<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
>

<channel>
	<title>The Security Catalyst&#187; Podcast</title>
	<atom:link href="http://www.securitycatalyst.com/category/podcast/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securitycatalyst.com</link>
	<description>harnessing the human side of security</description>
	<lastBuildDate>Wed, 25 Jan 2012 15:57:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
<!-- podcast_generator="Blubrry PowerPress/2.0.4" -->
	<itunes:summary>harnessing the human side of security</itunes:summary>
	<itunes:author>The Security Catalyst</itunes:author>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://www.securitycatalyst.com/wp-content/plugins/powerpress/itunes_default.jpg" />
	<itunes:subtitle>harnessing the human side of security</itunes:subtitle>
	<image>
		<title>The Security Catalyst&#187; Podcast</title>
		<url>http://www.securitycatalyst.com/wp-content/plugins/powerpress/rss_default.jpg</url>
		<link>http://www.securitycatalyst.com/category/podcast/</link>
	</image>
		<item>
		<title>Effectively Communicating the Value of Cloud Security Presentation</title>
		<link>http://www.securitycatalyst.com/2011/10/effectively-communicating-the-value-of-cloud-security-presentation/</link>
		<comments>http://www.securitycatalyst.com/2011/10/effectively-communicating-the-value-of-cloud-security-presentation/#comments</comments>
		<pubDate>Fri, 21 Oct 2011 15:23:06 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Effective Communication]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Videos]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[communicating effectively]]></category>
		<category><![CDATA[effectively communicating]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=3590</guid>
		<description><![CDATA[Perplexed by the challenge of cloud security, let alone how to communicate the value of taking an approach that secures information? The rapid growth and adoption of cloud computing leads to sometimes confusing situations where security remains an afterthought. At a time when everyone is expected to do more with less, the difference between success [...]]]></description>
			<content:encoded><![CDATA[<p>Perplexed by the challenge of cloud security, let alone how to communicate the value of taking an approach that secures information?</p>
<p>The rapid growth and adoption of cloud computing leads to sometimes confusing situations where security remains an afterthought.</p>
<p>At a time when everyone is expected to do more with less, the difference between success and failure hinges upon the ability to communicate effectively. In fact, many people now realize the ability to communicate the value of security, and of their efforts, is the difference between career success and failure.</p>
<p>I recently considered how to cut through the confusion surrounding &#8220;cloud security&#8221; to <a href="http://www.securitycatalyst.com/effectively-communicating-the-value-of-security/">successfully communicate the value</a> of our efforts and shared some insights during the <a href="https://twitter.com/#!/BrightTALK">BrightTalk</a> cloud security summit. Special thanks toÂ <a href="https://twitter.com/#!/TrendMicro">Trend Micro</a>, <a href="https://twitter.com/#!/symanteccloud">Symantec</a>, <a href="https://twitter.com/#!/daveshackleford">Dave Shackleford</a> and <a href="https://twitter.com/#!/lmacvittie">Lori MacVittie</a>Â for sharing time, research and experience with me.</p>
<p>Blending their insights and experiences with my <a href="http://www.securitycatalyst.com/learn/">studies and models of how to effectively communicate value</a> resulted in some interesting findings, including the need to translate our security experiences into the cloud is as (maybe more) important than selecting the right examples. The result is a 45-minute briefing, shared below.</p>
<p>Check out the recording here:<br />
<object width="656" height="627" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowscriptaccess" value="always" /><param name="allowfullscreen" value="true" /><param name="wmode" value="transparent" /><param name="flashvars" value="channelid=288&amp;commid=34463&amp;autoStart=false&amp;fromdc=false&amp;css=" /><param name="src" value="http://www.brighttalk.com/clients/flashplatform/viewer/no_channel/loader.swf" /><embed width="656" height="627" type="application/x-shockwave-flash" src="http://www.brighttalk.com/clients/flashplatform/viewer/no_channel/loader.swf" allowscriptaccess="always" allowfullscreen="true" wmode="transparent" flashvars="channelid=288&amp;commid=34463&amp;autoStart=false&amp;fromdc=false&amp;css=" /><a href="http://www.brighttalk.com/channel/288">A BrightTALK Channel</a></object></p>
<p>&nbsp;</p>
<p>I work to help harness the human side of security; without a doubt, the challenges we face in our journey to the cloud is less technical and more dependent on our ability to successfully communicate with each other, with decision makers and with our colleagues who use the solutions we design, deploy and maintain.</p>
<p><strong>This presentation is only the beginning.</strong></p>
<p>I continue to research, test and help industry, enterprise and individuals to improve how we distill and and effectively communicate the value of security.</p>
<p><strong>How can I help you?</strong></p>
<p>Reach out with comments, questions and suggestions or share your communication challenges with me and we can explore how to solve them together.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2011/10/effectively-communicating-the-value-of-cloud-security-presentation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Awareness Roundtable: Defining Security Awareness â€“ Audio Download</title>
		<link>http://www.securitycatalyst.com/2011/07/security-awareness-roundtable-defining-security-awareness-audio-download/</link>
		<comments>http://www.securitycatalyst.com/2011/07/security-awareness-roundtable-defining-security-awareness-audio-download/#comments</comments>
		<pubDate>Thu, 21 Jul 2011 13:15:39 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Security Awareness]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=3541</guid>
		<description><![CDATA[The first episode of the Security Awareness Roundtable addressed the importance of defining security awareness the right way. The audio of the roundtable is now available for download and enjoyment. Joined by Justin Bovee and Steve Ellis, we presented the definition of security awareness, explored how it sets the stage for success and offered insights [...]]]></description>
			<content:encoded><![CDATA[<p>The first episode of the Security Awareness Roundtable addressed the importance of defining security awareness the right way.</p>
<p>The audio of the roundtable is now available for download and enjoyment.<a href="http://www.securitycatalyst.com/wp-content/uploads/2011/07/SecurityRoundTable.jpg"><img class="alignright size-medium wp-image-3537" title="SecurityRoundTable" src="http://www.securitycatalyst.com/wp-content/uploads/2011/07/SecurityRoundTable-300x300.jpg" alt="" width="300" height="300" /></a></p>
<p>Joined by Justin Bovee and Steve Ellis, we presented the definition of security awareness, explored how it sets the stage for success and offered insights into using the definition to build an effective program.</p>
<p>We also talked about how this definition makes it possible to turn what is often considered a cost into an investment â€“ while satisfying compliance issues and a sometimes sour attitude toward â€œsecurity awareness training.â€ Weâ€™ll go deeper on that topic in August.</p>
<p>We covered a lot of ground in a short period.</p>
<p>Iâ€™ll be expanding on key concepts in this blog, my CSO column, and offering some additional resources to help the establishment of effective security awareness programs.</p>
<p>Check out the event page to see what others contributed, ask questions and offer your thoughts (I keep tabs on all questions, comments and contributions for future roundtables): <a href="http://www.focus.com/roundtables/security-awareness-roundtable-defining-security-awareness/">http://www.focus.com/roundtables/security-awareness-roundtable-defining-security-awareness/</a></p>
<p>In the meantime, while or after listening to the roundtable:</p>
<ul>
<li><a href="https://twitter.com/">Engage with me on twitter</a> to talk about security awareness, effective communication of security or whatever is on your mind</li>
<li>Send me email or submit questions for this or an upcoming roundtable</li>
<li>Check out and participate in the security awareness section growing on Focus.com by clicking on <a href="http://www.focus.com/topic/security-awareness/">http://www.focus.com/topic/security-awareness/</a></li>
</ul>
<p>On August 24<sup>th</sup>, join us for our second Security Awareness Roundtable and learn how to invest in security awareness, how to get budget and how much it should cost.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2011/07/security-awareness-roundtable-defining-security-awareness-audio-download/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcast/security-awareness-roundtable-defining-security-awareness-july-2011.mp3" length="26608467" type="audio/mpeg" />
			<itunes:subtitle>The first episode of the Security Awareness Roundtable addressed the importance of defining security awareness the right way. - The audio of the roundtable is now available for download and enjoyment. - Joined by Justin Bovee and Steve Ellis,</itunes:subtitle>
		<itunes:summary>The first episode of the Security Awareness Roundtable addressed the importance of defining security awareness the right way.

The audio of the roundtable is now available for download and enjoyment.

Joined by Justin Bovee and Steve Ellis, we presented the definition of security awareness, explored how it sets the stage for success and offered insights into using the definition to build an effective program.

We also talked about how this definition makes it possible to turn what is often considered a cost into an investment â€“ while satisfying compliance issues and a sometimes sour attitude toward â€œsecurity awareness training.â€ Weâ€™ll go deeper on that topic in August.

We covered a lot of ground in a short period.

Iâ€™ll be expanding on key concepts in this blog, my CSO column, and offering some additional resources to help the establishment of effective security awareness programs.

Check out the event page to see what others contributed, ask questions and offer your thoughts (I keep tabs on all questions, comments and contributions for future roundtables): http://www.focus.com/roundtables/security-awareness-roundtable-defining-security-awareness/

In the meantime, while or after listening to the roundtable:

	Engage with me on twitter to talk about security awareness, effective communication of security or whatever is on your mind
	Send me email or submit questions for this or an upcoming roundtable
	Check out and participate in the security awareness section growing on Focus.com by clicking on http://www.focus.com/topic/security-awareness/

On August 24th, join us for our second Security Awareness Roundtable and learn how to invest in security awareness, how to get budget and how much it should cost.</itunes:summary>
		<itunes:author>The Security Catalyst</itunes:author>
		<itunes:explicit>no</itunes:explicit>
	</item>
		<item>
		<title>Into the Breach â€“ Audio Series â€“ Chapter 11 (Outsource with Security and Success)</title>
		<link>http://www.securitycatalyst.com/2010/06/into-the-breach-audio-chapter-11/</link>
		<comments>http://www.securitycatalyst.com/2010/06/into-the-breach-audio-chapter-11/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 09:53:19 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[mssp]]></category>
		<category><![CDATA[outsource]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=3006</guid>
		<description><![CDATA[Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy. This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png"><img class="alignleft size-full wp-image-2578" title="itb-audioseries-150px" src="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png" alt="" width="150" height="150" /></a>Welcome to the continuation of the <a href="http://www.securitycatalyst.com/into-the-breach/"><strong><em>Into the Breach: Protect Your Business by Managing People, Information and Risk</em></strong></a> audio series. <a href="http://www.securitycatalyst.com/into-the-breach/buy-into-the-breach/">(Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy</a>.</p>
<p>This series, underwritten by <a href="http://www.vmware.com/products/configuration-manager/resource.html">Configuresoft, now part of EMC</a>, is the full and unabridged audio version of <em>Into the Breach</em>, written by Michael Santarcangelo and read by the author.</p>
<h3>What youâ€™ll find in this episode (Chapter 11)</h3>
<p>Outsourcing makes sense for a lot of organizations and continues to gain in popularity. Does this drive to outsource and partner actually increase security and protection of information?</p>
<p>By leveraging the strategy and concepts shared in <em>Into the Breach</em>, learn how to build a firm foundation for success â€“ including how to measure the effectiveness of the partner and ensure mutual and lasting benefit from the arrangement.</p>
<ul>
<li>Learn how to establish appropriate and measurable criteria upon which to make better decisions</li>
<li>Understand how to assess potential partners and providers to ensure appropriate fit and mutual success</li>
<li>Gain insights into verifying and building relationships based on trust and mutual understanding</li>
</ul>
<p>If outsourcing and working with partners is part of the process, then this chapter is a must listen.</p>
<h3>Put the power of Into the Breach to work for youâ€¦</h3>
<p>After listening to this segment of <em>Into the Breach</em>, keep the energy going and support the shift in thinking and inspire behavior change by</p>
<ol>
<li>Engage with Michael on twitter (<a href="http://twitter.com/catalyst">http://twitter.com/catalyst</a>)</li>
<li>Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!</li>
<li><strong>Check out </strong><strong><em>Awareness that Worksâ„¢</em></strong><strong> â€“ Michael Santarcangeloâ€™s program to guide smart investment in people, with guaranteed results (this program pays for itself). </strong></li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2010/06/into-the-breach-audio-chapter-11/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcast/ITB-Santarcangelo-CHAPTER-11.mp3" length="10474902" type="audio/mpeg" />
			<itunes:keywords>breach,catalyst,mssp,outsource,security</itunes:keywords>
		<itunes:subtitle>Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy. - </itunes:subtitle>
		<itunes:summary>Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy.

This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the author.
What youâ€™ll find in this episode (Chapter 11)
Outsourcing makes sense for a lot of organizations and continues to gain in popularity. Does this drive to outsource and partner actually increase security and protection of information?

By leveraging the strategy and concepts shared in Into the Breach, learn how to build a firm foundation for success â€“ including how to measure the effectiveness of the partner and ensure mutual and lasting benefit from the arrangement.

	Learn how to establish appropriate and measurable criteria upon which to make better decisions
	Understand how to assess potential partners and providers to ensure appropriate fit and mutual success
	Gain insights into verifying and building relationships based on trust and mutual understanding

If outsourcing and working with partners is part of the process, then this chapter is a must listen.
Put the power of Into the Breach to work for youâ€¦
After listening to this segment of Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by

	Engage with Michael on twitter (http://twitter.com/catalyst)
	Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!
	Check out Awareness that Worksâ„¢ â€“ Michael Santarcangeloâ€™s program to guide smart investment in people, with guaranteed results (this program pays for itself).</itunes:summary>
		<itunes:author>The Security Catalyst</itunes:author>
		<itunes:explicit>no</itunes:explicit>
	</item>
		<item>
		<title>Into the Breach Audio Book Chapter 10: Reducing the Cost of Compliance</title>
		<link>http://www.securitycatalyst.com/2010/05/into-the-breach-audio-series-chapter-10/</link>
		<comments>http://www.securitycatalyst.com/2010/05/into-the-breach-audio-series-chapter-10/#comments</comments>
		<pubDate>Tue, 04 May 2010 10:06:00 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>
		<category><![CDATA[Into the Breach Audio Book]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[awareness that works]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2943</guid>
		<description><![CDATA[Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves today&#8217;s challenges and pick up a complete copy. This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png"><img class="alignleft size-full wp-image-2578" title="itb-audioseries-150px" src="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png" alt="" width="150" height="150" /></a>Welcome to the continuation of the <a href="http://www.securitycatalyst.com/into-the-breach/"><strong><em>Into the Breach: Protect Your Business by Managing People, Information and Risk</em></strong></a> audio series. <a href="http://www.securitycatalyst.com/into-the-breach/buy-into-the-breach/">(Click this link) to learn more about this how this book solves today&#8217;s challenges and pick up a complete copy</a>.</p>
<p>This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of <em>Into the Breach</em>, written by Michael Santarcangelo and read by the author.</p>
<h3>In this episode (Chapter 10)</h3>
<p>Compliance is not a commodity that can be purchased. And demonstrating compliance at a point in time does not mean information is being protected properly. There is a growing chorus of practitioners that suggest compliance is not security; however, proper security can and often does lead to effective compliance.</p>
<p>The key in managing risk and demonstrating compliance is to engage people in the process of assessing and protecting information â€“ with and without the use of technology and controls.</p>
<p>In this chapter, I share some personal experiences and research that demonstrate the difference between a reactionary approach to compliance and a more mature process that addresses many needs at once.</p>
<p>If you find yourself drowning in compliance â€“ or are trying to convince others of a different approach â€“ this chapter is written for you.</p>
<h3>Put the power of Into the Breach to work for youâ€¦</h3>
<p>After listening to this segment of <em>Into the Breach</em>, keep the energy going and support the shift in thinking and inspire behavior change by</p>
<ol>
<li>Engage with Michael on twitter (<a href="http://twitter.com/catalyst">http://twitter.com/catalyst</a>)</li>
<li>Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2010/05/into-the-breach-audio-series-chapter-10/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcast/ITB-Santarcangelo-CHAPTER-10.mp3" length="9024246" type="audio/mpeg" />
			<itunes:keywords>awareness,awareness that works,breach,catalyst,compliance,security</itunes:keywords>
		<itunes:subtitle>Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves today&#039;s challenges and pick up a complete copy. - </itunes:subtitle>
		<itunes:summary>Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves today&#039;s challenges and pick up a complete copy.

This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the author.
In this episode (Chapter 10)
Compliance is not a commodity that can be purchased. And demonstrating compliance at a point in time does not mean information is being protected properly. There is a growing chorus of practitioners that suggest compliance is not security; however, proper security can and often does lead to effective compliance.

The key in managing risk and demonstrating compliance is to engage people in the process of assessing and protecting information â€“ with and without the use of technology and controls.

In this chapter, I share some personal experiences and research that demonstrate the difference between a reactionary approach to compliance and a more mature process that addresses many needs at once.

