<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for InfoReck</title>
	<atom:link href="http://www.robbreck.net/blog/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.robbreck.net/blog</link>
	<description>Enterprise InfoSec from Robb Reck</description>
	<lastBuildDate>Wed, 09 May 2012 00:03:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>Comment on Making Security Metrics That Matter by Robb Reck</title>
		<link>http://www.robbreck.net/blog/enterprise_information_security/making-security-metrics-that-matter/#comment-897</link>
		<dc:creator>Robb Reck</dc:creator>
		<pubDate>Wed, 09 May 2012 00:03:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.robbreck.net/blog/?p=506#comment-897</guid>
		<description>Andy,

Thank you for taking the time to read and comment. As you said, there is a lot of room for us to improve our security alignment. Fortunately, it&#039;s fun. I appreciate the kind words.

-Robb</description>
		<content:encoded><![CDATA[<p>Andy,</p>
<p>Thank you for taking the time to read and comment. As you said, there is a lot of room for us to improve our security alignment. Fortunately, it&#8217;s fun. I appreciate the kind words.</p>
<p>-Robb</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Making Security Metrics That Matter by Andy Bochman</title>
		<link>http://www.robbreck.net/blog/enterprise_information_security/making-security-metrics-that-matter/#comment-741</link>
		<dc:creator>Andy Bochman</dc:creator>
		<pubDate>Mon, 23 Apr 2012 12:27:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.robbreck.net/blog/?p=506#comment-741</guid>
		<description>Robb - this is great.  This message is starting to get through to the security masses, though slowly. Thanks for helping to speed it up !!!

Andy</description>
		<content:encoded><![CDATA[<p>Robb &#8211; this is great.  This message is starting to get through to the security masses, though slowly. Thanks for helping to speed it up !!!</p>
<p>Andy</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Security Depends on IT Maturity by Steve Lodin</title>
		<link>http://www.robbreck.net/blog/enterprise_information_security/security-depends-on-mature-it-governance/#comment-606</link>
		<dc:creator>Steve Lodin</dc:creator>
		<pubDate>Tue, 20 Mar 2012 23:54:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.robbreck.net/blog/?p=422#comment-606</guid>
		<description>Completely agree.  I&#039;ve seen cases where new systems in the PCI segment don&#039;t have FIM installed or logging enabled, new networks pop up that aren&#039;t put in the vulnerability scanner, etc...  The CAB should catch this, but the right people and the right questions must be asked during CAB meetings.  Otherwise, the CAB is just a rubberstamp process without value.</description>
		<content:encoded><![CDATA[<p>Completely agree.  I&#8217;ve seen cases where new systems in the PCI segment don&#8217;t have FIM installed or logging enabled, new networks pop up that aren&#8217;t put in the vulnerability scanner, etc&#8230;  The CAB should catch this, but the right people and the right questions must be asked during CAB meetings.  Otherwise, the CAB is just a rubberstamp process without value.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Security Depends on IT Maturity by Lou Rabon</title>
		<link>http://www.robbreck.net/blog/enterprise_information_security/security-depends-on-mature-it-governance/#comment-602</link>
		<dc:creator>Lou Rabon</dc:creator>
		<pubDate>Mon, 19 Mar 2012 20:50:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.robbreck.net/blog/?p=422#comment-602</guid>
		<description>Hey Robb,

Just found this via the Palo Alto Networks twitter feed.  So true!  I have been battling this problem for years...and the worst part is that it leads to a kind of &quot;security apathy&quot;, where the least common denominator is usually taken as a solution with no overarching framework and commitment to improvement.  It needs to come from the top and have board and exec team signoff and leadership.

Great post!
Lou</description>
		<content:encoded><![CDATA[<p>Hey Robb,</p>
<p>Just found this via the Palo Alto Networks twitter feed.  So true!  I have been battling this problem for years&#8230;and the worst part is that it leads to a kind of &#8220;security apathy&#8221;, where the least common denominator is usually taken as a solution with no overarching framework and commitment to improvement.  It needs to come from the top and have board and exec team signoff and leadership.</p>
<p>Great post!<br />
Lou</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on RSA Conference 2012 &#8211; Wrap-Up by RSA Round-up 2012 &#171; VPN Haus</title>
		<link>http://www.robbreck.net/blog/enterprise_information_security/rsa-conference-2012-wrap-up/#comment-570</link>
		<dc:creator>RSA Round-up 2012 &#171; VPN Haus</dc:creator>
		<pubDate>Tue, 06 Mar 2012 19:38:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.robbreck.net/blog/?p=433#comment-570</guid>
		<description>[...] For the full post, click here. [...]</description>
		<content:encoded><![CDATA[<p>[...] For the full post, click here. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on RSA Conference 2012: Day 1 Highlights by Robb Reck</title>
		<link>http://www.robbreck.net/blog/enterprise_information_security/rsa-conference-2012-highlights/#comment-569</link>
		<dc:creator>Robb Reck</dc:creator>
		<pubDate>Sun, 04 Mar 2012 19:27:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.robbreck.net/blog/?p=425#comment-569</guid>
		<description>Daya,

Thanks for the note. I believe that the intent behind of the quote you mention (&quot;The destination should achieve compliance, not be compliance&quot;) is that when organizations are architecting their security programs it should be done with an eye toward implementing proper security, NOT toward passing a particular regulation or standard. I have written a few blog posts on this topic in the past if you want to read my thoughts on the matter. 

http://www.robbreck.net/blog/enterprise_information_security/security-leads-to-compliance/
http://www.robbreck.net/blog/enterprise_information_security/proactive-security-versus-reactive-compliance/
http://www.robbreck.net/blog/enterprise_information_security/compliance-leads-to-security-breaches/

I am looking forward to your thoughts. I am always interested in dialog about these subjects. 

