<?xml version="1.0" encoding="ISO-8859-1"?>
<!-- generator="FeedCreator 1.7.2-ppt (info@mypapit.net)" -->
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="http://sun.systemnews.com/rss/IT-News-Watch-Security">
        <title>System News for Sun Users</title>
        <description>News about IT News Watch - Security</description>
        <link>http://sun.systemnews.com</link>
       <dc:date>2013-06-20T06:43:37+01:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/184/2/IT-News-Watch-Security/31416"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/184/2/IT-News-Watch-Security/31417"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/184/2/IT-News-Watch-Security/31418"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/184/1/IT-News-Watch-Security/31317"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/184/1/IT-News-Watch-Security/31318"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/184/1/IT-News-Watch-Security/31319"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/184/1/IT-News-Watch-Security/31320"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/184/1/IT-News-Watch-Security/31321"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/183/5/IT-News-Watch-Security/31235"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/183/5/IT-News-Watch-Security/31236"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/183/3/IT-News-Watch-Security/31031"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/183/3/IT-News-Watch-Security/31034"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/183/2/IT-News-Watch-Security/30931"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/182/2/IT-News-Watch-Security/30545"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/182/2/IT-News-Watch-Security/30546"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/182/2/IT-News-Watch-Security/30552"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/182/1/IT-News-Watch-Security/30448"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/182/1/IT-News-Watch-Security/30451"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/182/1/IT-News-Watch-Security/30452"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/181/4/IT-News-Watch-Security/30358"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/181/4/IT-News-Watch-Security/30365"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/181/4/IT-News-Watch-Security/30366"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/181/3/IT-News-Watch-Security/30266"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/181/3/IT-News-Watch-Security/30275"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/181/2/IT-News-Watch-Security/30169"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/181/2/IT-News-Watch-Security/30170"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/181/2/IT-News-Watch-Security/30176"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/181/1/IT-News-Watch-Security/30082"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/181/1/IT-News-Watch-Security/30083"/>
                <rdf:li rdf:resource="http://sun.systemnews.com/articles/181/1/IT-News-Watch-Security/30085"/>
            </rdf:Seq>
        </items>
    </channel>
    <item rdf:about="http://sun.systemnews.com/articles/184/2/IT-News-Watch-Security/31416">
        <dc:format>text/html</dc:format>
        <dc:date>2013-06-14T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>9 Tips, Tricks and Must-Haves for Security Awareness Programs</title>
        <link>http://sun.systemnews.com/articles/184/2/IT-News-Watch-Security/31416</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/184/2/IT-News-Watch-Security/31416&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/184/2/networkworld.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;What are the essential ingredients for making a security awareness program successful?&quot; asks Joan Goodchild in &quot;Network World&quot;.

&lt;p&gt;
&quot;Check out these 9 tips from CSO contributors on how to make awareness work in your organization:&quot;

&lt;p&gt;

&lt;ul&gt;

&lt;li&gt;Metrics

&lt;li&gt;Flexibility

&lt;li&gt;Some allowance of rule breaking

&lt;li&gt;A challenging new approach

&lt;li&gt;C-Level support 

&lt;li&gt;Partnering with key departments

&lt;li&gt;Creativity

&lt;li&gt;An effective time frame

&lt;li&gt;A multimedia approach

&lt;/ul&gt;

&lt;p&gt;
Read on for details.  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/184/2/IT-News-Watch-Security/31417">
        <dc:format>text/html</dc:format>
        <dc:date>2013-06-14T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>Is Security Professional Development Too Expensive?</title>
        <link>http://sun.systemnews.com/articles/184/2/IT-News-Watch-Security/31417</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/184/2/IT-News-Watch-Security/31417&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/184/2/darkreading.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;Paid trainings and certificates serve vital role, but open-source-style security education offerings could make the entire security education field more complete and affordable,&quot; comments Ericka Chickowski in &quot;Dark Reading&quot;.

