 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Trenches &#187; Policy</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/it-trenches/tag/policy/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/it-trenches</link>
	<description></description>
	<lastBuildDate>Fri, 19 Nov 2010 14:37:59 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Did you see this? &#8211; FREE TRAINING: Technet Virtual Lab: Managing Bandwidth Using Windows QOS</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-free-training-technet-virtual-lab-managing-bandwidth-using-windows-qos/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-free-training-technet-virtual-lab-managing-bandwidth-using-windows-qos/#comments</comments>
		<pubDate>Mon, 01 Dec 2008 19:40:51 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[administration]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[design]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[IT education]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Performance]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[server]]></category>
		<category><![CDATA[troubleshooting]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-free-training-technet-virtual-lab-managing-bandwidth-using-windows-qos/</guid>
		<description><![CDATA[For those of you considering using Microsoft Windows Server 2008, you might want to check out this TechNet Virtual Lab: Managing Network Bandwidth Using Windows Quality of Service (QOS) You will learn about using Windows Server 2008 to control bandwidth usage using protocol definitions as well as control bandwidth for particular applications. In case you have [...]]]></description>
				<content:encoded><![CDATA[<p>For those of you considering using Microsoft Windows Server 2008, you might want to check out this <a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032393785&amp;EventCategory=3&amp;culture=en-US&amp;CountryCode=US" title="Technet Virtual Lab"><span>TechNet Virtual Lab: Managing Network Bandwidth Using  Windows Quality of Service (QOS)</span></a> You will <a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032393785&amp;EventCategory=3&amp;culture=en-US&amp;CountryCode=US" title="Technet Virtual Lab"><span></span></a>learn about using Windows Server 2008 to control bandwidth usage using protocol definitions as well as control bandwidth for particular applications. In case you have not done any of these Virtual labs, they are an excellent <strong>FREE!</strong> training resource.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-free-training-technet-virtual-lab-managing-bandwidth-using-windows-qos/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Alternatives to e-mail attachments &#8211; SharePoint is risky!</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/alternatives-to-e-mail-attachments/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/alternatives-to-e-mail-attachments/#comments</comments>
		<pubDate>Thu, 09 Oct 2008 15:00:20 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[administration]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[design]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[intellectual property]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[policy enforcement]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SharePoint]]></category>
		<category><![CDATA[Storage]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[website]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/alternatives-to-e-mail-attachments/</guid>
		<description><![CDATA[I&#8217;m looking for some help on this topic and have posted a question to the ITKE community. Hopefully someone out there has had some experience with this service for your organization and can provide some valuable insight. One group I participate in is a mailing list from SANS. If you have not attended a SANS [...]]]></description>
				<content:encoded><![CDATA[<p>I&#8217;m looking for some help on this topic and have posted <a href="http://itknowledgeexchange.techtarget.com/itanswers/alternatives-to-email-file-attachments/" target="_blank">a question to the ITKE community</a>. Hopefully someone out there has had some experience with this service for your organization and can provide some valuable insight.</p>
<p>One group I participate in is a mailing list from <a href="http://www.sans.org" target="_blank">SANS</a>. If you have not attended a SANS event or education, then you should try to get to one of their events. They are one, if not, the premier non-vendor related security and systems administration group in the IT industry. I posed the same question to this peer group and have had some very good responses. Some suggestions for solutions have come back and include:</p>
<p><!--[if gte mso 9]&amp;gt;     Normal   0               false   false   false      EN-US   X-NONE   X-NONE                                                     MicrosoftInternetExplorer4                                                   --><!--[if gte mso 9]&amp;gt;                                                                                                                                                                                                                                                                                                                                                                                                                                --> <!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1107304683 0 0 159 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;} @font-face 	{font-family:Verdana; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:536871559 0 0 0 415 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Verdana","sans-serif"; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman";} a:link, span.MsoHyperlink 	{mso-style-priority:99; 	color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:purple; 	mso-themecolor:followedhyperlink; 	text-decoration:underline; 	text-underline:single;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	font-size:10.0pt; 	mso-ansi-font-size:10.0pt; 	mso-bidi-font-size:10.0pt;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&amp;gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;}  --><span>Microsoft Office SharePoint (<a href="http://www.microsoft.com/sharepoint/default.mspx">http://www.microsoft.com/sharepoint/default.mspx</a>)</span></p>
