<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>PxI</title>
	<atom:link href="http://piipci.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://piipci.wordpress.com</link>
	<description></description>
	<lastBuildDate>Wed, 22 Jul 2009 12:23:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='piipci.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>PxI</title>
		<link>http://piipci.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://piipci.wordpress.com/osd.xml" title="PxI" />
	<atom:link rel='hub' href='http://piipci.wordpress.com/?pushpress=hub'/>
		<item>
		<title>What&#8217;s your secret question redux</title>
		<link>http://piipci.wordpress.com/2009/07/22/whats-your-secret-question-redux/</link>
		<comments>http://piipci.wordpress.com/2009/07/22/whats-your-secret-question-redux/#comments</comments>
		<pubDate>Wed, 22 Jul 2009 12:23:16 +0000</pubDate>
		<dc:creator>ekleintop</dc:creator>
				<category><![CDATA[Data Security/PII]]></category>

		<guid isPermaLink="false">http://piipci.wordpress.com/?p=151</guid>
		<description><![CDATA[That recent Twitter hack relied on, guess what, resetting a password using secret questions.  Read the details here.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=piipci.wordpress.com&amp;blog=7297559&amp;post=151&amp;subd=piipci&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>That recent Twitter hack relied on, guess what,  resetting a password using secret questions.  <a href="http://www.computerworld.com/s/article/9135661/Report_Hacker_broke_into_Twitter_e_mail_with_help_from_Hotmail?taxonomyId=17">Read the details here</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/piipci.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/piipci.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/piipci.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/piipci.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/piipci.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/piipci.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/piipci.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/piipci.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/piipci.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/piipci.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/piipci.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/piipci.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/piipci.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/piipci.wordpress.com/151/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=piipci.wordpress.com&amp;blog=7297559&amp;post=151&amp;subd=piipci&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://piipci.wordpress.com/2009/07/22/whats-your-secret-question-redux/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e703e3571a130f7acab94e6c7bb171ff?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ekleintop</media:title>
		</media:content>
	</item>
		<item>
		<title>Nevada mandates PCI-DSS</title>
		<link>http://piipci.wordpress.com/2009/06/24/nevada-mandates-pci-dss/</link>
		<comments>http://piipci.wordpress.com/2009/06/24/nevada-mandates-pci-dss/#comments</comments>
		<pubDate>Wed, 24 Jun 2009 12:35:40 +0000</pubDate>
		<dc:creator>ekleintop</dc:creator>
				<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://piipci.wordpress.com/?p=148</guid>
		<description><![CDATA[Nevada is the first state to pass legislation that requires companies doing business in the state processing credit cards to comply with the PCI-DSS.  Suprising they beat Cailfornia to the punch, but I suspect other states will follow suit in short order.  Read here.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=piipci.wordpress.com&amp;blog=7297559&amp;post=148&amp;subd=piipci&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Nevada is the first state to pass legislation that requires companies doing business in the state processing credit cards to comply with the PCI-DSS.  Suprising they beat Cailfornia to the punch, but I suspect other states will follow suit in short order.  <a href="http://pcianswers.com/2009/06/22/nevada-mandates-pci-dss/">Read here.</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/piipci.wordpress.com/148/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/piipci.wordpress.com/148/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/piipci.wordpress.com/148/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/piipci.wordpress.com/148/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/piipci.wordpress.com/148/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/piipci.wordpress.com/148/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/piipci.wordpress.com/148/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/piipci.wordpress.com/148/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/piipci.wordpress.com/148/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/piipci.wordpress.com/148/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/piipci.wordpress.com/148/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/piipci.wordpress.com/148/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/piipci.wordpress.com/148/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/piipci.wordpress.com/148/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=piipci.wordpress.com&amp;blog=7297559&amp;post=148&amp;subd=piipci&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://piipci.wordpress.com/2009/06/24/nevada-mandates-pci-dss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e703e3571a130f7acab94e6c7bb171ff?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ekleintop</media:title>
		</media:content>
	</item>
		<item>
		<title>MasterCard &#8211; On-site assessments extended to level 2 merchants</title>
		<link>http://piipci.wordpress.com/2009/06/19/mastercard-on-site-assessments-extended-to-level-2-merchants/</link>
		<comments>http://piipci.wordpress.com/2009/06/19/mastercard-on-site-assessments-extended-to-level-2-merchants/#comments</comments>
		<pubDate>Fri, 19 Jun 2009 13:11:53 +0000</pubDate>
		<dc:creator>ekleintop</dc:creator>
