<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Retail Information Security</title>
	
	<link>http://www.retailinfosec.com</link>
	<description>Retail &amp; Hospitality Information Security (including PCI)</description>
	<pubDate>Fri, 26 Feb 2010 19:26:34 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/retailinfosec/aloi" /><feedburner:info uri="retailinfosec/aloi" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>YouTube - Hitler and Cloud Computing Security</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/2-orDo87u_Q/</link>
		<comments>http://www.retailinfosec.com/2010/02/26/youtube-hitler-and-cloud-computing-security/#comments</comments>
		<pubDate>Fri, 26 Feb 2010 19:26:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[funny]]></category>

		<category><![CDATA[video]]></category>

		<category><![CDATA[weird]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/2010/02/26/youtube-hitler-and-cloud-computing-security/</guid>
		<description><![CDATA[
I had know idea that there was a genre of online comedy videos that used scenes of Hitler from movies coupled with fake closed caption information&#8230;.
Didn&#8217;t really think Hitler could be all that funny, but this one is pretty good.  Mind - I don&#8217;t speak a lick of German and have no idea what is really being said here, but the captions are hilarious&#8230;
Thanks to ReadWriteWeb for the spot.
YouTube - Hitler and Cloud Computing Security.


]]></description>
			<content:encoded><![CDATA[<p><object width="425" height="350"><param name="movie" value="http://www.youtube.com/v/VjfaCoA2sQk&#038;feature=player_embedded#"></param><param name="wmode" value="transparent"></param><embed src="http://www.youtube.com/v/VjfaCoA2sQk&#038;feature=player_embedded#" type="application/x-shockwave-flash" wmode="transparent" width="425" height="350"></embed></object></p>
<p>I had know idea that there was a genre of online comedy videos that used scenes of Hitler from movies coupled with fake closed caption information&#8230;.</p>
<p>Didn&#8217;t really think Hitler could be all that funny, but this one is pretty good.  Mind - I don&#8217;t speak a lick of German and have no idea what is really being said here, but the captions are hilarious&#8230;</p>
<p>Thanks to ReadWriteWeb for the spot.</p>
<p><a href="http://www.youtube.com/watch?v=VjfaCoA2sQk&amp;feature=player_embedded#" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.youtube.com');">YouTube - Hitler and Cloud Computing Security</a>.</p>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/2-orDo87u_Q" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/02/26/youtube-hitler-and-cloud-computing-security/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/02/26/youtube-hitler-and-cloud-computing-security/</feedburner:origLink></item>
		<item>
		<title>NRF 2010 Follow-Up (it didn’t suck)</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/IcUrEVpFyQA/</link>
		<comments>http://www.retailinfosec.com/2010/01/18/nrf-2010-follow-up-it-didnt-suck/#comments</comments>
		<pubDate>Mon, 18 Jan 2010 15:54:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[NRF]]></category>

