<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WSJ needs a smack upside the head</title>
	<atom:link href="http://infosecplace.com/blog/2007/08/02/wsj-needs-a-smack-upside-the-head/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosecplace.com/blog/2007/08/02/wsj-needs-a-smack-upside-the-head/</link>
	<description>Commentary on the State of Information Security</description>
	<lastBuildDate>Thu, 02 Feb 2012 20:22:19 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Wolfgang Leithner</title>
		<link>http://infosecplace.com/blog/2007/08/02/wsj-needs-a-smack-upside-the-head/comment-page-1/#comment-19607</link>
		<dc:creator>Wolfgang Leithner</dc:creator>
		<pubDate>Thu, 09 Aug 2007 12:31:50 +0000</pubDate>
		<guid isPermaLink="false">http://infosecplace.com/blog/2007/08/02/wsj-needs-a-smack-upside-the-head/#comment-19607</guid>
		<description>As a IT Security Consultant for the better part of the last decade I think it largely depends on the basic intelligence of the CEO/CIO/CFO you are talking to.
The smart ones will see the necessity for awareness training while the not so smart ones will make it an &quot;IT only&quot; issue to stay ahead of their users to keep the company safe from harm.

Unfortunately in times of twindling IT resources this is a battle we cannot win and so I personally got *very* scared when I read the article because of all the (mostly unnecessary and tidious) work this will produce, because virtually everyone *will* test all the proposed &#039;workarounds&#039;.

I am not sure if in the long run the posted article will be considered good or harmfull.

BR
Wolfgang</description>
		<content:encoded><![CDATA[<p>As a IT Security Consultant for the better part of the last decade I think it largely depends on the basic intelligence of the CEO/CIO/CFO you are talking to.<br />
The smart ones will see the necessity for awareness training while the not so smart ones will make it an &#8220;IT only&#8221; issue to stay ahead of their users to keep the company safe from harm.</p>
<p>Unfortunately in times of twindling IT resources this is a battle we cannot win and so I personally got *very* scared when I read the article because of all the (mostly unnecessary and tidious) work this will produce, because virtually everyone *will* test all the proposed &#8216;workarounds&#8217;.</p>
<p>I am not sure if in the long run the posted article will be considered good or harmfull.</p>
<p>BR<br />
Wolfgang</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Compliance &#38; Security Connection</title>
		<link>http://infosecplace.com/blog/2007/08/02/wsj-needs-a-smack-upside-the-head/comment-page-1/#comment-19603</link>
		<dc:creator>The Compliance &#38; Security Connection</dc:creator>
		<pubDate>Wed, 08 Aug 2007 17:39:46 +0000</pubDate>
		<guid isPermaLink="false">http://infosecplace.com/blog/2007/08/02/wsj-needs-a-smack-upside-the-head/#comment-19603</guid>
		<description>&lt;strong&gt;Wall Street Journal post Raises Ire of IT Security Pros...&lt;/strong&gt;

The Compliance and Security Connection Home Page A recent Wall Street Journal post by Vauhini Vara, Ten Things Your IT Department Won&#039;t Tell You, provided suggestions for doing an end-around your IT department. As you might expect, the topics centered...</description>
		<content:encoded><![CDATA[<p><strong>Wall Street Journal post Raises Ire of IT Security Pros&#8230;</strong></p>
<p>The Compliance and Security Connection Home Page A recent Wall Street Journal post by Vauhini Vara, Ten Things Your IT Department Won&#8217;t Tell You, provided suggestions for doing an end-around your IT department. As you might expect, the topics centered&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Farnum</title>
		<link>http://infosecplace.com/blog/2007/08/02/wsj-needs-a-smack-upside-the-head/comment-page-1/#comment-19573</link>
		<dc:creator>Michael Farnum</dc:creator>
		<pubDate>Thu, 02 Aug 2007 20:32:57 +0000</pubDate>
		<guid isPermaLink="false">http://infosecplace.com/blog/2007/08/02/wsj-needs-a-smack-upside-the-head/#comment-19573</guid>
		<description>&lt;p&gt;Damn it, Tim!  Stop being so optimistic!  I am trying to spread FUD here! :)&lt;/p&gt;

&lt;p&gt;Actually, very good point&lt;/p&gt;

Michael
</description>
		<content:encoded><![CDATA[<p>Damn it, Tim!  Stop being so optimistic!  I am trying to spread FUD here! <img src='http://infosecplace.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Actually, very good point</p>
<p>Michael</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim Wagner</title>
		<link>http://infosecplace.com/blog/2007/08/02/wsj-needs-a-smack-upside-the-head/comment-page-1/#comment-19572</link>
		<dc:creator>Tim Wagner</dc:creator>
		<pubDate>Thu, 02 Aug 2007 20:16:19 +0000</pubDate>
		<guid isPermaLink="false">http://infosecplace.com/blog/2007/08/02/wsj-needs-a-smack-upside-the-head/#comment-19572</guid>
		<description>Michael,
While I agree this was not a very smart thing to publish, I think it really just gave the security community ammunition. For those of you who focus on Awareness training, this is definitely something I would be bringing to management. The conversation is simple, look we are doing everything we can to protect the company, but then WSJ goes and tells the average user how to overcome our defenses, we really should invest in awareness training so our users understand why NOT to do these things. I&#039;m not sure how a resonable and responsible CEO/CIO/CFO could defend against this. Maybe Santa will chime in on this.

My point, for every idiotic experience in this world, there is an equal opportunity to learn and teach.</description>
		<content:encoded><![CDATA[<p>Michael,<br />
While I agree this was not a very smart thing to publish, I think it really just gave the security community ammunition. For those of you who focus on Awareness training, this is definitely something I would be bringing to management. The conversation is simple, look we are doing everything we can to protect the company, but then WSJ goes and tells the average user how to overcome our defenses, we really should invest in awareness training so our users understand why NOT to do these things. I&#8217;m not sure how a resonable and responsible CEO/CIO/CFO could defend against this. Maybe Santa will chime in on this.</p>
<p>My point, for every idiotic experience in this world, there is an equal opportunity to learn and teach.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

