<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Data Risk Governance</title>
	<atom:link href="http://datariskgovernance.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://datariskgovernance.com</link>
	<description>Exploring the intersection between information security, privacy, technology and the law.</description>
	<lastBuildDate>Thu, 03 May 2012 19:24:01 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='datariskgovernance.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Data Risk Governance</title>
		<link>http://datariskgovernance.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://datariskgovernance.com/osd.xml" title="Data Risk Governance" />
	<atom:link rel='hub' href='http://datariskgovernance.com/?pushpress=hub'/>
		<item>
		<title>Is the CISSP worth it anymore?</title>
		<link>http://datariskgovernance.com/2012/05/03/is-the-cissp-worth-it-anymore/</link>
		<comments>http://datariskgovernance.com/2012/05/03/is-the-cissp-worth-it-anymore/#comments</comments>
		<pubDate>Thu, 03 May 2012 18:20:51 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://datariskgovernance.com/?p=454</guid>
		<description><![CDATA[Update 05/03/12 The CISSP is still going strong and remains a de facto starting point for most hiring managers in information security.   The level of difficulty of the exam is likely slowing the rate of dilution. Update 1/05/11 The Employment Value of Multiple Certifications, by BankInfoSecurity.com. Check out this no B.S. employer perspective on [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datariskgovernance.com&amp;blog=7143300&amp;post=454&amp;subd=datariskgovernance&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Update 05/03/12</p>
<p>The <a href="www.networkworld.com/news/2012/050312-cybersecurity-tips-258931.html">CISSP is still going strong</a> and remains a de facto starting point for most hiring managers in information security.   The level of difficulty of the exam is likely slowing the rate of dilution.</p>
<p>Update 1/05/11</p>
<p><a href="http://www.bankinfosecurity.com/articles.php?art_id=1265">The Employment Value of Multiple Certifications</a>, by BankInfoSecurity.com.</p>
<p><a href="http://web.interhack.com/company/contact">Check out this no B.S. employer perspective on hiring certified job candidates:</a> &#8220;Interested in CISSP, SSCP, CISA, and PMP certification holders. (N.B., this is largely a courtesy to our clients; we do not expect that certification will make you an expert and neither should you.)&#8221;</p>
<p>Original Post, 10/23/09:</p>
<p><strong><span style="text-decoration:underline;">Life Cycle</span></strong></p>
<p>Let&#8217;s consider the life cycle of a professional certification (at least in the IT field):</p>
<p>1- The sponsoring organization wants to market the certification and promote it so more and more people obtain it. This means an initial grandfathering process whereby the organization sponsoring the cert. can get (presumably) experienced and prominent practitioners to get the certification and give it some credibility.</p>
<p>2- The difficulty of the exams and requirements are slowly improved. This allows more for swift early adoption and then a quality check on the way to achieving critical mass, slowing the momentum so the certificate doesn&#8217;t peak too early. If a certification achieves instant and widespread fame, it will be considered cheap and watered down.</p>
<p>3- As the inevitable dilution of the certification&#8217;s value occurs, due to the number of barely qualified individuals holding it, organizations begin creating specializations or advanced classes of their general certification, to create a &#8220;new&#8221; certification that can start over with the certification life cycle.</p>
<p>4- As yesterday&#8217;s preeminent and prestigious certification becomes today&#8217;s standard, the uniqueness of those gaining the credential becomes lessened.  Applying familiar bell curves to the population of skilled workers (10/80/10 or 20/60/20) the best and the average are all able to pass the test.  If in fact, even some of the lesser skilled professionals can pass the test, the certifying organizations may have a cash cow but will be short lived because the certification will do little for hiring managers in discerning IT talent.  Therefore, <strong>a test-based certification loses its ability over time to differentiate skills in the workforce, as more and more of the lesser skilled attain the certification.</strong></p>
<p>5- Eventually, the certification becomes so unhelpful as an indicator of specialized skills, that the industry, which once benefited by its sifting effect of the pool of job applicants, no longer rely on it and stop asking for it altogether.</p>
<p>It would seem to me that the CISSP is somewhere in between #3 and #4 in the above life cycle.</p>
<p><strong><span style="text-decoration:underline;">Rote Memorization vs. Practical Skills</span></strong></p>
<p>Like most certifications, the CISSP includes required sponsorship and minimum work experience. Presumably this is to help prevent just anyone from walking in off the street and passing the exam, further diluting the value of the credential.  This practice doesn&#8217;t seem to be able to prevent the eventual dilution of the certification by mass distribution among those with minimal skills, although it probably slows the process.</p>
<p>The certifications that require practical performance are harder to pass, and therefore retain their prestige in the marketplace. One of the best examples of this is probably Cisco&#8217;s  CCIE certification, which requires the test taker to actually troubleshoot and repair a broken or mis-configured network. The test is notorious.  <a href="http://www.networkworld.com/news/2006/022006-widernet-ccie-side1.html">Cisco claims the lifetime pass rate of the CCIE is 26%</a>, much lower than the California bar exam.</p>
