<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Software Associates. &#187; Add new tag</title>
	<atom:link href="http://www.software.co.il/tag/add-new-tag/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.software.co.il</link>
	<description>Security and compliance specialists for medical device and healthcare companies</description>
	<lastBuildDate>Wed, 08 Feb 2012 06:36:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Data security &#8211; is psychology more important than technology?</title>
		<link>http://www.software.co.il/2009/06/data-security-technology/</link>
		<comments>http://www.software.co.il/2009/06/data-security-technology/#comments</comments>
		<pubDate>Wed, 17 Jun 2009 07:40:31 +0000</pubDate>
		<dc:creator>Danny Lieberman</dc:creator>
				<category><![CDATA[Data leakage]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[Add new tag]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Data loss]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[GFC]]></category>
		<category><![CDATA[Identity theft]]></category>
		<category><![CDATA[Internal security]]></category>
		<category><![CDATA[IT Governance]]></category>
		<category><![CDATA[Pharmaceutical]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=1522</guid>
		<description><![CDATA[We had a discussion with a prospect for a DLP (data loss prevention) system) that started with discussing the pros and cons of various DLP solutions (Verdasys, Mcafee DLP, Websense, Fidelis Security) and finished with a drill-down into how they can build a business case to acquire and implement data security technology. After a very ...]]></description>
			<content:encoded><![CDATA[<p>We had a discussion with a prospect for a DLP (data loss prevention) system) that started with discussing the pros and cons of various DLP solutions (<a title="Verdasys - agent DLP" href="http://www.verdasys.com" target="_blank">Verdasys</a>, <a title="Mcafee DLP" href="http://www.mcafee.com" target="_blank">Mcafee DLP</a>, <a title="Websense Data Security" href="http://www.websense.com" target="_blank">Websense</a>, <a title="Fidelis Security Systems XPS" href="http://www.fidelissecurity.com" target="_blank">Fidelis Security</a>) and finished with a drill-down into how they can build a business case to acquire and implement data security technology. After a very interesting session &#8211; the CIO asked me &#8211; &#8220;So why did you start with technology? we should have started with the <a title="Business case, business decision making" href="http://www.businesscase.com/" target="_blank">business case</a>?&#8221;  I replied &#8211; &#8220;Got your attention, didn&#8217;t I!&#8221;</p>
<p>Talking with clients we stress threat modeling and analysis and doing quantitative risk analysis but I believe that<strong> psychology may be more important than the technology. </strong>This is for several reasons:</p>
<p><span id="more-3665"></span></p>
<ul>
<li><strong>Preventing data breach</strong> <strong>events is an admission of weakness</strong>. Data loss is caused by an attack launched from inside the company (whether by a trusted insider, business partner or malicious hacker). attacks that exploit internal vulnerabilities like the new Sharepoint server that the marketing team installed last week without consulting with the IT security team.  Who wants to spend  money on something when the first step is admitting that you&#8217;re vulnerable and that your existing security systems, policies and procedures do not meet business requirements?</li>
<li><strong>The need for instant gratification</strong><strong>.</strong> Need to keep food fresh? &#8211; buy a fridge, Want music, voice, SMS, Web and mail? &#8211; buy an iPhone, Want IT security &#8211; buy a UTM appliance from Checkpoint or Cisco, want a CRM system &#8211; get salesforce.com, need a new enterprise software system &#8211; outsource to India. This is related to two other needs I think:</li>
<li><strong>The need to keep things simple</strong> and</li>
<li><strong>The need to walk on the safe side, not on the wild side</strong>.   Who wants to spend 6 figures on a DLP solution that requires a risk assessment from someone who isn&#8217;t your accountant,  a complex policy implementation by people who need to learn your business, integration with internal procedures and processes with employees who could care less, and buyin from a CEO who is scrappling for survival with the board during the biggest financial crisis in 80 years?</li>
</ul>
<p>I will talk about how to sell DLP through the psychology and not the technology in an upcoming post. Stay tuned.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/2009/06/data-security-technology/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>US Military firms recruiting hacker soldiers</title>
		<link>http://www.software.co.il/2009/06/us-military-firms-recruiting-hacker-soldiers/</link>
		<comments>http://www.software.co.il/2009/06/us-military-firms-recruiting-hacker-soldiers/#comments</comments>
		<pubDate>Tue, 09 Jun 2009 13:01:53 +0000</pubDate>
		<dc:creator>Danny Lieberman</dc:creator>
				<category><![CDATA[Information security]]></category>
		<category><![CDATA[Add new tag]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Data loss]]></category>
		<category><![CDATA[data loss prevention]]></category>
		<category><![CDATA[Data retention]]></category>
		<category><![CDATA[Islamic Terror]]></category>
		<category><![CDATA[Obama]]></category>
		<category><![CDATA[Social Networking]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=1500</guid>
		<description><![CDATA[It seems that the GFC is creating a movement of migratory hi-tech workers from Silicon Valley to the Beltway. I&#8217;m not sure that an unemployed IT security analyst turned hacker is the best choice for a defense contractor &#8211; the really good guys and gals are always in demand &#8211; and those DC summers are ...]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.software.co.il/data-breaches.html"><img class="alignleft" title="Neville Chamberlain - Peace in Our Time" src="http://upload.wikimedia.org/wikipedia/commons/thumb/0/0c/MunichAgreement_.jpg/350px-MunichAgreement_.jpg" alt="" width="280" height="191" /></a></p>
<p>It seems that the GFC is creating a movement of migratory hi-tech workers from Silicon Valley to the Beltway. I&#8217;m not sure that an unemployed IT security analyst turned hacker is the best choice for a defense contractor &#8211; the really good guys and gals are always in demand &#8211; and those DC summers are the pits. The weather in Mountain View is a lot nicer.</p>
<p><span id="ctl00_body_spnBody">Daniel D. Allen, who works for Northrop Grumman, claims that federal spending on computer security now totals USD 10 billion annually, including classified programs. So there is a lot of lard in the <a title="Pork Barrel" href="http://en.wikipedia.org/wiki/Pork_barrel" target="_blank">pork barrel</a> for cyberninjas who don&#8217;t mind the 95% humidity.  And with the recently publicized <a title="Computer Spies Breach Fighter-Jet Project " href="http://online.wsj.com/article/SB124027491029837401.html" target="_blank">data breach</a> of </span><span id="ctl00_body_spnBody">sensitive </span><span id="ctl00_body_spnBody"> design and electronic systems </span><span id="ctl00_body_spnBody">data  from the $300BN F-35 Lightning II fighter project &#8211; there&#8217;s plenty of asses to be covered. Then again &#8211; with <a title="Neville Chamberlain - Peace in our time" href="http://en.wikipedia.org/wiki/Peace_for_our_time" target="_blank">peace in our time</a> looking to arrive by end of year from President Obama, we will not need all that hardware &#8211; I hear the beer is pretty good in Munich.<br />
</span></p>
<p>Here is the article on <a title=" US military recruiting 'hacker soldiers'" href="http://www.presstv.ir/detail.aspx?id=96621&amp;sectionid=3510203" target="_blank">Presstv</a> -</p>
<blockquote><p><span id="ctl00_body_spnBody">Military giants including Northrop Grumman, General Dynamics, Lockheed Martin and Raytheon are now busy with recruiting &#8220;hacker soldiers&#8221; to address the new demand for an unconventional cyberwar and in a way to blend the new capabilities into the nation&#8217;s war planning. </span></p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/2009/06/us-military-firms-recruiting-hacker-soldiers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

