<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>BlogInfoSec.com &#187; Privacy</title>
	<atom:link href="http://www.bloginfosec.com/category/privacy/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bloginfosec.com</link>
	<description>An Information Security Magazine in a Blog Format</description>
	<lastBuildDate>Thu, 29 Jul 2010 10:00:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<atom:link rel='hub' href='http://www.bloginfosec.com/?pushpress=hub'/>
		<item>
		<title>Privacy NO More</title>
		<link>http://www.bloginfosec.com/2010/05/20/privacy-no-more/</link>
		<comments>http://www.bloginfosec.com/2010/05/20/privacy-no-more/#comments</comments>
		<pubDate>Thu, 20 May 2010 10:00:52 +0000</pubDate>
		<dc:creator>Ronald Redling</dc:creator>
				<category><![CDATA[CSO/CISO Perspectives]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[hr]]></category>
		<category><![CDATA[human resources]]></category>
		<category><![CDATA[IANS]]></category>
		<category><![CDATA[YouTube]]></category>

		<guid isPermaLink="false">http://www.bloginfosec.com/?p=1462</guid>
		<description><![CDATA[The biggest scare at this years IANS event was not news about botnet attacks from Belarus or data leaks, but the increased scrutiny by Human Resource Departments of prospective candidates to include social media.  So, do not be surprised when you are asked during an interview to provide information about your blogs or websites, [...]<br /><!-- Begin Adify tag for "bloginfosec.com rss" Ad Space (728x90) ID #5674307 -->
<script type="text/javascript">
	sr_adspace_id = 5674307;
	sr_adspace_width = 728;
	sr_adspace_height = 90;
	sr_adspace_type = "graphic";
	sr_ad_new_window = true;
	
</script>
<script type="text/javascript" src="http://ad.afy11.net/srad.js?azId=5674307">
</script>
<!-- End Adify tag for "bloginfosec.com rss" Ad Space (728x90) ID #5674307 --><br />]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>The biggest scare at this years IANS event was not news about botnet attacks from Belarus or data leaks, but the increased scrutiny by Human Resource Departments of prospective candidates to include social media.  So, do not be surprised when you are asked during an interview to provide information about your blogs or websites, or to logon and provide Human Resources access to your Facebook account.</p>
<p>Any person having graduated from high school or college during the past 10 years has a high probability of being included some form of electronic media, knowingly or not.  A simple indiscretion at a party or on Spring Break can result in being the primary reason to be excluded for consideration for that choice position.  You never know who has a YouTube camera.</p>
<p>But the scrutiny does not stop there.  It is not longer sufficient to have stellar references, clean credit history and be drug free.  Where is the separation between what is considered a personal and professional life?  Any person can have belong to an association, group, volunteer for a charity, etc. that may not be considered as appropriate.  </p>
<p>Do these preclude a person from satisfactorily executing the roles and responsibilities as required?     </p>
<p>Not so long ago, the analogy to be a Boy Scout meant you walked in a different light, but now even that could be a problem.</p>
<!-- sphereit end --><img src="http://www.bloginfosec.com/?ak_action=api_record_view&id=1462&type=feed" alt="" /><hr />
<p><small>© <a href="http://www.bloginfosec.com">BlogInfoSec.com</a>, 2010. |
<a href="http://www.bloginfosec.com/2010/05/20/privacy-no-more/">Permalink</a> |
<a href="http://www.bloginfosec.com/2010/05/20/privacy-no-more/#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.bloginfosec.com/2010/05/20/privacy-no-more/&title=Privacy NO More">del.icio.us</a>
<br/>
Post tags: <a href="http://www.bloginfosec.com/tag/botnet/" rel="tag">botnet</a>, <a href="http://www.bloginfosec.com/tag/facebook/" rel="tag">facebook</a>, <a href="http://www.bloginfosec.com/tag/hr/" rel="tag">hr</a>, <a href="http://www.bloginfosec.com/tag/human-resources/" rel="tag">human resources</a>, <a href="http://www.bloginfosec.com/tag/ians/" rel="tag">IANS</a>, <a href="http://www.bloginfosec.com/tag/privacy/" rel="tag">Privacy</a>, <a href="http://www.bloginfosec.com/tag/youtube/" rel="tag">YouTube</a><br/>
</small></p>
<p><small>Feed enhanced by <a href='http://planetozh.com/blog/my-projects/wordpress-plugin-better-feed-rss/'>Better Feed</a> from  <a href='http://planetozh.com/blog/'>Ozh</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bloginfosec.com/2010/05/20/privacy-no-more/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Net-Witness of the Persecution</title>
		<link>http://www.bloginfosec.com/2010/03/09/net-witness-of-the-persecution/</link>
		<comments>http://www.bloginfosec.com/2010/03/09/net-witness-of-the-persecution/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 11:00:18 +0000</pubDate>
		<dc:creator>C. Warren Axelrod</dc:creator>
				<category><![CDATA[Compliance and Laws]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Information Security News]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[CSI]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[insider threat]]></category>
		<category><![CDATA[NetWitness]]></category>
		<category><![CDATA[spotlight]]></category>
		<category><![CDATA[VerizonBusiness Data Breaches report]]></category>
		<category><![CDATA[Wall Street Journal]]></category>

