<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
   <title>The Lens</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/" />
   <link rel="self" type="application/atom+xml" href="http://blog.ncircle.com/blogs/the-lens/atom.xml" />
   <id>tag:blog.ncircle.com,2011:/blogs/the-lens/4</id>
   <updated>2011-06-28T02:46:30Z</updated>
   
   <generator uri="http://www.sixapart.com/movabletype/">Movable Type 3.38</generator>

<entry>
   <title>Are You Scanning Often Enough?</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2011/06/are_you_scanning_often_enough_1.html" />
   <id>tag:blog.ncircle.com,2011:/blogs/the-lens//4.612</id>
   
   <published>2011-06-28T02:34:04Z</published>
   <updated>2011-06-28T02:46:30Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
One of the metrics collected and shared in the Vulnerability Management Benchmark is Average Days Since Last Scan, otherwise known as scan frequency. It&apos;s available for free as part of the Basic package. This metric was a fairly surprising one...
   </content>
</entry>
<entry>
   <title>The Crowd is Dead, Long Live the Crowd</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2011/06/the_crowd_is_dead_long_live_th.html" />
   <id>tag:blog.ncircle.com,2011:/blogs/the-lens//4.600</id>
   
   <published>2011-06-07T18:50:00Z</published>
   <updated>2011-06-07T18:55:00Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
Until now, the information security community has relied on rumors, conversations and sparse breach reports to develop some kind of consensus on what vulnerability management metrics should look like. The metrics themselves haven&apos;t been hard to come by, but how...
   </content>
</entry>
<entry>
   <title>CCM 5.10 and Cyber-Ark Integration</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2011/05/ccm_510_and_cyberark_integrati_1.html" />
   <id>tag:blog.ncircle.com,2011:/blogs/the-lens//4.599</id>
   
   <published>2011-05-26T21:27:21Z</published>
   <updated>2011-05-26T19:37:39Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
We&apos;re thrilled to announce that Configuration Compliance Manager version 5.10 is available now. While there are a whole bunch of useful features in this release, the integration with Cyber-Ark&apos;s Application Identity Manager, part of their Privileged Identity Management Suite, is...
   </content>
</entry>
<entry>
   <title>Security Through Obscurity and the TSA</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2009/12/security_through_obscurity_and.html" />
   <id>tag:blog.ncircle.com,2009:/blogs/the-lens//4.564</id>
   
   <published>2009-12-09T16:11:15Z</published>
   <updated>2009-12-09T17:03:34Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
ABC news reports today that the TSA screening manual was accidentally posted online with formerly redacted information included. &quot;This is an appalling and astounding breach of security that terrorists could easily exploit,&quot; said Clark Kent Ervin, the former inspector general...
   </content>
</entry>
<entry>
   <title>Vulnerability Management Panel Discussion</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2009/07/vulnerability_management_panel.html" />
   <id>tag:blog.ncircle.com,2009:/blogs/the-lens//4.554</id>
   
   <published>2009-07-27T14:13:46Z</published>
   <updated>2009-07-27T14:15:43Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
WhitehatWorld organized this vulnerability management thought leaders panel discussion. I was lucky enough to participate as a panelist. You can listen to the recording here....
   </content>
</entry>
<entry>
   <title>Mild mannered company by day ...</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2009/04/mild_mannered_company_by_day.html" />
   <id>tag:blog.ncircle.com,2009:/blogs/the-lens//4.538</id>
   
   <published>2009-04-23T14:37:24Z</published>
   <updated>2009-04-23T14:42:35Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
... superheros by night, or trade show at least. These guys were close enough to our booth that I managed a snapshot. I&apos;m sure I wasn&apos;t the only one, given how proficient they were at striking this pose. I wonder...
   </content>
</entry>
<entry>
   <title>Web Applications: The Biggest Risk to the Enterprise</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2009/04/web_applications_the_biggest_r.html" />
   <id>tag:blog.ncircle.com,2009:/blogs/the-lens//4.536</id>
   
   <published>2009-04-22T03:34:31Z</published>
   <updated>2009-04-22T03:56:55Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
(This post is a taste of my presentation at the nCircle booth at RSA. Come by and see it if this is interesting). Web application risk is a hot topic these days, but there&apos;s something missing from the discussion. Vendors...
   </content>
</entry>
<entry>
   <title>Hello Old Friend Moscone</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2009/04/hello_old_friend_moscone.html" />
   <id>tag:blog.ncircle.com,2009:/blogs/the-lens//4.533</id>
   