If you find yourself drowning in compliance â€“ or are trying to convince others of a different approach â€“ this chapter is written for you.
Put the power of Into the Breach to work for youâ€¦
After listening to this segment of Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by

	Engage with Michael on twitter (http://twitter.com/catalyst)
	Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!</itunes:summary>
		<itunes:author>The Security Catalyst</itunes:author>
		<itunes:explicit>no</itunes:explicit>
	</item>
		<item>
		<title>Into the Breach â€“ Audio Series â€“ Chapter 9 (Extending the Conversation: Rewards Beyond Protecting Information)</title>
		<link>http://www.securitycatalyst.com/2010/04/into-the-breach-audio-chapter-9/</link>
		<comments>http://www.securitycatalyst.com/2010/04/into-the-breach-audio-chapter-9/#comments</comments>
		<pubDate>Tue, 06 Apr 2010 10:06:30 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[awareness that works]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[into the breach]]></category>
		<category><![CDATA[santarcangelo]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2893</guid>
		<description><![CDATA[Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy. This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png"><img class="alignright size-full wp-image-2578" title="itb-audioseries-150px" src="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png" alt="" width="150" height="150" /></a>Welcome to the continuation of the <a href="http://www.securitycatalyst.com/into-the-breach/"><strong><em>Into the Breach: Protect Your Business by Managing People, Information and Risk</em></strong></a> audio series. <a href="http://www.securitycatalyst.com/into-the-breach/buy-into-the-breach/">(Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy</a>.</p>
<p>This series, underwritten by <a href="http://www.vmware.com/products/configuration-manager/resource.html">Configuresoft, now part of EMC</a>, is the full and unabridged audio version of <em>Into the Breach</em>, written by Michael Santarcangelo and read by the author.</p>
<h3>What youâ€™ll find in this episode (Chapter 9)</h3>
<p>Writing this book and testing these methods revealed a surprise: people who are engaged â€“ connected more closely to the consequences of their actions â€“ do more than protect information.</p>
<p>This chapter explores additional benefits from the improved communication and insights that come from following the strategies and elements shared in <em>Into the Breach</em>, including:</p>
<ul>
<li>Quickly align business and technology organizations (true alignment, not lip service)</li>
<li>Harnessing the power of people to uncover new revenue opportunities</li>
<li>Leveraging and engaging individuals in the act of reducing waste while doing more with less</li>
</ul>
<h3>You want more, so after listeningâ€¦</h3>
<p>After listening to this segment of <em>Into the Breach</em>, keep the energy going and support the shift in thinking and inspire behavior change by</p>
<ol>
<li>Engaging (not following) Michael on twitter (<a href="http://twitter.com/catalyst">http://twitter.com/catalyst</a>)</li>
<li>Subscribing to The Security Catalyst podcast &amp; blog to get more insights</li>
<li><strong>3. </strong><strong>Checking out <em>Awareness that Worksâ„¢</em> â€“ a new program from Michael Santarcangelo to guide smart investment in people, with guaranteed results (this program pays for itself). </strong></li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2010/04/into-the-breach-audio-chapter-9/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcast/ITB-Santarcangelo-CHAPTER-9.mp3" length="8261334" type="audio/mpeg" />
			<itunes:keywords>awareness,awareness that works,catalyst,into the breach,santarcangelo</itunes:keywords>
		<itunes:subtitle>Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy. - </itunes:subtitle>
		<itunes:summary>Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy.

This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the author.
What youâ€™ll find in this episode (Chapter 9)
Writing this book and testing these methods revealed a surprise: people who are engaged â€“ connected more closely to the consequences of their actions â€“ do more than protect information.

This chapter explores additional benefits from the improved communication and insights that come from following the strategies and elements shared in Into the Breach, including:

	Quickly align business and technology organizations (true alignment, not lip service)
	Harnessing the power of people to uncover new revenue opportunities
	Leveraging and engaging individuals in the act of reducing waste while doing more with less

You want more, so after listeningâ€¦
After listening to this segment of Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by

	Engaging (not following) Michael on twitter (http://twitter.com/catalyst)
	Subscribing to The Security Catalyst podcast &amp; blog to get more insights
	3. Checking out Awareness that Worksâ„¢ â€“ a new program from Michael Santarcangelo to guide smart investment in people, with guaranteed results (this program pays for itself).</itunes:summary>
		<itunes:author>The Security Catalyst</itunes:author>
		<itunes:explicit>no</itunes:explicit>
	</item>
		<item>
		<title>Into the Breach â€“ Audio Series â€“ Chapter 8 (Measuring Success)</title>
		<link>http://www.securitycatalyst.com/2010/03/into-the-breach-audio-chapter-8/</link>
		<comments>http://www.securitycatalyst.com/2010/03/into-the-breach-audio-chapter-8/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 09:40:22 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[awareness that works]]></category>
		<category><![CDATA[measurement]]></category>
		<category><![CDATA[metrics]]></category>
		<category><![CDATA[qualitative]]></category>
		<category><![CDATA[quantitative]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2768</guid>
		<description><![CDATA[Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy. This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio [...]]]></description>
			<content:encoded><![CDATA[<p><!--StartFragment--><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png"><img class="alignleft size-full wp-image-2578" title="itb-audioseries-150px" src="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png" alt="" width="150" height="150" /></a>Welcome to the continuation of the <a href="http://www.securitycatalyst.com/into-the-breach/"><strong><em>Into the Breach: Protect Your Business by Managing People, Information and Risk</em></strong></a> audio series. <a href="http://www.securitycatalyst.com/into-the-breach/buy-into-the-breach/">(Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy</a>. This series, underwritten by <a href="http://www.vmware.com/products/configuration-manager/resource.html">Configuresoft, now part of EMC</a>, is the full and unabridged audio version of <em>Into the Breach</em>, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).</p>
<h3>What youâ€™ll find in this episode (Chapter <img src='http://www.securitycatalyst.com/wp-includes/images/smilies/icon_cool.gif' alt='8)' class='wp-smiley' /> </h3>
<p>The strategy has been revealed. The fundamentals of what is now The Catalyst Method have been shared (note: if you want the update on The Catalyst Method, drop me an email). The key considerations for a pilot shared â€“ and now it is time to measure success.</p>
<p><strong>So how do you measure what matters so you can communicate what counts?</strong></p>
<p>In this chapter, â€œMeasuring Success,â€ Michael draws on his background of social science and economics to explain a powerful approach to measuring success. Learn how to use the right mix of qualitative and quantitative measurements to get the feedback necessary for success.</p>
<p>Learn how to measure what matters and communicate what counts.</p>
<h3>Put the power of Into the Breach to work for youâ€¦</h3>
<p>After listening to this segment ofÂ Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by</p>
<ol>
<li>Engage with Michael on twitter (<a href="http://twitter.com/catalyst">http://twitter.com/catalyst</a>)</li>
<li>Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!</li>
<li> Check outÂ Awareness that Worksâ„¢ â€“ Michael Santarcangeloâ€™s program to guide smart investment in people, with guaranteed results (this program pays for itself).</li>
</ol>
<p><!--EndFragment--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2010/03/into-the-breach-audio-chapter-8/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcast/ITB-Santarcangelo-CHAPTER-8.mp3" length="11163078" type="audio/mpeg" />
			<itunes:keywords>awareness,awareness that works,measurement,metrics,qualitative,quantitative,risk,security</itunes:keywords>
		<itunes:subtitle>Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy.</itunes:subtitle>
		<itunes:summary>Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy. This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).
What youâ€™ll find in this episode (Chapter 8)
The strategy has been revealed. The fundamentals of what is now The Catalyst Method have been shared (note: if you want the update on The Catalyst Method, drop me an email). The key considerations for a pilot shared â€“ and now it is time to measure success.

So how do you measure what matters so you can communicate what counts?

In this chapter, â€œMeasuring Success,â€ Michael draws on his background of social science and economics to explain a powerful approach to measuring success. Learn how to use the right mix of qualitative and quantitative measurements to get the feedback necessary for success.

Learn how to measure what matters and communicate what counts.
Put the power of Into the Breach to work for youâ€¦
After listening to this segment ofÂ Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by

	Engage with Michael on twitter (http://twitter.com/catalyst)
	Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!
	 Check outÂ Awareness that Worksâ„¢ â€“ Michael Santarcangeloâ€™s program to guide smart investment in people, with guaranteed results (this program pays for itself).</itunes:summary>
		<itunes:author>The Security Catalyst</itunes:author>
		<itunes:explicit>no</itunes:explicit>
	</item>
		<item>
		<title>Into the Breach â€“ Audio Series â€“ Chapter 7 (Putting the Strategy to Work: A Pilot)</title>
		<link>http://www.securitycatalyst.com/2010/02/into-the-breach-audio-chapter-7/</link>
		<comments>http://www.securitycatalyst.com/2010/02/into-the-breach-audio-chapter-7/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 10:45:50 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[Catalyst Foundation Seriesâ„¢]]></category>
		<category><![CDATA[into the breach]]></category>
		<category><![CDATA[pilot]]></category>
		<category><![CDATA[santarcangelo]]></category>
		<category><![CDATA[strategy]]></category>
		<category><![CDATA[The Catalyst Methodâ„¢]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2710</guid>
		<description><![CDATA[Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy. This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png"><img class="alignleft size-full wp-image-2578" title="itb-audioseries-150px" src="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png" alt="" width="150" height="150" /></a>Welcome to the continuation of the <a href="http://www.securitycatalyst.com/into-the-breach/"><strong><em>Into the Breach: Protect Your Business by Managing People, Information and Risk</em></strong></a> audio series. <a href="http://www.securitycatalyst.com/into-the-breach/buy-into-the-breach/">(Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy</a>. This series, underwritten by <a href="http://www.vmware.com/products/configuration-manager/resource.html">Configuresoft, now part of EMC</a>, is the full and unabridged audio version of <em>Into the Breach</em>, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).</p>
<h3>What youâ€™ll find in this episode (Chapter 7)</h3>
<p>The strategy has been revealed. The fundamentals of what is now The Catalyst Method have been shared (note: if you want the update on The Catalyst Method, contact us to learn more).</p>
<p><strong>So how do you implement in a way that gets results?<span style="font-weight: normal;"> </span></strong></p>
<p>In this chapter, â€œPutting the Strategy to Work: A Pilot,â€ Michael explains the basic approach â€“ with key insights â€“ to engaging people in the process of protecting information. Learn how to select the pilot approach that works best, build the team and plan a strategy that drives tactical and strategic success.</p>
<p>There is no â€œone-size-fits allâ€ approach, and this chapter lays out how to make the right decisions the first time. Get a jumpstart on success with this chapter.</p>
<h3>Put the power of Into the Breach to work for youâ€¦</h3>
<p>After listening to this segment ofÂ Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by</p>
<ol>
<li>Engage with Michael on twitter (<a href="http://twitter.com/catalyst">http://twitter.com/catalyst</a>)</li>
<li>Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!</li>
<li> Check outÂ Awareness that Worksâ„¢ â€“ Michael Santarcangeloâ€™s program to guide smart investment in people, with guaranteed results (this program pays for itself).</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2010/02/into-the-breach-audio-chapter-7/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcast/ITB-Santarcangelo-CHAPTER-7.mp3" length="7848342" type="audio/mpeg" />
			<itunes:keywords>catalyst,Catalyst Foundation Seriesâ„¢,into the breach,pilot,santarcangelo,strategy,The Catalyst Methodâ„¢</itunes:keywords>
		<itunes:subtitle>Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy.</itunes:subtitle>
		<itunes:summary>Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy. This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).
What youâ€™ll find in this episode (Chapter 7)
The strategy has been revealed. The fundamentals of what is now The Catalyst Method have been shared (note: if you want the update on The Catalyst Method, contact us to learn more).

So how do you implement in a way that gets results? 

In this chapter, â€œPutting the Strategy to Work: A Pilot,â€ Michael explains the basic approach â€“ with key insights â€“ to engaging people in the process of protecting information. Learn how to select the pilot approach that works best, build the team and plan a strategy that drives tactical and strategic success.

There is no â€œone-size-fits allâ€ approach, and this chapter lays out how to make the right decisions the first time. Get a jumpstart on success with this chapter.
Put the power of Into the Breach to work for youâ€¦
After listening to this segment ofÂ Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by

	Engage with Michael on twitter (http://twitter.com/catalyst)
	Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!
	 Check outÂ Awareness that Worksâ„¢ â€“ Michael Santarcangeloâ€™s program to guide smart investment in people, with guaranteed results (this program pays for itself).</itunes:summary>
		<itunes:author>The Security Catalyst</itunes:author>
		<itunes:explicit>no</itunes:explicit>
	</item>
		<item>
		<title>Into the Breach â€“ Audio Series â€“ Chapter 6 (Implementing The Strategy to Protect Information)</title>
		<link>http://www.securitycatalyst.com/2010/01/into-the-breach-audio-chapter-6/</link>
		<comments>http://www.securitycatalyst.com/2010/01/into-the-breach-audio-chapter-6/#comments</comments>
		<pubDate>Wed, 06 Jan 2010 02:21:25 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[santarcangelo]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[the catalyst method]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2648</guid>
		<description><![CDATA[Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy. This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png"><img class="alignleft size-full wp-image-2578" title="itb-audioseries-150px" src="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png" alt="" width="150" height="150" /></a>Welcome to the continuation of the <a href="http://www.securitycatalyst.com/into-the-breach/"><strong><em>Into the Breach: Protect Your Business by Managing People, Information and Risk</em></strong></a> audio series. <a href="http://www.securitycatalyst.com/into-the-breach/buy-into-the-breach/">(Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy</a>. This series, underwritten by <a href="http://www.vmware.com/products/configuration-manager/resource.html">Configuresoft, now part of EMC</a>, is the full and unabridged audio version of <em>Into the Breach</em>, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).</p>
<h3>What youâ€™ll find in this episode (Chapter 6)</h3>
<p>Chapter Six is where Michael explains how to customize and implement the Strategy to Protect Information. The information he shares is designed for immediate results by harnessing the power of people. By asking the right questions &#8212; in the right way &#8212; people are connected to the consequences of their actions and share information about known and unknown risks about the information they use every day.</p>
<p>The elements of this chapter are the building blocks to what is now calledÂ The Catalyst Methodâ„¢ &#8212; what Michael teaches, guides and uses to help organizations get results that improve awareness assessments and help deliver Awareness that Worksâ„¢.</p>
<h3>Put the power of Into the Breach to work for youâ€¦</h3>
<p>After listening to this segment ofÂ Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by</p>
<ol>
<li>Engage with Michael on twitter (<a href="http://twitter.com/catalyst">http://twitter.com/catalyst</a>)</li>
<li>Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!</li>
<li> Check outÂ Awareness that Worksâ„¢ â€“ Michael Santarcangeloâ€™s program to guide smart investment in people, with guaranteed results (this program pays for itself).</li>
</ol>
<ol></ol>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2010/01/into-the-breach-audio-chapter-6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcast/ITB-Santarcangelo-CHAPTER-6.mp3" length="15032070" type="audio/mpeg" />
			<itunes:keywords>breach,catalyst,risk management,santarcangelo,security,the catalyst method</itunes:keywords>
		<itunes:subtitle>Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy.</itunes:subtitle>
		<itunes:summary>Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy. This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).
What youâ€™ll find in this episode (Chapter 6)
Chapter Six is where Michael explains how to customize and implement the Strategy to Protect Information. The information he shares is designed for immediate results by harnessing the power of people. By asking the right questions -- in the right way -- people are connected to the consequences of their actions and share information about known and unknown risks about the information they use every day.

The elements of this chapter are the building blocks to what is now calledÂ The Catalyst Methodâ„¢ -- what Michael teaches, guides and uses to help organizations get results that improve awareness assessments and help deliver Awareness that Worksâ„¢.
Put the power of Into the Breach to work for youâ€¦
After listening to this segment ofÂ Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by

	Engage with Michael on twitter (http://twitter.com/catalyst)
	Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!
	 Check outÂ Awareness that Worksâ„¢ â€“ Michael Santarcangeloâ€™s program to guide smart investment in people, with guaranteed results (this program pays for itself).</itunes:summary>
		<itunes:author>The Security Catalyst</itunes:author>
		<itunes:explicit>no</itunes:explicit>
	</item>
		<item>
		<title>Into the Breach â€“ Audio Series â€“ Chapter 5 (The Strategy to Protect Information)</title>
		<link>http://www.securitycatalyst.com/2009/12/into-the-breach-audio-series-chapter-5/</link>
		<comments>http://www.securitycatalyst.com/2009/12/into-the-breach-audio-series-chapter-5/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 21:23:18 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[emc]]></category>
		<category><![CDATA[into the breach]]></category>
		<category><![CDATA[santarcangelo]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/into-the-breach-%e2%80%93-audio-series-%e2%80%93-chapter-5-the-strategy-to-protect-information/</guid>
		<description><![CDATA[Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy. This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png"><img class="alignleft size-full wp-image-2578" title="itb-audioseries-150px" src="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png" alt="" width="150" height="150" /></a>Welcome to the continuation of the <a href="http://www.securitycatalyst.com/into-the-breach/"><strong><em>Into the Breach: Protect Your Business by Managing People, Information and Risk</em></strong></a> audio series. <a href="http://www.securitycatalyst.com/into-the-breach/buy-into-the-breach/">(Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy</a>.</p>
<p>This series, underwritten by <a href="http://www.vmware.com/products/configuration-manager/resource.html">Configuresoft, now part of EMC</a>, is the full and unabridged audio version of <em>Into the Breach</em>, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).</p>
<h3>What youâ€™ll find in episode 6, Into the Breach: Chapter 5 (The Strategy to Protect Information)</h3>
<p>Chapter 5 is the introduction to Part II of Into the Breach &#8212; where the focus shifts to looking at what needs to be done. I outline a powerful, yet simple, approach dubbed &#8220;The Strategy to Protect Information.&#8221;</p>
<p>Key is the focus on information, not data, and the three steps that any organization must follow in order to be effective. The balance of Part II explains how &#8211; but just learning and understanding the three part strategy is transformative.</p>
<p>After listening to this chapter, you will know the strategy and be able to apply it to your current challenge &#8212; small and tactical or larger and organizational.</p>
<h3>Put the power of Into the Breach to work for youâ€¦</h3>
<p>After listening to this segment ofÂ Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by</p>
<ol>
<li>Engage with Michael on twitter (<a href="http://twitter.com/catalyst">http://twitter.com/catalyst</a>)</li>
<li>Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!</li>
<li>Check outÂ Awareness that Worksâ„¢ â€“ Michael Santarcangeloâ€™s program to guide smart investment in people, with guaranteed results (this program pays for itself).</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2009/12/into-the-breach-audio-series-chapter-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://securitycatalyst.com/podcast/ITB-Santarcangelo-CHAPTER-5.mp3" length="13425894" type="audio/mpeg" />
			<itunes:keywords>breach,catalyst,emc,into the breach,Podcast,santarcangelo</itunes:keywords>
		<itunes:subtitle>Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy. - </itunes:subtitle>
		<itunes:summary>Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy.

