<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>advent-im</title>
	<atom:link href="http://adventim.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://adventim.wordpress.com</link>
	<description>holistic security blog</description>
	<lastBuildDate>Tue, 21 Feb 2012 15:15:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='adventim.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/378ad3f56739aa6dcf2b7a5edb681cb2?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>advent-im</title>
		<link>http://adventim.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://adventim.wordpress.com/osd.xml" title="advent-im" />
	<atom:link rel='hub' href='http://adventim.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Bring Your Own Device to work, let&#8217;s think about that one&#8230;</title>
		<link>http://adventim.wordpress.com/2012/02/17/bring-your-own-device-to-work-lets-think-about-that-one/</link>
		<comments>http://adventim.wordpress.com/2012/02/17/bring-your-own-device-to-work-lets-think-about-that-one/#comments</comments>
		<pubDate>Fri, 17 Feb 2012 11:17:53 +0000</pubDate>
		<dc:creator>Ellie Hurst</dc:creator>
				<category><![CDATA[consultancy]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[ISO27001]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[physical security]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security consultants]]></category>
		<category><![CDATA[security management]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Avanade]]></category>
		<category><![CDATA[bring your own device]]></category>
		<category><![CDATA[BYOD]]></category>
		<category><![CDATA[cost saving]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[data risk]]></category>
		<category><![CDATA[flexible working]]></category>
		<category><![CDATA[information loss]]></category>
		<category><![CDATA[IT budgets]]></category>
		<category><![CDATA[laptop]]></category>
		<category><![CDATA[mobile device]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[security policy]]></category>
		<category><![CDATA[security threat]]></category>
		<category><![CDATA[smartphone]]></category>
		<category><![CDATA[tablet]]></category>
		<category><![CDATA[work life balance]]></category>

		<guid isPermaLink="false">http://adventim.wordpress.com/?p=176</guid>
		<description><![CDATA[Should it work for you but more importantly can it work for you? Dave Wharton, Senior Security Consultant, Advent IM With the proliferation of Smartphones and Tablets there is a growing trend that allows or turns a blind eye to &#8230; <a href="http://adventim.wordpress.com/2012/02/17/bring-your-own-device-to-work-lets-think-about-that-one/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=adventim.wordpress.com&amp;blog=27864670&amp;post=176&amp;subd=adventim&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h1><span style="color:#333333;"><strong>Should it work for you but more importantly can it work for you?</strong></span></h1>
<h4><span style="color:#333333;"><strong><em>Dave Wharton, Senior Security Consultant, Advent IM</em></strong></span></h4>
<p><a href="http://adventim.files.wordpress.com/2012/02/dentrix-mobile.jpg"><img class="wp-image-183 alignleft" title="Mobile devices" src="http://adventim.files.wordpress.com/2012/02/dentrix-mobile.jpg?w=208&#038;h=126" alt="" width="208" height="126" /></a></p>
<h2><span style="color:#333333;"><strong><em>With the proliferation of Smartphones and Tablets there is a growing trend that allows or turns a blind eye to the use of personal devices for work purposes but is it safe and can a company really justify it in the event something goes wrong?   </em></strong></span></h2>
<p><span style="color:#333333;">In an era where flexibility and mobility is the key, there seems to be a growing acceptance by companies (or is it a sense of inevitability) that staff should be allowed to use their own devices to do their work on – BYOD.  Whether this is using a PC at home or using their Smartphones, Tablets and Laptops on the move, there is no question staff are doing it either with or without the blessing of their company.  A recent BBC article on BYOD quoted a survey by Avanade (a business technology company) in which it was found that 88% of executives said employees used their own devices for business purposes (<a href="http://www.bbc.co.uk/news/business-17017570"><span style="color:#333333;">http://www.bbc.co.uk/news/business-17017570</span></a>).  Another survey found that while 48% of employers would never allow BYOD, 57% agreed that some staff used personal devices without consent.  </span></p>
<p><span style="color:#333333;">So what, might you ask?<em>  </em></span></p>
<p><span style="color:#333333;"><em> </em><em>My PC at work is slow and takes an age to open an email and if I try to do two things at once it just freezes or my boss needs this by tomorrow and I’ll be damned if I’m staying behind again tonight.  </em></span></p>
<p><span style="color:#333333;">When faced with such challenges is it any wonder that staff want to take advantage of their state of the art device that provides functionality and performance a company ICT manager can only dream of.  The appeal to companies is there also, productivity improves and staff are content but at what price?  Companies that allow BYOD should be under no illusion that it does not come without risk.  By allowing staff to use their own devices, companies are in effect relinquishing control of how their information (sensitive or otherwise) is imported and exported from their business networks and are also allowing the connection of untrusted devices.  Thereby, increasing the risk of malware attacks, data compromise and perhaps more worryingly exposing the business to reputational harm or costly fines in the event of a data protection breach.  Is there any managing director or senior partner who would welcome the scrutiny of the Information Commissioners Officer?</span></p>
<p><span style="color:#333333;">So what is the answer?  The straight forward answer is not to allow it and I am not going to advocate the use of BYOD here.  There are number of reasons why you shouldn’t and perhaps only one reason why you should.  While employee satisfaction is clearly important the main advantage to employers comes down to cost.  By allowing BYOD there are potential savings in ICT infrastructure, as in effect you are passing (somewhat unfairly) the burden of upgrades to your staff.  You could even offer staff an annual bonus for using their own devices and to share the cost of upgrading and still save money.  A very convincing argument in favour of BYOD was also presented on ZDNet (<a href="http://www.zdnet.com/blog/virtualization/byod-the-inevitable-reality/3953"><span style="color:#333333;">http://www.zdnet.com/blog/virtualization/byod-the-inevitable-reality/3953</span></a>) although I would disagree (obviously) with the views on security and argue that this is where governance comes in (see below).    </span></p>
<p><span style="color:#333333;">However, as I said earlier if you do so you relinquish control which in my view will always be too high a price.  Now some will argue that as soon as you provide staff with a Smartphone or Laptop you lose control of these devices the second they walk off the premises so why worry about using BYOD.  However, I would contend that this is where governance comes in.  Issuing staff with company owned devices means you determine (among others): </span></p>
<ul>
<li><span style="color:#333333;">What devices are permitted;</span></li>
<li><span style="color:#333333;">The operating system and how it is kept secure with the latest security updates and patches;</span></li>
<li><span style="color:#333333;">The strength and quality of passwords used;</span></li>
<li><span style="color:#333333;">What anti-malware software is used and perhaps more importantly how it is updated:</span></li>
<li><span style="color:#333333;">How data is stored and protected on the device;</span></li>
<li><span style="color:#333333;">How and where the device connects to the internet;</span></li>
<li><span style="color:#333333;">What removable media (eg. USB memory sticks, CDs, etc) is permitted.</span></li>
</ul>
<p><span style="color:#333333;">And with governance and compliance checking you can ensure that the above points are always maintained and that the device is used in accordance with your companies acceptable use policies.  Can you honestly say your staff will be as vigilant in protecting their own devices, have a look at this regarding passwords on mobile phones (<a href="http://www.scmagazineuk.com/consumers-failing-to-take-mobile-security-seriously-says-sophos/article/209294/"><span style="color:#333333;">http://www.scmagazineuk.com/consumers-failing-to-take-mobile-security-seriously-says-sophos/article/209294/</span></a>).  You may also want to consider that your staff will also probably let their friends and family use their devices but will be less inclined to do so with a company owned device.    </span></p>
<p><span style="color:#333333;">To support my view I have a challenge for you.  Take a look at the advice for an effective cyber defence provided by the UK Government’s Centre for the Protection of Critical National Infrastructure (<a href="http://www.cpni.gov.uk/advice/infosec/Critical-controls"><span style="color:#333333;">http://www.cpni.gov.uk/advice/infosec/Critical-controls</span></a>) and see how allowing BYOD compares against the advice provided.  You might also want to see how your organisation’s ICT infrastructure meets the listed controls while you’re on, particularly if you are holding large volumes of customer personal data.     </span></p>
<p><span style="color:#333333;">So should/can BYOD work for you?  My answer is no on both counts.  My advice is organisations that want to protect their own information and that of their clients should even consider implementing an information security management system.  Such as that provided by the International Standards Organisation 27001 standard, which provides a structured series of controls a part of which will assist organisations in implementing a business-supporting and secure ICT programme.    </span></p>
<div class="mceTemp"></div>
<div class="mceTemp"><a href="http://adventim.files.wordpress.com/2012/02/leaky-bucket.jpg"><img class="alignright size-full wp-image-186" title="leaky bucket" src="http://adventim.files.wordpress.com/2012/02/leaky-bucket.jpg?w=584" alt=""   /></a></div>
<p><span style="color:#333333;">However and despite my claim I wouldn’t advocate the use of BYOD, if you find yourself in a position where you have no choice.  There are some steps you can take to reduce the risk (if only slightly) of BYOD: </span></p>
<ol>
<li><span style="color:#333333;">Identify what types of devices will be permitted and which won’t;</span></li>
<li><span style="color:#333333;">Authorise permitted devices and block all others;</span></li>
<li><span style="color:#333333;">Segregate particularly sensitive company/client data on the network and consider what access will be permitted from remote devices;</span></li>
<li><span style="color:#333333;">Insist on specific encryption standards for data storage and using WiFi;</span></li>
<li><span style="color:#333333;">Insist that anti-malware is installed, kept up to date and the device is regularly scanned;</span></li>
<li><span style="color:#333333;">Insist that a remote emergency wiping capability is added to the device for if the device is lost/stolen;</span></li>
<li><span style="color:#333333;">Keep up to date with the latest threats and vulnerabilities and have a policy in place for responding accordingly;</span></li>
<li><span style="color:#333333;">Develop, educate and enforce BYOD policies that cover Steps 1 to 7 and:</span></li>
</ol>
<ul>
<ul>
<li><span style="color:#333333;"> Immediate actions if the device is lost or stolen</span></li>
<li><span style="color:#333333;">The impact on a staff member’s expectation to privacy when connecting their device to the company network;</span></li>
<li><span style="color:#333333;">How the device can connect to company networks;</span></li>
<li><span style="color:#333333;">Acceptable use for email and the internet;</span></li>
<li><span style="color:#333333;">The wiping of data when a staff member upgrades/replaces their device;</span></li>
<li><span style="color:#333333;">The wiping of data when a staff member leaves the company.</span></li>
</ul>
</ul>
<p><span style="color:#333333;">Consider compliance checking on devices to ensure the above is occurring;</span></p>
<p><span style="color:#333333;">Consider what support options the company might offer for the devices.</span></p>
<p><span style="color:#333333;"><strong>Dave Wharton, Senior Security Consultant, Advent IM</strong></span></p>
<br /> Tagged: <a href='http://adventim.wordpress.com/tag/avanade/'>Avanade</a>, <a href='http://adventim.wordpress.com/tag/bring-your-own-device/'>bring your own device</a>, <a href='http://adventim.wordpress.com/tag/byod/'>BYOD</a>, <a href='http://adventim.wordpress.com/tag/cost-saving/'>cost saving</a>, <a href='http://adventim.wordpress.com/tag/cyber/'>cyber</a>, <a href='http://adventim.wordpress.com/tag/data-breach/'>data breach</a>, <a href='http://adventim.wordpress.com/tag/data-loss/'>data loss</a>, <a href='http://adventim.wordpress.com/tag/data-risk/'>data risk</a>, <a href='http://adventim.wordpress.com/tag/flexible-working/'>flexible working</a>, <a href='http://adventim.wordpress.com/tag/information-loss/'>information loss</a>, <a href='http://adventim.wordpress.com/tag/information-security/'>information security</a>, <a href='http://adventim.wordpress.com/tag/it-budgets/'>IT budgets</a>, <a href='http://adventim.wordpress.com/tag/laptop/'>laptop</a>, <a href='http://adventim.wordpress.com/tag/mobile-device/'>mobile device</a>, <a href='http://adventim.wordpress.com/tag/risk/'>risk</a>, <a href='http://adventim.wordpress.com/tag/risk-assessment/'>risk assessment</a>, <a href='http://adventim.wordpress.com/tag/security-policy/'>security policy</a>, <a href='http://adventim.wordpress.com/tag/security-threat/'>security threat</a>, <a href='http://adventim.wordpress.com/tag/smartphone/'>smartphone</a>, <a href='http://adventim.wordpress.com/tag/tablet/'>tablet</a>, <a href='http://adventim.wordpress.com/tag/work-life-balance/'>work life balance</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/adventim.wordpress.com/176/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/adventim.wordpress.com/176/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/adventim.wordpress.com/176/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/adventim.wordpress.com/176/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/adventim.wordpress.com/176/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/adventim.wordpress.com/176/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/adventim.wordpress.com/176/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/adventim.wordpress.com/176/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/adventim.wordpress.com/176/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/adventim.wordpress.com/176/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/adventim.wordpress.com/176/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/adventim.wordpress.com/176/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/adventim.wordpress.com/176/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/adventim.wordpress.com/176/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=adventim.wordpress.com&amp;blog=27864670&amp;post=176&amp;subd=adventim&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://adventim.wordpress.com/2012/02/17/bring-your-own-device-to-work-lets-think-about-that-one/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b0fd815674d40d9f2671f56918cec3dc?s=96&#38;d=wavatar&#38;r=G" medium="image">
			<media:title type="html">adventim</media:title>
		</media:content>

