<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>The Situational Room by eIQnetworks &#187; best practices</title>
	<atom:link href="http://situationalroom.wordpress.com/tag/best-practices/feed/" rel="self" type="application/rss+xml" />
	<link>http://situationalroom.wordpress.com</link>
	<description></description>
	<lastBuildDate>Sun, 05 Feb 2012 21:25:28 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='situationalroom.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>The Situational Room by eIQnetworks &#187; best practices</title>
		<link>http://situationalroom.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://situationalroom.wordpress.com/osd.xml" title="The Situational Room by eIQnetworks" />
	<atom:link rel='hub' href='http://situationalroom.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Security Best Practices, Linkous-Style</title>
		<link>http://situationalroom.wordpress.com/2009/09/25/security-best-practices-linkous-style/</link>
		<comments>http://situationalroom.wordpress.com/2009/09/25/security-best-practices-linkous-style/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 00:00:26 +0000</pubDate>
		<dc:creator>John Linkous</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[best practices]]></category>
		<category><![CDATA[compliance automation]]></category>
		<category><![CDATA[security automation]]></category>
		<category><![CDATA[security management]]></category>
		<category><![CDATA[security program]]></category>
		<category><![CDATA[situational awareness]]></category>
		<category><![CDATA[strategy]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=171</guid>
		<description><![CDATA[eIQ&#8217;s own security and compliance evangelist John Linkous took some time to step away from his bully pulpit to contribute a list of practices for Linda Musthaler&#8217;s Network World column. Although he&#8217;s no Jim Bakker, John can sling security fire and brimstone with the best of them. He provides some good food for thought for [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=171&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div>eIQ&#8217;s own security and compliance evangelist John Linkous took some time to step away from his bully pulpit to contribute a list of practices for <a href="http://www.networkworld.com/newsletters/techexec/2009/090925-musthaler.html" target="_blank">Linda Musthaler&#8217;s Network World column</a>. Although he&#8217;s no Jim Bakker, John can sling security fire and brimstone with the best of them. He provides some good food for thought for any security professional. Check it out and be converted.</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/171/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/171/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/171/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/171/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/171/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/171/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/171/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/171/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/171/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/171/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/171/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/171/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/171/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/171/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=171&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2009/09/25/security-best-practices-linkous-style/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/26b8228ee1d43d6035459b3a2feefa69?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">phylum</media:title>
		</media:content>
	</item>
		<item>
		<title>eIQcast, Episode 14 &#8211; &#8220;Analyzing Melissa Hathaway&#8217;s Recommendations&#8221;</title>
		<link>http://situationalroom.wordpress.com/2009/05/04/eiqcast-episode-14-analyzing-melissa-hathaways-recommendations/</link>
		<comments>http://situationalroom.wordpress.com/2009/05/04/eiqcast-episode-14-analyzing-melissa-hathaways-recommendations/#comments</comments>
		<pubDate>Mon, 04 May 2009 00:00:04 +0000</pubDate>
		<dc:creator>John Linkous</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[best practices]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[enterprise security]]></category>
		<category><![CDATA[security management]]></category>
		<category><![CDATA[security program]]></category>
		<category><![CDATA[situational awareness]]></category>
		<category><![CDATA[strategy]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=118</guid>
		<description><![CDATA[During one of the most hyped keynotes at the recent RSA conference, President Obama&#8217;s &#8220;cyber-security czar&#8221; Melissa Hathaway outlined at a high level plans for improved security within the federal government. In the latest episode of eIQcast, Host Ross Levanto and eIQnetworks Product Evangelist John Linkous analyze Hathaway&#8217;s comments and the industry&#8217;s reaction to them. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=118&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>During one of the most hyped keynotes at the recent RSA conference, President Obama&#8217;s &#8220;cyber-security czar&#8221; Melissa Hathaway outlined at a high level plans for improved security within the federal government.</p>
<p>In the latest episode of eIQcast, Host Ross Levanto and eIQnetworks Product Evangelist John Linkous analyze Hathaway&#8217;s comments and the industry&#8217;s reaction to them. The report Hathaway recently completed and sent to the President has not been made public; it&#8217;s expected that many of her recommendations will emphasize the need for ongoing monitoring of networks and security controls, as well as the need for the White House to step up its management of IT security across the entire government.</p>
<p>Editor&#8217;s note: This episode was recorded on Friday, May 1, and therefore references the RSA Conference that ended on April 23.</p>
<p>Running time: 10:57</p>
<p><img src="http://counters.gigya.com/wildfire/IMP/CXNID=2000002.0NXC/bT*xJmx*PTEyNDE*NTIzNDUxNjAmcHQ9MTI*MTQ1MjM*ODE2MyZwPTg*NjgxJmQ9Jmc9MSZ*PSZvPTg4MTkxNWRjNzQ1ODQzZWI5NzA3NDE5YjE4ZDU4YWM4Jm9mPTA=.gif" border="0" alt="" width="0" height="0" /></p>
<div><a href="http://eiqcast.podomatic.com/" target="eiqcast"><img src="http://www.podomatic.com/images/share/player_logo.jpg" border="0" alt="" /></a></div>
<p>Direct Link: <a href="http://eiqcast.podomatic.com/entry/2009-05-04T08_49_21-07_00" target="_blank">http://eiqcast.podOmatic.com/entry/2009-05-04T08_49_21-07_00</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/118/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/118/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/118/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/118/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/118/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/118/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/118/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/118/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/118/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/118/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/118/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/118/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/118/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/118/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=118&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2009/05/04/eiqcast-episode-14-analyzing-melissa-hathaways-recommendations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/26b8228ee1d43d6035459b3a2feefa69?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">phylum</media:title>
		</media:content>

