<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" version="2.0">

<channel>
<title>CERT's Podcast Series: Security for Business Leaders</title>
<link>http://www.cert.org/podcast</link>
<language>en-us</language>
<itunes:subtitle>Fresh discussions on the importance of security within organizations</itunes:subtitle>
<itunes:author>CERT</itunes:author>
<itunes:explicit>no</itunes:explicit>
<description>In this series of podcasts, CERT provides both general principles and specific starting points for business leaders who want to launch an enterprise-wide security effort or make sure their existing security program is as good as it can be.</description>
<itunes:owner>
<itunes:name>CERT</itunes:name>
<itunes:email>podcast@cert.org</itunes:email>
</itunes:owner>
<itunes:image href="http://www.cert.org/podcast/images/ep_art.jpg" />
<itunes:category text="Technology">
<itunes:category text="Tech News" />
</itunes:category>

<item>
<title>NIST Catalog of Security and Privacy Controls, Including Insider Threat</title>
<itunes:author>Ron Ross</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20120424ross-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20120424ross-full.mp3></guid>
<description>Security controls, including those for insider threat, are the safeguards necessary to protect information and information systems.</description>
<pubDate>Tue, 24 Apr 2012 10:56:37 -0400</pubDate>
<itunes:duration>28:09</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20120424ross-full.mp3" length="16899502" type="audio/mp3" />
</item>
<item>
<title>Cisco's Adoption of CERT Secure Coding Standards</title>
<itunes:author>Martin Sebor</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20120228sebor-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20120228sebor-full.mp3></guid>
<description>Implementing secure coding standards to reduce the number of vulnerabilities that can escape into operational systems is a sound  business decision.</description>
<pubDate>Tue, 28 Feb 2012 13:51:04 -0500</pubDate>
<itunes:duration>24:40</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20120228sebor-full.mp3" length="17765123" type="audio/mp3" />
</item>
<item>
<title>How to Become a Cyber Warrior</title>
<itunes:author>Dennis Allen</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20120131allen2-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20120131allen2-full.mp3></guid>
<description>Protecting the internet and its users against cyber attacks requires a significant increase in the number of skilled cyber warriors.</description>
<pubDate>Tue, 31 Jan 2012 13:12:32 -0500</pubDate>
<itunes:duration>25:35</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20120131allen2-full.mp3" length="15352921" type="audio/mp3" />
</item>
<item>
<title>Considering Security and Privacy in the Move to Electronic Health Records</title>
<itunes:author>Deborah Lafky</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20111220lafky-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20111220lafky-full.mp3></guid>
<description>Electronic health records bring many benefits along with security and privacy challenges.</description>
<pubDate>Tue, 20 Dec 2011 13:26:02 -0500</pubDate>
<itunes:duration>28:26</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20111220lafky-full.mp3" length="17070888" type="audio/mp3" />
</item>
<item>
<title>Measuring Operational Resilience</title>
<itunes:author>Julia Allen</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20111004allen-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20111004allen-full.mp3></guid>
<description>Measures of operational resilience should answer key questions, inform decisions, and affect behavior.</description>
<pubDate>Tue, 04 Oct 2011 11:48:44 -0400</pubDate>
<itunes:duration>25:31</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20111004allen-full.mp3" length="15314738" type="audio/mp3" />
</item>
<item>
<title>Why Organizations Need a Secure Domain Name System</title>
<itunes:author>Alex Nicoll</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20110906nicoll-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20110906nicoll-full.mp3></guid>
<description>Use of Domain Name System security extensions can help prevent website hijacking attacks.</description>
<pubDate>Tue, 06 Sep 2011 12:41:48 -0400</pubDate>
<itunes:duration>20:50</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20110906nicoll-full.mp3" length="12508902" type="audio/mp3" />
</item>
<item>
<title>Controls for Monitoring the Security of Cloud Services at All Seven Layers</title>
<itunes:author>Jonathan Spring</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20110802spring-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20110802spring-full.mp3></guid>
<description>Depending on the service model, cloud providers and customers can monitor and implement controls to better protect their sensitive information.</description>
<pubDate>Tue, 02 Aug 2011 10:43:13 -0400</pubDate>
<itunes:duration>19:18</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20110802spring-full.mp3" length="11587293" type="audio/mp3" />
</item>
<item>
<title>Building a Malware Analysis Capability</title>
<itunes:author>Jeff Gennari</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20110712gennari-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20110712gennari-full.mp3></guid>
<description>Analyzing malware is essential to assess the damage and reduce the impact associated with ongoing infection.</description>
<pubDate>Tue, 12 Jul 2011 11:31:09 -0400</pubDate>
<itunes:duration>24:46</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20110712gennari-full.mp3" length="11893123" type="audio/mp3" />
</item>
<item>
<title>Using the Smart Grid Maturity Model (SGMM)</title>
