<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Network View &#187; ruby on rails</title>
	<atom:link href="http://www.anuesystems.com/blog/tag/ruby-on-rails/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anuesystems.com/blog</link>
	<description></description>
	<lastBuildDate>Thu, 15 Jul 2010 15:30:09 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Security Pros on Twitter (SPoT): Alex Hutton/@AlexHutton</title>
		<link>http://www.anuesystems.com/blog/2009/09/15/security-pros-on-twitter-spot-alex-hutton/</link>
		<comments>http://www.anuesystems.com/blog/2009/09/15/security-pros-on-twitter-spot-alex-hutton/#comments</comments>
		<pubDate>Tue, 15 Sep 2009 15:30:52 +0000</pubDate>
		<dc:creator>Tommy P. Landry</dc:creator>
				<category><![CDATA[Monitoring Optimization]]></category>
		<category><![CDATA[Network Monitoring]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[@alexhutton]]></category>
		<category><![CDATA[@gattaca]]></category>
		<category><![CDATA[@sfoak]]></category>
		<category><![CDATA[Adam Shostack]]></category>
		<category><![CDATA[alex hutton]]></category>
		<category><![CDATA[Andrew Stewart]]></category>
		<category><![CDATA[archer]]></category>
		<category><![CDATA[brooke paul]]></category>
		<category><![CDATA[business intelligence]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[dan houser]]></category>
		<category><![CDATA[dave lewis]]></category>
		<category><![CDATA[david mortman]]></category>
		<category><![CDATA[ed bellis]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[grc]]></category>
		<category><![CDATA[infraguard]]></category>
		<category><![CDATA[isaca]]></category>
		<category><![CDATA[issa]]></category>
		<category><![CDATA[jabber]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[management science]]></category>
		<category><![CDATA[masters of beer appreciation]]></category>
		<category><![CDATA[miryokuteki hinshitsu]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[ruby on rails]]></category>
		<category><![CDATA[security management]]></category>
		<category><![CDATA[security mba]]></category>
		<category><![CDATA[security metrics]]></category>
		<category><![CDATA[shrdlu]]></category>
		<category><![CDATA[the new school of information security]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.anuesystems.com/blog/?p=358</guid>
		<description><![CDATA[Welcome to our ninth installment of Security Pros on Twitter.  This week, we are featuring Alex Hutton, who "works in Risk Intelligence for a Fortune-something company", according to his profile on The New School of Information Security blog, where Alex is one of the main contributors of content. The blog shares its name with a 2008 book authored by blog founders Adam Shostack and Andrew Stewart, and they are joined by some savvy security pros including Alex, David Mortman, and Brooke Paul. Mr. Hutton has been involved in security since the early '90s, and we are very glad to profile him as a SPoT.]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 132px"><img title="SPoT: Alex Hutton / @AlexHutton" src="http://newschoolsecurity.com/images/alex-sm.jpg" alt="SPoT: Alex Hutton / @AlexHutton" width="122" height="123" /><p class="wp-caption-text">SPoT: Alex Hutton / @AlexHutton</p></div>
<p>Welcome to our ninth installment of <a title="Security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">Security</a> Pros on Twitter.  This week, we are featuring Alex Hutton, who &#8220;works in Risk Intelligence for a Fortune-something company&#8221;, according to his profile on <a title="The New School of Information Security blog" href="http://newschoolsecurity.com/" target="_blank">The New School of Information Security blog</a>, where Alex is one of the main contributors of content. The blog shares its name with a 2008 book authored by blog founders Adam Shostack and Andrew Stewart, and they are joined by some savvy <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> pros including Alex, <a title="Twitter: David Mortman" href="http://twitter.com/mortman" target="_blank">David Mortman</a>, and Brooke Paul. Mr. Hutton has been involved in <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> since the early &#8217;90s, and we are very glad to profile him as a SPoT.</p>
<p><strong>Real Name:</strong> Alex Hutton<br />
<strong>Twitter Handle:</strong> <a title="Twitter: Alex Hutton" href="http://twitter.com/alexhutton" target="_blank">@alexhutton</a><br />
<strong>Top 3 Social Media/Networking Sites:</strong><br />
<a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a>, <a title="Facebook" href="http://www.facebook.com/" target="_blank">Facebook</a>, <a title="LinkedIn" href="http://www.linkedin.com/" target="_blank">LinkedIn</a></p>
<p><em><strong>1. In which area(s) of <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> are you most involved? </strong></em><br />
I love <a title="Wikipedia: Risk Management" href="http://en.wikipedia.org/wiki/Risk_management" target="_blank">Risk</a>, <a title="Wikipedia: Management Science" href="http://en.wikipedia.org/wiki/Management_science" target="_blank">Management Science</a>, &amp; <a title="SANS: A Guide to Security Metrics" href="http://www.sans.org/reading_room/whitepapers/auditing/a_guide_to_security_metrics_55?show=55.php&amp;cat=auditing" target="_blank">Security Metrics</a>.</p>
