<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>I Am Security &#187; risk management</title>
	<atom:link href="http://www.iamit.org/blog/tag/risk-management/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.iamit.org/blog</link>
	<description>Security news and research</description>
	<lastBuildDate>Wed, 25 Jan 2012 11:13:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
<cloud domain='www.iamit.org' port='80' path='/blog/?rsscloud=notify' registerProcedure='' protocol='http-post' />
	<copyright>Copyright &#xA9; I Am Security 2011 </copyright>
	<managingEditor>iamit@iamit.org (I Am Security)</managingEditor>
	<webMaster>iamit@iamit.org (I Am Security)</webMaster>
	<image>
		<url>http://www.iamit.org/blog/wp-content/plugins/podpress/images/powered_by_podpress.jpg</url>
		<title>I Am Security</title>
		<link>http://www.iamit.org/blog</link>
		<width>144</width>
		<height>144</height>
	</image>
	<itunes:subtitle></itunes:subtitle>
	<itunes:summary>Security news and research</itunes:summary>
	<itunes:keywords></itunes:keywords>
	<itunes:category text="Society &#38; Culture" />
	<itunes:author>I Am Security</itunes:author>
	<itunes:owner>
		<itunes:name>I Am Security</itunes:name>
		<itunes:email>iamit@iamit.org</itunes:email>
	</itunes:owner>
	<itunes:block>no</itunes:block>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://www.iamit.org/blog/wp-content/plugins/podpress/images/powered_by_podpress_large.jpg" />
		<item>
		<title>Information Security, Homeland Security, and finding someone to pin it on</title>
		<link>http://www.iamit.org/blog/2011/10/information-security-homeland-security-and-finding-someone-to-pin-it-on/</link>
		<comments>http://www.iamit.org/blog/2011/10/information-security-homeland-security-and-finding-someone-to-pin-it-on/#comments</comments>
		<pubDate>Mon, 24 Oct 2011 22:05:03 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[anonymous]]></category>
		<category><![CDATA[Attribution]]></category>
		<category><![CDATA[Behavior]]></category>
		<category><![CDATA[Blame]]></category>
		<category><![CDATA[electronic infrastructure]]></category>
		<category><![CDATA[Ethics]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[LulzSec]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security exercise]]></category>
		<category><![CDATA[Social psychology]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=668</guid>
		<description><![CDATA[In the recent spree of cyber attacks on a plethora of US and international government and federal related establishments a lot of speculations are being thrown around as authorities are trying to find the threat community behind it. As computer &#8230; <a href="http://www.iamit.org/blog/2011/10/information-security-homeland-security-and-finding-someone-to-pin-it-on/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.iamit.org/blog/2011/10/information-security-homeland-security-and-finding-someone-to-pin-it-on/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The curious case of Dropbox security</title>
		<link>http://www.iamit.org/blog/2011/04/the-curious-case-of-dropbox-security/</link>
		<comments>http://www.iamit.org/blog/2011/04/the-curious-case-of-dropbox-security/#comments</comments>
		<pubDate>Wed, 13 Apr 2011 14:42:33 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[Attack Vector]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[Cloud storage]]></category>
		<category><![CDATA[Dropbox]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=593</guid>
		<description><![CDATA[After the disclosure of the host_id authentication issues that plagued the popular Dropbox service last week, a new issue came up with the fact that Dropbox can detect whether the files you are trying to upload to their cloud already &#8230; <a href="http://www.iamit.org/blog/2011/04/the-curious-case-of-dropbox-security/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.iamit.org/blog/2011/04/the-curious-case-of-dropbox-security/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>SCADA, control systems and security &#8211; not necessarily enemies</title>
		<link>http://www.iamit.org/blog/2011/04/scada-control-systems-and-security-not-necessarily-enemies/</link>
		<comments>http://www.iamit.org/blog/2011/04/scada-control-systems-and-security-not-necessarily-enemies/#comments</comments>
		<pubDate>Wed, 06 Apr 2011 07:55:56 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[National security]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=582</guid>
		<description><![CDATA[Insights from the NISA International SCADA Security Forum conference (NISA stands for National Information Security Authority, which is a division of the Israeli Security Agency). We all know that SCADA has been considered a security nightmare for a long time. &#8230; <a href="http://www.iamit.org/blog/2011/04/scada-control-systems-and-security-not-necessarily-enemies/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.iamit.org/blog/2011/04/scada-control-systems-and-security-not-necessarily-enemies/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Defense through Offense, and how APT fits there</title>
		<link>http://www.iamit.org/blog/2011/04/defense-through-offense-and-how-apt-fits-there/</link>
		<comments>http://www.iamit.org/blog/2011/04/defense-through-offense-and-how-apt-fits-there/#comments</comments>
		<pubDate>Sun, 03 Apr 2011 10:32:31 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[apt]]></category>
		<category><![CDATA[attack tools]]></category>
		<category><![CDATA[Attack Vector]]></category>
		<category><![CDATA[Computer security]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[penetration test]]></category>
		<category><![CDATA[red team]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[social network]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=577</guid>
		<description><![CDATA[I&#8217;m guessing that having &#8220;APT&#8221; in anything that goes outside for public consumption these days is mandatory, but this post actually has a good reason to do so. If you look back just one post in the past, we were &#8230; <a href="http://www.iamit.org/blog/2011/04/defense-through-offense-and-how-apt-fits-there/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.iamit.org/blog/2011/04/defense-through-offense-and-how-apt-fits-there/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Defining Penetration Testing</title>
		<link>http://www.iamit.org/blog/2011/03/defining-penetration-testing/</link>
		<comments>http://www.iamit.org/blog/2011/03/defining-penetration-testing/#comments</comments>
