<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-2136426982704236755.post8194605051078518464..comments</id><updated>2009-06-30T08:09:40.657-07:00</updated><category term='mobile'/><category term='organizations'/><category term='cyberwar'/><category term='smarg_grid'/><category term='standards/policies'/><category term='certifications'/><category term='instruction'/><category term='malware/exploits/vulns'/><category term='newsmedia'/><category term='privacy'/><category term='security_fail'/><category term='complexity'/><category term='press'/><category term='RSA'/><category term='patches'/><category term='drinfosec'/><category term='presentation'/><category term='medical'/><category term='academia'/><category term='email'/><category term='security_solutions'/><category term='humor'/><category term='future'/><category term='keynotes'/><category term='reviews'/><category term='research'/><category term='process'/><category term='security_hype'/><category term='government'/><category term='legal'/><category term='cloud'/><category term='terrorism'/><category term='forensics'/><category term='misc'/><category term='cybercrime'/><category term='report'/><category term='people'/><category term='qotd'/><category term='web2.0'/><category term='irp/drp/bcp'/><category term='wireless'/><category term='education/training/awareness'/><category term='financial_data'/><category term='social_networking'/><category term='metrics_and_risk'/><category term='e-spy'/><category term='health'/><category term='conferences'/><category term='management'/><title type='text'>Comments on Dr. InfoSec™: Data security 'flouted by workers'</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.drinfosec.com/feeds/8194605051078518464/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2136426982704236755/8194605051078518464/comments/default'/><link rel='alternate' type='text/html' href='http://blog.drinfosec.com/2009/06/data-security-flouted-by-workers.html'/><author><name>DrInfoSec</name><uri>http://www.blogger.com/profile/04203172703592313484</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2136426982704236755.post-8212920019123368045</id><published>2009-06-30T08:09:40.657-07:00</published><updated>2009-06-30T08:09:40.657-07:00</updated><title type='text'>Dennis&amp;#39;s point about cost justification reinfo...</title><content type='html'>Dennis&amp;#39;s point about cost justification reinforces the first bullet point in my original post. Without appropriate support for Information security, companies are locked in a reactive cycle of risk management.&lt;br /&gt;&lt;br /&gt;In order to evolve from a reactive stance (event occurs, costs incurred, security gets management&amp;#39;s attention) to a pro-active stance (i.e. actively track and manage risks), executive management and information security have to improve their ability to communicate. &lt;br /&gt;&lt;br /&gt;In a perfect world, both sides would modify the way they communicate to reach each other. In practice, the information security side has to find the right approach to reach their management&amp;#39;s attention to appropriately convey the business impact of non-action.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2136426982704236755/8194605051078518464/comments/default/8212920019123368045'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2136426982704236755/8194605051078518464/comments/default/8212920019123368045'/><link rel='alternate' type='text/html' href='http://blog.drinfosec.com/2009/06/data-security-flouted-by-workers.html?showComment=1246374580657#c8212920019123368045' title=''/><author><name>DrInfoSec</name><uri>http://www.blogger.com/profile/04203172703592313484</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.drinfosec.com/2009/06/data-security-flouted-by-workers.html' ref='tag:blogger.com,1999:blog-2136426982704236755.post-8194605051078518464' source='http://www.blogger.com/feeds/2136426982704236755/posts/default/8194605051078518464' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1649172088'/></entry><entry><id>tag:blogger.com,1999:blog-2136426982704236755.post-5409809929351169002</id><published>2009-06-30T07:47:28.847-07:00</published><updated>2009-06-30T07:47:28.847-07:00</updated><title type='text'>You forgot about cost justification.  Most people ...</title><content type='html'>You forgot about cost justification.  Most people won&amp;#39;t initiate any security initiatives until an outage, attack, or outbreak impacts their bottom line.&lt;br /&gt;&lt;br /&gt;Information Security has at least made it from the back room to the board room.  And those in the board room are extremely concerned about how much money an incident cost them.  If the focus towards security is measured as a cost to prevent the cumulative cost from an incident, then the you will win the backing of the higher management teams.&lt;br /&gt;&lt;br /&gt;Let&amp;#39;s face it, they don&amp;#39;t care about the bells and whistles, they just want to know that the money spent is going to keep the company name, and theirs, from being in the media for a breach/incident.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2136426982704236755/8194605051078518464/comments/default/5409809929351169002'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2136426982704236755/8194605051078518464/comments/default/5409809929351169002'/><link rel='alternate' type='text/html' href='http://blog.drinfosec.com/2009/06/data-security-flouted-by-workers.html?showComment=1246373248847#c5409809929351169002' title=''/><author><name>Dennis_London</name><uri>http://www.blogger.com/profile/03076696284635984480</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.drinfosec.com/2009/06/data-security-flouted-by-workers.html' ref='tag:blogger.com,1999:blog-2136426982704236755.post-8194605051078518464' source='http://www.blogger.com/feeds/2136426982704236755/posts/default/8194605051078518464' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1894155060'/></entry></feed>
