<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Third Defense Blog</title>
	<atom:link href="http://thirddefense.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://thirddefense.wordpress.com</link>
	<description></description>
	<lastBuildDate>Sat, 07 Jan 2012 01:23:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='thirddefense.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Third Defense Blog</title>
		<link>http://thirddefense.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://thirddefense.wordpress.com/osd.xml" title="Third Defense Blog" />
	<atom:link rel='hub' href='http://thirddefense.wordpress.com/?pushpress=hub'/>
		<item>
		<title>SIRA Webinars</title>
		<link>http://thirddefense.wordpress.com/2012/01/06/sira-webinars/</link>
		<comments>http://thirddefense.wordpress.com/2012/01/06/sira-webinars/#comments</comments>
		<pubDate>Sat, 07 Jan 2012 01:23:18 +0000</pubDate>
		<dc:creator>Jared</dc:creator>
				<category><![CDATA[General Goodness]]></category>

		<guid isPermaLink="false">http://thirddefense.wordpress.com/?p=665</guid>
		<description><![CDATA[Quick cross post if you&#8217;re interested in watching some of the SIRA webinars. They&#8217;re available to everyone on the SIRA blog. Keefer/Pfost&#8217;s presentation on &#8220;Moneysec: Applying Moneyball…&#8221; here: https://www.societyinforisk.org/content/sira-monthly-webinar-982011-17-gmt12-edt9-pdt-brian-keefer-and-jared-pfost-moneysec#comment-3 Herath&#8217;s presentation on Cyberinsurance here: https://www.societyinforisk.org/content/sira-monthly-webinar-5122011-12-pm10-am-edtpdt-it-risk-privacy-and-other-legal-concerns Rosenquist&#8217;s presentation on TARA here: https://www.societyinforisk.org/content/sira-monthly-webinar-8112011-1200pm-edt900am-pst-matthew-rosenquist-tara<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thirddefense.wordpress.com&amp;blog=12584692&amp;post=665&amp;subd=thirddefense&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Quick cross post if you&#8217;re interested in watching some of the SIRA webinars. They&#8217;re available to everyone on the SIRA blog.</p>
<div>Keefer/Pfost&#8217;s presentation on &#8220;Moneysec: Applying Moneyball…&#8221; here: <a href="https://www.societyinforisk.org/content/sira-monthly-webinar-982011-17-gmt12-edt9-pdt-brian-keefer-and-jared-pfost-moneysec#comment-3" target="_blank">https://www.societyinforisk.org/content/sira-monthly-webinar-982011-17-gmt12-edt9-pdt-brian-keefer-and-jared-pfost-moneysec#comment-3</a></div>
<div></div>
<div>Herath&#8217;s presentation on Cyberinsurance here:</div>
<div><a href="https://www.societyinforisk.org/content/sira-monthly-webinar-5122011-12-pm10-am-edtpdt-it-risk-privacy-and-other-legal-concerns" target="_blank">https://www.societyinforisk.org/content/sira-monthly-webinar-5122011-12-pm10-am-edtpdt-it-risk-privacy-and-other-legal-concerns</a></div>
<div></div>
<div>Rosenquist&#8217;s presentation on TARA here:</div>
<div><a href="https://www.societyinforisk.org/content/sira-monthly-webinar-8112011-1200pm-edt900am-pst-matthew-rosenquist-tara" target="_blank">https://www.societyinforisk.org/content/sira-monthly-webinar-8112011-1200pm-edt900am-pst-matthew-rosenquist-tara</a></div>
<div></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thirddefense.wordpress.com/665/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thirddefense.wordpress.com/665/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/thirddefense.wordpress.com/665/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/thirddefense.wordpress.com/665/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/thirddefense.wordpress.com/665/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/thirddefense.wordpress.com/665/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/thirddefense.wordpress.com/665/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/thirddefense.wordpress.com/665/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/thirddefense.wordpress.com/665/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/thirddefense.wordpress.com/665/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/thirddefense.wordpress.com/665/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/thirddefense.wordpress.com/665/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/thirddefense.wordpress.com/665/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/thirddefense.wordpress.com/665/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thirddefense.wordpress.com&amp;blog=12584692&amp;post=665&amp;subd=thirddefense&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thirddefense.wordpress.com/2012/01/06/sira-webinars/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3cea42c20c909a1af57059f8bcd42ce2?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Jared</media:title>
		</media:content>
	</item>
		<item>
		<title>Our New Videos!</title>
		<link>http://thirddefense.wordpress.com/2011/12/30/our-new-videos/</link>
		<comments>http://thirddefense.wordpress.com/2011/12/30/our-new-videos/#comments</comments>
		<pubDate>Sat, 31 Dec 2011 06:48:16 +0000</pubDate>
		<dc:creator>Jared</dc:creator>
				<category><![CDATA[General Goodness]]></category>

		<guid isPermaLink="false">http://thirddefense.wordpress.com/?p=661</guid>
		<description><![CDATA[Hello all. We just posted updated screen casts of all our apps on our web site. Vids are sprinkled throughout and cataloged on their own page. I tried to keep them short so lots of cool stuff left on the cutting room floor. They&#8217;re also in HD so you should be able to see the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thirddefense.wordpress.com&amp;blog=12584692&amp;post=661&amp;subd=thirddefense&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hello all. We just posted updated screen casts of all our apps on our <a title="Third Defense Home" href="http://www.thirddefense.com" target="_blank">web site</a>. Vids are sprinkled throughout and cataloged on their own <a title="Third Defense Videos" href="http://thirddefense.com/video.html" target="_blank">page</a>. I tried to keep them short so lots of cool stuff left on the cutting room floor. They&#8217;re also in HD so you should be able to see the apps this time. Fortunately I didn&#8217;t include video of me talking so you&#8217;re safe.</p>
<p>Please let us know if you&#8217;d like to see more or specific tutorials.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thirddefense.wordpress.com/661/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thirddefense.wordpress.com/661/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/thirddefense.wordpress.com/661/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/thirddefense.wordpress.com/661/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/thirddefense.wordpress.com/661/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/thirddefense.wordpress.com/661/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/thirddefense.wordpress.com/661/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/thirddefense.wordpress.com/661/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/thirddefense.wordpress.com/661/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/thirddefense.wordpress.com/661/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/thirddefense.wordpress.com/661/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/thirddefense.wordpress.com/661/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/thirddefense.wordpress.com/661/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/thirddefense.wordpress.com/661/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thirddefense.wordpress.com&amp;blog=12584692&amp;post=661&amp;subd=thirddefense&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thirddefense.wordpress.com/2011/12/30/our-new-videos/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3cea42c20c909a1af57059f8bcd42ce2?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Jared</media:title>
		</media:content>
	</item>
		<item>
		<title>Guest Post: Blue Hat Blog</title>
		<link>http://thirddefense.wordpress.com/2011/11/04/guest-post-blue-hat-blog/</link>
		<comments>http://thirddefense.wordpress.com/2011/11/04/guest-post-blue-hat-blog/#comments</comments>
		<pubDate>Fri, 04 Nov 2011 22:49:23 +0000</pubDate>
