<?xml version="1.0"?>
<rss version="2.0" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:yt="http://gdata.youtube.com/schemas/2007" xmlns:atom="http://www.w3.org/2005/Atom">
   <channel>
      <title>Anton/Brando Aggregator</title>
      <description>Pipes Output</description>
      <link>http://pipes.yahoo.com/pipes/pipe.info?_id=6f0b4ebda27dc361cbdb9a076f2934f6</link>
      <atom:link rel="next" href="http://pipes.yahoo.com/pipes/pipe.run?_id=6f0b4ebda27dc361cbdb9a076f2934f6&amp;_render=rss&amp;page=2"/>
      <pubDate>Wed, 19 Jun 2013 04:14:42 +0000</pubDate>
      <generator>http://pipes.yahoo.com/pipes/</generator>
      <item>
         <title>May 2013 Roundup</title>
         <link>http://feedproxy.google.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/03yms79FH6c/</link>
         <description>What was popular in May? It&amp;#8217;s almost summer time! And of course, we have all kinds of horrific weather impacting parts of the country that many of us call home. I played an extra in a show about hackers (does this mean I need to join SAG?), and have been speaking to all kinds of [...]</description>
         <guid isPermaLink="false">https://www.brandenwilliams.com/?p=4100</guid>
         <pubDate>Mon, 03 Jun 2013 22:34:24 +0000</pubDate>
         <content:encoded><![CDATA[<div id="attachment_1576" class="wp-caption alignright" style="width:260px;"><a rel="nofollow" target="_blank" href="http://www.anchorman-themovie.com/"><img class="size-full wp-image-1576" title="Stay Classy, San Diego!" alt="Stay Classy, San Diego!" src="https://www.brandenwilliams.com/wp-content/uploads/2009/11/ron-burgundy.jpg" width="250" height="208"/></a><p class="wp-caption-text">Stay Classy, San Diego!</p></div>
<p>What was popular in May? It&#8217;s almost summer time! And of course, we have all kinds of horrific weather impacting parts of the country that many of us call home. I played an extra in a show about hackers (does this mean I need to join SAG?), and have been speaking to all kinds of companies about their products and services. I even spoke at a few shows and did a webcast!</p>
<p>Here are the five most popular posts from the last month:</p>
<ol>
<li><a rel="nofollow" title="How Starbucks is Revolutionizing Mobile (micro) Payments" target="_blank" href="https://www.brandenwilliams.com/blog/2013/01/24/how-starbucks-is-revolutionizing-micropayments/">How Starbucks is Revolutionizing Mobile (Micro) Payments</a>. This post just won&#8217;t quit! It switched places with the next post from last month, but it&#8217;s still a big deal. You know how you see those crazy fools that pass their phone in front of some magical sensor at Starbucks and never seem to pull out their wallet, yet walk away with coffee? That is really part of a huge master plan to reduce the impact that payments has on the organization. Check out the scenarios discussed!</li>
<li><a rel="nofollow" title="The Only Customer Service Script You Will Ever Need" target="_blank" href="https://www.brandenwilliams.com/blog/2012/09/11/the-only-customer-service-script-you-will-ever-need/">The Only Customer Service Script You Will Ever Need</a>. Is it a sign that the economy is turning around? Is customer service is less important now that customers are easiser to come by? Check out this diversion from security that will make you think about how you interact with your customers.</li>
<li><a rel="nofollow" title="The Definition of Cardholder Data" target="_blank" href="https://www.brandenwilliams.com/blog/2009/09/30/the-definition-of-cardholder-data/">The Definition of Cardholder Data</a>. Yet another powerhouse that is keeping on top of the links. It&#8217;s still on people&#8217;s minds, probably because they are looking for ways to drop systems out of scope of PCI DSS, or because they are looking at the new <a rel="nofollow" title="PCI Releases eCommerce Guidelines, READ THIS FIRST!" target="_blank" href="https://www.brandenwilliams.com/blog/2013/02/01/pci-releases-ecommerce-guidelines-read-this-first/">eCommerce guidance</a> from the Council. Hopefully this is a good benchmark for you.</li>
<li><a rel="nofollow" title="PCI Requirements Review: Patching &amp; IPS" target="_blank" href="https://www.brandenwilliams.com/blog/2012/06/15/pci-requirements-review/">PCI Requirements Review</a>. Here&#8217;s a quick review on Patching and IDS. Back in the top five again, so I wonder if this post with the previous has signaled assessment season is well underway for 2013.</li>
<li><a rel="nofollow" title="A few tips for getting ahead of PCI Compliance" target="_blank" href="https://www.brandenwilliams.com/blog/2013/03/26/a-few-tips-for-getting-ahead-of-pci-compliance/">A Few Tips for Getting Ahead of PCI Compliance</a>. The great folks over at Tripwire caught me in the hallway right before my book signing with Anton. Check out this quick video for some timely tips on getting ahead of PCI Compliance!</li>
</ol>
<p>Thanks for stopping by!</p>

<p><strong>Possibly Related Posts:</strong></p>
<ul>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/05/06/april-2013-roundup/">April 2013 Roundup</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/03/11/february-2013-roundup/">February 2013 Roundup</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/02/04/january-2013-roundup/">January 2013 Roundup</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/01/28/links-from-2013-01-25-through-2013-01-28/">Links from 2013-01-25 through 2013-01-28</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/01/21/links-from-2013-01-15-through-2013-01-21/">Links from 2013-01-15 through 2013-01-21</a></li>
</ul><br />
<p><a rel="nofollow" class="a2a_dd a2a_target addtoany_share_save" target="_blank" href="http://www.addtoany.com/share_save#url=https%3A%2F%2Fwww.brandenwilliams.com%2Fblog%2F2013%2F06%2F03%2Fmay-2013-roundup%2F&amp;title=May%202013%20Roundup" id="wpa2a_2"><img src="https://www.brandenwilliams.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p><div class="feedflare">
<a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?a=03yms79FH6c:MEI5HT2yXBE:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?d=yIl2AUoC8zA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?a=03yms79FH6c:MEI5HT2yXBE:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?i=03yms79FH6c:MEI5HT2yXBE:V_sGLiPBpWU" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/03yms79FH6c" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>Monthly Blog Round-Up – May 2013</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/JS1LfusdNoY/monthly-blog-round-up-may-2013.html</link>
         <description>&lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt;Here is my next &lt;strong&gt;monthly &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.blogger.com/chuvakin.blogspot.com/&quot;&gt;&quot;Security Warrior&quot; blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;/div&gt; &lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt; &lt;ol&gt; &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html&quot;&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top of this list – the checklist is still a very useful tool for many people. “&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html&quot;&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html&quot;&gt;updated version&lt;/a&gt;)  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html&quot;&gt;On Choosing SIEM&lt;/a&gt;” is another old classic (from 2010) that often shows up on my top list; it covers some tips on choosing SIEM tools.  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html&quot;&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011.  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/06/why-no-open-source-siem-ever.html&quot;&gt;Why No Open Source SIEM, EVER?&lt;/a&gt;” contains some of my thinking from 2009. Is it relevant now? Well, you be the judge. &lt;li&gt;My classic &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/07/chuvakin.blogspot.com/search/label/PCI_Log_Review&quot;&gt;PCI DSS Log Review series&lt;/a&gt; is popular as well. The outlined log review approach is useful for building other types of log review processes and procedures, whether regulatory or not.&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt; &lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt;In addition, I’d like to draw your attention to a few recent posts from &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;my Gartner blog&lt;/a&gt;: &lt;br&gt;&lt;br&gt;&lt;strong&gt;Current research:&lt;/strong&gt;&lt;/div&gt; &lt;ul dir=&quot;ltr&quot;&gt; &lt;li&gt; &lt;div style=&quot;text-align:left;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/05/23/my-next-research-area-incident-response/&quot;&gt;My Next Research Area: Incident Response&lt;/a&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt; &lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt;&lt;strong&gt;Past network forensics research:&lt;/strong&gt;&lt;br&gt;&lt;/div&gt; &lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/05/20/alert-driven-vs-exploration-driven-security-analysis/&quot;&gt;Alert-driven vs Exploration-driven Security Analysis&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/03/08/on-futility-of-dead-packet-storage/&quot;&gt;On Futility of Dead Packet Storage&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/02/15/processes-for-network-forensics/&quot;&gt;Processes for Network Forensics&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/02/05/use-cases-for-network-forensics-tools/&quot;&gt;Use Cases for Network Forensics Tools&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/01/29/network-forensics-defined/&quot;&gt;Network Forensics Defined?&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;strong&gt;Past security data sharing research:&lt;/strong&gt;&lt;br&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/04/04/from-ips-to-ttps/&quot;&gt;From IPs to TTPs&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/03/22/consumption-of-shared-security-data/&quot;&gt;Consumption of Shared Security Data&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/02/20/on-trust-in-security-data-sharing/&quot;&gt;On Trust in Security Data Sharing&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/02/10/on-security-data-sharing-research/&quot;&gt;On Security Data Sharing Research&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/05/09/on-security-data-sharing/&quot;&gt;On Security Data Sharing&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/05/29/more-on-dos-and-shared-security/&quot;&gt;More on DoS and Shared Security&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;strong&gt;Miscellaneous fun posts:&lt;/strong&gt;&lt;br&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/05/06/patch-management-not-a-solved-problem/&quot;&gt;Patch Management – NOT A Solved Problem!&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/04/15/9-reasons-why-building-a-big-data-security-analytics-tool-is-like-building-a-flying-car/&quot;&gt;9 Reasons Why Building A Big Data Security Analytics Tool Is Like Building a Flying Car&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/04/12/bye-bye-compliance-thinking-welcome-military-thinking/&quot;&gt;Bye-bye, Compliance Thinking. Welcome, Military Thinking!&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;(see my published Gartner research &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.gartner.com/AnalystBiography?authorId=40636&quot;&gt;here&lt;/a&gt;)&lt;/p&gt; &lt;p&gt;Also see my past &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Annual&quot;&gt;annual&lt;/a&gt; “Top Popular Blog Posts” – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html&quot;&gt;2007&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html&quot;&gt;2008&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html&quot;&gt;2009&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html&quot;&gt;2010&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html&quot;&gt;2011&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2013/01/annual-blog-round-up-2012.html&quot;&gt;2012&lt;/a&gt;.&lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all content at &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securitywarrior.org/&quot;&gt;SecurityWarrior blog&lt;/a&gt; was written before I &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/last-blog-post.html&quot;&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Previous post in this endless series:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2013/05/monthly-blog-round-up-april-2013.html&quot;&gt;Monthly Blog Round-Up – April 2013&lt;/a&gt; &lt;li&gt;All posts tagged &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=JS1LfusdNoY:w_Fxcx9DGK8:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=JS1LfusdNoY:w_Fxcx9DGK8:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=JS1LfusdNoY:w_Fxcx9DGK8:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/JS1LfusdNoY&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-8446792735417332548</guid>
         <pubDate>Mon, 03 Jun 2013 10:13:00 +0000</pubDate>
      </item>
      <item>
         <title>No such file or directory, RVM and Rubies!</title>
         <link>http://feedproxy.google.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/rdlVOAfrJAw/</link>
         <description>This is quite a diversion, but it&amp;#8217;s something that I want documented and indexed by the G00gles of the world in case someone else has a problem like me. If you are not interested in Ruby, or Rails, or RVM, skip this and will see you later on in the week! I recently had an [...]</description>
         <guid isPermaLink="false">https://www.brandenwilliams.com/?p=4096</guid>
         <pubDate>Sun, 02 Jun 2013 14:09:17 +0000</pubDate>
         <content:encoded><![CDATA[<p>This is quite a diversion, but it&#8217;s something that I want documented and indexed by the G00gles of the world in case someone else has a problem like me. If you are not interested in Ruby, or Rails, or RVM, skip this and will see you later on in the week!</p>
<div id="attachment_4097" class="wp-caption alignright" style="width:115px;"><a rel="nofollow" target="_blank" href="http://www.ruby-lang.org/"><img class="size-full wp-image-4097" alt="Ruby!" src="https://www.brandenwilliams.com/wp-content/uploads/2013/06/ruby_logo.gif" width="105" height="109"/></a><p class="wp-caption-text">Ruby!</p></div>
<p>I recently had an issue that stumped me (as well as the great folks in the #rvm channel on <a rel="nofollow" target="_blank" href="http://chat.freenode.net">Freenode</a>). In the process of setting up RVM, I initially made the mistake of doing it as root on a Debian (Squeeze) machine. Cautionary word, you are good playing with the system rubies provided by APT, but if you want to get to the bleeding edge, do all of your RVM installation and dev work as a user, not root. It caused some interesting conflicts. But no worries, this simple command completely reset my RVM setup (as in, I completely removed everything and started over):</p>
<blockquote>
<pre># rvm implode</pre>
</blockquote>
<p>Fun name for a command, and boy does it work. Next, I went <a rel="nofollow" target="_blank" href="https://rvm.io/rvm/install/">here</a> and ran through their process of re-setting up RVM. Everything completed, and after a quick &#8220;rvm reload&#8221; I was able to see my RVM infrastructure fine. But trying to validate the ruby installed didn&#8217;t work. Doing a ruby -v gave me:</p>
<blockquote>
<pre>bash: /path/to/my/home/.rvm/rubies/ruby-2.0.0-p195/bin/ruby: No such file or directory</pre>
</blockquote>
<p>Yet, the file was there, permissions were correct, and by all accounts there should not be any errors. But as you can imagine, when you can&#8217;t run the ruby interpreter, nothing is going to work. Like NADA. After some tinkering with the guys on #rvm, they figured out that the binaries they assembled were at fault. So if you are ever in this situation, the command you want to run to avoid binaries and build from source is:</p>
<blockquote>
<pre>$ rvm reinstall 2.0.0-p195 --disable-binary</pre>
</blockquote>
<p>Provided you have all the tools needed to build a binary on your machine, this will grab the correct source and build it from scratch. Everything is beautiful now! Working like a champ:</p>
<blockquote>
<pre>$ ruby -v
ruby 2.0.0p195 (2013-05-14 revision 40734) [x86_64-linux]</pre>
</blockquote>
<p>So there ya go. Hopefully you never end up getting this strange &#8220;No such file or directory&#8221; error, but if you do, try disabling a binary build.</p>

<p><strong>Possibly Related Posts:</strong></p>
<ul>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/05/14/garmins-missed-opportunity/">Garmin&#8217;s Missed Opportunity</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/04/25/the-gotchas-of-emv-for-the-us/">The Gotchas of EMV for the US Consumer</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/04/16/a-funny-thing-happened-on-the-way-to-the-vatican/">A Funny Thing Happened On The Way To The Vatican</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/03/19/to-catch-a-plagiarizer/">To Catch a Plagiarizer</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/01/24/how-starbucks-is-revolutionizing-micropayments/">How Starbucks is Revolutionizing Mobile (micro) Payments</a></li>
</ul><br />
<p><a rel="nofollow" class="a2a_dd a2a_target addtoany_share_save" target="_blank" href="http://www.addtoany.com/share_save#url=https%3A%2F%2Fwww.brandenwilliams.com%2Fblog%2F2013%2F06%2F02%2Fno-such-file-or-directory-rvm-and-rubies%2F&amp;title=No%20such%20file%20or%20directory%2C%20RVM%20and%20Rubies%21" id="wpa2a_4"><img src="https://www.brandenwilliams.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p><div class="feedflare">
<a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?a=rdlVOAfrJAw:VmKI5doGbVs:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?d=yIl2AUoC8zA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?a=rdlVOAfrJAw:VmKI5doGbVs:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?i=rdlVOAfrJAw:VmKI5doGbVs:V_sGLiPBpWU" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/rdlVOAfrJAw" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>Adventures in Rails</title>
         <link>http://feedproxy.google.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/KP4h-UdTQbU/</link>
         <description>It has been quite a while since I did any hardcore coding. Since that time, I have dabbled in various web projects, but programmers who don&amp;#8217;t practice tend to get stuck in ruts. Most of the time, I would use my skills to solve small problems using methods and technologies I knew worked. If you [...]</description>
         <guid isPermaLink="false">https://www.brandenwilliams.com/?p=4093</guid>
         <pubDate>Fri, 31 May 2013 14:00:49 +0000</pubDate>
         <content:encoded><![CDATA[<p>It has been quite a while since I did any hardcore coding. Since that time, I have dabbled in various web projects, but programmers who don&#8217;t practice tend to get stuck in ruts. Most of the time, I would use my skills to solve small problems using methods and technologies I knew worked. If you want examples of that, go check out <a rel="nofollow" target="_blank" href="http://brandolabs.com/">Brando Labs</a>. Why do I continually pull tools like Perl, PHP, sed, Bash, and Python out to solve problems? Because I know how they work, and the learning curve to get back into the swing of things is relatively shallow.</p>
<div id="attachment_3590" class="wp-caption alignright" style="width:250px;"><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/wp-content/uploads/2012/04/2196843477_fc2163da90_m.jpg"><img class="size-full wp-image-3590" alt="Hands on: &quot;MacBook Air&quot;" src="https://www.brandenwilliams.com/wp-content/uploads/2012/04/2196843477_fc2163da90_m.jpg" width="240" height="160"/></a><p class="wp-caption-text">Hands on: &#8220;MacBook Air&#8221;</p></div>
<p>Back in the Stone days, I ended up taking a week long Java class that had me coding in JSP and servlets for a time. Object Oriented Programming was a struggle for me. I was taught Top-down procedural programming starting in Pascal &amp; C/C++, but it took this class to get the object thing to click. I am bringing this up because I have decided to re-visit a technology I saw in its 1.0 iteration, Rails. Or more specifically, <a rel="nofollow" target="_blank" href="http://rubyonrails.org/">Ruby on Rails</a>.</p>
<p>WOW it has come a long way since 2005!</p>
<p>In the last eight years, it seems to have become the standard for rapid web development. After completing the <a rel="nofollow" target="_blank" href="http://ruby.railstutorial.org/">fabulous tutorial by Michael Hartl</a>, I&#8217;m recognizing the constructs everywhere (especially with the <a rel="nofollow" target="_blank" href="http://twitter.github.io/bootstrap/">Twitter Bootstrap</a> paintbrush). But that&#8217;s not the point of this post. There were two things very interesting to me that I observed in the Hartl tutorial that I hope will trickle down into other development courses. Maybe I&#8217;ve never been exposed to them because I&#8217;ve been out of the professional dev world for so long, or maybe it&#8217;s just a fluke, but I think both of these will go a long way to improving the quality and security of software for the developers who follow them.</p>
<p>The first observation was the discussion of security in application code. In a number of instances, Michael specifically calls out tweaks to a rails configuration and the specific code to promote a secure application. He even takes it a step further and makes the faithful reader perform several exercises to promote security. I hope this pushes itself down into the colleges and schools that offer courses on development. Thinking about secure development starts from the first printf(&#8220;Hello world.&#8221;).</p>
<p>The second observation was the notion of <a rel="nofollow" target="_blank" href="https://en.wikipedia.org/wiki/Test-driven_development">Test-Driven Development</a> (TDD). In nearly all of my development experience, we rushed to get functionality out the door and hastily tested it, passing the builds along to another group to test and tell us what we missed. This is a horribly broken way to build software and requires excess manual effort to complete the testing process which gets more complex with every build. Repeatedly testing the same things over and over again gets monotonous and human nature all but guarantees mistakes.</p>
