<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
>

<channel>
	<title>Speaking of Security - The RSA Blog and Podcast &#187; Jason Rader</title>
	<atom:link href="http://blogs.rsa.com/author/jrader/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.rsa.com</link>
	<description>The Security Blog for Security Professionals</description>
	<lastBuildDate>Fri, 17 May 2013 12:30:58 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5</generator>
<!-- podcast_generator="Blubrry PowerPress/4.0.7" -->
	<itunes:summary>The Speaking of Security podcast features lively discussion with industry experts on the latest issues and trends in the security industry.</itunes:summary>
	<itunes:author>RSA, The Security Division of EMC</itunes:author>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://blogs.rsa.com/wp-content/uploads/userphoto/sos.png" />
	<itunes:owner>
		<itunes:name>RSA, The Security Division of EMC</itunes:name>
		<itunes:email>podcast@rsa.com</itunes:email>
	</itunes:owner>
	<managingEditor>podcast@rsa.com (RSA, The Security Division of EMC)</managingEditor>
	<itunes:subtitle>The Security Blog for Security Professionals</itunes:subtitle>
	<itunes:keywords>Security, Cyber Crime, APTs, Sam Curry, RSA, EMC, Advanced Persistant Threats, Fraud</itunes:keywords>
	<image>
		<title>Speaking of Security - The RSA Blog and Podcast &#187; Jason Rader</title>
		<url>http://blogs.rsa.com/wp-content/uploads/userphoto/sos.png</url>
		<link>http://blogs.rsa.com</link>
	</image>
	<itunes:category text="Technology">
		<itunes:category text="Tech News" />
		<itunes:category text="Podcasting" />
	</itunes:category>
		<item>
		<title>Want to Save the Universe?</title>
		<link>http://blogs.rsa.com/want-to-save-the-universe/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=want-to-save-the-universe</link>
		<comments>http://blogs.rsa.com/want-to-save-the-universe/#comments</comments>
		<pubDate>Tue, 08 Jan 2013 13:30:13 +0000</pubDate>
		<dc:creator>Jason Rader</dc:creator>
				<category><![CDATA[Big data]]></category>
		<category><![CDATA[Cyber Security Training]]></category>
		<category><![CDATA[Data Loss Prevention]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[Governance, Risk & Compliance (GRC)]]></category>
		<category><![CDATA[Advanced Persistent Threats]]></category>
		<category><![CDATA[CIRC]]></category>
		<category><![CDATA[RSA Conference]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=7662</guid>
		<description><![CDATA[I like Star Trek. I’ve always wanted to be Captain Kirk (had to pick one…Picard is great too) sitting in that chair on the bridge of the Enterprise with seemingly endless resources at my disposal with a mission to protect the universe. I’m not giving up, but that’s probably not going to happen. However, I do get a bit of the same thrill as I have the opportunity to work in the Critical Incident Response Center lab we have set up at RSA for research and demonstration purposes.]]></description>
				<content:encoded><![CDATA[<p>I like Star Trek. I’ve always wanted to be Captain Kirk (had to pick one…Picard is great too) sitting in that chair on the bridge of the Enterprise with seemingly endless resources at my disposal with a mission to protect the universe. I’m not giving up, but that’s probably not going to happen. However, I do get a bit of the same thrill as I have the opportunity to work in the Critical Incident Response Center lab we have set up at RSA for research and demonstration purposes.</p>
<p>Affectionately known as the “mini-CIRC”, this impressive lab is modeled after the real EMC CIRC and similarly leverages EMC and RSA products into an Enterprise console (see what I did there?). Unlike the production CIRC at EMC, the mini-CIRC has dozens of virtual machines assembled as attackers, malware distribution sites, drop zones, and command &amp; control servers. It allows a group of analysts to operate in a real environment with the real tools and the real screens and try to detect and fend off a real attack.  Make no mistake, this is no screen shot click thru…it’s the real tools with real data that’s being generated in real time…but unlike real life, if something goes horribly wrong in the mini-CIRC we can reset it back and debrief and give it another try.</p>
<p><a href="http://blogs.rsa.com/wp-content/uploads/CIRC-DSC_363.jpg"><img class="alignnone size-large wp-image-7679" alt="CIRC-DSC_363" src="http://blogs.rsa.com/wp-content/uploads/CIRC-DSC_363-1024x665.jpg" width="468" height="303" /></a></p>
<h3>Kobayashi Maru anyone?</h3>
<p>This safe environment gives us the opportunity to train analysts on not just the tools but also the techniques, the team dynamics, and the processes and procedures involved in a real attack. Like the <span style="text-decoration: underline"><strong><a href="http://en.wikipedia.org/wiki/Kobayashi_Maru">Kobayashi Maru</a></strong></span> in Star Trek we can keep playing the “unwinnable scenario” until we’ve learned the attacker’s techniques and methods. Then we can take this knowledge and ingest it back into our real program. When the Klingons alter their attack, we alter the scenario and can keep our response current.</p>
<h3>How Can I Play?</h3>
<p>We are working on several ways to allow those with a desire to get access to this resource. RSA Conference will be an opportunity for those who attend the 2013 conference in San Francisco who desire some hands on access to get some. Our Executive Briefing Center also has plans to make this available for those who visit the RSA EBC in Bedford, MA. And for those wanting extensive time and training, RSA Education Services is developing a full course called the Advanced Threat Workshop that includes multiple days in this environment working with a team and assuming different roles.</p>
<p>If you’re interested in more information about obtaining the skills and getting the practice required to save the universe, Jason Rader can be contacted via <strong><span style="text-decoration: underline"><a href="mailto:jason.rader@rsa.com">jason.rader@rsa.com</a></span></strong></p>
<p><em>Jason Rader is the Chief Security Strategist for RSA Global Services</em></p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fwant-to-save-the-universe%2F&amp;t=Want%20to%20Save%20the%20Universe%3F"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Want%20to%20Save%20the%20Universe%3F%20-%20http%3A%2F%2Fblogs.rsa.com%2Fwant-to-save-the-universe%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fwant-to-save-the-universe%2F&amp;title=Want%20to%20Save%20the%20Universe%3F&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=I%20like%20Star%20Trek.%20I%E2%80%99ve%20always%20wanted%20to%20be%20Captain%20Kirk%20%28had%20to%20pick%20one%E2%80%A6Picard%20is%20great%20too%29%20sitting%20in%20that%20chair%20on%20the%20bridge%20of%20the%20Enterprise%20with%20seemingly%20endless%20resources%20at%20my%20disposal%20with%20a%20mission%20to%20protect%20the%20universe.%20I%E2%80%99m%20not%20giving%20up%2C%20but%20that%E2%80%99s%20probably%20not%20going%20to%20happen.%20However%2C%20I%20do%20get%20a%20bit%20of%20the%20same%20thrill%20as%20I%20have%20the%20opportunity%20to%20work%20in%20the%20Critical%20Incident%20Response%20Center%20lab%20we%20have%20set%20up%20at%20RSA%20for%20research%20and%20demonstration%20purposes."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Want%20to%20Save%20the%20Universe%3F&body=http%3A%2F%2Fblogs.rsa.com%2Fwant-to-save-the-universe%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-7662')" id="sociable-post-7662" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fwant-to-save-the-universe%2F&amp;t=Want%20to%20Save%20the%20Universe%3F"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fwant-to-save-the-universe%2F&amp;title=Want%20to%20Save%20the%20Universe%3F&amp;notes=I%20like%20Star%20Trek.%20I%E2%80%99ve%20always%20wanted%20to%20be%20Captain%20Kirk%20%28had%20to%20pick%20one%E2%80%A6Picard%20is%20great%20too%29%20sitting%20in%20that%20chair%20on%20the%20bridge%20of%20the%20Enterprise%20with%20seemingly%20endless%20resources%20at%20my%20disposal%20with%20a%20mission%20to%20protect%20the%20universe.%20I%E2%80%99m%20not%20giving%20up%2C%20but%20that%E2%80%99s%20probably%20not%20going%20to%20happen.%20However%2C%20I%20do%20get%20a%20bit%20of%20the%20same%20thrill%20as%20I%20have%20the%20opportunity%20to%20work%20in%20the%20Critical%20Incident%20Response%20Center%20lab%20we%20have%20set%20up%20at%20RSA%20for%20research%20and%20demonstration%20purposes."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fwant-to-save-the-universe%2F&amp;title=Want%20to%20Save%20the%20Universe%3F&amp;bodytext=I%20like%20Star%20Trek.%20I%E2%80%99ve%20always%20wanted%20to%20be%20Captain%20Kirk%20%28had%20to%20pick%20one%E2%80%A6Picard%20is%20great%20too%29%20sitting%20in%20that%20chair%20on%20the%20bridge%20of%20the%20Enterprise%20with%20seemingly%20endless%20resources%20at%20my%20disposal%20with%20a%20mission%20to%20protect%20the%20universe.%20I%E2%80%99m%20not%20giving%20up%2C%20but%20that%E2%80%99s%20probably%20not%20going%20to%20happen.