		<dc:creator>Jared</dc:creator>
				<category><![CDATA[General Goodness]]></category>

		<guid isPermaLink="false">http://thirddefense.wordpress.com/?p=657</guid>
		<description><![CDATA[Quick pointer to a guest entry on the Blue Hat Blog. I&#8217;ll post a pointer if my recorded session is available online.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thirddefense.wordpress.com&amp;blog=12584692&amp;post=657&amp;subd=thirddefense&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Quick pointer to a guest entry on the <a title="blue hat" href="http://blogs.technet.com/b/bluehat/archive/2011/11/03/beliefs-from-an-ex-softy.aspx" target="_blank">Blue Hat Blog</a>. I&#8217;ll post a pointer if my recorded session is available online.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thirddefense.wordpress.com/657/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thirddefense.wordpress.com/657/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/thirddefense.wordpress.com/657/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/thirddefense.wordpress.com/657/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/thirddefense.wordpress.com/657/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/thirddefense.wordpress.com/657/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/thirddefense.wordpress.com/657/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/thirddefense.wordpress.com/657/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/thirddefense.wordpress.com/657/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/thirddefense.wordpress.com/657/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/thirddefense.wordpress.com/657/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/thirddefense.wordpress.com/657/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/thirddefense.wordpress.com/657/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/thirddefense.wordpress.com/657/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thirddefense.wordpress.com&amp;blog=12584692&amp;post=657&amp;subd=thirddefense&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thirddefense.wordpress.com/2011/11/04/guest-post-blue-hat-blog/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3cea42c20c909a1af57059f8bcd42ce2?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Jared</media:title>
		</media:content>
	</item>
		<item>
		<title>Podcast: hanging with Santarcangelo et al. to transform awareness</title>
		<link>http://thirddefense.wordpress.com/2011/09/29/podcast-hanging-with-santarcangelo-et-al-to-transform-awareness/</link>
		<comments>http://thirddefense.wordpress.com/2011/09/29/podcast-hanging-with-santarcangelo-et-al-to-transform-awareness/#comments</comments>
		<pubDate>Thu, 29 Sep 2011 19:58:01 +0000</pubDate>
		<dc:creator>Jared</dc:creator>
				<category><![CDATA[General Goodness]]></category>

		<guid isPermaLink="false">http://thirddefense.wordpress.com/?p=654</guid>
		<description><![CDATA[Quick post to share a podcast on how to make awareness programs make a difference. Many thanks to Michael Santarcangelo, the Security Catalyst, for letting me join in. It&#8217;s good to see there&#8217;s room for a process junkie when great practitioners get together. It was also nice to meet the Focus folks who run a [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thirddefense.wordpress.com&amp;blog=12584692&amp;post=654&amp;subd=thirddefense&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Quick post to share a podcast on how to make awareness programs make a difference. Many thanks to Michael Santarcangelo, the <a title="Security Catalyst" href="www.securitycatalyst.com">Security Catalyst</a>, for letting me join in. It&#8217;s good to see there&#8217;s room for a process junkie when great practitioners get together. It was also nice to meet the Focus folks who run a well oiled shop. You can find the podcast <a title="Security Awareness" href="http://www.focus.com/roundtables/security-awareness-roundtable-security-awareness-month-trans/" target="_blank">here</a>. All feedback welcome!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thirddefense.wordpress.com/654/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thirddefense.wordpress.com/654/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/thirddefense.wordpress.com/654/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/thirddefense.wordpress.com/654/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/thirddefense.wordpress.com/654/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/thirddefense.wordpress.com/654/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/thirddefense.wordpress.com/654/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/thirddefense.wordpress.com/654/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/thirddefense.wordpress.com/654/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/thirddefense.wordpress.com/654/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/thirddefense.wordpress.com/654/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/thirddefense.wordpress.com/654/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/thirddefense.wordpress.com/654/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/thirddefense.wordpress.com/654/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thirddefense.wordpress.com&amp;blog=12584692&amp;post=654&amp;subd=thirddefense&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thirddefense.wordpress.com/2011/09/29/podcast-hanging-with-santarcangelo-et-al-to-transform-awareness/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3cea42c20c909a1af57059f8bcd42ce2?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Jared</media:title>
		</media:content>
	</item>
		<item>
		<title>Can metrics save money on PCI compliance?</title>
		<link>http://thirddefense.wordpress.com/2011/09/29/can-metrics-save-money-on-pci-compliance/</link>
		<comments>http://thirddefense.wordpress.com/2011/09/29/can-metrics-save-money-on-pci-compliance/#comments</comments>
		<pubDate>Thu, 29 Sep 2011 08:15:27 +0000</pubDate>
		<dc:creator>Jared</dc:creator>
				<category><![CDATA[General Goodness]]></category>
		<category><![CDATA[Metrics]]></category>

		<guid isPermaLink="false">http://thirddefense.wordpress.com/?p=633</guid>
		<description><![CDATA[I continue to be impressed by the VZ team. Their latest PCI Compliance Report continues their contribution of data sharing with the industry. Here are a couple cherry picked passages from the exec sum: &#8220;Essentially unchanged from last year, only 21 percent of organizations were fully compliant at the time of their Initial Report on [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thirddefense.wordpress.com&amp;blog=12584692&amp;post=633&amp;subd=thirddefense&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I continue to be impressed by the VZ team. Their latest <a title="verizon pci compliance report" href="http://www.verizonbusiness.com/resources/reports/rp_2011-payment-card-industry-compliance-report_en_xg.pdf" target="_blank">PCI Compliance Report</a> continues their contribution of data sharing with the industry. Here are a couple cherry picked passages from the exec sum:</p>
<p>&#8220;Essentially unchanged from last year, only 21 percent of<br />
organizations were fully compliant at the time of their Initial<br />
Report on Compliance (IROC). This is interesting, since most<br />
were validated to be in compliance during their prior assessment.<br />
What causes this erosion over the course of the year?&#8221;</p>
<p>&#8230;.</p>
<p>Organizations struggled most with the following PCI<br />
requirements: 3 (protect stored cardholder data), 10 (track and<br />
monitor access), 11 (regularly test systems and processes), and<br />
12 (maintain security policies).&#8221;</p>
<p>Here&#8217;s another passage that surprises no one, from pg. 29:</p>
<p>&#8220;the secret to maintaining compliance lies largely in treating it as a daily part of conducting business. To achieve this, the correct mind-set must be instilled across the organization, and this type of integration must come from the top down.&#8221;</p>