<div id="attachment_3869" class="wp-caption alignleft" style="width:250px;"><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/wp-content/uploads/2012/10/4952847207_96b4a9d62a_m.jpg"><img class="size-full wp-image-3869" alt="Patched Tube, by Morten Liebach" src="https://www.brandenwilliams.com/wp-content/uploads/2012/10/4952847207_96b4a9d62a_m.jpg" width="240" height="181"/></a><p class="wp-caption-text">Patched Tube, by Morten Liebach</p></div>
<p>In TDD, you write the test before you write the code. It sounds strange, and seems counter intuitive to every fiber in our body that says &#8220;STAY PRODUCTIVE,&#8221; but it&#8217;s one of those long term benefits that pays massive dividends as your application gets bigger and crazier. For example, let&#8217;s say you have an application that has users, but you want to add blog items (or microposts in Michael&#8217;s tutorial), you first write a test to see if the blog table exists with all the properties you would expect it to have. You run your tests, they fail of course, and then you write the code to make the tests pass (thus adding the functionality you are looking for in the first place!). Now, every time you run your larger application tests, this test will run and you will quickly learn if you break something that makes part or all of your functionality disappear. The same thing goes for displaying information. Write a test to see if the information is displayed (it will fail), then add code to make that test pass.</p>
<p>So while this may be old hat to some of you out there, I found it interesting enough to pass it along to the larger audience. There are tremendous implicaitions for PCI DSS related applications in using both of these methods. Building security tests in will ensure that you don&#8217;t introduce bugs that disclose payment card data, logins, or introduce SQL injection vulnerabilities. Going back and building these tests can be a pain, but it&#8217;s already a big part of the technical debt your application is carrying. Consider this preventative work—or good work to prioritize in the system even if it causes new features to be pushed down the road.</p>

<p><strong>Possibly Related Posts:</strong></p>
<ul>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/05/21/in-favor-of-scenario-planning/">In Favor of Scenario Planning</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/04/25/the-gotchas-of-emv-for-the-us/">The Gotchas of EMV for the US Consumer</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/03/26/a-few-tips-for-getting-ahead-of-pci-compliance/">A few tips for getting ahead of PCI Compliance</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/02/21/fixing-the-cas-a-new-approach/">Fixing the CAs, A New Approach</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/02/14/pci-ssc-releases-cloud-guidance/">PCI SSC Releases Cloud Guidance</a></li>
</ul><br />
<p><a rel="nofollow" class="a2a_dd a2a_target addtoany_share_save" target="_blank" href="http://www.addtoany.com/share_save#url=https%3A%2F%2Fwww.brandenwilliams.com%2Fblog%2F2013%2F05%2F31%2Fadventures-in-rails%2F&amp;title=Adventures%20in%20Rails" id="wpa2a_6"><img src="https://www.brandenwilliams.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p><div class="feedflare">
<a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?a=KP4h-UdTQbU:VHLcHmvVmaQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?d=yIl2AUoC8zA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?a=KP4h-UdTQbU:VHLcHmvVmaQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?i=KP4h-UdTQbU:VHLcHmvVmaQ:V_sGLiPBpWU" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/KP4h-UdTQbU" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>In Favor of Scenario Planning</title>
         <link>http://feedproxy.google.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/yhDaTAsjCcY/</link>
         <description>Harvard Business Review recently published an article by Angela Wilkinson and Roland Kupers called &amp;#8220;Living in the Futures.&amp;#8221; In it, Wilkinson and Kupers discuss the function of scenario planning at Shell—a practice that has been going on in earnest since the 1960s at the company. There are a number of great nuggets that we can [...]</description>
         <guid isPermaLink="false">https://www.brandenwilliams.com/?p=4084</guid>
         <pubDate>Tue, 21 May 2013 14:50:25 +0000</pubDate>
         <content:encoded><![CDATA[<p>Harvard Business Review recently published an article by Angela Wilkinson and Roland Kupers called &#8220;<a rel="nofollow" target="_blank" href="http://hbr.org/2013/05/living-in-the-futures/ar/1">Living in the Futures</a>.&#8221; In it, Wilkinson and Kupers discuss the function of scenario planning at Shell—a practice that has been going on in earnest since the 1960s at the company. There are a number of great nuggets that we can use here in information security to help us plan for inevitable security events. The main goal of scenario planning at Shell is to open up the minds of managers and executives to the possibilities of events in the future. It&#8217;s designed to buck the trend of thinking that the future will be much like the present, such that when things happen they are well poised to make adjustments to weather the storm (or capitalize on the opportunity). In fact, a former head of this program is quoted in the article describing this as a technique to &#8220;manipulate people into being open-minded.&#8221;</p>
<div id="attachment_3646" class="wp-caption alignright" style="width:209px;"><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/wp-content/uploads/2012/05/6758894579_6f0e9a199e_n.jpg"><img class="size-medium wp-image-3646" alt="Spoon, by felixtsao" src="https://www.brandenwilliams.com/wp-content/uploads/2012/05/6758894579_6f0e9a199e_n-199x300.jpg" width="199" height="300"/></a><p class="wp-caption-text">Spoon, by felixtsao</p></div>
<p>Shell&#8217;s scenario planning team builds alternate realities for executives to work through to prepare them to sense change and be prepared to address it. Through this, Shell says they have found ways to be more sensitive to weak indicators that change may be coming.</p>
<p>We need to do the same thing in information security. My formula for scenario planning centers on some kind of security incident (duh). It should be run at least quarterly, and the scenarios should vary such that you can rotate executives in and out of the planning (maybe the COO is in two of the four yearly tabletop exercises) and practice dealing with different kinds of problems. Practicing the same problem over and over will make you good at that, but Murphy will make sure that something else happens instead.</p>
<p>Jimmy Davidson, scenario planning lead in the 60s and 70s, says that scenarios should be more plausible than probable. He says, &#8220;(&#8230;) you can never identify all the forces at play. If you could, and see their interactions, then real prediction of the future would be simple.&#8221; For example, when we build our scenarios for information security we might do a scenario where a contractor for our firm goes rogue and steals a laptop containing IP even if we don&#8217;t have any contractors today or plan on them in the future. It&#8217;s certainly plausible, and will prepare you for dealing with a number of variations of that same scenario.</p>
<p>Scenarios should be updated as needed and follow current market trends. If we were doing this ten years ago we probably wouldn&#8217;t practice falling victim to an advanced threat by a nation state; but we should be doing this today. How do you do scenario planning today? Four IT/IS guys and a box of donuts around a conference table without executive presence? Or full fledged mock chaos?</p>
<p>&nbsp;</p>

<p><strong>Possibly Related Posts:</strong></p>
<ul>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/05/31/adventures-in-rails/">Adventures in Rails</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/02/21/fixing-the-cas-a-new-approach/">Fixing the CAs, A New Approach</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/02/14/pci-ssc-releases-cloud-guidance/">PCI SSC Releases Cloud Guidance</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/02/12/want-to-learn-more-about-the-research-behind-the-phoenix-project/">Want to learn more about the Research behind the Phoenix Project?</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/02/07/roadmap-to-a-secure-organization/">Roadmap to a Secure Organization</a></li>
</ul><br />
<p><a rel="nofollow" class="a2a_dd a2a_target addtoany_share_save" target="_blank" href="http://www.addtoany.com/share_save#url=https%3A%2F%2Fwww.brandenwilliams.com%2Fblog%2F2013%2F05%2F21%2Fin-favor-of-scenario-planning%2F&amp;title=In%20Favor%20of%20Scenario%20Planning" id="wpa2a_8"><img src="https://www.brandenwilliams.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p><div class="feedflare">
<a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?a=yhDaTAsjCcY:VM3Krkei8xM:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?d=yIl2AUoC8zA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?a=yhDaTAsjCcY:VM3Krkei8xM:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?i=yhDaTAsjCcY:VM3Krkei8xM:V_sGLiPBpWU" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/yhDaTAsjCcY" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>Garmin’s Missed Opportunity</title>
         <link>http://feedproxy.google.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/DVZimfLM9_E/</link>
         <description>Businesses are moving faster than ever in this digital economy, and entrepreneurs build and showcase new innovative products or business models every day. The term that is thrown around to describe this phenomenon is called &amp;#8216;disruption&amp;#8217;. As an example, the iPod and iTunes Store disrupted the music industry in a way that forced companies to [...]</description>
         <guid isPermaLink="false">https://www.brandenwilliams.com/?p=4077</guid>
         <pubDate>Tue, 14 May 2013 14:55:24 +0000</pubDate>
         <content:encoded><![CDATA[<p>Businesses are moving faster than ever in this digital economy, and entrepreneurs build and showcase new innovative products or business models every day. The term that is thrown around to describe this phenomenon is called &#8216;disruption&#8217;. As an example, the iPod and iTunes Store disrupted the music industry in a way that forced companies to re-invent their businesses. Remember back in the 1990s when you could find an actual record store? Sure, most of us bought CDs, but it was still a store dedicated to the sale of music. I have fond memories of visiting Blockbuster Music and trying out CDs before I bought them.</p>
<div id="attachment_3267" class="wp-caption alignleft" style="width:250px;"><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/wp-content/uploads/2011/11/2299961067_862985ced7_m.jpg"><img class="size-full wp-image-3267" alt="The Data Center, by Tu Holmes" src="https://www.brandenwilliams.com/wp-content/uploads/2011/11/2299961067_862985ced7_m.jpg" width="240" height="135"/></a><p class="wp-caption-text">The Data Center, by Tu Holmes</p></div>
<p>But Apple changed all of that. They disrupted an established market where prices were fairly constant and controlled and turned it on its head with both an innovative product (iPod), and an innovative business model (iTunes Store). They forced businesses who didn&#8217;t keep up to close. They forced producers to put a more solid set of 10-12 songs on an album since consumers could now just buy the one or two they wanted for a fraction of the cost of the album. This is disruptive innovation, a collection of ideas that largely makes up the work of Clayton M. Christensen&#8217;s Disruption Theory<sup><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/05/14/garmins-missed-opportunity/#footnote_0_4077" id="identifier_0_4077" class="footnote-link footnote-identifier-link" title="Google this for tons and tons of stuff.">1</a></sup>.</p>
<p>Many established businesses came to be from big innovations that made them the standard in an industry. Garmin is one of those companies—largely known for consumerizing GPS technology. Through the 1990s and 2000s, they continually innovated on their consumer GPS technology<sup><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/05/14/garmins-missed-opportunity/#footnote_1_4077" id="identifier_1_4077" class="footnote-link footnote-identifier-link" title="Including that failed call phone product, remember that?">2</a></sup> to go from just your lat/long coordinates to breadcrumbs to moving maps for roads, oceans, and airways. They found ways to embed their technology into cars with turn by turn direction. Some of us have the external units that suction cup to the window, and others have it built in.</p>
<p>This market is currently being disrupted something fierce by smartphones and turn-by-turn directions. With  few exceptions, I can&#8217;t imagine someone with this capability on their smartphone shelling out hundreds of dollars on another device with another cable and another subscription.</p>
<div id="attachment_2643" class="wp-caption alignright" style="width:250px;"><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/wp-content/uploads/2011/01/2191408271_2a93b4299c_m.jpg"><img class="size-full wp-image-2643" alt="/lalala, by striatic" src="https://www.brandenwilliams.com/wp-content/uploads/2011/01/2191408271_2a93b4299c_m.jpg" width="240" height="180"/></a><p class="wp-caption-text">/lalala, by striatic</p></div>
<p>I recently went to investigate updating the maps on my in-vehicle GPS and was shocked to learn that Garmin wanted <strong>$250</strong> for the new map package. $250! That&#8217;s more than the price of a new external GPS, and don&#8217;t forget the package is updated every year.</p>
<p>Garmin is missing a massive opportunity to control in-vehicle navigation in the mobile market. I can assure you, I would rather have a touch screen with all kinds of vehicular automation without a GPS feature than be forced to pay each year to update the map. I&#8217;m not saying that Garmin needs to give it out for free, but if they do choose to charge for it they should pick a small price to create subscription revenue. Something like $20/year for the new maps would be acceptable.</p>
<p>Some investors in major funds have taken a bearish attitude toward Garmin, so maybe this may help adjust expectations. Even though Apple has shown us that turn-by-turn navigation in a smart phone isn&#8217;t perfect, for the most part it is an acceptable analog—especially when you need an address on a street that didn&#8217;t exist a few years ago.</p>

<p><strong>Possibly Related Posts:</strong></p>
<ul>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/06/02/no-such-file-or-directory-rvm-and-rubies/">No such file or directory, RVM and Rubies!</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/04/25/the-gotchas-of-emv-for-the-us/">The Gotchas of EMV for the US Consumer</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/04/16/a-funny-thing-happened-on-the-way-to-the-vatican/">A Funny Thing Happened On The Way To The Vatican</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/03/19/to-catch-a-plagiarizer/">To Catch a Plagiarizer</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/01/24/how-starbucks-is-revolutionizing-micropayments/">How Starbucks is Revolutionizing Mobile (micro) Payments</a></li>
</ul><br />
<ol class="footnotes"><li id="footnote_0_4077" class="footnote">Google this for tons and tons of stuff.</li><li id="footnote_1_4077" class="footnote">Including that failed call phone product, remember that?</li></ol><p><a rel="nofollow" class="a2a_dd a2a_target addtoany_share_save" target="_blank" href="http://www.addtoany.com/share_save#url=https%3A%2F%2Fwww.brandenwilliams.com%2Fblog%2F2013%2F05%2F14%2Fgarmins-missed-opportunity%2F&amp;title=Garmin%E2%80%99s%20Missed%20Opportunity" id="wpa2a_10"><img src="https://www.brandenwilliams.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p><div class="feedflare">
<a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?a=DVZimfLM9_E:nF0tiOEx808:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?d=yIl2AUoC8zA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?a=DVZimfLM9_E:nF0tiOEx808:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?i=DVZimfLM9_E:nF0tiOEx808:V_sGLiPBpWU" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/DVZimfLM9_E" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>April 2013 Roundup</title>
         <link>http://feedproxy.google.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/U_N9bzmBTWA/</link>
         <description>What was popular in April? April was a rough month for many folks (as it historically has been). We have had crazy weather all over the US, and I was able to experience a few new cities with El Wiforino. Thank goodness for the great food choices in London! I&amp;#8217;m so glad that was our [...]</description>
         <guid isPermaLink="false">https://www.brandenwilliams.com/?p=4074</guid>
         <pubDate>Mon, 06 May 2013 22:53:30 +0000</pubDate>
         <content:encoded><![CDATA[<div id="attachment_1576" class="wp-caption alignright" style="width:260px;"><a rel="nofollow" target="_blank" href="http://www.anchorman-themovie.com/"><img class="size-full wp-image-1576" title="Stay Classy, San Diego!" alt="Stay Classy, San Diego!" src="https://www.brandenwilliams.com/wp-content/uploads/2009/11/ron-burgundy.jpg" width="250" height="208"/></a><p class="wp-caption-text">Stay Classy, San Diego!</p></div>
<p>What was popular in April? April was a rough month for many folks (as it historically has been). We have had crazy weather all over the US, and I was able to experience a few new cities with El Wiforino. Thank goodness for the great food choices in London! I&#8217;m so glad that was our last stop.</p>
<p>Here are the five most popular posts from the last month:</p>
<ol>
<li><a rel="nofollow" title="The Only Customer Service Script You Will Ever Need" target="_blank" href="https://www.brandenwilliams.com/blog/2012/09/11/the-only-customer-service-script-you-will-ever-need/">The Only Customer Service Script You Will Ever Need</a>. This is the post that keeps on bringing people back! Maybe spring break travel issues? Check out this diversion from security that will make you think about how you interact with your customers.</li>
<li><a rel="nofollow" title="How Starbucks is Revolutionizing Mobile (micro) Payments" target="_blank" href="https://www.brandenwilliams.com/blog/2013/01/24/how-starbucks-is-revolutionizing-micropayments/">How Starbucks is Revolutionizing Mobile (Micro) Payments</a>. For the fourth month in a row, this post is really keeping people moving. I even had an industry colleague talk to me about it as we were buying coffee at said coffee chain. You know how you see those crazy fools that pass their phone in front of some magical sensor at Starbucks and never seem to pull out their wallet, yet walk away with coffee? That is really part of a huge master plan to reduce the impact that payments has on the organization. Check out the scenarios discussed!</li>
<li><a rel="nofollow" title="The Definition of Cardholder Data" target="_blank" href="https://www.brandenwilliams.com/blog/2009/09/30/the-definition-of-cardholder-data/">The Definition of Cardholder Data</a>. Another oldie but goodie for the seventh month in a row. It&#8217;s still on people&#8217;s minds, probably because they are looking for ways to drop systems out of scope of PCI DSS, or because they are looking at the new <a rel="nofollow" title="PCI Releases eCommerce Guidelines, READ THIS FIRST!" target="_blank" href="https://www.brandenwilliams.com/blog/2013/02/01/pci-releases-ecommerce-guidelines-read-this-first/">eCommerce guidance</a> from the Council. Hopefully this is a good benchmark for you.</li>
<li><a rel="nofollow" title="PCI Requirements Review: Patching &amp; IPS" target="_blank" href="https://www.brandenwilliams.com/blog/2012/06/15/pci-requirements-review/">PCI Requirements Review</a>. Here&#8217;s a quick review on Patching and IDS. Back in the top five again, so I wonder if this post with the previous has signaled assessment season may have kicked off early this year.</li>
<li><a rel="nofollow" title="A few tips for getting ahead of PCI Compliance" target="_blank" href="https://www.brandenwilliams.com/blog/2013/03/26/a-few-tips-for-getting-ahead-of-pci-compliance/">A Few Tips for Getting Ahead of PCI Compliance</a>. The great folks over at Tripwire caught me in the hallway right before my book signing with Anton. Check out this quick video for some timely tips on getting ahead of PCI Compliance!</li>
</ol>
<p>Thanks for stopping by!</p>

<p><strong>Possibly Related Posts:</strong></p>
<ul>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/06/03/may-2013-roundup/">May 2013 Roundup</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/03/11/february-2013-roundup/">February 2013 Roundup</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/02/04/january-2013-roundup/">January 2013 Roundup</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/01/28/links-from-2013-01-25-through-2013-01-28/">Links from 2013-01-25 through 2013-01-28</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/01/21/links-from-2013-01-15-through-2013-01-21/">Links from 2013-01-15 through 2013-01-21</a></li>
</ul><br />
<p><a rel="nofollow" class="a2a_dd a2a_target addtoany_share_save" target="_blank" href="http://www.addtoany.com/share_save#url=https%3A%2F%2Fwww.brandenwilliams.com%2Fblog%2F2013%2F05%2F06%2Fapril-2013-roundup%2F&amp;title=April%202013%20Roundup" id="wpa2a_12"><img src="https://www.brandenwilliams.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p><div class="feedflare">
<a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?a=U_N9bzmBTWA:I1grerAZ2JY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?d=yIl2AUoC8zA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?a=U_N9bzmBTWA:I1grerAZ2JY:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?i=U_N9bzmBTWA:I1grerAZ2JY:V_sGLiPBpWU" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/U_N9bzmBTWA" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>Monthly Blog Round-Up – April 2013</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/A1sS66WAk2Q/monthly-blog-round-up-april-2013.html</link>
         <description>&lt;div dir=&quot;ltr&quot; style=&quot;text-align:left;&quot;&gt;
&lt;div dir=&quot;ltr&quot; style=&quot;text-align:left;&quot;&gt;
Here is my next &lt;strong&gt;monthly &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.blogger.com/chuvakin.blogspot.com/&quot;&gt;&quot;Security Warrior&quot; blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;/div&gt;
&lt;div dir=&quot;ltr&quot; style=&quot;text-align:left;&quot;&gt;
&lt;ol&gt;
&lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html&quot;&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top of this list – the checklist is still a very useful tool for many people. “&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html&quot;&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html&quot;&gt;updated version&lt;/a&gt;) &lt;/li&gt;
&lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html&quot;&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011. &lt;/li&gt;
&lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html&quot;&gt;On Choosing SIEM&lt;/a&gt;” is another old classic (from 2010) that often shows up on my top list; it covers some tips on choosing SIEM tools.  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/11/siem-bloggables.html&quot;&gt;“SIEM Bloggables”&lt;/a&gt; covers a few high-level SIEM use cases and my view (at the time) of key SIEM functions. &lt;/li&gt;
&lt;li&gt;My classic &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/07/chuvakin.blogspot.com/search/label/PCI_Log_Review&quot;&gt;PCI DSS Log Review series&lt;/a&gt; is popular as well. The outlined log review approach is useful for building other types of log review processes and procedures, whether regulatory or not.&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
In addition, I’d like to draw your attention to a few recent posts from &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;my Gartner blog&lt;/a&gt;: &lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Current network forensics research:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/03/08/on-futility-of-dead-packet-storage/&quot;&gt;On Futility of Dead Packet Storage&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/02/15/processes-for-network-forensics/&quot;&gt;Processes for Network Forensics&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/02/05/use-cases-for-network-forensics-tools/&quot;&gt;Use Cases for Network Forensics Tools&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/01/29/network-forensics-defined/&quot;&gt;Network Forensics Defined?&lt;/a&gt; &lt;/li&gt;
&lt;/ul&gt;
&lt;strong&gt;Current security data sharing research:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/04/04/from-ips-to-ttps/&quot;&gt;From IPs to TTPs&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/03/22/consumption-of-shared-security-data/&quot;&gt;Consumption of Shared Security Data&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/02/20/on-trust-in-security-data-sharing/&quot;&gt;On Trust in Security Data Sharing&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/02/10/on-security-data-sharing-research/&quot;&gt;On Security Data Sharing Research&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/05/09/on-security-data-sharing/&quot;&gt;On Security Data Sharing&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/05/29/more-on-dos-and-shared-security/&quot;&gt;More on DoS and Shared Security&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;strong&gt;Miscellaneous fun posts:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/04/10/my-coverage-areas-reminder/&quot;&gt;My Coverage Areas Reminder&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/04/12/bye-bye-compliance-thinking-welcome-military-thinking/&quot;&gt;Bye-bye, Compliance Thinking. Welcome, Military Thinking!&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/04/15/9-reasons-why-building-a-big-data-security-analytics-tool-is-like-building-a-flying-car/&quot;&gt;9 Reasons Why Building A Big Data Security Analytics Tool Is Like Building a Flying Car&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/04/17/on-being-an-analyst-or-who-are-we-hiring/&quot;&gt;On Being An Analyst or WHO Are We Hiring?&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/04/29/verizon-dbir-2013-highlights-and-favorites/&quot;&gt;Verizon DBIR 2013 Highlights and Favorites&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
(see my published Gartner research &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.gartner.com/AnalystBiography?authorId=40636&quot;&gt;here&lt;/a&gt;)&lt;br /&gt;
Also see my past &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Annual&quot;&gt;annual&lt;/a&gt; “Top Popular Blog Posts” – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html&quot;&gt;2007&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html&quot;&gt;2008&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html&quot;&gt;2009&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html&quot;&gt;2010&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html&quot;&gt;2011&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2013/01/annual-blog-round-up-2012.html&quot;&gt;2012&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all content at &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securitywarrior.org/&quot;&gt;SecurityWarrior blog&lt;/a&gt; was written before I &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/last-blog-post.html&quot;&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;strong&gt;Previous post in this endless series:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2013/04/monthly-blog-round-up-march-2013.html&quot;&gt;Monthly Blog Round-Up – March 2013&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;All posts tagged &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=A1sS66WAk2Q:ZVcIFLzNyQc:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=A1sS66WAk2Q:ZVcIFLzNyQc:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=A1sS66WAk2Q:ZVcIFLzNyQc:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/A1sS66WAk2Q&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-5311582652999508743</guid>
         <pubDate>Wed, 01 May 2013 14:07:00 +0000</pubDate>
      </item>
      <item>
         <title>The Gotchas of EMV for the US Consumer</title>
         <link>http://feedproxy.google.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/PS37cSgpKqg/</link>
         <description>Some of you may know that I spent a little over a week on vacation with my wife traipsing through Europe this month. And even though I was constantly yelled at for walking too fast or running to check out some grey squirrel (they are tan here in the US), we had a fabulous time. [...]</description>
         <guid isPermaLink="false">https://www.brandenwilliams.com/?p=4070</guid>
         <pubDate>Thu, 25 Apr 2013 13:46:16 +0000</pubDate>
         <content:encoded><![CDATA[<p>Some of you may know that I spent a little over a week on vacation with my wife traipsing through Europe this month. And even though I was constantly yelled at for walking too fast or running to check out some grey squirrel (they are tan here in the US), we had a fabulous time. We had a few hitches in our travels as any trip will, but one in particular caught us very much by surprise.</p>
<div id="attachment_3141" class="wp-caption alignleft" style="width:250px;"><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/wp-content/uploads/2011/09/2606490817_5908c70ed7_m.jpg"><img class="size-full wp-image-3141" alt="Chip, by Declan Jewell" src="https://www.brandenwilliams.com/wp-content/uploads/2011/09/2606490817_5908c70ed7_m.jpg" width="240" height="160"/></a><p class="wp-caption-text">Chip, by Declan Jewell</p></div>
<p>I made it a point to get my most commonly used credit cards (unfortunately, the one tied to my checking account is WAY behind the times here) re-issued with a chip in them so I would have plenty of fun over in Europe looking like a local and entering my PIN into all of these mobile readers. But something peculiar was happening that didn&#8217;t make sense to me until I had a few transactions rejected.</p>
<p>If you recall, the implementation of EMV here in the states is going to be Chip and <strong>SIGN</strong>, not Chip and PIN. So instead of inserting your card in the slot and punching in a PIN, it reads the chip, sends off the authentication info, and then you sign the slip just like you would here in the US for a normal swipe transaction. 95% of the time this worked just fine. I had one instance in a pub in Florence (yes, I found an Irish pub and had to sample some of their delicious beers because let&#8217;s face it, Peroni and Moretti are meh) where I watched the bartender SWIPE my card for it to be quickly denied. Lesson 1, if there is a chip reader available, there may be a security feature in the card that requires you to use the chip slot and not the swipe. Once he used the chip slot, things went through as normal.</p>
<p>Now, flash forward a few days to Barcelona. I&#8217;m particularly excited because the weather was very nice, the sun was shining, and we were a bit northeast of Barceloneta, so we needed to take the Metro. I thought, sweet. No problem! This would be a chance for me to use the PIN I assigned to both of the cards because there is no way that there will be a person down there to accept the card for signature. I was right about the lack of personnel support, but boy was I wrong about the PIN thing.</p>
<p>DENIED!</p>
<p>DENIED!</p>
<p>DENIED!</p>
<p>I felt like that one day in college where I thought I was going to be a big shot and buy a round for the bar. &#8220;Don&#8217;t worry, guys! I&#8217;ve got a MASTERCARD!&#8221; Aaaaand, over its limit.</p>
<p>So I found some cash, fed the hungry ticket machine, and got us fare for two days on the metro. But I was confused! Wasn&#8217;t this whole chip thing supposed to solve my problems with paying in Europe?</p>
<div id="attachment_1747" class="wp-caption alignright" style="width:250px;"><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/wp-content/uploads/2010/01/3537904106_57fe05b12b_m.jpg"><img class="size-full wp-image-1747" alt="my bank sucks, by B Rosen" src="https://www.brandenwilliams.com/wp-content/uploads/2010/01/3537904106_57fe05b12b_m.jpg" width="240" height="161"/></a><p class="wp-caption-text">my bank sucks, by B Rosen</p></div>
<p>I spent a few minutes on the phone with my bank when I got back and figured something out. My card that is issued in the US and made to work with US systems ONLY works the US way. Meaning, as it stands today, my card CANNOT be used in a Chip &amp; PIN scenario, and ONLY can be used with Chip &amp; SIGN. This means that any automated machine will not be able to accept my cards because they all require the Chip over the swipe if present and the only way they can accept my Chip card is with a signature.</p>
<p>That, my friends, is EMV&#8217;s manifestation of the Catch-22.</p>
<p>So as you are issued your new EMV card here in the US, be aware of the limitations (including your ATM cash retrieval limits if you get in a bind!) of the implementation before you stand for ten minutes in a line that will just get stuck with you fumbling around with your non-standard card.</p>

<p><strong>Possibly Related Posts:</strong></p>
<ul>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/06/02/no-such-file-or-directory-rvm-and-rubies/">No such file or directory, RVM and Rubies!</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/05/31/adventures-in-rails/">Adventures in Rails</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/05/14/garmins-missed-opportunity/">Garmin&#8217;s Missed Opportunity</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/04/16/a-funny-thing-happened-on-the-way-to-the-vatican/">A Funny Thing Happened On The Way To The Vatican</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/03/26/a-few-tips-for-getting-ahead-of-pci-compliance/">A few tips for getting ahead of PCI Compliance</a></li>
</ul><br />
<p><a rel="nofollow" class="a2a_dd a2a_target addtoany_share_save" target="_blank" href="http://www.addtoany.com/share_save#url=https%3A%2F%2Fwww.brandenwilliams.com%2Fblog%2F2013%2F04%2F25%2Fthe-gotchas-of-emv-for-the-us%2F&amp;title=The%20Gotchas%20of%20EMV%20for%20the%20US%20Consumer" id="wpa2a_14"><img src="https://www.brandenwilliams.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p><div class="feedflare">
<a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?a=PS37cSgpKqg:fHRELlt7whs:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?d=yIl2AUoC8zA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?a=PS37cSgpKqg:fHRELlt7whs:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?i=PS37cSgpKqg:fHRELlt7whs:V_sGLiPBpWU" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/PS37cSgpKqg" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>A Funny Thing Happened On The Way To The Vatican</title>
         <link>http://feedproxy.google.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/zfDtRhM7-dA/</link>
         <description>As a global traveler, I tend to be subject to more than anyone&amp;#8217;s fair share of security checks. This means that I am ready for them, and also tend to find patterns in things. For example, if you are in a domestic US airport (where security is TSA, not private), you don&amp;#8217;t have to take [...]</description>
         <guid isPermaLink="false">https://www.brandenwilliams.com/?p=4061</guid>
         <pubDate>Tue, 16 Apr 2013 14:30:33 +0000</pubDate>
         <content:encoded><![CDATA[<p>As a global traveler, I tend to be subject to more than anyone&#8217;s fair share of security checks. This means that I am ready for them, and also tend to find patterns in things. For example, if you are in a domestic US airport (where security is TSA, not private), you don&#8217;t have to take your liquids out. I have been putting them in the top pocket of my roll aboard for years now and have only been stopped in Bozeman, MT (private security), where all the bad guys go. But try that same trick through London Heathrow, and you are guaranteed a 15-45 minute delay.</p>
<div class="wp-caption alignleft" style="width:235px;"><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/wp-content/uploads/2013/04/20130415-165922.jpg"><img class="size-full " alt="20130415-165922.jpg" src="https://www.brandenwilliams.com/wp-content/uploads/2013/04/20130415-165922.jpg" width="225" height="300"/></a><p class="wp-caption-text">Chris &amp; I at Trevi Fountain.</p></div>
<p>I visited the Vatican on Saturday, and thought the security was peculiar. For example, getting through the Vatican Museum (the only way commoners can go to see the Sistene Chapel) requires a basic security check, but I only had to put my camera down on the belt and the metal detector didn&#8217;t go off with my phone in my pocket. After going through there, we went to see St Peter&#8217;s Basilica and were forced to wait in yet another security line. This one was pretty amusing as EVERY third person or so set off the metal detector, but the guard just waved everyone through without even looking at why we set off the alarm. I guess it pays to tour when there are crowds.</p>
<p>Security controls really have two major characteristics that make them enforceable and respected. The must be relevant to the user (I would expect to have a complex password or be checked for guns when entering St Peter&#8217;s), and consistently enforced (if there is a complexity requirement in policy, machines better enforce it when I test it). The human element may bring some challenges here where people try to test parts of the control (if I think passwords are stupid, I just write them down somewhere), or find creative ways to subvert it. Compliance initiatives sometimes hurt us here because users don&#8217;t see the relevance, and systems don&#8217;t properly enforce the controls&#8230; just like what I saw at St. Peter&#8217;s.</p>
<p>The most accurate representation I have seen thus far was in Florence at one of the MANY museums. My phone set off the metal detector and the guard asked to see what was in my pockets. I showed him, and he let me through. That seemed to be a much more appropriate use and enforcement of controls. So as you design your controls, think about the user experience (and be sure you are subject to the same control!).</p>

<p><strong>Possibly Related Posts:</strong></p>
<ul>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/06/02/no-such-file-or-directory-rvm-and-rubies/">No such file or directory, RVM and Rubies!</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/05/14/garmins-missed-opportunity/">Garmin&#8217;s Missed Opportunity</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/04/25/the-gotchas-of-emv-for-the-us/">The Gotchas of EMV for the US Consumer</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/03/19/to-catch-a-plagiarizer/">To Catch a Plagiarizer</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/01/24/how-starbucks-is-revolutionizing-micropayments/">How Starbucks is Revolutionizing Mobile (micro) Payments</a></li>
</ul><br />
<p><a rel="nofollow" class="a2a_dd a2a_target addtoany_share_save" target="_blank" href="http://www.addtoany.com/share_save#url=https%3A%2F%2Fwww.brandenwilliams.com%2Fblog%2F2013%2F04%2F16%2Fa-funny-thing-happened-on-the-way-to-the-vatican%2F&amp;title=A%20Funny%20Thing%20Happened%20On%20The%20Way%20To%20The%20Vatican" id="wpa2a_16"><img src="https://www.brandenwilliams.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p><div class="feedflare">
<a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?a=zfDtRhM7-dA:FX6W_8ioNgA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?d=yIl2AUoC8zA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?a=zfDtRhM7-dA:FX6W_8ioNgA:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?i=zfDtRhM7-dA:FX6W_8ioNgA:V_sGLiPBpWU" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/zfDtRhM7-dA" height="1" width="1"/>]]></content:encoded>
         <category>Diversions</category>
      </item>
      <item>
         <title>Monthly Blog Round-Up – March 2013</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/AZre3KKYIYc/monthly-blog-round-up-march-2013.html</link>
         <description>&lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt;Here is my next &lt;strong&gt;monthly &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.blogger.com/chuvakin.blogspot.com/&quot;&gt;&quot;Security Warrior&quot; blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt;&lt;/div&gt; &lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt; &lt;ol&gt; &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html&quot;&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top of this list – the checklist is still a very useful tool for many people. “&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html&quot;&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html&quot;&gt;updated version&lt;/a&gt;, and, yes, I know it really needs another update)  &lt;li&gt;My classic &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/07/chuvakin.blogspot.com/search/label/PCI_Log_Review&quot;&gt;PCI DSS Log Review series&lt;/a&gt; is popular as well. The outlined log review approach is useful for building other types of log review processes and procedures, whether regulatory or not.  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html&quot;&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011.  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html&quot;&gt;On Choosing SIEM&lt;/a&gt;” is another old classic (from 2010) that often shows up on my top list; it covers some tips on choosing SIEM tools.  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/11/siem-bloggables.html&quot;&gt;“SIEM Bloggables”&lt;/a&gt; covers a few high-level SIEM use cases and my view (at the time) of key SIEM functions.&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt; &lt;p&gt;In addition, I’d like to draw your attention to a few recent posts from &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;my Gartner blog&lt;/a&gt;: &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Current network forensics research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/03/08/on-futility-of-dead-packet-storage/&quot;&gt;On Futility of Dead Packet Storage&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/02/15/processes-for-network-forensics/&quot;&gt;Processes for Network Forensics&lt;/a&gt; &lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/02/05/use-cases-for-network-forensics-tools/&quot;&gt;Use Cases for Network Forensics Tools&lt;/a&gt; &lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/01/29/network-forensics-defined/&quot;&gt;Network Forensics Defined?&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Current security data sharing research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/03/22/consumption-of-shared-security-data/&quot;&gt;Consumption of Shared Security Data&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/02/20/on-trust-in-security-data-sharing/&quot;&gt;On Trust in Security Data Sharing&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/02/10/on-security-data-sharing-research/&quot;&gt;On Security Data Sharing Research&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/05/09/on-security-data-sharing/&quot;&gt;On Security Data Sharing&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/12/11/our-log-standards-paper-publishes/&quot;&gt;Our Log Standards Paper Publishes&lt;/a&gt; (mentions select data sharing standards)  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/05/29/more-on-dos-and-shared-security/&quot;&gt;More on DoS and Shared Security&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Miscellaneous fun posts:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/03/04/a-quiet-assumption/&quot;&gt;A Quiet Assumption&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/03/27/too-late-to-fight-cyber/&quot;&gt;Too Late to Fight “Cyber”&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Also see my past &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Annual&quot;&gt;annual&lt;/a&gt; “Top Popular Blog Posts” – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html&quot;&gt;2007&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html&quot;&gt;2008&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html&quot;&gt;2009&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html&quot;&gt;2010&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html&quot;&gt;2011&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2013/01/annual-blog-round-up-2012.html&quot;&gt;2012&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all content at &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securitywarrior.org&quot;&gt;SecurityWarrior blog&lt;/a&gt; was written before I &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/last-blog-post.html&quot;&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Previous post in this endless series:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2013/03/monthly-blog-round-up-february-2013.html&quot;&gt;Monthly Blog Round-Up – February 2013&lt;/a&gt; &lt;li&gt;All posts tagged &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=AZre3KKYIYc:6Vw2cT-ge54:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=AZre3KKYIYc:6Vw2cT-ge54:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=AZre3KKYIYc:6Vw2cT-ge54:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/AZre3KKYIYc&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-7278940753117566192</guid>