%20However%2C%20I%20do%20get%20a%20bit%20of%20the%20same%20thrill%20as%20I%20have%20the%20opportunity%20to%20work%20in%20the%20Critical%20Incident%20Response%20Center%20lab%20we%20have%20set%20up%20at%20RSA%20for%20research%20and%20demonstration%20purposes."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fwant-to-save-the-universe%2F&amp;title=Want%20to%20Save%20the%20Universe%3F"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fwant-to-save-the-universe%2F&title=Want%20to%20Save%20the%20Universe%3F"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fwant-to-save-the-universe%2F&amp;title=Want%20to%20Save%20the%20Universe%3F&amp;annotation=I%20like%20Star%20Trek.%20I%E2%80%99ve%20always%20wanted%20to%20be%20Captain%20Kirk%20%28had%20to%20pick%20one%E2%80%A6Picard%20is%20great%20too%29%20sitting%20in%20that%20chair%20on%20the%20bridge%20of%20the%20Enterprise%20with%20seemingly%20endless%20resources%20at%20my%20disposal%20with%20a%20mission%20to%20protect%20the%20universe.%20I%E2%80%99m%20not%20giving%20up%2C%20but%20that%E2%80%99s%20probably%20not%20going%20to%20happen.%20However%2C%20I%20do%20get%20a%20bit%20of%20the%20same%20thrill%20as%20I%20have%20the%20opportunity%20to%20work%20in%20the%20Critical%20Incident%20Response%20Center%20lab%20we%20have%20set%20up%20at%20RSA%20for%20research%20and%20demonstration%20purposes."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fwant-to-save-the-universe%2F&amp;t=Want%20to%20Save%20the%20Universe%3F"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Want%20to%20Save%20the%20Universe%3F&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fwant-to-save-the-universe%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=I%20like%20Star%20Trek.%20I%E2%80%99ve%20always%20wanted%20to%20be%20Captain%20Kirk%20%28had%20to%20pick%20one%E2%80%A6Picard%20is%20great%20too%29%20sitting%20in%20that%20chair%20on%20the%20bridge%20of%20the%20Enterprise%20with%20seemingly%20endless%20resources%20at%20my%20disposal%20with%20a%20mission%20to%20protect%20the%20universe.%20I%E2%80%99m%20not%20giving%20up%2C%20but%20that%E2%80%99s%20probably%20not%20going%20to%20happen.%20However%2C%20I%20do%20get%20a%20bit%20of%20the%20same%20thrill%20as%20I%20have%20the%20opportunity%20to%20work%20in%20the%20Critical%20Incident%20Response%20Center%20lab%20we%20have%20set%20up%20at%20RSA%20for%20research%20and%20demonstration%20purposes."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fwant-to-save-the-universe%2F&amp;Title=Want%20to%20Save%20the%20Universe%3F"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fwant-to-save-the-universe%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fwant-to-save-the-universe%2F&amp;title=Want%20to%20Save%20the%20Universe%3F&amp;selection=I%20like%20Star%20Trek.%20I%E2%80%99ve%20always%20wanted%20to%20be%20Captain%20Kirk%20%28had%20to%20pick%20one%E2%80%A6Picard%20is%20great%20too%29%20sitting%20in%20that%20chair%20on%20the%20bridge%20of%20the%20Enterprise%20with%20seemingly%20endless%20resources%20at%20my%20disposal%20with%20a%20mission%20to%20protect%20the%20universe.%20I%E2%80%99m%20not%20giving%20up%2C%20but%20that%E2%80%99s%20probably%20not%20going%20to%20happen.%20However%2C%20I%20do%20get%20a%20bit%20of%20the%20same%20thrill%20as%20I%20have%20the%20opportunity%20to%20work%20in%20the%20Critical%20Incident%20Response%20Center%20lab%20we%20have%20set%20up%20at%20RSA%20for%20research%20and%20demonstration%20purposes."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fwant-to-save-the-universe%2F&amp;t=Want%20to%20Save%20the%20Universe%3F&amp;s=I%20like%20Star%20Trek.%20I%E2%80%99ve%20always%20wanted%20to%20be%20Captain%20Kirk%20%28had%20to%20pick%20one%E2%80%A6Picard%20is%20great%20too%29%20sitting%20in%20that%20chair%20on%20the%20bridge%20of%20the%20Enterprise%20with%20seemingly%20endless%20resources%20at%20my%20disposal%20with%20a%20mission%20to%20protect%20the%20universe.%20I%E2%80%99m%20not%20giving%20up%2C%20but%20that%E2%80%99s%20probably%20not%20going%20to%20happen.%20However%2C%20I%20do%20get%20a%20bit%20of%20the%20same%20thrill%20as%20I%20have%20the%20opportunity%20to%20work%20in%20the%20Critical%20Incident%20Response%20Center%20lab%20we%20have%20set%20up%20at%20RSA%20for%20research%20and%20demonstration%20purposes."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fwant-to-save-the-universe%2F&amp;title=Want%20to%20Save%20the%20Universe%3F&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fwant-to-save-the-universe%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-7662')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-7662',true)" class="close">

		  <img onclick="hide_sociable('post-7662',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/want-to-save-the-universe/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/want-to-save-the-universe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2013 Security Resolutions</title>
		<link>http://blogs.rsa.com/2013-security-resolutions/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=2013-security-resolutions</link>
		<comments>http://blogs.rsa.com/2013-security-resolutions/#comments</comments>
		<pubDate>Wed, 02 Jan 2013 17:30:14 +0000</pubDate>
		<dc:creator>Jason Rader</dc:creator>
				<category><![CDATA[Cyber Security Training]]></category>
		<category><![CDATA[Governance, Risk & Compliance (GRC)]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[security strategy]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=7659</guid>
		<description><![CDATA[Now that the Mayan calendar gives us until October 13, 4772, we have some time to focus on 2013 in earnest. As I was thinking of my resolutions for 2013, I thought I'd compile some of the things that I predict will be on the resolution list for many organizations in the New Year.]]></description>
				<content:encoded><![CDATA[<div>
<p>Now that the <span style="text-decoration: underline"><strong><a href="http://en.wikipedia.org/wiki/Maya_calendar">Mayan calendar</a></strong></span> gives us until October 13, 4772, we have some time to focus on 2013 in earnest. As I was thinking of my resolutions for 2013, I thought I&#8217;d compile some of the things that I predict will be on the resolution list for many organizations in the New Year.</p>
</div>
<h2>Start With A Strategy</h2>
<p>Sounds silly, I know, but some people still shoot from the hip when it comes to security initiatives and their desired outcomes, how they map back to business objectives, and what metrics to use to measure success. I know it can be a hassle getting all of the business units together and mediating the process, but it’s worth it! Everyone understanding the goals and having their input validated will go a long way to getting buy-in across the board. And that will go a long way to the success of the strategy.</p>
<h2>Leverage What You’re Already Doing</h2>
<p>Chances are, you’re already doing a pretty good job in many areas. One opportunity for a more secure 2013 could be to leverage the efforts that may be siloed in your organization and look at them as parts of an overall solution. Part of your strategy should have been to define what security capabilities are needed to support the business objectives…and these capabilities can most likely be obtained by using the investment in people, process, and technology that has already been made and augmenting it with a holistic approach to the problem. Security analytics could be the glue for this.</p>
<h2>Reevaluate The Tools You’re Using</h2>
<p>&#8220;If you do what you’ve always done, you’re going to get what you’ve always gotten.&#8221; This may sound like the opposite of the previous point, but bear with me…it is very possible that the amount of effort it takes for your highly skilled security team to detect a security incident could be reduced by simply changing or adding some capabilities. Less effort = less time = quicker resolution = less exposure to the threat. That is pretty simple math. <img src='http://blogs.rsa.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<h2>Invest In Your People &#8211; “Sharpen the Saw”</h2>
<p>Let’s not forget the people who are keeping our data safe and within the perimeter of our networks. These folks are great but they are typically buried in operations all day. This means that all of their opportunity to learn new skills happens on the job…which could lead to a situation where the “learning experience” results in an exposure.  As you plan for 2013, plan to allow these folks some downtime to attend conferences, take classes to enhance their skills, and play in the lab with new technologies and tools. Right now, these folks are in high demand, and retaining top talent should always be a top priority.</p>
<p>That’s my short list…I hope this validated your 2013 security plan, and if not, you’ve still got a little time before the ball drops.</p>