<p class="MsoNormal"><span>OpenText – Livelink (<a href="http://www.opentext.com/2/sol-products/sol-pro-llecm10.htm">http://www.opentext.com/2/sol-products/sol-pro-llecm10.htm</a>)</span></p>
<p class="MsoNormal"><span>Webex Connect – (<a href="http://webex.com/enterprise/index.html">http://webex.com/enterprise/index.html</a>) (There are other flavors for small &amp; medium business)</span></p>
<p class="MsoNormal"><span> Accellion &#8211; (http://www.accellion.com)</span></p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">These are very interesting solutions and I will certainly be looking at all potential candidates. One thing that bothers me about the SharePoint option is its security capabilities. SharePoint is typically Microsoft Active Directory integrated. This has major security implications and in fact CSO magazine has posted a recent article on this topic. I recommend that you read the article and understand what risks the SharePoint solution may open for your organization.</p>
<p class="MsoPlainText"><a href="http://cxolyris.cxomedia.com/t/2738521/795826/30002/0/" target="_blank">Why Security Pros Hate Microsoft SharePoint</a></p>
<p class="MsoPlainText">Microsoft&#8217;s SharePoint collaboration platform is all the rage in today&#8217;s business world, especially since third parties gained the ability to plug security holes. But managing it can still be a nightmare for IT security shops.</p>
<p class="MsoPlainText">I am still looking for more references and ideas for this solution, so please share what you are doing for your organization and it will be much appreciated by me and other readers.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/alternatives-to-e-mail-attachments/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Did you see this? &#8211; Encyclopedia of internal network security threats</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-encyclopedia-of-internal-network-security-threats/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-encyclopedia-of-internal-network-security-threats/#comments</comments>
		<pubDate>Fri, 19 Sep 2008 12:53:21 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[antivirus]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Browsers]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[design]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[homeland security]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[man-in-the-middle]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[troubleshooting]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[website]]></category>
		<category><![CDATA[WWW]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-encyclopedia-of-internal-network-security-threats/</guid>
		<description><![CDATA[Promisec has released an online encyclopedia of internal network security threats. This is available online for free. There is a lot of information to look through and decide how the risks affect your organization. Take for example the entry describing GoogleTalk. The site rates it as one of the top 5 internal threats. The more [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://http://www.promisec.com/encyclopedia/" target="_blank">Promisec</a> has released an online encyclopedia of internal network security threats. This is available online for free. There is a lot of information to look through and decide how the risks affect your organization.</p>
<p>Take for example the entry describing <a href="http://www.promisec.com/encyclopedia/InternalThreatsDetails.asp?catID=6394&amp;itemID=37255" target="_blank">GoogleTalk</a>. The site rates it as one of the top 5 internal threats.</p>
<p>The more we know about these risks the better prepared we can be. Thanks for your time. Let’s be good network citizens together &amp; practice safe networking!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-encyclopedia-of-internal-network-security-threats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RANT: Am I responsible for training technology staff at other companies?</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/rant-am-i-responsible-for-training-technology-staff-at-other-companies/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/rant-am-i-responsible-for-training-technology-staff-at-other-companies/#comments</comments>
		<pubDate>Thu, 11 Sep 2008 16:36:44 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[administration]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[design]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[policy enforcement]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[WAN]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/rant-am-i-responsible-for-training-technology-staff-at-other-companies/</guid>
