<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Jabablog &#187; Vulnerabilities</title>
	<atom:link href="http://blog.jabawoki.com/tag/vulnerabilities/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.jabawoki.com</link>
	<description>Nothing to see here, Move along...</description>
	<lastBuildDate>Fri, 05 Mar 2010 13:17:04 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<!-- podcast_generator="podPress/8.8" - maintenance_release="8.8.4" -->
		<copyright>2006-2010 </copyright>
		<managingEditor>jay@jabawoki.com (Jabawoki)</managingEditor>
		<webMaster>jay@jabawoki.com (Jabawoki)</webMaster>
		<category>music</category>
		<ttl>1440</ttl>
		<itunes:keywords>House,electro,hard,mix,dj,hardcore,hardstyle,trance, progressive, house, music, hardcore, handbag, happy, tech, deep, security, infosec, itsec, jay, abbott, jay abbott, jabawoki</itunes:keywords>
		<itunes:subtitle>Jabawoki Presents: </itunes:subtitle>
		<itunes:summary>House Music Mixes, everything from electro to hard, from 2000 onwards, courtesy of Jabawoki.</itunes:summary>
		<itunes:author>Jabawoki</itunes:author>
		<itunes:category text="Music"/>
<itunes:category text="Games &amp; Hobbies">
	<itunes:category text="Hobbies"/>
</itunes:category>
<itunes:category text="Technology"/>
		<itunes:owner>
			<itunes:name>Jabawoki</itunes:name>
			<itunes:email>jay@jabawoki.com</itunes:email>
		</itunes:owner>
		<itunes:block>No</itunes:block>
		<itunes:explicit>no</itunes:explicit>
		<itunes:image href="http://blog.jabawoki.com/wp-content/plugins/podpress/images/SubSide-Large.jpg" />
		<image>
			<url>http://blog.jabawoki.com/wp-content/plugins/podpress/images/SubSide-small.jpg</url>
			<title>Jabablog</title>
			<link>http://blog.jabawoki.com</link>
			<width>144</width>
			<height>144</height>
		</image>
		<item>
		<title>The Asymmetry of Security</title>
		<link>http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/</link>
		<comments>http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/#comments</comments>
		<pubDate>Wed, 26 Nov 2008 19:24:14 +0000</pubDate>
		<dc:creator>Jabs</dc:creator>
				<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[IISP]]></category>
		<category><![CDATA[thoughts]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://blog.jabawoki.com/?p=1692</guid>
		<description><![CDATA[Personally, I think this is one of the most important concepts of today. Its simple enough to grasp and illustrates the point very well.
Consider these examples:

From an effort perspective, the effort required to secure a system is significantly less than that required to exploit it.
From a cost perspective, it is less expensive to prevent a [...]]]></description>
			<content:encoded><![CDATA[<p>Personally, I think this is one of the most important concepts of today. Its simple enough to grasp and illustrates the point very well.<span id="more-1692"></span></p>
<p>Consider these examples:</p>
<ol>
<li>From an effort perspective, the effort required to secure a system is significantly less than that required to exploit it.</li>
<li>From a cost perspective, it is less expensive to prevent a serious data breach than it is to clean up and recover from one.</li>
</ol>
<p>Point 1 above was illustrated very clearly to me on the <a href="http://blog.jabawoki.com/2008/08/01/iisp-top-gun-event-manchester-30-june-2008/" target="_self">IISP&#8217;s TopGun event</a> I attended recently, and is a scenario that you have to step back from to fully appreciate. Eg. If you have a smallish network, with most modern services such as web, email, mobile, databases, websites etc, then the effort to secure that is quite mammoth. You have to consider the perimeter, the information, how its stored and used, what services are on offer and the impacts etc. Then you have to consider every conceivable vulnerability, patching strategies and stay on top and at least up to speed with the curve of change. All of these efforts equate to a team of people, but all it takes to break in, is 1 person with a brain, motive, and a few freely available tools.</p>
<p>Point 2 of course, was illustrated very well by a <a href="http://www.vontu.com/downloads/ponemon_07_thankyou.asp" target="_blank">study </a>by the <a href="http://www.ponemon.org/" target="_blank">Pnemon Instutue LLC</a> in conjunction with <a href="http://www.pgp.com/" target="_blank">PGP</a> and <a href="http://www.vontu.com" target="_blank">Vontu (Symantec)</a>, this study evaluated the true cost of a breach of data security and considered factors such as direct and indirect costs, and has trended the data over the last few years with enlightening results.</p>