This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).
What youâ€™ll find in episode 6, Into the Breach: Chapter 5 (The Strategy to Protect Information)
Chapter 5 is the introduction to Part II of Into the Breach -- where the focus shifts to looking at what needs to be done. I outline a powerful, yet simple, approach dubbed &quot;The Strategy to Protect Information.&quot;

Key is the focus on information, not data, and the three steps that any organization must follow in order to be effective. The balance of Part II explains how - but just learning and understanding the three part strategy is transformative.

After listening to this chapter, you will know the strategy and be able to apply it to your current challenge -- small and tactical or larger and organizational.
Put the power of Into the Breach to work for youâ€¦
After listening to this segment ofÂ Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by

	Engage with Michael on twitter (http://twitter.com/catalyst)
	Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!
	Check outÂ Awareness that Worksâ„¢ â€“ Michael Santarcangeloâ€™s program to guide smart investment in people, with guaranteed results (this program pays for itself).</itunes:summary>
		<itunes:author>The Security Catalyst</itunes:author>
		<itunes:explicit>no</itunes:explicit>
	</item>
		<item>
		<title>Into the Breach â€“ Audio Series â€“ Chapter 4 (The Solution: Manage People, Information and Risk)</title>
		<link>http://www.securitycatalyst.com/2009/11/into-the-breach-audio-series-chapter-4/</link>
		<comments>http://www.securitycatalyst.com/2009/11/into-the-breach-audio-series-chapter-4/#comments</comments>
		<pubDate>Tue, 03 Nov 2009 11:36:26 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2456</guid>
		<description><![CDATA[Episode 5: Into the Breach: Chapter 4 (The Solution: Manage People, Information and Risk) Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy. This [...]]]></description>
			<content:encoded><![CDATA[<h3><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png"><img class="alignleft size-full wp-image-2578" title="itb-audioseries-150px" src="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png" alt="" width="150" height="150" /></a>Episode 5: Into the Breach: Chapter 4 (The Solution: Manage People, Information and Risk)</h3>
<p>Welcome to the continuation of the <a href="http://www.securitycatalyst.com/into-the-breach/"><strong><em>Into the Breach: Protect Your Business by Managing People, Information and Risk</em></strong></a> audio series. <a href="http://www.securitycatalyst.com/into-the-breach/buy-into-the-breach/">(Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy</a>. This series, underwritten by <a href="http://www.vmware.com/products/configuration-manager/resource.html">Configuresoft, now part of EMC</a>, is the full and unabridged audio version of <em>Into the Breach</em>, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).</p>
<h3>What youâ€™ll find in this episode (Chapter 4)</h3>
<p>Chapter four wraps up the first part of Into the Breach with a candid discussion about the current approaches to managing risk â€“ and why they are not working. Michael explains that risk management is based on curves, not continuums, then dives deeper into the three barriers to effective risk management: scale, perception and probability. While looking at each, Michael makes suggestions on how to overcome them, then introduces the concept of managing risk on the efficient frontier.</p>
<h3>Put the power of Into the Breach to work for youâ€¦</h3>
<p>After listening to this segment ofÂ Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by</p>
<ol>
<li>Engage with Michael on twitter (<a href="http://twitter.com/catalyst">http://twitter.com/catalyst</a>)</li>
<li>Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!</li>
<li>Check outÂ Awareness that Worksâ„¢ â€“ Michael Santarcangeloâ€™s program to guide smart investment in people, with guaranteed results (this program pays for itself).</li>
</ol>
<ol></ol>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2009/11/into-the-breach-audio-series-chapter-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcast/ITB-Santarcangelo-CHAPTER-4.mp3" length="15104214" type="audio/mpeg" />
			<itunes:subtitle>Episode 5: Into the Breach: Chapter 4 (The Solution: Manage People, Information and Risk) Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series.</itunes:subtitle>
		<itunes:summary>Episode 5: Into the Breach: Chapter 4 (The Solution: Manage People, Information and Risk)
Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâ€™s challenges and pick up a complete copy. This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).
What youâ€™ll find in this episode (Chapter 4)
Chapter four wraps up the first part of Into the Breach with a candid discussion about the current approaches to managing risk â€“ and why they are not working. Michael explains that risk management is based on curves, not continuums, then dives deeper into the three barriers to effective risk management: scale, perception and probability. While looking at each, Michael makes suggestions on how to overcome them, then introduces the concept of managing risk on the efficient frontier.
Put the power of Into the Breach to work for youâ€¦
After listening to this segment ofÂ Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by

	Engage with Michael on twitter (http://twitter.com/catalyst)
	Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!
	Check outÂ Awareness that Worksâ„¢ â€“ Michael Santarcangeloâ€™s program to guide smart investment in people, with guaranteed results (this program pays for itself).</itunes:summary>
		<itunes:author>The Security Catalyst</itunes:author>
		<itunes:explicit>no</itunes:explicit>
	</item>
		<item>
		<title>Into the Breach &#8211; Audio Book Chapter &#8211; 3 &#8220;Breaking the Security Diet&#8221;</title>
		<link>http://www.securitycatalyst.com/2009/10/into-the-breach-audio-series-chapter-3/</link>
		<comments>http://www.securitycatalyst.com/2009/10/into-the-breach-audio-series-chapter-3/#comments</comments>
		<pubDate>Wed, 07 Oct 2009 02:15:17 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Into the Breach Audio Book]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[assessment]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[into the breach]]></category>
		<category><![CDATA[keynote speaker]]></category>
		<category><![CDATA[regulation]]></category>
		<category><![CDATA[santarcangelo]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2406</guid>
		<description><![CDATA[Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves today&#8217;s challenges and pick up a complete copy. This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio [...]]]></description>
			<content:encoded><![CDATA[<h3><span style="font-weight: normal; font-size: 13px;"><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png"><img class="alignleft size-full wp-image-2578" title="itb-audioseries-150px" src="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png" alt="" width="150" height="150" /></a>Welcome to the continuation of the <a href="http://www.securitycatalyst.com/into-the-breach/"><strong><em>Into the Breach: Protect Your Business by Managing People, Information and Risk</em></strong></a> audio series. <a href="http://www.securitycatalyst.com/into-the-breach/buy-into-the-breach/">(Click this link) to learn more about this how this book solves today&#8217;s challenges and pick up a complete copy</a>. This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of <em>Into the Breach</em>, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).</span></h3>
<h3>In chapter 3 : Breaking the Security Diet</h3>
<p><em>Breaking the security diet</em> is recognition that what happens in organizations today is more akin to a crash diet than a healthy approach to securing information. In this chapter, Michael reveals the high cost of this &#8220;fad diet&#8221; approach and shines a light on the new fad diet: <strong>encryption</strong>. However, there is a solution, and Michael explains how to break the fad diet, improve leadership and engage individuals. A pivotal chapter in the book, designed to create a fundamental change in the way organizations and individuals protect information.</p>
<h3>Put the power of Into the Breach to work for you</h3>
<p>After listening to this segment of <em>Into the Breach</em>, keep the energy going and support the shift in thinking and inspire behavior change by</p>
<ol>
<li>Engage with Michael on twitter (<a href="http://twitter.com/catalyst">http://twitter.com/catalyst</a>)</li>
<li>Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2009/10/into-the-breach-audio-series-chapter-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcast/ITB-Santarcangelo-CHAPTER-3.mp3" length="11584278" type="audio/mpeg" />
			<itunes:keywords>assessment,audit,catalyst,compliance,encryption,into the breach,keynote speaker,regulation,santarcangelo</itunes:keywords>
		<itunes:subtitle>Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves today&#039;s challenges and pick up a complete copy. This series,</itunes:subtitle>
		<itunes:summary>Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves today&#039;s challenges and pick up a complete copy. This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).
In chapter 3 : Breaking the Security Diet
Breaking the security diet is recognition that what happens in organizations today is more akin to a crash diet than a healthy approach to securing information. In this chapter, Michael reveals the high cost of this &quot;fad diet&quot; approach and shines a light on the new fad diet: encryption. However, there is a solution, and Michael explains how to break the fad diet, improve leadership and engage individuals. A pivotal chapter in the book, designed to create a fundamental change in the way organizations and individuals protect information.
Put the power of Into the Breach to work for you
After listening to this segment of Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by

	Engage with Michael on twitter (http://twitter.com/catalyst)
	Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!</itunes:summary>
		<itunes:author>The Security Catalyst</itunes:author>
		<itunes:explicit>no</itunes:explicit>
	</item>
		<item>
		<title>Into the Breach â€“ Audio Series â€“ Chapter 2 (People Just Want to Do Their Jobs)</title>
		<link>http://www.securitycatalyst.com/2009/09/into-the-breach-audio-series-chapter-2/</link>
		<comments>http://www.securitycatalyst.com/2009/09/into-the-breach-audio-series-chapter-2/#comments</comments>
		<pubDate>Tue, 01 Sep 2009 13:34:53 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[emc]]></category>
		<category><![CDATA[into the breach]]></category>
		<category><![CDATA[santarcangelo]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2293</guid>
		<description><![CDATA[Welcome to the audio series of Into the Breach: Protect Your Business by Managing People, Information and Risk (click this link to learn more about this book and pick up a complete copy â€“ to get started on your personal journey). This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged [...]]]></description>
			<content:encoded><![CDATA[<p><!--StartFragment--></p>
<h3><span style="font-weight: normal; font-size: 13px;"><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png"><img class="alignleft size-full wp-image-2578" title="itb-audioseries-150px" src="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png" alt="" width="150" height="150" /></a>Welcome to the audio series of <a href="http://www.securitycatalyst.com/into-the-breach/"><strong><em>Into the Breach: Protect Your Business by Managing People, Information and Risk</em></strong></a><strong><em> </em></strong>(<a href="http://www.securitycatalyst.com/into-the-breach/buy-into-the-breach/">click this link to learn more about this book and pick up a complete copy â€“ to get started on your personal journey</a>). This series, underwritten by <a href="http://www.vmware.com/products/configuration-manager/resource.html">Configuresoft, now part of EMC</a>, is the full and unabridged audio version of <em>Into the Breach</em>, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).</span></h3>
<h3>What youâ€™ll find in this episode (Chapter 2: People Just Want to do their Jobs)</h3>
<p>Chapter 2 reframes the challenge with powerful insights about the way people â€œjust want to do their jobs.â€ Michael introduces what he calls the two principlesÂ  &#8211; a powerful concept about how people do their jobs, and an eye-opener that leads to improved interactions. The corollary to these principles is also explored, along with guidance on what to do about it. With a focus on individuals, Michael explains, â€œCompliance is not a video gameâ€ and reveals that a common approach of â€œexclusionâ€ is creating more harm than good. The chapter wraps up with a discussion of â€œthe human response to painâ€ â€“ with a common example played out in organizations everywhere.</p>
<h3>Put the power of Into the Breach to work for youâ€¦</h3>
<p>After listening to this segment ofÂ Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by</p>
<ol>
<li>Engage with Michael on twitter (<a href="http://twitter.com/catalyst">http://twitter.com/catalyst</a>)</li>
<li>Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!</li>
<li>Check outÂ Awareness that Worksâ„¢ â€“ Michael Santarcangeloâ€™s program to guide smart investment in people, with guaranteed results (this program pays for itself).</li>
</ol>
<ol></ol>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2009/09/into-the-breach-audio-series-chapter-2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcast/ITB-Santarcangelo-CHAPTER-2.mp3" length="13480326" type="audio/mpeg" />
			<itunes:keywords>awareness,catalyst,compliance,emc,into the breach,santarcangelo</itunes:keywords>
		<itunes:subtitle>Welcome to the audio series of Into the Breach: Protect Your Business by Managing People, Information and Risk (click this link to learn more about this book and pick up a complete copy â€“ to get started on your personal journey). This series,</itunes:subtitle>
		<itunes:summary>Welcome to the audio series of Into the Breach: Protect Your Business by Managing People, Information and Risk (click this link to learn more about this book and pick up a complete copy â€“ to get started on your personal journey). This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).
What youâ€™ll find in this episode (Chapter 2: People Just Want to do their Jobs)
Chapter 2 reframes the challenge with powerful insights about the way people â€œjust want to do their jobs.â€ Michael introduces what he calls the two principlesÂ  - a powerful concept about how people do their jobs, and an eye-opener that leads to improved interactions. The corollary to these principles is also explored, along with guidance on what to do about it. With a focus on individuals, Michael explains, â€œCompliance is not a video gameâ€ and reveals that a common approach of â€œexclusionâ€ is creating more harm than good. The chapter wraps up with a discussion of â€œthe human response to painâ€ â€“ with a common example played out in organizations everywhere.
Put the power of Into the Breach to work for youâ€¦
After listening to this segment ofÂ Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by

	Engage with Michael on twitter (http://twitter.com/catalyst)
	Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!
	Check outÂ Awareness that Worksâ„¢ â€“ Michael Santarcangeloâ€™s program to guide smart investment in people, with guaranteed results (this program pays for itself).</itunes:summary>
		<itunes:author>The Security Catalyst</itunes:author>
		<itunes:explicit>no</itunes:explicit>
	</item>
		<item>
		<title>Into the Breach &#8211; Audio Series &#8211; Chapter 1 (Breach: A Human Problem)</title>
		<link>http://www.securitycatalyst.com/2009/08/into-the-breach-audio-series-chapter-1/</link>
		<comments>http://www.securitycatalyst.com/2009/08/into-the-breach-audio-series-chapter-1/#comments</comments>
		<pubDate>Wed, 05 Aug 2009 00:54:36 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[into the breach]]></category>
		<category><![CDATA[Security Awareness]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2201</guid>
		<description><![CDATA[Welcome to the audio series of Into the Breach: Protect Your Business by Managing People, Information and Risk (click this link to learn more about this book and pick up a complete copy â€“ to get started on your personal journey). This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged [...]]]></description>
			<content:encoded><![CDATA[<h3><span style="font-weight: normal; font-size: 13px;"><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png"><img class="alignleft size-full wp-image-2578" title="itb-audioseries-150px" src="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png" alt="" width="150" height="150" /></a>Welcome to the audio series of <strong><em><a href="http://www.securitycatalyst.com/into-the-breach/">Into the Breach: Protect Your Business by Managing People, Information and Risk</a> </em></strong>(<a href="http://www.securitycatalyst.com/into-the-breach/buy-into-the-breach/">click this link to learn more about this book and pick up a complete copy â€“ to get started on your personal journey</a>). This series, underwritten by <a href="http://www.vmware.com/products/configuration-manager/resource.html">Configuresoft, now part of EMC</a>, is the full and unabridged audio version of <em>Into the Breach</em>, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).</span></h3>
<h3>What youâ€™ll find in this episode (Chapter 1: Breach: A Human Problem)</h3>
<p>Chapter 1 defines the challenge of breach as a â€œhuman problemâ€ and begins the journey to understand how and why we got where we are today. Michael reveals how reliance on technology has masked the true nature of the problem and explains how to re-think the way technology supports the needs of people. He also suggests that a focus on breach is too narrow, and that all information must be protected.</p>
<blockquote><p>Update from Michael: the updated approach is to focus on the human paradox &#8211; introduced in this segment &#8211; that points out the unintentional, but systematic, disconnection of people from the consequences of their actions. This means &#8220;breach&#8221; and information protection is less a human problem than a paradox; my focus is on connecting people back to the consequences of their actions and presenting solutions that turn the cost of working with people into an investment.</p></blockquote>
<p><strong>Put the power of Into the Breach to work for youâ€¦</strong></p>
<p>After listening to this segment ofÂ Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by</p>
<ol>
<li>Engage with Michael on twitter (<a href="http://twitter.com/catalyst">http://twitter.com/catalyst</a>)</li>
<li>Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!</li>
<li>Check outÂ Awareness that Worksâ„¢ â€“ Michael Santarcangeloâ€™s program to guide smart investment in people, with guaranteed results (this program pays for itself).</li>
</ol>
<ol></ol>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2009/08/into-the-breach-audio-series-chapter-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcast/ITB-Santarcangelo-CHAPTER-1.mp3" length="8853606" type="audio/mpeg" />
			<itunes:keywords>breach,catalyst,Information Protection,into the breach,Security Awareness</itunes:keywords>
		<itunes:subtitle>Welcome to the audio series of Into the Breach: Protect Your Business by Managing People, Information and Risk (click this link to learn more about this book and pick up a complete copy â€“ to get started on your personal journey). This series,</itunes:subtitle>
		<itunes:summary>Welcome to the audio series of Into the Breach: Protect Your Business by Managing People, Information and Risk (click this link to learn more about this book and pick up a complete copy â€“ to get started on your personal journey). This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).
What youâ€™ll find in this episode (Chapter 1: Breach: A Human Problem)
Chapter 1 defines the challenge of breach as a â€œhuman problemâ€ and begins the journey to understand how and why we got where we are today. Michael reveals how reliance on technology has masked the true nature of the problem and explains how to re-think the way technology supports the needs of people. He also suggests that a focus on breach is too narrow, and that all information must be protected.
Update from Michael: the updated approach is to focus on the human paradox - introduced in this segment - that points out the unintentional, but systematic, disconnection of people from the consequences of their actions. This means &quot;breach&quot; and information protection is less a human problem than a paradox; my focus is on connecting people back to the consequences of their actions and presenting solutions that turn the cost of working with people into an investment.
Put the power of Into the Breach to work for youâ€¦

