<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>ISECOM on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/isecom/</link>
    <description>Recent content in ISECOM on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 13 Dec 2010 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/isecom/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>The OSSTMM 3 – What I like about it</title>
      <link>https://insinuator.net/2010/12/the-osstmm-3-what-i-like-about-it/</link>
      <pubDate>Mon, 13 Dec 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/12/the-osstmm-3-what-i-like-about-it/</guid>
      <description>&lt;p&gt;Given the upcoming public release of &lt;a href=&#34;http://www.isecom.org&#34;&gt;ISECOM&lt;/a&gt;‘s &lt;a href=&#34;http://www.isecom.org/osstmm/&#34;&gt;Open Source Security Testing Methodology Manual (OSSTMM)&lt;/a&gt; version 3, I took the opportunity to have a closer look at it. While we at ERNW never adopted the OSSTMM for our own way of performing security assessments (mostly due to the fact that performing assessments is our main business since 2001 and our approach has been developed and constantly honed since then so that we’re simply used to doing it “our way”) I’ve followed parts of ISECOM’s work quite closely as some of the brightest minds in the security space are contributing to it and they come up with innovative ideas regularly.&lt;br&gt;&#xA;So I was eager to get an early copy of it to spend some weekend time going through it (where I live we have about 40 cm of snow currently so there’s “plenty of occasions for a cosy reading session” ;-))&lt;br&gt;&#xA;One can read the OSSTMM (at least) two ways: as a manual for performing security testing or as a “whole philosophy of approaching [information] security”. I did the latter and will comment on it in a two-part post, covering the things I liked first and taking a more critical perspective on some portions in the second. Here we go with the first, in an unordered manner:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Our Favorite Subject: [It’s all about] Risk</title>
      <link>https://insinuator.net/2010/07/our-favorite-subject-its-all-about-risk/</link>
      <pubDate>Sun, 11 Jul 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/07/our-favorite-subject-its-all-about-risk/</guid>
      <description>&lt;p&gt;Some days ago my old friend Pete Herzog from &lt;a href=&#34;http://www.isecom.org&#34;&gt;ISECOM&lt;/a&gt; posted a blog entry titled “Hackers May Be Giants with Sharp Teeth” &lt;a href=&#34;https://www.infosecisland.com/blogview/5031-Hackers-May-Be-Giants-with-Sharp-Teeth.html&#34;&gt;here&lt;/a&gt; which – along with some quite insightful reflections on the way kids perceive “bad people” – contains his usual rant on (the uselessness of) risk assessment.&lt;br&gt;&#xA;Given that this debate (whether taking a risk-based infosec approach is a wise thing or not) is a constant element of our – Pete’s and mine – long lasting relationship I somehow feel enticed to respond 😉&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
