<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.ism-community.org/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>The ISM-Community</title><link>http://www.ism-community.org/blogs/</link><description>A Community Project Dedicated to Improving Practical Information Security Management </description><dc:language>en-US</dc:language><generator>CommunityServer 2007 (Build: 20423.869)</generator><item><title>Risk Assessment Methodology Update</title><link>http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/07/11/risk-assessment-methodology-update.aspx</link><pubDate>Wed, 11 Jul 2007 11:28:00 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:1037</guid><dc:creator>rybolov</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;With a couple of volunteers, work on the RA Methodology has been moving forward.&amp;nbsp; I spent some of the last week working on the front and back of it, adding in the niceties like the license snippet, links to other risk assessment/management guides, etc.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;While I can crank out the various sections myself, I would like a couple more volunteers to help out, especially people who will &amp;quot;adopt&amp;quot; one of the following sections and commit to getting it to 75% done:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Determine Threats&lt;/li&gt;&lt;li&gt;Determine Countermeasures&lt;/li&gt;&lt;li&gt;Determine Vulnerabilities&lt;/li&gt;&lt;li&gt;Determine Risk&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;I&amp;#39;ve found that with more people working on the document, it gets a very different flavor than if there is one sole author.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Until next time&lt;/p&gt;&lt;p&gt;--Rybolov&amp;nbsp;&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=1037" width="1" height="1"&gt;</description><category domain="http://www.ism-community.org/blogs/riskmanagementblog/archive/tags/risk+assessment/default.aspx">risk assessment</category></item><item><title>The T10 </title><link>http://www.ism-community.org/blogs/trainingandawarenessblog/archive/2007/07/01/the-t10.aspx</link><pubDate>Sat, 30 Jun 2007 23:41:00 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:1019</guid><dc:creator>tsmith</dc:creator><slash:comments>3</slash:comments><description>As you would have no doubt seen, the Top Ten was released last week in an absolute media frenzy :) Great to get it out there and thanks to everyone who contributed. I think it serves as a good basic guideline and hopefully offers food for thought with the &amp;#39;Tips and Tricks&amp;#39; provided by industry veterans at the end of each section.
I will get back to some more regular posting now. Thanks again to all who contributed to the Top Ten.&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=1019" width="1" height="1"&gt;</description></item><item><title>ISM-Community Releases Top Ten for IT Security Management</title><link>http://www.ism-community.org/blogs/trainingandawarenessblog/archive/2007/06/29/ism-community-releases-top-ten-for-it-security-management.aspx</link><pubDate>Fri, 29 Jun 2007 20:22:00 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:1016</guid><dc:creator>rybolov</dc:creator><slash:comments>2</slash:comments><description>&lt;p class="MsoNormal"&gt;&lt;span&gt;Press Release for the ISM Top Ten List:&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;

&lt;h1&gt;&lt;span&gt;ISM-Community Releases Top Ten for IT Security Management&lt;/span&gt;&lt;/h1&gt;&lt;h5&gt;&lt;span&gt;Worldwide community of information security managers cuts
through the FUD to offer the fundamentals&lt;/span&gt;&lt;/h5&gt;


&lt;p class="MsoNormal"&gt;

&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span&gt;Washington, DC June 28&lt;sup&gt;th&lt;/sup&gt;, 2007 —
The Non-Profit Information Security Management Community (http:
//www.ism-community.org/) today announced its ISM-Community Top Ten list, an awareness
document that describes a series of key issues that effect today’s information security
managers.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span&gt;Taking a refreshing break from the typical
fear, uncertainty, and doubt that information security managers are deluged
with on a daily basis, the ISM-Community presents a simple, easily-understood,
pragmatic approach towards managing information security.&lt;/span&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;p class="MsoNormal"&gt;&lt;i&gt;&amp;quot;The ISM Community Top 10 will provide security management and
professionals with guiding principles to build a solid program within any
organization. It also serves as a great reminder to managers of existing
programs to focus on the fundamentals.&amp;quot;--Ed Bellis, CISO Orbitz Worldwide,
ISM-Community Top Ten Contributor&lt;/i&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;i&gt;&lt;span&gt;&lt;/span&gt;&lt;/i&gt;

&lt;p class="MsoNormalIndent" style="margin-left:0in;"&gt;&lt;span&gt;The Top Ten
list describes key concepts that should be part of any effective information
security program.&lt;span&gt;&amp;nbsp; &lt;/span&gt;Organizations can
quickly compare their current information security program against the Top Ten
list and determine if and whether they need to improve.&lt;/span&gt;&lt;/p&gt;