				<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://piipci.wordpress.com/?p=144</guid>
		<description><![CDATA[Looks like as far as self assessments are concerned MC thinks the fox hasn&#8217;t been guarding the hen house very well.  Starting in Dec 2010 level 2 merchants will have to undergo on-site security assessments ala level 1 merchants.  Even though this is a MC only requirement the effect will be felt by all level [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=piipci.wordpress.com&amp;blog=7297559&amp;post=144&amp;subd=piipci&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Looks like as far as self assessments are concerned MC thinks the fox hasn&#8217;t been guarding the hen house very well.  Starting in Dec 2010 level 2 merchants will have to undergo on-site security assessments ala level 1 merchants.  Even though this is a MC only requirement the effect will be felt by all level 2 merchants.  <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=security&amp;articleId=9134572&amp;taxonomyId=17&amp;intsrc=kc_top">Read here.</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/piipci.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/piipci.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/piipci.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/piipci.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/piipci.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/piipci.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/piipci.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/piipci.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/piipci.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/piipci.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/piipci.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/piipci.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/piipci.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/piipci.wordpress.com/144/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=piipci.wordpress.com&amp;blog=7297559&amp;post=144&amp;subd=piipci&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://piipci.wordpress.com/2009/06/19/mastercard-on-site-assessments-extended-to-level-2-merchants/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e703e3571a130f7acab94e6c7bb171ff?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ekleintop</media:title>
		</media:content>
	</item>
		<item>
		<title>Mid week challange</title>
		<link>http://piipci.wordpress.com/2009/06/10/mid-week-challange/</link>
		<comments>http://piipci.wordpress.com/2009/06/10/mid-week-challange/#comments</comments>
		<pubDate>Wed, 10 Jun 2009 14:19:20 +0000</pubDate>
		<dc:creator>ekleintop</dc:creator>
				<category><![CDATA[Data Security/PII]]></category>

		<guid isPermaLink="false">http://piipci.wordpress.com/?p=138</guid>
		<description><![CDATA[Here is a little challenge, maybe not so little, to get your security juices flowing again.  It&#8217;s some security 101 stuff, that low hanging fruit that can close the door on a possible breach.  When was the last time you bounced your user accounts (Active directory, &#8216;nix, remote access) up against an active employee listing?  [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=piipci.wordpress.com&amp;blog=7297559&amp;post=138&amp;subd=piipci&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Here is a little challenge, maybe not so little, to get your security juices flowing again.  It&#8217;s some security 101 stuff, that low hanging fruit that can close the door on a possible breach.  When was the last time you bounced your user accounts (Active directory, &#8216;nix, remote access) up against an active employee listing?  Against a list of active contractors/temps?  Do you even have such lists?  My experience has been it either never has been done, has been a while, or the lists do not exist.  The <a href="http://www.verizonbusiness.com/resources/security/reports/2009_databreach_rp.pdf">2009 Verizon Data Breach Report</a> noted several instances of breaches that were a direct result of active user accounts being used by recently terminated employees.  This is simple stuff that gets overlooked but goes a long way in improving your security posture.</p>
<p>If you are not a script writer like me take a look at <a href="http://www.somarsoft.com/">DumpSec from the SystemTools folks.</a> It&#8217;s a great little free app that will dump your Active Directory accounts (sorry &#8216;nix folks but you are better script writers than the Windows crew, right?) into a file for import into your favorite spreadsheet/DB.  Add your employee/contractor/temp lists, shake and stir, and viola!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/piipci.wordpress.com/138/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/piipci.wordpress.com/138/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/piipci.wordpress.com/138/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/piipci.wordpress.com/138/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/piipci.wordpress.com/138/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/piipci.wordpress.com/138/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/piipci.wordpress.com/138/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/piipci.wordpress.com/138/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/piipci.wordpress.com/138/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/piipci.wordpress.com/138/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/piipci.wordpress.com/138/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/piipci.wordpress.com/138/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/piipci.wordpress.com/138/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/piipci.wordpress.com/138/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=piipci.wordpress.com&amp;blog=7297559&amp;post=138&amp;subd=piipci&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://piipci.wordpress.com/2009/06/10/mid-week-challange/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e703e3571a130f7acab94e6c7bb171ff?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ekleintop</media:title>