After listening to this segment ofÂ Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by

	Engage with Michael on twitter (http://twitter.com/catalyst)
	Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!
	Check outÂ Awareness that Worksâ„¢ â€“ Michael Santarcangeloâ€™s program to guide smart investment in people, with guaranteed results (this program pays for itself).</itunes:summary>
		<itunes:author>The Security Catalyst</itunes:author>
		<itunes:explicit>no</itunes:explicit>
	</item>
		<item>
		<title>Into the Breach &#8211; Audio Series &#8211; The Introduction</title>
		<link>http://www.securitycatalyst.com/2009/07/into-the-breach-audio-series-the-introduction/</link>
		<comments>http://www.securitycatalyst.com/2009/07/into-the-breach-audio-series-the-introduction/#comments</comments>
		<pubDate>Sun, 05 Jul 2009 18:43:04 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[audio series]]></category>
		<category><![CDATA[configuresoft]]></category>
		<category><![CDATA[emc]]></category>
		<category><![CDATA[into the breach]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2037</guid>
		<description><![CDATA[Welcome to the audio series of Into the Breach: Protect Your Business by Managing People, Information and Risk (click this link to learn more about this book). This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png"><img class="alignleft size-full wp-image-2578" title="itb-audioseries-150px" src="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png" alt="" width="150" height="150" /></a>Welcome to the audio series of <strong><em>Into the Breach: Protect Your Business by Managing People, Information and Risk </em></strong>(<a href="http://www.securitycatalyst.com/into-the-breach/" target="_blank">click this link to learn more about this book</a>). This series, underwritten by <a href="http://configuresoft.com/" target="_blank">Configuresoft, now part of EMC</a>, is the full and unabridged audio version of <em>Into the Breach</em>, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the last Tuesday of each month (there are 13 chapters total).</p>
<h3>What youâ€™ll find in this segment</h3>
<p>The Introduction explores the nature of the challenge faced by organizations around the world. As we prepare for the journey â€œInto the Breachâ€, it is revealed that breaches are only symptoms, and the real challenge is described as a human paradox. Setting the stage for a shift in thinking necessary to get results, three common myths are exposed and addressed. A powerful strategy to protect information is shared, and the clarion call to engage, empower and enable people is sounded.</p>
<h3>Put the power of Into the Breach to work for youâ€¦</h3>
<p>After listening to this segment ofÂ Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by</p>
<ol>
<li>Engage with Michael on twitter (<a href="http://twitter.com/catalyst">http://twitter.com/catalyst</a>)</li>
<li>Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!</li>
<li>Check outÂ Awareness that Worksâ„¢ â€“ Michael Santarcangeloâ€™s program to guide smart investment in people, with guaranteed results (this program pays for itself).</li>
</ol>
<ol></ol>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2009/07/into-the-breach-audio-series-the-introduction/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcast/ITB-Santarcangelo-INTRODUCTION.mp3" length="9640278" type="audio/mpeg" />
			<itunes:keywords>audio series,configuresoft,emc,into the breach,Podcast,twitter</itunes:keywords>
		<itunes:subtitle>Welcome to the audio series of Into the Breach: Protect Your Business by Managing People, Information and Risk (click this link to learn more about this book). This series, underwritten by Configuresoft, now part of EMC,</itunes:subtitle>
		<itunes:summary>Welcome to the audio series of Into the Breach: Protect Your Business by Managing People, Information and Risk (click this link to learn more about this book). This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the last Tuesday of each month (there are 13 chapters total).
What youâ€™ll find in this segment
The Introduction explores the nature of the challenge faced by organizations around the world. As we prepare for the journey â€œInto the Breachâ€, it is revealed that breaches are only symptoms, and the real challenge is described as a human paradox. Setting the stage for a shift in thinking necessary to get results, three common myths are exposed and addressed. A powerful strategy to protect information is shared, and the clarion call to engage, empower and enable people is sounded.
Put the power of Into the Breach to work for youâ€¦
After listening to this segment ofÂ Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by

	Engage with Michael on twitter (http://twitter.com/catalyst)
	Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!
	Check outÂ Awareness that Worksâ„¢ â€“ Michael Santarcangeloâ€™s program to guide smart investment in people, with guaranteed results (this program pays for itself).</itunes:summary>
		<itunes:author>The Security Catalyst</itunes:author>
		<itunes:explicit>no</itunes:explicit>
	</item>
		<item>
		<title>Security Catalyst Show â€“ February 16 2009 â€“ Certification &amp; Accreditation</title>
		<link>http://www.securitycatalyst.com/2009/02/security-catalyst-show-%e2%80%93-february-16-2009-%e2%80%93-certification-accreditation/</link>
		<comments>http://www.securitycatalyst.com/2009/02/security-catalyst-show-%e2%80%93-february-16-2009-%e2%80%93-certification-accreditation/#comments</comments>
		<pubDate>Mon, 16 Feb 2009 17:18:46 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[accreditation]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[certification]]></category>
		<category><![CDATA[into the breach]]></category>
		<category><![CDATA[potomac forum]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=1106</guid>
		<description><![CDATA[Welcome to the Security Catalyst Program &#8211; bringing you the ideas, insights and tools necessary to change the way people protect information. I am Michael Santarcangelo, your personal catalyst on this journey. Thanks for listening! On todayâ€™s program, we explore Certification and Accreditation with the help of three experts who share an absolute wealth of [...]]]></description>
			<content:encoded><![CDATA[<p><!--StartFragment--></p>
<p class="MsoNormal">Welcome to the Security Catalyst Program &#8211; bringing you the ideas, insights and tools necessary to change the way people protect information. I am Michael Santarcangelo, your personal catalyst on this journey. Thanks for listening!</p>
<p class="MsoNormal"><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/02/certify.jpg"><img class="alignright size-medium wp-image-1108" title="Binders stack" src="http://www.securitycatalyst.com/wp-content/uploads/2009/02/certify-300x199.jpg" alt="Binders stack" width="300" height="199" /></a>On todayâ€™s program, we explore Certification and Accreditation with the help of three experts who share an absolute wealth of knowledge.</p>
<h3>A few quick notes</h3>
<p class="MsoNormal">1. <em>Into the Breach</em> is available as an eBook and signed Hardcover from <a href="http://www.securitycatalyst.com/into-the-breach/">www.intothebreach.com</a> Learn more about how to engage users, restore responsibility and hold people to account. In fact, this book lays out how to reduce costs without increasing risk, turn insiders into allies and manage people, information and risk better.</p>
<p class="MsoNormal">2. For 2009, I am excited to announce the expansion of the Security Catalyst Blog &#8211; with the awesome Catalyst Contributors. Visit the blog each day to get a fresh perspective</p>
<p class="MsoNormal">3. I&#8217;m in the process of revamping the podcast series for 2009. I know a lot of people are struggling &#8211; and in addition to being a voice of optimism, I&#8217;m building a team to share information and strategies necessary for making a difference this year. If you want to contribute, or if you are facing a challenge and need some help &#8211; shoot me an email: <a href="mailto:securitycatalyst@gmail.com">securitycatalyst@gmail.com</a></p>
<p class="MsoNormal">Stay tuned for more information.</p>
<p class="MsoNormal">For today&#8217;s program, I am joined by Mike Smith, Graydon McKee and Joe Faraone to discuss C&amp;A.</p>
<h3>Links at a glance</h3>
<p class="MsoNormal">The presentation that started the idea for this episode: <a href="http://www.slideshare.net/rybolov/why-care-about-government-security?src=embed">http://www.slideshare.net/rybolov/why-care-about-government-security?src=embed</a></p>
<p class="MsoNormal">Graydon, Joe, and Mike teach 2-day C&amp;A workshop and a 5-Fridays NIST Framework for FISMA workshop for the Potomac Forum. <a href="http://www.potomacforum.org/">http://www.potomacforum.org/</a></p>
<p class="MsoNormal">Graydonâ€™s blog: <a href="http://www.ascensionriskmanagement.com/BlogOne/">http://www.ascensionriskmanagement.com/BlogOne/</a></p>
<p class="MsoNormal">Papers and presentations: <a href="http://www.ascensionriskmanagement.com/BlogOne/paperspresentations/">http://www.ascensionriskmanagement.com/BlogOne/paperspresentations/</a></p>
<p class="MsoNormal">Mikeâ€™s blog:<a href="http://www.guerilla-ciso.com/">http://www.guerilla-ciso.com/</a></p>
<p class="MsoNormal">Papers and presentations: <a href="http://www.guerilla-ciso.com/papers-and-presentations">http://www.guerilla-ciso.com/papers-and-presentations</a></p>
<p class="MsoNormal">The most relevant NIST publications are special publications 800-37 and 800-53, available here: <a href="http://csrc.nist.gov/publications/PubsSPs.html">http://csrc.nist.gov/publications/PubsSPs.html</a></p>
<p class="MsoNormal"><strong>About the Experts</strong></p>
<p class="MsoNormal"><strong>Mike Smith</strong></p>
<p class="MsoNormal"><span>Michael Smith is a Manager in the Audit and Enterprise Risk Services organization of Deloitte &amp; Touche LLP, where he leads engagements to provide security services to both commercial enterprises and government agencies. Prior to Joining Deloitte, Michael served as the Chief Information Security Officer with the Unisys Federal Service Delivery Center based in Reston, Virginia.<span>Â  </span>His scope of responsibility included both providing governance and managing risk for several data centers, Security Operations Center, Network Operations Center, and Server Management Team.</span></p>
<p class="MsoNormal"><strong>Graydon McKee</strong></p>
<p class="MsoNormal">Graydon McKee is the Vice President and Chief Operating Officer of Ascension Risk Management LLC.<span>Â  </span>Graydon is an accomplished Risk Management/Information Security professional with extensive experience in developing and implementing Information Risk Management and Information Security Programs to clients in both the public and private sector.<span>Â  </span>He is a recognized leader in government regulatory compliance (Federal Information Security Management Act and the Defense Information Technology Security Certification and Accreditation Process compliance) and has taught the process to over 2,000 individuals representing over 600 federal government agencies and offices.<span>Â  </span></p>
<p class="MsoNormal"><strong>Joe Faraone</strong></p>
<p class="MsoNormal"><span>Joe Faraone is a Senior Information Security Architect with GCI Corporation, based in Reston, Virginia with over 20 yearsâ€™ experience in Information Security. Joe has delivered services for numerous Federal customers including Certification and Accreditation support, Security Governance Gap Analysis and Independent Validation and Verification (IV&amp;V).<span>Â  </span>Over his career, he has served as Lead Independent Security Engineer, Manager and Architect of a managed security center for an Intelligence Community Agency, and has performed Certification and Accreditation services for several high-assurance systems.</span></p>
<p><!--EndFragment--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2009/02/security-catalyst-show-%e2%80%93-february-16-2009-%e2%80%93-certification-accreditation/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcast/TSC-20090216.mp3" length="31930808" type="audio/mpeg" />
			<itunes:keywords>accreditation,catalyst,certification,into the breach,potomac forum</itunes:keywords>
		<itunes:subtitle>Welcome to the Security Catalyst Program - bringing you the ideas, insights and tools necessary to change the way people protect information. I am Michael Santarcangelo, your personal catalyst on this journey. Thanks for listening! On todayâ€™s program,</itunes:subtitle>
		<itunes:summary>Welcome to the Security Catalyst Program - bringing you the ideas, insights and tools necessary to change the way people protect information. I am Michael Santarcangelo, your personal catalyst on this journey. Thanks for listening!
On todayâ€™s program, we explore Certification and Accreditation with the help of three experts who share an absolute wealth of knowledge.

A few quick notes
1. Into the Breach is available as an eBook and signed Hardcover from www.intothebreach.com Learn more about how to engage users, restore responsibility and hold people to account. In fact, this book lays out how to reduce costs without increasing risk, turn insiders into allies and manage people, information and risk better.
2. For 2009, I am excited to announce the expansion of the Security Catalyst Blog - with the awesome Catalyst Contributors. Visit the blog each day to get a fresh perspective
3. I&#039;m in the process of revamping the podcast series for 2009. I know a lot of people are struggling - and in addition to being a voice of optimism, I&#039;m building a team to share information and strategies necessary for making a difference this year. If you want to contribute, or if you are facing a challenge and need some help - shoot me an email: securitycatalyst@gmail.com
Stay tuned for more information.
For today&#039;s program, I am joined by Mike Smith, Graydon McKee and Joe Faraone to discuss C&amp;A.

Links at a glance
The presentation that started the idea for this episode: http://www.slideshare.net/rybolov/why-care-about-government-security?src=embed
Graydon, Joe, and Mike teach 2-day C&amp;A workshop and a 5-Fridays NIST Framework for FISMA workshop for the Potomac Forum. http://www.potomacforum.org/
Graydonâ€™s blog: http://www.ascensionriskmanagement.com/BlogOne/
Papers and presentations: http://www.ascensionriskmanagement.com/BlogOne/paperspresentations/
Mikeâ€™s blog:http://www.guerilla-ciso.com/
Papers and presentations: http://www.guerilla-ciso.com/papers-and-presentations
The most relevant NIST publications are special publications 800-37 and 800-53, available here: http://csrc.nist.gov/publications/PubsSPs.html
About the Experts
Mike Smith
Michael Smith is a Manager in the Audit and Enterprise Risk Services organization of Deloitte &amp; Touche LLP, where he leads engagements to provide security services to both commercial enterprises and government agencies. Prior to Joining Deloitte, Michael served as the Chief Information Security Officer with the Unisys Federal Service Delivery Center based in Reston, Virginia.Â  His scope of responsibility included both providing governance and managing risk for several data centers, Security Operations Center, Network Operations Center, and Server Management Team.
Graydon McKee
Graydon McKee is the Vice President and Chief Operating Officer of Ascension Risk Management LLC.Â  Graydon is an accomplished Risk Management/Information Security professional with extensive experience in developing and implementing Information Risk Management and Information Security Programs to clients in both the public and private sector.Â  He is a recognized leader in government regulatory compliance (Federal Information Security Management Act and the Defense Information Technology Security Certification and Accreditation Process compliance) and has taught the process to over 2,000 individuals representing over 600 federal government agencies and offices.Â  
Joe Faraone
Joe Faraone is a Senior Information Security Architect with GCI Corporation, based in Reston, Virginia with over 20 yearsâ€™ experience in Information Security. Joe has delivered services for numerous Federal customers including Certification and Accreditation support, Security Governance Gap Analysis and Independent Validation and Verification (IV&amp;V).Â  Over his career, he has served as Lead Independent Security Engineer, Manager and Architect of a managed security center for an Intelligence Community Agency,</itunes:summary>
		<itunes:author>The Security Catalyst</itunes:author>
		<itunes:explicit>no</itunes:explicit>
	</item>
		<item>
		<title>Security Roundtable for October 11, 2008 &#8211; Social Media Ethics</title>
		<link>http://www.securitycatalyst.com/2008/10/security-roundtable-for-october-11-2008-social-media-ethics/</link>
		<comments>http://www.securitycatalyst.com/2008/10/security-roundtable-for-october-11-2008-social-media-ethics/#comments</comments>
		<pubDate>Wed, 22 Oct 2008 13:43:23 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[ethics]]></category>
		<category><![CDATA[social media]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=577</guid>
		<description><![CDATA[The world of blogging, podcasting and social media is a dynamic â€“and dominant â€“ force in the way individuals share and consume information. In this fast-paced approach to sharing, we stop to consider the ethics involved. With the help of Jennifer LeggioÂ  - social media expert, former journalist and friend of the Security Roundtable â€“ [...]]]></description>
			<content:encoded><![CDATA[<p><!--StartFragment--></p>
<p class="MsoNormal">The world of blogging, podcasting and social media is a dynamic â€“and dominant â€“ force in the way individuals share and consume information. In this fast-paced approach to sharing, we stop to consider the ethics involved.</p>
<p class="MsoNormal">With the help of Jennifer Leggio<span>Â  </span>- social media expert, former journalist and friend of the Security Roundtable â€“ we tackle the issue of ethics. During this highly informative roundtable discussion, we tackle the responsibility (and credibility) of bloggers, podcasters and especially the individual responsibility of those consuming the information.</p>
<p class="MsoNormal">This episode is packed with ideas and comments that will get the juices flowing. If you want to continue to conversation with us â€“ join us in the Security Catalyst Community (just pay attention to the naming standard â€“ you must use your real name).</p>
<h2>Learn more about the participants:</h2>
<p class="MsoNormal"><strong>Jennifer Leggio</strong></p>
<p class="MsoNormal"><a href="http://www.zdnet.com/blog/feeds">http://blogs.zdnet.com/feeds/</a></p>
<p class="MsoNormal"><a href="http://mediaphyter.wordpress.com/">http://mediaphyter.wordpress.com/</a></p>
<p class="MsoNormal"><a href="http://twitter.com/mediaphyter">http://twitter.com/mediaphyter</a></p>
<p class="MsoNormal"><strong>Martin McKeay</strong></p>
<p class="MsoNormal"><a href="http://www.mckeay.net/">http://www.mckeay.net/</a></p>
<p class="MsoNormal"><a href="http://netsecpodcast.com/">http://netsecpodcast.com/</a></p>
<p class="MsoNormal"><a href="http://twitter.com/mckeay">http://twitter.com/mckeay</a></p>
<p class="MsoNormal"><strong>Michael Santarcangelo</strong></p>
<p class="MsoNormal"><a href="http://www.securitycatalyst.com/">http://www.securitycatalyst.com/</a></p>
<p class="MsoNormal"><a href="http://www.securitycatalyst.com/into-the-breach/">http://www.intothebreach.com/</a> (books now available â€“ eBook or hardcover)</p>
<p class="MsoNormal"><a href="http://twitter.com/catalyst">http://twitter.com/catalyst</a></p>
<p><!--EndFragment--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2008/10/security-roundtable-for-october-11-2008-social-media-ethics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securityroundtable.com/podcast/SRT-20081011.mp3" length="38869658" type="audio/mpeg" />
			<itunes:keywords>ethics,social media</itunes:keywords>
		<itunes:subtitle>The world of blogging, podcasting and social media is a dynamic â€“and dominant â€“ force in the way individuals share and consume information. In this fast-paced approach to sharing, we stop to consider the ethics involved. </itunes:subtitle>
		<itunes:summary>The world of blogging, podcasting and social media is a dynamic â€“and dominant â€“ force in the way individuals share and consume information. In this fast-paced approach to sharing, we stop to consider the ethics involved.
With the help of Jennifer LeggioÂ  - social media expert, former journalist and friend of the Security Roundtable â€“ we tackle the issue of ethics. During this highly informative roundtable discussion, we tackle the responsibility (and credibility) of bloggers, podcasters and especially the individual responsibility of those consuming the information.
This episode is packed with ideas and comments that will get the juices flowing. If you want to continue to conversation with us â€“ join us in the Security Catalyst Community (just pay attention to the naming standard â€“ you must use your real name).