		<media:content url="http://adventim.files.wordpress.com/2012/02/dentrix-mobile.jpg?w=300" medium="image">
			<media:title type="html">Mobile devices</media:title>
		</media:content>

		<media:content url="http://adventim.files.wordpress.com/2012/02/leaky-bucket.jpg" medium="image">
			<media:title type="html">leaky bucket</media:title>
		</media:content>
	</item>
		<item>
		<title>FOI and the Great British Public</title>
		<link>http://adventim.wordpress.com/2012/02/16/foi-and-the-great-british-public/</link>
		<comments>http://adventim.wordpress.com/2012/02/16/foi-and-the-great-british-public/#comments</comments>
		<pubDate>Thu, 16 Feb 2012 14:30:41 +0000</pubDate>
		<dc:creator>Ellie Hurst</dc:creator>
				<category><![CDATA[information security]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[Freedom of Information]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[FOI]]></category>
		<category><![CDATA[civil service]]></category>
		<category><![CDATA[local government]]></category>
		<category><![CDATA[central government]]></category>

		<guid isPermaLink="false">http://adventim.wordpress.com/?p=150</guid>
		<description><![CDATA[A Guardian article yesterday said that Civil Servants feel that The Freedom of Information Act (FOI) has not improved Government. You can read it here if you missed it. You&#8217;ve got to have a system. I agree with the bulk of &#8230; <a href="http://adventim.wordpress.com/2012/02/16/foi-and-the-great-british-public/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=adventim.wordpress.com&amp;blog=27864670&amp;post=150&amp;subd=adventim&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A Guardian article yesterday said that Civil Servants feel that The Freedom of Information Act (FOI) has not improved Government.</p>
<p>You can read it <a href="http://www.guardian.co.uk/politics/2012/feb/13/freedom-of-information-ministry-justice">here </a>if you missed it.</p>
<dl class="wp-caption alignleft">
<dt class="wp-caption-dt"><a href="http://adventim.files.wordpress.com/2012/02/documents_g_k.jpg"><img class="size-medium wp-image-151" title="documents_g_k" src="http://adventim.files.wordpress.com/2012/02/documents_g_k.jpg?w=300&#038;h=213" alt="" width="300" height="213" /></a></dt>
<dd class="wp-caption-dd">You&#8217;ve got to have a system.</dd>
</dl>
<p>I agree with the bulk of this article. I am not totally convinced that &#8220;Joe or Joanne Bloggs&#8221; were ever really sure what FOI is meant for.</p>
<p>Of course, there have been some crackpot, waste of time requests. That was always going to happen. But to quote our Commerical Director, &#8220;Freedom of Information &#8211; nice idea, but it&#8217;s not being used to any great effect by the public. This seems to driven by an apparent apathy. &#8221; She goes on to say, &#8220;The country gives the appearance sometimes of being politically disinterested &#8211; just look at the turn out for local elections. The key question is, if it&#8217;s purpose was to engage the public was it just poorly promoted or is the Great British Public just indifferent and apathetic?&#8221;</p>
<p>Good question. It seems to me that the more local it gets, the interested people get, as Local Government appears to receive more FOI requests (shame they aren&#8217;t quite so keen on turning out for elections but there we are). This may indicate a disconnect with Central Government and lack of interest or that people generally want more information about the &#8216;in my backyard&#8217; type of question.</p>
<p>So what do people think of FOI? There seems to be confusion between FOI and Data Protection Act &#8211; again think about how these have been presented to the public and it may not be so surprising. Few people realise that organisations have an obligation to maintain a publication scheme and few public organsations proactively market their publication schemes.</p>
<p>FOI seems to come into its own for journalists looking for information &#8211; sometimes justified, sometimes salacious, for their stories. This is in danger of bringing the whole scheme into disrepute and that would be a shame.</p>
<p>I spoke to Mike Gillespie, our MD about this yesterday and he said, &#8220;Yes, however don&#8217;t lose sight that this report discussed in the article, was written by civil servants, and civil servants have to process FOI requests&#8230;&#8221; So imagine that now it is beginning to be viewed and discussed as a &#8220;costly burden&#8221; means there may be changes ahead.</p>
<br /> Tagged: <a href='http://adventim.wordpress.com/tag/central-government/'>central government</a>, <a href='http://adventim.wordpress.com/tag/civil-service/'>civil service</a>, <a href='http://adventim.wordpress.com/tag/data-protection/'>data protection</a>, <a href='http://adventim.wordpress.com/tag/foi/'>FOI</a>, <a href='http://adventim.wordpress.com/tag/freedom-of-information/'>Freedom of Information</a>, <a href='http://adventim.wordpress.com/tag/local-government/'>local government</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/adventim.wordpress.com/150/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/adventim.wordpress.com/150/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/adventim.wordpress.com/150/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/adventim.wordpress.com/150/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/adventim.wordpress.com/150/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/adventim.wordpress.com/150/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/adventim.wordpress.com/150/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/adventim.wordpress.com/150/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/adventim.wordpress.com/150/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/adventim.wordpress.com/150/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/adventim.wordpress.com/150/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/adventim.wordpress.com/150/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/adventim.wordpress.com/150/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/adventim.wordpress.com/150/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=adventim.wordpress.com&amp;blog=27864670&amp;post=150&amp;subd=adventim&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://adventim.wordpress.com/2012/02/16/foi-and-the-great-british-public/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b0fd815674d40d9f2671f56918cec3dc?s=96&#38;d=wavatar&#38;r=G" medium="image">
			<media:title type="html">adventim</media:title>
		</media:content>

		<media:content url="http://adventim.files.wordpress.com/2012/02/documents_g_k.jpg?w=300" medium="image">
			<media:title type="html">documents_g_k</media:title>
		</media:content>
	</item>
		<item>
		<title>The new EU General Data Protection Regulation and the right to be forgotten</title>
		<link>http://adventim.wordpress.com/2012/01/23/the-new-eu-general-data-protection-regulation-and-the-right-to-be-forgotten/</link>
		<comments>http://adventim.wordpress.com/2012/01/23/the-new-eu-general-data-protection-regulation-and-the-right-to-be-forgotten/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 14:59:58 +0000</pubDate>
		<dc:creator>Ellie Hurst</dc:creator>
				<category><![CDATA[consultancy]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection act]]></category>
		<category><![CDATA[data protection directive]]></category>
		<category><![CDATA[eu security]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security consultants]]></category>
		<category><![CDATA[security management]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[cookies]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[european commission]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[justice commissioner]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[personal security]]></category>
		<category><![CDATA[right to be forgotten]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://adventim.wordpress.com/?p=143</guid>
		<description><![CDATA[The new EU General Data Protection Regulation, to provide greater harmonization of data protection rules across Europe,  will be published on 26 January.  So what?  Well, rather than being something radically different or new for organisations and data controllers to &#8230; <a href="http://adventim.wordpress.com/2012/01/23/the-new-eu-general-data-protection-regulation-and-the-right-to-be-forgotten/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=adventim.wordpress.com&amp;blog=27864670&amp;post=143&amp;subd=adventim&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><em><strong>The new EU General Data Protection Regulation, to provide greater harmonization of data protection rules across Europe,  will be published on 26 January.  So what? </strong></em></p>
<p><div id="attachment_145" class="wp-caption alignleft" style="width: 224px"><a href="http://adventim.files.wordpress.com/2012/01/mp9003826491.jpg"><img class="size-medium wp-image-145" title="MP900382649[1]" src="http://adventim.files.wordpress.com/2012/01/mp9003826491.jpg?w=214&#038;h=300" alt="" width="214" height="300" /></a><p class="wp-caption-text">The right to be forgotten? If Data Protection principles are being adhered to, is it really a change?</p></div>Well, rather than being something radically different or new for organisations and data controllers to get to grips with, the new Regulation trumpets compliance with two of our existing data protection principles; Personal data shall not be kept for longer than is necessary, and Personal data shall not be transferred to a country or territory outside the European Economic Area (EEA).</p>
<p>For example, the much-heralded ‘le droit à l’oubli’ clause (‘the right to be forgotten’ apparently, although my school boy French was limited to ordering half a kilo of sausages with predictably hilarious results) will require person’s internet histories to be deleted after use (e.g. cookies) has incited some rather inflammatory statements in some areas.  Data protection compliance has been likened to some onerous kill-joy like Blakey from the bawdy 1970s television programme ‘On The Buses’ (<a href="http://www.scmagazineuk.com/new-data-protection-laws-will-see-blakey-in-every-business/article/218287/?DCMP=EMC-SCUK_Newswire">http://www.scmagazineuk.com/new-data-protection-laws-will-see-blakey-in-every-business/article/218287/?DCMP=EMC-SCUK_Newswire</a>).  However, in the end this is just applying the well-worn requirement to retain information for only as long as you require and then permanently delete it.</p>
<p>Likewise, the ‘new’ Regulation also addresses extra-territorial actions by third countries such as the USA Patriot Act and the USA Foreign Intelligence Surveillance Act and imposes barriers for foreign judicial authorities to access European data.  This issue became international news recently when a US court requested European Twitter account details (<a href="http://www.bbc.co.uk/news/world-us-canada-12459989">http://www.bbc.co.uk/news/world-us-canada-12459989</a>).  However when all is said and done the Regulation is only reinforcing what we should all be doing anyway; i.e. not transmitting personal data outside the EEA unless there is a good and lawful reason (for the UK these are set out in Schedule 4 of the Data Protection Act &#8211; <a href="http://www.legislation.gov.uk/ukpga/1998/29/schedule/4">http://www.legislation.gov.uk/ukpga/1998/29/schedule/4</a>).</p>
<p>The Regulation is also published against the growing issue of Cloud-based computing platforms, where service providers experience host client data globally is and it is not always clear that all of the information is permanently deleted when the client goes elsewhere.</p>
<p>So how do organisations ensure compliance with data protection against a backdrop of technological change, increased costs and a more competitive market place?</p>
<p>Well, I am sorry if it is a disappointment to you, but you do not all need to go out and get a ‘Blakey’ (anyway, there are not enough of us to go around!)</p>
<ul>
<li>Firstly, identify accountable business ‘experts’ to be responsible for your business data, including compliance with statutory requirements like data protection (they could also be ‘on point’ for information security and business continuity in their areas, but I digress);</li>
<li>Secondly, talk to and coordinate these business representatives to find out where your organisation’s personal data is (a small governance team would be ideal).  It is amazing where it ends up (e.g. cookies) and you can’t look after it until you know where it is;</li>
<li>Next, identify the legal, regulatory, contractual, best practice and business requirements for your business information; and</li>
<li>Finally conduct regular assessments of your compliance against these requirements so you can monitor progress (or otherwise).</li>
</ul>
<p>Advent IM Consultant &#8211; Mark Goddard</p>
<br /> Tagged: <a href='http://adventim.wordpress.com/tag/cookies/'>cookies</a>, <a href='http://adventim.wordpress.com/tag/data-loss/'>data loss</a>, <a href='http://adventim.wordpress.com/tag/data-protection/'>data protection</a>, <a href='http://adventim.wordpress.com/tag/data-protection-act/'>data protection act</a>, <a href='http://adventim.wordpress.com/tag/data-protection-directive/'>data protection directive</a>, <a href='http://adventim.wordpress.com/tag/european-commission/'>european commission</a>, <a href='http://adventim.wordpress.com/tag/information-security/'>information security</a>, <a href='http://adventim.wordpress.com/tag/internet/'>internet</a>, <a href='http://adventim.wordpress.com/tag/justice-commissioner/'>justice commissioner</a>, <a href='http://adventim.wordpress.com/tag/personal-data/'>personal data</a>, <a href='http://adventim.wordpress.com/tag/personal-security/'>personal security</a>, <a href='http://adventim.wordpress.com/tag/right-to-be-forgotten/'>right to be forgotten</a>, <a href='http://adventim.wordpress.com/tag/security/'>Security</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/adventim.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/adventim.wordpress.com/143/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/adventim.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/adventim.wordpress.com/143/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/adventim.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/adventim.wordpress.com/143/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/adventim.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/adventim.wordpress.com/143/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/adventim.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/adventim.wordpress.com/143/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/adventim.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/adventim.wordpress.com/143/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/adventim.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/adventim.wordpress.com/143/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=adventim.wordpress.com&amp;blog=27864670&amp;post=143&amp;subd=adventim&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://adventim.wordpress.com/2012/01/23/the-new-eu-general-data-protection-regulation-and-the-right-to-be-forgotten/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b0fd815674d40d9f2671f56918cec3dc?s=96&#38;d=wavatar&#38;r=G" medium="image">
			<media:title type="html">adventim</media:title>
		</media:content>

