<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for Data Risk Governance</title>
	<atom:link href="http://datariskgovernance.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://datariskgovernance.com</link>
	<description>Exploring the intersection between information security, privacy, technology and the law.</description>
	<lastBuildDate>Thu, 19 Apr 2012 16:03:14 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>Comment on Privacy by Michael Sim</title>
		<link>http://datariskgovernance.com/state-statutes/#comment-5807</link>
		<dc:creator><![CDATA[Michael Sim]]></dc:creator>
		<pubDate>Thu, 19 Apr 2012 16:03:14 +0000</pubDate>
		<guid isPermaLink="false">http://datariskgovernance.com/?page_id=20#comment-5807</guid>
		<description><![CDATA[March 2012 - Found your ISSA Feb 2011 article on the web (quite by chance) and found in enlightening. Thanks Matt for taking the time to work out the intricacies of data transfers regarding the 95/46/EC Directive and making it accessible to lay people such as myself. Michael SIM, CISA, CISM, CISSP, BS 25999 Business Continuity]]></description>
		<content:encoded><![CDATA[<p>March 2012 &#8211; Found your ISSA Feb 2011 article on the web (quite by chance) and found in enlightening. Thanks Matt for taking the time to work out the intricacies of data transfers regarding the 95/46/EC Directive and making it accessible to lay people such as myself. Michael SIM, CISA, CISM, CISSP, BS 25999 Business Continuity</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Is the CISSP worth it anymore? by ITauditSecurity</title>
		<link>http://datariskgovernance.com/2012/05/03/is-the-cissp-worth-it-anymore/#comment-1131</link>
		<dc:creator><![CDATA[ITauditSecurity]]></dc:creator>
		<pubDate>Mon, 24 Jan 2011 00:51:30 +0000</pubDate>
		<guid isPermaLink="false">http://datariskgovernance.com/?p=454#comment-1131</guid>
		<description><![CDATA[I think the CISSP is between 2 &amp; 3, not 3 &amp; 4. I still find it respected and valued. Certs don&#039;t prove anything other than you were able to meet a certain level of qualification. Hiring managers still have to do their due diligence, but if you don&#039;t have certs today, you will be passed over for jobs. It&#039;s that simple.

There&#039;s a lot of bad doctors and lawyers out there too.

If you&#039;re reading this and were thinking of pursuing the CISSP, I still urge you to do it. If you&#039;re not super skilled, you&#039;ll gain from the study; if you already are super skilled, passing it should be easy. In either case, you&#039;ll have an advantage over the next person. Where&#039;s the downside?]]></description>
		<content:encoded><![CDATA[<p>I think the CISSP is between 2 &amp; 3, not 3 &amp; 4. I still find it respected and valued. Certs don&#8217;t prove anything other than you were able to meet a certain level of qualification. Hiring managers still have to do their due diligence, but if you don&#8217;t have certs today, you will be passed over for jobs. It&#8217;s that simple.</p>
<p>There&#8217;s a lot of bad doctors and lawyers out there too.</p>
<p>If you&#8217;re reading this and were thinking of pursuing the CISSP, I still urge you to do it. If you&#8217;re not super skilled, you&#8217;ll gain from the study; if you already are super skilled, passing it should be easy. In either case, you&#8217;ll have an advantage over the next person. Where&#8217;s the downside?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Resources by Information Security Policy &#171; Data Risk Governance</title>
		<link>http://datariskgovernance.com/resources/#comment-1008</link>
		<dc:creator><![CDATA[Information Security Policy &#171; Data Risk Governance]]></dc:creator>
		<pubDate>Fri, 17 Dec 2010 21:33:04 +0000</pubDate>
		<guid isPermaLink="false">http://datariskgovernance.com/?page_id=31#comment-1008</guid>
		<description><![CDATA[[...] Resources [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Resources [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Is the CISSP worth it anymore? by walterbyrd</title>
		<link>http://datariskgovernance.com/2012/05/03/is-the-cissp-worth-it-anymore/#comment-918</link>
		<dc:creator><![CDATA[walterbyrd]]></dc:creator>
		<pubDate>Mon, 08 Nov 2010 15:42:00 +0000</pubDate>
		<guid isPermaLink="false">http://datariskgovernance.com/?p=454#comment-918</guid>
		<description><![CDATA[I am surprised that you have not taken DoD directive 8570 into account. For installations that are managed under that directive, the CISSP is not just a &quot;de facto&quot; standard, it is an official standard for most specializations. 

There are other certs, which will sometimes qualify for this or that. But, from my experience the CISSP is &quot;it&quot; in an 8570 environment.]]></description>
		<content:encoded><![CDATA[<p>I am surprised that you have not taken DoD directive 8570 into account. For installations that are managed under that directive, the CISSP is not just a &#8220;de facto&#8221; standard, it is an official standard for most specializations. </p>
<p>There are other certs, which will sometimes qualify for this or that. But, from my experience the CISSP is &#8220;it&#8221; in an 8570 environment.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Is the CISSP worth it anymore? by Mike D</title>
		<link>http://datariskgovernance.com/2012/05/03/is-the-cissp-worth-it-anymore/#comment-876</link>
		<dc:creator><![CDATA[Mike D]]></dc:creator>
		<pubDate>Tue, 05 Oct 2010 20:56:41 +0000</pubDate>
		<guid isPermaLink="false">http://datariskgovernance.com/?p=454#comment-876</guid>
		<description><![CDATA[Good to see that all my hard work is in vain..   :-)

Seriously,  If a security manager takes a certification as gospel, then I guess they are leaving themselves open to all sorts of issues. As any CISSP can tell you, not doing your &quot;due diligence&quot; or not using &quot;Due Care&quot; or at least using the &quot;Prudent Man Rule&quot; can lead to all sorts of undesired consequences.. 