		<media:content url="http://counters.gigya.com/wildfire/IMP/CXNID=2000002.0NXC/bT*xJmx*PTEyNDE*NTIzNDUxNjAmcHQ9MTI*MTQ1MjM*ODE2MyZwPTg*NjgxJmQ9Jmc9MSZ*PSZvPTg4MTkxNWRjNzQ1ODQzZWI5NzA3NDE5YjE4ZDU4YWM4Jm9mPTA=.gif" medium="image" />

		<media:content url="http://www.podomatic.com/images/share/player_logo.jpg" medium="image" />
	</item>
		<item>
		<title>eIQcast, Episode 10 &#8211; &#8220;Electronic Health Records&#8221;</title>
		<link>http://situationalroom.wordpress.com/2009/03/16/eiqcast-episode-10-electronic-health-records/</link>
		<comments>http://situationalroom.wordpress.com/2009/03/16/eiqcast-episode-10-electronic-health-records/#comments</comments>
		<pubDate>Mon, 16 Mar 2009 00:00:39 +0000</pubDate>
		<dc:creator>John Linkous</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[best practices]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[compliance automation]]></category>
		<category><![CDATA[frameworks]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[podcast]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=88</guid>
		<description><![CDATA[The American Recovery and Reinvestment Act signed by President Obama last month includes a new initiative to create standard electronic health records over the next few years. Since a standard way to exchange health information opens up the possibility of a hacker attack, the federal government is creating new rules to protect the health records. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=88&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.flickr.com/photos/juhansonin/393271975/" target="_blank"></a>The American Recovery and Reinvestment Act signed by President Obama last month includes a new initiative to create standard electronic health records over the next few years. Since a standard way to exchange health information opens up the possibility of a hacker attack, the federal government is creating new rules to protect the health records.</p>
<p>In this episode of eIQcast, Ross Levanto interviews eIQnetworks Product Evangelist John Linkous. They walk through the new initiative outlined in the act and the timeline for the new IT rules addressing electronic record protection.</p>
<p>Running time: 11:22</p>
<p><img src="http://counters.gigya.com/wildfire/IMP/CXNID=2000002.0NXC/bT*xJmx*PTEyMzcyMzYzODM*MjcmcHQ9MTIzNzIzNjM4NjE*OCZwPTg*NjgxJmQ9Jmc9MSZ*PSZvPTg4MTkxNWRjNzQ1ODQzZWI5NzA3NDE5YjE4ZDU4YWM4.gif" border="0" alt="" width="0" height="0" /></p>
<div><a href="http://eiqcast.podomatic.com/" target="eiqcast"><img src="http://www.podomatic.com/images/share/player_logo.jpg" border="0" alt="" /></a></div>
<p><a href="http://www.gigyamailbutton.com/wildfire/gigyamailbutton.ashx?url=aHR*cDovL3dpbGRmaXJlLmdpZ3lhLmNvbS93aWxkZmlyZS93ZnBvcC5hc3B4P21vZHVsZT1lbWFpbCZ1cmw9aHR*cCUzYSUyZiUyZnd3dy5wb2RvbWF*aWMuY29tJTJmcG9kY2FzdCUyZmVtYmVk" target="_blank"><img src="http://cdn.gigya.com/wildfire/i/includeShareButton.gif" border="0" alt="" width="60" height="20" /></a></p>
<p>Direct Link: <a href="http://eiqcast.podomatic.com/entry/2009-03-16T13_40_07-07_00" target="_blank">http://eiqcast.podOmatic.com/entry/2009-03-16T13_40_07-07_00</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/88/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=88&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2009/03/16/eiqcast-episode-10-electronic-health-records/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/26b8228ee1d43d6035459b3a2feefa69?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">phylum</media:title>
		</media:content>

