<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Andy ITGuy - Information Security Blog</title>
	<atom:link href="http://andyitguy.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://andyitguy.com</link>
	<description>A voice of reason in a world of FUD</description>
	<lastBuildDate>Fri, 04 May 2012 05:04:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='andyitguy.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Andy ITGuy - Information Security Blog</title>
		<link>http://andyitguy.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://andyitguy.com/osd.xml" title="Andy ITGuy - Information Security Blog" />
	<atom:link rel='hub' href='http://andyitguy.com/?pushpress=hub'/>
		<item>
		<title>Dealing with a business that doesn&#8217;t want you.</title>
		<link>http://andyitguy.com/2012/03/01/dealing-with-a-business-that-doesnt-want-you/</link>
		<comments>http://andyitguy.com/2012/03/01/dealing-with-a-business-that-doesnt-want-you/#comments</comments>
		<pubDate>Thu, 01 Mar 2012 22:07:19 +0000</pubDate>
		<dc:creator>andyitguy</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">https://awillingham.wordpress.com/?p=1061</guid>
		<description><![CDATA[We all face it at some point in our career. You are tasked with securing &#8220;x&#8221; and the business doesn&#8217;t want you doing your job. Sure they may put on a smile when audit or compliance are in the room but when they are alone in their office or in their team meetings they are [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andyitguy.com&#038;blog=18191111&#038;post=1061&#038;subd=awillingham&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>We all face it at some point in our career. You are tasked with securing &#8220;x&#8221; and the business doesn&#8217;t want you doing your job. Sure they may put on a smile when audit or compliance are in the room but when they are alone in their office or in their team meetings they are stabbing a voodoo doll that resembles you or you walk in on a dart game where the board has been covered by your picture. They stall, delay, ignore and fight your every request. They build cases to support their argument that security is a burden to them getting their work done. Each scenario plays out a bit differently but in the end they are all the same. Security is not wanted.</p>
<p>I&#8217;ve worked in a few places where <strike>I</strike> security wasn&#8217;t wanted. We were there because someone said we had to be. It may have been regulators, auditors, compliance departments, a governing body for the industry, or the parent company or business itself required that we be there.  But the particular business you support (or the business as a whole) wants nothing to do with you. That is frustrating for someone who believes strongly in the value of security to an organization. It&#8217;s tough to get up day after day and make the trek into the office when you know that you are going to be ignored and have to fight for every inch of ground that you gain. After several days like this the little bit of ground that you gain doesn&#8217;t give you the warm fuzzies that you would hope to get after a hard day&#8217;s work.</p>
<p>So what do you do? How do you keep your sanity and remain civil to your friends and family? How do you deal with this? How do you get your job done while facing constant opposition? Better yet how do you work through the situation and hopefully change some mind s and get the business on board with you?</p>
<p>In many cases you are going to have to start with changing the way security is viewed by the business. Usually, and unfortunately, security is often known for saying &#8220;no&#8221;, slowing down productivity, delaying product launch, impacting usability, and &#8220;keeping me from updating my Facebook status with my lunch choice for today&#8221; . This doesn&#8217;t set well with our customers (the business) for lots of reasons.<br />
1. They are the customer and the customer is always right.<br />
2. Their job is to produce and security hinders production.<br />
3. They are tasked with fiscal responsibility and security is seen as being a cost center with little<br />
     to no return or value<br />
4. Their job is to keep employee moral up and security hinders that.</p>
<p>Let&#8217;s look at each of these and see what we can do to effect real change that will improve our image and relationship with the business. </p>
<p><strong>They are the customer and the customer is always right.</strong><br />
At least that is how they see it and we should let them believe it. Actually we need to act as if it is true. In reality it isn&#8217;t true anymore for its than it is for anyone else. Yet the principle behind it is very important in keeping the customer happy. Our mindset should be &#8220;if they want it then we will make it happen&#8221;. That doesn&#8217;t mean that they get what they want exactly. It means that we work with them to find a solution that will meet their needs and keep it secure. The days of saying no are behind us and we have to change the negative image that we have because of those days. If you are supporting  a business that has never had security work with them then the first time you do this you may have to make sure you have smelling salts with you. If you take&#8221;no&#8221; out of your vocabulary and work to make things happen you will be amazed at how quickly the business starts to change their attitude towards security.</p>
<p><strong>Their job is to produce and security hinders production.</strong><br />
One of the biggest complaints that I hear about security initiatives is that they often slow down the release cycle of products and programs. Sometimes there is not a whole lot that we can do about this especially early on. In today&#8217;s world we can&#8217;t ignore the need to implement security but we also can&#8217;t rush into it headfirst work little to no reward for how it impacts the work that the business is tasked to do. (Wow! That hurt to write that) One of the best things that we can do to minimize the negative impacts here is to make sure that we communicate with the business as to what is being done, why it&#8217;s happening, how it will benefit them (this one can be a tough sell), and what you are doing to make this as painless as possible. It&#8217;s also important not to have a &#8220;grin and bear it&#8221; attitude. If you can get good data that will show how the slowdown should only be temporary that will also be a big plus. Many times the problems caused by security programs will either go away or at least be reduced over time as people get used to the new processes and learn how to work with the security program.</p>
<p><strong>They are tasked with fiscal responsibility and security is seen as being a cost center with little to no return or value</strong><br />
