<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>noFUD - No Fear Uncertainty or Doubt</title>
	
	<link>http://nofud.org</link>
	<description>Information security analysis by Akshay Aggarwal</description>
	<lastBuildDate>Fri, 10 Apr 2009 19:44:11 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain="nofud.org" port="80" path="/?rsscloud=notify" registerProcedure="" protocol="http-post" />
<image>
		<url>http://www.gravatar.com/blavatar/8f5584191510ae54e6663a5337b91af4?s=96&amp;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>noFUD - No Fear Uncertainty or Doubt</title>
		<link>http://nofud.org</link>
	</image>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/noFUD" type="application/rss+xml" /><feedburner:emailServiceId>noFUD</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
		<title>Shrinking Budgets: Application Security Tools vs Process Tradeoff</title>
		<link>http://feedproxy.google.com/~r/noFUD/~3/PlCMaqPfcm0/</link>
		<comments>http://nofud.org/2009/04/10/shrinking-budgets-application-security-tools-vs-process-tradeoff/#comments</comments>
		<pubDate>Fri, 10 Apr 2009 19:44:11 +0000</pubDate>
		<dc:creator>akshay aggarwal</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Leadership]]></category>
		<category><![CDATA[SDL]]></category>
		<category><![CDATA[SDLC]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://nofud.wordpress.com/2009/04/10/shrinking-budgets-application-security-tools-vs-process-tradeoff/</guid>
		<description><![CDATA[An all too familiar scene repeated itself two weeks ago. My good friend &#38; CISO of a mid-sized technology company, lets call him Alok, went into a budget planning meeting and came out as a shadow of his former self. To be more precise a 85% version of the Alok that I know. He had just been handed a 15% reduction in budget.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nofud.org&blog=3571192&post=92&subd=nofud&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>An all too familiar scene repeated itself two weeks ago. My good friend &amp; CISO of a mid-sized technology company, lets call him Alok, went into a budget planning meeting and came out as a shadow of his former self. To be more precise a 85% version of the Alok that I know. He had just been handed a 15% reduction in budget.</p>
<p>Like most managers, Alok, started taking stock of his mini-empire and prioritizing things that he could do without. Luckily he had already expected a cut and so had planned ahead. Unluckily, he had planned for a 6% reduction not a 15% reduction. After some brainstorming and taking some tough decisions he had cut costs by 10%. Now began his quest for the elusive final 5%. His organization had started the transition from being a network security centric organization to a more application security centric organization around 15 months ago. So, a solution posed by one of his managers was to drop the security engineering process integration program and replace it with a set of static analysis tools they had just evaluated. This strategy had paid of handsomely for them in the network security field. Ron, one of the leading application architects in the organization was opposed to the idea. Thus started a turf war, which left some angry, most frustrated and everyone confused.</p>
<p>Unlike most managers, Alok reached out for advice. He asked me to share my experience with customers in similar budgetary situations &amp; maturity. This is how our conversation went:</p>
<p><em>Alok</em>: So I think the automated security tools can help us reduce risk and save us money. Unfortunately, I have to reduce budget and I’m thinking of buying &lt;snip&gt; tool to drive efficiency. What do you think?</p>
<p><em>Akshay</em>: I’m sorry that you have had a budget cut. A lot of my clients have been facing a similar situation. Before I answer your question can you tell me what value you expect to derive from the tool?</p>
<p><em>Alok</em>: We are looking to get standardized security bugs and find all the vulnerabilities that exist in our code base. </p>
<p>Akshay: Do you know how the tool compares to a manual security code review. I mean, what kind of coverage does it give you? And is that coverage good enough for your organization?</p>
<p>Alok: No, we haven’t examined that. Assume that it is. Should we go ahead? You know I can get more done with less by buying the tool and getting rid of my contingent vendor staff.</p>
<p>Akshay: Well, the tool that you mentioned will need to be used by both your development team and your security team. Have you considered the cost of training people to use it? </p>
<p>Alok: No. What other impacts and costs may there be?</p>
<p>Akshay: I imagine the development staff&#160; is also being reduced. I imagine that they will resist taking on additional work while having to let go off people. In my experience when clients by static analysis or other tools , a large portion of them end up as shelfware. Not enough thought is given to how to integrate this in existing into development lifecycles. Application security is <a href="http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/">fundamentally a process problem</a> and you can’t solve it just by using tools.</p>
<p>In my opinion, this is a great time for forward looking organizations to re-engineer their development process to integrate security into the process. People are the biggest resistors of change. Culture change is the toughest challenge when moving to a SDL like process. The prevailing lean development team, a more malleable workforce and forward looking leadership can and should be leveraged in these tough economic times to make the organization healthier for the future. </p>
<p>- Akshay </p>
Posted in Application Security, Information Technology, Leadership, SDL, SDLC, Security, Strategy, Tools  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/nofud.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/nofud.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/nofud.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/nofud.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/nofud.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/nofud.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/nofud.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/nofud.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/nofud.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/nofud.wordpress.com/92/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nofud.org&blog=3571192&post=92&subd=nofud&ref=&feed=1" /></div>
<p><a href="http://feedads.g.doubleclick.net/~a/2DH5JJImlpHCzavw4lnwzKgTlnQ/0/da"><img src="http://feedads.g.doubleclick.net/~a/2DH5JJImlpHCzavw4lnwzKgTlnQ/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/2DH5JJImlpHCzavw4lnwzKgTlnQ/1/da"><img src="http://feedads.g.doubleclick.net/~a/2DH5JJImlpHCzavw4lnwzKgTlnQ/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/noFUD?a=PlCMaqPfcm0:VlCndFLaOuI:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/noFUD?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=PlCMaqPfcm0:VlCndFLaOuI:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/noFUD?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=PlCMaqPfcm0:VlCndFLaOuI:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/noFUD?i=PlCMaqPfcm0:VlCndFLaOuI:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=PlCMaqPfcm0:VlCndFLaOuI:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/noFUD?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=PlCMaqPfcm0:VlCndFLaOuI:l6gmwiTKsz0"><img src="http://feeds.feedburner.com/~ff/noFUD?d=l6gmwiTKsz0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=PlCMaqPfcm0:VlCndFLaOuI:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/noFUD?i=PlCMaqPfcm0:VlCndFLaOuI:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=PlCMaqPfcm0:VlCndFLaOuI:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/noFUD?d=TzevzKxY174" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/noFUD/~4/PlCMaqPfcm0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://nofud.org/2009/04/10/shrinking-budgets-application-security-tools-vs-process-tradeoff/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7f872956a89dba537d87a7a1494d19be?s=96&amp;d=monsterid" medium="image">
			<media:title type="html">akshay</media:title>
		</media:content>
	<feedburner:origLink>http://nofud.org/2009/04/10/shrinking-budgets-application-security-tools-vs-process-tradeoff/</feedburner:origLink></item>
		<item>
		<title>Akshay’s Uncertainty Principle: Observing Some Metrics Changes Them</title>
		<link>http://feedproxy.google.com/~r/noFUD/~3/obaAEsWPD6o/</link>
		<comments>http://nofud.org/2009/03/24/akshays-uncertainty-principle-observing-some-metrics-changes-them/#comments</comments>
		<pubDate>Tue, 24 Mar 2009 16:32:00 +0000</pubDate>
		<dc:creator>akshay aggarwal</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Leadership]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[metrics]]></category>