<p>I may be projecting but while I read the report, I kept visualizing the ops and security teams scrambling between the initial and final assessments to hurry up and get compliant. Given the data above, deep down they knew they&#8217;ll be doing the same thing next year. This got me wondering: how much time, money, and opportunity cost is spent scrambling to get compliant? How can we reduce this cost?</p>
<p>Here&#8217;s a hypothesis:<strong> the cost of running a compliant shop is less than the cost to run annual fire drills. </strong>Boy I&#8217;d love to test this hypothesis. This also fits into my favorite question about metrics: is control effectiveness increased simply by the fact it&#8217;s being measured? Mind you I&#8217;m talking about measuring, not auditing. This PCI report clearly shows audits don&#8217;t improve controls throughout the year. What if we applied metrics to key operating controls under the PCI scope? Would a minor investment in spinning up a metrics program be less than the annual effort to get compliant? Is the cost of maintaining a control less than the cost of scrambling to fix it?</p>
<p>I took the liberty to identify a candidate set of metrics that may help answer these questions. I ran through the requirements and selected 23 metrics. I don&#8217;t think we need a metric for every requirement. My goal was to identify metrics that provide visibility to a group of controls. E.g. % of users with completed role verification per some schedule. This metric may knock off multiple requirements e.g. least privilege, segregation of duties, terminations, vendor, and remote access. I also focused on the operational controls vs. design decisions e.g. metrics aren&#8217;t a fit to measure your encryption design.</p>
<p>Here are the 23 (feel free to scroll down and read them later if you want more monologue):</p>
<table border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="top" width="145">Metric Title</td>
<td valign="top" width="138">Category</td>
<td valign="top" width="312">Description</td>
</tr>
<tr>
<td valign="top" width="145">Post-prod. Vulns.</td>
<td valign="top" width="138">Application</td>
<td valign="top" width="312"># Post-production applications vulnerabilities Target: 0 Support PCI requirement 6.5.</td>
</tr>
<tr>
<td valign="top" width="145">Secure Development</td>
<td valign="top" width="138">Application</td>
<td valign="top" width="312">% of in scope application development projects that follow secure development practices. Focus on PCI requirement 6.3 and 6.5.</td>
</tr>
<tr>
<td valign="top" width="145">Change Control Security</td>
<td valign="top" width="138">Change Control</td>
<td valign="top" width="312">Number of changes that reduce or violate security policy. Focus on PCI requirement 6.4.</td>
</tr>
<tr>
<td valign="top" width="145">Production Access</td>
<td valign="top" width="138">Change Control</td>
<td valign="top" width="312">Number of non-operations personnel with access to production systems. Focus on developer access to address PCI 6.4.</td>
</tr>
<tr>
<td valign="top" width="145">PCI Servers</td>
<td valign="top" width="138">Data</td>
<td valign="top" width="312">Number of actual in scope servers holding PCI data compared to known target number. Goal is to set a target and verify at &lt;regular intervals&gt;.</td>
</tr>
<tr>
<td valign="top" width="145">Retention</td>
<td valign="top" width="138">Data</td>
<td valign="top" width="312">Number of in scope records past data retention policy. Frequency: quarterly Target: 0</td>
</tr>
<tr>
<td valign="top" width="145">Device Management</td>
<td valign="top" width="138">Device</td>
<td valign="top" width="312">% of devices managed per PCI requirements. Scanners and/or configuration management agents are good sources to produce this metric. e.g. 1.4 Install personal firewall software on any mobile and/or employee-owned computers 2.2 Develop configuration standards for all system components. 5.1 Antivirus use and management.</td>
</tr>
<tr>
<td valign="top" width="145">Device Vulns</td>
<td valign="top" width="138">Device</td>
<td valign="top" width="312">Number of unaccepted patch &amp; config vulnerabilities beyond predetermined time frames e.g. sev 5 within 30 days. target: 0 source: scanner frequency: as frequent as feasible for your org. prerequisites: policy stating patch SLA in days per vuln severity level, identified asset group by business importance. Focus on PCI requirements 6.1, 6.2, 11.2.</td>
</tr>
<tr>
<td valign="top" width="145">Intrusion Detection</td>
<td valign="top" width="138">Device</td>
<td valign="top" width="312">% of in scope system traffic monitored by IDS/IPS on a &lt;quarterly&gt; basis. target: 100% Focus on PCI requirement 11.4.</td>
</tr>
<tr>
<td valign="top" width="145">Integrity Monitoring</td>
<td valign="top" width="138">Device</td>
<td valign="top" width="312">% of in scope systems with file integrity monitoring on a &lt;quarterly&gt; basis. target: 100% Focus on PCI requirement 11.5.</td>
</tr>
<tr>
<td valign="top" width="145">Firewall Review</td>
<td valign="top" width="138">Firewall</td>
<td valign="top" width="312">% of firewall and router rule sets reviewed &lt;at least every 6 months&gt; target: 100% Supports PCI requirement 1.1 &#8220;review firewall and router rule sets at least every six months.&#8221;</td>
</tr>
<tr>
<td valign="top" width="145">Default Credentials</td>
<td valign="top" width="138">IAM</td>
<td valign="top" width="312"># servers/infrastructure devices with default credentails target: 0 source: scanner, manual A&amp;P frequency: &lt;depends on org e.g. quarterly&gt; Focus on PCI requirement 8.</td>
</tr>
<tr>
<td valign="top" width="145">Terminations</td>
<td valign="top" width="138">IAM</td>
<td valign="top" width="312"># of Employee terminations outside predetermined time frames Target: 0 Focus on PCI requirement 7.</td>
</tr>
<tr>
<td valign="top" width="145">Role Verification</td>
<td valign="top" width="138">IAM</td>
<td valign="top" width="312">% of users with completed role verification per schedule target: 100% source: manual or automated frequency: semi-annual Focus on PCI requirement 7.</td>
</tr>
<tr>
<td valign="top" width="145">Credential Strength</td>
<td valign="top" width="138">IAM</td>
<td valign="top" width="312">% servers/infrastructure devices with 2-factor or password complexity reqs target: 100% source: config review, manual A&amp;P frequency: semi-annual Focus on PCI requirement 8.</td>
</tr>
<tr>
<td valign="top" width="145">Incident Response</td>
<td valign="top" width="138">Incident Response</td>
<td valign="top" width="312">Number of incidents not handled in accordance to documented incident response procedures. target: 0 Focus on PCI requirement 12.5 and 12.9.</td>
</tr>
<tr>
<td valign="top" width="145">System Monitoring</td>
<td valign="top" width="138">Monitoring</td>
<td valign="top" width="312">% of in scope systems monitored per PCI requirements. target: 100%</td>
</tr>
<tr>
<td valign="top" width="145">Unauthorized WLAN</td>
<td valign="top" width="138">Monitoring</td>
<td valign="top" width="312">Number of unauthorized WLANs identified on a quarterly basis. target: 0 Focus on PCI requirement 11.1.</td>
</tr>
<tr>
<td valign="top" width="145">Visitor Badge Return</td>
<td valign="top" width="138">Physical Security</td>
<td valign="top" width="312">Percentage of visitor badges returned per &lt;time period&gt;. Focus on PCI requirement 9. The goal is to identify an inexpensive metric that provides some attention to physical access. The assumption is measurement in one area will increase the effectiveness of others.</td>
</tr>
<tr>
<td valign="top" width="145">Policy Review</td>
<td valign="top" width="138">Policy</td>
<td valign="top" width="312">% policies reviewed on an &lt;annual basis&gt;. Focus on PCI requirement 12.1.</td>
</tr>
<tr>
<td valign="top" width="145">Closed Risk Dispositions</td>
<td valign="top" width="138">Risk Assessment</td>
<td valign="top" width="312">Number of risks identified during the annual assessment without a risk owner and disposition e.g. accept, mitigate, transfer. target: 0 Focus on PCI requirement 12.2.</td>
</tr>
<tr>
<td valign="top" width="145">Vendor Remediation</td>
<td valign="top" width="138">Vendor</td>
<td valign="top" width="312"># of vendor security findings that have not been addressed within committed time frames. Helps support PCI 2.4 Shared hosting providers must protect each entity’s hosted environment and cardholder data.</td>
