<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Alchemy Security</title>
	<atom:link href="http://alchemysecurity.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://alchemysecurity.com</link>
	<description>Dedicated to the art and science of securing private information</description>
	<lastBuildDate>Wed, 31 Aug 2011 14:10:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>Alchemy Security Awarded ArcSight VAR Certification</title>
		<link>http://alchemysecurity.com/press-release/alchemy-security-awarded-arcsight-var-certification/</link>
		<comments>http://alchemysecurity.com/press-release/alchemy-security-awarded-arcsight-var-certification/#comments</comments>
		<pubDate>Tue, 07 Sep 2010 13:23:33 +0000</pubDate>
		<dc:creator>Joe Bonnell</dc:creator>
				<category><![CDATA[Press Release]]></category>

		<guid isPermaLink="false">http://alchemysecurity.com/?p=623</guid>
		<description><![CDATA[<p>SOC Services and SIEM Specialist’s Experience and Deep Knowledge Recognized with
Gold Partner Status in ArcSight Connections Channel Program
</p>
<p>DENVER, CO &#8211; September 7, 2010 &#8211; Alchemy Security, well-known information security risk management pioneers, today announced a Value Added Reseller (VAR) agreement with <a href="http://www.arcsight.com">ArcSight</a>, Inc. (NASDAQ: ARST), a leading global provider of cybersecurity and compliance solutions. As a Gold Partner in [...]]]></description>
			<content:encoded><![CDATA[<p><strong>SOC Services and SIEM Specialist’s Experience and Deep Knowledge Recognized with<br />
Gold Partner Status in ArcSight Connections Channel Program<br />
</strong></p>
<p>DENVER, CO &#8211; September 7, 2010 &#8211; Alchemy Security, well-known information security risk management pioneers, today announced a Value Added Reseller (VAR) agreement with <a href="http://www.arcsight.com">ArcSight</a>, Inc. (NASDAQ: ARST), a leading global provider of cybersecurity and compliance solutions. As a Gold Partner in the newly structured ArcSight Connections Channel Program, Alchemy Security expands its partnership with ArcSight to offer mutual clients extensive expertise in solving strategic security challenges and implementing long lasting security programs. </p>
<p>“Alchemy Security offers strategic and enduring security solutions to our joint customers,” said Chris Triolo, vice president of solutions for ArcSight. “The company has worked with demanding international organizations and the team executes with efficiency and precision. We are proud to have Alchemy Security represent our brand in the marketplace.”</p>
<p>As a Gold Partner in the ArcSight Connections Channel Program, Alchemy Security joins a premier tier of partners recognized for their strong commitment to driving ArcSight business.  ArcSight extends dedicated business plan development support and higher financial incentives, as well as other program benefits to its Gold partners. </p>
<p>As an industry innovator, Alchemy Security is recognized for its broad competency in security information and event management (SIEM). Alchemy Security developed the world&#8217;s first Agile SOC model to be used by SMEs (Small Medium Enterprises) and global organizations alike to build robust security operations centers, custom tailored to meet the client&#8217;s specific organizational needs. This methodology has now been adopted by the ArcSight SOC services team. </p>
<p>“The exceptional flexibility and holistic approach to information security that ArcSight allows for is a competitive differentiator for us.  It lets our consultants deliver a balanced approach to business, compliance, security intelligence, and IT operations,” said Joe Bonnell, Alchemy Security, CEO. “Increasing our role in bringing ArcSight to more enterprises is exciting.  Our goal is to ensure organizations are no longer flying blind so that information security practitioners can prioritize limited resources in the most sensible manner possible.”</p>
<p>“Information security intelligence is an extremely complex problem. We have used every major SIEM solution on the market and nobody else comes close to ArcSight, particularly when you add compliance requirements from mandates like PCI and HIPAA / HITECH. ArcSight has the only solution that can actually deliver the goods,” adds Peter Schawacker, Managing Principal for SOC Services, Alchemy Security.</p>
<p>Alchemy Security provides comprehensive security and risk management services and solutions that include:</p>
<li> SOC Express™ </li>
<ul>
<li>establishes fully functioning Security Operations Centers within 90 days </li>
</ul>
<li> Co-managed SIEM support </li>
<ul>
<li>enables clients to utilize virtual ArcSight expertise in a cost-effective on-demand fashion </li>
</ul>
<li> Application/Environmental Log Analysis </li>
<ul>