		<guid isPermaLink="false">http://www.bloginfosec.com/?p=1389</guid>
		<description><![CDATA[There is an interesting article in the February 18, 2010 Wall Street Journal by Siobhan Gorman, with the title “Hackers Attack 2,411 Firms: Global Offensive Snagged Corporate, Personal Data; Operation Is Still Running.” It describes how staff of the security services firm, NetWitness, discovered a broad and intensive hack into numerous government and private entities. [...]<br /><!-- Begin Adify tag for "bloginfosec.com rss" Ad Space (728x90) ID #5674307 -->
<script type="text/javascript">
	sr_adspace_id = 5674307;
	sr_adspace_width = 728;
	sr_adspace_height = 90;
	sr_adspace_type = "graphic";
	sr_ad_new_window = true;
	
</script>
<script type="text/javascript" src="http://ad.afy11.net/srad.js?azId=5674307">
</script>
<!-- End Adify tag for "bloginfosec.com rss" Ad Space (728x90) ID #5674307 --><br />]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>There is an interesting article in the February 18, 2010 <em>Wall Street Journal </em>by Siobhan Gorman, with the title “Hackers Attack 2,411 Firms: Global Offensive Snagged Corporate, Personal Data; Operation Is Still Running.” It describes how staff of the security services firm, NetWitness, discovered a broad and intensive hack into numerous government and private entities. The discovery took place on January 26, 2010, during a routine installation of  the company’s technology at a major corporation. Amit Yoran, who is a former national cyber security “czar”, founded NetWitness.</p>
<!-- sphereit end --><img src="http://www.bloginfosec.com/?ak_action=api_record_view&id=1389&type=feed" alt="" />(...)<br/>Read the rest of <a href="http://www.bloginfosec.com/2010/03/09/net-witness-of-the-persecution/">Net-Witness of the Persecution</a> (524 words)<hr />
<p><small>© <a href="http://www.bloginfosec.com">BlogInfoSec.com</a>, 2010. |
<a href="http://www.bloginfosec.com/2010/03/09/net-witness-of-the-persecution/">Permalink</a> |
<a href="http://www.bloginfosec.com/2010/03/09/net-witness-of-the-persecution/#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.bloginfosec.com/2010/03/09/net-witness-of-the-persecution/&title=Net-Witness of the Persecution">del.icio.us</a>
<br/>
Post tags: <a href="http://www.bloginfosec.com/tag/csi/" rel="tag">CSI</a>, <a href="http://www.bloginfosec.com/tag/data-breach/" rel="tag">data breach</a>, <a href="http://www.bloginfosec.com/tag/data-breaches/" rel="tag">data breaches</a>, <a href="http://www.bloginfosec.com/tag/fbi/" rel="tag">FBI</a>, <a href="http://www.bloginfosec.com/tag/insider-threat/" rel="tag">insider threat</a>, <a href="http://www.bloginfosec.com/tag/netwitness/" rel="tag">NetWitness</a>, <a href="http://www.bloginfosec.com/tag/spotlight/" rel="tag">spotlight</a>, <a href="http://www.bloginfosec.com/tag/verizonbusiness-data-breaches-report/" rel="tag">VerizonBusiness Data Breaches report</a>, <a href="http://www.bloginfosec.com/tag/wall-street-journal/" rel="tag">Wall Street Journal</a><br/>
</small></p>
<p><small>Feed enhanced by <a href='http://planetozh.com/blog/my-projects/wordpress-plugin-better-feed-rss/'>Better Feed</a> from  <a href='http://planetozh.com/blog/'>Ozh</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bloginfosec.com/2010/03/09/net-witness-of-the-persecution/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A-Buzz About Google</title>
		<link>http://www.bloginfosec.com/2010/03/01/a-buzz-about-google/</link>
		<comments>http://www.bloginfosec.com/2010/03/01/a-buzz-about-google/#comments</comments>
		<pubDate>Mon, 01 Mar 2010 11:00:02 +0000</pubDate>
		<dc:creator>C. Warren Axelrod</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security in Popular Culture]]></category>
		<category><![CDATA[Buzz]]></category>
		<category><![CDATA[Gmail]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[ISSA]]></category>
		<category><![CDATA[personal information]]></category>
		<category><![CDATA[spotlight]]></category>
		<category><![CDATA[The Huffington Post]]></category>

		<guid isPermaLink="false">http://www.bloginfosec.com/?p=1383</guid>
		<description><![CDATA[It appears that the official Google position, as expressed by CEO Eric Schmidt, in a December 3, 2009 interview by Maria (NOT Mario, as The Huffington Post stated) Bartiromo on CNBC, is that if you didn’t want the data to be compromised, you “… maybe you shouldn’t be doing it.” Actually, if you think about [...]<br /><!-- Begin Adify tag for "bloginfosec.com rss" Ad Space (728x90) ID #5674307 -->
<script type="text/javascript">
	sr_adspace_id = 5674307;
	sr_adspace_width = 728;
	sr_adspace_height = 90;
	sr_adspace_type = "graphic";
	sr_ad_new_window = true;
	