</tr>
<tr>
<td valign="top" width="145">Vendor Assessments</td>
<td valign="top" width="138">Vendor</td>
<td valign="top" width="312">Percent of vendors who receive security assessments within policy e.g. vendors with sensitive data/services must be reviewed semi-annually. Helps support PCI 2.4 and 12.8. Shared hosting providers must protect each entity’s hosted environment and cardholder data.</td>
</tr>
</tbody>
</table>
<ul>
<li>An interesting observation is that our MoneySec list of metrics only contains 15. Recall the MoneyBall inspired list of metrics is a candidate list to identify key controls that correlate with reducing incidents. If all our hypotheses were correct, we could show that compliance focuses on too many things that don&#8217;t matter (but that&#8217;s another post).</li>
</ul>
<p>I fully understand you&#8217;re not going to spin up a metrics program for all 23 without some demonstration of value. So I propose you start with one metric, my favorite, that covers many PCI requirements: number of scanner-sourced vulnerabilities past due. This is a great metric because it requires:</p>
<ul>
<li>you regularly scan</li>
<li>have a process to rank vulnerabilities</li>
<li>have a pre-negotiated service level in days to fix vulns based on severity level</li>
<li>have the ability to age vulnerabilities</li>
</ul>
<p>This metric knocks off all kinds of PCI reqs e.g. conducting scans, mitigating vulns, default creds, patches, config vulns, everything a scanner catches that&#8217;s listed in PCI.</p>
<p>Here&#8217;s an example using our Vuln Tracker tool to age vulns from popular scanners. Note you can use other tools or a spreadsheet (as Brian Keefer demonstrated in our MoneySec presentation).</p>
<div class="mceTemp mceIEcenter">
<dl class="wp-caption aligncenter">
<dt class="wp-caption-dt"><a href="http://thirddefense.files.wordpress.com/2011/09/past_due1.png"><img class="size-full wp-image-640" title="vulnerability tracker" src="http://thirddefense.files.wordpress.com/2011/09/past_due1.png?w=630&#038;h=172" alt="vulnerability tracker" width="630" height="172" /></a></dt>
</dl>
</div>
<p>This example shows a couple hundred vulns overdue, some older than 3 months. From a metrics point of view, you could set a target value for Overdue Vulns at say 10 vulns per month. Here&#8217;s how that might look using our Metrics Manager (again, any old spreadsheet will suffice).</p>
<p><a href="http://thirddefense.files.wordpress.com/2011/09/device_vuln_ex1.png"><img class="aligncenter size-full wp-image-645" title="Device vulnerabilities" src="http://thirddefense.files.wordpress.com/2011/09/device_vuln_ex1.png?w=630&#038;h=379" alt="" width="630" height="379" /></a></p>
<p>This shows the history of mitigation performance and how well we performed to our expected target.</p>
<p>What do you think? Does the simple fact of looking at something change its behavior? In my experience, yes. So if you have the annual privilege of meeting your QSA, see if you can save your company money by maintaining compliance vs. getting compliant on an annual basis.</p>
<p>Please do provide feedback on the list of metrics above. It was just me and my pint who produced them and I&#8217;m sure they can improve!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thirddefense.wordpress.com/633/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thirddefense.wordpress.com/633/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/thirddefense.wordpress.com/633/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/thirddefense.wordpress.com/633/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/thirddefense.wordpress.com/633/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/thirddefense.wordpress.com/633/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/thirddefense.wordpress.com/633/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/thirddefense.wordpress.com/633/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/thirddefense.wordpress.com/633/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/thirddefense.wordpress.com/633/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/thirddefense.wordpress.com/633/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/thirddefense.wordpress.com/633/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/thirddefense.wordpress.com/633/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/thirddefense.wordpress.com/633/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thirddefense.wordpress.com&amp;blog=12584692&amp;post=633&amp;subd=thirddefense&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thirddefense.wordpress.com/2011/09/29/can-metrics-save-money-on-pci-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3cea42c20c909a1af57059f8bcd42ce2?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Jared</media:title>
		</media:content>

		<media:content url="http://thirddefense.files.wordpress.com/2011/09/past_due1.png" medium="image">
			<media:title type="html">vulnerability tracker</media:title>
		</media:content>

		<media:content url="http://thirddefense.files.wordpress.com/2011/09/device_vuln_ex1.png" medium="image">
			<media:title type="html">Device vulnerabilities</media:title>
		</media:content>
	</item>
		<item>
		<title>In touch with your inner consultant</title>
		<link>http://thirddefense.wordpress.com/2011/08/31/in-touch-with-your-inner-consultant/</link>
		<comments>http://thirddefense.wordpress.com/2011/08/31/in-touch-with-your-inner-consultant/#comments</comments>
		<pubDate>Thu, 01 Sep 2011 01:29:28 +0000</pubDate>
		<dc:creator>Jared</dc:creator>
				<category><![CDATA[Assessments]]></category>
		<category><![CDATA[General Goodness]]></category>
		<category><![CDATA[Risk Communicator]]></category>

		<guid isPermaLink="false">http://thirddefense.wordpress.com/?p=603</guid>
		<description><![CDATA[While helping folks build fun, cool processes like assessing risks with fancy web apps, a nagging trend emerged. Security pro&#8217;s are often overwhelmed with random requests to provide advice or approve designs to support internal projects. Some of these requests come early to support official projects e.g. we need your help designing the next ERP [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thirddefense.wordpress.com&amp;blog=12584692&amp;post=603&amp;subd=thirddefense&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>While helping folks build fun, cool processes like assessing risks with fancy web apps, a nagging trend emerged. Security pro&#8217;s are often overwhelmed with random requests to provide advice or approve designs to support internal projects. Some of these requests come early to support official projects e.g. we need your help designing the next ERP implementation. However most are ad hoc, random, and disrupt an already over-crowded work week. Or worse yet, the security team isn&#8217;t engaged until the day before go-live! How can under resourced security pro&#8217;s get in front of all this?</p>
<p>Simple. No free lunch.</p>
<p>Internal consulting, project support, business enablement, whatever you want to call it, is a service. This service should be recognized, advertised, resourced, and measured. At one point in my history, we put engagements into time buckets e.g. &lt; 4 hours, &lt; 1 week, 1-3 weeks. Each security pro then had a certain % of their time assigned to internal consulting. When they became overwhelmed, it was their job to escalate to me. We had a published process to assign, gauge, and prioritize the work effort. During a time of layoffs and cost cutting, we actually justified and earned another FTE because we could show the demand and value. I said we either start saying &#8220;we&#8217;ll have to get to you in xx days&#8221; or we need more quality folks. Magic.</p>
<p>Lots of anecdotes to share but I&#8217;ll spare you. I will leave you with some of the tools we used to formalize the process. Mind you, not everyone on the team supported this formality. Some folks liked being the Go-To-Guy. They didn&#8217;t appreciate having to say, &#8220;I&#8217;d love to help you directly but we have a standard way to serve you, please visit &lt;portal url&gt; and enter your request. We&#8217;ll get back to you within 1 day.&#8221; The magic happened when the go-to folks were totally swamped. They got to remain focused and the business was served.</p>