<li>educates clients as to gaps in policy vs. operating environment, estimate EPS and other considerations required for ArcSight architecture &#038; deployment </li>
</ul>
<li>Security intelligence staffing and training </li>
<ul>
<li>ensures smooth transition project initiation and ongoing operations </li>
</ul>
<li>Security consulting</li>
<ul>
<li>extends client security teams with niche information security expertise </ul>
</li>
<p>About Alchemy Security:<br />
Alchemy Security provides sophisticated, strategic and enduring information security solutions for compliance, security intelligence, and business imperative initiatives. A holistic and cost effective approach to IT asset protection delivers the right balance of support, service and consultation to global retail, banking, technology, and health care organizations.  Alchemy Security is an ArcSight Gold partner, preferred vendor, and Value Added Reseller.  For more information please visit www.alchemysecurity.com</p>
<p>###</p>
<p>For more information:<br />
Heidi Groshelle<br />
Groshelle Communications<br />
415.307.1380<br />
heidi@groshelle.com</p>
]]></content:encoded>
			<wfw:commentRss>http://alchemysecurity.com/press-release/alchemy-security-awarded-arcsight-var-certification/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Alchemy Security Announces Hosting of &#8220;Mile High Security&#8221; B-Sides Event</title>
		<link>http://alchemysecurity.com/events/alchemy-security-announces-hosting-of-mile-high-security-bsides-event-2/</link>
		<comments>http://alchemysecurity.com/events/alchemy-security-announces-hosting-of-mile-high-security-bsides-event-2/#comments</comments>
		<pubDate>Thu, 22 Apr 2010 22:08:20 +0000</pubDate>
		<dc:creator>Joe Bonnell</dc:creator>
				<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://alchemysecurity.com/?p=595</guid>
		<description><![CDATA[<p>Alchemy Security is proud to announce that we&#8217;ll be hosting a Security B-Sides &#8220;Mile High Security&#8221; event at our corporate headquarters here in Denver on June 18th. To learn more or to attend the event you can check out the details <a href="http://www.securitybsides.com/BSidesDenver">here</a>.</p>
]]></description>
			<content:encoded><![CDATA[<p>Alchemy Security is proud to announce that we&#8217;ll be hosting a Security B-Sides &#8220;Mile High Security&#8221; event at our corporate headquarters here in Denver on June 18th. To learn more or to attend the event you can check out the details <a href="http://www.securitybsides.com/BSidesDenver">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://alchemysecurity.com/events/alchemy-security-announces-hosting-of-mile-high-security-bsides-event-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Peter Schawacker to Present at ISSA Ottawa Chapter</title>
		<link>http://alchemysecurity.com/soc/peter-schawacker-to-present-at-issa-ottawa-chapter/</link>
		<comments>http://alchemysecurity.com/soc/peter-schawacker-to-present-at-issa-ottawa-chapter/#comments</comments>
		<pubDate>Thu, 08 Apr 2010 03:30:13 +0000</pubDate>
		<dc:creator>Joe Bonnell</dc:creator>
				<category><![CDATA[Agile Security]]></category>
		<category><![CDATA[Security Operations]]></category>

		<guid isPermaLink="false">http://alchemysecurity.com/?p=566</guid>
		<description><![CDATA[<p>Mark your calendars. Peter Schawacker, Managing Principal SOC Services, will be sharing his latest thoughts on the subjects of Agile Security &#038; SOC at the Ottawa Chapter of ISSA <a href="http://www.issa-ottawa.ca/">April 29th</a>. </p>
]]></description>
			<content:encoded><![CDATA[<p>Mark your calendars. Peter Schawacker, Managing Principal SOC Services, will be sharing his latest thoughts on the subjects of Agile Security &#038; SOC at the Ottawa Chapter of ISSA <a href="http://www.issa-ottawa.ca/">April 29th</a>. </p>
]]></content:encoded>
			<wfw:commentRss>http://alchemysecurity.com/soc/peter-schawacker-to-present-at-issa-ottawa-chapter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Peter Schawacker to present on Agile SOC at UNIX Users Association of Southern California- LA Chapter</title>
		<link>http://alchemysecurity.com/scrum/peter-schawacker-to-present-on-agile-soc-at-unix-users-association-of-southern-california-la-chapter/</link>
		<comments>http://alchemysecurity.com/scrum/peter-schawacker-to-present-on-agile-soc-at-unix-users-association-of-southern-california-la-chapter/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 20:15:33 +0000</pubDate>
		<dc:creator>Joe Bonnell</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Scrum]]></category>
		<category><![CDATA[Security Operations]]></category>

		<guid isPermaLink="false">http://alchemysecurity.com/?p=561</guid>
		<description><![CDATA[<p>Peter Schawacker, Principal Consultant SOC Services will be presenting at the <a href="http://bolthole.com/uuala/">UNIX Users Association of Southern California- LA Chapter</a> on May 6 to discuss Agile SOC practices used to build world-class security operations centers.</p>
