<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: No such thing as best practices&#8230;</title>
	<atom:link href="http://spiresecurity.com/?feed=rss2&#038;p=259" rel="self" type="application/rss+xml" />
	<link>http://spiresecurity.com/?p=259</link>
	<description>Risk and Cybersecurity Analysis</description>
	<lastBuildDate>Wed, 21 Aug 2013 23:28:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Alex</title>
		<link>http://spiresecurity.com/?p=259&#038;cpage=1#comment-351</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Thu, 01 Nov 2007 14:17:11 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=259#comment-351</guid>
		<description><![CDATA[I think you could make the case that there are &quot;common&quot; practices or even &quot;lazy&quot; practices, but for the same reasons above I challange the assertion that they are &quot;best&quot; or even just &quot;good&quot;.
]]></description>
		<content:encoded><![CDATA[<p>I think you could make the case that there are &#8220;common&#8221; practices or even &#8220;lazy&#8221; practices, but for the same reasons above I challange the assertion that they are &#8220;best&#8221; or even just &#8220;good&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andy Willingham</title>
		<link>http://spiresecurity.com/?p=259&#038;cpage=1#comment-350</link>
		<dc:creator>Andy Willingham</dc:creator>
		<pubDate>Thu, 01 Nov 2007 13:27:51 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=259#comment-350</guid>
		<description><![CDATA[Pete,
The problem is that we try to tie best practices to technology and not concepts. Even saying &quot;you need a firewall&quot; is a technology best practice, in a conceptual sort of way. :) What we need to do is say &quot;You need to ensure that your internal systems are protected from the external world.&quot; How is that done? Usually a firewall but that may not be the best answer in every case. Just like PCI gets fairly specific on each step they at least leave some leeway with the &quot;compensating controls&quot; statements. Yes auditors needs something to compare you to but if you can prove that what you have works then why should you spend extra effort on something else that is considered &quot;best practice&quot;.
]]></description>
		<content:encoded><![CDATA[<p>Pete,<br />
The problem is that we try to tie best practices to technology and not concepts. Even saying &#8220;you need a firewall&#8221; is a technology best practice, in a conceptual sort of way. <img src='http://spiresecurity.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  What we need to do is say &#8220;You need to ensure that your internal systems are protected from the external world.&#8221; How is that done? Usually a firewall but that may not be the best answer in every case. Just like PCI gets fairly specific on each step they at least leave some leeway with the &#8220;compensating controls&#8221; statements. Yes auditors needs something to compare you to but if you can prove that what you have works then why should you spend extra effort on something else that is considered &#8220;best practice&#8221;.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
