<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: &#8220;Security first&#8221; please!</title>
	<atom:link href="http://www.mckeay.net/2009/01/16/security-first-please/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mckeay.net/2009/01/16/security-first-please/</link>
	<description>The views of one man on security, privacy and anything else that catches his attention.  The views expressed on this blog do not reflect the views of my employer or anyone other than myself.</description>
	<lastBuildDate>Thu, 02 Feb 2012 21:45:54 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Tom</title>
		<link>http://www.mckeay.net/2009/01/16/security-first-please/comment-page-1/#comment-4154</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Wed, 28 Jan 2009 19:54:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2009/01/16/security-first-please/#comment-4154</guid>
		<description>While compliance may provide some minimum level of security, it is a pretty low bar to meet.  It may be better to measure compliance and measure security risk independent of each other.  An organization could definitely be insecure and also compliant with PCI and other regulations.  Conversely, an organization could be adequately secured and non-compliant.</description>
		<content:encoded><![CDATA[<p>While compliance may provide some minimum level of security, it is a pretty low bar to meet.  It may be better to measure compliance and measure security risk independent of each other.  An organization could definitely be insecure and also compliant with PCI and other regulations.  Conversely, an organization could be adequately secured and non-compliant.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Network Security Blog &#187; Saturday morning reading 01/24/09</title>
		<link>http://www.mckeay.net/2009/01/16/security-first-please/comment-page-1/#comment-4128</link>
		<dc:creator>Network Security Blog &#187; Saturday morning reading 01/24/09</dc:creator>
		<pubDate>Sat, 24 Jan 2009 14:35:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2009/01/16/security-first-please/#comment-4128</guid>
		<description>[...] and continuing to improve upon it, which is a step many organizations forget.&#160; Didn&#8217;t I write something on this [...]</description>
		<content:encoded><![CDATA[<p>[...] and continuing to improve upon it, which is a step many organizations forget.&nbsp; Didn&#8217;t I write something on this [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anton Chuvakin</title>
		<link>http://www.mckeay.net/2009/01/16/security-first-please/comment-page-1/#comment-4102</link>
		<dc:creator>Anton Chuvakin</dc:creator>
		<pubDate>Fri, 16 Jan 2009 18:26:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2009/01/16/security-first-please/#comment-4102</guid>
		<description>Congrats, Martin! You discovered the HIDDEN point in my post...

You say:

&quot;other than chosing a new vendor if the current one is just paying lip service to scanning.&quot;

Yes, BUT the truly SCARRRRRRRY point that I was hinting at is:

&quot;chosing a new vendor if the current one is just NOT (!!!) paying lip service to scanning.&quot;

Think about it...</description>
		<content:encoded><![CDATA[<p>Congrats, Martin! You discovered the HIDDEN point in my post&#8230;</p>
<p>You say:</p>
<p>&#8220;other than chosing a new vendor if the current one is just paying lip service to scanning.&#8221;</p>
<p>Yes, BUT the truly SCARRRRRRRY point that I was hinting at is:</p>
<p>&#8220;chosing a new vendor if the current one is just NOT (!!!) paying lip service to scanning.&#8221;</p>
<p>Think about it&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