         <pubDate>Mon, 01 Apr 2013 16:35:45 +0000</pubDate>
      </item>
      <item>
         <title>A few tips for getting ahead of PCI Compliance</title>
         <link>http://feedproxy.google.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/19axdtPXn0M/</link>
         <description>The great guys at Tripwire found me outside of the bookstore at RSA Conference this year and wanted to have a quick chat about PCI Compliance! Check out the video below for a few tips that might be helpful for you as you continue your way down this journey. Possibly Related Posts: Adventures in Rails [...]</description>
         <guid isPermaLink="false">https://www.brandenwilliams.com/?p=4055</guid>
         <pubDate>Tue, 26 Mar 2013 13:22:23 +0000</pubDate>
         <content:encoded><![CDATA[<p>The great guys at <a rel="nofollow" target="_blank" href="http://www.tripwire.com/state-of-security/compliance/pci/branden-williams-on-tips-to-get-ahead-of-pci-compliance-requirements/">Tripwire</a> found me outside of the bookstore at RSA Conference this year and wanted to have a quick chat about PCI Compliance! Check out the video below for a few tips that might be helpful for you as you continue your way down this journey.</p>
<p></p> 

<p><strong>Possibly Related Posts:</strong></p>
<ul>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/05/31/adventures-in-rails/">Adventures in Rails</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/04/25/the-gotchas-of-emv-for-the-us/">The Gotchas of EMV for the US Consumer</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/02/14/pci-ssc-releases-cloud-guidance/">PCI SSC Releases Cloud Guidance</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/02/01/pci-releases-ecommerce-guidelines-read-this-first/">PCI Releases eCommerce Guidelines, READ THIS FIRST!</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2012/12/03/the-cnp-fraud-cliff/">The CNP Fraud Cliff</a></li>
</ul><br />
<p><a rel="nofollow" class="a2a_dd a2a_target addtoany_share_save" target="_blank" href="http://www.addtoany.com/share_save#url=https%3A%2F%2Fwww.brandenwilliams.com%2Fblog%2F2013%2F03%2F26%2Fa-few-tips-for-getting-ahead-of-pci-compliance%2F&amp;title=A%20few%20tips%20for%20getting%20ahead%20of%20PCI%20Compliance" id="wpa2a_18"><img src="https://www.brandenwilliams.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p><div class="feedflare">
<a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?a=19axdtPXn0M:80FG50Ba2Rc:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?d=yIl2AUoC8zA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?a=19axdtPXn0M:80FG50Ba2Rc:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?i=19axdtPXn0M:80FG50Ba2Rc:V_sGLiPBpWU" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/19axdtPXn0M" height="1" width="1"/>]]></content:encoded>
         <category>PCI</category>
      </item>
      <item>
         <title>To Catch a Plagiarizer</title>
         <link>http://feedproxy.google.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/KvuDo9eF6PM/</link>
         <description>I&amp;#8217;m not a young pup anymore. Not that I&amp;#8217;m nearing retirement anytime soon, but I find it amazing how much things have changed in the academic world since I first started my bachelors degree in 1996. I can&amp;#8217;t prove it (yet), but I can almost guarantee that students in grades six through twelve have no [...]</description>
         <guid isPermaLink="false">https://www.brandenwilliams.com/?p=4049</guid>
         <pubDate>Tue, 19 Mar 2013 17:54:20 +0000</pubDate>
         <content:encoded><![CDATA[<p>I&#8217;m not a young pup anymore. Not that I&#8217;m nearing retirement anytime soon, but I find it amazing how much things have changed in the academic world since I first started my bachelors degree in 1996. I can&#8217;t prove it (yet), but I can almost guarantee that students in grades six through twelve have no real experience or knowledge of encyclopedias. I remember being envious of friends of mine who had those books in their houses. All that knowledge right at their fingertips, and here I was going to the library, LIKE A SUCKER!</p>
<div id="attachment_1236" class="wp-caption alignright" style="width:250px;"><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/wp-content/uploads/2009/08/54389823_88dbffdf7d_m.jpg"><img class="size-full wp-image-1236" alt="Streeter Seidell, Comedian, by Zach Klein" src="https://www.brandenwilliams.com/wp-content/uploads/2009/08/54389823_88dbffdf7d_m.jpg" width="240" height="160"/></a><p class="wp-caption-text">Streeter Seidell, Comedian, by Zach Klein</p></div>
<p>Now that I am working on my third spin as a student through the academic world (just under eight years from my last exit as a student and about five years from my exit as a professor), I see escalations on both sides of the plagiarism problem—the students (and professionals) abusing the system and organizations trying to stop it. When I was a professor, plagiarism was relatively easy to spot. A good number of my students were not native English speakers, and the ones that were had escaped their bachelors degree without a refined ability to express themselves through written prose. So you can imagine that when I would receive a paper with some awkwardly worded paragraphs and see a beautifully formatted and written grouping of sentences right in the middle, I started asking questions about where this text was lifted from. And thanks to the expansiveness of Google, it&#8217;s pretty easy to find plagiarism.</p>
<p>In the worst case, I had a student that plagiarized nearly half of his paper from another source without any references. We always tried to give the student the benefit of the doubt, but could not accept the work as-is (immediate zero plus a potential to turn it back to the university for disciplinary action). As someone who had taught higher-education, I felt very prepared for the lectures we would get on plagiarism in my doctoral program. For the most part, nothing was too surprising. It&#8217;s a serious offense to publish something as your own when it is not. The biggest trick to avoiding plagiarism is to only write in your own words but reference the sources you use to build those words. That is, avoid direct quotes and <strong>never</strong> use the copy and paste functions prevalent in every word processor.</p>
<p>My first couple of quarters were absolute killers on writing for me. I had to develop my academic voice and get used to standing on the backs of other scholars. Imagine my surprise when I used the same techniques in the past on a total whim to discover another student plagiarizing. Accidental or not, it&#8217;s still a serious issue that is unpleasant for everyone to deal with.</p>
<p>To close out this post, I wanted to offer some tips to avoid plagiarism so you don&#8217;t end up in a bad situation as you move through your academic and professional career. Everyone makes mistakes, but this short guideline should help ensure you don&#8217;t end up plagiarizing:</p>
<ul>
<li>Realize that your papers (and students before you) are probably added to one of a few databases to check for plagiarism, so don&#8217;t give away your past work and don&#8217;t copy another learner&#8217;s work.</li>
<li>When in doubt, cite. Go find a solid reference if you need to back a claim up.</li>
<li><strong>NEVER</strong> USE COPY/PASTE!</li>
<li>Don&#8217;t try to play the &#8220;All I need to do is change a few words and it&#8217;s not plagiarism&#8221; game after violating the above rule. Just write it in your own words.</li>
<li>Do not turn in one of your old papers as new/current work.</li>
<li>Google can be a great research tool, but it can also be a great whistle blower. If you can access something through it, so can your professor.</li>
<li>It&#8217;s better to confront problems in the learning process with a professor before risking plagiarizing to meet some deliverable date.</li>
</ul>

<p><strong>Possibly Related Posts:</strong></p>
<ul>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/06/02/no-such-file-or-directory-rvm-and-rubies/">No such file or directory, RVM and Rubies!</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/05/14/garmins-missed-opportunity/">Garmin&#8217;s Missed Opportunity</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/04/25/the-gotchas-of-emv-for-the-us/">The Gotchas of EMV for the US Consumer</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/04/16/a-funny-thing-happened-on-the-way-to-the-vatican/">A Funny Thing Happened On The Way To The Vatican</a></li>
<li><a rel="nofollow" target="_blank" href="https://www.brandenwilliams.com/blog/2013/01/24/how-starbucks-is-revolutionizing-micropayments/">How Starbucks is Revolutionizing Mobile (micro) Payments</a></li>
</ul><br />
<p><a rel="nofollow" class="a2a_dd a2a_target addtoany_share_save" target="_blank" href="http://www.addtoany.com/share_save#url=https%3A%2F%2Fwww.brandenwilliams.com%2Fblog%2F2013%2F03%2F19%2Fto-catch-a-plagiarizer%2F&amp;title=To%20Catch%20a%20Plagiarizer" id="wpa2a_20"><img src="https://www.brandenwilliams.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p><div class="feedflare">
<a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?a=KvuDo9eF6PM:IEWZo9BsgNw:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?d=yIl2AUoC8zA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?a=KvuDo9eF6PM:IEWZo9BsgNw:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/BrandenWilliamsSecurityConvergenceBlog?i=KvuDo9eF6PM:IEWZo9BsgNw:V_sGLiPBpWU" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/KvuDo9eF6PM" height="1" width="1"/>]]></content:encoded>
         <category>Diversions</category>
      </item>
      <item>
         <title>Monthly Blog Round-Up – February 2013</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/Ovsz_vfUeEU/monthly-blog-round-up-february-2013.html</link>
         <description>&lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt;Here is my next &lt;strong&gt;monthly &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.blogger.com/chuvakin.blogspot.com/&quot;&gt;&quot;Security Warrior&quot; blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt;&lt;/div&gt; &lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt; &lt;ol&gt; &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html&quot;&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top of this list – the checklist is still a very useful tool for many people. “&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html&quot;&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html&quot;&gt;updated version&lt;/a&gt;, and, yes, I know it really needs another update)  &lt;li&gt;My classic &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/07/chuvakin.blogspot.com/search/label/PCI_Log_Review&quot;&gt;PCI DSS Log Review series&lt;/a&gt; is popular as well. The outlined log review approach is useful for building other types of log review processes and procedures, whether regulatory or not.  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html&quot;&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011.  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html&quot;&gt;On Choosing SIEM&lt;/a&gt;” is another old classic (from 2010) that shows up on my top list; it covers some tips on&amp;nbsp; choosing SIEM tools.  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/11/siem-bloggables.html&quot;&gt;“SIEM Bloggables”&lt;/a&gt; covers a few high-level SIEM use cases and my view (at the time) of key SIEM functions.&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt; &lt;p&gt;In addition, I’d like to draw your attention to a few recent posts from &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;my Gartner blog&lt;/a&gt;: &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Current network forensics research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt; &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/02/15/processes-for-network-forensics/&quot;&gt;Processes for Network Forensics&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/02/05/use-cases-for-network-forensics-tools/&quot;&gt;Use Cases for Network Forensics Tools&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/01/29/network-forensics-defined/&quot;&gt;Network Forensics Defined?&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Current security data sharing research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/02/20/on-trust-in-security-data-sharing/&quot;&gt;On Trust in Security Data Sharing&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/02/10/on-security-data-sharing-research/&quot;&gt;On Security Data Sharing Research&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/05/09/on-security-data-sharing/&quot;&gt;On Security Data Sharing&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/12/11/our-log-standards-paper-publishes/&quot;&gt;Our Log Standards Paper Publishes&lt;/a&gt; (mentions select data sharing standards)  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/05/29/more-on-dos-and-shared-security/&quot;&gt;More on DoS and Shared Security&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Previous DLP research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/01/04/dlp-education-andor-automation/&quot;&gt;DLP: Education and/or Automation?&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/12/31/more-on-internal-data-loss-incidents/&quot;&gt;More On Internal Data Loss Incidents&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/12/27/on-internally-lost-data-and-dlp-discovery/&quot;&gt;On “Internally Lost Data” and DLP Discovery&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/12/17/on-risks-of-dlp/&quot;&gt;On Risks of DLP&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/12/12/dlp-and-data-classification/&quot;&gt;DLP and Data Classification&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/12/07/dlp-discover-first-or-monitor-first/&quot;&gt;DLP: Discover First or Monitor First?&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/11/30/on-dlp-and-pci-dss/&quot;&gt;On DLP and PCI DSS&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/11/09/on-dlp-and-ip-theft/&quot;&gt;On DLP and IP Theft&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/11/01/dlp-andorforvs-data-security/&quot;&gt;DLP and/or/for/vs Data Security&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/10/25/on-dlp-processes-or-no-dlp-for-dummies/&quot;&gt;On DLP Processes or “No DLP For Dummies”&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/10/19/on-dlp-research/&quot;&gt;On DLP Research&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Also see my past &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Annual&quot;&gt;annual&lt;/a&gt; “Top Popular Blog Posts” – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html&quot;&gt;2007&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html&quot;&gt;2008&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html&quot;&gt;2009&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html&quot;&gt;2010&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html&quot;&gt;2011&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2013/01/annual-blog-round-up-2012.html&quot;&gt;2012&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all content at &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securitywarrior.org&quot;&gt;SecurityWarrior blog&lt;/a&gt; was written before I &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/last-blog-post.html&quot;&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Previous post in this endless series:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2013/02/monthly-blog-round-up-january-2013.html&quot;&gt;Monthly Blog Round-Up – January 2013&lt;/a&gt;  &lt;li&gt;All posts tagged &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=Ovsz_vfUeEU:aBJ5-YKNOVs:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=Ovsz_vfUeEU:aBJ5-YKNOVs:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=Ovsz_vfUeEU:aBJ5-YKNOVs:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/Ovsz_vfUeEU&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-8908816474937082251</guid>
         <pubDate>Mon, 04 Mar 2013 15:21:50 +0000</pubDate>
      </item>
      <item>
         <title>Monthly Blog Round-Up – December 2012</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/gSoJ8j5eFww/monthly-blog-round-up-december-2012.html</link>
         <description>&lt;div dir=&quot;ltr&quot; style=&quot;text-align:left;&quot;&gt;
&lt;div dir=&quot;ltr&quot; style=&quot;text-align:left;&quot;&gt;
Here is my next &lt;strong&gt;monthly &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.blogger.com/chuvakin.blogspot.com/&quot;&gt;&quot;Security Warrior&quot; blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;/div&gt;
&lt;div dir=&quot;ltr&quot; style=&quot;text-align:left;&quot;&gt;
&lt;ol&gt;
&lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html&quot;&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top of this list – the checklist is still a very useful tool for many people. “&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html&quot;&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html&quot;&gt;updated version&lt;/a&gt;, and, yes, I know it really needs another update)  &lt;/li&gt;
&lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html&quot;&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011.  &lt;/li&gt;
&lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html&quot;&gt;On Choosing SIEM&lt;/a&gt;” is another old classic (from 2010) that shows up on my top list; it covers some tips on&amp;nbsp; choosing SIEM tools.  &lt;/li&gt;
&lt;li&gt;My classic &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/PCI_Log_Review&quot;&gt;PCI DSS Log Review&lt;/a&gt; series is popular as well. The approach is useful for building other types of log review processes and procedures, whether regulatory or not.  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/11/siem-bloggables.html&quot;&gt;“SIEM Bloggables”&lt;/a&gt; covers a few high-level SIEM use cases and my view (at the time) of key SIEM functions.&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
In addition, I’d like to draw your attention to a few posts from &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;my Gartner blog&lt;/a&gt;: &lt;br /&gt;
&lt;strong&gt;Current DLP research:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/12/27/on-internally-lost-data-and-dlp-discovery/&quot;&gt;On “Internally Lost Data” and DLP Discovery&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/12/17/on-risks-of-dlp/&quot;&gt;On Risks of DLP&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/12/12/dlp-and-data-classification/&quot;&gt;DLP and Data Classification&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/12/07/dlp-discover-first-or-monitor-first/&quot;&gt;DLP: Discover First or Monitor First?&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/11/30/on-dlp-and-pci-dss/&quot;&gt;On DLP and PCI DSS&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/11/09/on-dlp-and-ip-theft/&quot;&gt;On DLP and IP Theft&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/11/01/dlp-andorforvs-data-security/&quot;&gt;DLP and/or/for/vs Data Security&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/10/25/on-dlp-processes-or-no-dlp-for-dummies/&quot;&gt;On DLP Processes or “No DLP For Dummies”&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/10/19/on-dlp-research/&quot;&gt;On DLP Research&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
Also see my past &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Annual&quot;&gt;annual&lt;/a&gt; “Top Posts” – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html&quot;&gt;2007&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html&quot;&gt;2008&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html&quot;&gt;2009&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html&quot;&gt;2010&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html&quot;&gt;2011&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all content at &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securitywarrior.org/&quot;&gt;SecurityWarrior blog&lt;/a&gt; was written before I &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/last-blog-post.html&quot;&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;strong&gt;Previous post in this endless series:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/12/monthly-blog-round-up-november-2012.html&quot;&gt;Monthly Blog Round-Up – November 2012&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;All posts tagged &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=gSoJ8j5eFww:wY4-lfqPRmQ:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=gSoJ8j5eFww:wY4-lfqPRmQ:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=gSoJ8j5eFww:wY4-lfqPRmQ:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/gSoJ8j5eFww&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-6302121057368583120</guid>
         <pubDate>Fri, 01 Feb 2013 16:47:54 +0000</pubDate>
         <category>Monthly</category>
      </item>
      <item>
         <title>Annual Blog Round-Up – 2012</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/IPG4Y6MOKxU/annual-blog-round-up-2012.html</link>
         <description>&lt;div dir=&quot;ltr&quot; style=&quot;text-align:left;&quot;&gt;
Here is my &lt;strong&gt;annual &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/&quot;&gt;&quot;Security Warrior&quot; blog&lt;/a&gt; &lt;/strong&gt;round-up of top 10 popular posts/topics in 2012.  &lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html&quot;&gt;Simple Log Review Checklist Released!&lt;/a&gt;” was again the most popular this year. The checklist, a list of critical things to look for while reviewing&amp;nbsp; system, network and security logs when responding to a security incident  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/PCI_Log_Review&quot;&gt;PCI DSS Log Review&lt;/a&gt; series of posts take the #2 spot; they are about planning and executing PCI DSS-driven log review at an organization  &lt;/li&gt;
&lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html&quot;&gt;On Choosing SIEM&lt;/a&gt;” is about &lt;em&gt;the least wrong way&lt;/em&gt; of choosing a SIEM tool – as well as why the right way is so unpopular.  &lt;/li&gt;
&lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html&quot;&gt;On Free Log Management Tools&lt;/a&gt;” is another &lt;em&gt;perma-popular&lt;/em&gt; post, presenting a companion resource to the log checklist above  &lt;/li&gt;
&lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html&quot;&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” is an &lt;em&gt;EXAMPLE&lt;/em&gt; criteria list for choosing a SIEM.  &lt;/li&gt;
&lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/log-management-at-0-and-1hrweek.html&quot;&gt;Log Management at $0 and 1hr/week?&lt;/a&gt;” is pretty much what it is. How to do log management under extreme budget AND time constraints?  &lt;/li&gt;
&lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/08/updated-with-community-feedback-sans_06.html&quot;&gt;Updated With Community Feedback SANS Top 7 Essential Log Reports&lt;/a&gt;” and an older “&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/07/sans-top-5-essential-log-reports-update.html&quot;&gt;SANS Top 5 Essential Log Reports Update!&lt;/a&gt;” &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/11/siem-bloggables.html&quot;&gt;“SIEM Bloggables”&lt;/a&gt; has one possible view on higher-level SIEM use cases and basic functionality, and a quick discussion of SIEM user types. &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/06/how-do-i-get-best-siem.html&quot;&gt;“How Do I Get The Best SIEM?”&lt;/a&gt; is a discussion (circa 2010) about approaches to choosing SIEM tools and matching functionality to requirements. &lt;/li&gt;
&lt;li&gt;2009 post called “&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/12/log-management-siem.html&quot;&gt;Log Management + SIEM = ?&lt;/a&gt;” gives some quick architecture advice on combining SIEM and log management &lt;/li&gt;
&lt;/ol&gt;
&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content was written before I &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/last-blog-post.html&quot;&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;here&lt;/a&gt;. &lt;br /&gt;
Also see my past &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Annual&quot;&gt;annual&lt;/a&gt; “Top Posts” – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html&quot;&gt;2007&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html&quot;&gt;2008&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html&quot;&gt;2009&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html&quot;&gt;2010&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html&quot;&gt;2011&lt;/a&gt;.&lt;br /&gt;
  &lt;br /&gt;
&lt;/div&gt;
&lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=IPG4Y6MOKxU:JRkmOfAVsYM:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=IPG4Y6MOKxU:JRkmOfAVsYM:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=IPG4Y6MOKxU:JRkmOfAVsYM:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/IPG4Y6MOKxU&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-5961219046491024254</guid>
         <pubDate>Fri, 01 Feb 2013 16:47:31 +0000</pubDate>
      </item>
      <item>
         <title>Monthly Blog Round-Up – January 2013</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/0WmRiHZvVts/monthly-blog-round-up-january-2013.html</link>
         <description>&lt;div dir=&quot;ltr&quot; style=&quot;text-align:left;&quot;&gt;
&lt;div dir=&quot;ltr&quot; style=&quot;text-align:left;&quot;&gt;
Here is my next &lt;strong&gt;monthly &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.blogger.com/chuvakin.blogspot.com/&quot;&gt;&quot;Security Warrior&quot; blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;/div&gt;
&lt;div dir=&quot;ltr&quot; style=&quot;text-align:left;&quot;&gt;
&lt;ol&gt;
&lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html&quot;&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top of this list – the checklist is still a very useful tool for many people. “&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html&quot;&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html&quot;&gt;updated version&lt;/a&gt;, and, yes, I know it really needs another update)  &lt;/li&gt;
&lt;li&gt;My classic &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/PCI_Log_Review&quot;&gt;PCI DSS Log Review&lt;/a&gt; series is popular as well. The outlined log review approach is useful for building other types of log review processes and procedures, whether regulatory or not.  &lt;/li&gt;
&lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html&quot;&gt;On Choosing SIEM&lt;/a&gt;” is another old classic (from 2010) that shows up on my top list; it covers some tips on&amp;nbsp; choosing SIEM tools.  &lt;/li&gt;
&lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html&quot;&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011.  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/11/siem-bloggables.html&quot;&gt;“SIEM Bloggables”&lt;/a&gt; covers a few high-level SIEM use cases and my view (at the time) of key SIEM functions.&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
In addition, I’d like to draw your attention to a few posts from &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;my Gartner blog&lt;/a&gt;: &lt;br /&gt;
&lt;strong&gt;Current network forensics research:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/01/29/network-forensics-defined/&quot;&gt;Network Forensics Defined?&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;strong&gt;Previous SIEM research:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/01/07/my-siem-papers-are-out/&quot;&gt;My SIEM Papers Are Out&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;strong&gt;Previous DLP research:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2013/01/04/dlp-education-andor-automation/&quot;&gt;DLP: Education and/or Automation?&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/12/31/more-on-internal-data-loss-incidents/&quot;&gt;More On Internal Data Loss Incidents&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/12/27/on-internally-lost-data-and-dlp-discovery/&quot;&gt;On “Internally Lost Data” and DLP Discovery&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/12/17/on-risks-of-dlp/&quot;&gt;On Risks of DLP&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/12/12/dlp-and-data-classification/&quot;&gt;DLP and Data Classification&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/12/07/dlp-discover-first-or-monitor-first/&quot;&gt;DLP: Discover First or Monitor First?&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/11/30/on-dlp-and-pci-dss/&quot;&gt;On DLP and PCI DSS&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/11/09/on-dlp-and-ip-theft/&quot;&gt;On DLP and IP Theft&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/11/01/dlp-andorforvs-data-security/&quot;&gt;DLP and/or/for/vs Data Security&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/10/25/on-dlp-processes-or-no-dlp-for-dummies/&quot;&gt;On DLP Processes or “No DLP For Dummies”&lt;/a&gt;  &lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/10/19/on-dlp-research/&quot;&gt;On DLP Research&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
Also see my past &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Annual&quot;&gt;annual&lt;/a&gt; “Top Popular Blog Posts” – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html&quot;&gt;2007&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html&quot;&gt;2008&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html&quot;&gt;2009&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html&quot;&gt;2010&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html&quot;&gt;2011&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2013/01/annual-blog-round-up-2012.html&quot;&gt;2012&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all content at &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securitywarrior.org/&quot;&gt;SecurityWarrior blog&lt;/a&gt; was written before I &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/last-blog-post.html&quot;&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;strong&gt;Previous post in this endless series:&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2013/01/monthly-blog-round-up-december-2012.html&quot;&gt;Monthly Blog Round-Up – December 2012&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;All posts tagged &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=0WmRiHZvVts:Y-bJ0hYtb0U:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=0WmRiHZvVts:Y-bJ0hYtb0U:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=0WmRiHZvVts:Y-bJ0hYtb0U:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/0WmRiHZvVts&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-7529956352160494976</guid>
         <pubDate>Fri, 01 Feb 2013 16:47:05 +0000</pubDate>
         <category>Monthly</category>
      </item>
      <item>
         <title>Links for 2013-01-10 [del.icio.us]</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/OfNLHW6LoYc/anton18</link>
         <description>&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.nbcnews.com/technology/technolog/year-didnt-happen-2012s-incorrect-security-predictions-1B7821218&quot;&gt;The year that didn't happen: 2012's incorrect security predictions - Technology on NBCNews.com&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://communities.intel.com/community/openportit/blog/2013/01/03/top-10-security-predictions-for-2013-and-beyond&quot;&gt;Top 10 Security Predictions for 2013 and Beyond&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.netspi.com/blog/2012/12/12/2013-cyber-threat-forecast-released/&quot;&gt;2013 Cyber Threat Forecast Released | NetSPI Blog&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.veracode.com/blog/2012/12/2013-prediction-its-a-mad-mad-mobile-world/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+SourceConference+%28SOURCE+Conference%29&quot;&gt;2013 Prediction &amp;ndash; It&amp;rsquo;s a Mad, Mad, Mobile World&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/OfNLHW6LoYc&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <guid isPermaLink="false">http://del.icio.us/anton18#2013-01-10</guid>
         <pubDate>Fri, 11 Jan 2013 08:00:00 +0000</pubDate>
      </item>
      <item>
         <title>Links for 2013-01-07 [del.icio.us]</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/KK0f15KGe1U/anton18</link>
         <description>&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://instituteforadvancedsecurity.com/ias-blogs/community-blogs/b/institute_for_advanced_security/archive/2012/12/17/predictions-for-a-secure-planet.aspx&quot;&gt;Predictions for a Secure Planet - Institute for Advanced Security - Expert Blogs - IBM Institute for Advanced Security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityweek.com/now-world-didnt-end-whats-next-it-security-2013&quot;&gt;Now That The World Didn't End, What's Next for IT Security in 2013? | SecurityWeek.Com&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/KK0f15KGe1U&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <guid isPermaLink="false">http://del.icio.us/anton18#2013-01-07</guid>
         <pubDate>Tue, 08 Jan 2013 08:00:00 +0000</pubDate>
      </item>
      <item>
         <title>Links for 2013-01-06 [del.icio.us]</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/oEbO3ZJQLqQ/anton18</link>
         <description>&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.veracode.com/blog/2012/12/2013-prediction-its-a-mad-mad-mobile-world/&quot;&gt;2013 Prediction &amp;ndash; It&amp;rsquo;s a Mad, Mad, Mobile World&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/oEbO3ZJQLqQ&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <guid isPermaLink="false">http://del.icio.us/anton18#2013-01-06</guid>
         <pubDate>Mon, 07 Jan 2013 08:00:00 +0000</pubDate>
      </item>
      <item>
         <title>Links for 2013-01-03 [del.icio.us]</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/ruE_jFvw14s/anton18</link>
         <description>&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blog.opengroup.org/2013/01/02/2013-open-group-predictions-vol-1/&quot;&gt;2013 Open Group Predictions, Vol. 1 | The Open Group Blog&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/ruE_jFvw14s&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <guid isPermaLink="false">http://del.icio.us/anton18#2013-01-03</guid>
         <pubDate>Fri, 04 Jan 2013 08:00:00 +0000</pubDate>
      </item>
      <item>
         <title>Links for 2012-12-27 [del.icio.us]</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/n4n7h_T3ZK0/anton18</link>
         <description>&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://hackmageddon.com/2012/12/26/browsing-security-predictions-for-2013/&quot;&gt;Browsing Security Predictions for 2013 &amp;laquo; Hackmageddon.com&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/n4n7h_T3ZK0&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <guid isPermaLink="false">http://del.icio.us/anton18#2012-12-27</guid>
         <pubDate>Fri, 28 Dec 2012 08:00:00 +0000</pubDate>
      </item>
      <item>
         <title>Links for 2012-12-26 [del.icio.us]</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/7TxkrSCxtlM/anton18</link>
         <description>&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.computerweekly.com/blogs/david_lacey/2012/12/predictions_for_2013.html&quot;&gt;Predictions for 2013 - David Lacey's IT Security Blog&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://blog.lookout.com/blog/2012/12/13/2013-mobile-threat-predictions/&quot;&gt;2013 Mobile Threat Predictions | The Official Lookout Blog&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/7TxkrSCxtlM&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <guid isPermaLink="false">http://del.icio.us/anton18#2012-12-26</guid>
         <pubDate>Thu, 27 Dec 2012 08:00:00 +0000</pubDate>
      </item>
      <item>
         <title>Links for 2012-12-22 [del.icio.us]</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/tv7pehPN-jg/anton18</link>
         <description>&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.sans.edu/research/security-laboratory/article/2140&quot;&gt;Security Predictions 2013-2014: Emerging Trends in IT and Security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.symantec.com/connect/blogs/top-5-security-predictions-2013-symantec-0&quot;&gt;Top 5 Security Predictions for 2013 from Symantec | Symantec Connect Community&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://community.spiceworks.com/topic/283695-2013-security-predictions&quot;&gt;2013 Security Predictions - Spiceworks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.csoonline.com/security-leadership/2447/infosec-predictions-2013-shoot-me-please&quot;&gt;Infosec predictions for 2013? Shoot me, please | CSO Blogs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://vmblog.com/archive/2012/11/13/bromium-security-predictions-2013-malware-cross-pollination-and-next-generation-virtualization.aspx&quot;&gt;Bromium: Security Predictions 2013 - Malware Cross-Pollination and Next-Generation Virtualization : VMblog.com - Virtualization Technology News and Information for Everyone&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.technet.com/b/security/archive/2012/12/13/using-the-past-to-predict-the-future-top-5-threat-predictions-for-2013.aspx&quot;&gt;Using the Past to Predict the Future: Top 5 Threat Predictions for 2013 - Microsoft Security Blog - Site Home - TechNet Blogs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.f-secure.com/weblog/archives/00002472.html&quot;&gt;Seven Predictions for 2013 - F-Secure Weblog : News from the Lab&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://research.zscaler.com/2012/12/2013-security-predictions.html&quot;&gt;Zscaler Research: 2013 Security Predictions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://news.softpedia.com/news/Top-5-Security-Predictions-for-2013-from-ISF-310455.shtml&quot;&gt;Top 5 Security Predictions for 2013 from ISF - Softpedia&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.govinfosecurity.com/blogs/5-predictions-on-govt-infosec-in-2013-p-1396&quot;&gt;5 Predictions on Gov't Infosec in 2013&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/tv7pehPN-jg&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <guid isPermaLink="false">http://del.icio.us/anton18#2012-12-22</guid>
         <pubDate>Sun, 23 Dec 2012 08:00:00 +0000</pubDate>
      </item>
      <item>
         <title>PCI Compliance Book Giveaway #2</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/11hUcb5lT3g/pci-compliance-book-giveaway-2.html</link>
         <description>&lt;p&gt;OK folks, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.pcicompliancebook.info&quot;&gt;our PCI Compliance book&lt;/a&gt; has been out for a few months now, and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.brandenwilliams.com/blog/&quot;&gt;Branden&lt;/a&gt; &amp;amp; I thought it would be fun to give away a copy with &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/11/pci-compliance-book-giveaway.html&quot;&gt;another&lt;/a&gt; contest! We have assembled a group of three independent judges who will look at the submissions and pick winners for each competition. The winner will receive a &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.pcicompliancebook.info/&quot;&gt;free, signed copy of the book&lt;/a&gt;! In fact, it would be one of those rare “dual-signed” copies with both of our signatures (and the book will have to travel from TX to CA – or from CA to TX – for this &lt;img style=&quot;border-bottom-style:none;border-right-style:none;border-top-style:none;border-left-style:none;&quot; class=&quot;wlEmoticon wlEmoticon-smile&quot; alt=&quot;Smile&quot; src=&quot;http://lh6.ggpht.com/-IRrZLfzdg-8/UMpuRFwTeaI/AAAAAAAAWjU/S6H6DGvDEDA/wlEmoticon-smile2.png?imgmax=800&quot;&gt;)&lt;/p&gt; &lt;p&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.brandenwilliams.com/wp-content/uploads/2009/08/41YwOvKjZCL._SL500_AA240_.jpg&quot;&gt;&lt;img style=&quot;display:inline;float:right;margin-left:0px;margin-right:0px;&quot; title=&quot;PCI Compliance&quot; alt=&quot;&quot; align=&quot;right&quot; src=&quot;https://www.brandenwilliams.com/wp-content/uploads/2009/08/41YwOvKjZCL._SL500_AA240_.jpg&quot; width=&quot;240&quot; height=&quot;240&quot;&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;So, on to the second contest (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/11/pci-compliance-book-giveaway.html&quot;&gt;first one&lt;/a&gt;).  &lt;p&gt;Our book attempts to draw a middle line between the black &amp;amp; white “audit” style of looking at PCI DSS and the loosey-goosey “anything goes” view. We want to take a compliance-friendly and security-friendly, practitioners line. However, sometimes even a compliance guy has to be CREATIVE!  &lt;p&gt;&lt;strong&gt;So our second challenge to you, in the comments below, please tell us about your &lt;em&gt;MOST CREATIVE PCI DSS CONTROL&lt;/em&gt; you implemented, assessed or even witnessed. &lt;/strong&gt; &lt;p&gt;&lt;strong&gt;HOWEVER, it will help your submission if such control was also ACCEPTED by a QSA. We will absolutely reject the creative control submissions that have no chance of making your environment PCI DSS compliant…&lt;/strong&gt; &lt;p&gt;You’ve got about a week (until the end of December 21st), and we will announce the winners after the holidays!  &lt;p&gt;It doesn’t matter if you comment here or on &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.brandenwilliams.com/blog/2012/11/14/pci-compliance-book-giveaway/&quot;&gt;Branden’s blog&lt;/a&gt;, we will capture all of them.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Related posts:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/11/pci-compliance-book-giveaway.html&quot;&gt;PCI Compliance Book Giveaway #1&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/12/pci-compliance-book-giveawayresults.html&quot;&gt;PCI Compliance Book Giveaway #1 –Results&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=11hUcb5lT3g:GbX6IxmHHGA:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=11hUcb5lT3g:GbX6IxmHHGA:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=11hUcb5lT3g:GbX6IxmHHGA:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/11hUcb5lT3g&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-8589986653861326427</guid>
         <pubDate>Fri, 14 Dec 2012 00:09:40 +0000</pubDate>
         <media:thumbnail height="72" url="http://lh6.ggpht.com/-IRrZLfzdg-8/UMpuRFwTeaI/AAAAAAAAWjU/S6H6DGvDEDA/s72-c/wlEmoticon-smile2.png?imgmax=800" width="72"/>
      </item>
      <item>
         <title>PCI Compliance Book Giveaway–Results</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/zHBCqtbIPYs/pci-compliance-book-giveawayresults.html</link>
