<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet href="/css/rss20.xsl" type="text/xsl"?>
<rss xmlns:pheedo="http://www.pheedo.com/namespace/pheedo" version="2.0" xml:base="http://blogs.csoonline.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title>Steven Fox&#039;s blog</title>
		<link>http://blogs.csoonline.com/blog/steven_fox</link>
		<description></description>
		<language>en</language>
		<item>
			<title>&quot;IT Risk&quot; does not exist.</title>
			<link>http://feeds.csoonline.com/click.phdo?i=f43573ef72a5b737d23f3cd411b2e362</link>
			<pheedo:origLink>http://blogs.csoonline.com/it_risk_does_not_exist</pheedo:origLink>
			<description>&lt;p&gt;Yes, ladies and gentlemen, according to the Institure of Internal Auditors(IIA), &quot;there is no such thing as &#039;IT Risk&#039;&quot;.  After closing a semester of teaching web application security, I wanted to share my observations and concerns regarding the understanding of &quot;risk&quot; among the next generation of security professionals.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://blogs.csoonline.com/it_risk_does_not_exist&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;&lt;br clear=&quot;both&quot; style=&quot;clear: both;&quot;/&gt;
&lt;br clear=&quot;both&quot; style=&quot;clear: both;&quot;/&gt;
  &lt;a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:b9f6e657dae6f50e2970c351a5e2ca2e:xofTef7rgu2g50WOK6aKghsDFRJNE3rDEESQE9lNiCMZdZIwemnHK47VH8sPBCJcGfII%2Bwr3%2Fom0'&gt;&lt;img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/&gt;&lt;/a&gt;
  &lt;a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:43ca461da6b20c16f1eaab55c41d6452:CFAQMSmGuQ1haP5rW%2B9DRoAZCd91geEMRUOha9W1bNvMBXzLsGfmHrIA7%2FdU4m57BFievORyu2WDIw%3D%3D'&gt;&lt;img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/&gt;&lt;/a&gt;
  &lt;a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:cecd6df1ec1b5798e894247d75726222:rUrcsuofej%2FwtEvWXbbrs%2FaqbEPaWI%2FNOGdHVAByvd6nGr5JBB0SZ2FyVsSvAmINfjgcFVXbgFyPRg%3D%3D'&gt;&lt;img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/&gt;&lt;/a&gt;
  &lt;a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:956c02d236aebc6c68081a55446e53b0:k0DUakAeZjpXBhp0zx6FF4TgjV4BL2oBlnGAzGnAsV9%2BxB9%2FUneitBFfjxj5W3W8Uty0tE4n94Eq1g%3D%3D'&gt;&lt;img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/&gt;&lt;/a&gt;
&lt;br clear=&quot;both&quot; style=&quot;clear: both;&quot;/&gt;
&lt;a href=&quot;http://www.pheedo.com/click.phdo?s=f43573ef72a5b737d23f3cd411b2e362&amp;p=1&quot;&gt;&lt;img alt=&quot;&quot; style=&quot;border: 0;&quot; border=&quot;0&quot; src=&quot;http://www.pheedo.com/img.phdo?s=f43573ef72a5b737d23f3cd411b2e362&amp;p=1&quot;/&gt;&lt;/a&gt;
&lt;img src=&quot;http://www.pheedo.com/feeds/tracker.php?i=f43573ef72a5b737d23f3cd411b2e362&quot; style=&quot;display: none;&quot; border=&quot;0&quot; height=&quot;1&quot; width=&quot;1&quot; alt=&quot;&quot;/&gt;
</description>
			<comments>http://blogs.csoonline.com/it_risk_does_not_exist#comment</comments>
			<category domain="http://blogs.csoonline.com/blog_categories/data_protection">Data Protection</category>
			<category domain="http://blogs.csoonline.com/blog_categories/business_continuity">Business Continuity</category>
			<category domain="http://blogs.csoonline.com/blog_categories/leadership">Leadership</category>
			<category domain="http://blogs.csoonline.com/blog_categories/career">Career</category>
			<pubDate>Fri, 26 Dec 2008 16:11:49 -0500</pubDate>
			<dc:creator>Steven Fox</dc:creator>
			<guid isPermaLink="false">850 at http://blogs.csoonline.com</guid>
		</item>
		<item>
			<title>A CEO&#039;s tale of disappointment</title>