<p>In a bit of self-promotion, we recently added a template in <a title="risk communicator" href="http://thirddefense.com/rc.html" target="_blank">Risk Communicator</a> to support general consulting requests. This template is a bit different because it contains a set of questions to identify risks, similar to control based templates like PCI. The goal is to provide a consistent set of questions enabling assessors to quickly understand the solution and key control requirements. Once you define a well formed risk statement (impact and likelihood evidence), you have the option of completing the workflow to help the business improve their decisions where to spend.</p>
<p>This approach isn&#8217;t a substitute for a comprehensive assessment, it&#8217;s a quick hit and can/should be customized. Here are the base questions in the Risk Communicator template: (apologies but I can&#8217;t convince wordpress to get the table in html, here&#8217;s the pdf)</p>
<p><a href="http://thirddefense.files.wordpress.com/2011/08/basic_questions.pdf">basic_questions</a></p>
<p>Of course having a slick risk assessment application pales in comparison to a well defined process. Here are a few generic deliverables to get you started:</p>
<p><a href="http://thirddefense.files.wordpress.com/2011/08/project_support_thots.pdf">Project Support Overview Slide</a></p>
<p><a href="http://thirddefense.files.wordpress.com/2011/08/project_swim.pdf">Project Support Workflow</a></p>
<p><a href="http://thirddefense.files.wordpress.com/2011/08/simple_raci.pdf">Simple RACI for Project Support roles</a></p>
<p>Some of these may be too basic or even complex for your group. Recall that one person may play multiple roles.</p>
<p>Few more notes:</p>
<ul>
<li>A great way to get started is to simply formalize how the security team is engaged. An internal portal is best e.g. custom sharepoint site, but a shared mailbox will do at the start.</li>
<li>Be sure to enforce the process. Ignoring the engagement point defeats the purpose.</li>
<li>Get exec support and market your service. The engagement point, process, and key SME&#8217;s should be advertised like rock stars.</li>
<li>Project support should be recognized in the list of services your team provides, whether or not you have a fancy service catalog.</li>
<li>Metrics: how about</li>
</ul>
<blockquote>
<ul>
<li>% requests served within SLA</li>
<li># of requests +/- predicted per quarter e.g. we anticipated 30 but received 60!</li>
</ul>
</blockquote>
<ul>
<li>Get credit. Internal consulting should be included in your perf goals and review. cha-ching.</li>
</ul>
<p>The ultimate goal is to serve the organization while enjoying your job.</p>
<p>I hope you find these useful. Please contact me or leave a comment with feedback or questions.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thirddefense.wordpress.com/603/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thirddefense.wordpress.com/603/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/thirddefense.wordpress.com/603/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/thirddefense.wordpress.com/603/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/thirddefense.wordpress.com/603/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/thirddefense.wordpress.com/603/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/thirddefense.wordpress.com/603/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/thirddefense.wordpress.com/603/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/thirddefense.wordpress.com/603/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/thirddefense.wordpress.com/603/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/thirddefense.wordpress.com/603/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/thirddefense.wordpress.com/603/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/thirddefense.wordpress.com/603/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/thirddefense.wordpress.com/603/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thirddefense.wordpress.com&amp;blog=12584692&amp;post=603&amp;subd=thirddefense&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thirddefense.wordpress.com/2011/08/31/in-touch-with-your-inner-consultant/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3cea42c20c909a1af57059f8bcd42ce2?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Jared</media:title>
		</media:content>
	</item>
		<item>
		<title>How Old Is That Vuln?</title>
		<link>http://thirddefense.wordpress.com/2011/07/27/how-old-is-that-vuln/</link>
		<comments>http://thirddefense.wordpress.com/2011/07/27/how-old-is-that-vuln/#comments</comments>
		<pubDate>Thu, 28 Jul 2011 00:54:29 +0000</pubDate>
		<dc:creator>Jared</dc:creator>
				<category><![CDATA[Assessments]]></category>
		<category><![CDATA[General Goodness]]></category>

		<guid isPermaLink="false">http://thirddefense.wordpress.com/?p=590</guid>
		<description><![CDATA[I root for vuln scanners to succeed (no pun intended).  Back in the day scanners helped automate a laborious task and they&#8217;ve continued to improve their products. However their fight in the marketplace is far from over. While vuln scanners own the vulnerability assessment market, for some reason they never quite finished delivering on vulnerability [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thirddefense.wordpress.com&amp;blog=12584692&amp;post=590&amp;subd=thirddefense&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I root for vuln scanners to succeed (no pun intended).  Back in the day scanners helped automate a laborious task and they&#8217;ve continued to improve their products. However their fight in the marketplace is far from over. While vuln scanners own the vulnerability assessment market, for some reason they never quite finished delivering on vulnerability <em>management</em> i.e.  ensure unacceptable vulns are remediated per policy.</p>
<p>Today we&#8217;re seeing GRC and other vendors consume vuln scans like they&#8217;re commodity pork bellies.  They add on some workflow, connectors, reporting, and presto, you have the technology capable of supporting a great assessment service (almost as good as bacon).</p>
<p>This post has two purposes. One is to wax all nostalgic on how much I love vuln scanners. The other is to help explain why Third Defense just released a reporting extension on top of them. No, we are not providing all the workflow like the GRC crowd. We&#8217;re simply responding to a customer request who asked if we could help them out. Since I&#8217;ve been asking vuln scan vendors to produce this report for years, I said YES.</p>
<p>The report is simply to show vulnerability age compared to policy. It&#8217;s easy to age a vulnerability on specific hosts across scans. It&#8217;s also incredibly powerful for a security team to report on overdue vulns per asset group. The goal is to increase accountability and drive risk acceptance|mitigation decisions across business owners. Odds are you already have pre-negotiated mitigation time frames per sev level with the Ops group. Some folks include these time frames in policy. Others yet call them Service Level Agreements.</p>
<p>Either way, you now have an easy way to show vuln age. Here are the steps:</p>
<ol>
<li>Paste your existing asset group names, owners, and IP ranges into the Vuln Tracker app</li>
<li>Assign a remediation date per group and sev level</li>
<li>Upload scans</li>
</ol>
<p>The result is a simple histogram that can show:</p>
<ul>
<li>Age of all vulns across all groups</li>
<li>All Overdue vulns</li>
<li>Vuln age per group</li>
<li>Overdue vulns per group</li>
</ul>
<p>Here&#8217;s a screen snip (click to expand):</p>
<p><a href="http://thirddefense.files.wordpress.com/2011/07/vulntracker.png"><img class="aligncenter size-full wp-image-592" title="Vulnerability Tracker " src="http://thirddefense.files.wordpress.com/2011/07/vulntracker.png?w=630&#038;h=243" alt="example" width="630" height="243" /></a></p>