<p><strong><em>2. What <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> topics will be the most important in the next 18 months? Why? </em></strong><br />
Regulatory pressures &amp; <a title="Wikipedia: Business Intelligence" href="http://en.wikipedia.org/wiki/Business_intelligence" target="_blank">Business Intelligence</a>.</p>
<p>I think we&#8217;re going to see Regulatory pressures (both government and private pressures) increase, because I believe that our industry will continue to see people outside our profession try to &#8220;solve&#8221; our problems for us.  The danger being that their good intentions will lead us towards an undesirable destination.</p>
<p>Business Intelligence for InfoSec, done right, could be a major catalyst towards solving significant problems in <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a>.  If we&#8217;re lucky, it&#8217;ll destroy <a title="GRC" href="https://www.grc.com/passwords.htm" target="_blank">GRC</a> as we know it.</p>
<p><em><strong>3. Biggest Pet Peeve: Name one thing about Network <a title="Security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">Security</a> that you wish business stakeholders would understand and why.</strong></em><br />
Wow, if you&#8217;ll forgive me for saying so, I think that question is backwards.  If you think about it, it&#8217;s rather egotistical to think that &#8220;they&#8221; need to &#8220;get&#8221; us.  Nope, my perspective is that they sign the paychecks, so &#8220;we&#8221; need to &#8220;get&#8221; them.</p>
<p><em><strong>4. Tell us why you became so active on Twitter and any other important social media outlets. What value are you getting?</strong></em><br />
I became active when I was developing Risk Analytical software using <a title="Ruby On Rails" href="http://rubyonrails.org/" target="_blank">Ruby On Rails</a>.  <a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a> was just kind of experimental then, a neat <a title="RoR App" href="http://rubyonrails.org/applications" target="_blank">RoR app</a> to play with.  I was also very interested in how my application would provide <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> practitioners with a feeling of &#8220;<a title="Wikipedia: Miryokuteki Hinshitsu" href="http://en.wikipedia.org/wiki/Miryokuteki_Hinshitsu" target="_blank">Miryokuteki Hinshitsu</a>&#8220;, and thought maybe Twitter (or rather twitter-like functionality) might be a piece of that.  The idea being rather than long, arduous web forms in <a title="Archer Software" href="http://www.archer-soft.com/project-management.htm" target="_blank">Archer</a>-like software for project management, <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> analysts could just &#8220;tweet&#8221; their processes and outcomes back to a central server using an <a title="Wikipedia: Instant Messaging" href="http://en.wikipedia.org/wiki/Instant_messaging" target="_blank">IM</a>-like interface (yeah, this was back when you could still use <a title="Jabber" href="http://www.jabber.org/" target="_blank">Jabber</a> for Twitter).</p>
<p>The value I get is twofold.  First, I get to meet good people.  That&#8217;s important, as everyone has perspective that contributes to your world view, and I believe that your world view is only as good as it is broad.  Second, and related to that, I get to watch really smart people talk.  For example, I used to <em>despise</em> <a title="PCI-DSS: About" href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank">PCI-DSS</a>, and now I don&#8217;t.  That&#8217;s largely because of conversations I&#8217;ve had with <a title="Twitter: Mike (sfoak)" href="http://twitter.com/sfoak" target="_blank">@sfoak</a> and others on Twitter who desire that we stop whining and start solving problems.</p>
<p><em><strong>5. Name one <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> peer whom everyone with an interest in Network <a title="Security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">Security</a> should follow. (Okay to name two if you can&#8217;t decide on only one)</strong></em><br />
Only two?!  <a title="Twitter: Ed Bellis" href="http://twitter.com/ebellis" target="_blank">Ed Bellis (@ebellis)</a> and <a title="Twitter: Dave Lewis" href="http://twitter.com/gattaca" target="_blank">Dave Lewis (@gattaca)</a> &#8211; both <a title="Wikipedia: Security Management" href="http://en.wikipedia.org/wiki/Security_management" target="_blank">Security Management</a>, both with massive amounts of &#8220;get it&#8221;ness.  Apologies to dozens of others I would have liked to have mentioned.  And everybody mentions <a title="Twitter: shrdlu" href="http://twitter.com/shrdlu" target="_blank">@shrdlu</a>, so he goes without saying.</p>
<p><em><strong>6. What&#8217;s your take on <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> for social media and cloud services in general? Top concerns, overstated issues, etc.</strong></em><br />
IMHO, <a title="Wikipedia: Social Media" href="http://en.wikipedia.org/wiki/Social_media" target="_blank">social media</a> represents more of a time-wasting threat than new attack vector threat.  With regards to the <a title="Wikipedia: Cloud Computing" href="http://en.wikipedia.org/wiki/Cloud_computing" target="_blank">cloud</a>, it&#8217;s going to be a mess. And I like that.</p>
