<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for Data Risk Governance</title>
	<atom:link href="http://datariskgovernance.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://datariskgovernance.com</link>
	<description>Exploring the intersection between information security, privacy, technology and the law.</description>
	<lastBuildDate>Mon, 24 Jan 2011 00:51:30 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>Comment on Is the CISSP worth it anymore? by ITauditSecurity</title>
		<link>http://datariskgovernance.com/2010/03/10/is-the-cissp-worth-it-anymore/#comment-1131</link>
		<dc:creator><![CDATA[ITauditSecurity]]></dc:creator>
		<pubDate>Mon, 24 Jan 2011 00:51:30 +0000</pubDate>
		<guid isPermaLink="false">http://datariskgovernance.com/?p=454#comment-1131</guid>
		<description><![CDATA[I think the CISSP is between 2 &amp; 3, not 3 &amp; 4. I still find it respected and valued. Certs don&#039;t prove anything other than you were able to meet a certain level of qualification. Hiring managers still have to do their due diligence, but if you don&#039;t have certs today, you will be passed over for jobs. It&#039;s that simple.

There&#039;s a lot of bad doctors and lawyers out there too.

If you&#039;re reading this and were thinking of pursuing the CISSP, I still urge you to do it. If you&#039;re not super skilled, you&#039;ll gain from the study; if you already are super skilled, passing it should be easy. In either case, you&#039;ll have an advantage over the next person. Where&#039;s the downside?]]></description>
		<content:encoded><![CDATA[<p>I think the CISSP is between 2 &amp; 3, not 3 &amp; 4. I still find it respected and valued. Certs don&#8217;t prove anything other than you were able to meet a certain level of qualification. Hiring managers still have to do their due diligence, but if you don&#8217;t have certs today, you will be passed over for jobs. It&#8217;s that simple.</p>
<p>There&#8217;s a lot of bad doctors and lawyers out there too.</p>
<p>If you&#8217;re reading this and were thinking of pursuing the CISSP, I still urge you to do it. If you&#8217;re not super skilled, you&#8217;ll gain from the study; if you already are super skilled, passing it should be easy. In either case, you&#8217;ll have an advantage over the next person. Where&#8217;s the downside?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Resources by Information Security Policy &#171; Data Risk Governance</title>
		<link>http://datariskgovernance.com/resources/#comment-1008</link>
		<dc:creator><![CDATA[Information Security Policy &#171; Data Risk Governance]]></dc:creator>
		<pubDate>Fri, 17 Dec 2010 21:33:04 +0000</pubDate>
		<guid isPermaLink="false">http://datariskgovernance.com/?page_id=31#comment-1008</guid>
		<description><![CDATA[[...] Resources [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Resources [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Is the CISSP worth it anymore? by walterbyrd</title>
		<link>http://datariskgovernance.com/2010/03/10/is-the-cissp-worth-it-anymore/#comment-918</link>
		<dc:creator><![CDATA[walterbyrd]]></dc:creator>
		<pubDate>Mon, 08 Nov 2010 15:42:00 +0000</pubDate>
		<guid isPermaLink="false">http://datariskgovernance.com/?p=454#comment-918</guid>
		<description><![CDATA[I am surprised that you have not taken DoD directive 8570 into account. For installations that are managed under that directive, the CISSP is not just a &quot;de facto&quot; standard, it is an official standard for most specializations. 

There are other certs, which will sometimes qualify for this or that. But, from my experience the CISSP is &quot;it&quot; in an 8570 environment.]]></description>
		<content:encoded><![CDATA[<p>I am surprised that you have not taken DoD directive 8570 into account. For installations that are managed under that directive, the CISSP is not just a &#8220;de facto&#8221; standard, it is an official standard for most specializations. </p>
<p>There are other certs, which will sometimes qualify for this or that. But, from my experience the CISSP is &#8220;it&#8221; in an 8570 environment.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Is the CISSP worth it anymore? by Mike D</title>
		<link>http://datariskgovernance.com/2010/03/10/is-the-cissp-worth-it-anymore/#comment-876</link>
		<dc:creator><![CDATA[Mike D]]></dc:creator>
		<pubDate>Tue, 05 Oct 2010 20:56:41 +0000</pubDate>
		<guid isPermaLink="false">http://datariskgovernance.com/?p=454#comment-876</guid>
		<description><![CDATA[Good to see that all my hard work is in vain..   :-)

Seriously,  If a security manager takes a certification as gospel, then I guess they are leaving themselves open to all sorts of issues. As any CISSP can tell you, not doing your &quot;due diligence&quot; or not using &quot;Due Care&quot; or at least using the &quot;Prudent Man Rule&quot; can lead to all sorts of undesired consequences.. 

