<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The Economist on Breach Disclosure</title>
	<atom:link href="http://newschoolsecurity.com/2010/03/the-economist-on-breach-disclosure/feed/" rel="self" type="application/rss+xml" />
	<link>http://newschoolsecurity.com/2010/03/the-economist-on-breach-disclosure/</link>
	<description>The Blog Inspired By The Book</description>
	<lastBuildDate>Wed, 08 Feb 2012 09:21:02 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: LonerVamp</title>
		<link>http://newschoolsecurity.com/2010/03/the-economist-on-breach-disclosure/#comment-1088</link>
		<dc:creator>LonerVamp</dc:creator>
		<pubDate>Wed, 03 Mar 2010 19:53:53 +0000</pubDate>
		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1391#comment-1088</guid>
		<description>I need to grab a copy of the article, but just to add some comments...

First, I will always agree that sharing information and disclosing breaches is a benefit, from a security perspective. 

Has this pushed companies to invest more in prevention? I&#039;m not sure. I think plenty is spent on avoiding disclosures, reducing compliance/risk scope, and satisfying audits. Does that improve prevention or detection? Hard to say.

I always wait for comparisons between IT security audits and financial audits; hell I often find myself thinking the same thing. My big problem with that, though, is similar to why I think checklist compliance is weak. Financial practices are very objective, painfully so. There are only so many ways to do things, and while it is mindboggling to non-accountants, they ultimately all do make predictable and comparable sense. IT solutions are still as much artful as they are predictable. One company&#039;s network may dramatically differ from another company, even those in direct competition to each other in the same exact space. How do you get any sort of checklist that will be effective enough to offer value across the board without incurring even more financial barriers to entry into business in a digital world?

That rant dives pretty far into checklist compliance, but if anyone wants to start having public audits and comparisons like financial audits, it&#039;s a dirty and necessary topic. Then again, it&#039;s not like insurance (or financial audits to reflect business ethics/health) is an exact science...</description>
		<content:encoded><![CDATA[<p>I need to grab a copy of the article, but just to add some comments&#8230;</p>
<p>First, I will always agree that sharing information and disclosing breaches is a benefit, from a security perspective. </p>
<p>Has this pushed companies to invest more in prevention? I&#8217;m not sure. I think plenty is spent on avoiding disclosures, reducing compliance/risk scope, and satisfying audits. Does that improve prevention or detection? Hard to say.</p>
<p>I always wait for comparisons between IT security audits and financial audits; hell I often find myself thinking the same thing. My big problem with that, though, is similar to why I think checklist compliance is weak. Financial practices are very objective, painfully so. There are only so many ways to do things, and while it is mindboggling to non-accountants, they ultimately all do make predictable and comparable sense. IT solutions are still as much artful as they are predictable. One company&#8217;s network may dramatically differ from another company, even those in direct competition to each other in the same exact space. How do you get any sort of checklist that will be effective enough to offer value across the board without incurring even more financial barriers to entry into business in a digital world?</p>
<p>That rant dives pretty far into checklist compliance, but if anyone wants to start having public audits and comparisons like financial audits, it&#8217;s a dirty and necessary topic. Then again, it&#8217;s not like insurance (or financial audits to reflect business ethics/health) is an exact science&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben</title>
		<link>http://newschoolsecurity.com/2010/03/the-economist-on-breach-disclosure/#comment-1079</link>
		<dc:creator>Ben</dc:creator>
		<pubDate>Tue, 02 Mar 2010 15:26:24 +0000</pubDate>
		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1391#comment-1079</guid>
		<description>I think this is a very good thing, to be honest. Sorry to disappoint and agree with you! :) We chatted a bit about it at the ABA InfoSec Committee meeting over the weekend and even the lawyers think it&#039;s a good idea to have better breach reporting. It&#039;s almost like the world is becoming so insane that it&#039;s actually sane. :)</description>
		<content:encoded><![CDATA[<p>I think this is a very good thing, to be honest. Sorry to disappoint and agree with you! <img src='http://newschoolsecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  We chatted a bit about it at the ABA InfoSec Committee meeting over the weekend and even the lawyers think it&#8217;s a good idea to have better breach reporting. It&#8217;s almost like the world is becoming so insane that it&#8217;s actually sane. <img src='http://newschoolsecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James K. Adamson</title>
		<link>http://newschoolsecurity.com/2010/03/the-economist-on-breach-disclosure/#comment-1076</link>
		<dc:creator>James K. Adamson</dc:creator>
		<pubDate>Tue, 02 Mar 2010 13:21:43 +0000</pubDate>
		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1391#comment-1076</guid>
		<description>Grabbed this issue on my way through the airport to an infosec gig and am looking forward to reading the full article.  Just the info on the growth of information being produced was mind boggling!</description>
		<content:encoded><![CDATA[<p>Grabbed this issue on my way through the airport to an infosec gig and am looking forward to reading the full article.  Just the info on the growth of information being produced was mind boggling!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

