<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>NetSPI Blog</title>
	<atom:link href="http://www.netspi.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.netspi.com/blog</link>
	<description>Information security consulting</description>
	<pubDate>Mon, 26 Jul 2010 21:26:00 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Not so Independent Agents?</title>
		<link>http://www.netspi.com/blog/2010/07/26/not-so-independent-agents/</link>
		<comments>http://www.netspi.com/blog/2010/07/26/not-so-independent-agents/#comments</comments>
		<pubDate>Mon, 26 Jul 2010 21:26:00 +0000</pubDate>
		<dc:creator>David Gianna</dc:creator>
		
		<category><![CDATA[PCI]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[independent agency]]></category>

		<category><![CDATA[payment gateway]]></category>

		<category><![CDATA[SAQ]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=912</guid>
		<description><![CDATA[In the realm of PCI, the network of independent agents might not be so independent after all. When one thinks of agents, one thinks of real estate, insurance and travel. They all provide a service, they all take information, and they all accept payments. Some of these are independent agents who own their own agency [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/07/26/not-so-independent-agents/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Windows Tools in BackTrack</title>
		<link>http://www.netspi.com/blog/2010/07/21/windows-tools-in-backtrack/</link>
		<comments>http://www.netspi.com/blog/2010/07/21/windows-tools-in-backtrack/#comments</comments>
		<pubDate>Thu, 22 Jul 2010 00:37:34 +0000</pubDate>
		<dc:creator>Scott Sutherland</dc:creator>
		
		<category><![CDATA[Application Security]]></category>

		<category><![CDATA[hacker tools]]></category>

		<category><![CDATA[PCI Requirement 11.3]]></category>

		<category><![CDATA[penetration testing]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=892</guid>
		<description><![CDATA[
For those of you who aren’t in the loop, BackTrack is a Live Linux distribution that ships with a large number of open source tools that can be used to assess the security of networks, systems, and applications.  At this point, most IT professionals and 14 year old computer geeks are at least generally [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/07/21/windows-tools-in-backtrack/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Invisible Threats: Insecure Service Accounts</title>
		<link>http://www.netspi.com/blog/2010/07/01/invisible-threats-insecure-service-accounts/</link>
		<comments>http://www.netspi.com/blog/2010/07/01/invisible-threats-insecure-service-accounts/#comments</comments>
		<pubDate>Thu, 01 Jul 2010 15:23:36 +0000</pubDate>
		<dc:creator>Scott Sutherland</dc:creator>
		
		<category><![CDATA[Application Security]]></category>

		<category><![CDATA[Least Privilege]]></category>

		<category><![CDATA[Windows Penetration Testing]]></category>

		<category><![CDATA[Windows Service Accounts]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=856</guid>
		<description><![CDATA[
In the wonderful world of Windows, service accounts are basically the man behind the curtain.  Almost invisible to the naked eye, they can be used to run almost any application you can dream up.   That includes everything from database services to anti-virus agents.  Unfortunately, many companies have a “set it and [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/07/01/invisible-threats-insecure-service-accounts/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Common Compliance Hurdles Part 2: Non-compliant Applications</title>
		<link>http://www.netspi.com/blog/2010/06/23/common-compliance-hurdles-part-2-non-compliant-applications/</link>
		<comments>http://www.netspi.com/blog/2010/06/23/common-compliance-hurdles-part-2-non-compliant-applications/#comments</comments>
		<pubDate>Wed, 23 Jun 2010 19:36:43 +0000</pubDate>
		<dc:creator>Ryan Wakeham</dc:creator>
		
		<category><![CDATA[PCI]]></category>

		<category><![CDATA[pci compliance]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=850</guid>
		<description><![CDATA[In this, the second installment in a series discussing common PCI compliance challenges, I address non-compliant payment applications.  Such applications are nearly ubiquitous in the cardholder data environments of smaller merchants (and even some of the larger ones).  However, merchants that store cardholder data are rarely able to attain a compliant state when using an [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/06/23/common-compliance-hurdles-part-2-non-compliant-applications/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The Systems That Time Forgot</title>
		<link>http://www.netspi.com/blog/2010/06/15/the-systems-that-time-forgot/</link>
		<comments>http://www.netspi.com/blog/2010/06/15/the-systems-that-time-forgot/#comments</comments>
		<pubDate>Tue, 15 Jun 2010 20:04:24 +0000</pubDate>
		<dc:creator>Scott Sutherland</dc:creator>
		