		<description><![CDATA[You may have seen in one of my past blog posts that we relocated a site over a weekend. As a result of that move we are continuing to clean-up various network access issues for services that existed in the old facility but are not available at the new facility. In the old facility some [...]]]></description>
				<content:encoded><![CDATA[<p>You may have seen in one of my <a href="http://itknowledgeexchange.techtarget.com/it-trenches/moving-a-datacenter-one-weekend-done/" target="_blank">past blog</a> posts that we relocated a site over a weekend. As a result of that move we are continuing to clean-up various network access issues for services that existed in the old facility but are not available at the new facility.</p>
<p>In the old facility some of the users were required to use a kiosk or standalone computer to access customer extranets using VPN. We wanted to make this easier in the new facility and get rid of the standalone computers and internet connections. As we approach each instance of VPN access, we have to ask the standard questions of what is the destination IP address and what ports need to be opened on the firewall for this service. I recently came across a customer technology staff member at another organization who was responsible for the remote access service but could not answer these standard application questions. The answer I was given was just open any-to-any ports for their destination IP (at least he knew their IP address for this service). I don&#8217;t think this was a junior staff member either answering the question. This is the person responsible for interfacing with suppliers!</p>
<p>Well, after walking around and burning off some frustration, I took some steps to try to identify how the application works and make firewall changes according to what I discovered. Working with my managed security partner I went through the following steps:</p>
<p>1. Configure a private client machine and designate as single source of traffic.</p>
<p>2. Define firewall rule to permit any traffic from this client to the destination IP.</p>
<p>3. Run VPN application  and capture details about TCP/UDP ports during the conversation.</p>
<p>4. Close the any-to-any rule and open ports discovered in step #3.</p>
<p>Well, things did work pretty well but apparently there are some other ports needed to be opened, so once again I am asking this customer to help us as their supplier to gain access to their network. We will see if I have to get someone else involved in his organization even though I was told he manages this by himself.</p>
<p>hmmmm&#8230; so have you ever had to train someone at another organization that you deal with how to do their job?</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/rant-am-i-responsible-for-training-technology-staff-at-other-companies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Did you see this? &#8211; 2007 Web Application Security Statistics Project</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-2007-web-application-security-statistics-project/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-2007-web-application-security-statistics-project/#comments</comments>
		<pubDate>Mon, 08 Sep 2008 16:49:58 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[awareness]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[Development]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Metrics]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[website]]></category>
		<category><![CDATA[WWW]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-2007-web-application-security-statistics-project/</guid>
		<description><![CDATA[The Web Application Security Consortium (WASC) is pleased to announce the WASC Web Application Security Statistics Project 2007. This initiative is a collaborative industry wide effort to pool together sanitized website vulnerability data and to gain a better understanding about the web application vulnerability landscape.   Goals 1. Identify the prevalence and probability of different [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0               false   false   false      EN-US   X-NONE   X-NONE                                                                                                        --><!--[if gte mso 9]&gt;                                                                                                                                                                                                                                                                                                                                                                                                                                --> <!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1107304683 0 0 159 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;} @font-face 	{font-family:Consolas; 	panose-1:2 11 6 9 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:modern; 	mso-font-pitch:fixed; 	mso-font-signature:-1610611985 1073750091 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} a:link, span.MsoHyperlink 	{mso-style-priority:99; 	color:blue; 	mso-themecolor:hyperlink; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:purple; 	mso-themecolor:followedhyperlink; 	text-decoration:underline; 	text-underline:single;} p.MsoPlainText, li.MsoPlainText, div.MsoPlainText 	{mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-link:"Plain Text Char"; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.5pt; 	font-family:Consolas; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} span.PlainTextChar 	{mso-style-name:"Plain Text Char"; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-unhide:no; 	mso-style-locked:yes; 	mso-style-link:"Plain Text"; 	mso-ansi-font-size:10.5pt; 	mso-bidi-font-size:10.5pt; 	font-family:Consolas; 	mso-ascii-font-family:Consolas; 	mso-hansi-font-family:Consolas;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;}  --></p>
