<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Art of Information Security &#187; Podcast</title>
	<atom:link href="http://artofinfosec.com/category/podcast/feed/" rel="self" type="application/rss+xml" />
	<link>http://artofinfosec.com</link>
	<description>Random Insights on Protecting Data, Privacy, and Digital Infrastructure</description>
	<lastBuildDate>Thu, 21 Jan 2010 17:03:49 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Art of Information Security Episode 002: GTAGs and Safe Harbors</title>
		<link>http://artofinfosec.com/4/aois-002-gtags-and-safe-harbors/</link>
		<comments>http://artofinfosec.com/4/aois-002-gtags-and-safe-harbors/#comments</comments>
		<pubDate>Sat, 29 Dec 2007 05:09:20 +0000</pubDate>
		<dc:creator>Erik</dc:creator>
				<category><![CDATA[News and Info]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[GTAG]]></category>
		<category><![CDATA[NIST]]></category>

		<guid isPermaLink="false">http://artofinfosec.com/4/art-of-information-security-episode-002-gtags-and-safe-harbors/</guid>
		<description><![CDATA[Art of Info Sec 002: GTAGs and Safe Harbors
GTAG&#8217;s
The Institute of Internal Auditors has been releasing a white paper series on issues related to IT Risk Management and Information Security. The paper&#8217;s are titled as GTAGs, which is an acronym for Global Technology Audit Guidance. The project is very ambitious, trying to break down major [...]<p><br/><br/><a href="http://artofinfosec.com/4/aois-002-gtags-and-safe-harbors/">Art of Information Security Episode 002: GTAGs and Safe Harbors</a></p>
]]></description>
			<content:encoded><![CDATA[<p><a href="http://artofinfosec.com/wp-content/uploads/2007/12/aois-002-gtags-and-safe-harbors.m4a" title="Art of Info Sec 002: GTAGs and Safe Harbors">Art of Info Sec 002: GTAGs and Safe Harbors</a></p>
<p><strong>GTAG&#8217;s</strong></p>
<p><a href="http://www.theiia.org">The Institute of Internal Auditors</a> has been releasing a white paper series on issues related to IT Risk Management and Information Security. The paper&#8217;s are titled as GTAGs, which is an acronym for <a href="http://www.theiia.org/guidance/technology/gtag/" title="GTAG Landing Page">Global Technology Audit Guidance</a>. The project is very ambitious, trying to break down major technical topics, the IT risks associated with them, and the controls that are available in a concise format accessible to senior risk executives.</p>
<p>Of the nine that have been released to date, several caught my eye. Here are the ones I would like to highlight:</p>
<ul>
<li>Auditing Application Controls</li>
<li>Change and Patch Management Controls</li>
<li>Identity and Access Management</li>
<li>Information Technology Outsourcing</li>
<li>Managing and Auditing Privacy Risks</li>
<li>Managing and Auditing IT Vulnerabilities</li>
</ul>
<p>You can find the library of papers at  <a href="http://www.theiia.org/guidance/technology/gtag/" target="_blank">The IIA&#8217;s GTAG portal</a>. New materials are released regularly.</p>
<p><strong>In Other News&#8230; </strong></p>
<p>Earlier this month I participated in a Webinar titled <a href="http://http://www.venafi.com/replays/webinar120507/" title="Webinar Link">&#8220;Getting More Encryption for Less&#8221;</a>. At the end of the call there were a few interesting questions during the Q and A session, one of which I wanted to recap here&#8230;</p>
<p>Question: Will Federal Privacy Regulations include Cryptography Standards for &#8220;Safe Harbors&#8221; ?</p>
<ul>
<li>Discuss what a Safe Harbor is, using California Security Breach Information Act (SB-1386) as an example</li>
<li>Introduce <a href="http://csrc.nist.gov/">NIST</a>, <a href="http://http://en.wikipedia.org/wiki/Federal_Information_Processing_Standard" target="_blank">FIPS</a>, and  <a href="http://en.wikipedia.org/wiki/FIPS_140-2" target="_blank">FIPS 140-2</a></li>
</ul>
<p>Cheers, Erik</p>
<p><br/><br/><a href="http://artofinfosec.com/4/aois-002-gtags-and-safe-harbors/">Art of Information Security Episode 002: GTAGs and Safe Harbors</a></p>
]]></content:encoded>
			<wfw:commentRss>http://artofinfosec.com/4/aois-002-gtags-and-safe-harbors/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://artofinfosec.com/wp-content/uploads/2007/12/aois-002-gtags-and-safe-harbors.m4a" length="7202485" type="audio/mpeg" />
		</item>
		<item>
		<title>Art of Info Sec 001: Quick Business Case</title>
		<link>http://artofinfosec.com/22/art-of-info-sec-001-quick-business-case/</link>
		<comments>http://artofinfosec.com/22/art-of-info-sec-001-quick-business-case/#comments</comments>
		<pubDate>Tue, 13 Nov 2007 01:56:59 +0000</pubDate>
		<dc:creator>Erik</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Professional Development]]></category>
		<category><![CDATA[Business Case]]></category>
		<category><![CDATA[Erik Heidt]]></category>
		<category><![CDATA[RSA Conference]]></category>

		<guid isPermaLink="false">http://artofinfosec.com/?p=22</guid>
		<description><![CDATA[Art of Info Sec 001: Quick Business Case

Here it is !
This is the first podcast in the series I have planned. This is a slidecast of the Quick Business Case presentation which I recently delivered at RSA Europe (and similar to the presentation I delivered at RSA USA back in February).
As this is my first [...]<p><br/><br/><a href="http://artofinfosec.com/22/art-of-info-sec-001-quick-business-case/">Art of Info Sec 001: Quick Business Case</a></p>
]]></description>
			<content:encoded><![CDATA[<p><a title="Art of Info Sec 001: Quick Business Case" href="http://artofinfosec.com/wp-content/uploads/2007/12/aois-001-quick-business-case.mov">Art of Info Sec 001: Quick Business Case<br />
</a></p>
<p>Here it is !</p>
<p>This is the first podcast in the series I have planned. This is a slidecast of the Quick Business Case presentation which I recently delivered at RSA Europe (and similar to the presentation I delivered at RSA USA back in February).</p>
<p>As this is my first foray into this media &#8211; combining audio podcasting with presentation slides &#8211; please accept a few production glitches and provide feedback.</p>
<p>Cheers,</p>
<p>Erik Heidt</p>
<p><br/><br/><a href="http://artofinfosec.com/22/art-of-info-sec-001-quick-business-case/">Art of Info Sec 001: Quick Business Case</a></p>
]]></content:encoded>
			<wfw:commentRss>http://artofinfosec.com/22/art-of-info-sec-001-quick-business-case/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://artofinfosec.com/wp-content/uploads/2007/12/aois-001-quick-business-case.mov" length="22446553" type="video/quicktime" />
		</item>
	</channel>
</rss>
