<?xml version="1.0" encoding="UTF-8"?><rss version="0.92">
<channel>
	<title>ISSCP Security Blog</title>
	<link>http://www.isscp.com/blog</link>
	<description>Network / Information Security Blog</description>
	<lastBuildDate>Wed, 21 Jul 2010 13:26:24 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	<!-- generator="WordPress/3.0" -->

	<item>
		<title>Training, training, training,  Yet NO knowledge</title>
		<description><![CDATA[<p>It is very strange that when you look around you can find many, many training courses and seminars on HIPAA. From a providing information point of view, the market is well provided for.  Yet walk into you local doctor&#8217;s office or local hopsital, and ask a few basic questions and blam, they don&#8217;t know HIPAA [Click to Read more...]]]></description>
		<link>http://www.isscp.com/blog/?p=103</link>
			</item>
	<item>
		<title>Need for multi-talented security team</title>
		<description><![CDATA[<p>Based on the current attack vectors that are taking place, we need defense teams that are multi-talented.</p>
<p>Attacks are no longer simple and scatter gun, like the Nigerian scam. The principle behind this type of attack is launch a hundreds of thousands attacks and hope that just a very few stick. Grammar was poor, yet overall [Click to Read more...]]]></description>
		<link>http://www.isscp.com/blog/?p=92</link>
			</item>
	<item>
		<title>HIPAA Audit steps,  continued</title>
		<description><![CDATA[<p>Previous steps</p>
Step 3 : Risk Assessment
<p>Now we need to consider the threats, both actual and perceived. Identify and discuss them, then list cost-effective solutions. In the solutions identify what is needed and possible methods to implement the solution. After all threats have been identified you might find a single solution that will address more than [Click to Read more...]]]></description>
		<link>http://www.isscp.com/blog/?p=71</link>
			</item>
	<item>
		<title>HIPAA always changing</title>
		<description><![CDATA[<p>One question I love asking coverd entities, &#8220;What and when was the latest change made to HIPAA?&#8221; I ask this for two reasons,    One:  to see what they know and how up to date they are,  and    Two: because HIPAA always changes.     In a previous post I have already indicated the change in 2008 from [Click to Read more...]]]></description>
		<link>http://www.isscp.com/blog/?p=87</link>
			</item>
	<item>
		<title>Steps of a HIPAA audit</title>
		<description><![CDATA[<p>HIPAA audits are just like any audit or project they require the proper steps.</p>
Step 1 : Project Planning
<p>The planning and scoping of a project is often one of the hardest parts of project management. Audits, like a HIPAA audit, are a targeted project with findings or shortcomings as their project deliverables.  If the audit scope [Click to Read more...]]]></description>
		<link>http://www.isscp.com/blog/?p=69</link>
			</item>
	<item>
		<title>RISK Analysis Audit</title>
		<description><![CDATA[<p>Most Security regulations like HIPAA, SOX, GLBA and PCI (which is an industry standard Not a regulation),  all call for a risk analysis audit.  To many this is an unknown or difficult process, so I thought I would present the common goals for a Risk-based Analysis Audit</p>
<p>GOAL 1: The network defined</p>
<p style="padding-left: 30px;">We need to [Click to Read more...]]]></description>
		<link>http://www.isscp.com/blog/?p=51</link>
			</item>
	<item>
		<title>Why can&#8217;t we allow specialists in the IT industry?</title>
		<description><![CDATA[<p>Read an article that just blew me away!</p>
<p>&#8220;An IT auditor may also work a a forensic specialist (cyberforensic) where the objective is usually directed toward potential crimes or nefarious deeds&#8221;</p>
<p>Then let us make lawnmower mechanics,  aviation engineers. Let us have the local lawnmower repair guy service the jet engines to 747s. Obviously we will not!.  [Click to Read more...]]]></description>
		<link>http://www.isscp.com/blog/?p=49</link>
			</item>
	<item>
		<title>Disaster Recovery Planning:  tabletop exercises</title>
		<description><![CDATA[<p>For most medical practitioners the full concept of Disaster Recovery Planning (DRP) is sadly not fully understood.  This often comes from a very weak approach to Risk Management, since the two concepts are very interrelated.  [ By the way: HIPAA does calls for both, Disaster Recovery Plan see 164.308(a)(7)(ii)(B)  and Risk Management see 164.308(a)(1)(ii)(B)  ]</p>
