<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NovaInfosecPortal.com &#187; 20-security-controls</title>
	<atom:link href="http://www.novainfosecportal.com/tag/20-security-controls/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.novainfosecportal.com</link>
	<description>News, events, &#38; resources for infosec professionals in NoVA, DC, &#38; MD</description>
	<lastBuildDate>Mon, 06 Feb 2012 18:30:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Top 3 NoVA Infosec Blog Posts of the Week</title>
		<link>http://www.novainfosecportal.com/2009/06/22/top-3-nova-infosec-blog-posts-of-the-week-13/</link>
		<comments>http://www.novainfosecportal.com/2009/06/22/top-3-nova-infosec-blog-posts-of-the-week-13/#comments</comments>
		<pubDate>Mon, 22 Jun 2009 14:00:31 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Blogs/Podcasts]]></category>
		<category><![CDATA[20-security-controls]]></category>
		<category><![CDATA[csc]]></category>
		<category><![CDATA[cyberhiker]]></category>
		<category><![CDATA[dc]]></category>
		<category><![CDATA[electricfork]]></category>
		<category><![CDATA[gemini-security]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[infoesc]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[local-bloggers]]></category>
		<category><![CDATA[local-security-bloggers]]></category>
		<category><![CDATA[md]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[sanitizing-webb-apps]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[top-3-nova-bloggers]]></category>
		<category><![CDATA[web-apps]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=1717</guid>
		<description><![CDATA[While posts from local bloggers seemed a little scarce this week (due to Father&#8217;s Day, perhaps?) we still have some awesome posts to feature this week. While we only feature three posts every week, don&#8217;t forget that you can also check out our list of local security bloggers to get even more quality information during the week from the area&#8217;s very best. #3 &#8211; Security as Rhetoric: Do you ever get tired of telling your managers or potential clients that &#8220;security is a process, not a product?&#8221; If so, you&#8217;re not alone, since @electricfork wrote an entire post dedicated to this dilemma. Saying that &#8220;I do not like the expression anymore than any other watered-down talking point that politicians use on an election year,&#8221; @electricfork presents some possible replacements for the often quoted phrase, such as &#8220;security is a characteristic&#8221; and &#8220;security is a system of combined systems.&#8221; If you&#8217;ve got your own idea of what phrase to use instead of &#8220;security is a process, not a product,&#8221; or think that the phrase should stay in common security jargon, be sure to read the post and add to the discussion. #2 &#8211; Why CSC Fails: For those of you who [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Top+3+NoVA+Infosec+Blog+Posts+of+the+Week+http%3A%2F%2Fj.mp%2Foyo3jS" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2009/06/22/top-3-nova-infosec-blog-posts-of-the-week-13/&amp;t=Top+3+NoVA+Infosec+Blog+Posts+of+the+Week" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p>While posts from local bloggers seemed a little scarce this week (due to Father&#8217;s Day, perhaps?) we still have some awesome posts to feature this week.</p>
<p>While we only feature three posts every week, don&#8217;t forget that you can also check out our <a href="http://www.novainfosecportal.com/resources/infosec-blogs-podcasts/">list</a> of local security bloggers to get even more quality information during the week from the area&#8217;s very best.</p>
<p><strong>#3 &#8211; Security as Rhetoric</strong>: Do you ever get tired of telling your managers or potential clients that &#8220;security is a process, not a product?&#8221; If so, you&#8217;re not alone, since <a href="http://www.twitter.com/electricfork">@electricfork</a> wrote an entire post dedicated to this dilemma. Saying that &#8220;I do not like the expression anymore than any other watered-down talking point that politicians use on an election year,&#8221; @electricfork presents some possible replacements for the often quoted phrase, such as &#8220;security is a characteristic&#8221; and &#8220;security is a system of combined systems.&#8221; If you&#8217;ve got your own idea of what phrase to use instead of &#8220;security is a process, not a product,&#8221; or think that the phrase should stay in common security jargon, be sure to <a href="http://electricfork.com/blog/115/talking-points">read the post</a> and add to the discussion.<span id="more-1717"></span></p>
<p><strong>#2 &#8211; Why CSC Fails</strong>: For those of you who have read the <a href="http://www.sans.org/cag/">20 Critical Security Controls</a> list that was released in May, chances are that <a href="http://www.twitter.com/cyberhiker">@cyberhiker</a> is preaching to the choir when he shares some of his concerns about CSC in his latest post &#8220;Disturbing Trend.&#8221; In his post, @cyberhiker has this to say about CSC: &#8220;So where is the part about laying down a strategy or developing an initial policy that needs to be followed[?]&#8221; He goes on to note that CSC doesn&#8217;t seem to be concerned with system-specific risk analysis anymore, and has relegated the security process down to a &#8216;top 20&#8242; list, with managers being most focused on numbers 1-20, and relatively unconcerned with risks that fall outside the list. To hear more of what @cyberhiker has to say, you can read the full post <a href="http://howisthatassuranceevidence.blogspot.com/2009/06/disturbing-trend.html">here</a>.</p>
<p><strong>#1 &#8211; Sanitize Those Web Apps</strong>: The first blog post in what will be (we hope) a fairly long series, <a href="http://www.twitter.com/geminisecurity">@geminisecurity</a> discusses the often overlooked topic of cleaning up web apps. Writing that &#8220;[c]leaning such data is vitally important in maintaining the security of a website or web application,&#8221; @geminisecurity offers some helpful tips on how to keep your web apps squeaky clean. Since we&#8217;re running out of clever euphemisms for keeping things clean, we&#8217;ll just let you read the <a href="http://securitymusings.com/article/1139/sanitizing-input-in-web-apps-part-1">post</a> for yourself.</p>
<p>Well, that’s all for this week. Be sure to follow me <a href="http://www.twitter.com/grecs">@grecs</a> during the week for more great posts from local bloggers. And a happy belated Father&#8217;s Day to all of you Dads out there!</p>
<p style="text-align: center;">o o o o o</p>
<p style="text-align: center;"><em>Speaking of great local bloggers… we’re looking for some great guest bloggers to feature on NovaInfosecPortal. If you’re interested, feel free to <a href="../contact-us/">contact us</a> or <a href="http://www.twitter.com/grecs">send us a tweet</a>. </em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Top+3+NoVA+Infosec+Blog+Posts+of+the+Week+http%3A%2F%2Fj.mp%2Foyo3jS" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2009/06/22/top-3-nova-infosec-blog-posts-of-the-week-13/&amp;t=Top+3+NoVA+Infosec+Blog+Posts+of+the+Week" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2009/06/22/top-3-nova-infosec-blog-posts-of-the-week-13/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