<p>I fully expect vuln scan vendors to add in this report someday. It would be cool if we helped hasten the process. Until then, I encourage you to try out this report. The increased visibility into remediation performance works wonders. In my experience, maturing the vuln mngt process is the easiest across all of security. It&#8217;s rewarding to sit down with ops every month and translate vuln definitions into risk statements for your business. Take the next step and verify the appropriate remediation occurs.</p>
<p>As always, we welcome your feedback, even if it&#8217;s to remind us that we&#8217;re crazy to add a feature like this :)</p>
<p>Quick note: out of the gate we only support nessus. Let us know if you&#8217;d like to see more.</p>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thirddefense.wordpress.com/590/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thirddefense.wordpress.com/590/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/thirddefense.wordpress.com/590/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/thirddefense.wordpress.com/590/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/thirddefense.wordpress.com/590/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/thirddefense.wordpress.com/590/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/thirddefense.wordpress.com/590/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/thirddefense.wordpress.com/590/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/thirddefense.wordpress.com/590/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/thirddefense.wordpress.com/590/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/thirddefense.wordpress.com/590/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/thirddefense.wordpress.com/590/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/thirddefense.wordpress.com/590/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/thirddefense.wordpress.com/590/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thirddefense.wordpress.com&amp;blog=12584692&amp;post=590&amp;subd=thirddefense&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thirddefense.wordpress.com/2011/07/27/how-old-is-that-vuln/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3cea42c20c909a1af57059f8bcd42ce2?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Jared</media:title>
		</media:content>

		<media:content url="http://thirddefense.files.wordpress.com/2011/07/vulntracker.png" medium="image">
			<media:title type="html">Vulnerability Tracker </media:title>
		</media:content>
	</item>
		<item>
		<title>Will The Public Sector Show Us How It&#8217;s Done?</title>
		<link>http://thirddefense.wordpress.com/2011/06/21/will-the-public-sector-show-us-how-its-done/</link>
		<comments>http://thirddefense.wordpress.com/2011/06/21/will-the-public-sector-show-us-how-its-done/#comments</comments>
		<pubDate>Tue, 21 Jun 2011 19:35:03 +0000</pubDate>
		<dc:creator>Jared</dc:creator>
				<category><![CDATA[General Goodness]]></category>

		<guid isPermaLink="false">http://thirddefense.wordpress.com/?p=583</guid>
		<description><![CDATA[I&#8217;m still forming the thought here and want to get some feedback. I pose this question not because I think the public sector is better than private at managing risk. I pose it because it&#8217;s easier (sometimes mandated) that the public sector share data with the taxpayers. Which industry is going to step forward and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thirddefense.wordpress.com&amp;blog=12584692&amp;post=583&amp;subd=thirddefense&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m still forming the thought here and want to get some feedback. I pose this question not because I think the public sector is better than private at managing risk. I pose it because it&#8217;s easier (sometimes mandated) that the public sector share data with the taxpayers. Which industry is going to step forward and start sharing examples of risk program structure, tools, deliverables, metrics, etc?</p>
<p>Thanks to Justin Somaini for his pointer to the <a href="http://www.somaini.net/justins-journal/2011/6/20/the-grace-of-risk-managment.html">University of CA ERM program</a>. Yesterday I had Grace Cricket&#8217;s <a href="http://www.ucop.edu/riskmgt/documents/2010-1011-sp-webinar/lib/playback.html" target="_blank">webinar </a>on ERM running in the background. When something caught my ear, I&#8217;d check it out on UC&#8217;s fantastic <a>Resources </a>site. Below are some notes I jotted down. <strong>Huge disclaimer</strong>: I didn&#8217;t take the time to listen to everything or view all the resources. The purpose of the this post and these notes are to incite interest and Thank Grace and co for sharing!</p>
<p><em>Begin rough notes and soundbites:</em></p>
<p>&#8220;How do you know if you&#8217;re doing well?&#8221; Develop KPI&#8217;s, find the data. Instead of asking (stakeholders) what keeps them up at night. Ask them how they measure success. (me: Brilliant!). In the past, data was ad hoc and manual, not repeatable. Need technology to manage information. Selected IBM to develop solution.</p>
<p>- Developed ERM maturity model. Use S&amp;P rating methodology.</p>
<p>- Retrospective reviews of impacts &gt; $50k. (me: great source of evidence)</p>
<p>- ERM is basically a COE to cross pillars of risk management.</p>
<p>- developed an ERMIS: single portal, organizes information for monitoring performance.</p>
<p>- Developed Risk Assessment <a href="http://www.ucop.edu/riskmgt/erm/risk_assessment.html" target="_blank">workbooks</a>. (me: these are simple but a great starting point. I fully expect their use isn&#8217;t consistent, not always data driven, subject to politics, etc. but it&#8217;s a start for them)</p>
<p>- Probably could have spend a lot of money on fancy tools but folks are able to use simple tools, empower them to use something familiar e.g. xls</p>
<p>- combination of pull surveys vs. push assessments (me: the xls workbooks). complement by ERM maturity rating e.g. rims.org? 107 ERM activities across 5 categories. Self rate cmm like scale to rate ERM program itself.</p>
<p>- question from audience: what&#8217;s the motivation to start: 1. need an overall champion e.g. CRO. 2. need for a unified response to catastrophic incidents</p>
<p>- (52 mins in) ERM tracking: identified ~40 Ent. Risks across broad categories e.g. the one IT risk entry: Title &#8220;Decentralization of systems leading to data inconsistencies and fragmentation.<br />
Mitigation: Senior leadership has recently put in place storage contols in this area;<br />
Development and Maintenance Standards and (hard to hear?) local policies.<br />
Data, Monitoring &amp; Reporting: Reported at local level; Programing quality assurance and testing: approvals by programming managers and users before moving new systems or changes to production.</p>
<p>- advice: identify lowest hanging fruit, iterate</p>
<p>- about 700 KPI&#8217;s across ERM (me: I assume across the whole UC ecosystem)</p>
<p>- Risk Appetite: to begin, just show performance against average of institutions across UC system e.g. yellow is 5% of average.</p>
<p>- question from audience: Do you charge each institution for ERM services?  No, funded centrally.</p>
<p>- Can ERM quantify it&#8217;s benefit e.g. &#8220;elminimated cost of claims system @ $4M, ERM costs 2.5M/year. Improved credit rating.</p>
<p>- 1:08 in: First big win was workers comp. &#8220;cost of risk for fy09/10 reduced from $18.46 to $14.76&#8243; ??</p>
<p>- first win was leveraging individual risk assessment tools. Next win will probably be to leverage the portal roll-up.</p>
<p>- How is CRO perceived e.g. auditors? Depends. Use qualitative to get past &#8220;sin factor.&#8221; Need to leverage qual and quant. Not an audit, no overlap from compliance. Focused on helping individual owners manage risk more effectively.</p>
<p>- CRO is a generalist to break down silos e.g. Financial, Safety, Compliance, IT Governance.</p>
<p><em>End rough notes and soundbites.</em></p>
<p>I don&#8217;t know if UC&#8217;s ERM program is good or bad. I do know I appreciate the insight. I also know we need more sharing. Please let me know as you come across great examples we can all learn from.</p>
