<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Network View &#187; LinkedIn</title>
	<atom:link href="http://www.anuesystems.com/blog/tag/linkedin/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anuesystems.com/blog</link>
	<description></description>
	<lastBuildDate>Thu, 15 Jul 2010 15:30:09 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>MeThinks: Now is a Great Time to Give Thanks</title>
		<link>http://www.anuesystems.com/blog/2009/11/24/methinks-now-is-a-great-time-to-give-thanks/</link>
		<comments>http://www.anuesystems.com/blog/2009/11/24/methinks-now-is-a-great-time-to-give-thanks/#comments</comments>
		<pubDate>Tue, 24 Nov 2009 23:31:30 +0000</pubDate>
		<dc:creator>Tommy P. Landry</dc:creator>
				<category><![CDATA[Anue Systems]]></category>
		<category><![CDATA[Monitoring Optimization]]></category>
		<category><![CDATA[Network Emulation]]></category>
		<category><![CDATA[Network Monitoring]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Tool Aggregation]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[Branden Williams]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[erin jacobs]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[holiday]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[methinks]]></category>
		<category><![CDATA[mike pennacchi]]></category>
		<category><![CDATA[monitoring]]></category>
		<category><![CDATA[net tool optimizer]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[network emulator]]></category>
		<category><![CDATA[packet analysis]]></category>
		<category><![CDATA[pci]]></category>
		<category><![CDATA[pre-deployment testing]]></category>
		<category><![CDATA[thanksgiving]]></category>
		<category><![CDATA[tommy landry]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.anuesystems.com/blog/?p=496</guid>
		<description><![CDATA[This week we will enjoy a major holiday here in the USA, Thanksgiving. This tradition originated in the earliest days of our country's existence, and we still take pause once each year to celebrate all of the good things that life has placed before us. While this is most certainly a time to enjoy family and be together, we want to take a brief moment to express gratitude as a company for the good things that have befallen us in the past year.]]></description>
			<content:encoded><![CDATA[<p>This week we will enjoy a major holiday here in the USA, Thanksgiving. This tradition originated in the earliest days of our country&#8217;s existence, and we still take pause once each year to celebrate all of the good things that life has placed before us.</p>
<p>While this is most certainly a time to enjoy family and be together, I want to take a brief moment to express gratitude for the good things that have befallen our company in the past year.</p>
<p>Harkening back to a weekly sports column I wrote in 2008, I offer you <a title="RotoExperts: MeThinks; Stream a Little Stream" href="http://rotoexperts.com/content/view/2622/151/" target="_blank">MeThinks</a>. The official definition of the word is &#8220;it occurred to me&#8221;, so today <strong>MeThinks </strong>I am thankful for:</p>
<ol>
<li>Every single one of the 500+ customers who have bought <a title="Anue Systems Network Emulators" href="http://www.anuesystems.com/Products_NetworkEmulator_landing.shtml" target="_blank">Network Emulators</a> and <a title="Anue 5200 Series Net Tool Optimizer" href="http://anuesystems.com/Products_ToolOptimizer_about.shtml" target="_blank">Net Tool Optimizers</a> from Anue Systems in our seven years of existence.</li>
<li>Our outstanding group of channel partners who are out there in the field spreading the word about <a title="DMMC page" href="http://anuesystems.com/Products_ToolOptimizer_DynamicMany-to-ManyConnectivity.shtml" target="_blank">Monitoring Optimization</a> and <a title="Anue Pre-Deployment Testing NEMs" href="http://anuesystems.com/Solutions_NEM.shtml" target="_blank">Pre-Deployment Testing</a></li>
<li><a title="Twitter: Erin Jacobs" href="http://twitter.com/SecBarbie" target="_blank">Erin Jacobs</a>, <a title="LinkedIn: Mike Pennacchi" href="http://www.linkedin.com/pub/mike-pennacchi/1/794/525" target="_blank">Mike Pennacchi</a>, and <a title="Twitter: Branden Williams" href="http://twitter.com/BrandenWilliams" target="_blank">Branden Williams</a>, the three thought leaders in packet analysis, security, and PCI compliance who are presenting their outstanding knowledge at the <a title="Eye on Security Webinar Series" href="http://www.anuesystems.com/Resources_NTO_EyeonSecurity_Webinars.shtml" target="_blank">Eye on Security webinar series</a>.</li>
<li>Every out of band monitoring tool vendor, without whom Monitoring Optimization would be merely words on a page.</li>
<li>Our competitors, for pushing us to make our Monitoring Optimization solution better and better with each passing month.</li>
<li>The good folks who offer outstanding and free social media tools such as <a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a>, <a title="LinkedIn" href="http://www.linkedin.com/" target="_blank">LinkedIn</a>, <a title="Facebook" href="http://www.facebook.com/" target="_blank">Facebook</a>, <a title="PitchEngine" href="http://www.pitchengine.com/" target="_blank">PitchEngine</a>, and <a title="WordPress" href="http://wordpress.org/" target="_blank">WordPress</a>. Social media is here to stay, and we are glad to have the opportunity to take part in the community itself.</li>
<li>The <a title="City of Austin" href="http://www.ci.austin.tx.us/" target="_blank">City of Austin</a> for providing us such a beautiful city and highly educated population with whom we can interact, work, and thrive. We can&#8217;t say how important it is to operate in such a progressive, innovative, and open-minded culture.</li>
<li>All of our hard-working employees who have helped poise us for continued growth heading into next year.</li>
</ol>
<p>And finally, we are thankful for you, the readers of this blog. Without you, these words are just words, but with your gracious attention and feedback, we can enjoy a continuous and rewarding conversation.</p>
<p>MeThinks 2010 will be a great year to know Anue Systems. Join with us for this exciting ride.</p>
<p style="text-align: center;">
<div class="wp-caption aligncenter" style="width: 510px"><img class=" " title="Couldn't have said it better myself!" src="http://farm1.static.flickr.com/2/2086641_23234fb0f8.jpg" alt="Thank You!" width="500" height="375" /><p class="wp-caption-text">Couldn&#39;t have said it better myself!</p></div>
<p class="bookmark-me">
    <script type="text/javascript">
	    yahooBuzzArticleHeadline = "MeThinks: Now is a Great Time to Give Thanks";
	    yahooBuzzArticleId = "http://www.anuesystems.com/blog/2009/11/24/methinks-now-is-a-great-time-to-give-thanks/";
    </script>
    <script type="text/javascript"
        src="http://d.yimg.com/ds/badge2.js"
        badgetype="logo">
    </script>    
    <a title="technorati.com" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F24%2Fmethinks-now-is-a-great-time-to-give-thanks%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/technorati.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="del.icio.us" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F24%2Fmethinks-now-is-a-great-time-to-give-thanks%2F&amp;title=MeThinks%3A+Now+is+a+Great+Time+to+Give+Thanks"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/delicious.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="stumbleupon.com" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F24%2Fmethinks-now-is-a-great-time-to-give-thanks%2F&amp;title=MeThinks%3A+Now+is+a+Great+Time+to+Give+Thanks"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/stumbleupon.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="digg.com" href="http://digg.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F24%2Fmethinks-now-is-a-great-time-to-give-thanks%2F&amp;title=MeThinks%3A+Now+is+a+Great+Time+to+Give+Thanks"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/digg.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.facebook.com" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F24%2Fmethinks-now-is-a-great-time-to-give-thanks%2F&amp;t=MeThinks%3A+Now+is+a+Great+Time+to+Give+Thanks"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/facebook.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="bookmarks.yahoo.com" href="http://bookmarks.yahoo.com/toolbar/savebm?opener=tb&amp;u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F24%2Fmethinks-now-is-a-great-time-to-give-thanks%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoo.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.google.com" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F24%2Fmethinks-now-is-a-great-time-to-give-thanks%2F&amp;title=MeThinks%3A+Now+is+a+Great+Time+to+Give+Thanks"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/google.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="furl.com" href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F24%2Fmethinks-now-is-a-great-time-to-give-thanks%2F&amp;t=MeThinks%3A+Now+is+a+Great+Time+to+Give+Thanks"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/furl.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="reddit.com" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F24%2Fmethinks-now-is-a-great-time-to-give-thanks%2F&amp;title=MeThinks%3A+Now+is+a+Great+Time+to+Give+Thanks"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/reddit.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="propeller.com" href="http://www.propeller.com/submit/?U=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F24%2Fmethinks-now-is-a-great-time-to-give-thanks%2F&amp;T=MeThinks%3A+Now+is+a+Great+Time+to+Give+Thanks"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/propeller.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="windowslive.com" href="https://favorites.live.com/quickadd.aspx?mkt=en-us&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F24%2Fmethinks-now-is-a-great-time-to-give-thanks%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/windowslive.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="myweb2.search.yahoo.com" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F24%2Fmethinks-now-is-a-great-time-to-give-thanks%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoomyweb.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="linkedin.com" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F24%2Fmethinks-now-is-a-great-time-to-give-thanks%2F&amp;title=MeThinks%3A+Now+is+a+Great+Time+to+Give+Thanks"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/linkedin.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="twitthis.com" href="http://twitthis.com/twit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F24%2Fmethinks-now-is-a-great-time-to-give-thanks%2F&amp;title=MeThinks%3A+Now+is+a+Great+Time+to+Give+Thanks"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/twitter.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.anuesystems.com/blog/2009/11/24/methinks-now-is-a-great-time-to-give-thanks/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Security Pros on Twitter (SPoT): David Mortman / @mortman</title>
		<link>http://www.anuesystems.com/blog/2009/09/30/security-pros-on-twitter-spot-david-mortman/</link>
		<comments>http://www.anuesystems.com/blog/2009/09/30/security-pros-on-twitter-spot-david-mortman/#comments</comments>
		<pubDate>Wed, 30 Sep 2009 19:21:33 +0000</pubDate>
		<dc:creator>Tommy P. Landry</dc:creator>
				<category><![CDATA[Anue Systems]]></category>
		<category><![CDATA[Monitoring Optimization]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[@mortman]]></category>
		<category><![CDATA[alex hutton]]></category>
		<category><![CDATA[Blackhat]]></category>
		<category><![CDATA[cloud services]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[cso]]></category>
		<category><![CDATA[data recovery]]></category>
		<category><![CDATA[david mortman]]></category>
		<category><![CDATA[Defcon]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[hipaa]]></category>
		<category><![CDATA[jeremiah grossman]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[meta-data]]></category>
		<category><![CDATA[outsourcing]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[rsa conference]]></category>
		<category><![CDATA[SecTor]]></category>
		<category><![CDATA[Shmoocon]]></category>
		<category><![CDATA[shrdlu]]></category>
		<category><![CDATA[the new school of information technology]]></category>
		<category><![CDATA[toorcon]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[uptime]]></category>

		<guid isPermaLink="false">http://www.anuesystems.com/blog/?p=373</guid>
		<description><![CDATA[Welcome to the final installment of the Security Pros on Twitter (SPoT) Series on The Network View. Today we focus on a gentleman who we have followed since our very early days on Twitter: David Mortman. According to his bio, Mr. Mortman is a CSO who is currently seeking his new adventure, so if you like what you read here, perhaps you can explore working together. 