		</media:content>
	</item>
		<item>
		<title>Overworked government workers flub..</title>
		<link>http://piipci.wordpress.com/2009/06/03/overworked-government-workers-flub/</link>
		<comments>http://piipci.wordpress.com/2009/06/03/overworked-government-workers-flub/#comments</comments>
		<pubDate>Wed, 03 Jun 2009 20:57:19 +0000</pubDate>
		<dc:creator>ekleintop</dc:creator>
				<category><![CDATA[Musings]]></category>

		<guid isPermaLink="false">http://piipci.wordpress.com/?p=134</guid>
		<description><![CDATA[It&#8217;s no big story that a government office has manged to release sensitive information again.   It&#8217;s the excuse in the second half of the article I find disturbing.  In a statement from a Government Printing Office (GPO) spokesman they suggest the error was due to the &#8220;sheer volume&#8221; of documents the GPO processes.  Read [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=piipci.wordpress.com&amp;blog=7297559&amp;post=134&amp;subd=piipci&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s no big story that a government office has manged to release sensitive information again.   It&#8217;s the excuse in the second half of <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=Security&amp;articleId=9133921&amp;taxonomyId=17&amp;pageNumber=2">the article</a> I find disturbing.  In a statement from a Government Printing Office (GPO) spokesman they suggest the error was due to the &#8220;sheer volume&#8221; of documents the GPO processes.  <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=security&amp;articleId=9133921&amp;taxonomyId=17&amp;intsrc=kc_top">Read entire article here.</a></p>
<p>&#8220;On average, the GPO produces &#8220;approximately 160 House documents each Congress,&#8221; the statement said. During the 109th Congress, the GPO produced 157 reports, while in the 110th Congress, 161 reports were published, the statement said.&#8221;</p>
<p>That&#8217;s 160 WHOLE documents?  Am I missing something?  That works out to less than 1 document a day, assuming they are all processed during the session (if my math is correct .65 per day is the result of 157 docs /242 days).  I&#8217;ll email <a href="http://dsc.discovery.com/fansites/dirtyjobs/dirtyjobs.html">Mike over at Dirty Jobs</a> to see if he is up for the challenge.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/piipci.wordpress.com/134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/piipci.wordpress.com/134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/piipci.wordpress.com/134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/piipci.wordpress.com/134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/piipci.wordpress.com/134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/piipci.wordpress.com/134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/piipci.wordpress.com/134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/piipci.wordpress.com/134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/piipci.wordpress.com/134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/piipci.wordpress.com/134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/piipci.wordpress.com/134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/piipci.wordpress.com/134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/piipci.wordpress.com/134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/piipci.wordpress.com/134/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=piipci.wordpress.com&amp;blog=7297559&amp;post=134&amp;subd=piipci&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://piipci.wordpress.com/2009/06/03/overworked-government-workers-flub/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e703e3571a130f7acab94e6c7bb171ff?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ekleintop</media:title>
		</media:content>
	</item>
		<item>
		<title>What&#8217;s your secret question?</title>
		<link>http://piipci.wordpress.com/2009/05/19/whats-your-secret-question/</link>
		<comments>http://piipci.wordpress.com/2009/05/19/whats-your-secret-question/#comments</comments>
		<pubDate>Tue, 19 May 2009 12:45:37 +0000</pubDate>
		<dc:creator>ekleintop</dc:creator>
				<category><![CDATA[Data Security/PII]]></category>

		<guid isPermaLink="false">http://piipci.wordpress.com/?p=128</guid>
		<description><![CDATA[Passwords are our front doors to all sorts of sensitive data &#38; information.  So what&#8217;s your Mother&#8217;s maiden name?  Read here. Schecter&#8217;s paper. (PDF link) Schneier&#8217;s take back in &#8217;05.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=piipci.wordpress.com&amp;blog=7297559&amp;post=128&amp;subd=piipci&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Passwords are our front doors to all sorts of sensitive data &amp; information.  So what&#8217;s your Mother&#8217;s maiden name?  <a href="http://www.technologyreview.com/web/22662/page1/">Read here.</a></p>
<p><a href="http://research.microsoft.com/apps/pubs/default.aspx?id=79594">Schecter&#8217;s paper</a>. (<a href="http://research.microsoft.com/pubs/79594/oakland09.pdf">PDF link</a>)</p>
<p><a href="http://www.schneier.com/blog/archives/2005/02/the_curse_of_th.html">Schneier&#8217;s take back in &#8217;05.</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/piipci.wordpress.com/128/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/piipci.wordpress.com/128/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/piipci.wordpress.com/128/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/piipci.wordpress.com/128/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/piipci.wordpress.com/128/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/piipci.wordpress.com/128/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/piipci.wordpress.com/128/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/piipci.wordpress.com/128/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/piipci.wordpress.com/128/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/piipci.wordpress.com/128/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/piipci.wordpress.com/128/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/piipci.wordpress.com/128/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/piipci.wordpress.com/128/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/piipci.wordpress.com/128/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=piipci.wordpress.com&amp;blog=7297559&amp;post=128&amp;subd=piipci&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://piipci.wordpress.com/2009/05/19/whats-your-secret-question/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e703e3571a130f7acab94e6c7bb171ff?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ekleintop</media:title>
