<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-2397196717839865841.post6427134842514179130..comments</id><updated>2010-05-22T23:23:14.870+10:00</updated><category term='career advice'/><category term='australian information security market'/><category term='economics'/><category term='AISA'/><category term='FUD'/><category term='sacred cows'/><category term='webappsec'/><category term='vulnerability management'/><category term='IPS'/><category term='security patching'/><category term='futurism'/><category term='DoS'/><category term='causes'/><category term='privacy'/><category term='information security governance'/><title type='text'>Comments on Infamous Agenda: Best bang for buck security initiatives</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.infamousagenda.com/feeds/6427134842514179130/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2397196717839865841/6427134842514179130/comments/default'/><link rel='alternate' type='text/html' href='http://www.infamousagenda.com/2010/05/best-bang-for-buck-security-initiatives.html'/><author><name>Matthew Hackling</name><uri>http://www.blogger.com/profile/12211732838162218259</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2397196717839865841.post-2065822361515077219</id><published>2010-05-22T23:23:14.860+10:00</published><updated>2010-05-22T23:23:14.860+10:00</updated><title type='text'>I had touched on this in an OWASP talk. In short, ...</title><content type='html'>I had touched on this in an OWASP talk. In short, developer training works, user training doesn&amp;#39;t. Not that it shouldn&amp;#39;t be done but I wouldn&amp;#39;t invest a huge chunk of time.&lt;br /&gt;&lt;br /&gt;There&amp;#39;s a lot of stuff out there in terms of scoring visible impressions on the board - I defer to stuff like the Pragmatic EA ( see &lt;a href="http://www.enterprisearchitectureblog.com/labels/Enterprise%20Architecture%20program%20credibility.html" rel="nofollow"&gt;here&lt;/a&gt;). EAs have been at this for longer, or at least better experience than most security architects IMHO.&lt;br /&gt;&lt;br /&gt;Long term, these will add value but in essence, good architects and managers need to chalk up runs on the board and quickly to establish credibility and value otherwise they risk being seen as ineffectual and running things from their &amp;quot;ivory towers&amp;quot;.&lt;br /&gt;&lt;br /&gt;Taking your example, why not take a few of your suggestions that can be done quickly and generate rapid results within the first 30 days? There was an article in CIO magazine ages back that suggested that effective leaders at that level need to have an action plan for generating results fast. Security leaders likewise need to do the same.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2397196717839865841/6427134842514179130/comments/default/2065822361515077219'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2397196717839865841/6427134842514179130/comments/default/2065822361515077219'/><link rel='alternate' type='text/html' href='http://www.infamousagenda.com/2010/05/best-bang-for-buck-security-initiatives.html?showComment=1274534594860#c2065822361515077219' title=''/><author><name>Jarrod</name><uri>http://www.blogger.com/profile/09705073585945953338</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01961497227698185767'/><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.infamousagenda.com/2010/05/best-bang-for-buck-security-initiatives.html' ref='tag:blogger.com,1999:blog-2397196717839865841.post-6427134842514179130' source='http://www.blogger.com/feeds/2397196717839865841/posts/default/6427134842514179130' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1926495770'/></entry><entry><id>tag:blogger.com,1999:blog-2397196717839865841.post-2964571468531315808</id><published>2010-05-20T22:14:34.882+10:00</published><updated>2010-05-20T22:14:34.882+10:00</updated><title type='text'>Is there evidence that we could use to compare the...</title><content type='html'>Is there evidence that we could use to compare the effectiveness of security awareness training to other mitigations?  Is security awareness training objectively the &amp;quot;best bang for the buck&amp;quot;?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2397196717839865841/6427134842514179130/comments/default/2964571468531315808'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2397196717839865841/6427134842514179130/comments/default/2964571468531315808'/><link rel='alternate' type='text/html' href='http://www.infamousagenda.com/2010/05/best-bang-for-buck-security-initiatives.html?showComment=1274357674882#c2964571468531315808' title=''/><author><name>mcw</name><uri>http://mark.c.wallace.pip.verisignlabs.com/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/openid16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.infamousagenda.com/2010/05/best-bang-for-buck-security-initiatives.html' ref='tag:blogger.com,1999:blog-2397196717839865841.post-6427134842514179130' source='http://www.blogger.com/feeds/2397196717839865841/posts/default/6427134842514179130' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-424022553'/></entry></feed>
