<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Heartland Proves that Log Data is NOT Enough</title>
	<atom:link href="http://blog.eiqnetworks.com/2009/01/22/heartland-proves-that-log-data-is-not-enough/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.eiqnetworks.com/2009/01/22/heartland-proves-that-log-data-is-not-enough/</link>
	<description>Perspectives on Security and Compliance Management from eIQnetworks</description>
	<lastBuildDate>Thu, 29 Oct 2009 15:57:47 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: IS Security &#187; Blog Archive &#187; Risk analysis alternatives</title>
		<link>http://blog.eiqnetworks.com/2009/01/22/heartland-proves-that-log-data-is-not-enough/#comment-14</link>
		<dc:creator>IS Security &#187; Blog Archive &#187; Risk analysis alternatives</dc:creator>
		<pubDate>Mon, 26 Jan 2009 22:56:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.eiqnetworks.com/?p=65#comment-14</guid>
		<description>[...] Mike Rothman, former independent who just re-entered the corporate workforce, threw in his own two cents.  The case he uses is a vendor that was complaint with the PCI standard, as many others have, and [...]</description>
		<content:encoded><![CDATA[<p>[...] Mike Rothman, former independent who just re-entered the corporate workforce, threw in his own two cents.  The case he uses is a vendor that was complaint with the PCI standard, as many others have, and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Rothman</title>
		<link>http://blog.eiqnetworks.com/2009/01/22/heartland-proves-that-log-data-is-not-enough/#comment-12</link>
		<dc:creator>Mike Rothman</dc:creator>
		<pubDate>Fri, 23 Jan 2009 13:16:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.eiqnetworks.com/?p=65#comment-12</guid>
		<description>Ed, the point wasn&#039;t that log data or log management isn&#039;t helpful. But it&#039;s not going to be sufficient to really stop these kinds of attacks. In many cases the attackers turn logging off, which leaves the organization flying blind - if they are only relying on log data. Logs are critical in investigating issues and gathering information, but many organizations don&#039;t take advantage of other data types they are already gathering (in a lot of cases).</description>
		<content:encoded><![CDATA[<p>Ed, the point wasn&#8217;t that log data or log management isn&#8217;t helpful. But it&#8217;s not going to be sufficient to really stop these kinds of attacks. In many cases the attackers turn logging off, which leaves the organization flying blind &#8211; if they are only relying on log data. Logs are critical in investigating issues and gathering information, but many organizations don&#8217;t take advantage of other data types they are already gathering (in a lot of cases).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ed Chopskie</title>
		<link>http://blog.eiqnetworks.com/2009/01/22/heartland-proves-that-log-data-is-not-enough/#comment-11</link>
		<dc:creator>Ed Chopskie</dc:creator>
		<pubDate>Fri, 23 Jan 2009 00:02:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.eiqnetworks.com/?p=65#comment-11</guid>
		<description>Mike, great post. I think its too early to totally discount log management in this breach. According to the Verizon Business research note that came out last year that analyzed 500 breaches over 4 years, 82% of the time the breach evidence was in the logs. 

What is clear that just because an org is PCI DSS compliant, doesnt mean that they are safe. 

Ed Chopskie
VP Marketing
SenSage</description>
		<content:encoded><![CDATA[<p>Mike, great post. I think its too early to totally discount log management in this breach. According to the Verizon Business research note that came out last year that analyzed 500 breaches over 4 years, 82% of the time the breach evidence was in the logs. </p>
<p>What is clear that just because an org is PCI DSS compliant, doesnt mean that they are safe. </p>
<p>Ed Chopskie<br />
VP Marketing<br />
SenSage</p>
]]></content:encoded>
	</item>
</channel>
</rss>
