<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Compliance and Controls</title>
	<atom:link href="http://www.itcomplianceandcontrols.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.itcomplianceandcontrols.com</link>
	<description>Converging Business, Information, and Controls</description>
	<lastBuildDate>Mon, 30 Jan 2012 20:00:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2</generator>
		<item>
		<title>Weekly recap of Tweets, Links, and Ideas</title>
		<link>http://www.itcomplianceandcontrols.com/2012/01/30/weekly-recap-of-tweets-links-and-ideas-27/</link>
		<comments>http://www.itcomplianceandcontrols.com/2012/01/30/weekly-recap-of-tweets-links-and-ideas-27/#comments</comments>
		<pubDate>Mon, 30 Jan 2012 20:00:00 +0000</pubDate>
		<dc:creator>James</dc:creator>
				<category><![CDATA[Technology Strategy Orchestration]]></category>
		<category><![CDATA[2011]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[realtime]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/2012/01/30/weekly-recap-of-tweets-links-and-ideas-27/</guid>
		<description><![CDATA[Please find below my mostly focused mentions on #infosec and relevant topics since 01-23-2012 .]]></description>
			<content:encoded><![CDATA[<ul class="ws_tweet_list">
<li class="ws_tweet">Weekly recap of Tweets, Links, and Ideas: Please find below my mostly focused mentions on <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> and relevant &#8230; <a href="http://t.co/yy1nZQPp" rel="nofollow">http://t.co/yy1nZQPp</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/161585544009228288">2012-01-23</a></li>
<li class="ws_tweet">Neck deep in debate .. awesome start to day! <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> <a href="http://search.twitter.com/search?q=%23lovewhatyoudo">#lovewhatyoudo</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/162531416301768704">2012-01-26</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/securityninja">@securityninja</a>: &quot;Culture Eats Strategy For Lunch&quot; <a href="http://t.co/3w7xMBX2" rel="nofollow">http://t.co/3w7xMBX2</a>  &lt;&#8211; yes, I heard that quote before &amp; used it.. effective <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/162532977472049152">2012-01-26</a></li>
<li class="ws_tweet"><a href="http://search.twitter.com/search?q=%23kutski">#kutski</a> just used a &quot;flame on&quot; drop &#8230; awesome .. totally made my morning <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/162539152297041920">2012-01-26</a></li>
<li class="ws_tweet"><a href="http://search.twitter.com/search?q=%23symantec">#symantec</a> says &quot;disable / uninstall&quot; pcanywhere as fix due to src breach <a href="http://t.co/WPS7fe4f" rel="nofollow">http://t.co/WPS7fe4f</a> Advise 2 days old for vuln 6 yrs old <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/162541402843119617">2012-01-26</a></li>
<li class="ws_tweet">Release of Symantec source code leads to ‘uninstall’ recommendation: Symantec was the victim of an attack where &#8230; <a href="http://t.co/LKtwKWNa" rel="nofollow">http://t.co/LKtwKWNa</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/162547495900155905">2012-01-26</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/vttym">@vttym</a>:  What difficulty level you play your games on in the first playthrough! <a href="http://t.co/7IC0Zf8t" rel="nofollow">http://t.co/7IC0Zf8t</a> &lt;- hard, but I die a lot too <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/162548809086418944">2012-01-26</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/Scobleizer">@Scobleizer</a>: Only about 30% of Davos participants are on Twitter. &lt;&#8211; rather have valuable content from 30% than manufactured junk .. u? <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/162549256589287425">2012-01-26</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/andrewsmhay">@andrewsmhay</a>: I can tell that <a href="http://search.twitter.com/search?q=%23RSAC">#RSAC</a> is quickly approaching based on the number of irrelevant PR &lt;- not irrelevent <a href="http://t.co/MViWA1li" rel="nofollow">http://t.co/MViWA1li</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/162551294568042496">2012-01-26</a></li>
<li class="ws_tweet">Anyone have a neat website or mobile tool that I can use to coordinate people at <a href="http://search.twitter.com/search?q=%23RSAC">#RSAC</a> ?  How to heard cats is the use case <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/162564385158598656">2012-01-26</a></li>
<li class="ws_tweet">Problem with eating at 6am  and marathon calls makes for delayed lunch. <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/162581070561292288">2012-01-26</a></li>
<li class="ws_tweet">Latest Thoughts: Release of Symantec source code leads to &#039;uninstall&#039; recommendation <a href="http://t.co/acmXUdKg" rel="nofollow">http://t.co/acmXUdKg</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/162604750917992448">2012-01-26</a></li>
<li class="ws_tweet">The Great CON is out! <a href="http://t.co/bWCVdIp6" rel="nofollow">http://t.co/bWCVdIp6</a> ▸ Top stories today via <a href="http://twitter.com/pcitraining">@pcitraining</a> <a href="http://twitter.com/pcissc">@pcissc</a> <a href="http://twitter.com/angioplastyorg">@angioplastyorg</a> <a href="http://twitter.com/xyprotechnology">@xyprotechnology</a> <a href="http://twitter.com/robhale77">@robhale77</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/162607476754219009">2012-01-26</a></li>
<li class="ws_tweet">Seems Tim Cook of <a href="http://search.twitter.com/search?q=%23Apple">#Apple</a> is good at giving away money, so far since loss of Steve Jobs, he has boosted donations &amp; added major discounts <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/162614606051807234">2012-01-26</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/TechCrunch">@TechCrunch</a>: Twitter Changes The &quot;Contours&quot; Of Censorship w/ Country-By-Country Blocking <a href="http://t.co/QFhqZJcL" rel="nofollow">http://t.co/QFhqZJcL</a> &lt;- if capable, censor bots! <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/162690810486337536">2012-01-26</a></li>
