﻿<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">

<channel>

<title>Gideon's INFOSEC List</title>
<description>&quot;I typically forward interesting security resources and news articles to information security contacts as a matter of professional courtesy. Over the years the list of people grew and it made sense to use a mailing list to automate distribution. If you&apos;re interested in information security, it may be the list for you. I keep the volume low and the value high&quot;.</description>
<atom:link href="http://www.gideonrasmussen.com/rssfeed.xml" rel="self" type="application/rss+xml" />
<link>http://www.gideonrasmussen.com/gideons-infosec-list.html</link>
<language>en-us</language>
<copyright>Copyright 2002 - 2007 Gideon T. Rasmussen All Rights Reserved.</copyright>
<lastBuildDate>Fri, 16 Nov 2007 18:45:00 EST</lastBuildDate>
<category>Security</category> 
<category>Technology</category> 

<item>
<title>Failure Mode and Effects Analysis: Process and System Risk Assessment</title>
<description>Failure mode and effects analysis (FMEA) is widely used by corporations, manufacturing firms and the U.S. military to evaluate processes or systems (e.g. an incident-response process or a three-tiered application). It prioritizes potential failures by impact severity, probability of occurrence and likelihood of detection. FMEA risk ratings and narrative rationale can be used to quantify exposure to management and facilitate remediation. Most recently, FMEA was incorporated into Six Sigma and the Information Technology Infrastructure Library (ITIL).</description>
<guid>http://www.gideonrasmussen.com/article-17.html</guid>
<pubDate>Sat, 26 Apr 2008 08:51:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Information Security Career</title>
<description>My INFOSEC professional page has been revised to include advice beyond preparing for the CISSP, CISM and CISA. Page topics include: obtaining practical experience, becoming certified and taking control of your career. A career path diagram is included. The page also contains a few certifications you may not be aware of.
</description>
<guid>http://www.gideonrasmussen.com/infosec-prof.html</guid>
<pubDate>Sat, 23 Feb 2008 14:26:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>The Federal Bureau of Investigation - Capabilities and Service</title>
<description>This article provides an overview of FBI teams, InfraGard and the FBI Citizens&apos; Academy.  It was written after attending 8 FBI Citizens&apos; Academy briefings.  The content was distilled from 14 pages of class notes (not including hand written ERT notes and handouts).  The topics will be of interest to security and business professionals (e.g. the computer crime program, the white collar crime program, engagement models, etc.).  The FBI provides valuable services and support freely available to businesses.
</description>
<guid>http://www.gideonrasmussen.com/article-16.html</guid>
<pubDate>Fri, 16 Nov 2007 18:45:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Alternate Duty List</title>
<description>I had my first exposure to an alternate duties list in the US Air Force. It is a useful way to keep track of roles that go unnoticed (until someone leaves). The list should include a description of each role and a primary and alternate for each. For example:</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-34.html</guid>
<pubDate>Fri, 26 Oct 2007 20:30:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Disaster Recovery Audit</title>
<description>Here is a response to one of my contacts regarding a disaster recovery audit. She wanted to assess the effectiveness of security during a DR test.</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-33.html</guid>
<pubDate>Tue, 26 Jun 2007 02:44:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Security Acumen: Business First</title>
<description>The line between business and information security professionals is blurring. Government regulations have mandated security practices over the past decade. The resulting changes are evident. Security professionals are being given seats at the executive table and within lines of business. Business acumen is quickly becoming the eleventh domain of information security. To adapt, security professionals must align with business management and develop depth and breadth within business.</description>
<guid>http://www.gideonrasmussen.com/article-15.html</guid>
<pubDate>Wed, 9 May 2007 23:56:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Cyberwar: A Threat to Business</title>
<description>It&apos;s no secret that large U.S. businesses are in the crosshairs of foreign government entities and terrorists. According to Maj. Gen. William Lord, &quot;China has downloaded 10 to 20 terabytes of data from the NIPRNet,&quot; the Department of Defense network used for transmitting sensitive information. It is only a matter of time before military and terrorist organizations target commercial organizations. In fact, the Department of Homeland Security recently warned of potential Internet attacks on the U.S. stock market and banking Web sites. Large businesses offer an attractive target and the potential impact is very high.</description>
<guid>http://www.gideonrasmussen.com/article-14.html</guid>
<pubDate>Thu, 8 Mar 2007 02:43:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Unified Compliance Project (UCP)</title>
<description>The Unified Compliance Project is worth considering. &quot;ITCi&apos;s Unified Compliance Project (UCP) is the first independent initiative to exclusively support IT compliance management. The UCP parses and reconstructs complex corporate regulations into a holistic IT compliance view. Most importantly, by focusing on commonalities across regulations, standards-based development, and simplified architectures, the UCP supports a strategic approach to IT compliance that reduces cost, limits liability, and leverages the value of compliance-related technologies and services across the enterprise.&quot;</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-30.html</guid>
<pubDate>Wed, 31 Jan 2007 03:03:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>CISSP and CISA Prep Advice</title>
<description>The CISSP and CISA are the top two information security certifications. Both are well regarded throughout industry and are worth the journey for professional development. Ensure you meet the minimum requirements before studying for either exam. I recommend taking the CISSP first, followed by the CISA within one year.</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-29.html</guid>