&lt;p&gt;
&quot;As the security industry continues to grapple with a shortage in skilled professionals, particularly within very specific niches like application security, the state of security professional development continues to keep the industry locked up in a number of hotly contested debates. Beyond the most obvious argument over the value of security certifications, some security pundits have stepped up to argue about a more fundamental impediment to rising the tide for all boats in the industry: the cost of paid training...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/184/2/IT-News-Watch-Security/31418">
        <dc:format>text/html</dc:format>
        <dc:date>2013-06-14T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>Rogue Employees, Malware Exploits and Unauthorized Software</title>
        <link>http://sun.systemnews.com/articles/184/2/IT-News-Watch-Security/31418</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/184/2/IT-News-Watch-Security/31418&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/184/2/net-security.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;While IT security professionals recognize the threat posed by unwitting employees, many still admit to allowing administrative privileges to go unmanaged, making organizations increasingly vulnerable to malware exploits and unauthorized software, according to Avecto,&quot; writes &lt;A HREF=&quot;http://sun.systemnews.com/go/2?a=31418&amp;l=http%3A%2F%2Fwww.net-security.org%2Fsecworld.php%3Fid%3D15017&quot; target=&quot;_new&quot;&gt;HelpNet Security&lt;/A&gt;.

&lt;p&gt;
&quot;The study, conducted at Infosecurity Europe in London, UK, surveyed more than 500 decision-making information security professionals. It reveals the extent to which organizations allow employees full control over their desktops, without implementing adequate controls to defend against accidental or deliberate misuse of privileges...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/184/1/IT-News-Watch-Security/31317">
        <dc:format>text/html</dc:format>
        <dc:date>2013-06-08T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>3 Lessons from Layered Defense's Missed Attacks</title>
        <link>http://sun.systemnews.com/articles/184/1/IT-News-Watch-Security/31317</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/184/1/IT-News-Watch-Security/31317&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/184/1/darkreading.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;Layering security measures typically protects systems better: Research (PDF) by three University of Michigan graduate students in 2008, for example, found that using multiple antivirus engines result in much better protection than using a single program&quot;, reports Robert Lemos in &quot;Dark Reading&quot;.

&lt;p&gt;
&quot;Yet recent analysis by NSS Labs highlights that layering security devices rarely catches all attacks, and the attacks that manage to dodge defenses do so with regularity. The analysis -- a survey of the company&amp;#39;s past tests of next-generation firewalls, intrusion prevention systems, and endpoint protection software -- found that the tested products tended to fail in similar ways. While two products always performed better together than individually, their combined performances varied tremendously...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/184/1/IT-News-Watch-Security/31318">
        <dc:format>text/html</dc:format>
        <dc:date>2013-06-08T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>How to Secure USB Drives and Other Portable Storage Devices</title>
        <link>http://sun.systemnews.com/articles/184/1/IT-News-Watch-Security/31318</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/184/1/IT-News-Watch-Security/31318&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/184/1/itworld.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;As individuals and organizations digitize more data, they become more susceptible to major data breaches,&quot; comments Paul Mah in &quot;IT World&quot;.

&lt;p&gt;
&quot;Though convenient, inexpensive USB flash memory sticks and other portable storage devices certainly don&amp;#39;t help the cause, beacuse workers use them transport databases and other confidential information. On top of the real danger of misused data, major data breaches also cause damaging negative publicity.

&lt;p&gt;
It may seem inherently complex, but securing portable storage devices is within reach for small businesses. Here&amp;#39;s what organizations can do to secure their data...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/184/1/IT-News-Watch-Security/31319">
        <dc:format>text/html</dc:format>
        <dc:date>2013-06-08T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>Security Pros Fail In Business Lingo</title>
        <link>http://sun.systemnews.com/articles/184/1/IT-News-Watch-Security/31319</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/184/1/IT-News-Watch-Security/31319&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/184/1/darkreading.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;Kelly Jackson Higgins writes in &quot;Dark Reading&quot;, &quot;Non-executive-level security professionals just aren&amp;#39;t communicating well or coherently with senior executives, a new survey shows.

&lt;p&gt;
That&amp;#39;s in contrast to their superiors on the executive side of the security house, who appear to have somewhat hacked the proper business language and perspective: While about 38 percent of non-exec security pros say they use business-oriented language when they communicate with corporate execs, nearly half of exec-level security pros say they do...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/184/1/IT-News-Watch-Security/31320">
        <dc:format>text/html</dc:format>
        <dc:date>2013-06-08T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>University Fined $400,000 After Disabled Firewall Put Medical Records at Risk</title>
        <link>http://sun.systemnews.com/articles/184/1/IT-News-Watch-Security/31320</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/184/1/IT-News-Watch-Security/31320&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/184/1/techworld.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;A medical facility run by Idaho State University (ISU) has been fined $400,000 after thousands of patient records were left in an unprotected state when firewall monitoring was disabled,&quot; reports John E Dunn in  &quot;TechWorld&quot;].

