<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>NetSPI Blog</title>
	<atom:link href="http://www.netspi.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.netspi.com/blog</link>
	<description>Information security consulting</description>
	<pubDate>Wed, 10 Mar 2010 21:30:04 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Observations from HIMSS</title>
		<link>http://www.netspi.com/blog/2010/03/10/observations-from-himss/</link>
		<comments>http://www.netspi.com/blog/2010/03/10/observations-from-himss/#comments</comments>
		<pubDate>Wed, 10 Mar 2010 21:30:04 +0000</pubDate>
		<dc:creator>Deke George</dc:creator>
		
		<category><![CDATA[Industry]]></category>

		<category><![CDATA[healthcare]]></category>

		<category><![CDATA[healthcare security]]></category>

		<category><![CDATA[Healthcare security requirements]]></category>

		<category><![CDATA[HITRUST]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=677</guid>
		<description><![CDATA[I was at the Healthcare Information and Management Systems Society (HIMSS) national conference last week in Atlanta. Overall, the conference wasn’t much different than past years. From an information security perspective the presentations and conversations were limited, but there were a number of interesting things that I took away from the conference. 
First and foremost, healthcare [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/03/10/observations-from-himss/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Manual vs. Automated Testing</title>
		<link>http://www.netspi.com/blog/2010/01/22/manual-vs-automated-testing/</link>
		<comments>http://www.netspi.com/blog/2010/01/22/manual-vs-automated-testing/#comments</comments>
		<pubDate>Sat, 23 Jan 2010 00:04:26 +0000</pubDate>
		<dc:creator>Seth Peter</dc:creator>
		
		<category><![CDATA[CTO's Corner]]></category>

		<category><![CDATA[Application Security]]></category>

		<category><![CDATA[Automated tools]]></category>

		<category><![CDATA[Manual testing]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=669</guid>
		<description><![CDATA[. . . no single application assessment or code review product could find more than about 35% of the total vulnerabilities GE could find with a manual process. That alone should encourage anyone serious about eradicating vulnerabilities within their applications to step it up a notch!]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/01/22/manual-vs-automated-testing/feed/</wfw:commentRss>
		</item>
		<item>
		<title>HITRUST Part 4 Looking Forward</title>
		<link>http://www.netspi.com/blog/2010/01/13/hitrust-part-4-looking-forward/</link>
		<comments>http://www.netspi.com/blog/2010/01/13/hitrust-part-4-looking-forward/#comments</comments>
		<pubDate>Wed, 13 Jan 2010 22:52:56 +0000</pubDate>
		<dc:creator>Yan Kravchenko</dc:creator>
		
		<category><![CDATA[Industry]]></category>

		<category><![CDATA[CSF]]></category>

		<category><![CDATA[healthcare]]></category>

		<category><![CDATA[HITRUST]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=527</guid>
		<description><![CDATA[In this conclusion of the HITRUST blog series, I would like to discuss some definite opportunities and challenges that HITRUST is likely to face.]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/01/13/hitrust-part-4-looking-forward/feed/</wfw:commentRss>
		</item>
		<item>
		<title>What is happening in the application security arena?</title>
		<link>http://www.netspi.com/blog/2010/01/07/what-is-happening-in-the-application-security-arena/</link>
		<comments>http://www.netspi.com/blog/2010/01/07/what-is-happening-in-the-application-security-arena/#comments</comments>
		<pubDate>Fri, 08 Jan 2010 00:52:19 +0000</pubDate>
		<dc:creator>Steve Kerns</dc:creator>
		
		<category><![CDATA[Application Security]]></category>

		<category><![CDATA[OWASP]]></category>

		<category><![CDATA[vulnerability assessment]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=619</guid>
		<description><![CDATA[According to Gartner, 75% of the attacks are coming though web applications and not through the network. This means greater emphasis needs to be placed on application security. However, this does not appear to be happening.]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/01/07/what-is-happening-in-the-application-security-arena/feed/</wfw:commentRss>
		</item>
		<item>
		<title>HITRUST Part 3 Certification Explained</title>
		<link>http://www.netspi.com/blog/2009/12/30/hitrust-part-3-certification-explained/</link>
		<comments>http://www.netspi.com/blog/2009/12/30/hitrust-part-3-certification-explained/#comments</comments>
		<pubDate>Wed, 30 Dec 2009 21:19:05 +0000</pubDate>
		<dc:creator>Yan Kravchenko</dc:creator>
		
		<category><![CDATA[Industry]]></category>

		<category><![CDATA[CSF]]></category>

		<category><![CDATA[healthcare]]></category>

		<category><![CDATA[HITRUST]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=513</guid>
		<description><![CDATA[As a continuation of the HITRUST blog series, in this post I would like to explore the concept of certification, and what it means.]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2009/12/30/hitrust-part-3-certification-explained/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Vulnerability Alert: FCKeditor Arbitrary File Upload</title>
		<link>http://www.netspi.com/blog/2009/12/19/vulnerability-alert-fckeditor-arbitrary-file-upload/</link>
		<comments>http://www.netspi.com/blog/2009/12/19/vulnerability-alert-fckeditor-arbitrary-file-upload/#comments</comments>
		<pubDate>Sat, 19 Dec 2009 19:32:16 +0000</pubDate>
		<dc:creator>Scott Sutherland</dc:creator>
		