		<category><![CDATA[PCI News]]></category>

		<category><![CDATA[PCI Philosophy / Approach]]></category>

		<category><![CDATA[Retailers]]></category>

		<category><![CDATA[Vendors]]></category>

		<category><![CDATA[application security]]></category>

		<category><![CDATA[headline]]></category>

		<category><![CDATA[NetSPI]]></category>

		<category><![CDATA[PA-DSS]]></category>

		<category><![CDATA[PCI-DSS]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=377</guid>
		<description><![CDATA[As promised, I&#8217;m posting this as a follow-up to this year&#8217;s NRF show in NYC.  It is going to be a short post as there really isn&#8217;t a lot to talk about from the show, particularly in terms of security or compliance.
The big news this year is that the show didn&#8217;t suck.  Someone told me that it was the best attended show (by retailers) in the last 5 years.  I&#8217;m not sure if that&#8217;s an official ruling from the NRF, but I can certainly attest to the fact that traffic ...]]></description>
			<content:encoded><![CDATA[<p>As promised, I&#8217;m posting this as a follow-up to this year&#8217;s NRF show in NYC.  It is going to be a short post as there really isn&#8217;t a lot to talk about from the show, particularly in terms of security or compliance.</p>
<p>The big news this year is that the show didn&#8217;t suck.  Someone told me that it was the best attended show (by retailers) in the last 5 years.  I&#8217;m not sure if that&#8217;s an official ruling from the NRF, but I can certainly attest to the fact that traffic was significantly better than last year.  Last year we had all kinds of time to hang out in people&#8217;s booths and talk with technology clients and vendors about security - this year most of the significant vendors had retailer traffic a lot of the time.  I will say that it was hard to tell with Motorola (who had one of the largest booths) who apparently brought every employee within a 200-mile radius of New York to the show - seriously&#8230;.<span id="more-377"></span></p>
<p>Our clients all seemed to be very busy (which is good) and while they certainly spent time with us, we didn&#8217;t infringe on their hospitality too much as they had clients to see and non-clients to (hopefully) impress.</p>
<p>In terms of security - there wasn&#8217;t much to be found on the expo floor.  We didn&#8217;t see any booths (I heard that one of NetSPI&#8217;s competitors was hanging out in someone&#8217;s booth, but we never found them) from major security and compliance players and, while security and PCI were certainly still being used to push product (it was printed on a ton of booth signs), it was very surface-level this year.  No one seemed to be at all that interested in a deep discussion - they just knew that their product did x, y, and z for PCI&#8230;  Most of the software companies didn&#8217;t even have their primary security person at the show.  Even AT&amp;T and Verizon, both having acquired large security practices didn&#8217;t really talk about security - they focused their efforts on retail technology divisions or communications.</p>
<p>I think, with the economy and retail marketplace slowly improving, technology companies that really don&#8217;t understand compliance and security (and don&#8217;t want the burden of supporting deep discussions around the same) have decided that they are going to relegate compliance to a &#8216;check-box&#8217; activity.  In other words, &#8216;I am PA-DSS compliant, so I don&#8217;t really have to talk about security anymore, thanks&#8230;&#8217;</p>
<p>My reaction to this attitude - I see opportunities for vendors that really are willing to understand compliance, it&#8217;s impact on retailers, and their own ability to positively influence a retailer&#8217;s compliance efforts.  I see problems for companies that check their box and then wash their hands of clients&#8217; compliance concerns.</p>
<p>For the organization I work for, I think it might actually be a good thing in the long term as we help our clients take the first path and better prepare their teams (both on the technical and marketing side of the house) for supporting their clients.  It certainly seemed to be playing out well for our clients at the show - they not only had their compliance box &#8216;checked&#8217;, but they were using that experience and the knowledge that they actively gained from the relationship to better position their clients and, therefore, their own brands and products.</p>
<p>Regardless, the show this year was a big improvement over last and most likely indicates an improved outlook for the retail community and the broader economy (retailer spending tends to foreshadow economic conditions) and that&#8217;s good news regardless.  Again, I&#8217;m disappointed about the lack of security-focused discussion at the show this year, but happy that retail might be slowly coming out of a very difficult time.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://pindebit.blogspot.com/2010/01/ingenico-launches-secure-multimedia.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/pindebit.blogspot.com');">Ingenico Launches Secure Multimedia Powerhouse iSC350 to Kick-Off 99th NRF Show</a> (pindebit.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//abcnews.go.com/Business/wireStory%3Fid%3D8971649&amp;a=9125470&amp;rid=7ecf9603-43c9-8f30-a119-a516a4931b15&amp;e=8cb626fa06e2581a0e30b883b53535c8" onclick="javascript:pageTracker._trackPageview('/outbound/article/r.zemanta.com');">Retail Faces Uncertainty as CIT Enters Bankruptcy</a> (abcnews.go.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.shoppingblog.com/blog/1228093" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.shoppingblog.com');">Late Season Surge Helps Retail Sales Gain 3.6% Over Last year</a> (shoppingblog.com)</li>
<li class="zemanta-article-ul-li"><a href="http://pindebit.blogspot.com/2010/01/source-technologies-introduces-next.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/pindebit.blogspot.com');">Source Technologies Introduces Next-Generation of PilotPoint™ Self-Service Bill Payment Kiosk</a> (pindebit.blogspot.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/7ecf9603-43c9-8f30-a119-a516a4931b15/" onclick="javascript:pageTracker._trackPageview('/outbound/article/reblog.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=7ecf9603-43c9-8f30-a119-a516a4931b15" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/IcUrEVpFyQA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/01/18/nrf-2010-follow-up-it-didnt-suck/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/01/18/nrf-2010-follow-up-it-didnt-suck/</feedburner:origLink></item>
		<item>
		<title>So….. it’s been awhile……</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/ZTPnIqzefts/</link>
		<comments>http://www.retailinfosec.com/2010/01/06/so-its-been-awhile/#comments</comments>
		<pubDate>Wed, 06 Jan 2010 20:37:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[PCI News]]></category>