&lt;blockquote&gt;&lt;p class="MsoNormalIndent"&gt;&lt;i&gt;&lt;span&gt;“The ISM-Community Top Ten offers invaluable insight into how to get
security management embedded into your organization – advice from some of the
top InfoSec people in the industry.” --Tim Smith, Director Bridge Point
Communication, Top Ten Main Author&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;&lt;/blockquote&gt;

&lt;p class="MsoNormal"&gt;&lt;span&gt;The Top Ten list is released under a
Creative Commons license and can be downloaded for free from the ISM-Community
website at &lt;a href="http://www.ism-community.org/files/"&gt;http://www.ism-community.org/files/&lt;/a&gt;
.&lt;/span&gt;&lt;/p&gt;

&lt;blockquote&gt;&lt;p class="MsoNormalIndent"&gt;&lt;i&gt;&lt;span&gt;&amp;quot;The Chief Security Officers and Chief Information Security
Officers that I’ve talked to about the ISM&lt;span&gt;&amp;nbsp;
&lt;/span&gt;Top Ten have told me, ‘Finally, some home truths and straight-talking
advice from real world security people and not thinly disguised marketing or
spin from people wanting you to buy products’&amp;quot; –Mark Curphey,
ISM-Community Founder&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;&lt;/blockquote&gt;

&lt;p class="MsoNormal"&gt;&lt;span&gt;The ISM-Community is developing other
projects along the lines of the Top Ten to be released throughout the upcoming
months touching on 5 key focus areas: identity and privacy, risk management,
policies and standards, training and awareness, and information security
management commons.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-left:0.5in;"&gt;&lt;i&gt;&lt;span&gt;&amp;quot;If the Top Ten is an indicator, the ISM-Community shows real
promise to become the thought leaders in information security management.&lt;span&gt;&amp;nbsp; &lt;/span&gt;The Top Ten is an excellent starting point,
and future projects will only build upon the foundation that the Top Ten
provides.”—Michael Smith, ISM-Community Leader&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;span&gt;For additional information or inquiries contact:
Michael Smith at 703.855.0890 (Not for Publication), &lt;a href="mailto:info.ismcommunity@gmail.com"&gt;info.ismcommunity@gmail.com&lt;/a&gt; or &lt;a href="http://www.ism-community.org//"&gt;http://www.ism-community.org/&lt;/a&gt; .&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span&gt;About ISM-Community:&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;span&gt;The ISM-Community, founded in 2006 by a
group of information security managers, is a &lt;/span&gt;&lt;span&gt;“Community of Practice” where people can
collaborate on information security both online and in person, creating and
sharing things that improve everyone’s collective working life and that
everyone can use for free, without conditions.&lt;span&gt;&amp;nbsp;
&lt;/span&gt;We don’t want the baggage of formal organizations, politics or hidden
agendas but do want a sensible amount of organization and structure.&lt;span&gt;&amp;nbsp; &lt;/span&gt;More information can be found on our website
at &lt;a href="http://www.ism-community.org/aboutus.aspx"&gt;http://www.ism-community.org/aboutus.aspx&lt;/a&gt;
&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;a href="http://www.ism-community.org/files/folders/trainingandawarenessrelease/entry1015.aspx" target="_blank"&gt;Downloadable .doc&lt;br /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=1016" width="1" height="1"&gt;</description><category domain="http://www.ism-community.org/blogs/trainingandawarenessblog/archive/tags/top+ten/default.aspx">top ten</category><category domain="http://www.ism-community.org/blogs/trainingandawarenessblog/archive/tags/press/default.aspx">press</category><category domain="http://www.ism-community.org/blogs/trainingandawarenessblog/archive/tags/ism-community/default.aspx">ism-community</category></item><item><title>Mailing Lists Coming to ISM-Community.org</title><link>http://www.ism-community.org/blogs/commonsblog/archive/2007/06/27/mailing-lists-coming-to-ism-community-org.aspx</link><pubDate>Wed, 27 Jun 2007 17:38:14 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:1001</guid><dc:creator>mcurphey</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;You might well notice some changes on the home page today. The portal hasn&amp;#39;t really had much TLC for a while and its been hard to find things and&amp;nbsp;participate. That is changing. Today I installed the enterprise email gateway. This allows you to subscribe to a forum as if it were a mailing list. In fact its the best of both worlds, its both a mailing list and a forum. You can start, receive&amp;nbsp;and reply to discussions using email or online via the web site and even both at the same time. It&amp;#39;s your choice. We are having some configuration challenges with receiving and processing mail so the upgrade is not complete but you can subscribe to receive new threads via email for the Risk Management forum now and within a few days I am sure well have it all ironed out. As soon as we have this major upgrade completed I will send out an email and we enable it on all the forums. &lt;/p&gt; &lt;p&gt;Login and poke around at this URL if you are interested.&lt;/p&gt; &lt;p&gt;&lt;a title="http://www.ism-community.org/forums/ForumSubscriptions.aspx" href="http://www.ism-community.org/forums/ForumSubscriptions.aspx"&gt;http://www.ism-community.org/forums/ForumSubscriptions.aspx&lt;/a&gt;&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=1001" width="1" height="1"&gt;</description></item><item><title>ISM-Community Combined Feed</title><link>http://www.ism-community.org/blogs/commonsblog/archive/2007/06/22/ism-community-combined-feed.aspx</link><pubDate>Sat, 23 Jun 2007 00:30:00 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:979</guid><dc:creator>rybolov</dc:creator><slash:comments>1</slash:comments><description>