Don&#8217;t worry, I&#8217;m not going down the security ROI path with this one. As with most everything coast goes down over time so your job is to show the business how you too are being fiscally responsible. Be open with them about how cost and expenses rise and fall. Don&#8217;t ask them to find something without having a clear plan that shows them the cost and benefit aspects. Have plan A, B, and C when you need something new. Shot for the stars but be willing to settle for less. Also don&#8217;t come to them with a proposal that is stupid expensive when times are tough. You should never go to them unprepared. Remember they are business people not technology people and they want a business case not cool, flashy lights.</p>
<p><strong>Their job is to keep employee moral up and security hinders that.</strong><br />
In this area there are several things that we can do to improve our image.<br />
° Follow all of your policies. If they see you on Facebook when everyone else is blocked you will be vilified and your credibility will be damaged.<br />
°Don&#8217;t block access to websites and technology without a good reason. There are few reasons and cases where complete exile from&#8221;non-business&#8221; sites is necessary so don&#8217;t do it just because you can.<br />
°Expect everyone, including executives, to follow policies.<br />
°Don&#8217;t deploy security that makes it too difficult for employees to do their job.<br />
°Expect (read &#8211; demand) your employees to answer questions, work to solve problems, not say no, and do it all with a smile and an attitude that lets the customer know that they are not being a &#8220;stupid user&#8221;, even if they are. We all have our &#8220;stupid user&#8221; areas. Imagine how you would feel if you were expected to do something that you knew nothing about.</p>
<p>That does it. If you are tasked with making the business like you hopefully this will help. If you have been through this before, or are going through it now, please feel free to leave comments with what did and didn&#8217;t work for you.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/awillingham.wordpress.com/1061/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/awillingham.wordpress.com/1061/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/awillingham.wordpress.com/1061/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/awillingham.wordpress.com/1061/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/awillingham.wordpress.com/1061/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/awillingham.wordpress.com/1061/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/awillingham.wordpress.com/1061/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/awillingham.wordpress.com/1061/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/awillingham.wordpress.com/1061/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/awillingham.wordpress.com/1061/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/awillingham.wordpress.com/1061/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/awillingham.wordpress.com/1061/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/awillingham.wordpress.com/1061/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/awillingham.wordpress.com/1061/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andyitguy.com&#038;blog=18191111&#038;post=1061&#038;subd=awillingham&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://andyitguy.com/2012/03/01/dealing-with-a-business-that-doesnt-want-you/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/df0f87a34a724532d87b3719b97f20f8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">andyitguy</media:title>
		</media:content>
	</item>
		<item>
		<title>Cudos to Apple</title>
		<link>http://andyitguy.com/2012/02/27/cudos-to-apple/</link>
		<comments>http://andyitguy.com/2012/02/27/cudos-to-apple/#comments</comments>
		<pubDate>Mon, 27 Feb 2012 22:24:27 +0000</pubDate>
		<dc:creator>andyitguy</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Apple]]></category>

		<guid isPermaLink="false">https://awillingham.wordpress.com/?p=1059</guid>
		<description><![CDATA[It was either late 2006 or late 2007 my brother in law bought his girlfriend a IPod nano. He paid $250 for it and after he got it he realized that for only $50 more here could have gotten a 30th iPod instead of the 4gb nano. He couldn&#8217;t return it because he had it [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andyitguy.com&#038;blog=18191111&#038;post=1059&#038;subd=awillingham&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>It was either late 2006 or late 2007 my brother in law bought his girlfriend a IPod nano. He paid $250 for it and after he got it he realized that for only $50 more here could have gotten a 30th iPod instead of the 4gb nano. He couldn&#8217;t return it because he had it engraved so he asked mange if I wood buy it from him for the discounted price of $200. This was before I had decided that Apple was the evil empire so I bought it. I used it up until 2010 when I bought a new mp3 player. I kept the nano and let my oldest daughter have it. Then late last year I received an email from Apple starting that the battery might blow up if I didn&#8217;t send it in for replacement, so I did.<br />
Today I received my replacement and much to my surprise it was a newer model of the nano and it was a 8gb model. It&#8217;s still a generation or two old but that&#8217;s better than the 6 year old one that I had. Thanks Apple, stories like this just may help to repair the career ruining, don&#8217;t give a care, terrible customer service reputation that you&#8217;ve built over the years.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/awillingham.wordpress.com/1059/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/awillingham.wordpress.com/1059/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/awillingham.wordpress.com/1059/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/awillingham.wordpress.com/1059/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/awillingham.wordpress.com/1059/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/awillingham.wordpress.com/1059/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/awillingham.wordpress.com/1059/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/awillingham.wordpress.com/1059/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/awillingham.wordpress.com/1059/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/awillingham.wordpress.com/1059/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/awillingham.wordpress.com/1059/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/awillingham.wordpress.com/1059/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/awillingham.wordpress.com/1059/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/awillingham.wordpress.com/1059/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andyitguy.com&#038;blog=18191111&#038;post=1059&#038;subd=awillingham&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://andyitguy.com/2012/02/27/cudos-to-apple/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/df0f87a34a724532d87b3719b97f20f8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">andyitguy</media:title>