<li class="ws_tweet">Any truth to the whole sun / flare thing messing with networks and connectivity? <a href="http://search.twitter.com/search?q=%23urbanmyth">#urbanmyth</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/162927331059580929">2012-01-27</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/suffert">@suffert</a>: <a href="http://t.co/RQWzz5NL" rel="nofollow">http://t.co/RQWzz5NL</a>  &lt; Map with more than 10,000 industrial control systems hooked up to internet via <a href="http://twitter.com/Wired">@Wired</a> <a href="http://search.twitter.com/search?q=%23SHODAN">#SHODAN</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/163803801323700224">2012-01-29</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2012/01/30/weekly-recap-of-tweets-links-and-ideas-27/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Weekly recap of Tweets, Links, and Ideas</title>
		<link>http://www.itcomplianceandcontrols.com/2012/01/23/weekly-recap-of-tweets-links-and-ideas-26/</link>
		<comments>http://www.itcomplianceandcontrols.com/2012/01/23/weekly-recap-of-tweets-links-and-ideas-26/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 20:00:00 +0000</pubDate>
		<dc:creator>James</dc:creator>
				<category><![CDATA[Technology Strategy Orchestration]]></category>
		<category><![CDATA[2011]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[realtime]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/2012/01/23/weekly-recap-of-tweets-links-and-ideas-26/</guid>
		<description><![CDATA[Please find below my mostly focused mentions on #infosec and relevant topics since 01-16-2012 .]]></description>
			<content:encoded><![CDATA[<ul class="ws_tweet_list">
<li class="ws_tweet">Latest Thoughts: When Cryptography is irrelevant, bypassing key card security <a href="http://t.co/x3Sbe5Gc" rel="nofollow">http://t.co/x3Sbe5Gc</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/159431703918690304">2012-01-17</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/Urvaksh">@Urvaksh</a>: Lunch: 2 energy bars &amp; 8 cups of coffee. Yeah, Friday&#039;s going to be that good. <a href="http://search.twitter.com/search?q=%23AtlBizChron">#AtlBizChron</a> &lt;- the best things come from focus <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/159449497670402048">2012-01-17</a></li>
<li class="ws_tweet">When vendors attack, inspired by India espionage reports of USCC and Symantec: The attacker victim scenarios we &#8230; <a href="http://t.co/921Rudjc" rel="nofollow">http://t.co/921Rudjc</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/159571725418364928">2012-01-18</a></li>
<li class="ws_tweet">Latest Thoughts: When vendors attack, inspired by India espionage reports of USCC and Symantec <a href="http://t.co/ujBSYF5j" rel="nofollow">http://t.co/ujBSYF5j</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/159614764404838401">2012-01-18</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/heidishey">@heidishey</a>: New self assessment tool for Forrester  infosec metrics maturity model! <a href="http://t.co/5XBUvjuC" rel="nofollow">http://t.co/5XBUvjuC</a>  &lt;&#8211; HTTP ERROR, new link? <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/159632043423182849">2012-01-18</a></li>
<li class="ws_tweet">Update and final GSA Rule provides value related to Vendor 3rd party audits: The GSA Final Rule got a lot of att&#8230; <a href="http://t.co/F6ajUYzq" rel="nofollow">http://t.co/F6ajUYzq</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/159682516800901121">2012-01-18</a></li>
<li class="ws_tweet">Would you be PCI Compliant if there were not fines, fees, damages?  Possible result of court case: An interestin&#8230; <a href="http://t.co/nnetn9zu" rel="nofollow">http://t.co/nnetn9zu</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/159939911775031296">2012-01-19</a></li>
<li class="ws_tweet">Latest Thoughts: Would you be PCI Compliant if there were not fines, fees, damages?  Possible result of court case <a href="http://t.co/F2f9UFab" rel="nofollow">http://t.co/F2f9UFab</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/159977259573329920">2012-01-19</a></li>
<li class="ws_tweet">&quot; <a href="http://search.twitter.com/search?q=%23PCI">#PCI</a> compliance is fiercely expensive, but all it does is protect against accidents&quot; <a href="http://t.co/TgHRNTkD" rel="nofollow">http://t.co/TgHRNTkD</a> &lt;- interesting observ <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/159989675644297216">2012-01-19</a></li>
<li class="ws_tweet">Oh a new year and so many new opportunities.  Gotta love the passion in our industry! <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/159999075641597952">2012-01-19</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/TomSellers">@TomSellers</a>: Symantec, did your DLP product catch the exfiltration of source code? &lt;&#8211; their <a href="http://search.twitter.com/search?q=%23RSAC">#RSAC</a> talks shld be updated to provide intel <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/160003191629549570">2012-01-19</a></li>
<li class="ws_tweet">The Great CON is out! <a href="http://t.co/bWCVdIp6" rel="nofollow">http://t.co/bWCVdIp6</a> ▸ Top stories today via <a href="http://twitter.com/rcs_pos">@rcs_pos</a> <a href="http://twitter.com/siliconshecky">@siliconshecky</a> <a href="http://twitter.com/bfpennington">@bfpennington</a> <a href="http://twitter.com/heartlandhpy">@heartlandhpy</a> <a href="http://twitter.com/bulwarkz">@bulwarkz</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/160070785162153984">2012-01-19</a></li>
<li class="ws_tweet">Vendor Proof of Security, GSA Final Rule and how it can help everybody else: The GSA Final Rule got a lot of att&#8230; <a href="http://t.co/sNMkLc4Q" rel="nofollow">http://t.co/sNMkLc4Q</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/160283866102374400">2012-01-20</a></li>
<li class="ws_tweet">Latest Thoughts: Vendor Proof of Security, GSA Final Rule and how it can help everybody else <a href="http://t.co/rNO19DIE" rel="nofollow">http://t.co/rNO19DIE</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/160339547408961538">2012-01-20</a></li>