]]></description>
			<content:encoded><![CDATA[<p>Peter Schawacker, Principal Consultant SOC Services will be presenting at the <a href="http://bolthole.com/uuala/">UNIX Users Association of Southern California- LA Chapter</a> on May 6 to discuss Agile SOC practices used to build world-class security operations centers.</p>
]]></content:encoded>
			<wfw:commentRss>http://alchemysecurity.com/scrum/peter-schawacker-to-present-on-agile-soc-at-unix-users-association-of-southern-california-la-chapter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Damon Cortesi to Present At Seattle Chapter of National Information Security Group (NAISG)</title>
		<link>http://alchemysecurity.com/events/damon-cortesi-to-present-at-seattle-chapter-of-national-information-security-group-naisg/</link>
		<comments>http://alchemysecurity.com/events/damon-cortesi-to-present-at-seattle-chapter-of-national-information-security-group-naisg/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 20:07:43 +0000</pubDate>
		<dc:creator>Joe Bonnell</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Web Application Security]]></category>

		<guid isPermaLink="false">http://alchemysecurity.com/?p=559</guid>
		<description><![CDATA[<p>Damon Cortesi, Principal Consultant at Alchemy Security will present on common security failures associated with Social Media Web Applications such as Twitter, Facebook, and other online web sites at the <a href="http://seattle.naisg.org/">Seattle chapter</a> of NAISG.</p>
]]></description>
			<content:encoded><![CDATA[<p>Damon Cortesi, Principal Consultant at Alchemy Security will present on common security failures associated with Social Media Web Applications such as Twitter, Facebook, and other online web sites at the <a href="http://seattle.naisg.org/">Seattle chapter</a> of NAISG.</p>
]]></content:encoded>
			<wfw:commentRss>http://alchemysecurity.com/events/damon-cortesi-to-present-at-seattle-chapter-of-national-information-security-group-naisg/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Peter Schawacker Presents on Agile Security at UNIX Users Association of Southern California</title>
		<link>http://alchemysecurity.com/scrum/peter-schawacker-presents-on-agile-security-at-unix-users-association-of-southern-california/</link>
		<comments>http://alchemysecurity.com/scrum/peter-schawacker-presents-on-agile-security-at-unix-users-association-of-southern-california/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 19:57:57 +0000</pubDate>
		<dc:creator>Joe Bonnell</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Scrum]]></category>
		<category><![CDATA[Security Operations]]></category>

		<guid isPermaLink="false">http://alchemysecurity.com/?p=554</guid>
		<description><![CDATA[<p>Peter Schawacker, Principal Consultant for our SOC Consulting group <a href="http://www.uuasc.org/p1001.html">discusses</a> how Agile Security techniques can be used to better secure environments at the <a href="http://www.uuasc.org/">UNIX Users Association of Southern California</a>. </p>
]]></description>
			<content:encoded><![CDATA[<p>Peter Schawacker, Principal Consultant for our SOC Consulting group <a href="http://www.uuasc.org/p1001.html">discusses</a> how Agile Security techniques can be used to better secure environments at the <a href="http://www.uuasc.org/">UNIX Users Association of Southern California</a>. </p>
]]></content:encoded>
			<wfw:commentRss>http://alchemysecurity.com/scrum/peter-schawacker-presents-on-agile-security-at-unix-users-association-of-southern-california/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Damon Cortesi to Present at Security BSides Las Vegas</title>
		<link>http://alchemysecurity.com/events/damon-cortesi-to-present-at-security-bsides-las-vegas/</link>
		<comments>http://alchemysecurity.com/events/damon-cortesi-to-present-at-security-bsides-las-vegas/#comments</comments>
		<pubDate>Tue, 21 Jul 2009 16:04:17 +0000</pubDate>
		<dc:creator>Joe Bonnell</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Social Networking]]></category>

		<guid isPermaLink="false">http://alchemysecurity.com/?p=462</guid>
		<description><![CDATA[<p>Principal Consultant Damon Cortesi will be presenting at <a href="http://www.securitybsides.com/BSidesLasVegas ">Security BSides Las Vegas</a>. Damon&#8217;s talk will cover security considerations within social networking sites such as Twitter, as well as web-application related challenges organizations face in the web 2.0 space.</p>
]]></description>
			<content:encoded><![CDATA[<p>Principal Consultant Damon Cortesi will be presenting at <a href="http://www.securitybsides.com/BSidesLasVegas ">Security BSides Las Vegas</a>. Damon&#8217;s talk will cover security considerations within social networking sites such as Twitter, as well as web-application related challenges organizations face in the web 2.0 space.</p>