<p><em>Jason Rader is the Chief Security Strategist for RSA Global Services; he can be reached at <a href="mailto:jason.rader@rsa.com">jason.rader@rsa.com</a></em></p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2F2013-security-resolutions%2F&amp;t=2013%20Security%20Resolutions"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=2013%20Security%20Resolutions%20-%20http%3A%2F%2Fblogs.rsa.com%2F2013-security-resolutions%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2F2013-security-resolutions%2F&amp;title=2013%20Security%20Resolutions&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=Now%20that%20the%20Mayan%20calendar%20gives%20us%20until%20October%2013%2C%204772%2C%20we%20have%20some%20time%20to%20focus%20on%202013%20in%20earnest.%20As%20I%20was%20thinking%20of%20my%20resolutions%20for%202013%2C%20I%20thought%20I%27d%20compile%20some%20of%20the%20things%20that%20I%20predict%20will%20be%20on%20the%20resolution%20list%20for%20many%20organizations%20in%20the%20New%20Year."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=2013%20Security%20Resolutions&body=http%3A%2F%2Fblogs.rsa.com%2F2013-security-resolutions%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-7659')" id="sociable-post-7659" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2F2013-security-resolutions%2F&amp;t=2013%20Security%20Resolutions"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2F2013-security-resolutions%2F&amp;title=2013%20Security%20Resolutions&amp;notes=Now%20that%20the%20Mayan%20calendar%20gives%20us%20until%20October%2013%2C%204772%2C%20we%20have%20some%20time%20to%20focus%20on%202013%20in%20earnest.%20As%20I%20was%20thinking%20of%20my%20resolutions%20for%202013%2C%20I%20thought%20I%27d%20compile%20some%20of%20the%20things%20that%20I%20predict%20will%20be%20on%20the%20resolution%20list%20for%20many%20organizations%20in%20the%20New%20Year."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2F2013-security-resolutions%2F&amp;title=2013%20Security%20Resolutions&amp;bodytext=Now%20that%20the%20Mayan%20calendar%20gives%20us%20until%20October%2013%2C%204772%2C%20we%20have%20some%20time%20to%20focus%20on%202013%20in%20earnest.%20As%20I%20was%20thinking%20of%20my%20resolutions%20for%202013%2C%20I%20thought%20I%27d%20compile%20some%20of%20the%20things%20that%20I%20predict%20will%20be%20on%20the%20resolution%20list%20for%20many%20organizations%20in%20the%20New%20Year."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2F2013-security-resolutions%2F&amp;title=2013%20Security%20Resolutions"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2F2013-security-resolutions%2F&title=2013%20Security%20Resolutions"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2F2013-security-resolutions%2F&amp;title=2013%20Security%20Resolutions&amp;annotation=Now%20that%20the%20Mayan%20calendar%20gives%20us%20until%20October%2013%2C%204772%2C%20we%20have%20some%20time%20to%20focus%20on%202013%20in%20earnest.%20As%20I%20was%20thinking%20of%20my%20resolutions%20for%202013%2C%20I%20thought%20I%27d%20compile%20some%20of%20the%20things%20that%20I%20predict%20will%20be%20on%20the%20resolution%20list%20for%20many%20organizations%20in%20the%20New%20Year."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2F2013-security-resolutions%2F&amp;t=2013%20Security%20Resolutions"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=2013%20Security%20Resolutions&amp;URL=http%3A%2F%2Fblogs.rsa.com%2F2013-security-resolutions%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=Now%20that%20the%20Mayan%20calendar%20gives%20us%20until%20October%2013%2C%204772%2C%20we%20have%20some%20time%20to%20focus%20on%202013%20in%20earnest.%20As%20I%20was%20thinking%20of%20my%20resolutions%20for%202013%2C%20I%20thought%20I%27d%20compile%20some%20of%20the%20things%20that%20I%20predict%20will%20be%20on%20the%20resolution%20list%20for%20many%20organizations%20in%20the%20New%20Year."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2F2013-security-resolutions%2F&amp;Title=2013%20Security%20Resolutions"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2F2013-security-resolutions%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2F2013-security-resolutions%2F&amp;title=2013%20Security%20Resolutions&amp;selection=Now%20that%20the%20Mayan%20calendar%20gives%20us%20until%20October%2013%2C%204772%2C%20we%20have%20some%20time%20to%20focus%20on%202013%20in%20earnest.%20As%20I%20was%20thinking%20of%20my%20resolutions%20for%202013%2C%20I%20thought%20I%27d%20compile%20some%20of%20the%20things%20that%20I%20predict%20will%20be%20on%20the%20resolution%20list%20for%20many%20organizations%20in%20the%20New%20Year."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2F2013-security-resolutions%2F&amp;t=2013%20Security%20Resolutions&amp;s=Now%20that%20the%20Mayan%20calendar%20gives%20us%20until%20October%2013%2C%204772%2C%20we%20have%20some%20time%20to%20focus%20on%202013%20in%20earnest.%20As%20I%20was%20thinking%20of%20my%20resolutions%20for%202013%2C%20I%20thought%20I%27d%20compile%20some%20of%20the%20things%20that%20I%20predict%20will%20be%20on%20the%20resolution%20list%20for%20many%20organizations%20in%20the%20New%20Year."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2F2013-security-resolutions%2F&amp;title=2013%20Security%20Resolutions&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2F2013-security-resolutions%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-7659')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-7659',true)" class="close">

		  <img onclick="hide_sociable('post-7659',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/2013-security-resolutions/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/2013-security-resolutions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Worried about Advanced Threats? RSA Education Services can help!</title>
		<link>http://blogs.rsa.com/worried-about-advanced-threats-rsa-education-services-can-help/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=worried-about-advanced-threats-rsa-education-services-can-help</link>
		<comments>http://blogs.rsa.com/worried-about-advanced-threats-rsa-education-services-can-help/#comments</comments>
		<pubDate>Mon, 10 Dec 2012 13:30:34 +0000</pubDate>
		<dc:creator>Jason Rader</dc:creator>
				<category><![CDATA[Cyber Security Training]]></category>
		<category><![CDATA[Cybercrime and Fraud]]></category>
		<category><![CDATA[Cyberwarfare]]></category>
		<category><![CDATA[RSA Conference]]></category>
		<category><![CDATA[Security Management]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=7423</guid>
		<description><![CDATA[“We need to champion and develop a new breed of Cyber Security Analyst…This new breed of analyst must have the right analytical skills, ‘big picture’ thinking and much needed collaborative “people skills” to ensure smooth information sharing with multiple stakeholders.” - Art Coviello]]></description>
				<content:encoded><![CDATA[<p>I’d like to start out with a quote from RSA’s Executive Chairman, Art Coviello, from his Keynote at RSA Conference in February this year…</p>
<p><strong><em>“We need to champion and develop a new breed of Cyber Security Analyst…This new breed of analyst must have the right analytical skills, ‘big picture’ thinking and much needed collaborative “people skills” to ensure smooth information sharing with multiple stakeholders.”</em></strong></p>
<p>Since then, that quote has pretty much been our mantra here in RSA Education Services as we’ve updated our RSA NetWitness courses and are charging forward with our new Advanced Cyber Defense curriculum. Both of these efforts are exciting to me and I’ll definitely blog again about them at a later date. For now, let’s talk about the update to our <span style="text-decoration: underline;"><strong><a href="https://training.rsasecurity.com/etraining_enu/start.swe?SWERowId=1-2DLC09&amp;SWEField=s_1_1_21_20&amp;SWERowIds=SWERowId0%3d1-2DLC09&amp;SWENeedContext=true&amp;SWESP=false&amp;SWEMethod=Drilldown&amp;SWECmd=InvokeMethod&amp;W=t&amp;SWEVI=&amp;SWEPOC=&amp;SWETargetView=&amp;SWEDIC=false&amp;SWEReqRowId=1&amp;_sn=P0HWHzGFGHRsfKQTMEV8fGDIgDbnAHHEtrm6mklvDqU_&amp;SWEView=RSA+SM+Training+Course+Overview+Details+View&amp;SWETVI=&amp;SWEC=1&amp;SWEM=&amp;SWEBID=-1&amp;SWESPa=&amp;SWEContainer=&amp;SWETS=&amp;SWETA=&amp;SWEApplet=RSA+SM+Training+Course+Overview+List+Applet&amp;SWETS=1354826179232" target="_blank">RSA NetWitness Administration </a></strong></span>course.</p>
<p>The content for this instructor-led class has been revamped and extended to three days. The course is now task-based and includes new topics like NetWitness for Logs and external authentication. The class is now 60 percent hands-on to provide real-life experience and includes a capstone project.</p>
<p>This course is appropriate for customers that are focused on the administration of the RSA NetWitness product as it provides an overview, hands-on installation and configuration of components. The course also covers integration with other products, monitoring capabilities and troubleshooting of common issues.</p>
<p>Soon to be released will be the new RSA NetWitness Analysis and RSA NetWitness Forensics Fundamentals courses, which are intended to provide security analysts with a road map for intelligence-drive security using RSA NetWitness.</p>
<p>Stay tuned for the latest in RSA Education’s efforts to empower the next generation of Cyber Security Analyst.</p>