		<guid isPermaLink="false">http://nofud.wordpress.com/2009/03/24/akshays-uncertainty-principle-observing-some-metrics-changes-them/</guid>
		<description><![CDATA[You’ve probably heard of the famous&#160; Heisenberg Uncertainty Principle&#160; in Quantum physics. It states 
“The more precisely the position is determined, the less precisely the momentum is known in this instant, and vice versa.”      &#8211;Heisenberg, uncertainty paper, 1927

This principle is related to the observer effect. In physics, the term observer [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nofud.org&blog=3571192&post=87&subd=nofud&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>You’ve probably heard of the famous&#160; Heisenberg Uncertainty Principle&#160; in Quantum physics. It states </p>
<blockquote><p>“The more precisely the position is determined, the less precisely the momentum is known in this instant, and vice versa.”      <br />&#8211;Heisenberg, uncertainty paper, 1927</p>
</blockquote>
<p>This principle is related to the observer <a href="http://nofud.files.wordpress.com/2009/03/image.png"><img style="display:inline;margin-left:0;margin-right:0;border-width:0;" title="Heisenberg in 1927" border="0" alt="Heisenberg in 1927" align="right" src="http://nofud.files.wordpress.com/2009/03/image-thumb.png?w=167&#038;h=244" width="167" height="244" /></a>effect. In physics, the term <b><a href="http://en.wikipedia.org/wiki/Observer_effect_(physics)" target="_blank">observer effect</a></b> refers to changes that the act of observation will make on the phenomenon being observed.</p>
<p>Ok, now to get to the point. As a business manager responsible for P&amp;L, I am asked to produce several performance metrics or revenue metrics. Some of these metrics are simple and straightforward&#160; Key Performance Indicators (KPIs). KPIs can include net revenue, profit, # of new customers or in our case customer satisfaction numbers.</p>
<p>The problem with metrics crops up when we need to measure a property and no mechanism exists to measure it quickly or the metric is not representative of the property being measured. In general this happens when the following scenarios arise:</p>
<ol>
<li><font face="Georgia">Metric is not available: No mechanism is in place to measure the property at that time. </font></li>
<li><font face="Georgia">Property is not measurable: No metrics are available to capture the property.</font> </li>
<li><font face="Georgia">Deliver unplanned metrics quickly: Metrics that the system was not designed to capture need to be measured quickly. </font></li>
<li><font face="Georgia">CSF masquerading as KPI: Critical Success Factors are vital elements for a strategy to be successful and should not be confused with KPIs which quantify strategic performance.&#160; The metric being asked for is a CSF not a KPI. </font></li>
</ol>
</p>
</p>
</p>
</p>
<p>In simple words, the amount of effort required to <em>measure</em> the metric changes the amount of effort we can dedicate to <em>create</em> the metric. The act of measuring the metric changes it.&#160; For example, in the economic downturn several teams have had to reduce headcount. If this barebones team is now asked to capture&#160; information on how a recently released tool is being used by customers without that mechanism already in place, then they cannot deliver that metric without additional effort that will impact the overall KPIs.The problem that arises is what I’ve dubbed the <strong>Akshay’s Uncertainty Principle</strong>:</p>
<blockquote><p>In a resource constrained environment, a new or modified metric cannot be measured without impacting the metric itself.</p>
</blockquote>
<p>- Akshay</p>
<p>If you like this post, <a title="Sbscribe to my feed" href="http://feeds2.feedburner.com/noFUD">subscribe to the RSS feed</a>&#160;<a title="noFUD RSS Feed" href="http://feeds2.feedburner.com/noFUD"><img style="border-bottom:0;border-left:0;display:inline;margin-left:0;border-top:0;margin-right:0;border-right:0;" title="feed-icon-28x28" border="0" alt="feed-icon-28x28" src="http://nofud.files.wordpress.com/2009/03/feedicon28x28.png?w=28&#038;h=28" width="28" height="28" /></a></p>
Posted in Business, Leadership, Strategy Tagged: metrics <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/nofud.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/nofud.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/nofud.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/nofud.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/nofud.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/nofud.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/nofud.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/nofud.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/nofud.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/nofud.wordpress.com/87/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nofud.org&blog=3571192&post=87&subd=nofud&ref=&feed=1" /></div>
<p><a href="http://feedads.g.doubleclick.net/~a/OMt20cjeR-DtOA_v0cXf60KZIT4/0/da"><img src="http://feedads.g.doubleclick.net/~a/OMt20cjeR-DtOA_v0cXf60KZIT4/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/OMt20cjeR-DtOA_v0cXf60KZIT4/1/da"><img src="http://feedads.g.doubleclick.net/~a/OMt20cjeR-DtOA_v0cXf60KZIT4/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/noFUD?a=obaAEsWPD6o:dL9RrcPD0Vs:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/noFUD?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=obaAEsWPD6o:dL9RrcPD0Vs:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/noFUD?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=obaAEsWPD6o:dL9RrcPD0Vs:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/noFUD?i=obaAEsWPD6o:dL9RrcPD0Vs:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=obaAEsWPD6o:dL9RrcPD0Vs:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/noFUD?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=obaAEsWPD6o:dL9RrcPD0Vs:l6gmwiTKsz0"><img src="http://feeds.feedburner.com/~ff/noFUD?d=l6gmwiTKsz0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=obaAEsWPD6o:dL9RrcPD0Vs:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/noFUD?i=obaAEsWPD6o:dL9RrcPD0Vs:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=obaAEsWPD6o:dL9RrcPD0Vs:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/noFUD?d=TzevzKxY174" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/noFUD/~4/obaAEsWPD6o" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://nofud.org/2009/03/24/akshays-uncertainty-principle-observing-some-metrics-changes-them/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7f872956a89dba537d87a7a1494d19be?s=96&amp;d=monsterid" medium="image">
			<media:title type="html">akshay</media:title>
		</media:content>

		<media:content url="http://nofud.files.wordpress.com/2009/03/image-thumb.png" medium="image">
			<media:title type="html">Heisenberg in 1927</media:title>
		</media:content>