Learn more about the participants:
Jennifer Leggio
http://blogs.zdnet.com/feeds/
http://mediaphyter.wordpress.com/
http://twitter.com/mediaphyter
Martin McKeay
http://www.mckeay.net/
http://netsecpodcast.com/
http://twitter.com/mckeay
Michael Santarcangelo
http://www.securitycatalyst.com/
http://www.intothebreach.com/ (books now available â€“ eBook or hardcover)
http://twitter.com/catalyst</itunes:summary>
		<itunes:author>The Security Catalyst</itunes:author>
		<itunes:explicit>no</itunes:explicit>
	</item>
		<item>
		<title>Security Roundtable for September 27, 2008</title>
		<link>http://www.securitycatalyst.com/2008/10/security-roundtable-for-september-27-2008/</link>
		<comments>http://www.securitycatalyst.com/2008/10/security-roundtable-for-september-27-2008/#comments</comments>
		<pubDate>Wed, 01 Oct 2008 12:14:17 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[into the breach]]></category>
		<category><![CDATA[SRT]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=539</guid>
		<description><![CDATA[Social media and social networking continue to spread &#8211; and that includes the security community. If you have heard about twitter, wondered about a service that begins with â€˜twit&#8217; and have pondered the advantages and concerns &#8211; listen in to the Security Roundtable that discusses those very points. Our guest for this episode is Zach [...]]]></description>
			<content:encoded><![CDATA[<p>Social media and social networking continue to spread &#8211; and that includes the security community. If you have heard about twitter, wondered about a service that begins with â€˜twit&#8217; and have pondered the advantages and concerns &#8211; listen in to the Security Roundtable that discusses those very points.</p>
<p>Our guest for this episode is Zach &#8211; security professional, friend of the show and curator of the Security Twits list.</p>
<p>Twitter: <a href="http://twitter.com/">www.twitter.com</a></p>
<p>Zach: <a href="http://twitter.com/quine">http://twitter.com/quine</a></p>
<p>Michael: <a href="http://twitter.com/catalyst">http://twitter.com/catalyst</a></p>
<p>Martin: <a href="http://twitter.com/mckeay">http://twitter.com/mckeay</a></p>
<p>Â </p>
<p>Security Twits: http://n0where.org/security-twits/</p>
<p>Â </p>
<p>Next Recording: Saturday, October 11, 2008 @ 10a Eastern &#8211; look for the live stream (and your chance to participate) around 10:15.</p>
<p>Â </p>
<p>PS: 10 Days after the break-in and theft &#8211; we&#8217;re still working with insurance and others to sort out the mess, get the laptops replaced and head back out on the road. I will be posting a complete run-down of what happened, what we did well, what we learned and how we are going to improve. I&#8217;m also following the advice of my book &#8211; and will be publishing a set of requirements and inviting participation as we all learn smarter ways to protect ourselves. This will hit home for small businesses and those who travel a lot.Â </p>
<p>I am confirming some exciting opportunities this week and next &#8211; and should be back out on the road within the next 10-15 days. The theft slowed us down a bit, but has not stopped us. Not one bit. Thanks for your continued support and help!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2008/10/security-roundtable-for-september-27-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securityroundtable.com/podcast/SRT-20080927.mp3" length="37738682" type="audio/mpeg" />
			<itunes:keywords>catalyst,into the breach,SRT</itunes:keywords>
		<itunes:subtitle>Social media and social networking continue to spread - and that includes the security community. If you have heard about twitter, wondered about a service that begins with â€˜twit&#039; and have pondered the advantages and concerns - listen in to the Secur...</itunes:subtitle>
		<itunes:summary>Social media and social networking continue to spread - and that includes the security community. If you have heard about twitter, wondered about a service that begins with â€˜twit&#039; and have pondered the advantages and concerns - listen in to the Security Roundtable that discusses those very points.

Our guest for this episode is Zach - security professional, friend of the show and curator of the Security Twits list.

Twitter: www.twitter.com

Zach: http://twitter.com/quine

Michael: http://twitter.com/catalyst

Martin: http://twitter.com/mckeay

Â 

Security Twits: http://n0where.org/security-twits/

Â 

Next Recording: Saturday, October 11, 2008 @ 10a Eastern - look for the live stream (and your chance to participate) around 10:15.

Â 

PS: 10 Days after the break-in and theft - we&#039;re still working with insurance and others to sort out the mess, get the laptops replaced and head back out on the road. I will be posting a complete run-down of what happened, what we did well, what we learned and how we are going to improve. I&#039;m also following the advice of my book - and will be publishing a set of requirements and inviting participation as we all learn smarter ways to protect ourselves. This will hit home for small businesses and those who travel a lot.Â 

I am confirming some exciting opportunities this week and next - and should be back out on the road within the next 10-15 days. The theft slowed us down a bit, but has not stopped us. Not one bit. Thanks for your continued support and help!</itunes:summary>
		<itunes:author>The Security Catalyst</itunes:author>
		<itunes:explicit>no</itunes:explicit>
	</item>
		<item>
		<title>Reminder: Catalyst Live! Talkcast tomorrow, 2pm ET</title>
		<link>http://www.securitycatalyst.com/2008/09/reminder-catalyst-live-talkcast-tomorrow-2pm-et/</link>
		<comments>http://www.securitycatalyst.com/2008/09/reminder-catalyst-live-talkcast-tomorrow-2pm-et/#comments</comments>
		<pubDate>Thu, 18 Sep 2008 15:00:27 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[freeware]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[talkcast]]></category>
		<category><![CDATA[talkshoe]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=532</guid>
		<description><![CDATA[I take the stage today to share some insights on &#8220;Awareness that Works&#8221; &#8211; live in Nashville, TN. In the event you were unable to join me in Nashville (or even if you did), we can keep the conversation going tomorrow during the first Catalyst Live! talkcast: Join me on Friday â€“ September 19th â€“ [...]]]></description>
			<content:encoded><![CDATA[<p>I take the stage today to share some insights on &#8220;Awareness that Works&#8221; &#8211; live in Nashville, TN. In the event you were unable to join me in Nashville (or even if you did), we can keep the conversation going tomorrow during the first Catalyst Live! talkcast:</p>
<p><!--StartFragment--></p>
<p class="MsoNormal">Join me on <a href="http://www.talkshoe.com/talkshoe/web/tcForward.jsp?masterId=25233&amp;cmd=tcf">Friday â€“ September 19<sup>th</sup> â€“ at 2pm ET (11am PT) for Catalyst Live!</a> â€“ a live chat hosted by Michael Santarcangelo. This week, we look deeper into my recent freeware experience and welcome Dave Cole from Symantec to the call.</p>
<p class="MsoNormal">Iâ€™ll be monitoring twitter and the talkshoe client during the call, allowing us to field live calls, chats and instant messages. Participate in the conversation!</p>
<h1>Join In!</h1>
<p class="MsoNormal">Join the conversation on <a href="http://www.talkshoe.com/talkshoe/">TalkShoe</a> by using the spiffy browser-only client. For the more adventurous, check out the shiny <a href="http://www.talkshoe.com/talkshoe/web/Downloads.jsp?pushNav=1&amp;cmd=download">TalkShoe Pro Java client</a>.</p>
<p class="MsoNormal">To listen and join in â€“ including to ask questions and engage in the conversation, launch your browser an click here: <a href="http://www.talkshoe.com/talkshoe/web/tcForward.jsp?masterId=25233&amp;cmd=tcf">http://www.talkshoe.com/tc/25233</a> on Friday at 2pm ET.</p>
<p><span>Call in on regular phone or VOIP lines: dial (724) 444-7444 and enter the talkcast ID, 25233.</span><!--EndFragment--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2008/09/reminder-catalyst-live-talkcast-tomorrow-2pm-et/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Roundtable for September 13</title>
		<link>http://www.securitycatalyst.com/2008/09/security-roundtable-for-september-13/</link>
		<comments>http://www.securitycatalyst.com/2008/09/security-roundtable-for-september-13/#comments</comments>
		<pubDate>Wed, 17 Sep 2008 11:30:39 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[mckeay]]></category>
		<category><![CDATA[security roundtable]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=534</guid>
		<description><![CDATA[Martin McKeay and I are evolving the Security Roundtable: weâ€™ll be recording every other week at 7 am Pacific/10a Eastern on Saturday mornings. And weâ€™ll be streaming the recording live (http://hak5radio.com:8000/srt.mp3.m3u), opening a chat session and encouraging more bloggers and podcasters to join us. Our goal is simple: keep the program simple, under an hour [...]]]></description>
			<content:encoded><![CDATA[<p><!--StartFragment--></p>
<p class="MsoNormal">Martin McKeay and I are evolving the <a href="http://www.securityroundtable.com/">Security Roundtable</a>: weâ€™ll be recording every other week at 7 am Pacific/10a Eastern on Saturday mornings. And weâ€™ll be streaming the recording live (http://hak5radio.com:8000/srt.mp3.m3u), opening a chat session and encouraging more bloggers and podcasters to join us.</p>
<p class="MsoNormal">Our goal is simple: keep the program simple, under an hour and relevant while blending together the voices of the community. This is also an opportunity for members of the community to participate through segments. Rather than have a larger, static â€œpanelâ€ of people, weâ€™re exploring more voices, shorter segments and more interactive. Weâ€™d love to know what you think, what you want to hear and if you want to be involved. <span>Â </span></p>
<p class="MsoNormal">While we consider this recording to be an experiment â€“ it is a show where I learned from the conversation. In fact, I look forward to listening to it again. Our guest for the show is Marc Massar, Principal Solutions Architect at Venafi. I had interviewed Venafi previously (and liked their approach) and was happy to welcome Marc to the program.</p>
<p class="MsoNormal">Our rules are/were simple: no sales pitch. Marc didnâ€™t need the rules â€“ heâ€™s got a solid background and jumped right into a meaty discussion about the industry and how we can improve our solutions.</p>
<p class="MsoNormal"><a href="http://www.securityroundtable.com/podcast/SRT-20080913.mp3">Security Roundtable for September 13th, 2008</a></p>
<p class="MsoNormal">The next SRT will be recorded on September 27th, 2008 at 7:00 a.m. PDT.<span>Â  </span>Iâ€™ll be in Las Vegas â€“ so for me, it will actually be nice and early (and Iâ€™ll find some Mountain Dew before we start â€“ MD should sponsor me!).</p>
<p><!--EndFragment--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2008/09/security-roundtable-for-september-13/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securityroundtable.com/podcast/SRT-20080913.mp3" length="49284811" type="audio/mpeg" />
			<itunes:keywords>catalyst,mckeay,security roundtable</itunes:keywords>
		<itunes:subtitle>Martin McKeay and I are evolving the Security Roundtable: weâ€™ll be recording every other week at 7 am Pacific/10a Eastern on Saturday mornings. And weâ€™ll be streaming the recording live (http://hak5radio.com:8000/srt.mp3.m3u),</itunes:subtitle>
		<itunes:summary>Martin McKeay and I are evolving the Security Roundtable: weâ€™ll be recording every other week at 7 am Pacific/10a Eastern on Saturday mornings. And weâ€™ll be streaming the recording live (http://hak5radio.com:8000/srt.mp3.m3u), opening a chat session and encouraging more bloggers and podcasters to join us.
Our goal is simple: keep the program simple, under an hour and relevant while blending together the voices of the community. This is also an opportunity for members of the community to participate through segments. Rather than have a larger, static â€œpanelâ€ of people, weâ€™re exploring more voices, shorter segments and more interactive. Weâ€™d love to know what you think, what you want to hear and if you want to be involved. Â 
While we consider this recording to be an experiment â€“ it is a show where I learned from the conversation. In fact, I look forward to listening to it again. Our guest for the show is Marc Massar, Principal Solutions Architect at Venafi. I had interviewed Venafi previously (and liked their approach) and was happy to welcome Marc to the program.
Our rules are/were simple: no sales pitch. Marc didnâ€™t need the rules â€“ heâ€™s got a solid background and jumped right into a meaty discussion about the industry and how we can improve our solutions.
Security Roundtable for September 13th, 2008
The next SRT will be recorded on September 27th, 2008 at 7:00 a.m. PDT.Â  Iâ€™ll be in Las Vegas â€“ so for me, it will actually be nice and early (and Iâ€™ll find some Mountain Dew before we start â€“ MD should sponsor me!).</itunes:summary>
		<itunes:author>The Security Catalyst</itunes:author>
		<itunes:explicit>no</itunes:explicit>
	</item>
		<item>
		<title>Catalyst Live! Talkcast â€“ Friday</title>
		<link>http://www.securitycatalyst.com/2008/09/catalyst-live-talkcast-%e2%80%93-friday/</link>
		<comments>http://www.securitycatalyst.com/2008/09/catalyst-live-talkcast-%e2%80%93-friday/#comments</comments>
		<pubDate>Mon, 15 Sep 2008 07:49:18 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[freeware]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[talkshoe]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=529</guid>
		<description><![CDATA[Join me on Friday â€“ September 19th â€“ at 2pm ET (11am PT) for Catalyst Live! â€“ a live chat hosted by Michael Santarcangelo. This week, we look deeper into my recent freeware experience and welcome Dave Cole from Symantec to the call. Iâ€™ll be monitoring twitter and the talkshoe client during the call, allowing [...]]]></description>
			<content:encoded><![CDATA[<p><!--StartFragment--></p>
<h1></h1>
<p class="MsoNormal">Join me on <a href="http://www.talkshoe.com/talkshoe/web/tcForward.jsp?masterId=25233&amp;cmd=tcf">Friday â€“ September 19<sup>th</sup> â€“ at 2pm ET (11am PT) for Catalyst Live!</a> â€“ a live chat hosted by Michael Santarcangelo. This week, we look deeper into my recent freeware experience and welcome Dave Cole from Symantec to the call.</p>
<p class="MsoNormal">Iâ€™ll be monitoring twitter and the talkshoe client during the call, allowing us to field live calls, chats and instant messages. Participate in the conversation!</p>
<h1>Join In!</h1>
<p class="MsoNormal">Join the conversation on <a href="http://www.talkshoe.com/talkshoe/">TalkShoe</a> by using the spiffy browser-only client. For the more adventurous, check out the shiny <a href="http://www.talkshoe.com/talkshoe/web/Downloads.jsp?pushNav=1&amp;cmd=download">TalkShoe Pro Java client</a>.</p>
<p class="MsoNormal">To listen and join in â€“ including to ask questions and engage in the conversation, launch your browser an click here: <a href="http://www.talkshoe.com/talkshoe/web/tcForward.jsp?masterId=25233&amp;cmd=tcf">http://www.talkshoe.com/tc/25233</a> on Friday at 2pm ET.</p>
<p class="MsoNormal">Call in on regular phone or VOIP lines: dial (724) 444-7444 and enter the talkcast ID, 25233.Â </p>
<p><!--EndFragment--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2008/09/catalyst-live-talkcast-%e2%80%93-friday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Catalyst Live! &#8211; Talkcast on Thursday, September 4, noon Eastern</title>
		<link>http://www.securitycatalyst.com/2008/09/security-catalyst-live-talkcast-on-thursday-september-4-noon-eastern/</link>
		<comments>http://www.securitycatalyst.com/2008/09/security-catalyst-live-talkcast-on-thursday-september-4-noon-eastern/#comments</comments>
		<pubDate>Tue, 02 Sep 2008 03:04:51 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/2008/09/security-catalyst-live-talkcast-on-thursday-september-4-noon-eastern/</guid>
		<description><![CDATA[The first Security Catalyst Live talkcast is scheduled for Thursday, September 4, 2008 at Noon Eastern. Check it out here: http://www.talkshoe.com/tc/25233 The first episode is going to deal with the question: Is Freeware Really Free? and will feature special guest Dave Cole from Symantec. This is an opportunity to discuss, live, some research findings I [...]]]></description>
			<content:encoded><![CDATA[<p>The first Security Catalyst Live talkcast is scheduled for Thursday, September 4, 2008 at Noon Eastern.</p>
<p>Check it out here: <a href="http://www.talkshoe.com/talkshoe/web/tcForward.jsp?masterId=25233&amp;cmd=tcf">http://www.talkshoe.com/tc/25233</a></p>
<p>The first episode is going to deal with the question: Is Freeware Really Free? and will feature special guest Dave Cole from Symantec.</p>
<p>This is an opportunity to discuss, live, some research findings I will be sharing this week, as well as engaging in good conversation. I look forward to speaking with you on Thursday!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2008/09/security-catalyst-live-talkcast-on-thursday-september-4-noon-eastern/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Catalyst Show for 23 July 2008 &#124; Breach Breakdown with Adam Dodge</title>
		<link>http://www.securitycatalyst.com/2008/07/security-catalyst-show-for-23-july-2008-breach-breakdown-with-adam-dodge/</link>
		<comments>http://www.securitycatalyst.com/2008/07/security-catalyst-show-for-23-july-2008-breach-breakdown-with-adam-dodge/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 02:32:07 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Add new tag]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[breach breakdown]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[dodge]]></category>
		<category><![CDATA[esi]]></category>
		<category><![CDATA[into the breach]]></category>
		<category><![CDATA[ohio]]></category>
		<category><![CDATA[santarcangelo]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=488</guid>
		<description><![CDATA[]]></description>
			<content:encoded><![CDATA[]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2008/07/security-catalyst-show-for-23-july-2008-breach-breakdown-with-adam-dodge/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcast/TSC-20080723.mp3" length="13832950" type="audio/mpeg" />
			<itunes:keywords>Add new tag,breach,breach breakdown,catalyst,dodge,esi,into the breach,ohio,santarcangelo</itunes:keywords>
		<itunes:subtitle></itunes:subtitle>
		<itunes:summary></itunes:summary>
		<itunes:author>The Security Catalyst</itunes:author>
		<itunes:explicit>no</itunes:explicit>
	</item>
		<item>
		<title>Security Catalyst Show &#8211; Pop Culture Security Edition &#8211; July 2008</title>
		<link>http://www.securitycatalyst.com/2008/07/security-catalyst-show-pop-culture-security-edition-july-2008/</link>
		<comments>http://www.securitycatalyst.com/2008/07/security-catalyst-show-pop-culture-security-edition-july-2008/#comments</comments>
		<pubDate>Wed, 16 Jul 2008 04:57:18 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[monty python]]></category>
		<category><![CDATA[PCS]]></category>
		<category><![CDATA[pop culture security]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[thomas crown affair]]></category>
		<category><![CDATA[trojan horse]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=479</guid>
		<description><![CDATA[Whether responsible for security awareness training -- or just interested in communicating more effectively, the PCS series is designed to bring insights that get people thinking differently about protecting information.