<pubDate>Sat, 6 Jan 2007 02:33:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Terrorism E-Mail Alerts</title>
<description>The TRC-Alerts mailing list provides FLASH style alerts as critical information relating to terrorism or homeland security is released. Examples include attacks relevant to U.S. homeland security, changes in the homeland security status, international conflict issues, or the capture of a high-profile terrorist.</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-28.html</guid>
<pubDate>Sun, 31 Dec 2006 16:01:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Security Awareness Program</title>
<description>An awareness campaign is the foundation of an effective information security program. It has three objectives: (1) Ensure all personnel have an awareness of common threats and a familiarity with security policies and procedures (2) Foster a culture of security and (3) Demonstrate the active support of senior management and information security personnel. Here are tips for establishing a strong security awareness program within your organization:</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-26.html</guid>
<pubDate>Sun, 5 Nov 2006 15:19:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Security Breach Lists</title>
<description>Security breach lists are an interesting read and can be useful for: * Identifying trends in emerging security threats * Providing examples of why a control is necessary * Citing real world compromises in presentations, etc.</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-25.html</guid>
<pubDate>Mon, 16 Oct 2006 14:52:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Compliance Burden - Forest for the Trees?</title>
<description>In my experience many organizations are overwhelmed by compliance activities and lose sight of what INFOSEC programs are meant for, insulating the organization against unacceptable risk. When security resources are taxed with compliance activities, their core duties suffer. Common distractions include: </description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-24.html</guid>
<pubDate>Wed, 4 Oct 2006 23:41:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>The Emergency Email and Wireless Network</title>
<description>This free service is useful for being notified of emergency events. To subscribe, visit http://www.emergencyemail.org and...</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-23.html</guid>
<pubDate>Sat, 16 Sep 2006 02:00:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>The VA Stolen Laptop - Lessons Learned</title>
<description>As security professionals most of you know the VA lost control of 26 million social security numbers when a laptop was stolen on May 3rd. Here are the lessons learned from my perspective:</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-22.html</guid>
<pubDate>Wed, 13 Sep 2006 02:40:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Insider Risk Management Guide</title>
<description>&quot;The threat posed by authorized personnel is well documented by research and court cases. According to ACFE, U.S. organizations loose an estimated $652 billion to fraud annually. Unfortunately, insider threat is not limited to fraud. There is also sabotage, negligence, human error and exploitation by outsiders to consider. If you have not taken a hard look at insider threat controls in your organization, now is the time.&quot; Written by yours truly...</description>
<guid>http://www.gideonrasmussen.com/article-13.html</guid>
<pubDate>Thu, 31 Aug 2006 23:09:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Use the Features of Network Switches</title>
<description>Properly configured, switches can add another layer of security to your network. This article provides best practices configurations that should be considered for any organization. The tips within can help isolate systems from hackers, prevent the spread of zero day viruses and prevent unauthorized systems from connecting to your network.
</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-20.html</guid>
<pubDate>Thu, 17 Aug 2006 00:51:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>System Security Plan Tool</title>
<description>&quot;As we started the research for the HIPAA and 17799 projects we came across a number of references to DITSCAP and NITSCAP. The purpose of the system security plan (SSP) is to provide an overview of the security requirements of the system and describe the controls in place or planned, responsibilities and expected behavior of all individuals who access the system.&quot;  Read more and access the tool...</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-19.html</guid>
<pubDate>Thu, 17 Aug 2006 00:18:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Fraud Examination - An INFOSEC Niche</title>
<description>Last month I came across a report on Occupational Fraud &amp; Abuse and was intrigued by its contents. It separates fraud into categories and details specific examples of how fraud is committed.</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-18.html</guid>
<pubDate>Sat, 22 Jul 2006 01:02:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Systematic Removal of Accesses: Pull the Key from the Lock</title>
<description>Systematic removal of accesses refers to revoking physical and logical accesses when a person leaves an organization or their role changes. In the absence of a formal process, lingering privileges can be used to access systems, applications and office space. Potential damage includes theft of funds, equipment or intellectual property, disclosure of confidential information, and/or damage to property or personnel. Read more...</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-17.html</guid>
<pubDate>Thu, 6 Jul 2006 20:14:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>13 Ways to Get Your Developers on Board with Software Security</title>
<description>This article provides solid advice for implementing security in your software development processes. It takes developers into consideration and includes resource links.</description>
<guid>http://www.spidynamics.com/spilabs/education/articles/software-security.html</guid>
<pubDate>Thu, 22 Jun 2006 20:10:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Questions to Gauge Security Awareness</title>
<description>This is my response to a post asking for high level questions to gauge security awareness in an organization:</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-15.html</guid>
