
<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Savid Insight &#187; IT Consulting</title>
	<atom:link href="http://www.savidtech.com/blog/category/it-consulting/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.savidtech.com/blog</link>
	<description>Savid Technologies thoughts on technology, IT, information security, and business</description>
	<lastBuildDate>Sun, 08 Jan 2012 22:27:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<div id='fb-root'></div>
					<script type='text/javascript'>
						window.fbAsyncInit = function()
						{
							FB.init({appId: null, status: true, cookie: true, xfbml: true});
						};
						(function()
						{
							var e = document.createElement('script'); e.async = true;
							e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js';
							document.getElementById('fb-root').appendChild(e);
						}());
					</script>	
						<item>
		<title>Obama on Cyber Security Awareness Month</title>
		<link>http://www.savidtech.com/blog/it-consulting/obama-on-cyber-security-awareness-month/</link>
		<comments>http://www.savidtech.com/blog/it-consulting/obama-on-cyber-security-awareness-month/#comments</comments>
		<pubDate>Sat, 23 Oct 2010 23:41:14 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[IT Consulting]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Barack Obama]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cybercriminals]]></category>
		<category><![CDATA[Department of Defense]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[National Cyber Security Division]]></category>
		<category><![CDATA[President Obama]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=367</guid>
		<description><![CDATA[Obama proposed a joint effort by the government and private sector to ensure cybersecurity but also reminded us of individual responsibility.
]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/it-consulting/obama-on-cyber-security-awareness-month/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fit-consulting%2Fobama-on-cyber-security-awareness-month%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fit-consulting%2Fobama-on-cyber-security-awareness-month%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>In case you didn’t already know, October is National Cyber <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">Security</a> Awareness Month.  Since its inception in 2001 by the <a href="http://www.savidtech.com/blog/tag/national-cyber-security-division/" class="st_tag internal_tag" rel="tag" title="Posts tagged with National Cyber Security Division">National Cyber Security Division</a>, the NCSAM encourages cybersecurity vigilance, education, and awareness for U.S. citizens and businesses.</p>
<p>This year, the White House issued a press release on October 1st proclaiming CSAM by <a href="http://www.savidtech.com/blog/tag/president-obama/" class="st_tag internal_tag" rel="tag" title="Posts tagged with President Obama">President Obama</a>.  The release discusses how our nation’s growing dependence on cyber and information-related technologies, coupled with an increasing threat of <a href="http://www.savidtech.com/blog/tag/malicious/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Malicious">malicious</a> cyber attacks and loss of privacy, has given rise to the need for greater security of our digital networks and infrastructures.  Therefore, during CSAM, we must “rededicate ourselves to promoting <a href="http://www.savidtech.com/blog/tag/cyber-security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with cyber security">cyber security</a> initiatives that ensure the confidentiality of sensitive information.”</p>
<p>Obama also reiterated how his administration is committed to treating our digital infrastructure as a strategic national asset and protecting this infrastructure is a national security priority.</p>
<p>The President followed up this proclamation in his weekly web address.  “The lesson is clear. This cyber threat is one of the most serious economic and national security challenges we face as a nation,” citing how millions of Americans are victimized by <a href="http://www.savidtech.com/blog/tag/identity-theft/" class="st_tag internal_tag" rel="tag" title="Posts tagged with identity theft">identity theft</a> and <a href="http://www.savidtech.com/blog/tag/cybercriminals/" class="st_tag internal_tag" rel="tag" title="Posts tagged with cybercriminals">cybercriminals</a> cost U.S. companies billions of dollars.</p>
<p>Obama proposed a joint effort by the government and private sector to ensure cybersecurity but also reminded us of individual responsibility.</p>
<p><a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">It</a>’s no wonder the president is so gung ho about cybersecurity since his own campaign <a href="http://www.savidtech.com/blog/tag/servers/" class="st_tag internal_tag" rel="tag" title="Posts tagged with servers">servers</a> fell victim to <a href="http://www.savidtech.com/blog/tag/hackers/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Hackers">hackers</a> when he was running for office.</p>
<p>Other than reaffirming his stance on the importance of cybersecurity and providing some obvious simple tips, the address did not contain much in the way of specific plans of actions to enhance it.  Still, it was the most the president has had to say about the topic since his 16-minute speech in May when he declared he would create a new cyber security office at the White House.</p>
<p>This office still has no appointed coordinator.  The cyber czar would coordinate with disconnected agencies that cannot pool their resources on this issue, including the CIA, the FBI, the NSA, and the <a href="http://www.savidtech.com/blog/tag/department-of-defense/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Department of Defense">Department of Defense</a>.  Maybe NCSAM is a good excuse to finally choose that cyber czar we have been hearing about for so long.</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/barack-obama/" title="Barack Obama" rel="tag">Barack Obama</a>, <a href="http://www.savidtech.com/blog/tag/cyber-security/" title="cyber security" rel="tag">cyber security</a>, <a href="http://www.savidtech.com/blog/tag/cybercriminals/" title="cybercriminals" rel="tag">cybercriminals</a>, <a href="http://www.savidtech.com/blog/tag/department-of-defense/" title="Department of Defense" rel="tag">Department of Defense</a>, <a href="http://www.savidtech.com/blog/tag/identity-theft/" title="identity theft" rel="tag">identity theft</a>, <a href="http://www.savidtech.com/blog/tag/national-cyber-security-division/" title="National Cyber Security Division" rel="tag">National Cyber Security Division</a>, <a href="http://www.savidtech.com/blog/tag/president-obama/" title="President Obama" rel="tag">President Obama</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/it-consulting/obama-on-cyber-security-awareness-month/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>1 thing you have to do if you virtualize</title>
		<link>http://www.savidtech.com/blog/it-consulting/1-thing-you-have-to-do-if-you-virtualize/</link>
		<comments>http://www.savidtech.com/blog/it-consulting/1-thing-you-have-to-do-if-you-virtualize/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 18:54:01 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[IT Consulting]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[green]]></category>
		<category><![CDATA[green computing]]></category>
		<category><![CDATA[information technology]]></category>
		<category><![CDATA[infrastructure hardware]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[performance management]]></category>
		<category><![CDATA[performance problems]]></category>
		<category><![CDATA[scalable infrastructure]]></category>
		<category><![CDATA[servers]]></category>
		<category><![CDATA[smb]]></category>