			<link>http://feeds.csoonline.com/click.phdo?i=b33237b098e3447f6a762b8462314474</link>
			<pheedo:origLink>http://blogs.csoonline.com/a_ceos_tale_of_disappointment</pheedo:origLink>
			<description>&lt;p&gt;I met the CEO of a holding company on a recent flight to North Carolina.  Our conversation started on the topic of my &#039;Art of War&#039; column.  The column, I explained, is focused on sharing Sun Tzu&#039;s insights on strategy with information security practitioners.  At firts he was silent, but I could tell something was wrong.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://blogs.csoonline.com/a_ceos_tale_of_disappointment&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;&lt;br style=&quot;clear: both;&quot;/&gt;
    &lt;a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:e987e007e39249a6348e73a49d3993a8:lUOvepZNXs%2FhgKMQDh1CcegHP2WBC83WfS1Ls2UozqbE1X51WwGJm1F%2B0u%2F5J14YmyrQmM1nU2TY'&gt;&lt;img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/&gt;&lt;/a&gt;
    &lt;a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:6f4c708fc786cafc0358710953c47ec9:K%2Bx5W7wP851XgMgWIefYeiwPPzRVcYsNG0ATa8Be67BIGWiZatXom9zhaziqkTjWqJJVZd%2F6dcBgzw%3D%3D'&gt;&lt;img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/&gt;&lt;/a&gt;
    &lt;a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:9357713bbc242ff618f1febc3ede3bb6:XWT0B5MSk%2ByBi%2FJTYQG2h%2B8jVeaOp9A7mHtehyNlPsGJ5euNes0Z5VCzc%2F6rjD0rupMK2pQKKWWWAA%3D%3D'&gt;&lt;img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/&gt;&lt;/a&gt;
    &lt;a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:518752c46dce8c7686cd4a5f741fa638:lMGZ2bkzNNuMVqacRiORevdHzhujEKVJwFq2VxIjHxSldDrxBWg4X9%2Fni6ujsJJEYwwQXoF2gpUG%2BQ%3D%3D'&gt;&lt;img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/&gt;&lt;/a&gt;
&lt;br style=&quot;clear: both;&quot;/&gt;
&lt;a href=&quot;http://www.pheedo.com/click.phdo?s=b33237b098e3447f6a762b8462314474&quot;&gt;&lt;img alt=&quot;&quot; style=&quot;border: 0;&quot; border=&quot;0&quot; src=&quot;http://www.pheedo.com/img.phdo?s=b33237b098e3447f6a762b8462314474&quot;/&gt;&lt;/a&gt;
&lt;img src=&quot;http://www.pheedo.com/feeds/tracker.php?i=b33237b098e3447f6a762b8462314474&quot; style=&quot;display: none;&quot; border=&quot;0&quot; height=&quot;1&quot; width=&quot;1&quot; alt=&quot;&quot;/&gt;
</description>
			<comments>http://blogs.csoonline.com/a_ceos_tale_of_disappointment#comment</comments>
			<category domain="http://blogs.csoonline.com/blog_categories/data_protection">Data Protection</category>
			<category domain="http://blogs.csoonline.com/blog_categories/identity_management">Identity Management</category>
			<category domain="http://blogs.csoonline.com/blog_categories/leadership">Leadership</category>
			<category domain="http://blogs.csoonline.com/blog_categories/career">Career</category>
			<pubDate>Sun, 28 Sep 2008 15:02:45 -0400</pubDate>
			<dc:creator>Steven Fox</dc:creator>
			<guid isPermaLink="false">793 at http://blogs.csoonline.com</guid>
		</item>
		<item>
			<title>Security Paradigms</title>
			<link>http://www.pheedo.com/click.phdo?i=84dd8515d232606a6f5ef6084ee4b882</link>
			<pheedo:origLink>http://blogs.csoonline.com/security_paradigms</pheedo:origLink>
			<description>&lt;div class=&quot;blog_header&quot;&gt;
							&lt;div class=&quot;title&quot;&gt;&lt;a href=&quot;/blog/steven_fox&quot;&gt;Security Paradigms&lt;/a&gt;&lt;/div&gt;
							&lt;div class=&quot;byline&quot;&gt;by &lt;a href=&quot;/user/steven_fox&quot;&gt;Steven Fox&lt;/a&gt;&lt;/div&gt;
							&lt;div class=&quot;blogger&quot;&gt;&lt;img  src=&quot;http://blogs.csoonline.com/sites/blogs.csoonline.com/files/pictures/picture-261.jpg&quot;/&gt;&lt;/div&gt;