<p>Despite both of these points clearly illustrating that the best way to tackle the security conundrum is head on and proactively, those of us in the industry will all surely testify that getting the right backing, funding, and often, even the right audience with the business, is still a hard task. From my perspective, I will keep on trying, and keep on flying the flag in the hope that one day reality sets in and my job / life gets easier!</p>
<div class='wp_likes' id='wp_likes_post-1692'><a class='like' href="javascript:wp_likes.like(1692);" title='' ><img src="http://blog.jabawoki.com/wp-content/plugins/wp-likes/images/like.png" alt='' border='0'/>Like</a><span class='text'></span>
<div class='unlike'><a href="javascript:wp_likes.unlike(1692);">Unlike</a></div>
</div>
<div class="lightsocial_container"><a class="lightsocial_a" href="http://digg.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F&amp;title=The+Asymmetry+of+Security"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.reddit.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F&amp;title=The+Asymmetry+of+Security"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/reddit.png" alt="Reddit This" title="Reddit This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F&amp;title=The+Asymmetry+of+Security"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://buzz.yahoo.com/buzz?targetUrl=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F&amp;headline=The+Asymmetry+of+Security"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/yahoo_buzz.png" alt="Buzz This" title="Buzz This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dzone.com/links/add.html?title=The+Asymmetry+of+Security&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dzone.png" alt="Vote on DZone" title="Vote on DZone" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.facebook.com/sharer.php?t=The+Asymmetry+of+Security&amp;u=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://delicious.com/save?title=The+Asymmetry+of+Security&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dotnetkicks.com/kick/?title=The+Asymmetry+of+Security&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetkicks.png" alt="Kick It on DotNetKicks.com" title="Kick It on DotNetKicks.com" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://dotnetshoutout.com/Submit?title=The+Asymmetry+of+Security&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetshoutout.png" alt="Shout it" title="Shout it" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F&amp;title=The+Asymmetry+of+Security&amp;summary=&amp;source="><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.technorati.com/faves?add=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://twitter.com/home?status=Reading+http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F11%2F26%2Fthe-asymmetry-of-security%2F&amp;title=The+Asymmetry+of+Security"><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/google_buzz.png" alt="Google Buzz (aka. Google Reader)" title="Google Buzz (aka. Google Reader)" /></a>&nbsp;&nbsp;</div>
	Tags: <a href="http://blog.jabawoki.com/tag/iisp/" title="IISP" rel="tag">IISP</a>, <a href="http://blog.jabawoki.com/tag/infosec/" title="InfoSec" rel="tag">InfoSec</a>, <a href="http://blog.jabawoki.com/tag/thoughts/" title="thoughts" rel="tag">thoughts</a>, <a href="http://blog.jabawoki.com/tag/vulnerabilities/" title="Vulnerabilities" rel="tag">Vulnerabilities</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.jabawoki.com/2008/06/30/iisp-topgun/" title="IISP Top Gun event, Manchester, 30 June 2008 (June 30, 2008)">IISP Top Gun event, Manchester, 30 June 2008</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/18/anything-that-can-be-engineered-by-mankind/" title="Anything that can be engineered by mankind&#8230;.. (November 18, 2008)">Anything that can be engineered by mankind&#8230;..</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/18/acme-supercomputing-inc-roadrunner-beware/" title="ACME Supercomputing Inc &#8211; Roadrunner Beware (November 18, 2008)">ACME Supercomputing Inc &#8211; Roadrunner Beware</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/02/snort-rocks/" title="Snort Rocks! (July 2, 2008)">Snort Rocks!</a> (2)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/19/security-as-a-career/" title="Security as a Career (November 19, 2008)">Security as a Career</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