		<category><![CDATA[storage]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=377</guid>
		<description><![CDATA[Virtualization saves money and the environment.  But it is not without a potentially major disadvantage.]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/it-consulting/1-thing-you-have-to-do-if-you-virtualize/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fit-consulting%2F1-thing-you-have-to-do-if-you-virtualize%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fit-consulting%2F1-thing-you-have-to-do-if-you-virtualize%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Whenever executives discuss <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">IT</a> and cost cutting, invariably two topics come up: <a href="http://www.savidtech.com/blog/tag/virtualization/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Virtualization">Virtualization</a> and the Cloud. Don&#8217;t even get started on the topic of the cloud, and the chance for rain. <a href="http://www.savidtech.com/blog/tag/virtualization/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Virtualization">Virtualization</a> is a good topic to discuss since some items may be unfamiliar to you (especially those in the <a href="http://www.savidtech.com/blog/tag/smb/" class="st_tag internal_tag" rel="tag" title="Posts tagged with smb">SMB</a>).</p>
<p>By now, most companies have adopted, or at least looked into, overhauling their IT infrastructure with virtualization solutions. Virtualization is said to reduce costs, simplify management and scalability, and limit the toll computing has on the environment. Since 2005, virtualization software has quickly changed the landscape of enterprise computing.</p>
<p>For those unfamiliar with the concept, virtualization involves abstracting computer resources by combining several physical systems into virtual machines on one powerful system. Virtualization consolidates underutilized hardware, such as <a href="http://www.savidtech.com/blog/tag/servers/" class="st_tag internal_tag" rel="tag" title="Posts tagged with servers">servers</a>, <a href="http://www.savidtech.com/blog/tag/storage/" class="st_tag internal_tag" rel="tag" title="Posts tagged with storage">storage</a> devices, and network resources, virtually partitioning it for multiple machines.</p>
<p>The reason virtualization has become such a favorable trend in IT computing is probably because the advantages are so easy to grasp. First of all, the physicality of managing hundreds of machines is simplified while allowing for a <a href="http://www.savidtech.com/blog/tag/scalable-infrastructure/" class="st_tag internal_tag" rel="tag" title="Posts tagged with scalable infrastructure">scalable infrastructure</a>. Plugs and cables do not have to be rearranged every time there is a change in hardware. This reduces the workload of the system administrator. Virtualization allows hardware resources to be pooled such as sharing storage or network bandwidth, so hardware does not go underutilized. Less hardware means less energy costs, both to run and to cool. Altogether, these advantages lower the costs for infrastructure, hardware, power, and cooling.</p>
<p>You’ve probably had the <a href="http://www.savidtech.com/blog/tag/green/" class="st_tag internal_tag" rel="tag" title="Posts tagged with green">green</a> benefits of virtualization stressed to you. According to VMware, for every server virtualized, you can save about 7,000 kilowatt hours, or four tons of CO2 emissions, every year. Virtualization can cut the power demand of ten machines down to one and save almost 80 percent on an electricity bill. VMware even has a <a href="http://www.vmware.com/solutions/green/calculator.html">green calculator </a>on their website which allows you to see your virtualization benefits in terms of energy savings, cost reduction and environmental impact. A quick calculation shows that virtualizing 200 servers is the equivalent of planting 4,000 trees.</p>
<p>Of course, businesses are more concerned with reducing costs than reducing the size of their carbon footprints. With this in mind, there are a few disadvantages, or at least pitfalls, that may be created with a switch to virtualization.</p>
<p>But there is a down side &#8211; it is likely that performance degradation will occur when switching to a virtualization infrastructure if the virtual infrastructure was not properly architected. (which seems to be the case all too many times we get involved). In most organizations there is often a lack of tools and expertise available to monitor and analyze virtual environments to find and correct issues that affect performance. A study by Aberdeen shows that enterprises that had an 85% success rate in identifying performance issues in a physical environment, now only have a 37% success rate in a virtualized one. Also, improved response time for managing <a href="http://www.savidtech.com/blog/tag/business/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Business">business</a>-critical applications fell from 67% in a physical environment to 39% in a virtual one.</p>
<p>Many enterprises find that there is a tradeoff between decreased staffing and power costs and less than optimal performance. Sometimes this means that the advantages manifested by virtualization are less than expected so ensure you have adequately measured the minimum performance requirements for your infrastructure before you go run off and virtualize everything.</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/green/" title="green" rel="tag">green</a>, <a href="http://www.savidtech.com/blog/tag/green-computing/" title="green computing" rel="tag">green computing</a>, <a href="http://www.savidtech.com/blog/tag/information-technology/" title="information technology" rel="tag">information technology</a>, <a href="http://www.savidtech.com/blog/tag/infrastructure-hardware/" title="infrastructure hardware" rel="tag">infrastructure hardware</a>, <a href="http://www.savidtech.com/blog/tag/networking/" title="networking" rel="tag">networking</a>, <a href="http://www.savidtech.com/blog/tag/performance-management/" title="performance management" rel="tag">performance management</a>, <a href="http://www.savidtech.com/blog/tag/performance-problems/" title="performance problems" rel="tag">performance problems</a>, <a href="http://www.savidtech.com/blog/tag/scalable-infrastructure/" title="scalable infrastructure" rel="tag">scalable infrastructure</a>, <a href="http://www.savidtech.com/blog/tag/servers/" title="servers" rel="tag">servers</a>, <a href="http://www.savidtech.com/blog/tag/smb/" title="smb" rel="tag">smb</a>, <a href="http://www.savidtech.com/blog/tag/storage/" title="storage" rel="tag">storage</a>, <a href="http://www.savidtech.com/blog/tag/virtualization/" title="Virtualization" rel="tag">Virtualization</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/it-consulting/1-thing-you-have-to-do-if-you-virtualize/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Predictions on Cybercrime for 2010</title>
		<link>http://www.savidtech.com/blog/network-security/predictions-on-cybercrime-for-2010/</link>
		<comments>http://www.savidtech.com/blog/network-security/predictions-on-cybercrime-for-2010/#comments</comments>
		<pubDate>Sun, 20 Dec 2009 16:34:58 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[IT Consulting]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Network security]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=395</guid>
		<description><![CDATA[The cybercrime underground has evolved into an elaborate economy where, in 2009, cybercriminals have begun to network, collaborate, and pool resources for mutual gain.  Malware infected PCs and botnets are bought and sold like commodities.  I expect this trend will continue in 2010, and it may be the most dangerous prediction.  Combating such cybercrime organizations will require the same organization among security experts. 