		</media:content>
	</item>
		<item>
		<title>Making A Change</title>
		<link>http://andyitguy.com/2012/02/09/making-a-change/</link>
		<comments>http://andyitguy.com/2012/02/09/making-a-change/#comments</comments>
		<pubDate>Thu, 09 Feb 2012 19:21:31 +0000</pubDate>
		<dc:creator>andyitguy</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[tablet]]></category>

		<guid isPermaLink="false">https://awillingham.wordpress.com/?p=1053</guid>
		<description><![CDATA[I&#8217;m making a pretty big change in my technology usage. I&#8217;m moving from a laptop to a tablet for my personal computing use. I&#8217;ve been wanting a tablet for a while because of the smaller footprint and less weight to carry around. I like the flexibility of a tablet as well. They can do most [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andyitguy.com&#038;blog=18191111&#038;post=1053&#038;subd=awillingham&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m making a pretty big change in my technology usage. I&#8217;m moving from a laptop to a tablet for my personal computing use. I&#8217;ve been wanting a tablet for a while because of the smaller footprint and less weight to carry around. I like the flexibility of a tablet as well. They can do most things that a laptop can do and there are lots of apps to choose from that work better on a tablet than a phone. Our also gives me the conscience of an e-reader which I&#8217;ve wanted for a while and its better since I&#8217;m not limited to specific book formats.</p>
<p>Of course you have to be careful when you download apps. The potential for malicious behavior, poor coding and compromise are just around the corner. Hmm, sounds like the same problems PC&#8217;s have with software from major vendors. This will be interesting as I work through the change and make the required adjustments. I&#8217;ve been at it for just over a week and so far so good. Let&#8217;s just hope that it stays good. This thing cost to much to toss aside.</p>
<p>So far I&#8217;ve  only real issue had been with some web pages not rendering properly. It&#8217;s not too bad and only happens on some pages. If any one else has made the switch is love to hear your stories, good and bad.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/awillingham.wordpress.com/1053/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/awillingham.wordpress.com/1053/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/awillingham.wordpress.com/1053/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/awillingham.wordpress.com/1053/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/awillingham.wordpress.com/1053/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/awillingham.wordpress.com/1053/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/awillingham.wordpress.com/1053/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/awillingham.wordpress.com/1053/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/awillingham.wordpress.com/1053/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/awillingham.wordpress.com/1053/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/awillingham.wordpress.com/1053/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/awillingham.wordpress.com/1053/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/awillingham.wordpress.com/1053/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/awillingham.wordpress.com/1053/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andyitguy.com&#038;blog=18191111&#038;post=1053&#038;subd=awillingham&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://andyitguy.com/2012/02/09/making-a-change/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/df0f87a34a724532d87b3719b97f20f8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">andyitguy</media:title>
		</media:content>
	</item>
		<item>
		<title>No place for dishonesty</title>
		<link>http://andyitguy.com/2012/01/20/no-place-for-dishonesty/</link>
		<comments>http://andyitguy.com/2012/01/20/no-place-for-dishonesty/#comments</comments>
		<pubDate>Fri, 20 Jan 2012 04:03:57 +0000</pubDate>
		<dc:creator>andyitguy</dc:creator>
				<category><![CDATA[Character]]></category>
		<category><![CDATA[information security]]></category>

		<guid isPermaLink="false">https://awillingham.wordpress.com/?p=1049</guid>
		<description><![CDATA[Happy New Year! I hope each of you had a great holiday season and that 2012 has started off well for you. I know for me I&#8217;m really hoping that this year my life can slow down some but if the first 3 weeks of the year is any indication then I may be in [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andyitguy.com&#038;blog=18191111&#038;post=1049&#038;subd=awillingham&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Happy New Year! I hope each of you had a great holiday season and that 2012 has started off well for you. I know for me I&#8217;m really hoping that this year my life can slow down some but if the first 3 weeks of the year is any indication then I may be in trouble. <img src='http://s0.wp.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> &#160; For those of you who don&#8217;t know I&#8217;ve decided to take a short sabbatical from the Southern Fried Security Podcast. That was one area where I could step away and know that things would be in good hands and still keep some sanity. I don&#8217;t plan on it being a long break but don&#8217;t know when I&#8217;ll be back as of yet.</p>
<p>Now on to the actual reason that I&#8217;m writing this post&#8230;&#8230;</p>
<p>As many of you know some hackers released source code for an older version of a couple of Symantec products. Symantec said that it would have no real impact on their customers because the code was for products that were 5 or 6 years old. They also said that the code wasn&#8217;t taken from them but from a business partner. I guess their conscious got the best of them because now they have decided to come clean and admit that the data was actually taken from them in a breech of their network. When you read the various articles the picture is still a bit fuzzy. Were they breached recently or 6 years ago? If it was that long ago why are we just now finding this out or worse yet why didn&#8217;t they know it until recently. If you read some of the quotes from Symantec spokesperson Chris Paden it almost seems to say that the breach happened in 2006 but they just discovered it. Lots and lots of unanswered questions and questionable comments and actions.</p>
