBOlW6U:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=Q6rprTmmn6Q:EnGWzBOlW6U:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=Q6rprTmmn6Q:EnGWzBOlW6U:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=Q6rprTmmn6Q:EnGWzBOlW6U:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=Q6rprTmmn6Q:EnGWzBOlW6U:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=Q6rprTmmn6Q:EnGWzBOlW6U:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2012/01/19/my-dog-knows-you-don%e2%80%99t-look-like-me/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecblog.antonaylward.com/2012/01/19/my-dog-knows-you-don%e2%80%99t-look-like-me/</feedburner:origLink></item>
		<item>
		<title>How to decide on what DVD backup software to use</title>
		<link>http://feedproxy.google.com/~r/TheInfosecBlog/~3/cPscMhmsJok/</link>
		<comments>http://infosecblog.antonaylward.com/2012/01/17/how-to-decide-what-backup-software-to-use/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 14:24:57 +0000</pubDate>
		<dc:creator>antonaylward</dc:creator>
				<category><![CDATA[How-to]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[backups]]></category>
		<category><![CDATA[K3b]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=889</guid>
		<description>You do do backups don&amp;#8217;t you?  Backups to DVD is easy, but what software to use? Why not simply k3b ? But if it some down to it, there&amp;#8217;s a decision tree you can and should work though. Do you want the DVD backup &amp;#8216;mountable&amp;#8217;? If it is then you can see each file and [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=cPscMhmsJok:w8vHV1fRUhA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=cPscMhmsJok:w8vHV1fRUhA:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=cPscMhmsJok:w8vHV1fRUhA:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=cPscMhmsJok:w8vHV1fRUhA:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=cPscMhmsJok:w8vHV1fRUhA:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=cPscMhmsJok:w8vHV1fRUhA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=cPscMhmsJok:w8vHV1fRUhA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=cPscMhmsJok:w8vHV1fRUhA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=cPscMhmsJok:w8vHV1fRUhA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=cPscMhmsJok:w8vHV1fRUhA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2012/01/17/how-to-decide-what-backup-software-to-use/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecblog.antonaylward.com/2012/01/17/how-to-decide-what-backup-software-to-use/</feedburner:origLink></item>
		<item>
		<title>Doubts about “Defense in Depth”</title>
		<link>http://feedproxy.google.com/~r/TheInfosecBlog/~3/kc-NbylCiI0/</link>
		<comments>http://infosecblog.antonaylward.com/2011/11/30/doubts-about-defense-in-dept/#comments</comments>
		<pubDate>Wed, 30 Nov 2011 15:02:13 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Failures]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Standards]]></category>
		<category><![CDATA[controls]]></category>
		<category><![CDATA[Defece in depth]]></category>
		<category><![CDATA[Ken Thompson]]></category>
		<category><![CDATA[perimeter]]></category>
		<category><![CDATA[trust]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=888</guid>
		<description> So to have great (subjective) protection your layered protection and controls have to be &amp;#8220;bubbled&amp;#8221; as opposed to linear (to slow down or impede a  direct attack). I have doubts about &amp;#8220;defence in depth&amp;#8221; analogies with the military that many people in InfoSec use. Read what they are really talking about in those military examples: [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=kc-NbylCiI0:jZXhxJaU8Qs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=kc-NbylCiI0:jZXhxJaU8Qs:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=kc-NbylCiI0:jZXhxJaU8Qs:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=kc-NbylCiI0:jZXhxJaU8Qs:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=kc-NbylCiI0:jZXhxJaU8Qs:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=kc-NbylCiI0:jZXhxJaU8Qs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=kc-NbylCiI0:jZXhxJaU8Qs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=kc-NbylCiI0:jZXhxJaU8Qs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=kc-NbylCiI0:jZXhxJaU8Qs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=kc-NbylCiI0:jZXhxJaU8Qs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2011/11/30/doubts-about-defense-in-dept/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecblog.antonaylward.com/2011/11/30/doubts-about-defense-in-dept/</feedburner:origLink></item>