<li class="ws_tweet">So this is what the Flu feels like. Awesome. <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/160452414447697921">2012-01-20</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2012/01/23/weekly-recap-of-tweets-links-and-ideas-26/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Update and final GSA Rule provides value related to Vendor 3rd party audits</title>
		<link>http://www.itcomplianceandcontrols.com/2012/01/18/update-and-final-gsa-rule-provides-value-related-to-vendor-3rd-party-audits/</link>
		<comments>http://www.itcomplianceandcontrols.com/2012/01/18/update-and-final-gsa-rule-provides-value-related-to-vendor-3rd-party-audits/#comments</comments>
		<pubDate>Wed, 18 Jan 2012 15:05:39 +0000</pubDate>
		<dc:creator>James</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[2012]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[gsa]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[IT Compliance and Controls]]></category>
		<category><![CDATA[regulations]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vendor]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=179</guid>
		<description><![CDATA[The GSA Final Rule got a lot of attention in the government services sector as it solidified the requirements related to security and third parties.  The Final Rule makes it clear that upon winning a contract and to continue the contract ongoing performance and attestation is required of the Security program.  Specifically the language states [...]]]></description>
			<content:encoded><![CDATA[<p>The GSA Final Rule got a lot of attention in the government services sector as it solidified the requirements related to security and third parties.  The Final Rule makes it clear that upon winning a contract and to continue the contract ongoing performance and attestation is required of the Security program.  Specifically the language states the following:</p>
<blockquote><p>&#8220;&#8230;the rule requires contractors, within 30 days after contract award to submit an IT Security Plan to the contracting officer and contracting officer&#8217;s representative that describes the processes and procedures that will be followed to ensure appropriate security of IT resources that are developed, processed, or used under the contract. The rule will also require that contractors submit written proof of IT security authorization six months after award, and verify that the IT Security Plan remains valid annually. Where this information is not already available, this may mean small businesses will need to become familiar with the requirements, research the requirements, develop the documents, submit the information, and create the infrastructure to track, monitor and report compliance with the requirements.&#8221;</p></blockquote>
<p>While the idea of 3rd party audits and attestations is common practice in the private sector, there are a few interesting considerations that businesses should consider adopting as appropriate based on the type of vendor.</p>
<blockquote><p>&#8220;&#8230;ensure appropriate security of IT resources that are developed, processed, or used under the contract&#8230;&#8221;</p></blockquote>
<p>Businesses when setting up agreements with third parties should be engaged at the relationship discovery stage and upon contract.  Specifically architect what are the appropriate security safeguards for the type of vendor and what will be the scope of processes of the vendor.  This is becoming more present across the spectrum of industries, but the maturity of the above process is just emerging in mature organizations.</p>
<blockquote><p>&#8220;&#8230;verify that the IT Security Plan remains valid annually&#8230;&#8221;</p></blockquote>
<p>Business relationships must be managed.  Operational and performance metrics exist for each vendor and if a vendor misses a contractual agreement, there are usual fines and contract adjustments that result.  The management of vendor operational information security to the agreed upon plan should also be executed.  This is a great opportunity to establish a routine, efficient, and appropriate validation / attestation process.</p>
<p>The takeaway here is that the practices securing businesses must evolve to address the introduced risks of third parties.  There is a need to be balanced in the requests to vendors and so a progressive security plan that reflects the relationship is appropriate.</p>
<p><a href="http://www.infosecisland.com/blogview/19301-GSA-Final-Rule-Requires-Vendor-Proof-of-Security.html#.TwyT1HSUeXg.twitter">InfosecIsland has a nice writeup</a> of the full GSA Final Rule here, and the actual rule is <a href="http://www.gpo.gov/fdsys/pkg/FR-2012-01-06/html/2011-33543.htm">available here too</a>.</p>
<p>Other thoughts / Considerations?</p>
<p>James DeLuccia</p>
<p>//cc at PCI DSS &amp; IT Controls</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2012/01/18/update-and-final-gsa-rule-provides-value-related-to-vendor-3rd-party-audits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Does competition bread better Security, Enterprise Architecture leading IT Transformation</title>
		<link>http://www.itcomplianceandcontrols.com/2012/01/17/does-competition-bread-better-security-enterprise-architecture-leading-it-transformation/</link>
		<comments>http://www.itcomplianceandcontrols.com/2012/01/17/does-competition-bread-better-security-enterprise-architecture-leading-it-transformation/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 21:06:59 +0000</pubDate>
		<dc:creator>James</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[2012]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[controls]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[ea]]></category>
		<category><![CDATA[enterprise architecture]]></category>
		<category><![CDATA[Executive]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[IT Compliance and Controls]]></category>
		<category><![CDATA[james deluccia]]></category>
		<category><![CDATA[metrics]]></category>
		<category><![CDATA[open group]]></category>
		<category><![CDATA[realtime]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/?p=176</guid>