		<category><![CDATA[featured]]></category>

		<category><![CDATA[2010]]></category>

		<category><![CDATA[NetSPI]]></category>

		<category><![CDATA[New Year]]></category>

		<category><![CDATA[NRF]]></category>

		<category><![CDATA[PA-DSS]]></category>

		<category><![CDATA[PCI-DSS]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=369</guid>
		<description><![CDATA[I haven&#8217;t posted anything forever!!!
Bad Alex!
Well, I&#8217;m heading out to another NRF this weekend and I promise that I&#8217;ll post something either from the show or shortly thereafter.  It might have something to do with how poorly security is represented at the show (other than at least 25 &#8216;Instant PCI&#8217; offerings and Trustwave throwing money around&#8230;), but we&#8217;ll see.
If anyone out there is actually going to be at NRF and is interested in connecting, please let me know - alex.crittenden@yahoo.com - and we&#8217;ll figure something out.
Thanks and Happy New Year!
Related ...]]></description>
			<content:encoded><![CDATA[<p>I haven&#8217;t posted anything forever!!!</p>
<p>Bad Alex!</p>
<p>Well, I&#8217;m heading out to another NRF this weekend and I promise that I&#8217;ll post something either from the show or shortly thereafter.  It might have something to do with how poorly security is represented at the show (other than at least 25 &#8216;Instant PCI&#8217; offerings and Trustwave throwing money around&#8230;), but we&#8217;ll see.</p>
<p>If anyone out there is actually going to be at NRF and is interested in connecting, please let me know - alex.crittenden@yahoo.com - and we&#8217;ll figure something out.</p>
<p>Thanks and Happy New Year!</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://pindebit.blogspot.com/2009/12/nrf-discusses-11-billion-vmc-payout.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/pindebit.blogspot.com');">NRF Discusses $1.1 Billion V/MC Payout</a> (pindebit.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.nytimes.com/2010/01/05/your-money/credit-and-debit-cards/05visa.html%3Fpartner%3Drss%26amp%3Bemc%3Drss&amp;a=11132300&amp;rid=e064fa52-fabb-8b07-bedf-cec7b90e55b4&amp;e=0810cea62b42ebbabc27f3eea527851a" onclick="javascript:pageTracker._trackPageview('/outbound/article/r.zemanta.com');">The Card Game: How Visa, Using Card Fees, Dominates a Market</a> (nytimes.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.shoppingblog.com/blog/1228093" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.shoppingblog.com');">Late Season Surge Helps Retail Sales Gain 3.6% Over Last year</a> (shoppingblog.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/e064fa52-fabb-8b07-bedf-cec7b90e55b4/" onclick="javascript:pageTracker._trackPageview('/outbound/article/reblog.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=e064fa52-fabb-8b07-bedf-cec7b90e55b4" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/ZTPnIqzefts" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/01/06/so-its-been-awhile/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/01/06/so-its-been-awhile/</feedburner:origLink></item>
		<item>
		<title>PCI ‘Open Mic’ Webinar in Early December</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/4TOczd6ZNXQ/</link>
		<comments>http://www.retailinfosec.com/2009/12/01/pci-open-mic-webinar-in-early-december/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 19:17:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Alerts]]></category>

		<category><![CDATA[Conferences / Webinars]]></category>

		<category><![CDATA[PCI News]]></category>

		<category><![CDATA[PCI Philosophy / Approach]]></category>

		<category><![CDATA[PED / Payment Terminals]]></category>

		<category><![CDATA[PA-DSS]]></category>

		<category><![CDATA[PCI]]></category>

		<category><![CDATA[PCI-DSS]]></category>

		<category><![CDATA[PCI-SSC]]></category>

		<category><![CDATA[webinar]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/2009/12/01/pci-open-mic-webinar-in-early-december/</guid>
		<description><![CDATA[The Council is hosting a couple of &#8216;open mic&#8217; webinars for industry stakeholders on the 8th and 9th of December.  They are trying to update the industry following the Community Meeting and get some feedback or questions&#8230;.
These are typically reserved for Participating Organizations, but for this round they are opening it up to the broader industry&#8230;  Here&#8217;s the link:
PCI Council Webinar Release


]]></description>
			<content:encoded><![CDATA[<p>The Council is hosting a couple of &#8216;open mic&#8217; webinars for industry stakeholders on the 8th and 9th of December.  They are trying to update the industry following the Community Meeting and get some feedback or questions&#8230;.</p>
<p>These are typically reserved for Participating Organizations, but for this round they are opening it up to the broader industry&#8230;  Here&#8217;s the link:</p>
<p><a href="https://www.pcisecuritystandards.org/pdfs/pr_091130_open_mic.pdf" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.pcisecuritystandards.org');">PCI Council Webinar Release</a></p>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/4TOczd6ZNXQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2009/12/01/pci-open-mic-webinar-in-early-december/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2009/12/01/pci-open-mic-webinar-in-early-december/</feedburner:origLink></item>
		<item>
		<title>Quick News Note - IBM Acquires Guardium</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/6ldcrxKvqS0/</link>
		<comments>http://www.retailinfosec.com/2009/12/01/quick-news-note-ibm-acquires-guardium/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 15:58:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[PCI News]]></category>

		<category><![CDATA[Vendors]]></category>

		<category><![CDATA[acquisition]]></category>

		<category><![CDATA[consolidation]]></category>

		<category><![CDATA[guardium]]></category>

		<category><![CDATA[ibm]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/2009/12/01/quick-news-note-ibm-acquires-guardium/</guid>
		<description><![CDATA[IBM continues to quietly buy up both analytics companies and (more importantly for us) security companies&#8230;  After picking up Ounce Labs earlier, IBM has now acquired Guardium.
Guardium - IBM Acquires Guardium.


]]></description>
			<content:encoded><![CDATA[<p>IBM continues to quietly buy up both analytics companies and (more importantly for us) security companies&#8230;  After picking up Ounce Labs earlier, IBM has now acquired Guardium.</p>
<p><a href="http://www.guardium.com/index.php/pr/923" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.guardium.com');">Guardium - IBM Acquires Guardium</a>.</p>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/6ldcrxKvqS0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2009/12/01/quick-news-note-ibm-acquires-guardium/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2009/12/01/quick-news-note-ibm-acquires-guardium/</feedburner:origLink></item>
		<item>
		<title>Another Interesting Lawsuit</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/QUj1fTC-bw4/</link>
		<comments>http://www.retailinfosec.com/2009/11/25/another-interesting-lawsuit/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 15:40:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Interesting]]></category>

