<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Network View &#187; IT Audit</title>
	<atom:link href="http://www.anuesystems.com/blog/category/it-audit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anuesystems.com/blog</link>
	<description></description>
	<lastBuildDate>Thu, 15 Jul 2010 15:30:09 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Security Pros on Twitter (SPoT): Michael R. Farnum / @m1a1vet</title>
		<link>http://www.anuesystems.com/blog/2009/09/22/security-pros-on-twitter-spot-michael-r-farnum-m1a1vet/</link>
		<comments>http://www.anuesystems.com/blog/2009/09/22/security-pros-on-twitter-spot-michael-r-farnum-m1a1vet/#comments</comments>
		<pubDate>Tue, 22 Sep 2009 15:54:08 +0000</pubDate>
		<dc:creator>Tommy P. Landry</dc:creator>
				<category><![CDATA[Anue Systems]]></category>
		<category><![CDATA[IT Audit]]></category>
		<category><![CDATA[Infrastructure Security]]></category>
		<category><![CDATA[Monitoring Optimization]]></category>
		<category><![CDATA[Network Monitoring]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Networking Protocols]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[@beaker]]></category>
		<category><![CDATA[an information security place]]></category>
		<category><![CDATA[Blackhat]]></category>
		<category><![CDATA[chris]]></category>
		<category><![CDATA[Christofer Hoff]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[Defcon]]></category>
		<category><![CDATA[dlp]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[heartland]]></category>
		<category><![CDATA[jabba the hutt]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[m1a1vet]]></category>
		<category><![CDATA[naisg]]></category>
		<category><![CDATA[pci]]></category>
		<category><![CDATA[podcast]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[robert carr]]></category>
		<category><![CDATA[rsa conference]]></category>
		<category><![CDATA[social network]]></category>
		<category><![CDATA[trisc]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[visio]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[youtube]]></category>

		<guid isPermaLink="false">http://www.anuesystems.com/blog/?p=365</guid>
		<description><![CDATA[Welcome to today's entry in the ongoing SPoT series. Today, we are covering someone who serves a different role in security, Michael R. Farnum, who is a Pre-Sales Security Engineer for a VAR / Consulting company. Most of our SPoTs to date have been client-side practitioners, but that is most certainly not a requirement to be considered a "Security Pro". Mr. Farnum is also known for his role in An Information Security Place, a blog which offers insightful security podcasts a minimum of once each month. The podcast discusses a range of topics, including hacking, security breaches, PCI, vulnerabilities, security/compliance audits, and cybersecurity.]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 223px"><img class="    " title="SPoT: Michael R. Farnum / @m1a1vet" src="http://www.anuesystems.com/blog/MICHAEL.JPG" alt="SPoT: Michael R. Farnum / @m1a1vet" width="213" height="298" /><p class="wp-caption-text">SPoT: Michael R. Farnum / @m1a1vet</p></div>
<p>Welcome to today&#8217;s entry in the ongoing SPoT series. Today, we are covering someone who serves a different role in <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a>, <a title="Twitter: Michael R. Farnum" href="http://twitter.com/m1a1vet" target="_blank">Michael R. Farnum</a>, who is a Pre-Sales <a title="Security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">Security</a> Engineer for a VAR / Consulting company. Most of our SPoTs to date have been client-side practitioners, but that is most certainly not a requirement to be considered a &#8220;<a title="Security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">Security</a> Pro&#8221;. Mr. Farnum is also known for his role in <a title="An Information Security Place Blog" href="http://infosecplace.com/blog/" target="_blank">An Information Security Place</a>, a blog which offers insightful <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> podcasts a minimum of once each month. The podcast discusses a range of topics, including hacking, <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> breaches, PCI, vulnerabilities, <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a>/compliance audits, and cybersecurity.</p>
<p><strong>Real Name: </strong>Michael Farnum<br />
<strong>Twitter Handle: </strong><a title="Twitter: Michael R. Farnum" href="http://twitter.com/m1a1vet" target="_blank">@m1a1vet</a><br />
<strong>Top 3 Social Media/Networking Sites: </strong><br />
<a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a>, <a title="LinkedIn" href="http://www.linkedin.com/" target="_blank">LinkedIn</a>, <a title="YouTube" href="http://www.youtube.com/" target="_blank">YouTube</a></p>
<p><em><strong>1. In which area(s) of <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> are you most involved?</strong></em><br />