&lt;p&gt;With some coaching and Yahoo! Pipes non-wizardry (it&amp;#39;s CISO-proof, all drag-n-drop programming), I have thrown together a combined blog feed that contains the feed for the &amp;quot;official&amp;quot; ISM-Community blog feeds plus the personal/work/$foo blogs from community members.&amp;nbsp; If you feel slighted that I didn&amp;#39;t include your feed, please don&amp;#39;t send me poison-pen email letters, just drop me a nice email and I&amp;#39;ll add you in.&amp;nbsp; =)&amp;nbsp; I know there are people that I missed, but I&amp;#39;m trying to add them as I can.&lt;br /&gt; &lt;/p&gt;
&lt;p&gt;&lt;a href="http://pipes.yahoo.com/pipes/pipe.info?_id=4jPqQOfW2xGdvhlPX0sBXw" target="_blank"&gt;The combined blog feed is linked to from here&lt;/a&gt;.&amp;nbsp; It&amp;#39;s not necessarily all ISM-Related (I go off about zombies and flyfishing from time to time, Curphey talks about the varieties of grapes in his vineyard, etc) so there might be some noise that you&amp;#39;re not so keen on.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.ism-community.org/blogs/" target="_blank"&gt;The &amp;quot;official feed is linked to from here&lt;/a&gt;.&amp;nbsp; This is a feed from the 5 focus areas and hardly has any noise at all.&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;Cheers&lt;br /&gt;
--Mike&amp;nbsp;&lt;/p&gt;
&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=979" width="1" height="1"&gt;</description><category domain="http://www.ism-community.org/blogs/commonsblog/archive/tags/series+of+pipes/default.aspx">series of pipes</category><category domain="http://www.ism-community.org/blogs/commonsblog/archive/tags/feeds/default.aspx">feeds</category><category domain="http://www.ism-community.org/blogs/commonsblog/archive/tags/ism-community/default.aspx">ism-community</category><category domain="http://www.ism-community.org/blogs/commonsblog/archive/tags/blogs/default.aspx">blogs</category></item><item><title>Getting Back on the Horse</title><link>http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/06/21/getting-back-on-the-horse.aspx</link><pubDate>Fri, 22 Jun 2007 02:25:00 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:965</guid><dc:creator>rybolov</dc:creator><slash:comments>3</slash:comments><description>
&lt;p&gt;&amp;quot;First we said it was too cold and that the fish were not feeding.&amp;nbsp; Then we said it was too sunny and the fish were scared.&amp;nbsp; Then we discovered that the fish had gone elsewhere.&amp;nbsp; When we found the fish, we started casting to them with nice juicy baitfish flies.&amp;quot;&lt;/p&gt;
&lt;p&gt;So also is the story of the &lt;a href="http://www.ism-community.org/files/folders/riskmanagementrelease/entry743.aspx" target="_blank"&gt;ISM Community Risk Assessment Methodology&lt;/a&gt;.&amp;nbsp; After more than a few false-starts (Curphey changing the server platform, some flirtation with FAIR, almost scoring a free methodology to have and to hold, the apparent ADHD of the project lead), we are continuing down the merry path of creating our own risk assessment methodology.&lt;/p&gt;
&lt;p&gt;Now that we&amp;#39;re back to casting for trout, I would like to issue an Internet-wide call for volunteers.&amp;nbsp; What I&amp;#39;m looking for is about a dozen people who know Risk Assessment and simultaneously know how to write well.&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;Really the methodology consists of several parts:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A document that describes the process (partially started)&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;A set of artifacts to assist in the process such as inventory spreadsheets and a risk register (partially done)&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;Reference implementations where we take the process and test it out (not yet, we need the process first)&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;References and similar projects&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Glossary&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Foo&lt;br /&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
I have a &lt;a href="http://www.hungryfishconsulting.com/ismcommunity/RA%20Methodology%20Status%202007%2006%2021.xls" target="_blank"&gt;handy-dandy spreadsheet to track status&lt;/a&gt;.&amp;nbsp; If you are interested in helping out, go to the RA forum at &lt;a href="http://www.ism-community.org/forums/t/564.aspx" target="_blank"&gt;http://www.ism-community.org/forums/t/564.aspx&lt;/a&gt; (it&amp;#39;s broken right now, I tried to upload the spreadsheet and it bombed out on me) or shoot me an email with a description of what you would like to help out with.&lt;/p&gt;