		<category><![CDATA[PCI News]]></category>

		<category><![CDATA[Retailers]]></category>

		<category><![CDATA[Vendors]]></category>

		<category><![CDATA[application security]]></category>

		<category><![CDATA[featured]]></category>

		<category><![CDATA[business]]></category>

		<category><![CDATA[hospitality]]></category>

		<category><![CDATA[PA-DSS]]></category>

		<category><![CDATA[PCI-DSS]]></category>

		<category><![CDATA[Point of sale]]></category>

		<category><![CDATA[Radiant Systems]]></category>

		<category><![CDATA[Restaurant]]></category>

		<category><![CDATA[Technology]]></category>

		<category><![CDATA[vendor responsibility]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=358</guid>
		<description><![CDATA[This one has some significant implications for software security and the role &#38; responsibility of technology vendors.  Here&#8217;s the link:
Radiant Systems and Computer World responsible for breach affecting restaurants – lawsuit
What&#8217;s most interesting to me in all of this is that fact that the restaurants seem to &#8216;get it&#8217; - they understand the holistic impact of PCI on process, procedures, technology, etc. and, after being smacked around by the card brands for being the merchant where the breach occured, they have taken that holistic understanding and are working to hold ...]]></description>
			<content:encoded><![CDATA[<p>This one has some significant implications for software security and the role &amp; responsibility of technology vendors.  Here&#8217;s the link:</p>
<h3><a id="aptureLink_fs2GZGuE6t" href="http://www.databreaches.net/?p=8408" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.databreaches.net');">Radiant Systems and Computer World responsible for breach affecting restaurants – lawsuit</a></h3>
<p>What&#8217;s most interesting to me in all of this is that fact that the restaurants seem to &#8216;get it&#8217; - they understand the holistic impact of PCI on process, procedures, technology, etc. and, after being smacked around by the card brands for being the merchant where the breach occured, they have taken that holistic understanding and are working to hold their providers responsible.</p>
<p>Should be interesting to see how this plays out for all parties involved - it could have a real impact on POS software providers, the service organizations, and merchants of all sizes&#8230;</p>
<p><a id="aptureLink_Y7ogiPzOKQ" style="margin: 0pt auto; padding: 0px 6px; text-align: center; display: block;" href="http://en.wikipedia.org/wiki/PA-DSS" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');"><img style="border: 0px none;" title="PA-DSS" src="http://placeholder.apture.com/ph/360x280_WikipediaArticle/" alt="" width="360" height="280" /></a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/222ec700-4baa-4f3b-8fe1-d548e4a6d860/" onclick="javascript:pageTracker._trackPageview('/outbound/article/reblog.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=222ec700-4baa-4f3b-8fe1-d548e4a6d860" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/QUj1fTC-bw4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2009/11/25/another-interesting-lawsuit/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2009/11/25/another-interesting-lawsuit/</feedburner:origLink></item>
		<item>
		<title>SharePoint and Security</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/Mkyrda56gh8/</link>
		<comments>http://www.retailinfosec.com/2009/11/10/sharepoint-and-security-2/#comments</comments>
		<pubDate>Tue, 10 Nov 2009 13:38:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Vendors]]></category>

		<category><![CDATA[application security]]></category>

		<category><![CDATA[featured]]></category>

		<category><![CDATA[Microsoft]]></category>

		<category><![CDATA[Microsoft SharePoint]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=341</guid>
		<description><![CDATA[



Image by Wonderlane via Flickr



 

With the Microsoft SharePoint conference having recently taken place, I have been thinking a lot about SharePoint lately (haven’t you?) and about what a powerful and dangerous tool it can be.

 
Before I get into what I&#8217;ve been thinking about, here are a few things to consider:


 

