<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for Credit Union InfoSec</title>
	<atom:link href="http://cuinfosec.wordpress.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://cuinfosec.wordpress.com</link>
	<description>Random Thoughts on IT Security in the Credit Union Industry</description>
	<lastBuildDate>Mon, 25 May 2009 06:07:33 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on How much power do the bad guys have? by Ferinannnd</title>
		<link>http://cuinfosec.wordpress.com/2007/08/31/how-power-do-the-bad-guys-have/#comment-340</link>
		<dc:creator>Ferinannnd</dc:creator>
		<pubDate>Mon, 25 May 2009 06:07:33 +0000</pubDate>
		<guid isPermaLink="false">http://cuinfosec.wordpress.com/2007/08/31/how-power-do-the-bad-guys-have/#comment-340</guid>
		<description>Хорошо что удалось отыскать такой замечательный блог, а то последнее время уже начал думать что инет это мусорка сплошная.</description>
		<content:encoded><![CDATA[<p>Хорошо что удалось отыскать такой замечательный блог, а то последнее время уже начал думать что инет это мусорка сплошная.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on In the eyes of a Phiser by Rimma</title>
		<link>http://cuinfosec.wordpress.com/2007/05/21/in-the-eyes-of-a-phiser/#comment-339</link>
		<dc:creator>Rimma</dc:creator>
		<pubDate>Thu, 09 Apr 2009 00:36:35 +0000</pubDate>
		<guid isPermaLink="false">http://cuinfosec.wordpress.com/2007/05/21/in-the-eyes-of-a-phiser/#comment-339</guid>
		<description>Extraordinarity: ,</description>
		<content:encoded><![CDATA[<p>Extraordinarity: ,</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on In the eyes of a Phiser by matt</title>
		<link>http://cuinfosec.wordpress.com/2007/05/21/in-the-eyes-of-a-phiser/#comment-337</link>
		<dc:creator>matt</dc:creator>
		<pubDate>Thu, 19 Jun 2008 07:54:44 +0000</pubDate>
		<guid isPermaLink="false">http://cuinfosec.wordpress.com/2007/05/21/in-the-eyes-of-a-phiser/#comment-337</guid>
		<description>Of course education about email scams phising and how it is done is the best way to protect people against these scams dont follow links from emails instant messengers etc... bookmark the authentic site if you need to.... and also making clear how illegal it is and unethical to phish somebody because little teenagers will think they can be an ultimate Hax0r and try and get one of there school enemy&#039;s email account because it seems doable for them.</description>
		<content:encoded><![CDATA[<p>Of course education about email scams phising and how it is done is the best way to protect people against these scams dont follow links from emails instant messengers etc&#8230; bookmark the authentic site if you need to&#8230;. and also making clear how illegal it is and unethical to phish somebody because little teenagers will think they can be an ultimate Hax0r and try and get one of there school enemy&#8217;s email account because it seems doable for them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About by bibomedia</title>
		<link>http://cuinfosec.wordpress.com/about/#comment-336</link>
		<dc:creator>bibomedia</dc:creator>
		<pubDate>Fri, 29 Feb 2008 05:32:41 +0000</pubDate>
		<guid isPermaLink="false">#comment-336</guid>
		<description>:)</description>
		<content:encoded><![CDATA[<p> <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Web server log review by Devarshi</title>
		<link>http://cuinfosec.wordpress.com/2007/06/12/web-server-log-review/#comment-170</link>
		<dc:creator>Devarshi</dc:creator>
		<pubDate>Wed, 24 Oct 2007 17:42:10 +0000</pubDate>
		<guid isPermaLink="false">http://cuinfosec.wordpress.com/2007/06/12/web-server-log-review/#comment-170</guid>
		<description>Hi,
      When I open my login page it shows me message in I.E. that server application unavailable,see log entry in web server to review this file.</description>
		<content:encoded><![CDATA[<p>Hi,<br />
      When I open my login page it shows me message in I.E. that server application unavailable,see log entry in web server to review this file.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on BBB Phishing by drapetomaniac</title>
		<link>http://cuinfosec.wordpress.com/2007/05/29/bbb-phishing/#comment-156</link>
		<dc:creator>drapetomaniac</dc:creator>
		<pubDate>Tue, 09 Oct 2007 14:26:30 +0000</pubDate>
		<guid isPermaLink="false">http://cuinfosec.wordpress.com/2007/05/29/bbb-phishing/#comment-156</guid>
		<description>BBB is leaking customer data and has known since at least August.
