
<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: A Federal Takeover of Cyber Security?</title>
	<atom:link href="http://techliberation.com/2009/03/13/a-federal-takeover-of-cyber-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://techliberation.com/2009/03/13/a-federal-takeover-of-cyber-security/</link>
	<description>Keeping politicians&#039; hands off the Net &#38; everything else related to technology</description>
	<lastBuildDate>Sun, 27 May 2012 22:43:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Reese Payton</title>
		<link>http://techliberation.com/2009/03/13/a-federal-takeover-of-cyber-security/comment-page-1/#comment-65413</link>
		<dc:creator>Reese Payton</dc:creator>
		<pubDate>Wed, 18 Mar 2009 07:44:30 +0000</pubDate>
		<guid isPermaLink="false">http://techliberation.com/?p=17440#comment-65413</guid>
		<description>&lt;p&gt;Federal responsibility, no way! Please keep us posted on the results.&lt;br&gt;Reese Payton&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Federal responsibility, no way! Please keep us posted on the results.<br />Reese Payton</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Reese Payton</title>
		<link>http://techliberation.com/2009/03/13/a-federal-takeover-of-cyber-security/comment-page-1/#comment-61968</link>
		<dc:creator>Reese Payton</dc:creator>
		<pubDate>Wed, 18 Mar 2009 03:44:30 +0000</pubDate>
		<guid isPermaLink="false">http://techliberation.com/?p=17440#comment-61968</guid>
		<description>&lt;p&gt;Federal responsibility, no way! Please keep us posted on the results.&lt;br&gt;Reese Payton&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Federal responsibility, no way! Please keep us posted on the results.<br />Reese Payton</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Reese Payton</title>
		<link>http://techliberation.com/2009/03/13/a-federal-takeover-of-cyber-security/comment-page-1/#comment-58756</link>
		<dc:creator>Reese Payton</dc:creator>
		<pubDate>Wed, 18 Mar 2009 02:44:30 +0000</pubDate>
		<guid isPermaLink="false">http://techliberation.com/?p=17440#comment-58756</guid>
		<description>&lt;p&gt;Federal responsibility, no way! Please keep us posted on the results.&lt;br&gt;Reese Payton&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Federal responsibility, no way! Please keep us posted on the results.<br />Reese Payton</p>]]></content:encoded>
	</item>
	<item>
		<title>By: rybolov</title>
		<link>http://techliberation.com/2009/03/13/a-federal-takeover-of-cyber-security/comment-page-1/#comment-58720</link>
		<dc:creator>rybolov</dc:creator>
		<pubDate>Mon, 16 Mar 2009 14:00:46 +0000</pubDate>
		<guid isPermaLink="false">http://techliberation.com/?p=17440#comment-58720</guid>
		<description>&lt;p&gt;Hi jim and Tim&lt;br&gt;&lt;br&gt;The key problem for security is mentioned in the Princeton podcast: there is a shortage of skilled labor and a shortage of people who are cross-trained into having some security skills.&lt;br&gt;&lt;br&gt;One thing I want to make clear: there is no return on investment for security.  Security is a cost, and only in very rare circumstances is there a return on security costs.  Instead, good security is cost reduction or loss prevention, an entirely different model.&lt;br&gt;&lt;br&gt;We do have some industry self-regulation happening.  PCI-DSS is a good example.&lt;br&gt;&lt;br&gt;I do see a disconnect in Jim&#039;s article.  Forensics do not equal liability, they equal the ability to track down the &quot;real&quot; evildoer, but you still might have an issue of negligence.  Negligence is a better model for us to look at when we set public policy.&lt;br&gt;&lt;br&gt;If you really want to push security in public policy, have a look at the various data breach laws that have been pushed.  S.459 comes to mind.  &lt;a href=&quot;http://thomas.loc.gov/cgi-bin/bdquery/z?d110:S495:&quot; rel=&quot;nofollow&quot;&gt;http://thomas.loc.gov/cgi-bin/bdquery/z?d110:S495:&lt;/a&gt;&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Hi jim and Tim<br /><br />The key problem for security is mentioned in the Princeton podcast: there is a shortage of skilled labor and a shortage of people who are cross-trained into having some security skills.<br /><br />One thing I want to make clear: there is no return on investment for security.  Security is a cost, and only in very rare circumstances is there a return on security costs.  Instead, good security is cost reduction or loss prevention, an entirely different model.<br /><br />We do have some industry self-regulation happening.  PCI-DSS is a good example.<br /><br />I do see a disconnect in Jim&#39;s article.  Forensics do not equal liability, they equal the ability to track down the &#8220;real&#8221; evildoer, but you still might have an issue of negligence.  Negligence is a better model for us to look at when we set public policy.<br /><br />If you really want to push security in public policy, have a look at the various data breach laws that have been pushed.  S.459 comes to mind.  <a href="http://thomas.loc.gov/cgi-bin/bdquery/z?d110:S495:" rel="nofollow">http://thomas.loc.gov/cgi-bin/bdquery/z?d110:S495:</a></p>]]></content:encoded>
	</item>
</channel>
</rss>