						&lt;/div&gt;&lt;ul class=&quot;posts&quot;&gt;&lt;li&gt;&lt;a href=&quot;/it_risk_does_not_exist&quot;&gt;&quot;IT Risk&quot; does not exist.&lt;/a&gt;&lt;p&gt;Yes, ladies and gentlemen, according to the Institure of Internal Auditors(IIA), &quot;there is no such thing as &#039;IT Risk&#039;&quot;.  After closing a semester of teaching web application security, I wanted to share my observations and concerns regarding the understanding of &quot;risk&quot; among the next generation of security professionals.&lt;p&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;/a_ceos_tale_of_disappointment&quot;&gt;A CEO&#039;s tale of disappointment&lt;/a&gt;&lt;p&gt;I met the CEO of a holding company on a recent flight to North Carolina.  Our conversation started on the topic of my &#039;Art of War&#039; column.  The column, I explained, is focused on sharing Sun Tzu&#039;s insights on strategy with information security practitioners.  At firts he was silent, but I could tell something was wrong.&lt;p&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;/the_effect_of_paradigms_on_our_perspective_of_security&quot;&gt;The effect of paradigms on our perspective of security.&lt;/a&gt;&lt;p&gt;“Your paradigm is so intrinsic to your mental process that you are hardly aware of its existence, until you try to communicate with someone with a different paradigm.” 
 --Donella Meadows

     For some of us, security is realized through physical and network controls that address the risks to a given environment.  Others view techniques aimed at education and user empowerment as critical to organizational security.  Then there are those who march onto the risk landscape under the banner of effective governance and oversight.
&lt;p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class=&quot;read_more&quot;&gt;» &lt;a href=&quot;/blog/steven_fox&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://blogs.csoonline.com/security_paradigms&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;&lt;br style=&quot;clear: both;&quot;/&gt;
    &lt;a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:250009c4545670f71692041670dafde4:gCpRPJfYpZ41QTkZ%2FgjwfEwX5KXOrrPVTyQyN%2B6oV9TAE3HrzUqP7NJVzhctsbWgxu39LcnE47lp'&gt;&lt;img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/&gt;&lt;/a&gt;
    &lt;a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:3b302df60f13afe199e349b7b739c35b:h3tXMAvb5OKl0HnaftDCpqFyxcuP0Dr4ibZAKnh9P0JlqjCWLMF5m4NW3Bv%2FEtadQHlknBSltI2eQA%3D%3D'&gt;&lt;img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/&gt;&lt;/a&gt;
    &lt;a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:039834b59cf86fd11e859b94be4fa23a:ZDg%2F08ZWV14xPOvl7an8KGYDGQu5mhnkM47lMjSFQCpz37tlOF%2FJC0xu0TPupn1aUClc7wOeUsoMEg%3D%3D'&gt;&lt;img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/&gt;&lt;/a&gt;
    &lt;a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:9a9ca974d5400c36ccefe3bd9029733a:GCW25X1ckdGpWrobrUQ5jwVaGYcxxJTNH8tD9zAva2J8T%2BTKiay13vpH%2FAk%2BuaVvRF92JQSBxN%2BRlw%3D%3D'&gt;&lt;img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/&gt;&lt;/a&gt;
&lt;br style=&quot;clear: both;&quot;/&gt;
&lt;img alt=&quot;&quot; style=&quot;border: 0; height:1px; width:1px;&quot; border=&quot;0&quot; src=&quot;http://www.pheedo.com/img.phdo?i=84dd8515d232606a6f5ef6084ee4b882&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;
&lt;img src=&quot;http://www.pheedo.com/feeds/tracker.php?i=84dd8515d232606a6f5ef6084ee4b882&quot; style=&quot;display: none;&quot; border=&quot;0&quot; height=&quot;1&quot; width=&quot;1&quot; alt=&quot;&quot;/&gt;
</description>
			<comments>http://blogs.csoonline.com/security_paradigms#comment</comments>
