<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.2" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Security Views Case Study #4 – Blissfully Aiding and Abetting Hackers</title>
	<link>http://securityviews.com/blog/2007/07/25/case-study-owned-database-servers/</link>
	<description>Actionable security ideas for managers.</description>
	<pubDate>Fri, 05 Dec 2008 16:31:10 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.2</generator>

	<item>
		<title>by: Scott</title>
		<link>http://securityviews.com/blog/2007/07/25/case-study-owned-database-servers/#comment-2367</link>
		<pubDate>Sat, 25 Aug 2007 21:16:57 +0000</pubDate>
		<guid>http://securityviews.com/blog/2007/07/25/case-study-owned-database-servers/#comment-2367</guid>
					<description>@mroonie

Thanks for the link.  Bruce's essay is right on, from my point of view.  In fact, barring the invention of the mythical &quot;Magic Crypto Fairy Dust&quot;, I think more organizations will have to do just what Bruce says.  Form a number of distinct networks for different types of information. They would have strictly limited, or no access, for interaction between them.</description>
		<content:encoded><![CDATA[<p>@mroonie</p>
<p>Thanks for the link.  Bruce&#8217;s essay is right on, from my point of view.  In fact, barring the invention of the mythical &#8220;Magic Crypto Fairy Dust&#8221;, I think more organizations will have to do just what Bruce says.  Form a number of distinct networks for different types of information. They would have strictly limited, or no access, for interaction between them.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: mroonie</title>
		<link>http://securityviews.com/blog/2007/07/25/case-study-owned-database-servers/#comment-1982</link>
		<pubDate>Thu, 16 Aug 2007 17:24:53 +0000</pubDate>
		<guid>http://securityviews.com/blog/2007/07/25/case-study-owned-database-servers/#comment-1982</guid>
					<description>I think a lot of it also has to do with the fact that this breach occurred at a university.  According to Jonathan Penn from Forrester Research, universities tend to use many different services for information management.  Security solutions are also different for every department.  It's especially difficult to try to come up with one solution that works for all departments within a university.

Bruce Schnier has an &lt;a href=&quot;http://www.schneier.com/essay-149.html&quot; rel=&quot;nofollow&quot;&gt;essay&lt;/a&gt; about it on his blog that touches on that touches on the challenges that universities have to face when it comes to information security.  Definitely a worthwhile read.</description>
		<content:encoded><![CDATA[<p>I think a lot of it also has to do with the fact that this breach occurred at a university.  According to Jonathan Penn from Forrester Research, universities tend to use many different services for information management.  Security solutions are also different for every department.  It&#8217;s especially difficult to try to come up with one solution that works for all departments within a university.</p>
<p>Bruce Schnier has an <a href="http://www.schneier.com/essay-149.html" rel="nofollow">essay</a> about it on his blog that touches on that touches on the challenges that universities have to face when it comes to information security.  Definitely a worthwhile read.
</p>
]]></content:encoded>
				</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.294 seconds -->
