<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for My Information Security Job</title>
	<atom:link href="http://www.myinfosecjob.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.myinfosecjob.com</link>
	<description>Your reliable source for Information Security - Risk Management - Compliance jobs around the world</description>
	<lastBuildDate>Wed, 04 Apr 2012 20:04:59 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>Comment on 5 Scary Types of Security Professionals You Will Meet in Your Career by MD</title>
		<link>http://www.myinfosecjob.com/2012/04/5-scary-types-of-security-professionals-you-will-meet-in-your-career/comment-page-1/#comment-5450</link>
		<dc:creator>MD</dc:creator>
		<pubDate>Wed, 04 Apr 2012 20:04:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.myinfosecjob.com/?p=9181#comment-5450</guid>
		<description>Good article Adriano,

As you indicated in article chances are you&#039;ve met someone that posses all 5 mentioned qualities(personally i did) but yet to meet someone who posses both very deep hands-on experience mixed with theoretical ones-i think this is because security field is very large w/ so many domains. Maybe that comes with time on the job and some credentials(schools+certifications)...good reading though.</description>
		<content:encoded><![CDATA[<p>Good article Adriano,</p>
<p>As you indicated in article chances are you&#8217;ve met someone that posses all 5 mentioned qualities(personally i did) but yet to meet someone who posses both very deep hands-on experience mixed with theoretical ones-i think this is because security field is very large w/ so many domains. Maybe that comes with time on the job and some credentials(schools+certifications)&#8230;good reading though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on 5 Scary Types of Security Professionals You Will Meet in Your Career by Zman</title>
		<link>http://www.myinfosecjob.com/2012/04/5-scary-types-of-security-professionals-you-will-meet-in-your-career/comment-page-1/#comment-5449</link>
		<dc:creator>Zman</dc:creator>
		<pubDate>Wed, 04 Apr 2012 12:41:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.myinfosecjob.com/?p=9181#comment-5449</guid>
		<description>I defintely agree with the findings, I have met a few, and even been a few of these during my Infosec career, but the author hits the nail on the head that infosec needs to be more &quot;in-tune&quot; with the bussiness needs, its not about saying &quot;no&quot; its about getting to &quot;yes&quot; and that is going to take compromise, and some risk management and threat modeling of your processes and proceedures. Then you can better present the issues at hand to the business and make it palitable in their eyes and then you will probably see your security posture improve.</description>
		<content:encoded><![CDATA[<p>I defintely agree with the findings, I have met a few, and even been a few of these during my Infosec career, but the author hits the nail on the head that infosec needs to be more &#8220;in-tune&#8221; with the bussiness needs, its not about saying &#8220;no&#8221; its about getting to &#8220;yes&#8221; and that is going to take compromise, and some risk management and threat modeling of your processes and proceedures. Then you can better present the issues at hand to the business and make it palitable in their eyes and then you will probably see your security posture improve.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on 6 Reasons Why You Should NOT Work With Information Security by Pekae</title>
		<link>http://www.myinfosecjob.com/2011/08/6-reasons-why-you-should-not-work-with-information-security/comment-page-1/#comment-5448</link>
		<dc:creator>Pekae</dc:creator>
		<pubDate>Wed, 04 Apr 2012 07:36:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.myinfosecjob.com/?p=8507#comment-5448</guid>
		<description>Only just caught up with this - great, humorous article Adriano. Having been in IT 35 years and InfoSec for 15 of them, it really rings true (with a grain of tongue-in-cheek). 

