<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>paulmudgett.com</title>
	<atom:link href="http://paulmudgett.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://paulmudgett.com</link>
	<description>Information Security &#38; Business Leadership</description>
	<lastBuildDate>Fri, 11 May 2012 16:48:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>&#8220;You Have My Word On It&#8221;</title>
		<link>http://paulmudgett.com/2012/05/11/youhavemywordonit/</link>
		<comments>http://paulmudgett.com/2012/05/11/youhavemywordonit/#comments</comments>
		<pubDate>Fri, 11 May 2012 16:48:30 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[security mistakes]]></category>
		<category><![CDATA[security vision]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=483</guid>
		<description><![CDATA[Over the years I&#8217;ve had the privilege to hire and work with some talented information security consultants.  Whether they came on to perform a 3rd party assessment necessary to drive remediation efforts (or satisfy compliance obligations), helped troubleshoot an issue or perform initial configuration on new tools, I&#8217;ve been fortunate, in most cases, to separate [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/05/11/youhavemywordonit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Occam&#8217;s Razor for Information Security</title>
		<link>http://paulmudgett.com/2012/04/10/occams-razor-for-information-security/</link>
		<comments>http://paulmudgett.com/2012/04/10/occams-razor-for-information-security/#comments</comments>
		<pubDate>Tue, 10 Apr 2012 19:11:00 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[due diligence]]></category>
		<category><![CDATA[security scotoma]]></category>
		<category><![CDATA[security vision]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=468</guid>
		<description><![CDATA[What if the principle of Occam&#8217;s Razor was applied to information security controls? &#8220;All things being equal, a simpler explanation is better than a more complex one&#8221; In other words, if we spent more time applying simple controls rather than chasing buzzwords and &#8220;big stories&#8221;, would we see an overall reduction in data breaches?  According [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/04/10/occams-razor-for-information-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Checkbox Security Fails Again</title>
		<link>http://paulmudgett.com/2012/04/04/checkbox-security-fails-again/</link>
		<comments>http://paulmudgett.com/2012/04/04/checkbox-security-fails-again/#comments</comments>
		<pubDate>Wed, 04 Apr 2012 16:41:31 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[due diligence]]></category>
		<category><![CDATA[federal legislation]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[ISO 27001/27002]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[PII]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=453</guid>
		<description><![CDATA[Regulatory compliance is often a confusing mess.  Rattling off the alphabet of compliance can often result in dizziness, headaches, and for some, a bad case of nausea.   PCI-DSS, HIPAA, HITECH, GLB, SOX, and heck, might as well throw in some state data breach notification laws as well.  Congress doesn&#8217;t want to stop there as [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/04/04/checkbox-security-fails-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Follow-up Thought:  Facebook Credentials and Hiring Process</title>
		<link>http://paulmudgett.com/2012/04/02/follow-up-thought-facebook-credentials-and-hiring-process/</link>
		<comments>http://paulmudgett.com/2012/04/02/follow-up-thought-facebook-credentials-and-hiring-process/#comments</comments>
		<pubDate>Mon, 02 Apr 2012 20:44:44 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[Ethics]]></category>
		<category><![CDATA[disgruntled employee]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[PII]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=448</guid>
		<description><![CDATA[Just a quick follow-up to my previous post &#8220;Before I hire you I&#8217;ll need the keys to your home&#8230;&#8221; I read a comment on LinkedIn that said there were no laws prohibiting employers from asking you to turn over your Facebook credentials so they can see your private information.  In my non-lawyerly view I think [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/04/02/follow-up-thought-facebook-credentials-and-hiring-process/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>They did WHAT with my data?</title>
		<link>http://paulmudgett.com/2012/03/29/they-did-what-with-my-data/</link>
		<comments>http://paulmudgett.com/2012/03/29/they-did-what-with-my-data/#comments</comments>
		<pubDate>Thu, 29 Mar 2012 15:41:35 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[disgruntled employee]]></category>
		<category><![CDATA[due diligence]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[insider threat]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=434</guid>
