<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" version="2.0">

<channel>
<title>CERT's Podcast Series: Security for Business Leaders</title>
<link>http://www.cert.org/podcast</link>
<language>en-us</language>
<itunes:subtitle>Fresh discussions on the importance of security within organizations</itunes:subtitle>
<itunes:author>CERT</itunes:author>
<itunes:explicit>no</itunes:explicit>
<description>In this series of podcasts, CERT provides both general principles and specific starting points for business leaders who want to launch an enterprise-wide security effort or make sure their existing security program is as good as it can be.</description>
<itunes:owner>
<itunes:name>CERT</itunes:name>
<itunes:email>podcast@cert.org</itunes:email>
</itunes:owner>
<itunes:image href="http://www.cert.org/podcast/images/ep_art.jpg" />
<itunes:category text="Technology">
<itunes:category text="Tech News" />
</itunes:category>

<item>
<title>Connecting the Dots Between IT Operations and Security</title>
<itunes:author>Gene Kim</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080513kim-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080513kim-full.mp3></guid>
<description>High performing organizations effectively integrate information security controls into mainstream IT operational processes.</description>
<pubDate>Tue, 13 May 2008 11:02:16 -0400</pubDate>
<itunes:duration>24:39</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080513kim-full.mp3" length="5918491" type="audio/mp3" />
</item>
<item>
<title>Getting in Front of Social Engineering</title>
<itunes:author>Gary Hinson</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080429hinson-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080429hinson-full.mp3></guid>
<description>Helping your staff learn how to identify social engineering attempts is the first step in thwarting them.</description>
<pubDate>Tue, 29 Apr 2008 14:27:50 -0400</pubDate>
<itunes:duration>23:33</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080429hinson-full.mp3" length="11486485" type="audio/mp3" />
</item>
<item>
<title>Using Benchmarks to Make Better Security Decisions</title>
<itunes:author>Betsy Nichols</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080415nichols-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080415nichols-full.mp3></guid>
<description>Benchmark results can be used to compare with peers, drive performance, and help determine how much security is enough.</description>
<pubDate>Tue, 15 Apr 2008 12:42:50 -0400</pubDate>
<itunes:duration>20:07</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080415nichols-full.mp3" length="4829542" type="audio/mp3" />
</item>
<item>
<title>Protecting Information Privacy - How To and Lessons Learned</title>
<itunes:author>Kim Hargraves</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080401hargraves-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080401hargraves-full.mp3></guid>
<description>Aligning with business objectives, integrating with enterprise risks, and collaborating with stakeholders are key to ensuring information privacy.</description>
<pubDate>Tue, 01 Apr 2008 12:35:48 -0400</pubDate>
<itunes:duration>22:12</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080401hargraves-full.mp3" length="5329260" type="audio/mp3" />
</item>
<item>
<title>Initiating a Security Metrics Program: Key Points to Consider</title>
<itunes:author>Sam Merrell</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080318merrell-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080318merrell-full.mp3></guid>
<description>A sound security metrics program is grounded in selecting data that is relevant to consumers and collecting it from repeatable processes.</description>
<pubDate>Tue, 18 Mar 2008 09:54:13 -0400</pubDate>
<itunes:duration>12:04</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080318merrell-full.mp3" length="2902020" type="audio/mp3" />
</item>
<item>
<title>Insider Threat and the Software Development Life Cycle</title>
<itunes:author>Dawn Cappelli</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080304cappelli-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080304cappelli-full.mp3></guid>
<description>Significant insider threat vulnerabilities can be introduced (and mitigated) during all phases of the software development life cycle.</description>
<pubDate>Tue, 04 Mar 2008 10:21:53 -0500</pubDate>
<itunes:duration>23:33</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080304cappelli-full.mp3" length="5652810" type="audio/mp3" />
</item>
<item>
<title>Tackling the Growing Botnet Threat</title>
<itunes:author>Nicholas Ianelli</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080219ianelli-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080219ianelli-full.mp3></guid>
<description>Business leaders need to understand the risks to their organizations caused by the proliferation of botnets.</description>
<pubDate>Tue, 19 Feb 2008 11:15:36 -0500</pubDate>
<itunes:duration>20:33</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080219ianelli-full.mp3" length="4935584" type="audio/mp3" />
</item>
<item>
<title>Building a Security Metrics Program</title>
<itunes:author>Betsy Nichols</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080205nichols-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080205nichols-full.mp3></guid>
<description>Selecting and reporting meaningful security metrics depend on picking topics of great interest, defining the business context, and having access to sound data.</description>
<pubDate>Tue, 05 Feb 2008 10:44:57 -0500</pubDate>
<itunes:duration>22:33</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080205nichols-full.mp3" length="5417004" type="audio/mp3" />
</item>

