<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Pay it forward / Advice for the security admin and manager</title>
	<atom:link href="http://infosecplace.com/blog/2006/08/03/pay-it-forward-advice-for-the-security-admin-and-manager/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosecplace.com/blog/2006/08/03/pay-it-forward-advice-for-the-security-admin-and-manager/</link>
	<description>Commentary on the State of Information Security</description>
	<lastBuildDate>Sun, 10 Jan 2010 16:13:08 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Anton on Security</title>
		<link>http://infosecplace.com/blog/2006/08/03/pay-it-forward-advice-for-the-security-admin-and-manager/comment-page-1/#comment-354</link>
		<dc:creator>Anton on Security</dc:creator>
		<pubDate>Fri, 11 Aug 2006 06:43:45 +0000</pubDate>
		<guid isPermaLink="false">http://infosecplace.com/blog/2006/08/03/pay-it-forward-advice-for-the-security-admin-and-manager/#comment-354</guid>
		<description>&lt;strong&gt;Anton&#039;s Security Tip of the Week #1...&lt;/strong&gt;

Upon seeing folks giving security tips of the day on their blogs (like here, here, here ; SANS jumped in as well), I decided to follow along and join the initiative. One of the bloggers called it &quot;pay it forward&quot;......</description>
		<content:encoded><![CDATA[<p><strong>Anton&#8217;s Security Tip of the Week #1&#8230;</strong></p>
<p>Upon seeing folks giving security tips of the day on their blogs (like here, here, here ; SANS jumped in as well), I decided to follow along and join the initiative. One of the bloggers called it &#8220;pay it forward&#8221;&#8230;&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Washington</title>
		<link>http://infosecplace.com/blog/2006/08/03/pay-it-forward-advice-for-the-security-admin-and-manager/comment-page-1/#comment-326</link>
		<dc:creator>Mark Washington</dc:creator>
		<pubDate>Mon, 07 Aug 2006 14:19:35 +0000</pubDate>
		<guid isPermaLink="false">http://infosecplace.com/blog/2006/08/03/pay-it-forward-advice-for-the-security-admin-and-manager/#comment-326</guid>
		<description>I agree for the most part and I would like to add the following to your due diligence in procedures.  There is a third part and it is enforcement.  You can all the policies and procedures readily available to your user base, however if you do not enforcement that has &quot;teeth&quot; there is really no point on having a policy or procedure unless you are under some type of regulatory compliance.  As an example the VA&#039;s stolen laptop fiasco.  There was a break down in procedures and probably a breakdown on security awareness within the organization.  However there was enforcement (probably because the whole mess went public), one could argue that the enforce was somewhat severe, but regardless it was enforcement.  Due dilgience in policies and procedures is great, but without enforcement what is the point?

Mark</description>
		<content:encoded><![CDATA[<p>I agree for the most part and I would like to add the following to your due diligence in procedures.  There is a third part and it is enforcement.  You can all the policies and procedures readily available to your user base, however if you do not enforcement that has &#8220;teeth&#8221; there is really no point on having a policy or procedure unless you are under some type of regulatory compliance.  As an example the VA&#8217;s stolen laptop fiasco.  There was a break down in procedures and probably a breakdown on security awareness within the organization.  However there was enforcement (probably because the whole mess went public), one could argue that the enforce was somewhat severe, but regardless it was enforcement.  Due dilgience in policies and procedures is great, but without enforcement what is the point?</p>
<p>Mark</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alan Shimel</title>
		<link>http://infosecplace.com/blog/2006/08/03/pay-it-forward-advice-for-the-security-admin-and-manager/comment-page-1/#comment-182</link>
		<dc:creator>Alan Shimel</dc:creator>
		<pubDate>Fri, 04 Aug 2006 05:54:29 +0000</pubDate>
		<guid isPermaLink="false">http://infosecplace.com/blog/2006/08/03/pay-it-forward-advice-for-the-security-admin-and-manager/#comment-182</guid>
		<description>Michael - no offense taken that we are not as big as Cisco or some other shops. We just try harder ;-)  Seriously, I am glad that at least we are calling you and asking for your business!</description>
		<content:encoded><![CDATA[<p>Michael &#8211; no offense taken that we are not as big as Cisco or some other shops. We just try harder <img src='http://infosecplace.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />   Seriously, I am glad that at least we are calling you and asking for your business!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mcwresearch.com &#187; Pay it forward: Know Your Network</title>
		<link>http://infosecplace.com/blog/2006/08/03/pay-it-forward-advice-for-the-security-admin-and-manager/comment-page-1/#comment-175</link>
		<dc:creator>mcwresearch.com &#187; Pay it forward: Know Your Network</dc:creator>
		<pubDate>Thu, 03 Aug 2006 21:32:04 +0000</pubDate>
		<guid isPermaLink="false">http://infosecplace.com/blog/2006/08/03/pay-it-forward-advice-for-the-security-admin-and-manager/#comment-175</guid>
		<description>[...] Michael Farnum at An Information Security Place posted a tip today about due diligence (my post today ties into &#8216;due diligence&#8217; nicely). [...]</description>
		<content:encoded><![CDATA[<p>[...] Michael Farnum at An Information Security Place posted a tip today about due diligence (my post today ties into &#8216;due diligence&#8217; nicely). [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