Having sat for the exam (and no results as of yet... 3 1/2 weeks &amp; counting...) I believe in the certification process, and believe it can root out the no experience type of test taker.  Without my extensive background of over 10 years in IT Management &amp; 15 years as a programmer, I would&#039;ve been somewhat lost.]]></description>
		<content:encoded><![CDATA[<p>Good to see that all my hard work is in vain..   <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Seriously,  If a security manager takes a certification as gospel, then I guess they are leaving themselves open to all sorts of issues. As any CISSP can tell you, not doing your &#8220;due diligence&#8221; or not using &#8220;Due Care&#8221; or at least using the &#8220;Prudent Man Rule&#8221; can lead to all sorts of undesired consequences.. </p>
<p>Having sat for the exam (and no results as of yet&#8230; 3 1/2 weeks &amp; counting&#8230;) I believe in the certification process, and believe it can root out the no experience type of test taker.  Without my extensive background of over 10 years in IT Management &amp; 15 years as a programmer, I would&#8217;ve been somewhat lost.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Is the CISSP worth it anymore? by Ahmad Wasiuta</title>
		<link>http://datariskgovernance.com/2012/05/03/is-the-cissp-worth-it-anymore/#comment-850</link>
		<dc:creator><![CDATA[Ahmad Wasiuta]]></dc:creator>
		<pubDate>Thu, 16 Sep 2010 18:58:26 +0000</pubDate>
		<guid isPermaLink="false">http://datariskgovernance.com/?p=454#comment-850</guid>
		<description><![CDATA[This is a very entertaining post. I am glad to see this subject being written about. I like reading these types of articles they help to keep me in the loop.]]></description>
		<content:encoded><![CDATA[<p>This is a very entertaining post. I am glad to see this subject being written about. I like reading these types of articles they help to keep me in the loop.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Zubulake v. UBS Warburg LLC (Zubulake V) by Chiriqui, Panama</title>
		<link>http://datariskgovernance.com/ediscovery/e-discovery-course-fall-2009/zubulake-v-zubulake-v-ubs-warburg-llc/#comment-669</link>
		<dc:creator><![CDATA[Chiriqui, Panama]]></dc:creator>
		<pubDate>Wed, 12 May 2010 09:32:25 +0000</pubDate>
		<guid isPermaLink="false">http://datariskgovernance.com/?page_id=328#comment-669</guid>
		<description><![CDATA[Super post - and nifty domain by the way!]]></description>
		<content:encoded><![CDATA[<p>Super post &#8211; and nifty domain by the way!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Risk Management by Matt</title>
		<link>http://datariskgovernance.com/risk-assessment/#comment-375</link>
		<dc:creator><![CDATA[Matt]]></dc:creator>
		<pubDate>Thu, 18 Feb 2010 20:42:21 +0000</pubDate>
		<guid isPermaLink="false">http://datariskgovernance.com/?page_id=25#comment-375</guid>
		<description><![CDATA[Link fixed. Thanks!]]></description>
		<content:encoded><![CDATA[<p>Link fixed. Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Risk Management by J Barker</title>
		<link>http://datariskgovernance.com/risk-assessment/#comment-354</link>
		<dc:creator><![CDATA[J Barker]]></dc:creator>
		<pubDate>Mon, 08 Feb 2010 14:18:23 +0000</pubDate>
		<guid isPermaLink="false">http://datariskgovernance.com/?page_id=25#comment-354</guid>
		<description><![CDATA[The link to a &quot;sample risk assessment&quot; is broken on following page
http://datariskgovernance.com/risk-assessment/]]></description>
		<content:encoded><![CDATA[<p>The link to a &#8220;sample risk assessment&#8221; is broken on following page<br />
<a href="http://datariskgovernance.com/risk-assessment/" rel="nofollow">http://datariskgovernance.com/risk-assessment/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on eDiscovery by Gordon Thomas</title>
		<link>http://datariskgovernance.com/ediscovery/#comment-336</link>
		<dc:creator><![CDATA[Gordon Thomas]]></dc:creator>
		<pubDate>Mon, 01 Feb 2010 05:54:13 +0000</pubDate>
		<guid isPermaLink="false">http://datariskgovernance.com/?page_id=266#comment-336</guid>
		<description><![CDATA[Thanks. There is some useful infomation here good work.  sorry I cannot leave a constructive comment as i am abit out of my deph I will be checking back here periodically for your new updates. london insurance 30 St Mary Axe, london, EC3A 8EP 020 7193 4776]]></description>
		<content:encoded><![CDATA[<p>Thanks. There is some useful infomation here good work.  sorry I cannot leave a constructive comment as i am abit out of my deph I will be checking back here periodically for your new updates. london insurance 30 St Mary Axe, london, EC3A 8EP 020 7193 4776</p>
]]></content:encoded>
	</item>
</channel>
</rss>