		<media:content url="http://adventim.files.wordpress.com/2012/01/mp9003826491.jpg?w=214" medium="image">
			<media:title type="html">MP900382649[1]</media:title>
		</media:content>
	</item>
		<item>
		<title>The safest place to keep your data&#8230;&#8221;Cloud&#8221; or &#8220;Train&#8221;..?</title>
		<link>http://adventim.wordpress.com/2012/01/19/the-safest-place-to-keep-your-data-cloud-or-train/</link>
		<comments>http://adventim.wordpress.com/2012/01/19/the-safest-place-to-keep-your-data-cloud-or-train/#comments</comments>
		<pubDate>Thu, 19 Jan 2012 11:42:47 +0000</pubDate>
		<dc:creator>Ellie Hurst</dc:creator>
				<category><![CDATA[consultancy]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[ISO27001]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security consultants]]></category>
		<category><![CDATA[security management]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[USB]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[cloud provider]]></category>
		<category><![CDATA[Cloud top tips]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data sanitisation]]></category>
		<category><![CDATA[safe data storage]]></category>
		<category><![CDATA[secure data]]></category>
		<category><![CDATA[secure data storage]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://adventim.wordpress.com/?p=131</guid>
		<description><![CDATA[How will &#8220;Cloud&#8221; compete with &#8220;Train&#8221;? We all know that the Cloud is the place to store all your data right? We used to think that &#8220;Train&#8221; was the best place to store our data and some traditionalists, such as &#8230; <a href="http://adventim.wordpress.com/2012/01/19/the-safest-place-to-keep-your-data-cloud-or-train/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=adventim.wordpress.com&amp;blog=27864670&amp;post=131&amp;subd=adventim&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>How will &#8220;Cloud&#8221; compete with &#8220;Train&#8221;?</strong></p>
<p>We all know that the <strong>Cloud</strong> is the place to store all your data right? We used to think that<strong> &#8220;Train&#8221;</strong> was the best place to store our data and some traditionalists, such as the person who left the Olympic Security plans on <a href="http://tgr.ph/wKmgQZ" target="_blank">&#8220;<strong>Train&#8221;</strong></a> clearly think it’s still the best data storage option. Of course, there is also<strong> <a href="http://bit.ly/xUTYMU" target="_blank">&#8220;Taxi&#8221;</a> </strong> &#8211; still popular but you can only get your data to go on a maximum 20 mile round trip, so it&#8217;s a bit limited really. Not as limited as<strong> <a href="http://bit.ly/yB91e5" target="_blank">&#8220;Pub&#8221;</a></strong> though this is a data storage concept that is still hanging around after all these years.</p>
<div class="mceTemp" style="text-align:left;">
<dl class="wp-caption alignleft">
<dt class="wp-caption-dt"><a href="http://adventim.files.wordpress.com/2012/01/mp900387512.jpg"><img class="size-thumbnail wp-image-133" title="MP900387512" src="http://adventim.files.wordpress.com/2012/01/mp900387512.jpg?w=107&#038;h=150" alt="" width="107" height="150" /></a></dt>
<dd class="wp-caption-dd">&#8220;I found this on the back seat of a Taxi.&#8221;</dd>
</dl>
</div>
<p>OK,  joking aside, are businesses and organisations going into the Cloud fully armed with information? If they aren&#8217;t, then they may as well stick with Train and Taxi. We have put together a guide to help inform, dispel some myths &#8211; as we see them, and give some real clarity and guidance. With sincere thanks to our gifted and expert Consultants.</p>
<p>SC Magazine published an interesting piece just before Christmas on Cloud computing (<a href="http://www.scmagazineuk.com/loglogic-the-public-cloud-will-be-breached-next-year/article/219907/"><span style="text-decoration:underline;">http://www.scmagazineuk.com/loglogic-the-public-Cloud-will-be-breached-next-year/article/219907/</span></a>).</p>
<p>Amongst the issues identified in the article were:</p>
<ul>
<li>That Cloud-based infrastructure has a distinctive threat profile (right);</li>
<li>That the answer to Cloud security is through compliance and standards (to a degree); and</li>
<li>That Cloud service providers should be regulated by an independent body (we don’t agree).</li>
</ul>
<p>These three assertions are worth some further digging and clarification.</p>
<p>The distinguishing threats relating to Cloud services have been well publicised but here is a quick run-down of our top Cloud-based information security threats:</p>
<p>I.            System Complexity – Public Cloud services offered by providers have a serious underlying complication—subscribing organisations typically share components and resources with other subscribers that are unknown to them. Threats to network and computing infrastructures continue to increase each year and have become more sophisticated. Having to share an infrastructure with unknown outside parties can be a major drawback for some applications and requires a high level of assurance for the strength of the security mechanisms used for logical separation.</p>
<p>II.            Shared Multi-tenancy –<strong> </strong>While not unique to Cloud computing, logical separation is a non-trivial problem that is exacerbated by the scale of Cloud computing.  An attacker could also pose as a subscriber to exploit vulnerabilities from within the Cloud environment to gain unauthorized access.</p>
<p>III.            The Internet – Applications and data that were previously accessed from the confines an organisation’s network, but moved to the Cloud, must now face increased risk from network threats that were previously defended against at the perimeter of the organisation’s network and from new threats that target the exposed end-points.</p>
<p>IV.            Compliance – When information crosses borders the governing legal, privacy, and regulatory regimes can be ambiguous and raise a variety of concerns. Consequently, constraints on the trans-border flow of sensitive data, as well as the requirements on the protection afforded the data, have become the subject of national and regional privacy and security laws and regulations. Among the concerns to be addressed are whether the laws in the jurisdiction where the data was collected permit the flow, whether those laws continue to apply to the data post transfer, and whether the laws at the destination present additional risks or benefits.</p>
<p>V.            Loss of control – Remote administrative access as the single means of managing the assets of the organisation held in the Cloud also increases risk, compared with a traditional data centre, where administrative access to platforms can be restricted to direct or internal connections</p>
<p>VI.            Mechanism cracking – With Cloud computing, a task that would take five days to run on a single computer takes only 20 minutes to accomplish on a cluster of 400 virtual machines. Because cryptography is used widely in authentication, data confidentiality and integrity, and other security mechanisms, these mechanisms become, in effect, less effective with the availability of cryptographic key cracking Cloud services. Granted this isn’t just a Cloud based threat – traditional types of system are also possible targets.</p>
<p>VII.            Insider Access / Threat –<strong> </strong>Data processed or stored outside the confines of an organisation, its firewall, and other security controls bring with it an inherent level of risk. The insider security threat is a well-known issue for most organisations and, despite the name, applies as well to outsourced Cloud services. With the Cloud, insider threats go beyond those posed by current or former employees to include contractors, organisational affiliates, and other parties that have received access to an organisation’s networks, systems, and data to carry out or facilitate operations. Incidents may involve various types of fraud, sabotage of information resources, and theft of confidential information. Incidents may also be caused unintentionally—for instance, a bank employee sending out sensitive customer information to the wrong Google mail account.</p>
<p>VIII.            Data Ownership -<strong> </strong>The organisation’s ownership rights over the data must be firmly established in the service contract to enable a basis for trust. The continuing controversy over privacy and data ownership rights for social networking users illustrates the impact that ambiguous terms can have on the parties involved. Ideally, the contract should state clearly that the organisation retains ownership over all its data; that the Cloud provider acquires no rights or licenses through the agreement to use the data for its own purposes, including intellectual property rights or licenses; and that the Cloud provider does not acquire and may not claim any ownership interest in the data.</p>