</script>
<script type="text/javascript" src="http://ad.afy11.net/srad.js?azId=5674307">
</script>
<!-- End Adify tag for "bloginfosec.com rss" Ad Space (728x90) ID #5674307 --><br />]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>It appears that the official Google position, as expressed by CEO Eric Schmidt, in a December 3, 2009 interview by Maria (NOT Mario, as <strong>The Huffington Post</strong> stated) Bartiromo on CNBC, is that if you didn’t want the data to be compromised, you “… maybe you shouldn’t be doing it.” Actually, if you think about it, <strong>The Huffington Post</strong>’s misstatement, at <a href="http://www.huffingtonpost.com/2009/12/07/google-ceo-on-privacy-if_n_383105.html">www.huffingtonpost.com/2009/12//07/google-ceo-on-privacy-if_n_383105.html</a>  is a perfect example of how one’s profile might be corrupted forever due to some inadvertent typographical error. Think of all the rumors about sex-change surgery and the like, which this change in first name might generate. When I searched on “Mario Bartiromo,” I got 5,950 hits, which included posts such as “Mario Bartiromo isn’t even the hottests [sic] woman at CNBC.” The Web is clearly rife with errors of omission and commission regarding personal information, as well as all other categories of information.</p>
<!-- sphereit end --><img src="http://www.bloginfosec.com/?ak_action=api_record_view&id=1383&type=feed" alt="" />(...)<br/>Read the rest of <a href="http://www.bloginfosec.com/2010/03/01/a-buzz-about-google/">A-Buzz About Google</a> (480 words)<hr />
<p><small>© <a href="http://www.bloginfosec.com">BlogInfoSec.com</a>, 2010. |
<a href="http://www.bloginfosec.com/2010/03/01/a-buzz-about-google/">Permalink</a> |
<a href="http://www.bloginfosec.com/2010/03/01/a-buzz-about-google/#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.bloginfosec.com/2010/03/01/a-buzz-about-google/&title=A-Buzz About Google">del.icio.us</a>
<br/>
Post tags: <a href="http://www.bloginfosec.com/tag/buzz/" rel="tag">Buzz</a>, <a href="http://www.bloginfosec.com/tag/gmail/" rel="tag">Gmail</a>, <a href="http://www.bloginfosec.com/tag/google/" rel="tag">Google</a>, <a href="http://www.bloginfosec.com/tag/issa/" rel="tag">ISSA</a>, <a href="http://www.bloginfosec.com/tag/personal-information/" rel="tag">personal information</a>, <a href="http://www.bloginfosec.com/tag/privacy/" rel="tag">Privacy</a>, <a href="http://www.bloginfosec.com/tag/spotlight/" rel="tag">spotlight</a>, <a href="http://www.bloginfosec.com/tag/the-huffington-post/" rel="tag">The Huffington Post</a><br/>
</small></p>
<p><small>Feed enhanced by <a href='http://planetozh.com/blog/my-projects/wordpress-plugin-better-feed-rss/'>Better Feed</a> from  <a href='http://planetozh.com/blog/'>Ozh</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bloginfosec.com/2010/03/01/a-buzz-about-google/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud Computing Security at Newsweek</title>
		<link>http://www.bloginfosec.com/2010/01/26/cloud-computing-security-at-newsweek/</link>
		<comments>http://www.bloginfosec.com/2010/01/26/cloud-computing-security-at-newsweek/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 11:00:41 +0000</pubDate>
		<dc:creator>Kenneth F. Belva</dc:creator>
				<category><![CDATA[CSO/CISO Perspectives]]></category>
		<category><![CDATA[Compliance and Laws]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[InfoSec Economics]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[daniel lyons]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[newsweek]]></category>
		<category><![CDATA[nicholas carr]]></category>
		<category><![CDATA[spotlight]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.bloginfosec.com/?p=1309</guid>
		<description><![CDATA[Daniel Lyons will publish an op-ed on the insecurity of cloud computing in Newsweek&#8216;s February 1st, 2010 issue. The  main thrust of the article can be summarized as such:
But there is one big, glaring problem with cloud computing, and it just got laid bare in Google&#8217;s recent problems with China: your stuff isn&#8217;t safe. Google [...]<br /><!-- Begin Adify tag for "bloginfosec.com rss" Ad Space (728x90) ID #5674307 -->
<script type="text/javascript">
	sr_adspace_id = 5674307;
	sr_adspace_width = 728;
	sr_adspace_height = 90;
	sr_adspace_type = "graphic";
	sr_ad_new_window = true;
	