-Robb</description>
		<content:encoded><![CDATA[<p>Daya,</p>
<p>Thanks for the note. I believe that the intent behind of the quote you mention (&#8220;The destination should achieve compliance, not be compliance&#8221;) is that when organizations are architecting their security programs it should be done with an eye toward implementing proper security, NOT toward passing a particular regulation or standard. I have written a few blog posts on this topic in the past if you want to read my thoughts on the matter. </p>
<p><a href="http://www.robbreck.net/blog/enterprise_information_security/security-leads-to-compliance/" rel="nofollow">http://www.robbreck.net/blog/enterprise_information_security/security-leads-to-compliance/</a><br />
<a href="http://www.robbreck.net/blog/enterprise_information_security/proactive-security-versus-reactive-compliance/" rel="nofollow">http://www.robbreck.net/blog/enterprise_information_security/proactive-security-versus-reactive-compliance/</a><br />
<a href="http://www.robbreck.net/blog/enterprise_information_security/compliance-leads-to-security-breaches/" rel="nofollow">http://www.robbreck.net/blog/enterprise_information_security/compliance-leads-to-security-breaches/</a></p>
<p>I am looking forward to your thoughts. I am always interested in dialog about these subjects. </p>
<p>-Robb</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on RSA Conference 2012: Day 1 Highlights by Daya Puls</title>
		<link>http://www.robbreck.net/blog/enterprise_information_security/rsa-conference-2012-highlights/#comment-568</link>
		<dc:creator>Daya Puls</dc:creator>
		<pubDate>Sun, 04 Mar 2012 17:44:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.robbreck.net/blog/?p=425#comment-568</guid>
		<description>Hi Robb, Thanks for your RSA Conference 2012 thoughts. I was unable to attend this year and have been going through conference withdrawal.

I am interested in hearing more about one of your bulleted items above; &#039;“The destination should achieve compliance, not be compliance.”&#039; First, I&#039;d like to understand what you mean before I can agree or disagree. Do you mean that our efforts to secure the enterprise should achieve compliance and that our destination should not just be meeting some compliance standard?

Thanks again.

Daya</description>
		<content:encoded><![CDATA[<p>Hi Robb, Thanks for your RSA Conference 2012 thoughts. I was unable to attend this year and have been going through conference withdrawal.</p>
<p>I am interested in hearing more about one of your bulleted items above; &#8216;“The destination should achieve compliance, not be compliance.”&#8217; First, I&#8217;d like to understand what you mean before I can agree or disagree. Do you mean that our efforts to secure the enterprise should achieve compliance and that our destination should not just be meeting some compliance standard?</p>
<p>Thanks again.</p>
<p>Daya</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Security impact of putting it in the cloud by Ren Li</title>
		<link>http://www.robbreck.net/blog/enterprise_information_security/security-impact-of-putting-it-in-the-cloud/#comment-563</link>
		<dc:creator>Ren Li</dc:creator>
		<pubDate>Wed, 22 Feb 2012 00:51:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.robbreck.net/blog/?p=415#comment-563</guid>
		<description>From the outsourcing prospect of adopting cloud, considering issues wrapped around service providers, the sensitivity of data that will be release to the providers, and the people who will be allowed to access the cloud would probably be a good idea before adopting the cloud service. I think that the sensitivity of data must be considered first and above everything. Just like that before you upload a picture onto the Internet, you have to consider whether it contains private factors first. Because you know that once it is uploaded, everything pretty much gone wild like spreading fire.</description>
		<content:encoded><![CDATA[<p>From the outsourcing prospect of adopting cloud, considering issues wrapped around service providers, the sensitivity of data that will be release to the providers, and the people who will be allowed to access the cloud would probably be a good idea before adopting the cloud service. I think that the sensitivity of data must be considered first and above everything. Just like that before you upload a picture onto the Internet, you have to consider whether it contains private factors first. Because you know that once it is uploaded, everything pretty much gone wild like spreading fire.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Why do we Pen Test? by Robb Reck</title>
		<link>http://www.robbreck.net/blog/enterprise_information_security/why-do-we-pen-test/#comment-549</link>
		<dc:creator>Robb Reck</dc:creator>
		<pubDate>Fri, 13 Jan 2012 23:21:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.robbreck.net/blog/?p=406#comment-549</guid>
		<description>Thomas,

I definitely agree. InfoSec and Audit (Internal Audit at least) have much more in common than they do different. And both teams can be much more effective by working together. Please take a look at a post I wrote about the subject a while back. 

http://www.robbreck.net/blog/enterprise_information_security/internal-audit-and-information-security/</description>
		<content:encoded><![CDATA[<p>Thomas,</p>
<p>I definitely agree. InfoSec and Audit (Internal Audit at least) have much more in common than they do different. And both teams can be much more effective by working together. Please take a look at a post I wrote about the subject a while back. </p>
<p><a href="http://www.robbreck.net/blog/enterprise_information_security/internal-audit-and-information-security/" rel="nofollow">http://www.robbreck.net/blog/enterprise_information_security/internal-audit-and-information-security/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Why do we Pen Test? by Thomas Butler, CPA, CIA, CISSP, CEH, ECSA, LPT, CISA</title>
		<link>http://www.robbreck.net/blog/enterprise_information_security/why-do-we-pen-test/#comment-548</link>
		<dc:creator>Thomas Butler, CPA, CIA, CISSP, CEH, ECSA, LPT, CISA</dc:creator>
		<pubDate>Fri, 13 Jan 2012 22:46:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.robbreck.net/blog/?p=406#comment-548</guid>
		<description>It is the same situation with auditing.</description>
		<content:encoded><![CDATA[<p>It is the same situation with auditing.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

