<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jon&#039;s Network &#187; around the web girl</title>
	<atom:link href="http://jonsnetwork.com/category/around-the-web-girl/feed/" rel="self" type="application/rss+xml" />
	<link>http://jonsnetwork.com</link>
	<description>Network Security News, Analysis and Ephemera</description>
	<lastBuildDate>Tue, 06 Mar 2012 08:01:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>RSA Conference 2012</title>
		<link>http://jonsnetwork.com/2012/03/rsa-conference-2012/</link>
		<comments>http://jonsnetwork.com/2012/03/rsa-conference-2012/#comments</comments>
		<pubDate>Mon, 05 Mar 2012 16:34:43 +0000</pubDate>
		<dc:creator>Jon</dc:creator>
				<category><![CDATA[around the web girl]]></category>

		<guid isPermaLink="false">http://jonsnetwork.com/?p=914</guid>
		<description><![CDATA[RSA 2012 was my first RSA. I used a vendor code to get an expo-only pass. I&#8217;ll be attending again since it&#8217;s a good chance to visit vendors, customers, prospects and online buddies in a short amount of time. I had the chance to speak briefly to Richard Bejtlich, whose NSM principles we borrow from [...]]]></description>
			<content:encoded><![CDATA[<p>RSA 2012 was my first RSA.  I used a vendor code to get an expo-only pass. I&#8217;ll be attending again since it&#8217;s a good chance to visit vendors, customers, prospects and online buddies in a short amount of time.</p>

<p>I had the chance to speak briefly to <a href="http://taosecurity.blogspot.com/">Richard Bejtlich</a>, whose NSM principles we borrow from at our company when giving advice to customers.  I recently revived my interest in metrics so I asked about metrics. He said to track two metrics: incidents per unit time and elapsed time to resolution per incident.  An incident is whatever your organization thinks it is.</p>

<p>I was as a breakfast on Wednesday morning with a panel of about 8 CISOs from large corporations.  Afterward I asked a couple of them which KPIs they use or have developed.  I know the sample size is small, but it appears that they all develop their own indicators and don&#8217;t share with other CISOs or are in the process of developing them.  The reason for this is no company wants anyone to see how much money they spend on security or risk they tolerate compared to their peers.  Seems to me that they wouldn&#8217;t be giving their peers any advantage but perhaps there is a social stigma to sharing this stuff &#8211; like admitting you have herpes. </p>

<p>During the breakfast, a few of the CISOs also mentioned that security ROI is a waste of time and just to look at TCO.  I&#8217;m of the opinion that you can&#8217;t avoid at least a gut ROI calculation.  If you calculate the TCO, then decide it is worth purchasing, you just calculated the ROI right?  My need to call it something else since it isn&#8217;t an investment per se.  Paying for security is usually trying to avoid a probable loss.  Like paying extra for a car with airbags</p>

<p>These same CISOs also said quantitative risk management is a waste of time and unnecessary.  I don&#8217;t think you can escape at least a gut risk calculation and that the quantitative and qualitative are just different ends of a spectrum rather than binary options.</p>
]]></content:encoded>
			<wfw:commentRss>http://jonsnetwork.com/2012/03/rsa-conference-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Find Files with No User or Group</title>
		<link>http://jonsnetwork.com/2011/08/find-files-with-no-user-or-group/</link>
		<comments>http://jonsnetwork.com/2011/08/find-files-with-no-user-or-group/#comments</comments>
		<pubDate>Sat, 20 Aug 2011 23:21:30 +0000</pubDate>
		<dc:creator>Jon</dc:creator>
				<category><![CDATA[around the web girl]]></category>

		<guid isPermaLink="false">http://jonsnetwork.com/?p=899</guid>
		<description><![CDATA[This command can yield some interesting information: find / -nouser -o -nogroup Learned about it while playing with NeXpose today.]]></description>
			<content:encoded><![CDATA[<p>This command can yield some interesting information:</p>

<p><code>find / -nouser -o -nogroup</code></p>

<p>Learned about it while playing with NeXpose today.</p>
]]></content:encoded>
			<wfw:commentRss>http://jonsnetwork.com/2011/08/find-files-with-no-user-or-group/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mobile Security Webcast</title>
		<link>http://jonsnetwork.com/2011/07/mobile-security-webcast/</link>
		<comments>http://jonsnetwork.com/2011/07/mobile-security-webcast/#comments</comments>
		<pubDate>Sat, 16 Jul 2011 05:29:14 +0000</pubDate>
		<dc:creator>Jon</dc:creator>
				<category><![CDATA[around the web girl]]></category>

