<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Don&#8217;t Get Too Caught Up in the Patch Game: How to Tell if a System is &#8220;Secure&#8221;</title>
	<atom:link href="http://blog.impactalabs.com/2008/12/03/how-to-tell-if-a-system-is-secure/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.impactalabs.com/2008/12/03/how-to-tell-if-a-system-is-secure/</link>
	<description></description>
	<lastBuildDate>Mon, 09 Aug 2010 16:41:11 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Kevin Lam (IMPACTA)</title>
		<link>http://blog.impactalabs.com/2008/12/03/how-to-tell-if-a-system-is-secure/#comment-24</link>
		<dc:creator><![CDATA[Kevin Lam (IMPACTA)]]></dc:creator>
		<pubDate>Wed, 17 Dec 2008 16:46:53 +0000</pubDate>
		<guid isPermaLink="false">http://impactalabs.wordpress.com/?p=87#comment-24</guid>
		<description><![CDATA[Just to be fair to Secunia.com, it&#039;s the media that typically skews data like this and makes unfound states indicating that something is &quot;secure&quot; or &quot;not secure&quot; -- not Secunia.com.  Just in case anyone felt that I was trying to jab at Secunia.com.  They have always been a great source of information security insight and knowledge so I would always encourage listening to what they have to say.

--Kevin]]></description>
		<content:encoded><![CDATA[<p>Just to be fair to Secunia.com, it&#8217;s the media that typically skews data like this and makes unfound states indicating that something is &#8220;secure&#8221; or &#8220;not secure&#8221; &#8212; not Secunia.com.  Just in case anyone felt that I was trying to jab at Secunia.com.  They have always been a great source of information security insight and knowledge so I would always encourage listening to what they have to say.</p>
<p>&#8211;Kevin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Reidar Balstad</title>
		<link>http://blog.impactalabs.com/2008/12/03/how-to-tell-if-a-system-is-secure/#comment-23</link>
		<dc:creator><![CDATA[Reidar Balstad]]></dc:creator>
		<pubDate>Wed, 17 Dec 2008 11:47:11 +0000</pubDate>
		<guid isPermaLink="false">http://impactalabs.wordpress.com/?p=87#comment-23</guid>
		<description><![CDATA[Interesting discussion; *when* is any system deemed &quot;secure&quot; ?! In my personal opinion, as long as we humans operate them; probably never. There will always be new angles of attack to a system, because this is human nature; exploration, discovery, challenges, overcoming obstacles and conquering. Security only exists at a high level, when the operator fully understands every aspect of a) the system&#039;s workings, and b) the consequences of any action taken on the system.

Now, to the origin of the article this blog was based on. We (Secunia) used data from our PSI Patch Scanner, as the basis of a blog of our own: http://secunia.com/blog/37/
Note that we do not, ever, state that a computer is secure when patch management is in place. This is a media spin on things, mostly because they do not fully understand the complexity of &quot;security&quot;.

True, the numbers are probably worse than the data from Secunia reveal. To quote the blog post:
&quot;Please note. Due to the way data is collected by the Secunia PSI all results presented here are to be considered &quot;best case&quot; scenarios, the real numbers are likely to be worse.&quot;
So, to back up Kevin&#039;s statement: yes the numbers are probably worse.

The consensus is that full security is difficult to achieve, and would rely on a number of things (Vulnerability Management, AV, FireWall, Policy management/enforcement, end-user education) but core to the effort is patch management. This is also by far the cheapest, and easiest step in the process. With at least Patch Management in place, an important step has been taken towards relative security.

Stay Secure
psi.secunia.com]]></description>
		<content:encoded><![CDATA[<p>Interesting discussion; *when* is any system deemed &#8220;secure&#8221; ?! In my personal opinion, as long as we humans operate them; probably never. There will always be new angles of attack to a system, because this is human nature; exploration, discovery, challenges, overcoming obstacles and conquering. Security only exists at a high level, when the operator fully understands every aspect of a) the system&#8217;s workings, and b) the consequences of any action taken on the system.</p>
<p>Now, to the origin of the article this blog was based on. We (Secunia) used data from our PSI Patch Scanner, as the basis of a blog of our own: <a href="http://secunia.com/blog/37/" rel="nofollow">http://secunia.com/blog/37/</a><br />
Note that we do not, ever, state that a computer is secure when patch management is in place. This is a media spin on things, mostly because they do not fully understand the complexity of &#8220;security&#8221;.</p>
<p>True, the numbers are probably worse than the data from Secunia reveal. To quote the blog post:<br />
&#8220;Please note. Due to the way data is collected by the Secunia PSI all results presented here are to be considered &#8220;best case&#8221; scenarios, the real numbers are likely to be worse.&#8221;<br />
So, to back up Kevin&#8217;s statement: yes the numbers are probably worse.</p>
<p>The consensus is that full security is difficult to achieve, and would rely on a number of things (Vulnerability Management, AV, FireWall, Policy management/enforcement, end-user education) but core to the effort is patch management. This is also by far the cheapest, and easiest step in the process. With at least Patch Management in place, an important step has been taken towards relative security.</p>
<p>Stay Secure<br />
psi.secunia.com</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pete Herzog</title>
		<link>http://blog.impactalabs.com/2008/12/03/how-to-tell-if-a-system-is-secure/#comment-22</link>
		<dc:creator><![CDATA[Pete Herzog]]></dc:creator>
		<pubDate>Tue, 16 Dec 2008 20:14:54 +0000</pubDate>
		<guid isPermaLink="false">http://impactalabs.wordpress.com/?p=87#comment-22</guid>
		<description><![CDATA[You&#039;re right about the patch thing. When we dissected the components of &quot;security&quot; to assure a thorough test can be made for the OSSTMM, one of the first things we realized is that the model and definition for security was off. We ended up going with very specific definitions which actually fits to what you write here. Security is a physical separation between a threat and an asset at a determined vector. Safety is how a threat or its impact is controlled. So to be secure from lightning you would move into a mountain. To be safe from it, you would put up rods and stay indoors, away from windows. 

From there we break it down even further but what we find it allows us to handle things like whether patch is or isn&#039;t security.]]></description>
		<content:encoded><![CDATA[<p>You&#8217;re right about the patch thing. When we dissected the components of &#8220;security&#8221; to assure a thorough test can be made for the OSSTMM, one of the first things we realized is that the model and definition for security was off. We ended up going with very specific definitions which actually fits to what you write here. Security is a physical separation between a threat and an asset at a determined vector. Safety is how a threat or its impact is controlled. So to be secure from lightning you would move into a mountain. To be safe from it, you would put up rods and stay indoors, away from windows. </p>
<p>From there we break it down even further but what we find it allows us to handle things like whether patch is or isn&#8217;t security.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