<p>IX.            Data Sanitisation -<strong> </strong>The data sanitisation practices that a Cloud provider implements have obvious implications for security. Sanitisation is the removal of sensitive data from a storage device, including servers, in various situations, such as when a storage device is removed from service or moved elsewhere to be stored. Data sanitisation also applies to backup copies made for recovery and restoration of service, and also residual data remaining upon termination of service. In a Cloud computing environment, data from one subscriber is physically combined with the data of other subscribers, which can complicate matters. For instance, many examples exist of researchers obtaining used drives from online auctions and other sources and recovering large amounts of sensitive information from them.</p>
<p>So what is the answer to these Cloud-based security conundrums?  Compliance with information security standards as Mr Churchward* suggests.  Well, in part is the rather cryptic answer to that one, I think.  There are some very good information security standards and control sets out there (COBIT, ISO/IEC27001:2005 and the UK government’s HMG Information Assurance Standards being just some examples).  However, every experienced information security professional will know or have known at least one organisation for which the having the standard is the means as well as the ends and that frustratingly they maintain a visage of information security competency when the assessor arrives for their next audit but that in-between audits security is just a byword for inconvenience.  So if</p>
<p>The sight of a Cloud services provider brandishing a given security certification is not sufficient assurance, what is?  We suggest these three steps to Cloud contractual heaven:</p>
<ol>
<li>The right to audit.  And then do it.  And don’t pick a service provider who is based a 36 hour flight away unless you – and your management – are prepared to send someone to their data centre to do the audit!</li>
<li>Talk to prospective service providers about the threats above.  If they are coy, defensive, or babble techno-speak make sure you are content to receive the same level of effrontery when you have a query, business interruption scenario or concern about your data.</li>
<li>Does the would-be service provider sub-contract out its storage, security, administration or anything else?  The very flexibility of Cloud-based services means your data or responsibility of your data can be syndicated out by your nominal provider in the blink of an eye.  You wouldn’t sub-contract out your office space so readily would you…?</li>
</ol>
<p>On the point of standards, it is probably worth clarifying a couple of points for the unwary arising from the SC Magazine article:</p>
<ul>
<li>ISO/IEC27001:2005 is the international (not just UK) standard for Information Security Management Systems.  ISO/IEC27002:2005 is the accompanying guidance for the implementation of the security controls listed in Annex A of ISO/IEC27001:2005;</li>
<li>Neither ISO/IEC27001:2005 or ISO/IEC27002:2005 mention Cloud computing however most of the 133 controls are or could be applicable to a Cloud computing environment.  The explicit inclusion of reference to Cloud services is amongst proposals for changes to the Standard in the future; and</li>
<li>There are already two approved international standards for Cloud-based technology relevant to security (<a href="http://www.iso.org/iso/iso_catalogue/catalogue_tc/catalogue_detail.htm?csnumber=53458"><span style="text-decoration:underline;">http://www.iso.org/iso/iso_catalogue/catalogue_tc/catalogue_detail.htm?csnumber=53458</span></a> and <a href="http://www.iso.org/iso/iso_catalogue/catalogue_tc/catalogue_detail.htm?csnumber=59388"><span style="text-decoration:underline;">http://www.iso.org/iso/iso_catalogue/catalogue_tc/catalogue_detail.htm?csnumber=59388</span></a>), though they are definitely for the propeller-heads amongst you!!</li>
</ul>
<p>And what of Mr Churchward’s* assertion that “we need something externally policed, not self-certified, and a recognised industry body”?  Well, I am not sure we agree insomuch as regulatory, and enforcement bodies already exist for all sorts of activities relating to information security, Cloud-based or otherwise, and it seems an unnecessary burden to introduce another.  Bodies with an interest in maintaining and improving Cloud security include statutory regulators such as the Information Commissioner’s Office (ICO), and indeed the Irish Data Protection Commissioner is currently working with one well-known international Cloud operation (Facebook) to improve their compliance arrangements (<a href="http://dataprotection.ie/viewdoc.asp?DocID=1175&amp;m=f"><span style="text-decoration:underline;">http://dataprotection.ie/viewdoc.asp?DocID=1175&amp;m=f</span></a>).</p>
<p>So to wrap up, we recommend that organisations considering entering in to agreements with Cloud service providers:</p>
<p>Conduct appropriate due diligence before doing so, including a full risk assessment, considering the risks laid out above;</p>
<ol>
<li>Make sure that they have the right contractual security clauses in place falling out from the risk assessment (e.g. if data sanitisation is a major issue for your organisation, make sure it is robustly referenced in the contract); and</li>
<li>Ensure that your external service providers, including Cloud operators, are part of your audit and assurance programme (this programme should also be risk based – looking at the higher priority areas more frequently and in more depth).</li>
</ol>
<p><a href="http://www.advent-IM.co.uk" target="_blank">www.advent-IM.co.uk</a></p>
<p>*LogLogic CEO Guy Churchward – quoted in SC Magazine article</p>
<br /> Tagged: <a href='http://adventim.wordpress.com/tag/cloud/'>cloud</a>, <a href='http://adventim.wordpress.com/tag/cloud-computing/'>cloud computing</a>, <a href='http://adventim.wordpress.com/tag/cloud-provider/'>cloud provider</a>, <a href='http://adventim.wordpress.com/tag/cloud-top-tips/'>Cloud top tips</a>, <a href='http://adventim.wordpress.com/tag/data-protection/'>data protection</a>, <a href='http://adventim.wordpress.com/tag/data-sanitisation/'>data sanitisation</a>, <a href='http://adventim.wordpress.com/tag/information-security/'>information security</a>, <a href='http://adventim.wordpress.com/tag/risk-assessment/'>risk assessment</a>, <a href='http://adventim.wordpress.com/tag/safe-data-storage/'>safe data storage</a>, <a href='http://adventim.wordpress.com/tag/secure-data/'>secure data</a>, <a href='http://adventim.wordpress.com/tag/secure-data-storage/'>secure data storage</a>, <a href='http://adventim.wordpress.com/tag/security/'>Security</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/adventim.wordpress.com/131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/adventim.wordpress.com/131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/adventim.wordpress.com/131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/adventim.wordpress.com/131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/adventim.wordpress.com/131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/adventim.wordpress.com/131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/adventim.wordpress.com/131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/adventim.wordpress.com/131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/adventim.wordpress.com/131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/adventim.wordpress.com/131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/adventim.wordpress.com/131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/adventim.wordpress.com/131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/adventim.wordpress.com/131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/adventim.wordpress.com/131/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=adventim.wordpress.com&amp;blog=27864670&amp;post=131&amp;subd=adventim&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://adventim.wordpress.com/2012/01/19/the-safest-place-to-keep-your-data-cloud-or-train/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b0fd815674d40d9f2671f56918cec3dc?s=96&#38;d=wavatar&#38;r=G" medium="image">
			<media:title type="html">adventim</media:title>
		</media:content>

