<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>paulmudgett.com&#187; ISO 27001/27002</title>
	<atom:link href="http://paulmudgett.com/tag/iso-2700127002/feed/" rel="self" type="application/rss+xml" />
	<link>http://paulmudgett.com</link>
	<description>Information Security &#38; Business Leadership</description>
	<lastBuildDate>Fri, 11 May 2012 16:48:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Checkbox Security Fails Again</title>
		<link>http://paulmudgett.com/2012/04/04/checkbox-security-fails-again/</link>
		<comments>http://paulmudgett.com/2012/04/04/checkbox-security-fails-again/#comments</comments>
		<pubDate>Wed, 04 Apr 2012 16:41:31 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[due diligence]]></category>
		<category><![CDATA[federal legislation]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[ISO 27001/27002]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[PII]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=453</guid>
		<description><![CDATA[Regulatory compliance is often a confusing mess.  Rattling off the alphabet of compliance can often result in dizziness, headaches, and for some, a bad case of nausea.   PCI-DSS, HIPAA, HITECH, GLB, SOX, and heck, might as well throw in some state data breach notification laws as well.  Congress doesn&#8217;t want to stop there as [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/04/04/checkbox-security-fails-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Risk-based Information Security</title>
		<link>http://paulmudgett.com/2009/12/28/risk-based-information-security/</link>
		<comments>http://paulmudgett.com/2009/12/28/risk-based-information-security/#comments</comments>
		<pubDate>Mon, 28 Dec 2009 18:50:15 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[ISO 27001/27002]]></category>
		<category><![CDATA[security enabler]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=114</guid>
		<description><![CDATA[How do you even start protecting your information assets if you don&#8217;t have an understanding of the risk to them?  I would venture to say&#8230; you don&#8217;t.  It&#8217;s difficult for some to get started down this path because they quickly get overwhelmed with the task at hand.  Many times, a good effort gets set aside [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/12/28/risk-based-information-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Baby Steps &#8211; Information Security Process Improvement</title>
		<link>http://paulmudgett.com/2009/11/13/baby-steps-information-security-process-improvement/</link>
		<comments>http://paulmudgett.com/2009/11/13/baby-steps-information-security-process-improvement/#comments</comments>
		<pubDate>Fri, 13 Nov 2009 18:57:22 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[ISO 27001/27002]]></category>
		<category><![CDATA[security automation]]></category>
		<category><![CDATA[security enabler]]></category>
		<category><![CDATA[security vision]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=89</guid>
		<description><![CDATA[Organizations can quickly become overwhelmed when trying to implement a comprehensive information security program.  There are many barriers.  Cost.  Time.  Competency.   As I&#8217;ve posted before, security is an ongoing process and needs to be in order to deal with the changing business environment and evolving threat landscape.  Instead of implementing the very best (and most [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/11/13/baby-steps-information-security-process-improvement/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Using a Framework to Navigate Regulatory Compliance</title>
		<link>http://paulmudgett.com/2009/10/21/using-a-framework-to-navigate-regulatory-compliance/</link>
		<comments>http://paulmudgett.com/2009/10/21/using-a-framework-to-navigate-regulatory-compliance/#comments</comments>
		<pubDate>Wed, 21 Oct 2009 22:48:49 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[ISO 27001/27002]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/blog/?p=59</guid>
		<description><![CDATA[The regulatory environment overseeing the protection of sensitive information is incredibly crowded.  Sarbanes-Oxley (SOX), Graham-Leach-Bliley (GLB), the Health Insurance Portability and Accountability Act (HIPAA), HITECH, Red Flags, Payment Card Industry Data Security Standard (PCI-DSS), among a host of state laws and audit guidelines seems to provide the Fort Know of IT risk management if organizations [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/10/21/using-a-framework-to-navigate-regulatory-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