		</media:content>
	</item>
		<item>
		<title>Two cost of breach studies</title>
		<link>http://piipci.wordpress.com/2009/05/15/two-cost-of-breach-studies/</link>
		<comments>http://piipci.wordpress.com/2009/05/15/two-cost-of-breach-studies/#comments</comments>
		<pubDate>Fri, 15 May 2009 19:47:40 +0000</pubDate>
		<dc:creator>ekleintop</dc:creator>
				<category><![CDATA[Data Security/PII]]></category>

		<guid isPermaLink="false">http://piipci.wordpress.com/?p=123</guid>
		<description><![CDATA[For your weekend reading, here are some studies from the Ponemon Institute on the costs of data breaches. The Fourth Annual Cost of a Data Breach PDF link. A related report is Ponemon&#8217;s 2008 Annual Cost of a Data Breach Study. Get it here (free registration required). The Cost of a Lost Laptop PDF link.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=piipci.wordpress.com&amp;blog=7297559&amp;post=123&amp;subd=piipci&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>For your weekend reading, here are some studies from the <a href="http://www.ponemon.org/index.php">Ponemon Institute</a> on the costs of data breaches.</p>
<p>The Fourth Annual Cost of a Data Breach <strong></strong><a href="http://www.ponemon.org/local/upload/fckjail/generalcontent/18/file/2008-2009%20US%20Cost%20of%20Data%20Breach%20Report%20Final.pdf">PDF link.</a> A related report is Ponemon&#8217;s 2008 Annual Cost of a Data Breach Study. <a href="http://www.encryptionreports.com/">Get it here (free registration required)</a>.</p>
<p>The Cost of a Lost Laptop <strong></strong><a href="http://www.ponemon.org/local/upload/fckjail/generalcontent/18/file/Cost%20of%20a%20Lost%20Laptop%20White%20Paper%20Final%203.pdf">PDF link.</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/piipci.wordpress.com/123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/piipci.wordpress.com/123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/piipci.wordpress.com/123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/piipci.wordpress.com/123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/piipci.wordpress.com/123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/piipci.wordpress.com/123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/piipci.wordpress.com/123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/piipci.wordpress.com/123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/piipci.wordpress.com/123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/piipci.wordpress.com/123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/piipci.wordpress.com/123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/piipci.wordpress.com/123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/piipci.wordpress.com/123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/piipci.wordpress.com/123/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=piipci.wordpress.com&amp;blog=7297559&amp;post=123&amp;subd=piipci&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://piipci.wordpress.com/2009/05/15/two-cost-of-breach-studies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e703e3571a130f7acab94e6c7bb171ff?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ekleintop</media:title>
		</media:content>
	</item>
		<item>
		<title>Inside a data leak audit</title>
		<link>http://piipci.wordpress.com/2009/05/12/inside-a-data-leak-audit/</link>
		<comments>http://piipci.wordpress.com/2009/05/12/inside-a-data-leak-audit/#comments</comments>
		<pubDate>Tue, 12 May 2009 14:40:57 +0000</pubDate>
		<dc:creator>ekleintop</dc:creator>
				<category><![CDATA[Data Security/PII]]></category>

		<guid isPermaLink="false">http://piipci.wordpress.com/?p=118</guid>
		<description><![CDATA[E-mail can be a big source of potential data exposures.  Read here. I like the advice that you have to take the encryption decision out of the senders hands, they will inevitably forget to encrypt something sensitive.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=piipci.wordpress.com&amp;blog=7297559&amp;post=118&amp;subd=piipci&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>E-mail can be a big source of potential data exposures.  <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=security&amp;articleId=9132827&amp;taxonomyId=17&amp;intsrc=kc_top">Read here.</a></p>
<p>I like the advice that you have to take the encryption decision out of the senders hands, they will inevitably forget to encrypt something sensitive.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/piipci.wordpress.com/118/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/piipci.wordpress.com/118/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/piipci.wordpress.com/118/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/piipci.wordpress.com/118/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/piipci.wordpress.com/118/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/piipci.wordpress.com/118/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/piipci.wordpress.com/118/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/piipci.wordpress.com/118/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/piipci.wordpress.com/118/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/piipci.wordpress.com/118/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/piipci.wordpress.com/118/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/piipci.wordpress.com/118/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/piipci.wordpress.com/118/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/piipci.wordpress.com/118/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=piipci.wordpress.com&amp;blog=7297559&amp;post=118&amp;subd=piipci&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://piipci.wordpress.com/2009/05/12/inside-a-data-leak-audit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e703e3571a130f7acab94e6c7bb171ff?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ekleintop</media:title>