<item>
<title>Inadvertent Data Disclosure on Peer-to-Peer Networks</title>
<itunes:author>M. Eric Johnson</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080122johnson-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080122johnson-full.mp3></guid>
<description>Peer-to-peer networks are being used today to unintentionally disclose government, commercial, and personal information.</description>
<pubDate>Tue, 22 Jan 2008 10:12:16 -0500</pubDate>
<itunes:duration>20:13</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080122johnson-full.mp3" length="9710220" type="audio/mp3" />
</item>
<item>
<title>Information Compliance: A Growing Challenge for Business Leaders</title>
<itunes:author>Tom Smedinghoff</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080108smedinghoff-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080108smedinghoff-full.mp3></guid>
<description>Directors and senior executives are personally accountable for protecting information entrusted to their care.</description>
<pubDate>Tue, 08 Jan 2008 10:17:09 -0500</pubDate>
<itunes:duration>21:53</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080108smedinghoff-full.mp3" length="5256594" type="audio/mp3" />
</item>
<item>
<title>Internal Audit's Role in Information Security: An Introduction</title>
<itunes:author>Dan Swanson</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20071210swanson-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20071210swanson-full.mp3></guid>
<description>Internal Audit can serve a key role in putting an effective information security program in place, and keeping it there.</description>
<pubDate>Mon, 10 Dec 2007 22:16:22 -0500</pubDate>
<itunes:duration>14:25</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20071210swanson-full.mp3" length="3464350" type="audio/mp3" />
</item>
<item>
<title>What Business Leaders Can Expect from Security Degree Programs</title>
<itunes:author>Sean Beggs</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20071127beggs-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20071127beggs-full.mp3></guid>
<description>Information security degree programs are proliferating, but what do they really offer business leaders who are seeking knowledgeable employees?</description>
<pubDate>Tue, 27 Nov 2007 12:10:19 -0500</pubDate>
<itunes:duration>18:29</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20071127beggs-full.mp3" length="4440284" type="audio/mp3" />
</item>
<item>
<title>The Path from Information Security Risk Assessment to Compliance</title>
<itunes:author>Bill Wilson</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20071113wilson-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20071113wilson-full.mp3></guid>
<description>Information security risk assessment, performed in concert with operational risk management, can contribute to compliance as an outcome.</description>
<pubDate>Tue, 13 Nov 2007 12:03:01 -0500</pubDate>
<itunes:duration>26:17</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20071113wilson-full.mp3" length="6312706" type="audio/mp3" />
</item>
<item>
<title>Computer Forensics for Business Leaders: Building Robust Policies and Processes</title>
<itunes:author>Cal Waits</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20071030waits-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20071030waits-full.mp3></guid>
<description>Business Leaders can play a key role in computer forensics by establishing strong policies and proactively testing to ensure those policies work in tough situations.</description>
<pubDate>Tue, 30 Oct 2007 11:50:34 -0400</pubDate>
<itunes:duration>12:21</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20071030waits-full.mp3" length="2970123" type="audio/mp3" />
</item>
<item>
<title>Business Resilience: A More Compelling Argument for Information Security</title>
<itunes:author>Scott Dynes</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20071016dynes-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20071016dynes-full.mp3></guid>
<description>A business resilience argument can bridge the communication gap that often exists between information security officers and business leaders.</description>
<pubDate>Tue, 16 Oct 2007 11:02:38 -0400</pubDate>
<itunes:duration>24:33</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20071016dynes-full.mp3" length="5895409" type="audio/mp3" />
</item>
<item>
<title>Resiliency Engineering: Integrating Security, IT Operations, and Business Continuity</title>
<itunes:author>Lisa Young</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20071015young-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20071015young-full.mp3></guid>
<description>By taking a holistic view of business resilience - similar in many ways to classical engineering - business leaders can help their organizations stand up to known and unknown threats.</description>
<pubDate>Mon, 15 Oct 2007 15:42:04 -0400</pubDate>
<itunes:duration>18:23</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20071015young-full.mp3" length="4415240" type="audio/mp3" />
</item>
<item>
<title>The Human Side of Security Trade-Offs</title>
<itunes:author>G. Newby, S. Losi</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/28Newby.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/28Newby.mp3</guid>
<description>It's easy to think of security as a collection of technologies and tools - but people are the real key to any security effort.</description>
<pubDate>Tue, 18 Sep 2007 11:30:00 -0400</pubDate>
<itunes:duration>27:14</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/28Newby.mp3" length="6541606" type="audio/mp3"/>
</item>