		<guid isPermaLink="false">http://jonsnetwork.com/2011/07/mobile-security-webcast/</guid>
		<description><![CDATA[Here is a recorded webcast by Daniel Miessler:http://t.co/Zf5GhL8]]></description>
			<content:encoded><![CDATA[<div class='posterous_autopost'>Here is a recorded webcast by Daniel Miessler:<p /><div><span style="font-family: arial, sans-serif; font-size: 13px; line-height: 18px;"><a href="http://t.co/Zf5GhL8" class="ot-anchor" style="color: rgb(51, 102, 204); cursor: pointer; text-decoration: none;">http://t.co/Zf5GhL8</a></span></div>  </div>
]]></content:encoded>
			<wfw:commentRss>http://jonsnetwork.com/2011/07/mobile-security-webcast/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bank Robbery Analysis</title>
		<link>http://jonsnetwork.com/2011/07/bank-robbery-analysis/</link>
		<comments>http://jonsnetwork.com/2011/07/bank-robbery-analysis/#comments</comments>
		<pubDate>Thu, 14 Jul 2011 06:31:08 +0000</pubDate>
		<dc:creator>Jon</dc:creator>
				<category><![CDATA[around the web girl]]></category>

		<guid isPermaLink="false">http://jonsnetwork.com/2011/07/bank-robbery-analysis/</guid>
		<description><![CDATA[Interesting article that applies the OSSTMM to a famous diamond heist. http://www.isecom.org/Bank_Robbery_Analysis_OSSTMM3.pdf]]></description>
			<content:encoded><![CDATA[<div class='posterous_autopost'>Interesting article that applies the OSSTMM to a famous diamond heist. <p /> <a href="http://www.isecom.org/Bank_Robbery_Analysis_OSSTMM3.pdf">http://www.isecom.org/Bank_Robbery_Analysis_OSSTMM3.pdf</a>  </div>
]]></content:encoded>
			<wfw:commentRss>http://jonsnetwork.com/2011/07/bank-robbery-analysis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Internet sales tax: Online retailers to start collecting sales taxes in California</title>
		<link>http://jonsnetwork.com/2011/06/internet-sales-tax-online-retailers-to-start-collecting-sales-taxes-in-california/</link>
		<comments>http://jonsnetwork.com/2011/06/internet-sales-tax-online-retailers-to-start-collecting-sales-taxes-in-california/#comments</comments>
		<pubDate>Thu, 30 Jun 2011 23:24:23 +0000</pubDate>
		<dc:creator>Jon</dc:creator>
				<category><![CDATA[around the web girl]]></category>

		<guid isPermaLink="false">http://jonsnetwork.com/2011/06/internet-sales-tax-online-retailers-to-start-collecting-sales-taxes-in-california/</guid>
		<description><![CDATA[Well, this just sucks. http://www.latimes.com/business/la-fi-amazon-tax-20110630,0,4344787.story]]></description>
			<content:encoded><![CDATA[<div class='posterous_autopost'>Well, this just sucks. <p /> <a href="http://www.latimes.com/business/la-fi-amazon-tax-20110630,0,4344787.story">http://www.latimes.com/business/la-fi-amazon-tax-20110630,0,4344787.story</a>  </div>
]]></content:encoded>
			<wfw:commentRss>http://jonsnetwork.com/2011/06/internet-sales-tax-online-retailers-to-start-collecting-sales-taxes-in-california/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>$1 Billion That Nobody Wants</title>
		<link>http://jonsnetwork.com/2011/06/1-billion-that-nobody-wants/</link>
		<comments>http://jonsnetwork.com/2011/06/1-billion-that-nobody-wants/#comments</comments>
		<pubDate>Thu, 30 Jun 2011 03:35:56 +0000</pubDate>
		<dc:creator>Jon</dc:creator>
				<category><![CDATA[around the web girl]]></category>

		<guid isPermaLink="false">http://jonsnetwork.com/2011/06/1-billion-that-nobody-wants/</guid>
		<description><![CDATA[http://n.pr/ilLcLO No one wants to use the dollar coins the government is minting and they are piling up in a warehouse. They keep minting them though because of congressional mandate.]]></description>
			<content:encoded><![CDATA[<div class='posterous_autopost'><a href="http://n.pr/ilLcLO">http://n.pr/ilLcLO</a> <p /> No one wants to use the dollar coins the government is minting and they are piling up in a warehouse. They keep minting them though because of congressional mandate.  </div>
]]></content:encoded>
			<wfw:commentRss>http://jonsnetwork.com/2011/06/1-billion-that-nobody-wants/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phone Marketing Blacklist</title>
		<link>http://jonsnetwork.com/2011/06/phone-marketing-blacklist/</link>
		<comments>http://jonsnetwork.com/2011/06/phone-marketing-blacklist/#comments</comments>
		<pubDate>Tue, 28 Jun 2011 20:35:51 +0000</pubDate>
		<dc:creator>Jon</dc:creator>
				<category><![CDATA[around the web girl]]></category>