<p>For further information and to check out our complete course catalog, visit the <span style="text-decoration: underline;"><strong><a href="http://www.emc.com/training/rsa-education-services/index.htm" target="_blank">RSA Education Services web site</a></strong></span>.</p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fworried-about-advanced-threats-rsa-education-services-can-help%2F&amp;t=Worried%20about%20Advanced%20Threats%3F%20RSA%20Education%20Services%20can%20help%21"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Worried%20about%20Advanced%20Threats%3F%20RSA%20Education%20Services%20can%20help%21%20-%20http%3A%2F%2Fblogs.rsa.com%2Fworried-about-advanced-threats-rsa-education-services-can-help%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fworried-about-advanced-threats-rsa-education-services-can-help%2F&amp;title=Worried%20about%20Advanced%20Threats%3F%20RSA%20Education%20Services%20can%20help%21&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=%E2%80%9CWe%20need%20to%20champion%20and%20develop%20a%20new%20breed%20of%20Cyber%20Security%20Analyst%E2%80%A6This%20new%20breed%20of%20analyst%20must%20have%20the%20right%20analytical%20skills%2C%20%E2%80%98big%20picture%E2%80%99%20thinking%20and%20much%20needed%20collaborative%20%E2%80%9Cpeople%20skills%E2%80%9D%20to%20ensure%20smooth%20information%20sharing%20with%20multiple%20stakeholders.%E2%80%9D%20-%20Art%20Coviello"></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Worried%20about%20Advanced%20Threats%3F%20RSA%20Education%20Services%20can%20help%21&body=http%3A%2F%2Fblogs.rsa.com%2Fworried-about-advanced-threats-rsa-education-services-can-help%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-7423')" id="sociable-post-7423" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fworried-about-advanced-threats-rsa-education-services-can-help%2F&amp;t=Worried%20about%20Advanced%20Threats%3F%20RSA%20Education%20Services%20can%20help%21"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fworried-about-advanced-threats-rsa-education-services-can-help%2F&amp;title=Worried%20about%20Advanced%20Threats%3F%20RSA%20Education%20Services%20can%20help%21&amp;notes=%E2%80%9CWe%20need%20to%20champion%20and%20develop%20a%20new%20breed%20of%20Cyber%20Security%20Analyst%E2%80%A6This%20new%20breed%20of%20analyst%20must%20have%20the%20right%20analytical%20skills%2C%20%E2%80%98big%20picture%E2%80%99%20thinking%20and%20much%20needed%20collaborative%20%E2%80%9Cpeople%20skills%E2%80%9D%20to%20ensure%20smooth%20information%20sharing%20with%20multiple%20stakeholders.%E2%80%9D%20-%20Art%20Coviello"></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fworried-about-advanced-threats-rsa-education-services-can-help%2F&amp;title=Worried%20about%20Advanced%20Threats%3F%20RSA%20Education%20Services%20can%20help%21&amp;bodytext=%E2%80%9CWe%20need%20to%20champion%20and%20develop%20a%20new%20breed%20of%20Cyber%20Security%20Analyst%E2%80%A6This%20new%20breed%20of%20analyst%20must%20have%20the%20right%20analytical%20skills%2C%20%E2%80%98big%20picture%E2%80%99%20thinking%20and%20much%20needed%20collaborative%20%E2%80%9Cpeople%20skills%E2%80%9D%20to%20ensure%20smooth%20information%20sharing%20with%20multiple%20stakeholders.%E2%80%9D%20-%20Art%20Coviello"></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fworried-about-advanced-threats-rsa-education-services-can-help%2F&amp;title=Worried%20about%20Advanced%20Threats%3F%20RSA%20Education%20Services%20can%20help%21"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fworried-about-advanced-threats-rsa-education-services-can-help%2F&title=Worried%20about%20Advanced%20Threats%3F%20RSA%20Education%20Services%20can%20help%21"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fworried-about-advanced-threats-rsa-education-services-can-help%2F&amp;title=Worried%20about%20Advanced%20Threats%3F%20RSA%20Education%20Services%20can%20help%21&amp;annotation=%E2%80%9CWe%20need%20to%20champion%20and%20develop%20a%20new%20breed%20of%20Cyber%20Security%20Analyst%E2%80%A6This%20new%20breed%20of%20analyst%20must%20have%20the%20right%20analytical%20skills%2C%20%E2%80%98big%20picture%E2%80%99%20thinking%20and%20much%20needed%20collaborative%20%E2%80%9Cpeople%20skills%E2%80%9D%20to%20ensure%20smooth%20information%20sharing%20with%20multiple%20stakeholders.%E2%80%9D%20-%20Art%20Coviello"></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fworried-about-advanced-threats-rsa-education-services-can-help%2F&amp;t=Worried%20about%20Advanced%20Threats%3F%20RSA%20Education%20Services%20can%20help%21"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Worried%20about%20Advanced%20Threats%3F%20RSA%20Education%20Services%20can%20help%21&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fworried-about-advanced-threats-rsa-education-services-can-help%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=%E2%80%9CWe%20need%20to%20champion%20and%20develop%20a%20new%20breed%20of%20Cyber%20Security%20Analyst%E2%80%A6This%20new%20breed%20of%20analyst%20must%20have%20the%20right%20analytical%20skills%2C%20%E2%80%98big%20picture%E2%80%99%20thinking%20and%20much%20needed%20collaborative%20%E2%80%9Cpeople%20skills%E2%80%9D%20to%20ensure%20smooth%20information%20sharing%20with%20multiple%20stakeholders.%E2%80%9D%20-%20Art%20Coviello"></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fworried-about-advanced-threats-rsa-education-services-can-help%2F&amp;Title=Worried%20about%20Advanced%20Threats%3F%20RSA%20Education%20Services%20can%20help%21"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fworried-about-advanced-threats-rsa-education-services-can-help%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fworried-about-advanced-threats-rsa-education-services-can-help%2F&amp;title=Worried%20about%20Advanced%20Threats%3F%20RSA%20Education%20Services%20can%20help%21&amp;selection=%E2%80%9CWe%20need%20to%20champion%20and%20develop%20a%20new%20breed%20of%20Cyber%20Security%20Analyst%E2%80%A6This%20new%20breed%20of%20analyst%20must%20have%20the%20right%20analytical%20skills%2C%20%E2%80%98big%20picture%E2%80%99%20thinking%20and%20much%20needed%20collaborative%20%E2%80%9Cpeople%20skills%E2%80%9D%20to%20ensure%20smooth%20information%20sharing%20with%20multiple%20stakeholders.%E2%80%9D%20-%20Art%20Coviello"></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fworried-about-advanced-threats-rsa-education-services-can-help%2F&amp;t=Worried%20about%20Advanced%20Threats%3F%20RSA%20Education%20Services%20can%20help%21&amp;s=%E2%80%9CWe%20need%20to%20champion%20and%20develop%20a%20new%20breed%20of%20Cyber%20Security%20Analyst%E2%80%A6This%20new%20breed%20of%20analyst%20must%20have%20the%20right%20analytical%20skills%2C%20%E2%80%98big%20picture%E2%80%99%20thinking%20and%20much%20needed%20collaborative%20%E2%80%9Cpeople%20skills%E2%80%9D%20to%20ensure%20smooth%20information%20sharing%20with%20multiple%20stakeholders.%E2%80%9D%20-%20Art%20Coviello"></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fworried-about-advanced-threats-rsa-education-services-can-help%2F&amp;title=Worried%20about%20Advanced%20Threats%3F%20RSA%20Education%20Services%20can%20help%21&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fworried-about-advanced-threats-rsa-education-services-can-help%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-7423')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-7423',true)" class="close">

		  <img onclick="hide_sociable('post-7423',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/worried-about-advanced-threats-rsa-education-services-can-help/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/worried-about-advanced-threats-rsa-education-services-can-help/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Answering Questions About the CISSP Certification</title>
		<link>http://blogs.rsa.com/answering-questions-about-the-cissp-certification/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=answering-questions-about-the-cissp-certification</link>
		<comments>http://blogs.rsa.com/answering-questions-about-the-cissp-certification/#comments</comments>
		<pubDate>Tue, 17 Jul 2012 18:00:06 +0000</pubDate>
		<dc:creator>Jason Rader</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[CISSP]]></category>
		<category><![CDATA[Security Training]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=5795</guid>
		<description><![CDATA[I just finished teaching RSA’s CISSP exam prep course last week (good times) and I was asked some questions that I felt were appropriate to answer in a blog post because they might be of interest to a wider audience. So here goes… #1 Is CISSP still a worthy credential to obtain? This is a [...]]]></description>
				<content:encoded><![CDATA[<p>I just finished teaching RSA’s CISSP exam prep course last week (good times) and I was asked some questions that I felt were appropriate to answer in a blog post because they might be of interest to a wider audience. So here goes…</p>
<h4><em>#1 Is CISSP still a worthy credential to obtain?</em></h4>