<p>Another notoriously difficult certification to achieve is the GIAC Security Expert (GSE), offered by SANS. <a href="http://www.giac.org/certifications/gse.php">There are only 30 of them in the world</a>, as of Sept. 30, 2010.  The best thing about the GSE is that it is so difficult and expensive to obtain, (two years and ~ $15,000) the risk of it becoming a watered down laughing-stock in the IT Security industry is virtually nil.  The down side is that it is still so obscure, and probably will remain so because of cost barriers, it isn&#8217;t going to score many points in the hiring process until late- round interviews, when you meet with the security gurus.</p>
<p>The most challenging aspect of these practical skills-based certifications is the actual performance of what you learn. You are literally dropped off in a real IT environment for a couple days and you can&#8217;t come out until all is well. Good Luck!</p>
<p><span style="text-decoration:underline;"><strong>Money Talks, Posers Walk</strong></span></p>
<p>There is a double-edged sword to how hard to make your certification, and I suspect it boils down to money.  Here is the Hobson&#8217;s Choice to make if you are a certification authority introducing a new certification:</p>
<ol>
<li><strong>Skills</strong>: The certification needs to be hard and thorough enough to demonstrate competency.</li>
<li><strong>Price/Cost</strong>: The certification must be priced to generate enough revenue to pay for the overhead required to create it, test for it and offer member services, while yielding a profit. However, it can&#8217;t be priced so high that cost becomes a bar to many people.</li>
<li><strong>Credibility</strong>: The certification must be earned by enough people that it gains a foothold in the marketplace and becomes a de facto measuring stick of the profession, or at least holds enough weight in industry that it becomes sought after by hiring managers.</li>
</ol>
<p><strong>This then becomes the dilemma: You can have any two of the three qualities above, but not all three.</strong> If you shoot for all three, your certification will be a one hit wonder that will become a fossilized certificate found between the strata of the IT archaeological record.  Just like my Novell Netware 5 CNE.</p>
<p>(I purposely ignored the distinction between vendor neutral and vendor product-based certifications. It doesn&#8217;t seem relevant to the overriding issue of certification dilution. I understand that a CNE is worthless today b/c the Netware platform did not survive the Microsoft/Novell war, and because of release obsolescence.)</p>
<p>Here is <a href="http://internetcop.org/2008/03/who-wants-to-be-cissp.html">an author who isn&#8217;t quite so &#8220;down&#8221; on the CISSP</a>.</p>
<p>Here is <a href="http://www.rootedyour.com/node/7">a typical complaint regarding the CISSP</a>.   Interestingly, the author advocates professional licensing of information security professionals. He does not consider the fact that he would then have to triple his salary requirements in order to get malpractice insurance.  The threat of litigation against professional misconduct is the single greatest force driving the exorbitant prices charged by licensed professionals (lawyers and doctors) who work under threat of tort litigation. (I&#8217;m not intending to get into a debate over tort reform here.)</p>
<p>The argument to professionally license security experts is analogous to the old argument running back into the 90&#8242;s to license software developers, at least those that write code in life support and critical systems, (airline traffic control, space exploration, medical devices, etc.)  I remember vigorous debates on this topic in Dr. Dobbs Journal.</p>
<p>In summary, if you are seeking employment in, or a job transfer within the information security field, the CISSP is still a de facto requirement in many job descriptions.  You&#8217;ll need the certificate to get past the HR threshold criteria. But don&#8217;t expect any security managers to think you are any better than their worst security employee, who probably also holds a CISSP.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datariskgovernance.wordpress.com/454/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datariskgovernance.wordpress.com/454/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datariskgovernance.wordpress.com/454/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datariskgovernance.wordpress.com/454/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/datariskgovernance.wordpress.com/454/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/datariskgovernance.wordpress.com/454/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/datariskgovernance.wordpress.com/454/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/datariskgovernance.wordpress.com/454/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datariskgovernance.wordpress.com/454/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datariskgovernance.wordpress.com/454/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datariskgovernance.wordpress.com/454/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datariskgovernance.wordpress.com/454/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datariskgovernance.wordpress.com/454/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datariskgovernance.wordpress.com/454/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datariskgovernance.com&amp;blog=7143300&amp;post=454&amp;subd=datariskgovernance&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://datariskgovernance.com/2012/05/03/is-the-cissp-worth-it-anymore/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c5f357fe09ba9d2fc0ed4a34c652d3f8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">msorenz</media:title>
