<?xml version="1.0" encoding="UTF-8"?><rss version="0.92">
<channel>
	<title>Marcos Christodonte II - Information Security Blog</title>
	<link>http://christodonte.com</link>
	<description>A few words about information security</description>
	<lastBuildDate>Sat, 22 Jan 2011 13:09:55 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	<!-- generator="WordPress/abc" -->

	<item>
		<title>Risk-based auditing to achieve enterprise security</title>
		<description><![CDATA[Here&#8217;s a new piece I wrote for SearchSecurity.com on using a risk-based auditing methodology to achieve enterprise security. Some topics covered include: Why use a risk-based audit How to perform a risk assessment Tips on categorizing assets Classifying assets by criticality and confidentiality levels Calculating risk and risk ranking Developing an audit plan A six-step [...]]]></description>
		<link>http://christodonte.com/2010/04/risk-based-auditing-to-achieve-enterprise-security/</link>
			</item>
	<item>
		<title>Book Review: Wireshark Network Analysis</title>
		<description><![CDATA[  I was a little nervous when I started reading this book. Chapter 1 provided an overview of network analysis, but had a lot of “personality.” When I read, “Wait…more data is coming in…and more…and…SCREECH!” I wasn’t too sure if I was going to finish the book. At over 700 pages, I was hoping that [...]]]></description>
		<link>http://christodonte.com/2010/04/book-review-wireshark-network-analysis/</link>
			</item>
	<item>
		<title>Creating a proactive incident response program</title>
		<description><![CDATA[I recently wrote an article for SearchSecurity.com on creating a proactive incident response program. Here&#8217;s the introduction (click the link above to continue reading): Information security incidents are a fact of life. We have witnessed them on the news and within our own organizations &#8212; attackers are getting into networks and stealing corporate secrets and [...]]]></description>
		<link>http://christodonte.com/2010/03/creating-a-proactive-incident-response-program/</link>
			</item>
	<item>
		<title>Researchers Display Rootkit Capability on Smartphones</title>
		<description><![CDATA[Rutgers just posted a news release about malware research against smartphones. The Professor and student researchers discussed how their rootkits could &#8220;eavesdrop on a meeting, track its owner’s travels, or rapidly drain its battery to render the phone useless.&#8221; They were able to send &#8220;invisible&#8221; text messages to the infected phone, activating the rootkit, and [...]]]></description>
		<link>http://christodonte.com/2010/02/researchers-display-rootkit-capability-on-smartphones/</link>
			</item>
	<item>
		<title>Employees, Questions, and Business Risk&#8230;</title>
		<description><![CDATA[I was reading an article today by Jay Forte about having a value discussion with your employees. The article was quite interesting, and as I read it, I thought about how his guidance also applied to security. Jay outlined what managers could tell their employees to help them add value to their organizations. Part of [...]]]></description>
		<link>http://christodonte.com/2010/02/employees-questions-and-business-risk/</link>
			</item>
	<item>
		<title>Excerpt of Cyber Within</title>
		<description><![CDATA[I&#8217;ve had a few requests for an excerpt of my book, Cyber Within, so I&#8217;ve decided to post one online. Here&#8217;s the link: Cyber Within Excerpt Enjoy!]]></description>
		<link>http://christodonte.com/2010/01/excerpt-of-cyber-within/</link>
			</item>
	<item>
		<title>Cyber Within is Now Available</title>
		<description><![CDATA[It&#8217;s been a busy few weeks! Just wanted to let everyone know that my new book, Cyber Within, is now available at Amazon.com Q. Why did I write Cyber Within? A. I wrote Cyber Within to provide employees with an interesting guide to help them understand cyber and insider threats. The book is meant to [...]]]></description>
		<link>http://christodonte.com/2010/01/cyber-within-my-new-book-is-now-available/</link>
			</item>
	<item>
		<title>All Versions of IE Vulnerable to Zero-day Attack?</title>
		<description><![CDATA[In case you haven&#8217;t heard, there&#8217;s been a zero-day attack against several big companies such as Google, Adobe, and others. The reports and chatter all started when Google reported that they might be taking another approach in conducting operations in China. I think this statement dropped a few jaws, &#8220;In mid-December, we detected a highly [...]]]></description>
		<link>http://christodonte.com/2010/01/all-versions-of-ie-vulnerable-to-zero-day-attack/</link>
			</item>
	<item>
		<title>IP Address Spoofing</title>
		<description><![CDATA[In everyday conversation, we tend to use language that is foreign to others around us. While people sometimes give us a head nod, or say “uh huh,” they don’t always know what we’re talking about. Frankly, their body language tells the true story, especially when they display the “thousand mile stare,” or confused facial gesture. [...]]]></description>
		<link>http://christodonte.com/2009/12/ip-address-spoofing/</link>
			</item>
	<item>
		<title>Best practices for (small) botnets</title>
		<description><![CDATA[Check out my new article at SearchSecurity.com where I outline Best practices for (small) botnets. Short excerpt: Recent large-scale botnet events, such as those used to disrupt Twitter and Facebook, have been highly publicized in the news. While these high-profile security events have been hard to miss, it&#8217;s the smaller, stealthier botnet attacks that may [...]]]></description>
		<link>http://christodonte.com/2009/12/best-practices-for-small-botnets/</link>
			</item>
</channel>
</rss>