<p>This is a fair question as the certification has been around over a decade. My answer involved a comparison of the current security credentials out there, the acceptance of those credentials in the market, the authority that defines and maintains the credential, and the level of expertise required to obtain the credential. We arrived at the conclusion that the CISSP is one of a very few security certifications out there that are worth the time, money and effort to acquire. It certainly isn’t everything to everyone but it does represent a fundamental knowledge of “all things security” and the certification process after the exam validates a certain amount of experience. And it still looks good on a resume!</p>
<h4><em>#2 Why is RSA offering this course?</em></h4>
<p>RSA, The Security Division of EMC not only has a series of products that can be used to mitigate many of the threats that the CISSP addresses, it also has a Professional Services group, a Security and Risk Management group of EMC Consulting, and an Education Services group. Between all of these groups we deliver solutions to thousands of clients each year dealing with the latest threats and business needs. The CISSP talks about many topics from an academic perspective with a generic approach. I think taking the RSA course gives you the knowledge required to pass the exam while additionally giving the insight into the latest happenings in the security world. RSA’s CISSP course gives a CISSP candidate the additional information that will be valid well past the exam.</p>
<h4><em>#3 Has the CISSP test changed recently?</em></h4>
<p>Yes on two levels. First there is an updated <a href="https://www.isc2.org/cib/default.aspx">Candidate Information Bulletin</a> (CIB) that was issued in 2012 with the most up to date information related to the exam objectives…RSA’s course aligns with this. Secondly, and most exciting in my opinion, the exam is now offered through <a href="http://www.pearsonvue.com/isc2">PearsonVue testing centers</a>. This means you don’t have to wait for an exam to be offered in your area as was traditionally done, you can register and take the exam whenever you like. I still recommend registering early…the test is long and seats are limited in testing centers, but this really makes it easier to take the exam.</p>
<h4><em>Now a shameless plug… </em> <img src='http://blogs.rsa.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </h4>
<p>I’ve been teaching CISSP courses for over 10 years and RSA’s course is really the best way to go to get the most bang for your buck and the best use of your time. If you’d like to join me, check the schedule at RSA’s <a href="http://www.emc.com/training/rsa-education-services/index.htm">Training Site</a> and register. There are courses available in the US, Europe, and Asia Pacific right now.</p>
<p><strong>Jason Rader</strong> is the Chief Security Strategist for RSA Global Services and can be reached at <a href="mailto:jason.rader@rsa.com">jason.rader@rsa.com</a></p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fanswering-questions-about-the-cissp-certification%2F&amp;t=Answering%20Questions%20About%20the%20CISSP%20Certification"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Answering%20Questions%20About%20the%20CISSP%20Certification%20-%20http%3A%2F%2Fblogs.rsa.com%2Fanswering-questions-about-the-cissp-certification%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fanswering-questions-about-the-cissp-certification%2F&amp;title=Answering%20Questions%20About%20the%20CISSP%20Certification&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=I%20just%20finished%20teaching%20RSA%E2%80%99s%20CISSP%20exam%20prep%20course%20last%20week%20%28good%20times%29%20and%20I%20was%20asked%20some%20questions%20that%20I%20felt%20were%20appropriate%20to%20answer%20in%20a%20blog%20post%20because%20they%20might%20be%20of%20interest%20to%20a%20wider%20audience.%20So%20here%20goes%E2%80%A6%0D%0A%231%20Is%20CISSP%20st"></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Answering%20Questions%20About%20the%20CISSP%20Certification&body=http%3A%2F%2Fblogs.rsa.com%2Fanswering-questions-about-the-cissp-certification%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-5795')" id="sociable-post-5795" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fanswering-questions-about-the-cissp-certification%2F&amp;t=Answering%20Questions%20About%20the%20CISSP%20Certification"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fanswering-questions-about-the-cissp-certification%2F&amp;title=Answering%20Questions%20About%20the%20CISSP%20Certification&amp;notes=I%20just%20finished%20teaching%20RSA%E2%80%99s%20CISSP%20exam%20prep%20course%20last%20week%20%28good%20times%29%20and%20I%20was%20asked%20some%20questions%20that%20I%20felt%20were%20appropriate%20to%20answer%20in%20a%20blog%20post%20because%20they%20might%20be%20of%20interest%20to%20a%20wider%20audience.%20So%20here%20goes%E2%80%A6%0D%0A%231%20Is%20CISSP%20st"></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fanswering-questions-about-the-cissp-certification%2F&amp;title=Answering%20Questions%20About%20the%20CISSP%20Certification&amp;bodytext=I%20just%20finished%20teaching%20RSA%E2%80%99s%20CISSP%20exam%20prep%20course%20last%20week%20%28good%20times%29%20and%20I%20was%20asked%20some%20questions%20that%20I%20felt%20were%20appropriate%20to%20answer%20in%20a%20blog%20post%20because%20they%20might%20be%20of%20interest%20to%20a%20wider%20audience.%20So%20here%20goes%E2%80%A6%0D%0A%231%20Is%20CISSP%20st"></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fanswering-questions-about-the-cissp-certification%2F&amp;title=Answering%20Questions%20About%20the%20CISSP%20Certification"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fanswering-questions-about-the-cissp-certification%2F&title=Answering%20Questions%20About%20the%20CISSP%20Certification"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fanswering-questions-about-the-cissp-certification%2F&amp;title=Answering%20Questions%20About%20the%20CISSP%20Certification&amp;annotation=I%20just%20finished%20teaching%20RSA%E2%80%99s%20CISSP%20exam%20prep%20course%20last%20week%20%28good%20times%29%20and%20I%20was%20asked%20some%20questions%20that%20I%20felt%20were%20appropriate%20to%20answer%20in%20a%20blog%20post%20because%20they%20might%20be%20of%20interest%20to%20a%20wider%20audience.%20So%20here%20goes%E2%80%A6%0D%0A%231%20Is%20CISSP%20st"></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fanswering-questions-about-the-cissp-certification%2F&amp;t=Answering%20Questions%20About%20the%20CISSP%20Certification"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Answering%20Questions%20About%20the%20CISSP%20Certification&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fanswering-questions-about-the-cissp-certification%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=I%20just%20finished%20teaching%20RSA%E2%80%99s%20CISSP%20exam%20prep%20course%20last%20week%20%28good%20times%29%20and%20I%20was%20asked%20some%20questions%20that%20I%20felt%20were%20appropriate%20to%20answer%20in%20a%20blog%20post%20because%20they%20might%20be%20of%20interest%20to%20a%20wider%20audience.%20So%20here%20goes%E2%80%A6%0D%0A%231%20Is%20CISSP%20st"></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fanswering-questions-about-the-cissp-certification%2F&amp;Title=Answering%20Questions%20About%20the%20CISSP%20Certification"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fanswering-questions-about-the-cissp-certification%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fanswering-questions-about-the-cissp-certification%2F&amp;title=Answering%20Questions%20About%20the%20CISSP%20Certification&amp;selection=I%20just%20finished%20teaching%20RSA%E2%80%99s%20CISSP%20exam%20prep%20course%20last%20week%20%28good%20times%29%20and%20I%20was%20asked%20some%20questions%20that%20I%20felt%20were%20appropriate%20to%20answer%20in%20a%20blog%20post%20because%20they%20might%20be%20of%20interest%20to%20a%20wider%20audience.%20So%20here%20goes%E2%80%A6%0D%0A%231%20Is%20CISSP%20st"></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fanswering-questions-about-the-cissp-certification%2F&amp;t=Answering%20Questions%20About%20the%20CISSP%20Certification&amp;s=I%20just%20finished%20teaching%20RSA%E2%80%99s%20CISSP%20exam%20prep%20course%20last%20week%20%28good%20times%29%20and%20I%20was%20asked%20some%20questions%20that%20I%20felt%20were%20appropriate%20to%20answer%20in%20a%20blog%20post%20because%20they%20might%20be%20of%20interest%20to%20a%20wider%20audience.%20So%20here%20goes%E2%80%A6%0D%0A%231%20Is%20CISSP%20st"></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fanswering-questions-about-the-cissp-certification%2F&amp;title=Answering%20Questions%20About%20the%20CISSP%20Certification&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fanswering-questions-about-the-cissp-certification%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-5795')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-5795',true)" class="close">

		  <img onclick="hide_sociable('post-5795',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/answering-questions-about-the-cissp-certification/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/answering-questions-about-the-cissp-certification/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Ultimate Defense Against Advanced Persistent Threats</title>