Together with Alex Hutton and other leading security experts, David is one of the masterminds behind The New School of Information Security. Take a look at David's most recent post titled Meta-Data? for a good read about the appropriate level of information that is required to have important strategic discussions about security. The post has already spawned a conversation within it's comments.]]></description>
			<content:encoded><![CDATA[<p>Welcome to the final installment of the <a title="The Network View: Security Pros on Twitter (SPoT): Jack Daniel/@jack_daniel" href="http://www.anuesystems.com/blog/?s=SPoT" target="_blank">Security Pros on Twitter (SPoT) Series</a> on <a title="The Network View" href="http://www.anuesystems.com/blog/" target="_blank">The Network View</a>.</p>
<div class="wp-caption alignleft" style="width: 266px"><img class="   " title="SPoT: David Mortman / @mortman" src="http://www.anuesystems.com/blog/mort-steampunk.jpg" alt="SPoT: David Mortman / @mortman" width="256" height="381" /><p class="wp-caption-text">SPoT: David Mortman / @mortman</p></div>
<p>Today we focus on a gentleman who we have followed since our very early days on Twitter: David Mortman. According to his bio, Mr. Mortman is a CSO who is currently seeking his new adventure, so if you like what you read here, perhaps you can explore working together.</p>
<p>Together with <a title="The Network View: Alex Hutton" href="http://www.anuesystems.com/blog/2009/09/15/security-pros-on-twitter-spot-alex-hutton/" target="_blank">Alex Hutton</a> and other leading security experts, David is one of the masterminds behind <a title="The New School of Information Security blog" href="http://newschoolsecurity.com/" target="_blank">The New School of Information Security</a>. Take a look at David&#8217;s most recent post titled <a title="The New School of Information Security blog: Meta-Data?" href="http://newschoolsecurity.com/2009/09/meta-data/" target="_blank">Meta-Data?</a> for a good read about the appropriate level of information that is required to have important strategic discussions about security. The post has already spawned a conversation within it&#8217;s comments.</p>
<p><strong>Real Name: </strong>David Mortman<br />
<strong>Twitter Handle: </strong><a title="Twitter: David Mortman" href="http://twitter.com/mortman" target="_blank">@mortman</a><br />
<strong>Top 3 Social Media/Networking Sites:</strong><br />
<a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a> is the main one I use, although I have accounts on <a title="Facebook" href="http://www.facebook.com/" target="_blank">Facebook</a> and <a title="LinkedIn" href="http://www.linkedin.com/" target="_blank">LinkedIn</a> as well</p>
<p><em><strong>1. In which area(s) of security are you most involved? </strong></em><br />
These days I&#8217;m largely involved in management, <a title="Security Risk" href="http://www.security-risk-analysis.com/" target="_blank">risk</a>, <a title="Privacy" href="http://en.wikipedia.org/wiki/Privacy" target="_blank">privacy</a> and <a title="Regulatory Compliance" href="http://en.wikipedia.org/wiki/Regulatory_compliance" target="_blank">compliance</a>, although I still do some technical security work as well.</p>
<p><strong><em>2. What security topics will be the most important in the next 18 months? Why? </em></strong><br />
Compliance by a long shot, there are lots of new regulations on the horizon, plus <a title="PCI Data Security Standard" href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank">PCI</a> and the new changes to <a title="HIPAA" href="http://www.hhs.gov/ocr/privacy/hipaa/understanding/index.html" target="_blank">HIPAA</a>, all of which will keep lots of folks busy.</p>
<p><strong><em>3. Biggest Pet Peeve: Name one thing about Network Security that you wish business stakeholders would understand and why. </em></strong><br />
One of my personal long term goals is for business stakeholders to better understand what security can and can&#8217;t do for them.</p>
<p><em><strong>4. Tell us why you became so active on Twitter and any other important social media outlets. What value are you getting? </strong></em><br />
<a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a> started out as just an convenient way for me to keep in touch with peers in a more interactive way than  email. It quickly became a great medium to launch discussions about security and privacy issues.</p>
<p><em><strong>5. Name one security peer whom everyone with an interest in Network Security should follow. (Okay to name 2 if you can&#8217;t decide on only one) </strong></em><br />
Jeremiah Grossman (<a title="Twitter: Jeremiah Grossman" href="http://twitter.com/Jeremiahg" target="_blank">@JeremiahG</a>), <a title="SPoT Profile: Alex Hutton (The Network View)" href="http://www.anuesystems.com/blog/2009/09/15/security-pros-on-twitter-spot-alex-hutton/" target="_blank">Alex Hutton</a> (<a title="Twitter: Alex Hutton" href="http://twitter.com/alexhutton" target="_blank">@AlexHutton</a>), and Shrdlu (<a title="Twitter: shrdlu" href="http://twitter.com/shrdlu" target="_blank">@shrdlu</a>)<em> [EDITOR'S NOTE: Does anyone actually know @shrdlu's real name?]</em>.</p>
<p><strong><em>6. What&#8217;s your take on security for social media and cloud services in general? Top concerns, overstated issues, etc. </em></strong><br />
I think that having security concerns with <a title="Wikipedia: Social Media" href="http://en.wikipedia.org/wiki/Social_media" target="_blank">social media</a> and <a title="Wikipedia: Cloud Computing Services" href="http://en.wikipedia.org/wiki/Cloud_computing" target="_blank">cloud services</a> is important, but that they are often over-hyped in the media. My biggest concerns are around reliability with regards to <a title="Wikipedia: Uptime" href="http://en.wikipedia.org/wiki/Up_time" target="_blank">uptime</a> / <a title="Wikipedia: Data Recovery" href="http://en.wikipedia.org/wiki/Data_recovery" target="_blank">data recovery</a> and <a title="Wikipedia: Compliance" href="http://en.wikipedia.org/wiki/Compliance_%28regulation%29" target="_blank">compliance</a>. Largely going to the cloud isn&#8217;t significantly different than other forms of <a title="Wikipedia: Outsourcing" href="http://en.wikipedia.org/wiki/Outsourcing" target="_blank">outsourcing</a>, provided you can get the appropriate protections for your business. This does mean that you can&#8217;t just use any cloud service &#8220;willy-nilly&#8221;, but that&#8217;s not any different then any other outsourcing agreement. As for social media, this is largely an education issue, similar to what companies have had to deal with in  public IM services that have been around for over a decade now. We just need to remind employees what is and is not appropriate to discuss, and remind them that social media is, in fact, a public forum.</p>
<p><strong><em>7. What are the top 3 real-world (i.e. live) events you&#8217;d recommend for networking with security professionals? </em></strong><br />
<a title="RSA Conference" href="http://www.rsaconference.com/index.htm" target="_blank">RSA</a>, <a title="Blackhat" href="http://www.blackhat.com/" target="_blank">Blackhat</a>/<a title="Defcon" href="http://www.defcon.org/" target="_blank">Defcon</a> and any conference I am at <img src='http://www.anuesystems.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> .</p>
<p>Seriously though, I hear great things about <a title="Shmoocon" href="http://www.shmoocon.org/" target="_blank">Shmoocon</a>, <a title="Toorcon" href="http://www.toorcon.org/" target="_blank">Toorcon</a>, and <a title="SecTor Conference" href="http://www.sector.ca/" target="_blank">SecTor</a>.</p>
<p><strong>Security Pros on Twitter (SPoT) Series Wrap Up</strong></p>
<p>We have greatly enjoyed networking with all of these impressive SPoTs, and we hope you have also found the content enjoyable and informative.  Our next series will profile some key technical sales personnel at security tool companies, and we hope you are looking forward to it as much as we are.</p>
<p>As always, we want your feedback. Got a hot topic you want to see discussed on here? Want to contribute a guest post? Have an idea for an interesting additional series on any topic in network monitoring or security? Bring &#8216;em on; we&#8217;re all ears.</p>
<p class="bookmark-me">
    <script type="text/javascript">
	    yahooBuzzArticleHeadline = "Security Pros on Twitter (SPoT): David Mortman / @mortman";
	    yahooBuzzArticleId = "http://www.anuesystems.com/blog/2009/09/30/security-pros-on-twitter-spot-david-mortman/";
    </script>
    <script type="text/javascript"
        src="http://d.yimg.com/ds/badge2.js"
        badgetype="logo">
    </script>    
    <a title="technorati.com" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F30%2Fsecurity-pros-on-twitter-spot-david-mortman%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/technorati.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="del.icio.us" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F30%2Fsecurity-pros-on-twitter-spot-david-mortman%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+David+Mortman+%2F+%40mortman"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/delicious.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="stumbleupon.com" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F30%2Fsecurity-pros-on-twitter-spot-david-mortman%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+David+Mortman+%2F+%40mortman"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/stumbleupon.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="digg.com" href="http://digg.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F30%2Fsecurity-pros-on-twitter-spot-david-mortman%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+David+Mortman+%2F+%40mortman"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/digg.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.facebook.com" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F30%2Fsecurity-pros-on-twitter-spot-david-mortman%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+David+Mortman+%2F+%40mortman"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/facebook.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="bookmarks.yahoo.com" href="http://bookmarks.yahoo.com/toolbar/savebm?opener=tb&amp;u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F30%2Fsecurity-pros-on-twitter-spot-david-mortman%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoo.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.google.com" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F30%2Fsecurity-pros-on-twitter-spot-david-mortman%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+David+Mortman+%2F+%40mortman"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/google.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="furl.com" href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F30%2Fsecurity-pros-on-twitter-spot-david-mortman%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+David+Mortman+%2F+%40mortman"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/furl.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="reddit.com" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F30%2Fsecurity-pros-on-twitter-spot-david-mortman%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+David+Mortman+%2F+%40mortman"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/reddit.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="propeller.com" href="http://www.propeller.com/submit/?U=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F30%2Fsecurity-pros-on-twitter-spot-david-mortman%2F&amp;T=Security+Pros+on+Twitter+%28SPoT%29%3A+David+Mortman+%2F+%40mortman"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/propeller.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="windowslive.com" href="https://favorites.live.com/quickadd.aspx?mkt=en-us&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F30%2Fsecurity-pros-on-twitter-spot-david-mortman%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/windowslive.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="myweb2.search.yahoo.com" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F30%2Fsecurity-pros-on-twitter-spot-david-mortman%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoomyweb.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="linkedin.com" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F30%2Fsecurity-pros-on-twitter-spot-david-mortman%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+David+Mortman+%2F+%40mortman"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/linkedin.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="twitthis.com" href="http://twitthis.com/twit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F30%2Fsecurity-pros-on-twitter-spot-david-mortman%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+David+Mortman+%2F+%40mortman"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/twitter.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.anuesystems.com/blog/2009/09/30/security-pros-on-twitter-spot-david-mortman/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Pros on Twitter (SPoT): Michael R. Farnum / @m1a1vet</title>
		<link>http://www.anuesystems.com/blog/2009/09/22/security-pros-on-twitter-spot-michael-r-farnum-m1a1vet/</link>
		<comments>http://www.anuesystems.com/blog/2009/09/22/security-pros-on-twitter-spot-michael-r-farnum-m1a1vet/#comments</comments>
		<pubDate>Tue, 22 Sep 2009 15:54:08 +0000</pubDate>
		<dc:creator>Tommy P. Landry</dc:creator>
				<category><![CDATA[Anue Systems]]></category>
		<category><![CDATA[IT Audit]]></category>
		<category><![CDATA[Infrastructure Security]]></category>
		<category><![CDATA[Monitoring Optimization]]></category>
		<category><![CDATA[Network Monitoring]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Networking Protocols]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[@beaker]]></category>
		<category><![CDATA[an information security place]]></category>
		<category><![CDATA[Blackhat]]></category>
		<category><![CDATA[chris]]></category>
		<category><![CDATA[Christofer Hoff]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[Defcon]]></category>
		<category><![CDATA[dlp]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[heartland]]></category>
		<category><![CDATA[jabba the hutt]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[m1a1vet]]></category>
		<category><![CDATA[naisg]]></category>
		<category><![CDATA[pci]]></category>
		<category><![CDATA[podcast]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[robert carr]]></category>
		<category><![CDATA[rsa conference]]></category>
		<category><![CDATA[social network]]></category>
		<category><![CDATA[trisc]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[visio]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[youtube]]></category>

		<guid isPermaLink="false">http://www.anuesystems.com/blog/?p=365</guid>
		<description><![CDATA[Welcome to today's entry in the ongoing SPoT series. Today, we are covering someone who serves a different role in security, Michael R. Farnum, who is a Pre-Sales Security Engineer for a VAR / Consulting company. Most of our SPoTs to date have been client-side practitioners, but that is most certainly not a requirement to be considered a "Security Pro". Mr. Farnum is also known for his role in An Information Security Place, a blog which offers insightful security podcasts a minimum of once each month. The podcast discusses a range of topics, including hacking, security breaches, PCI, vulnerabilities, security/compliance audits, and cybersecurity.]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 223px"><img class="    " title="SPoT: Michael R. Farnum / @m1a1vet" src="http://www.anuesystems.com/blog/MICHAEL.JPG" alt="SPoT: Michael R. Farnum / @m1a1vet" width="213" height="298" /><p class="wp-caption-text">SPoT: Michael R. Farnum / @m1a1vet</p></div>
<p>Welcome to today&#8217;s entry in the ongoing SPoT series. Today, we are covering someone who serves a different role in security, <a title="Twitter: Michael R. Farnum" href="http://twitter.com/m1a1vet" target="_blank">Michael R. Farnum</a>, who is a Pre-Sales Security Engineer for a VAR / Consulting company. Most of our SPoTs to date have been client-side practitioners, but that is most certainly not a requirement to be considered a &#8220;Security Pro&#8221;. Mr. Farnum is also known for his role in <a title="An Information Security Place Blog" href="http://infosecplace.com/blog/" target="_blank">An Information Security Place</a>, a blog which offers insightful security podcasts a minimum of once each month. The podcast discusses a range of topics, including hacking, security breaches, PCI, vulnerabilities, security/compliance audits, and cybersecurity.</p>
<p><strong>Real Name: </strong>Michael Farnum<br />
<strong>Twitter Handle: </strong><a title="Twitter: Michael R. Farnum" href="http://twitter.com/m1a1vet" target="_blank">@m1a1vet</a><br />
<strong>Top 3 Social Media/Networking Sites: </strong><br />
<a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a>, <a title="LinkedIn" href="http://www.linkedin.com/" target="_blank">LinkedIn</a>, <a title="YouTube" href="http://www.youtube.com/" target="_blank">YouTube</a></p>
<p><em><strong>1. In which area(s) of security are you most involved?</strong></em><br />
