<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-7652481.post3902967003034854046..comments</id><updated>2007-07-04T11:22:37.047-04:00</updated><category term='MySQL'/><category term='Tor'/><category term='NSM'/><category term='dns'/><category term='Snort'/><category term='book review'/><category term='Sguil'/><category term='apt'/><category term='hacking'/><category term='Perl'/><category term='Events'/><category term='WTF?'/><category term='OSSEC'/><category term='management'/><title type='text'>Comments on Infosec Potpourri: Tired of all the talk</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.vorant.com/feeds/3902967003034854046/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/3902967003034854046/comments/default'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2007/07/tired-of-all-talk.html'/><author><name>David Bianco</name><uri>http://www.blogger.com/profile/09760835714791462863</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7652481.post-8813591784768091973</id><published>2007-07-04T11:22:00.000-04:00</published><updated>2007-07-04T11:22:00.000-04:00</updated><title type='text'>The government does care, it's that how do you man...</title><content type='html'>The government does care, it's that how do you manage a $68Billion IT budget and include security?  It's hard to do, and all the naysayers for the most part have never tried to do it.  There isn't any security management model that we have today that scales to that size.&lt;BR/&gt;&lt;BR/&gt;I teach FISMA and C&amp;A to contractors, vendors, and government employees and security in the government is a lot harder than you would think.&lt;BR/&gt;&lt;BR/&gt;Anyway, I talk about this stuff all the time on my blog.  Check it out:  &lt;A HREF="http://www.guerilla-ciso.com/" REL="nofollow"&gt;http://www.guerilla-ciso.com/&lt;/A&gt;.  For the really juicy stuff, hit the FISMA topic.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/3902967003034854046/comments/default/8813591784768091973'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/3902967003034854046/comments/default/8813591784768091973'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2007/07/tired-of-all-talk.html?showComment=1183562520000#c8813591784768091973' title=''/><author><name>rybolov</name><uri>http://www.blogger.com/profile/09022232218670789122</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.vorant.com/2007/07/tired-of-all-talk.html' ref='tag:blogger.com,1999:blog-7652481.post-3902967003034854046' source='http://www.blogger.com/feeds/7652481/posts/default/3902967003034854046' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1338651393'/></entry><entry><id>tag:blogger.com,1999:blog-7652481.post-3794466465479443805</id><published>2007-07-04T00:16:00.000-04:00</published><updated>2007-07-04T00:16:00.000-04:00</updated><title type='text'>I disagree, in that I do think the government care...</title><content type='html'>I disagree, in that I do think the government cares about cybersecurity.  It's just that they don't seem to know how to &lt;B&gt;do&lt;/B&gt; it, or even &lt;B&gt;what security actually means&lt;/B&gt;.  &lt;BR/&gt;&lt;BR/&gt;Don't get me wrong:  I recognize that there are significant challenges to be overcome here.  Even at the level of individual Departments, the organizations are huge, and meaningful change is slow and painful.  But even if the Departments &lt;B&gt;want&lt;/B&gt; to change, it's pretty clear that they don't know how.  &lt;BR/&gt;&lt;BR/&gt;It comes down to the fact that cybersecurity is usually confused with compliance, reporting and other paperwork.  All important pieces, to be sure, but they're fundamentally crippled without adequate people and resources.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/3902967003034854046/comments/default/3794466465479443805'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/3902967003034854046/comments/default/3794466465479443805'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2007/07/tired-of-all-talk.html?showComment=1183522560000#c3794466465479443805' title=''/><author><name>David Bianco</name><uri>http://www.blogger.com/profile/09760835714791462863</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.vorant.com/2007/07/tired-of-all-talk.html' ref='tag:blogger.com,1999:blog-7652481.post-3902967003034854046' source='http://www.blogger.com/feeds/7652481/posts/default/3902967003034854046' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-2136160136'/></entry><entry><id>tag:blogger.com,1999:blog-7652481.post-1173072780949605527</id><published>2007-07-03T15:02:00.000-04:00</published><updated>2007-07-03T15:02:00.000-04:00</updated><title type='text'>Persanally I do not think the Federal Government r...</title><content type='html'>Persanally I do not think the Federal Government really cares about cybersecurity.  You talk about the different agencies but each agency is broken up into dozens of separate fiefdoms.  Each of these duplicate efforts which costs even more money taxpayer money.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/3902967003034854046/comments/default/1173072780949605527'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/3902967003034854046/comments/default/1173072780949605527'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2007/07/tired-of-all-talk.html?showComment=1183489320000#c1173072780949605527' title=''/><author><name>dave</name><uri>http://www.blogger.com/profile/04540029428151790839</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.vorant.com/2007/07/tired-of-all-talk.html' ref='tag:blogger.com,1999:blog-7652481.post-3902967003034854046' source='http://www.blogger.com/feeds/7652481/posts/default/3902967003034854046' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-291388791'/></entry></feed>