&lt;p&gt;Cheers&lt;br /&gt;
--Mike&lt;br /&gt;&amp;nbsp;&lt;/p&gt;
&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=965" width="1" height="1"&gt;</description><category domain="http://www.ism-community.org/blogs/riskmanagementblog/archive/tags/risk+assessment/default.aspx">risk assessment</category><category domain="http://www.ism-community.org/blogs/riskmanagementblog/archive/tags/risk+management/default.aspx">risk management</category><category domain="http://www.ism-community.org/blogs/riskmanagementblog/archive/tags/ism-community/default.aspx">ism-community</category></item><item><title>New Project Leader for Policies and Standards Focus Area</title><link>http://www.ism-community.org/blogs/policiesandstandardsblog/archive/2007/06/08/new-project-leader-for-policies-and-standards-focus-area.aspx</link><pubDate>Fri, 08 Jun 2007 12:41:01 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:958</guid><dc:creator>mcurphey</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;/p&gt; &lt;p&gt;Ciske van Oosten has agreed to take over the Policies and Standards project at the ISM Community. Ciske runs a great blog focused on policies and standards at &lt;a href="http://infosec-risk.blogspot.com/"&gt;http://infosec-risk.blogspot.com/&lt;/a&gt;.  &lt;p&gt;The idea behind the Policies and Standards project is to build and maintain a comprehensive and well written free set of policies and standards. These things are rarely competitive advantages to any company and so collaboration can benefit everyone. There are some documents now floating around as donations from various companies which is also great.  &lt;p&gt;Ciske has written a great guide to policies and standards and has some great ideas and passion to make this project happen. &lt;p&gt;The discussion forum is here &lt;a href="http://www.ism-community.org/forums/68.aspx"&gt;http://www.ism-community.org/forums/68.aspx&lt;/a&gt; and I am sure Ciske will be sending some updates and have a project plan via the ISM blog for the project here &lt;a href="http://www.ism-community.org/focusareas/21/PoliciesAndStandardsBlog/focusarea.aspx"&gt;http://www.ism-community.org/focusareas/21/PoliciesAndStandardsBlog/focusarea.aspx&lt;/a&gt; &lt;p&gt;If you have any policies and standards you would donated as baseline documents please contact Ciske via the forums.  &lt;p&gt;Cheers, &lt;p&gt;Mark&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=958" width="1" height="1"&gt;</description><category domain="http://www.ism-community.org/blogs/policiesandstandardsblog/archive/tags/ProjectNews/default.aspx">ProjectNews</category></item><item><title>ISM Community Top Ten - Draft</title><link>http://www.ism-community.org/blogs/policiesandstandardsblog/archive/2007/06/04/ism-community-top-ten-draft.aspx</link><pubDate>Mon, 04 Jun 2007 14:43:48 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:947</guid><dc:creator>mcurphey</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;I have just uploaded the ISM Community Top Ten Draft &lt;a href="http://www.ism-community.org/files/folders/trainingandawarenessrelease/entry946.aspx"&gt;here&lt;/a&gt;. The intention of the T10 is to provide a short and concise awareness document. In the same genre as the SANS Top 20 and OWASP Top Ten it can be used by business managers as well as information security professionals to&amp;nbsp;provoke thought about&amp;nbsp;their current information security programs. &lt;/p&gt; &lt;p&gt;We plan to release the final&amp;nbsp;document next week. There have been several volunteers who have kindly offered to translate it into other languages. The current draft requires some final touches and if anyone has some time today or tomorrow please download it, edit it with tracking turned on (important) and email it to me (mark at curphey dot com). &lt;/p&gt; &lt;p&gt;What is required is;&lt;/p&gt; &lt;p&gt;1. Proof reading (grammar, accuracy and completeness)&lt;/p&gt; &lt;p&gt;2. Tips and Tricks from the field added to sections 8, 9 and 10&lt;/p&gt; &lt;p&gt;Any major changes we can consider for an updated version later this year.&lt;/p&gt; &lt;p&gt;Cheers.&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=947" width="1" height="1"&gt;</description><category domain="http://www.ism-community.org/blogs/policiesandstandardsblog/archive/tags/ProjectNews/default.aspx">ProjectNews</category></item><item><title>A quiet week....</title><link>http://www.ism-community.org/blogs/identityandprivacyblog/archive/2007/05/28/a-quiet-week.aspx</link><pubDate>Mon, 28 May 2007 09:08:00 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:941</guid><dc:creator>klo</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Since my flurry of activity a week ago and subsequent blog posting and creation of new threads, the Identity and Privacy forum has been VERY quiet....&lt;br /&gt;&lt;/p&gt;&lt;p&gt;I am not sure if it&amp;#39;s because there was just too much information posted at one time? Or because nobody has anything to say?&lt;/p&gt;&lt;p&gt;Agenda this week is that I pull together the framework for the &amp;#39;identity and privacy&amp;#39; guide. That I promised before the end of May, and just realised that this is Thursday this week! Time passes fast when it&amp;#39;s fun!