<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss'><id>tag:blogger.com,1999:blog-7185731378551246027</id><updated>2009-12-20T09:32:28.627-05:00</updated><title type='text'>Red Light Security</title><subtitle type='html'>Techniques, trends, and tidbits for Information Security Professionals</subtitle><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default?start-index=26&amp;max-results=25'/><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.redlightsecurity.com/feeds/atom.xml'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>35</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-552796860769765128</id><published>2009-12-20T08:39:00.002-05:00</published><updated>2009-12-20T08:41:51.367-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Application Security'/><title type='text'>Breach of the Drones</title><summary type='text'>When it was discovered that video feeds from U.S. Predator and Reaper unmanned drones were being hacked by insurgents in Iraq, it became evident that cybersecurity has a long way to go to become more secure. The natural reaction is to point the finger at software producers, the government, and the push for functionality over security. But it may be that a different model is needed for the </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/552796860769765128/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=552796860769765128' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/552796860769765128'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/552796860769765128'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2009/12/breach-of-drones.html' title='Breach of the Drones'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-6120234179498425439</id><published>2009-12-16T07:00:00.001-05:00</published><updated>2009-12-16T08:10:03.971-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Secure Coding Practices'/><category scheme='http://www.blogger.com/atom/ns#' term='Application Security'/><title type='text'>Implementing Trust Between Systems</title><summary type='text'>When designing or reviewing a system, it is common to ensure that trust is established between end-users and the applications. Trust in this context means that the users are trusted because they have proven their identity, and their authority to access the application has been verified. Many times, trust between system components is overlooked. This can be a deadly sin for software design that </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/6120234179498425439/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=6120234179498425439' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/6120234179498425439'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/6120234179498425439'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2009/12/implementing-trust-between-systems.html' title='Implementing Trust Between Systems'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-5167896681919723085</id><published>2009-12-15T07:00:00.003-05:00</published><updated>2009-12-15T07:29:20.123-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Career'/><title type='text'>Cybersecurity in 2010: Bubble or Blip?</title><summary type='text'>Take a look at Google trends for the word "cybersecurity", and see what you find. In the third quarter of 2008, there were two small blips on the radar for this search term. In 2009 there was a sharp rise throughout the year. What will 2010 look like for cybersecurity, and are we at the beginning of a cybersecurity bubble?The Internet bubble was driven primarily by new web technologies and the </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/5167896681919723085/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=5167896681919723085' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/5167896681919723085'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/5167896681919723085'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2009/12/cybersecurity-in-2010-bubble-or-blip.html' title='Cybersecurity in 2010: Bubble or Blip?'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-7605474681107572538</id><published>2009-12-14T07:00:00.000-05:00</published><updated>2009-12-14T07:08:14.613-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Career'/><category scheme='http://www.blogger.com/atom/ns#' term='Critical Infrastructure Protection'/><title type='text'>Cybersecurity Government Job Fair</title><summary type='text'>With the increasing attention to cybersecurity in the government sector and in critical infrastructure protection, the Department of Homeland Security announced in October that it would be hiring for as many as 1,000 cybersecurity jobs. DHS is moving forward on that promise with a virtual job fair.The job fair can be accessed at http://www.dhs.gov/xabout/careers/cyberjobfair, and it works like a </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/7605474681107572538/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=7605474681107572538' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/7605474681107572538'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/7605474681107572538'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2009/12/cybersecurity-government-job-fair.html' title='Cybersecurity Government Job Fair'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-666659197247676097</id><published>2009-12-13T09:26:00.000-05:00</published><updated>2009-12-13T09:32:02.993-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cryptography'/><category scheme='http://www.blogger.com/atom/ns#' term='Security Tools'/><title type='text'>On-the-fly Encryption with TrueCrypt</title><summary type='text'>How sensitive is your data? You may use highly confidential data at work or at home. If you are concerned about the potential exposure of that data, encryption may be a good solution for ensuring that your data remains protected. One tool that you can use to encrypt your data is TrueCrypt. It is a free, open source program that works on Windows 7/Vista/XP, Mac OS X, and Linux.TrueCrypt is a very </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/666659197247676097/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=666659197247676097' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/666659197247676097'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/666659197247676097'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2009/12/on-fly-encryption-with-truecrypt.html' title='On-the-fly Encryption with TrueCrypt'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-898918706450493912</id><published>2008-04-28T20:58:00.005-04:00</published><updated>2009-12-11T23:50:30.909-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virtualization'/><title type='text'>Spinning Out of Control: Securely Managing Virtual Sprawl</title><summary type='text'>Server virtualization is taking hold. It boasts so many advantages that it is likely to become the standard for data centers around the world. It saves money by maximizing hardware resources. It reduces the number of physical servers, which reduces power consumption. It also revolutionizes server deployment by allowing servers to be copied as easily as files on the file system. Add to this the </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/898918706450493912/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=898918706450493912' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/898918706450493912'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/898918706450493912'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2008/04/spinning-out-of-control-securely.html' title='Spinning Out of Control: Securely Managing Virtual Sprawl'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-1563012877600896537</id><published>2008-04-16T22:18:00.007-04:00</published><updated>2009-12-12T17:28:15.156-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virtualization'/><title type='text'>Virtualization: Red Pill or Blue?