<p>Thanks again Grace!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thirddefense.wordpress.com/583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thirddefense.wordpress.com/583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/thirddefense.wordpress.com/583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/thirddefense.wordpress.com/583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/thirddefense.wordpress.com/583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/thirddefense.wordpress.com/583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/thirddefense.wordpress.com/583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/thirddefense.wordpress.com/583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/thirddefense.wordpress.com/583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/thirddefense.wordpress.com/583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/thirddefense.wordpress.com/583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/thirddefense.wordpress.com/583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/thirddefense.wordpress.com/583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/thirddefense.wordpress.com/583/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thirddefense.wordpress.com&amp;blog=12584692&amp;post=583&amp;subd=thirddefense&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thirddefense.wordpress.com/2011/06/21/will-the-public-sector-show-us-how-its-done/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3cea42c20c909a1af57059f8bcd42ce2?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Jared</media:title>
		</media:content>
	</item>
		<item>
		<title>Source Seattle Slides &amp; Goodness</title>
		<link>http://thirddefense.wordpress.com/2011/06/20/source-seattle-slides-goodness/</link>
		<comments>http://thirddefense.wordpress.com/2011/06/20/source-seattle-slides-goodness/#comments</comments>
		<pubDate>Mon, 20 Jun 2011 21:02:23 +0000</pubDate>
		<dc:creator>Jared</dc:creator>
				<category><![CDATA[General Goodness]]></category>
		<category><![CDATA[Magnificent 7]]></category>

		<guid isPermaLink="false">http://thirddefense.wordpress.com/?p=576</guid>
		<description><![CDATA[I had a great time meeting new folks at Source Seattle. I must admit I hadn&#8217;t heard of Source before the Source Boston event. Many folks I follow on twitter (see @JaredPfost for a list) were all a-buzz about Source Boston. I had to reach out to Stacy Thayer (@StacyThayer) and join in the fun. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thirddefense.wordpress.com&amp;blog=12584692&amp;post=576&amp;subd=thirddefense&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I had a great time meeting new folks at <a title="source seattle" href="http://www.sourceconference.com/seattle/" target="_blank">Source Seattle</a>. I must admit I hadn&#8217;t heard of Source before the Source Boston event. Many folks I follow on twitter (see @JaredPfost for a list) were all a-buzz about Source Boston. I had to reach out to Stacy Thayer (@StacyThayer) and join in the fun. I&#8217;m glad I did and look forward to helping Stacy and co. promote Source in the future. Boston may have success with professional sports but Seattle has better beer. If that&#8217;s not the foundation to develop the best security conference, I don&#8217;t know what is&#8230;</p>
<p>Anyway, here&#8217;s the official slideshare <a href="http://www.slideshare.net/SOURCEConference/how-much-security" target="_blank">link </a>to my session on How To Find The Right Amount of Security Spend.</p>
<p>Update: 30 min video <a title="here" href="http://blip.tv/sourceseattle2011/jared-pfost-how-to-find-the-right-amount-of-security-spend-5426992" target="_blank">here</a>.</p>
<p>Here are the slides in .pdf:  <a href="http://thirddefense.files.wordpress.com/2011/06/how_much_security.pdf">How_Much_Security</a>. Let me know if you&#8217;d like the source ppt slides (do you feel less comfortable downloading a .pdf or .ppt :).</p>
<p>Aside: one of my favorite talks was from Myles Conley http://www.sourceconference.com/seattle/speakers_2011.asp#mconley</p>
<p>Keep on the lookout for his slides when they&#8217;re available. Myles did an excellent job analyzing breach data to emphasize what roles infosec organizations really need i.e. web app dev&#8217;s may be cool but perhaps project managers may be more useful&#8230;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thirddefense.wordpress.com/576/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thirddefense.wordpress.com/576/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/thirddefense.wordpress.com/576/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/thirddefense.wordpress.com/576/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/thirddefense.wordpress.com/576/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/thirddefense.wordpress.com/576/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/thirddefense.wordpress.com/576/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/thirddefense.wordpress.com/576/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/thirddefense.wordpress.com/576/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/thirddefense.wordpress.com/576/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/thirddefense.wordpress.com/576/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/thirddefense.wordpress.com/576/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/thirddefense.wordpress.com/576/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/thirddefense.wordpress.com/576/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thirddefense.wordpress.com&amp;blog=12584692&amp;post=576&amp;subd=thirddefense&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thirddefense.wordpress.com/2011/06/20/source-seattle-slides-goodness/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3cea42c20c909a1af57059f8bcd42ce2?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Jared</media:title>
		</media:content>
	</item>
		<item>
		<title>Metrics Rule!</title>
		<link>http://thirddefense.wordpress.com/2011/05/17/metrics-rule/</link>
		<comments>http://thirddefense.wordpress.com/2011/05/17/metrics-rule/#comments</comments>
		<pubDate>Wed, 18 May 2011 00:26:38 +0000</pubDate>
		<dc:creator>Jared</dc:creator>
				<category><![CDATA[Assessments]]></category>
		<category><![CDATA[General Goodness]]></category>
		<category><![CDATA[Magnificent 7]]></category>

		<guid isPermaLink="false">http://thirddefense.wordpress.com/?p=563</guid>
		<description><![CDATA[I&#8217;ve written a lot about metrics, starting with their role and value in the Magnificent 7 series. I recently provided additional context in the Security Spending post. I&#8217;ll continue focusing on metrics until they become mainstream or I fall on my sword. I think they&#8217;re that important and if I took a CISO job tomorrow, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thirddefense.wordpress.com&amp;blog=12584692&amp;post=563&amp;subd=thirddefense&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve written a lot about metrics, starting with their role and value in the <a title="security metrics" href="https://thirddefense.wordpress.com/2010/04/02/magnificent-77-metrics-and-scorecards/" target="_blank">Magnificent 7 series</a>. I recently provided additional context in the <a title="security spending" href="https://thirddefense.wordpress.com/2011/04/20/how-much-should-we-spend-on-security/" target="_blank">Security Spending post.</a> I&#8217;ll continue focusing on metrics until they become mainstream or I fall on my sword. I think they&#8217;re that important and if I took a CISO job tomorrow, evaluating the state of metrics would be one of my top three tasks. This post is inspired by email threads I had last week with a couple true security leaders who wanted to compare notes. I was also inspired by a great article from <a title="spire security" href="http://spiresecurity.com/" target="_blank">Pete Lindstrom</a> on <a title="strategic security metric framework" href="http://www.csoonline.com/article/print/682043" target="_blank">Building Out Your Strategic Security Metric Framework</a>. It&#8217;s a great article but I want to make sure folks consider a couple additions.</p>