		</media:content>
	</item>
		<item>
		<title>Advanced E-Discovery Institute 2011</title>
		<link>http://datariskgovernance.com/2011/11/17/advanced-e-discovery-institute-2011/</link>
		<comments>http://datariskgovernance.com/2011/11/17/advanced-e-discovery-institute-2011/#comments</comments>
		<pubDate>Thu, 17 Nov 2011 13:47:01 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://datariskgovernance.com/?p=947</guid>
		<description><![CDATA[&#160; Notes taken during presentations made at the 2011 Advanced E-Discovery Institute, held at the Ritz Carlton hotel, Washington D.C., November 17-18 2011. &#160;<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datariskgovernance.com&amp;blog=7143300&amp;post=947&amp;subd=datariskgovernance&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<p><a href="http://wp.me/PtYiw-fj">Notes taken</a> during presentations made at the 2011 Advanced E-Discovery Institute, held at the Ritz Carlton hotel, Washington D.C., November 17-18 2011.</p>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datariskgovernance.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datariskgovernance.wordpress.com/947/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datariskgovernance.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datariskgovernance.wordpress.com/947/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/datariskgovernance.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/datariskgovernance.wordpress.com/947/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/datariskgovernance.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/datariskgovernance.wordpress.com/947/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datariskgovernance.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datariskgovernance.wordpress.com/947/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datariskgovernance.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datariskgovernance.wordpress.com/947/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datariskgovernance.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datariskgovernance.wordpress.com/947/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datariskgovernance.com&amp;blog=7143300&amp;post=947&amp;subd=datariskgovernance&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://datariskgovernance.com/2011/11/17/advanced-e-discovery-institute-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c5f357fe09ba9d2fc0ed4a34c652d3f8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">msorenz</media:title>
		</media:content>
	</item>
		<item>
		<title>Information Security Policy</title>
		<link>http://datariskgovernance.com/2010/12/17/information-security-policy/</link>
		<comments>http://datariskgovernance.com/2010/12/17/information-security-policy/#comments</comments>
		<pubDate>Fri, 17 Dec 2010 21:32:58 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://datariskgovernance.com/?p=939</guid>
		<description><![CDATA[New Policy content added to the Resources section.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datariskgovernance.com&amp;blog=7143300&amp;post=939&amp;subd=datariskgovernance&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>New <a title="Policy" href="http://datariskgovernance.com/resources/policy/">Policy </a>content added to the <a title="Resources" href="http://datariskgovernance.com/resources/">Resources </a>section.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datariskgovernance.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datariskgovernance.wordpress.com/939/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datariskgovernance.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datariskgovernance.wordpress.com/939/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/datariskgovernance.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/datariskgovernance.wordpress.com/939/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/datariskgovernance.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/datariskgovernance.wordpress.com/939/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datariskgovernance.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datariskgovernance.wordpress.com/939/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datariskgovernance.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datariskgovernance.wordpress.com/939/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datariskgovernance.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datariskgovernance.wordpress.com/939/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datariskgovernance.com&amp;blog=7143300&amp;post=939&amp;subd=datariskgovernance&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://datariskgovernance.com/2010/12/17/information-security-policy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c5f357fe09ba9d2fc0ed4a34c652d3f8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">msorenz</media:title>
		</media:content>
	</item>
		<item>
		<title>SANS Legal 523: Law of Data Security and Investigations</title>
		<link>http://datariskgovernance.com/2010/12/16/sans-legal-523-law-of-data-security-and-investigations/</link>
		<comments>http://datariskgovernance.com/2010/12/16/sans-legal-523-law-of-data-security-and-investigations/#comments</comments>
		<pubDate>Fri, 17 Dec 2010 04:26:07 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://datariskgovernance.com/?p=903</guid>