		<media:content url="http://nofud.files.wordpress.com/2009/03/feedicon28x28.png" medium="image">
			<media:title type="html">feed-icon-28x28</media:title>
		</media:content>
	<feedburner:origLink>http://nofud.org/2009/03/24/akshays-uncertainty-principle-observing-some-metrics-changes-them/</feedburner:origLink></item>
		<item>
		<title>RIP: Jack Louis passes on</title>
		<link>http://feedproxy.google.com/~r/noFUD/~3/V78DWSOINkI/</link>
		<comments>http://nofud.org/2009/03/19/rip-jack-louis-passes-on/#comments</comments>
		<pubDate>Thu, 19 Mar 2009 16:38:00 +0000</pubDate>
		<dc:creator>akshay aggarwal</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://nofud.wordpress.com/2009/03/19/rip-jack-louis-passes-on/</guid>
		<description><![CDATA[Jack Louis of Outpost24 passed away on Sunday as a result of a house fire in Sweden. He was known for the security scan tool Unicornscan. Some of you may remember him from Sockstress, a vulnerability that can trigger denial of service on any system listens for remote connections using TCP. Jack and my paths [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nofud.org&blog=3571192&post=83&subd=nofud&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Jack Louis of Outpost24 passed away on Sunday as a result of a house fire in Sweden. He was known for the security scan tool <a href="http://www.unicornscan.org/" target="_blank">Unicornscan</a>. Some of you may remember him from <a href="http://en.wikipedia.org/wiki/Sock_stress" target="_blank">Sockstress</a>, a vulnerability that can trigger denial of service on any system listens for remote connections using TCP. Jack and my paths had crossed a few times in both competitively and intellectually fulfilling ways.</p>
<p>- Akshay</p>
Posted in Security  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/nofud.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/nofud.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/nofud.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/nofud.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/nofud.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/nofud.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/nofud.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/nofud.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/nofud.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/nofud.wordpress.com/83/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nofud.org&blog=3571192&post=83&subd=nofud&ref=&feed=1" /></div>
<p><a href="http://feedads.g.doubleclick.net/~a/-lC_DYF16iCaQwtsARUW0wKFiD4/0/da"><img src="http://feedads.g.doubleclick.net/~a/-lC_DYF16iCaQwtsARUW0wKFiD4/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/-lC_DYF16iCaQwtsARUW0wKFiD4/1/da"><img src="http://feedads.g.doubleclick.net/~a/-lC_DYF16iCaQwtsARUW0wKFiD4/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/noFUD?a=V78DWSOINkI:M5nOwJD1bkM:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/noFUD?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=V78DWSOINkI:M5nOwJD1bkM:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/noFUD?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=V78DWSOINkI:M5nOwJD1bkM:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/noFUD?i=V78DWSOINkI:M5nOwJD1bkM:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=V78DWSOINkI:M5nOwJD1bkM:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/noFUD?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=V78DWSOINkI:M5nOwJD1bkM:l6gmwiTKsz0"><img src="http://feeds.feedburner.com/~ff/noFUD?d=l6gmwiTKsz0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=V78DWSOINkI:M5nOwJD1bkM:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/noFUD?i=V78DWSOINkI:M5nOwJD1bkM:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=V78DWSOINkI:M5nOwJD1bkM:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/noFUD?d=TzevzKxY174" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/noFUD/~4/V78DWSOINkI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://nofud.org/2009/03/19/rip-jack-louis-passes-on/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7f872956a89dba537d87a7a1494d19be?s=96&amp;d=monsterid" medium="image">
			<media:title type="html">akshay</media:title>
		</media:content>
	<feedburner:origLink>http://nofud.org/2009/03/19/rip-jack-louis-passes-on/</feedburner:origLink></item>
		<item>
		<title>Response to InfoSec X Prize Part 1</title>
		<link>http://feedproxy.google.com/~r/noFUD/~3/ULF_iPuWUWs/</link>
		<comments>http://nofud.org/2009/03/04/response-to-infosec-x-prize-part-1/#comments</comments>
		<pubDate>Wed, 04 Mar 2009 18:02:00 +0000</pubDate>
		<dc:creator>akshay aggarwal</dc:creator>
				<category><![CDATA[Innovation]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[X Prize]]></category>

		<guid isPermaLink="false">http://nofud.wordpress.com/2009/03/04/response-to-infosec-x-prize-part-1/</guid>
		<description><![CDATA[So I’ve been quite amazed by the amount of discussion and feedback i have received from colleagues and peers on my original post on creating fundamental change through competition. I will be posting some of the written replies that I received and which people have kindly consented to having me post.
Here is a response sent [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nofud.org&blog=3571192&post=74&subd=nofud&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>So I’ve been quite amazed by the amount of discussion and feedback i have received from colleagues and peers on my <a href="http://nofud.org/2009/01/22/the-infosec-x-prize-fundamental-change-through-competition/" target="_blank">original post</a> on creating fundamental change through competition. I will be posting some of the written replies that I received and which people have kindly consented to having me post.</p>
<p>Here is a response sent to me by my friend Olav Opedal with Microsoft’s Information Security group:</p>
<blockquote><p><a name="_MailEndCompose"><span style="color:#000000;">I believe the change has already happened, but you haven’t seen much of it translated into off the shelf products. The change that I see, is based on the use of applied mathematical solutions found in other science branches, such as using power-law distributions describing social networks to define who should have access to what along with physics heat models applied to network traffic. With this, I mean using real time multi-dimensional analysis of network traffic, user actions, content and context of transmissions etc to determine a probability of appropriateness of the actions. In other words using mathematical models to find the change point as soon as possible, and discard anomalies that has little effect on the CIA triangle. One thing that is clear, is that information must be given an economic value to enable a decision point to be set for action versus inaction. </span></a></p></blockquote>
<p>So does all information need to be given economic value? If so, can all information be given economic value? This is an interesting train of thought to follow.</p>
<p>- Akshay</p>
<p>If you like this post, <a href="http://feeds2.feedburner.com/noFUD" title="Subscribe to my feed" rel="alternate"><img src="http://www.feedburner.com/fb/images/pub/feed-icon32x32.png" alt=""></a><a href="http://feeds2.feedburner.com/noFUD" title="Sbscribe to my feed" rel="alternate">Subscribe in a reader</a></p>
Posted in Innovation, Security, X Prize  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/nofud.wordpress.com/74/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/nofud.wordpress.com/74/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/nofud.wordpress.com/74/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/nofud.wordpress.com/74/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/nofud.wordpress.com/74/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/nofud.wordpress.com/74/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/nofud.wordpress.com/74/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/nofud.wordpress.com/74/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/nofud.wordpress.com/74/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/nofud.wordpress.com/74/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nofud.org&blog=3571192&post=74&subd=nofud&ref=&feed=1" /></div>
<p><a href="http://feedads.g.doubleclick.net/~a/YKRN7k5UEcgw_gpLHFBkBOlKvbE/0/da"><img src="http://feedads.g.doubleclick.net/~a/YKRN7k5UEcgw_gpLHFBkBOlKvbE/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/YKRN7k5UEcgw_gpLHFBkBOlKvbE/1/da"><img src="http://feedads.g.doubleclick.net/~a/YKRN7k5UEcgw_gpLHFBkBOlKvbE/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/noFUD?a=ULF_iPuWUWs:-2Klzvw3ueA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/noFUD?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=ULF_iPuWUWs:-2Klzvw3ueA:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/noFUD?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=ULF_iPuWUWs:-2Klzvw3ueA:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/noFUD?i=ULF_iPuWUWs:-2Klzvw3ueA:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=ULF_iPuWUWs:-2Klzvw3ueA:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/noFUD?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=ULF_iPuWUWs:-2Klzvw3ueA:l6gmwiTKsz0"><img src="http://feeds.feedburner.com/~ff/noFUD?d=l6gmwiTKsz0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=ULF_iPuWUWs:-2Klzvw3ueA:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/noFUD?i=ULF_iPuWUWs:-2Klzvw3ueA:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=ULF_iPuWUWs:-2Klzvw3ueA:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/noFUD?d=TzevzKxY174" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/noFUD/~4/ULF_iPuWUWs" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://nofud.org/2009/03/04/response-to-infosec-x-prize-part-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7f872956a89dba537d87a7a1494d19be?s=96&amp;d=monsterid" medium="image">
			<media:title type="html">akshay</media:title>
		</media:content>