Because I am a pre-sales security engineer for a security consultant / VAR, I tend to have my fingers in a lot of <a title="Security Pie" href="http://securitypie.com/" target="_blank">pies</a>.  I talk to clients about <a title="How to Begin IT Risk Management" href="http://www.eweek.com/c/a/Security/How-to-Begin-IT-Risk-Management-Five-Steps-to-Getting-What-You-Want/" target="_blank">risk</a>, <a title="Regulatory Compliance" href="http://en.wikipedia.org/wiki/Regulatory_compliance" target="_blank">compliance</a>, and <a title="IT Security Assessment" href="http://en.wikipedia.org/wiki/Information_Technology_Security_Assessment" target="_blank">security assessments</a>.  I also talk to them about security technologies to  fill the gaps found when doing a <a title="Perform a gap analysis of security" href="http://articles.techrepublic.com.com/5100-10878_11-5875322.html" target="_blank">gap analysis</a> or <a title="IT Security Assessment" href="http://en.wikipedia.org/wiki/Information_Technology_Security_Assessment" target="_blank">assessment</a>.  I have to keep pretty current in those areas as best I can [to] find opportunities to help my clients.  I also podcast about security quite a bit (since Twitter and work has pushed down my blogging volume).<br />
<em><strong><br />
2. What security topics will be the most important in the next 18 months? Why?</strong></em><br />
I think more and more disillusionment with <a title="PCI Data Security Standard" href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank">PCI</a> will really begin to cause the <a title="PCI Security Standards Council" href="https://www.pcisecuritystandards.org/" target="_blank">PCI Security Standards Council</a> headaches.  I believe you are going to see some big push back on PCI DSS by companies of all sizes, as more and more money has to be spent on keeping &#8220;compliant&#8221;.  Though I have had major issues with <a title="Heartland CEO on Data Breaches" href="http://www.csoonline.com/article/499527/Heartland_CEO_on_Data_Breach_QSAs_Let_Us_Down" target="_blank">Robert Carr, CEO of Heartland Payment Systems</a>, in his recent interviews, I believe the auditing process has really come under fire lately and will continue to do so.  It is a broken model.</p>
<p>Of course, <a title="Wikipedia: Cloud Computing" href="http://en.wikipedia.org/wiki/Cloud_computing" target="_blank">cloud computing</a> will continue to move up and up in everyone&#8217;s mind, in both infrastructure and, necessarily, security.  Even if the economy improves, I believe this is a train [on which] more and more companies will jump, to varying degrees.  And specific to compliance, if cloud providers can start showing that compliance headaches can at least be eased by the Cloud, then it will grow even more.  I know that is a <em>huge</em> question, but if they can at least make CEOs and CIOs believe it, the Cloud will grow.  I don&#8217;t like it, but there it is.<br />
<em><strong><br />
3. Biggest Pet Peeve: Name one thing about Network Security that you wish business stakeholders would understand and why.</strong></em><br />
Let me change the focus of this question.  I think the failure to secure one&#8217;s business infrastructure is a failure of basic responsibility.  This is not just a business stakeholder issue, because security is not <em>just</em> about the ability of the business to turn a profit.  Of course, security is a driver for profit if done right and applied correctly.  But if the economy as a whole has major issues, then that business and every other business will begin to feel pain.</p>
<p>Here is what I mean.  Good security measures contribute to the whole economy.  Just like businesses often become a part of their neighborhood or the community as a whole by contributing money and resources for good causes, those businesses should also contribute resources to the security of the Internet as good Internet citizens.  They <em>must</em> look at how their security posture affects the whole of the Internet.  The Internet is, obviously, a <em>huge</em> part of the economy.  When a company becomes a cesspool of malware, they become a hindrance and a detriment to that economy.  Business over the Internet is not going to stop, but I wonder how much better it could be if even one third of businesses would clean themselves up.<br />
<em><strong><br />
4. Tell us why you became so active on Twitter and any other important social media outlets. What value are you getting?</strong></em><br />
<a title="Twitter: Michael R. Farnum" href="http://twitter.com/m1a1vet" target="_blank">Twitter</a> started out simply an outlet for my way of thinking.  I am a &#8220;<a title="Wikipedia: Snippet" href="http://en.wikipedia.org/wiki/Snippet" target="_blank">snippet</a>&#8221; thinker.  I am a <a title="Quipper Definition" href="http://www.lexic.us/definition-of/quipper" target="_blank">quipper</a>, if that is a word.  I used to blog a lot, and I felt that I always needed to expand on my thoughts when I blogged.  But I often simply wanted to kick out a thought and just forget about it, or at least save it for later.  Twitter gave me a way to do that without feeling &#8220;guilty&#8221; for not expounding.  I sometimes get into trouble via Twitter, but that is because I sometimes <a title="Quip" href="http://www.merriam-webster.com/dictionary/quip" target="_blank">quip</a> without thinking first.  There are a <em>lot</em> of people doing research on various subjects and products via Twitter, so I have to be careful.</p>
<p>That same dimension of Twitter is what makes it so valuable.  So many people are giving their &#8220;<a title="Two-Cent's Worth" href="http://www.phrases.org.uk/meanings/393950.html" target="_blank">two-cent&#8217;s worth</a>,&#8221; that I can literally come up with ideas on security which would never have naturally occurred to me without the inspiration from some Infosec Twit.  It gives me options to take to clients.<br />
<em><strong><br />
5. Name one security peer whom everyone with an interest in Network Security should follow. (Okay to name two if you can&#8217;t decide on only one)</strong></em><br />
Without a doubt, Chris Hoff (<a title="Twitter: Christofer Hoff" href="http://twitter.com/beaker" target="_blank">@beaker</a>) is on of the top on my list.  His insights into security continue to astound me.  He is always on the forefront of security ideas, and his spectacular imagination makes his method of dispersal of those ideas entertaining.<br />
<em><strong><br />
6. What&#8217;s your take on security for social media and cloud services in general? Top concerns, overstated issues, etc.</strong></em></p>
<div class="wp-caption alignright" style="width: 301px"><img class="  " title="Jabba the Hut" src="http://sunbulli.com/wp-content/uploads/2007/04/jabba.jpg" alt="Jabba the Hut" width="291" height="315" /><p class="wp-caption-text">The Cloud: A Modern-day Jabba the Hut?</p></div>
<p>As stated above, cloud services make me nervous.  I used to trust that &#8220;blob&#8221; out there where all my lines seem to terminate in the <a title="Microsoft Visio" href="http://office.microsoft.com/en-us/visio/default.aspx" target="_blank">Visio</a> drawing.  But now that cloud providers want to get all my data floating out there, that trust has diminished quite a bit.  I just don&#8217;t see the same enterprise that is buying <a title="Wikipedia: Data Loss Prevention" href="http://en.wikipedia.org/wiki/Data_Loss_Prevention" target="_blank">DLP</a> letting all their data go into this mass that looks more and more like <a title="Jabba the Hutt" href="http://www.starwars.com/databank/character/jabbathehutt/" target="_blank">Jabba the Hutt</a> everyday.</p>
<p><a title="Wikipedia: Social Media" href="http://en.wikipedia.org/wiki/Social_media" target="_blank">Social media</a> is going to grow and grow and grow.  I can&#8217;t go a day without hearing about another <a title="Wikipedia: Social Network" href="http://en.wikipedia.org/wiki/Social_network" target="_blank">social network</a>.  I don&#8217;t think it is a fad.  But it will continue to cause great security fears for me.  I no longer have a <a title="Facebook" href="http://www.facebook.com/" target="_blank">Facebook</a> account, because I just got sucked into it so quickly that I was not guarding my content very well.  Yes, I only allowed certain people to see my page,  but the temptation to let more and more people see it was getting out of control.  That is why it never ceases to amaze me how so many security folks have Facebook pages and are on other social media sites.  I don&#8217;t fault them.  if they weigh the risk and deem it appropriate, then more power to &#8216;em.  But I know my propensities, so I had to stop myself.  If you are an infosec professional, then you have to look <em>very</em> closely to see if those types of sites are good for you [or not].<br />
<em><strong><br />
7. What are the top 3 real-world (i.e. live) events you&#8217;d recommend for networking with security professionals?</strong></em></p>
<ul>
<li>I am more and more into local user groups and conferences.  I have attended <a title="TRISC" href="http://www.trisc.org/" target="_blank">TRISC</a> here in Texas, and I attend local <a title="ISSA" href="https://www.issa.org/" target="_blank">ISSA</a> meetings.  I am also looking to start up a local Houston <a title="NAISG" href="http://www.naisg.org/" target="_blank">NAISG</a> chapter.  That kind of event appeals to me.</li>
<li> The <a title="RSA Conference" href="http://www.rsaconference.com/index.htm" target="_blank">RSA Conference</a> is something I attend more for the socializing aspect (security bloggers gathering).</li>
<li><a title="Blackhat" href="http://www.blackhat.com/" target="_blank">BlackHat</a>/<a title="Defcon" href="http://www.defcon.org/" target="_blank">Defcon</a> are a must if you want to rub elbows with the geekier group.</li>
</ul>
<p class="bookmark-me">
    <script type="text/javascript">
	    yahooBuzzArticleHeadline = "Security Pros on Twitter (SPoT): Michael R. Farnum / @m1a1vet";
	    yahooBuzzArticleId = "http://www.anuesystems.com/blog/2009/09/22/security-pros-on-twitter-spot-michael-r-farnum-m1a1vet/";
    </script>
    <script type="text/javascript"
        src="http://d.yimg.com/ds/badge2.js"
        badgetype="logo">
    </script>    
    <a title="technorati.com" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/technorati.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="del.icio.us" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Michael+R.+Farnum+%2F+%40m1a1vet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/delicious.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="stumbleupon.com" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Michael+R.+Farnum+%2F+%40m1a1vet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/stumbleupon.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="digg.com" href="http://digg.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Michael+R.+Farnum+%2F+%40m1a1vet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/digg.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.facebook.com" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Michael+R.+Farnum+%2F+%40m1a1vet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/facebook.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="bookmarks.yahoo.com" href="http://bookmarks.yahoo.com/toolbar/savebm?opener=tb&amp;u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoo.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.google.com" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Michael+R.+Farnum+%2F+%40m1a1vet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/google.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="furl.com" href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Michael+R.+Farnum+%2F+%40m1a1vet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/furl.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="reddit.com" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Michael+R.+Farnum+%2F+%40m1a1vet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/reddit.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="propeller.com" href="http://www.propeller.com/submit/?U=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F&amp;T=Security+Pros+on+Twitter+%28SPoT%29%3A+Michael+R.+Farnum+%2F+%40m1a1vet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/propeller.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="windowslive.com" href="https://favorites.live.com/quickadd.aspx?mkt=en-us&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/windowslive.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="myweb2.search.yahoo.com" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoomyweb.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="linkedin.com" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Michael+R.+Farnum+%2F+%40m1a1vet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/linkedin.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="twitthis.com" href="http://twitthis.com/twit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F22%2Fsecurity-pros-on-twitter-spot-michael-r-farnum-m1a1vet%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Michael+R.+Farnum+%2F+%40m1a1vet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/twitter.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.anuesystems.com/blog/2009/09/22/security-pros-on-twitter-spot-michael-r-farnum-m1a1vet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Pros on Twitter (SPoT): Alex Hutton/@AlexHutton</title>
		<link>http://www.anuesystems.com/blog/2009/09/15/security-pros-on-twitter-spot-alex-hutton/</link>
		<comments>http://www.anuesystems.com/blog/2009/09/15/security-pros-on-twitter-spot-alex-hutton/#comments</comments>
		<pubDate>Tue, 15 Sep 2009 15:30:52 +0000</pubDate>
		<dc:creator>Tommy P. Landry</dc:creator>
				<category><![CDATA[Monitoring Optimization]]></category>
		<category><![CDATA[Network Monitoring]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[@alexhutton]]></category>
		<category><![CDATA[@gattaca]]></category>
		<category><![CDATA[@sfoak]]></category>
		<category><![CDATA[Adam Shostack]]></category>
		<category><![CDATA[alex hutton]]></category>
		<category><![CDATA[Andrew Stewart]]></category>
		<category><![CDATA[archer]]></category>
		<category><![CDATA[brooke paul]]></category>
		<category><![CDATA[business intelligence]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[dan houser]]></category>
		<category><![CDATA[dave lewis]]></category>
		<category><![CDATA[david mortman]]></category>
		<category><![CDATA[ed bellis]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[grc]]></category>
		<category><![CDATA[infraguard]]></category>
		<category><![CDATA[isaca]]></category>
		<category><![CDATA[issa]]></category>
		<category><![CDATA[jabber]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[management science]]></category>
		<category><![CDATA[masters of beer appreciation]]></category>
		<category><![CDATA[miryokuteki hinshitsu]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[ruby on rails]]></category>
		<category><![CDATA[security management]]></category>
		<category><![CDATA[security mba]]></category>
		<category><![CDATA[security metrics]]></category>
		<category><![CDATA[shrdlu]]></category>
		<category><![CDATA[the new school of information security]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.anuesystems.com/blog/?p=358</guid>
		<description><![CDATA[Welcome to our ninth installment of Security Pros on Twitter.  This week, we are featuring Alex Hutton, who "works in Risk Intelligence for a Fortune-something company", according to his profile on The New School of Information Security blog, where Alex is one of the main contributors of content. The blog shares its name with a 2008 book authored by blog founders Adam Shostack and Andrew Stewart, and they are joined by some savvy security pros including Alex, David Mortman, and Brooke Paul. Mr. Hutton has been involved in security since the early '90s, and we are very glad to profile him as a SPoT.]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 132px"><img title="SPoT: Alex Hutton / @AlexHutton" src="http://newschoolsecurity.com/images/alex-sm.jpg" alt="SPoT: Alex Hutton / @AlexHutton" width="122" height="123" /><p class="wp-caption-text">SPoT: Alex Hutton / @AlexHutton</p></div>
<p>Welcome to our ninth installment of Security Pros on Twitter.  This week, we are featuring Alex Hutton, who &#8220;works in Risk Intelligence for a Fortune-something company&#8221;, according to his profile on <a title="The New School of Information Security blog" href="http://newschoolsecurity.com/" target="_blank">The New School of Information Security blog</a>, where Alex is one of the main contributors of content. The blog shares its name with a 2008 book authored by blog founders Adam Shostack and Andrew Stewart, and they are joined by some savvy security pros including Alex, <a title="Twitter: David Mortman" href="http://twitter.com/mortman" target="_blank">David Mortman</a>, and Brooke Paul. Mr. Hutton has been involved in security since the early &#8217;90s, and we are very glad to profile him as a SPoT.</p>
<p><strong>Real Name:</strong> Alex Hutton<br />
<strong>Twitter Handle:</strong> <a title="Twitter: Alex Hutton" href="http://twitter.com/alexhutton" target="_blank">@alexhutton</a><br />