This month James Costello and I break down -- in less than 20 minutes -- how to use Pop Culture references and examples to explain two simple security concepts: trojan horse and social engineering.

Time is tight - so we work fast to get rid of the boring and plain ways to explain concepts and share the insights we use to connect with people and make a difference. Listen, learn and contribute!]]></description>
			<content:encoded><![CDATA[<div id="ak7v1">
<p>Whether responsible for security awareness training &#8212; or just interested in communicating more effectively, the PCS series is designed to bring insights that get people thinking differently about protecting information.</p>
<p>This month James Costello and I break down &#8211;<span style="color: #ff0000;"> </span><strong><em><span style="color: #ff0000;">in less than 20 minutes</span></em></strong> &#8212; how to use Pop Culture references and examples to explain two simple security concepts: trojan horse and social engineering.</p>
<p>Time is tight &#8211; so we work fast to get rid of the boring and plain ways to explain concepts and share the insights we use to connect with people and make a difference. Listen, learn and contribute!</p>
<p>Direct Link:Â TSC-20080716.mp3</p>
<p><strong>Call for challenges</strong></p>
<p>Â Email us at: popculturesecurity **SHIFT2** securitycatalyst [dot] com</p>
<p>Â Phone number is 206-350-8346</p>
<p>== Detailed Show Notes After the Break ==</p>
<p>(and by detailed, I mean&#8230; wow. Detailed &#8211; Thanks to James for pulling the links together!!)</p>
<p><span id="more-479"></span><strong>On this episode</strong></p>
<p>5 Critical Life Lessons your can Learn from Kung Fu Panda</p>
<p><a href="http://www.dumblittleman.com/2008/07/5-critical-life-lessons-you-can-learn.html">http://www.dumblittleman.com/2008/07/5-critical-life-lessons-you-can-learn.html</a></p>
<p>Â </p>
<p><strong>The Trojan Horse</strong></p>
<ul class="unIndentedList">
<li>Â Â Â Â Â  Defined:Â  Wikipedia &#8211; original Trojan Horse &#8211; <a href="http://en.wikipedia.org/wiki/Trojan_horse">http://en.wikipedia.org/wiki/Trojan_horse</a></li>
<li>Â Â Â Â Â  Wikipedia -Trojan Horse in computing:Â  http://en.wikipedia.org/wiki/Trojan_horse_(computing)</li>
<li>Â Â Â Â Â  Dictionary.com &#8211; <a href="http://dictionary.reference.com/browse/trojan+horse?x=0&amp;y=0">http://dictionary.reference.com/search?q=trojan+horse&amp;x=0&amp;y=0</a></li>
<li>Â Â Â Â Â  Whatis.com &#8211; <a href="http://searchsecurity.techtarget.com/definition/Trojan-horse">http://searchsecurity.techtarget.com/sDefinition/0,,sid14_gci213221,00.html</a></li>
</ul>
<p>Examples:</p>
<p><em>Ocean&#8217;s Eleven</em> &#8211; not the good one with Frank Sinatra, the remake with George Clooney</p>
<ul class="unIndentedList">
<li>Â Â Â Â Â  IMDB link &#8211; <a href="http://www.imdb.com/title/tt0240772/">http://www.imdb.com/title/tt0240772/</a></li>
<li>Â Â Â Â Â  NetFlix link &#8211; <a href="http://www.netflix.com/Movie/Ocean_s_Eleven/60021783?trkid=222336&amp;lnkctr=srchrd-sr&amp;strkid=1922003599_0_0">http://www.netflix.com/Movie/Ocean_s_Eleven/60021783?trkid=222336&amp;lnkctr=srchrd-sr&amp;strkid=1922003599_0_0</a></li>
<li>Â Â Â Â Â  Trailer &#8211; <a href="http://www.imdb.com/title/tt0240772/trailers-screenplay-vi1822294297">http://www.imdb.com/title/tt0240772/trailers-screenplay-vi1822294297</a></li>
<li>Â Â Â Â Â  Hulu clips:Â  http://www.hulu.com/search/oceans+eleven?company=tbs&amp;type=all</li>
</ul>
<p>Example of a scene:</p>
<p>the container that supposedly contains diamonds sent to the vault that the acrobat is hiding inside.</p>
<p>Â </p>
<p><em>Thomas Crown Affair</em> (Pierce Bronson and the Hottie Rene Russo)</p>
<ul class="unIndentedList">
<li>Â Â Â Â Â  IMDB link &#8211; <a href="http://www.imdb.com/title/tt0155267/">http://www.imdb.com/title/tt0155267/</a></li>
<li>Â Â Â Â Â  NetFlix link &#8211; <a href="http://www.netflix.com/Movie/The_Thomas_Crown_Affair/22589663?trkid=222336&amp;lnkctr=srchrd-sr&amp;strkid=1347506257_0_0">http://www.netflix.com/Movie/The_Thomas_Crown_Affair/22589663?trkid=222336&amp;lnkctr=srchrd-sr&amp;strkid=1347506257_0_0</a></li>
<li>Â Â Â Â Â  Trailer (Requires Real Player) &#8211; http://www.film.com/movies/mediaplayback/the-thomas-crown-affair/17115147</li>
</ul>
<p>Examples of scene:</p>
<p>Early on in the film a statue of horse is delivered to the museum.Â  No one knows what to do with it so it gets set off to the side.Â  There are several people hiding inside who break out to break into the museum</p>
<p>Â </p>
<p><em>Monty Python and the Holy Grail</em></p>
<ul class="unIndentedList">
<li>Â Â Â Â Â  IMDB link &#8211; <a href="http://www.imdb.com/title/tt0071853/">http://www.imdb.com/title/tt0071853/</a></li>
<li>Â Â Â Â Â  Trailer link &#8211; <a href="http://www.imdb.com/title/tt0071853/trailers-screenplay-vi1217855769">http://www.imdb.com/title/tt0071853/trailers-screenplay-vi1217855769</a></li>
<li>Â Â Â Â Â  NetFlix link &#8211; <a href="http://www.netflix.com/Movie/Monty_Python_and_the_Holy_Grail/771476?trkid=222336&amp;lnkctr=srchrd-sr&amp;strkid=784608964_1_0">http://www.netflix.com/Movie/Monty_Python_and_the_Holy_Grail/771476?trkid=222336&amp;lnkctr=srchrd-sr&amp;strkid=784608964_1_0</a></li>
</ul>
<p>Scene:Â  Attacking the castle the French have taken control of &#8211; Trojan Rabbit</p>
<p>This is an example of how some really bad malware is written &#8211; the package gets delivered before the payload is really ready and trojan rabbit will get shot right back out of the castle</p>
<p>Â </p>
<p><strong>Social Engineering</strong></p>
<ul class="unIndentedList">
<li>Â Â Â Â Â  Wikipedia &#8211; http://en.wikipedia.org/wiki/Social_engineering_(security)</li>
<li>Â Â Â Â Â  Dictionary.com &#8211; <a href="http://dictionary.reference.com/browse/social+engineering?x=0&amp;y=0">http://dictionary.reference.com/search?q=social+engineering&amp;x=0&amp;y=0</a></li>
</ul>
<p>Â </p>
<p>Examples:</p>
<p><em>Wall Street</em></p>
<ul class="unIndentedList">
<li>Â Â Â Â Â  IMDB &#8211; <a href="http://www.imdb.com/title/tt0094291/">http://www.imdb.com/title/tt0094291/</a></li>
<li>Â Â Â Â Â  trailer &#8211; <a href="http://www.imdb.com/title/tt0094291/trailers-screenplay-vi3554738457">http://www.imdb.com/title/tt0094291/trailers-screenplay-vi3554738457</a></li>
<li>Â Â Â Â Â  NetFlix link &#8211; <a href="http://www.netflix.com/Movie/Wall_Street/60003330?trkid=222336&amp;lnkctr=srchrd-sr&amp;strkid=790572831_0_0">http://www.netflix.com/Movie/Wall_Street/60003330?trkid=222336&amp;lnkctr=srchrd-sr&amp;strkid=790572831_0_0</a></li>
</ul>
<p>Example scenes:</p>
<p>a) talking with his buddy (James Spader), the attorney is initially reluctant to share any information, but Charlie Sheen&#8217;s character convinces him that everyone is doing it</p>
<p>b) posing as a janitor to gain information.Â  Who has access to your office when you are not there.</p>
<p>Â </p>
<p><em>Monty Python and the Holy Grail</em></p>
<ul class="unIndentedList">
<li>Â Â Â Â Â  IMDB link &#8211; <a href="http://www.imdb.com/title/tt0071853/">http://www.imdb.com/title/tt0071853/</a></li>
<li>Â Â Â Â Â  Trailer link &#8211; <a href="http://www.imdb.com/title/tt0071853/trailers-screenplay-vi1217855769">http://www.imdb.com/title/tt0071853/trailers-screenplay-vi1217855769</a></li>
<li>Â Â Â Â Â  NetFlix link &#8211; <a href="http://www.netflix.com/Movie/Monty_Python_and_the_Holy_Grail/771476?trkid=222336&amp;lnkctr=srchrd-sr&amp;strkid=784608964_1_0">http://www.netflix.com/Movie/Monty_Python_and_the_Holy_Grail/771476?trkid=222336&amp;lnkctr=srchrd-sr&amp;strkid=784608964_1_0</a></li>
</ul>
<p>Example of a scene:</p>
<p>Where Lancelot goes to the castle filled with women because of the Grail shaped light at the top</p>
<p>Also the women attempt to use sex to keep the knights at the castle</p>
<p>Â </p>
<p><em>Fletch</em></p>
<ul class="unIndentedList">
<li>Â Â Â Â Â  IMDB link &#8211; <a href="http://www.imdb.com/title/tt0089155/">http://www.imdb.com/title/tt0089155/</a></li>
<li>Â Â Â Â Â  trailer link &#8211; <a href="http://www.imdb.com/title/tt0089155/trailers-screenplay-vi3064398105">http://www.imdb.com/title/tt0089155/trailers-screenplay-vi3064398105</a></li>
<li>Â Â Â Â Â  NetFlix link &#8211; <a href="http://www.netflix.com/Movie/Fletch/510088?trkid=222336&amp;lnkctr=srchrd-sr&amp;strkid=1956738209_0_0">http://www.netflix.com/Movie/Fletch/510088?trkid=222336&amp;lnkctr=srchrd-sr&amp;strkid=1956738209_0_0</a></li>
</ul>
<p>Â </p>
<p>Chevy Chase/Fletch uses social engineering to obtain the information he needs &#8211; he uses disguises, voices and fake ID&#8217;s to get what he wants</p>
<p>Â </p>
<p><strong><em>Would you participate in a live, call-in show?</em></strong></p>
<p><strong><em>If so, send us an email!!</em></strong></p>
<p>Â </p>
<p><strong>Coming Up</strong></p>
<p><em>August: Lessons learned from Burn Notice on the USA Network</em></p>
<p>This is available, free, as a streamed series. Plenty of clips. Anyone has access and appeals to a wide audience.</p>
<ul class="unIndentedList">
<li>Â Â Â Â Â  USA Network &#8211; full episodes:Â  <a href="http://www.usanetwork.com/series/burnnotice/video/fullep/">http://www.usanetwork.com/series/burnnotice/video/fullep/</a></li>
<li>Â Â Â Â Â  USA Network &#8211; Clips:Â  <a href="http://www.usanetwork.com/series/burnnotice/video/new.html">http://www.usanetwork.com/series/burnnotice/video/new.html</a></li>
<li>Â Â Â Â Â  Hulu &#8211; Clips:Â  <a href="http://www.hulu.com/search?query=burn+notice">http://www.hulu.com/videos/search?query=burn+notice</a></li>
</ul>
<p>If nothing else, check out the interviews with Matt Nix. Brilliant writing!</p>
<p>Â </p>
<p><em>September: Back to School Edition</em></p>
<p>Thinking about School of Rock and Back to School and maybe Summer School thrown in for giggles. Got ideas? Want to be part of the show?<em></em></p>
<p>Â </p>
<p><strong>Movie to watch this month for ideas </strong></p>
<p>Social Engineering &#8211; Defcon last year &#8211; our friend Mike Murray presented The Science of Social Engineering: NLP, Hypnosis and the Science of Persuasion &#8211; available on Google Video here:Â  <a href="http://video.google.com/videoplay?docid=-1210687204734530548&amp;hl=en">http://video.google.com/videoplay?docid=-1210687204734530548&amp;hl=en</a></p>
<p>(and no, he didn&#8217;t &#8220;persuade&#8221; us to include this. It was the Jackson he slipped us)</p>
<p>Â </p>
<p><em>Call for challenges</em></p>
<p><em>Â Email us at: popculturesecurity **SHIFT2** securitycatalyst [dot] com</em></p>
<p><em>Â Phone number is 206-350-8346</p>
<p></em>Â </div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2008/07/security-catalyst-show-pop-culture-security-edition-july-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcast/TSC-20080716.mp3" length="9916855" type="audio/mpeg" />
			<itunes:keywords>catalyst,monty python,PCS,pop culture security,social engineering,thomas crown affair,trojan horse</itunes:keywords>
		<itunes:subtitle>Whether responsible for security awareness training -- or just interested in communicating more effectively, the PCS series is designed to bring insights that get people thinking differently about protecting information.  </itunes:subtitle>
		<itunes:summary>Whether responsible for security awareness training -- or just interested in communicating more effectively, the PCS series is designed to bring insights that get people thinking differently about protecting information.