		<media:content url="http://www.feedburner.com/fb/images/pub/feed-icon32x32.png" medium="image" />
	<feedburner:origLink>http://nofud.org/2009/03/04/response-to-infosec-x-prize-part-1/</feedburner:origLink></item>
		<item>
		<title>Baking Security In: A Comic Strip View of SDL</title>
		<link>http://feedproxy.google.com/~r/noFUD/~3/9NtkooDaKHc/</link>
		<comments>http://nofud.org/2009/02/19/baking-security-in-a-comic-strip-view-of-sdl/#comments</comments>
		<pubDate>Thu, 19 Feb 2009 23:07:00 +0000</pubDate>
		<dc:creator>akshay aggarwal</dc:creator>
				<category><![CDATA[Comics]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[SDL]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://nofud.wordpress.com/2009/02/19/baking-security-in-a-comic-strip-view-of-sdl/</guid>
		<description><![CDATA[So how do you take your average developer who scoffs at security from the careless and brash aka Kevin,  to the poster child  for good development practices aka  Kevlarr. Well, the Microsoft SDL team has the answer for you. The team recently started publishing a series of web comics detailing the travails of the dev [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nofud.org&blog=3571192&post=68&subd=nofud&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>So how do you take your average developer who scoffs at security from <a href="http://nofud.files.wordpress.com/2009/02/kevin.png"><img style="border-bottom:0;border-left:0;display:inline;margin-left:0;border-top:0;margin-right:0;border-right:0;" title="Kevin" src="http://nofud.files.wordpress.com/2009/02/kevin-thumb.png?w=125&#038;h=240" border="0" alt="Kevin" width="125" height="240" align="left" /></a><a href="http://nofud.files.wordpress.com/2009/02/2.png"><img style="border-bottom:0;border-left:0;display:inline;margin-left:0;border-top:0;margin-right:0;border-right:0;" title="Kevlarr" src="http://nofud.files.wordpress.com/2009/02/2-thumb.png?w=125&#038;h=240" border="0" alt="Kevlarr" width="125" height="240" align="right" /></a>the careless and brash aka Kevin,  to the poster child  for good development practices aka  Kevlarr. Well, the <a href="http://microsoft.com/sdl" target="_blank">Microsoft SDL</a> team has the answer for you. The team recently started publishing a series of <a href="http://www.microsoft.com/security/bakingsecurityin/strips.htm" target="_blank">web comics</a> detailing the travails of the dev team at Contoso who are under attack from the League of Malware. Along the way they battle with foes such as Spam Bot and Social Engineer while getting help from Vigil and Nforcer. Strip 11 of this interesting attempt to socialize security is below:<a href="http://nofud.files.wordpress.com/2009/02/image.png"><img style="border-bottom:0;border-left:0;display:inline;border-top:0;border-right:0;" title="image" src="http://nofud.files.wordpress.com/2009/02/image-thumb.png?w=409&#038;h=603" border="0" alt="image" width="409" height="603" /></a><a href="http://nofud.files.wordpress.com/2009/02/21.png"></a></p>
<p>Socializing security is essential for organizations to drive culture change from one based on FUD to one based on an understanding of security needs. People are the most complex part of  the security puzzle. Most people take the easy way out and will avoid the things  they fear or don’t understand. Every CIO should ask the what his/her organizations plans around socializing security are. So what are they?</p>
<p>- Akshay</p>
<p>If you like this post, <a title="Subscribe to my feed" rel="alternate" href="http://feeds2.feedburner.com/noFUD"><img src="http://www.feedburner.com/fb/images/pub/feed-icon32x32.png" alt="" /></a><a title="Sbscribe to my feed" rel="alternate" href="http://feeds2.feedburner.com/noFUD">Subscribe in a reader</a></p>
Posted in Comics, Microsoft, SDL, Security  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/nofud.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/nofud.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/nofud.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/nofud.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/nofud.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/nofud.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/nofud.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/nofud.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/nofud.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/nofud.wordpress.com/68/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nofud.org&blog=3571192&post=68&subd=nofud&ref=&feed=1" /></div>
<p><a href="http://feedads.g.doubleclick.net/~a/HN-Kcze0crW020CEUJ4bPphGns0/0/da"><img src="http://feedads.g.doubleclick.net/~a/HN-Kcze0crW020CEUJ4bPphGns0/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/HN-Kcze0crW020CEUJ4bPphGns0/1/da"><img src="http://feedads.g.doubleclick.net/~a/HN-Kcze0crW020CEUJ4bPphGns0/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/noFUD?a=9NtkooDaKHc:LFvWKw574SQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/noFUD?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=9NtkooDaKHc:LFvWKw574SQ:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/noFUD?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=9NtkooDaKHc:LFvWKw574SQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/noFUD?i=9NtkooDaKHc:LFvWKw574SQ:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=9NtkooDaKHc:LFvWKw574SQ:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/noFUD?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=9NtkooDaKHc:LFvWKw574SQ:l6gmwiTKsz0"><img src="http://feeds.feedburner.com/~ff/noFUD?d=l6gmwiTKsz0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=9NtkooDaKHc:LFvWKw574SQ:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/noFUD?i=9NtkooDaKHc:LFvWKw574SQ:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=9NtkooDaKHc:LFvWKw574SQ:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/noFUD?d=TzevzKxY174" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/noFUD/~4/9NtkooDaKHc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://nofud.org/2009/02/19/baking-security-in-a-comic-strip-view-of-sdl/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7f872956a89dba537d87a7a1494d19be?s=96&amp;d=monsterid" medium="image">
			<media:title type="html">akshay</media:title>
		</media:content>

		<media:content url="http://nofud.files.wordpress.com/2009/02/kevin-thumb.png" medium="image">
			<media:title type="html">Kevin</media:title>
		</media:content>

		<media:content url="http://nofud.files.wordpress.com/2009/02/2-thumb.png" medium="image">
			<media:title type="html">Kevlarr</media:title>
		</media:content>

		<media:content url="http://nofud.files.wordpress.com/2009/02/image-thumb.png" medium="image">
			<media:title type="html">image</media:title>
		</media:content>