<strong>Top 3 Social Media/Networking Sites:</strong><br />
<a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a>, <a title="Facebook" href="http://www.facebook.com/" target="_blank">Facebook</a>, <a title="LinkedIn" href="http://www.linkedin.com/" target="_blank">LinkedIn</a></p>
<p><em><strong>1. In which area(s) of security are you most involved? </strong></em><br />
I love <a title="Wikipedia: Risk Management" href="http://en.wikipedia.org/wiki/Risk_management" target="_blank">Risk</a>, <a title="Wikipedia: Management Science" href="http://en.wikipedia.org/wiki/Management_science" target="_blank">Management Science</a>, &amp; <a title="SANS: A Guide to Security Metrics" href="http://www.sans.org/reading_room/whitepapers/auditing/a_guide_to_security_metrics_55?show=55.php&amp;cat=auditing" target="_blank">Security Metrics</a>.</p>
<p><strong><em>2. What security topics will be the most important in the next 18 months? Why? </em></strong><br />
Regulatory pressures &amp; <a title="Wikipedia: Business Intelligence" href="http://en.wikipedia.org/wiki/Business_intelligence" target="_blank">Business Intelligence</a>.</p>
<p>I think we&#8217;re going to see Regulatory pressures (both government and private pressures) increase, because I believe that our industry will continue to see people outside our profession try to &#8220;solve&#8221; our problems for us.  The danger being that their good intentions will lead us towards an undesirable destination.</p>
<p>Business Intelligence for InfoSec, done right, could be a major catalyst towards solving significant problems in security.  If we&#8217;re lucky, it&#8217;ll destroy <a title="GRC" href="https://www.grc.com/passwords.htm" target="_blank">GRC</a> as we know it.</p>
<p><em><strong>3. Biggest Pet Peeve: Name one thing about Network Security that you wish business stakeholders would understand and why.</strong></em><br />
Wow, if you&#8217;ll forgive me for saying so, I think that question is backwards.  If you think about it, it&#8217;s rather egotistical to think that &#8220;they&#8221; need to &#8220;get&#8221; us.  Nope, my perspective is that they sign the paychecks, so &#8220;we&#8221; need to &#8220;get&#8221; them.</p>
<p><em><strong>4. Tell us why you became so active on Twitter and any other important social media outlets. What value are you getting?</strong></em><br />
I became active when I was developing Risk Analytical software using <a title="Ruby On Rails" href="http://rubyonrails.org/" target="_blank">Ruby On Rails</a>.  <a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a> was just kind of experimental then, a neat <a title="RoR App" href="http://rubyonrails.org/applications" target="_blank">RoR app</a> to play with.  I was also very interested in how my application would provide security practitioners with a feeling of &#8220;<a title="Wikipedia: Miryokuteki Hinshitsu" href="http://en.wikipedia.org/wiki/Miryokuteki_Hinshitsu" target="_blank">Miryokuteki Hinshitsu</a>&#8220;, and thought maybe Twitter (or rather twitter-like functionality) might be a piece of that.  The idea being rather than long, arduous web forms in <a title="Archer Software" href="http://www.archer-soft.com/project-management.htm" target="_blank">Archer</a>-like software for project management, security analysts could just &#8220;tweet&#8221; their processes and outcomes back to a central server using an <a title="Wikipedia: Instant Messaging" href="http://en.wikipedia.org/wiki/Instant_messaging" target="_blank">IM</a>-like interface (yeah, this was back when you could still use <a title="Jabber" href="http://www.jabber.org/" target="_blank">Jabber</a> for Twitter).</p>
<p>The value I get is twofold.  First, I get to meet good people.  That&#8217;s important, as everyone has perspective that contributes to your world view, and I believe that your world view is only as good as it is broad.  Second, and related to that, I get to watch really smart people talk.  For example, I used to <em>despise</em> <a title="PCI-DSS: About" href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank">PCI-DSS</a>, and now I don&#8217;t.  That&#8217;s largely because of conversations I&#8217;ve had with <a title="Twitter: Mike (sfoak)" href="http://twitter.com/sfoak" target="_blank">@sfoak</a> and others on Twitter who desire that we stop whining and start solving problems.</p>
<p><em><strong>5. Name one security peer whom everyone with an interest in Network Security should follow. (Okay to name two if you can&#8217;t decide on only one)</strong></em><br />
Only two?!  <a title="Twitter: Ed Bellis" href="http://twitter.com/ebellis" target="_blank">Ed Bellis (@ebellis)</a> and <a title="Twitter: Dave Lewis" href="http://twitter.com/gattaca" target="_blank">Dave Lewis (@gattaca)</a> &#8211; both <a title="Wikipedia: Security Management" href="http://en.wikipedia.org/wiki/Security_management" target="_blank">Security Management</a>, both with massive amounts of &#8220;get it&#8221;ness.  Apologies to dozens of others I would have liked to have mentioned.  And everybody mentions <a title="Twitter: shrdlu" href="http://twitter.com/shrdlu" target="_blank">@shrdlu</a>, so he goes without saying.</p>
<p><em><strong>6. What&#8217;s your take on security for social media and cloud services in general? Top concerns, overstated issues, etc.</strong></em><br />
IMHO, <a title="Wikipedia: Social Media" href="http://en.wikipedia.org/wiki/Social_media" target="_blank">social media</a> represents more of a time-wasting threat than new attack vector threat.  With regards to the <a title="Wikipedia: Cloud Computing" href="http://en.wikipedia.org/wiki/Cloud_computing" target="_blank">cloud</a>, it&#8217;s going to be a mess. And I like that.</p>
<p><em><strong>7. What are the top 3 real-world (i.e. live) events you&#8217;d recommend for networking with security professionals?</strong></em><br />
I would break down real world events into two categories &#8211; local and non-local.  Pick any of the large non-local events to try to get travel budget for.  Networking with peers is super-important for your career on so many levels.  That said, I&#8217;d spend a ton of time getting to know the local environment, even if that means creating your own informal events (especially  if your <a title="ISSA" href="http://www.issa.org/" target="_blank">ISSA</a>/<a title="ISACA" href="http://www.isaca.org/" target="_blank">ISACA</a>/<a title="InfraGard" href="http://www.infragard.net/" target="_blank">Infraguard</a> meetings are &#8220;Death by Powerpoint&#8221;, with little time for socialization).  The most successful professional events I&#8217;ve ever gone to was our <a title="Security Masters of Beer Appreciation Group, LinkedIn" href="http://www.linkedin.com/groupInvitation?groupID=1780794&amp;sharedKey=506602733EE1" target="_blank">Security MBA</a> (Masters of Beer Appreciation) events in Columbus organized by <a title="Twitter: Dan Houser" href="http://twitter.com/1cissp" target="_blank">Dan Houser</a>.  We can put our professional guard down, not be over-exposed to some &#8220;speaker&#8221;, and really have meaningful conversations about our professional and personal lives.</p>
<p class="bookmark-me">
    <script type="text/javascript">
	    yahooBuzzArticleHeadline = "Security Pros on Twitter (SPoT): Alex Hutton/@AlexHutton";
	    yahooBuzzArticleId = "http://www.anuesystems.com/blog/2009/09/15/security-pros-on-twitter-spot-alex-hutton/";
    </script>
    <script type="text/javascript"
        src="http://d.yimg.com/ds/badge2.js"
        badgetype="logo">
    </script>    
    <a title="technorati.com" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/technorati.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="del.icio.us" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Alex+Hutton%2F%40AlexHutton"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/delicious.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="stumbleupon.com" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Alex+Hutton%2F%40AlexHutton"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/stumbleupon.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="digg.com" href="http://digg.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Alex+Hutton%2F%40AlexHutton"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/digg.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.facebook.com" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Alex+Hutton%2F%40AlexHutton"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/facebook.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="bookmarks.yahoo.com" href="http://bookmarks.yahoo.com/toolbar/savebm?opener=tb&amp;u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoo.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.google.com" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Alex+Hutton%2F%40AlexHutton"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/google.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="furl.com" href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Alex+Hutton%2F%40AlexHutton"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/furl.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="reddit.com" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Alex+Hutton%2F%40AlexHutton"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/reddit.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="propeller.com" href="http://www.propeller.com/submit/?U=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F&amp;T=Security+Pros+on+Twitter+%28SPoT%29%3A+Alex+Hutton%2F%40AlexHutton"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/propeller.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="windowslive.com" href="https://favorites.live.com/quickadd.aspx?mkt=en-us&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/windowslive.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="myweb2.search.yahoo.com" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoomyweb.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="linkedin.com" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Alex+Hutton%2F%40AlexHutton"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/linkedin.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="twitthis.com" href="http://twitthis.com/twit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Alex+Hutton%2F%40AlexHutton"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/twitter.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.anuesystems.com/blog/2009/09/15/security-pros-on-twitter-spot-alex-hutton/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Pros on Twitter (SPoT): Andy Willingham/@AndyWillingham</title>
		<link>http://www.anuesystems.com/blog/2009/09/09/security-pros-on-twitter-spot-andy-willingham/</link>
		<comments>http://www.anuesystems.com/blog/2009/09/09/security-pros-on-twitter-spot-andy-willingham/#comments</comments>
		<pubDate>Wed, 09 Sep 2009 16:24:59 +0000</pubDate>
		<dc:creator>Tommy P. Landry</dc:creator>
				<category><![CDATA[Infrastructure Security]]></category>
		<category><![CDATA[Integrity Monitoring]]></category>
		<category><![CDATA[Network Monitoring]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[@andywillingham]]></category>
		<category><![CDATA[Andy ITGuy]]></category>
		<category><![CDATA[andy willingham]]></category>
		<category><![CDATA[Canadian]]></category>
		<category><![CDATA[change control]]></category>
		<category><![CDATA[dc 404]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[FUD]]></category>
		<category><![CDATA[information security officer]]></category>
		<category><![CDATA[infragard]]></category>
		<category><![CDATA[issa]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[michael santarcangello]]></category>
		<category><![CDATA[naisg]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[security catalyst]]></category>
		<category><![CDATA[the cloud]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.anuesystems.com/blog/?p=335</guid>
		<description><![CDATA[This week we look to another talented Security Pro, Mr. Andy Willingham. In his day gig, Andy serves as Information Security Officer for a Financial Services Holding Company, a role he evolved into from his extensive hands-on experience with Administrating the network. In an effort to establish and evangelize his security objectives, Andy is quite active on social media, and he also keeps his own blog titled Andy ITGuy; The voice of reason in a world of FUD. His blog highlights key events in security, latest news and developments, and his take on select topics of interest. We recommend you give a look to it to hear some of the important commentary Andy has available for your reading enjoyment.]]></description>
			<content:encoded><![CDATA[<p>This week we look to another talented Security Pro, Mr. Andy Willingham. In his day gig, Andy serves as Information Security Officer for a Financial Services Holding Company, a role he evolved into from his extensive hands-on experience with Administrating the network. In an effort to establish and evangelize his security objectives, Andy is quite active on social media, and he also keeps his own blog titled <a title="Blog: Andy ITGuy" href="http://www.andyitguy.com/blog/" target="_blank">Andy ITGuy; The voice of reason in a world of FUD</a>. His blog highlights key events in security, latest news and developments, and his take on select topics of interest. We recommend you give a look to it to hear some of the important commentary Andy has available for your reading enjoyment.</p>
<div class="wp-caption alignleft" style="width: 228px"><img class="       " title="SPoT: Andy Willingham / @andywillingham" src="http://www.anuesystems.com/blog/P4300562.JPG" alt="SPoT: Andy Willingham / @andywillingham" width="218" height="394" /><p class="wp-caption-text">SPoT: Andy Willingham / @andywillingham</p></div>
<p><strong>Real Name: </strong>Andy Willingham<br />
<strong>Twitter Handle:</strong> <a title="Twitter: Andy Willingham" href="http://twitter.com/andywillingham" target="_blank">@andywillingham</a><br />
<strong>Top 3 Social Media/Networking Sites: </strong><br />
<a title="LinkedIn" href="http://www.linkedin.com/" target="_blank">Linkedin</a>, <a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a>, <a title="Facebook" href="http://www.facebook.com" target="_blank">Facebook</a></p>
<p><em><strong>1. In which area(s) of security are you most involved? </strong></em><br />
I started out in Network Security but have focused mostly on program development, regulatory compliance, and architecture for the last few years.</p>
<p><em><strong>2. What security topics will be the most important in the next 18 months? Why? </strong></em><br />
I think we really need to focus on user education, reclaiming the desktop, social media and “The Cloud”. The first two will give us the biggest bang for our buck, and the last two have to be tamed before they get too far out of hand. They are coming fast and furious, and we can’t stop them, so we’d better learn how to secure them.</p>
<p><em><strong>3. Biggest Pet Peeve: Name one thing about Network Security that you wish business stakeholders would understand and why.</strong></em><br />
We have got to start involving security in the beginning stages of projects. I can’t tell you how many times I have found out about something in a Change Control meeting when the business was trying to get approval to go live with something. They had been working on it for months, and no one ever said “Hey, I wonder if Security would have any concerns about what we’re doing?”. It only hurts them in the long run, because they end up getting delayed on launch, or if someone with enough clout “insists” that it still go live, they end up spending lots of time and money fixing things that could have been prevented. It looks bad to their customers because of all the down time and bad features.<br />
<em><strong><br />
4. Tell us why you became so active on Twitter and any other important social media outlets. What value are you getting? </strong></em><br />
I’ve spent much of my career in smaller companies with limited tech staff, and there have been lots of times when I needed someone to bounce an idea or question off of, but the only option that I had was an online forum. Not that there is anything wrong with that, but you are taking a chance that 1) someone will know the answer and 2) that person will actually check the forums and see your question, which can often take several days. With <a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a> and other social media sites, I’ve got experts in all fields right there willing to help out. It also keeps me informed on up to the minute happenings in security, and it is lots of fun to banter with and trade ideas with others in near real-time.</p>
<p><em><strong>5. Name one security peer whom everyone with an interest in Network Security should follow. (Okay to name two if you can&#8217;t decide on only one)</strong></em><br />
Michael Santarcangello, The Security Catalyst, <a title="Twitter: Michael Santarcangello" href="http://twitter.com/catalyst" target="_blank">@catalyst</a> on Twitter. Santa thinks like no other security pro that I know. He is on to something that has the potential to set the security industry, and by default the companies we protect, on it’s ear. He not only realizes that we need a shift in how we think and how we practice security, but he has a plan and is actively getting the word out.</p>