This month James Costello and I break down -- in less than 20 minutes -- how to use Pop Culture references and examples to explain two simple security concepts: trojan horse and social engineering.

Time is tight - so we work fast to get rid of the boring and plain ways to explain concepts and share the insights we use to connect with people and make a difference. Listen, learn and contribute!</itunes:summary>
		<itunes:author>The Security Catalyst</itunes:author>
		<itunes:explicit>no</itunes:explicit>
	</item>
		<item>
		<title>The July Security Rountable is available: Battling Botnets with Botnets</title>
		<link>http://www.securitycatalyst.com/2008/07/the-july-security-rountable-is-available-battling-botnets-with-botnets/</link>
		<comments>http://www.securitycatalyst.com/2008/07/the-july-security-rountable-is-available-battling-botnets-with-botnets/#comments</comments>
		<pubDate>Wed, 09 Jul 2008 14:51:31 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[ethics]]></category>
		<category><![CDATA[Security Catalyst Community]]></category>
		<category><![CDATA[security roundtable]]></category>
		<category><![CDATA[SRT]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=473</guid>
		<description><![CDATA[Complete details are available here:Â http://www.securityroundtable.com/2008/07/security-roundtable-for-july-2008-battling-botnets-with-botnets/ The discussion ran a bit longer than we alloted, yet even on our review listen proved worth every minute. We raised some interesting questions and look forward to sharing the conversation with you. This is only the beginning and we invite you to share your ideas, insights and feedback in [...]]]></description>
			<content:encoded><![CDATA[<div>
<p class="MsoNormal">Complete details are available here:Â http://www.securityroundtable.com/2008/07/security-roundtable-for-july-2008-battling-botnets-with-botnets/</p>
<p class="MsoNormal">The discussion ran a bit longer than we alloted, yet even on our review listen proved worth every minute. We raised some interesting questions and look forward to sharing the conversation with you. This is only the beginning and we invite you to share your ideas, insights and feedback in the Security Catalyst Community.Â </p>
<p class="MsoNormal">Â </p>
<p class="MsoNormal">Thanks to the panel:</p>
<ul>
<li>Colin Dixon |Â <a href="http://www.cs.washington.edu/homes/ckd/">http://www.cs.washington.edu/homes/ckd/</a></li>
<li>Andrew Hay |Â <a href="http://www.andrewhay.ca/">http://www.andrewhay.ca/</a></li>
<li>Martin McKeay |Â <a href="http://www.mckeay.net">www.mckeay.net</a></li>
<li>Michael Santarcangelo |Â <a href="http://www.securitycatalyst.com">www.securitycatalyst.com</a>Â &amp;Â <a href="http://www.securitycatalyst.com/into-the-breach/">www.intothebreach.com</a></li>
</ul>
<p class="MsoNormal">Joining the conversation in the Security Catalyst Community</p>
<p class="MsoNormal">Share your ideas in theÂ Security Catalyst Community.Â Your participation is your currency (means no charge to join) &#8211; the more you contribute the more you learn and the more valuable the community becomes to everyone (so dive in and share). If you have not yet registered, please remember to useÂ firstname.lastnameÂ as the standard.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2008/07/the-july-security-rountable-is-available-battling-botnets-with-botnets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securityroundtable.com/podcast/SRT-2008-07.mp3" length="65933086" type="audio/mpeg" />
			<itunes:keywords>botnets,catalyst,ethics,Security Catalyst Community,security roundtable,SRT</itunes:keywords>
		<itunes:subtitle>Complete details are available here:Â http://www.securityroundtable.com/2008/07/security-roundtable-for-july-2008-battling-botnets-with-botnets/ The discussion ran a bit longer than we alloted, yet even on our review listen proved worth every minute.</itunes:subtitle>
		<itunes:summary>Complete details are available here:Â http://www.securityroundtable.com/2008/07/security-roundtable-for-july-2008-battling-botnets-with-botnets/
The discussion ran a bit longer than we alloted, yet even on our review listen proved worth every minute. We raised some interesting questions and look forward to sharing the conversation with you. This is only the beginning and we invite you to share your ideas, insights and feedback in the Security Catalyst Community.Â 
Â 
Thanks to the panel:


	Colin Dixon |Â http://www.cs.washington.edu/homes/ckd/
	Andrew Hay |Â http://www.andrewhay.ca/
	Martin McKeay |Â www.mckeay.net
	Michael Santarcangelo |Â www.securitycatalyst.comÂ &amp;Â www.intothebreach.com

Joining the conversation in the Security Catalyst Community
Share your ideas in theÂ Security Catalyst Community.Â Your participation is your currency (means no charge to join) - the more you contribute the more you learn and the more valuable the community becomes to everyone (so dive in and share). If you have not yet registered, please remember to useÂ firstname.lastnameÂ as the standard.</itunes:summary>
		<itunes:author>The Security Catalyst</itunes:author>
		<itunes:explicit>no</itunes:explicit>
	</item>
		<item>
		<title>netcast for this week: I was the (surprise) guest host on the Netsec Podcast</title>
		<link>http://www.securitycatalyst.com/2008/07/netcast-for-this-week-i-was-the-surprise-guest-host-on-the-netsec-podcast/</link>
		<comments>http://www.securitycatalyst.com/2008/07/netcast-for-this-week-i-was-the-surprise-guest-host-on-the-netsec-podcast/#comments</comments>
		<pubDate>Thu, 03 Jul 2008 20:02:45 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[mckeay]]></category>
		<category><![CDATA[netsec podcast]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=466</guid>
		<description><![CDATA[One of the true benefits of sharing thoughts through spoken and written word is the ability to meet quality people. I thrive on conversation &#8211; especially discourse that leads to new understanding. I am a firm believer that through purposeful conversation, honest intentions and open minds we can solve a lot of challenges we face. [...]]]></description>
			<content:encoded><![CDATA[<p>One of the true benefits of sharing thoughts through spoken and written word is the ability to meet quality people. I thrive on conversation &#8211; especially discourse that leads to new understanding. I am a firm believer that through purposeful conversation, honest intentions and open minds we can solve a lot of challenges we face.</p>
<p>So when Martin McKeay and I were &#8220;chatting&#8221; online Tuesday night, he popped in with &#8220;Hey &#8211; no pressure, but do you want to cohost tonight?&#8221; It took about a minute to decide. He shared some links to stories to talk about and I took 30 minutes to read them and write down some ideas &#8211; and then boom &#8211; we recorded.</p>
<p>I really enjoyed the conversation and was really amped at the end. It took me a while to get ready for bed &#8211; my mind was still engaged. I hope you have a similar experience when listening!</p>
<p>Find the show notes here:Â <a href="http://netsecpodcast.com/?p=48">http://netsecpodcast.com/?p=48</a></p>
<p>And the direct link to the program here:Â http://media.libsyn.com/media/mckeay/nsp-070108-ep110.mp3</p>
<p>Â </p>
<p>(PS: I hope you still chose to listen to the programming on The Security Catalyst; however, somewhere in the feedchange, we seem to have confused iTunes. If it doesn&#8217;t look like we have new shows &#8211; you may want to unsubscribe and resubscribe.)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2008/07/netcast-for-this-week-i-was-the-surprise-guest-host-on-the-netsec-podcast/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://media.libsyn.com/media/mckeay/nsp-070108-ep110.mp3" length="60824138" type="audio/mpeg" />
			<itunes:keywords>mckeay,netsec podcast,Podcast,security</itunes:keywords>
		<itunes:subtitle>One of the true benefits of sharing thoughts through spoken and written word is the ability to meet quality people. I thrive on conversation - especially discourse that leads to new understanding. I am a firm believer that through purposeful conversati...</itunes:subtitle>
		<itunes:summary>One of the true benefits of sharing thoughts through spoken and written word is the ability to meet quality people. I thrive on conversation - especially discourse that leads to new understanding. I am a firm believer that through purposeful conversation, honest intentions and open minds we can solve a lot of challenges we face.

So when Martin McKeay and I were &quot;chatting&quot; online Tuesday night, he popped in with &quot;Hey - no pressure, but do you want to cohost tonight?&quot; It took about a minute to decide. He shared some links to stories to talk about and I took 30 minutes to read them and write down some ideas - and then boom - we recorded.

I really enjoyed the conversation and was really amped at the end. It took me a while to get ready for bed - my mind was still engaged. I hope you have a similar experience when listening!

Find the show notes here:Â http://netsecpodcast.com/?p=48

And the direct link to the program here:Â http://media.libsyn.com/media/mckeay/nsp-070108-ep110.mp3

Â 

(PS: I hope you still chose to listen to the programming on The Security Catalyst; however, somewhere in the feedchange, we seem to have confused iTunes. If it doesn&#039;t look like we have new shows - you may want to unsubscribe and resubscribe.)</itunes:summary>
		<itunes:author>The Security Catalyst</itunes:author>
		<itunes:explicit>no</itunes:explicit>
	</item>
		<item>
		<title>Security Roundtable for June 2008: Clarion Call of the Jericho Forum</title>
		<link>http://www.securitycatalyst.com/2008/06/security-roundtable-for-june-2008-clarion-call-of-the-jericho-forum/</link>
		<comments>http://www.securitycatalyst.com/2008/06/security-roundtable-for-june-2008-clarion-call-of-the-jericho-forum/#comments</comments>
		<pubDate>Thu, 12 Jun 2008 04:24:36 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[jericho forum]]></category>
		<category><![CDATA[santarcangelo]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=453</guid>
		<description><![CDATA[If you believe the Jericho Forum has called for the end to firewalls, then you need to stop what you&#8217;re doing and take a listen to this month&#8217;s Security Roundtable. After attending an interesting discussion during RSA, Martin and I invited the Jericho Forum to join us at the roundtable to talk more about what [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>If you believe the Jericho Forum has called for the end to firewalls, then you need to stop what you&#8217;re doing and take a listen to this month&#8217;s Security Roundtable.</p>
<p>After attending an interesting discussion during RSA, Martin and I invited the Jericho Forum to join us at the roundtable to talk more about what Jericho Forum is, an what it does. We learned a lot and share the discussion with you&#8230;</p>
<p>Joining us on the program:</p>
<p>Â </p>
<ul>
<li>Michael Santarcangelo -Â <a href="http://www.securitycatalyst.com/blog/">The Security Catalyst</a>Â and author ofÂ <a href="http://www.securitycatalyst.com/into-the-breach/">Into the Breach</a></li>
<li>Martin McKeay &#8211; Host of theÂ <a href="http://www.mckeay.net/">Network Security Podcast</a>Â and Captain Privacy</li>
<li><a href="http://rationalsecurity.typepad.com/">Chris Hoff</a>Â - Luminary and Jogger</li>
<li>Paul Simmonds (bio below) &#8211; Co-Founder Jericho Forum</li>
<li>Shane Buckley (bio below) &#8211; CEOÂ Rohati Systems</li>
</ul>
<p>Â </p>
<p>Â </p>
<p>Learn more about Jericho Forum:Â <a href="http://www.opengroup.org/jericho/">http://www.opengroup.org/jericho/</a></p>
<p>Â </p>
<p>Â </p>
<p><span style="font-family: Tahoma;"><strong><span style="font-size: x-small;">Paul Simmonds, Co-founder and board of management Jericho ForumÂ  &amp; former CISO, ICI</span></strong><br />
</span>Until May 2008 Paul Simmonds was the CISO at ICI (<a class="moz-txt-link-abbreviated" title="http://www.ici.com" href="BLOCKED::http://www.ici.com">www.ici.com</a>). Paulâ€™s varied career has included Electronic counter-measures, Theatre Lighting, North Sea Oil control systems, JET (Nuclear Fusion Research) and commercial radio.Â Prior to joining ICI in 2001 he was Head of Information Security with a high security web hosting company and before that spent seven years with Motorola, as global information security manager.Â </p>
<p>Paul was awarded European Chief Security Officer of the year at the 2005 SC Magazine Awards and is listed in both the 2004 &amp; 2005 global top 50 most powerful people in networking by the US publication Network World. Â Paul sits on the management board of the Jericho Forum and the Executive Advisory Board of ISSA UK. He also is a British Canoe Union Level 3 Kayak Coach.</p>
<p>Â </p>
<p class="MsoNormal"><strong><span lang="EN-IE">Shane Buckley, President &amp; CEO, Rohati Systems, Inc.</span></strong></p>
<p class="MsoNormal"><strong><span lang="EN-IE">Shane Buckley is the President and Chief Executive Officer at Rohati Systems, Inc. Buckley comes to Rohati with more than 20 years of global executive and general management expertise, having held senior executive positions in the United States, Europe, the Middle East and Asia-Pacific.</span></strong></p>
<p class="MsoNormal">Â </p>
<p class="MsoNormal">Before taking the helm at Rohati, Buckley served as Chief Operating Officer at Nevis Networks, Inc. a leader in network access control. Previously, he was Vice President of Worldwide Enterprises for Juniper Networks. Prior to that, he served as the International President of Peribit Networks, the leader in Network Optimization. Juniper Networks purchased Peribit in June 2005 for $380M. Before Peribit, Buckley served as Chief Executive Officer of Conduit Software, a provider of Directory Assistance and Wireless Applications solutions. Previously, he was Vice President, EMEA at 3Com. In this role, he managed a $2.2 billion business unit and was responsible for 3Comâ€™s distribution strategy, OEM partnerships and reseller channels. Buckley also chaired 3Comâ€™s Global Distribution Council, was a member of the companyâ€™s worldwide OEM steering team, and served as 3Comâ€™s head of operations for the Asia-Pacific Region based in Hong Kong and Tokyo.<span>Â </span></p>
<p class="MsoNormal">Â </p>
<p class="MsoNormal">Buckley is a frequent speaker at high-level industry trade shows and events such as Gitex, CeBIT and The Wall Street Journal Europe conference. He has also contributed to a number of magazines and news programs including MSNBC, SABC and Middle East Business news. He holds an engineering degree from the Cork Institute of Technology in Ireland.</p>
<p>Â </p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2008/06/security-roundtable-for-june-2008-clarion-call-of-the-jericho-forum/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Security Catalyst Show &#8211; Pop Culture Security (debut): Night at the Museum</title>
		<link>http://www.securitycatalyst.com/2008/05/security-catalyst-show-pop-culture-security-debut-night-at-the-museum/</link>
		<comments>http://www.securitycatalyst.com/2008/05/security-catalyst-show-pop-culture-security-debut-night-at-the-museum/#comments</comments>
		<pubDate>Wed, 28 May 2008 12:37:59 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[pop culture security]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=452</guid>
		<description><![CDATA[Learn how to use Pop Culture to connect with those around you. This movie held many lessons for those responsible for security in addition to providing some excellent examples for us to anchor our points to. We will work to keep the program short, informative and useful - especially if you are interested in building a security awareness training program that works!]]></description>
			<content:encoded><![CDATA[<p>Welcome to the debut of the Pop Culture Security program &#8211; a monthly installment of the Security Catalyst Show. Please also welcome James Costello &#8211; the man with the idea for this program and my cohost on this effort. This program explores and explains how to use pop culture to communicate security concepts to those around you. We explain by doing, and respond to your challenges.</p>
<p>This podcast is based, to a large extent, on the work James did in preparing for and delivering a peer to peer session at the RSA conference this year. While sitting at Mel&#8217;s the morning of his presentation, we enjoyed a conversation about the topic that kept on going, and immediately decided the best way to extend the conversation and build on his efforts was to produce a monthly program.</p>
<p>For our first piece of Pop Culture to use as a reference point to better explain security, we selected <a href="http://en.wikipedia.org/wiki/Night_at_the_Museum">Night at the Museum</a> &#8211; a comedy with Ben Stiller that is currently (or was) running on <a href="http://www.hbo.com/">Home Box Office (HBO</a>).Â </p>
<p>Movie at IMDB (including synopsis):Â http://www.imdb.com/title/tt0477347/</p>
<p>Movie Trailer:Â http://www.imdb.com/video/screenplay/vi2459500825/</p>
<p>This movie held many lessons for those responsible for security in addition to providing some excellent examples for us to anchor our points to. We will work to keep the program short, informative and useful &#8211; especially if you are interested in building a security awareness training program that works!</p>
<p>To participate in the monthly challenge:</p>
<ul>
<li>callÂ Â 206-350-8346 and leave us a message with your challenge</li>
<li>email popculturesecurity &amp;at&amp; securitycatalyst dot com</li>
</ul>
<p>Â </p>
<p>PS: I recently purchased a snowball microphone in an effort to streamline my audio programs and preserve quality. So far, I am disappointed with the quality of the unit &#8211; and feel that my sound is hollow and tinny; as such, I&#8217;ll be exploring how to restore the sound quality I appreciate in the coming days. The challenge is capturing sound in a way that works with Skype for many of this interviews, but is still portable. If you have experiences, ideas and suggestions for something functional, portable and reliable &#8211; shoot me a note. In the meantime, enjoy the programs. More to come next week, with an &#8220;Author Interview.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2008/05/security-catalyst-show-pop-culture-security-debut-night-at-the-museum/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>TSC May 21 2008 &#124; The Right Way to Address the Debian OpenSSL Vulnerability</title>
		<link>http://www.securitycatalyst.com/2008/05/tsc-may-21-2008-the-right-way-to-address-the-debian-openssl-vulnerability/</link>
		<comments>http://www.securitycatalyst.com/2008/05/tsc-may-21-2008-the-right-way-to-address-the-debian-openssl-vulnerability/#comments</comments>
		<pubDate>Wed, 21 May 2008 16:21:48 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[openSSL]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[venafi]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=449</guid>
		<description><![CDATA[During this program, Paul (from Venafi) and I start by exploring how to engage business users in the conversation. We progress to tactical and strategic ways to address this challenge while realizing this is an opportunity to make some improvements that bring better future results.