A Microsoft employee recently told me that SharePoint has been the most rapidly adopted product in Microsoft&#8217;s history. While I haven&#8217;t been able to confirm this, it doesn&#8217;t really matter - what matters is, it&#8217;s everywhere and it ...]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 250px;">
<dt class="wp-caption-dt"><a href="http://www.flickr.com/photos/71401718@N00/3008060321" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.flickr.com');"><img title="12 Microsoft SharePoint Sites - Winners of the..." src="http://farm4.static.flickr.com/3279/3008060321_f43ebc6c1d_m.jpg" alt="12 Microsoft SharePoint Sites - Winners of the..." width="240" height="151" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image by <a href="http://www.flickr.com/photos/71401718@N00/3008060321" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.flickr.com');">Wonderlane</a> via Flickr</dd>
</dl>
</div>
</div>
<p><!--[if gte mso 9]><xml> <w:WordDocument> <w:View>Normal</w:View> <w:Zoom>0</w:Zoom> <w:TrackMoves></w> <w:TrackFormatting></w> <w:PunctuationKerning></w> <w:ValidateAgainstSchemas></w> <w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid> <w:IgnoreMixedContent>false</w:IgnoreMixedContent> <w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText> <w:DoNotPromoteQF></w> <w:LidThemeOther>EN-US</w:LidThemeOther> <w:LidThemeAsian>X-NONE</w:LidThemeAsian> <w:LidThemeComplexScript>X-NONE</w:LidThemeComplexScript> <w:Compatibility> <w:BreakWrappedTables></w> <w:SnapToGridInCell></w> <w:WrapTextWithPunct></w> <w:UseAsianBreakRules></w> <w:DontGrowAutofit></w> <w:SplitPgBreakAndParaMark></w> <w:DontVertAlignCellWithSp></w> <w:DontBreakConstrainedForcedTables></w> <w:DontVertAlignInTxbx></w> <w:Word11KerningPairs></w> <w:CachedColBalance></w> <w:UseFELayout></w> </w:Compatibility> <w:BrowserLevel>MicrosoftInternetExplorer4</w:BrowserLevel> <m:mathPr> <m:mathFont m:val="Cambria Math"></m> <m:brkBin m:val="before"></m> <m:brkBinSub m:val="&#45;-"></m> <m:smallFrac m:val="off"></m> <m:dispDef></m> <m:lMargin m:val="0"></m> <m:rMargin m:val="0"></m> <m:defJc m:val="centerGroup"></m> <m:wrapIndent m:val="1440"></m> <m:intLim m:val="subSup"></m> <m:naryLim m:val="undOvr"></m> </m:mathPr></w:WordDocument> </xml><![endif]--><!--[if gte mso 9]><xml> <w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"   DefSemiHidden="true" DefQFormat="false" DefPriority="99"   LatentStyleCount="267"> <w:LsdException Locked="false" Priority="0" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Normal"></w> <w:LsdException Locked="false" Priority="0" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="heading 1"></w> <w:LsdException Locked="false" Priority="0" QFormat="true" Name="heading 2"></w> <w:LsdException Locked="false" Priority="0" QFormat="true" Name="heading 3"></w> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"></w> <w:LsdException Locked="false" Priority="0" QFormat="true" Name="heading 5"></w> <w:LsdException Locked="false" Priority="0" QFormat="true" Name="heading 6"></w> <w:LsdException Locked="false" Priority="0" QFormat="true" Name="heading 7"></w> <w:LsdException Locked="false" Priority="0" QFormat="true" Name="heading 8"></w> <w:LsdException Locked="false" Priority="0" QFormat="true" Name="heading 9"></w> <w:LsdException Locked="false" Priority="39" Name="toc 1"></w> <w:LsdException Locked="false" Priority="39" Name="toc 2"></w> <w:LsdException Locked="false" Priority="39" Name="toc 3"></w> <w:LsdException Locked="false" Priority="39" Name="toc 4"></w> <w:LsdException Locked="false" Priority="39" Name="toc 5"></w> <w:LsdException Locked="false" Priority="39" Name="toc 6"></w> <w:LsdException Locked="false" Priority="39" Name="toc 7"></w> <w:LsdException Locked="false" Priority="39" Name="toc 8"></w> <w:LsdException Locked="false" Priority="39" Name="toc 9"></w> <w:LsdException Locked="false" Priority="0" Name="header"></w> <w:LsdException Locked="false" Priority="0" Name="footer"></w> <w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"></w> <w:LsdException Locked="false" Priority="0" Name="page number"></w> <w:LsdException Locked="false" Priority="0" Name="List Bullet 2"></w> <w:LsdException Locked="false" Priority="10" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Title"></w> <w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"></w> <w:LsdException Locked="false" Priority="0" QFormat="true" Name="Body Text"></w> <w:LsdException Locked="false" Priority="11" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Subtitle"></w> <w:LsdException Locked="false" Priority="22" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Strong"></w> <w:LsdException Locked="false" Priority="20" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Emphasis"></w> <w:LsdException Locked="false" Priority="59" SemiHidden="false"    UnhideWhenUsed="false" Name="Table Grid"></w> <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"></w> <w:LsdException Locked="false" Priority="1" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="No Spacing"></w> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading"></w> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List"></w> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid"></w> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1"></w> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2"></w> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1"></w> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2"></w> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1"></w> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2"></w> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3"></w> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List"></w> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading"></w> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List"></w> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid"></w> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 1"></w> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 1"></w> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 1"></w> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"></w> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"></w> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 1"></w> <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"></w> <w:LsdException Locked="false" Priority="34" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"></w> <w:LsdException Locked="false" Priority="29" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Quote"></w> <w:LsdException Locked="false" Priority="30" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"></w> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 1"></w> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"></w> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"></w> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"></w> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 1"></w> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 1"></w> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 1"></w> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 1"></w> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 2"></w> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 2"></w> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 2"></w> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"></w> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"></w> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 2"></w> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 2"></w> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"></w> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"></w> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"></w> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 2"></w> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 2"></w> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 2"></w> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 2"></w> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 3"></w> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 3"></w> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 3"></w> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"></w> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"></w> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 3"></w> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 3"></w> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"></w> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"></w> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"></w> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 3"></w> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 3"></w> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 3"></w> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 3"></w> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 4"></w> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 4"></w> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 4"></w> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"></w> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"></w> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 4"></w> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 4"></w> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"></w> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"></w> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"></w> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 4"></w> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 4"></w> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 4"></w> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 4"></w> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 5"></w> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 5"></w> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 