Because I am a pre-sales <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> engineer for a <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> consultant / VAR, I tend to have my fingers in a lot of <a title="Security Pie" href="http://securitypie.com/" target="_blank">pies</a>.  I talk to clients about <a title="How to Begin IT Risk Management" href="http://www.eweek.com/c/a/Security/How-to-Begin-IT-Risk-Management-Five-Steps-to-Getting-What-You-Want/" target="_blank">risk</a>, <a title="Regulatory Compliance" href="http://en.wikipedia.org/wiki/Regulatory_compliance" target="_blank">compliance</a>, and <a title="IT Security Assessment" href="http://en.wikipedia.org/wiki/Information_Technology_Security_Assessment" target="_blank">security assessments</a>.  I also talk to them about <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> technologies to  fill the gaps found when doing a <a title="Perform a gap analysis of security" href="http://articles.techrepublic.com.com/5100-10878_11-5875322.html" target="_blank">gap analysis</a> or <a title="IT Security Assessment" href="http://en.wikipedia.org/wiki/Information_Technology_Security_Assessment" target="_blank">assessment</a>.  I have to keep pretty current in those areas as best I can [to] find opportunities to help my clients.  I also podcast about <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> quite a bit (since Twitter and work has pushed down my blogging volume).<br />
<em><strong><br />
2. What <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> topics will be the most important in the next 18 months? Why?</strong></em><br />
I think more and more disillusionment with <a title="PCI Data Security Standard" href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank">PCI</a> will really begin to cause the <a title="PCI Security Standards Council" href="https://www.pcisecuritystandards.org/" target="_blank">PCI Security Standards Council</a> headaches.  I believe you are going to see some big push back on PCI DSS by companies of all sizes, as more and more money has to be spent on keeping &#8220;compliant&#8221;.  Though I have had major issues with <a title="Heartland CEO on Data Breaches" href="http://www.csoonline.com/article/499527/Heartland_CEO_on_Data_Breach_QSAs_Let_Us_Down" target="_blank">Robert Carr, CEO of Heartland Payment Systems</a>, in his recent interviews, I believe the auditing process has really come under fire lately and will continue to do so.  It is a broken model.</p>
<p>Of course, <a title="Wikipedia: Cloud Computing" href="http://en.wikipedia.org/wiki/Cloud_computing" target="_blank">cloud computing</a> will continue to move up and up in everyone&#8217;s mind, in both infrastructure and, necessarily, <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a>.  Even if the economy improves, I believe this is a train [on which] more and more companies will jump, to varying degrees.  And specific to compliance, if cloud providers can start showing that compliance headaches can at least be eased by the Cloud, then it will grow even more.  I know that is a <em>huge</em> question, but if they can at least make CEOs and CIOs believe it, the Cloud will grow.  I don&#8217;t like it, but there it is.<br />
<em><strong><br />
3. Biggest Pet Peeve: Name one thing about Network <a title="Security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">Security</a> that you wish business stakeholders would understand and why.</strong></em><br />
Let me change the focus of this question.  I think the failure to secure one&#8217;s business infrastructure is a failure of basic responsibility.  This is not just a business stakeholder issue, because <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> is not <em>just</em> about the ability of the business to turn a profit.  Of course, <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> is a driver for profit if done right and applied correctly.  But if the economy as a whole has major issues, then that business and every other business will begin to feel pain.</p>
<p>Here is what I mean.  Good <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> measures contribute to the whole economy.  Just like businesses often become a part of their neighborhood or the community as a whole by contributing money and resources for good causes, those businesses should also contribute resources to the <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> of the Internet as good Internet citizens.  They <em>must</em> look at how their <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> posture affects the whole of the Internet.  The Internet is, obviously, a <em>huge</em> part of the economy.  When a company becomes a cesspool of malware, they become a hindrance and a detriment to that economy.  Business over the Internet is not going to stop, but I wonder how much better it could be if even one third of businesses would clean themselves up.<br />
<em><strong><br />
4. Tell us why you became so active on Twitter and any other important social media outlets. What value are you getting?</strong></em><br />
<a title="Twitter: Michael R. Farnum" href="http://twitter.com/m1a1vet" target="_blank">Twitter</a> started out simply an outlet for my way of thinking.  I am a &#8220;<a title="Wikipedia: Snippet" href="http://en.wikipedia.org/wiki/Snippet" target="_blank">snippet</a>&#8221; thinker.  I am a <a title="Quipper Definition" href="http://www.lexic.us/definition-of/quipper" target="_blank">quipper</a>, if that is a word.  I used to blog a lot, and I felt that I always needed to expand on my thoughts when I blogged.  But I often simply wanted to kick out a thought and just forget about it, or at least save it for later.  Twitter gave me a way to do that without feeling &#8220;guilty&#8221; for not expounding.  I sometimes get into trouble via Twitter, but that is because I sometimes <a title="Quip" href="http://www.merriam-webster.com/dictionary/quip" target="_blank">quip</a> without thinking first.  There are a <em>lot</em> of people doing research on various subjects and products via Twitter, so I have to be careful.</p>