		<guid isPermaLink="false">http://jonsnetwork.com/2011/06/phone-marketing-blacklist/</guid>
		<description><![CDATA[I have been getting calls at my work number from an 800 number where the caller is a recording. Usually it is at night or on the weekend so I just get a voice message of the recording. Today I picked up and out of habit hit &#8217;3&#8242; since that is delete on my voicemail [...]]]></description>
			<content:encoded><![CDATA[<div class='posterous_autopost'>I have been getting calls at my work number from an 800 number where the caller is a recording. Usually it is at night or on the weekend so I just get a voice message of the recording. Today I picked up and out of habit hit &#8217;3&#8242; since that is delete on my voicemail service. The call transferred to the blacklist service where I received instructions on how to remove my number from their list. Just had to hit &#8217;2&#8242;. I guess I got lucky.  </div>
]]></content:encoded>
			<wfw:commentRss>http://jonsnetwork.com/2011/06/phone-marketing-blacklist/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DEF CON® 19 Hacking Conference</title>
		<link>http://jonsnetwork.com/2011/06/def-con%c2%ae-19-hacking-conference/</link>
		<comments>http://jonsnetwork.com/2011/06/def-con%c2%ae-19-hacking-conference/#comments</comments>
		<pubDate>Thu, 09 Jun 2011 05:44:16 +0000</pubDate>
		<dc:creator>Jon</dc:creator>
				<category><![CDATA[around the web girl]]></category>

		<guid isPermaLink="false">http://jonsnetwork.com/2011/06/def-con%c2%ae-19-hacking-conference/</guid>
		<description><![CDATA[I think I will go this year. https://www.defcon.org/html/defcon-19/dc-19-index.html]]></description>
			<content:encoded><![CDATA[<div class='posterous_autopost'>I think I will go this year. <p /> <a href="https://www.defcon.org/html/defcon-19/dc-19-index.html">https://www.defcon.org/html/defcon-19/dc-19-index.html</a>  </div>
]]></content:encoded>
			<wfw:commentRss>http://jonsnetwork.com/2011/06/def-con%c2%ae-19-hacking-conference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why Zombies Love PCI Video</title>
		<link>http://jonsnetwork.com/2011/06/why-zombies-love-pci-video/</link>
		<comments>http://jonsnetwork.com/2011/06/why-zombies-love-pci-video/#comments</comments>
		<pubDate>Thu, 09 Jun 2011 05:41:37 +0000</pubDate>
		<dc:creator>Jon</dc:creator>
				<category><![CDATA[around the web girl]]></category>

		<guid isPermaLink="false">http://jonsnetwork.com/2011/06/why-zombies-love-pci-video/</guid>
		<description><![CDATA[Josh Corman of the 451 Group. The gist is that compliance regulations are too static and set the bar too low to protect us against attackers. http://www.youtube.com/watch?v=JQEBYxp_vKs]]></description>
			<content:encoded><![CDATA[<div class='posterous_autopost'>Josh Corman of the 451 Group. The gist is that compliance regulations are too static and set the bar too low to protect us against attackers. <a href="http://www.youtube.com/watch?v=JQEBYxp_vKs">http://www.youtube.com/watch?v=JQEBYxp_vKs</a>  </div>
]]></content:encoded>
			<wfw:commentRss>http://jonsnetwork.com/2011/06/why-zombies-love-pci-video/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why to use the cloud</title>
		<link>http://jonsnetwork.com/2011/06/why-to-use-the-cloud/</link>
		<comments>http://jonsnetwork.com/2011/06/why-to-use-the-cloud/#comments</comments>
		<pubDate>Tue, 07 Jun 2011 07:43:19 +0000</pubDate>
		<dc:creator>Jon</dc:creator>
				<category><![CDATA[around the web girl]]></category>

		<guid isPermaLink="false">http://jonsnetwork.com/2011/06/why-to-use-the-cloud/</guid>
		<description><![CDATA[http://www.singlenameserver.com/1142/is-it-time-to-abandon-cloud-computing According to this healthcare CIO, the chief benefit is saving you time. Don&#8217;t expect less downtime or cost.]]></description>
			<content:encoded><![CDATA[<div class='posterous_autopost'><a href="http://www.singlenameserver.com/1142/is-it-time-to-abandon-cloud-computing">http://www.singlenameserver.com/1142/is-it-time-to-abandon-cloud-computing</a> <p /> According to this healthcare CIO, the chief benefit is saving you time. Don&#8217;t expect less downtime or cost.  </div>
]]></content:encoded>
			<wfw:commentRss>http://jonsnetwork.com/2011/06/why-to-use-the-cloud/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