			<pubDate>Fri, 19 Sep 2008 08:13:53 -0400</pubDate>
			<dc:creator>Steven Fox</dc:creator>
			<guid isPermaLink="false">781 at http://blogs.csoonline.com</guid>
		</item>
		<item>
			<title>The effect of paradigms on our perspective of security.</title>
			<link>http://www.pheedo.com/click.phdo?i=08baf3de7582c40c1ad9ad00bfba6689</link>
			<pheedo:origLink>http://blogs.csoonline.com/the_effect_of_paradigms_on_our_perspective_of_security</pheedo:origLink>
			<description>&lt;p&gt;“Your paradigm is so intrinsic to your mental process that you are hardly aware of its existence, until you try to communicate with someone with a different paradigm.”&lt;br /&gt;
 --Donella Meadows&lt;/p&gt;
&lt;p&gt;     For some of us, security is realized through physical and network controls that address the risks to a given environment.  Others view techniques aimed at education and user empowerment as critical to organizational security.  Then there are those who march onto the risk landscape under the banner of effective governance and oversight.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://blogs.csoonline.com/the_effect_of_paradigms_on_our_perspective_of_security&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;&lt;br style=&quot;clear: both;&quot;/&gt;
    &lt;a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:228b2745f94a03d71ce2f250b561d56a:%2Fg3mObTiSmJenzfXiFCGh%2ByKa1hzX3avilRlyD9dGs4c3%2FteK4TcqXZRajOFNXA7ch8%2FmNibn0uT'&gt;&lt;img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/&gt;&lt;/a&gt;
    &lt;a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:81d8d439956e702d7b136f0c6a9d76a1:QNhaZtDFg3P1uHmpbDCdZzOrpW0omGo2bt2n%2FYBz6CSTi3uQ6iYsvBOK%2FlxwrfZHb6AU%2FBlKpNzo%2FA%3D%3D'&gt;&lt;img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/&gt;&lt;/a&gt;
    &lt;a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:470e07626e8be4633fa462e7c0eab32f:Lt5%2F5edQ%2B5jUymrqeb5vohtq5e%2FYQixDeWH1bHslD9RnKZRM0dTs26KTBwvOCbowGEVvg%2FhRn9y%2F9Q%3D%3D'&gt;&lt;img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/&gt;&lt;/a&gt;
    &lt;a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:df25e12bb243fd4b3dffcd1253f4ee50:hYt2TM%2Blho%2FO7sRrMx7veNnn2ncVP3t1rUjG7eVsz2%2B4sLw3Pbv7VI5%2B6Xp7azgo3y7vUxJq1prezA%3D%3D'&gt;&lt;img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/&gt;&lt;/a&gt;
&lt;br style=&quot;clear: both;&quot;/&gt;
&lt;img alt=&quot;&quot; style=&quot;border: 0; height:1px; width:1px;&quot; border=&quot;0&quot; src=&quot;http://www.pheedo.com/img.phdo?i=08baf3de7582c40c1ad9ad00bfba6689&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;
&lt;img src=&quot;http://www.pheedo.com/feeds/tracker.php?i=08baf3de7582c40c1ad9ad00bfba6689&quot; style=&quot;display: none;&quot; border=&quot;0&quot; height=&quot;1&quot; width=&quot;1&quot; alt=&quot;&quot;/&gt;
</description>
			<comments>http://blogs.csoonline.com/the_effect_of_paradigms_on_our_perspective_of_security#comment</comments>
			<category domain="http://blogs.csoonline.com/blog_categories/data_protection">Data Protection</category>
			<category domain="http://blogs.csoonline.com/blog_categories/identity_management">Identity Management</category>
			<category domain="http://blogs.csoonline.com/blog_categories/physical_security">Physical Security</category>
			<category domain="http://blogs.csoonline.com/blog_categories/leadership">Leadership</category>
			<category domain="http://blogs.csoonline.com/blog_categories/career">Career</category>
			<pubDate>Thu, 18 Sep 2008 23:27:02 -0400</pubDate>
			<dc:creator>Steven Fox</dc:creator>
			<guid isPermaLink="false">780 at http://blogs.csoonline.com</guid>
		</item>
	</channel>
</rss>