<p><strong><em>6. What&#8217;s your take on security for social media and cloud services in general? Top concerns, overstated issues, etc.</em></strong><br />
First off, as I said earlier, they are here to stay, and we had better do something about it. We can’t just sit back and wait until our company adopts them, and then try to figure out how to secure them. Chances are there are people in your company who are already using them, and you just don’t know about it yet. As security pros, we have to know the issues, concerns, and threats to fix them before they become problems.  My first concern is that [this movement] is happening too fast and the industry is not keeping up. Businesses are adopting them without taking proper measures to ensure that they are being used in a secure manner. As for overstated issues, there are a few, but what makes them overstated is that lots of “experts” are talking about them and complaining about them withoutt offering any real solutions. It’s okay to talk about problems so that others become aware of them, but then you need to either quit talking or start offering something of value.</p>
<p><em><strong>7. What are the top 3 real-world (i.e. live) events you&#8217;d recommend for networking with security professionals?</strong></em><br />
Picking a specific three is hard because what you choose (especially if it costs money) needs to be based on what your area of focus is. <a title="RSA Conference" href="http://www.rsaconference.com/index.htm" target="_blank">RSA</a> is a safe bet for most any aspect of security, but beyond that, it gets foggy. If you have the budget, I’d say do something like this: Go to RSA and one conference that is specific to your area of expertise. Then I’d say find local chapters such as <a title="NAISG" href="http://www.naisg.org/" target="_blank">NAISG</a>, <a title="ISSA" href="http://www.issa.org/" target="_blank">ISSA</a>, <a title="InfraGard" href="http://www.infragard.net/" target="_blank">InfraGard</a>, <a title="Twitter: DC 404" href="http://twitter.com/dc404" target="_blank">DC 404</a>, etc., and attend their meetings and events. If you can do those three things, then you will be able to build a network that will serve you well in solving problems, answering questions, and finding new positions when the time comes to move on.</p>
<p class="bookmark-me">
    <script type="text/javascript">
	    yahooBuzzArticleHeadline = "Security Pros on Twitter (SPoT): Andy Willingham/@AndyWillingham";
	    yahooBuzzArticleId = "http://www.anuesystems.com/blog/2009/09/09/security-pros-on-twitter-spot-andy-willingham/";
    </script>
    <script type="text/javascript"
        src="http://d.yimg.com/ds/badge2.js"
        badgetype="logo">
    </script>    
    <a title="technorati.com" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F09%2Fsecurity-pros-on-twitter-spot-andy-willingham%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/technorati.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="del.icio.us" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F09%2Fsecurity-pros-on-twitter-spot-andy-willingham%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Andy+Willingham%2F%40AndyWillingham"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/delicious.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="stumbleupon.com" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F09%2Fsecurity-pros-on-twitter-spot-andy-willingham%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Andy+Willingham%2F%40AndyWillingham"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/stumbleupon.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="digg.com" href="http://digg.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F09%2Fsecurity-pros-on-twitter-spot-andy-willingham%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Andy+Willingham%2F%40AndyWillingham"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/digg.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.facebook.com" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F09%2Fsecurity-pros-on-twitter-spot-andy-willingham%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Andy+Willingham%2F%40AndyWillingham"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/facebook.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="bookmarks.yahoo.com" href="http://bookmarks.yahoo.com/toolbar/savebm?opener=tb&amp;u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F09%2Fsecurity-pros-on-twitter-spot-andy-willingham%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoo.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.google.com" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F09%2Fsecurity-pros-on-twitter-spot-andy-willingham%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Andy+Willingham%2F%40AndyWillingham"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/google.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="furl.com" href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F09%2Fsecurity-pros-on-twitter-spot-andy-willingham%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Andy+Willingham%2F%40AndyWillingham"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/furl.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="reddit.com" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F09%2Fsecurity-pros-on-twitter-spot-andy-willingham%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Andy+Willingham%2F%40AndyWillingham"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/reddit.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="propeller.com" href="http://www.propeller.com/submit/?U=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F09%2Fsecurity-pros-on-twitter-spot-andy-willingham%2F&amp;T=Security+Pros+on+Twitter+%28SPoT%29%3A+Andy+Willingham%2F%40AndyWillingham"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/propeller.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="windowslive.com" href="https://favorites.live.com/quickadd.aspx?mkt=en-us&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F09%2Fsecurity-pros-on-twitter-spot-andy-willingham%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/windowslive.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="myweb2.search.yahoo.com" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F09%2Fsecurity-pros-on-twitter-spot-andy-willingham%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoomyweb.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="linkedin.com" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F09%2Fsecurity-pros-on-twitter-spot-andy-willingham%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Andy+Willingham%2F%40AndyWillingham"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/linkedin.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="twitthis.com" href="http://twitthis.com/twit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F09%2Fsecurity-pros-on-twitter-spot-andy-willingham%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Andy+Willingham%2F%40AndyWillingham"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/twitter.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.anuesystems.com/blog/2009/09/09/security-pros-on-twitter-spot-andy-willingham/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Security Pros on Twitter (SPoT): Jeff Kirsch/@GhostNomad</title>
		<link>http://www.anuesystems.com/blog/2009/09/03/security-pros-on-twitter-spot-jeff-kirschghostnomad/</link>
		<comments>http://www.anuesystems.com/blog/2009/09/03/security-pros-on-twitter-spot-jeff-kirschghostnomad/#comments</comments>
		<pubDate>Thu, 03 Sep 2009 13:55:31 +0000</pubDate>
		<dc:creator>Tommy P. Landry</dc:creator>
				<category><![CDATA[IT Audit]]></category>
		<category><![CDATA[Monitoring Optimization]]></category>
		<category><![CDATA[Network Monitoring]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[@beaker]]></category>
		<category><![CDATA[@jack_daniel]]></category>
		<category><![CDATA[Christofer Hoff]]></category>
		<category><![CDATA[cisa]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[Defcon]]></category>
		<category><![CDATA[digital identity]]></category>
		<category><![CDATA[ghostnomad]]></category>
		<category><![CDATA[information security summit]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[infrastructure]]></category>
		<category><![CDATA[it auditor]]></category>
		<category><![CDATA[it risk]]></category>
		<category><![CDATA[jack daniel]]></category>
		<category><![CDATA[jeff kirsch]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[pauldotcom]]></category>
		<category><![CDATA[securitycatalyst]]></category>
		<category><![CDATA[Shmoocon]]></category>
		<category><![CDATA[the security catalyst]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.anuesystems.com/blog/?p=336</guid>
		<description><![CDATA[We hope you enjoyed our previous interview with Jack Daniel. We've profiled some heavy hitters and thought leaders in the Security Scene, but there are a range of security professionals on Twitter with something interesting and important to say. In an effort to share a well-rounded range of SPs, today we turn our attention to a gentleman who caught our attention early in our tenure in the Twitter-sphere: Jeff Kirsch (a.k.a. @ghostnomad).]]></description>
			<content:encoded><![CDATA[<p>We hope you enjoyed our<a title="The Network View: Security Pros on Twitter (SPoT): Jack Daniel/@jack_daniel" href="http://www.anuesystems.com/blog/2009/08/26/security-pros-on-twitter-spot-jack-danieljack_daniel/" target="_blank"> previous interview with Jack Daniel</a>. We&#8217;ve profiled some heavy hitters and thought leaders in the Security Scene, but there are a range of security professionals on Twitter with something interesting and important to say. In an effort to share a well-rounded range of SPs, today we turn our attention to a gentleman who caught our attention early in our tenure in the Twitter-sphere: Jeff Kirsch (a.k.a. @ghostnomad).</p>
<div class="wp-caption alignright" style="width: 234px"><img class=" " title="SPoT: Jeff Kirsch / @ghostnomad" src="http://www.anuesystems.com/blog/Imaage001-3x.JPG" alt="SPoT: Jeff Kirsch / @ghostnomad" width="224" height="252" /><p class="wp-caption-text">SPoT: Jeff Kirsch / @ghostnomad</p></div>
<p>Jeff describes himself as &#8220;<span><em>Infosec geek, IT risk (yes I am a risk), <a title="CISA" href="http://www.isaca.org/Template.cfm?Section=CISA_Certification&amp;Template=/TaggedPage/TaggedPageDisplay.cfm&amp;TPLID=16&amp;ContentID=4526" target="_blank">CISA</a>, husband and father</em>&#8220;. As you can tell from his bio, he offers a a nice blend of professional and personal information, with a little fun thrown in, which is precisely what you&#8217;ll find in his tweets. Jeff personifies what many of us hope to find on Twitter: &#8220;real, interesting, and engaging people.&#8221;<br />
</span></p>
<p><strong>Real Name: </strong>Jeff Kirsch<br />
<strong>Twitter Handle: </strong><a title="Twitter: Jeff Kirsch" href="http://twitter.com/ghostnomad" target="_blank">ghostnomad </a><br />
<strong>Top 3 Social Media/Networking Sites: </strong><br />
<a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a>, <a title="LinkedIn" href="http://www.linkedin.com/" target="_blank">Linkedin</a>, <a title="The Security Catalyst" href="http://www.securitycatalyst.com/" target="_blank">SecurityCatalyst.com </a></p>
<p><em><strong>1.</strong> <strong>In which area(s) of security are you most involved</strong>? </em><br />
I have been an IT Auditor for the last 8 years. I get to work with many aspects of security, but I find myself always drawn to the core infrastructure. If I am digging into operating systems, databases, or network security, then I am happy.<br />
<em><strong><br />
2. What security topics will be the most important in the next 18 months? Why? </strong></em><br />
Protecting what provides value has always been and will always be the most important challenge in security. I know that is a broad statement, but the technologies are always changing, thus provide a wide array of potential to the threat landscape. Ultimately, systems that provide a service have value and are targets. Being able to adapt to those trends will be most important.</p>
<p><em><strong>3. Biggest Pet Peeve: Name one thing about Network Security that you wish business stakeholders would understand and why. </strong></em><br />
Business requirements should be built into systems, instead of designing a system for security and then creating exceptions to the controls. Exceptions to security are typically not intended to create security holes; they result from a failure to design all needed business requirements into the security structure. Having good communication between security and business design are important early in a project to close any gaps that may arise.</p>
<p><em><strong>4. Tell us why you became so active on Twitter and any other important social media outlets. What value are you getting? </strong></em><br />
I originally joined <a title="LinkedIn" href="http://www.linkedin.com/" target="_blank">LinkedIn </a>on advice from the <a title="PaulDotCom.com" href="http://pauldotcom.com/" target="_blank">Pauldotcom Security Weekly</a> podcast when they discussed protecting your <a title="Wikipedia: Digital Identity" href="http://en.wikipedia.org/wiki/Digital_identity" target="_blank">digital identity</a>. It made sense; even if I had limited information available on my own profiles, that is better than having inaccurate information freely available. I jumped on Twitter later because it seemed the place to be. I thought I would just lurk around and drink from the Infosec knowledge tap, but I never expected to participate. Being on <a title="Twitter: Jeff Kirsch" href="http://twitter.com/ghostnomad" target="_blank">Twitter</a> has allowed me to interact with people I probably would have been afraid to talk with otherwise.</p>
<p><strong><em>5. Name one security peer whom everyone with an interest in Network Security should follow. (Okay to name 2 if you can&#8217;t decide on only one) </em></strong><br />
I find Jack Daniel (<a title="Twitter: Jack Daniel" href="http://twitter.com/jack_daniel" target="_blank">@jack_daniel</a>) is a great source of information for all the is network infrastructure <em><strong>[Editor's Note: Jeff submitted this answer before the Jack Daniel profile went live]</strong></em>. He has a no nonsense approach to dealing with issues that he sees arise. Christofer Hoff (<a title="Twitter: Christofer Hoff" href="http://twitter.com/beaker" target="_blank">@beaker</a>) is certainly someone I recommend when it comes to the cloud. To say he spends a lot of time with his head in the clouds is not a negative thing in the least, and he gets down to business as well. There are many people out there that bring unique perspectives, and I enjoy the banter.</p>
<p><strong><em>6. What&#8217;s your take on security for social media and cloud services in general? Top concerns, overstated issues, etc. </em></strong><br />
I think social media and cloud services face similar threats that “traditional” technology faces. When you put information someone wants in a place they perceive they can get it, you usually see a lot of determination and effort put into gaining access. It is important to focus on educating people about how we can use these technologies while protecting the information that drives their usefulness.<br />
<strong><em><br />
7. What are the top 3 real-world (i.e. live) events you&#8217;d recommend for networking with security professionals? </em></strong><br />
I don’t get out all that often, but when I do I stick with local events. I still engage a broad range of security professional at local events. I like the <a title="Information Security Summit" href="http://www.informationsecuritysummit.org/" target="_blank">Northeast Ohio Information Security Summit</a>, and always find great value in the people I meet. From my social network, I would say <a title="Defcon" href="http://www.defcon.org/" target="_blank">Defcon</a> and <a title="Shmoocon" href="http://www.shmoocon.org/" target="_blank">Shmoocon</a> sound like really great places to get together with security people from all around. Those are on my wish list for the near future.</p>
<p class="bookmark-me">
    <script type="text/javascript">
	    yahooBuzzArticleHeadline = "Security Pros on Twitter (SPoT): Jeff Kirsch/@GhostNomad";
	    yahooBuzzArticleId = "http://www.anuesystems.com/blog/2009/09/03/security-pros-on-twitter-spot-jeff-kirschghostnomad/";
    </script>
    <script type="text/javascript"
        src="http://d.yimg.com/ds/badge2.js"
        badgetype="logo">
    </script>    