		<media:content url="http://www.feedburner.com/fb/images/pub/feed-icon32x32.png" medium="image" />
	<feedburner:origLink>http://nofud.org/2009/02/19/baking-security-in-a-comic-strip-view-of-sdl/</feedburner:origLink></item>
		<item>
		<title>Microsoft IT Solutions: Full Drive Encryption using BitLocker</title>
		<link>http://feedproxy.google.com/~r/noFUD/~3/_bU3GxOywe0/</link>
		<comments>http://nofud.org/2009/02/07/microsoft-it-solutions-full-drive-encryption-using-bitlocker/#comments</comments>
		<pubDate>Sat, 07 Feb 2009 17:30:00 +0000</pubDate>
		<dc:creator>akshay aggarwal</dc:creator>
				<category><![CDATA[Consulting]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Innovation]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://nofud.wordpress.com/2009/02/07/microsoft-it-solutions-full-drive-encryption-using-bitlocker/</guid>
		<description><![CDATA[One of the challenges that I have been focusing my team on this fiscal year has been creating new solutions that leverage the learning that Microsoft IT has had in deploying technology or solving problems. Microsoft IT generally has to deploy new technologies from Microsoft several months before they are generally available for general release [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nofud.org&blog=3571192&post=58&subd=nofud&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>One of the challenges that I have been focusing my team on this fiscal year has been creating new solutions that leverage the learning that Microsoft IT has had in deploying technology or solving problems. Microsoft IT generally has to deploy new technologies from Microsoft several months before they are generally available for general release in a process known as <em>dogfooding</em>. Often it needs to develop and deploy solutions multiple times as the product cycles through from betas to release candidates to the released version. Customers will find solutions that will leverage this deep expertise and experience useful in speeding up the architecture &amp; deployments of their solutions.</p>
<p>In this series Microsoft IT Solutions, I will be detailing some of this innovation coming out of Microsoft’s InfoSec group. The first of the series is Full Drive Encryption using BitLocker®. I asked <strong>Richard Lewis, Security Architect</strong> on my team &amp; the creator of this solution kit to describe the BitLocker FDE solution. Here is his description:</p>
<blockquote><p>The InfoSec team recently created and delivered the BitLocker Service Kit for the Core I/O Service Line under the Security, Identity and Access Management (SIAM) portfolio. SIAM is a portfolio offering from Microsoft Services.&#160; SIAM is divided into six offerings that address particular security IT capabilities – the BitLocker Service Kit was created under the <i>Enterprise Data Security Optimization</i> IT capability. </p>
<p>The BitLocker Service Kit provides Microsoft Services sales and delivery roles with the resources they need to sell and deliver comprehensive Full Volume Encryption solutions based on Windows Bitlocker Drive Encryption. Ultimately this Service Kit helps Microsoft Services accelerate their customer’s BitLocker deployment timeline and therefore Windows Vista deployment, decrease the risk of data loss, and increase customer satisfaction. Overall this kit contains over twenty different documents such as checklists, guides, worksheets, operation guides, architecture and design documents to help our sales and delivery consultants to deploy BitLocker in an optimized manner. </p>
<p>The resource who led creation of this service kit was also involved in the MSIT BitLocker deployment and is currently helping a large financial services organization deploy BitLocker to over 100,000+ desktops. Learning and feedback from the MSIT internal BitLocker deployment were instrumental in creation of this Service Kit and will continue to be used as InfoSec goes in the field and helps Microsoft customers with their BitLocker deployments. This kit demonstrates that IP from MSIT projects add value to our products &amp; ultimately our customers.&#160; </p>
</blockquote>
<p>Drop me a note if you would like some additional details on this solution kit or the innovation process within Microsoft.</p>
<p>- Akshay    </p>
Posted in Consulting, Information Technology, Innovation, Microsoft, Security  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/nofud.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/nofud.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/nofud.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/nofud.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/nofud.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/nofud.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/nofud.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/nofud.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/nofud.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/nofud.wordpress.com/58/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nofud.org&blog=3571192&post=58&subd=nofud&ref=&feed=1" /></div>
<p><a href="http://feedads.g.doubleclick.net/~a/DqMDEq6sB-hr7D41RLd9QizhOU4/0/da"><img src="http://feedads.g.doubleclick.net/~a/DqMDEq6sB-hr7D41RLd9QizhOU4/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/DqMDEq6sB-hr7D41RLd9QizhOU4/1/da"><img src="http://feedads.g.doubleclick.net/~a/DqMDEq6sB-hr7D41RLd9QizhOU4/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/noFUD?a=_bU3GxOywe0:udg1BHNiN6w:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/noFUD?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=_bU3GxOywe0:udg1BHNiN6w:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/noFUD?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=_bU3GxOywe0:udg1BHNiN6w:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/noFUD?i=_bU3GxOywe0:udg1BHNiN6w:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=_bU3GxOywe0:udg1BHNiN6w:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/noFUD?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=_bU3GxOywe0:udg1BHNiN6w:l6gmwiTKsz0"><img src="http://feeds.feedburner.com/~ff/noFUD?d=l6gmwiTKsz0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=_bU3GxOywe0:udg1BHNiN6w:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/noFUD?i=_bU3GxOywe0:udg1BHNiN6w:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=_bU3GxOywe0:udg1BHNiN6w:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/noFUD?d=TzevzKxY174" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/noFUD/~4/_bU3GxOywe0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://nofud.org/2009/02/07/microsoft-it-solutions-full-drive-encryption-using-bitlocker/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7f872956a89dba537d87a7a1494d19be?s=96&amp;d=monsterid" medium="image">
			<media:title type="html">akshay</media:title>
		</media:content>
	<feedburner:origLink>http://nofud.org/2009/02/07/microsoft-it-solutions-full-drive-encryption-using-bitlocker/</feedburner:origLink></item>
		<item>
		<title>Note to Fannie Mae: Dealing with Logic Bombs</title>
		<link>http://feedproxy.google.com/~r/noFUD/~3/oQjn0oQkvf0/</link>
		<comments>http://nofud.org/2009/01/31/note-to-fannie-mae-dealing-with-logic-bombs/#comments</comments>
		<pubDate>Sat, 31 Jan 2009 17:30:00 +0000</pubDate>
		<dc:creator>akshay aggarwal</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Finance]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Strategy]]></category>