		<description><![CDATA[What are your employees doing with your data? I know&#8230; they are all doing their jobs and not doing anything out of the ordinary.  Unfortunately, that isn&#8217;t always the case.  Time and time again, we see individuals inside an organization abusing their access to inappropriately view, or in the worst case steal, sensitive information. Take [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/03/29/they-did-what-with-my-data/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Before I hire you I&#8217;ll need the keys to your home&#8230;</title>
		<link>http://paulmudgett.com/2012/03/27/before-i-hire-you-ill-need-the-keys-to-your-home/</link>
		<comments>http://paulmudgett.com/2012/03/27/before-i-hire-you-ill-need-the-keys-to-your-home/#comments</comments>
		<pubDate>Tue, 27 Mar 2012 18:06:00 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Ethics]]></category>
		<category><![CDATA[due diligence]]></category>
		<category><![CDATA[social media]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=428</guid>
		<description><![CDATA[I wouldn&#8217;t believe it if I didn&#8217;t read multiple stories talking about employers asking prospective employees to hand over their Facebook passwords during job interviews.  This is simply outrageous yet I can see how those who have been looking for work for over a year may feel compelled to provide their credentials or lose an [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/03/27/before-i-hire-you-ill-need-the-keys-to-your-home/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>I Was Just Trying To Help&#8230;</title>
		<link>http://paulmudgett.com/2012/03/23/i-was-just-trying-to-help/</link>
		<comments>http://paulmudgett.com/2012/03/23/i-was-just-trying-to-help/#comments</comments>
		<pubDate>Fri, 23 Mar 2012 16:10:22 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Awareness and Education]]></category>
		<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[insider threat]]></category>
		<category><![CDATA[security awareness]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=424</guid>
		<description><![CDATA[&#8220;I don&#8217;t have access to that budget file.  Can you give it to me?&#8221; As easy as that security controls meant to provide access to information to only those who need it to do their job (the practice of least privilege) is bypassed by well intentioned employees.  They only want to help but their behavior [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/03/23/i-was-just-trying-to-help/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacker Motivation &#8211; Does it Matter?</title>
		<link>http://paulmudgett.com/2012/03/22/hacker-motivation-does-it-matter/</link>
		<comments>http://paulmudgett.com/2012/03/22/hacker-motivation-does-it-matter/#comments</comments>
		<pubDate>Thu, 22 Mar 2012 17:32:37 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[security awareness]]></category>
		<category><![CDATA[security scotoma]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=417</guid>
		<description><![CDATA[Motivation according to Dictionary.com is &#8220;the act or an instance of motivating, or providing with a reason to act in a certain way.&#8221;   While stealing data from organizations continues to be financially motivated the 2012 Verizon Data Breach Report indicated an increase in data theft as a result of hacktivism (data breaches aimed at advancing [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/03/22/hacker-motivation-does-it-matter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;We Don&#8217;t Need Security.. We Collect Taxes&#8221;</title>
		<link>http://paulmudgett.com/2012/03/21/we-dont-need-security-we-collect-taxes/</link>
		<comments>http://paulmudgett.com/2012/03/21/we-dont-need-security-we-collect-taxes/#comments</comments>
		<pubDate>Wed, 21 Mar 2012 22:04:05 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[National InfoSec]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[National Cyber Security]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[security leadership]]></category>
		<category><![CDATA[security mistakes]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=412</guid>
		<description><![CDATA[If looking for a gold mine of sensitive information, the IRS appears to be the place to find it.  When individuals file their returns, the expectation is that it is well protected by the United States Government.  Unfortunately, the Government Accountability Office (GAO) has found a pattern of weakness in how the IRS protects our [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/03/21/we-dont-need-security-we-collect-taxes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The real 1 percenters&#8230;.</title>
		<link>http://paulmudgett.com/2012/03/12/the-real-1-percenters/</link>
		<comments>http://paulmudgett.com/2012/03/12/the-real-1-percenters/#comments</comments>
		<pubDate>Mon, 12 Mar 2012 18:15:16 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[security context]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=405</guid>
		<description><![CDATA[There are a lot of vendors pushing their wares using zero-day exploits as a chief selling piece in their propaganda.  The problem is, the vast majority of servers are compromised by known vulnerabilities and a failure in the patching process.   It stands to reason that there is more bang-for-the-buck by addressing issues such as vulnerability [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/03/12/the-real-1-percenters/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