<p>So what&#8217;s the point? Honesty, Integrity, Character, Trust. All things that people and companies need to embrace. Let&#8217;s face it we are living in hard times right now. Many companies are struggling and doing all they can to keep their heads above water and consumers (individual and business) are looking long and hard at where they are spending their money. They are also looking at the total value for their dollar and they want to know that the company they are doing business with isn&#8217;t trying to pull the wool over their eyes. I know that if a company changes their story and is vague on something like this then it says to me that they will do it in other areas and it erodes my trust in them.&#160; The same holds true for an individual. If you are not honest in some areas how can I trust you in others?</p>
<p>On Wednesday I noticed that Josh Corman (@joshcorman) posted the following tweet couple of tweets.</p>
<blockquote><p><a href="https://twitter.com/joshcorman"><u><font color="#0066cc">joshcorman</font></u></a> Joshua Corman </p>
<p>If $SecurityVendor uses deception / social eng to separate you from your $$$, how are they not just another adversary?</p>
<p><a href="https://twitter.com/joshcorman">joshcorman</a> Joshua Corman&#160; </p>
<p>.<a href="https://twitter.com/gollmann"><s>@</s><strong>gollmann</strong></a> there are a lot of things $SecurityVendors shouldn&#8217;t do. Some abuse the implicit &quot;trusted adviser&quot; expectation more than others</p>
<p><a href="https://twitter.com/#!/joshcorman/status/159722534651174912">18 Jan</a></p>
<p>&#160;</p>
</blockquote>
<p>I’m sure most of us have stories of vendors gone wild. Ones who sold you what you didn’t need or what wasn’t right for your environment. Sold you too much or baited you with a little only to hit you with the big stuff later. Maybe they gave you a good deal on what you needed but too you to the cleaners on professional services to make it work. Sometimes it’s the company culture that encourages it and sometimes it just a unscrupulous sales person or a SE who it working off commission and wants a nice Christmas at your expense. The problem still goes back to character, integrity and trust. If they aren’t there then someone will get hurt.</p>
<p>To be fair it also happens on the side of the customer. Often times they will try to take the vendor for all they can get even if it’s lots more than they paid for. Maybe they broke something but they want to get it fixed for free so they will try to make it look like it was defective. I remember one time early in my career we were having problems with a data circuit and in my troubleshooting I determined that the problem was with the smart jack&#160; that our T1 terminated at. I called the local telco and put in a trouble ticket and they scheduled a time for a tech to be out to look at it. My boss called and told me to take a paperclip and short out the smart jack. The telco would charge us for a service call if it turned out that the problem wasn’t with their equipment and he didn’t want to risk having to pay. I refused to do it and it turned out that I was right anyway the jack was bad. To me it just wasn’t worth tossing my integrity out the door to possible save the company a couple of hundred dollars. Not to mention the fact that if I did that then what else would my boss expect me to do. It’s a slippery slope and we can’t afford to go down it. </p>
<p>Don’t get me wrong I’m not condemning Symantec b/c I don’t know all of the facts. They just happened to be the one that got me on my soap box.&#160; I hope that Symantec is able to clear this up and that we discover that the twisted stories are all the handiwork of a few individuals who can be replaced with people of integrity. I’d hate to know that it was a corporate culture of lying that was behind this. There are already enough companies out there who will do all they can to keep and make more money no matter who it hurts. We have enough “evil” companies out there already and we don’t need more. We need to be people of integrity and we need to demand it of the companies that we do business with.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/awillingham.wordpress.com/1049/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/awillingham.wordpress.com/1049/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/awillingham.wordpress.com/1049/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/awillingham.wordpress.com/1049/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/awillingham.wordpress.com/1049/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/awillingham.wordpress.com/1049/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/awillingham.wordpress.com/1049/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/awillingham.wordpress.com/1049/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/awillingham.wordpress.com/1049/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/awillingham.wordpress.com/1049/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/awillingham.wordpress.com/1049/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/awillingham.wordpress.com/1049/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/awillingham.wordpress.com/1049/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/awillingham.wordpress.com/1049/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andyitguy.com&#038;blog=18191111&#038;post=1049&#038;subd=awillingham&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://andyitguy.com/2012/01/20/no-place-for-dishonesty/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/df0f87a34a724532d87b3719b97f20f8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">andyitguy</media:title>
		</media:content>
	</item>
		<item>
		<title>Book Review: America the Vulnerable</title>
		<link>http://andyitguy.com/2011/10/17/book-review-america-the-vulnerable/</link>
		<comments>http://andyitguy.com/2011/10/17/book-review-america-the-vulnerable/#comments</comments>
		<pubDate>Mon, 17 Oct 2011 16:51:55 +0000</pubDate>
		<dc:creator>andyitguy</dc:creator>
				<category><![CDATA[information security]]></category>
		<category><![CDATA[Book Reviews]]></category>

		<guid isPermaLink="false">http://www.andyitguy.com/blog/?p=998</guid>