&lt;p&gt;
&quot;According to the medical information commissioner, the US Department of Health Human Services (HHS), the records of 17,500 patients at the University&amp;#39;s 29 Pocatello Family Medicine Clinics were left unsecured for 10 months...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/184/1/IT-News-Watch-Security/31321">
        <dc:format>text/html</dc:format>
        <dc:date>2013-06-08T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>Why We Won't Get International Cyberwarfare Standards</title>
        <link>http://sun.systemnews.com/articles/184/1/IT-News-Watch-Security/31321</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/184/1/IT-News-Watch-Security/31321&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/184/1/internetevolution.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;ASA Risk Consultants added its voice this week to the slowly growing chorus of voices demanding a coordinated international response to cyberattacks. In a research note circulated by IDG, ASA asserts that &amp;#39;nations will need to come to an agreement on how cyber warfare should be handled,&quot; reports  Kim Davis in &quot;Internet Evolution&quot;.

&lt;p&gt;
&quot;Nations should establish lasting peace and end world poverty, too. There&amp;#39;s always something new for the to-do list. Don&amp;#39;t hold your breath on any of these...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/183/5/IT-News-Watch-Security/31235">
        <dc:format>text/html</dc:format>
        <dc:date>2013-06-02T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>Experts Highlight Top Data Breach Vulnerabilities</title>
        <link>http://sun.systemnews.com/articles/183/5/IT-News-Watch-Security/31235</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/183/5/IT-News-Watch-Security/31235&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/183/5/net-security.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;Hidden vulnerabilities lie in everyday activities that can expose personal information and lead to data breach, including buying gas with a credit card or wearing a pacemaker,&quot; reports and article in  &quot;Help Net Security&quot;.

&lt;p&gt;
&quot;Every transaction and health record is now collected, categorized, sorted, and analyzedÂ'and can be hacked. Microcomputers that control aspects of everyday lifeÂ'from heart rhythms and insulin levels, to the operation of manufacturing plants and data centers, to the use of electricity in homes and gasoline usage in carsÂ'are increasingly at risk for data breach and can threaten public safety.

&lt;p&gt;
Industry experts offer insights on top hidden vulnerabilities that can cause data breach:...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/183/5/IT-News-Watch-Security/31236">
        <dc:format>text/html</dc:format>
        <dc:date>2013-06-02T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>Too Much Infosec Regulation Undermines Security, Warns NAB</title>
        <link>http://sun.systemnews.com/articles/183/5/IT-News-Watch-Security/31236</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/183/5/IT-News-Watch-Security/31236&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/183/5/theregister.co.uk.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;More prescriptive regulation of the security posture in industry sectors like banking could have the paradoxical impact of reducing security, according to Andrew Dell, head of IT security services at the National Australia Bank,&quot; reports Richard Chirgwin in &quot;The Register&quot;.

&lt;p&gt;
&quot;&amp;#39;We have to become much more agile and proactive Â- how we look at, how we react to cybercrime. Our posture is changing from &amp;#39;observe and analyse&amp;#39; to &amp;#39;detect and respond&amp;#39;,&amp;#39; Dell told the 2013 Trend Micro Evolve Security Conference...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/183/3/IT-News-Watch-Security/31031">
        <dc:format>text/html</dc:format>
        <dc:date>2013-05-19T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>10 Reasons SQL Injection Still Works</title>
        <link>http://sun.systemnews.com/articles/183/3/IT-News-Watch-Security/31031</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/183/3/IT-News-Watch-Security/31031&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/183/3/darkreading.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;After all of these years, SQL injection vulnerabilities still stand as an old reliable for attackers seeking to break into corporate databases,&quot; writes Ericka Chickowski in &quot;Dark Reading&quot;.