		<description><![CDATA[An article published on Open Group&#8217;s site has a nice Q&#38;A with Jeanne Ross a Scientist at MIT Center for information systems research, and an author of 3 books.  She is a speaker on how adoption of enterprise architecture (EA) leads to greater efficiencies and better business agility.  Reading the interview I had a few [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.opengroup.org/2012/01/11/mits-ross-on-how-enterprise-architecture-and-it-more-than-ever-lead-to-business-transformation/">An article published on Open Group&#8217;s site</a> has a nice Q&amp;A with Jeanne Ross a Scientist at MIT Center for information systems research, and an author of 3 books.  She is a speaker on how adoption of enterprise architecture (EA) leads to greater efficiencies and better business agility.  Reading the interview I had a few challenges for business leaders and information security professionals.</p>
<p>The first is that when a target is established and projects are executed to achieve that target, the business performs better.  This is demosntrated by a few examples of the author, and highlighted in the article:</p>
<blockquote><p>&#8220;&#8230;we can ascribe to architecture is that when companies have competition, then they can establish any kind of performance target they want, whether it’s faster revenue growth or better profitability, and then architect themselves so they can achieve their goals. Then, we can monitor that.&#8221;</p></blockquote>
<p>It seems ANY target will improve the business.  Grasping onto the Getting Things Done mindset, this leads teams all the way up to the CIO/CISO leaders to set stretch goals.  These targets could be lower incidents; better response time; lower downtime; lower end-user complaints; faster turn around of projects; lower fail rates; etc&#8230;  the key of course is to be ethical in how these metrics are achieved (obviously, or not, that reaching better customer complaint ratios should be done where quality and speed are measured to ensure that dual either are not lost as a result of the new target.</p>
<blockquote><p>&#8220;We also have statistical support in some of the work we’ve done that shows that high performers in our sample of 102 companies, in fact, had greater architecture maturity. They had deployed a number of practices associated with good architecture.&#8221;</p></blockquote>
<p>Architecture breeds discipline and matures an organization from &#8220;heroes&#8217;.  An interesting advantage for those growing their businesses in a rapid fashion and need to achieve a broader security posture.  This though is also true in most other businesses.  It is hard to consider a business where defining a discipline (that still enables brilliance and innovation) on architecture and in this case information security practices is not an advantage:</p>
<ul>
<li>Businesses grown by acquisition benefit from having a superior on-boarding process of new companies allowing for single measurable and manageable structures</li>
<li>Historic / existing establishments benefit where processes gain efficiency and effectiveness against newly defined targets</li>
</ul>
<blockquote><p>&#8220;We really just need architecture to pull out unnecessary cost and to enable desirable reusability&#8221;</p></blockquote>
<p>This is a key point &#8211; technology is evolving and is incredibly capable, but the utility of such are not efficient.  There is tremendous opportunity to remove duplication and leverage existing information security processes and technology.  This is a natural effect of systems and technology growing in capability, but also shifting needs directed by the business and risk landscape.  The joke of &#8220;shelf-ware&#8221; can be referred to here, just be sure it is not a reflection.</p>
<p>The article / interview for me brought forward ideas where we can be different within information security and leverage the approach and toolsets to enhance businesses.  I would encourage a read of the article, <a href="http://blog.opengroup.org/2012/01/11/mits-ross-on-how-enterprise-architecture-and-it-more-than-ever-lead-to-business-transformation/">here</a>, and a deeper consideration as to what goals the business could (or even a team within a larger entity) set and adjust accordingly.  Tis the New Year afterall.</p>
<p>Best,<br />
James DeLuccia IV</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2012/01/17/does-competition-bread-better-security-enterprise-architecture-leading-it-transformation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Weekly recap of Tweets, Links, and Ideas</title>
		<link>http://www.itcomplianceandcontrols.com/2012/01/16/weekly-recap-of-tweets-links-and-ideas-25/</link>
		<comments>http://www.itcomplianceandcontrols.com/2012/01/16/weekly-recap-of-tweets-links-and-ideas-25/#comments</comments>
		<pubDate>Mon, 16 Jan 2012 20:00:00 +0000</pubDate>
		<dc:creator>James</dc:creator>
				<category><![CDATA[Technology Strategy Orchestration]]></category>
		<category><![CDATA[2011]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[realtime]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/2012/01/16/weekly-recap-of-tweets-links-and-ideas-25/</guid>
		<description><![CDATA[Please find below my mostly focused mentions on #infosec and relevant topics since 01-09-2012 .]]></description>
			<content:encoded><![CDATA[<ul class="ws_tweet_list">
<li class="ws_tweet">RT <a href="http://twitter.com/joshcorman">@joshcorman</a>: we have indefensible infrastructure &amp; too much of it. 2 ways to be rich, get more or want less. &lt;&#8211; agree w/ less is best <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/156825169082589185">2012-01-10</a></li>
<li class="ws_tweet">Failure of Industry presumes ineffective toolset .. not Execution? <a href="http://twitter.com/SpireSec">@SpireSec</a> <a href="http://twitter.com/Wh1t3Rabbit">@Wh1t3Rabbit</a> <a href="http://twitter.com/mortman">@mortman</a> <a href="http://twitter.com/joshcorman">@joshcorman</a> <a href="http://twitter.com/rmogull">@rmogull</a> <a href="http://twitter.com/RobHale77">@RobHale77</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/156825647677837312">2012-01-10</a></li>