		<item>
		<title>On the HP Printer Hack</title>
		<link>http://feedproxy.google.com/~r/TheInfosecBlog/~3/bD6Y6Pq4z8s/</link>
		<comments>http://infosecblog.antonaylward.com/2011/11/30/on-th-hp-printer-hack/#comments</comments>
		<pubDate>Wed, 30 Nov 2011 12:45:36 +0000</pubDate>
		<dc:creator>antonaylward</dc:creator>
				<category><![CDATA[FAQ]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Alan Cooper]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[Printer]]></category>
		<category><![CDATA[Risk analysis]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=887</guid>
		<description>The hack to make the HP printers burn was interesting, but lets face it, a printer today is a  special purpose computer and a computer almost always has a flaw which can be exploited. In his book on UI design &amp;#8220;The Inmates are Running the Asylum&amp;#8221;, Alan Cooper makes the point that just about everything [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=bD6Y6Pq4z8s:WKmN5AzY6z8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=bD6Y6Pq4z8s:WKmN5AzY6z8:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=bD6Y6Pq4z8s:WKmN5AzY6z8:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=bD6Y6Pq4z8s:WKmN5AzY6z8:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=bD6Y6Pq4z8s:WKmN5AzY6z8:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=bD6Y6Pq4z8s:WKmN5AzY6z8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=bD6Y6Pq4z8s:WKmN5AzY6z8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=bD6Y6Pq4z8s:WKmN5AzY6z8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=bD6Y6Pq4z8s:WKmN5AzY6z8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=bD6Y6Pq4z8s:WKmN5AzY6z8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2011/11/30/on-th-hp-printer-hack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecblog.antonaylward.com/2011/11/30/on-th-hp-printer-hack/</feedburner:origLink></item>
		<item>
		<title>Which Risk Framework to Use: FAIR, FRAP, OCTAVE, SABSA …</title>
		<link>http://feedproxy.google.com/~r/TheInfosecBlog/~3/PsTIUYae4H8/</link>
		<comments>http://infosecblog.antonaylward.com/2011/11/13/which-risk-framework-to-use-fair-frap-octave-sabsa/#comments</comments>
		<pubDate>Sun, 13 Nov 2011 16:37:57 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
				<category><![CDATA[How-to]]></category>
		<category><![CDATA[ISO27K]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[COBIT]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[Risk analysis]]></category>
		<category><![CDATA[Risk assessment]]></category>
		<category><![CDATA[Risk Management]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=886</guid>
		<description>What framework would you use to provide for quantitative or qualitative risk analysis at both the micro and macro level?  I&amp;#8217;m asking about a true risk assessment framework not merely a checklist. Yes, this is a bit of a META-Question. But then its Sunday, a day for contemplation&amp;#8230; When does something like these stop being [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=PsTIUYae4H8:2oYL6BOq8I0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=PsTIUYae4H8:2oYL6BOq8I0:D7DqB2pKExk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=PsTIUYae4H8:2oYL6BOq8I0:D7DqB2pKExk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=PsTIUYae4H8:2oYL6BOq8I0:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=PsTIUYae4H8:2oYL6BOq8I0:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=PsTIUYae4H8:2oYL6BOq8I0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=PsTIUYae4H8:2oYL6BOq8I0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=PsTIUYae4H8:2oYL6BOq8I0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheInfosecBlog?a=PsTIUYae4H8:2oYL6BOq8I0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheInfosecBlog?i=PsTIUYae4H8:2oYL6BOq8I0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2011/11/13/which-risk-framework-to-use-fair-frap-octave-sabsa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecblog.antonaylward.com/2011/11/13/which-risk-framework-to-use-fair-frap-octave-sabsa/</feedburner:origLink></item>
	</channel>
</rss>