</script>
<script type="text/javascript" src="http://ad.afy11.net/srad.js?azId=5674307">
</script>
<!-- End Adify tag for "bloginfosec.com rss" Ad Space (728x90) ID #5674307 --><br />]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p><a href="http://en.wikipedia.org/wiki/Daniel_Lyons" target="_blank">Daniel Lyons</a> will <a href="http://www.newsweek.com/id/231792" target="_blank">publish an op-ed on the insecurity</a> of <a href="http://en.wikipedia.org/wiki/Cloud_computing" target="_blank">cloud computing</a> in <a href="http://www.newsweek.com/id/231792" target="_blank">Newsweek</a>&#8216;s February 1st, 2010 issue. The  main thrust of the article can be summarized as such:</p>
<blockquote><p>But there is one big, glaring problem with cloud computing, and it just got laid bare in Google&#8217;s recent problems with China: your stuff isn&#8217;t safe. Google insists that cloud computing is perfectly secure. But of course Google says that—it&#8217;s trying to build a business out of it.</p>
<p>But if Google is so secure, how come Chinese hackers broke into its corporate servers and stole its intellectual property? Google won&#8217;t say exactly what information got filched, but if the company can&#8217;t protect its own intellectual property, how can it protect yours?</p></blockquote>
<p>Lyons then quotes <a href="http://en.wikipedia.org/wiki/Nicholas_Carr" target="_blank">Nicholas Carr</a> for the opposing opinion:</p>
<blockquote><p>Carr argues that while Google and other cloud providers can&#8217;t guarantee perfect security, they probably do a better job of fending off hackers than most companies can do on their own. On the other hand, Carr says, pooling millions of companies into a single big provider creates bigger individual targets. A hacker who cracks into a cloud can get at everybody&#8217;s stuff.</p></blockquote>
<p>Professionally speaking, I need to agree with Carr on this one. Publicly traded companies such as Google in the US must comply with various of regulations, most notably <a href="http://en.wikipedia.org/wiki/Sarbanes-oxley" target="_blank">Sarbanes-Oxley</a>. They are bound to compliance measures that help increase the security in their publicly traded organization. And, Carr is also correct to point out that cloud computing companies/domains are a larger target with a greater impact if the institution is breached.</p>
<p>There are two points that are not touched on by the Op-Ed. </p>
<!-- sphereit end --><img src="http://www.bloginfosec.com/?ak_action=api_record_view&id=1309&type=feed" alt="" />(...)<br/>Read the rest of <a href="http://www.bloginfosec.com/2010/01/26/cloud-computing-security-at-newsweek/">Cloud Computing Security at Newsweek</a> (265 words)<hr />
<p><small>© <a href="http://www.bloginfosec.com">BlogInfoSec.com</a>, 2010. |
<a href="http://www.bloginfosec.com/2010/01/26/cloud-computing-security-at-newsweek/">Permalink</a> |
<a href="http://www.bloginfosec.com/2010/01/26/cloud-computing-security-at-newsweek/#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.bloginfosec.com/2010/01/26/cloud-computing-security-at-newsweek/&title=Cloud Computing Security at Newsweek">del.icio.us</a>
<br/>
Post tags: <a href="http://www.bloginfosec.com/tag/cloud-computing/" rel="tag">cloud computing</a>, <a href="http://www.bloginfosec.com/tag/daniel-lyons/" rel="tag">daniel lyons</a>, <a href="http://www.bloginfosec.com/tag/exploits/" rel="tag">exploits</a>, <a href="http://www.bloginfosec.com/tag/google/" rel="tag">Google</a>, <a href="http://www.bloginfosec.com/tag/newsweek/" rel="tag">newsweek</a>, <a href="http://www.bloginfosec.com/tag/nicholas-carr/" rel="tag">nicholas carr</a>, <a href="http://www.bloginfosec.com/tag/spotlight/" rel="tag">spotlight</a>, <a href="http://www.bloginfosec.com/tag/vulnerability/" rel="tag">vulnerability</a><br/>
</small></p>
<p><small>Feed enhanced by <a href='http://planetozh.com/blog/my-projects/wordpress-plugin-better-feed-rss/'>Better Feed</a> from  <a href='http://planetozh.com/blog/'>Ozh</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bloginfosec.com/2010/01/26/cloud-computing-security-at-newsweek/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Classy Data (pt. 2) – Context and Handling</title>
		<link>http://www.bloginfosec.com/2009/09/13/classy-data-pt-2-%e2%80%93-context-and-handling/</link>
		<comments>http://www.bloginfosec.com/2009/09/13/classy-data-pt-2-%e2%80%93-context-and-handling/#comments</comments>
		<pubDate>Mon, 14 Sep 2009 01:52:14 +0000</pubDate>
		<dc:creator>C. Warren Axelrod</dc:creator>
				<category><![CDATA[Compliance and Laws]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[data classification]]></category>
		<category><![CDATA[data handling. data destruction]]></category>
		<category><![CDATA[data life cycle]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[information classification]]></category>
		<category><![CDATA[spotlight]]></category>

		<guid isPermaLink="false">http://www.bloginfosec.com/?p=1133</guid>
		<description><![CDATA[The category of a particular data item may have been carefully arrived at and cast in concrete, as it were. But data do not live in unchanging isolation, nor are they always used for the same purpose or in the same manner.

I recall going through some old papers recently and I found an old tax-filing [...]<br /><!-- Begin Adify tag for "bloginfosec.com rss" Ad Space (728x90) ID #5674307 -->
<script type="text/javascript">
	sr_adspace_id = 5674307;
	sr_adspace_width = 728;
	sr_adspace_height = 90;
	sr_adspace_type = "graphic";
	sr_ad_new_window = true;
	