		<media:content url="http://adventim.files.wordpress.com/2012/01/mp900387512.jpg?w=107" medium="image">
			<media:title type="html">MP900387512</media:title>
		</media:content>
	</item>
		<item>
		<title>Integrated Security &#8211; Mike Gillespie</title>
		<link>http://adventim.wordpress.com/2012/01/16/integrated-security-mike-gillespie/</link>
		<comments>http://adventim.wordpress.com/2012/01/16/integrated-security-mike-gillespie/#comments</comments>
		<pubDate>Mon, 16 Jan 2012 14:29:12 +0000</pubDate>
		<dc:creator>Ellie Hurst</dc:creator>
				<category><![CDATA[consultancy]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[integrated systems]]></category>
		<category><![CDATA[ISO27001]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[physical security]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security consultants]]></category>
		<category><![CDATA[security management]]></category>
		<category><![CDATA[training]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[USB]]></category>
		<category><![CDATA[Advent]]></category>
		<category><![CDATA[BMS]]></category>
		<category><![CDATA[Building Management]]></category>
		<category><![CDATA[building management systems]]></category>
		<category><![CDATA[business continuity]]></category>
		<category><![CDATA[Command centre V7]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[FM]]></category>
		<category><![CDATA[Gallagher]]></category>
		<category><![CDATA[Integrated Security]]></category>
		<category><![CDATA[Integrated systems]]></category>
		<category><![CDATA[MySecurityManager]]></category>
		<category><![CDATA[product launch]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[security integration]]></category>