         <description>&lt;p&gt;Our &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/11/pci-compliance-book-giveaway.html&quot;&gt;PCI Compliance Book Giveaway&lt;/a&gt; has ended – with a bang!&amp;nbsp; The winning entry (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/11/pci-compliance-book-giveaway.html&quot;&gt;submitted here&lt;/a&gt;) is below:&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;&quot;Hilarious in a sad way, the worst PCI fail I ever had was getting&lt;br&gt;solicited by a Wedding / Bridal catalog company to assist them in&lt;br&gt;improving their online ordering and bridal catalog subscription&lt;br&gt;service. I had no contract with them, this was just a preliminary&lt;br&gt;&quot;Let's see what we can do for you.&quot; They sent us their website, and&lt;br&gt;also e-mailed me a copy of their site's source code.&lt;br&gt;In the source code was an SQL dump of over 7 years of brides personal&lt;br&gt;information including names, addresses, birthdays, and FULL credit&lt;br&gt;card numbers, expiration dates, CCVs, card type, phone numbers, email&lt;br&gt;addresses, and unencrypted passwords.&lt;br&gt;In shock of seeing this, I called the potential client, said we&lt;br&gt;couldn't help them and deleted the data as completely as I could.&lt;br&gt;Eek!&quot;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;The winner, “James P”, please mail your address to &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;mailto:authors@pcicompliancebook.info&quot;&gt;authors@pcicompliancebook.info&lt;/a&gt; and we will mail you your signed copy of &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.pcicompliancebook.info&quot;&gt;The PCI Book&lt;/a&gt;, 3rd edition. And, no, we won’t charge your credit card for that &lt;img style=&quot;border-bottom-style:none;border-right-style:none;border-top-style:none;border-left-style:none;&quot; class=&quot;wlEmoticon wlEmoticon-smile&quot; alt=&quot;Smile&quot; src=&quot;http://lh5.ggpht.com/-xR3A56TARYk/UL56Gneg6NI/AAAAAAAAWeA/1d30qNvEP1A/wlEmoticon-smile%25255B2%25255D.png?imgmax=800&quot;&gt; &lt;p&gt;The runner-up entries were: &lt;p&gt;“A very large retailer decides to reorganize their IT department to be more responsive and reactive. As part of that reorganization, they create a group titled 'Enterprise Monitoring' that is responsible for the care/feeding of the log management and analysis solutions. Centralized personnel that actually do the monitoring are pushed out to the business units where, according to IT management, the actual monitoring belongs. Everyone at the meeting announcing this decision says that the name. Enterprise Monitoring, needs to be changed because it gives the impression that the group does the monitoring, but they are over ruled.&lt;br&gt;Spin ahead almost a year later to their PCI assessment. The monitoring personnel that were pushed out to the business units were, surprise/surprise, were seen as new bodies that could be used for everything BUT monitoring. So, we have great log management and analysis solutions running, but no one has been monitoring anything for almost a year! When asked, the business units point to the Enterprise Monitoring group and say that it is their responsibility because they are 'Enterprise Monitoring'. DUH!﻿” (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://plus.google.com/104051623244958334514/posts/g2rfKAXwU7Q&quot;&gt;source&lt;/a&gt;) &lt;p&gt;and &lt;p&gt;“I work with a stadium and arena concessions operation that once told me they were compliant because they put their card swipe readers on the counter and turned them around to face the customer. They no longer touched the cards so this made them compliant. True story.” (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.brandenwilliams.com/blog/2012/11/14/pci-compliance-book-giveaway/&quot;&gt;source&lt;/a&gt;) &lt;p&gt;and &lt;p&gt;“It’s a not a fail, but I certainly found humor in this. When enrolling in training with the PCI Security Standards Council, if you would like pay by credit card they ask that you write your CC#, CVV, Expiration, etc on the invoice and fax it or mail it to them. They note, it is a secure and password protected fax. I expected something a little more from the people who create the standards, but hey that’s one way to reduce your scope. Upon receiving the invoice, it was an LOL moment. ” (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.brandenwilliams.com/blog/2012/11/14/pci-compliance-book-giveaway/&quot;&gt;source&lt;/a&gt;) &lt;p&gt;MORE PCI Book CONTESTS ARE COMING!! Stand by….&lt;/p&gt;  &lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=zHBCqtbIPYs:WM8rbhcB9KI:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=zHBCqtbIPYs:WM8rbhcB9KI:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=zHBCqtbIPYs:WM8rbhcB9KI:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/zHBCqtbIPYs&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-7784640038738267568</guid>
         <pubDate>Tue, 04 Dec 2012 22:32:59 +0000</pubDate>
         <media:thumbnail height="72" url="http://lh5.ggpht.com/-xR3A56TARYk/UL56Gneg6NI/AAAAAAAAWeA/1d30qNvEP1A/s72-c/wlEmoticon-smile%25255B2%25255D.png?imgmax=800" width="72"/>
      </item>
      <item>
         <title>Monthly Blog Round-Up – November 2012</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/tf_MnRwfUwM/monthly-blog-round-up-november-2012.html</link>
         <description>&lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt;Here is my next &lt;strong&gt;monthly &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.blogger.com/chuvakin.blogspot.com/&quot;&gt;&quot;Security Warrior&quot; blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt;&lt;/div&gt; &lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt; &lt;ol&gt; &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html&quot;&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top of this list – the checklist is still a very useful tool for many people. “&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html&quot;&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html&quot;&gt;updated version&lt;/a&gt;, and, yes, I know it really needs another update)  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/11/pci-compliance-book-giveaway.html&quot;&gt;PCI Compliance Book Giveaway!&lt;/a&gt;” announces &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.brandenwilliams.com/blog/&quot;&gt;our&lt;/a&gt; new contest and its prize – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.pcicompliancebook.info&quot;&gt;The PCI Compliance book&lt;/a&gt;. We will announce the winner any day now. &lt;li&gt;My classic &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/07/chuvakin.blogspot.com/search/label/PCI_Log_Review&quot;&gt;PCI DSS Log Review series&lt;/a&gt; is popular as well. The approach is useful for building other types of log review processes and procedures, whether regulatory or not. &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html&quot;&gt;On Choosing SIEM&lt;/a&gt;” is another old classic (from 2010) that shows up on my top list; it covers some tips on&amp;nbsp; choosing SIEM tools.  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html&quot;&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011. &lt;/li&gt;&lt;/ol&gt;&lt;/div&gt; &lt;p&gt;In addition, I’d like to draw your attention to a few posts from &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;my Gartner blog&lt;/a&gt;: &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Current DLP research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/11/30/on-dlp-and-pci-dss/&quot;&gt;On DLP and PCI DSS&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/11/09/on-dlp-and-ip-theft/&quot;&gt;On DLP and IP Theft&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/11/01/dlp-andorforvs-data-security/&quot;&gt;DLP and/or/for/vs Data Security&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/10/25/on-dlp-processes-or-no-dlp-for-dummies/&quot;&gt;On DLP Processes or “No DLP For Dummies”&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/10/19/on-dlp-research/&quot;&gt;On DLP Research&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Also see my past &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Annual&quot;&gt;annual&lt;/a&gt; “Top Posts” – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html&quot;&gt;2007&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html&quot;&gt;2008&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html&quot;&gt;2009&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html&quot;&gt;2010&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html&quot;&gt;2011&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all content at &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securitywarrior.org&quot;&gt;SecurityWarrior blog&lt;/a&gt; was written before I &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/last-blog-post.html&quot;&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Previous post in this endless series:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/11/monthly-blog-round-up-october-2012.html&quot;&gt;Monthly Blog Round-Up – October 2012&lt;/a&gt; &lt;li&gt;All posts tagged &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=tf_MnRwfUwM:amqbDXl5ASA:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=tf_MnRwfUwM:amqbDXl5ASA:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=tf_MnRwfUwM:amqbDXl5ASA:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/tf_MnRwfUwM&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-6747014106434522321</guid>
         <pubDate>Mon, 03 Dec 2012 15:43:12 +0000</pubDate>
         <category>Monthly</category>
      </item>
      <item>
         <title>PCI Compliance Book Giveaway!</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/SgaQUOT0nec/pci-compliance-book-giveaway.html</link>
         <description>&lt;p&gt;OK folks, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.pcicompliancebook.info&quot;&gt;our PCI Compliance book&lt;/a&gt; has been out for a couple of months now, and Branden &amp;amp; I thought it would be fun to give a way a couple of copies with a contest! We have assembled a group of three independent judges that will take a whittled down list and pick winners for each competition. The winner will receive a &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.pcicompliancebook.info/&quot;&gt;free, signed copy of the book&lt;/a&gt;!&lt;/p&gt; &lt;p&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.brandenwilliams.com/wp-content/uploads/2009/08/41YwOvKjZCL._SL500_AA240_.jpg&quot;&gt;&lt;img title=&quot;PCI Compliance&quot; alt=&quot;&quot; src=&quot;https://www.brandenwilliams.com/wp-content/uploads/2009/08/41YwOvKjZCL._SL500_AA240_.jpg&quot; width=&quot;240&quot; height=&quot;240&quot;&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;So, on to the first contest.  &lt;p&gt;Our book attempts to draw a middle line between the black &amp;amp; white “audit” style of looking at PCI DSS and the loosey-goosey anything goes view. We want to take a compliance-friendly, practitioners line. But we’ve all been in those meetings when you look at a particular defense of a control (or lack thereof) and you can’t help but laugh a little bit on the ridiculous nature of what was presented.  &lt;p&gt;&lt;strong&gt;So our first challenge to you, in the comments below, please tell us about your MOST HILARIOUS PCI FAIL. &lt;/strong&gt; &lt;p&gt;You’ve got a week (until the end of Wednesday, November 21st), and we will announce the winners after the US Thanksgiving holiday! &lt;p&gt;It doesn’t matter if you comment here or on &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.brandenwilliams.com/blog/2012/11/14/pci-compliance-book-giveaway/&quot;&gt;Branden’s blog&lt;/a&gt;, we will capture all of them.&lt;/p&gt;  &lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=SgaQUOT0nec:EyW7GW6gpYc:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=SgaQUOT0nec:EyW7GW6gpYc:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=SgaQUOT0nec:EyW7GW6gpYc:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/SgaQUOT0nec&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-4033420457311775457</guid>
         <pubDate>Thu, 15 Nov 2012 23:51:35 +0000</pubDate>
      </item>
      <item>
         <title>Monthly Blog Round-Up – October 2012</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/ZT_qP-R-pvM/monthly-blog-round-up-october-2012.html</link>
         <description>&lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt;Here is my next &lt;strong&gt;monthly &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.blogger.com/chuvakin.blogspot.com/&quot;&gt;&quot;Security Warrior&quot; blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt;&lt;/div&gt; &lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt; &lt;ol&gt; &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html&quot;&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top of this list – the checklist is still a very useful tool for many people. “&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html&quot;&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html&quot;&gt;updated version&lt;/a&gt;, and, yes, I know it needs another update)  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html&quot;&gt;On Choosing SIEM&lt;/a&gt;” is another old classic (from 2010) that shows up on my top list; it covers some tips on&amp;nbsp; choosing SIEM tools.  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html&quot;&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011.  &lt;li&gt;My &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/07/chuvakin.blogspot.com/search/label/PCI_Log_Review&quot;&gt;PCI DSS Log Review series&lt;/a&gt; is popular as well. It actually needs no introduction.  &lt;li&gt;SIEM use cases (however they are defined) seem to be on a lot of minds and so &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/11/siem-bloggables.html&quot;&gt;“SIEM Bloggables”&lt;/a&gt; post (and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/12/log-management-siem.html&quot;&gt;this one&lt;/a&gt; too) is on my top list.&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt; &lt;p&gt;In addition, I’d like to draw your attention to a few posts from &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;my Gartner blog&lt;/a&gt;: &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Current DLP research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/11/01/dlp-andorforvs-data-security/&quot;&gt;DLP and/or/for/vs Data Security&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/10/25/on-dlp-processes-or-no-dlp-for-dummies/&quot;&gt;On DLP Processes or “No DLP For Dummies”&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/10/19/on-dlp-research/&quot;&gt;On DLP Research&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Recent SIEM research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/09/24/on-output-driven-siem/&quot;&gt;On “Output-driven” SIEM&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/09/17/on-siem-maturity-scale-and-maybe-on-cmm-too/&quot;&gt;On SIEM Maturity Scale and Maybe On CMM Too&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/09/14/my-siem-workshop-sas-day/&quot;&gt;My SIEM Workshop / SAS Day&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/08/24/on-siem-deployment-evolution/&quot;&gt;On SIEM Deployment Evolution&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/08/09/on-people-running-siem/&quot;&gt;On People Running SIEM&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/09/14/my-siem-workshop-sas-day/&quot;&gt;My SIEM Workshop / SAS Day&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/07/30/on-siem-processespractices/&quot;&gt;On SIEM Processes/Practices&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/07/25/on-large-scale-siem-architecture/&quot;&gt;On Large-scale SIEM Architecture&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/07/18/some-of-the-big-siem-questions/&quot;&gt;Some of the Big SIEM Questions&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/07/13/my-upcoming-siem-research/&quot;&gt;My Upcoming SIEM Research&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Also see my past &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Annual&quot;&gt;annual&lt;/a&gt; “Top Posts” – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html&quot;&gt;2007&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html&quot;&gt;2008&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html&quot;&gt;2009&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html&quot;&gt;2010&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html&quot;&gt;2011&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all content at &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securitywarrior.org&quot;&gt;SecurityWarrior blog&lt;/a&gt; was written before I &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/last-blog-post.html&quot;&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Previous post in this endless series:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/10/monthly-blog-round-up-september-2012.html&quot;&gt;Monthly Blog Round-Up – September 2012&lt;/a&gt;  &lt;li&gt;All posts tagged &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=ZT_qP-R-pvM:YYlGBA4LWVc:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=ZT_qP-R-pvM:YYlGBA4LWVc:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=ZT_qP-R-pvM:YYlGBA4LWVc:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/ZT_qP-R-pvM&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-6009497223280902365</guid>
         <pubDate>Thu, 01 Nov 2012 17:48:20 +0000</pubDate>
         <category>Monthly</category>
      </item>
      <item>
         <title>Monthly Blog Round-Up – September 2012</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/cTMnDO900Mo/monthly-blog-round-up-september-2012.html</link>
         <description>&lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt;Here is my next &lt;strong&gt;monthly &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.blogger.com/chuvakin.blogspot.com/&quot;&gt;&quot;Security Warrior&quot; blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt;&lt;/div&gt; &lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt; &lt;ol&gt; &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html&quot;&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top of this list – the checklist is still a very useful tool for many people. “&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html&quot;&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html&quot;&gt;updated version&lt;/a&gt;, and, yes, I know it needs another update…)  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html&quot;&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011.  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html&quot;&gt;On Choosing SIEM&lt;/a&gt;” is another old classic (from 2010) that shows up on my top list; it covers some tips on&amp;nbsp; choosing SIEM tools.  &lt;li&gt;My &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/07/chuvakin.blogspot.com/search/label/PCI_Log_Review&quot;&gt;PCI DSS Log Review series&lt;/a&gt; is popular as well. It actually needs no introduction &lt;img style=&quot;border-bottom-style:none;border-right-style:none;border-top-style:none;border-left-style:none;&quot; class=&quot;wlEmoticon wlEmoticon-smile&quot; alt=&quot;Smile&quot; src=&quot;http://lh3.ggpht.com/-DlqMUuKbLp4/UGnBUKP1qjI/AAAAAAAAV_I/NkAZrPhlKLk/wlEmoticon-smile%25255B2%25255D.png?imgmax=800&quot;&gt; &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/03/myth-of-siem-as-analyst-in-box-or-how.html&quot;&gt;The Myth of SIEM as “An Analyst-in-the-box” or How NOT to Pick a SIEM-II?&lt;/a&gt;” is about how some organizations want to buy a SIEM and pretend they now have security monitoring&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;In addition, I’d like to draw your attention to a few posts from &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;my Gartner blog&lt;/a&gt;:  &lt;p&gt;&lt;strong&gt;Current SIEM research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/09/24/on-output-driven-siem/&quot;&gt;On “Output-driven” SIEM&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/09/17/on-siem-maturity-scale-and-maybe-on-cmm-too/&quot;&gt;On SIEM Maturity Scale and Maybe On CMM Too&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/09/14/my-siem-workshop-sas-day/&quot;&gt;My SIEM Workshop / SAS Day&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/08/24/on-siem-deployment-evolution/&quot;&gt;On SIEM Deployment Evolution&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/08/09/on-people-running-siem/&quot;&gt;On People Running SIEM&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/09/14/my-siem-workshop-sas-day/&quot;&gt;My SIEM Workshop / SAS Day&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/07/30/on-siem-processespractices/&quot;&gt;On SIEM Processes/Practices&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/07/25/on-large-scale-siem-architecture/&quot;&gt;On Large-scale SIEM Architecture&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/07/18/some-of-the-big-siem-questions/&quot;&gt;Some of the Big SIEM Questions&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/07/13/my-upcoming-siem-research/&quot;&gt;My Upcoming SIEM Research&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Other fun Gartner blog posts:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/08/29/on-nebulous-security-policies/&quot;&gt;On Nebulous Security Policies&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/06/29/how-are-we-doing-compared-to-peers/&quot;&gt;How Are We Doing Compared To Peers?&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Also see my past &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Annual&quot;&gt;annual&lt;/a&gt; “Top Posts” – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html&quot;&gt;2007&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html&quot;&gt;2008&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html&quot;&gt;2009&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html&quot;&gt;2010&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html&quot;&gt;2011&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content at SecurityWarrior blog was written before I &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/last-blog-post.html&quot;&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Previous post in this endless series:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/09/monthly-blog-round-up-august-2012.html&quot;&gt;Monthly Blog Round-Up – August 2012&lt;/a&gt;  &lt;li&gt;All posts tagged &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=cTMnDO900Mo:VUZPpiJ1bdM:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=cTMnDO900Mo:VUZPpiJ1bdM:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=cTMnDO900Mo:VUZPpiJ1bdM:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/cTMnDO900Mo&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-4824438890776312517</guid>
         <pubDate>Mon, 01 Oct 2012 16:14:09 +0000</pubDate>
         <media:thumbnail height="72" url="http://lh3.ggpht.com/-DlqMUuKbLp4/UGnBUKP1qjI/AAAAAAAAV_I/NkAZrPhlKLk/s72-c/wlEmoticon-smile%25255B2%25255D.png?imgmax=800" width="72"/>
         <category>Monthly</category>
      </item>
      <item>
         <title>Monthly Blog Round-Up – August 2012</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/bYeJLuLN4lA/monthly-blog-round-up-august-2012.html</link>