</script>
<script type="text/javascript" src="http://ad.afy11.net/srad.js?azId=5674307">
</script>
<!-- End Adify tag for "bloginfosec.com rss" Ad Space (728x90) ID #5674307 --><br />]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>The category of a particular data item may have been carefully arrived at and cast in concrete, as it were. But data do not live in unchanging isolation, nor are they always used for the same purpose or in the same manner.</p>
<!-- sphereit end --><img src="http://www.bloginfosec.com/?ak_action=api_record_view&id=1133&type=feed" alt="" />(...)<br/>Read the rest of <a href="http://www.bloginfosec.com/2009/09/13/classy-data-pt-2-%e2%80%93-context-and-handling/">Classy Data (pt. 2) – Context and Handling</a> (889 words)<hr />
<p><small>© <a href="http://www.bloginfosec.com">BlogInfoSec.com</a>, 2009. |
<a href="http://www.bloginfosec.com/2009/09/13/classy-data-pt-2-%e2%80%93-context-and-handling/">Permalink</a> |
<a href="http://www.bloginfosec.com/2009/09/13/classy-data-pt-2-%e2%80%93-context-and-handling/#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.bloginfosec.com/2009/09/13/classy-data-pt-2-%e2%80%93-context-and-handling/&title=Classy Data (pt. 2) – Context and Handling">del.icio.us</a>
<br/>
Post tags: <a href="http://www.bloginfosec.com/tag/compliance/" rel="tag">compliance</a>, <a href="http://www.bloginfosec.com/tag/data-classification/" rel="tag">data classification</a>, <a href="http://www.bloginfosec.com/tag/data-handling-data-destruction/" rel="tag">data handling. data destruction</a>, <a href="http://www.bloginfosec.com/tag/data-life-cycle/" rel="tag">data life cycle</a>, <a href="http://www.bloginfosec.com/tag/encryption/" rel="tag">Encryption</a>, <a href="http://www.bloginfosec.com/tag/information-classification/" rel="tag">information classification</a>, <a href="http://www.bloginfosec.com/tag/spotlight/" rel="tag">spotlight</a><br/>
</small></p>
<p><small>Feed enhanced by <a href='http://planetozh.com/blog/my-projects/wordpress-plugin-better-feed-rss/'>Better Feed</a> from  <a href='http://planetozh.com/blog/'>Ozh</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bloginfosec.com/2009/09/13/classy-data-pt-2-%e2%80%93-context-and-handling/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Classy Data (pt. 1) – Categorization</title>
		<link>http://www.bloginfosec.com/2009/08/03/classy-data-pt-1-%e2%80%93-categorization/</link>
		<comments>http://www.bloginfosec.com/2009/08/03/classy-data-pt-1-%e2%80%93-categorization/#comments</comments>
		<pubDate>Mon, 03 Aug 2009 10:00:59 +0000</pubDate>
		<dc:creator>C. Warren Axelrod</dc:creator>
				<category><![CDATA[Compliance and Laws]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Risk Analysis]]></category>
		<category><![CDATA[classified]]></category>
		<category><![CDATA[confidential]]></category>
		<category><![CDATA[consumer]]></category>
		<category><![CDATA[customer]]></category>
		<category><![CDATA[data classification]]></category>
		<category><![CDATA[harm]]></category>
		<category><![CDATA[internal]]></category>
		<category><![CDATA[non-public personal information]]></category>
		<category><![CDATA[non-sensitive]]></category>
		<category><![CDATA[NPPI]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[proprietary]]></category>
		<category><![CDATA[public]]></category>
		<category><![CDATA[reputational risk]]></category>
		<category><![CDATA[sensitive]]></category>
		<category><![CDATA[spotlight]]></category>

		<guid isPermaLink="false">http://www.bloginfosec.com/?p=1027</guid>
		<description><![CDATA[How many times have you heard the following?
“First classify the data into internal, confidential, secret, etc. This determines how the data should be handled. Then assign a data owner who must approve who has access to the data and what they can do with them. Oh, and by the way, the data owner assumes the [...]<br /><!-- Begin Adify tag for "bloginfosec.com rss" Ad Space (728x90) ID #5674307 -->
<script type="text/javascript">
	sr_adspace_id = 5674307;
	sr_adspace_width = 728;
	sr_adspace_height = 90;
	sr_adspace_type = "graphic";
	sr_ad_new_window = true;
	
</script>
<script type="text/javascript" src="http://ad.afy11.net/srad.js?azId=5674307">
</script>
<!-- End Adify tag for "bloginfosec.com rss" Ad Space (728x90) ID #5674307 --><br />]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>How many times have you heard the following?</p>
<p>“First classify the data into internal, confidential, secret, etc. This determines how the data should be handled. Then assign a data owner who must approve who has access to the data and what they can do with them. Oh, and by the way, the data owner assumes the risk related to inappropriate disclosure and use of his or her data.”</p>
<p>Well, there is only one thing wrong with the above – everything! In the next three columns we will discuss the many fallacies contained in these common assertions.</p>
<!-- sphereit end --><img src="http://www.bloginfosec.com/?ak_action=api_record_view&id=1027&type=feed" alt="" />(...)<br/>Read the rest of <a href="http://www.bloginfosec.com/2009/08/03/classy-data-pt-1-%e2%80%93-categorization/">Classy Data (pt. 1) – Categorization</a> (760 words)<hr />
<p><small>© <a href="http://www.bloginfosec.com">BlogInfoSec.com</a>, 2009. |
<a href="http://www.bloginfosec.com/2009/08/03/classy-data-pt-1-%e2%80%93-categorization/">Permalink</a> |
<a href="http://www.bloginfosec.com/2009/08/03/classy-data-pt-1-%e2%80%93-categorization/#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.bloginfosec.com/2009/08/03/classy-data-pt-1-%e2%80%93-categorization/&title=Classy Data (pt. 1) – Categorization">del.icio.us</a>
<br/>
Post tags: <a href="http://www.bloginfosec.com/tag/classified/" rel="tag">classified</a>, <a href="http://www.bloginfosec.com/tag/confidential/" rel="tag">confidential</a>, <a href="http://www.bloginfosec.com/tag/consumer/" rel="tag">consumer</a>, <a href="http://www.bloginfosec.com/tag/customer/" rel="tag">customer</a>, <a href="http://www.bloginfosec.com/tag/data-classification/" rel="tag">data classification</a>, <a href="http://www.bloginfosec.com/tag/harm/" rel="tag">harm</a>, <a href="http://www.bloginfosec.com/tag/internal/" rel="tag">internal</a>, <a href="http://www.bloginfosec.com/tag/non-public-personal-information/" rel="tag">non-public personal information</a>, <a href="http://www.bloginfosec.com/tag/non-sensitive/" rel="tag">non-sensitive</a>, <a href="http://www.bloginfosec.com/tag/nppi/" rel="tag">NPPI</a>, <a href="http://www.bloginfosec.com/tag/pii/" rel="tag">PII</a>, <a href="http://www.bloginfosec.com/tag/proprietary/" rel="tag">proprietary</a>, <a href="http://www.bloginfosec.com/tag/public/" rel="tag">public</a>, <a href="http://www.bloginfosec.com/tag/reputational-risk/" rel="tag">reputational risk</a>, <a href="http://www.bloginfosec.com/tag/sensitive/" rel="tag">sensitive</a>, <a href="http://www.bloginfosec.com/tag/spotlight/" rel="tag">spotlight</a><br/>
</small></p>
<p><small>Feed enhanced by <a href='http://planetozh.com/blog/my-projects/wordpress-plugin-better-feed-rss/'>Better Feed</a> from  <a href='http://planetozh.com/blog/'>Ozh</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bloginfosec.com/2009/08/03/classy-data-pt-1-%e2%80%93-categorization/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bill Gates, Facebook and Privacy Controls</title>
		<link>http://www.bloginfosec.com/2009/07/27/bill-gates-facebook-and-privacy-controls/</link>
		<comments>http://www.bloginfosec.com/2009/07/27/bill-gates-facebook-and-privacy-controls/#comments</comments>
		<pubDate>Mon, 27 Jul 2009 09:00:07 +0000</pubDate>
		<dc:creator>Kenneth F. Belva</dc:creator>
				<category><![CDATA[Human Elements]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security in Popular Culture]]></category>
		<category><![CDATA[application security]]></category>
		<category><![CDATA[bill gates]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[gates]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[spotlight]]></category>
		<category><![CDATA[templates]]></category>
		<category><![CDATA[web applications]]></category>