&lt;p&gt;
&quot;Beyond the obvious &quot;hackers do what works&quot; explanation, there are additional dynamics at play that keep SQL injection in the limelight. Among the top 10 most impactful reasons why SQL injection persists, experts named technical missteps, business process issues, and attack environment factors. Here&amp;#39;s how they broke things down...&quot;

&lt;p&gt;

&lt;ul&gt;

&lt;li&gt;We&amp;#39;re Maintaining Juicy Targets

&lt;li&gt;At Least Go Least Privilege

&lt;li&gt;SQLi: Attacker&amp;#39;s &quot;Easy Button&quot;

&lt;li&gt;Insecure Development Architecture

&lt;li&gt;Trusting Input

&lt;li&gt;Agnosticism At All Costs

&lt;li&gt;Legacy Code

&lt;li&gt;Code Samples Outdated

&lt;li&gt;Flaws Easy To Fall Through Cracks

&lt;li&gt;Budget Shortfalls

&lt;/ul&gt;

&lt;p&gt;
Read on for details.  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/183/3/IT-News-Watch-Security/31034">
        <dc:format>text/html</dc:format>
        <dc:date>2013-05-19T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>6 Steps for a Successful Data Security Control Implementation</title>
        <link>http://sun.systemnews.com/articles/183/3/IT-News-Watch-Security/31034</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/183/3/IT-News-Watch-Security/31034&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/183/3/informationweek.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;Neil Thacker, writing for &quot;Information Week&quot;], reports,
&quot;It&amp;#39;s time to move from infrastructure-only security to infrastructure and data security control, asserts Neil Thacker, Security and Strategy officer, Websense. He shares six steps for a successful data security control implementation...&quot;

&lt;p&gt;

&lt;ul&gt;

&lt;li&gt;Calculate the value of your data 

&lt;li&gt;Make your ROI case

&lt;li&gt;Monitor and log your data

&lt;li&gt;Apply data security controls 

&lt;li&gt;Find your data 

&lt;li&gt;Implement proactive protection and up employee education

&lt;/ul&gt;

&lt;p&gt;
Read on for details.  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/183/2/IT-News-Watch-Security/30931">
        <dc:format>text/html</dc:format>
        <dc:date>2013-05-12T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>What's The Secret to a Great Password?</title>
        <link>http://sun.systemnews.com/articles/183/2/IT-News-Watch-Security/30931</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/183/2/IT-News-Watch-Security/30931&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/183/2/smallbusiness.yahoo.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;As your neighbors leave their house one morning, you see them slip a spare house key from under their doormat, then set the key on top of the mat, where it glints in the sun. That&amp;#39;s essentially the same as scrawling a username and password on a bright Post-it note, then sticking it on the computer monitor,&quot; opines Erin Delaney in an article for &quot;Yahoo Small Advisor.&quot;

&lt;p&gt;
&quot;If the Post-it password seems foolish, it&amp;#39;s also revealing. With every new login a person creates, the person is forced to balance competing agendas of efficiency, security and human memory...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/182/2/IT-News-Watch-Security/30545">
        <dc:format>text/html</dc:format>
        <dc:date>2013-04-22T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>Employees Still Use Online File Sharing, Even If Companies Prohibit Its Use</title>
        <link>http://sun.systemnews.com/articles/182/2/IT-News-Watch-Security/30545</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/182/2/IT-News-Watch-Security/30545&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/182/2/computerworld.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;More than 75% of corporations have policies that prohibit the use of consumer online file sharing and collaboration tools, yet employee use of the services is still rampant, according to an Enterprise Strategy Group survey.
reports Lucas Mearian in &quot;ComputerWorld.&quot;

&lt;p&gt;
&quot;The thing is, IT had control of the data in the past. Now, it has only been three years since this (OFS) market has taken off and now data is everywhere,&quot; said Terri McClure, who spoke at SNW here Tuesday...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/182/2/IT-News-Watch-Security/30546">
        <dc:format>text/html</dc:format>
        <dc:date>2013-04-22T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>Making Security Simple</title>
        <link>http://sun.systemnews.com/articles/182/2/IT-News-Watch-Security/30546</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/182/2/IT-News-Watch-Security/30546&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/182/2/csoonline.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;Conventional wisdom says that simple security is an oxymoron. Good security is complex, while uncomplicated security is weak,&quot;
writes Stefan Hammond in &quot;CSO Online&quot;].