		<description><![CDATA[I love to read unfortunately I don’t have time to read too much but I do listen to books as much as possible in my car and when working around the house. I try to have at least one book in print that I’m reading all the time and often I’ve got 3 or 4 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andyitguy.com&#038;blog=18191111&#038;post=1005&#038;subd=awillingham&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I love to read unfortunately I don’t have time to read too much but I do listen to books as much as possible in my car and when working around the house. I try to have at least one book in print that I’m reading all the time and often I’ve got 3 or 4 going at a time and I read a little here and there on each depending on my mood. Not too long ago I was asked to read a book and do a review of it on the blog. That book is “America the Vulnerable” by Joel Brenner. I get asked to review lots of books, mostly technical ones and I usually refuse but this one I decided to accept because I love reading books like this. They are usually exciting to read, full of good information and help to raise awareness of the state of technology security. This book does all that and some. </p>
<p>Mr. Brenner is a former top-level NSA insider and he seems to have the inside scoop on a lot of pretty scary stuff. He does a good job of telling a interesting tale and doing so on a level that anyone can understand. He explains concepts that those of you who read my blog already understand but there is a chance that your parents and their friends don’t understand. He also doesn’t just tell a story or try to scare you. He offers some insight into some things that need to be done and can be done to make some changes that hopefully will make a difference. </p>
<p>I like the way that he calls out both public and private networks being behind the curve when it comes to security. He highlights things that you and I do everyday that can impact your security, my security and everyone else on the internet. He gives examples of things that could happen and tells us about things that have happened. One of the things that I really enjoyed was a story about a “hit” that took place in Dubai. Those who were involved still haven’t been caught but the whole thing took place on camera. That is how we know what happened. Due to digital surveillance that occurs daily in Dubai those who participated were caught on video and the authorities were able to track them back to their original flights into Dubai. Unfortunately that’s as far as they were able to get. The point here though is that 20 years ago they would have never even known that much. Technology has it’s blessings in helping out with such things but it also has it’s curse because it has brought about the loss of privacy and anonymity in many ways. </p>
<p>This is a book that I like and would not hesitate to recommend to my friends and family. It has lots of useful info that will educate and inform those who need to know.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/awillingham.wordpress.com/1005/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/awillingham.wordpress.com/1005/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/awillingham.wordpress.com/1005/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/awillingham.wordpress.com/1005/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/awillingham.wordpress.com/1005/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/awillingham.wordpress.com/1005/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/awillingham.wordpress.com/1005/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/awillingham.wordpress.com/1005/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/awillingham.wordpress.com/1005/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/awillingham.wordpress.com/1005/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/awillingham.wordpress.com/1005/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/awillingham.wordpress.com/1005/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/awillingham.wordpress.com/1005/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/awillingham.wordpress.com/1005/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andyitguy.com&#038;blog=18191111&#038;post=1005&#038;subd=awillingham&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://andyitguy.com/2011/10/17/book-review-america-the-vulnerable/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/df0f87a34a724532d87b3719b97f20f8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">andyitguy</media:title>
		</media:content>
	</item>
		<item>
		<title>SC Magazine Debate</title>
		<link>http://andyitguy.com/2011/09/14/sc-magazine-debate/</link>
		<comments>http://andyitguy.com/2011/09/14/sc-magazine-debate/#comments</comments>
		<pubDate>Wed, 14 Sep 2011 14:38:34 +0000</pubDate>
		<dc:creator>andyitguy</dc:creator>
				<category><![CDATA[information security]]></category>
		<category><![CDATA[SC Magazine]]></category>

		<guid isPermaLink="false">http://www.andyitguy.com/blog/?p=995</guid>
		<description><![CDATA[A few weeks ago I was approached by someone at SC Magazine and asked to present a short argument in favor of Security Awareness Training. This is a &#8220;Point/Counterpoint feature where someone else was to be against Security Awareness Training. Imagine my surprise when a coworker stopped by my desk to show her surprise at [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andyitguy.com&#038;blog=18191111&#038;post=1004&#038;subd=awillingham&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div>A few weeks ago I was approached by someone at SC Magazine and asked to present a short argument in favor of Security Awareness Training. This is a &#8220;Point/Counterpoint feature where someone else was to be against Security Awareness Training. Imagine my surprise when a coworker stopped by my desk to show her surprise at seeing my name and picture in the magazine. She showed me the page and lo and behold my &#8220;foe&#8221; in this argument is Amrit Williams. How fitting considering the history that he and I have in disagreeing on topics in the past. Anyway if you are interested you can find our thought either in the print version on pg 13 or by clicking on the link below.</div>
<div><a href="http://www.scmagazineus.com/debate-security-awareness-training-is-a-worthwhile-investment/article/209791/">http://www.scmagazineus.com/debate-security-awareness-training-is-a-worthwhile-investment/article/209791/</a></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/awillingham.wordpress.com/1004/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/awillingham.wordpress.com/1004/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/awillingham.wordpress.com/1004/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/awillingham.wordpress.com/1004/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/awillingham.wordpress.com/1004/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/awillingham.wordpress.com/1004/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/awillingham.wordpress.com/1004/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/awillingham.wordpress.com/1004/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/awillingham.wordpress.com/1004/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/awillingham.wordpress.com/1004/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/awillingham.wordpress.com/1004/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/awillingham.wordpress.com/1004/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/awillingham.wordpress.com/1004/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/awillingham.wordpress.com/1004/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andyitguy.com&#038;blog=18191111&#038;post=1004&#038;subd=awillingham&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://andyitguy.com/2011/09/14/sc-magazine-debate/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/df0f87a34a724532d87b3719b97f20f8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">andyitguy</media:title>