		<link>http://blogs.rsa.com/the-ultimate-defense-against-advanced-persistent-threats/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=the-ultimate-defense-against-advanced-persistent-threats</link>
		<comments>http://blogs.rsa.com/the-ultimate-defense-against-advanced-persistent-threats/#comments</comments>
		<pubDate>Thu, 31 May 2012 15:57:16 +0000</pubDate>
		<dc:creator>Jason Rader</dc:creator>
				<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[Insider Risk]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=5262</guid>
		<description><![CDATA[Sorry about that, I knew the title would pull you in&#8230;but what I have to say will, in the end, support the headline. The reason for the showmanship is that if the title had been “End User Training and Awareness is Important” or “Training End Users Will Help Your Bottom Line” you may not have [...]]]></description>
				<content:encoded><![CDATA[<p>Sorry about that, I knew the title would pull you in&#8230;but what I have to say will, in the end, support the headline. The reason for the showmanship is that if the title had been “End User Training and Awareness is Important” or “Training End Users Will Help Your Bottom Line” you may not have clicked (I know you would have clicked anyway mom). But seriously, end user training <em>is</em> the new hotness.</p>
<p>As you can tell from the byline, I work for RSA, The Security Division of EMC, and unless you are a noob in the security space you can probably remember an incident in the not so distant past where RSA was in the headlines for a data breach. Yes, RSA, The <em>Security Division</em> of EMC. There have been many forensic breakdowns of the event itself, but I just want to reference <a href="http://blogs.rsa.com/rivner/anatomy-of-an-attack/">Uri Rivner’s initial blog post</a> related to the attack. Yup, the initial foothold was obtained by someone clicking and opening an attachment in an obviously suspect (to me, anyway) email that was in their Junk Mail folder. Junk Mail Folder? Yes!</p>
<p>This reminds me of 2 quotes that sum up the situation from both sides:</p>
<h5>“Wisdom consists in being able to distinguish among dangers and make a choice of the least harmful.” — <a href="http://en.wikipedia.org/wiki/Niccolo_Machiavelli">Niccolo Machiavelli</a>, The Prince</h5>
<h5>“The user&#8217;s going to pick dancing pigs over security every time.” — <a href="http://en.wikipedia.org/wiki/Bruce_Schneier">Bruce Schneier</a></h5>
<p>So we need to empower the end user to make good decisions and at least let them know the risk of the dancing pigs, right? Making end users wise in the ways of security may sound like a daunting task, and it is, but thanks to the folks at the <a href="http://irec.executiveboard.com/">Information Risk Executive Council</a> we have a few user behaviors that we should focus on to start with.</p>
<ul>
<li>Clean Desk Policy</li>
<li>Avoiding Phishing</li>
<li>Locking Computer When Away</li>
<li>Physically Securing Devices</li>
<li>Personal Use of Web</li>
<li>Using Good Passwords</li>
<li>Not Sharing Passwords</li>
<li>Not Discussing Sensitive Information in Public</li>
<li>Not Working on Sensitive Information in Public</li>
<li>Not Using the Web for Personal Use on a Corporate Asset</li>
<li>Not Allowing Tailgating</li>
<li>Not Attaching Non-corporate Devices to The Corporate Network</li>
</ul>
<p>Ok, these certainly aren’t awesome or revolutionary…BUT, you can’t just send a bulleted list like this out to the user base and expect them to “get it” either. Your job is to <em>not</em> put your employees in a position to make an ethical decision for the company. They should know how and what to do in situations they will be confronted with on a daily basis…and yes, <em>you</em> have to prepare them for that.</p>
<p>How, you say? Here are a few suggestions. First, start by using real examples from your organization’s real experiences. Did someone fall prey to a phishing scheme? Talk about it at the next all-hands meeting and give tips on how to avoid the threat. It’s ok (and actually good) for an organization to acknowledge that something happened and use it as a teaching/learning tool. Likewise, if you don’t want a certain behavior to happen, say it. Enable your users with the information and resources and let them make <em>educated</em> decisions on what to do and what not to click on. And like when you send your kids off to college, they’ll hopefully make the right choices 70% of the time. <img src='http://blogs.rsa.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Finally, review the list above and determine the triage of which behaviors have the highest impact on your organization. Then set out to define the risky behaviors your users are engaging in and show them the reasons they are risky and give them the guidance they need to make good decisions. And then, you&#8217;ll have lowered your overall risk profile for Advanced Threats and actually <em>most threats</em>. See, I told you we&#8217;d get there.</p>
<p>Hey, wait a minute, shouldn’t there be a program around this whole endeavor? Yes, absolutely. We’ll be talking about that next time…until then, safe travels.</p>
<p>Jason Rader is the Chief Security Strategist for RSA Global Services and can be reached at <a href="mailto:jason.rader@rsa.com">jason.rader@rsa.com</a></p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fthe-ultimate-defense-against-advanced-persistent-threats%2F&amp;t=The%20Ultimate%20Defense%20Against%20Advanced%20Persistent%20Threats"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=The%20Ultimate%20Defense%20Against%20Advanced%20Persistent%20Threats%20-%20http%3A%2F%2Fblogs.rsa.com%2Fthe-ultimate-defense-against-advanced-persistent-threats%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fthe-ultimate-defense-against-advanced-persistent-threats%2F&amp;title=The%20Ultimate%20Defense%20Against%20Advanced%20Persistent%20Threats&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=Sorry%20about%20that%2C%20I%20knew%20the%20title%20would%20pull%20you%20in%26%238230%3Bbut%20what%20I%20have%20to%20say%20will%2C%20in%20the%20end%2C%20support%20the%20headline.%20The%20reason%20for%20the%20showmanship%20is%20that%20if%20the%20title%20had%20been%20%E2%80%9CEnd%20User%20Training%20and%20Awareness%20is%20Important%E2%80%9D%20or%20%E2%80%9CTraining%20End%20Users%20Will%20Help%20Your%20Bottom%20Line%E2%80%9D%20you%20may%20not%20have%20%5B...%5D"></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=The%20Ultimate%20Defense%20Against%20Advanced%20Persistent%20Threats&body=http%3A%2F%2Fblogs.rsa.com%2Fthe-ultimate-defense-against-advanced-persistent-threats%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-5262')" id="sociable-post-5262" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fthe-ultimate-defense-against-advanced-persistent-threats%2F&amp;t=The%20Ultimate%20Defense%20Against%20Advanced%20Persistent%20Threats"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-ultimate-defense-against-advanced-persistent-threats%2F&amp;title=The%20Ultimate%20Defense%20Against%20Advanced%20Persistent%20Threats&amp;notes=Sorry%20about%20that%2C%20I%20knew%20the%20title%20would%20pull%20you%20in%26%238230%3Bbut%20what%20I%20have%20to%20say%20will%2C%20in%20the%20end%2C%20support%20the%20headline.%20The%20reason%20for%20the%20showmanship%20is%20that%20if%20the%20title%20had%20been%20%E2%80%9CEnd%20User%20Training%20and%20Awareness%20is%20Important%E2%80%9D%20or%20%E2%80%9CTraining%20End%20Users%20Will%20Help%20Your%20Bottom%20Line%E2%80%9D%20you%20may%20not%20have%20%5B...%5D"></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fthe-ultimate-defense-against-advanced-persistent-threats%2F&amp;title=The%20Ultimate%20Defense%20Against%20Advanced%20Persistent%20Threats&amp;bodytext=Sorry%20about%20that%2C%20I%20knew%20the%20title%20would%20pull%20you%20in%26%238230%3Bbut%20what%20I%20have%20to%20say%20will%2C%20in%20the%20end%2C%20support%20the%20headline.%20The%20reason%20for%20the%20showmanship%20is%20that%20if%20the%20title%20had%20been%20%E2%80%9CEnd%20User%20Training%20and%20Awareness%20is%20Important%E2%80%9D%20or%20%E2%80%9CTraining%20End%20Users%20Will%20Help%20Your%20Bottom%20Line%E2%80%9D%20you%20may%20not%20have%20%5B...%5D"></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-ultimate-defense-against-advanced-persistent-threats%2F&amp;title=The%20Ultimate%20Defense%20Against%20Advanced%20Persistent%20Threats"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-ultimate-defense-against-advanced-persistent-threats%2F&title=The%20Ultimate%20Defense%20Against%20Advanced%20Persistent%20Threats"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fthe-ultimate-defense-against-advanced-persistent-threats%2F&amp;title=The%20Ultimate%20Defense%20Against%20Advanced%20Persistent%20Threats&amp;annotation=Sorry%20about%20that%2C%20I%20knew%20the%20title%20would%20pull%20you%20in%26%238230%3Bbut%20what%20I%20have%20to%20say%20will%2C%20in%20the%20end%2C%20support%20the%20headline.