<p>So [Click to Read more...]]]></description>
		<link>http://www.isscp.com/blog/?p=41</link>
			</item>
	<item>
		<title>Complaint Driven Vs Audit Driven</title>
		<description><![CDATA[<p>Complaint Driven Vs. Audit Driven</p>
<p>In October 2008 OIG (Office of Inspector General) conducted an audit of CMS (Centers for Medicare &#38; Medicaid Services) regarding their oversight of HIPAA.  Read the link for more information it is well worthwhile, though for many the impact may be subdued in auditees (auditor speak or lingo).</p>
<p>My summary of the [Click to Read more...]]]></description>
		<link>http://www.isscp.com/blog/?p=30</link>
			</item>
	<item>
		<title>What we DO NOT look out for.</title>
		<description><![CDATA[<p>This was born out of two sequences of events:</p>
<p>(1) Attending the SANS webcast Virtual rountable: featuring Ed Skoudis, Mike Poor, and Hal Pomeranz, the discussion point concerning cyber warfare / cyber attack was raised due to the current activity against South Korean and US government networks.</p>
<p>(2) During the same week I was reading &#8220;The Management [Click to Read more...]]]></description>
		<link>http://www.isscp.com/blog/?p=23</link>
			</item>
	<item>
		<title>The ostrich the great Defender</title>
		<description><![CDATA[The ostrich the great Defender, sorry I mean Pretender.
<p>Why is it that when we have addictive problems, like drugs and alcohol we address the issue by stating you can only get right, once you admit you have a problem.  This is why so many meetings have &#8220;Hi my name is  X, I am [Click to Read more...]]]></description>
		<link>http://www.isscp.com/blog/?p=3</link>
			</item>
	<item>
		<title>System Logs: Nightmare or Treasure trove</title>
		<description><![CDATA[System Logs: Nightmare OR Treasure trove?
<p>Posted: October 03rd 2007</p>
<p>I guess the answer to the question depends on the lorg reader&#8217;s (the human reader) approach, feelings and job function/description. Sadly there are many &#8220;log readers&#8221; that seek the &#8220;instant society approach to completing their duties. They seek systems and applications to read the log files and [Click to Read more...]]]></description>
		<link>http://www.isscp.com/blog/?p=5</link>
			</item>
	<item>
		<title>HIPAA: The Compliance you either Love or hate</title>
		<description><![CDATA[HIPAA: The Compliance you either Love or hate
<p>Posted: August 30th 2007</p>
<p>Of all the Compliance regulations, HIPAA stands out from the rest.</p>

The medical industry, run from it and hate to even hear/read about it.
The Department of Health and Human Services (ones in-charge), do not even strongly enforce it.
&#8220;A complaint driven process&#8221; (exerpt from the law itself). [Click to Read more...]]]></description>
		<link>http://www.isscp.com/blog/?p=6</link>
			</item>
	<item>
		<title>IT Governance, Why run from it</title>
		<description><![CDATA[IT Governance, Why run from it?
<p>Posted: August 29th 2007</p>
<p>It&#8217;s been six years since the 2001 Enron scandal erupted, resulting in Compliance and Governance beguin elevated            today.</p>
<p>Large (Fortune 1000 companies) have had to comply, and to a large degree, are quite willing due to the [Click to Read more...]]]></description>
		<link>http://www.isscp.com/blog/?p=7</link>
			</item>
	<item>
		<title>Why is incident response SO IMPORTANT</title>
		<description><![CDATA[Why is Incident Respons So IMPORTANT?
<p>Posted: August 28th 2007</p>
<p>Incident Response plays a vital role along with  an organization&#8217;s DRP (disaster receovery plan). We must be sure it            is implemented correctly?</p>
<p>Incident Response has a preset structure: Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned.
These steps [Click to Read more...]]]></description>
		<link>http://www.isscp.com/blog/?p=8</link>
			</item>
	<item>
		<title>Why is SAS 70 confused with security</title>
		<description><![CDATA[<p>
Does SAS 70 imply tight security?
Does SAS 70 prove no vulnerabilities?
These questions and more are answered for your understanding.]]></p>
Why is SAS 70 confused with security?
<p>Posted: August 27th 2007</p>
<p>In talking with multiple busines partners, it never ceases to amaze me that there is such a small grasp of         [Click to Read more...]]]></description>
		<link>http://www.isscp.com/blog/?p=9</link>
			</item>
</channel>
</rss>