<p class="MsoPlainText">The Web Application Security Consortium (WASC) is pleased to announce the WASC Web Application Security Statistics Project 2007. This initiative is a collaborative industry wide effort to pool together sanitized website vulnerability data and to gain a better understanding about the web application vulnerability landscape.</p>
<p class="MsoPlainText"> </p>
<p class="MsoPlainText">Goals</p>
<p class="MsoPlainText">1. Identify the prevalence and probability of different vulnerability classes 2. Compare testing methodologies against what types of vulnerabilities they<span> </span>are likely to identify.</p>
<p class="MsoPlainText"> </p>
<p class="MsoPlainText">The statistics was compiled from web application security assessment projects which were made by the following companies in 2007 (in alphabetic</p>
<p class="MsoPlainText">order):</p>
<p class="MsoPlainText"> </p>
<p class="MsoPlainText">- Booz Allen Hamilton</p>
<p class="MsoPlainText">- BT</p>
<p class="MsoPlainText">- Cenzic with Hailstorm and ClickToSecure</p>
<p class="MsoPlainText">- dblogic.it</p>
<p class="MsoPlainText">- HP Application Security Center with WebInspect</p>
<p class="MsoPlainText">- Positive Technologies with MaxPatrol</p>
<p class="MsoPlainText">- Veracode with Veracode Security Review</p>
<p class="MsoPlainText">- WhiteHat Security with WhiteHat Sentinel</p>
<p class="MsoPlainText"> </p>
<p class="MsoPlainText">The overall statistics includes analysis results of 32,717 sites and 69,476 vulnerabilities of different degrees of severity. The detailed information can be found here:</p>
<p class="MsoPlainText"> </p>
<p><span><a href="http://www.webappsec.org/projects/statistics/">http://www.webappsec.org/projects/statistics/</a></span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-2007-web-application-security-statistics-project/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Did you see (listen to) this? &#8211; Podcast on preventing spam</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-listen-to-this-podcast-on-preventing-spam/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-listen-to-this-podcast-on-preventing-spam/#comments</comments>
		<pubDate>Wed, 03 Sep 2008 19:28:55 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[administration]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[IT education]]></category>
		<category><![CDATA[Metrics]]></category>
		<category><![CDATA[Performance]]></category>
		<category><![CDATA[podcast]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-listen-to-this-podcast-on-preventing-spam/</guid>
		<description><![CDATA[An audio podcast on how SPAM is generated along with an examination on the frameworks and technologies that help manage and reduce SPAM. This may be a great tutorial for you and/or your users. CERTStation Media &#8211; Spam-Prevent.mp3 I just ran my monthly e-mail statistics and these are the results: 97,000 msgs/day inbound 8,800 msgs/day [...]]]></description>
				<content:encoded><![CDATA[<p>An audio podcast on how SPAM is generated along with an examination on the frameworks and technologies that help manage and reduce SPAM.</p>
<p>This may be a great tutorial for you and/or your users.</p>
<p><a href="http://usp.hdaar.com/radio/hdmedia/Spam-Prevent.mp3" target="_blank">CERTStation Media &#8211; Spam-Prevent.mp3</a></p>
<p>I just ran my monthly e-mail statistics and these are the results:</p>
<p>97,000 msgs/day inbound</p>
<p>8,800 msgs/day delivered to end users &#8211; 9%</p>
<p>22,200 msgs/day quarantined as spam &#8211; 23%</p>
<p>66,000 msgs/day blocked as spam &#8211; 67%</p>
<p>This month had higher than normal quarantine activity. Quarantine has been running about 15% and blocking around 75%.  How does your mail stack up?</p>
<p>Thanks for your time. Let’s be good network citizens together &amp; practice safe networking!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-listen-to-this-podcast-on-preventing-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://usp.hdaar.com/radio/hdmedia/Spam-Prevent.mp3" length="8329825" type="audio/x-mpeg" />
		</item>
		<item>
		<title>Operation Sentinel &#8211; Manhattan becomes &#8220;Big Brother&#8221;</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/operation-sentinel-manhattan-becomes-big-brother/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/operation-sentinel-manhattan-becomes-big-brother/#comments</comments>
		<pubDate>Tue, 02 Sep 2008 18:22:29 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[awareness]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[dhs]]></category>
		<category><![CDATA[homeland security]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[policy enforcement]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/operation-sentinel-manhattan-becomes-big-brother/</guid>
		<description><![CDATA[Hopefully you have read my previous blog entry about IT Equipment Search &#38; Seizure at US Borders. Well, if that is not enough to make you think Big Brother is here and watching, then take a look at the article NYPD seeks to screen vehicles entering Manhattan. This could be come one of the grandest [...]]]></description>