<item>
<title>Dual Perspectives: A CIO's and CISO's Take on Security</title>
<itunes:author>P. Morrison, B. Boni, J. Allen</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/27MorrisonBoni.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/27MorrisonBoni.mp3</guid>
<description>Given that you can't secure everything, managing security risk to a "commercially reasonable degree" can lead to the best possible solution.</description>
<pubDate>Tue, 04 Sep 2007 15:45:00 -0400</pubDate>
<itunes:duration>26:20</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/27MorrisonBoni.mp3" length="6322700" type="audio/mp3" />
</item>


<item>
<title>Tackling Security at the National Level: A Resource for Leaders</title>
<itunes:author>J. Carpenter, J. Allen</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/26Carpenter.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/26Carpenter.mp3</guid>
<description>Business leaders can use national CSIRTs (Computer Security Incident Response Teams) as a key resource when dealing with incidents with a national or worldwide scope.</description>
<pubDate>Tue, 21 Aug 2007 11:45:00 -0400</pubDate>
<itunes:duration>22:18</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/26Carpenter.mp3" length="5358070" type="audio/mp3" />
</item>


<item>
<title>Reducing Security Costs with Standard Configurations: U.S. Government Initiatives</title>
<itunes:author>C. Kreitner, J. Allen</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/25Kreitner.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/25Kreitner.mp3</guid>
<description>Information security costs can be significantly reduced by enforcing standard configurations for widely deployed systems.</description>
<pubDate>Tue, 07 Aug 2007 11:30:00 -0400</pubDate>
<itunes:duration>25:08</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/25Kreitner.mp3" length="6037262" type="audio/mp3" />
</item>


<item>
<title>Real-World Security for Business Leaders</title>
<itunes:author>P. Fusco, W. Pollak</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/24Fusco.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/24Fusco.mp3</guid>
<description>Security is not an option - but it may be time to start viewing it as a business enabler, rather than just a cost of doing business.</description>
<pubDate>Tue, 24 Jul 2007 15:30:00 -0400</pubDate>
<itunes:duration>20:26</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/24Fusco.mp3" length="4907902" type="audio/mp3" />
</item>


<item>
<title>Using Standards to Build an Information Security Program</title>
<itunes:author>W. Wilson, J. Allen</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/23WilsonAllen.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/23WilsonAllen.mp3</guid>
<description>Business leaders can use international standards to create a business- and risk-based information security program.</description>
<pubDate>Tue, 10 Jul 2007 11:30:00 -0400</pubDate>
<itunes:duration>27:51</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/23WilsonAllen.mp3" length="6689250" type="audio/mp3" />
</item>


<item>
<title>Getting Real About Security Governance</title>
<itunes:author>J. Allen, S. Losi</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/22LosiAllen.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/22LosiAllen.mp3</guid>
<description>Enterprise security governance is not just a vague idea - it can be achieved by implementing a defined, repeatable process with specific activities.</description>
<pubDate>Tue, 26 Jun 2007 11:30:00 -0400</pubDate>
<itunes:duration>19:23</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/22LosiAllen.mp3" length="4655180" type="audio/mp3" />
</item>


<item>
<title>Convergence: Integrating Physical and IT Security</title>
<itunes:author>B. Crowell, B. Contos</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/21CrowellContos.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/21CrowellContos.mp3</guid>
<description>Deploying common solutions for physical and IT security is a cost-effective way to reduce risk and save money.</description>
<pubDate>Tue, 12 Jun 2007 11:30:00 -0400</pubDate>
<itunes:duration>28:43</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/21CrowellContos.mp3" length="6895812" type="audio/mp3" />
</item>


<item>
<title>IT Infrastructure: Tips for Navigating Tough Spots</title>
<itunes:author>S. Huth</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20HuthKalinowski.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/20HuthKalinowski.mp3</guid>
<description>Organizations occasionally may need to redefine their IT infrastructures - but to succeed, they must be prepared to handle tricky situations.</description>
<pubDate>Tue, 29 May 2007 10:30:00 -0400</pubDate>
<itunes:duration>22:33</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20HuthKalinowski.mp3" length="5416484" type="audio/mp3" />
</item>


<item>
<title>The Value of De-Identified Personal Data</title>
<itunes:author>S. Ganow</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/19Ganow.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/19Ganow.mp3</guid>
<description>As the legal compliance landscape grows increasingly complex, de-identification can help organizations share data more securely.</description>
<pubDate>Tue, 15 May 2007 10:30:00 -0400</pubDate>
<itunes:duration>31:24</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/19Ganow.mp3" length="7539480" type="audio/mp3" />
</item>