		<media:content url="http://counters.gigya.com/wildfire/IMP/CXNID=2000002.0NXC/bT*xJmx*PTEyMzcyMzYzODM*MjcmcHQ9MTIzNzIzNjM4NjE*OCZwPTg*NjgxJmQ9Jmc9MSZ*PSZvPTg4MTkxNWRjNzQ1ODQzZWI5NzA3NDE5YjE4ZDU4YWM4.gif" medium="image" />

		<media:content url="http://www.podomatic.com/images/share/player_logo.jpg" medium="image" />

		<media:content url="http://cdn.gigya.com/wildfire/i/includeShareButton.gif" medium="image" />
	</item>
		<item>
		<title>eIQcast, Episode 4 &#8211; Drilldown on COBIT</title>
		<link>http://situationalroom.wordpress.com/2009/01/13/eiqcast-episode-4-drilldown-on-cobit/</link>
		<comments>http://situationalroom.wordpress.com/2009/01/13/eiqcast-episode-4-drilldown-on-cobit/#comments</comments>
		<pubDate>Tue, 13 Jan 2009 00:00:49 +0000</pubDate>
		<dc:creator>John Linkous</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[best practices]]></category>
		<category><![CDATA[COBIT]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[frameworks]]></category>
		<category><![CDATA[podcast]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=36</guid>
		<description><![CDATA[In this episode, John Linkous and Mike Rothman drill deep into the COSO/COBIT framework. Why do you care? Well a good part of the acceptable practices of little regulations like Sarbanes-Oxley and FISMA are directly related to COBIT. Thus, if you have to worry about those regulations, you should be familiar with COBIT. Check it [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=36&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In this episode, John Linkous and Mike Rothman drill deep into the COSO/COBIT framework. Why do you care? Well a good part of the acceptable practices of little regulations like Sarbanes-Oxley and FISMA are directly related to COBIT. Thus, if you have to worry about those regulations, you should be familiar with COBIT. Check it out.</p>
<p>Running time: 11:42</p>
<div><a href="http://eiqcast.podomatic.com/" target="eiqcast"><img src="http://www.podomatic.com/images/share/player_logo.jpg" border="0" alt="" /></a></div>
<p><a href="http://www.gigyamailbutton.com/wildfire/gigyamailbutton.ashx?url=aHR*cDovL3d3dy5naWd5YS5jb2*vd2lsZGZpcmUvd2Zwb3AuYXNweD9tb2R1bGU9ZW1haWwmdXJsPWh*dHAlM*ElMkYlMkZ3d3clMkVwb2RvbWF*aWMlMkVjb2*lMkZwb2RjYXN*JTJGZW1iZWQlMkZlaXFjYXN*" target="_blank"><img src="http://cdn.gigya.com/wildfire/i/includeShareButton.gif" border="0" alt="" width="60" height="20" /></a><img src="http://counters.gigya.com/wildfire/IMP/CXNID=2000002.0NXC/bT*xJmx*PTEyMzE4NjQ5Mjg3ODcmcHQ9MTIzMTg2NDkzNDg3MCZwPTg*NjgxJmQ9Jmc9MSZ*PSZvPTg4MTkxNWRjNzQ1ODQzZWI5NzA3NDE5YjE4ZDU4YWM4.gif" border="0" alt="" width="0" height="0" /></p>
<p>Direct Link: <a href="http://eiqcast.podomatic.com/entry/2009-01-13T08_32_55-08_00" target="_blank">http://eiqcast.podOmatic.com/entry/2009-01-13T08_32_55-08_00</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/36/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=36&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2009/01/13/eiqcast-episode-4-drilldown-on-cobit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/26b8228ee1d43d6035459b3a2feefa69?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">phylum</media:title>
		</media:content>

