<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>paulmudgett.com&#187; Should Have Known Better</title>
	<atom:link href="http://paulmudgett.com/category/should-have-known-better/feed/" rel="self" type="application/rss+xml" />
	<link>http://paulmudgett.com</link>
	<description>Information Security &#38; Business Leadership</description>
	<lastBuildDate>Fri, 11 May 2012 16:48:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Occam&#8217;s Razor for Information Security</title>
		<link>http://paulmudgett.com/2012/04/10/occams-razor-for-information-security/</link>
		<comments>http://paulmudgett.com/2012/04/10/occams-razor-for-information-security/#comments</comments>
		<pubDate>Tue, 10 Apr 2012 19:11:00 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[due diligence]]></category>
		<category><![CDATA[security scotoma]]></category>
		<category><![CDATA[security vision]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=468</guid>
		<description><![CDATA[What if the principle of Occam&#8217;s Razor was applied to information security controls? &#8220;All things being equal, a simpler explanation is better than a more complex one&#8221; In other words, if we spent more time applying simple controls rather than chasing buzzwords and &#8220;big stories&#8221;, would we see an overall reduction in data breaches?  According [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/04/10/occams-razor-for-information-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;We Don&#8217;t Need Security.. We Collect Taxes&#8221;</title>
		<link>http://paulmudgett.com/2012/03/21/we-dont-need-security-we-collect-taxes/</link>
		<comments>http://paulmudgett.com/2012/03/21/we-dont-need-security-we-collect-taxes/#comments</comments>
		<pubDate>Wed, 21 Mar 2012 22:04:05 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[National InfoSec]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[National Cyber Security]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[security leadership]]></category>
		<category><![CDATA[security mistakes]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=412</guid>
		<description><![CDATA[If looking for a gold mine of sensitive information, the IRS appears to be the place to find it.  When individuals file their returns, the expectation is that it is well protected by the United States Government.  Unfortunately, the Government Accountability Office (GAO) has found a pattern of weakness in how the IRS protects our [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/03/21/we-dont-need-security-we-collect-taxes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Dog&#8230;.  Old Tricks</title>
		<link>http://paulmudgett.com/2011/09/17/new-dog-old-tricks/</link>
		<comments>http://paulmudgett.com/2011/09/17/new-dog-old-tricks/#comments</comments>
		<pubDate>Sat, 17 Sep 2011 15:15:20 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Awareness and Education]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[security awareness]]></category>
		<category><![CDATA[social media]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=386</guid>
		<description><![CDATA[Funny how the anonymous nature of the Internet continues to mock us all.   Back on September 8th, a fake FBI profile was distributed via Twitter as shown in a recent post on Naked Security &#8211; Fake FBI Anonymous psychological profile &#8211; a lesson to all Internet users. It takes me back to an old New [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2011/09/17/new-dog-old-tricks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Close the barn door&#8230; the horse is out!</title>
		<link>http://paulmudgett.com/2010/12/15/close-the-barn-door-the-horse-is-out/</link>
		<comments>http://paulmudgett.com/2010/12/15/close-the-barn-door-the-horse-is-out/#comments</comments>
		<pubDate>Wed, 15 Dec 2010 21:57:51 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[disgruntled employee]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[insider threat]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=284</guid>
		<description><![CDATA[It never fails. Information security controls are immediately put into place AFTER a significant security incident has happened.  This is true even when these controls are reasonable to have in place and could have prevented the incident from happening at all.   Often, decisions made after an incident are knee-jerk reactions rather than business-minded protections. As [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2010/12/15/close-the-barn-door-the-horse-is-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lessons Not Learned &#8211; Public-Private non-communication in CyberSecurity</title>
		<link>http://paulmudgett.com/2010/08/20/lessons-not-learned-public-private-non-communication-in-cybersecurity/</link>
		<comments>http://paulmudgett.com/2010/08/20/lessons-not-learned-public-private-non-communication-in-cybersecurity/#comments</comments>
		<pubDate>Fri, 20 Aug 2010 23:46:13 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[cyber czar]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[National Cyber Security]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=242</guid>
