<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Security Minded - from Kai the Security Guy - All Comments</title><link>http://blogs.technet.com/b/kaiaxford/</link><description>Some thoughts on security (and other stuff) from a Microsoft security professional</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: New Editor of the Microsoft Technical Audiences Security Newsletter</title><link>http://blogs.technet.com/b/kaiaxford/archive/2009/08/17/new-editor-of-the-microsoft-technical-audiences-security-newsletter.aspx#3293438</link><pubDate>Thu, 12 Nov 2009 17:11:44 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3293438</guid><dc:creator>Jon W</dc:creator><description>&lt;p&gt;Thinking of DirectAccess as &amp;quot;a 5,000 mile CAT-5 cable&amp;quot; isn't doing it for me; I'd worry about that even more!&lt;/p&gt;
&lt;p&gt;Some details would be nice about how/why it's safe to allow an additional access route that doesn't *appear* to require the same level of authentication as the old VPN route.&lt;/p&gt;
&lt;p&gt;I'm sure I'm not the only one...&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3293438" width="1" height="1"&gt;</description></item><item><title>re: 2008 Crimes Against Children Conference</title><link>http://blogs.technet.com/b/kaiaxford/archive/2008/08/18/2008-crimes-against-children-conference.aspx#3292207</link><pubDate>Sun, 08 Nov 2009 00:51:45 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3292207</guid><dc:creator>Sherry Friedlander</dc:creator><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;Thank you for being a part of helping keep children safe. A Child Is Missing Alert Program is available to law enforcment 24/7/365 and is FREE. We are presently helping over 5000 departments nationwide. &amp;nbsp;We are available to all departments in the US. &amp;nbsp;so if we can be of help in your area please contact A Child Is Missing Alert for more information.&lt;/p&gt;
&lt;p&gt;sherry Friedlander &amp;nbsp;sherryf@achildismissing.org&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3292207" width="1" height="1"&gt;</description></item><item><title>re: New Editor of the Microsoft Technical Audiences Security Newsletter</title><link>http://blogs.technet.com/b/kaiaxford/archive/2009/08/17/new-editor-of-the-microsoft-technical-audiences-security-newsletter.aspx#3276157</link><pubDate>Mon, 24 Aug 2009 01:27:57 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3276157</guid><dc:creator>Shems</dc:creator><description>&lt;p&gt;Also, I want to hear your valid feedback. Don’t email me about how you ‘re sent in money to some Nigerian prince and you haven’t seen your money since. &lt;/p&gt;
&lt;p&gt;----------------------&lt;/p&gt;
&lt;p&gt;ROFLOL ... &lt;/p&gt;
&lt;p&gt;Valid feedback; I'm about to write articles; I've done some preliminary work to test my ability to write -in english- and be considered valuable. If I write an article it has to be worthwile !!! Besides, I don't want to 'be foolish' or -worse- be taken lightly.&lt;/p&gt;
&lt;p&gt;Shems&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3276157" width="1" height="1"&gt;</description></item><item><title>re: Sweetie…can I make some security modifications to the car?</title><link>http://blogs.technet.com/b/kaiaxford/archive/2009/02/16/sweetie-can-i-make-some-security-modifications-to-the-car.aspx#3246516</link><pubDate>Thu, 28 May 2009 06:36:28 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3246516</guid><dc:creator>Sean Kearney</dc:creator><description>&lt;p&gt;I immediately thought as you commented about the &amp;quot;parking lot&amp;quot;.&lt;/p&gt;
&lt;p&gt;Now THERE'S a deterrent to anybody trying cause problems with security on the computer side...&lt;/p&gt;
&lt;p&gt;&amp;quot;Quick Put that data down! &amp;nbsp;Here comes the Administrator! &amp;nbsp;And... what's that at the top of the truck?!?!&amp;quot; &lt;/p&gt;
&lt;p&gt;RUN AWAYYYYYYYY!!!&lt;/p&gt;