		<media:content url="http://www.podomatic.com/images/share/player_logo.jpg" medium="image" />

		<media:content url="http://cdn.gigya.com/wildfire/i/includeShareButton.gif" medium="image" />

		<media:content url="http://counters.gigya.com/wildfire/IMP/CXNID=2000002.0NXC/bT*xJmx*PTEyMzE4NjQ5Mjg3ODcmcHQ9MTIzMTg2NDkzNDg3MCZwPTg*NjgxJmQ9Jmc9MSZ*PSZvPTg4MTkxNWRjNzQ1ODQzZWI5NzA3NDE5YjE4ZDU4YWM4.gif" medium="image" />
	</item>
		<item>
		<title>The Great Thing About Standards&#8230;</title>
		<link>http://situationalroom.wordpress.com/2008/10/22/the-great-thing-about-standards/</link>
		<comments>http://situationalroom.wordpress.com/2008/10/22/the-great-thing-about-standards/#comments</comments>
		<pubDate>Wed, 22 Oct 2008 00:00:43 +0000</pubDate>
		<dc:creator>John Linkous</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[best practices]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[controls]]></category>
		<category><![CDATA[frameworks]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=6</guid>
		<description><![CDATA[“…is that there are so many of them to choose from”, or at least so goes the old saying. Information security is no exception; the byzantine tangle of best practices, standards, frameworks, and various governmental and industry mandates that are either dedicated to information security or contain security-related requirements shows no sign of abatement or [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=6&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>“…is that there are so many of them to choose from”, or at least so goes the old saying. Information security is no exception; the byzantine tangle of best practices, standards, frameworks, and various governmental and industry mandates that are either dedicated to information security or contain security-related requirements shows no sign of abatement or unification anytime soon. Of course, if you’re a person who’s responsible for implementing all that stuff in your environment, you’re probably feeling some pain. Establishing common controls to meet compliance is a well-tested approach to meeting compliance, but where to begin?</p>
<p>Fortunately, some standards and frameworks for managing security are really starting to mature, to the point where they can become a starting point for building risk-driven common controls that easily map to regulations and other compliance drivers. Most of these frameworks and standards have been around for a number of years but through a combination of broad adoption, continuous feedback from adopters, and a mature management and improvement process, they are rapidly becoming a great starting point for building comprehensive information security. Here are three that I believe are well-balanced (addressing both technical and logical controls), risk-based (where the implementation of some or all controls is based on an analysis of risk to systems and data), and can be implemented across any industry:</p>
<ul>
<li>· <strong>PCI Security Council (PCI) Data Security Standard (DSS) 2.0</strong> – Recently released, the 2.0 version of the PCI-DSS standard focuses on a solid combination of static, pre-defined technical controls (e.g., minimum password lengths and complexity requirements), risk-based technical controls (e.g., business continuity infrastructure), and logical controls (e.g., written policies and procedures, and separation of duty). Although designed specifically for securing chain of custody around credit card data, PCI-DSS is rapidly becoming a standard of controls that organizations are applying to different types of data.</li>
<li>· <strong>ISACA Control Objectives for Information Technology (COBIT) 4.1</strong> – The COBIT framework has long been a framework for managing information security. With a focus on processes – not just technology – COBIT has become the standard high-level framework used by global auditing firms to audit against compliance with SOX Sections 302/404, J-SOX, and other major financial regulations that address financial controls. Like other frameworks, COBIT is relatively light on technical controls (although there are some specific technical controls defined for applications, such as event auditing and monitoring); instead, the goal of COBIT is to provide a framework for using risk-based decisions to build and maintain a complete IT management program.</li>
<li>· <strong>International Standards Organization (IS) 27002:2005</strong> – One of many IT-related best practice documents issued by ISO, ISO27002 (formerly known as ISO17799) is geared toward helping an organization establish risk-based decisions to build and maintain a security program. Unlike COBIT, which is focused on general IT controls, ISO27002 focuses very squarely on information security. Being part of the ISO family, ISO27002 is augmented with additional ISO-delivered guidance to help certain verticals – healthcare and financial services, for example – implement specific controls that are not only ISO27002 compatible, but compatible with other industry-specific laws and guidance.</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/6/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=6&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2008/10/22/the-great-thing-about-standards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/26b8228ee1d43d6035459b3a2feefa69?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">phylum</media:title>
		</media:content>
	</item>
	</channel>
</rss>