]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/network-security/predictions-on-cybercrime-for-2010/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fpredictions-on-cybercrime-for-2010%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fpredictions-on-cybercrime-for-2010%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>With the end of 2009 approaching, cybersecurity engineers as well as <a href="http://www.savidtech.com/blog/tag/cybercriminals/" class="st_tag internal_tag" rel="tag" title="Posts tagged with cybercriminals">cybercriminals</a> are looking to next year to see what the future of internet <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> holds.  Where will current cybercrime trends go and what new ones will emerge?  Well, here are a few of my predictions on what virtual mines the Internet landscape will have in 2010.</p>
<p><strong>Emboldened <a href="http://www.savidtech.com/blog/tag/social-engineering/" class="st_tag internal_tag" rel="tag" title="Posts tagged with social engineering">Social Engineering</a> </strong>– This should be no surprise to anyone in cybersecurity or who has read this blog before.  In 2009 cybercriminals realized that social engineering is the easiest way to obtain sensitive information from users.  And while social engineering was big this year, <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a> will continue to grow exponentially next year.  Expect social engineers to become more organized and bolder in their methods.  There may be more incidents where social engineers visit sites physically to gain <a href="http://www.savidtech.com/blog/tag/trust/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trust">trust</a> and information that no software can physically protect.</p>
<p><strong>Social <a href="http://www.savidtech.com/blog/tag/networking/" class="st_tag internal_tag" rel="tag" title="Posts tagged with networking">Networking</a> Sites Will Become a Bigger Target </strong>– Social networking sites like Twitter and Facebook are only gaining popularity and no amount of security warnings are going to keep users away.  Cybercriminals will use these sites to their advantage in two ways.  While I believe the sites themselves will become more proactive in creating security defenses, the third party applications made for these sites will have exploitable vulnerabilities.  Additionally, social networking site users will increasingly become the victims of social engineering.  These sites give social engineers a terrific medium for contacting, communicating with, and taking advantage of users.</p>
<p><strong>Ransomware Will Replace Scareware </strong>– Hijacking a users PC and holding it for ransom may seem outrageous, but it’s happening now and proving to be more profitable than scareware tactics that users are now growing wise to.  Expect cybercriminals to go where the money is – users would rather pay a small price to regain control of their PCs than go through the trouble of manually removing malware – or nuking their PCs.</p>
<p><strong>Mobile Devices Will Be Hit Hard</strong> – Mobile phones have enjoyed their short lives mostly free of threats while continuing to propagate.  But now that they have increased in complexity, becoming mini notebook computers, the likelihood of vulnerabilities has also increased.  2009 saw the Sexy Space botnet and the iPhoneOS.Ikee – what awaits our precious smartphones in 2010?</p>
<p><strong>Organized Cybercrime</strong> – The cybercrime underground has evolved into an elaborate economy where, in 2009, cybercriminals have begun to network, collaborate, and pool resources for mutual gain.  Malware infected PCs and botnets are bought and sold like commodities.  I expect this trend will continue in 2010, and it may be the most dangerous prediction.  Combating such cybercrime organizations will require the same organization among security experts.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/network-security/predictions-on-cybercrime-for-2010/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Transparency and IT: The Federal IT Dashboard</title>
		<link>http://www.savidtech.com/blog/it-consulting/transparency-and-it-the-federal-it-dashboard/</link>
		<comments>http://www.savidtech.com/blog/it-consulting/transparency-and-it-the-federal-it-dashboard/#comments</comments>
		<pubDate>Wed, 01 Jul 2009 13:08:57 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[IT Consulting]]></category>
		<category><![CDATA[CIOs]]></category>
		<category><![CDATA[dashboard]]></category>
		<category><![CDATA[fiduciary responsibility]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[management frameworks]]></category>
		<category><![CDATA[office of management and budget]]></category>
		<category><![CDATA[project management]]></category>
		<category><![CDATA[Tim O'Reilly]]></category>
		<category><![CDATA[transparency]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=206</guid>
		<description><![CDATA[The new Federal IT dash board is a website where we, the American People, the investors if you will, are now able to see the performance of our investments in the US government.]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/it-consulting/transparency-and-it-the-federal-it-dashboard/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fit-consulting%2Ftransparency-and-it-the-federal-it-dashboard%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fit-consulting%2Ftransparency-and-it-the-federal-it-dashboard%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>If you run an <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">IT</a> organization and have not had a chance to look at the new <a href="http://it.usaspending.gov/" mce_href="http://it.usaspending.gov/">Federal IT dashboard</a>, take sometime today and look at it. The <a href="http://www.savidtech.com/blog/tag/transparency/" class="st_tag internal_tag" rel="tag" title="Posts tagged with transparency">transparency</a> that our new Federal CIO, Vivek Kundra, built is great! We, the American People, the investors if you will, are now able to see the performance of our investments in the US government. I have always touted <a href="http://www.savidtech.com/blog/tag/transparency/" class="st_tag internal_tag" rel="tag" title="Posts tagged with transparency">transparency</a> for IT and now project by project, each CIO within the government is required to report progress on all of their projects to the public.</p>
<p>Amazingly, Vivek only gave the <a href="http://www.savidtech.com/blog/tag/cios/" class="st_tag internal_tag" rel="tag" title="Posts tagged with CIOs">CIOs</a> 30 days to get their information up to date and even more importantly, since the IT <a href="http://www.savidtech.com/blog/tag/dashboard/" class="st_tag internal_tag" rel="tag" title="Posts tagged with dashboard">dashboard</a> obtains its information from the <a href="http://www.savidtech.com/blog/tag/office-of-management-and-budget/" class="st_tag internal_tag" rel="tag" title="Posts tagged with office of management and budget">Office of Management and Budget</a> (OMB), the agency <a href="http://www.savidtech.com/blog/tag/cios/" class="st_tag internal_tag" rel="tag" title="Posts tagged with CIOs">CIOs</a> have to not only update the information but update it through the proper channels for it to be placed into the dashboard.</p>
<p>With one simple portal, Vivek has increased the use of the standardized project <a href="http://www.savidtech.com/blog/tag/management-frameworks/" class="st_tag internal_tag" rel="tag" title="Posts tagged with management frameworks">management frameworks</a> in place throughout the government, increased the accuracy of information, and has helped create a sense of urgency and <a href="http://www.savidtech.com/blog/tag/fiduciary-responsibility/" class="st_tag internal_tag" rel="tag" title="Posts tagged with fiduciary responsibility">fiduciary responsibility</a> for each agency CIO because their performance is now open for all to see. Similar to posting your review for all to see on the company bulletin board, we have advocated that public access to information increases the chance that an employee will &#8220;do the right thing&#8221; For example, we recommend that when you are starting to deploy change management processes internally that any person that bypasses the change management controls and introduces an outage have their picture posted on a company wiki, sharepoint portal, etc as the &#8220;wild wild west cowboy&#8221; that &#8220;caused the problems&#8221;.</p>
<p>A little bit of public humiliation may be just what we need to get the governments IT projects back on track! Some examples:</p>
<ul>
<li>49% of the VA&#8217;s IT projects are behind schedule</li>