		<guid isPermaLink="false">http://adventim.wordpress.com/?p=122</guid>
		<description><![CDATA[As promised the follow up to Mike&#8217;s speaking engagements and a chance to watch and listen to his expert comment and opinion on system integration. With thanks to Gallagher for the invitation to speak at their Command Centre V7 launch &#8230; <a href="http://adventim.wordpress.com/2012/01/16/integrated-security-mike-gillespie/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=adventim.wordpress.com&amp;blog=27864670&amp;post=122&amp;subd=adventim&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='584' height='359' src='http://www.youtube.com/embed/EcGHF3IXgK0?version=3&amp;rel=1&amp;fs=1&amp;showsearch=0&amp;showinfo=1&amp;iv_load_policy=1&amp;wmode=transparent' frameborder='0'></iframe></span>
<p>As promised the follow up to Mike&#8217;s speaking engagements and a chance to watch and listen to his expert comment and opinion on system integration.</p>
<p>With thanks to Gallagher for the invitation to speak at their Command Centre V7 launch event.</p>
<p>Ellie</p>
<p><a title="Advent IM Ltd website" href="http://www.advent-im.co.uk" target="_blank">www.advent-im.co.uk</a></p>
<p>&nbsp;</p>
<br /> Tagged: <a href='http://adventim.wordpress.com/tag/advent/'>Advent</a>, <a href='http://adventim.wordpress.com/tag/bms/'>BMS</a>, <a href='http://adventim.wordpress.com/tag/building-management/'>Building Management</a>, <a href='http://adventim.wordpress.com/tag/building-management-systems/'>building management systems</a>, <a href='http://adventim.wordpress.com/tag/business-continuity/'>business continuity</a>, <a href='http://adventim.wordpress.com/tag/command-centre-v7/'>Command centre V7</a>, <a href='http://adventim.wordpress.com/tag/data-breach/'>data breach</a>, <a href='http://adventim.wordpress.com/tag/fm/'>FM</a>, <a href='http://adventim.wordpress.com/tag/gallagher/'>Gallagher</a>, <a href='http://adventim.wordpress.com/tag/information-security/'>information security</a>, <a href='http://adventim.wordpress.com/tag/integrated-security/'>Integrated Security</a>, <a href='http://adventim.wordpress.com/tag/integrated-systems-2/'>Integrated systems</a>, <a href='http://adventim.wordpress.com/tag/mysecuritymanager/'>MySecurityManager</a>, <a href='http://adventim.wordpress.com/tag/physical-security/'>physical security</a>, <a href='http://adventim.wordpress.com/tag/product-launch/'>product launch</a>, <a href='http://adventim.wordpress.com/tag/security/'>Security</a>, <a href='http://adventim.wordpress.com/tag/security-breach/'>security breach</a>, <a href='http://adventim.wordpress.com/tag/security-integration/'>security integration</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/adventim.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/adventim.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/adventim.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/adventim.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/adventim.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/adventim.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/adventim.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/adventim.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/adventim.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/adventim.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/adventim.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/adventim.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/adventim.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/adventim.wordpress.com/122/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=adventim.wordpress.com&amp;blog=27864670&amp;post=122&amp;subd=adventim&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://adventim.wordpress.com/2012/01/16/integrated-security-mike-gillespie/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b0fd815674d40d9f2671f56918cec3dc?s=96&#38;d=wavatar&#38;r=G" medium="image">
			<media:title type="html">adventim</media:title>
		</media:content>
	</item>
		<item>
		<title>Security System Integration &#8211; follow up on Mike&#8217;s speaking dates</title>
		<link>http://adventim.wordpress.com/2012/01/13/security-system-integration-follow-up-on-mikes-speaking-dates/</link>
		<comments>http://adventim.wordpress.com/2012/01/13/security-system-integration-follow-up-on-mikes-speaking-dates/#comments</comments>
		<pubDate>Fri, 13 Jan 2012 15:23:15 +0000</pubDate>
		<dc:creator>Ellie Hurst</dc:creator>
				<category><![CDATA[consultancy]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[integrated systems]]></category>
		<category><![CDATA[ISO27001]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[physical security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security consultants]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[BMS]]></category>
		<category><![CDATA[Building Management]]></category>
		<category><![CDATA[Facility Management]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[security integration]]></category>
		<category><![CDATA[systems]]></category>

		<guid isPermaLink="false">http://adventim.wordpress.com/?p=85</guid>
		<description><![CDATA[I am in the process of editing the video of Mike&#8217;s speaking engagements. This should be up and running next week at some point and will feature on the website and on our YouTube channel. I will post details here. &#8230; <a href="http://adventim.wordpress.com/2012/01/13/security-system-integration-follow-up-on-mikes-speaking-dates/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=adventim.wordpress.com&amp;blog=27864670&amp;post=85&amp;subd=adventim&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I am in the process of editing the video of Mike&#8217;s speaking engagements. This should be up and running next week at some point and will feature on the website and on our YouTube channel. I will post details here.</p>
<p>We know that integrating security systems works to both save cost and improve efficiency. We also know that integrating security and Building Management systems can take this to a whole new level. Watch this space.</p>
<p><a href="http://adventim.files.wordpress.com/2012/01/mm900040991.gif"><img class="alignleft size-thumbnail wp-image-120" title="MM900040991" src="http://adventim.files.wordpress.com/2012/01/mm900040991.gif?w=150&#038;h=80" alt="" width="150" height="80" /></a></p>
<br /> Tagged: <a href='http://adventim.wordpress.com/tag/bms/'>BMS</a>, <a href='http://adventim.wordpress.com/tag/building-management/'>Building Management</a>, <a href='http://adventim.wordpress.com/tag/facility-management/'>Facility Management</a>, <a href='http://adventim.wordpress.com/tag/security/'>Security</a>, <a href='http://adventim.wordpress.com/tag/security-integration/'>security integration</a>, <a href='http://adventim.wordpress.com/tag/systems/'>systems</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/adventim.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/adventim.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/adventim.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/adventim.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/adventim.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/adventim.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/adventim.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/adventim.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/adventim.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/adventim.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/adventim.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/adventim.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/adventim.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/adventim.wordpress.com/85/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=adventim.wordpress.com&amp;blog=27864670&amp;post=85&amp;subd=adventim&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://adventim.wordpress.com/2012/01/13/security-system-integration-follow-up-on-mikes-speaking-dates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b0fd815674d40d9f2671f56918cec3dc?s=96&#38;d=wavatar&#38;r=G" medium="image">
			<media:title type="html">adventim</media:title>
		</media:content>