<li class="ws_tweet">Security posture shifts .. tools exist to support endeavor .. competent teams &amp; biz execution define success .. not one alone, or industry <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/156825921804972032">2012-01-10</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/rmogull">@rmogull</a>: I no longer buy anything electronic that I can&#039;t update the SW on. Including my car.  &lt;&#8211; updating = hack = enhance; good idea! <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/156826311392886784">2012-01-10</a></li>
<li class="ws_tweet">To those New Years athletes, PLEASE focus on form and not speed / effort.  Swim, weights, running .. you&#039;ll get better, promise + no injury <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/156827784088522752">2012-01-10</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/planetrussell">@planetrussell</a>: Indian Intelligence Infiltrated US Govt. Networks <a href="http://t.co/XW3Q13NT" rel="nofollow">http://t.co/XW3Q13NT</a> <a href="http://twitter.com/cyberwar">@cyberwar</a> <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> <a href="http://search.twitter.com/search?q=%23infragard">#infragard</a> &lt;- we must be better <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/157155288036814849">2012-01-11</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/BrianHonan">@BrianHonan</a>: when will biz realize a pen-test will not show how secure they are? &lt;- only shows effectiveness of the deployed controls <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/157156672018714624">2012-01-11</a></li>
<li class="ws_tweet">Interesting &#8230; GOOG won BBVA as largest Cloud Bank deal; plan to limit to internal systems. Line will bc grey quickly <a href="http://t.co/eKOUGHtw" rel="nofollow">http://t.co/eKOUGHtw</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/157195432638939136">2012-01-11</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/quentynblog">@quentynblog</a>: Like many <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> people I implicitly trust 1 person &lt;&#8211; I don&#039;t trust him either!  Human Error represents to high a risk <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/157195640261197824">2012-01-11</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/krypt3ia">@krypt3ia</a>: For those of you into the <a href="http://search.twitter.com/search?q=%23OSINT">#OSINT</a> I suggest first reading that file dump to be the NATO OSINT manual. &lt;- the 2001 handbook? <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/157198399152721921">2012-01-11</a></li>
<li class="ws_tweet">So under HITECH Act Breach of PHI must be listed here <a href="http://t.co/TUf4q42Q" rel="nofollow">http://t.co/TUf4q42Q</a> but list doesn&#039;t seem updated .. did law change? <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/157207685291454464">2012-01-11</a></li>
<li class="ws_tweet">Argh &#8230; I need to toss a packet analyzer &amp; figure out what my firm is doing to my computer .. VPN on = creeping perf; VPN off = brilliant <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/157464511207575552">2012-01-12</a></li>
<li class="ws_tweet">I am officially presenting at the <a href="http://search.twitter.com/search?q=%23IIA">#IIA</a> <a href="http://search.twitter.com/search?q=%23GAM">#GAM</a> conf in March!  Topic: Pragmatic risk mgmt &amp; prac on social media. <a href="http://http://bit.ly/y9y7vZ" rel="nofollow">http://http://bit.ly/y9y7vZ</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/157468512955269120">2012-01-12</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/jeremiahg">@jeremiahg</a>: A small merchant filed suit against US Bank for seizing funds to pay PCI fines <a href="http://t.co/hrhixcEX" rel="nofollow">http://t.co/hrhixcEX</a> &lt;- Class Action possible? <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/157469224812548096">2012-01-12</a></li>
<li class="ws_tweet">The Great CON is out! <a href="http://t.co/bWCVdIp6" rel="nofollow">http://t.co/bWCVdIp6</a> ▸ Top stories today via <a href="http://twitter.com/moduloitgrc">@moduloitgrc</a> <a href="http://twitter.com/idt911">@idt911</a> <a href="http://twitter.com/thelogicgroup">@thelogicgroup</a> <a href="http://twitter.com/xyprotechnology">@xyprotechnology</a> <a href="http://twitter.com/epaymentamerica">@epaymentamerica</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/157534290450718720">2012-01-12</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2012/01/16/weekly-recap-of-tweets-links-and-ideas-25/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Weekly recap of Tweets, Links, and Ideas</title>
		<link>http://www.itcomplianceandcontrols.com/2012/01/09/weekly-recap-of-tweets-links-and-ideas-24/</link>
		<comments>http://www.itcomplianceandcontrols.com/2012/01/09/weekly-recap-of-tweets-links-and-ideas-24/#comments</comments>
		<pubDate>Mon, 09 Jan 2012 20:00:00 +0000</pubDate>
		<dc:creator>James</dc:creator>
				<category><![CDATA[Technology Strategy Orchestration]]></category>
		<category><![CDATA[2011]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[realtime]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/2012/01/09/weekly-recap-of-tweets-links-and-ideas-24/</guid>
		<description><![CDATA[Please find below my mostly focused mentions on #infosec and relevant topics since 01-02-2012 .]]></description>
			<content:encoded><![CDATA[<ul class="ws_tweet_list">
<li class="ws_tweet">Weekly recap of Tweets, Links, and Ideas: Please find below my mostly focused mentions on <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> and relevant &#8230; <a href="http://t.co/emyCaAb9" rel="nofollow">http://t.co/emyCaAb9</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/153957923150757889">2012-01-02</a></li>
<li class="ws_tweet">2012 Plan: Full Ironman; Run 1,300 miles; Learn new skills, &amp; new adventures, &amp; follow my passion w/in complex InfoSec scenarios&#8230; you? <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/154570110118526977">2012-01-04</a></li>