<p><em><strong>7. What are the top 3 real-world (i.e. live) events you&#8217;d recommend for networking with <a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a> professionals?</strong></em><br />
I would break down real world events into two categories &#8211; local and non-local.  Pick any of the large non-local events to try to get travel budget for.  Networking with peers is super-important for your career on so many levels.  That said, I&#8217;d spend a ton of time getting to know the local environment, even if that means creating your own informal events (especially  if your <a title="ISSA" href="http://www.issa.org/" target="_blank">ISSA</a>/<a title="ISACA" href="http://www.isaca.org/" target="_blank">ISACA</a>/<a title="InfraGard" href="http://www.infragard.net/" target="_blank">Infraguard</a> meetings are &#8220;Death by Powerpoint&#8221;, with little time for socialization).  The most successful professional events I&#8217;ve ever gone to was our <a title="Security Masters of Beer Appreciation Group, LinkedIn" href="http://www.linkedin.com/groupInvitation?groupID=1780794&amp;sharedKey=506602733EE1" target="_blank">Security MBA</a> (Masters of Beer Appreciation) events in Columbus organized by <a title="Twitter: Dan Houser" href="http://twitter.com/1cissp" target="_blank">Dan Houser</a>.  We can put our professional guard down, not be over-exposed to some &#8220;speaker&#8221;, and really have meaningful conversations about our professional and personal lives.</p>
<p class="bookmark-me">
    <script type="text/javascript">
	    yahooBuzzArticleHeadline = "<a title="Security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">Security</a> Pros on Twitter (SPoT): Alex Hutton/@AlexHutton";
	    yahooBuzzArticleId = "http://www.anuesystems.com/blog/2009/09/15/<a title="security" href="http://anuesystems.com/Resources_NTO_EyeonSecurity_Home.shtml" title="Eye on Security">security</a>-pros-on-twitter-spot-alex-hutton/";
    </script>
    <script type="text/javascript"
        src="http://d.yimg.com/ds/badge2.js"
        badgetype="logo">
    </script>    
    <a title="technorati.com" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/technorati.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="del.icio.us" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Alex+Hutton%2F%40AlexHutton"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/delicious.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="stumbleupon.com" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Alex+Hutton%2F%40AlexHutton"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/stumbleupon.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="digg.com" href="http://digg.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Alex+Hutton%2F%40AlexHutton"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/digg.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.facebook.com" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Alex+Hutton%2F%40AlexHutton"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/facebook.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="bookmarks.yahoo.com" href="http://bookmarks.yahoo.com/toolbar/savebm?opener=tb&amp;u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoo.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.google.com" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Alex+Hutton%2F%40AlexHutton"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/google.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="furl.com" href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Alex+Hutton%2F%40AlexHutton"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/furl.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="reddit.com" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Alex+Hutton%2F%40AlexHutton"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/reddit.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="propeller.com" href="http://www.propeller.com/submit/?U=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F&amp;T=Security+Pros+on+Twitter+%28SPoT%29%3A+Alex+Hutton%2F%40AlexHutton"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/propeller.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="windowslive.com" href="https://favorites.live.com/quickadd.aspx?mkt=en-us&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/windowslive.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="myweb2.search.yahoo.com" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoomyweb.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="linkedin.com" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Alex+Hutton%2F%40AlexHutton"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/linkedin.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="twitthis.com" href="http://twitthis.com/twit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F09%2F15%2Fsecurity-pros-on-twitter-spot-alex-hutton%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Alex+Hutton%2F%40AlexHutton"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/twitter.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.anuesystems.com/blog/2009/09/15/security-pros-on-twitter-spot-alex-hutton/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