<p>That same dimension of Twitter is what makes it so valuable.  So many people are giving their &#8220;<a title="Two-Cent's Worth" href="http://www.phrases.org.uk/meanings/393950.html" target="_blank">two-cent&#8217;s worth</a>,&#8221; that I can literally come up with ideas on <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> which would never have naturally occurred to me without the inspiration from some Infosec Twit.  It gives me options to take to clients.<br />
<em><strong><br />
5. Name one <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> peer whom everyone with an interest in Network <a title="Security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">Security</a> should follow. (Okay to name two if you can&#8217;t decide on only one)</strong></em><br />
Without a doubt, Chris Hoff (<a title="Twitter: Christofer Hoff" href="http://twitter.com/beaker" target="_blank">@beaker</a>) is on of the top on my list.  His insights into <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> continue to astound me.  He is always on the forefront of <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> ideas, and his spectacular imagination makes his method of dispersal of those ideas entertaining.<br />
<em><strong><br />
6. What&#8217;s your take on <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> for social media and cloud services in general? Top concerns, overstated issues, etc.</strong></em></p>
<div class="wp-caption alignright" style="width: 301px"><img class="  " title="Jabba the Hut" src="http://sunbulli.com/wp-content/uploads/2007/04/jabba.jpg" alt="Jabba the Hut" width="291" height="315" /><p class="wp-caption-text">The Cloud: A Modern-day Jabba the Hut?</p></div>
<p>As stated above, cloud services make me nervous.  I used to trust that &#8220;blob&#8221; out there where all my lines seem to terminate in the <a title="Microsoft Visio" href="http://office.microsoft.com/en-us/visio/default.aspx" target="_blank">Visio</a> drawing.  But now that cloud providers want to get all my data floating out there, that trust has diminished quite a bit.  I just don&#8217;t see the same enterprise that is buying <a title="Wikipedia: Data Loss Prevention" href="http://en.wikipedia.org/wiki/Data_Loss_Prevention" target="_blank">DLP</a> letting all their data go into this mass that looks more and more like <a title="Jabba the Hutt" href="http://www.starwars.com/databank/character/jabbathehutt/" target="_blank">Jabba the Hutt</a> everyday.</p>
<p><a title="Wikipedia: Social Media" href="http://en.wikipedia.org/wiki/Social_media" target="_blank">Social media</a> is going to grow and grow and grow.  I can&#8217;t go a day without hearing about another <a title="Wikipedia: Social Network" href="http://en.wikipedia.org/wiki/Social_network" target="_blank">social network</a>.  I don&#8217;t think it is a fad.  But it will continue to cause great <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> fears for me.  I no longer have a <a title="Facebook" href="http://www.facebook.com/" target="_blank">Facebook</a> account, because I just got sucked into it so quickly that I was not guarding my content very well.  Yes, I only allowed certain people to see my page,  but the temptation to let more and more people see it was getting out of control.  That is why it never ceases to amaze me how so many <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> folks have Facebook pages and are on other social media sites.  I don&#8217;t fault them.  if they weigh the risk and deem it appropriate, then more power to &#8216;em.  But I know my propensities, so I had to stop myself.  If you are an infosec professional, then you have to look <em>very</em> closely to see if those types of sites are good for you [or not].<br />
<em><strong><br />
7. What are the top 3 real-world (i.e. live) events you&#8217;d recommend for networking with <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> professionals?</strong></em></p>
<ul>
<li>I am more and more into local user groups and conferences.  I have attended <a title="TRISC" href="http://www.trisc.org/" target="_blank">TRISC</a> here in Texas, and I attend local <a title="ISSA" href="https://www.issa.org/" target="_blank">ISSA</a> meetings.  I am also looking to start up a local Houston <a title="NAISG" href="http://www.naisg.org/" target="_blank">NAISG</a> chapter.  That kind of event appeals to me.</li>
<li> The <a title="RSA Conference" href="http://www.rsaconference.com/index.htm" target="_blank">RSA Conference</a> is something I attend more for the socializing aspect (<a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> bloggers gathering).</li>
<li><a title="Blackhat" href="http://www.blackhat.com/" target="_blank">BlackHat</a>/<a title="Defcon" href="http://www.defcon.org/" target="_blank">Defcon</a> are a must if you want to rub elbows with the geekier group.</li>
</ul>
<p class="bookmark-me">
    <script type="text/javascript">
	    yahooBuzzArticleHeadline = "<a title="Security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">Security</a> Pros on Twitter (SPoT): Michael R. Farnum / @m1a1vet";
	    yahooBuzzArticleId = "http://www.anuesystems.com/blog/2009/09/22/<a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a>-pros-on-twitter-spot-michael-r-farnum-m1a1vet/";
    </script>
    <script type="text/javascript"
        src="http://d.yimg.com/ds/badge2.js"
        badgetype="logo">
    </script>    