http://drapetomaniacs.com/articles/2007/09/30/bbb-leaks-consumer-and-business-data</description>
		<content:encoded><![CDATA[<p>BBB is leaking customer data and has known since at least August.<br />
<a href="http://drapetomaniacs.com/articles/2007/09/30/bbb-leaks-consumer-and-business-data" rel="nofollow">http://drapetomaniacs.com/articles/2007/09/30/bbb-leaks-consumer-and-business-data</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Facebook ID Probe by Trey Reeme</title>
		<link>http://cuinfosec.wordpress.com/2007/08/30/facebook-id-probe/#comment-110</link>
		<dc:creator>Trey Reeme</dc:creator>
		<pubDate>Fri, 31 Aug 2007 16:20:46 +0000</pubDate>
		<guid isPermaLink="false">http://cuinfosec.wordpress.com/2007/08/30/facebook-id-probe/#comment-110</guid>
		<description>I think it&#039;s a prime education opportunity, like you.  Obviously not a reason for folks to stay away from social networks but to use common sense - hopefully FIs won&#039;t place a lot of fear into their members (or more likely their parents).

Thanks for sharing this!</description>
		<content:encoded><![CDATA[<p>I think it&#8217;s a prime education opportunity, like you.  Obviously not a reason for folks to stay away from social networks but to use common sense &#8211; hopefully FIs won&#8217;t place a lot of fear into their members (or more likely their parents).</p>
<p>Thanks for sharing this!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Incident Response (How Prepaired Are We) by Courtney Treadaway</title>
		<link>http://cuinfosec.wordpress.com/2007/07/24/incident-response-how-prepaired-are-we/#comment-32</link>
		<dc:creator>Courtney Treadaway</dc:creator>
		<pubDate>Tue, 31 Jul 2007 20:57:08 +0000</pubDate>
		<guid isPermaLink="false">http://cuinfosec.wordpress.com/2007/07/24/incident-response-how-prepaired-are-we/#comment-32</guid>
		<description>We just recently posted a discussion on our site about Incident Response plans, too.  We spend a great deal of time either auditing and/or consulting with financial institutions, and Incident Response Plans are one of the most overlooked aspects of overall Information Security programs.

Even if a plan exists, it is seems rarely well-implemented.  I couldn&#039;t agree more with the guidance you mentioned here, and would encourage any institution that develops a plan to ensure that IT staff are quite familiar with proper procedures.</description>
		<content:encoded><![CDATA[<p>We just recently posted a discussion on our site about Incident Response plans, too.  We spend a great deal of time either auditing and/or consulting with financial institutions, and Incident Response Plans are one of the most overlooked aspects of overall Information Security programs.</p>
<p>Even if a plan exists, it is seems rarely well-implemented.  I couldn&#8217;t agree more with the guidance you mentioned here, and would encourage any institution that develops a plan to ensure that IT staff are quite familiar with proper procedures.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The Confusion (RA, VA, &amp; PT) by Kirk</title>
		<link>http://cuinfosec.wordpress.com/2007/05/16/the-confusion/#comment-2</link>
		<dc:creator>Kirk</dc:creator>
		<pubDate>Mon, 21 May 2007 16:01:10 +0000</pubDate>
		<guid isPermaLink="false">http://cuinfosec.wordpress.com/2007/05/16/the-confusion/#comment-2</guid>
		<description>RA - List/Define the risks along with steps taken, if any, to mitigate the risks.  For example, giving your developers access to live code isn&#039;t a vulnerability but it is a risk.
VA - Assessment of known system vulnerabilities.  For example, an un-patched windows server is likely to have many vulnerabilities that could be exploited.
PT - Simply put, a &quot;hacker&quot; attemps to get into your systems from outside your organization, as a test.</description>
		<content:encoded><![CDATA[<p>RA &#8211; List/Define the risks along with steps taken, if any, to mitigate the risks.  For example, giving your developers access to live code isn&#8217;t a vulnerability but it is a risk.<br />
VA &#8211; Assessment of known system vulnerabilities.  For example, an un-patched windows server is likely to have many vulnerabilities that could be exploited.<br />
PT &#8211; Simply put, a &#8220;hacker&#8221; attemps to get into your systems from outside your organization, as a test.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