%20The%20reason%20for%20the%20showmanship%20is%20that%20if%20the%20title%20had%20been%20%E2%80%9CEnd%20User%20Training%20and%20Awareness%20is%20Important%E2%80%9D%20or%20%E2%80%9CTraining%20End%20Users%20Will%20Help%20Your%20Bottom%20Line%E2%80%9D%20you%20may%20not%20have%20%5B...%5D"></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fthe-ultimate-defense-against-advanced-persistent-threats%2F&amp;t=The%20Ultimate%20Defense%20Against%20Advanced%20Persistent%20Threats"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=The%20Ultimate%20Defense%20Against%20Advanced%20Persistent%20Threats&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fthe-ultimate-defense-against-advanced-persistent-threats%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=Sorry%20about%20that%2C%20I%20knew%20the%20title%20would%20pull%20you%20in%26%238230%3Bbut%20what%20I%20have%20to%20say%20will%2C%20in%20the%20end%2C%20support%20the%20headline.%20The%20reason%20for%20the%20showmanship%20is%20that%20if%20the%20title%20had%20been%20%E2%80%9CEnd%20User%20Training%20and%20Awareness%20is%20Important%E2%80%9D%20or%20%E2%80%9CTraining%20End%20Users%20Will%20Help%20Your%20Bottom%20Line%E2%80%9D%20you%20may%20not%20have%20%5B...%5D"></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fthe-ultimate-defense-against-advanced-persistent-threats%2F&amp;Title=The%20Ultimate%20Defense%20Against%20Advanced%20Persistent%20Threats"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fthe-ultimate-defense-against-advanced-persistent-threats%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fthe-ultimate-defense-against-advanced-persistent-threats%2F&amp;title=The%20Ultimate%20Defense%20Against%20Advanced%20Persistent%20Threats&amp;selection=Sorry%20about%20that%2C%20I%20knew%20the%20title%20would%20pull%20you%20in%26%238230%3Bbut%20what%20I%20have%20to%20say%20will%2C%20in%20the%20end%2C%20support%20the%20headline.%20The%20reason%20for%20the%20showmanship%20is%20that%20if%20the%20title%20had%20been%20%E2%80%9CEnd%20User%20Training%20and%20Awareness%20is%20Important%E2%80%9D%20or%20%E2%80%9CTraining%20End%20Users%20Will%20Help%20Your%20Bottom%20Line%E2%80%9D%20you%20may%20not%20have%20%5B...%5D"></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fthe-ultimate-defense-against-advanced-persistent-threats%2F&amp;t=The%20Ultimate%20Defense%20Against%20Advanced%20Persistent%20Threats&amp;s=Sorry%20about%20that%2C%20I%20knew%20the%20title%20would%20pull%20you%20in%26%238230%3Bbut%20what%20I%20have%20to%20say%20will%2C%20in%20the%20end%2C%20support%20the%20headline.%20The%20reason%20for%20the%20showmanship%20is%20that%20if%20the%20title%20had%20been%20%E2%80%9CEnd%20User%20Training%20and%20Awareness%20is%20Important%E2%80%9D%20or%20%E2%80%9CTraining%20End%20Users%20Will%20Help%20Your%20Bottom%20Line%E2%80%9D%20you%20may%20not%20have%20%5B...%5D"></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-ultimate-defense-against-advanced-persistent-threats%2F&amp;title=The%20Ultimate%20Defense%20Against%20Advanced%20Persistent%20Threats&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fthe-ultimate-defense-against-advanced-persistent-threats%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-5262')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-5262',true)" class="close">

		  <img onclick="hide_sociable('post-5262',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/the-ultimate-defense-against-advanced-persistent-threats/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/the-ultimate-defense-against-advanced-persistent-threats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Best Equip Your Security Program</title>
		<link>http://blogs.rsa.com/5043/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=5043</link>
		<comments>http://blogs.rsa.com/5043/#comments</comments>
		<pubDate>Tue, 01 May 2012 17:54:05 +0000</pubDate>
		<dc:creator>Jason Rader</dc:creator>
				<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=5043</guid>
		<description><![CDATA[We have seen action movies where the protagonist, stripped of his weapon, manages to find some everyday item like a stick or pen and disarm several baddies, rescue the hostages, and disable the imminent threat to mankind. We accept this premise because it happens every day; ingenuity, experience, and persistence often overcome the lack of a specific tool. We, as 21st century professionals, leverage these skills and the resources at hand to overcome the daily crises and defeat evil (or save a file that has accidentally been deleted). Cue the heroic background music…]]></description>
				<content:encoded><![CDATA[<p>We have seen action movies where the protagonist, stripped of his weapon, manages to find some everyday item like a stick or pen and disarm several baddies, rescue the hostages, and disable the imminent threat to mankind. We accept this premise because it happens every day; ingenuity, experience, and persistence often overcome the lack of a specific tool. We, as 21<sup>st</sup> century professionals, leverage these skills and the resources at hand to overcome the daily crises and defeat evil (or save a file that has accidentally been deleted). Cue the heroic background music…</p>
<div>
<p>Now that I have set the stage for the conversation…let&#8217;s talk about an organization’s typical approach to security. Got a problem with this? Buy a tool designed to fix it! Got a problem with that? Buy a tool designed to fix that! Worried about APTs? Buy an APT tool! New threat? New tool! New problem? Look for a tool that addresses it specifically! Who manages all of this? It must be IT because they’re good with this kind of stuff…(fade to black)</p>
<p><strong><em>It’s not the tools, it’s the people!</em></strong></p>
<p>Don’t get the wrong impression, I love technology! I believe the right types of tools in your program are going to make your program more efficient, economical and effective. But it won’t be the technology that manages to leverage these outcomes…it will be the people that implement, integrate and optimize them. That’s what makes <span style="text-decoration: underline;"><strong><a href="http://en.wikipedia.org/wiki/Jason_Bourne" target="_blank">Jason Bourne </a></strong></span>and <span style="text-decoration: underline;"><strong><a href="http://en.wikipedia.org/wiki/MacGyver" target="_blank">MacGyver </a></strong></span>so great; they take the resources that are available and they use their expert <em>skills</em> to get the job done even when the tools are less than ideal.</p>
<p><a href="http://blogs.rsa.com/wp-content/uploads/macgyver.jpg"><img class="alignnone size-medium wp-image-5070" title="macgyver" src="http://blogs.rsa.com/wp-content/uploads/macgyver-300x225.jpg" alt="" width="300" height="225" /></a><br />
image credit: <em><a href="http://rda-forever.com/index.php?option=com_jmovies&amp;Itemid=69&amp;task=showcategory&amp;catid=17" target="_blank">Richard Dean Anderson Forever</a></em></p>
<p><strong><em>Tools are great; the right people protecting your assets are better.</em></strong></p>
<p>Let&#8217;s cut to the chase (scene?) if you are trying to build/enhance/extend your security capabilities; just looking at technology is short sighted. I consult with organizations all the time that have these grand designs of where they want to be from a security operations or incident response perspective and they have a road map of the technologies and even the facilities that will be required…but they haven’t thought about the skill sets they’ll need to pull this off and whether they have them internally or will have to go out into the market to acquire them. If they haven’t thought of this, aren’t they picking the tools out before they know if it will be James Bond or Chuck Norris that will be carrying out this mission? The success of the mission is at stake!</p>
<p><strong><em>“Help me Obi-Wan Kenobi. You’re my only hope.”</em></strong></p>
<p>If there is one thing that makes a security program successful it is the people executing it. Education, experience and empowerment are the new hope in securing your organization. I strongly recommend that an organization’s first step in enhancing its security program is to empower their security staff, get them access to security intelligence, exposure to other practitioners and provide them training in management-level security not just product security (because most have an engineering background). Most transformative security projects have a ramp-up time that is measured in months or even quarters, so invest in your “A” level talent.</p>
<p>A current high potential employee has an understanding of your business, its objectives, has relationships within the company and an understanding of operations. It takes an outsider many months to get this knowledge…and training an internal employee will be exponentially less expensive than hiring someone from the outside with the skill set you desire.</p>
<p><strong><em>Just a little thought shift that can make a big difference.</em></strong></p>