<li>41% of Department of Homeland <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">Security</a> projects have &#8220;significant concerns&#8221;</li>
<li><span>The Smithsonian Institution receives $60M and the majority of that investment goes to IT Infrastructure Maintenance</span></li>
<li><span>The DoE has had an almost 50% decrease in IT spending since 2002</span></li>
</ul>
<p>Oh, and in case you were wondering&#8230;many(over 30%) of the governments IT projects are behind or in need for serious help.</p>
<p>Check out Tim O&#8217;Reilly&#8217;s <a href="http://radar.oreilly.com/2009/06/radical-transparency-federal-it-dashboard.html" mce_href="http://radar.oreilly.com/2009/06/radical-transparency-federal-it-dashboard.html">blog post about the Federal IT dashboard</a> for more information on how it was constructed and how it receives data.</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/cios/" title="CIOs" rel="tag">CIOs</a>, <a href="http://www.savidtech.com/blog/tag/dashboard/" title="dashboard" rel="tag">dashboard</a>, <a href="http://www.savidtech.com/blog/tag/fiduciary-responsibility/" title="fiduciary responsibility" rel="tag">fiduciary responsibility</a>, <a href="http://www.savidtech.com/blog/tag/it/" title="IT" rel="tag">IT</a>, <a href="http://www.savidtech.com/blog/tag/management-frameworks/" title="management frameworks" rel="tag">management frameworks</a>, <a href="http://www.savidtech.com/blog/tag/office-of-management-and-budget/" title="office of management and budget" rel="tag">office of management and budget</a>, <a href="http://www.savidtech.com/blog/tag/project-management/" title="project management" rel="tag">project management</a>, <a href="http://www.savidtech.com/blog/tag/tim-oreilly/" title="Tim O&#039;Reilly" rel="tag">Tim O&#039;Reilly</a>, <a href="http://www.savidtech.com/blog/tag/transparency/" title="transparency" rel="tag">transparency</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/it-consulting/transparency-and-it-the-federal-it-dashboard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HackersBlog – White or Black Hat?</title>
		<link>http://www.savidtech.com/blog/network-security/hackersblog-%e2%80%93-white-or-black-hat/</link>
		<comments>http://www.savidtech.com/blog/network-security/hackersblog-%e2%80%93-white-or-black-hat/#comments</comments>
		<pubDate>Mon, 29 Jun 2009 16:28:40 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[IT Consulting]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[anonymous hackers]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[bitdefender]]></category>
		<category><![CDATA[breaches]]></category>
		<category><![CDATA[customer data]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[kapersky]]></category>
		<category><![CDATA[private customer]]></category>
		<category><![CDATA[security vulnerabilities]]></category>
		<category><![CDATA[security vulnerability]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=103</guid>
		<description><![CDATA[This is the controversy surrounding “HackersBlog.org” – a blog where anonymous hackers alert the public about security vulnerabilities.  Each blog entry lists the site hacked, how the data was captured, and what private information is accessible.
]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/network-security/hackersblog-%e2%80%93-white-or-black-hat/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fhackersblog-%25e2%2580%2593-white-or-black-hat%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fhackersblog-%25e2%2580%2593-white-or-black-hat%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Consider this:  A hacker finds a <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> hole on your website that exposes hundreds of thousands <a href="http://www.savidtech.com/blog/tag/private-customer/" class="st_tag internal_tag" rel="tag" title="Posts tagged with private customer">private customer</a> data including names, emails, and even passwords.  The hacker does not steal this information.  Instead, he quietly alerts you via email; but at the same time he makes the <a href="http://www.savidtech.com/blog/tag/security-vulnerability/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security vulnerability">security vulnerability</a> public information on his blog.</p>
<p>Do you: A) Thank the hacker for bringing the security vulnerability to your attention?  Or, B) seek legal action against the hacker who damaged your company’s reputation by alerting the public about your sloppy security?</p>
<p>This is the controversy surrounding “<a href="http://www.HackersBlog.org">HackersBlog.org</a>” – a blog where <a href="http://www.savidtech.com/blog/tag/anonymous-hackers/" class="st_tag internal_tag" rel="tag" title="Posts tagged with anonymous hackers">anonymous hackers</a> alert the public about <a href="http://www.savidtech.com/blog/tag/security-vulnerabilities/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security vulnerabilities">security vulnerabilities</a>.  Each blog entry lists the site hacked, how the data was captured, and what private information is accessible.</p>
<p>The site made its first splash when a Romanian hacker named “Unu” hacked the databases of <a href="http://www.savidtech.com/blog/tag/kapersky/" class="st_tag internal_tag" rel="tag" title="Posts tagged with kapersky">Kapersky</a> – ironically, one of the leading companies in the security and <a href="http://www.savidtech.com/blog/tag/antivirus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with antivirus">antivirus</a> market.  “Seems incredible but unfortunately, its true,” writes Unu, “Alter one of the parameters and you have access to EVERYTHING: users, activation codes, lists of bugs, admins, shop, etc.”</p>
<p>The next target, which occurred the very next day, was <a href="http://www.savidtech.com/blog/tag/bitdefender/" class="st_tag internal_tag" rel="tag" title="Posts tagged with bitdefender">BitDefender</a> – another antivirus software company.  Unu used an SQL injection to show how data could be easily extracted.</p>
<p>In an official statement, Kapersky denied the attack was successful.  BitDefender called the hack an attack and portrayed <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a> negatively even though “the action did not intend to steal information but simply show a vulnerability.”  Usually when sites are hacked, the companies are left scrambling to put out the public relations fires.</p>
<p>So, alerting the website via email about the found vulnerability?  That sounds white hat enough.  So why expose the flaw to everyone publicly on the Internet and wreck the reputation of that company?  “If we just send an email, without making it public they would fix only that parameter that we announced,” says Unu, “and it is possible [for there] to be others too.”</p>
<p>It seems that HackersBlog owes its allegiance to the public and not to the companies who allow for these <a href="http://www.savidtech.com/blog/tag/breaches/" class="st_tag internal_tag" rel="tag" title="Posts tagged with breaches">breaches</a> in security.  &#8220;I&#8217;m not a criminal, I [am] not a burglar,” says Unu, “You do the work of a [pentesting firm] that could test the security of the site or [sic] server at the request of the owner. The difference is that the firm makes this for a big sum of money, a very big sum of money, and we do it as a hobby, for pleasure, free, and most of the times we do that much better, but we don’t even get a simple ‘Thank you.’”</p>
<p>Leave me a comment and let me know what you think about this Hacker Blog site!</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/anonymous-hackers/" title="anonymous hackers" rel="tag">anonymous hackers</a>, <a href="http://www.savidtech.com/blog/tag/antivirus/" title="antivirus" rel="tag">antivirus</a>, <a href="http://www.savidtech.com/blog/tag/bitdefender/" title="bitdefender" rel="tag">bitdefender</a>, <a href="http://www.savidtech.com/blog/tag/breaches/" title="breaches" rel="tag">breaches</a>, <a href="http://www.savidtech.com/blog/tag/customer-data/" title="customer data" rel="tag">customer data</a>, <a href="http://www.savidtech.com/blog/tag/hackers/" title="Hackers" rel="tag">Hackers</a>, <a href="http://www.savidtech.com/blog/tag/it/" title="IT" rel="tag">IT</a>, <a href="http://www.savidtech.com/blog/tag/kapersky/" title="kapersky" rel="tag">kapersky</a>, <a href="http://www.savidtech.com/blog/tag/private-customer/" title="private customer" rel="tag">private customer</a>, <a href="http://www.savidtech.com/blog/tag/security-vulnerabilities/" title="security vulnerabilities" rel="tag">security vulnerabilities</a>, <a href="http://www.savidtech.com/blog/tag/security-vulnerability/" title="security vulnerability" rel="tag">security vulnerability</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/network-security/hackersblog-%e2%80%93-white-or-black-hat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Understanding Your Attackers with a Honeypot</title>