    <a title="technorati.com" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/technorati.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="del.icio.us" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Michael+R.+Farnum+%2F+%40m1a1vet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/delicious.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="stumbleupon.com" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Michael+R.+Farnum+%2F+%40m1a1vet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/stumbleupon.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="digg.com" href="http://digg.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Michael+R.+Farnum+%2F+%40m1a1vet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/digg.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.facebook.com" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Michael+R.+Farnum+%2F+%40m1a1vet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/facebook.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="bookmarks.yahoo.com" href="http://bookmarks.yahoo.com/toolbar/savebm?opener=tb&amp;u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoo.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.google.com" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Michael+R.+Farnum+%2F+%40m1a1vet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/google.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="furl.com" href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Michael+R.+Farnum+%2F+%40m1a1vet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/furl.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="reddit.com" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Michael+R.+Farnum+%2F+%40m1a1vet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/reddit.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="propeller.com" href="http://www.propeller.com/submit/?U=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F&amp;T=Security+Pros+on+Twitter+%28SPoT%29%3A+Michael+R.+Farnum+%2F+%40m1a1vet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/propeller.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="windowslive.com" href="https://favorites.live.com/quickadd.aspx?mkt=en-us&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/windowslive.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="myweb2.search.yahoo.com" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoomyweb.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="linkedin.com" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Michael+R.+Farnum+%2F+%40m1a1vet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/linkedin.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="twitthis.com" href="http://twitthis.com/twit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Michael+R.+Farnum+%2F+%40m1a1vet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/twitter.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.anuesystems.com/blog/2009/09/22/security-pros-on-twitter-spot-michael-r-farnum-m1a1vet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Pros on Twitter (SPoT): Jeff Kirsch/@GhostNomad</title>
		<link>http://www.anuesystems.com/blog/2009/09/03/security-pros-on-twitter-spot-jeff-kirschghostnomad/</link>
		<comments>http://www.anuesystems.com/blog/2009/09/03/security-pros-on-twitter-spot-jeff-kirschghostnomad/#comments</comments>
		<pubDate>Thu, 03 Sep 2009 13:55:31 +0000</pubDate>
		<dc:creator>Tommy P. Landry</dc:creator>
				<category><![CDATA[IT Audit]]></category>
		<category><![CDATA[Monitoring Optimization]]></category>
		<category><![CDATA[Network Monitoring]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[@beaker]]></category>
		<category><![CDATA[@jack_daniel]]></category>
		<category><![CDATA[Christofer Hoff]]></category>
		<category><![CDATA[cisa]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[Defcon]]></category>
		<category><![CDATA[digital identity]]></category>
		<category><![CDATA[ghostnomad]]></category>
		<category><![CDATA[information security summit]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[infrastructure]]></category>
		<category><![CDATA[it auditor]]></category>
		<category><![CDATA[it risk]]></category>
		<category><![CDATA[jack daniel]]></category>
		<category><![CDATA[jeff kirsch]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[pauldotcom]]></category>
		<category><![CDATA[securitycatalyst]]></category>
		<category><![CDATA[Shmoocon]]></category>
		<category><![CDATA[the security catalyst]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.anuesystems.com/blog/?p=336</guid>
		<description><![CDATA[We hope you enjoyed our previous interview with Jack Daniel. We've profiled some heavy hitters and thought leaders in the Security Scene, but there are a range of security professionals on Twitter with something interesting and important to say. In an effort to share a well-rounded range of SPs, today we turn our attention to a gentleman who caught our attention early in our tenure in the Twitter-sphere: Jeff Kirsch (a.k.a. @ghostnomad).]]></description>
			<content:encoded><![CDATA[<p>We hope you enjoyed our<a title="The Network View: Security Pros on Twitter (SPoT): Jack Daniel/@jack_daniel" href="http://www.anuesystems.com/blog/2009/08/26/security-pros-on-twitter-spot-jack-danieljack_daniel/" target="_blank"> previous interview with Jack Daniel</a>. We&#8217;ve profiled some heavy hitters and thought leaders in the <a title="Security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">Security</a> Scene, but there are a range of <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> professionals on Twitter with something interesting and important to say. In an effort to share a well-rounded range of SPs, today we turn our attention to a gentleman who caught our attention early in our tenure in the Twitter-sphere: Jeff Kirsch (a.k.a. @ghostnomad).</p>
