<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Why does forum software has more security features than &#8220;enterprise&#8221; tool chains?</title>
	<atom:link href="http://www.greebo.net/2007/09/27/why-does-forum-software-has-more-security-features-than-enterprise-tool-chains/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.greebo.net/2007/09/27/why-does-forum-software-has-more-security-features-than-enterprise-tool-chains/</link>
	<description>mostly useless crap from me</description>
	<pubDate>Thu, 04 Dec 2008 19:40:33 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
		<item>
		<title>By: Big Red</title>
		<link>http://www.greebo.net/2007/09/27/why-does-forum-software-has-more-security-features-than-enterprise-tool-chains/#comment-14912</link>
		<dc:creator>Big Red</dc:creator>
		<pubDate>Tue, 16 Oct 2007 00:56:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.greebo.net/2007/09/27/why-does-forum-software-has-more-security-features-than-enterprise-tool-chains/#comment-14912</guid>
		<description>Not strictly related, but a good paper for the warm fuzzy old days from before you or I were born.



PE</description>
		<content:encoded><![CDATA[<p>Not strictly related, but a good paper for the warm fuzzy old days from before you or I were born.</p>
<p>PE</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Big Red</title>
		<link>http://www.greebo.net/2007/09/27/why-does-forum-software-has-more-security-features-than-enterprise-tool-chains/#comment-14535</link>
		<dc:creator>Big Red</dc:creator>
		<pubDate>Mon, 01 Oct 2007 01:31:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.greebo.net/2007/09/27/why-does-forum-software-has-more-security-features-than-enterprise-tool-chains/#comment-14535</guid>
		<description>"Accountability is simply missing. Yes, many systems have logs, but they are business irrelevant. My personal view is that if a business person doesn’t care about a log entry, it’s not worth collecting. Accountability is the key here, not 1 GB of logs per day "

Couldn't agree more Nodster. There's a veritable shitload of wasted resource on collecting info that's never (going to be) used.

As well as asking "Why?" and "How" questions around each datum, it's often worth getting a risk or legislative compliance person involved. Been to one client site recently where they were collecting (what seemed to me) the weirdest collection of stuff. When I asked why, it ended up they had gone through an extensive risk/legislative review (compared against business rather than technical ends) and found the bare minimum of stuff they needed to collect. The geeks added in a couple of other data, which they wanted to use for performance tuning purposes.

Good post.

PE</description>
		<content:encoded><![CDATA[<p>&#8220;Accountability is simply missing. Yes, many systems have logs, but they are business irrelevant. My personal view is that if a business person doesn’t care about a log entry, it’s not worth collecting. Accountability is the key here, not 1 GB of logs per day &#8221;</p>
<p>Couldn&#8217;t agree more Nodster. There&#8217;s a veritable shitload of wasted resource on collecting info that&#8217;s never (going to be) used.</p>
<p>As well as asking &#8220;Why?&#8221; and &#8220;How&#8221; questions around each datum, it&#8217;s often worth getting a risk or legislative compliance person involved. Been to one client site recently where they were collecting (what seemed to me) the weirdest collection of stuff. When I asked why, it ended up they had gone through an extensive risk/legislative review (compared against business rather than technical ends) and found the bare minimum of stuff they needed to collect. The geeks added in a couple of other data, which they wanted to use for performance tuning purposes.</p>
<p>Good post.</p>
<p>PE</p>
]]></content:encoded>
	</item>
</channel>
</rss>