<item>
<title>Adapting to Changing Risk Environments: Operational Resilience</title>
<itunes:author>R. Caralli</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/18Caralli.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/18Caralli.mp3</guid>
<description>Business leaders need to ensure that their organizations can keep critical business processes and services up and running in the face of the unexpected.</description>
<pubDate>Tue, 1 May 2007 10:30:00 -0400</pubDate>
<itunes:duration>24:44</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/18Caralli.mp3" length="5942024" type="audio/mp3" />
</item>


<item>
<title>Computer Forensics for Business Leaders: A Primer</title>
<itunes:author>R. Nolan</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/17Nolan.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/17Nolan.mp3</guid>
<description>Computer forensics is often overlooked when planning an incident response strategy; however, it is a critical part of incident response, and business leaders need to understand how to tackle it.</description>
<pubDate>Tue, 17 Apr 2007 10:30:00 -0400</pubDate>
<itunes:duration>16:31</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/17Nolan.mp3" length="3966520" type="audio/mp3" />
</item>


<item>
<title>The Real Secrets of Incident Management</title>
<itunes:author>G. Killcrece</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/16KillcreceRuefle.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/16KillcreceRuefle.mp3</guid>
<description>Incident management is not just about technical response. It is a cross-enterprise effort that requires good communication and informed risk management.</description>
<pubDate>Tue, 3 Apr 2007 10:30:00 -0400</pubDate>
<itunes:duration>21:16</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/16KillcreceRuefle.mp3" length="5107002" type="audio/mp3" />
</item>


<item>
<title>The Legal Side of Global Security</title>
<itunes:author>J. Westby</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/15Westby.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/15Westby.mp3</guid>
<description>Business leaders, including legal counsel, need to understand how to tackle complex security issues for a global enterprise.</description>
<pubDate>Tue, 20 Mar 2007 10:30:00 -0400</pubDate>
<itunes:duration>25:55</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/15Westby.mp3" length="6223700" type="audio/mp3" />
</item>


<item>
<title>A New Look at the Business of IT Education</title>
<itunes:author>L. Rogers</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/14Rogers.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/14Rogers.mp3</guid>
<description>System administrators increasingly need business savvy in addition to technical skills, and IT training courses must try to keep pace with this trend.</description>
<pubDate>Tue, 6 Mar 2007 10:30:00 -0400</pubDate>
<itunes:duration>17:51</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/14Rogers.mp3" length="4288280" type="audio/mp3" />
</item>


<item>
<title>Crisis Communications During a Security Incident</title>
<itunes:author>K. Kimberland</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/13Kimberland.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/13Kimberland.mp3</guid>
<description>Business leaders need to be prepared to communicate with the media and their staff during a high-profile security incident or crisis.</description>
<pubDate>Tue, 20 Feb 2007 10:30:00 -0400</pubDate>
<itunes:duration>13:41</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/13Kimberland.mp3" length="3288132" type="audio/mp3" />
</item>


<item>
<title>Assuring Mission Success in Complex Environments</title>
<itunes:author>C. Alberts</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/12Alberts.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/12Alberts.mp3</guid>
<description>Analysis tools are needed for assessing complex organizational and technological issues that are well beyond traditional approaches.</description>
<pubDate>Tue, 6 Feb 2007 10:30:00 -0400</pubDate>
<itunes:duration>17:48</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/12Alberts.mp3" length="4275514" type="audio/mp3" />
</item>



<item>
<title>Privacy: The Slow Tipping Point</title>
<itunes:author>A. Acquisti</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/11Acquisti.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/11Acquisti.mp3</guid>
<description>A trend toward more and more data disclosure, as seen in online social networks, may be causing users to become desensitized to privacy breaches in general.</description>
<pubDate>Tue, 23 Jan 2007 10:30:00 -0400</pubDate>
<itunes:duration>17:41</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/11Acquisti.mp3" length="4249520" type="audio/mp3" />
</item>


<item>
<title>Building Staff Competence in Security</title>
<itunes:author>B. Laswell</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/10Laswell.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/10Laswell.mp3</guid>
<description>Practical specifications and guidelines now exist that define necessary knowledge, skills, and competencies for staff members in a range of security positions - from practitioners to managers.</description>
<pubDate>Tue, 9 Jan 2007 10:30:00 -0400</pubDate>
<itunes:duration>21:55</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/10Laswell.mp3" length="5265456" type="audio/mp3" />
</item>



