<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>paulmudgett.com&#187; vulnerability management</title>
	<atom:link href="http://paulmudgett.com/tag/vulnerability-management/feed/" rel="self" type="application/rss+xml" />
	<link>http://paulmudgett.com</link>
	<description>Information Security &#38; Business Leadership</description>
	<lastBuildDate>Fri, 11 May 2012 16:48:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>The real 1 percenters&#8230;.</title>
		<link>http://paulmudgett.com/2012/03/12/the-real-1-percenters/</link>
		<comments>http://paulmudgett.com/2012/03/12/the-real-1-percenters/#comments</comments>
		<pubDate>Mon, 12 Mar 2012 18:15:16 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[security context]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=405</guid>
		<description><![CDATA[There are a lot of vendors pushing their wares using zero-day exploits as a chief selling piece in their propaganda.  The problem is, the vast majority of servers are compromised by known vulnerabilities and a failure in the patching process.   It stands to reason that there is more bang-for-the-buck by addressing issues such as vulnerability [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/03/12/the-real-1-percenters/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Don&#8217;t Let FUD Trump Value</title>
		<link>http://paulmudgett.com/2010/01/22/dont-let-fud-trump-value/</link>
		<comments>http://paulmudgett.com/2010/01/22/dont-let-fud-trump-value/#comments</comments>
		<pubDate>Fri, 22 Jan 2010 19:36:08 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Awareness and Education]]></category>
		<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[security awareness]]></category>
		<category><![CDATA[strategic asset]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=132</guid>
		<description><![CDATA[The Google &#8220;Aurora&#8221; incident illustrates an ongoing problem with the &#8220;media motivated&#8221; approach many organization take in regards to information security.  A major event happens and there is a short-lived window of opportunity to ride the &#8220;it can happen to us&#8221; wave to secure some funding for the latest toy or gadget.  Unfortunately, some executives [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2010/01/22/dont-let-fud-trump-value/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Risk-based Information Security</title>
		<link>http://paulmudgett.com/2009/12/28/risk-based-information-security/</link>
		<comments>http://paulmudgett.com/2009/12/28/risk-based-information-security/#comments</comments>
		<pubDate>Mon, 28 Dec 2009 18:50:15 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[ISO 27001/27002]]></category>
		<category><![CDATA[security enabler]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=114</guid>
		<description><![CDATA[How do you even start protecting your information assets if you don&#8217;t have an understanding of the risk to them?  I would venture to say&#8230; you don&#8217;t.  It&#8217;s difficult for some to get started down this path because they quickly get overwhelmed with the task at hand.  Many times, a good effort gets set aside [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/12/28/risk-based-information-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lessons in Due Diligence</title>
		<link>http://paulmudgett.com/2009/12/02/lessons-in-due-diligence/</link>
		<comments>http://paulmudgett.com/2009/12/02/lessons-in-due-diligence/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 19:24:41 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[due diligence]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[security mistakes]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=106</guid>
		<description><![CDATA[An article by Kim Zetter on Wired.com caught my attention:  &#8220;Restaurants Sue Vendor for Unsecured Card Processor&#8221;. The gist is that several restaurants purchased Point-of-Sale (POS) systems from a particular vendor.  These POS systems that were sold were apparently not Payment Card Industry &#8211; Data Security Standard (PCI-DSS) compliant and that resulted in a breach [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/12/02/lessons-in-due-diligence/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Patch Management Only 1/2 the Battle</title>
		<link>http://paulmudgett.com/2009/10/14/patch-management-still-a-problem/</link>
		<comments>http://paulmudgett.com/2009/10/14/patch-management-still-a-problem/#comments</comments>
		<pubDate>Wed, 14 Oct 2009 18:12:30 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/blog/?p=53</guid>
		<description><![CDATA[An audit of cybersecurity for DHS’ nine most frequently visited Web sites found that although general security protocols were followed, there were still a number of vulnerabilities and gaps in security, including inconsistent management of security patching and security assessments.  Lipowicz, Alice.  &#8220;DHS Web sites vulnerable to hackers, IG says&#8221;, Federal Computer Week, 09Oct2009. It [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/10/14/patch-management-still-a-problem/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