		<description><![CDATA[This past week I&#8217;ve had the privilege of attending the one of the nation&#8217;s best training events dealing with information security and legal issues. See my review here.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datariskgovernance.com&amp;blog=7143300&amp;post=903&amp;subd=datariskgovernance&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This past week I&#8217;ve had the privilege of attending the one of the nation&#8217;s best training events dealing with information security and legal issues. See my review <a title="SANS Legal 523: Law of Data Security and Investigations" href="http://datariskgovernance.com/conferences/review-sans-legal-523-law-of-data-security-investigations/">here</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datariskgovernance.wordpress.com/903/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datariskgovernance.wordpress.com/903/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datariskgovernance.wordpress.com/903/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datariskgovernance.wordpress.com/903/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/datariskgovernance.wordpress.com/903/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/datariskgovernance.wordpress.com/903/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/datariskgovernance.wordpress.com/903/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/datariskgovernance.wordpress.com/903/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datariskgovernance.wordpress.com/903/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datariskgovernance.wordpress.com/903/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datariskgovernance.wordpress.com/903/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datariskgovernance.wordpress.com/903/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datariskgovernance.wordpress.com/903/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datariskgovernance.wordpress.com/903/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datariskgovernance.com&amp;blog=7143300&amp;post=903&amp;subd=datariskgovernance&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://datariskgovernance.com/2010/12/16/sans-legal-523-law-of-data-security-and-investigations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c5f357fe09ba9d2fc0ed4a34c652d3f8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">msorenz</media:title>
		</media:content>
	</item>
		<item>
		<title>Infected by Malware: Throw the Computer Away?</title>
		<link>http://datariskgovernance.com/2010/12/16/infected-by-malware-throw-the-computer-away/</link>
		<comments>http://datariskgovernance.com/2010/12/16/infected-by-malware-throw-the-computer-away/#comments</comments>
		<pubDate>Fri, 17 Dec 2010 02:03:27 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://datariskgovernance.com/?p=883</guid>
		<description><![CDATA[There are some forms of malware circulating that infect the persistent memory on graphics processing cards (GPU), network interface cards and any other hardware component that contains its own memory distinct from the computers RAM. This means that you cannot remove the malware simply by reinstalling your operating system after formatting your hard drive, because [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datariskgovernance.com&amp;blog=7143300&amp;post=883&amp;subd=datariskgovernance&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>There are some forms of malware circulating that infect the persistent memory on graphics processing cards (GPU), network interface cards and any other hardware component that contains its own memory distinct from the computers RAM. This means that you cannot remove the malware simply by reinstalling your operating system after formatting your hard drive, because the malware is located in the memory of one of your hardware components. The difficulty in removing the malware from these locations may just mean you&#8217;re better off throwing the computer out and buying a new one! This has been the case for some organizations that have been infected by these types of malware. So much for not hurting the hardware.</p>
<p>http://www.vizworld.com/2010/09/gpuassisted-malware/</p>
<p>Discovered: http://www.theregister.co.uk/2009/03/24/persistent_bios_rootkits/</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datariskgovernance.wordpress.com/883/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datariskgovernance.wordpress.com/883/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datariskgovernance.wordpress.com/883/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datariskgovernance.wordpress.com/883/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/datariskgovernance.wordpress.com/883/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/datariskgovernance.wordpress.com/883/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/datariskgovernance.wordpress.com/883/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/datariskgovernance.wordpress.com/883/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datariskgovernance.wordpress.com/883/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datariskgovernance.wordpress.com/883/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datariskgovernance.wordpress.com/883/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datariskgovernance.wordpress.com/883/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datariskgovernance.wordpress.com/883/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datariskgovernance.wordpress.com/883/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datariskgovernance.com&amp;blog=7143300&amp;post=883&amp;subd=datariskgovernance&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://datariskgovernance.com/2010/12/16/infected-by-malware-throw-the-computer-away/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c5f357fe09ba9d2fc0ed4a34c652d3f8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">msorenz</media:title>