5"></w> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"></w> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"></w> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 5"></w> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 5"></w> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"></w> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"></w> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"></w> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 5"></w> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 5"></w> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 5"></w> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 5"></w> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 6"></w> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 6"></w> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 6"></w> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"></w> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"></w> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 6"></w> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 6"></w> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"></w> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"></w> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"></w> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 6"></w> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 6"></w> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 6"></w> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 6"></w> <w:LsdException Locked="false" Priority="19" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"></w> <w:LsdException Locked="false" Priority="21" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"></w> <w:LsdException Locked="false" Priority="31" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"></w> <w:LsdException Locked="false" Priority="32" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"></w> <w:LsdException Locked="false" Priority="33" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Book Title"></w> <w:LsdException Locked="false" Priority="37" Name="Bibliography"></w> <w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"></w> </w:LatentStyles> </xml><![endif]--> <!--[if gte mso 10]><br />
<mce:style><!   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} --></p>
<p><!--[endif]--></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">With the Microsoft SharePoint conference having recently taken place, I have been thinking a lot about SharePoint lately (haven’t you?) and about what a powerful and dangerous tool it can be.</span></p>
<p></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">Before I get into what I&#8217;ve been thinking about, here are a few things to consider:</span></p>
<p></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;"> </span></p>
<ul>
<li><!--[if !supportLists]--><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">A Microsoft employee recently told me that SharePoint has been the most rapidly adopted product in Microsoft&#8217;s history.<span> </span>While I haven&#8217;t been able to confirm this, it doesn&#8217;t really matter - what matters is, it&#8217;s everywhere and it got there quickly&#8230;</span></li>
</ul>
<ul>
<li><!--[if !supportLists]--><!--[endif]--><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">A large number of the installations where first put in as side projects or experiments that ended up proving out.</span></li>
</ul>
<ul>
<li><!--[if !supportLists]--><span style="font-size: 10pt; font-family: Symbol;"><span><span style="font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; font-family: &quot;Times New Roman&quot;;"> </span></span></span><!--[endif]--><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">SharePoint, particularly when it&#8217;s an experiment, seems to be initially managed by someone that takes it on as an additional responsibility because they realize the power of the solution and want to wake their company up to the possibilities – it’s not a core focus of their position.<span> </span></span></li>
</ul>
<ul>
<li><!--[if !supportLists]--><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">If SharePoint is embraced by an organization, it quickly expands to include huge amounts of data - often including data that is very sensitive.</span></li>
</ul>
<ul>
<li><!--[if !supportLists]--><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">Once SharePoint becomes part of how a company functions, new SharePoint functionality is often built and implemented by the organization (often these efforts are out-sourced, particularly before internal SharePoint expertise is built-up.)</span></li>
</ul>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">I think the entire concept of SharePoint (and the other knowledge sharing solutions out there) is fantastic.<span> </span>I&#8217;m a big believer in collaboration and data sharing and the positive impact that can be had when a company empowers its employees.<span> </span>The ability to manage, through a common platform, access to company data is great.</span></p>
<p></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">Now, If you read the points above, you should quickly see that there is also a real potential for disaster here as well - a complicated environment, access to huge amounts of potentially sensitive information, and application customization that could possibly have an impact on access to all of that information…</span></p>
<p></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">Maybe it&#8217;s not cardholder data and the card brands aren&#8217;t threatening you with fines and the like, but I don&#8217;t think any retailer would like to have their quarterly numbers leaked before the official release date.<span> </span>How about trade or manufacturing secrets sold to a competitor?<span> </span>Employee&#8217;s personal information exposed and used in identity theft?<span> </span>Information about an upcoming merger leaked to the competition?</span></p>
<p></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">These issues are real and can be just as damaging as any compliance issue.</span></p>
<p></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">I guess my point is this - SharePoint can be a very powerful tool for an organization, but, just because it may not include PCI-relevant data doesn&#8217;t mean that security isn&#8217;t important.<span> </span>SharePoint provides access to data that you typically don&#8217;t want leaving the company and it needs to be considered a potential security risk – not shut down, not curtailed to the point where it’s useless, but it does need to be considered when looking at your security strategy.</span></p>
<p></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">And yes, you certainly can use SharePoint itself to handle user management and access, but don&#8217;t place all your hope in managing users - understand the overall security picture of your SharePoint implementation. <span> </span>It&#8217;s the only way of really understanding the risks involved.</span></p>
<p></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">Interestingly enough, it doesn&#8217;t seem like there are many out in the security community that have really been able to show expertise with SharePoint security assessment and gap analysis - plenty that claim to understand user management, but very few have experience looking at SharePoint security holistically.</span></p>
<p></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">There are a few firms that have developed expertise and proven themselves, but I think the SharePoint user community is currently hard-pressed to find good, independent partners that aren&#8217;t also trying to sell them SharePoint development or hosting services (which I find sorta funny because none of these companies seem to recognize the inherent conflict of interest involved with that model.)</span></p>
<p></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><a id="aptureLink_IFS1hVaNfl" style="margin: 0pt auto; padding: 0px 6px; text-align: center; display: block;" href="http://search.twitter.com/search?q=SharePoint%20security" onclick="javascript:pageTracker._trackPageview('/outbound/article/search.twitter.com');"><img style="border: 0px none;" title="What people are saying about &quot;SharePoint security&quot;" src="http://placeholder.apture.com/ph/370x341_TwitterArticle/" alt="" width="370" height="341" /></a></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.cmswatch.com/Trends/1729-SharePoint-2010-Pros-Cons?source=RSS" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.cmswatch.com');">Eight Pros and Eight Cons to SharePoint 2010</a> (cmswatch.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.cmswatch.com/Trends/1721-SharePoint-Conference-Wrap-Up?source=RSS" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.cmswatch.com');">Closing thoughts on SharePoint Conference</a> (cmswatch.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/b1130427-aa68-41c4-bbc6-149e35d9d4bf/" onclick="javascript:pageTracker._trackPageview('/outbound/article/reblog.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=b1130427-aa68-41c4-bbc6-149e35d9d4bf" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/Mkyrda56gh8" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2009/11/10/sharepoint-and-security-2/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2009/11/10/sharepoint-and-security-2/</feedburner:origLink></item>
		<item>
		<title>Finally…  The PA-DSS Questions Answered</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/MjkDdI80N6Y/</link>
		<comments>http://www.retailinfosec.com/2009/11/05/finally-the-pa-dss-questions-answered/#comments</comments>
		<pubDate>Thu, 05 Nov 2009 17:27:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[application security]]></category>