         <description>&lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt;Here is my next &lt;strong&gt;monthly &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.blogger.com/chuvakin.blogspot.com/&quot;&gt;&quot;Security Warrior&quot; blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt;&lt;/div&gt; &lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt; &lt;ol&gt; &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html&quot;&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top of this list – the checklist is still a very useful tool for many people. “&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html&quot;&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html&quot;&gt;updated version&lt;/a&gt;, and, yes, I know it needs another update…)  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html&quot;&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011.  &lt;li&gt;My &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/07/chuvakin.blogspot.com/search/label/PCI_Log_Review&quot;&gt;PCI DSS Log Review series&lt;/a&gt; is popular as well. &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html&quot;&gt;On Choosing SIEM&lt;/a&gt;” is another old classic (from 2010) that shows up on my top list. &lt;li&gt;Next is “&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/03/siem-resourcing-or-how-much-friggin.html&quot;&gt;SIEM Resourcing or How Much the Friggin’ Thing Would REALLY Cost Me?&lt;/a&gt;” While reading this, also check &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.slideshare.net/anton_chuvakin/something-fun-about-using-siem-by-dr-anton-chuvakin&quot;&gt;this presentation&lt;/a&gt;. &lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;In addition, I’d like to draw your attention to a few posts from &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;my Gartner blog&lt;/a&gt;:  &lt;p&gt;&lt;strong&gt;Current SIEM research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/08/24/on-siem-deployment-evolution/&quot;&gt;On SIEM Deployment Evolution&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/08/09/on-people-running-siem/&quot;&gt;On People Running SIEM&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/07/30/on-siem-processespractices/&quot;&gt;On SIEM Processes/Practices&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/07/25/on-large-scale-siem-architecture/&quot;&gt;On Large-scale SIEM Architecture&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/07/18/some-of-the-big-siem-questions/&quot;&gt;Some of the Big SIEM Questions&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/07/13/my-upcoming-siem-research/&quot;&gt;My Upcoming SIEM Research&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Other fun posts:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/08/29/on-nebulous-security-policies/&quot;&gt;On Nebulous Security Policies&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/06/29/how-are-we-doing-compared-to-peers/&quot;&gt;How Are We Doing Compared To Peers?&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Also see my past &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Annual&quot;&gt;annual&lt;/a&gt; “Top Posts” – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html&quot;&gt;2007&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html&quot;&gt;2008&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html&quot;&gt;2009&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html&quot;&gt;2010&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html&quot;&gt;2011&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content at SecurityWarrior blog was written before I &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/last-blog-post.html&quot;&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Previous post in this endless series:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/08/monthly-blog-round-up-july-2012.html&quot;&gt;Monthly Blog Round-Up – July 2012&lt;/a&gt; &lt;li&gt;All posts tagged &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=bYeJLuLN4lA:CeqTKtrJ2tQ:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=bYeJLuLN4lA:CeqTKtrJ2tQ:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=bYeJLuLN4lA:CeqTKtrJ2tQ:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/bYeJLuLN4lA&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-6497991929657086093</guid>
         <pubDate>Mon, 10 Sep 2012 14:46:57 +0000</pubDate>
         <category>Monthly</category>
      </item>
      <item>
         <title>One Year at Gartner!</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/norND4pTUdY/one-year-at-gartner.html</link>
         <description>&lt;p&gt;Believe it or not, but I've been at Gartner for a year. One whole year has passed since &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/last-blog-post.html&quot;&gt;that infamous blog post&lt;/a&gt;. I don't feel like diving into deep reflections and long contemplations about it, but I wanted to share how it was. During this year, I …&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;strong&gt;learned a lot&lt;/strong&gt;, and expanded my security knowledge into new areas such as &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/category/denial-of-service/&quot;&gt;denial of service defense&lt;/a&gt;&amp;nbsp; &lt;li&gt;found out that &lt;strong&gt;being an analyst is a lot of fun&lt;/strong&gt;  &lt;li&gt;realized that there are &lt;strong&gt;many levels of writing excellence&lt;/strong&gt; beyond the level that I thought I had …  &lt;li&gt;interacted with &lt;strong&gt;a lot of smart people&lt;/strong&gt; both within and outside Gartner  &lt;li&gt;&lt;strong&gt;helped&lt;/strong&gt; dozens of our clients – both security vendors and large enterprises - with their security challenges, some simple and some pretty esoteric  &lt;li&gt;&lt;strong&gt;discovered&lt;/strong&gt; that a lot of companies are not where our industry pundits and &quot;thought leaders&quot; say they are (“what is more common&amp;nbsp; today at large organizations, cloud or Windows 2000?”) &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;That's about it - I am really looking forward to my second year!&lt;/p&gt;  &lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=norND4pTUdY:eJvlpvrb8bs:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=norND4pTUdY:eJvlpvrb8bs:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=norND4pTUdY:eJvlpvrb8bs:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/norND4pTUdY&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-7126207522515143014</guid>
         <pubDate>Thu, 02 Aug 2012 17:28:52 +0000</pubDate>
      </item>
      <item>
         <title>Monthly Blog Round-Up – July 2012</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/h6XD4UYmMLg/monthly-blog-round-up-july-2012.html</link>
         <description>&lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt;Here is my next &lt;strong&gt;monthly &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.blogger.com/chuvakin.blogspot.com/&quot;&gt;&quot;Security Warrior&quot; blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt;&lt;/div&gt; &lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt; &lt;ol&gt; &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html&quot;&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top – the checklist is still a very useful tool for many people. “&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html&quot;&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html&quot;&gt;updated version&lt;/a&gt;)  &lt;li&gt;Next is “&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/03/siem-resourcing-or-how-much-friggin.html&quot;&gt;SIEM Resourcing or How Much the Friggin’ Thing Would REALLY Cost Me?&lt;/a&gt;” While reading this, also check &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.slideshare.net/anton_chuvakin/something-fun-about-using-siem-by-dr-anton-chuvakin&quot;&gt;this presentation&lt;/a&gt;. &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/on-siem-services.html&quot;&gt;On SIEM Services&lt;/a&gt;” appearance on this list reminds me that the Internet has a mind of its own as this post is closely related to what I am working on right now &lt;img style=&quot;border-bottom-style:none;border-right-style:none;border-top-style:none;border-left-style:none;&quot; class=&quot;wlEmoticon wlEmoticon-smile&quot; alt=&quot;Smile&quot; src=&quot;http://lh4.ggpht.com/-DF2Ps8MnATc/UBlFsji89AI/AAAAAAAAVYs/JfiejerKIrE/wlEmoticon-smile%25255B2%25255D.png?imgmax=800&quot;&gt; &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html&quot;&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011.  &lt;li&gt;Finally, “&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/07/book-review-up-and-to-right-strategy.html&quot;&gt;Book Review: “UP and to the RIGHT: Strategy and Tactics of Analyst Influence: A complete guide to analyst influence” by Richard Stiennon&lt;/a&gt;” made it to the top 5 as well.&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;In addition, I’d like to draw your attention to a few posts from &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;my Gartner blog&lt;/a&gt;:  &lt;p&gt;&lt;strong&gt;Current SIEM research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/07/30/on-siem-processespractices/&quot;&gt;On SIEM Processes/Practices&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/07/25/on-large-scale-siem-architecture/&quot;&gt;On Large-scale SIEM Architecture&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/07/18/some-of-the-big-siem-questions/&quot;&gt;Some of the Big SIEM Questions&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/07/13/my-upcoming-siem-research/&quot;&gt;My Upcoming SIEM Research&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Other fun posts:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/06/29/how-are-we-doing-compared-to-peers/&quot;&gt;How Are We Doing Compared To Peers?&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Also see my past &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Annual&quot;&gt;annual&lt;/a&gt; “Top Posts” – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html&quot;&gt;2007&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html&quot;&gt;2008&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html&quot;&gt;2009&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html&quot;&gt;2010&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html&quot;&gt;2011&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content was written before I &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/last-blog-post.html&quot;&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Previous post in this endless series:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/07/monthly-blog-round-up-june-2012.html&quot;&gt;Monthly Blog Round-Up – June 2012&lt;/a&gt;&lt;/li&gt; &lt;li&gt;All posts tagged &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=h6XD4UYmMLg:gyUAa1e1IUA:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=h6XD4UYmMLg:gyUAa1e1IUA:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=h6XD4UYmMLg:gyUAa1e1IUA:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/h6XD4UYmMLg&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-4728736385312907599</guid>
         <pubDate>Wed, 01 Aug 2012 15:05:23 +0000</pubDate>
         <media:thumbnail height="72" url="http://lh4.ggpht.com/-DF2Ps8MnATc/UBlFsji89AI/AAAAAAAAVYs/JfiejerKIrE/s72-c/wlEmoticon-smile%25255B2%25255D.png?imgmax=800" width="72"/>
         <category>Monthly</category>
      </item>
      <item>
         <title>Metricon 7 Workshop Reminder</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/XMrHuA1PLU8/metricon-7-workshop-reminder.html</link>
         <description>&lt;p&gt;Just a quick reminder about the Metricon 7 workshop on security metrics.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Date&lt;/strong&gt;: August 7, 2012&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Location&lt;/strong&gt;: Bellevue, WA (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.usenix.org/conference/usenixsecurity12/hotel-and-travel-information&quot;&gt;co-located with USENIX 12&lt;/a&gt;)&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Registration&lt;/strong&gt;:&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.usenix.org/conference/usenixsecurity12/registration-information&quot;&gt;https://www.usenix.org/conference/usenixsecurity12/registration-information&lt;/a&gt;&amp;nbsp; (pick just the metrics workshop or the entire event)&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Agenda&lt;/strong&gt;:&lt;/p&gt; &lt;p&gt;1. Introduction to Metricon, security metrics and workshop goals by Anton Chuvakin (9:00-9:30) &lt;p&gt;2. “Even Giant Metrics Programs Start Small” by David Severski (9:30-10:30) &lt;p&gt;3. Break (10:30-10:45) &lt;p&gt;4. PANEL: “Rules of the Road for Useful Security Metrics” (10:45-11:30) &lt;p&gt;5. Mini-talk 1 and 2 – &lt;strong&gt;TBD&lt;/strong&gt; (11:30-12:00) &lt;p&gt;6. Lunch break (12:00-1:00)  &lt;p&gt;7. “What We Want to See in Security Metrics” by Christopher Carlson (1:00-2:00) &lt;p&gt;8. PANEL: “What We Know to Work in Security Metrics” (2:00-2:30) &lt;p&gt;9. “Application Security Metrics We Use” Steve Mckinney (2:30-3:00) &lt;p&gt;10. Break (3:00 – 3:15) &lt;p&gt;11. &quot;Threat Genomics and Threat Modeling” by Jon Espenschied (3:15-4:15) &lt;p&gt;12. Discussion time, everybody shares lessons, highlights, etc (4:15-5:00) &lt;p&gt;13. Conclusions, results and action items by Anton Chuvakin (5:00-5:15) &lt;p&gt;&lt;strong&gt;Additional details: &lt;/strong&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securitymetrics.org/content/Wiki.jsp?page=Metricon7.0&quot;&gt;here&lt;/a&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;See you there!&lt;/p&gt;  &lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=XMrHuA1PLU8:OWpgYVVcK10:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=XMrHuA1PLU8:OWpgYVVcK10:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=XMrHuA1PLU8:OWpgYVVcK10:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/XMrHuA1PLU8&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-5110081205355225635</guid>
         <pubDate>Fri, 20 Jul 2012 00:20:39 +0000</pubDate>
      </item>
      <item>
         <title>Book Review: “UP and to the RIGHT: Strategy and Tactics of Analyst Influence: A complete guide to analyst influence” by Richard Stiennon</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/q8LAjqM9Ru8/book-review-up-and-to-right-strategy.html</link>
         <description>&lt;p&gt;This is not a book for everybody (and your grandmother probably does not need to read it; neither does an average IT professional). However, I think that &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.amazon.com/UP-RIGHT-Strategy-Influence-influence/dp/0985460709/&quot;&gt;this book&lt;/a&gt; is pure gold for those tasked with interacting with analyst firms.&lt;br&gt;&lt;br&gt;I am an analyst, and I wish every vendor client read this book and followed some of the advice given there. It would reduce pain on both sides of the conversation, as well as make the interactions more valuable for – again! - both sides.  &lt;p&gt;Obviously, this is not a book to guarantee your IT product a favorable placement in analyst research. It is also not a book on how to bamboozle the analysts, despite its focus on analyst influence. However, it is definitely a book to make sure that well deserving products, developed and marketed by good teams of people, don't get sidelined.  &lt;p&gt;Some of the specifics that I liked include the influence pyramid concept, social media techniques, a careful approach to managing corporate Wikipedia entries, specific approaches to various analyst activities (such as calls, reports, advisory days and conferences), etc. My favorite sections (both fun to read as well as insightful!) are the one on “guerrilla tactics” and the obligatory “what not to do” chapter (the latter has a few sad case studies of IT vendors who screwed themselves up). Another great chapter covers the role of a vendor sales team in both helping the interaction with the analyst firm and avoiding some embarrassing mistakes.  &lt;p&gt;In fact, this book makes me proud to be an analyst. Then again, maybe it is my ego talking as the book seems to project an impression that “an analyst is the most important person in the world“, at least as far as IT vendors are concerned. &lt;p&gt;Finally, if you are a IT vendor marketer, remember: when you say “holistic,&quot; some analysts think “imaginary.” &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.linkedin.com/in/stiennon&quot;&gt;Richard&lt;/a&gt; suggests to scrub your presentations of silly meaningless words like “synergy” and “holistic.” &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/book%20review&quot;&gt;All book reviews.&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=q8LAjqM9Ru8:ZcD_IPxrFyg:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=q8LAjqM9Ru8:ZcD_IPxrFyg:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=q8LAjqM9Ru8:ZcD_IPxrFyg:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/q8LAjqM9Ru8&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-3366973795501676766</guid>
         <pubDate>Tue, 17 Jul 2012 17:09:01 +0000</pubDate>
      </item>
      <item>
         <title>Monthly Blog Round-Up – June 2012</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/-6SKkQLflAk/monthly-blog-round-up-june-2012.html</link>
         <description>&lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt;Here is my next &lt;strong&gt;monthly &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.blogger.com/chuvakin.blogspot.com/&quot;&gt;&quot;Security Warrior&quot; blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt;&lt;/div&gt; &lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt; &lt;ol&gt; &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html&quot;&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top – the checklist is still a very useful tool for many people. “&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html&quot;&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html&quot;&gt;updated version&lt;/a&gt;)  &lt;li&gt;My &lt;a rel=&quot;nofollow&quot;&gt;PCI DSS Log Review series&lt;/a&gt; is popular as well. &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html&quot;&gt;On Choosing SIEM&lt;/a&gt;” is about &lt;em&gt;the least wrong way&lt;/em&gt; of choosing a SIEM tool – as well as why the right way is so unpopular.  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html&quot;&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm.  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/log-management-at-0-and-1hrweek.html&quot;&gt;Log Management at $0 and 1hr/week?&lt;/a&gt;” is where a lot of companies still are, thus this post became popular again.&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;In addition, I’d like to draw your attention to a few posts from &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;my Gartner blog&lt;/a&gt;:  &lt;p&gt;&lt;strong&gt;Denial of Service research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/05/29/more-on-dos-and-shared-security/&quot;&gt;More on DoS and Shared Security&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/05/15/on-dos-detection/&quot;&gt;On DoS Detection&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/05/03/wanted-dead-or-alive-application-dos-attack/&quot;&gt;Wanted Dead or Alive: Application DoS Attack&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/04/26/availability-security-and-why-is-dos-fun/&quot;&gt;Availability, Security and Why is DoS Fun?&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/06/06/quick-dos-attack-taxonomy/&quot;&gt;Quick DoS Attack Taxonomy&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/05/29/more-on-dos-and-shared-security/&quot;&gt;More on DoS and Shared Security&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Other fun posts:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/06/29/how-are-we-doing-compared-to-peers/&quot;&gt;How Are We Doing Compared To Peers?&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/06/04/on-stuxnet-revelations/&quot;&gt;On Stuxnet Revelations&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Also see my past &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Annual&quot;&gt;annual&lt;/a&gt; “Top Posts” – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html&quot;&gt;2007&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html&quot;&gt;2008&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html&quot;&gt;2009&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html&quot;&gt;2010&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html&quot;&gt;2011&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content was written before I &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/last-blog-post.html&quot;&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/06/monthly-blog-round-up-may-2012.html&quot;&gt;Monthly Blog Round-Up – May 2012&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=-6SKkQLflAk:JiSDAcL7GNU:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=-6SKkQLflAk:JiSDAcL7GNU:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=-6SKkQLflAk:JiSDAcL7GNU:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/-6SKkQLflAk&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-432918764277939940</guid>
         <pubDate>Mon, 09 Jul 2012 22:10:25 +0000</pubDate>
         <category>Monthly</category>
      </item>
      <item>
         <title>&quot;PCI Compliance&quot;, 3rd edition - Out On August 6, 2012</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/fcmlQsy1org/pci-compliance-3rd-edition-out-on.html</link>
         <description>&lt;div dir=&quot;ltr&quot; style=&quot;text-align:left;&quot;&gt;
A new edition (3rd) of our book &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.amazon.com/PCI-Compliance-Third-Edition-Understand/dp/159749948X&quot;&gt;&quot;PCI Compliance&lt;/a&gt;&quot; is coming out on August 6, 2012.&lt;br /&gt;
It covers PCI DSS 2.0, as requested by many of our readers. &amp;nbsp;Other new materials include Emerging Technology and Alternative Payment Schemes, PCI for the Small Business, etc. A full ToC for this new edition is &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.elsevier.com/wps/find/bookdescription.cws_home/727897/description#description&quot;&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Get the book in print or for Kindle!&lt;br /&gt;
&lt;br /&gt;
 

&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=fcmlQsy1org:HPsaLduKlyc:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=fcmlQsy1org:HPsaLduKlyc:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=fcmlQsy1org:HPsaLduKlyc:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/fcmlQsy1org&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-4551134351136414561</guid>
         <pubDate>Wed, 13 Jun 2012 06:05:07 +0000</pubDate>
      </item>
      <item>
         <title>Monthly Blog Round-Up – May 2012</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/hi3zteaqA60/monthly-blog-round-up-may-2012.html</link>