		</media:content>
	</item>
		<item>
		<title>Breaking out of compliance management (part 1)</title>
		<link>http://andyitguy.com/2011/09/13/breaking-out-of-compliance-management-part-1/</link>
		<comments>http://andyitguy.com/2011/09/13/breaking-out-of-compliance-management-part-1/#comments</comments>
		<pubDate>Tue, 13 Sep 2011 16:53:28 +0000</pubDate>
		<dc:creator>andyitguy</dc:creator>
				<category><![CDATA[compliance]]></category>
		<category><![CDATA[risk management]]></category>

		<guid isPermaLink="false">http://www.andyitguy.com/blog/?p=994</guid>
		<description><![CDATA[After my last post on “Risk Management or Compliance Management” Martin Fisher and I talked about it on the SFS Podcast. It gave me an opportunity to “rant” more and as usual Martin has some good insight into things. Ranting is fine for a bit but if that is all there is then why bother [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andyitguy.com&#038;blog=18191111&#038;post=1003&#038;subd=awillingham&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>After my last post on “<a href="http://www.andyitguy.com/blog/?p=992" target="_blank">Risk Management or Compliance Management</a>” Martin Fisher and I talked about it on the SFS Podcast. It gave me an opportunity to “rant” more and as usual Martin has some good insight into things. Ranting is fine for a bit but if that is all there is then why bother to blog. There needs to be some actionable items to move things forward so here are some thoughts on getting back to Risk Management and away from “pure” compliance management.</p>
<p>I’m going to approach this from a generic angle because it will be different for each company due to many factors. This will probably work better for the SMB market due to the complexity of large enterprises but with some creative thinking you should be able to use this as a template for them as well. So if you are a security pro in and are tired of doing compliance management instead of risk management what do you do? </p>
<p>First you want to make a plan and prepare a strategy. Lay out the goals for for what you want to accomplish. Who do you need to influence?&#160; Your boss, a business leader, company leadership? </p>
<p> A good place to start is with a good understanding of what you currently have. Do you know your environment? Do you have an asset list of all systems (Hardware, OS, applications, services, accounts, etc)? What patches do you have installed and what software updates do you currently have? What infrastructure components are in place? What are the various connections to the outside world? Do you have Extranets? Things such as this are key to the next step.</p>
<p>Do a Gap analysis to determine what you need to do to get from where you are to where you need to be. After that do a risk analysis on the gap. It doesn’t have to be fancy or even follow a particular methodology just as long as you are doing a through job and not just looking at things through the blood colored glasses of a security pro. Talk to others who are in the business and can give you insight. Ask questions of others in different roles to help you understand better and be able to view the “problem” from the security angle, the business angle, the user angle, the customer angle. These things will help you when you present your recommendations because you can anticipate questions and concerns ahead of time and have answers and alternatives prepared. Plus it really adds to your credibility because they see that you are serious about this and not just spouting off.</p>
<p>Next you will want to look at ways to close the gap. Don’t just think technology. What process changes can be made? You will be able to answer this because you took the time to talk to others and learn from them. Are there policies in place that address this and if so do they address it fully or are there areas that need to be shored up? What about current technology that is already in place can it be used to solve some problems? Then look at “new” technology that could be implemented. Also don’t forget awareness programs and other training that can reduce the likelihood that someone in the company will make a mistake due to lack of knowledge.</p>
<p>Now go back and look at what you can realistically do given resources available to you. Think about time, talent, money, etc… and build a case for doing what you can, but don’t stop there. Build the case for going beyond. Why is what you can do not enough? What risks will still be there that need to be addressed? Why do they need to be addressed and explain it in a way that the business managers and others that are not security focused will understand. I love this “nugget” from Mike Rothman’s “Pragmatic CSO”, put together different presentations for Plan A, B, and C. With A being getting everything on your list, C being the minimum you can get by with and B is somewhere in between. </p>
<p>Once you feel that you have built your case(s) then run them by others in the company who can help you refine them so that what you present to management is first class. After that practice your presentation many, many times and make sure that you have asked the right questions (those that management will ask) and have your answers prepared. </p>
