<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>NetSPI Blog &#187; Industry</title>
	<atom:link href="http://www.netspi.com/blog/category/industry/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.netspi.com/blog</link>
	<description>Information security consulting</description>
	<pubDate>Mon, 26 Jul 2010 21:26:00 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Is PCI driving the development of information security within healthcare?</title>
		<link>http://www.netspi.com/blog/2010/06/14/is-pci-driving-the-development-of-information-security-within-healthcare/</link>
		<comments>http://www.netspi.com/blog/2010/06/14/is-pci-driving-the-development-of-information-security-within-healthcare/#comments</comments>
		<pubDate>Mon, 14 Jun 2010 15:45:01 +0000</pubDate>
		<dc:creator>Deke George</dc:creator>
		
		<category><![CDATA[Industry]]></category>

		<category><![CDATA[healthcare]]></category>

		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=830</guid>
		<description><![CDATA[I like to watch industries evolve in how they deal with information security. It was interesting to watch retail evolve as PCI got more organized.  The PCI Council put together the DSS with dates and penalties for breaches and non-compliance, and that drove significant change. It appears that a similar major change within healthcare is [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/06/14/is-pci-driving-the-development-of-information-security-within-healthcare/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Secure360</title>
		<link>http://www.netspi.com/blog/2010/05/21/secure360/</link>
		<comments>http://www.netspi.com/blog/2010/05/21/secure360/#comments</comments>
		<pubDate>Fri, 21 May 2010 15:00:37 +0000</pubDate>
		<dc:creator>Deke George</dc:creator>
		
		<category><![CDATA[Industry]]></category>

		<category><![CDATA[Information Security]]></category>

		<category><![CDATA[risk]]></category>

		<category><![CDATA[Secure360]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=826</guid>
		<description><![CDATA[We held the Secure360 conference in the Twin Cities last week. Presentation topics included PCI, cloud computing, and problems within the security industry. While it can get tiring discussing the industry&#8217;s problems, I like trying to understand the difficult nature of information security and enjoy the challenge of trying to overcome the obstacles related to rationally [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/05/21/secure360/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Risk, Security and Subjectivity Within PCI</title>
		<link>http://www.netspi.com/blog/2010/04/02/risk-security-and-subjectivity-within-pci/</link>
		<comments>http://www.netspi.com/blog/2010/04/02/risk-security-and-subjectivity-within-pci/#comments</comments>
		<pubDate>Fri, 02 Apr 2010 18:03:41 +0000</pubDate>
		<dc:creator>Deke George</dc:creator>
		
		<category><![CDATA[Industry]]></category>

		<category><![CDATA[PCI]]></category>

		<category><![CDATA[pci compliance]]></category>

		<category><![CDATA[pci trends]]></category>

		<category><![CDATA[PCI-DSS]]></category>

		<category><![CDATA[Ponemon]]></category>

		<category><![CDATA[Thales]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=703</guid>
		<description><![CDATA[In late March Thales released an interesting report on the state of PCI – “PCI DSS Trends 2010: QSA Insights Report.”  The report was written by the Ponemon Institute and it highlights the difficulty of taking into account risk, security and subjectivity within the PCI DSS compliance standard. If you haven’t read it, here’s a [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/04/02/risk-security-and-subjectivity-within-pci/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Observations from HIMSS</title>
		<link>http://www.netspi.com/blog/2010/03/10/observations-from-himss/</link>
		<comments>http://www.netspi.com/blog/2010/03/10/observations-from-himss/#comments</comments>
		<pubDate>Wed, 10 Mar 2010 21:30:04 +0000</pubDate>
		<dc:creator>Deke George</dc:creator>
		
		<category><![CDATA[Industry]]></category>

		<category><![CDATA[healthcare]]></category>

		<category><![CDATA[healthcare security]]></category>

		<category><![CDATA[Healthcare security requirements]]></category>

		<category><![CDATA[HITRUST]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=677</guid>
		<description><![CDATA[I was at the Healthcare Information and Management Systems Society (HIMSS) national conference last week in Atlanta. Overall, the conference wasn’t much different than past years. From an information security perspective the presentations and conversations were limited, but there were a number of interesting things that I took away from the conference. 
First and foremost, healthcare [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/03/10/observations-from-himss/feed/</wfw:commentRss>
		</item>
		<item>
		<title>HITRUST Part 4 Looking Forward</title>
		<link>http://www.netspi.com/blog/2010/01/13/hitrust-part-4-looking-forward/</link>
		<comments>http://www.netspi.com/blog/2010/01/13/hitrust-part-4-looking-forward/#comments</comments>
		<pubDate>Wed, 13 Jan 2010 22:52:56 +0000</pubDate>
		<dc:creator>Yan Kravchenko</dc:creator>
		
		<category><![CDATA[Industry]]></category>

		<category><![CDATA[CSF]]></category>

		<category><![CDATA[healthcare]]></category>

		<category><![CDATA[HITRUST]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=527</guid>
		<description><![CDATA[In this conclusion of the HITRUST blog series, I would like to discuss some definite opportunities and challenges that HITRUST is likely to face.]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/01/13/hitrust-part-4-looking-forward/feed/</wfw:commentRss>
		</item>
		<item>
		<title>HITRUST Part 3 Certification Explained</title>
		<link>http://www.netspi.com/blog/2009/12/30/hitrust-part-3-certification-explained/</link>
		<comments>http://www.netspi.com/blog/2009/12/30/hitrust-part-3-certification-explained/#comments</comments>
		<pubDate>Wed, 30 Dec 2009 21:19:05 +0000</pubDate>
		<dc:creator>Yan Kravchenko</dc:creator>
		