<li class="ws_tweet">The Great CON is out! <a href="http://t.co/bWCVdIp6" rel="nofollow">http://t.co/bWCVdIp6</a> ▸ Top stories today via <a href="http://twitter.com/tcmbc">@tcmbc</a> <a href="http://twitter.com/tarunu">@tarunu</a> <a href="http://twitter.com/bfpennington">@bfpennington</a> <a href="http://twitter.com/spva">@spva</a> <a href="http://twitter.com/mdmolzen">@mdmolzen</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/154997323263520768">2012-01-05</a></li>
<li class="ws_tweet">The adaption of malware &amp; worms is always impressive .. requires equal responses .. Ramnit <a href="http://t.co/cJSlalzw" rel="nofollow">http://t.co/cJSlalzw</a> &lt;- summary <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/155325008745476099">2012-01-06</a></li>
<li class="ws_tweet">Management of risk and <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> safeguards should be as responsive as the threat landscape .. what is stopping us? <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/155325264384110592">2012-01-06</a></li>
<li class="ws_tweet">Nice short write up on Ramnit &#8230; infections and clean links to online reports <a href="http://t.co/PzS4z7np" rel="nofollow">http://t.co/PzS4z7np</a> <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/155325716521689088">2012-01-06</a></li>
<li class="ws_tweet">&quot;over 75% of crimeware attacks go undetected by the best anti-malware software&quot;, the 25% needs addressing but alt safeguards req&#039;d <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/155398269000876032">2012-01-06</a></li>
<li class="ws_tweet">Crime ware effectiveness stat referenced URL: <a href="http://t.co/f7LOvOKJ" rel="nofollow">http://t.co/f7LOvOKJ</a> <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/155398644982480896">2012-01-06</a></li>
<li class="ws_tweet">Interesting guidance on <a href="http://search.twitter.com/search?q=%23SocialMedia">#SocialMedia</a> use, programs, monitoring, governance, &amp; their effectiveness from SEC <a href="http://t.co/zzJSHhPq" rel="nofollow">http://t.co/zzJSHhPq</a> PDF <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/155401753704140800">2012-01-06</a></li>
<li class="ws_tweet">Hackers accessed the code for Symantec &amp; reinforces that risk assessments are prudent, as factors change <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> <a href="http://t.co/6n07zmRk" rel="nofollow">http://t.co/6n07zmRk</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/155404889151913986">2012-01-06</a></li>
<li class="ws_tweet">Short article on Fujitsu project dev a counter-neutralization tool against Virii <a href="http://t.co/2NjLGTXN" rel="nofollow">http://t.co/2NjLGTXN</a> &lt;- so many problems here <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/155409743689691137">2012-01-06</a></li>
<li class="ws_tweet">Stuxnet variants &quot;tilded&quot; <a href="http://t.co/sahphmXa" rel="nofollow">http://t.co/sahphmXa</a> allow for modular reuse <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/155410020362756096">2012-01-06</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/nselby">@nselby</a>: &#039;I can&#039;t give you the pink tag before boarding. It&#039;s a security breach.&#039; -Delta gate attendant, ATL. &lt;- training fail <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/155659911425044481">2012-01-07</a></li>
<li class="ws_tweet">Loving Hendriks and tonic these days. A must try if u like or have not liked gin before. <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/155835645825269760">2012-01-07</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/Quachen">@Quachen</a>: Def Sec. Panetta: Cyber Attack Could Paralyze US: <a href="http://t.co/TbHUetmf" rel="nofollow">http://t.co/TbHUetmf</a> &lt;- nice write up; will private sec. play same role? <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/156033632220348416">2012-01-08</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/integrisec">@integrisec</a>: RT <a href="http://twitter.com/KimZetter">@KimZetter</a> Why the Symantec source code leak is no big deal &#8211; <a href="http://t.co/SQrKxyPE" rel="nofollow">http://t.co/SQrKxyPE</a> &lt;- &amp; no one reuses code or practices <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/156034038409342978">2012-01-08</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/retheauditors">@retheauditors</a>: &quot;The auditor is decidedly not supposed to be trusted advisor to company.&quot; Chmn PCAOB in speech. <a href="http://t.co/491igB85" rel="nofollow">http://t.co/491igB85</a> &lt;-hm <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/156092739358949376">2012-01-08</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2012/01/09/weekly-recap-of-tweets-links-and-ideas-24/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Weekly recap of Tweets, Links, and Ideas</title>
		<link>http://www.itcomplianceandcontrols.com/2012/01/02/weekly-recap-of-tweets-links-and-ideas-23/</link>
		<comments>http://www.itcomplianceandcontrols.com/2012/01/02/weekly-recap-of-tweets-links-and-ideas-23/#comments</comments>
		<pubDate>Mon, 02 Jan 2012 20:00:00 +0000</pubDate>
		<dc:creator>James</dc:creator>
				<category><![CDATA[Technology Strategy Orchestration]]></category>
		<category><![CDATA[2011]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[realtime]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/2012/01/02/weekly-recap-of-tweets-links-and-ideas-23/</guid>
		<description><![CDATA[Please find below my mostly focused mentions on #infosec and relevant topics since 12-26-2011 .]]></description>
			<content:encoded><![CDATA[<ul class="ws_tweet_list">
<li class="ws_tweet">Any benefit in hitting Interop / Symantec VISION in Vegas?  Tracks don&#039;t look impressive .. Symantec looks like a product con <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> true? <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/151359643057262592">2011-12-26</a></li>
<li class="ws_tweet">Loving the &quot;end of year bests&quot; on BBC RADIO1 &#8230; awesome tunes of the year jammed together.  Perfect for banging through work <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/151360105219227649">2011-12-26</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/mrkoot">@mrkoot</a>: <a href="http://t.co/VaVESXf6" rel="nofollow">http://t.co/VaVESXf6</a> claims that 80 <a href="http://twitter.com/STRATFOR">@STRATFOR</a> clients have same pw &lt;- &amp; surprising # of &quot;test&quot; &amp; such accounts w/ same pw <a href="http://twitter.com/mikko">@mikko</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/151374218615996416">2011-12-26</a></li>