<p>Now it’s up to Management how they respond but at the very least if you have done this well you will build credibility so that next time they listen to you more closely and value your input.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/awillingham.wordpress.com/1003/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/awillingham.wordpress.com/1003/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/awillingham.wordpress.com/1003/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/awillingham.wordpress.com/1003/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/awillingham.wordpress.com/1003/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/awillingham.wordpress.com/1003/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/awillingham.wordpress.com/1003/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/awillingham.wordpress.com/1003/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/awillingham.wordpress.com/1003/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/awillingham.wordpress.com/1003/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/awillingham.wordpress.com/1003/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/awillingham.wordpress.com/1003/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/awillingham.wordpress.com/1003/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/awillingham.wordpress.com/1003/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andyitguy.com&#038;blog=18191111&#038;post=1003&#038;subd=awillingham&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://andyitguy.com/2011/09/13/breaking-out-of-compliance-management-part-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/df0f87a34a724532d87b3719b97f20f8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">andyitguy</media:title>
		</media:content>
	</item>
		<item>
		<title>Risk Management or Compliance Management</title>
		<link>http://andyitguy.com/2011/09/09/risk-management-or-compliance-management/</link>
		<comments>http://andyitguy.com/2011/09/09/risk-management-or-compliance-management/#comments</comments>
		<pubDate>Sat, 10 Sep 2011 03:07:21 +0000</pubDate>
		<dc:creator>andyitguy</dc:creator>
				<category><![CDATA[information security]]></category>

		<guid isPermaLink="false">http://www.andyitguy.com/blog/?p=992</guid>
		<description><![CDATA[Timing is everything. Sometimes it works in your favor and sometimes it sneaks up and bits you in the butt. I wrote this last night (Thursday) and didn’t get around to posting it and then today I see several people pointing to this video on the very topic I wrote about. Oh Well, here it [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andyitguy.com&#038;blog=18191111&#038;post=1002&#038;subd=awillingham&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Timing is everything. Sometimes it works in your favor and sometimes it sneaks up and bits you in the butt. I wrote this last night (Thursday) and didn’t get around to posting it and then today <a href="http://www.youtube.com/watch?v=CBdg0682Qzg&amp;feature=player_embedded">I see several people pointing to this video on the very topic I wrote about</a>. Oh Well, here it is a day late and a dollar short.</p>
<p>I’ve been thinking a lot lately about “Risk management”. After all that is the core of a security professional is supposed to do. We help the business manage the risk that they face. Sounds great in theory but how well does it really work. What I’m seeing is a not real risk management so much as compliance management. We are tasked with ensuring that the business doesn’t fall below the compliance threshold and that is considered risk management. We talk to the business about issues and give them our input on what needs to be done and we are told “that’s not required by regulation X or policy Z” so the business will approve the minimum that gets them “compliant” and they then go on about their merry way.</p>
<p>Some will say that if this happens then you are just ineffective in selling your program or solution and maybe that is the case from time to time but I think it’s a much deeper problem than that. The business is focused on doing business and they push back on those things that they see as being a hindrance. They are more concerned about ensuring that Customer Connie and Client Clint don’t have to do anything themselves to protect their interactions with the business. They don’t want to negatively impact the customer experience and I get that. Very few people like it when they are constantly being asked to verify their actions online and they will go elsewhere if given the opportunity. The problem is that the business has taken the hard line and wants security to be completely seamless and invisible to the customer. Now the business has become the department of NO. No, we don’t want to deploy something that requires the customer to take action. No, we don’t want to deploy a solution that will slow the transaction by 1/2 a second. No, we don’t want to change the way we code we want you to install something that fixes (or hides)our mistakes for us.</p>
<p>The business has fully bought into the compliance mentality and doesn’t want to go beyond it. They tell us that they want us to manage risk but what they really mean is that they want us to ensure that they are not at risk of being out of compliance. Unless of course the compliance requires too much of them they they want either a compensating control or to accept the risk and hope that it never comes back to bite them. Then once it does they blame security because we didn’t push hard enough or didn’t inform them of the potential for it to be this bad. Of course the 20 different emails and slide decks where we laid all of this out doesn’t matter at this point. It’s still our fault for not doing our job.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/awillingham.wordpress.com/1002/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/awillingham.wordpress.com/1002/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/awillingham.wordpress.com/1002/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/awillingham.wordpress.com/1002/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/awillingham.wordpress.com/1002/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/awillingham.wordpress.com/1002/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/awillingham.wordpress.com/1002/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/awillingham.wordpress.com/1002/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/awillingham.wordpress.com/1002/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/awillingham.wordpress.com/1002/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/awillingham.wordpress.com/1002/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/awillingham.wordpress.com/1002/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/awillingham.wordpress.com/1002/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/awillingham.wordpress.com/1002/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andyitguy.com&#038;blog=18191111&#038;post=1002&#038;subd=awillingham&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://andyitguy.com/2011/09/09/risk-management-or-compliance-management/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/df0f87a34a724532d87b3719b97f20f8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">andyitguy</media:title>
		</media:content>
	</item>
		<item>
		<title>OK Mr. Jobs…. You win</title>
		<link>http://andyitguy.com/2011/08/22/ok-mr-jobs-you-win/</link>