&lt;p&gt;

&lt;p&gt;
Whenever security is discussed, I think of Bruce Schneier. The US-based security guru describes crime and prevention forcefully. What&amp;#39;s YOUR security profile?

&lt;p&gt;
Much of our everyday security practices are unconscious, notes Schneier. We do them out of habit, and don&amp;#39;t recognize them as strategic security decisions...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/182/2/IT-News-Watch-Security/30552">
        <dc:format>text/html</dc:format>
        <dc:date>2013-04-22T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>How Attackers Choose Which Vulnerabilities to Exploit</title>
        <link>http://sun.systemnews.com/articles/182/2/IT-News-Watch-Security/30552</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/182/2/IT-News-Watch-Security/30552&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/182/2/darkreading.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;It&amp;#39;s an old but true adage: To protect yourself against a criminal, you have to think like a criminal. This certainly applies to IT security professionals working to keep their organizations&amp;#39; systems and data safe: To protect against a cyber attacker, you have to think like a cyber attacker,&quot; writes Michael Cobb
in &quot;Dark Reading.&quot;

&lt;p&gt;
According to Verizon&amp;#39;s 2012 Data Breach Investigations Report, 81% of data breaches utilized some form of hacking, and 94% of the attacks were not classified as difficult. Even those attacks that were more complex often used simple techniques to gain an initial foothold...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/182/1/IT-News-Watch-Security/30448">
        <dc:format>text/html</dc:format>
        <dc:date>2013-04-22T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>Victim of $440K Wire Fraud Can't Blame Bank for Loss, Judge Rules</title>
        <link>http://sun.systemnews.com/articles/182/1/IT-News-Watch-Security/30448</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/182/1/IT-News-Watch-Security/30448&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/182/1/computerworld.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;A federal court in Missouri has rejected an escrow firm&amp;#39;s attempt to blame its bank for a $440,000 cyberheist in March 2010,&quot; reports
Jaikumar Vijayan in &quot;ComputerWorld.&quot;

&lt;p&gt;
&quot;In a ruling last week, the U.S. District Court for the Western District of Missouri held that Choice Escrow and Title LLC had essentially failed to follow its bank&amp;#39;s recommended security procedures and therefore had only itself to blame for the loss...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/182/1/IT-News-Watch-Security/30451">
        <dc:format>text/html</dc:format>
        <dc:date>2013-04-22T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>15 Worst Data Breaches</title>
        <link>http://sun.systemnews.com/articles/182/1/IT-News-Watch-Security/30451</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/182/1/IT-News-Watch-Security/30451&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/182/1/csoonline.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;Data security breaches happen daily in too many places at once to keep count. But what constitutes a huge breach versus a small one? For some perspective, we take a look at 15 of the biggest incidents in recent memory...&quot;, writes Taylor Armerding in &quot;CSO.&quot;

&lt;p&gt;

&lt;ul&gt;

&lt;li&gt;Heartland Payment Systems

&lt;li&gt;TJX

&lt;li&gt;Epsilon

&lt;li&gt;RSA

&lt;li&gt;Stuxnet

&lt;li&gt;Department of Veterans Affairs

&lt;li&gt;Sony PlayStation Network

&lt;li&gt;ESTsoft

&lt;li&gt;Gawker Media

&lt;li&gt;Google, etc.

&lt;li&gt;VeriSign

&lt;li&gt;CardSystems

&lt;li&gt;AOL

&lt;li&gt;Monster.com

&lt;li&gt;Fidelity National Information Services

&lt;/ul&gt;

&lt;p&gt;
Read on for details.  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/182/1/IT-News-Watch-Security/30452">
        <dc:format>text/html</dc:format>
        <dc:date>2013-04-22T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>Misconfigured, Open DNS Servers Used In Record-Breaking DDoS Attack</title>
        <link>http://sun.systemnews.com/articles/182/1/IT-News-Watch-Security/30452</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/182/1/IT-News-Watch-Security/30452&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/182/1/darkreading.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;Biggest-ever distributed denial-of-service attack originally aimed at Spamhaus escalates and hits other corners of the Net&quot;, says
Kelly Jackson Higgins in &quot;Dark Reading.&quot;