		<guid isPermaLink="false">http://nofud.wordpress.com/2009/01/31/note-to-fannie-mae-dealing-with-logic-bombs/</guid>
		<description><![CDATA[Today, it was revealed that a departing contractor left Fannie Mae with a parting gift – a Logic Bomb designed to take 4000 of the financial giants servers &#38; their data. Since this news broke, a number of concerned CIOs have requested my team for some guidance on how to deal with logic bombs. So [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nofud.org&blog=3571192&post=53&subd=nofud&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Today, it was revealed that a departing contractor left Fannie Mae with a <a href="http://blog.wired.com/27bstroke6/2009/01/fannie.html" target="_blank">parting gift</a> – a <em>Logic Bomb</em> designed to take 4000 of the financial giants servers &amp; their data. Since this news broke, a number of concerned CIOs have requested my team for some guidance on how to deal with logic bombs. So here is a quick lesson on these malicious attacks.</p>
<blockquote><p>A <strong>Logic Bomb</strong> is a malicious piece of code inserted into a software system that executes when certain conditions are met most commonly a set date. A Logic Bomb that goes off on a particular date is called <strong>Time Bomb</strong>.</p></blockquote>
<p>In this case the attack was successful because the contractor’s authorization to access systems was not revoked after he was let go. In technical identity management systems like <a href="http://www.microsoft.com/windowsserver2008/en/us/ida-identity-lifecycle-management.aspx" target="_blank">ILM</a> this is known as deprovisioning.</p>
<p>Logic Bombs are usually indistinguishable from normal code and are inserted into the system by a programmer who has authority to the system. They are a type of insidious attacks called <em>insider attacks.</em> These are the most difficult class of attacks to detect and mitigate. The CSI/FBI 2005 Computer Crime and Security Survey indicated that 56% of organizations reported some level of security breach from within their organization.  So a note to all you CIOs/CSOs, if you think that only your internet facing assets face a high risk of attack… think again.</p>
<p>What can you do to avoid a fate like Fannie Mae. Sadly your options are limited and dependent on a strict adherence to process. This is what you can do (in order of immediate to long term):</p>
<ul>
<li><span style="font-family:Georgia;">Deprovision user accounts for individuals who have been let go while they are on premises or even before you inform them</span></li>
<li><span style="font-family:Georgia;">For programmers, create a copy of their files and code before they leave. These can be compared with copies of files and code after a few days to look for changes.</span></li>
<li><span style="font-family:Georgia;">After a person with access to critical digital assets including systems and code leaves the org, invest in having a peer double check for logic bombs that may have been left behind</span></li>
<li><span style="font-family:Georgia;">Change access credentials to critical systems periodically and consider two factor authentication.</span></li>
<li><span style="font-family:Georgia;">Use an identity management system to manage provisioning &amp; deprovisioning user accounts</span></li>
<li><span style="font-family:Georgia;">Invest in a multi-tiered logging and auditing systems with separation of duties between the monitored and monitoring parties. This ensures a trail of evidence for prosecution in the case that you are indicted.</span></li>
</ul>
<p>Plan ahead to deny the ability to the disgruntled to plant log bombs; failing that defuse the logic bombs,;failing that hit the deck and hope that the script has a bug.</p>
<p>- Akshay</p>
<p>If you like this post, <a title="Subscribe to my feed" rel="alternate" href="http://feeds2.feedburner.com/noFUD"><img src="http://www.feedburner.com/fb/images/pub/feed-icon32x32.png" alt="" /></a><a title="Sbscribe to my feed" rel="alternate" href="http://feeds2.feedburner.com/noFUD">Subscribe in a reader</a></p>
Posted in Application Security, Finance, Microsoft, Risk, Security, Strategy  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/nofud.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/nofud.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/nofud.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/nofud.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/nofud.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/nofud.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/nofud.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/nofud.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/nofud.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/nofud.wordpress.com/53/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nofud.org&blog=3571192&post=53&subd=nofud&ref=&feed=1" /></div>
<p><a href="http://feedads.g.doubleclick.net/~a/D9n6sojuYTdXQ7bMO9SGRqL7Zz0/0/da"><img src="http://feedads.g.doubleclick.net/~a/D9n6sojuYTdXQ7bMO9SGRqL7Zz0/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/D9n6sojuYTdXQ7bMO9SGRqL7Zz0/1/da"><img src="http://feedads.g.doubleclick.net/~a/D9n6sojuYTdXQ7bMO9SGRqL7Zz0/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/noFUD?a=oQjn0oQkvf0:_56aOH2X_X4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/noFUD?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=oQjn0oQkvf0:_56aOH2X_X4:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/noFUD?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=oQjn0oQkvf0:_56aOH2X_X4:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/noFUD?i=oQjn0oQkvf0:_56aOH2X_X4:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=oQjn0oQkvf0:_56aOH2X_X4:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/noFUD?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=oQjn0oQkvf0:_56aOH2X_X4:l6gmwiTKsz0"><img src="http://feeds.feedburner.com/~ff/noFUD?d=l6gmwiTKsz0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=oQjn0oQkvf0:_56aOH2X_X4:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/noFUD?i=oQjn0oQkvf0:_56aOH2X_X4:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=oQjn0oQkvf0:_56aOH2X_X4:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/noFUD?d=TzevzKxY174" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/noFUD/~4/oQjn0oQkvf0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://nofud.org/2009/01/31/note-to-fannie-mae-dealing-with-logic-bombs/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7f872956a89dba537d87a7a1494d19be?s=96&amp;d=monsterid" medium="image">
			<media:title type="html">akshay</media:title>
		</media:content>

		<media:content url="http://www.feedburner.com/fb/images/pub/feed-icon32x32.png" medium="image" />
	<feedburner:origLink>http://nofud.org/2009/01/31/note-to-fannie-mae-dealing-with-logic-bombs/</feedburner:origLink></item>
		<item>
		<title>The InfoSec X Prize: Fundamental Change Through Competition</title>
		<link>http://feedproxy.google.com/~r/noFUD/~3/8vPzyQ7kJyI/</link>
		<comments>http://nofud.org/2009/01/22/the-infosec-x-prize-fundamental-change-through-competition/#comments</comments>
		<pubDate>Thu, 22 Jan 2009 17:25:00 +0000</pubDate>
		<dc:creator>akshay aggarwal</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Finance]]></category>
		<category><![CDATA[Innovation]]></category>
		<category><![CDATA[Leadership]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[X Prize]]></category>