		<category><![CDATA[Industry]]></category>

		<category><![CDATA[CSF]]></category>

		<category><![CDATA[healthcare]]></category>

		<category><![CDATA[HITRUST]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=513</guid>
		<description><![CDATA[As a continuation of the HITRUST blog series, in this post I would like to explore the concept of certification, and what it means.]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2009/12/30/hitrust-part-3-certification-explained/feed/</wfw:commentRss>
		</item>
		<item>
		<title>HITRUST Part 2: Taking a First Look at the CSF</title>
		<link>http://www.netspi.com/blog/2009/12/07/hitrust-part-2-taking-a-first-look-at-the-csf/</link>
		<comments>http://www.netspi.com/blog/2009/12/07/hitrust-part-2-taking-a-first-look-at-the-csf/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 02:14:16 +0000</pubDate>
		<dc:creator>Yan Kravchenko</dc:creator>
		
		<category><![CDATA[Industry]]></category>

		<category><![CDATA[ARRA]]></category>

		<category><![CDATA[COBIT]]></category>

		<category><![CDATA[CSF]]></category>

		<category><![CDATA[FTC]]></category>

		<category><![CDATA[HIPAA]]></category>

		<category><![CDATA[HITECH]]></category>

		<category><![CDATA[HITRUST]]></category>

		<category><![CDATA[ISO]]></category>

		<category><![CDATA[NIST]]></category>

		<category><![CDATA[PCI]]></category>

		<category><![CDATA[Red Flags Rule]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=497</guid>
		<description><![CDATA[In continuation of the HITRUST blog series, in this post I would like to take a closer look at the Common Security Framework (CSF), and what it’s all about. ]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2009/12/07/hitrust-part-2-taking-a-first-look-at-the-csf/feed/</wfw:commentRss>
		</item>
		<item>
		<title>What is HITRUST? - Part 1</title>
		<link>http://www.netspi.com/blog/2009/12/04/what-is-hitrust-part-1/</link>
		<comments>http://www.netspi.com/blog/2009/12/04/what-is-hitrust-part-1/#comments</comments>
		<pubDate>Fri, 04 Dec 2009 17:37:03 +0000</pubDate>
		<dc:creator>Yan Kravchenko</dc:creator>
		
		<category><![CDATA[Industry]]></category>

		<category><![CDATA[ARRA]]></category>

		<category><![CDATA[CSF]]></category>

		<category><![CDATA[healthcare]]></category>

		<category><![CDATA[HIPAA]]></category>

		<category><![CDATA[HITECH]]></category>

		<category><![CDATA[HITRUST]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=503</guid>
		<description><![CDATA[HITRUST is rapidly gaining popularity in the healthcare and security consulting fields, and NetSPI is investing significant resources in developing services that will assist clients in taking advantage of the new Common Security Framework (CSF). As a way of introducing this new development, I will write a series of blog posts intended to familiarize anyone interested with just what HITRUST and the CSF are all about.]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2009/12/04/what-is-hitrust-part-1/feed/</wfw:commentRss>
		</item>
		<item>
		<title>&#8220;60 Minutes&#8221; on Cyber Security Risks</title>
		<link>http://www.netspi.com/blog/2009/11/09/60-minutes-on-cyber-security-risks/</link>
		<comments>http://www.netspi.com/blog/2009/11/09/60-minutes-on-cyber-security-risks/#comments</comments>
		<pubDate>Mon, 09 Nov 2009 20:50:44 +0000</pubDate>
		<dc:creator>Ryan Wakeham</dc:creator>
		
		<category><![CDATA[Industry]]></category>

		<category><![CDATA["60 Minutes"]]></category>

		<category><![CDATA[critical infrastructure]]></category>

		<category><![CDATA[information security vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=462</guid>
		<description><![CDATA[ “60 Minutes” did justice to the severity of the problem. . . .
At the same time, the program was lacking with regard to solutions. There is nothing about these vulnerabilities that prevents them from being mitigated; IT security professionals solve similar problems every day. ]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2009/11/09/60-minutes-on-cyber-security-risks/feed/</wfw:commentRss>
		</item>
		<item>
		<title>PCI in Europe Today</title>
		<link>http://www.netspi.com/blog/2009/11/03/pci-in-europe-today/</link>
		<comments>http://www.netspi.com/blog/2009/11/03/pci-in-europe-today/#comments</comments>
		<pubDate>Tue, 03 Nov 2009 16:30:06 +0000</pubDate>
		<dc:creator>Deke George</dc:creator>
		
		<category><![CDATA[Industry]]></category>

		<category><![CDATA[Chip and PIN]]></category>

		<category><![CDATA[PCI Community Meeting Prague]]></category>

		<category><![CDATA[PCI in Europe]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=416</guid>
		<description><![CDATA[It’s been discussed quite frequently that the Europeans are behind North America in implementing PCI, especially at the merchant level. . . The consensus at this year’s conference was that this situation is beginning to change. ]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2009/11/03/pci-in-europe-today/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