</title><summary type='text'>Virtualization technologies have been compared to the movie, The Matrix. In this, Neo and other humans, are captured in a virtual world. Neo is offered a blue pill or a red pill. The blue pill will return him to his normal unreal world in the matrix. The red will set his mind free by exposing the matrix. When it comes to virtualization technologies, the red pill and blue pill have similar </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/1563012877600896537/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=1563012877600896537' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/1563012877600896537'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/1563012877600896537'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2008/04/virtualization-red-pill-or-blue.html' title='Virtualization: Red Pill or Blue?'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-2258492525403911821</id><published>2008-04-13T09:47:00.004-04:00</published><updated>2009-12-12T17:29:29.434-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virtualization'/><title type='text'>Patch Management In a Virtual World</title><summary type='text'>As more and more companies adopt virtualization in their data centers to reduce the number of physical servers and save money, security strategies need to be developed in parallel. While security may push back on this movement and resist its adoption, it will be far more beneficial to develop security strategies to deal effectively with advancing virtualization technologies.Patch management is </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/2258492525403911821/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=2258492525403911821' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/2258492525403911821'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/2258492525403911821'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2008/04/patch-management-in-virtual-world.html' title='Patch Management In a Virtual World'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-1667508377851756975</id><published>2008-03-11T18:37:00.005-04:00</published><updated>2009-12-12T17:30:01.028-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Process'/><title type='text'>Six Sigma for Security, Part 5: Staying in Control</title><summary type='text'>After you have moved through the define, measure, analyze, and improve stages of your Six Sigma for Security project, you are ready to move into the control phase. Your security operations should always operate in the control phase. If so, the control phase for Six Sigma is merely a matter of adding your improvements into your existing controls.Here are some tools that you may find helpful in the</summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/1667508377851756975/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=1667508377851756975' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/1667508377851756975'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/1667508377851756975'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2008/03/six-sigma-for-security-part-5-staying.html' title='Six Sigma for Security, Part 5: Staying in Control'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-3409058256914412681</id><published>2008-03-08T16:45:00.004-05:00</published><updated>2009-12-12T17:30:27.769-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Process'/><title type='text'>Six Sigma for Security, Part 4: Making Improvements</title><summary type='text'>You have made your security program measurable. You have identified problem areas that keep you from meeting targets in your critical to quality (CTQ) goals. Now it is time to move on to making improvements and measuring their effectiveness.One of the great things about Six Sigma is that improvements are tied to specific metrics, with a goal to reduce variation and improve your average. To make </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/3409058256914412681/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=3409058256914412681' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/3409058256914412681'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/3409058256914412681'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2008/03/six-sigma-for-security-part-4-making.html' title='Six Sigma for Security, Part 4: Making Improvements'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-4373214918745434451</id><published>2008-03-06T22:09:00.005-05:00</published><updated>2009-12-12T17:31:49.723-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Process'/><title type='text'>Six Sigma for Security, Part 3: Analyzing the Data</title><summary type='text'>Making security measurable is only the beginning of Six Sigma for Security. The purpose of security metrics is not the metrics themselves but what you do with them. The next phase is to analyze the data and find opportunities for improvement.The analysis phase is what makes Six Sigma stand out. In it you will use statistics to find where you can make improvements. There are two improvements in </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/4373214918745434451/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=4373214918745434451' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/4373214918745434451'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/4373214918745434451'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2008/03/six-sigma-for-security-part-3-analyzing.html' title='Six Sigma for Security, Part 3: Analyzing the Data'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-685587884650168120</id><published>2008-03-05T21:26:00.006-05:00</published><updated>2009-12-12T17:32:17.209-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Process'/><title type='text'>Six Sigma for Security, Part 2: Measuring</title><summary type='text'>After you have defined the Critical to Quality (CTQ) goals of your security program, the next step is to determine how to measure them. Creating a measurement plan for security is like creating a scoreboard. It allows you to gauge at any time how successful you are and your level of protection.Keep in mind that at the outset of this Six Sigma project we determined that we would not just measure </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/685587884650168120/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=685587884650168120' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/685587884650168120'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/685587884650168120'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2008/03/six-sigma-for-security-part-2-measuring.html' title='Six Sigma for Security, Part 2: Measuring'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-5264607011024732873</id><published>2008-03-01T19:27:00.007-05:00</published><updated>2009-12-12T17:32:49.291-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Process'/><title type='text'>Six Sigma for Security, Part 1: Defining Success</title><summary type='text'>How do you measure the effectiveness of your security program? Unlike business metrics which