&lt;p&gt;BTW, Great Session you did in Sheridan College, glad to have met you :)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3246516" width="1" height="1"&gt;</description></item><item><title>re: Is Cloud Computing Really Risk Transference?</title><link>http://blogs.technet.com/b/kaiaxford/archive/2009/02/18/is-cloud-computing-really-risk-transference.aspx#3246264</link><pubDate>Wed, 27 May 2009 20:01:26 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3246264</guid><dc:creator>John</dc:creator><description>&lt;p&gt;I don't know why the technical media is blowing this up like it's some new great thing. &amp;nbsp;Cloud computing has been around for at least the last 10 years if not longer. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Conceptually shared web hosting platforms and file repository/sharing networks were some of the first clouds to surface on the Internet. &amp;nbsp;While, yes, these services are often used by the degenerates and vagabonds of the computing world, the concept in itself could be invaluable to smaller businesses without the financial or technical means to maintain their own datacenter. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;The only thing that's really emerged from the idea of cloud computing is that companies like IBM and Google have essentially taken a less than reputable concept (and, yes, shared hosting is often a less than reputable means of web hosting when dealing with some of these providers), cleaned it up, sprinkled some glitter on it, and marketted the heck out of it until it shined.&lt;/p&gt;
&lt;p&gt;But moving to the point of the discussion, I'd like to address Robert's take on the risk management factors of cloud computing versus in-house solutions. &amp;nbsp;I would have to say that no company should ever maintain confidential (operational, financial, personal, and personnel) data on a cloud. &amp;nbsp;To do so would be a liability that could and eventually will ruin you. &amp;nbsp;Robert, I'm going to have to disagree with you about &amp;quot;Closer is not necessarily safer or more responsible.&amp;quot; &amp;nbsp;Closer, with offsite backups, is probably the most responsible thing any organization could do with confidential data. &amp;nbsp;While, yes, there may be more security experts working in a datacenter, but nobody knows your data like you do. &amp;nbsp;And more times that you would think, you know a better way of securing your data than the acclaimed &amp;quot;IT Professionals&amp;quot;. &amp;nbsp;As well, you lose the ability to define your security standards.&lt;/p&gt;
&lt;p&gt;In my experience at my datacenter, data is most often compromised when people have extremely poor security standards or none at all. &amp;nbsp;I would say to put more faith in your own security standards than some phone jockey at Google making $10/hr. &amp;nbsp;You have no idea (outside of all the marketing and propaganda) what that datacenter's security is like, and they're not about to give you a technical breakdown.&lt;/p&gt;
&lt;p&gt;Cloud computing is a great idea, though. &amp;nbsp;I would recommend usage to just about any entreprenuers, small businesses, or educational institutions but never at the expense of their confidential data. &amp;nbsp;If you can not afford to maintain your confidential data in-house, your probably should rethink your business model.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3246264" width="1" height="1"&gt;</description></item><item><title>re: Is Cloud Computing Really Risk Transference?</title><link>http://blogs.technet.com/b/kaiaxford/archive/2009/02/18/is-cloud-computing-really-risk-transference.aspx#3224997</link><pubDate>Fri, 10 Apr 2009 16:27:42 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3224997</guid><dc:creator>tshinder</dc:creator><description>&lt;p&gt;Hi Kai,&lt;/p&gt;
&lt;p&gt;Great article.&lt;/p&gt;
&lt;p&gt;Check my observations at:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.windowsecurity.com/shinder/2009/04/10/is-cloud-computing-really-risk-transference/"&gt;http://blogs.windowsecurity.com/shinder/2009/04/10/is-cloud-computing-really-risk-transference/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;Tom&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3224997" width="1" height="1"&gt;</description></item><item><title>re: Is Cloud Computing Really Risk Transference?</title><link>http://blogs.technet.com/b/kaiaxford/archive/2009/02/18/is-cloud-computing-really-risk-transference.aspx#3214023</link><pubDate>Tue, 17 Mar 2009 16:27:07 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3214023</guid><dc:creator>Miles</dc:creator><description>&lt;p&gt;Internal or external hosting and how security control objectives are maintained is a very interesting topic. &lt;/p&gt;
&lt;p&gt;Technical controls alone are not adequate when dealing with outsourced arrangements. &lt;/p&gt;