    <a title="technorati.com" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/technorati.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="del.icio.us" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jeff+Kirsch%2F%40GhostNomad"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/delicious.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="stumbleupon.com" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jeff+Kirsch%2F%40GhostNomad"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/stumbleupon.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="digg.com" href="http://digg.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jeff+Kirsch%2F%40GhostNomad"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/digg.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.facebook.com" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Jeff+Kirsch%2F%40GhostNomad"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/facebook.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="bookmarks.yahoo.com" href="http://bookmarks.yahoo.com/toolbar/savebm?opener=tb&amp;u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoo.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.google.com" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jeff+Kirsch%2F%40GhostNomad"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/google.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="furl.com" href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Jeff+Kirsch%2F%40GhostNomad"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/furl.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="reddit.com" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jeff+Kirsch%2F%40GhostNomad"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/reddit.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="propeller.com" href="http://www.propeller.com/submit/?U=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F&amp;T=Security+Pros+on+Twitter+%28SPoT%29%3A+Jeff+Kirsch%2F%40GhostNomad"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/propeller.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="windowslive.com" href="https://favorites.live.com/quickadd.aspx?mkt=en-us&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/windowslive.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="myweb2.search.yahoo.com" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoomyweb.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="linkedin.com" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jeff+Kirsch%2F%40GhostNomad"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/linkedin.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="twitthis.com" href="http://twitthis.com/twit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F03%2Fsecurity-pros-on-twitter-spot-jeff-kirschghostnomad%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jeff+Kirsch%2F%40GhostNomad"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/twitter.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.anuesystems.com/blog/2009/09/03/security-pros-on-twitter-spot-jeff-kirschghostnomad/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Security Pros on Twitter (SPoT): Jack Daniel/@Jack_Daniel</title>
		<link>http://www.anuesystems.com/blog/2009/08/26/security-pros-on-twitter-spot-jack-danieljack_daniel/</link>
		<comments>http://www.anuesystems.com/blog/2009/08/26/security-pros-on-twitter-spot-jack-danieljack_daniel/#comments</comments>
		<pubDate>Wed, 26 Aug 2009 17:14:39 +0000</pubDate>
		<dc:creator>Tommy P. Landry</dc:creator>
				<category><![CDATA[Content Filtering]]></category>
		<category><![CDATA[Monitoring Optimization]]></category>
		<category><![CDATA[Network Monitoring]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[@jack_daniel]]></category>
		<category><![CDATA[@SecurityTwits]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[Blackhat]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[jack daniel]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[naisg]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[san jose]]></category>
		<category><![CDATA[Security B-Sides]]></category>
		<category><![CDATA[Shmoocon]]></category>
		<category><![CDATA[source boston]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[uncommon sense security]]></category>
		<category><![CDATA[utm]]></category>
		<category><![CDATA[vpn]]></category>

		<guid isPermaLink="false">http://www.anuesystems.com/blog/?p=324</guid>
		<description><![CDATA[Welcome to this week's installment of Security Pros on Twitter. Today's SP is a very well known security expert, and one who brings an intriguing dose of personality to the table, Jack Daniel. Self-described on Twitter as "Sporadic blogger, Tech Community Activist, InfoSec Curmudgeon, Reluctant CISSP, Amateur Blacksmith, and stuff", Mr Daniel is truly a man of many "hats." In addition to serving as the Director of the National Information Security Group (NAISG), Jack shares his musings on Twitter and his blog, Uncommon Sense Security.]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 176px"><img title="SPoT: Jack Daniel / @Jack_Daniel" src="http://www.anuesystems.com/blog/IMG_0550.jpg" alt="SPoT: Jack Daniel / @Jack_Daniel" width="166" height="315" /><p class="wp-caption-text">SPoT: Jack Daniel / @Jack_Daniel</p></div>
<p>Welcome to this week&#8217;s installment of Security Pros on Twitter. Today&#8217;s SP is a very well known security expert, and one who brings an intriguing dose of personality to the table, Jack Daniel. Self-described on Twitter as &#8220;<span>Sporadic blogger, Tech Community Activist, InfoSec Curmudgeon, Reluctant CISSP, Amateur Blacksmith, and stuff&#8221;, Mr Daniel is truly a man of many &#8220;hats.&#8221; In addition to serving as the </span>Director of the National Information Security Group (NAISG), Jack shares his musings on Twitter and his blog, <a title="Uncommon Sense Security" href="http://blog.uncommonsensesecurity.com/" target="_blank">Uncommon Sense Security</a>.</p>
<p><strong>Real Name: </strong>Jack Daniel<br />
<strong>Twitter Handle:</strong> <a title="Twitter: Jack Daniel" href="http://twitter.com/jack_daniel" target="_blank">@jack_daniel </a><br />
<strong>Top 3 Social Media/Networking Sites: </strong><br />
<a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a>, <a title="LinkedIn" href="http://www.linkedin.com/" target="_blank">Linkedin</a>, and <a title="Facebook" href="http://www.facebook.com/" target="_blank">Facebook </a>as a distant third</p>
<p><em><strong>1.</strong> <strong>In which area(s) of security are you most involved</strong>? </em><br />
I live and work in the <a title="Wikipedia: Unified Threat Management" href="http://en.wikipedia.org/wiki/Unified_Threat_Management" target="_blank">UTM</a> space, covering all the fundamentals of network security, <a title="Wikipedia: Firewall" href="http://en.wikipedia.org/wiki/Firewall" target="_blank">firewall</a>/<a title="Wikipedia: Content Filtering" href="http://en.wikipedia.org/wiki/Content_filtering" target="_blank">content filtering</a>/<a title="Wikipedia: Proxy Server" href="http://en.wikipedia.org/wiki/Proxy_server" target="_blank">proxies</a>/<a title="Wikipedia: Virtual Private Network" href="http://en.wikipedia.org/wiki/Virtual_private_network" target="_blank">VPNs</a>, etc.</p>
<p><em><strong>2. What security topics will be the most important in the next 18 months? Why? </strong></em><br />
It kills me to admit it, but &#8220;cloud&#8221; computing (whatever that means) will be very important.  Not because of the hype, but because, like <a title="Wikipedia: Virtualization" href="http://en.wikipedia.org/wiki/Virtualization" target="_blank">virtualization</a>, it will let us make old mistakes in new and creative ways while also offering exciting and original ways to get security wrong.</p>
<p>I also think that &#8220;<a title="Wikipedia: Antivirus" href="http://en.wikipedia.org/wiki/Antivirus" target="_blank">antivirus</a>&#8221; is of renewed importance.  Microsoft&#8217;s venture into free antivirus and the impact that will have on the AV industry, combined with the increasing irrelevance of traditional AV in defending against many modern attacks, means that it is time to step back and challenge what works, what doesn&#8217;t, and what to do about it.  We may not have many conversations about this, but we should.</p>
<p><strong><em>3. Biggest Pet Peeve: Name one thing about Network Security that you wish business stakeholders would understand and why.</em></strong><br />
A failure to grasp and act on the fundamentals.  In network security, this often manifests itself as an unhealthy push for needless complexity, which dramatically increases the likelihood of misconfiguration and failure.  (I&#8217;m not blaming anyone, but if I did, I would look toward San Jose, CA)  All the blinky-light boxes in the world will not overcome basic misconfiguration issues.</p>
<p><strong><em>4. Tell us why you became so active on Twitter and any other important social media outlets. What value are you getting?</em></strong><br />
My adoption of <a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a> was pretty slow, and has grown gradually over time.  It started as a way to stay in touch with friends and has expanded into a powerful (and still wonderfully inane) way to communicate.  I have gotten more out of Twitter than I can list in a short space, from friendships and information to Twitter being the starting point for the <a title="Security B-Sides" href="http://www.securitybsides.com/" target="_blank">Security B-Sides</a> events.</p>
<p><strong><em>5. Name one security peer whom everyone with an interest in Network Security should follow. (OK to name 2 if you can’t decide on only one)</em></strong><br />
That&#8217;s hard; I follow too many people for too many different reasons to pick one or two.  I&#8217;ll cop out and recommend following <a title="Twitter: Security Twits" href="http://twitter.com/securitytwits" target="_blank">@SecurityTwits</a>, that is a good way to find out who is saying or asking what, which leads to finding good people to follow.</p>
<p><em><strong>6. What’s your take on security for social media and cloud services in general? Top concerns, overstated issues, etc.</strong></em><br />
The fundamental insecurity of social media is also why people use it.  Platforms designed for openness and sharing of content are perfect for exploitation, but if you lock them down, you lose their value.  User education is the only solution, and that will only reach a limited number of people (and they don&#8217;t have to listen).  I have more hope for the security of cloud services in general; I think it will eventually be possible to do an acceptable job of securing the infrastructure, but as with everything else, the client implementation is where I see ongoing insecurity.</p>
<p><strong><em>7. What are the top 3 real-world (i.e. live) events you’d recommend for networking with security professionals?</em></strong><br />
<a title="RSA Conference" href="http://www.rsaconference.com/index.htm" target="_blank">RSA</a> and <a title="Blackhat" href="http://www.blackhat.com/" target="_blank">BlackHat</a> are giant events with many opportunities for socializing and networking.  <a title="SOURCE Boston" href="http://www.sourceconference.com/index.php/boston2010" target="_blank">SOURCE Boston</a> is a much smaller event &#8211; you could almost call it intimate &#8211; and it really encourages the feel of community.  I&#8217;ll cheat and add a fourth &#8211; <a title="Shmoocon" href="http://www.shmoocon.org/" target="_blank">Shmoocon</a> is a great and affordable event.</p>
<p class="bookmark-me">
    <script type="text/javascript">
	    yahooBuzzArticleHeadline = "Security Pros on Twitter (SPoT): Jack Daniel/@Jack_Daniel";
	    yahooBuzzArticleId = "http://www.anuesystems.com/blog/2009/08/26/security-pros-on-twitter-spot-jack-danieljack_daniel/";
    </script>
    <script type="text/javascript"
        src="http://d.yimg.com/ds/badge2.js"
        badgetype="logo">
    </script>    
    <a title="technorati.com" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F26%2Fsecurity-pros-on-twitter-spot-jack-danieljack_daniel%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/technorati.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="del.icio.us" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F26%2Fsecurity-pros-on-twitter-spot-jack-danieljack_daniel%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jack+Daniel%2F%40Jack_Daniel"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/delicious.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="stumbleupon.com" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F26%2Fsecurity-pros-on-twitter-spot-jack-danieljack_daniel%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jack+Daniel%2F%40Jack_Daniel"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/stumbleupon.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="digg.com" href="http://digg.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F26%2Fsecurity-pros-on-twitter-spot-jack-danieljack_daniel%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jack+Daniel%2F%40Jack_Daniel"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/digg.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.facebook.com" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F26%2Fsecurity-pros-on-twitter-spot-jack-danieljack_daniel%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Jack+Daniel%2F%40Jack_Daniel"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/facebook.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="bookmarks.yahoo.com" href="http://bookmarks.yahoo.com/toolbar/savebm?opener=tb&amp;u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F26%2Fsecurity-pros-on-twitter-spot-jack-danieljack_daniel%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoo.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.google.com" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F26%2Fsecurity-pros-on-twitter-spot-jack-danieljack_daniel%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jack+Daniel%2F%40Jack_Daniel"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/google.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="furl.com" href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F26%2Fsecurity-pros-on-twitter-spot-jack-danieljack_daniel%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Jack+Daniel%2F%40Jack_Daniel"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/furl.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="reddit.com" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F26%2Fsecurity-pros-on-twitter-spot-jack-danieljack_daniel%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jack+Daniel%2F%40Jack_Daniel"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/reddit.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="propeller.com" href="http://www.propeller.com/submit/?U=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F26%2Fsecurity-pros-on-twitter-spot-jack-danieljack_daniel%2F&amp;T=Security+Pros+on+Twitter+%28SPoT%29%3A+Jack+Daniel%2F%40Jack_Daniel"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/propeller.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="windowslive.com" href="https://favorites.live.com/quickadd.aspx?mkt=en-us&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F26%2Fsecurity-pros-on-twitter-spot-jack-danieljack_daniel%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/windowslive.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="myweb2.search.yahoo.com" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F26%2Fsecurity-pros-on-twitter-spot-jack-danieljack_daniel%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoomyweb.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="linkedin.com" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F26%2Fsecurity-pros-on-twitter-spot-jack-danieljack_daniel%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jack+Daniel%2F%40Jack_Daniel"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/linkedin.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="twitthis.com" href="http://twitthis.com/twit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F26%2Fsecurity-pros-on-twitter-spot-jack-danieljack_daniel%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jack+Daniel%2F%40Jack_Daniel"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/twitter.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.anuesystems.com/blog/2009/08/26/security-pros-on-twitter-spot-jack-danieljack_daniel/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Pros on Twitter (SPoT): Branden Williams/@BrandenWilliams</title>
		<link>http://www.anuesystems.com/blog/2009/08/18/security-pros-on-twitter-spot-branden-williamsbrandenwilliams/</link>
		<comments>http://www.anuesystems.com/blog/2009/08/18/security-pros-on-twitter-spot-branden-williamsbrandenwilliams/#comments</comments>
		<pubDate>Tue, 18 Aug 2009 17:06:15 +0000</pubDate>
		<dc:creator>Tommy P. Landry</dc:creator>
				<category><![CDATA[Monitoring Optimization]]></category>
		<category><![CDATA[Network Monitoring]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[@BrandenWilliams]]></category>
		<category><![CDATA[@DavidNavetta]]></category>
		<category><![CDATA[application security]]></category>
		<category><![CDATA[Blackhat]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[Branden Williams]]></category>
		<category><![CDATA[data discovery]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Information Security Forum]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[loss prevention]]></category>
		<category><![CDATA[netizens]]></category>
		<category><![CDATA[pci]]></category>
		<category><![CDATA[rsa conference]]></category>
		<category><![CDATA[Security Convergence]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[verisign]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://www.anuesystems.com/blog/?p=315</guid>