&lt;p&gt;
&quot;This was not your typical hacktivist DDoS attack: a massive, 300 gigabits-per-second traffic attack against volunteer spam filtering organization Spamhaus spread yesterday to multiple Internet exchanges and ultimately slowed traffic for users mainly in Europe...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/181/4/IT-News-Watch-Security/30358">
        <dc:format>text/html</dc:format>
        <dc:date>2013-03-31T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>9 Classic Hacking, Phishing and Social Engineering Lies</title>
        <link>http://sun.systemnews.com/articles/181/4/IT-News-Watch-Security/30358</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/181/4/IT-News-Watch-Security/30358&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/181/4/infoworld.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;In 9 dirty tricks: Social engineer&amp;#39;s favorite pick up lines, Chris Nickerson, founder of Lares, a Colorado-based security consultancy, explains why this old social-engineering trick is often still successful. He should know, he uses it frequently as a pen tester,&quot; reports 
Joan Goodchild in 
&lt;A HREF=&quot;http://sun.systemnews.com/go/2?a=30358&amp;l=http%3A%2F%2Fwww.infoworld.com%2Fslideshow%2F91935%2F9-classic-hacking-phishing-and-social-engineering-lies-214942&quot; target=&quot;_new&quot;&gt;InfoWorld&lt;/A&gt;

&lt;p&gt;
&quot;Scammers often take advantage of a timely event, like a high-profile piece of malware that is infecting many computers. The average, non-computer savvy employee gets nervous with the technicality of what the &quot;IT person&quot; on the phone is telling them...

&lt;p&gt;

&lt;ul&gt;

&lt;li&gt;This is Bob from IT. Your computer is infected.

&lt;li&gt;IÂ'm trapped in London! Help!

&lt;li&gt;Can you hold the door for me?

&lt;li&gt;Have you seen this blog about you?

&lt;li&gt;Your account has been closed

&lt;li&gt;Donate to the hurricane recovery efforts

&lt;li&gt;IÂ'm late and in a hurry! Please just let me in!

&lt;li&gt;Get a free Starbucks gift certificate!

&lt;li&gt;#popefrancis

&lt;/ul&gt;

&lt;p&gt;
Read on for details.  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/181/4/IT-News-Watch-Security/30365">
        <dc:format>text/html</dc:format>
        <dc:date>2013-03-31T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>Security Appliances Are Riddled With Serious Vulnerabilities, Researcher Says</title>
        <link>http://sun.systemnews.com/articles/181/4/IT-News-Watch-Security/30365</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/181/4/IT-News-Watch-Security/30365&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/181/4/pcworld.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;The majority of email and Web gateways, firewalls, remote access servers, U (united threat management) systems and other security appliances have serious vulnerabilities, according to a security researcher who analyzed products from multiple vendors&quot; reports Lucian Constantin in  &quot;PCWorld.&quot;]

&lt;p&gt;
&quot;Most security appliances are poorly maintained Linux systems with insecure Web applications installed on them, according to Ben Williams, a penetration tester at NCC Group, who presented his findings Thursday at the Black Hat Europe 2013 security conference in Amsterdam. His talk was entitled, &amp;#39;Ironic Exploitation of Security Products&amp;#39;...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/181/4/IT-News-Watch-Security/30366">
        <dc:format>text/html</dc:format>
        <dc:date>2013-03-31T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>Shifting from Compliance-Based IT Security to a Risk-Based Model</title>
        <link>http://sun.systemnews.com/articles/181/4/IT-News-Watch-Security/30366</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/181/4/IT-News-Watch-Security/30366&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/181/4/securityinfowatch.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;Joel Griffin writes in &quot;Security InfoWatch&quot;:

&lt;p&gt;
&quot;In the ever evolving threat landscape that is IT security, some security executives have become so focused on taking an approach that meets compliance requirements that their attention has become diverted away from some of the actual risks facing their respective organizations. Obviously complying with rules and regulations set forth is important, but some organizations are making it the primary guiding principle of their security program...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/181/3/IT-News-Watch-Security/30266">
        <dc:format>text/html</dc:format>
        <dc:date>2013-03-24T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>99 Percent Of Tested Applications Are Vulnerable To Attacks</title>
        <link>http://sun.systemnews.com/articles/181/3/IT-News-Watch-Security/30266</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/181/3/IT-News-Watch-Security/30266&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/181/3/darkreading.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;An article in
&lt;A HREF=&quot;http://sun.systemnews.com/go/2?a=30266&amp;l=http%3A%2F%2Fwww.darkreading.com%2Fsecurity%2Fnews%2F240150766%2F99-percent-of-tested-applications-are-vulnerable-to-attacks.html&quot; target=&quot;_new&quot;&gt;dark Reading&lt;/A&gt; states that 
&quot;Cenzic Inc., the leading provider of application security intelligence to reduce security risks, today released the Cenzic Trends Report for 2012. The report demonstrates that the overwhelming presence of web application vulnerabilities remains a constant problem, with an astounding 99% of applications tested revealing security risks, while additionally shedding light on pressing vulnerabilities within mobile application security.

&lt;p&gt;
Gathered during the Cenzic Managed Security team&amp;#39;s analysis of applications in production, the report reveals the massive number of vulnerabilities prevalent in web and mobile applications today. The report highlights the type, frequency and severity of vulnerabilities found and predicts which vulnerabilities will pose the greatest risk in web and mobile applications in production throughout 2013...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/181/3/IT-News-Watch-Security/30275">
        <dc:format>text/html</dc:format>
        <dc:date>2013-03-24T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>Identity fraud is up, but banks are up to the security challenge</title>
        <link>http://sun.systemnews.com/articles/181/3/IT-News-Watch-Security/30275</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/181/3/IT-News-Watch-Security/30275&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/181/3/net-security.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;In 2012, the total losses resulting from account takeover and new account fraud each rose by approximately 50% over the previous year,&quot; 
reports
&lt;A HREF=&quot;http://sun.systemnews.com/go/2?a=30275&amp;l=http%3A%2F%2Fwww.net-security.org%2Fsecworld.php%3Fid%3D14598&quot; target=&quot;_new&quot;&gt;Help Net Security.&lt;/A&gt; 

&lt;p&gt;

&lt;p&gt;
These two fraud types impact consumers most severely, and are historically more difficult for FIs to prevent and detect than any other major fraud type.

&lt;p&gt;
Today, Javelin Strategy &amp;amp; Research releases the firm&amp;#39;s 2013 Banking Identity Safety Scorecard...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/181/2/IT-News-Watch-Security/30169">
        <dc:format>text/html</dc:format>
        <dc:date>2013-03-17T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>Demand for IT Security Experts Outstrips Supply</title>
        <link>http://sun.systemnews.com/articles/181/2/IT-News-Watch-Security/30169</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/181/2/IT-News-Watch-Security/30169&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/181/2/computerworld.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;Demand for information security experts in the United States is outstripping the available supply by a widening margin, according to a pair of recently released reports,&quot; reports Jaikumar Vijayan in &quot;Computerworld.&quot;

&lt;p&gt;
&quot;A report from Burning Glass Technologies, which develops technologies designed to match people with jobs, shows that demand for cybersecurity professionals over the past five years grew 3.5 times faster than demand for other IT jobs and about 12 times faster than for all other jobs...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/181/2/IT-News-Watch-Security/30170">
        <dc:format>text/html</dc:format>
        <dc:date>2013-03-17T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>5 Most Dangerous New Hacking Techniques</title>
        <link>http://sun.systemnews.com/articles/181/2/IT-News-Watch-Security/30170</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/181/2/IT-News-Watch-Security/30170&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/181/2/crn.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;The rise of Stuxnet, Flame, Gause, the Olympic Games operations and Shamoon have all shed light on the issue of nation-state driven cyberwarfare and cyberespionage activities. Now that we are in cyberspace, we have another domain for humans to occupy and dominate, according to Ed Skoudis, founder of Counter Hack Challenges,&quot;
reports Robert Westervelt in &quot;CRN&quot;.