				<content:encoded><![CDATA[<p>Hopefully you have read my previous blog entry about <a href="http://itknowledgeexchange.techtarget.com/it-trenches/it-equipment-search-seizure-at-the-us-borders/" target="_blank">IT Equipment Search &amp; Seizure at US Borders</a>. Well, if that is not enough to make you think Big Brother is here and watching, then take a look at the article <a href="http://www.securityinfowatch.com/online/Homeland-Security/NYPD-seeks-to-screen-vehicles-entering-Manhattan/17167SIW359" target="_blank">NYPD seeks to screen vehicles entering Manhattan.</a> This could be come one of the grandest IT endeavors of all time. How do you track these vehicles? What criteria do you capture to be able to determine a threat or not? The article mentions images and radiological readings. I think that authenticating and ensuring readings and images are accurate would create a market need for supercomputer implementations in New York City. How often are the radiological scanning devices calibrated and tested? What skills does someone need to be able to do that? Can cameras be fooled and images wrong?</p>
<p>Who is paying for all of this for NYC? Is this really where the city should be spending its dollars on risk mitigation? Maybe someone should share my <a href="http://itknowledgeexchange.techtarget.com/it-trenches/managing-risk-vulnerability/" target="_blank">thoughts on managing risk &amp; vulnerability</a>.</p>
<p>Thanks for your time. Let’s be good network citizens together &amp; practice safe networking!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/operation-sentinel-manhattan-becomes-big-brother/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IT Equipment search &amp; seizure at the US borders</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/it-equipment-search-seizure-at-the-us-borders/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/it-equipment-search-seizure-at-the-us-borders/#comments</comments>
		<pubDate>Thu, 21 Aug 2008 20:08:36 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[administration]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[design]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[intellectual property]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[IT education]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[online identity]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[policy enforcement]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[WAN]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/it-equipment-search-seizure-at-the-us-borders/</guid>
		<description><![CDATA[I have recently been hearing some rumblings about this issue. I work for a firm with international locations and have travelled out of the country myself. So, this is a personal issue. What I am referring to is the situation described in this article by David Jonas of The Transnational: Airport Laptop Seizures Debated in [...]]]></description>
				<content:encoded><![CDATA[<p>I have recently been hearing some rumblings about this issue. I work for a firm with international locations and have travelled out of the country myself. So, this is a personal issue.</p>
<p>What I am referring to is the situation described in this article by David Jonas of The Transnational: <a href="http://www.thetransnational.travel/news.php?cid=laptop-seizure.Jul-08.09 " target="_blank">Airport Laptop Seizures Debated in Washington</a>. I know that I should have nothing to worry about if I do nothing wrong like any law abiding citizen of the world. However, what about the risk to an organization&#8217;s intellectual property?</p>
<p>Look at the comment <em>&#8230;the laptop seizure policy is not analogous to physical searches of persons and  belongings at airports: &#8220;Not only does the government get access to an  unprecedented wealth of material with a laptop border search, but the government  now has the ability to copy, store and analyze that information at its leisure.  In traditional border searches, travelers carried their suitcases with them once  they cleared customs. With laptop border searches, the government can keep  everything in the computer in perpetuity.&#8221;</em> So, who is responsible for the data once it is out of the traveller&#8217;s hands? What is the care &amp; duty of the government with regards to a company&#8217;s intellectual capital?</p>
<p>This issue seems like a bureaucratic (and maybe totalitarian leaning &#8211; think &#8220;Big Brother&#8221;) nightmare! Who would be considered the appropriate person to review the data on a device? What is their liability if the device or data is damaged during their review?</p>
<p>I know I don&#8217;t have an easy answer to these nagging questions and it will take much better minds and skills than mine to work through the protection and liability issues for an organization. What mechanisms do you use to protect equipment and data during travel? Maybe this situation is a boon to shipping organizations. More people may be shipping their gear ahead of them when travelling across the border or use equipment at a remote site and transfer data across a network.</p>
<p>This situation is definitely one to watch and be concerned about as world citizens.</p>
<p>Thanks for your time. Let’s be good network citizens together &amp; practice safe networking!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/it-equipment-search-seizure-at-the-us-borders/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Did you see this? &#8211; Need some Exchange advice/support</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-need-some-exchange-advicesupport/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-need-some-exchange-advicesupport/#comments</comments>