It comes from planning and following a process informed by experience â€“ and weâ€™ll share the insights with you in 30 minutes or less!]]></description>
			<content:encoded><![CDATA[<p><!--StartFragment--></p>
<p class="MsoNormal">It was disclosed last week that a vulnerability in the OpenSSL packages used by debian systems contained a flaw where random numbers were not actually random, paving the way for another attack vector.</p>
<p class="MsoNormal">Plenty of specific details and analysis can be found in different places, including:</p>
<p class="MsoNormal"><a href="http://wiki.debian.org/SSLkeys">http://wiki.debian.org/SSLkeys</a></p>
<p class="MsoNormal"><a href="http://www.us-cert.gov/cas/techalerts/TA08-137A.html">http://www.us-cert.gov/cas/techalerts/TA08-137A.html</a></p>
<p class="MsoNormal"><a href="http://www.kb.cert.org/vuls/id/925211">http://www.kb.cert.org/vuls/id/925211</a></p>
<p class="MsoNormal"><a href="http://secunia.com/advisories/30220/">http://secunia.com/advisories/30220/</a></p>
<p class="MsoNormal">For many, this signals the fire-drill of reaction and patching &#8212; just in time for a big holiday weekend (aka the â€œstart of summerâ€) here in the United States.</p>
<p class="MsoNormal">Just days before this was announced, I was introduced to <a href="http://www.venafi.com/">Venafi</a> (as a direct result of my press pass at RSA). During the conversation, I realized they really own the niche of Systems Management for Encryption. As we shared a lively and informative conversation, I was reminded that SSL is not just something we stick on web servers; it goes deeper and wider in many enterprises today. As soon as you have to manage many of these encrypted connections, the process gains some complication â€“ and is ripe for error. Step in Venafi.</p>
<p class="MsoNormal">When the debian vulnerability was announced, I immediately asked if Venafi would be willing to share some insights about how organizations <em>should</em> be handling this issue. This is bigger than patching (remember code red?) â€“ and I wanted a discussion that provided insights into how to manage this in a way that brought immediate results but also good long-term gain.</p>
<p class="MsoNormal">During this program, <a href="http://www.venafi.com/about/leadership/">Paul</a> (from <a href="http://www.venafi.com/">Venafi</a>) and I start by exploring how to engage business users in the conversation. We progress to tactical and strategic ways to address this challenge while realizing this is an opportunity to make some improvements that bring better future results.</p>
<p class="MsoNormal">It comes from planning and following a process informed by experience â€“ and weâ€™ll share the insights with you in 30 minutes or less!</p>
<p class="MsoNormal">In the wrap-up, I suggest following the approach of plan-do-review, outlined in this podcast: <a href="http://www.securitycatalyst.com/2008/01/the-security-catalyst-show-plan-do-review-your-way-to-success/">http://www.securitycatalyst.com/blog/2008/01/31/the-security-catalyst-show-plan-do-review-your-way-to-success/</a></p>
<p class="MsoNormal">Tune in next week for the debut of the Pop Culture Security podcast â€“ your monthly â€œhow-toâ€ for Security Awareness Training.</p>
<p><!--EndFragment--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2008/05/tsc-may-21-2008-the-right-way-to-address-the-debian-openssl-vulnerability/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>May 2008 Security Round Table &#124; RSA &#8211; Going Beyond the Hype</title>
		<link>http://www.securitycatalyst.com/2008/05/may-2008-security-round-table-rsa-going-beyond-the-hype/</link>
		<comments>http://www.securitycatalyst.com/2008/05/may-2008-security-round-table-rsa-going-beyond-the-hype/#comments</comments>
		<pubDate>Wed, 14 May 2008 23:58:37 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[blogger]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[SRT]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=447</guid>
		<description><![CDATA[I had a great time at RSA 2008 this year, but didn&#8217;t attend any keynotes and only saw some snippets of sessions. Yet I took several *quality* briefings during the course of the week &#8212; and will be interviewing, profiling and sharing my impressions over the coming months. I started the week a bit sad [...]]]></description>
			<content:encoded><![CDATA[<p>I had a great time at RSA 2008 this year, but didn&#8217;t attend any keynotes and only saw some snippets of sessions. Yet I took several *quality* briefings during the course of the week &#8212; and will be interviewing, profiling and sharing my impressions over the coming months. I started the week a bit sad &#8212; after walking the show floor, it felt to me that the industry was, en masse, running in entirely the wrong direction. I ended the week not only with renewed hope, but with new and powerful insights.</p>
<p>RSA carries a lot of hype. Now that the conference is over, Martin and I wanted to go beyond the hype and invited a panel with mixed experience to share with us their impressions, opinions and lessons learned. During this SRT, we cover the role of bloggers as media, the *real* value of RSA and a whole bunch of other interesting issues and perspectives.</p>
<p>I also share, near the end, what I thought the theme should have been. Thinking about it now, it is a good choice for next year, or even for a SCC conference!</p>
<p>This marks the return of the SRT. We already have the June SRT recorded &#8212; a great show with the Jericho Forum, dispelling a lot of myths and providing some good insight into how they are helping to drive change in the industry. In July we&#8217;ll tackle the issue of using botnets to fight botnets and August will revisit a topic raised during the May SRT &#8212; the responsibility of security bloggers and the role of new media.</p>
<p>Happy Listening.</p>
<p>Â </p>
<p>Â </p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2008/05/may-2008-security-round-table-rsa-going-beyond-the-hype/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Security Catalyst Show &#124; Plan &#8211; Do &#8211; Review your way to success</title>
		<link>http://www.securitycatalyst.com/2008/01/the-security-catalyst-show-plan-do-review-your-way-to-success/</link>
		<comments>http://www.securitycatalyst.com/2008/01/the-security-catalyst-show-plan-do-review-your-way-to-success/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 05:56:10 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[high/scope]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/2008/01/31/the-security-catalyst-show-plan-do-review-your-way-to-success/</guid>
		<description><![CDATA[Into the Breach is really taking shape &#8211; but I have been eager to get back behind the microphone and share the ideas and concepts I have been working on. You witnessed my transition to The Security Catalyst last year, and with it, my focus on changing the way people protect information. In this podcast, [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.securitycatalyst.com/into-the-breach/" target="_blank">Into the Breach</a> is really taking shape &#8211; but I have been eager to get back behind the microphone and share the ideas and concepts I have been working on. You witnessed my transition to The Security Catalyst last year, and with it, my focus on changing the way people protect information.</p>
<p>In this podcast, I share a simple and powerful concept that can be applied to anything you do: PLAN &#8211; DO &#8211; REVIEW</p>
<p>I first learned about PLAN &#8211; DO &#8211; REVIEW a few years back when it was time to learn about nursery schools, and one of the schools followed the HIGH/SCOPE method. Curious, I went to explore and learn more. Since then, I have tested and adapted the approach for my own use &#8211; with excellent results.</p>
<p>Now I share my experience with you.</p>
<p>Here are three links if you would like to learn more:</p>
<p>http://www.highscope.org/</p>
<p>http://en.wikipedia.org/wiki/High/Scope</p>
<p>http://www.perpetualpreschool.com/highscope/highscope_info.htm</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2008/01/the-security-catalyst-show-plan-do-review-your-way-to-success/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>The Security Catalyst Podcast: A Conversation with Brian Chess</title>
		<link>http://www.securitycatalyst.com/2007/11/the-security-catalyst-podcast-a-conversation-with-brian-chess/</link>
		<comments>http://www.securitycatalyst.com/2007/11/the-security-catalyst-podcast-a-conversation-with-brian-chess/#comments</comments>
		<pubDate>Thu, 29 Nov 2007 00:18:15 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[application security]]></category>
		<category><![CDATA[brian chess]]></category>
		<category><![CDATA[web security]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/2007/11/28/the-security-catalyst-podcast-a-conversation-with-brian-chess/</guid>
		<description><![CDATA[On this program, we share a conversation with Brian Chess, the author of Secure Programming with Static Analysis &#8211; a conversation that is a must listen for business leaders, security professionals and developers if you want to learn how to engage your teams to better protect information. Brian takes an approach with secure programming that [...]]]></description>
			<content:encoded><![CDATA[<p>On this program, we share a conversation with Brian Chess, the author of <a href="http://www.amazon.com/Programming-Analysis-Addison-Wesley-Software-Security/dp/0321424778/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1196292147&amp;sr=8-1" target="_blank">Secure Programming with Static Analysis</a> &#8211; a conversation that is a must listen for business leaders, security professionals and developers if you want to learn how to engage your teams to better protect information.</p>
<p>Brian takes an approach with secure programming that is similar to the approach I follow when assessing and implementing awareness and training programs. So whether you are a developer or not, you will change the way you protect information by listening to Brian!</p>
<p><strong>What I took away from my conversation with Brian</strong><br />
After reflecting on our conversation (I explain more during the podcast), here are the top five points I took away:</p>
<p>1. Introspection is important when looking to protect information. To me, this also means we have to stop blaming and looking to assign blame. We can look within, take (and encourage) responsibility and find solutions.</p>
<p>2. Trust is paramount.  We have to find ways to establish and maintain trust, offline and online.</p>
<p>3. We need to develop processes and tools to support our experts in a way that naturally engages them and encourages their participation in information protection.</p>
<p>4. New processes, new learning and new tools require an initial investment (time, money and resources) that may sometimes seem sizeable â€“ but the savings are realized rapidly and bring long-term positive benefits.</p>
<p>5. In security, we need to stop griping and learn to be good coming from behind. It&#8217;s okay, and we can do it.</p>
<p>What did you take away from this conversation? Send me an email: securitycatalyst@gmail.com, or better yet &#8211; join us in the security catalyst community â€“ www.securitycatalyst.org and share your insights with others.</p>
<p><strong>Information and Links</strong></p>
<p>Brian Chess, Ph.D., Founder &amp; Chief Scientist</p>
<p>http://extra.fortifysoftware.com/blog/bloggers.html</p>
<p>Dr. Chessâ€™s research focuses on methods for creating secure systems. He received his Ph.D. from the University of California at Santa Cruz, where he applied his background in integrated circuit test and verification to the problem of identifying security errors in software. In addition to authoring numerous patents and technical papers, Dr. Chess has more than ten years of experience in the commercial software arena, having led development efforts at Hewlett Packard and NetLedger.</p>
<p>Secure Programming with Static Analysis<a href="http://www.amazon.com/Programming-Analysis-Addison-Wesley-Software-Security/dp/0321424778/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1196292147&amp;sr=8-1" target="_blank"></p>
<p>http://www.amazon.com/Programming-Analysis-Addison-Wesley-Software-Security/dp/0321424778/ref=sr_1_1?ie=UTF8&#038;s=books&#038;qid=1196292147&#038;sr=8-1</a></p>
<p>Blogging with Brian Chess</p>
<p>http://extra.fortifysoftware.com/blog/</p>
<p><strong>Serving Your Needs</strong><br />
I thoroughly enjoy researching and producing these podcasts â€“ and looking forward to getting back into a programming schedule with a bit more regularity. Iâ€™ve also been impressed with the Talk Shoe service, and considering hosting more podcasts through Talk Shoe so you can listen in live.</p>
<p>Let me know if you would listen live and participate if we made that an option, and who you would like to share a conversation with by sending me a note: securitycatalyst@gmail.comAs always, thanks for the gift you give me by listening. If you liked the program, tell a friend. If not, tell me!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2007/11/the-security-catalyst-podcast-a-conversation-with-brian-chess/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Security Catalyst Podcast â€“ Why Virtual Teams Fail (and how to avoid it)</title>
		<link>http://www.securitycatalyst.com/2007/11/the-security-catalyst-podcast-why-virtual-teams-fail-and-how-to-avoid-it/</link>
		<comments>http://www.securitycatalyst.com/2007/11/the-security-catalyst-podcast-why-virtual-teams-fail-and-how-to-avoid-it/#comments</comments>
		<pubDate>Sat, 03 Nov 2007 11:19:06 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[online collaboration]]></category>
		<category><![CDATA[virtual teams]]></category>
		<category><![CDATA[web working]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/2007/11/03/the-security-catalyst-podcast-%e2%80%93-why-virtual-teams-fail-and-how-to-avoid-it/</guid>
		<description><![CDATA[This podcast explores how and why virtual teams fail, based on new research from a group of graduate students at Johns Hopkins Carey School of Business. My belief is that in order to protect information, we have to support the individual â€“ and make it easier for them to do their job. By learning more [...]]]></description>
			<content:encoded><![CDATA[<p>This podcast explores how and why virtual teams fail, based on new research from a group of graduate students at Johns Hopkins Carey School of Business.</p>
<p>My belief is that in order to protect information, we have to support the individual â€“ and make it easier for them to do their job. By learning more about how virtual teams fail, we can learn how to avoid mistakes and build stronger and more effective collaboration opportunities â€“ where people can do their jobs while taking responsibility for protecting information. By absorbing this research, you may also learn how to work more effectively on your own virtual teams.</p>
<p>After our interview, I share the top five things that I learned about nurturing and protecting virtual teams. I invite you to sit back, listen, learn and contribute. Iâ€™m happy to keep the conversation going in the security catalyst community.</p>
<p><strong>Background: Bring new knowledge to the field of work team behavior</strong><br />
A group of five graduate students (<em>Robert Darling, Cari Endicott, Lisa Fratino, Matsuno Inoue, and Ellen Snydman</em>) from the <a href="http://carey.jhu.edu/" target="_blank">Carey Business School of Johns Hopkins University</a> participating in a team building course under the leadership of Dr. Robert Pernick were charged with bringing new knowledge to the field of teaming.</p>
<p>This group elected to research the world of virtual teaming, and in doing so, found that here is a great body of literature on what makes virtual teams successful, but little written about what causes them to fail or become sub-optimized.Â  The teamâ€™s first research effort was to conduct structured interviews with a group of virtual teaming experts.</p>
<p>The experts interviews generally agreed that the success of virtual teams were threatened by:<br />
â€¢Â Â Â  Concerns regarding the ability to protect sensitive information<br />
â€¢Â Â Â  Lack of a single platform that provides all the tools necessary to optimize<br />
â€¢Â Â Â  The struggles of virtual communication<br />
â€¢Â Â Â  Poorly or under-trained users<br />
â€¢Â Â Â  The challenge of building trustÂ  without the use of face-to-face communication</p>
<p>Overall, the experts agreed that all of these obstacles can be overcome and unless combined into the â€œperfect stormâ€ are not likely to cause catastrophic failure. The experts felt very good about the work that is be done virtually and believe that the use of virtual teams will become even more prevalent into todayâ€™s global society.</p>
<p>The second phase of research involved the distribution of a short, online survey about virtual work.Â  The results of the survey are still be collected, but at this point there seems to be a great deal of overlap with the findings from the subject matter experts.Â  The podcast you are listening to will explore both elements of the research and will introduce yet another subject matter expert, Stu Snydman, the <a href="http://library.stanford.edu/depts/dlss/" target="_blank">Manager of Digital Production at the Stanford University Libraries</a>.</p>
<p>This podcast was created and hosted by Michael Santarcangelo and expertly engineered by Steve Witt. Thank, Steve!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2007/11/the-security-catalyst-podcast-why-virtual-teams-fail-and-how-to-avoid-it/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Security Round Table Episode 4 &#8211; Responsible Reporting of Breaches</title>
		<link>http://www.securitycatalyst.com/2006/09/srt-episode-4-responsible-reporting-of-breaches/</link>
		<comments>http://www.securitycatalyst.com/2006/09/srt-episode-4-responsible-reporting-of-breaches/#comments</comments>
		<pubDate>Sun, 17 Sep 2006 20:23:23 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Security Round Table]]></category>
		<category><![CDATA[Information Protection]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=166</guid>
		<description><![CDATA[How many times have you wondered what you would do if you find out your company wasn&#8217;t protecting information as they promised? What if you were a consultant or contractor? Is there a right way to report on privacy and security breaches? Join the Security Round Table with Special Guest Randal Schwartz to discuss this [...]]]></description>
			<content:encoded><![CDATA[<p>How many times have you wondered what you would do if you find out your company wasn&#8217;t protecting information as they promised? What if you were a consultant or contractor?</p>
<p>Is there a right way to report on privacy and security breaches?</p>
<p>Join the Security Round Table with Special Guest Randal Schwartz to discuss this important issue.</p>
<p>On this episode:</p>
<p>Larry Pesce | <a href="http://www.pauldotcom.com/" target="_blank">Pauldotcom Security Weekly</a> | Haxor the Matrix<br />
Martin McKeay | Network Security Blog &amp; Podcast<br />
Michael Santarcangelo | <a href="http://www.securitycatalyst.com/" target="_blank">The Security Catalyst</a><br />
Randal Schwartz | <a href="http://www.stonehenge.com/merlyn/" target="_blank">Stonehenge</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2006/09/srt-episode-4-responsible-reporting-of-breaches/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