		<link>http://www.savidtech.com/blog/network-security/understanding-your-attackers-with-a-honeypot/</link>
		<comments>http://www.savidtech.com/blog/network-security/understanding-your-attackers-with-a-honeypot/#comments</comments>
		<pubDate>Fri, 26 Jun 2009 20:28:45 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[IT Consulting]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[corporate managers]]></category>
		<category><![CDATA[decoy systems]]></category>
		<category><![CDATA[honey pot]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[honeypots]]></category>
		<category><![CDATA[information technology]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security budget]]></category>
		<category><![CDATA[Symantec]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=110</guid>
		<description><![CDATA[Honeypot data is a great way to loosen the purse strings of corporate managers who are hesitant to dip into the company budget.  You can make a case for a larger IT security budget by showing them the attack data on the honey pot – who is attacking, how they are attacking, how often, and, most importantly, what damage they could potentially do to the enterprise if the proper defenses are not built.  Actual data speaks louder than any verbal argument.
]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/network-security/understanding-your-attackers-with-a-honeypot/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Funderstanding-your-attackers-with-a-honeypot%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Funderstanding-your-attackers-with-a-honeypot%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>The reality of the situation is that there is no such thing as a 100% secure place on Earth.  <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">IT</a> <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> professionals can only do what they can to make things as secure as possible.  There is no computer <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> defense that will succeed every time, forever, or as I say when presenting at conferences &#8220;You cannot buy your <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> at the local best Buy&#8221;. (NOTE: If you have an indepth udnerstanding of heypots, you can skip this post)</p>
<p>Because of my interaction and association with the <a href="http://www.honeynet.org">Honeynet Project</a> I am frequently asked what benefits honeynets can provide to the normal everyday <a href="http://www.savidtech.com/blog/tag/it-security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT Security">IT security</a> engineer. Simply put, <a href="http://www.savidtech.com/blog/tag/honeypots/" class="st_tag internal_tag" rel="tag" title="Posts tagged with honeypots">honeypots</a> provide us with early warning so we can be vigilant and prepare our defenses accordingly. </p>
<p>Additionally, <a href="http://www.savidtech.com/blog/tag/honeypot/" class="st_tag internal_tag" rel="tag" title="Posts tagged with honeypot">honeypot</a> data is a great way to loosen the purse strings of <a href="http://www.savidtech.com/blog/tag/corporate-managers/" class="st_tag internal_tag" rel="tag" title="Posts tagged with corporate managers">corporate managers</a> who are hesitant to dip into the company budget.  You can make a case for a larger IT <a href="http://www.savidtech.com/blog/tag/security-budget/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security budget">security budget</a> by showing them the attack data on the <a href="http://www.savidtech.com/blog/tag/honey-pot/" class="st_tag internal_tag" rel="tag" title="Posts tagged with honey pot">honey pot</a> – who is attacking, how they are attacking, how often, and, most importantly, what damage they could potentially do to the enterprise if the proper defenses are not built.  Actual data speaks louder than any verbal argument.</p>
<p>Here’s an analogy to help you understand the importance of honeypots. </p>
<p>Imagine you are tasked with defending your king’s castle from an impending enemy attack.  But you don’t know who the enemy is, where they are coming from, how many there are, or what kind of attacks they will use.  They may use spears, rifles, or just sharp rocks.  They may attack on horseback, with catapults, or maybe with tanks.</p>
<p>So what kind of defenses should you build?  A 30 foot tall wall surrounding the castle or a moat?  Should you put archers in the towers or build turrets?  Maybe you should just pile up a few sandbags and hope for the best. Maybe the real problem is the village idiot on the inside&#8230; =)</p>
<p>Without knowing anything about the impending attack, you do not know what an appropriate defense would be.  You may dig a futile trench around your castle while the enemy attacks with stealth bombers.  Or you may encapsulate your entire castle in an impenetrable crystalline dome while your five attackers sling rocks at it.  The latter defense may work, but your king might not be too happy with you for wasting his whole treasury on an unnecessarily robust defense.</p>
<p>A Honeypot is perhaps like a decoy paper version of your castle set up a mile before your actual king’s castle.  The paper castle has no value, but you can see what attacks your enemy uses when they attack it, and thus prepare accordingly.</p>
<p>Honeypots allow you to understand what kind of attacks you can expect.  With this knowledge you can allocate resources to defenses appropriately, without under or overspending. Now, with all that said not everyone can run out and install a honeypot and solve their problems. Honeypots require a lot of maintenance, watching, and i fnot properly installed you can actually decrease the security of your network.</p>
<p>If you don&#8217;t want to take the chance of hurting your own security posture, there are services that will configure and run honeypots for you and provide you with their data. <a href="http://www.savidtech.com/blog/tag/symantec/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Symantec">Symantec</a> and <a href="http://www.savidtech.com/blog/tag/mcafee/" class="st_tag internal_tag" rel="tag" title="Posts tagged with McAfee">McAfee</a> offer such services.</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/corporate-managers/" title="corporate managers" rel="tag">corporate managers</a>, <a href="http://www.savidtech.com/blog/tag/decoy-systems/" title="decoy systems" rel="tag">decoy systems</a>, <a href="http://www.savidtech.com/blog/tag/honey-pot/" title="honey pot" rel="tag">honey pot</a>, <a href="http://www.savidtech.com/blog/tag/honeypot/" title="honeypot" rel="tag">honeypot</a>, <a href="http://www.savidtech.com/blog/tag/honeypots/" title="honeypots" rel="tag">honeypots</a>, <a href="http://www.savidtech.com/blog/tag/information-technology/" title="information technology" rel="tag">information technology</a>, <a href="http://www.savidtech.com/blog/tag/it/" title="IT" rel="tag">IT</a>, <a href="http://www.savidtech.com/blog/tag/it-security/" title="IT Security" rel="tag">IT Security</a>, <a href="http://www.savidtech.com/blog/tag/mcafee/" title="McAfee" rel="tag">McAfee</a>, <a href="http://www.savidtech.com/blog/tag/security/" title="security" rel="tag">security</a>, <a href="http://www.savidtech.com/blog/tag/security-budget/" title="security budget" rel="tag">security budget</a>, <a href="http://www.savidtech.com/blog/tag/symantec/" title="Symantec" rel="tag">Symantec</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/network-security/understanding-your-attackers-with-a-honeypot/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Satyam Crisis Casts Shadow of Doubt Over All Outsourcing</title>
		<link>http://www.savidtech.com/blog/it-consulting/satyam-crisis-casts-shadow-of-doubt-over-all-outsourcing/</link>
		<comments>http://www.savidtech.com/blog/it-consulting/satyam-crisis-casts-shadow-of-doubt-over-all-outsourcing/#comments</comments>
		<pubDate>Thu, 18 Jun 2009 18:13:26 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[IT Consulting]]></category>
		<category><![CDATA[global impact]]></category>
		<category><![CDATA[international football federation]]></category>
		<category><![CDATA[scandal]]></category>
		<category><![CDATA[trust]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=108</guid>
		<description><![CDATA[The future of Satyam does not look good.  Usually when we see a breach in customer trust of this magnitude in American firms customers flock to competitors the first chance they get.
