<?xml version="1.0" encoding="UTF-8"?><!-- generator="WordPress/abc" -->
<rss version="0.92">
<channel>
	<title>Alchemy Security</title>
	<link>http://alchemysecurity.com</link>
	<description>Dedicated to the art and science of securing private information</description>
	<lastBuildDate>Tue, 26 Jan 2010 20:35:12 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>Peter Schawacker to present on Agile SOC at UNIX Users Association of Southern California- LA Chapter</title>
		<description><![CDATA[<p>Peter Schawacker, Principal Consultant SOC Services will be presenting at the <a href="http://bolthole.com/uuala/">UNIX Users Association of Southern California- LA Chapter</a> on May 6 to discuss Agile SOC practices used to build world-class security operations centers.</p>
]]></description>
		<link>http://alchemysecurity.com/scrum/peter-schawacker-to-present-on-agile-soc-at-unix-users-association-of-southern-california-la-chapter/</link>
			</item>
	<item>
		<title>Damon Cortesi to Present At Seattle Chapter of National Information Security Group (NAISG)</title>
		<description><![CDATA[<p>Damon Cortesi, Principal Consultant at Alchemy Security will present on common security failures associated with Social Media Web Applications such as Twitter, Facebook, and other online web sites at the <a href="http://seattle.naisg.org/">Seattle chapter</a> of NAISG.</p>
]]></description>
		<link>http://alchemysecurity.com/events/damon-cortesi-to-present-at-seattle-chapter-of-national-information-security-group-naisg/</link>
			</item>
	<item>
		<title>Peter Schawacker Presents on Agile Security at UNIX Users Association of Southern California</title>
		<description><![CDATA[<p>Peter Schawacker, Principal Consultant for our SOC Consulting group <a href="http://www.uuasc.org/p1001.html">discusses</a> how Agile Security techniques can be used to better secure environments at the <a href="http://www.uuasc.org/">UNIX Users Association of Southern California</a>. </p>
]]></description>
		<link>http://alchemysecurity.com/scrum/peter-schawacker-presents-on-agile-security-at-unix-users-association-of-southern-california/</link>
			</item>
	<item>
		<title>Damon Cortesi to Present at Security BSides Las Vegas</title>
		<description><![CDATA[<p>Principal Consultant Damon Cortesi will be presenting at <a href="http://www.securitybsides.com/BSidesLasVegas ">Security BSides Las Vegas</a>. Damon&#8217;s talk will cover security considerations within social networking sites such as Twitter, as well as web-application related challenges organizations face in the web 2.0 space.</p>
]]></description>
		<link>http://alchemysecurity.com/events/damon-cortesi-to-present-at-security-bsides-las-vegas/</link>
			</item>
	<item>
		<title>PCI Compliance Becomes Scorecard for CSOs</title>
		<description><![CDATA[<p>Companies recertifying for the second or third year of PCI compliance are having a rough go of things as of late. A combination of the latest clarifications within the revised PCI DSS standard, along with the recent scoring matrix that compels assessors to ensure they have done a thorough job as part of the review, have caught an unfortunate number [...]]]></description>
		<link>http://alchemysecurity.com/general-security/pci-compliance-becomes-scorecard-for-csos/</link>
			</item>
	<item>
		<title>The Way Forward for Information Security</title>
		<description><![CDATA[<p>Every system has within it the limitation that it cannot exist unto itself.  The big problems of Information Security will remain intractable as long as industry participants continue to focus inward.  </p>
<p>For the past year or so, I have noticed that, at the same time that security technologies are reaching a certain degree of maturity, security projects remain [...]]]></description>
		<link>http://alchemysecurity.com/general-security/the-way-forward-for-information-security/</link>
			</item>
	<item>
		<title>Twitter Confidential Information Compromised Via Weak Password</title>
		<description><![CDATA[<p>As <a href="http://bits.blogs.nytimes.com/2009/07/15/hacker-exposes-private-twitter-documents/">noted</a>, poor password management trumps strong security technology every time. Any bets on how long before google *requires* strong passwords? Both are victims, both share blame. A side note about this hack is that it highlights the trust relationships (and residual risk) that business partnerships impart upon each other.</p>
]]></description>
		<link>http://alchemysecurity.com/general-security/twitter-confidential-information-compromised-via-weak-password/</link>
			</item>
	<item>
		<title>Preparing for your PCI-DSS v1.2 assessment</title>
		<description><![CDATA[<p>A number of <a href="/pci/pci-compliance-becomes-scorecard-for-csos/">dynamics are at work </a> that have made attaining PCI compliance a more difficult proposition over previous years. The guidance assessors are receiving from the PCI Council is that evidence must be provided that demonstrates your Infosec program is in place and functioning as designed. Expect to respond to requests for multiple change records that cover [...]]]></description>
		<link>http://alchemysecurity.com/pci/preparing-for-your-pci-dss-v1-2-assessment/</link>
			</item>
	<item>
		<title>Verizon Business releases annual data breach investigation report</title>
		<description><![CDATA[<p>Each year Verizon Business <a href="http://www.verizonbusiness.com/resources/security/reports/2009_databreach_rp.pdf">publishes</a> aggregate data breach information from forensics investigations the company has performed. This report yielded a number of interesting data points including: </p>

The majority of data breaches were caused by external sources. 74% emanated from external sources, 32% were linked to business partners, and only 20% percent were caused by insiders. This statistic flips on [...]]]></description>
		<link>http://alchemysecurity.com/general-security/verizon-business-releases-annual-data-breach-investigation-report/</link>
			</item>
	<item>
		<title>SSN numbers can be predicted</title>
		<description><![CDATA[SSNs can be predicted]]></description>
		<link>http://alchemysecurity.com/privacy/ssn-numbers-can-be-predicted/</link>
			</item>
</channel>
</rss>