		<description><![CDATA[One of the deficiencies that came to light in the aftermath of the 9/11 terrorist attacks was the communication failure between competing intelligence agencies.  A report released this past Monday from the Government Accountability Office shows that the same failure to communicate is happening in the cybersecurity arena.  The breakdown in this arena is between [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2010/08/20/lessons-not-learned-public-private-non-communication-in-cybersecurity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Be an Agile Defender</title>
		<link>http://paulmudgett.com/2010/03/18/be-an-agile-defender/</link>
		<comments>http://paulmudgett.com/2010/03/18/be-an-agile-defender/#comments</comments>
		<pubDate>Thu, 18 Mar 2010 17:56:39 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[security enabler]]></category>
		<category><![CDATA[security scotoma]]></category>
		<category><![CDATA[security vision]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=180</guid>
		<description><![CDATA[Anti-virus software is based on signatures of known viruses.  It&#8217;s a reactive product by nature and it should be known by now that these products are ineffective against new viruses and new variants.    That said, why test AV products against attacks they haven&#8217;t seen and then make a stink about it in a ComputerWorld article?  [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2010/03/18/be-an-agile-defender/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lawsuit, breaches and bashing&#8230; oh my!</title>
		<link>http://paulmudgett.com/2010/01/19/lawsuit-breaches-and-bashing-oh-my/</link>
		<comments>http://paulmudgett.com/2010/01/19/lawsuit-breaches-and-bashing-oh-my/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 17:39:38 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[security awareness]]></category>
		<category><![CDATA[security mistakes]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=129</guid>
		<description><![CDATA[Though it seems obvious that corporations have an obligation to protect the sensitive information they use for business it still amazes me that corporate behavior in this regard is still quite dismissive.  Lawsuits and public embarrassment seem to be the only catalyst for action for many organizations.  That is kind of sad.  Not only is [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2010/01/19/lawsuit-breaches-and-bashing-oh-my/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Failures in Leadership, Ethics, and Security</title>
		<link>http://paulmudgett.com/2009/11/25/failures-in-leadership-ethics-and-security/</link>
		<comments>http://paulmudgett.com/2009/11/25/failures-in-leadership-ethics-and-security/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 18:25:19 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[Ethics]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[insider threat]]></category>
		<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=103</guid>
		<description><![CDATA[A breach of patient personal information at University Medical Center has all the makings of a made for TV movie or at least provides an opportunity to examine issues in security, leadership, ethics, and even the knee-jerk reaction of ignorant politicians trying to use the opportunity to score some free publicity.  The story &#8220;FBI looking [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/11/25/failures-in-leadership-ethics-and-security/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Learning From Someone Else&#8217;s Breach</title>
		<link>http://paulmudgett.com/2009/11/20/learning-from-someone-elses-breach/</link>
		<comments>http://paulmudgett.com/2009/11/20/learning-from-someone-elses-breach/#comments</comments>
		<pubDate>Fri, 20 Nov 2009 19:37:07 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[security mistakes]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=100</guid>
		<description><![CDATA[A subsidiary of manged health care provider Health Net Inc, just reported the loss of personal information for 1.5 million customers that occurred six months ago according to a ComputerWorld article.  Without knowing all the details of the situation, I can only speculate as to some of the security controls and thoughts of the Health [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/11/20/learning-from-someone-elses-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Patch Management Only 1/2 the Battle</title>
		<link>http://paulmudgett.com/2009/10/14/patch-management-still-a-problem/</link>
		<comments>http://paulmudgett.com/2009/10/14/patch-management-still-a-problem/#comments</comments>
		<pubDate>Wed, 14 Oct 2009 18:12:30 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/blog/?p=53</guid>
		<description><![CDATA[An audit of cybersecurity for DHS’ nine most frequently visited Web sites found that although general security protocols were followed, there were still a number of vulnerabilities and gaps in security, including inconsistent management of security patching and security assessments.  Lipowicz, Alice.  &#8220;DHS Web sites vulnerable to hackers, IG says&#8221;, Federal Computer Week, 09Oct2009. It [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/10/14/patch-management-still-a-problem/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