Having sat for the exam (and no results as of yet... 3 1/2 weeks &amp; counting...) I believe in the certification process, and believe it can root out the no experience type of test taker.  Without my extensive background of over 10 years in IT Management &amp; 15 years as a programmer, I would&#039;ve been somewhat lost.]]></description>
		<content:encoded><![CDATA[<p>Good to see that all my hard work is in vain..   <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Seriously,  If a security manager takes a certification as gospel, then I guess they are leaving themselves open to all sorts of issues. As any CISSP can tell you, not doing your &#8220;due diligence&#8221; or not using &#8220;Due Care&#8221; or at least using the &#8220;Prudent Man Rule&#8221; can lead to all sorts of undesired consequences.. </p>
<p>Having sat for the exam (and no results as of yet&#8230; 3 1/2 weeks &amp; counting&#8230;) I believe in the certification process, and believe it can root out the no experience type of test taker.  Without my extensive background of over 10 years in IT Management &amp; 15 years as a programmer, I would&#8217;ve been somewhat lost.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Is the CISSP worth it anymore? by Ahmad Wasiuta</title>
		<link>http://datariskgovernance.com/2010/03/10/is-the-cissp-worth-it-anymore/#comment-850</link>
		<dc:creator><![CDATA[Ahmad Wasiuta]]></dc:creator>
		<pubDate>Thu, 16 Sep 2010 18:58:26 +0000</pubDate>
		<guid isPermaLink="false">http://datariskgovernance.com/?p=454#comment-850</guid>
		<description><![CDATA[This is a very entertaining post. I am glad to see this subject being written about. I like reading these types of articles they help to keep me in the loop.]]></description>
		<content:encoded><![CDATA[<p>This is a very entertaining post. I am glad to see this subject being written about. I like reading these types of articles they help to keep me in the loop.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Zubulake v. UBS Warburg LLC (Zubulake V) by Chiriqui, Panama</title>
		<link>http://datariskgovernance.com/ediscovery/e-discovery-course-fall-2009/zubulake-v-zubulake-v-ubs-warburg-llc/#comment-669</link>
		<dc:creator><![CDATA[Chiriqui, Panama]]></dc:creator>
		<pubDate>Wed, 12 May 2010 09:32:25 +0000</pubDate>
		<guid isPermaLink="false">http://datariskgovernance.com/?page_id=328#comment-669</guid>
		<description><![CDATA[Super post - and nifty domain by the way!]]></description>
		<content:encoded><![CDATA[<p>Super post &#8211; and nifty domain by the way!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Risk Management by Matt</title>
		<link>http://datariskgovernance.com/risk-assessment/#comment-375</link>
		<dc:creator><![CDATA[Matt]]></dc:creator>
		<pubDate>Thu, 18 Feb 2010 20:42:21 +0000</pubDate>
		<guid isPermaLink="false">http://datariskgovernance.com/?page_id=25#comment-375</guid>
		<description><![CDATA[Link fixed. Thanks!]]></description>
		<content:encoded><![CDATA[<p>Link fixed. Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Risk Management by J Barker</title>
		<link>http://datariskgovernance.com/risk-assessment/#comment-354</link>
		<dc:creator><![CDATA[J Barker]]></dc:creator>
		<pubDate>Mon, 08 Feb 2010 14:18:23 +0000</pubDate>
		<guid isPermaLink="false">http://datariskgovernance.com/?page_id=25#comment-354</guid>
		<description><![CDATA[The link to a &quot;sample risk assessment&quot; is broken on following page
http://datariskgovernance.com/risk-assessment/]]></description>
		<content:encoded><![CDATA[<p>The link to a &#8220;sample risk assessment&#8221; is broken on following page<br />
<a href="http://datariskgovernance.com/risk-assessment/" rel="nofollow">http://datariskgovernance.com/risk-assessment/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on eDiscovery by Gordon Thomas</title>
		<link>http://datariskgovernance.com/ediscovery/#comment-336</link>
		<dc:creator><![CDATA[Gordon Thomas]]></dc:creator>
		<pubDate>Mon, 01 Feb 2010 05:54:13 +0000</pubDate>
		<guid isPermaLink="false">http://datariskgovernance.com/?page_id=266#comment-336</guid>
		<description><![CDATA[Thanks. There is some useful infomation here good work.  sorry I cannot leave a constructive comment as i am abit out of my deph I will be checking back here periodically for your new updates. london insurance 30 St Mary Axe, london, EC3A 8EP 020 7193 4776]]></description>
		<content:encoded><![CDATA[<p>Thanks. There is some useful infomation here good work.  sorry I cannot leave a constructive comment as i am abit out of my deph I will be checking back here periodically for your new updates. london insurance 30 St Mary Axe, london, EC3A 8EP 020 7193 4776</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on European Union Data Privacy Directive 95/46/EC by coda</title>
		<link>http://datariskgovernance.com/state-statutes/european-union-data-privacy-directive-9546ec/#comment-209</link>
		<dc:creator><![CDATA[coda]]></dc:creator>
		<pubDate>Tue, 08 Dec 2009 21:38:53 +0000</pubDate>
		<guid isPermaLink="false">http://datariskgovernance.com/?page_id=331#comment-209</guid>
		<description><![CDATA[Hello
Appreciate your sharing thoughts on DPD.
Q. Article 20 - any jurisprudence regarding privacy impact assessment processes?]]></description>
		<content:encoded><![CDATA[<p>Hello<br />
Appreciate your sharing thoughts on DPD.<br />
Q. Article 20 &#8211; any jurisprudence regarding privacy impact assessment processes?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