<li class="ws_tweet">Weekly recap of Tweets, Links, and Ideas: Please find below my mostly focused mentions on <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> and relevant &#8230; <a href="http://t.co/nUaPrJdq" rel="nofollow">http://t.co/nUaPrJdq</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/151411937467564032">2011-12-26</a></li>
<li class="ws_tweet">&quot;Reveal their secrets &#8211; Protect our own&quot; &#8230; nice one liner for mission statement of 3 letter agency.. <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/151665688874983424">2011-12-27</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/Urvaksh">@Urvaksh</a>: Christmas came two days late. Untethethered jailbreak released. huzzah! &lt;&#8211; woot! <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/151672668188450816">2011-12-27</a></li>
<li class="ws_tweet">Sesame street should stick w/ old formula. This new programming is for the birds. <a href="http://search.twitter.com/search?q=%23brainwashing">#brainwashing</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/152396619139121152">2011-12-29</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/Urvaksh">@Urvaksh</a>: You want to know why you should jailbreak? Here&#039;s why. <a href="http://t.co/4c02WmQM" rel="nofollow">http://t.co/4c02WmQM</a> <a href="http://search.twitter.com/search?q=%23iOS">#iOS</a> &lt;- amazing <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/152398430428332032">2011-12-29</a></li>
<li class="ws_tweet">Any my friends here have a <a href="http://search.twitter.com/search?q=%23TRI">#TRI</a> bike?  Seeking recommendations <a href="http://search.twitter.com/search?q=%23Ironman">#Ironman</a> <a href="http://search.twitter.com/search?q=%232012">#2012</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/152399572403109889">2011-12-29</a></li>
<li class="ws_tweet">&quot;personal computers [are] the new LSD&quot; -SJ Bio. My / Our LSD. <a href="http://search.twitter.com/search?q=%23InfoSec">#InfoSec</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/152441595684335616">2011-12-29</a></li>
<li class="ws_tweet">The Great CON is out! <a href="http://t.co/bWCVdIp6" rel="nofollow">http://t.co/bWCVdIp6</a> ▸ Top stories today via <a href="http://twitter.com/thatdwayne">@thatdwayne</a> <a href="http://twitter.com/hfuhs">@hfuhs</a> <a href="http://twitter.com/jgamblin">@jgamblin</a> <a href="http://twitter.com/marcmassar">@marcmassar</a> <a href="http://twitter.com/cyberainc">@cyberainc</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/152460562238947328">2011-12-29</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/doctorow">@doctorow</a>: Why don&#039;t we have <a href="http://search.twitter.com/search?q=%23AV">#AV</a> 4 embedded systems? <a href="http://search.twitter.com/search?q=%2328C3">#28C3</a> &lt;- if we don&#039;t know we have a problem, do we?! <a href="http://search.twitter.com/search?q=%23InfoSec">#InfoSec</a> <a href="http://twitter.com/Beaker">@Beaker</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/152464421992665090">2011-12-29</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2012/01/02/weekly-recap-of-tweets-links-and-ideas-23/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Weekly recap of Tweets, Links, and Ideas</title>
		<link>http://www.itcomplianceandcontrols.com/2011/12/26/weekly-recap-of-tweets-links-and-ideas-22/</link>
		<comments>http://www.itcomplianceandcontrols.com/2011/12/26/weekly-recap-of-tweets-links-and-ideas-22/#comments</comments>
		<pubDate>Mon, 26 Dec 2011 20:00:00 +0000</pubDate>
		<dc:creator>James</dc:creator>
				<category><![CDATA[Technology Strategy Orchestration]]></category>
		<category><![CDATA[2011]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[realtime]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/2011/12/26/weekly-recap-of-tweets-links-and-ideas-22/</guid>
		<description><![CDATA[Please find below my mostly focused mentions on #infosec and relevant topics since 12-19-2011 .]]></description>
			<content:encoded><![CDATA[<ul class="ws_tweet_list">
<li class="ws_tweet">Dept of Human Health Services recovered $4 Billion in fraud&#8230; collected Jan/2011&#8230; curious Jan/2012 will be <a href="http://search.twitter.com/search?q=%23metricsmatter">#metricsmatter</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/148798336802099200">2011-12-19</a></li>
<li class="ws_tweet">End of year ritual:  Backup up everything; burning backup discs, and shipping to offsite .. Disaster recovery for the home enterprise. U? <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/148800387154055169">2011-12-19</a></li>
<li class="ws_tweet">&quot;Security Incidents = a virus on your computer&quot; &#8230; woah&#8230; interesting statement on his healthcare training <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/148868194776518656">2011-12-19</a></li>
<li class="ws_tweet">The Great CON is out! <a href="http://t.co/bWCVdIp6" rel="nofollow">http://t.co/bWCVdIp6</a> ▸ Top stories today via <a href="http://twitter.com/gotprivacy">@gotprivacy</a> <a href="http://twitter.com/moduloitgrc">@moduloitgrc</a> <a href="http://twitter.com/kazzyfizzy">@kazzyfizzy</a> <a href="http://twitter.com/iryanb">@iryanb</a> <a href="http://twitter.com/nightwolf42">@nightwolf42</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/149923855970996224">2011-12-22</a></li>
<li class="ws_tweet">Hey <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> peeps .. what are your thoughts of <a href="http://search.twitter.com/search?q=%23InterOp">#InterOp</a> or <a href="http://search.twitter.com/search?q=%23Symantec">#Symantec</a> Vision CONs in May?  Never been to either .. worth it? <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/151142246417309696">2011-12-25</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2011/12/26/weekly-recap-of-tweets-links-and-ideas-22/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Weekly recap of Tweets, Links, and Ideas</title>