		<guid isPermaLink="false">http://nofud.wordpress.com/2009/01/22/the-infosec-x-prize-fundamental-change-through-competition/</guid>
		<description><![CDATA[Today I had a thought provoking conversation with Dr. Peter Diamandis, Chairman and CEO of Zero Gravity Corporation &#38; X Prize Foundation, on radical &#38; fundamental change. Change that advances the status quo rather than relying on incremental change for gradual advance.
Arguably the Ansari X Prize (and others in the hopper) have achieved some breakthrough [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nofud.org&blog=3571192&post=50&subd=nofud&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Today I had a thought provoking conversation with <a target="_blank" href="http://www.xprize.org/blogs/dr-peter-diamandis">Dr. Peter Diamandis</a>, Chairman and CEO of Zero Gravity Corporation &amp; X Prize Foundation, on radical &amp; fundamental change. Change that advances the status quo rather than relying on incremental change for gradual advance.</p>
<p>Arguably the <a target="_blank" href="http://en.wikipedia.org/wiki/Ansari_X_Prize">Ansari X Prize</a> (and others in the hopper) have achieved some breakthrough successes. Most notable achievements of the X Prize are:</p>
<ul>
<li><font face="Georgia">Achieving fundamental advancement in technology using competition driven philanthropy</font> </li>
<li><font face="Georgia">High rate of investment with respect to prize money. An example Diamandis provided was $100 million invested in Ansari X prize for a $10 million prize</font> </li>
<li><font face="Georgia">Booster to commercial adoption resulting from the advancement made. An example is the rapid kick start of transatlantic commercial air services after Lindbergh’s successful attempt at the <a target="_blank" href="http://www.charleslindbergh.com/plane/orteig.asp">Orteig Prize</a> in 1927</font> </li>
</ul>
<p>Now this brings me to a theme of recurrent conversation between my friend Eric Rachner and I. It is my belief that there has not been a fundamental change in the field of information security in the last decade. Sure things have become better, people are more aware, tools are easier &amp; more reliable &amp; dozens of new vulnerabilities are being found everyday. A thinking practitioner of the craft will reflect and agree that though there have several neat innovation like the vulnerability marketplace, security development lifecycle etc., most of the effort is spent chasing technical bits &amp; byte issues. Once, as we walked over to get dinner, Microsoft’s InfoSec Director Chris H. expressed this sentiment concisely for me, “Organizations have to constantly fight to demonstrate miniscule changes in their risk meter.”</p>
<p>So I got to thinking, what would constitute a <em>fundamental change</em> in infosec. Something worthy of an X prize (or a mini version of the X prize for sake of argument). Before I go into my idea, let me qualify that security being a state of a system, a conversation about it would be incomplete without defining the system. “Achieving security” is like aspiring to a noun. So here is my first stab at a problem worthy of the <strong>InfoSec X Prize</strong></p>
<p>To win the <strong>InfoSec X Prize</strong> a&#160; team must successfully create a system that will in real time analyze security alerts from the world’s largest internet retailer and&#160; take corrective response with an accuracy rate of 99% when compared 10 man years of manual analysis by InfoSec experts.</p>
<p>I will be coming up with additional X Prize ideas and post them periodically. I would be very interesting in knowing <u>what solution you consider worthy of such a prize.</u> Drop me a note and remember that the following constraints would apply to the solution worthy of the <strong>Infosec X Prize</strong>&#160; :</p>
<ul>
<li><font face="Georgia">Must be achievable between 5-8 years of X Prize being instituted</font> </li>
<li><font face="Georgia">Non-government/private organizations should be able to develop the solution</font> </li>
<li><font face="Georgia">Solution should represent a revolutionary change in field of information security</font> </li>
</ul>
<p>- Akshay</p>
Posted in Application Security, Business, Finance, Innovation, Leadership, Research, Security, Strategy, X Prize  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/nofud.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/nofud.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/nofud.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/nofud.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/nofud.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/nofud.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/nofud.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/nofud.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/nofud.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/nofud.wordpress.com/50/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nofud.org&blog=3571192&post=50&subd=nofud&ref=&feed=1" /></div>
<p><a href="http://feedads.g.doubleclick.net/~a/BILmoCwmB0aM7GCQJFzi9y9GOdg/0/da"><img src="http://feedads.g.doubleclick.net/~a/BILmoCwmB0aM7GCQJFzi9y9GOdg/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/BILmoCwmB0aM7GCQJFzi9y9GOdg/1/da"><img src="http://feedads.g.doubleclick.net/~a/BILmoCwmB0aM7GCQJFzi9y9GOdg/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/noFUD?a=8vPzyQ7kJyI:dzLmvm_Y-KQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/noFUD?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=8vPzyQ7kJyI:dzLmvm_Y-KQ:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/noFUD?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=8vPzyQ7kJyI:dzLmvm_Y-KQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/noFUD?i=8vPzyQ7kJyI:dzLmvm_Y-KQ:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=8vPzyQ7kJyI:dzLmvm_Y-KQ:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/noFUD?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=8vPzyQ7kJyI:dzLmvm_Y-KQ:l6gmwiTKsz0"><img src="http://feeds.feedburner.com/~ff/noFUD?d=l6gmwiTKsz0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=8vPzyQ7kJyI:dzLmvm_Y-KQ:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/noFUD?i=8vPzyQ7kJyI:dzLmvm_Y-KQ:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=8vPzyQ7kJyI:dzLmvm_Y-KQ:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/noFUD?d=TzevzKxY174" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/noFUD/~4/8vPzyQ7kJyI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://nofud.org/2009/01/22/the-infosec-x-prize-fundamental-change-through-competition/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7f872956a89dba537d87a7a1494d19be?s=96&amp;d=monsterid" medium="image">
			<media:title type="html">akshay</media:title>
		</media:content>
	<feedburner:origLink>http://nofud.org/2009/01/22/the-infosec-x-prize-fundamental-change-through-competition/</feedburner:origLink></item>
		<item>
		<title>Microfinance: One Calf At A Time</title>
		<link>http://feedproxy.google.com/~r/noFUD/~3/E4JLCwQcgsc/</link>
		<comments>http://nofud.org/2008/12/22/microfinance-one-calf-at-a-time/#comments</comments>
		<pubDate>Mon, 22 Dec 2008 19:22:00 +0000</pubDate>
		<dc:creator>akshay aggarwal</dc:creator>
				<category><![CDATA[Finance]]></category>

		<guid isPermaLink="false">http://nofud.wordpress.com/2008/12/24/microfinance-one-calf-at-a-time/</guid>
		<description><![CDATA[Today while reading the repercussions of the Madoff scandal, I received an email informing me that a microfinance (MF)&#160; loan that I had made to a person in Central Asia to purchase livestock had been paid back in full and on time. In a week of bad financial news marked by financial greed at the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nofud.org&blog=3571192&post=45&subd=nofud&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Today while reading the repercussions of the Madoff scandal, I received an email informing me that a microfinance (MF)&#160; loan that I had made to a person in Central Asia to purchase livestock had been paid back in full and on time. In a week of bad financial news marked by financial greed at the top, it was heartening to realize the integrity of few at the bottom.&#160; </p>
<p>As of now the microfinance industry (MFI) seems to be bucking the trend of the global financial crisis. Repayment is still fairly high at 97-98% (according to <a target="_blank" href="http://www.swwb.org/">Women&#8217;s World Banking</a>). It seems that the size of MF market is insulating it from a downturn – the MF market is several times smaller than the losses in the current global financial crisis. Another factor protects MFIs as they do not serve the poorest of the poor. MFIs in general are geared towards mobilizing the entrepreneurial poor who are more economically active. </p>
<p>As the crisis develops further, there is an increasing risk that the MFIs may also see a liquidity crunch owing to recession in the US &amp; Europe, increasing default rates and difficulty in raising funds from investors. One trend seems certain though, the growth rate of the MFI will slow from the rapid expansions it has seen due to commercialization &amp; product diversification. Hopefully this will give the industry some breathing space to mature further and come out of this crisis stronger.</p>
<p>In any case, that one email buoyed my spirit and while all may not be well, all is not bad either.</p>
<p>- Akshay</p>
Posted in Finance  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/nofud.wordpress.com/45/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/nofud.wordpress.com/45/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/nofud.wordpress.com/45/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/nofud.wordpress.com/45/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/nofud.wordpress.com/45/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/nofud.wordpress.com/45/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/nofud.wordpress.com/45/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/nofud.wordpress.com/45/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/nofud.wordpress.com/45/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/nofud.wordpress.com/45/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nofud.org&blog=3571192&post=45&subd=nofud&ref=&feed=1" /></div>
<p><a href="http://feedads.g.doubleclick.net/~a/hywCanRTmhxO_yluIxTOZajJ0jU/0/da"><img src="http://feedads.g.doubleclick.net/~a/hywCanRTmhxO_yluIxTOZajJ0jU/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/hywCanRTmhxO_yluIxTOZajJ0jU/1/da"><img src="http://feedads.g.doubleclick.net/~a/hywCanRTmhxO_yluIxTOZajJ0jU/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/noFUD?a=E4JLCwQcgsc:z_tBg6WOQDQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/noFUD?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=E4JLCwQcgsc:z_tBg6WOQDQ:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/noFUD?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=E4JLCwQcgsc:z_tBg6WOQDQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/noFUD?i=E4JLCwQcgsc:z_tBg6WOQDQ:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=E4JLCwQcgsc:z_tBg6WOQDQ:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/noFUD?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=E4JLCwQcgsc:z_tBg6WOQDQ:l6gmwiTKsz0"><img src="http://feeds.feedburner.com/~ff/noFUD?d=l6gmwiTKsz0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=E4JLCwQcgsc:z_tBg6WOQDQ:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/noFUD?i=E4JLCwQcgsc:z_tBg6WOQDQ:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=E4JLCwQcgsc:z_tBg6WOQDQ:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/noFUD?d=TzevzKxY174" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/noFUD/~4/E4JLCwQcgsc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://nofud.org/2008/12/22/microfinance-one-calf-at-a-time/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7f872956a89dba537d87a7a1494d19be?s=96&amp;d=monsterid" medium="image">
			<media:title type="html">akshay</media:title>
		</media:content>
	<feedburner:origLink>http://nofud.org/2008/12/22/microfinance-one-calf-at-a-time/</feedburner:origLink></item>
		<item>
		<title>Business During Downturn: The Chain Of Trust</title>
		<link>http://feedproxy.google.com/~r/noFUD/~3/5W_mT6zdRvQ/</link>
		<comments>http://nofud.org/2008/12/18/business-during-downturn-the-chain-of-trust/#comments</comments>
		<pubDate>Fri, 19 Dec 2008 02:09:37 +0000</pubDate>
		<dc:creator>akshay aggarwal</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Leadership]]></category>