]]></content:encoded>
			<wfw:commentRss>http://alchemysecurity.com/events/damon-cortesi-to-present-at-security-bsides-las-vegas/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI Compliance Becomes Scorecard for CSOs</title>
		<link>http://alchemysecurity.com/general-security/pci-compliance-becomes-scorecard-for-csos/</link>
		<comments>http://alchemysecurity.com/general-security/pci-compliance-becomes-scorecard-for-csos/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 21:44:01 +0000</pubDate>
		<dc:creator>Joe Bonnell</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[General Security]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://alchemysecurity.com/?p=436</guid>
		<description><![CDATA[<p>Companies recertifying for the second or third year of PCI compliance are having a rough go of things as of late. A combination of the latest clarifications within the revised PCI DSS standard, along with the recent scoring matrix that compels assessors to ensure they have done a thorough job as part of the review, have caught an unfortunate number [...]]]></description>
			<content:encoded><![CDATA[<p>Companies recertifying for the second or third year of PCI compliance are having a rough go of things as of late. A combination of the latest clarifications within the revised PCI DSS standard, along with the recent scoring matrix that compels assessors to ensure they have done a thorough job as part of the review, have caught an unfortunate number of CISOs flat footed. Anyone who thinks they are about to go through a &#8220;check box exercise&#8221; could find themselves with small to large remediation efforts that are forcing many to miss their renewal dates.  These challenges are being exacerbated by the fact that assessors are getting better at their job, and security budgets are getting hit like everything else. These dynamics are generating some painful realities for those chartered to maintain compliance to this very thorough and rigorous standard. Unfortunately for most CISOs, the subtleties of <em>why</em> they are missing compliance dates and risk potential fines and/or change of compliance status for service providers, is lost on executive leadership. Based upon some things we&#8217;ve observed over the years, leadership changes aren&#8217;t necessarily a bad thing, but it doesn&#8217;t serve anyone&#8217;s interest to throw the baby out with the bathwater. </p>
<p><strong>What is a CEO to do?</strong><br />
Meanwhile, CEOs are struggling to drive the business forward in a historically difficult operating environment, and often view the Infosec team as being an impediment rather than an enabler to the business. An ill tempered CEO who thinks his CISO isn&#8217;t getting the job done does not bode well for our industry as playing a game of musical chairs merely slows down security initiatives, thus defeating what were certainly good intentions. What makes this decision more difficult is that the CEO has little tangible insight as to whether organizational risk is trending up or down. Graph charts depicting a downtrend of critical findings from Nessus scans surely don&#8217;t tell a CEO much about how much risk has been mitigated. Fact is, based upon our observations there are very few CISOs who even know <em>what</em> they are protecting outside of PCI related assets.</p>
<p><strong>Getting beyond the PCI scorecard</strong><br />
Within the current operating landscape, it’s incumbent upon CISOs (or equivalent in responsibility), to position within the organization that compliance is a shared problem between all parts of the business including IT operations, Security Operations, Human Resources, Legal, and Executive Leadership. It should further be made clear what exactly each part of the business is responsible for implementing, and hold all accountable. Finally, bringing effective communications supported by meaningful metrics to the subject are critical to help communicate throughout the leadership chain that residual risk is being appropriately managed and mitigated. </p>
<p>As for your next PCI assessment, unless you&#8217;ve consulted with your QSA to discuss changes made within the standard, it is wise to set expectations with varying levels of leadership that there will likely be findings that weren’t issues within previous years and to anticipate resource requirements accordingly.</p>
]]></content:encoded>
			<wfw:commentRss>http://alchemysecurity.com/general-security/pci-compliance-becomes-scorecard-for-csos/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Way Forward for Information Security</title>
		<link>http://alchemysecurity.com/general-security/the-way-forward-for-information-security/</link>