&lt;/p&gt;&lt;p&gt;Any suggestions on how I can &amp;#39;spice&amp;#39; up forum activity appreciated?&lt;/p&gt;&lt;p&gt;I am still looking for volunteers that have legal experience in IT to help us unravel the complexities when it comes to global privacy laws. I have created to threads for this in the &lt;a href="http://www.ism-community.org/forums/66.aspx"&gt;forums space&lt;/a&gt; of identity and privacy.&lt;/p&gt;&lt;p&gt;Karen&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=941" width="1" height="1"&gt;</description></item><item><title>What is an identity?</title><link>http://www.ism-community.org/blogs/identityandprivacyblog/archive/2007/05/21/what-is-an-identity.aspx</link><pubDate>Mon, 21 May 2007 18:56:00 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:937</guid><dc:creator>klo</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Hi, here comes the weekly update.... I am trying to post on during the weekend, but didn&amp;#39;t make it this weekend. However I do have a very nice new home office that materialized over the weekend, so feeling it was pretty productive, means I have a more comfortable environment on which to sit and post away on this ISM-community :-)&lt;/p&gt;&lt;p&gt;It has started raining this evening, so also very good weather today to be sitting indoors! Pity I can&amp;#39;t send some of this &amp;#39;down-under&amp;#39;, according to Tim they&amp;#39;re having a bad time through lack of rain there, and here is so lovely and wet!&lt;/p&gt;&lt;p&gt;OK, so updates during the week are as follows:&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;b&gt;1. What is an identity? &lt;/b&gt;It doesn&amp;#39;t matter how may virtual identities you have, whether they are alias or not, they all count as your identity and can have an impact on your reputation -your real reputation and your virtual. Check out the &lt;a href="http://www.ism-community.org/forums/t/512.aspx"&gt;forum &lt;/a&gt;to understand how we got here. If you dispute these conclusions, then you are welcome to post.&lt;/p&gt;&lt;p&gt;&lt;b&gt;2. There have been agreements also concerning the definitions of &amp;#39;identification&amp;#39; and &amp;#39;authentication&amp;#39;&lt;/b&gt;. Check out the &lt;a href="http://www.ism-community.org/files/folders/commonsrelease/entry803.aspx"&gt;glossary &lt;/a&gt;being compiled by Mark in the downloads space. If you want to understand how we got here take a visit to the &lt;a href="http://www.ism-community.org/forums/t/513.aspx"&gt;forum&lt;/a&gt;. We are also in agreedmentconcerning what is meant by &lt;b&gt;authorization&lt;/b&gt; surprisingly! Although there maybe some subtle re-wording later.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;3. A standard &lt;a href="http://www.ism-community.org/files/folders/identityandprivacyrelease/default.aspx"&gt;Privacy Policy&lt;/a&gt; has been uploaded&lt;/b&gt; into the download space. Although this is just one of several. I plan to add additional policies that include &amp;#39;opt-in&amp;#39; and &amp;#39;opt-out&amp;#39; as defaults. Check out the &lt;a href="http://www.ism-community.org/forums/t/551.aspx"&gt;privacy forum &lt;/a&gt;for more information on what I mean here.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;4. There are 2 new threads looking at privacy legislation&lt;/b&gt;. The first &lt;a href="http://www.ism-community.org/forums/t/581.aspx"&gt;thread &lt;/a&gt;on adoption of the DPA in the EU on a local country level, the second &lt;a href="http://www.ism-community.org/forums/t/582.aspx"&gt;thread &lt;/a&gt;in on differences in legislation between the EU and the US. Each of these threads are looking pretty empty right now, so please go in there and start posting!&lt;br /&gt;&lt;/p&gt;&lt;p&gt;This is all for now, have fun posting and look forward to meeting you there!&lt;/p&gt;&lt;p&gt;Karen&amp;nbsp;&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=937" width="1" height="1"&gt;</description></item><item><title>Weekly update - privacy policy donated and definition for AuthN</title><link>http://www.ism-community.org/blogs/identityandprivacyblog/archive/2007/05/13/weekly-update-privacy-policy-donated-and-definition-for-authn.aspx</link><pubDate>Sun, 13 May 2007 16:40:00 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:905</guid><dc:creator>klo</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;We have a standard privacy policy donated by SourceClear. Check out the following http://www.ism-community.org/forums/t/551.aspx.&lt;/p&gt;&lt;p&gt;And there have been some lively discussions concerning definitions on identity, identification, authentication and authorization that apart from being lively have been fun and got some of us thinking...&lt;br /&gt;&lt;/p&gt;&lt;p&gt;We have a glossary definition for AuthN: http://www.ism-community.org/blogs/commonsblog/archive/2007/05/10/it-s-all-about-semantics.aspx&lt;/p&gt;&lt;p&gt;We are ready to roll out more.... although my apologies the last week that I haven&amp;#39;t been so active as I have had other committments.&lt;/p&gt;&lt;p&gt;Looking forward to another fun week!