&lt;p&gt;
&quot;Skoudis told RSA Conference 2013 attendees that he worries about some of the risks of taking action over the Internet...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/181/2/IT-News-Watch-Security/30176">
        <dc:format>text/html</dc:format>
        <dc:date>2013-03-17T16:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>The Time for Sharing Cyber-Threat Data is Now</title>
        <link>http://sun.systemnews.com/articles/181/2/IT-News-Watch-Security/30176</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/181/2/IT-News-Watch-Security/30176&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/181/2/cioinsight.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;While controversy has long swirled around the proposed Cyber Intelligence Sharing and Information Act that was recently re-introduced in Congress, the information security community has no doubts that the time to share information on cyber-threats is here,&quot;
observes Tony Kontzer in &quot;CIO Insight.&quot;

&lt;p&gt;
&quot;During a panel discussion at the RSA Conference at San Francisco&amp;#39;s Moscone Center last Wednesday, top security executives agreed that corporations, which have largely shied away from sharing any information about their vulnerabilities, need to open up as never before. And, they said, itÂ's not going to be easy to make it happen...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/181/1/IT-News-Watch-Security/30082">
        <dc:format>text/html</dc:format>
        <dc:date>2013-03-09T17:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>Risk Vs Innovation: 5 Steps To Finding the Right Balance</title>
        <link>http://sun.systemnews.com/articles/181/1/IT-News-Watch-Security/30082</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/181/1/IT-News-Watch-Security/30082&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/181/1/wallstreetandtech.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;In today&amp;#39;s ultra-competitive, fast-moving environment, only the most agile and innovative financial firms can thrive,&quot; comments 
Melanie Rodier in &quot;Wall Street and Technology.&quot;

&lt;p&gt;
&quot;But with budgets still tight and investors&amp;#39; appetite for risk at an all-time low, firms who want to keep staying ahead of the game need to strike the right balance between risk and innovation...&quot;

&lt;p&gt;

&lt;ul&gt;

&lt;li&gt;Evaluate whether you will gain a competitive advantage

&lt;li&gt;Do a PoC.

&lt;li&gt;Find a business case for it.

&lt;li&gt;Decide how you are going to build a competitive edge

&lt;li&gt;Analyze risk at every point.

&lt;/ul&gt;

&lt;p&gt;
Read on for details.  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/181/1/IT-News-Watch-Security/30083">
        <dc:format>text/html</dc:format>
        <dc:date>2013-03-09T17:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>Watch a Chinese Military Hacker Launch a Successful Attack</title>
        <link>http://sun.systemnews.com/articles/181/1/IT-News-Watch-Security/30083</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/181/1/IT-News-Watch-Security/30083&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/181/1/networkworld.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;Thanks to cybersecurity firm Mandiant, we now have a video of a hacker believed to be linked to the Chinese military infiltrating and stealing files from unidentified English language targets,&quot; reports Colin Neagle in &quot;Network World.&quot;

&lt;p&gt;
&quot;The video comes as part of Mandiant&amp;#39;s 60-page report, first reported by the New York Times, that claims China&amp;#39;s military is responsible for cyberattacks on more than 140 foreign businesses, many of which are in the United States...&quot;  </description>
    </item>
    <item rdf:about="http://sun.systemnews.com/articles/181/1/IT-News-Watch-Security/30085">
        <dc:format>text/html</dc:format>
        <dc:date>2013-03-09T17:00:00+01:00</dc:date>
        <dc:source>http://sun.systemnews.com</dc:source>
        <title>5 Lessons from The FBI Insider Threat Program</title>
        <link>http://sun.systemnews.com/articles/181/1/IT-News-Watch-Security/30085</link>
        <description>&lt;a href=&quot;http://sun.systemnews.com/articles/181/1/IT-News-Watch-Security/30085&quot;&gt;&lt;img border=0 src=&quot;http://sun.systemnews.com/images/181/1/darkreading.png&quot; align=&quot;right&quot;&gt;&lt;/a&gt;&lt;p&gt;&quot;Insider threats may not have garnered the same sexy headlines that APTs did at this year&amp;#39;s RSA Conference, writes Ericka Chickowski in &quot;Dark Reading.&quot;

&lt;p&gt;
&quot;But two presenters with the Federal Bureau of Investigation (FBI) swung the spotlight back onto insiders during a session this week that offered enterprise security practitioners some lessons learned at the agency after more than a decade of fine-tuning its efforts to sniff out malicious insiders following the fallout from the disastrous Robert Hanssen espionage case...&quot;  </description>
    </item>
</rdf:RDF>
