<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: Are low standards better than no standards?</title>
	<atom:link href="http://www.mckeay.net/2010/05/21/are-low-standards-better-than-no-standards/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mckeay.net/2010/05/21/are-low-standards-better-than-no-standards/</link>
	<description>The views of one man on security, privacy and anything else that catches his attention.  The views expressed on this blog do not reflect the views of my employer or anyone other than myself.</description>
	<lastBuildDate>Thu, 02 Feb 2012 21:45:54 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Network Security Blog &#187; The Network Security Podcast, Episode 198</title>
		<link>http://www.mckeay.net/2010/05/21/are-low-standards-better-than-no-standards/comment-page-1/#comment-6110</link>
		<dc:creator>Network Security Blog &#187; The Network Security Podcast, Episode 198</dc:creator>
		<pubDate>Wed, 26 May 2010 03:29:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2010/05/21/are-low-standards-better-than-no-standards/#comment-6110</guid>
		<description>[...] Are Low Standards Better Than No Standards? Nope. [...]</description>
		<content:encoded><![CDATA[<p>[...] Are Low Standards Better Than No Standards? Nope. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric Irvin</title>
		<link>http://www.mckeay.net/2010/05/21/are-low-standards-better-than-no-standards/comment-page-1/#comment-6101</link>
		<dc:creator>Eric Irvin</dc:creator>
		<pubDate>Sat, 22 May 2010 03:32:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2010/05/21/are-low-standards-better-than-no-standards/#comment-6101</guid>
		<description>Well delivered. I think this would make a great round-table discussion at some point. While you&#039;ve made some good points, there are still questions such as, why even require a pen test, if the quality of such a test doesn&#039;t matter. The same should go for the ASV, why even require the cert if the results don&#039;t matter. While I agree that a checkmark from an ASV, just like a Pen Tester, and for that matter, a QSA lulls many in to a false sense of security (literally), we have to recall the intent of the requirements.

At the same time, I also acknowledge that as you said, if a vendor chooses to use the qualification bar, as a ceiling instead of the floor, then we are truly all providing our customers a disservice.</description>
		<content:encoded><![CDATA[<p>Well delivered. I think this would make a great round-table discussion at some point. While you&#8217;ve made some good points, there are still questions such as, why even require a pen test, if the quality of such a test doesn&#8217;t matter. The same should go for the ASV, why even require the cert if the results don&#8217;t matter. While I agree that a checkmark from an ASV, just like a Pen Tester, and for that matter, a QSA lulls many in to a false sense of security (literally), we have to recall the intent of the requirements.</p>
<p>At the same time, I also acknowledge that as you said, if a vendor chooses to use the qualification bar, as a ceiling instead of the floor, then we are truly all providing our customers a disservice.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Diami03</title>
		<link>http://www.mckeay.net/2010/05/21/are-low-standards-better-than-no-standards/comment-page-1/#comment-6098</link>
		<dc:creator>Diami03</dc:creator>
		<pubDate>Fri, 21 May 2010 17:24:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2010/05/21/are-low-standards-better-than-no-standards/#comment-6098</guid>
		<description>A+ for how you broke down DSS staying away from pen testers!!!!</description>
		<content:encoded><![CDATA[<p>A+ for how you broke down DSS staying away from pen testers!!!!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