         <description>&lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt;Here is my next &lt;strong&gt;monthly &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.blogger.com/chuvakin.blogspot.com/&quot;&gt;&quot;Security Warrior&quot; blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt;&lt;/div&gt; &lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt; &lt;ol&gt; &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/log-management-at-0-and-1hrweek.html&quot;&gt;Log Management at $0 and 1hr/week?&lt;/a&gt;” is where a lot of companies still are, thus this post became popular again. &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html&quot;&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top – the checklist is still a very useful tool for many people. “&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html&quot;&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html&quot;&gt;updated version&lt;/a&gt;)  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/06/why-no-open-source-siem-ever.html&quot;&gt;Why No Open Source SIEM, EVER?&lt;/a&gt;” (and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/02/short-observation-on-open-source-siem.html&quot;&gt;this&lt;/a&gt;) is next – for some weird reason. I suspect a lot of people still crave a free open source SIEM tool.  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html&quot;&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm. &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html&quot;&gt;On Choosing SIEM&lt;/a&gt;” is about &lt;em&gt;the least wrong way&lt;/em&gt; of choosing a SIEM tool – as well as why the right way is so unpopular. &lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;In addition, I’d like to draw your attention to a few posts from &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;my Gartner blog&lt;/a&gt;:  &lt;p&gt;&lt;strong&gt;Denial of Service research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/05/29/more-on-dos-and-shared-security/&quot;&gt;More on DoS and Shared Security&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/05/15/on-dos-detection/&quot;&gt;On DoS Detection&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/05/03/wanted-dead-or-alive-application-dos-attack/&quot;&gt;Wanted Dead or Alive: Application DoS Attack&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/04/26/availability-security-and-why-is-dos-fun/&quot;&gt;Availability, Security and Why is DoS Fun?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Also see my past &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Annual&quot;&gt;annual&lt;/a&gt; “Top Posts” – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html&quot;&gt;2007&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html&quot;&gt;2008&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html&quot;&gt;2009&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html&quot;&gt;2010&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html&quot;&gt;2011&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content was written before I &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/last-blog-post.html&quot;&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/05/monthly-blog-round-up-april-2012.html&quot;&gt;Monthly Blog Round-Up – April 2012&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=hi3zteaqA60:NezQws7nJa4:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=hi3zteaqA60:NezQws7nJa4:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=hi3zteaqA60:NezQws7nJa4:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/hi3zteaqA60&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-8023703006117659175</guid>
         <pubDate>Fri, 01 Jun 2012 15:37:24 +0000</pubDate>
      </item>
      <item>
         <title>Book Review: “Security De-Engineering: Solving the Problems in Information Risk Management” by Ian Tibble</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/OdaqQorHemU/book-review-security-de-engineering.html</link>
         <description>&lt;div dir=&quot;ltr&quot; style=&quot;text-align:left;&quot;&gt;
This book is probably the most thought-provoking book on security I read in the last 5-7 years! While I'm somewhat known from my proclivity to exaggerate, I assure you this is not an exaggeration. As I was reading it, I felt like I connected to deep layers of the subconsciousness of security industry.  &lt;br /&gt;
In fact, the influence this book already had on me is palpable: I found myself using some of the terms (such as author’s favorites, “intellectual capital” and “CASE”) and concepts on the next day after I started reading it.  &lt;br /&gt;
&lt;br /&gt;
As a brief summary, the book investigates the evolution of the way we do information security from the “hacker-lead” late 1990s to “compliance-heavy” late 2000s and today. The author also highlights dramatic problems with today's approach to security and suggests some of the solutions in the way people think and operate around security.  &lt;br /&gt;
&lt;br /&gt;
In fact, it might be one of the most influential books ever written in history of security industry - the one that appeared at the best possible time when it’s most needed. Along the same line, I have grown worried about the ranks of security professionals who are not hands-on with technology and who have never secured production systems. Just as the author, I've been grown frustrated with the ranks of idiots who equate compliance and security. Even author’s rant about ethics is something I've been thinking for years.  &lt;br /&gt;
&lt;br /&gt;
The author slaughters a few of the sacred cows of security industry: one that “executives are clueless” and the one that we “must have reliable actuarial data on incidents to stay relevant.” He also highlights a few categories of security products, which are notorious for not delivering value and explains the reasons for that. Most of his points are backed up by specific cases from his experience, going back to the end of 1990s when the security industry was born.  &lt;br /&gt;
&lt;br /&gt;
And, of course, as with any thought-provoking writing, I cannot say I agree with every word I read. For example, I am much less negative on the vulnerability assessment technology than the author (I don't think they give you 50% “false negatives” on common platforms today). Furthermore, I abhor the use (misuse, really) of “ROI” for justifying security spending. Style-wise, the author is a little too fond of repetitions to my taste. However, having a summary after each chapter is a great idea.  &lt;br /&gt;
&lt;br /&gt;
Finally, despite the unreasonably high price, I feel that every member of the security community MUST read this book. Literally every chapter will have insights that will make you a better security professional today.  &lt;br /&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/book%20review&quot;&gt;All book reviews.&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=OdaqQorHemU:WBb6zagZQl0:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=OdaqQorHemU:WBb6zagZQl0:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=OdaqQorHemU:WBb6zagZQl0:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/OdaqQorHemU&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-2279970692188469581</guid>
         <pubDate>Fri, 18 May 2012 22:44:56 +0000</pubDate>
      </item>
      <item>
         <title>Monthly Blog Round-Up – April 2012</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/X5Ltd59xXec/monthly-blog-round-up-april-2012.html</link>
         <description>&lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt;Here is my next &lt;strong&gt;monthly &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.blogger.com/chuvakin.blogspot.com/&quot;&gt;&quot;Security Warrior&quot; blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt;&lt;/div&gt; &lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt; &lt;ol&gt; &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html&quot;&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top – the checklist is still a very useful tool for many people. “&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html&quot;&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html&quot;&gt;updated version&lt;/a&gt;)  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/06/why-no-open-source-siem-ever.html&quot;&gt;Why No Open Source SIEM, EVER?&lt;/a&gt;” (and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/02/short-observation-on-open-source-siem.html&quot;&gt;this&lt;/a&gt;) is next – for some weird reason. I suspect a lot of people still crave a free open source SIEM tool. &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html&quot;&gt;On Choosing SIEM&lt;/a&gt;” is about &lt;em&gt;the least wrong way&lt;/em&gt; of choosing a SIEM tool – as well as why the right way is so unpopular.  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/log-management-at-0-and-1hrweek.html&quot;&gt;Log Management at $0 and 1hr/week?&lt;/a&gt;” is where a lot of companies still are, thus this post became popular again. &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/top-10-criteria-for-siem.html&quot;&gt;Top 10 Criteria for a SIEM?&lt;/a&gt;” came from one of my last projects I did when running my SIEM consulting firm.&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;In addition, I’d like to draw your attention to a few posts from &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;my Gartner blog&lt;/a&gt;: &lt;p&gt;&lt;strong&gt;Denial of Service research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/04/26/availability-security-and-why-is-dos-fun/&quot;&gt;Availability, Security and Why is DoS Fun?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Cloud security monitoring research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/04/23/my-cloud-security-monitoring-paper-publishes/&quot;&gt;My Cloud Security Monitoring Paper Publishes!&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/04/10/cloud-security-monitoring-the-who-question/&quot;&gt;Cloud Security Monitoring: The “Who” Question&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/01/21/cloud-security-monitoring-for-iaas-paas-saas/&quot;&gt;Cloud Security Monitoring for IaaS, PaaS, SaaS&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/01/14/more-on-security-monitoring-of-public-cloud-assets/&quot;&gt;More On Security Monitoring of Public Cloud Assets&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/03/13/is-cloud-secure-wtfc/&quot;&gt;Is Cloud Secure? WTFC!&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/01/09/cloud-security-monitoring/&quot;&gt;Cloud Security Monitoring!&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/02/07/cloud-security-monitoring-iaas-conundrum-2/&quot;&gt;Cloud Security Monitoring: IaaS Conundrum&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/02/16/cloud-is-different-so-monitoring-must-be-different/&quot;&gt;Cloud IS Different: So Monitoring Must Be Different?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Future SIEM analytics research:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/03/26/big-analytics-for-security-a-harbinger-or-an-outlier/&quot;&gt;“Big Analytics” for Security: A Harbinger or An Outlier?&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/02/02/many-faces-of-application-security-monitoring/&quot;&gt;Many Faces of Application Security Monitoring&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/03/15/more-on-application-security-monitoring/&quot;&gt;More on Application Security Monitoring&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Also see my past &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Annual&quot;&gt;annual&lt;/a&gt; “Top Posts” – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html&quot;&gt;2007&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html&quot;&gt;2008&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html&quot;&gt;2009&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html&quot;&gt;2010&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html&quot;&gt;2011&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content was written before I &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/last-blog-post.html&quot;&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;here&lt;/a&gt;.&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/04/monthly-blog-round-up-march-2012.html&quot;&gt;Monthly Blog Round-Up – March 2012&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=X5Ltd59xXec:xkD4b9qRz-U:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=X5Ltd59xXec:xkD4b9qRz-U:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=X5Ltd59xXec:xkD4b9qRz-U:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/X5Ltd59xXec&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-1637433199235093766</guid>
         <pubDate>Wed, 02 May 2012 03:11:27 +0000</pubDate>
      </item>
      <item>
         <title>Metricon 7 Call for Papers</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/hjsz_Gs21vE/metricon-7-call-for-papers.html</link>
         <description>&lt;p&gt;This is a Call for Papers (CFP) for &lt;strong&gt;Metricon 7.&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Key stats first:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;Conference date: &lt;strong&gt;August 7, 2012&lt;/strong&gt;&lt;/li&gt; &lt;li&gt;CFP deadline: &lt;strong&gt;May 31, 2012&lt;/strong&gt;&lt;/li&gt; &lt;li&gt;Conference location: &lt;strong&gt;Bellevue, WA&lt;/strong&gt;&lt;/li&gt; &lt;li&gt;Cost to attend:&lt;strong&gt; free &lt;/strong&gt;(&lt;em&gt;but you’d need to add value to discussions&lt;/em&gt;)&lt;strong&gt;.&lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;CFP follows below and can be found at &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://securitymetrics.org/content/Wiki.jsp?page=Metricon7.0&quot;&gt;SecurityMetrics site&lt;/a&gt;. &lt;p&gt;&lt;strong&gt;&lt;font size=&quot;4&quot;&gt;Metricon 7 - Security Metrics: Useful or Bust!!&lt;/font&gt;&lt;/strong&gt; &lt;p&gt;How to define, generate, and communicate security metrics you can use TODAY!  &lt;p&gt;This year, Metricon 7.0 is excited to issue a call for participation to the information security community. The event will occur &lt;strong&gt;August 7th 2012&lt;/strong&gt; collocated with USENIX in &lt;strong&gt;Bellevue, WA. &lt;/strong&gt; &lt;p&gt;Given that this is the 7th event, we think it is time to finally say it: security metrics MUST be useful NOW! Thus, the focus this year is on useful and usable metrics – not conceptual and theoretical stuff that sounds great, but cannot and will not be used in today’s organizations. Also, presentations and panels that talk about “How?” and “What?” will be strongly prioritized over “Why?”(and “whine”). Enterprises and tool vendors are both welcome to present! Academic researchers tacking the real-world problems are welcome as well.  &lt;p&gt;&lt;strong&gt;&lt;font size=&quot;3&quot;&gt;We want to see:&lt;br&gt;&lt;/font&gt;&lt;/strong&gt;• How you achieved “quick wins” with security metrics?&lt;br&gt;• How you define useful metrics, whether risk or operational?&lt;br&gt;• What metrics you track are the most useful?&lt;br&gt;• How did you solve a particular challenge in security metrics area?&lt;br&gt;• How your tool helps (not “can help”!) with collecting and analyzing security metric data?&lt;br&gt;• Who gets the metrics you create? How do they use them?&lt;br&gt;• What metrics you use to determine that security controls are effective?&lt;br&gt;• How organization generate actionable advice from security metrics?&lt;br&gt;• How to track that your security is improving using metrics?  &lt;p&gt;&lt;font size=&quot;3&quot;&gt;&lt;em&gt;We do not want:&lt;br&gt;&lt;/em&gt;&lt;/font&gt;• Uncollectable and unusable metrics&lt;br&gt;• Metrics philosophy&lt;br&gt;• Uncooked metrics that sound vaguely “interesting”  &lt;p&gt;Send submissions and your ideas for panels and presentations to &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;mailto:metricon7@securitymetrics.org&quot;&gt;metricon7@securitymetrics.org&lt;/a&gt;  &lt;p&gt;Deadline for presentation and talk submissions is &lt;strong&gt;May 31st, 2012&lt;/strong&gt;. Submissions should be sent to &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;mailto:Metricon7@securitymetrics.org&quot;&gt;Metricon7@securitymetrics.org&lt;/a&gt;.&lt;/p&gt;  &lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=hjsz_Gs21vE:KLDij9bvb58:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=hjsz_Gs21vE:KLDij9bvb58:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=hjsz_Gs21vE:KLDij9bvb58:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/hjsz_Gs21vE&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-5830886756831028666</guid>
         <pubDate>Mon, 30 Apr 2012 16:54:30 +0000</pubDate>
      </item>
      <item>
         <title>Monthly Blog Round-Up – March 2012</title>
         <link>http://feedproxy.google.com/~r/AntonChuvakinPersonalBlog/~3/_TqRQTNJkmg/monthly-blog-round-up-march-2012.html</link>
         <description>&lt;div style=&quot;text-align:left;&quot; dir=&quot;ltr&quot;&gt;Here is my next &lt;strong&gt;monthly &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.blogger.com/chuvakin.blogspot.com/&quot;&gt;&quot;Security Warrior&quot; blog&lt;/a&gt; &lt;/strong&gt;round-up of top 5 popular posts/topics this month:&lt;br&gt; &lt;ol&gt; &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/03/simple-log-review-checklist-released.html&quot;&gt;Simple Log Review Checklist Released!&lt;/a&gt;” is often at the top – the checklist is still a very useful tool for many people  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/08/updated-with-community-feedback-sans_06.html&quot;&gt;Updated With Community Feedback SANS Top 7 Essential Log Reports DRAFT2&lt;/a&gt;”, “&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/07/sans-top-5-essential-log-reports-update.html&quot;&gt;SANS Top 5 Essential Log Reports Update!&lt;/a&gt;” and their predecessor&amp;nbsp; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/07/sans-top-5-essential-log-reports-update.html&quot;&gt;“Top5 SANS Log Reports Update DRAFT”&lt;/a&gt; also show up close to the top. &lt;font color=&quot;#ff0000&quot;&gt;&lt;b&gt;&lt;i&gt;IF YOU WANT TO VOLUNTEER TO FINISH THIS DOCUMENT- PLEASE EMAIL ME!&lt;/i&gt;&lt;/b&gt; &lt;/font&gt; &lt;li&gt;My classic PCI DSS log review series is still on my Top 5: “&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/PCI_Log_Review&quot;&gt;Complete PCI DSS Log Review Procedures&lt;/a&gt;”; they are also useful for other compliance or security log review and log monitoring.  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/09/on-free-log-management-tools.html&quot;&gt;On Free Log Management Tools&lt;/a&gt;” is a companion to the checklist below (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/03/updated-free-log-management-tools.html&quot;&gt;updated version&lt;/a&gt;)  &lt;li&gt;“&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/04/on-choosing-siem.html&quot;&gt;On Choosing SIEM&lt;/a&gt;” is about &lt;em&gt;the least wrong way&lt;/em&gt; of choosing a SIEM tool – as well as why the right way is so unpopular. &lt;/li&gt;&lt;/ol&gt;In addition, I’d like to draw your attention to a few posts from &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;my Gartner blog&lt;/a&gt;:&lt;br&gt; &lt;ol&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/03/26/big-analytics-for-security-a-harbinger-or-an-outlier/&quot;&gt;“Big Analytics” for Security: A Harbinger or An Outlier?&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/02/02/many-faces-of-application-security-monitoring/&quot;&gt;Many Faces of Application Security Monitoring&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/03/15/more-on-application-security-monitoring/&quot;&gt;More on Application Security Monitoring&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/01/21/cloud-security-monitoring-for-iaas-paas-saas/&quot;&gt;Cloud Security Monitoring for IaaS, PaaS, SaaS&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/01/14/more-on-security-monitoring-of-public-cloud-assets/&quot;&gt;More On Security Monitoring of Public Cloud Assets&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/03/13/is-cloud-secure-wtfc/&quot;&gt;Is Cloud Secure? WTFC!&lt;/a&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/01/09/cloud-security-monitoring/&quot;&gt;Cloud Security Monitoring!&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/02/07/cloud-security-monitoring-iaas-conundrum-2/&quot;&gt;Cloud Security Monitoring: IaaS Conundrum&lt;/a&gt;  &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin/2012/02/16/cloud-is-different-so-monitoring-must-be-different/&quot;&gt;Cloud IS Different: So Monitoring Must Be Different?&lt;/a&gt;&lt;/li&gt;&lt;/ol&gt;Also see my past &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Monthly&quot;&gt;monthly&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/search/label/Annual&quot;&gt;annual&lt;/a&gt; “Top Posts” – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html&quot;&gt;2007&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2009/01/annual-blog-round-up-2008.html&quot;&gt;2008&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2009.html&quot;&gt;2009&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2010/01/annual-blog-round-up-2010.html&quot;&gt;2010&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/01/annual-blog-round-up-2011.html&quot;&gt;2011&lt;/a&gt;. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: all this content was written before I &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2011/07/last-blog-post.html&quot;&gt;joined Gartner&lt;/a&gt; on Aug 1, 2011 and is solely my personal view &lt;strong&gt;&lt;u&gt;&lt;em&gt;at the time of writing&lt;/em&gt;&lt;/u&gt;&lt;/strong&gt;. For my current security blogging, go &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.gartner.com/anton-chuvakin&quot;&gt;here&lt;/a&gt;.&lt;br&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://chuvakin.blogspot.com/2012/03/monthly-blog-round-up-february-2012.html&quot;&gt;Monthly Blog Round-Up – February 2012&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;  &lt;div class=&quot;blogger-post-footer&quot;&gt;About me: http://www.chuvakin.org&lt;/div&gt;&lt;div class=&quot;feedflare&quot;&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=_TqRQTNJkmg:9Soe0yEstXQ:yIl2AUoC8zA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=yIl2AUoC8zA&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=_TqRQTNJkmg:9Soe0yEstXQ:63t7Ie-LG7Y&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=63t7Ie-LG7Y&quot; border=&quot;0&quot;&gt;&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?a=_TqRQTNJkmg:9Soe0yEstXQ:7Q72WNTAKBA&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~ff/AntonChuvakinPersonalBlog?d=7Q72WNTAKBA&quot; border=&quot;0&quot;&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/_TqRQTNJkmg&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
         <author>anton@chuvakin.org (Anton Chuvakin)</author>
         <guid isPermaLink="false">tag:blogger.com,1999:blog-19553129.post-7590495911413651910</guid>
         <pubDate>Mon, 02 Apr 2012 17:17:08 +0000</pubDate>
         <category>Monthly</category>
      </item>
   </channel>
</rss>
<!-- fe4.yql.bf1.yahoo.com compressed/chunked Wed Jun 19 04:14:42 UTC 2013 -->