		<description><![CDATA[Welcome to this week's installment of Security Pros on Twitter. Today we turn our attention to an expert in a very important area of compliance, PCI DSS - the Payment Card Industry Data Security Standard - in addition to his other areas of security expertise. Branden Williams is the Director of the PCI Practice for Verisign, a global security consulting firm. He also maintains a Verisign blog focused on a range of security topics: Branden Williams' Security Convergence.]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignright" style="width: 217px"><img class="      " title="SPoT: Branden Williams / @BrandenWilliams" src="http://www.anuesystems.com/blog/Branden_Williams_Photo.jpg" alt="SPoT: Branden Williams / @BrandenWilliams" width="207" height="250" /><p class="wp-caption-text">SPoT: Branden Williams / @BrandenWilliams</p></div>
<p>Welcome to this week&#8217;s installment of Security Pros on Twitter. Today we turn our attention to an expert in a very important area of compliance, <a title="Wikipedia: PCI-DSS" href="http://en.wikipedia.org/wiki/PCI_DSS" target="_blank">PCI DSS</a> &#8211; the Payment Card Industry Data Security Standard &#8211; in addition to his other areas of security expertise. Branden Williams is the Director of the PCI Practice for <a title="Verisign" href="http://www.verisign.com/" target="_blank">Verisign</a>, a global security consulting firm. He also maintains a Verisign blog focused on a range of security topics: <a title="Branden Williams' Security Convergence Blog" href="http://blogs.verisign.com/securityconvergence/" target="_blank">Branden Williams&#8217; Security Convergence</a>.</p>
<p><strong>Real Name:</strong> Branden Williams<br />
<strong>Twitter Handle: </strong><a title="Twitter: Branden Williams" href="http://twitter.com/BrandenWilliams" target="_blank">@BrandenWilliams</a><br />
<strong>Top 3 Social Media/Networking Sites: </strong><br />
<a title="LinkedIn" href="http://www.linkedin.com/" target="_blank">Linkedin</a>, <a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a>, <a title="Facebook" href="http://www.facebook.com/" target="_blank">Facebook</a></p>
<p><em>1. <strong>In which area(s) of security are you most involved</strong>? </em><br />
My primary focus is <a title="Payment Security and PCI" href="https://www.pcisecuritystandards.org/" target="_blank">payment security</a>, however, my background is fairly technical and includes application development.</p>
<p><em><strong>2. What security topics will be the most important in the next 18 months? Why? </strong></em><br />
Application Security, Data Discovery and Loss Prevention, and Wireless.  The first two are inter-related as we continue to amass more data on more individuals, and need more ways to crunch the data.  Today, we have a myopic view of where our data lives, which unfortunately becomes focused when we lose it.  The latter is a catch-all.  More applications are going mobile, thanks to improvements in networks and devices like the iPhone.  Watch for attackers to flock to those platforms.</p>
<p><strong><em>3. Biggest Pet Peeve: Name one thing about Network Security that you wish business stakeholders would understand and why.</em></strong><br />
I’m not sure I have one particular one, but the future of security lies in the hands of those individuals that can speak to the business about quantitative risk in a way they can understand.  Security is a business issue, and they need to be on-board with it.</p>
<p><strong><em>4. Tell us why you became so active on Twitter and any other important social media outlets. What value are you getting?</em></strong><br />
I became active on Twitter to keep up with colleagues in the industry and to stay on top of the deluge of information available to <a title="Wikipedia: Netizens" href="http://en.wikipedia.org/wiki/Netizen" target="_blank">netizens</a>.  I’m getting a ton of value as it helps me promote <a title="Branden Williams' Security Convergence Blog" href="http://blogs.verisign.com/securityconvergence/" target="_blank">my blog</a> and allows me to learn more about emerging trends.</p>
<p><strong><em>5. Name one security peer whom everyone with an interest in Network Security should follow. (OK to name 2 if you can&#8217;t decide on only one)</em></strong><br />
<a title="Twitter: David Navetta" href="http://twitter.com/davidnavetta" target="_blank">@DavidNavetta</a> – Legal professionals need to have an open dialogue with Security pros.  This guy gets it, bigtime.</p>
<p><em><strong>6. What&#8217;s your take on security for social media and cloud services in general? Top concerns, overstated issues, etc.</strong></em><br />
The top concerns around this type of media really should be the content, not the method.  PR departments have to embrace this more real-time method of information dissemination, but moreover, employees have to realize that what they post leaves a permanent record.</p>
<p><strong><em>7. What are the top 3 real-world (i.e. live) events you&#8217;d recommend for networking with security professionals?</em></strong><br />
<a title="RSA Conference" href="http://www.rsaconference.com/index.htm" target="_blank">RSA Conference</a>, a long staple even though its attendance in recent years seems to have dwindled a bit.  <a title="Blackhat" href="http://www.blackhat.com/" target="_blank">Blackhat</a>, the best of the best are here.  <a title="Information Security Forum" href="https://www.securityforum.org/index.htm" target="_blank">Information Security Forum</a>, the global community is well represented here.</p>
<p class="bookmark-me">
    <script type="text/javascript">
	    yahooBuzzArticleHeadline = "Security Pros on Twitter (SPoT): Branden Williams/@BrandenWilliams";
	    yahooBuzzArticleId = "http://www.anuesystems.com/blog/2009/08/18/security-pros-on-twitter-spot-branden-williamsbrandenwilliams/";
    </script>
    <script type="text/javascript"
        src="http://d.yimg.com/ds/badge2.js"
        badgetype="logo">
    </script>    
    <a title="technorati.com" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F18%2Fsecurity-pros-on-twitter-spot-branden-williamsbrandenwilliams%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/technorati.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="del.icio.us" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F18%2Fsecurity-pros-on-twitter-spot-branden-williamsbrandenwilliams%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Branden+Williams%2F%40BrandenWilliams"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/delicious.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="stumbleupon.com" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F18%2Fsecurity-pros-on-twitter-spot-branden-williamsbrandenwilliams%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Branden+Williams%2F%40BrandenWilliams"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/stumbleupon.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="digg.com" href="http://digg.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F18%2Fsecurity-pros-on-twitter-spot-branden-williamsbrandenwilliams%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Branden+Williams%2F%40BrandenWilliams"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/digg.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.facebook.com" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F18%2Fsecurity-pros-on-twitter-spot-branden-williamsbrandenwilliams%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Branden+Williams%2F%40BrandenWilliams"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/facebook.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="bookmarks.yahoo.com" href="http://bookmarks.yahoo.com/toolbar/savebm?opener=tb&amp;u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F18%2Fsecurity-pros-on-twitter-spot-branden-williamsbrandenwilliams%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoo.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.google.com" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F18%2Fsecurity-pros-on-twitter-spot-branden-williamsbrandenwilliams%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Branden+Williams%2F%40BrandenWilliams"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/google.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="furl.com" href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F18%2Fsecurity-pros-on-twitter-spot-branden-williamsbrandenwilliams%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Branden+Williams%2F%40BrandenWilliams"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/furl.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="reddit.com" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F18%2Fsecurity-pros-on-twitter-spot-branden-williamsbrandenwilliams%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Branden+Williams%2F%40BrandenWilliams"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/reddit.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="propeller.com" href="http://www.propeller.com/submit/?U=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F18%2Fsecurity-pros-on-twitter-spot-branden-williamsbrandenwilliams%2F&amp;T=Security+Pros+on+Twitter+%28SPoT%29%3A+Branden+Williams%2F%40BrandenWilliams"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/propeller.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="windowslive.com" href="https://favorites.live.com/quickadd.aspx?mkt=en-us&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F18%2Fsecurity-pros-on-twitter-spot-branden-williamsbrandenwilliams%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/windowslive.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="myweb2.search.yahoo.com" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F18%2Fsecurity-pros-on-twitter-spot-branden-williamsbrandenwilliams%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoomyweb.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="linkedin.com" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F18%2Fsecurity-pros-on-twitter-spot-branden-williamsbrandenwilliams%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Branden+Williams%2F%40BrandenWilliams"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/linkedin.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="twitthis.com" href="http://twitthis.com/twit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F18%2Fsecurity-pros-on-twitter-spot-branden-williamsbrandenwilliams%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Branden+Williams%2F%40BrandenWilliams"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/twitter.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.anuesystems.com/blog/2009/08/18/security-pros-on-twitter-spot-branden-williamsbrandenwilliams/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Pros on Twitter (SPoT): Jennifer Jabbusch/@jjx</title>
		<link>http://www.anuesystems.com/blog/2009/08/12/security-pros-on-twitter-spot-jennifer-jabbuschjjx/</link>
		<comments>http://www.anuesystems.com/blog/2009/08/12/security-pros-on-twitter-spot-jennifer-jabbuschjjx/#comments</comments>
		<pubDate>Wed, 12 Aug 2009 13:44:43 +0000</pubDate>
		<dc:creator>Tommy P. Landry</dc:creator>
				<category><![CDATA[Infrastructure Security]]></category>
		<category><![CDATA[Network Monitoring]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[802.1X-REV]]></category>
		<category><![CDATA[@jjx]]></category>
		<category><![CDATA[carolina advanced digital]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[erin jacobs]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[host security]]></category>
		<category><![CDATA[IEEE]]></category>
		<category><![CDATA[interop]]></category>
		<category><![CDATA[jennifer jabbusch]]></category>
		<category><![CDATA[las vegas]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[mike fratto]]></category>
		<category><![CDATA[rich mogull]]></category>
		<category><![CDATA[rsa conference]]></category>
		<category><![CDATA[SecTor]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security uncorked]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[wireless security]]></category>

		<guid isPermaLink="false">http://www.anuesystems.com/blog/?p=304</guid>
		<description><![CDATA[We hope you enjoyed reading about Erin Jacobs last week. In this edition of SPoT, we offer you another respected security professional, and one who comes highly recommended by Ms. Jacobs - Jennifer Jabbusch.]]></description>
			<content:encoded><![CDATA[<p>We hope you enjoyed reading about Erin Jacobs last week. In this edition of SPoT, we offer you another respected security professional, and one who comes highly recommended by Ms. Jacobs &#8211; Jennifer Jabbusch.</p>
<div class="wp-caption alignright" style="width: 253px"><img class="  " title="SPoT: Jennifer Jabbusch / @jjx" src="http://www.anuesystems.com/blog/jj_20080726_crop1.jpg" alt="SPoT: Jennifer Jabbusch / @jjx" width="243" height="206" /><p class="wp-caption-text">SPoT: Jennifer Jabbusch / @jjx</p></div>
<p>Ms. Jabbusch is an experienced network security engineer and consultant at <a title="Carolina Advanced Digital" href="http://www.cadinc.com" target="_blank">Carolina Advanced Digital</a>. She holds a CISSP, among other certifications, and she also maintains the <a title="Security Uncorked" href="http://securityuncorked.com/" target="_blank">Security Uncorked, JJ&#8217;s Complete Unofficial Guide to Infosec</a> blog. Jennifer has consulted with a wide range of organizations and government entities, and she is also involved in various trainings and coursework to help share her security-related learnings.</p>
<p><strong>Real Name:</strong> Jennifer Jabbusch<br />
<strong>Twitter Handle:</strong> <a title="Twitter: Jennifer Jabbusch" href="http://twitter.com/jjx" target="_blank">@jjx</a><br />
<strong>Top 3 Social Media/Networking Sites:</strong><br />
<a title="LinkedIn" href="http://www.linkedin.com/" target="_blank">LinkedIn</a>, <a title="Facebook" href="http://www.facebook.com/" target="_blank">Facebook</a>, <a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a></p>
<p><strong><em>1. In which area(s) of security are you most involved?</em></strong><br />
<a title="NW: NW and Infra Security" href="http://www.networkworld.com/news/2009/080609-4-steps-to-better-network.html" target="_blank">Network &amp; Infrastructure Security</a></p>
<p><strong>2. What security topics will be the most important in the next 18 months? Why?</strong><br />
I could make up some great exciting answer here, but the truth is each organization is going to have their own top-priority security concern. Right now, I’m seeing trends from enterprise and government in <a title="Wikipedia: Wireless Security" href="http://en.wikipedia.org/wiki/Wireless_security" target="_blank">wireless security</a>, VoIP and the continuation of investigation in cloud and hosted security issues. In about 8-12 months, I think we’re going to see a renewed interest in the wired security standards that are coming with IEEE’s <a title="Security Uncorked: 802.1X-REV" href="http://securityuncorked.com/2008/05/8021x-rev-ya-heard-it-here-first/" target="_blank">802.1X-REV</a> because of the complete re-tooling of thought that will accompany it.</p>
<p><strong>3. Biggest Pet Peeve: Name one thing about Network Security that you wish business stakeholders would understand and why.</strong><br />
The intricacy of integration. The business side is used to solving problems with boxes. In the current network security environment, our solutions require an extensive amount of planning and integration between systems; you can’t simply install a magic box and make the problems go &#8220;bye-bye&#8221; any more.</p>
<p><strong>4. Tell us why you became so active on Twitter and any other important social media outlets. What value are you getting?</strong><br />
Several of my security colleagues dragged me in to <a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a> prior to a major security conference. I found it was a great way to share ideas, find others in my specific niche, and get feedback from colleagues. Of course, I definitely picked up a few new blog readers through Twitter, too.</p>
<p><strong>5. Name one security peer whom everyone with an interest in Network Security should follow. (Okay to name 2 if you can&#8217;t decide on only one)</strong><br />
Oh my gosh- that’s a hard one! There are so many people I get value from, for a variety of reasons. On the network security side, I’d have to say Mike Fratto (<a title="Twitter: Mike Fratto" href="http://twitter.com/mfratto" target="_blank">@mfratto</a>) for his unbiased and well-researched thoughts on various topics for Information Week. The next one that pops in my head would be Rich Mogull (<a title="Rich Mogull" href="http://twitter.com/rmogull" target="_blank">@rmogull) </a>because of his involvement in such a variety of interesting security-related projects. In addition to great security topics, these two, along with another dozen or so, keep me laughing each day.</p>
<p><strong>6. What&#8217;s your take on security for social media and cloud services in general? Top concerns, overstated issues, etc.</strong><br />
If I don’t own it, manage it, and see it; I don’t trust it. Our company policy mandates that no sensitive data is stored by a third party. We can outsource the services, but we’re not outsourcing the risk when the company&#8217;s reputation is at stake.</p>