<p>As you embark on your next great security conquest give some thought to the people and skill sets that you need to have on board before you start making a list of the technology that you need. Somewhere within your organization there may be a young <span style="text-decoration: underline;"><strong><a href="http://starwars.wikia.com/wiki/Padawan" target="_blank">Padawan </a></strong></span>who, when equipped with the right knowledge, training, and access to the right tools can become a Security Jedi and defend your universe against the attackers from the Dark Side.</p>
<p><em>(Roll Credits)</em></p>
<p><em><strong>Jason Rader</strong> is the Chief Security Strategist for RSA, The Security Division of EMC. He can be reached at <span style="text-decoration: underline;"><a href="mailto:jason.rader@rsa.com">jason.rader@rsa.com</a></span></em></p>
<p><strong>Stay tuned</strong>: In our next episode we will tackle the biggest threat in the universe…the end-user!</p>
</div>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2F5043%2F&amp;t=How%20to%20Best%20Equip%20Your%20Security%20Program"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=How%20to%20Best%20Equip%20Your%20Security%20Program%20-%20http%3A%2F%2Fblogs.rsa.com%2F5043%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2F5043%2F&amp;title=How%20to%20Best%20Equip%20Your%20Security%20Program&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=We%20have%20seen%20action%20movies%20where%20the%20protagonist%2C%20stripped%20of%20his%20weapon%2C%20manages%20to%20find%20some%20everyday%20item%20like%20a%20stick%20or%20pen%20and%20disarm%20several%20baddies%2C%20rescue%20the%20hostages%2C%20and%20disable%20the%20imminent%20threat%20to%20mankind.%20We%20accept%20this%20premise%20because%20it%20happens%20every%20day%3B%20ingenuity%2C%20experience%2C%20and%20persistence%20often%20overcome%20the%20lack%20of%20a%20specific%20tool.%20We%2C%20as%2021st%20century%20professionals%2C%20leverage%20these%20skills%20and%20the%20resources%20at%20hand%20to%20overcome%20the%20daily%20crises%20and%20defeat%20evil%20%28or%20save%20a%20file%20that%20has%20accidentally%20been%20deleted%29.%20Cue%20the%20heroic%20background%20music%E2%80%A6"></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=How%20to%20Best%20Equip%20Your%20Security%20Program&body=http%3A%2F%2Fblogs.rsa.com%2F5043%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-5043')" id="sociable-post-5043" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2F5043%2F&amp;t=How%20to%20Best%20Equip%20Your%20Security%20Program"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2F5043%2F&amp;title=How%20to%20Best%20Equip%20Your%20Security%20Program&amp;notes=We%20have%20seen%20action%20movies%20where%20the%20protagonist%2C%20stripped%20of%20his%20weapon%2C%20manages%20to%20find%20some%20everyday%20item%20like%20a%20stick%20or%20pen%20and%20disarm%20several%20baddies%2C%20rescue%20the%20hostages%2C%20and%20disable%20the%20imminent%20threat%20to%20mankind.%20We%20accept%20this%20premise%20because%20it%20happens%20every%20day%3B%20ingenuity%2C%20experience%2C%20and%20persistence%20often%20overcome%20the%20lack%20of%20a%20specific%20tool.%20We%2C%20as%2021st%20century%20professionals%2C%20leverage%20these%20skills%20and%20the%20resources%20at%20hand%20to%20overcome%20the%20daily%20crises%20and%20defeat%20evil%20%28or%20save%20a%20file%20that%20has%20accidentally%20been%20deleted%29.%20Cue%20the%20heroic%20background%20music%E2%80%A6"></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2F5043%2F&amp;title=How%20to%20Best%20Equip%20Your%20Security%20Program&amp;bodytext=We%20have%20seen%20action%20movies%20where%20the%20protagonist%2C%20stripped%20of%20his%20weapon%2C%20manages%20to%20find%20some%20everyday%20item%20like%20a%20stick%20or%20pen%20and%20disarm%20several%20baddies%2C%20rescue%20the%20hostages%2C%20and%20disable%20the%20imminent%20threat%20to%20mankind.%20We%20accept%20this%20premise%20because%20it%20happens%20every%20day%3B%20ingenuity%2C%20experience%2C%20and%20persistence%20often%20overcome%20the%20lack%20of%20a%20specific%20tool.%20We%2C%20as%2021st%20century%20professionals%2C%20leverage%20these%20skills%20and%20the%20resources%20at%20hand%20to%20overcome%20the%20daily%20crises%20and%20defeat%20evil%20%28or%20save%20a%20file%20that%20has%20accidentally%20been%20deleted%29.%20Cue%20the%20heroic%20background%20music%E2%80%A6"></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2F5043%2F&amp;title=How%20to%20Best%20Equip%20Your%20Security%20Program"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2F5043%2F&title=How%20to%20Best%20Equip%20Your%20Security%20Program"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2F5043%2F&amp;title=How%20to%20Best%20Equip%20Your%20Security%20Program&amp;annotation=We%20have%20seen%20action%20movies%20where%20the%20protagonist%2C%20stripped%20of%20his%20weapon%2C%20manages%20to%20find%20some%20everyday%20item%20like%20a%20stick%20or%20pen%20and%20disarm%20several%20baddies%2C%20rescue%20the%20hostages%2C%20and%20disable%20the%20imminent%20threat%20to%20mankind.%20We%20accept%20this%20premise%20because%20it%20happens%20every%20day%3B%20ingenuity%2C%20experience%2C%20and%20persistence%20often%20overcome%20the%20lack%20of%20a%20specific%20tool.%20We%2C%20as%2021st%20century%20professionals%2C%20leverage%20these%20skills%20and%20the%20resources%20at%20hand%20to%20overcome%20the%20daily%20crises%20and%20defeat%20evil%20%28or%20save%20a%20file%20that%20has%20accidentally%20been%20deleted%29.%20Cue%20the%20heroic%20background%20music%E2%80%A6"></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2F5043%2F&amp;t=How%20to%20Best%20Equip%20Your%20Security%20Program"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=How%20to%20Best%20Equip%20Your%20Security%20Program&amp;URL=http%3A%2F%2Fblogs.rsa.com%2F5043%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=We%20have%20seen%20action%20movies%20where%20the%20protagonist%2C%20stripped%20of%20his%20weapon%2C%20manages%20to%20find%20some%20everyday%20item%20like%20a%20stick%20or%20pen%20and%20disarm%20several%20baddies%2C%20rescue%20the%20hostages%2C%20and%20disable%20the%20imminent%20threat%20to%20mankind.%20We%20accept%20this%20premise%20because%20it%20happens%20every%20day%3B%20ingenuity%2C%20experience%2C%20and%20persistence%20often%20overcome%20the%20lack%20of%20a%20specific%20tool.%20We%2C%20as%2021st%20century%20professionals%2C%20leverage%20these%20skills%20and%20the%20resources%20at%20hand%20to%20overcome%20the%20daily%20crises%20and%20defeat%20evil%20%28or%20save%20a%20file%20that%20has%20accidentally%20been%20deleted%29.%20Cue%20the%20heroic%20background%20music%E2%80%A6"></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2F5043%2F&amp;Title=How%20to%20Best%20Equip%20Your%20Security%20Program"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2F5043%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2F5043%2F&amp;title=How%20to%20Best%20Equip%20Your%20Security%20Program&amp;selection=We%20have%20seen%20action%20movies%20where%20the%20protagonist%2C%20stripped%20of%20his%20weapon%2C%20manages%20to%20find%20some%20everyday%20item%20like%20a%20stick%20or%20pen%20and%20disarm%20several%20baddies%2C%20rescue%20the%20hostages%2C%20and%20disable%20the%20imminent%20threat%20to%20mankind.%20We%20accept%20this%20premise%20because%20it%20happens%20every%20day%3B%20ingenuity%2C%20experience%2C%20and%20persistence%20often%20overcome%20the%20lack%20of%20a%20specific%20tool.%20We%2C%20as%2021st%20century%20professionals%2C%20leverage%20these%20skills%20and%20the%20resources%20at%20hand%20to%20overcome%20the%20daily%20crises%20and%20defeat%20evil%20%28or%20save%20a%20file%20that%20has%20accidentally%20been%20deleted%29.%20Cue%20the%20heroic%20background%20music%E2%80%A6"></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2F5043%2F&amp;t=How%20to%20Best%20Equip%20Your%20Security%20Program&amp;s=We%20have%20seen%20action%20movies%20where%20the%20protagonist%2C%20stripped%20of%20his%20weapon%2C%20manages%20to%20find%20some%20everyday%20item%20like%20a%20stick%20or%20pen%20and%20disarm%20several%20baddies%2C%20rescue%20the%20hostages%2C%20and%20disable%20the%20imminent%20threat%20to%20mankind.%20We%20accept%20this%20premise%20because%20it%20happens%20every%20day%3B%20ingenuity%2C%20experience%2C%20and%20persistence%20often%20overcome%20the%20lack%20of%20a%20specific%20tool.%20We%2C%20as%2021st%20century%20professionals%2C%20leverage%20these%20skills%20and%20the%20resources%20at%20hand%20to%20overcome%20the%20daily%20crises%20and%20defeat%20evil%20%28or%20save%20a%20file%20that%20has%20accidentally%20been%20deleted%29.%20Cue%20the%20heroic%20background%20music%E2%80%A6"></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2F5043%2F&amp;title=How%20to%20Best%20Equip%20Your%20Security%20Program&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2F5043%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-5043')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-5043',true)" class="close">

		  <img onclick="hide_sociable('post-5043',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/5043/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/5043/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