		</media:content>
	</item>
		<item>
		<title>Live Blog From Georgetown Advanced E-Discovery Conference</title>
		<link>http://datariskgovernance.com/2010/11/18/live-blog-from-georgetown-advanced-e-discovery-conference/</link>
		<comments>http://datariskgovernance.com/2010/11/18/live-blog-from-georgetown-advanced-e-discovery-conference/#comments</comments>
		<pubDate>Thu, 18 Nov 2010 16:06:02 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[eDiscovery]]></category>

		<guid isPermaLink="false">http://datariskgovernance.com/?p=829</guid>
		<description><![CDATA[See my notes covering the below topics, here: 2010 Georgetown Advanced E-Discovery Institute (Nov. 18-19, 2010) Case Law Update International E-Discovery RULE 502: Inadvertent Waiver Proportionality: Is It Real or a Paper Tiger?  Kevin F. Brady, Conor R. Crowley, Joseph P. Guglielmo, Hon. Andrew J. Peck, Hon. Joseph R. Slights, III. Sedona Conference published in [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datariskgovernance.com&amp;blog=7143300&amp;post=829&amp;subd=datariskgovernance&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>See my notes covering the below topics, here: <a href="http://wp.me/PtYiw-dh">2010 Georgetown Advanced E-Discovery Institute (Nov. 18-19, 2010)</a></p>
<p style="padding-left:30px;">Case Law Update</p>
<p style="padding-left:30px;">International E-Discovery</p>
<p style="padding-left:30px;">RULE 502: Inadvertent Waiver</p>
<p style="padding-left:30px;">Proportionality: Is It Real or a Paper Tiger?  Kevin F.  Brady, Conor R. Crowley, Joseph P. Guglielmo, Hon. Andrew J. Peck, Hon.  Joseph R. Slights, III.</p>
<p style="padding-left:30px;">Sedona Conference published in October, 2010, the <a href="http://www.thesedonaconference.org/dltForm?did=Proportionality2010.pdf">Principles of Proportionality.</a></p>
<p style="padding-left:30px;">The Business of E-Discovery</p>
<p style="padding-left:60px;">Major  themes and lessons learned in the session: 1- The &#8220;problems&#8221; of  disappointing IT solutions for E-discovery is no different than the  general pitfalls of IT providing solutions for general business  problems. Good old-fashioned IT project management, requirements  gathering, and integration of business process (in this case, legal  processes) expertise in the delivery of technology.   2- Legal now has a  place at the table in the GRC and information governance. Chief  Compliance Officers are now able to have budgets dedicated to managing  the information risks of their organizations.</p>
<p style="padding-left:30px;">Not Just EU Privacy: A Global View on International E-Discovery</p>
<p style="padding-left:30px;">Early Evidence Assessment &amp; Strategies for Search, Retrieval &amp; Review (Early Case Assessment)</p>
<p style="padding-left:30px;">2010: A Sanctions Odyssey</p>
<p style="padding-left:30px;">Craig Ball, Database Discovery.</p>
<p style="padding-left:30px;">Cloud Computing; Dan Regard, Tanya Forsheit, Hon. Francis Allegra, Theresa Beaumont</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datariskgovernance.wordpress.com/829/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datariskgovernance.wordpress.com/829/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datariskgovernance.wordpress.com/829/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datariskgovernance.wordpress.com/829/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/datariskgovernance.wordpress.com/829/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/datariskgovernance.wordpress.com/829/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/datariskgovernance.wordpress.com/829/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/datariskgovernance.wordpress.com/829/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datariskgovernance.wordpress.com/829/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datariskgovernance.wordpress.com/829/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datariskgovernance.wordpress.com/829/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datariskgovernance.wordpress.com/829/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datariskgovernance.wordpress.com/829/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datariskgovernance.wordpress.com/829/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datariskgovernance.com&amp;blog=7143300&amp;post=829&amp;subd=datariskgovernance&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://datariskgovernance.com/2010/11/18/live-blog-from-georgetown-advanced-e-discovery-conference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c5f357fe09ba9d2fc0ed4a34c652d3f8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">msorenz</media:title>
		</media:content>
	</item>
		<item>
		<title>Is Stuxnet the &#8216;best&#8217; malware ever?</title>
		<link>http://datariskgovernance.com/2010/10/04/is-stuxnet-the-best-malware-ever/</link>
		<comments>http://datariskgovernance.com/2010/10/04/is-stuxnet-the-best-malware-ever/#comments</comments>
		<pubDate>Mon, 04 Oct 2010 18:32:27 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://datariskgovernance.com/?p=821</guid>