		<guid isPermaLink="false">http://www.bloginfosec.com/?p=1010</guid>
		<description><![CDATA[While in India this week, Bill Gates made the following comment:
He admitted that he once had a Facebook page, but every day “ten thousand people tried to be my friend.” He said he spent too much time trying to decide “Do I know them? Don’t I know them?” Ultimately, he said, “I had to give [...]<br /><!-- Begin Adify tag for "bloginfosec.com rss" Ad Space (728x90) ID #5674307 -->
<script type="text/javascript">
	sr_adspace_id = 5674307;
	sr_adspace_width = 728;
	sr_adspace_height = 90;
	sr_adspace_type = "graphic";
	sr_ad_new_window = true;
	
</script>
<script type="text/javascript" src="http://ad.afy11.net/srad.js?azId=5674307">
</script>
<!-- End Adify tag for "bloginfosec.com rss" Ad Space (728x90) ID #5674307 --><br />]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>While in India this week, <a href="http://www.nytimes.com/2009/07/25/technology/companies/25soft.html" target="_blank">Bill Gates made the following comment</a>:</p>
<blockquote><p>He admitted that he once had a Facebook page, but every day “ten thousand people tried to be my friend.” He said he spent too much time trying to decide “Do I know them? Don’t I know them?” Ultimately, he said, “I had to give it up.”</p></blockquote>
<p>Would it be incorrect to assume that Bill Gates is technology savvy? Gates could have easily avoided being so public by restricting his profile. He could have even set up a Fan page for all those that wanted to be his friend. (Although I think when he closed his account it was before Fan pages existed.) If we believe that Gates is competent &#8212; which I believe he is &#8212; what does that say about the ability of &#8220;normal&#8221; people to set the privacy controls on applications?</p>
<p>Most people do not take the time to restrict their Facebook profiles and allow anyone who becomes their friend to see all of the information contained in the page. As I&#8217;ve <a href="http://www.bloginfosec.com/2008/05/22/losing-friends-on-facebook-a-privacy-story/" target="_blank">written before</a>, this can lead to strange and unusual circumstances. The amount of time and effort most people need to set up the proper controls is too much for them.</p>
<!-- sphereit end --><img src="http://www.bloginfosec.com/?ak_action=api_record_view&id=1010&type=feed" alt="" />(...)<br/>Read the rest of <a href="http://www.bloginfosec.com/2009/07/27/bill-gates-facebook-and-privacy-controls/">Bill Gates, Facebook and Privacy Controls</a> (151 words)<hr />
<p><small>© <a href="http://www.bloginfosec.com">BlogInfoSec.com</a>, 2009. |
<a href="http://www.bloginfosec.com/2009/07/27/bill-gates-facebook-and-privacy-controls/">Permalink</a> |
<a href="http://www.bloginfosec.com/2009/07/27/bill-gates-facebook-and-privacy-controls/#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.bloginfosec.com/2009/07/27/bill-gates-facebook-and-privacy-controls/&title=Bill Gates, Facebook and Privacy Controls">del.icio.us</a>
<br/>
Post tags: <a href="http://www.bloginfosec.com/tag/application-security/" rel="tag">application security</a>, <a href="http://www.bloginfosec.com/tag/bill-gates/" rel="tag">bill gates</a>, <a href="http://www.bloginfosec.com/tag/facebook/" rel="tag">facebook</a>, <a href="http://www.bloginfosec.com/tag/gates/" rel="tag">gates</a>, <a href="http://www.bloginfosec.com/tag/microsoft/" rel="tag">microsoft</a>, <a href="http://www.bloginfosec.com/tag/privacy/" rel="tag">Privacy</a>, <a href="http://www.bloginfosec.com/tag/spotlight/" rel="tag">spotlight</a>, <a href="http://www.bloginfosec.com/tag/templates/" rel="tag">templates</a>, <a href="http://www.bloginfosec.com/tag/web-applications/" rel="tag">web applications</a><br/>
</small></p>
<p><small>Feed enhanced by <a href='http://planetozh.com/blog/my-projects/wordpress-plugin-better-feed-rss/'>Better Feed</a> from  <a href='http://planetozh.com/blog/'>Ozh</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bloginfosec.com/2009/07/27/bill-gates-facebook-and-privacy-controls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Einstein … Say Aaah!</title>
		<link>http://www.bloginfosec.com/2009/07/21/einstein-%e2%80%a6-say-aaah/</link>
		<comments>http://www.bloginfosec.com/2009/07/21/einstein-%e2%80%a6-say-aaah/#comments</comments>
		<pubDate>Tue, 21 Jul 2009 10:00:33 +0000</pubDate>
		<dc:creator>C. Warren Axelrod</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Information Security News]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Einstein]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[personal information]]></category>
		<category><![CDATA[Siobhan Gorman]]></category>
		<category><![CDATA[spotlight]]></category>

