<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Practical Issues in InfoSec &#187; Risk</title>
	<atom:link href="http://www.dlstrom.com/tag/risk/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.dlstrom.com</link>
	<description>... putting information security within reach of everyone!</description>
	<lastBuildDate>Tue, 20 Dec 2011 17:00:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Pets, Vets and InfoSec</title>
		<link>http://www.dlstrom.com/2009/09/04/pets-vets-and-infosec/</link>
		<comments>http://www.dlstrom.com/2009/09/04/pets-vets-and-infosec/#comments</comments>
		<pubDate>Fri, 04 Sep 2009 13:00:00 +0000</pubDate>
		<dc:creator>Dan Strom</dc:creator>
				<category><![CDATA[Planning]]></category>
		<category><![CDATA[Risk]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=282</guid>
		<description><![CDATA[We currently have two dogs and usually have multiple cats. We&#8217;ve had snakes, lizards, fish, birds, hedgehogs and other critters as pets in the past. So it was with great interest that I listened to the advertisement on the radio encouraging pet owners to take their pet to the veterinarian and have a semi-yearly risk [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="socialize-in-content" style="float:right;"><div class="socialize-in-button socialize-in-button-right"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.dlstrom.com/2009/09/04/pets-vets-and-infosec/" data-text="Pets, Vets and InfoSec" data-count="none" data-via="danstrom" data-related="danstrom"><!--Tweetter--></a></div><div class="socialize-in-button socialize-in-button-right"><iframe src="http://www.facebook.com/plugins/like.php?href=http://www.dlstrom.com/2009/09/04/pets-vets-and-infosec/&amp;layout=standard&amp;show_faces=false&amp;width=50&amp;action=like&amp;font=arial&amp;colorscheme=light&amp;height=65" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:50px !important; height:65px;" allowTransparency="true"></iframe></div></div><p>We currently have two dogs and usually have multiple cats. We&#8217;ve had snakes, lizards, fish, birds, hedgehogs and other critters as pets in the past.</p>
<p>So it was with great interest that I listened to the advertisement on the radio encouraging pet owners to take their pet to the veterinarian and have a semi-yearly risk and health assessment performed. This radio spot was sponsored by some veterinarian organization.</p>
<p>The selling point was that your pets may be exposed to diseases and parasites that you are unaware of and the assessment will help to detect and give a jump-start to remediation.</p>
<p>Wow! That sounds like what is done in information security.</p>
<ul>
<li>
Pets (dogs) will wonder around and stick their nose in places where it doesn&#8217;t belong.</li>
<li>
Users will visit just about any Internet site &#8211; even ones they shouldn&#8217;t.</li>
<li>
Pets will pick up parasites just by running through the brush.</li>
<li>
Users will get a virus, trojan or some other malware just by clicking a link in some spam email.</li>
</li>
<li>
Pets will sometimes have to be put on a leash to keep them from running off.</li>
<li>
Content filters are sometimes necessary for users.</li>
</ul>
<p>I could go on. The point is that just like with pets, we need to be constantly aware of the changing risks and take steps to adequately respond to that risk. </p>
<p>Who would have thought we could learn information security practices just by having pets?</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2009/09/04/pets-vets-and-infosec/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec Tip: Create A Risk Register</title>
		<link>http://www.dlstrom.com/2009/06/25/infosec-tip-create-a-risk-register/</link>
		<comments>http://www.dlstrom.com/2009/06/25/infosec-tip-create-a-risk-register/#comments</comments>
		<pubDate>Thu, 25 Jun 2009 13:00:16 +0000</pubDate>
		<dc:creator>Dan Strom</dc:creator>
				<category><![CDATA[Planning]]></category>
		<category><![CDATA[Risk]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=248</guid>
		<description><![CDATA[I don&#8217;t know if your memory is like mine, but sometimes I cannot remember what happened last week. Do you remember each and every information security exposure that is found? Several years ago I started keeping a Risk Register. This is very similar to the checkbook register that we all keep. When I find a [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="socialize-in-content" style="float:right;"><div class="socialize-in-button socialize-in-button-right"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.dlstrom.com/2009/06/25/infosec-tip-create-a-risk-register/" data-text="InfoSec Tip: Create A Risk Register" data-count="none" data-via="danstrom" data-related="danstrom"><!--Tweetter--></a></div><div class="socialize-in-button socialize-in-button-right"><iframe src="http://www.facebook.com/plugins/like.php?href=http://www.dlstrom.com/2009/06/25/infosec-tip-create-a-risk-register/&amp;layout=standard&amp;show_faces=false&amp;width=50&amp;action=like&amp;font=arial&amp;colorscheme=light&amp;height=65" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:50px !important; height:65px;" allowTransparency="true"></iframe></div></div><p>I don&#8217;t know if your memory is like mine, but sometimes I cannot remember what happened last week.</p>
<p>Do you remember each and every information security exposure that is found?</p>
<p>Several years ago I started keeping a Risk Register. This is very similar to the checkbook register that we all keep.</p>
<p>When I find a new exposure to our organization, I keep track of these things&#8230;</p>
<ol>
<li>
Date Risk Found</li>
<li>
Description of Risk</li>
<li>
Business Unit Impacted</li>
<li>
Steps Taken for Remediation</li>
<li>
Date of Each Step Taken</li>
</ol>
<p>Now, I&#8217;ll be honest. Many times I keep much more information that what is listed above. But, the above is a good start.</p>
<p>What are the benefits of keeping a Risk Register?</p>
<ul>
<li>
Helps with remembering what has been done.</li>
<li>
Helps with justifying InfoSec expenses.</li>
<li>
Helps in explaining what has been done to Management.</li>
<li>
Helps to identify the most vulnerable business unit.</li>
</ul>
<p>So, remove some items from the list of things you need to remember. Keep a Risk Register.</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2009/06/25/infosec-tip-create-a-risk-register/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