		<category><![CDATA[Application Security]]></category>

		<category><![CDATA[ASV Scanning]]></category>

		<category><![CDATA[PCI Requirement 11.2]]></category>

		<category><![CDATA[Upload Exploit]]></category>

		<category><![CDATA[vulnerability assessment]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=549</guid>
		<description><![CDATA[The worst kind of vulnerability in your environment is the one you don’t know exists. The “FCKeditor Arbitrary File Upload” issue seems to be just such a vulnerability.]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2009/12/19/vulnerability-alert-fckeditor-arbitrary-file-upload/feed/</wfw:commentRss>
		</item>
		<item>
		<title>HITRUST Part 2: Taking a First Look at the CSF</title>
		<link>http://www.netspi.com/blog/2009/12/07/hitrust-part-2-taking-a-first-look-at-the-csf/</link>
		<comments>http://www.netspi.com/blog/2009/12/07/hitrust-part-2-taking-a-first-look-at-the-csf/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 02:14:16 +0000</pubDate>
		<dc:creator>Yan Kravchenko</dc:creator>
		
		<category><![CDATA[Industry]]></category>

		<category><![CDATA[ARRA]]></category>

		<category><![CDATA[COBIT]]></category>

		<category><![CDATA[CSF]]></category>

		<category><![CDATA[FTC]]></category>

		<category><![CDATA[HIPAA]]></category>

		<category><![CDATA[HITECH]]></category>

		<category><![CDATA[HITRUST]]></category>

		<category><![CDATA[ISO]]></category>

		<category><![CDATA[NIST]]></category>

		<category><![CDATA[PCI]]></category>

		<category><![CDATA[Red Flags Rule]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=497</guid>
		<description><![CDATA[In continuation of the HITRUST blog series, in this post I would like to take a closer look at the Common Security Framework (CSF), and what it’s all about. ]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2009/12/07/hitrust-part-2-taking-a-first-look-at-the-csf/feed/</wfw:commentRss>
		</item>
		<item>
		<title>What is HITRUST? - Part 1</title>
		<link>http://www.netspi.com/blog/2009/12/04/what-is-hitrust-part-1/</link>
		<comments>http://www.netspi.com/blog/2009/12/04/what-is-hitrust-part-1/#comments</comments>
		<pubDate>Fri, 04 Dec 2009 17:37:03 +0000</pubDate>
		<dc:creator>Yan Kravchenko</dc:creator>
		
		<category><![CDATA[Industry]]></category>

		<category><![CDATA[ARRA]]></category>

		<category><![CDATA[CSF]]></category>

		<category><![CDATA[healthcare]]></category>

		<category><![CDATA[HIPAA]]></category>

		<category><![CDATA[HITECH]]></category>

		<category><![CDATA[HITRUST]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=503</guid>
		<description><![CDATA[HITRUST is rapidly gaining popularity in the healthcare and security consulting fields, and NetSPI is investing significant resources in developing services that will assist clients in taking advantage of the new Common Security Framework (CSF). As a way of introducing this new development, I will write a series of blog posts intended to familiarize anyone interested with just what HITRUST and the CSF are all about.]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2009/12/04/what-is-hitrust-part-1/feed/</wfw:commentRss>
		</item>
		<item>
		<title>IP Traceback: Has Its Time Arrived?</title>
		<link>http://www.netspi.com/blog/2009/11/18/ip-traceback-has-its-time-arrived/</link>
		<comments>http://www.netspi.com/blog/2009/11/18/ip-traceback-has-its-time-arrived/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 18:19:54 +0000</pubDate>
		<dc:creator>Ryan Wakeham</dc:creator>
		
		<category><![CDATA[Technology]]></category>

		<category><![CDATA[denial of service attacks]]></category>

		<category><![CDATA[IP spoofing]]></category>

		<category><![CDATA[IP traceback]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=488</guid>
		<description><![CDATA[In simple terms, IP traceback allows for the reliable identification of the source of IP traffic, despite techniques such as IP spoofing. Maybe its time has finally come.]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2009/11/18/ip-traceback-has-its-time-arrived/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How Good Are Your Application Security Assessments?</title>
		<link>http://www.netspi.com/blog/2009/11/16/how-good-are-your-application-security-assessments/</link>
		<comments>http://www.netspi.com/blog/2009/11/16/how-good-are-your-application-security-assessments/#comments</comments>
		<pubDate>Mon, 16 Nov 2009 18:53:31 +0000</pubDate>
		<dc:creator>Steve Kerns</dc:creator>
		
		<category><![CDATA[Application Security]]></category>

		<category><![CDATA[application security assessments]]></category>

		<category><![CDATA[Heartland Payment Systems]]></category>

		<category><![CDATA[QSA]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=481</guid>
		<description><![CDATA[I wonder if Heartland Payment Systems queried the QSA company on the background of the pen tester. Yes, the company was QSA-certified, but did the person or persons actually doing the penetration test have the education and experience needed to perform a pen test well?]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2009/11/16/how-good-are-your-application-security-assessments/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