		<category><![CDATA[headline]]></category>

		<category><![CDATA[PA-DSS]]></category>

		<category><![CDATA[PABP]]></category>

		<category><![CDATA[PADSS]]></category>

		<category><![CDATA[PCI PA-DSS]]></category>

		<category><![CDATA[PCI-DSS]]></category>

		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=349</guid>
		<description><![CDATA[OK - maybe not all of them, but the most common that I&#8217;m hearing anyway&#8230;
After asking you all to give me some questions for PA-DSS, I finally am getting around to posting up some answers.  Some of them are also taken directly from numerous conversations that I have had with software vendors over the last several months and, truthfully, I&#8217;m glad that I waited to put that post together&#8230;It&#8217;s not entirely retail focused, as PA-DSS crosses most industries, but I hope it proves useful in answering some common questions&#8230;
It&#8217;s located ...]]></description>
			<content:encoded><![CDATA[<p>OK - maybe not all of them, but the most common that I&#8217;m hearing anyway&#8230;</p>
<p>After asking you all to give me some questions for PA-DSS, I finally am getting around to posting up some answers.  Some of them are also taken directly from numerous conversations that I have had with software vendors over the last several months and, truthfully, I&#8217;m glad that I waited to put that post together&#8230;It&#8217;s not entirely retail focused, as PA-DSS crosses most industries, but I hope it proves useful in answering some common questions&#8230;</p>
<p>It&#8217;s located over at the NetSPI blog again and you can find it here - <a id="aptureLink_ExGHbNUKhu" href="http://www.netspi.com/blog/2009/11/05/questions-on-pa-dss-from-software-companies-and-straight-answers/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.netspi.com');">PA-DSS Questions</a>.  Still no comments yet on the NetSPI blog (we&#8217;re getting closer) so feel free to leave any commentary here and thanks for taking a look.</p>
<p><a id="aptureLink_qqKBg2FIsO" style="margin: 0pt auto; padding: 0px 6px; text-align: center; display: block;" href="http://search.twitter.com/search?q=PA-DSS" onclick="javascript:pageTracker._trackPageview('/outbound/article/search.twitter.com');"><img style="border: 0px none;" title="What people are saying about &quot;PA-DSS&quot;" src="http://placeholder.apture.com/ph/370x341_TwitterArticle/" alt="" width="370" height="341" /></a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/89e9e177-c854-4662-bb47-5b5e1acdd3e7/" onclick="javascript:pageTracker._trackPageview('/outbound/article/reblog.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=89e9e177-c854-4662-bb47-5b5e1acdd3e7" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/MjkDdI80N6Y" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2009/11/05/finally-the-pa-dss-questions-answered/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2009/11/05/finally-the-pa-dss-questions-answered/</feedburner:origLink></item>
		<item>
		<title>Don’t know what you got, till it’s gone….</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/MUyYByZLTQo/</link>
		<comments>http://www.retailinfosec.com/2009/11/04/dont-know-what-you-got-till-its-gone/#comments</comments>
		<pubDate>Wed, 04 Nov 2009 16:27:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Interesting]]></category>

