<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>paulmudgett.com&#187; security mistakes</title>
	<atom:link href="http://paulmudgett.com/tag/security-mistakes/feed/" rel="self" type="application/rss+xml" />
	<link>http://paulmudgett.com</link>
	<description>Information Security &#38; Business Leadership</description>
	<lastBuildDate>Fri, 11 May 2012 16:48:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>&#8220;You Have My Word On It&#8221;</title>
		<link>http://paulmudgett.com/2012/05/11/youhavemywordonit/</link>
		<comments>http://paulmudgett.com/2012/05/11/youhavemywordonit/#comments</comments>
		<pubDate>Fri, 11 May 2012 16:48:30 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[security mistakes]]></category>
		<category><![CDATA[security vision]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=483</guid>
		<description><![CDATA[Over the years I&#8217;ve had the privilege to hire and work with some talented information security consultants.  Whether they came on to perform a 3rd party assessment necessary to drive remediation efforts (or satisfy compliance obligations), helped troubleshoot an issue or perform initial configuration on new tools, I&#8217;ve been fortunate, in most cases, to separate [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/05/11/youhavemywordonit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;We Don&#8217;t Need Security.. We Collect Taxes&#8221;</title>
		<link>http://paulmudgett.com/2012/03/21/we-dont-need-security-we-collect-taxes/</link>
		<comments>http://paulmudgett.com/2012/03/21/we-dont-need-security-we-collect-taxes/#comments</comments>
		<pubDate>Wed, 21 Mar 2012 22:04:05 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[National InfoSec]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[National Cyber Security]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[security leadership]]></category>
		<category><![CDATA[security mistakes]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=412</guid>
		<description><![CDATA[If looking for a gold mine of sensitive information, the IRS appears to be the place to find it.  When individuals file their returns, the expectation is that it is well protected by the United States Government.  Unfortunately, the Government Accountability Office (GAO) has found a pattern of weakness in how the IRS protects our [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/03/21/we-dont-need-security-we-collect-taxes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Shame for InfoSec Transparency</title>
		<link>http://paulmudgett.com/2010/03/13/a-shame-for-infosec-transparency/</link>
		<comments>http://paulmudgett.com/2010/03/13/a-shame-for-infosec-transparency/#comments</comments>
		<pubDate>Sat, 13 Mar 2010 17:06:45 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Awareness and Education]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[security awareness]]></category>
		<category><![CDATA[security mistakes]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=167</guid>
		<description><![CDATA[The CISO of Pennsylvania was apparently fired after discussing a breach while serving on a panel at the recent RSA conference.  The removal appeared in several articles including this SCMagazine report.   The information provided by Bob Maley was a clear description of a threat that some states may face, an appropriate discussion for this panel.  [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2010/03/13/a-shame-for-infosec-transparency/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Cyber Maginot Line</title>
		<link>http://paulmudgett.com/2010/01/28/the-cyber-maginot-line/</link>
		<comments>http://paulmudgett.com/2010/01/28/the-cyber-maginot-line/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 19:55:54 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[National Cyber Security]]></category>
		<category><![CDATA[security mistakes]]></category>
		<category><![CDATA[security vision]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=136</guid>
		<description><![CDATA[Between 1930 and 1940, France built a massive system  of defenses known as the Maginot Line.  Designed to stop a German invasion, history illustrates its failure.  The 1940 German invasion of France skirted the defensive Maginot Line as they swiftly penetrated through the Ardennes by way of Belgium.  I&#8217;m not a historian and there are [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2010/01/28/the-cyber-maginot-line/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Lawsuit, breaches and bashing&#8230; oh my!</title>
		<link>http://paulmudgett.com/2010/01/19/lawsuit-breaches-and-bashing-oh-my/</link>
		<comments>http://paulmudgett.com/2010/01/19/lawsuit-breaches-and-bashing-oh-my/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 17:39:38 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[security awareness]]></category>
		<category><![CDATA[security mistakes]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=129</guid>