have tangible goals, such as revenue growth, inventory reduction, and sales force effectiveness, security's goal is to prevent internal and external breaches. Your goal in security should be to have nothing to measure - no virus attacks, no external breaches, no successful social engineering attacks, no </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/5264607011024732873/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=5264607011024732873' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/5264607011024732873'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/5264607011024732873'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2008/03/six-sigma-for-security-part-1-defining.html' title='Six Sigma for Security, Part 1: Defining Success'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-6510557424614684861</id><published>2008-03-01T08:33:00.007-05:00</published><updated>2009-12-12T17:56:01.575-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Privacy'/><title type='text'>Privacy on the Web, Part 4: How to Hide from Web Beacons</title><summary type='text'>Why would I want to hide from web beacons and consolidated web traffic analysis? I don't have anything to hide. We each make decisions about how much privacy and security to give up to gain convenience. The settings in web browsers - to save passwords, accept third party cookies, and keep authenticated sessions persistent over many days and across many sites - make using the web easier. For some </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/6510557424614684861/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=6510557424614684861' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/6510557424614684861'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/6510557424614684861'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2008/03/privacy-on-web-part-4-how-to-hide-from.html' title='Privacy on the Web, Part 4: How to Hide from Web Beacons'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-7104820343030888639</id><published>2008-02-06T06:40:00.004-05:00</published><updated>2009-12-12T17:57:01.600-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Privacy'/><title type='text'>Privacy on the Web, Part 3: Analytics, Recommendations, Summarizing, and Anonymity</title><summary type='text'>Since web beacons from outsourcing companies may be able to track your every move, you may wonder what they are doing with your information. This post discusses the positive side of collecting and using this information. It also touches on the issue of anonymity and privacy.AnalyticsIf you are running a web site today, you are probably using some form of web analytics. From the multi-billion </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/7104820343030888639/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=7104820343030888639' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/7104820343030888639'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/7104820343030888639'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2008/02/privacy-on-web-part-3-analytics.html' title='Privacy on the Web, Part 3: Analytics, Recommendations, Summarizing, and Anonymity'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-8860394597827585918</id><published>2008-02-05T06:14:00.002-05:00</published><updated>2009-12-12T17:57:40.724-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Privacy'/><title type='text'>Privacy on the Web, Part 2: How Beacons Work</title><summary type='text'>Web beacons are snippets of Javascript or HTML that create one pixel by one pixel image requests to a different web site that collects the data. This single pixel is invisible to the viewer of the web site. It is usually placed just inside the closing "body" tag of the page, although some analytics companies recommend that it be placed inside the opening "body" tag to improve accuracy.There are </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/8860394597827585918/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=8860394597827585918' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/8860394597827585918'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/8860394597827585918'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2008/02/privacy-on-web-part-2-how-beacons-work.html' title='Privacy on the Web, Part 2: How Beacons Work'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-57659467241077998</id><published>2008-02-04T05:48:00.004-05:00</published><updated>2009-12-12T17:58:19.156-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Privacy'/><title type='text'>Privacy on the Web, Part 1: The Beacons Know You</title><summary type='text'>Did you ever notice how a web site you have never visited before knows your interests enough to give you targeted advertisements? Sometimes, the ads are based on the content of the site, but other times, there appears to be no connection. There is an approach to collecting user information that crosses web site boundaries and maintains a history of your preferences.You may ask, how is this </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/57659467241077998/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=57659467241077998' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/57659467241077998'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/57659467241077998'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2008/02/privacy-on-web-part-1-beacons-know-you.html' title='Privacy on the Web, Part 1: The Beacons Know You'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-1431381661840948167</id><published>2008-02-01T06:11:00.002-05:00</published><updated>2009-12-13T09:40:15.709-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Process'/><title type='text'>Security Process Maturity: Level 5</title><summary type='text'>Security managers are often plagued by the question, “How do I make security measurable?” Since security does not produce a product or have a positive impact on the cash flow of a company, creating meaningful measurements that justify an organizations expenditure on security is challenging. This is where ISM3 provides a great tool for measuring security.ISM3's level five is about taking all of </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/1431381661840948167/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=1431381661840948167' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/1431381661840948167'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/1431381661840948167'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2008/02/security-process-maturity-level-5.html' title='Security Process Maturity: Level 5'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-8279307499924822114</id><published>2008-01-31T06:30:00.002-05:00</published><updated>2009-12-13T09:40:44.939-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Process'/><title type='text'>Security Process Maturity: Level 4</title><summary type='text'>Level four of ISM3 adds the remaining security processes in the model. This level requires the highest investment, but provides the highest level of protection against technical and internal threats. The security processes in this level are necessary if your organization operates in a highly regulated environments with information assets that are targets for attackers. Examples include stock </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/8279307499924822114/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=8279307499924822114' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/8279307499924822114'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/8279307499924822114'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2008/01/security-process-maturity-level-4.html' title='Security Process Maturity: Level 4'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-228876418663443418</id><published>2008-01-30T06:18:00.002-05:00</published><updated>2009-12-13T09:42:27.135-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Process'/><title type='text'>Security Process Maturity: Level 3</title><summary type='text'>The third level of ISM3 requires significant investment, but it provides a high level of protection against technical security threats. This level is important for organizations that have high security risks and many critical assets, especially externally facing applications.The jump from level two to level three does not add many processes, but the processes require more people and time </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/228876418663443418/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=228876418663443418' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/228876418663443418'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/228876418663443418'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2008/01/security-process-maturity-level-3.html' title='Security Process Maturity: Level 3'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-3132052436203367236</id><published>2008-01-29T06:45:00.002-05:00</published><updated>2009-12-13T09:43:04.551-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Process'/><title type='text'>Security Process Maturity: Level 2</title><summary type='text'>For most businesses, level one will not provide enough security to protect their information assets. If a company needs to demonstrate due care to its business partners, has many users of server-based applications, and sensitive information, it needs to move up to the security processes listed in ISM3's second level.Level two provides additional protection against technical security threats. It </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/3132052436203367236/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=3132052436203367236' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/3132052436203367236'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/3132052436203367236'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2008/01/security-process-maturity-level-2.html' title='Security Process Maturity: Level 2'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-1082571006704931093</id><published>2008-01-28T05:45:00.002-05:00</published><updated>2009-12-13T09:44:20.042-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Process'/><title type='text'>Security Process Maturity: Level 1</title><summary type='text'>How mature is security in your organization? Thanks to the ISM3 Consortium, we have a framework for measuring the security maturity of any organization. ISM3 looks at security as a set of defined processes. Each level of maturity has its own processes. Organizations can decide how much security is enough for their type of business and ensure that the processes at that level are defined and </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/1082571006704931093/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=1082571006704931093' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/1082571006704931093'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/1082571006704931093'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2008/01/security-process-maturity-level-1.html' title='Security Process Maturity: Level 1'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-2809301779909008042</id><published>2008-01-25T06:38:00.001-05:00</published><updated>2008-03-02T16:41:21.001-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Secure Coding Practices'/><title type='text'>Secure Coding Practices, Part 11: The Checklist</title><summary type='text'>This post wraps up the series on secure coding practices. Remember that secure coding begins with having coding standards that are communicated to software engineers. Awareness of the secure coding practices alone will help improve the security of your software applications.Next, remember that source code must be reviewed. This practice may be performed by software engineers, by a security </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/2809301779909008042/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=2809301779909008042' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/2809301779909008042'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/2809301779909008042'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2008/01/secure-coding-practices-part-11.html' title='Secure Coding Practices, Part 11: The Checklist'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-1009163540635153108</id><published>2008-01-24T09:56:00.001-05:00</published><updated>2008-03-02T16:40:42.515-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Secure Coding Practices'/><title type='text'>Secure Coding Practices, Part 10: Code Quality</title><summary type='text'>Overall code quality is important for secure applications. Software bugs may create opportunities for attackers to exploit the application or gain information they should not have about system internals or even user credentials.Security professionals may not know enough about the code they review to understand what is a defect and potential vulnerability. Some developers also overlook coding </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/1009163540635153108/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=1009163540635153108' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/1009163540635153108'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/1009163540635153108'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2008/01/secure-coding-practices-part-10-code.html' title='Secure Coding Practices, Part 10: Code Quality'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7185731378551246027.post-7854288078782357443</id><published>2008-01-23T06:04:00.001-05:00</published><updated>2008-03-02T16:40:12.544-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Secure Coding Practices'/><title type='text'>Secure Coding Practices, Part 9: Performance</title><summary type='text'>One of the security professional's concerns is the availability of systems. Although this may seem like the sole responsibility of the IT operations department, security assesses the risk to the availability of critical information assets. This is because attackers may not care about retrieving information or gaining access to your systems. They may simply want to attack your system to make it </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/7854288078782357443/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=7185731378551246027&amp;postID=7854288078782357443' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/7854288078782357443'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7185731378551246027/posts/default/7854288078782357443'/><link rel='alternate' type='text/html' href='http://www.redlightsecurity.com/2008/01/secure-coding-practices-part-9.html' title='Secure Coding Practices, Part 9: Performance'/><author><name>Steven McElwee</name><uri>http://www.blogger.com/profile/11941856369020054122</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13932001650989478284'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry></feed>