<item>
<title>Inside Defense-in-Depth</title>
<itunes:author>K. Rush</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/9Rush.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/9Rush.mp3</guid>
<description>Defense-in-Depth is one path toward enterprise resilience - the ability to withstand threats and failures. The foundational aspects of compliance management and risk management serve as stepping-stones to and supports for other, more technical aspects.</description>
<pubDate>Tue, 19 Dec 2006 10:30:00 -0400</pubDate>
<itunes:duration>15:43</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/9Rush.mp3" length="3776784" type="audio/mp3" />
</item>


<item>
<title>Evolving Business Models, Threats, and Technologies: A Conversation with CERT's Deputy Director for Technology</title>
<itunes:author>T. Longstaff</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/8Longstaff.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/8Longstaff.mp3</guid>
<description>Business models are evolving. This has challenging implications as security threats become more covert and technologies facilitate information migration.</description>
<pubDate>Tue, 12 Dec 2006 10:30:00 -0400</pubDate>
<itunes:duration>21:39</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/8Longstaff.mp3" length="5201936" type="audio/mp3" />
</item>


<item>
<title>Protecting Against Insider Threat</title>
<itunes:author>D. Cappelli</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/7Cappelli.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/7Cappelli.mp3</guid>
<description>The threat of attack from insiders is real and substantial. Insiders have a significant advantage over others who might want to harm an organization.</description>
<pubDate>Tue, 28 Nov 2006 10:30:00 -0400</pubDate>
<itunes:duration>27:08</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/7Cappelli.mp3" length="6516772" type="audio/mp3" />
</item>



<item>
<title>Change Management: The Security 'X' Factor</title>
<itunes:author>G. Kim</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/6Losi_Kim.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/6Losi_Kim.mp3</guid>
<description>In a recent survey of organizations' security posture, one factor separated high performers from the rest of the pack: change management.</description>
<pubDate>Tue, 14 Nov 2006 10:30:00 -0400</pubDate>
<itunes:duration>18:37</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/6Losi_Kim.mp3" length="4472206" type="audio/mp3" />
</item>



<item>
<title>CERT Lessons Learned: A Conversation with Rich Pethia, Director of CERT</title>
<itunes:author>R. Pethia</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/5Pethia_Discussion.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/5Pethia_Discussion.mp3</guid>
<description>Learn more about the future of CERT and Rich Pethia's view of the Internet security landscape.</description>
<pubDate>Tue, 31 Oct 2006 10:30:00 -0400</pubDate>
<itunes:duration>23:34</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/5Pethia_Discussion.mp3" length="5661472" type="audio/mp3" />
</item>


<item>
<title>Why Leaders Should Care About Security</title>
<itunes:author>J. Allen</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/1Why_Leaders_Should_Care_About_Security.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/1Why_Leaders_Should_Care_About_Security.mp3</guid>
<description>Leaders need to be security conscious and to treat adequate security as a non-negotiable requirement of being in business.</description>
<pubDate>Tue, 17 Oct 2006 12:58:20 -0400</pubDate>
<itunes:duration>17:52</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/1Why_Leaders_Should_Care_About_Security.mp3" length="4191096" type="audio/mp3" />
</item>

<item>
<title>The ROI of Security</title>
<itunes:author>S. Losi</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/2The_ROI_of_Security.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/2The_ROI_of_Security.mp3</guid>
<description>ROI is a useful tool because it enables comparison among investments in a consistent way.</description>
<pubDate>Tue, 17 Oct 2006 12:58:20 -0400</pubDate>
<itunes:duration>21:19</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/2The_ROI_of_Security.mp3" length="5117736" type="audio/mp3" />
</item>

<item>
<title>Proactive Remedies for Rising Threats</title>
<itunes:author>M. Lindner</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/3Proactive_Remedies_for_Rising_Threats.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/3Proactive_Remedies_for_Rising_Threats.mp3</guid>
<description>Threats to information security are increasingly stealthy, but they are on the rise and must be mitigated through sound policy and strategy.</description>
<pubDate>Tue, 17 Oct 2006 12:58:20 -0400</pubDate>
<itunes:duration>19:32</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/3Proactive_Remedies_for_Rising_Threats.mp3" length="4703712" type="audio/mp3" />
</item>


<item>
<title>Compliance vs. Buy-in</title>
<itunes:author>J. Allen</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/4Compliance_vs_Buy-In.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/4Compliance_vs_Buy-In.mp3</guid>
<description>Integrating security into standard business operating processes and procedures is more effective than treating security as a compliance exercise.
</description>
<pubDate>Tue, 17 Oct 2006 12:58:20 -0400</pubDate>
<itunes:duration>8:41</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/4Compliance_vs_Buy-In.mp3" length="2082600" type="audio/mp3" />
</item>

  
</channel>
</rss>