		<description><![CDATA[Though it seems obvious that corporations have an obligation to protect the sensitive information they use for business it still amazes me that corporate behavior in this regard is still quite dismissive.  Lawsuits and public embarrassment seem to be the only catalyst for action for many organizations.  That is kind of sad.  Not only is [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2010/01/19/lawsuit-breaches-and-bashing-oh-my/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lessons in Due Diligence</title>
		<link>http://paulmudgett.com/2009/12/02/lessons-in-due-diligence/</link>
		<comments>http://paulmudgett.com/2009/12/02/lessons-in-due-diligence/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 19:24:41 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[due diligence]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[security mistakes]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=106</guid>
		<description><![CDATA[An article by Kim Zetter on Wired.com caught my attention:  &#8220;Restaurants Sue Vendor for Unsecured Card Processor&#8221;. The gist is that several restaurants purchased Point-of-Sale (POS) systems from a particular vendor.  These POS systems that were sold were apparently not Payment Card Industry &#8211; Data Security Standard (PCI-DSS) compliant and that resulted in a breach [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/12/02/lessons-in-due-diligence/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Learning From Someone Else&#8217;s Breach</title>
		<link>http://paulmudgett.com/2009/11/20/learning-from-someone-elses-breach/</link>
		<comments>http://paulmudgett.com/2009/11/20/learning-from-someone-elses-breach/#comments</comments>
		<pubDate>Fri, 20 Nov 2009 19:37:07 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[security mistakes]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=100</guid>
		<description><![CDATA[A subsidiary of manged health care provider Health Net Inc, just reported the loss of personal information for 1.5 million customers that occurred six months ago according to a ComputerWorld article.  Without knowing all the details of the situation, I can only speculate as to some of the security controls and thoughts of the Health [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/11/20/learning-from-someone-elses-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Cloud Does Not Absolve Responsibility</title>
		<link>http://paulmudgett.com/2009/11/17/the-cloud-does-not-absolve-responsibility/</link>
		<comments>http://paulmudgett.com/2009/11/17/the-cloud-does-not-absolve-responsibility/#comments</comments>
		<pubDate>Tue, 17 Nov 2009 18:15:34 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[security awareness]]></category>
		<category><![CDATA[security mistakes]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=97</guid>
		<description><![CDATA[Cloud computing certainly offers cost management opportunities for organizations straining to maintain server infrastructure but there is more to consider than just server management.  Security in the cloud simply has not had an opportunity to mature.  Protecting servers, which no doubt cloud providers can do pretty effectively, is different than protecting information.   Those organizations that [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/11/17/the-cloud-does-not-absolve-responsibility/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>It&#8217;s Just One Little E-mail&#8230;</title>
		<link>http://paulmudgett.com/2009/08/06/its-just-one-little-e-mail/</link>
		<comments>http://paulmudgett.com/2009/08/06/its-just-one-little-e-mail/#comments</comments>
		<pubDate>Thu, 06 Aug 2009 20:55:38 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[security mistakes]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/blog/?p=31</guid>
		<description><![CDATA[How often is e-mail used to send documents and information that contains sensitive information?  I&#8217;ve seen consultants share sensitive information about clients this way as well as staff members just &#8220;trying to be helpful&#8221;.  I&#8217;m sure this happens all the time and it can be mitigated through training and providing staff the tools necessary to [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/08/06/its-just-one-little-e-mail/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When Will They Ever Learn&#8230;</title>
		<link>http://paulmudgett.com/2009/06/03/when-will-they-ever-learn/</link>
		<comments>http://paulmudgett.com/2009/06/03/when-will-they-ever-learn/#comments</comments>
		<pubDate>Wed, 03 Jun 2009 18:51:35 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[disgruntled employee]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[security mistakes]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/blog/?p=5</guid>
		<description><![CDATA[When an employee leaves a company either voluntarily or involuntary, the business must have the processes and procedures in place to immediately revoke access to information resources.   This isn&#8217;t a new concept in the information security realm but it is something that is often applied lackadaisically in organizations.  With the cost of breaches rising, leaving [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/06/03/when-will-they-ever-learn/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