		<media:content url="http://adventim.files.wordpress.com/2012/01/mm900040991.gif?w=150" medium="image">
			<media:title type="html">MM900040991</media:title>
		</media:content>
	</item>
		<item>
		<title>Knock Knowe &#8211; astonishing house and landscape design at Earlston</title>
		<link>http://adventim.wordpress.com/2012/01/11/knock-knowe-astonishing-house-and-landscape-design-at-earlston/</link>
		<comments>http://adventim.wordpress.com/2012/01/11/knock-knowe-astonishing-house-and-landscape-design-at-earlston/#comments</comments>
		<pubDate>Wed, 11 Jan 2012 11:57:38 +0000</pubDate>
		<dc:creator>Ellie Hurst</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://adventim.wordpress.com/?p=117</guid>
		<description><![CDATA[Knock Knowe &#8211; astonishing house and landscape design at Earlston.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=adventim.wordpress.com&amp;blog=27864670&amp;post=117&amp;subd=adventim&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://wp.me/p1U5Gw-2p">Knock Knowe &#8211; astonishing house and landscape design at Earlston</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/adventim.wordpress.com/117/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/adventim.wordpress.com/117/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/adventim.wordpress.com/117/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/adventim.wordpress.com/117/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/adventim.wordpress.com/117/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/adventim.wordpress.com/117/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/adventim.wordpress.com/117/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/adventim.wordpress.com/117/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/adventim.wordpress.com/117/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/adventim.wordpress.com/117/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/adventim.wordpress.com/117/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/adventim.wordpress.com/117/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/adventim.wordpress.com/117/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/adventim.wordpress.com/117/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=adventim.wordpress.com&amp;blog=27864670&amp;post=117&amp;subd=adventim&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://adventim.wordpress.com/2012/01/11/knock-knowe-astonishing-house-and-landscape-design-at-earlston/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b0fd815674d40d9f2671f56918cec3dc?s=96&#38;d=wavatar&#38;r=G" medium="image">
			<media:title type="html">adventim</media:title>
		</media:content>
	</item>
		<item>
		<title>Advent IM launches MySecurityManager</title>
		<link>http://adventim.wordpress.com/2011/12/08/advent-im-launches-mysecuritymanager/</link>
		<comments>http://adventim.wordpress.com/2011/12/08/advent-im-launches-mysecuritymanager/#comments</comments>
		<pubDate>Thu, 08 Dec 2011 16:42:20 +0000</pubDate>
		<dc:creator>Ellie Hurst</dc:creator>
				<category><![CDATA[consultancy]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[ISO27001]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security consultants]]></category>
		<category><![CDATA[security management]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[MySecurityManager]]></category>
		<category><![CDATA[outsource]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://adventim.wordpress.com/?p=100</guid>
		<description><![CDATA[Advent IM Ltd – the UKs leading independent, holistic security consultancy, today announced the launch of their new outsourced security service; MySecurityManager. Many businesses and organisations understand the need for robust security management. Given the amount of column inches, both &#8230; <a href="http://adventim.wordpress.com/2011/12/08/advent-im-launches-mysecuritymanager/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=adventim.wordpress.com&amp;blog=27864670&amp;post=100&amp;subd=adventim&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:left;" align="right"><a href="http://adventim.files.wordpress.com/2011/12/mysecuritymanager.jpg"><img class="alignright size-medium wp-image-101" title="MySecurityManager" src="http://adventim.files.wordpress.com/2011/12/mysecuritymanager.jpg?w=300&#038;h=75" alt="" width="300" height="75" /></a><em><strong>Advent IM Ltd – the UKs leading independent, holistic security consultancy, today announced the launch of their new outsourced security service; MySecurityManager.</strong></em></p>
<p>Many businesses and organisations understand the need for robust security management. Given the amount of column inches, both in print and online, devoted to data security breaches alone; it isn’t difficult to appreciate the importance of good, well managed policy.  We know that part of the solution can come from the use of technology, but technology only works at its optimum level when it is part of a solid strategy, which in turn is part of an organisation’s culture.</p>
<p>The cost of creating or maintaining a full time <strong>Security Manager</strong> role within an organisation can be challenging. Often the expertise required to build, implement and educate-in good policy is not available to many SME’s.   But<strong> risk</strong> appetite is not generally commensurate with budget so what is an SME to do?</p>
<p><strong>Advent IM</strong> Ltd has today introduced packaged solutions to suit most organisational <strong>security management</strong> needs. This selection of outsourced security packages, are a mixture of onsite presence, project management and email support. Because they are scalable and flexible, the service you buy will be appropriate to your organisation’s needs, therefore offering excellent value for a business where budget is not currently available to resource a full time Security Manager. Being a fixed price means that there are no nasty surprises or hidden costs.</p>
<p>The benefits of using such a service include; a pool of experts with many years’ experience &#8211; this level of expertise may normally be beyond budget; no need to recruit or train; no National Insurance; no sick pay; no holiday pay and many other important cost savings.</p>
<p><a href="http://adventim.files.wordpress.com/2011/12/mike-gillespie_headshot.jpg"><img class="alignleft size-medium wp-image-102" title="Mike Gillespie_headshot" src="http://adventim.files.wordpress.com/2011/12/mike-gillespie_headshot.jpg?w=300&#038;h=200" alt="" width="300" height="200" /></a> Advent IM’s Managing Director,Mike Gillespie said,</p>
<blockquote><p>            “Now every business can benefit from the huge amount of expertise that  our consultancy clients have long had access to and benefitted from.  Offering flexibility mixed with capability, <strong>My</strong><strong>Security</strong><strong>Manager</strong></p>
<p>is a must for any organisation that seeks an efficient and effective means  of closing that security knowledge gap”</p></blockquote>
<p>Details of the service can be found on the Advent IM website <a href="http://www.advent-im.co.uk/mysecuritymanager.aspx">http://www.advent-im.co.uk/mysecuritymanager.aspx</a> or by contacting the team.</p>
<br /> Tagged: <a href='http://adventim.wordpress.com/tag/data-protection/'>data protection</a>, <a href='http://adventim.wordpress.com/tag/information-security/'>information security</a>, <a href='http://adventim.wordpress.com/tag/mysecuritymanager/'>MySecurityManager</a>, <a href='http://adventim.wordpress.com/tag/outsource/'>outsource</a>, <a href='http://adventim.wordpress.com/tag/security/'>Security</a>, <a href='http://adventim.wordpress.com/tag/security-management/'>security management</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/adventim.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/adventim.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/adventim.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/adventim.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/adventim.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/adventim.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/adventim.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/adventim.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/adventim.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/adventim.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/adventim.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/adventim.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/adventim.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/adventim.wordpress.com/100/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=adventim.wordpress.com&amp;blog=27864670&amp;post=100&amp;subd=adventim&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://adventim.wordpress.com/2011/12/08/advent-im-launches-mysecuritymanager/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b0fd815674d40d9f2671f56918cec3dc?s=96&#38;d=wavatar&#38;r=G" medium="image">
			<media:title type="html">adventim</media:title>
		</media:content>

		<media:content url="http://adventim.files.wordpress.com/2011/12/mysecuritymanager.jpg?w=300" medium="image">
			<media:title type="html">MySecurityManager</media:title>
		</media:content>

		<media:content url="http://adventim.files.wordpress.com/2011/12/mike-gillespie_headshot.jpg?w=300" medium="image">
			<media:title type="html">Mike Gillespie_headshot</media:title>
		</media:content>
	</item>
		<item>
		<title>USB &#8211; Ubiquitous Security Breach?</title>
		<link>http://adventim.wordpress.com/2011/11/30/usb-ubiquitous-security-breach/</link>
		<comments>http://adventim.wordpress.com/2011/11/30/usb-ubiquitous-security-breach/#comments</comments>
		<pubDate>Wed, 30 Nov 2011 16:21:05 +0000</pubDate>
		<dc:creator>Ellie Hurst</dc:creator>
				<category><![CDATA[consultancy]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[ISO27001]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security consultants]]></category>
		<category><![CDATA[training]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[USB]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[kingston]]></category>
		<category><![CDATA[ponemon]]></category>
		<category><![CDATA[security breach]]></category>