]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/it-consulting/satyam-crisis-casts-shadow-of-doubt-over-all-outsourcing/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fit-consulting%2Fsatyam-crisis-casts-shadow-of-doubt-over-all-outsourcing%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fit-consulting%2Fsatyam-crisis-casts-shadow-of-doubt-over-all-outsourcing%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>The ramifications of the billion dollar fraud at Satyam in India are far-reaching indeed.  Not only is the future of Satyam in jeopardy, but the ripples from this incident will spread over all <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">IT</a> outsourcing in India and, to some extent, all outsourcing in foreign countries.</p>
<p>The Satyam chairman’s confession that he falsely inflated the firm’s revenue is really India’s first <a href="http://www.savidtech.com/blog/tag/scandal/" class="st_tag internal_tag" rel="tag" title="Posts tagged with scandal">scandal</a> of global significance.  But the financial service firms that relied upon Satyam for integral <a href="http://www.savidtech.com/blog/tag/business/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Business">business</a> operations have been burned badly. </p>
<p>And these lingering burns will cause additional hesitation when considering outsourcing to foreign countries.  The country of India itself will have to work hard to maintain its clean image in light of this scandal of Enron-esque proportions.  The enticing shimmer of inexpensive IT services overseas has lost some of its luster.</p>
<p>With 600 customers in over 60 countries, the <a href="http://www.savidtech.com/blog/tag/global-impact/" class="st_tag internal_tag" rel="tag" title="Posts tagged with global impact">global impact</a> of the scandal is sure to be echoed throughout the world.  Even the <a href="http://www.savidtech.com/blog/tag/international-football-federation/" class="st_tag internal_tag" rel="tag" title="Posts tagged with international football federation">international football federation</a> FIFA enlisted Satyam to develop an event management system for $200 million.</p>
<p>The future of Satyam does not look good.  Usually when we see a breach in customer <a href="http://www.savidtech.com/blog/tag/trust/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trust">trust</a> of this magnitude in American firms customers flock to competitors the first chance they get.</p>
<p>What better time to remind companies about the importance of performing due diligence on their outsourcing partners?  I recently saw a study that said that fewer than 43% of financial services companies undertake any form of due diligence when considering outsourcing partners, even though 46% of them believe that outsourcing is a way to achieve business transformation and a competitive edge.  I wonder how these numbers will change post-Satyam.</p>
<p>Often companies attempt to mitigate the risks of outsourcing by using larger vendors.  The fall of Satyam, one of the largest vendors out there, should teach us that this is not an effective strategy.  An effective due diligence procedure is the best way to mitigate the risks of outsourcing.</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/business/" title="Business" rel="tag">Business</a>, <a href="http://www.savidtech.com/blog/tag/global-impact/" title="global impact" rel="tag">global impact</a>, <a href="http://www.savidtech.com/blog/tag/international-football-federation/" title="international football federation" rel="tag">international football federation</a>, <a href="http://www.savidtech.com/blog/tag/scandal/" title="scandal" rel="tag">scandal</a>, <a href="http://www.savidtech.com/blog/tag/trust/" title="trust" rel="tag">trust</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/it-consulting/satyam-crisis-casts-shadow-of-doubt-over-all-outsourcing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>“Disinformation” Now a Big Trend Among Hackers</title>
		<link>http://www.savidtech.com/blog/it-consulting/%e2%80%9cdisinformation%e2%80%9d-now-a-big-trend-among-hackers/</link>
		<comments>http://www.savidtech.com/blog/it-consulting/%e2%80%9cdisinformation%e2%80%9d-now-a-big-trend-among-hackers/#comments</comments>
		<pubDate>Mon, 01 Jun 2009 16:13:12 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[IT Consulting]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[disinformation]]></category>
		<category><![CDATA[disinformation campaign]]></category>
		<category><![CDATA[false information]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[information leakage]]></category>
		<category><![CDATA[operation mincemeat]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[STEVE JOBS]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=36</guid>
		<description><![CDATA[According to a study on hacking incidents and trends for the first quarter of 2009, “Disinformation” is now the second most common attack outcome by hacking (losing to “Information Leakage” by only 3%).  This is a major jump since Disinformation was not even on the list in the previous study, falling somewhere below Phishing (3%).  Defacement, which can be distinguished from Disinformation because it spreads obviously false information, is third on this list.