		<description><![CDATA[Is Stuxnet the &#8216;best&#8217; malware ever?.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datariskgovernance.com&amp;blog=7143300&amp;post=821&amp;subd=datariskgovernance&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.computerworld.com/s/article/9185919/Is_Stuxnet_the_best_malware_ever_">Is Stuxnet the &#8216;best&#8217; malware ever?</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datariskgovernance.wordpress.com/821/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datariskgovernance.wordpress.com/821/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datariskgovernance.wordpress.com/821/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datariskgovernance.wordpress.com/821/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/datariskgovernance.wordpress.com/821/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/datariskgovernance.wordpress.com/821/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/datariskgovernance.wordpress.com/821/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/datariskgovernance.wordpress.com/821/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datariskgovernance.wordpress.com/821/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datariskgovernance.wordpress.com/821/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datariskgovernance.wordpress.com/821/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datariskgovernance.wordpress.com/821/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datariskgovernance.wordpress.com/821/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datariskgovernance.wordpress.com/821/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datariskgovernance.com&amp;blog=7143300&amp;post=821&amp;subd=datariskgovernance&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://datariskgovernance.com/2010/10/04/is-stuxnet-the-best-malware-ever/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c5f357fe09ba9d2fc0ed4a34c652d3f8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">msorenz</media:title>
		</media:content>
	</item>
		<item>
		<title>Failed Risk-Based Security: Notes from Donn Parker RSA 2010 Presentation</title>
		<link>http://datariskgovernance.com/2010/04/22/failed-risk-based-security-notes-from-donn-parker-rsa-2010-presentation/</link>
		<comments>http://datariskgovernance.com/2010/04/22/failed-risk-based-security-notes-from-donn-parker-rsa-2010-presentation/#comments</comments>
		<pubDate>Thu, 22 Apr 2010 17:23:08 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[19004365]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Risk Management & Compliance]]></category>

		<guid isPermaLink="false">http://datariskgovernance.com/?p=753</guid>
		<description><![CDATA[Failed Risk-Based Security<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datariskgovernance.com&amp;blog=7143300&amp;post=753&amp;subd=datariskgovernance&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://wp.me/PtYiw-bh">Failed Risk-Based Security</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datariskgovernance.wordpress.com/753/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datariskgovernance.wordpress.com/753/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datariskgovernance.wordpress.com/753/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datariskgovernance.wordpress.com/753/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/datariskgovernance.wordpress.com/753/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/datariskgovernance.wordpress.com/753/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/datariskgovernance.wordpress.com/753/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/datariskgovernance.wordpress.com/753/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datariskgovernance.wordpress.com/753/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datariskgovernance.wordpress.com/753/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datariskgovernance.wordpress.com/753/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datariskgovernance.wordpress.com/753/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datariskgovernance.wordpress.com/753/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datariskgovernance.wordpress.com/753/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datariskgovernance.com&amp;blog=7143300&amp;post=753&amp;subd=datariskgovernance&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://datariskgovernance.com/2010/04/22/failed-risk-based-security-notes-from-donn-parker-rsa-2010-presentation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c5f357fe09ba9d2fc0ed4a34c652d3f8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">msorenz</media:title>
		</media:content>
	</item>
		<item>
		<title>Helping Lawyers Overcome Cloud Anxiety</title>
		<link>http://datariskgovernance.com/2010/04/22/helping-lawyers-overcome-cloud-anxiety/</link>
		<comments>http://datariskgovernance.com/2010/04/22/helping-lawyers-overcome-cloud-anxiety/#comments</comments>
		<pubDate>Thu, 22 Apr 2010 17:08:26 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Controls]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Risk Assessment]]></category>

		<guid isPermaLink="false">http://datariskgovernance.com/?p=748</guid>
		<description><![CDATA[Author and attorney Julie Tower-Pierce contributed  short little article to the April 2010 issue of Information Security magazine, that encourages IT personnel to provide insight and clarity on cloud computing to corporate counsel. Corporate counsel are rightly concerned about a variety of data protection risks  stemming from the use of third-party computing services.  Tower-Pierce writes, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datariskgovernance.com&amp;blog=7143300&amp;post=748&amp;subd=datariskgovernance&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Author and attorney Julie Tower-Pierce contributed  short little article to the <a href="http://media.techtarget.com/Syndication/SECURITY/0410_ISM_final.pdf">April 2010 issue of Information Security magazine,</a> that encourages IT personnel to provide insight and clarity on cloud computing to corporate counsel. Corporate counsel are rightly concerned about a variety of data protection risks  stemming from the use of third-party computing services.  Tower-Pierce writes, &#8220;By using straightforward, practical explanations and real-world analogies/examples, minus excessive technicalities when possible, you can impart a firm understanding of the mechanics of cloud computing and help lawyers gain perspective.&#8221;</p>
