<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The New School of Information Security</title>
	<atom:link href="http://emergentchaos.com/archives/2008/03/the-new-school-of-information-security.html/feed" rel="self" type="application/rss+xml" />
	<link>http://emergentchaos.com/archives/2008/03/the-new-school-of-information-security.html</link>
	<description>The Emergent Chaos Jazz Combo</description>
	<lastBuildDate>Mon, 15 Mar 2010 15:02:09 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Iang</title>
		<link>http://emergentchaos.com/archives/2008/03/the-new-school-of-information-security.html/comment-page-1#comment-4435</link>
		<dc:creator>Iang</dc:creator>
		<pubDate>Tue, 11 Mar 2008 10:27:02 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2677#comment-4435</guid>
		<description>CJ calls it:  Spam is used for phishing.  If phishing is a threat, then spam must be part of that.
It is true that spam without meaningful content (noise) could be just modelled as a threat to governance of the organisation&#039;s assets (time &amp; attention &amp; budget).  It&#039;s close, but only an estimation;  to say that spam is only noise isn&#039;t sustainable.  Spam has been around since whenever, and its existence is proof of its success.  That success means someone in your organisation might click on it.  Quietly...
So, it&#039;s a threat, but it might still be an acceptable risk.
</description>
		<content:encoded><![CDATA[<p>CJ calls it:  Spam is used for phishing.  If phishing is a threat, then spam must be part of that.<br />
It is true that spam without meaningful content (noise) could be just modelled as a threat to governance of the organisation&#8217;s assets (time &#038; attention &#038; budget).  It&#8217;s close, but only an estimation;  to say that spam is only noise isn&#8217;t sustainable.  Spam has been around since whenever, and its existence is proof of its success.  That success means someone in your organisation might click on it.  Quietly&#8230;<br />
So, it&#8217;s a threat, but it might still be an acceptable risk.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jamsler</title>
		<link>http://emergentchaos.com/archives/2008/03/the-new-school-of-information-security.html/comment-page-1#comment-4434</link>
		<dc:creator>jamsler</dc:creator>
		<pubDate>Tue, 11 Mar 2008 09:33:36 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2677#comment-4434</guid>
		<description>Congratulations!  Looking forward to your always original thinking on the security issue.  Thanks for offering up some basic, practical ideas.
</description>
		<content:encoded><![CDATA[<p>Congratulations!  Looking forward to your always original thinking on the security issue.  Thanks for offering up some basic, practical ideas.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jayskew</title>
		<link>http://emergentchaos.com/archives/2008/03/the-new-school-of-information-security.html/comment-page-1#comment-4433</link>
		<dc:creator>jayskew</dc:creator>
		<pubDate>Mon, 10 Mar 2008 11:17:59 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2677#comment-4433</guid>
		<description>Arbitrary lines between job descriptions that permit some of them to ignore a problem like spam that has effects across all of them and has made many people completely abandon electronic mail seems to me part of the problem.
</description>
		<content:encoded><![CDATA[<p>Arbitrary lines between job descriptions that permit some of them to ignore a problem like spam that has effects across all of them and has made many people completely abandon electronic mail seems to me part of the problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://emergentchaos.com/archives/2008/03/the-new-school-of-information-security.html/comment-page-1#comment-4432</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Mon, 10 Mar 2008 11:07:38 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2677#comment-4432</guid>
		<description>I don&#039;t really want to rathole on the question of &quot;is spam an issue,&quot; but spam affects availability and integrity of email service, by overwhelming systems, and requiring filters, which are imperfect.
</description>
		<content:encoded><![CDATA[<p>I don&#8217;t really want to rathole on the question of &#8220;is spam an issue,&#8221; but spam affects availability and integrity of email service, by overwhelming systems, and requiring filters, which are imperfect.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CJ</title>
		<link>http://emergentchaos.com/archives/2008/03/the-new-school-of-information-security.html/comment-page-1#comment-4431</link>
		<dc:creator>CJ</dc:creator>
		<pubDate>Mon, 10 Mar 2008 10:23:00 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2677#comment-4431</guid>
		<description>&quot;In any field of the security arena, should something be considered an issue if it isn&#039;t a threat? Aren&#039;t the issues security is supposed to manage all threats?&quot;
Surely it must.  It lowers the bar for targeted phishing lures, which can enable all sorts of badness targeting your information, or in my case, critical infrastructure.
Dealing with the spam problem isn&#039;t that hard - just politically damning in today&#039;s environment.  Case in point, walk into any bank with a ski mask and watch what happens.