		<comments>http://andyitguy.com/2011/08/22/ok-mr-jobs-you-win/#comments</comments>
		<pubDate>Tue, 23 Aug 2011 03:27:01 +0000</pubDate>
		<dc:creator>andyitguy</dc:creator>
				<category><![CDATA[information security]]></category>

		<guid isPermaLink="false">http://www.andyitguy.com/blog/?p=990</guid>
		<description><![CDATA[Everyone said it would happen. One day I would open my eyes and see the light. I’d have a sudden urge to rush to the local Apple Store and run up to a sales clerk (or do they call them “sales genius”?) and utter those magical, mystical words “I want a Mac!” Well, I’m thinking [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andyitguy.com&#038;blog=18191111&#038;post=1001&#038;subd=awillingham&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Everyone said it would happen. One day I would open my eyes and see the light. I’d have a sudden urge to rush to the local Apple Store and run up to a sales clerk (or do they call them “sales genius”?) and utter those magical, mystical words “I want a Mac!” </p>
<p>Well, I’m thinking that the time may be upon me even as I type. I’m giving serious consideration to going out and buying not one, not two, not three……. but FOUR Macs. One for each separate household in my family. That way when they have computer problems they will no longer be able to call me for help because I can’t work on them, won’t work on them and refuse to work on them! My sister got one a few months ago and I haven’t talked to her since. Not because I refuse to but because she knows that I can’t and won’t help her with Mac problems. One of my Brother-in-laws got one a year or so ago and now when he calls we actually talk about things other than his computer problems. If it’s worked out so well in those two cases it’s bound to make my extended family relationships much better if they all have one. </p>
<p>Thanks You Mr. Jobs! I can’t believe it took me this long to see the light.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/awillingham.wordpress.com/1001/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/awillingham.wordpress.com/1001/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/awillingham.wordpress.com/1001/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/awillingham.wordpress.com/1001/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/awillingham.wordpress.com/1001/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/awillingham.wordpress.com/1001/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/awillingham.wordpress.com/1001/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/awillingham.wordpress.com/1001/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/awillingham.wordpress.com/1001/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/awillingham.wordpress.com/1001/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/awillingham.wordpress.com/1001/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/awillingham.wordpress.com/1001/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/awillingham.wordpress.com/1001/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/awillingham.wordpress.com/1001/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andyitguy.com&#038;blog=18191111&#038;post=1001&#038;subd=awillingham&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://andyitguy.com/2011/08/22/ok-mr-jobs-you-win/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/df0f87a34a724532d87b3719b97f20f8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">andyitguy</media:title>
		</media:content>
	</item>
		<item>
		<title>Focus.com Security Awareness Roundtable</title>
		<link>http://andyitguy.com/2011/08/03/focus-com-security-awareness-roundtable/</link>
		<comments>http://andyitguy.com/2011/08/03/focus-com-security-awareness-roundtable/#comments</comments>
		<pubDate>Wed, 03 Aug 2011 20:31:24 +0000</pubDate>
		<dc:creator>andyitguy</dc:creator>
				<category><![CDATA[Focus.com]]></category>
		<category><![CDATA[Awareness]]></category>
		<category><![CDATA[Human Paradox]]></category>

		<guid isPermaLink="false">http://www.andyitguy.com/blog/?p=989</guid>
		<description><![CDATA[Next week I am teaming up with 2 good friends (Michael Santarcangel0 @securitycatalyst; Chris Carpinello @chriscarpinello) and one new friend (Steve Ellis *steellis) to talk about security awareness and the Human Paradox. Join us on Wednesday Aug 10, 2011 at 2:00 PM EDT and if you can’t join then you can download the mp3 and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andyitguy.com&#038;blog=18191111&#038;post=1000&#038;subd=awillingham&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Next week I am teaming up with 2 good friends (Michael Santarcangel0 @securitycatalyst; Chris Carpinello @chriscarpinello) and one new friend (Steve Ellis *steellis) to talk about security awareness and the Human Paradox. Join us on Wednesday Aug 10, 2011 at 2:00 PM EDT and if you can’t join then you can download the mp3 and listen to it later (or several times)</p>
<p>The event is sponsored and hosted by <a href="http://www.focus.com/roundtables/security-awareness-roundtable-understanding-real-challenge/" target="_blank">Focus.com</a>. We would love to have you join us and join in the conversation.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/awillingham.wordpress.com/1000/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/awillingham.wordpress.com/1000/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/awillingham.wordpress.com/1000/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/awillingham.wordpress.com/1000/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/awillingham.wordpress.com/1000/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/awillingham.wordpress.com/1000/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/awillingham.wordpress.com/1000/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/awillingham.wordpress.com/1000/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/awillingham.wordpress.com/1000/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/awillingham.wordpress.com/1000/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/awillingham.wordpress.com/1000/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/awillingham.wordpress.com/1000/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/awillingham.wordpress.com/1000/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/awillingham.wordpress.com/1000/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andyitguy.com&#038;blog=18191111&#038;post=1000&#038;subd=awillingham&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://andyitguy.com/2011/08/03/focus-com-security-awareness-roundtable/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/df0f87a34a724532d87b3719b97f20f8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">andyitguy</media:title>
		</media:content>
	</item>
	</channel>
</rss>
