<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Bob Blakely on the Cybersecurity Conversation</title>
	<atom:link href="http://emergentchaos.com/archives/2009/07/bob-blakely-on-the-cybersecurity-conversation.html/feed" rel="self" type="application/rss+xml" />
	<link>http://emergentchaos.com/archives/2009/07/bob-blakely-on-the-cybersecurity-conversation.html</link>
	<description>The Emergent Chaos Jazz Combo</description>
	<lastBuildDate>Wed, 01 Feb 2012 19:20:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Adam</title>
		<link>http://emergentchaos.com/archives/2009/07/bob-blakely-on-the-cybersecurity-conversation.html/comment-page-1#comment-5925</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Wed, 08 Jul 2009 11:48:03 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=3159#comment-5925</guid>
		<description>Bob Blakely--I fully agree there&#039;s chicken and egg.  Which is why we need a conversation which includes a strategic level.
</description>
		<content:encoded><![CDATA[<p>Bob Blakely&#8211;I fully agree there&#8217;s chicken and egg.  Which is why we need a conversation which includes a strategic level.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bob Stratton</title>
		<link>http://emergentchaos.com/archives/2009/07/bob-blakely-on-the-cybersecurity-conversation.html/comment-page-1#comment-5924</link>
		<dc:creator>Bob Stratton</dc:creator>
		<pubDate>Tue, 07 Jul 2009 13:28:37 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=3159#comment-5924</guid>
		<description>The current &quot;information sharing&quot; discussion is directly parallel to the &quot;incident reporting&quot; discussion in which so many of us participated in the late &#039;80s and early &#039;90s. At the time, the legal frameworks were mostly non-existent. In the U.S. people were being charged with wire fraud for computer intrusions, and when I went to Japan in 1998, they told me the best they could do was charge intruders with tying up the phone lines. Very few of my commercial clients wanted to report incidents to authorities. Since then, there is a much better (if admittedly imperfect) legal infrastructure and significantly more savvy attorneys and police.
I think we&#039;re seeing a similar process now. I am witnessing a number of well-intentioned and at least partially functional efforts to bring together vendors, government(s) and sectors to figure out a) what to share, b) what the problems are around sharing it, and c) how to keep the cycle going.
Are some of them influenced by hidebound bureaucracy? Absolutely. Nonetheless, it&#039;s constructive movement. A process, not an event.
I am actually looking forward to the point where some of the trickier issues really come to the fore and force a reevaluation of how governments view multinational commercial entities. We&#039;ve all too often heard the refrain that &quot;the private sector owns and operates ~85% of critical infrastructures.&quot; It may just be my biases, but sometimes I think I hear frustration behind that when I hear it from governments.
I&#039;m hoping (perhaps wistfully) that the process of sharing rather sensitive information on outcomes will engender enough good will that the parties realize that industry isn&#039;t and shouldn&#039;t be government and vice versa.
</description>
		<content:encoded><![CDATA[<p>The current &#8220;information sharing&#8221; discussion is directly parallel to the &#8220;incident reporting&#8221; discussion in which so many of us participated in the late &#8217;80s and early &#8217;90s. At the time, the legal frameworks were mostly non-existent. In the U.S. people were being charged with wire fraud for computer intrusions, and when I went to Japan in 1998, they told me the best they could do was charge intruders with tying up the phone lines. Very few of my commercial clients wanted to report incidents to authorities. Since then, there is a much better (if admittedly imperfect) legal infrastructure and significantly more savvy attorneys and police.<br />
I think we&#8217;re seeing a similar process now. I am witnessing a number of well-intentioned and at least partially functional efforts to bring together vendors, government(s) and sectors to figure out a) what to share, b) what the problems are around sharing it, and c) how to keep the cycle going.<br />
Are some of them influenced by hidebound bureaucracy? Absolutely. Nonetheless, it&#8217;s constructive movement. A process, not an event.<br />
I am actually looking forward to the point where some of the trickier issues really come to the fore and force a reevaluation of how governments view multinational commercial entities. We&#8217;ve all too often heard the refrain that &#8220;the private sector owns and operates ~85% of critical infrastructures.&#8221; It may just be my biases, but sometimes I think I hear frustration behind that when I hear it from governments.<br />
I&#8217;m hoping (perhaps wistfully) that the process of sharing rather sensitive information on outcomes will engender enough good will that the parties realize that industry isn&#8217;t and shouldn&#8217;t be government and vice versa.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bob Blakley</title>
		<link>http://emergentchaos.com/archives/2009/07/bob-blakely-on-the-cybersecurity-conversation.html/comment-page-1#comment-5923</link>
		<dc:creator>Bob Blakley</dc:creator>
		<pubDate>Tue, 07 Jul 2009 12:22:58 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=3159#comment-5923</guid>
		<description>I think we may be confronting chickens and eggs.  California SB 1386&#039;s requirement for breach notification required companies experiencing a data breach to take blame in public.  It was this publicity that started to give us reliable breach information.
</description>
		<content:encoded><![CDATA[<p>I think we may be confronting chickens and eggs.  California SB 1386&#8242;s requirement for breach notification required companies experiencing a data breach to take blame in public.  It was this publicity that started to give us reliable breach information.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