&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Karen&amp;nbsp;&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=905" width="1" height="1"&gt;</description></item><item><title>Another week...</title><link>http://www.ism-community.org/blogs/trainingandawarenessblog/archive/2007/05/13/another-week.aspx</link><pubDate>Sun, 13 May 2007 10:58:00 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:903</guid><dc:creator>tsmith</dc:creator><slash:comments>2</slash:comments><description>&lt;p&gt;Another top ten review... This time, the entire ISM top ten is being put into one overall document and into a bit more of a logical flow. I&amp;#39;m awating the esteemed members of the Steering Commitee to review and we will re-publish. Each individual item in the top ten has been downloaded a few times but solid feedback has been somewhat lacking - hoping this will change that.&lt;/p&gt;
&lt;p&gt;I am trying to get together a list of Security Awareness online courses. Is anyone working on any open source versions at the moment that are SCORM compliant? Would love to se somethign we could start to use maybe to take the top ten to the next level - having an online distribution model.&lt;/p&gt;
&lt;p&gt;Please assist!&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=903" width="1" height="1"&gt;</description></item><item><title>Policies and Standards -Week Deux</title><link>http://www.ism-community.org/blogs/policiesandstandardsblog/archive/2007/05/10/policies-and-standards-week-deux.aspx</link><pubDate>Thu, 10 May 2007 14:33:14 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:899</guid><dc:creator>mcurphey</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;The summer is finally here in the South of France. Its 86 today and from this point until the end of Sept it should be sunny and hot.&lt;/p&gt; &lt;p&gt;We had a few offers for some policy documents but sadly most had strings attached that meant they would not be suitable for everyone to consume so it looks like well just need to start from the ground up. &lt;/p&gt; &lt;p&gt;My plan is as follows.&lt;/p&gt; &lt;p&gt;This week: review a stack of links I have to whitepapers, blogs etc&amp;nbsp;about policies and standards and summarize them along with some notes. From this we can then create a plan that solves the problems and develop a list of tasks. &lt;/p&gt; &lt;p&gt;Anyone volunteer to help me write some content?&lt;/p&gt; &lt;p&gt;Jason made some interesting points about writing policies and cited his blog. &lt;/p&gt; &lt;p&gt;&lt;a href="http://infosecalways.com/2007/05/08/roles-responsibilities-in-policy/"&gt;http://infosecalways.com/2007/05/08/roles-responsibilities-in-policy/&lt;/a&gt;&lt;/p&gt; &lt;p&gt;From the comments in his blog it seems there is some interest in defining roles and responsibilities in Information Security. &lt;/p&gt; &lt;p&gt;I have so much going on I forgot to post this and ask for a volunteer to get this idea off the ground. How about if we created an org chart of a few typical security departs (reporting up through the CIO, through legal and compliance, via another route etc) and defined a set of roles and responsibilities for the actors. I think this would be a valuable resource for many reasons. Any volunteers? I have a user persona template form which to start and I&amp;#39;ll buy you as much beer as you can drink in a 24 hour sitting!&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=899" width="1" height="1"&gt;</description></item><item><title>It's all About Semantics</title><link>http://www.ism-community.org/blogs/commonsblog/archive/2007/05/10/it-s-all-about-semantics.aspx</link><pubDate>Thu, 10 May 2007 14:18:32 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:895</guid><dc:creator>mcurphey</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;As you can see from the rolling titles on the front page of the ISM Community just getting agreement on simple terminology is not as simple as it could be. Thanks to some great contributions from ebreece, jason and dave we are starting to roll. &lt;/p&gt; &lt;p&gt;I have added a definition block to the Glossary working document that looks like this and when we are happy with the first set of definitions I will add them.&lt;/p&gt; &lt;p&gt;&lt;b&gt;Title&lt;/b&gt; &lt;h5&gt;Authentication&lt;/h5&gt; &lt;p&gt;&lt;b&gt;Definition&lt;/b&gt; &lt;p&gt;The process of determining whether someone or something is, in fact, who or what it has declared itself to be. &lt;p&gt;&lt;b&gt;Examples&lt;/b&gt; &lt;p&gt;User KLO is authenticated as she was able to provide her secret pass code. &lt;p&gt;I checked the dollar bill&amp;nbsp;to&amp;nbsp;authenticate that is was indeed real. &lt;p&gt;&lt;b&gt;References&lt;/b&gt; &lt;p&gt;Insert them here &lt;p&gt;&lt;b&gt;Notes&lt;/b&gt; &lt;p&gt;Insert them here &lt;p&gt;&lt;b&gt;ISM Community Discussion URL&lt;/b&gt; &lt;p&gt;&lt;a href="http://www.ism-community.org/forums/t/542.aspx"&gt;http://www.ism-community.org/forums/t/542.aspx&lt;/a&gt; &lt;p&gt;As always if anyone would like to volunteer to own updating the glossary and can commit to doing so in a regular basis please drop myself or Paul Zedeck an email. &lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=895" width="1" height="1"&gt;</description></item><item><title>What you don't see can't hurt you, my son</title><link>http://www.ism-community.org/blogs/trainingandawarenessblog/archive/2007/05/06/what-you-don-t-see-can-t-hurt-you-my-son.aspx</link><pubDate>Sat, 05 May 2007 14:31:40 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:835</guid><dc:creator>tsmith</dc:creator><slash:comments>6</slash:comments><description>&lt;p&gt;Things are a little strange in the State of Queensland. We are on level 5 water restrictions meaning no car washing (suits me), 4 minute showers (thats 3.45 minutes over what I have anyway), I can&amp;#39;t even put any more water in the swimming pool so you can see this is pretty serious. 