		</media:content>
	</item>
		<item>
		<title>How to destroy digitally stored information</title>
		<link>http://piipci.wordpress.com/2009/05/06/how-to-destroy-digitally-stored-information/</link>
		<comments>http://piipci.wordpress.com/2009/05/06/how-to-destroy-digitally-stored-information/#comments</comments>
		<pubDate>Wed, 06 May 2009 15:14:24 +0000</pubDate>
		<dc:creator>ekleintop</dc:creator>
				<category><![CDATA[Data Security/PII]]></category>

		<guid isPermaLink="false">http://piipci.wordpress.com/?p=114</guid>
		<description><![CDATA[PCI, Federal, and many state PII regulations require the proper destruction of data when an organization is done with it.  Here is an overview from CSO on data destruction methods.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=piipci.wordpress.com&amp;blog=7297559&amp;post=114&amp;subd=piipci&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>PCI, Federal, and many state PII regulations require the proper destruction of data when an organization is done with it.  <a href="http://www.csoonline.com/article/491786/Why_Information_Must_Be_Destroyed_Part_Two">Here is an overview</a> from CSO on data destruction methods.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/piipci.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/piipci.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/piipci.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/piipci.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/piipci.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/piipci.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/piipci.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/piipci.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/piipci.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/piipci.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/piipci.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/piipci.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/piipci.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/piipci.wordpress.com/114/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=piipci.wordpress.com&amp;blog=7297559&amp;post=114&amp;subd=piipci&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://piipci.wordpress.com/2009/05/06/how-to-destroy-digitally-stored-information/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e703e3571a130f7acab94e6c7bb171ff?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ekleintop</media:title>
		</media:content>
	</item>
		<item>
		<title>PCI’s Grading System Is Failing</title>
		<link>http://piipci.wordpress.com/2009/04/30/pci%e2%80%99s-grading-system-is-failing/</link>
		<comments>http://piipci.wordpress.com/2009/04/30/pci%e2%80%99s-grading-system-is-failing/#comments</comments>
		<pubDate>Thu, 30 Apr 2009 13:24:29 +0000</pubDate>
		<dc:creator>ekleintop</dc:creator>
				<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://piipci.wordpress.com/?p=110</guid>
		<description><![CDATA[The author discusses the concept of bringing risk analysis into the compliance grading process.  Sounds very sensible to me.  I am of a mind that for most large organizations being 100% compliant with PCI is a fleeting task.  I would rather ensure that high risk exposures are thoroughly identified, mitigated, and monitored than attempt to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=piipci.wordpress.com&amp;blog=7297559&amp;post=110&amp;subd=piipci&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The author discusses the concept of bringing risk analysis into the compliance grading process.  Sounds very sensible to me.  I am of a mind that for most large organizations being 100% compliant with PCI is a fleeting task.  I would rather ensure that high risk exposures are thoroughly identified, mitigated, and monitored than attempt to do a less than adequate job across the board to achieve an appearance of 100% compliance.  <a href="http://www.storefrontbacktalk.com/securityfraud/pcis-grading-system-is-failing/">Read here.</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/piipci.wordpress.com/110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/piipci.wordpress.com/110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/piipci.wordpress.com/110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/piipci.wordpress.com/110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/piipci.wordpress.com/110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/piipci.wordpress.com/110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/piipci.wordpress.com/110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/piipci.wordpress.com/110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/piipci.wordpress.com/110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/piipci.wordpress.com/110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/piipci.wordpress.com/110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/piipci.wordpress.com/110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/piipci.wordpress.com/110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/piipci.wordpress.com/110/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=piipci.wordpress.com&amp;blog=7297559&amp;post=110&amp;subd=piipci&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://piipci.wordpress.com/2009/04/30/pci%e2%80%99s-grading-system-is-failing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e703e3571a130f7acab94e6c7bb171ff?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ekleintop</media:title>
		</media:content>
	</item>
	</channel>
</rss>