&lt;p&gt;I'd suggest that as outsourcing data hosting becomes more widespread, attention to oustourced 3rd party Contracts is needed. &amp;nbsp;Focus should cover specific security requirements, such as right to audit, compliance with your company security policies (or at minimum a gap analysis or theirs and yours to manage risks accordingly) and also getting that downstream liability clause agreed :)&lt;/p&gt;
&lt;p&gt;I'd expect that some organisations will be attracted towards the financial benefit of cloud computing without understanding or factoring in the security exposure and implecations it presents. It is these types of organisations where visibility is needed. &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3214023" width="1" height="1"&gt;</description></item><item><title>re: Sweetie…can I make some security modifications to the car?</title><link>http://blogs.technet.com/b/kaiaxford/archive/2009/02/16/sweetie-can-i-make-some-security-modifications-to-the-car.aspx#3205469</link><pubDate>Sun, 22 Feb 2009 05:29:23 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3205469</guid><dc:creator>Dale</dc:creator><description>&lt;p&gt;Now it just needs some sort of bag to catch the brass before it rains all over the vehicle.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3205469" width="1" height="1"&gt;</description></item><item><title>re: Is Cloud Computing Really Risk Transference?</title><link>http://blogs.technet.com/b/kaiaxford/archive/2009/02/18/is-cloud-computing-really-risk-transference.aspx#3204959</link><pubDate>Fri, 20 Feb 2009 17:51:30 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3204959</guid><dc:creator>TechNet Archive</dc:creator><description>&lt;p&gt;Great points Robert and thanks for starting the discussion. &lt;/p&gt;
&lt;p&gt;I certainly agree that things can and often shoul dbe outsourced, but I worry about the ramifications as to what happens when the data for which I'm the legal custodian of, is compromised on someone else's box. &lt;/p&gt;
&lt;p&gt;From what I've seen, this is a question that is only beginning to make the legal rounds.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3204959" width="1" height="1"&gt;</description></item><item><title>re: Is Cloud Computing Really Risk Transference?</title><link>http://blogs.technet.com/b/kaiaxford/archive/2009/02/18/is-cloud-computing-really-risk-transference.aspx#3204898</link><pubDate>Fri, 20 Feb 2009 13:58:36 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3204898</guid><dc:creator>Robert</dc:creator><description>&lt;p&gt;It would be unfortunate if companies decided that keeping confidential customer data on their own servers physically in-house was the only way to be responsible. &amp;nbsp;It's rather like deciding that employing your own cleaning staff was the only way to keep your office premises secure, rather than hiring the services of an external cleaning firm. &lt;/p&gt;
&lt;p&gt;I read somewhere that firms must divide work into 4 categories based on the questions &amp;quot;Can the business survive without this?&amp;quot; and &amp;quot;Does this directly contribute to our bottom line?&amp;quot;. &amp;nbsp;For IT operations, most firms would answer &amp;quot;Yes&amp;quot; to the first question but &amp;quot;No&amp;quot; for the second. &amp;nbsp;In other words, it is critical to business survival, but more a supporting operation than a value-adding operation.&lt;/p&gt;
&lt;p&gt;An IT firm might justify maintaining their own servers, but a non-IT firm is unlikely to have the expertise and is better off finding an external supplier to maintain their supporting IT operations.&lt;/p&gt;
&lt;p&gt;Because IT is often such a critical system - all client data being stored etc - there needs to be a clear contract with adequate compensation being paid if ever systems fail (through data loss or theft) because it will inevitably have a damaging effect on the reputation as well as (value-adding) operations of the business.&lt;/p&gt;
&lt;p&gt;There is no easy answer about data breaches, but there is still a risk of data breaches for in-house data, and you could argue you are being more responsible to your customers by out-sourcing to experts than keeping it in-house with potentially under-qualified staff. &amp;nbsp;Think of the security in a data centre compared with your average small business! &amp;nbsp;Closer is not necessarily safer or more responsible.&lt;/p&gt;
&lt;p&gt;Someone else needs to answer the auditing question?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3204898" width="1" height="1"&gt;</description></item></channel></rss>