100kms North of Brisbane lies the Sunshine Coast area - these boys have their dams at 80% capacity! Laughing and joking as they water their car, garden, flush the toilet 20 times - they probably even water the water that&amp;#39;s how much water they have. &lt;/p&gt; &lt;p&gt;In a week where our esteemed prime minister, Little Johnny Howard told us to all pray for rain, you might think that perhaps we have lost a few marbles in this very very brown land. I&amp;#39;ve just found out that there&amp;#39;s a national rain day &lt;a title="national rain day" href="http://www.nationalrainday.com/"&gt;here in Canberra on the 8th May.&lt;/a&gt;&amp;nbsp;Mr McCallum of Melbourne, said National Rain Day involved people standing on the earth barefoot and being led through a guided short visualisation at 11am on the day. “The process is a prayer of attracting rain through raising collective consciousness, as opposed to attracting the lackof rain by acknowledging it,” Mr McCallum said. “This is a powerful tool that everyone can use to create positive change. Many successful&amp;nbsp;sports people and ancient races use visualisation.” &lt;/p&gt; &lt;p&gt;Well, I can visualise a lot of press for McCallum, a speaker and meditation leader of 17 years who helps people create the life they want to live with the law of attraction and quantum physics. “When you hold a thought with emotion for one minute and 11 seconds, you will attract that which you think about. Well, I vote we get some sponsorship at the ISM Community and get Mr McCallum around to a few of our cleints to give him the ultimate test - not easy stuff like making it rain but writing a series of policies and procedures that people read, get and follow. I can visualise Mr McCallum a beaten man and I further see me madly visualising for my alloted one minute and 11 seconds and still not understanding why any one would support Tottenham Hotspur.&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=835" width="1" height="1"&gt;</description></item><item><title>The Top Ten is Complete</title><link>http://www.ism-community.org/blogs/trainingandawarenessblog/archive/2007/05/04/the-top-ten-is-complete.aspx</link><pubDate>Fri, 04 May 2007 12:10:43 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:826</guid><dc:creator>tsmith</dc:creator><slash:comments>2</slash:comments><description>&lt;p&gt;The ISM Top Ten is now complete! All ten now uploaded for everyone&amp;#39;s pleasure. Please check them out and give me your opinions.&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=826" width="1" height="1"&gt;</description></item><item><title>Welcome to the Identity and Privacy Blog!</title><link>http://www.ism-community.org/blogs/identityandprivacyblog/archive/2007/05/03/welcome-to-the-identity-and-privacy-blog.aspx</link><pubDate>Thu, 03 May 2007 10:28:00 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:808</guid><dc:creator>klo</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Welcome to the Identity and Privacy Focus Area.&amp;nbsp;I plan to blog
post here weekly with&amp;nbsp;news of&amp;nbsp;progress for those that don&amp;#39;t want to
delve into the forums / mailing lists. You can subscribe to these
updates via RSS at the side bar.&lt;/p&gt; &lt;p&gt;A lot of research needs to be done: firstly we need to see what is
going on already in this space. Typical examples are Liberty Alliance,
Higgins and Eclipse, and FRAME projects, all in the space of identity
and privacy. We need to understand these projects what they offer and
how they differentiate. What can we take from there and re-use? What
can we offer in addition to help clear the confusion that we all feel
when presented with yet another ideal solution to resolve the identity management nightmare. In addition we need to dive into the changing landscape of identity and privacy, keep abreast of what&amp;#39;s happening out there, as it affects every one of us. Check out my &lt;a href="http://mysecuritybox.blogspot.com/"&gt;blog &lt;/a&gt;to have an idea of what I mean here.