<div class="wp-caption alignright" style="width: 234px"><img class=" " title="SPoT: Jeff Kirsch / @ghostnomad" src="http://www.anuesystems.com/blog/Imaage001-3x.JPG" alt="SPoT: Jeff Kirsch / @ghostnomad" width="224" height="252" /><p class="wp-caption-text">SPoT: Jeff Kirsch / @ghostnomad</p></div>
<p>Jeff describes himself as &#8220;<span><em>Infosec geek, IT risk (yes I am a risk), <a title="CISA" href="http://www.isaca.org/Template.cfm?Section=CISA_Certification&amp;Template=/TaggedPage/TaggedPageDisplay.cfm&amp;TPLID=16&amp;ContentID=4526" target="_blank">CISA</a>, husband and father</em>&#8220;. As you can tell from his bio, he offers a a nice blend of professional and personal information, with a little fun thrown in, which is precisely what you&#8217;ll find in his tweets. Jeff personifies what many of us hope to find on Twitter: &#8220;real, interesting, and engaging people.&#8221;<br />
</span></p>
<p><strong>Real Name: </strong>Jeff Kirsch<br />
<strong>Twitter Handle: </strong><a title="Twitter: Jeff Kirsch" href="http://twitter.com/ghostnomad" target="_blank">ghostnomad </a><br />
<strong>Top 3 Social Media/Networking Sites: </strong><br />
<a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a>, <a title="LinkedIn" href="http://www.linkedin.com/" target="_blank">Linkedin</a>, <a title="The Security Catalyst" href="http://www.securitycatalyst.com/" target="_blank">SecurityCatalyst.com </a></p>
<p><em><strong>1.</strong> <strong>In which area(s) of <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> are you most involved</strong>? </em><br />
I have been an IT Auditor for the last 8 years. I get to work with many aspects of <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a>, but I find myself always drawn to the core infrastructure. If I am digging into operating systems, databases, or network <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a>, then I am happy.<br />
<em><strong><br />
2. What <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> topics will be the most important in the next 18 months? Why? </strong></em><br />
Protecting what provides value has always been and will always be the most important challenge in <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a>. I know that is a broad statement, but the technologies are always changing, thus provide a wide array of potential to the threat landscape. Ultimately, systems that provide a service have value and are targets. Being able to adapt to those trends will be most important.</p>
<p><em><strong>3. Biggest Pet Peeve: Name one thing about Network <a title="Security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">Security</a> that you wish business stakeholders would understand and why. </strong></em><br />
Business requirements should be built into systems, instead of designing a system for <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> and then creating exceptions to the controls. Exceptions to <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> are typically not intended to create <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> holes; they result from a failure to design all needed business requirements into the <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> structure. Having good communication between <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> and business design are important early in a project to close any gaps that may arise.</p>
<p><em><strong>4. Tell us why you became so active on Twitter and any other important social media outlets. What value are you getting? </strong></em><br />
I originally joined <a title="LinkedIn" href="http://www.linkedin.com/" target="_blank">LinkedIn </a>on advice from the <a title="PaulDotCom.com" href="http://pauldotcom.com/" target="_blank">Pauldotcom Security Weekly</a> podcast when they discussed protecting your <a title="Wikipedia: Digital Identity" href="http://en.wikipedia.org/wiki/Digital_identity" target="_blank">digital identity</a>. It made sense; even if I had limited information available on my own profiles, that is better than having inaccurate information freely available. I jumped on Twitter later because it seemed the place to be. I thought I would just lurk around and drink from the Infosec knowledge tap, but I never expected to participate. Being on <a title="Twitter: Jeff Kirsch" href="http://twitter.com/ghostnomad" target="_blank">Twitter</a> has allowed me to interact with people I probably would have been afraid to talk with otherwise.</p>
<p><strong><em>5. Name one <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> peer whom everyone with an interest in Network <a title="Security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">Security</a> should follow. (Okay to name 2 if you can&#8217;t decide on only one) </em></strong><br />
I find Jack Daniel (<a title="Twitter: Jack Daniel" href="http://twitter.com/jack_daniel" target="_blank">@jack_daniel</a>) is a great source of information for all the is network infrastructure <em><strong>[Editor's Note: Jeff submitted this answer before the Jack Daniel profile went live]</strong></em>. He has a no nonsense approach to dealing with issues that he sees arise. Christofer Hoff (<a title="Twitter: Christofer Hoff" href="http://twitter.com/beaker" target="_blank">@beaker</a>) is certainly someone I recommend when it comes to the cloud. To say he spends a lot of time with his head in the clouds is not a negative thing in the least, and he gets down to business as well. There are many people out there that bring unique perspectives, and I enjoy the banter.</p>