		<category><![CDATA[Vendors]]></category>

		<category><![CDATA[acquisition]]></category>

		<category><![CDATA[opinion]]></category>

		<category><![CDATA[VeriSign]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/2009/11/04/dont-know-what-you-got-till-its-gone/</guid>
		<description><![CDATA[So everyone knows at this point that AT&#38;T has acquired VeriSign&#8217;s global security consulting business.&#160; I&#8217;m not really sure why AT&#38;T actually bought them although I&#8217;m sure that they have some sort of Grand Plan, much the same way that Verizon had when they acquired Cybertrust and all of the other companies that they bought over the years&#8230;&#160; 
What seems to really happen is that these large firms that don&#8217;t have a focus on security see an opportunity and spend a bunch of money to acquire well-known brands and, far ...]]></description>
			<content:encoded><![CDATA[<p>So everyone knows at this point that AT&amp;T has acquired VeriSign&#8217;s global security consulting business.&nbsp; I&#8217;m not really sure why AT&amp;T actually bought them although I&#8217;m sure that they have some sort of Grand Plan, much the same way that Verizon had when they acquired Cybertrust and all of the other companies that they bought over the years&#8230;&nbsp; </p>
<p>What seems to really happen is that these large firms that don&#8217;t have a focus on security see an opportunity and spend a bunch of money to acquire well-known brands and, far more importantly, the teams of consultants and managers and the processes that have actually made the brand so well-known.&nbsp; The problem is, the companies getting acquired aren&#8217;t really product companies - they are consulting firms.&nbsp; Pretty soon the consultants and business managers start realizing that they are now an afterthought at an organization that doesn&#8217;t really know what the hell to do with them - so they start to leave.&nbsp; </p>
<p>I haven&#8217;t been in the field as long as many and haven&#8217;t seen the various waves of acquisition that have occurred over the years in the security industry, but I have seen enough to believe that AT&amp;T is going to mess up VeriSign.&nbsp; They won&#8217;t be able to help themselves - they&#8217;ll turn the VeriSign consulting organization into an AT&amp;T company - making them an add-on services offering and most of the decent people are going to get very quickly sick of their new-found position as a loss-leading line item in a huge telecommunications contract.</p>
<p>Maybe I&#8217;m wrong and, for the sake of those at VeriSign, I hope that I am, but I won&#8217;t be surprised if there are suddenly a lot of the better VeriSign people rapidly looking to make a change.&nbsp; </p>
<div class="zemanta-pixie"><img class="zemanta-pixie-img" alt="" src="http://img.zemanta.com/pixy.gif?x-id=46ef960f-9200-81cf-ba27-e09b741c3c21" /></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/MUyYByZLTQo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2009/11/04/dont-know-what-you-got-till-its-gone/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2009/11/04/dont-know-what-you-got-till-its-gone/</feedburner:origLink></item>
		<item>
		<title>Beyond the PCI Audit:  Helping Merchants and Service Providers as a Partner</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/Ua-KXqrjvJ8/</link>
		<comments>http://www.retailinfosec.com/2009/10/23/beyond-the-pci-audit-helping-merchants-and-service-providers-as-a-partner/#comments</comments>
		<pubDate>Fri, 23 Oct 2009 18:24:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Conferences / Webinars]]></category>

		<category><![CDATA[PCI Philosophy / Approach]]></category>

		<category><![CDATA[featured]]></category>

		<category><![CDATA[NetSPI]]></category>

		<category><![CDATA[PCI]]></category>

		<category><![CDATA[PCI-DSS]]></category>

		<category><![CDATA[philosophy]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/2009/10/23/beyond-the-pci-audit-helping-merchants-and-service-providers-as-a-partner/</guid>
		<description><![CDATA[OK - this is the feedback on the Community Meeting that I had mentioned although it really turned into a philosophical post about what your PCI partners should really be doing for you (hint: being a partner).
This one&#8217;s over at the NetSPI blog as well (I swear that I&#8217;m still going to be posting over here on a more regular basis, but, since NetSPI&#8217;s doing a good job with the blog, I&#8217;m going to blend my posts between the two blogs&#8230;).  Any feedback is going to have to come here, ...]]></description>
			<content:encoded><![CDATA[<p>OK - this is the feedback on the Community Meeting that I had mentioned although it really turned into a philosophical post about what your PCI partners should really be doing for you (hint: being a partner).</p>
<p>This one&#8217;s over at the NetSPI blog as well (I swear that I&#8217;m still going to be posting over here on a more regular basis, but, since NetSPI&#8217;s doing a good job with the blog, I&#8217;m going to blend my posts between the two blogs&#8230;).  Any feedback is going to have to come here, though.  They still don&#8217;t have the commenting turned on&#8230;</p>
<p><a href="http://www.netspi.com/blog/2009/10/23/beyond-the-pci-audit-helping-merchants-and-service-providers-as-a-partner/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.netspi.com');">Beyond the PCI Audit:  Helping Merchants and Service Providers as a Partner</a></p>
<p>Technorati Tags: <a class="performancingtags" rel="tag" href="http://technorati.com/tag/PCI%20DSS" onclick="javascript:pageTracker._trackPageview('/outbound/article/technorati.com');">PCI DSS</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/PCI" onclick="javascript:pageTracker._trackPageview('/outbound/article/technorati.com');">PCI</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/NetSPI" onclick="javascript:pageTracker._trackPageview('/outbound/article/technorati.com');">NetSPI</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/security" onclick="javascript:pageTracker._trackPageview('/outbound/article/technorati.com');">security</a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/cb9a03e7-f4ea-81c7-b6e5-ebf281c264ad/" onclick="javascript:pageTracker._trackPageview('/outbound/article/reblog.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=cb9a03e7-f4ea-81c7-b6e5-ebf281c264ad" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/Ua-KXqrjvJ8" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2009/10/23/beyond-the-pci-audit-helping-merchants-and-service-providers-as-a-partner/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2009/10/23/beyond-the-pci-audit-helping-merchants-and-service-providers-as-a-partner/</feedburner:origLink></item>
	</channel>
</rss>