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;1. The first project I have started as part of this Focus Area is &lt;span style="font-weight:bold;text-decoration:underline;"&gt;to agree on definitions for common terminology used in the identity and privacy space&lt;/span&gt;. For example when we talk about &lt;i&gt;identity&lt;/i&gt; what are we talking about? A couple of threads have been started in the forum area for identity and privacy to encourage discussion. Take a look... the idea is not that there is a right or wrong answer, the point is that when we are in the future discussing&lt;i&gt; identity&lt;/i&gt;, &lt;i&gt;authentication &lt;/i&gt;or &lt;i&gt;authorization &lt;/i&gt;or whatever, that we all are talking the same language. A tip: when we are discussing these fundamentals, try and get back to basics. The result from these discussions will provide the foundation for all subsequent discussions and projects. &lt;/p&gt;&lt;p&gt;2. A parallel project will be &lt;span style="font-weight:bold;"&gt;t&lt;span style="text-decoration:underline;"&gt;he creation of a standard Privacy Policy&lt;/span&gt;&lt;/span&gt;. I have not started this yet. &lt;span style="text-decoration:underline;"&gt;If you would like to volunteer to help please post to the &lt;a&gt;identity and privacy forum&lt;/a&gt;&lt;/span&gt;. I will start a thread later today. Of course it goes without
saying that if any company would like to donate their policies and
standards or anyone has anything which would make a solid base then
please contact me. We can make sure there is nothing sensitive and all identifying data is stripped out before they are placed online. &lt;/p&gt;&lt;p&gt;Welcome and look forward to meeting you online!&lt;/p&gt;&lt;p&gt;Karen&amp;nbsp;&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=808" width="1" height="1"&gt;</description></item><item><title>State of Risk Management in ISM-Community</title><link>http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/05/02/state-of-risk-management-in-ism-community.aspx</link><pubDate>Wed, 02 May 2007 15:50:00 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:793</guid><dc:creator>rybolov</dc:creator><slash:comments>3</slash:comments><description>&lt;p&gt;ISM-Community was originally created and the steering committee formed in Fall of 2006.&amp;nbsp; During that time, one of our key activities was to come up with a list of projects that were worthwhile, and that list became somewhat of a direction for us to move in.&lt;/p&gt;&lt;p&gt;One of the first priorities has been to develop a risk assessment methodology.&amp;nbsp; Me being of a US Government mindset, my first question was &amp;quot;What&amp;#39;s wrong with NIST SP 800-30?&amp;quot;&amp;nbsp; Well, 800-30 is a good start, but like I&amp;#39;ve said before, there are some things such as templates, examples, and suggestions that NIST can&amp;#39;t give you because then all the auditors take it as gospel/doctrine instead of implementation technique.&amp;nbsp; We want to bridge that gap.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;We traveled down the RA Methodology road over the past 6 months or so and due to a handful of factors, mostly time constraints (find me a security person worth anything at all and they&amp;#39;re up to their eyeballs in projects) and a couple of false paths we&amp;#39;ve gone down (FAIR was a good one, but we had a philosophy/licensing issue), the project has stuttered.&lt;/p&gt;&lt;p&gt;What remains to be done?&amp;nbsp; Well, this is my roadmap for the near- to moderate-term future:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Finish off the remaining RA Methodology sections&lt;/li&gt;&lt;li&gt;Creation of artifacts/templates/examples to support the methodology&lt;br /&gt; &lt;/li&gt;&lt;li&gt;Field-testing to validate the methodology&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;At some point, the artifacts will suffer from scope-creep as they become a set of ISM .&amp;nbsp; That&amp;#39;s OK.&lt;br /&gt;&lt;p&gt;In true NPO form, I&amp;#39;m asking for volunteers who can help out.&amp;nbsp; The first step is to look at the &lt;a href="http://www.ism-community.org/files/folders/riskmanagementrelease/entry743.aspx" target="_blank"&gt;existing incarnation of the RA Methodology&lt;/a&gt; and make recommendations.&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=793" width="1" height="1"&gt;</description></item><item><title>One more to go</title><link>http://www.ism-community.org/blogs/trainingandawarenessblog/archive/2007/05/02/one-more-to-go.aspx</link><pubDate>Wed, 02 May 2007 12:23:00 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:792</guid><dc:creator>tsmith</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Took some advice and have blasted 9 of the ISM Top Ten up for review. The 10th and final one, &amp;#39;Make it easy for people to do the right thing (Polices and Proceudres Matter) will follow real soon.&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=792" width="1" height="1"&gt;</description></item><item><title>First of the ISM Top Ten - Use, Adopt and Align to Industry Standards</title><link>http://www.ism-community.org/blogs/trainingandawarenessblog/archive/2007/05/02/first-of-the-ism-top-ten-use-adopt-and-align-to-industry-standards.aspx</link><pubDate>Wed, 02 May 2007 01:26:00 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:761</guid><dc:creator>tsmith</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;I&amp;#39;ve just published the first guidline out of the ISM Top Ten as referenced in my previous blog post. Look forward to some feedback, in the meantime, I&amp;#39;ll keep them coming on a weekly basis!&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;TS.&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=761" width="1" height="1"&gt;</description></item></channel></rss>