]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/it-consulting/%e2%80%9cdisinformation%e2%80%9d-now-a-big-trend-among-hackers/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fit-consulting%2F%25e2%2580%259cdisinformation%25e2%2580%259d-now-a-big-trend-among-hackers%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fit-consulting%2F%25e2%2580%259cdisinformation%25e2%2580%259d-now-a-big-trend-among-hackers%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>One of my favorite activities we perform for clients is <a href="http://www.savidtech.com/blog/tag/social-engineering/" class="st_tag internal_tag" rel="tag" title="Posts tagged with social engineering">Social Engineering</a> so I thought that a recent trend, <a href="http://www.savidtech.com/blog/tag/disinformation/" class="st_tag internal_tag" rel="tag" title="Posts tagged with disinformation">disinformation</a>, would be an interesting topic to discuss:</p>
<p>In 1943, British Intelligence dressed up a corpse, equipped <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a> with fake operation plans, and floated <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a> out to sea where Axis troops would eventually recover <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a>.  The ruse was designed to make the Germans believe that the Allies planned to invade Greece and Sardinia, instead of Sicily, their actual target.</p>
<p>“<a href="http://www.savidtech.com/blog/tag/operation-mincemeat/" class="st_tag internal_tag" rel="tag" title="Posts tagged with operation mincemeat">Operation Mincemeat</a>” was a successful <a href="http://www.savidtech.com/blog/tag/disinformation-campaign/" class="st_tag internal_tag" rel="tag" title="Posts tagged with disinformation campaign">disinformation campaign</a>.  Also called “Black Propaganda,” Disinformation is the intention is to spread false or inaccurate information to damage or gain an upper-hand against an opponent.  While it was often used in wartime throughout history, the new battleground for disinformation is cyberspace where <a href="http://www.savidtech.com/blog/tag/hackers/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Hackers">hackers</a> spread disinformation about a company through their own systems.</p>
<p>According to a <a href="http://www.secure-enterprise20.org/files/Web%202%200%20Hacking%20Q1.pdf">study on hacking incidents </a>and trends for the first quarter of 2009, “Disinformation” is now the second most common attack outcome by hacking (losing to “<a href="http://www.savidtech.com/blog/tag/information-leakage/" class="st_tag internal_tag" rel="tag" title="Posts tagged with information leakage">Information Leakage</a>” by only 3%).  This is a major jump since Disinformation was not even on the list in the previous study, falling somewhere below Phishing (3%).  Defacement, which can be distinguished from Disinformation because it spreads obviously <a href="http://www.savidtech.com/blog/tag/false-information/" class="st_tag internal_tag" rel="tag" title="Posts tagged with false information">false information</a>, is third on this list.</p>
<p>And if you don’t think Disinformation can cost your company money, just ask <a href="http://www.savidtech.com/blog/tag/steve-jobs/" class="st_tag internal_tag" rel="tag" title="Posts tagged with STEVE JOBS">Steve Jobs</a> who recently shared sentiments with Mark Twain – “reports of my death have been greatly exaggerated.” </p>
<p>A hacker that broke into the live Mac Rumors Feed to announce – in all capital letters –“STEVE JOBS JUST DIED.”  It took three minutes before a retraction was given, “Steve did not die.”  In another incident, someone uploaded photos to Wired magazine’s website with a detailed story describing Steve having a cardiac arrest.  In this case, it wasn’t even a code flaw that allowed the disinformation to be publicized, but an obvious application design flaw.  Wired’s public image viewing utility allows anyone to upload whatever images they wish which are then viewable on their public website.<br />
 <br />
Harmless pranks?  The incidents caused Apple stock to plummet from the disinformation campaign.  Considering Steve’s recent health problems made the disinformation so plausible and the same disinformation was used on multiple occasions, you can’t help but wonder if the culprit has a vested interest in seeing Apple stock drop.</p>
<p>Disinformation isn’t going away.  Consider the rise of social network trends like Twitter.  Social networks are very susceptible to hacking in the first place.  Twitter allows news to be sent directly to thousands of users.  This makes it a very powerful platform for information or disinformation.</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/disinformation/" title="disinformation" rel="tag">disinformation</a>, <a href="http://www.savidtech.com/blog/tag/disinformation-campaign/" title="disinformation campaign" rel="tag">disinformation campaign</a>, <a href="http://www.savidtech.com/blog/tag/false-information/" title="false information" rel="tag">false information</a>, <a href="http://www.savidtech.com/blog/tag/hackers/" title="Hackers" rel="tag">Hackers</a>, <a href="http://www.savidtech.com/blog/tag/information-leakage/" title="information leakage" rel="tag">information leakage</a>, <a href="http://www.savidtech.com/blog/tag/it-security/" title="IT Security" rel="tag">IT Security</a>, <a href="http://www.savidtech.com/blog/tag/operation-mincemeat/" title="operation mincemeat" rel="tag">operation mincemeat</a>, <a href="http://www.savidtech.com/blog/tag/risk/" title="risk" rel="tag">risk</a>, <a href="http://www.savidtech.com/blog/tag/social-engineering/" title="social engineering" rel="tag">social engineering</a>, <a href="http://www.savidtech.com/blog/tag/steve-jobs/" title="STEVE JOBS" rel="tag">STEVE JOBS</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/it-consulting/%e2%80%9cdisinformation%e2%80%9d-now-a-big-trend-among-hackers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tech Insight: How To Protect Your Organization From Malicious Insiders</title>
		<link>http://www.savidtech.com/blog/network-security/tech-insight-how-to-protect-your-organization-from-malicious-insiders/</link>
		<comments>http://www.savidtech.com/blog/network-security/tech-insight-how-to-protect-your-organization-from-malicious-insiders/#comments</comments>
		<pubDate>Wed, 27 May 2009 13:23:23 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[IT Consulting]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[insiders]]></category>
		<category><![CDATA[Malicious]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=70</guid>
		<description><![CDATA[Read an article about How To Protect Your Organization From Malicious Insiders that I wrote as part of my report on data breaches from employees!]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/network-security/tech-insight-how-to-protect-your-organization-from-malicious-insiders/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Ftech-insight-how-to-protect-your-organization-from-malicious-insiders%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Ftech-insight-how-to-protect-your-organization-from-malicious-insiders%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>A couple weeks ago I wrote a Tech Insider Report for Dark Reading regarding <a class="headline" href="http://www.darkreading.com/insiderthreat/util/download.jhtml?id=176500028&amp;cat=whitepaper" target="_blank">Rotten Apples: How To Detect And Stop Malicious Insiders In Your Organization</a><br />