All I can say to Cellus is, if he rarely works more than 40hrs a week, then he&#039;s not living in the real world (or making an effort!), which sums up his whole reply.</description>
		<content:encoded><![CDATA[<p>Only just caught up with this &#8211; great, humorous article Adriano. Having been in IT 35 years and InfoSec for 15 of them, it really rings true (with a grain of tongue-in-cheek). </p>
<p>All I can say to Cellus is, if he rarely works more than 40hrs a week, then he&#8217;s not living in the real world (or making an effort!), which sums up his whole reply.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on 5 Scary Types of Security Professionals You Will Meet in Your Career by Ian Tibble</title>
		<link>http://www.myinfosecjob.com/2012/04/5-scary-types-of-security-professionals-you-will-meet-in-your-career/comment-page-1/#comment-5447</link>
		<dc:creator>Ian Tibble</dc:creator>
		<pubDate>Wed, 04 Apr 2012 03:14:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.myinfosecjob.com/?p=9181#comment-5447</guid>
		<description>Good article, thanks.
Infosec as an established business practice is only about 15 to 20 years old and we&#039;re still learning. I think most of us look for a sense of balance but none of us know where the balance point is, plus - lest we not forget, security is complex. With all this we can easily say that nobody&#039;s perfect and we&#039;re also not in a position to say &quot;i&#039;m better than him [or her]&quot;...because there&#039;s no reference point.
What criteria do we use to measure effectiveness as a security professional? CISSP? Ultimately we&#039;re not in any position to pass judgment my friends. 
One thing for sure though, if we&#039;re sat on a project board and we&#039;re asked to make a call on risk for something like a new app deployment, I would hope that we actually have seen a command shell prompt before and had some fairly major IT experience (this is related to at least one of the categories mentioned here).
Just my opinion - Analysts need to be tech-oriented to a heavy degree. It&#039;s all about balance. We need some sense of business costs when we&#039;re proposing safeguards, but hopefully our managers have a handle on that too. But as to how &quot;tech&quot; or how &quot;businessey&quot; we need to be...who can say?</description>
		<content:encoded><![CDATA[<p>Good article, thanks.<br />
Infosec as an established business practice is only about 15 to 20 years old and we&#8217;re still learning. I think most of us look for a sense of balance but none of us know where the balance point is, plus &#8211; lest we not forget, security is complex. With all this we can easily say that nobody&#8217;s perfect and we&#8217;re also not in a position to say &#8220;i&#8217;m better than him [or her]&#8220;&#8230;because there&#8217;s no reference point.<br />
What criteria do we use to measure effectiveness as a security professional? CISSP? Ultimately we&#8217;re not in any position to pass judgment my friends.<br />
One thing for sure though, if we&#8217;re sat on a project board and we&#8217;re asked to make a call on risk for something like a new app deployment, I would hope that we actually have seen a command shell prompt before and had some fairly major IT experience (this is related to at least one of the categories mentioned here).<br />
Just my opinion &#8211; Analysts need to be tech-oriented to a heavy degree. It&#8217;s all about balance. We need some sense of business costs when we&#8217;re proposing safeguards, but hopefully our managers have a handle on that too. But as to how &#8220;tech&#8221; or how &#8220;businessey&#8221; we need to be&#8230;who can say?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on 5 Scary Types of Security Professionals You Will Meet in Your Career by theman</title>
		<link>http://www.myinfosecjob.com/2012/04/5-scary-types-of-security-professionals-you-will-meet-in-your-career/comment-page-1/#comment-5445</link>
		<dc:creator>theman</dc:creator>
		<pubDate>Tue, 03 Apr 2012 22:29:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.myinfosecjob.com/?p=9181#comment-5445</guid>
		<description>Obvious. I hope you got paid for writing this. Does it mean I can quit deciphering fw/router rocket science bug release notes and midnight reloads? 