<pubDate>Tue, 6 Jun 2006 02:37:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>The Insider Threat</title>
<description>The threat posed by insiders should be a concern for every organization. Authorized personnel have the accesses to cause serious damage through theft, sabotage, neglect or error. CERT and the US Secret Service banded together and conducted a study of insider security incidents.</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-14.html</guid>
<pubDate>Mon, 22 May 2006 23:51:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Software Development: Building Security In</title>
<description>Development managers know that security should be built into new applications and incorporated into patches and new functionality. The challenge is implementing security in the fast paced world of development operations.</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-13.html</guid>
<pubDate>Thu, 11 May 2006 00:23:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Application Security</title>
<description>There is a disturbing trend in Internet threats, hackers are attacking at the application layer. Router ACLs, firewalls, demilitarized networks, intrusion detection software, all for naught... The malicious traffic complies with TCP/IP and follows the enforced path restricted by network gear. Layered network controls are still an absolute requirement. The application layer must be hardened as well. Here is how I recommend approaching application security:</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-12.html</guid>
<pubDate>Tue, 28 Mar 2006 03:34:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Protect Internal Networks from Internet Exposure</title>
<description>This article explains a common misconfiguration with serious security implications. The Split Tunneling feature of VPN clients leaves them connected to the Internet while accessing internal networks. This conduit exposes internal systems to hackers, viruses and other malware.</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-11.html</guid>
<pubDate>Sun, 26 Feb 2006 05:00:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Support for Strong Authentication</title>
<description>A FFIEC document considers &quot;single-factor authentication, as the only control mechanism, to be inadequate for high-risk transactions involving access to customer information or the movement of funds to other parties." "Financial institutions should assess the adequacy of such authentication techniques in light of new or changing risks such as phishing, pharming, malware, and the evolving sophistication of compromise techniques.&quot;</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-10.html</guid>
<pubDate>Tue, 21 Feb 2006 04:57:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>NIST Guidelines for Media Sanitization (Draft)</title>
<description>NIST raises an important topic. Each organization must have a process to properly dispose of hardware and media. The alternative is external leaks of sensitive information.</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-09.html</guid>
<pubDate>Wed, 8 Feb 2006 03:28:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Microsoft Shared Computer Toolkit for XP</title>
<description>This free toolkit hardens Windows XP to help mitigate the risk of establishing a public/shared workstation. Most organizations have at least one so I thought this would be of interest.</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-08.html</guid>
<pubDate>Sun, 1 Jan 2006 16:09:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Retaining INFOSEC Professionals</title>
<description>Here is a response to one of my contacts who is having difficulty retaining both team leaders and team members. His team is comprised of auditors. However most of the advice pertains to retaining INFOSEC professionals in general.</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-07.html</guid>
<pubDate>Thu, 29 Dec 2005 16:47:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Thoughts on eVaulting</title>
<description>Included below is my response to a post in the cisspforum. The person was considering e-vaulting versus traditional off-site storage of backup tapes.</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-06.html</guid>
<pubDate>Wed, 21 Dec 2005 04:37:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Circumventing Group Policy as a Limited User</title>
<description>This article from Mark Russinovich explains how a user account can overcome Active Directory group policy settings due to a Windows design flaw (versus a security vulnerability). It also includes an application as a proof of concept.</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-05.html</guid>
<pubDate>Thu, 15 Dec 2005 00:54:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Inexpensive Cisco Network Log Analysis</title>
<description>In this article Mark Lachniet explains why it's important to analyze logs and provides an inexpensive way to monitor Cisco logs using the Kiwi Syslog Daemon and Sawmill. The article is well written and includes screen shots.</description>
<guid>http://lachniet.com/cheaplogging</guid>
<pubDate>Tue, 13 Dec 2005 03:56:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Continuous Auditing Guide (ISSA)</title>
<description>Take a look at this guide for continuous auditing. It's well written and addresses an area that is often overlooked in information technology.</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-03.html</guid>
<pubDate>Fri, 9 Dec 2005 02:46:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Risk Management Template</title>
<description>George Spafford has posted a great risk management template. Also check out his Daily News Email List and articles.</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-02.html</guid>
<pubDate>Tue, 6 Dec 2005 01:56:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

<item>
<title>Home-Grown INFOSEC Professionals</title>
<description>Recently Marcia Wilson authored an article on how to become an information security professional. She raises an interesting topic. Mentoring coworkers
in how to break into the INFOSEC career field can be a powerful way to bolster your security program. Here are a few tips:</description>
<guid>http://www.gideonrasmussen.com/infosec-list/message-01.html</guid>
<pubDate>Tue, 29 Nov 2005 23:41:00 EST</pubDate>
<category>Security</category> 
<category>Technology</category>
</item>

</channel>

</rss>