		<pubDate>Wed, 20 Aug 2008 18:19:26 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[administration]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[CA]]></category>
		<category><![CDATA[certificate authority]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[design]]></category>
		<category><![CDATA[digital signatures]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Exchange 2007]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Outlook Web Access]]></category>
		<category><![CDATA[OWA]]></category>
		<category><![CDATA[Performance]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[policy enforcement]]></category>
		<category><![CDATA[Powershell]]></category>
		<category><![CDATA[RSS]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[toolkit]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[website]]></category>
		<category><![CDATA[wiki]]></category>
		<category><![CDATA[WWW]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-need-some-exchange-advicesupport/</guid>
		<description><![CDATA[Maybe you have already read my post about implementing new Exchange 2007 mailboxes for over 2000 users. If not&#8230; look here. So, as you see from this event, ongoing support for these global users on a new messaging system is going to be a real challenge. I found a great blog posting with links to [...]]]></description>
				<content:encoded><![CDATA[<p>Maybe you have already read my post about implementing new Exchange 2007 mailboxes for over 2000 users. If not&#8230; look <a href="http://itknowledgeexchange.techtarget.com/it-trenches/2000-users-new-mailboxes-one-weekend-done/" target="_blank">here</a>. So, as you see from this event, ongoing support for these global users on a new messaging system is going to be a real challenge.</p>
<p>I found a great <a href="http://weblog.infoworld.com/enterprisewindows/archives/2008/08/exchange_advice.html?source=NLC-ENTWINDOW&amp;cgd=2008-08-20" target="_blank">blog posting</a> with links to some excellent Exchange resources. Keep this in your toolkit for those times you just can&#8217;t find the answer elsewhere to those nagging Exchange problems. I see lots of other IT people struggling with this system and looking for support here at IT KnowledgeExchange.</p>
<p>Some other Exchange resources I recommend are:</p>
<p><a href="http://www.msexchange.org/" target="_blank">Microsoft Exchange Server Resource Site</a></p>
<p><a href="http://www.archiving101.com/" target="_blank">E-mail archiving</a></p>
<p><a href="http://www.microsoft.com/atwork/manageinfo/emailtools.mspx" target="_blank">Seven ways to organize your e-mail</a></p>
<p><a href="http://www.messagingtalk.org" target="_blank">MessagingTalk.org</a> &#8211; Portal for Microsoft Exchange Messaging &amp; Collaboration</p>
<p>Thanks for your time. Let’s be good network citizens together &amp; practice safe networking!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-need-some-exchange-advicesupport/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Managing risk &amp; vulnerability</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/managing-risk-vulnerability/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/managing-risk-vulnerability/#comments</comments>
		<pubDate>Thu, 14 Aug 2008 02:58:32 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[administration]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[design]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[IT education]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[policy enforcement]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/managing-risk-vulnerability/</guid>
		<description><![CDATA[Jotting some quick thoughts here after answering a user post. Thought I would place the same information here for all to see. This list is by no means complete and your thoughts are always welcome. Some ways to measure risk include: How valuable is the asset? How much of a threat exists? What is the [...]]]></description>
				<content:encoded><![CDATA[<p>Jotting some quick thoughts here after answering a user post. Thought I would place the same information here for all to see. This list is by no means complete and your thoughts are always welcome.</p>
<p>Some ways to measure risk include:</p>
<p>How valuable is the asset?<br />
How much of a threat exists?<br />
What is the impact if the system/service is exploited?<br />
Is the vulnerability rated high/medium/low?<br />
Can the risk be reduced?<br />
How easily can it be reduced considering costs, technology, staffing &amp; skills?<br />
What is the probability of the vulnerability being exploited?</p>
<p>You are asking yourself:<br />
What are you protecting?<br />
What can happen to it? &#8211; How can it happen?<br />
What does it mean to the business?<br />
How can the risk be reduced?<br />
How likely is it to happen given the existing conditions?</p>
<p>Risk assessment goal: identify &amp; prioritize risks.<br />
Risk management goal: manage risks to an acceptable level. This can be done by:</p>
<ul>
<li>Mitigate: select controls; implement; monitor</li>
<li> Transfer: purchase insurance</li>
<li>Accept: do nothing</li>
<li> Avoid: discontinue activity</li>
</ul>
<p>Thanks for your time. Let’s be good network citizens together &amp; practice safe networking!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/managing-risk-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