</description>
		<content:encoded><![CDATA[<p>&#8220;In any field of the security arena, should something be considered an issue if it isn&#8217;t a threat? Aren&#8217;t the issues security is supposed to manage all threats?&#8221;<br />
Surely it must.  It lowers the bar for targeted phishing lures, which can enable all sorts of badness targeting your information, or in my case, critical infrastructure.<br />
Dealing with the spam problem isn&#8217;t that hard &#8211; just politically damning in today&#8217;s environment.  Case in point, walk into any bank with a ski mask and watch what happens.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pedro</title>
		<link>http://emergentchaos.com/archives/2008/03/the-new-school-of-information-security.html/comment-page-1#comment-4430</link>
		<dc:creator>Pedro</dc:creator>
		<pubDate>Mon, 10 Mar 2008 09:50:17 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2677#comment-4430</guid>
		<description>I&#039;m planning to buy the book, it should be a good read. This is one of only two or three &#039;blogs&#039; I visit and I respect the authors.
It just irritates me when I read references to spam (and such like) in InfoSec publications when it hasn&#039;t anything to do with InfoSec.  I reckon we&#039;d make much better progress towards ITSec and InfoSec if the IT/ITSec/InfoSec/CorpGov industires could sort our their nomenclature and focus on tackling problems within their remit.
In any field of the security arena, should something be considered an issue if it isn&#039;t a threat?  Aren&#039;t the issues security is supposed to manage all threats?
</description>
		<content:encoded><![CDATA[<p>I&#8217;m planning to buy the book, it should be a good read. This is one of only two or three &#8216;blogs&#8217; I visit and I respect the authors.<br />
It just irritates me when I read references to spam (and such like) in InfoSec publications when it hasn&#8217;t anything to do with InfoSec.  I reckon we&#8217;d make much better progress towards ITSec and InfoSec if the IT/ITSec/InfoSec/CorpGov industires could sort our their nomenclature and focus on tackling problems within their remit.<br />
In any field of the security arena, should something be considered an issue if it isn&#8217;t a threat?  Aren&#8217;t the issues security is supposed to manage all threats?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: janice</title>
		<link>http://emergentchaos.com/archives/2008/03/the-new-school-of-information-security.html/comment-page-1#comment-4429</link>
		<dc:creator>janice</dc:creator>
		<pubDate>Mon, 10 Mar 2008 09:35:49 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2677#comment-4429</guid>
		<description>Can&#039;t wait for it to hit &#039;available&#039; status at bookstores here in Canada.  Congratulations, Adam!
</description>
		<content:encoded><![CDATA[<p>Can&#8217;t wait for it to hit &#8216;available&#8217; status at bookstores here in Canada.  Congratulations, Adam!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rob sama</title>
		<link>http://emergentchaos.com/archives/2008/03/the-new-school-of-information-security.html/comment-page-1#comment-4428</link>
		<dc:creator>rob sama</dc:creator>
		<pubDate>Mon, 10 Mar 2008 08:54:13 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2677#comment-4428</guid>
		<description>Thank you for the clarification, Napoleon Dynamite&#039;s friend.
Congratulations Adam (and Andrew)!
</description>
		<content:encoded><![CDATA[<p>Thank you for the clarification, Napoleon Dynamite&#8217;s friend.<br />
Congratulations Adam (and Andrew)!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Perplexed</title>
		<link>http://emergentchaos.com/archives/2008/03/the-new-school-of-information-security.html/comment-page-1#comment-4427</link>
		<dc:creator>Perplexed</dc:creator>
		<pubDate>Mon, 10 Mar 2008 08:53:41 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2677#comment-4427</guid>
		<description>Pedro - it says &quot;issue&quot; not &quot;threat&quot;.  Perhaps you should buy the book and see what it says before passing judgement :-)
</description>
		<content:encoded><![CDATA[<p>Pedro &#8211; it says &#8220;issue&#8221; not &#8220;threat&#8221;.  Perhaps you should buy the book and see what it says before passing judgement :-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pedro</title>
		<link>http://emergentchaos.com/archives/2008/03/the-new-school-of-information-security.html/comment-page-1#comment-4426</link>
		<dc:creator>Pedro</dc:creator>
		<pubDate>Mon, 10 Mar 2008 06:37:57 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2677#comment-4426</guid>
		<description>&quot;We start with a look at some persistent issues like spam and identity theft. From there, we look at why the information security industry hasn&#039;t just fixed them&quot;
Spam doesn&#039;t represent a threat to an organisation&#039;s information assets - it&#039;s merely an annoyance to the workforce and a drain on IT resources.  Statements like this only perpetuate the muddled line of thinking that confuses Information security with IT Security (hint: they&#039;re different!).
</description>
		<content:encoded><![CDATA[<p>&#8220;We start with a look at some persistent issues like spam and identity theft. From there, we look at why the information security industry hasn&#8217;t just fixed them&#8221;<br />
Spam doesn&#8217;t represent a threat to an organisation&#8217;s information assets &#8211; it&#8217;s merely an annoyance to the workforce and a drain on IT resources.  Statements like this only perpetuate the muddled line of thinking that confuses Information security with IT Security (hint: they&#8217;re different!).</p>
]]></content:encoded>
	</item>
</channel>
</rss>