		<guid isPermaLink="false">http://nofud.wordpress.com/2008/12/18/business-during-downturn-the-chain-of-trust/</guid>
		<description><![CDATA[Business during economic downturns brings to the surface the tiny fractures that were unnoticeable during the good times. It is a fertile ground to relearn some of the lessons of the past &#38; form wisdom for the future. I am going to try and capture some of the learning during this new series Business During [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nofud.org&blog=3571192&post=44&subd=nofud&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Business during economic downturns brings to the surface the tiny fractures that were unnoticeable during the good times. It is a fertile ground to relearn some of the lessons of the past &amp; form wisdom for the future. I am going to try and capture some of the learning during this new series <em>Business During Downturn</em>. </p>
<p>The past few months have convinced me that individuals &amp; organizations that pay close attention to the basics fare better going into a economic downturn. In particular, establishing and maintaining the sanctity of the chain of trust is very essential. The chain of trust is a relationship aspect of interdependent entities. It is based upon the credibility, accuracy and timeliness of business inputs like data, forecasting &amp; assumptions which are then sent up the chain to act as inputs for decision making. An economic downturn breeds anxiety, performance pressures and uncertainty &amp; so maintaining trust is essential for survival. I have recently felt the need for paying attention to 3 chains of trust in particular.</p>
<p>First is the trust between a salesman and sales management. Revenue forecasting is the key activity that helps the organization plan to survive and adapt to change. On the basis of this projection further trust (say with creditors) is established. The sales team need to redouble their efforts to adhere to the sales basics and stabilize projections within parameters acceptable to the org. I have observed that this is one of the biggest self-feeding problems. Wrong projections quickly add additional pressure to the relationship between a salesperson and their manager. Sales managers in turn find their relationship with their managers deteriorate leading to increased supervision, more administrative tasks, less flexibility… all the undesirables during a tough period. Sales people successful in good times but inaccurate in bad times find it hard to gain back the trust when conditions improve for the better.</p>
<p>Second is the trust between an organization and their suppliers/creditors. Some organizations misrepresent the situation to their creditors or set up false expectations with them. In my opinion, people forget that they are dealing with other people. People working for the creditor also have accountabilities and are much less likely to support you during a downturn and the subsequent upturn if they feel that they have been misled, their time abused or subjected to unnecessary stress. I saw a CEO deal with this effectively by instructing his staff to always answer a creditors inquiry in a timely manner, give a conservative payment schedule, share the assumptions that may positively or negatively impact the information and most importantly reiterate how they were committed to long-term relationship (and how their behavior was different than the competition). The CEO ensured the message was consistent across ranks and this had the added benefit of improving morale within his org. It better prepared his staff for taking calls from creditors. Everyone knows that talking to your creditor is like visiting your dentist. </p>
<p>Third is the trust delegated to the employees especially the sales force. Very often managers will ask employees to take tough decisions or be creative only to second guess the decision. This erodes the trust the employee has in his management and increases the sense of chaos. The manager needs to examine his issues around control &amp; trust or to take back the decision making authority. The long term implications of this for a sales person is that they lose credibility with the client and eventually the client knows that negotiated agreements with the sales person are not the final negotiated position. Their boss will play game…</p>
<p>I’d be very interested in your observations and lessons in this economic cycle. Feel free to drop me a note.</p>
<p>- akshay </p>
Posted in Business, Leadership  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/nofud.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/nofud.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/nofud.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/nofud.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/nofud.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/nofud.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/nofud.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/nofud.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/nofud.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/nofud.wordpress.com/44/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nofud.org&blog=3571192&post=44&subd=nofud&ref=&feed=1" /></div>
<p><a href="http://feedads.g.doubleclick.net/~a/cBHzn8fOZk38rGd_2pIKIgSi9Go/0/da"><img src="http://feedads.g.doubleclick.net/~a/cBHzn8fOZk38rGd_2pIKIgSi9Go/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/cBHzn8fOZk38rGd_2pIKIgSi9Go/1/da"><img src="http://feedads.g.doubleclick.net/~a/cBHzn8fOZk38rGd_2pIKIgSi9Go/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/noFUD?a=5W_mT6zdRvQ:pJdhZHhOz3U:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/noFUD?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=5W_mT6zdRvQ:pJdhZHhOz3U:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/noFUD?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=5W_mT6zdRvQ:pJdhZHhOz3U:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/noFUD?i=5W_mT6zdRvQ:pJdhZHhOz3U:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=5W_mT6zdRvQ:pJdhZHhOz3U:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/noFUD?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=5W_mT6zdRvQ:pJdhZHhOz3U:l6gmwiTKsz0"><img src="http://feeds.feedburner.com/~ff/noFUD?d=l6gmwiTKsz0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=5W_mT6zdRvQ:pJdhZHhOz3U:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/noFUD?i=5W_mT6zdRvQ:pJdhZHhOz3U:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/noFUD?a=5W_mT6zdRvQ:pJdhZHhOz3U:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/noFUD?d=TzevzKxY174" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/noFUD/~4/5W_mT6zdRvQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://nofud.org/2008/12/18/business-during-downturn-the-chain-of-trust/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7f872956a89dba537d87a7a1494d19be?s=96&amp;d=monsterid" medium="image">
			<media:title type="html">akshay</media:title>
		</media:content>
	<feedburner:origLink>http://nofud.org/2008/12/18/business-during-downturn-the-chain-of-trust/</feedburner:origLink></item>
	</channel>
</rss>