		<category><![CDATA[Application Security]]></category>

		<category><![CDATA[asset management]]></category>

		<category><![CDATA[Configuration Management]]></category>

		<category><![CDATA[PCI DSS Requirement 2]]></category>

		<category><![CDATA[penetration testing]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=835</guid>
		<description><![CDATA[Do you know about ALL of the systems on your network? If so, you’re in the minority. Identifying and actively managing all the systems on a network is not an easy task. Environments are constantly changing, asset owners come and go, and without a good asset management process, systems get lost in the shuffle. Unfortunately, [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/06/15/the-systems-that-time-forgot/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Is PCI driving the development of information security within healthcare?</title>
		<link>http://www.netspi.com/blog/2010/06/14/is-pci-driving-the-development-of-information-security-within-healthcare/</link>
		<comments>http://www.netspi.com/blog/2010/06/14/is-pci-driving-the-development-of-information-security-within-healthcare/#comments</comments>
		<pubDate>Mon, 14 Jun 2010 15:45:01 +0000</pubDate>
		<dc:creator>Deke George</dc:creator>
		
		<category><![CDATA[Industry]]></category>

		<category><![CDATA[healthcare]]></category>

		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=830</guid>
		<description><![CDATA[I like to watch industries evolve in how they deal with information security. It was interesting to watch retail evolve as PCI got more organized.  The PCI Council put together the DSS with dates and penalties for breaches and non-compliance, and that drove significant change. It appears that a similar major change within healthcare is [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/06/14/is-pci-driving-the-development-of-information-security-within-healthcare/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Secure360</title>
		<link>http://www.netspi.com/blog/2010/05/21/secure360/</link>
		<comments>http://www.netspi.com/blog/2010/05/21/secure360/#comments</comments>
		<pubDate>Fri, 21 May 2010 15:00:37 +0000</pubDate>
		<dc:creator>Deke George</dc:creator>
		
		<category><![CDATA[Industry]]></category>

		<category><![CDATA[Information Security]]></category>

		<category><![CDATA[risk]]></category>

		<category><![CDATA[Secure360]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=826</guid>
		<description><![CDATA[We held the Secure360 conference in the Twin Cities last week. Presentation topics included PCI, cloud computing, and problems within the security industry. While it can get tiring discussing the industry&#8217;s problems, I like trying to understand the difficult nature of information security and enjoy the challenge of trying to overcome the obstacles related to rationally [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/05/21/secure360/feed/</wfw:commentRss>
		</item>
		<item>
		<title>PCI Compliance: Now a Finance Issue as Well</title>
		<link>http://www.netspi.com/blog/2010/05/20/pci-compliance-now-a-finance-issue-as-well/</link>
		<comments>http://www.netspi.com/blog/2010/05/20/pci-compliance-now-a-finance-issue-as-well/#comments</comments>
		<pubDate>Thu, 20 May 2010 15:24:52 +0000</pubDate>
		<dc:creator>Lee Buttke</dc:creator>
		
		<category><![CDATA[PCI]]></category>

		<category><![CDATA[PCI-DSS]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=806</guid>
		<description><![CDATA[As an information security professional, my experience within the payment card security industry has taught me that credit card fraud is not just an information security or information technology issue, but increasingly also a financial one.
In order to process payment cards, organizations must execute agreements with financial institutions (&#8221;acquirers&#8221;) that legally obligate them to put [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/05/20/pci-compliance-now-a-finance-issue-as-well/feed/</wfw:commentRss>
		</item>
		<item>
		<title>PCI Assessors Meeting</title>
		<link>http://www.netspi.com/blog/2010/05/14/pci-assessors-meeting/</link>
		<comments>http://www.netspi.com/blog/2010/05/14/pci-assessors-meeting/#comments</comments>
		<pubDate>Fri, 14 May 2010 17:02:25 +0000</pubDate>
		<dc:creator>Lee Buttke</dc:creator>
		
		<category><![CDATA[PCI]]></category>

		<category><![CDATA[PA-DSS]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=802</guid>
		<description><![CDATA[I am currently on my way back from Las Vegas and the PCI (Payment Card Industry) Assessors Meeting.   I guess it is appropriate that the Delta flight that I am on is a cashless flight; you are now able to buy all the $5 Pringles you can eat with a credit card.  But I digress; [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/05/14/pci-assessors-meeting/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Are You Testing Your Web Application for Vulnerabilities?</title>
		<link>http://www.netspi.com/blog/2010/05/05/are-you-testing-your-web-application-for-vulnerabilities/</link>
		<comments>http://www.netspi.com/blog/2010/05/05/are-you-testing-your-web-application-for-vulnerabilities/#comments</comments>
		<pubDate>Wed, 05 May 2010 17:11:19 +0000</pubDate>
		<dc:creator>Steve Kerns</dc:creator>
		
		<category><![CDATA[Application Security]]></category>

		<category><![CDATA[code reviews]]></category>

		<category><![CDATA[PCI]]></category>

		<category><![CDATA[PCI-DSS]]></category>

		<category><![CDATA[Pentesting]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=728</guid>
		<description><![CDATA[As an organization that performs a large volume of code reviews and penetration tests, NetSPI is frequently asked which type of application assessment is the best option. Your primary options are a code review or a web application penetration test. Both are recommended and both find many of the vulnerabilities commonly found in web applications [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/05/05/are-you-testing-your-web-application-for-vulnerabilities/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