 that discusses the data <a href="http://www.savidtech.com/blog/tag/breaches/" class="st_tag internal_tag" rel="tag" title="Posts tagged with breaches">breaches</a> that occur from the inside. Last week, I wrote an article for <a href="http://www.darkeading.com">DarkReading.com </a>that is an excerpt from that report regarding <a href="http://www.darkreading.com/insiderthreat/security/attacks/showArticle.jhtml?articleID=217600658">How To Protect Your Organization From Malicious Insiders</a>. Go give <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a> a read!</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/data-breaches/" title="data breaches" rel="tag">data breaches</a>, <a href="http://www.savidtech.com/blog/tag/insiders/" title="insiders" rel="tag">insiders</a>, <a href="http://www.savidtech.com/blog/tag/malicious/" title="Malicious" rel="tag">Malicious</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/network-security/tech-insight-how-to-protect-your-organization-from-malicious-insiders/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Speaking at NetSecure &#8217;08</title>
		<link>http://www.savidtech.com/blog/network-security/speaking-at-netsecure-08/</link>
		<comments>http://www.savidtech.com/blog/network-security/speaking-at-netsecure-08/#comments</comments>
		<pubDate>Tue, 18 Mar 2008 17:33:36 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[IT Consulting]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[IT Security]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/network-security/speaking-at-netsecure-08/</guid>
		<description><![CDATA[I will be speaking on the professional development trends in malware at the annual NetSecure conference put on by IIT. Hopefully some of the readers can make it out. It is a great event. The info is below: IT Security and Forensics Conference and Expo http://www.cpd.iit.edu/netsecure08 Wednesday, March 26, 2008 Illinois Institute of Technology in [...]]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/network-security/speaking-at-netsecure-08/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fspeaking-at-netsecure-08%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fspeaking-at-netsecure-08%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>I will be speaking on the professional development trends in malware at the annual NetSecure conference put on by IIT. Hopefully some of the readers can make <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a> out. <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">It</a> is a great event. The info is below:</p>
<p>IT <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">Security</a> and Forensics Conference and Expo</p>
<p>http://www.cpd.iit.edu/netsecure08</p>
<p>Wednesday, March 26, 2008<br />
Illinois Institute of Technology in Wheaton, Illinois</p>
<p>Join us for NETSECURE&#8217;08: The 6th Annual <a href="http://www.savidtech.com/blog/tag/it-security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT Security">IT Security</a> and Forensics Conference and Expo. This multi-track technical conference is attended by 200+ IT professionals and will promote the open exchange of <a href="http://www.savidtech.com/blog/tag/it-security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT Security">IT security</a> and forensics information. Register now at http://www.cpd.iit.edu/netsecure08</p>
<p>Current Conference Presentations Include:</p>
<p>* &#8220;Annual CompTIA security research: Trends and strategies for information security&#8221;  Carol Balkcom &#8211; CompTIA</p>
<p>* &#8220;Cellular Wireless Key Managament&#8221; Alec Brusilovsky &#8211; Alcatel-Lucent</p>
<p>* &#8220;Microsoft Security &#8211; Growing up and Enterprise Ready&#8221;  Cordell Crane &#8211; Microsoft</p>
<p>* &#8220;Microsoft Security &#8211; Hands on approach with tools for Threat Modeling, Code Review and Discovery&#8221;  Ken Anderson &#8211; Microsoft</p>
<p>* &#8220;Professional Development Trends within Malware&#8221;  Michael Davis &#8211; Savid Technologies</p>
<p>* &#8220;Network Security: What You and Your Skills Are Worth&#8221;  Bob Fanelli &#8211; Robert Half Technology</p>
<p>* &#8220;Securing Windows &#8211; A Monumental Task?&#8221;  Mike Fekety &#8211; Performance Technologies</p>
<p>* &#8220;Building a Secure <a href="http://www.savidtech.com/blog/tag/storage/" class="st_tag internal_tag" rel="tag" title="Posts tagged with storage">Storage</a> Internet&#8221;  Chris Gladwin &#8211; CleverSafe</p>
<p>* &#8220;Do the Work Once: Harmonizing Compliance and Security Objectives&#8221;  Bonnie Goins</p>
<p>* &#8220;The Role of Penetration Testing in Security Audits&#8221;  Jeff Groman &#8211; Akibia</p>
<p>* &#8220;Penetration Testing: Let me probe your ports&#8221;  David Kennedy &#8211; SecureState</p>
<p>* &#8220;Combating Insider Threats on Databases&#8221;  Carl Kettler &#8211; Application Security, Inc.</p>
<p>* &#8220;Computer Security at Fermilab&#8221;  Frank Nagy and Tim Rupp &#8211; Fermi Lab</p>
<p>* &#8220;Building a Linux Custom Firewall&#8221;  Venkat Nandam</p>
<p>* &#8220;Security and Control Issues within Relational Databases&#8221;  David Ogbolumani &#8211; SunGard</p>
<p>* &#8220;Data: How much is there, and where is it at?&#8221;  John Pascoe &#8211; FBI Regional Computer Forensics Laboratory</p>
<p>* &#8220;Best security practices for Voice Wireless LANs&#8221;  John Poust &#8211; IEEE ComSoc</p>
<p>* &#8220;<a href="http://www.savidtech.com/blog/tag/virtualization/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Virtualization">Virtualization</a> Security and Best Practices&#8221;  Rob Randell &#8211; VMware</p>
<p>* &#8220;Out-Of-Band authentication using a real-time, multi-factor service model&#8221;  Andy Rolfe &#8211; Authentify</p>
<p>* &#8220;Fighting Spam: Tools, Tips, and Techniques&#8221;  Brian Sebby &#8211; Argonne National Laboratory</p>
<p>* &#8220;SSH&#8221;  Hemant Shah</p>
<p>* &#8220;Multi-Factor Authentication Solutions: An Overview of Regulations,  Vulnerabilities, and the Latest and Best Authentication Options&#8221;  Bob Thompson &#8211; Catalyst</p>
<p>* &#8220;A New Model for <a href="http://www.savidtech.com/blog/tag/business/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Business">Business</a> Contingency Operations&#8221;  Raymond Trygstad &#8211; Illinois Institute of Technology</p>
<p>* &#8220;Identity and Access Management&#8221;  Kevin Wang &#8211; Crowe</p>
<p>Details:</p>
<p>Date &#8211; Wednesday, March 26, 2008</p>
<p>Attend &#8211; $95 (includes breakfast, lunch, cocktail party, and conference tote bag and materials)</p>
<p>Exhibit &#8211; $325 (includes 2 free attendees)</p>
<p>Sponsor &#8211; $300-750 (includes 1-2 free attendees)</p>
<p>Register &#8211; www.cpd.iit.edu/netsecure08</p>
<p>Location &#8211; Illinois Institute of Technology’s Rice Campus in Wheaton, Illinois</p>
<p>Sponsors Include:</p>
<p>High Tech Crime Network (HTCN), Authentify, Inc., Microsoft, onShore Networks / Fortinet, SunGard Availability Services, IBM Rational, Project Leadership Associates, Robert Half Technology, Other World Computing, SecureState, CTH Technologies, Inc., Security Services &amp; Technologies, Catalyst Technology Group, Inc., Equivus, W.W. Grainger, Inc., CIMCO Communications, CIMCOR, Inc., Hegemony Consulting, Neohapsis, Inc., X-Ways Forensics, CompTIA Security+ Certification Program, Savid Technologies, Inc., ChicagoCon / The Ethical Hacker Network, UniForum, IEEE, and CPD.</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/it-security/" title="IT Security" rel="tag">IT Security</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/network-security/speaking-at-netsecure-08/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->