<p>The first is to recognize the resistance when building or expanding a metrics program. I haven&#8217;t heard anyone say they don&#8217;t want to measure. What I do hear is they don&#8217;t have enough time. Taking time away from business as usual and committed initiatives is tough so executive support is required. Do your executives really want to understand acceptable risk and efficiencies or not? If so, read more.</p>
<p>The second is the simple tactic of requiring each metric to have a target value. These targets define what &#8220;acceptable&#8221; means to asset and control owners. Targets are also a good forcing function to make sure a metric passes the &#8220;so what&#8221; test. Defining target values also normalizes % and integer based metrics. Stakeholders don&#8217;t have to understand every detail but they can quickly see if performance is above/below a committed level.</p>
<p>Now back to the inspiration for this post. Below is a list of metrics derived from a couple IT shops of my past and what I&#8217;ve seen/heard across my journey. You&#8217;ve seen me organize metrics by IT services and technical domains. This snapshot leverages the questions to define security investment: are we operating at acceptable risk, and are we as efficient a possible. I like this more business-friendly structure and for the true crazy elite, it aligns nicely into a <a title="IT security balanced scorecard" href="http://thirddefense.wordpress.com/2010/01/31/magnificent-27-balanced-scorecard/" target="_blank">balanced scorecard</a>. Obviously I can&#8217;t include target values for you but please make sure you do.</p>
<p><strong>Are we operating at acceptable risk?</strong></p>
<p>Applications</p>
<ul>
<li>% internal projects using SDL</li>
<li>% external projects with SDL in contract</li>
<li># pre-production (final security review) sev 1 security bugs</li>
<li># post-prod bugs for new/updated apps</li>
<li># security bugs identified in production application assessments</li>
<li>% SDLC staff trained</li>
</ul>
<p>Data</p>
<ul>
<li>% of PII encrypted/obfuscated per policy</li>
<li># of PII policy violations identified with DLP</li>
</ul>
<p>IAM</p>
<ul>
<li>% time to complete User Access Reviews</li>
<li>% of administrator accounts validated per policy cycle e.g. quarterly</li>
<li>% user accounts managed through automation (or central directory)</li>
<li>% of employees and non-employee workers with baseline access profiles</li>
<li>% accounts deprovisioned per SLA</li>
</ul>
<p>Vendor</p>
<ul>
<li>% critical vendors e.g. with PII, assessed per policy</li>
<li># of outstanding vendor risks</li>
</ul>
<p>Device (aka scanners are your friend)</p>
<ul>
<li>% workstations/laptops outside patch SLA (e.g. critical 7 days, important 30 days, maintenance 90 days)</li>
<li>% workstations/laptops with vulns outside SLA</li>
<li>% workstations and laptops Managed for Security where “managed” is a bundle of healthy agents e.g. AV, HIDS.</li>
<li>same as above for servers</li>
<li>%  accuracy of cmdb vs network enumeration (scan)</li>
</ul>
<p>Network</p>
<ul>
<li># Network attached devices with vulns outside SLA</li>
<li>% Accuracy of inventory (scan enumeration vs. cmdb)</li>
</ul>
<p>Security Monitoring</p>
<ul>
<li>% network monitored per policy</li>
<li>% servers monitored for security (may add a separate item for DB&#8217;s)</li>
<li>% security tickets resolved within SLA</li>
</ul>
<p>Incident</p>
<ul>
<li># of critical incidents</li>
<li># of moderate incidents</li>
<li>% incidents managed per SLA (identification, declaration, QFE, root cause, resolution)</li>
</ul>
<p>People</p>
<ul>
<li>% staff trained per policy</li>
<li>-Include outreach programs as appropriate e.g. cross-crash team meetings, brown bags, newsletters, sponsored socials, etc.</li>
<li>Might be cool to break out social engineering incidents separately?</li>
<li># compliments showered on security team (wouldn&#8217;t that be nice)</li>
</ul>
<p><strong>Are we as efficient as possible?</strong></p>
<p>Security Team Improvement</p>
<ul>
<li>% security tools and deployment rationalized (gauge of architecture discipline and utilization)</li>
<li># of security innovation ideas transformed into action (to encourage team participation) (yes, set a target value here too)</li>
</ul>
<p>Security Program</p>
<ul>
<li>% Infosec spend aligned to strategy (which is/should be aligned to biz strategy)</li>
<li>% security processes documented with assigned SLA&#8217;s (documented means RACI, swimlane, even SIPOC for all you nerds)</li>
<li>% of key security processes with completed FMEA (failure mode exception analysis i.e. how can/do we break)</li>
<li>% security initiatives completed on time</li>
<li>% security initiatives completed on budget</li>
</ul>
<p>Business Engagement</p>
<ul>
<li>% Line of Business security assessments completed on schedule e.g. semi-annual (aligned to budget cycle)</li>
<li>% risks identified without status resolution (accepted, mitigated, mitigating). This focuses on risks identified during assessments and consulting e.g. evaluating cloud services, authentication requirements, etc.</li>
<li>% consulting projects complete within SLA (volume and quality of LoB and IT projects supported with internal consulting)</li>
<li>% capacity of internal consulting team (gauge supply/demand)</li>
</ul>
<p>Compliance</p>
<ul>
<li># &#8220;significant&#8221; audit findings identified</li>
<li>% accepted remediation actions completed on time</li>
<li>% audits following process (pre-scheduled, proper scope, duration)</li>
<li>security violations managed per policy aka exception duration and risk acceptance by asset owner</li>
</ul>
<p style="text-align:center;">&#8230;&#8230;&#8230;&#8230;..</p>
<p>Phew, looks like a lot of work and it is. If you really want to go crazy, create a performance roll-up for each section or the list as a whole. Target values normalize metrics so you can communicate % above/below expected progress. For perspective, it took us years working through the above and unfortunately I didn&#8217;t always get to see it through i.e. bank collapses :-) Plus, if your experience is like mine, your team will resist most of the above because they don&#8217;t have the time. It&#8217;s up to leadership to set the work priorities, reward improvement, dissolve heroism, and recognize the costs and benefits of metrics. In my experience, the start-up pain is well worth the reward. Not only will you have a solid foundation to measure, you&#8217;ll have a great source of evidence for your risk assessment process!</p>
<p>I encourage you to critique, add, subtract from the above. I&#8217;ll update the based on feedback and maybe crowd source this a bit. There&#8217;s no one right answer and metrics will evolve over time. Hope this was helpful!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thirddefense.wordpress.com/563/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thirddefense.wordpress.com/563/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/thirddefense.wordpress.com/563/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/thirddefense.wordpress.com/563/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/thirddefense.wordpress.com/563/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/thirddefense.wordpress.com/563/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/thirddefense.wordpress.com/563/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/thirddefense.wordpress.com/563/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/thirddefense.wordpress.com/563/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/thirddefense.wordpress.com/563/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/thirddefense.wordpress.com/563/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/thirddefense.wordpress.com/563/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/thirddefense.wordpress.com/563/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/thirddefense.wordpress.com/563/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thirddefense.wordpress.com&amp;blog=12584692&amp;post=563&amp;subd=thirddefense&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thirddefense.wordpress.com/2011/05/17/metrics-rule/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3cea42c20c909a1af57059f8bcd42ce2?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">Jared</media:title>
		</media:content>
	</item>
	</channel>
</rss>