Looks like I can just spend 20 minutes a day writing Dilbert stories about dysfunction in the IT Sec workspace and have enough money left over to hot-wax my Benz.</description>
		<content:encoded><![CDATA[<p>Obvious. I hope you got paid for writing this. Does it mean I can quit deciphering fw/router rocket science bug release notes and midnight reloads? </p>
<p>Looks like I can just spend 20 minutes a day writing Dilbert stories about dysfunction in the IT Sec workspace and have enough money left over to hot-wax my Benz.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on 5 Scary Types of Security Professionals You Will Meet in Your Career by David D</title>
		<link>http://www.myinfosecjob.com/2012/04/5-scary-types-of-security-professionals-you-will-meet-in-your-career/comment-page-1/#comment-5443</link>
		<dc:creator>David D</dc:creator>
		<pubDate>Tue, 03 Apr 2012 14:10:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.myinfosecjob.com/?p=9181#comment-5443</guid>
		<description>What all of these five types have in common is in being categoric and absolute in promoting data security. Besides being simplistic it&#039;s also unprofessional. Whenever I&#039;m asked about whether specific IT practices and behavior should be permitted I always say that a risk assessment is first in order to see if there&#039;s a possible business justification.  This can entail a lot of work and the lazy prefer working off a check list.</description>
		<content:encoded><![CDATA[<p>What all of these five types have in common is in being categoric and absolute in promoting data security. Besides being simplistic it&#8217;s also unprofessional. Whenever I&#8217;m asked about whether specific IT practices and behavior should be permitted I always say that a risk assessment is first in order to see if there&#8217;s a possible business justification.  This can entail a lot of work and the lazy prefer working off a check list.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on 5 Scary Types of Security Professionals You Will Meet in Your Career by Sitaram</title>
		<link>http://www.myinfosecjob.com/2012/04/5-scary-types-of-security-professionals-you-will-meet-in-your-career/comment-page-1/#comment-5442</link>
		<dc:creator>Sitaram</dc:creator>
		<pubDate>Tue, 03 Apr 2012 13:55:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.myinfosecjob.com/?p=9181#comment-5442</guid>
		<description>Very interesting article. Nice to know.</description>
		<content:encoded><![CDATA[<p>Very interesting article. Nice to know.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Security Challenge #2 &#8211; PCI DSS by JJ</title>
		<link>http://www.myinfosecjob.com/2011/03/security-challenge-pci-dss-1/comment-page-1/#comment-5441</link>
		<dc:creator>JJ</dc:creator>
		<pubDate>Tue, 03 Apr 2012 01:55:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.myinfosecjob.com/?p=6600#comment-5441</guid>
		<description>Wow, you broke into the bank where I work and stole one of our network diagrams. Y&#039;all just hire the wrong type of QSA.

1. Install DLP on all desktops, servers and exit points. DLP fixes everything wrong with a flat network and unencrypted servers.

2. Install NAC on the non-data center switches to keep unauthorized sniffers off the network. Yes, apparently it is OK to have a malware-installed sniffer on one of our servers.

3. Pass GO and collect your RoC and bonus.</description>
		<content:encoded><![CDATA[<p>Wow, you broke into the bank where I work and stole one of our network diagrams. Y&#8217;all just hire the wrong type of QSA.</p>
<p>1. Install DLP on all desktops, servers and exit points. DLP fixes everything wrong with a flat network and unencrypted servers.</p>
<p>2. Install NAC on the non-data center switches to keep unauthorized sniffers off the network. Yes, apparently it is OK to have a malware-installed sniffer on one of our servers.</p>
<p>3. Pass GO and collect your RoC and bonus.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on 5 Scary Types of Security Professionals You Will Meet in Your Career by notorious</title>
		<link>http://www.myinfosecjob.com/2012/04/5-scary-types-of-security-professionals-you-will-meet-in-your-career/comment-page-1/#comment-5440</link>
		<dc:creator>notorious</dc:creator>
		<pubDate>Tue, 03 Apr 2012 01:45:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.myinfosecjob.com/?p=9181#comment-5440</guid>
		<description>I was expecting to read about 1337 hackers!</description>
		<content:encoded><![CDATA[<p>I was expecting to read about 1337 hackers!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Immigrating to Australia as an Information Security Professional – part 4 – Finding a Job by Sandeep Saini</title>
		<link>http://www.myinfosecjob.com/2010/06/immigrating-to-australia-as-an-information-security-professional-4-finding-a-job/comment-page-1/#comment-5435</link>
		<dc:creator>Sandeep Saini</dc:creator>
		<pubDate>Fri, 23 Mar 2012 07:21:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.myinfosecjob.com/?p=2328#comment-5435</guid>
		<description>Hi Adriano,

I appropriate the efforts you put in place to make people understand about the Information Security Job market in AUS.

I am very much impressed with all your articles &amp; personally want to thank you for the same.

I really want to immigrate to AUS but fears due to the future unemployment.

Kindly guide me when I really need to start &amp; where exactly.

Thanks &amp; Regards,

Sandeep Saini</description>
		<content:encoded><![CDATA[<p>Hi Adriano,</p>
<p>I appropriate the efforts you put in place to make people understand about the Information Security Job market in AUS.</p>
<p>I am very much impressed with all your articles &amp; personally want to thank you for the same.</p>
<p>I really want to immigrate to AUS but fears due to the future unemployment.</p>
<p>Kindly guide me when I really need to start &amp; where exactly.</p>
<p>Thanks &amp; Regards,</p>
<p>Sandeep Saini</p>
]]></content:encoded>
	</item>
</channel>
</rss>