<p>I have no qualms about this approach whatsoever. The challenge is getting the two sides to even have the conversation. Most likely, the conversation would originate during the a company&#8217;s vendor (third-party) assessment process. This is the most frequent interaction between in-house counsel and information security or other risk assessors. The contractual relationship is often hammered out simultaneously with the IT controls assessment.</p>
<p>Another opportune time to have the conversation is during a corporate risk committee or IT governance steering committee meeting. These meetings take on a variety of shapes, names and participants, but whatever the risk management authority looks like, it should incorporate discussions on emerging topics such as cloud computing.</p>
<p>A third opportunity to have such discussions would be to invite legal to participate in the development of a cloud computing security policy,  a part of a firm&#8217;s overall information security policy framework.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datariskgovernance.wordpress.com/748/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datariskgovernance.wordpress.com/748/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datariskgovernance.wordpress.com/748/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datariskgovernance.wordpress.com/748/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/datariskgovernance.wordpress.com/748/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/datariskgovernance.wordpress.com/748/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/datariskgovernance.wordpress.com/748/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/datariskgovernance.wordpress.com/748/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datariskgovernance.wordpress.com/748/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datariskgovernance.wordpress.com/748/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datariskgovernance.wordpress.com/748/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datariskgovernance.wordpress.com/748/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datariskgovernance.wordpress.com/748/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datariskgovernance.wordpress.com/748/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datariskgovernance.com&amp;blog=7143300&amp;post=748&amp;subd=datariskgovernance&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://datariskgovernance.com/2010/04/22/helping-lawyers-overcome-cloud-anxiety/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c5f357fe09ba9d2fc0ed4a34c652d3f8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">msorenz</media:title>
		</media:content>
	</item>
		<item>
		<title>ISO 31000</title>
		<link>http://datariskgovernance.com/2010/04/12/iso-31000/</link>
		<comments>http://datariskgovernance.com/2010/04/12/iso-31000/#comments</comments>
		<pubDate>Mon, 12 Apr 2010 19:50:34 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Risk Management & Compliance]]></category>
		<category><![CDATA[Standards & Frameworks]]></category>

		<guid isPermaLink="false">http://datariskgovernance.com/?p=737</guid>
		<description><![CDATA[Here&#8217;s a link to a short article describing the new ISO 31000:2009 standard, purportedly a generic risk management process guide that is industry agnostic.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datariskgovernance.com&amp;blog=7143300&amp;post=737&amp;subd=datariskgovernance&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s a <a href="http://tinyurl.com/yb7lu27">link to a short article</a> describing the new ISO 31000:2009 standard, purportedly a generic risk management process guide that is industry agnostic.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datariskgovernance.wordpress.com/737/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datariskgovernance.wordpress.com/737/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datariskgovernance.wordpress.com/737/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datariskgovernance.wordpress.com/737/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/datariskgovernance.wordpress.com/737/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/datariskgovernance.wordpress.com/737/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/datariskgovernance.wordpress.com/737/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/datariskgovernance.wordpress.com/737/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datariskgovernance.wordpress.com/737/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datariskgovernance.wordpress.com/737/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datariskgovernance.wordpress.com/737/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datariskgovernance.wordpress.com/737/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datariskgovernance.wordpress.com/737/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datariskgovernance.wordpress.com/737/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datariskgovernance.com&amp;blog=7143300&amp;post=737&amp;subd=datariskgovernance&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://datariskgovernance.com/2010/04/12/iso-31000/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c5f357fe09ba9d2fc0ed4a34c652d3f8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">msorenz</media:title>
		</media:content>
	</item>
	</channel>
</rss>