   <published>2009-04-21T14:15:14Z</published>
   <updated>2009-04-21T14:30:40Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
 I&apos;m lucky enough to get to San Francisco more than once a year, but for many folks the RSA conference is an annual trek. There are probably a few missing out this year because of restricted travel budgets as...
   </content>
</entry>
<entry>
   <title>PCI and Politics</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2009/03/pci_and_politics.html" />
   <id>tag:blog.ncircle.com,2009:/blogs/the-lens//4.524</id>
   
   <published>2009-03-13T15:54:18Z</published>
   <updated>2009-03-13T16:02:57Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
 Did you donate to Norm Coleman? Well, your credit card and donor information has been floating around the dark side of the internet. Wikileaks has published evidence of the data breach. The Minneapolis Star-Tribune has a piece on how...
   </content>
</entry>
<entry>
   <title>Next Step for Data Breach Laws</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2009/03/next_step_for_data_breach_laws.html" />
   <id>tag:blog.ncircle.com,2009:/blogs/the-lens//4.521</id>
   
   <published>2009-03-09T00:53:22Z</published>
   <updated>2009-03-09T01:59:21Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
 California pioneered laws around data breach disclosure with SB-1386, requiring that companies inform consumers when their data has been compromised. Now, state senator Joe Simitian wants to update the law with SB-20. The primary change is greater specificity around...
   </content>
</entry>
<entry>
   <title>Study finds you have a problem our product solves!</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2009/03/study_finds_you_have_a_problem.html" />
   <id>tag:blog.ncircle.com,2009:/blogs/the-lens//4.520</id>
   
   <published>2009-03-04T00:25:26Z</published>
   <updated>2009-03-04T01:05:13Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
You have to love a study run by a vendor where the results clearly demonstrate a problem that very vendor solves. What a pleasant surprise! Sarcasm aside, Damballa concluded that anti-virus misses a whole bunch of malware. We&apos;ve seen this...
   </content>
</entry>
<entry>
   <title>Web application security isn&apos;t just about web applications</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2009/02/web_application_security_isnt.html" />
   <id>tag:blog.ncircle.com,2009:/blogs/the-lens//4.518</id>
   
   <published>2009-02-27T21:11:32Z</published>
   <updated>2009-02-27T21:19:29Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
More Than 500,000 Websites Hit By New Form Of SQL Injection In &apos;08 It&apos;s new because it&apos;s automated and run from botnets. I&apos;m not sure that really counts as a &quot;new form of SQL injection,&quot; but I won&apos;t quibble. This...
   </content>
</entry>
<entry>
   <title>PCI Compliance Podcast at Practical eCommerce</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2009/02/pci_compliance_podcast_at_prac_1.html" />
   <id>tag:blog.ncircle.com,2009:/blogs/the-lens//4.517</id>
   
   <published>2009-02-26T15:04:55Z</published>
   <updated>2009-02-26T15:10:21Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
There&apos;s a short interview I did on PCI compliance over at Practical eCommerce. It&apos;s about fees that merchant account providers are charging their merchants. Although not part of the interview, these fees are clearly part of the distributive nature of...
   </content>
</entry>
<entry>
   <title>iPhone 2.0 is Less Secure</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2008/06/iphone_20_is_less_secure.html" />
   <id>tag:blog.ncircle.com,2008:/blogs/the-lens//4.479</id>
   
   <published>2008-06-10T20:13:31Z</published>
   <updated>2008-06-10T20:59:49Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
There&apos;s nothing quite as effective for illustrating a point than a top n list. Here are the top 4 reasons that the new iPhone is less secure than the previous version. 4. The Price How could the price make the...
   </content>
</entry>
<entry>
   <title>A Virtual Advantage</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2008/05/a_virtual_advantage.html" />
   <id>tag:blog.ncircle.com,2008:/blogs/the-lens//4.478</id>
   
   <published>2008-05-28T17:24:25Z</published>
   <updated>2008-05-28T17:43:12Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
First, the article. Second, the salient quote so that you don&apos;t really have to read said article: &quot;If you are getting any benefit from Microsoft&apos;s software, you need to have a license, whether that benefit is for physical machines or...
   </content>
</entry>

</feed>