		<comments>http://alchemysecurity.com/general-security/the-way-forward-for-information-security/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 16:55:12 +0000</pubDate>
		<dc:creator>Peter Schawacker</dc:creator>
				<category><![CDATA[General Security]]></category>
		<category><![CDATA[Security Operations]]></category>

		<guid isPermaLink="false">http://74.50.54.154/?p=422</guid>
		<description><![CDATA[<p>Every system has within it the limitation that it cannot exist unto itself.  The big problems of Information Security will remain intractable as long as industry participants continue to focus inward.  </p>
<p>For the past year or so, I have noticed that, at the same time that security technologies are reaching a certain degree of maturity, security projects remain [...]]]></description>
			<content:encoded><![CDATA[<p>Every system has within it the limitation that it cannot exist unto itself.  The big problems of Information Security will remain intractable as long as industry participants continue to focus inward.  </p>
<p>For the past year or so, I have noticed that, at the same time that security technologies are reaching a certain degree of maturity, security projects remain highly prone to failure.  Information Security seems  to have struck a ceiling in its development.  The tools that we have at our disposal – authentication, monitoring, etc. – seem to be adequate when properly implemented.  But proper implementation does not happen enough of the time.</p>
<p>Some time ago, I started taking excursions into the world of Project Management.  Certain colleagues of mine had encouraged me to look into PMI’s PMP certification and so I did.  What I found astounded me.  No one that I have encountered in the Project Management world (I visit lots of meetings PMI and Agile professionals) had a clue about Information Security.  My knee-jerk reaction was to deride the PM’s for their naïveté.  But then I recalled conversations with InfoSec people about Project Management.  Their attitude was not merely one of ignorance, but of distain for the Project Management as a whole!  Let me qualify this statement by saying that there exist a few InfoSec experts who appreciate the value of Project Management, and even a few who actually know how to manage projects.  But generally, my conversations and research in both worlds, PM and InfoSec reveal that these two communities are almost entirely unaware of each other.</p>
<p>The tools now exist; the craftsmen are capable and ready to build great security.  But the plans elude them.  Worse yet, the craftsmen usually insist that planning is to be avoided.  If we, as a profession are to advance our effectiveness throughout the industry , we must extend our understanding into fields of knowledge that will allow us to create those plans.</p>
<p>In the days and weeks ahead, I will present one   way forward for Information Security, from dependence upon tools and individual experts, toward managing teams that achieve results that exceed what has been left to individuals.</p>
]]></content:encoded>
			<wfw:commentRss>http://alchemysecurity.com/general-security/the-way-forward-for-information-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Twitter Confidential Information Compromised Via Weak Password</title>
		<link>http://alchemysecurity.com/general-security/twitter-confidential-information-compromised-via-weak-password/</link>
		<comments>http://alchemysecurity.com/general-security/twitter-confidential-information-compromised-via-weak-password/#comments</comments>
		<pubDate>Fri, 17 Jul 2009 05:15:24 +0000</pubDate>
		<dc:creator>Joe Bonnell</dc:creator>
				<category><![CDATA[General Security]]></category>
		<category><![CDATA[Headdesk]]></category>

		<guid isPermaLink="false">http://74.50.54.154/?p=398</guid>
		<description><![CDATA[<p>As <a href="http://bits.blogs.nytimes.com/2009/07/15/hacker-exposes-private-twitter-documents/">noted</a>, poor password management trumps strong security technology every time. Any bets on how long before google *requires* strong passwords? Both are victims, both share blame. A side note about this hack is that it highlights the trust relationships (and residual risk) that business partnerships impart upon each other.</p>
]]></description>
			<content:encoded><![CDATA[<p>As <a href="http://bits.blogs.nytimes.com/2009/07/15/hacker-exposes-private-twitter-documents/">noted</a>, poor password management trumps strong security technology every time. Any bets on how long before google *requires* strong passwords? Both are victims, both share blame. A side note about this hack is that it highlights the trust relationships (and residual risk) that business partnerships impart upon each other.</p>
]]></content:encoded>
			<wfw:commentRss>http://alchemysecurity.com/general-security/twitter-confidential-information-compromised-via-weak-password/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