		<guid isPermaLink="false">http://www.bloginfosec.com/?p=1002</guid>
		<description><![CDATA[Perhaps the most famous, or infamous, photograph of Albert Einstein is the one showing him irreverently sticking out his tongue in response to a photographer’s request that he smile. Incidentally one of the few original prints of the photograph sold at auction on June 19, 2009 for the princely sum of $74,324. In any event, [...]<br /><!-- Begin Adify tag for "bloginfosec.com rss" Ad Space (728x90) ID #5674307 -->
<script type="text/javascript">
	sr_adspace_id = 5674307;
	sr_adspace_width = 728;
	sr_adspace_height = 90;
	sr_adspace_type = "graphic";
	sr_ad_new_window = true;
	
</script>
<script type="text/javascript" src="http://ad.afy11.net/srad.js?azId=5674307">
</script>
<!-- End Adify tag for "bloginfosec.com rss" Ad Space (728x90) ID #5674307 --><br />]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>Perhaps the most famous, or infamous, photograph of Albert Einstein is the one showing him irreverently sticking out his tongue in response to a photographer’s request that he smile. Incidentally one of the few original prints of the photograph sold at auction on June 19, 2009 for the princely sum of $74,324. In any event, that image came to mind when I read an article, with the title “Troubles Plague Cyberspy Defense,” by Siobhan Gorman. The article appeared on the front page of the July 3-5, 2009 issue of the Wall Street Journal.</p>
<!-- sphereit end --><img src="http://www.bloginfosec.com/?ak_action=api_record_view&id=1002&type=feed" alt="" />(...)<br/>Read the rest of <a href="http://www.bloginfosec.com/2009/07/21/einstein-%e2%80%a6-say-aaah/">Einstein … Say Aaah!</a> (471 words)<hr />
<p><small>© <a href="http://www.bloginfosec.com">BlogInfoSec.com</a>, 2009. |
<a href="http://www.bloginfosec.com/2009/07/21/einstein-%e2%80%a6-say-aaah/">Permalink</a> |
<a href="http://www.bloginfosec.com/2009/07/21/einstein-%e2%80%a6-say-aaah/#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.bloginfosec.com/2009/07/21/einstein-%e2%80%a6-say-aaah/&title=Einstein … Say Aaah!">del.icio.us</a>
<br/>
Post tags: <a href="http://www.bloginfosec.com/tag/einstein/" rel="tag">Einstein</a>, <a href="http://www.bloginfosec.com/tag/identity-theft/" rel="tag">identity theft</a>, <a href="http://www.bloginfosec.com/tag/personal-information/" rel="tag">personal information</a>, <a href="http://www.bloginfosec.com/tag/privacy/" rel="tag">Privacy</a>, <a href="http://www.bloginfosec.com/tag/siobhan-gorman/" rel="tag">Siobhan Gorman</a>, <a href="http://www.bloginfosec.com/tag/spotlight/" rel="tag">spotlight</a><br/>
</small></p>
<p><small>Feed enhanced by <a href='http://planetozh.com/blog/my-projects/wordpress-plugin-better-feed-rss/'>Better Feed</a> from  <a href='http://planetozh.com/blog/'>Ozh</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bloginfosec.com/2009/07/21/einstein-%e2%80%a6-say-aaah/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Singular Security</title>
		<link>http://www.bloginfosec.com/2009/07/06/singular-security/</link>
		<comments>http://www.bloginfosec.com/2009/07/06/singular-security/#comments</comments>
		<pubDate>Mon, 06 Jul 2009 10:00:20 +0000</pubDate>
		<dc:creator>C. Warren Axelrod</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[artificial intelligence]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[grid computing]]></category>
		<category><![CDATA[NASA]]></category>
		<category><![CDATA[Singularity Univesity]]></category>
		<category><![CDATA[spotlight]]></category>

		<guid isPermaLink="false">http://www.bloginfosec.com/?p=989</guid>
		<description><![CDATA[As infosec professionals continue to struggle mightily trying keep up with the security and privacy vulnerabilities introduced by new technologies and IT environments, such as Web 2.0, Web 3.0 and Cloud Computing, there is a new game in town … singularity. As I will describe, singularity represents a quantum leap ahead in technology.