<p><strong><em>6. What&#8217;s your take on <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> for social media and cloud services in general? Top concerns, overstated issues, etc. </em></strong><br />
I think social media and cloud services face similar threats that “traditional” technology faces. When you put information someone wants in a place they perceive they can get it, you usually see a lot of determination and effort put into gaining access. It is important to focus on educating people about how we can use these technologies while protecting the information that drives their usefulness.<br />
<strong><em><br />
7. What are the top 3 real-world (i.e. live) events you&#8217;d recommend for networking with <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> professionals? </em></strong><br />
I don’t get out all that often, but when I do I stick with local events. I still engage a broad range of <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> professional at local events. I like the <a title="Information Security Summit" href="http://www.informationsecuritysummit.org/" target="_blank">Northeast Ohio Information Security Summit</a>, and always find great value in the people I meet. From my social network, I would say <a title="Defcon" href="http://www.defcon.org/" target="_blank">Defcon</a> and <a title="Shmoocon" href="http://www.shmoocon.org/" target="_blank">Shmoocon</a> sound like really great places to get together with <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> people from all around. Those are on my wish list for the near future.</p>
<p class="bookmark-me">
    <script type="text/javascript">
	    yahooBuzzArticleHeadline = "<a title="Security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">Security</a> Pros on Twitter (SPoT): Jeff Kirsch/@GhostNomad";
	    yahooBuzzArticleId = "http://www.anuesystems.com/blog/2009/09/03/<a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a>-pros-on-twitter-spot-jeff-kirschghostnomad/";
    </script>
    <script type="text/javascript"
        src="http://d.yimg.com/ds/badge2.js"
        badgetype="logo">
    </script>    
    <a title="technorati.com" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/technorati.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="del.icio.us" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jeff+Kirsch%2F%40GhostNomad"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/delicious.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="stumbleupon.com" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jeff+Kirsch%2F%40GhostNomad"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/stumbleupon.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="digg.com" href="http://digg.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jeff+Kirsch%2F%40GhostNomad"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/digg.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.facebook.com" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Jeff+Kirsch%2F%40GhostNomad"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/facebook.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="bookmarks.yahoo.com" href="http://bookmarks.yahoo.com/toolbar/savebm?opener=tb&amp;u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoo.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.google.com" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jeff+Kirsch%2F%40GhostNomad"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/google.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="furl.com" href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Jeff+Kirsch%2F%40GhostNomad"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/furl.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="reddit.com" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jeff+Kirsch%2F%40GhostNomad"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/reddit.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="propeller.com" href="http://www.propeller.com/submit/?U=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F&amp;T=Security+Pros+on+Twitter+%28SPoT%29%3A+Jeff+Kirsch%2F%40GhostNomad"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/propeller.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="windowslive.com" href="https://favorites.live.com/quickadd.aspx?mkt=en-us&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/windowslive.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="myweb2.search.yahoo.com" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoomyweb.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="linkedin.com" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jeff+Kirsch%2F%40GhostNomad"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/linkedin.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="twitthis.com" href="http://twitthis.com/twit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jeff+Kirsch%2F%40GhostNomad"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/twitter.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.anuesystems.com/blog/2009/09/03/security-pros-on-twitter-spot-jeff-kirschghostnomad/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