<p><strong>7. What are the top 3 real-world (i.e. live) events you&#8217;d recommend for networking with security professionals?</strong><br />
My favorites are <a title="RSA USA" href="http://www.rsaconference.com/2009/us/planning.htm" target="_blank">RSA USA</a>, <a title="INTEROP Las Vegas" href="http://www.interop.com/lasvegas/" target="_blank">INTEROP Las Vegas</a>, and <a title="SecTor Conference" href="http://www.sector.ca/" target="_blank">SecTor</a>. I was most pleasantly surprised with the type of content and level of professionalism at SecTor last year. It’s the one conference I speak at that I get up early for and stay late so I can watch all the other talks. It’s just THAT good!</p>
<p class="bookmark-me">
    <script type="text/javascript">
	    yahooBuzzArticleHeadline = "Security Pros on Twitter (SPoT): Jennifer Jabbusch/@jjx";
	    yahooBuzzArticleId = "http://www.anuesystems.com/blog/2009/08/12/security-pros-on-twitter-spot-jennifer-jabbuschjjx/";
    </script>
    <script type="text/javascript"
        src="http://d.yimg.com/ds/badge2.js"
        badgetype="logo">
    </script>    
    <a title="technorati.com" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F12%2Fsecurity-pros-on-twitter-spot-jennifer-jabbuschjjx%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/technorati.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="del.icio.us" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F12%2Fsecurity-pros-on-twitter-spot-jennifer-jabbuschjjx%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jennifer+Jabbusch%2F%40jjx"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/delicious.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="stumbleupon.com" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F12%2Fsecurity-pros-on-twitter-spot-jennifer-jabbuschjjx%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jennifer+Jabbusch%2F%40jjx"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/stumbleupon.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="digg.com" href="http://digg.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F12%2Fsecurity-pros-on-twitter-spot-jennifer-jabbuschjjx%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jennifer+Jabbusch%2F%40jjx"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/digg.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.facebook.com" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F12%2Fsecurity-pros-on-twitter-spot-jennifer-jabbuschjjx%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Jennifer+Jabbusch%2F%40jjx"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/facebook.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="bookmarks.yahoo.com" href="http://bookmarks.yahoo.com/toolbar/savebm?opener=tb&amp;u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F12%2Fsecurity-pros-on-twitter-spot-jennifer-jabbuschjjx%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoo.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.google.com" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F12%2Fsecurity-pros-on-twitter-spot-jennifer-jabbuschjjx%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jennifer+Jabbusch%2F%40jjx"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/google.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="furl.com" href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F12%2Fsecurity-pros-on-twitter-spot-jennifer-jabbuschjjx%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Jennifer+Jabbusch%2F%40jjx"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/furl.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="reddit.com" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F12%2Fsecurity-pros-on-twitter-spot-jennifer-jabbuschjjx%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jennifer+Jabbusch%2F%40jjx"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/reddit.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="propeller.com" href="http://www.propeller.com/submit/?U=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F12%2Fsecurity-pros-on-twitter-spot-jennifer-jabbuschjjx%2F&amp;T=Security+Pros+on+Twitter+%28SPoT%29%3A+Jennifer+Jabbusch%2F%40jjx"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/propeller.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="windowslive.com" href="https://favorites.live.com/quickadd.aspx?mkt=en-us&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F12%2Fsecurity-pros-on-twitter-spot-jennifer-jabbuschjjx%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/windowslive.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="myweb2.search.yahoo.com" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F12%2Fsecurity-pros-on-twitter-spot-jennifer-jabbuschjjx%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoomyweb.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="linkedin.com" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F12%2Fsecurity-pros-on-twitter-spot-jennifer-jabbuschjjx%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jennifer+Jabbusch%2F%40jjx"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/linkedin.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="twitthis.com" href="http://twitthis.com/twit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F08%2F12%2Fsecurity-pros-on-twitter-spot-jennifer-jabbuschjjx%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Jennifer+Jabbusch%2F%40jjx"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/twitter.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.anuesystems.com/blog/2009/08/12/security-pros-on-twitter-spot-jennifer-jabbuschjjx/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Pros on Twitter (SPoT): James Arlen/@myrcurial</title>
		<link>http://www.anuesystems.com/blog/2009/07/21/security-pros-on-twitter-spot-james-arlenmyrcurial/</link>
		<comments>http://www.anuesystems.com/blog/2009/07/21/security-pros-on-twitter-spot-james-arlenmyrcurial/#comments</comments>
		<pubDate>Tue, 21 Jul 2009 16:39:59 +0000</pubDate>
		<dc:creator>Tommy P. Landry</dc:creator>
				<category><![CDATA[Network Monitoring]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[#FollowFriday]]></category>
		<category><![CDATA[Blackhat]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Defcon]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[Hotmail]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[James Arlen]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[LiquidMatrix]]></category>
		<category><![CDATA[myrcurial]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[SecTor]]></category>
		<category><![CDATA[Shmoocon]]></category>
		<category><![CDATA[SourceBoston]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.anuesystems.com/blog/?p=253</guid>
		<description><![CDATA[Beginning this week, we are kicking off our new SPOT (Security Pros on Twitter) series, profiling security professionals who are present and active on Twitter. We will profile one SP each week through the rest of the summer.

Since Anue Systems  (@AnueSystems) first joined in on the Twitter fun, we have followed and interacted with a variety of folks, and these are the thought leaders who we'd turn to first with a specific, hands-on question regarding security of the internal network, the cloud, or even virtualized environments.

Without further ado, let's get to it...]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignright" style="width: 240px"><img class="   " title="James Arlen (@myrcurial)" src="http://www.anuesystems.com/blog/Myrcurial.jpg" alt="SPot: James Arlen/@myrcurial" width="230" height="286" /><p class="wp-caption-text">SPoT: James Arlen (@myrcurial)</p></div>
<p>Beginning this week, we are kicking off our new SPoT (Security Pros on <a title="Twitter" href="http://twitter.com" target="_blank">Twitter</a>) series, profiling security professionals who are present and active on Twitter. We will profile one SP each week through the rest of the summer.</p>
<p>Since Anue Systems  (<a title="Anue Systems Twitter Profile" href="http://twitter.com/AnueSystems" target="_blank">@AnueSystems</a>) first joined in on the Twitter fun, we have followed and interacted with a variety of folks, and these are the thought leaders who we&#8217;d turn to first with a specific, hands-on question regarding security of the internal network, the cloud, or even virtualized environments.</p>
<p>Without further ado, let&#8217;s get to it&#8230;</p>
<p><strong>Real Name: </strong>James Arlen<br />
<strong>Twitter Handle: </strong><a title="myrcurial Twitter Profile" href="http://twitter.com/myrcurial" target="_blank">@myrcurial</a><br />
<strong>Top 3 Social Media/Networking Sites: </strong><br />
<a title="Twitter" href="http://twitter.com" target="_blank">Twitter </a>/ <a title="LinkedIn" href="http://www.linkedin.com/" target="_blank">LinkedIn </a>/ <a title="LiquidMatrix Security Digest" href="http://www.liquidmatrix.org/" target="_blank">Liquidmatrix Security Digest</a>!</p>
<p><em><strong>1. In which area(s) of security are you most involved?</strong></em><br />
I used to be technical/tactical &#8211; IT Security. These days, I&#8217;m spending most of my time working on Organizational Security and Risk Management.</p>
<p><em><strong>2. What security topics will be the most important in the next 18 months? Why?</strong></em><br />
Of key importance (of course) is going to be the increasingly porous &#8220;perimeter&#8221; which will surpass database flaws as the primary source of data breaches. Unfortunately, the vendors are not on our side and are not going to help solve the problem. It needs to be fixed at the employee/user level through increased awareness of the problem and active cooperation on solutions.</p>
<p><em><strong>3. Biggest Pet Peeve: Name one thing about Network Security that you wish business stakeholders would understand and why.</strong></em><br />
The thing that is the hardest to explain is that the presence of a firewall isn&#8217;t going to save you (the business user) from your own foolish actions &#8211; the best preventative technological controls available can be bypassed by (a) 14 year old kids and (b) users doing what they feel is the best thing at the time. <em>[Once more for effect</em>] A firewall won&#8217;t save you from sending your customer list to 100 sales people and 1 ex-sales person&#8217;s Hotmail account.</p>
<p><em><strong>4. Tell us why you became so active on Twitter and any other important social media outlets. What value are you getting?</strong></em><br />
The primary reason that I became active on Twitter is to have access to a peer group. The Canadian security space is fairly compact, and sometimes, having an international opinion is a great thing. And of course, [I'm there for] the fooling about and goofing off &#8211; Twitter is an outlet for stress as much as it is an inlet for knowledge.</p>
<p><em><strong>5. Name one security peer whom everyone with an interest in Network Security should follow. (OK to name 2 if you can&#8217;t decide on only one)</strong></em><br />
Wow &#8211; it&#8217;s <a title="#FollowFriday search on Twitter" href="http://search.twitter.com/search?q=%23FollowFriday" target="_blank">#FollowFriday</a>! If you&#8217;re focused on Network Security, you should really be following <a title="Jack Daniel Twitter Profile" href="http://twitter.com/jack_daniel" target="_blank">@jack_daniel</a> and <a title="Jennifer J. Twitter Profile" href="http://twitter.com/jjx" target="_blank">@jjx</a>. He&#8217;s a curmudgeon who generally cuts to the core of the issue FAST. She&#8217;s about as unlikely a security expert as you can imagine &#8211; short, blonde, southern accent &#8211; but if you&#8217;re mature enough to value people for their skill rather than the package, she&#8217;ll teach you a thing or two that you never expected. <em>[The Network View has engaged with both of these security experts for inclusion in SPoT series as well.]</em></p>
<p><em><strong>6. What&#8217;s your take on security for social media and cloud services in general? Top concerns, overstated issues, etc.</strong></em><br />
Security &#8211; for social media? I&#8217;m pretty sure there isn&#8217;t much of that. My simplest response is that you shouldn&#8217;t depend on social media to provide you with any security &#8211; if you&#8217;re not comfortable putting it on a postcard or wearing it on a t-shirt, you shouldn&#8217;t be posting it to a social media site. With regard to cloud security &#8211; ask <a title="Beaker Twitter Profile" href="http://twitter.com/beaker" target="_blank">@Beaker</a>, I get all of my opinions from him.</p>
<p><strong><em>7. What are the top 3 real-world (i.e. live) events you&#8217;d recommend for networking with security professionals?</em></strong><br />
The number one thing is to remember that for any event &#8211; from a local SIG all the way up to <a title="Blackhat" href="http://www.blackhat.com/" target="_blank">Blackhat </a>or <a title="RSA Conference" href="https://365.rsaconference.com/index.jspa" target="_blank">RSA </a>- the most important thing to do is cruise the &#8220;Hallway Track&#8221;, get involved in conversations, and have an opinion. If you were coming to me and asking me where to spend your money &#8211; considering value for dollar &#8211; <a title="Defcon" href="http://www.defcon.org/" target="_blank">DEFCON</a>, <a title="Shmoocon" href="http://www.shmoocon.org/" target="_blank">Shmoocon</a>/<a title="Source Conference" href="http://www.sourceconference.com/" target="_blank">SourceBoston</a>/<a title="SecTor Conference" href="http://www.sector.ca/" target="_blank">SecTor</a>, and your local SIG. The big names (<a title="RSA Conference" href="https://365.rsaconference.com/index.jspa" target="_blank">RSA</a> and <a title="Blackhat" href="http://www.blackhat.com/" target="_blank">Blackhat</a>) are awesome, but unless someone is covering the tab, they&#8217;re crazy expensive and you can get the same content at the second tier conferences for less money with better access to the speakers.</p>
<p class="bookmark-me">
    <script type="text/javascript">
	    yahooBuzzArticleHeadline = "Security Pros on Twitter (SPoT): James Arlen/@myrcurial";
	    yahooBuzzArticleId = "http://www.anuesystems.com/blog/2009/07/21/security-pros-on-twitter-spot-james-arlenmyrcurial/";
    </script>
    <script type="text/javascript"
        src="http://d.yimg.com/ds/badge2.js"
        badgetype="logo">
    </script>    
    <a title="technorati.com" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/technorati.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="del.icio.us" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+James+Arlen%2F%40myrcurial"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/delicious.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="stumbleupon.com" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+James+Arlen%2F%40myrcurial"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/stumbleupon.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="digg.com" href="http://digg.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+James+Arlen%2F%40myrcurial"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/digg.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.facebook.com" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+James+Arlen%2F%40myrcurial"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/facebook.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="bookmarks.yahoo.com" href="http://bookmarks.yahoo.com/toolbar/savebm?opener=tb&amp;u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoo.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.google.com" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+James+Arlen%2F%40myrcurial"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/google.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="furl.com" href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+James+Arlen%2F%40myrcurial"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/furl.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="reddit.com" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+James+Arlen%2F%40myrcurial"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/reddit.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="propeller.com" href="http://www.propeller.com/submit/?U=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F&amp;T=Security+Pros+on+Twitter+%28SPoT%29%3A+James+Arlen%2F%40myrcurial"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/propeller.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="windowslive.com" href="https://favorites.live.com/quickadd.aspx?mkt=en-us&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/windowslive.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="myweb2.search.yahoo.com" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoomyweb.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="linkedin.com" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+James+Arlen%2F%40myrcurial"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/linkedin.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="twitthis.com" href="http://twitthis.com/twit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+James+Arlen%2F%40myrcurial"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/twitter.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.anuesystems.com/blog/2009/07/21/security-pros-on-twitter-spot-james-arlenmyrcurial/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