As reported by [...]<br /><!-- Begin Adify tag for "bloginfosec.com rss" Ad Space (728x90) ID #5674307 -->
<script type="text/javascript">
	sr_adspace_id = 5674307;
	sr_adspace_width = 728;
	sr_adspace_height = 90;
	sr_adspace_type = "graphic";
	sr_ad_new_window = true;
	
</script>
<script type="text/javascript" src="http://ad.afy11.net/srad.js?azId=5674307">
</script>
<!-- End Adify tag for "bloginfosec.com rss" Ad Space (728x90) ID #5674307 --><br />]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>As infosec professionals continue to struggle mightily trying keep up with the security and privacy vulnerabilities introduced by new technologies and IT environments, such as Web 2.0, Web 3.0 and Cloud Computing, there is a new game in town … singularity. As I will describe, singularity represents a quantum leap ahead in technology.</p>
<!-- sphereit end --><img src="http://www.bloginfosec.com/?ak_action=api_record_view&id=989&type=feed" alt="" />(...)<br/>Read the rest of <a href="http://www.bloginfosec.com/2009/07/06/singular-security/">Singular Security</a> (557 words)<hr />
<p><small>© <a href="http://www.bloginfosec.com">BlogInfoSec.com</a>, 2009. |
<a href="http://www.bloginfosec.com/2009/07/06/singular-security/">Permalink</a> |
<a href="http://www.bloginfosec.com/2009/07/06/singular-security/#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.bloginfosec.com/2009/07/06/singular-security/&title=Singular Security">del.icio.us</a>
<br/>
Post tags: <a href="http://www.bloginfosec.com/tag/artificial-intelligence/" rel="tag">artificial intelligence</a>, <a href="http://www.bloginfosec.com/tag/botnets/" rel="tag">botnets</a>, <a href="http://www.bloginfosec.com/tag/google/" rel="tag">Google</a>, <a href="http://www.bloginfosec.com/tag/grid-computing/" rel="tag">grid computing</a>, <a href="http://www.bloginfosec.com/tag/nasa/" rel="tag">NASA</a>, <a href="http://www.bloginfosec.com/tag/privacy/" rel="tag">Privacy</a>, <a href="http://www.bloginfosec.com/tag/singularity-univesity/" rel="tag">Singularity Univesity</a>, <a href="http://www.bloginfosec.com/tag/spotlight/" rel="tag">spotlight</a><br/>
</small></p>
<p><small>Feed enhanced by <a href='http://planetozh.com/blog/my-projects/wordpress-plugin-better-feed-rss/'>Better Feed</a> from  <a href='http://planetozh.com/blog/'>Ozh</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bloginfosec.com/2009/07/06/singular-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trust-Me Privacy</title>
		<link>http://www.bloginfosec.com/2009/05/04/trust-me-privacy/</link>
		<comments>http://www.bloginfosec.com/2009/05/04/trust-me-privacy/#comments</comments>
		<pubDate>Mon, 04 May 2009 11:00:49 +0000</pubDate>
		<dc:creator>C. Warren Axelrod</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[data mining]]></category>
		<category><![CDATA[spotlight]]></category>

		<guid isPermaLink="false">http://www.bloginfosec.com/?p=881</guid>
		<description><![CDATA[Here we go again. We see yet another case of lack of privacy protection and its devastating consequences.
In the &#8220;Link By Link&#8221; segment of the February 16, 2009 issue of the New York Times, Noam Cohen writes a column with the title &#8220;As Data Collecting Grows, Privacy Erodes.&#8221; Again we see that a top public [...]<br /><!-- Begin Adify tag for "bloginfosec.com rss" Ad Space (728x90) ID #5674307 -->
<script type="text/javascript">
	sr_adspace_id = 5674307;
	sr_adspace_width = 728;
	sr_adspace_height = 90;
	sr_adspace_type = "graphic";
	sr_ad_new_window = true;
	
</script>
<script type="text/javascript" src="http://ad.afy11.net/srad.js?azId=5674307">
</script>
<!-- End Adify tag for "bloginfosec.com rss" Ad Space (728x90) ID #5674307 --><br />]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>Here we go again. We see yet another case of lack of privacy protection and its devastating consequences.</p>
<p>In the &#8220;Link By Link&#8221; segment of the February 16, 2009 issue of the <em>New York Times</em>, Noam Cohen writes a column with the title &#8220;As Data Collecting Grows, Privacy Erodes.&#8221; Again we see that a top public hero is diminished by the unauthorized retention of personal data &#8211; in this case, it was Alex Rodriguez&#8217;s information about his using steroids.</p>
<!-- sphereit end --><img src="http://www.bloginfosec.com/?ak_action=api_record_view&id=881&type=feed" alt="" />(...)<br/>Read the rest of <a href="http://www.bloginfosec.com/2009/05/04/trust-me-privacy/">Trust-Me Privacy</a> (519 words)<hr />
<p><small>© <a href="http://www.bloginfosec.com">BlogInfoSec.com</a>, 2009. |
<a href="http://www.bloginfosec.com/2009/05/04/trust-me-privacy/">Permalink</a> |
<a href="http://www.bloginfosec.com/2009/05/04/trust-me-privacy/#comments">One comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.bloginfosec.com/2009/05/04/trust-me-privacy/&title=Trust-Me Privacy">del.icio.us</a>
<br/>
Post tags: <a href="http://www.bloginfosec.com/tag/data-mining/" rel="tag">data mining</a>, <a href="http://www.bloginfosec.com/tag/privacy/" rel="tag">Privacy</a>, <a href="http://www.bloginfosec.com/tag/spotlight/" rel="tag">spotlight</a><br/>
</small></p>
<p><small>Feed enhanced by <a href='http://planetozh.com/blog/my-projects/wordpress-plugin-better-feed-rss/'>Better Feed</a> from  <a href='http://planetozh.com/blog/'>Ozh</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bloginfosec.com/2009/05/04/trust-me-privacy/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