		<pubDate>Fri, 04 Mar 2011 11:03:26 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[penetration test]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[technical]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=573</guid>
		<description><![CDATA[I have been fortunate enough to be working with a group of peers from the security industry over the past few months (since November 2010) on finally creating a solid definition of what a penetration testing is. It has been &#8230; <a href="http://www.iamit.org/blog/2011/03/defining-penetration-testing/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.iamit.org/blog/2011/03/defining-penetration-testing/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Information Security Intelligence Report for 2010 and Predictions for 2011</title>
		<link>http://www.iamit.org/blog/2011/01/information-security-intelligence-report-for-2010-and-predictions-for-2011/</link>
		<comments>http://www.iamit.org/blog/2011/01/information-security-intelligence-report-for-2010-and-predictions-for-2011/#comments</comments>
		<pubDate>Mon, 24 Jan 2011 15:57:18 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[cyberwarfare]]></category>
		<category><![CDATA[eCrime]]></category>
		<category><![CDATA[malweb]]></category>
		<category><![CDATA[predictions]]></category>
		<category><![CDATA[press]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[social network]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[web2.0]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=566</guid>
		<description><![CDATA[Looking back at 2010 shows a widening gap between cybercrime and law enforcement capabilities, in conjunction to nations that have started the cyber-race to develop defensive and offensive capabilities. Most of the attacks analyzed in 2010 depict organizations that fall &#8230; <a href="http://www.iamit.org/blog/2011/01/information-security-intelligence-report-for-2010-and-predictions-for-2011/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.iamit.org/blog/2011/01/information-security-intelligence-report-for-2010-and-predictions-for-2011/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>the art of not thinking about elephants</title>
		<link>http://www.iamit.org/blog/2011/01/the-art-of-not-thinking-about-elephants/</link>
		<comments>http://www.iamit.org/blog/2011/01/the-art-of-not-thinking-about-elephants/#comments</comments>
		<pubDate>Thu, 06 Jan 2011 08:24:43 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Security Research]]></category>
		<category><![CDATA[Attack Vector]]></category>
		<category><![CDATA[exfiltration]]></category>
		<category><![CDATA[red team]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security policy]]></category>
		<category><![CDATA[technical]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=560</guid>
		<description><![CDATA[Approaching risk management should be done in the most holistic manner, this means that EVERY aspect of information flow should be taken into account. This article describes how a red-team test managed to exfiltrate data out of a closed/non-connected network using innovative thinking. <a href="http://www.iamit.org/blog/2011/01/the-art-of-not-thinking-about-elephants/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.iamit.org/blog/2011/01/the-art-of-not-thinking-about-elephants/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Learning from stux, and connecting more dots in infosec</title>
		<link>http://www.iamit.org/blog/2010/10/learning-from-stux-and-connecting-more-dots-in-infosec/</link>
		<comments>http://www.iamit.org/blog/2010/10/learning-from-stux-and-connecting-more-dots-in-infosec/#comments</comments>
		<pubDate>Mon, 11 Oct 2010 12:00:46 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[Attack Vector]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[cyberwarfare]]></category>
		<category><![CDATA[penetration test]]></category>
		<category><![CDATA[press]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[social network]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/2010/10/learning-from-stux-and-connecting-more-dots-in-infosec/</guid>
		<description><![CDATA[Learning from stuxnet on how we are exposed to similar attacks. Connecting the dots between technology, society, and the human factor when talking about cyberwarfare. <a href="http://www.iamit.org/blog/2010/10/learning-from-stux-and-connecting-more-dots-in-infosec/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.iamit.org/blog/2010/10/learning-from-stux-and-connecting-more-dots-in-infosec/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Pentesters and businessman are doing it wrong</title>
		<link>http://www.iamit.org/blog/2010/09/pentesters-and-businessman-are-doing-it-wrong/</link>
		<comments>http://www.iamit.org/blog/2010/09/pentesters-and-businessman-are-doing-it-wrong/#comments</comments>
		<pubDate>Mon, 27 Sep 2010 08:53:31 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[BruCon]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[penetration test]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Source]]></category>
		<category><![CDATA[technical]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=529</guid>
		<description><![CDATA[What we are doing wrong as a security services industry, what businesses are doing wrong when they engage us, and how to fix it <a href="http://www.iamit.org/blog/2010/09/pentesters-and-businessman-are-doing-it-wrong/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.iamit.org/blog/2010/09/pentesters-and-businessman-are-doing-it-wrong/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>The Turkish hack and another case for IL-CERT</title>
		<link>http://www.iamit.org/blog/2010/07/the-turkish-hack-and-another-case-for-il-cert/</link>
		<comments>http://www.iamit.org/blog/2010/07/the-turkish-hack-and-another-case-for-il-cert/#comments</comments>
		<pubDate>Mon, 19 Jul 2010 05:44:25 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[Attack Vector]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[press]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=499</guid>
		<description><![CDATA[You have been living under a rock if you haven&#8217;t heard of the Turkish hack a couple of days ago. Basically &#8211; a Turkish hacker forum that bolsters a strong anti-Israeli attitude has been practicing hacking and mostly defacing Israeli &#8230; <a href="http://www.iamit.org/blog/2010/07/the-turkish-hack-and-another-case-for-il-cert/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.iamit.org/blog/2010/07/the-turkish-hack-and-another-case-for-il-cert/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