		<guid isPermaLink="false">http://adventim.wordpress.com/?p=92</guid>
		<description><![CDATA[&#8220;Organisations do not understand the risks they face because of employee negligence but are not taking the necessary steps to secure USB drives.&#8221; This forms part of the introduction to the findings of the UK part of the survey by &#8230; <a href="http://adventim.wordpress.com/2011/11/30/usb-ubiquitous-security-breach/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=adventim.wordpress.com&amp;blog=27864670&amp;post=92&amp;subd=adventim&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div id="attachment_94" class="wp-caption alignleft" style="width: 295px"><a href="http://adventim.files.wordpress.com/2011/11/data-stick.jpg"><img class="size-full wp-image-94" title="data stick" src="http://adventim.files.wordpress.com/2011/11/data-stick.jpg?w=584" alt=""   /></a><p class="wp-caption-text">The Ubiquitous Data Breach or as we know it - the USB</p></div>
<p><em>&#8220;Organisations do not understand the risks they face because of employee negligence but are not taking the necessary steps to secure USB drives.&#8221;</em></p>
<p>This forms part of the introduction to the findings of the UK part of the survey by the Ponemon Institute on behalf of Kingston Technologies.</p>
<p>The results of the survey show the level of UK organisations negligently inactive when it comes to unauthorised use of USB devices. With a shocking 73% of <a href="http://media.kingston.com/pdfs/Ponemon/Ponemon_research_country_report_UK_1111.pdf" target="_blank">those surveyed </a>reporting within their organisations, employees using USB&#8217;s without obtaining permission and 72% said that data breaches had been caused by sensitive or confidential data on USBs being lost.</p>
<p>These results come as no surprise to many of us, the amount of stories we all read on a weekly basis about data sticks being lost, laptops being lost, or discs being left in taxis etc.is large.</p>
<p>The surprising thing in many ways is that despite these incidents, organisations are still  uncontrolled USBs to become prevalent &#8211; picked up at trade fairs and expos, the survey said 55% &#8211; I suspect this is actually much higher. And so business is relying on the common sense and integrity of its employees to use the devices sensibly. In fact, the sensible thing to do is have a policy, implement and educate in to your staff.</p>
<p>The survey shows a disappointing 32% has policy and controls in place to stop or limit employees misuse of USBs in the workplace. and 29% the technology to prevent or detect a virus or malware on USB drives before use by employees. Some organisations, as we know will create policy and then not educate it in to their people, lip service to a policy never works, hence the 73% of respondents having lost sensitive data.</p>
<p>We have said it before and will say it again, assess the risks (ask for help if you need to), design the policy and procedures (ask for help if you need to) implement and check it works, then educate it in.</p>
<p>Ellie</p>
<p><a title="Advent IM Website" href="http://www.advent-im.co.uk" target="_blank">www.advent-im.co.uk</a></p>
<p>From the report:</p>
<blockquote>
<p align="LEFT">The following are 10 USB security practices that many organizations in this study do not</p>
<p align="LEFT">practice:</p>
<p align="LEFT">1. Providing employees with approved, quality USB drives for use in the workplace.</p>
<p align="LEFT">2. Creating policies and training programs that define acceptable and unacceptable uses of</p>
<p align="LEFT">USB drives.</p>
<p align="LEFT">3. Making sure employees who have access to sensitive and confidential data only use secure</p>
<p align="LEFT">USB drives.</p>
<p align="LEFT">4. Determining USB drive reliability and integrity before purchase by confirming compliance with</p>
<p align="LEFT">leading security standards and ensuring that there is no malicious code on these tools.</p>
<p align="LEFT">5. Deploying encryption for data stored on the USB drive.</p>
<p align="LEFT">6. Monitoring and tracking USB drives as part of asset management procedures.</p>
<p align="LEFT">7. Scanning devices for virus or malware infections.</p>
<p align="LEFT">8. Using passwords or locks.</p>
<p align="LEFT">9. Encrypting sensitive data on USB drives.</p>
<p>10. Deploying procedures to recover lost USB drives.</p></blockquote>
<br /> Tagged: <a href='http://adventim.wordpress.com/tag/data-breach/'>data breach</a>, <a href='http://adventim.wordpress.com/tag/data-loss/'>data loss</a>, <a href='http://adventim.wordpress.com/tag/encryption/'>encryption</a>, <a href='http://adventim.wordpress.com/tag/kingston/'>kingston</a>, <a href='http://adventim.wordpress.com/tag/ponemon/'>ponemon</a>, <a href='http://adventim.wordpress.com/tag/risk-assessment/'>risk assessment</a>, <a href='http://adventim.wordpress.com/tag/security-breach/'>security breach</a>, <a href='http://adventim.wordpress.com/tag/usb/'>USB</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/adventim.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/adventim.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/adventim.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/adventim.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/adventim.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/adventim.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/adventim.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/adventim.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/adventim.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/adventim.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/adventim.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/adventim.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/adventim.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/adventim.wordpress.com/92/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=adventim.wordpress.com&amp;blog=27864670&amp;post=92&amp;subd=adventim&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://adventim.wordpress.com/2011/11/30/usb-ubiquitous-security-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b0fd815674d40d9f2671f56918cec3dc?s=96&#38;d=wavatar&#38;r=G" medium="image">
			<media:title type="html">adventim</media:title>
		</media:content>

		<media:content url="http://adventim.files.wordpress.com/2011/11/data-stick.jpg" medium="image">
			<media:title type="html">data stick</media:title>
		</media:content>
	</item>
		<item>
		<title>New Information Security Training dates for 2012</title>
		<link>http://adventim.wordpress.com/2011/11/17/new-information-security-training-dates-for-2012/</link>
		<comments>http://adventim.wordpress.com/2011/11/17/new-information-security-training-dates-for-2012/#comments</comments>
		<pubDate>Thu, 17 Nov 2011 15:57:57 +0000</pubDate>
		<dc:creator>Ellie Hurst</dc:creator>
				<category><![CDATA[consultancy]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[ISO27001]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security consultants]]></category>
		<category><![CDATA[training]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://adventim.wordpress.com/?p=78</guid>
		<description><![CDATA[We have added some new dates for Information Security Training next year to the website. These are currently February but we will be adding more, so either watch the blog, follow us on Twitter or check out the training section &#8230; <a href="http://adventim.wordpress.com/2011/11/17/new-information-security-training-dates-for-2012/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=adventim.wordpress.com&amp;blog=27864670&amp;post=78&amp;subd=adventim&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div id="attachment_21" class="wp-caption alignright" style="width: 310px"><a href="http://adventim.files.wordpress.com/2011/09/istock_000015672441medium.jpg"><img class="size-medium wp-image-21" title="risk lowered - security increased" src="http://adventim.files.wordpress.com/2011/09/istock_000015672441medium.jpg?w=300&#038;h=225" alt="risk balance" width="300" height="225" /></a><p class="wp-caption-text">lowering risk increases security</p></div>
<p>We have added some new dates for Information Security Training next year to the website.</p>
<p>These are currently February but we will be adding more, so either watch the blog, follow us on Twitter or check out the training section of our website&#8230;which you can find by clicking here&#8230;.<a href="http://bit.ly/tiPani">http://bit.ly/tiPani</a> .</p>
<p>If you have an enquiry about timings for any of the other courses then feel free to give us a ring or drop us an email or Tweet.</p>
<br /> Tagged: <a href='http://adventim.wordpress.com/tag/information-security/'>information security</a>, <a href='http://adventim.wordpress.com/tag/iso27001/'>ISO27001</a>, <a href='http://adventim.wordpress.com/tag/security/'>Security</a>, <a href='http://adventim.wordpress.com/tag/training/'>training</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/adventim.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/adventim.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/adventim.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/adventim.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/adventim.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/adventim.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/adventim.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/adventim.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/adventim.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/adventim.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/adventim.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/adventim.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/adventim.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/adventim.wordpress.com/78/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=adventim.wordpress.com&amp;blog=27864670&amp;post=78&amp;subd=adventim&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://adventim.wordpress.com/2011/11/17/new-information-security-training-dates-for-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b0fd815674d40d9f2671f56918cec3dc?s=96&#38;d=wavatar&#38;r=G" medium="image">
			<media:title type="html">adventim</media:title>
		</media:content>

		<media:content url="http://adventim.files.wordpress.com/2011/09/istock_000015672441medium.jpg?w=300" medium="image">
			<media:title type="html">risk lowered - security increased</media:title>
		</media:content>
	</item>
	</channel>
</rss>