		<link>http://www.itcomplianceandcontrols.com/2011/12/19/weekly-recap-of-tweets-links-and-ideas-21/</link>
		<comments>http://www.itcomplianceandcontrols.com/2011/12/19/weekly-recap-of-tweets-links-and-ideas-21/#comments</comments>
		<pubDate>Mon, 19 Dec 2011 20:00:00 +0000</pubDate>
		<dc:creator>James</dc:creator>
				<category><![CDATA[Technology Strategy Orchestration]]></category>
		<category><![CDATA[2011]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[realtime]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/2011/12/19/weekly-recap-of-tweets-links-and-ideas-21/</guid>
		<description><![CDATA[Please find below my mostly focused mentions on #infosec and relevant topics since 12-12-2011 .]]></description>
			<content:encoded><![CDATA[<ul class="ws_tweet_list">
<li class="ws_tweet">Weekly recap of Tweets, Links, and Ideas: Please find below my mostly focused mentions on <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> and relevant &#8230; <a href="http://t.co/AZVusZNs" rel="nofollow">http://t.co/AZVusZNs</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/146344258427830272">2011-12-12</a></li>
<li class="ws_tweet">What are everyone&#039;s thoughts regarding the <a href="http://search.twitter.com/search?q=%23HyTrust">#HyTrust</a> paper on <a href="http://search.twitter.com/search?q=%23Cloud">#Cloud</a> architectures re <a href="http://search.twitter.com/search?q=%23PCI">#PCI</a> ? <a href="http://t.co/LzLWUEEl" rel="nofollow">http://t.co/LzLWUEEl</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/146573737733525505">2011-12-13</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/BrandenWilliams">@BrandenWilliams</a>: Found this on the table of the office I am squatting in. (cc <a href="http://twitter.com/jdeluccia">@jdeluccia</a>) <a href="http://t.co/VlSGPVEB" rel="nofollow">http://t.co/VlSGPVEB</a> &lt;- good book <img src='http://www.itcomplianceandcontrols.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/146966316790714368">2011-12-14</a></li>
<li class="ws_tweet">The Great CON is out! <a href="http://t.co/bWCVdIp6" rel="nofollow">http://t.co/bWCVdIp6</a> ▸ Top stories today via <a href="http://twitter.com/gtbtechnologies">@gtbtechnologies</a> <a href="http://twitter.com/dtmratings">@dtmratings</a> <a href="http://twitter.com/egestalt">@egestalt</a> <a href="http://twitter.com/aumasson">@aumasson</a> <a href="http://twitter.com/stange205">@stange205</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/147387236311244802">2011-12-15</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/wimremes">@wimremes</a>: <a href="http://twitter.com/security4all">@security4all</a> 11&quot; 4GB RAM 128GB SSD <img src='http://www.itcomplianceandcontrols.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  &lt;- I have 13&#039; MBA &amp; it is amazing. <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/148049411648401408">2011-12-17</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2011/12/19/weekly-recap-of-tweets-links-and-ideas-21/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Weekly recap of Tweets, Links, and Ideas</title>
		<link>http://www.itcomplianceandcontrols.com/2011/12/12/weekly-recap-of-tweets-links-and-ideas-20/</link>
		<comments>http://www.itcomplianceandcontrols.com/2011/12/12/weekly-recap-of-tweets-links-and-ideas-20/#comments</comments>
		<pubDate>Mon, 12 Dec 2011 20:00:00 +0000</pubDate>
		<dc:creator>James</dc:creator>
				<category><![CDATA[Technology Strategy Orchestration]]></category>
		<category><![CDATA[2011]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[realtime]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.itcomplianceandcontrols.com/2011/12/12/weekly-recap-of-tweets-links-and-ideas-20/</guid>
		<description><![CDATA[Please find below my mostly focused mentions on #infosec and relevant topics since 12-05-2011 .]]></description>
			<content:encoded><![CDATA[<ul class="ws_tweet_list">
<li class="ws_tweet">Weekly recap of Tweets, Links, and Ideas: Please find below my mostly focused mentions on <a href="http://search.twitter.com/search?q=%23infosec">#infosec</a> and relevant &#8230; <a href="http://t.co/IEVIa6Af" rel="nofollow">http://t.co/IEVIa6Af</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/143794633158295552">2011-12-05</a></li>
<li class="ws_tweet">The Great CON is out! <a href="http://t.co/bWCVdIp6" rel="nofollow">http://t.co/bWCVdIp6</a> ▸ Top stories today via <a href="http://twitter.com/inetu">@inetu</a> <a href="http://twitter.com/drsethdb">@drsethdb</a> <a href="http://twitter.com/andrewrjamieson">@andrewrjamieson</a> <a href="http://twitter.com/hostway">@hostway</a> <a href="http://twitter.com/harrington_jo">@harrington_jo</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/144850511265411073">2011-12-08</a></li>
<li class="ws_tweet">RT <a href="http://twitter.com/leune">@leune</a>: Epic meltdown of 2yo &lt;- raging. My new favorite word for that <img src='http://www.itcomplianceandcontrols.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/144928092195004416">2011-12-08</a></li>
<li class="ws_tweet">Ok campers, it&#039;s cold outside &#8230; lets get this done.  Coffee, check.  wifi check, coffee check check &#8230; <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/145113321476063232">2011-12-09</a></li>
<li class="ws_tweet">I like simplenote app for iphone &#8230; like notepad (stupid simple) and accessible on web &#8230; <a href="http://twitter.com/armorguy">@armorguy</a>: <a href="http://twitter.com/csoandy">@csoandy</a> <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/145132568327630848">2011-12-09</a></li>
<li class="ws_tweet">Coffee pot full downstairs; Me stuck upstairs on another hour call &#8230;  = bad planning for me &#8230; <a class="ws_tweet_time" href="http://twitter.com/jdeluccia/statuses/145156926592913409">2011-12-09</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.itcomplianceandcontrols.com/2011/12/12/weekly-recap-of-tweets-links-and-ideas-20/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