<itunes:author>David White</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20110505white-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20110505white-full.mp3></guid>
<description>Over 100 electric power utilities are accelerating their transformation to the smart grid by using the Smart Grid Maturity Model.</description>
<pubDate>Thu, 05 May 2011 12:37:22 -0400</pubDate>
<itunes:duration>29:40</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20110505white-full.mp3" length="17806944" type="audio/mp3" />
</item>
<item>
<title>Integrated, Enterprise-Wide Risk Management: NIST 800-39 and CERT-RMM</title>
<itunes:author>Ron Ross</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20110329ross-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20110329ross-full.mp3></guid>
<description>BuBusiness l leaders must address risk at the enterprise, business process, and system levels to effectively protect against today's and tomorrow's threats.</description>
<pubDate>Tue, 29 Mar 2011 16:15:04 -0400</pubDate>
<itunes:duration>28:05</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20110329ross-full.mp3" length="16854506" type="audio/mp3" />
</item>
<item>
<title>Conducting Cyber Exercises at the National Level</title>
<itunes:author>Brett Lambo</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20110222lambo-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20110222lambo-full.mp3></guid>
<description>Scenario-based exercises help organizations, governments, and nations prepare for, identify, and mitigate cyber risks.</description>
<pubDate>Tue, 22 Feb 2011 15:31:12 -0500</pubDate>
<itunes:duration>23:14</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20110222lambo-full.mp3" length="13944626" type="audio/mp3" />
</item>
<item>
<title>Indicators and Controls for Mitigating Insider Threat</title>
<itunes:author>Michael Hanley</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20110125hanley-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20110125hanley-full.mp3></guid>
<description>Technical controls may be effective in helping prevent, detect, and respond to insider crimes. </description>
<pubDate>Tue, 25 Jan 2011 11:27:39 -0500</pubDate>
<itunes:duration>23:25</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20110125hanley-full.mp3" length="11251008" type="audio/mp3" />
</item>
<item>
<title>How Resilient Is My Organization?</title>
<itunes:author>Rich Caralli</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20101209caralli-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20101209caralli-full.mp3></guid>
<description>Use the CERT Resilience Management Model (CERT-RMM) to help ensure that critical assets and services perform as expected in the face of stress and disruption.</description>
<pubDate>Thu, 09 Dec 2010 13:27:23 -0500</pubDate>
<itunes:duration>39:01</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20101209caralli-full.mp3" length="23421504" type="audio/mp3" />
</item>
<item>
<title>Public-Private Partnerships - Essential for National Cyber Security </title>
<itunes:author>Sam Merrell</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20101130merrell-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20101130merrell-full.mp3></guid>
<description>Government agencies and private industry must build effective partnerships to secure national critical infrastructures. </description>
<pubDate>Tue, 30 Nov 2010 13:50:00 -0500</pubDate>
<itunes:duration>31:23</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20101130merrell-full.mp3" length="18842664" type="audio/mp3" />
</item>
<item>
<title>Software Assurance: A Master&#39;s Level Curriculum</title>
<itunes:author>Nancy Mead</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20101026mead-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20101026mead-full.mp3></guid>
<description>Knowledge about software assurance is essential to ensure that complex systems function as intended. </description>
<pubDate>Tue, 26 Oct 2010 13:27:43 -0400</pubDate>
<itunes:duration>34:36</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20101026mead-full.mp3" length="24923280" type="audio/mp3" />
</item>
<item>
<title>How to Develop More Secure Software - Practices from Thirty Organizations</title>
<itunes:author>Gary McGraw</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20100928mcgraw-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20100928mcgraw-full.mp3></guid>
<description>Organizations can benchmark their software security practices against 109 observed activities from 30 organizations.</description>
<pubDate>Tue, 28 Sep 2010 10:31:31 -0400</pubDate>
<itunes:duration>29:26</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20100928mcgraw-full.mp3" length="14128499" type="audio/mp3" />
</item>
<item>
<title>Mobile Device Security: Threats, Risks, and Actions to Take</title>
<itunes:author>Jonathan Frederick</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20100831frederick-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20100831frederick-full.mp3></guid>
<description>Internet-connected mobile devices are becoming increasingly attractive targets.</description>
<pubDate>Tue, 31 Aug 2010 10:52:04 -0400</pubDate>
<itunes:duration>26:14</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20100831frederick-full.mp3" length="6296704" type="audio/mp3" />
</item>
<item>
<title>Establishing a National Computer Security Incident Response Team (CSIRT)</title>
<itunes:author>John Haller</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20100819haller-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20100819haller-full.mp3></guid>
<description>A national CSIRT is essential for protecting national and economic security, and ensuring the continuity of government agencies and critical infrastructures.</description>
<pubDate>Thu, 19 Aug 2010 08:10:25 -0400</pubDate>
<itunes:duration>27:55</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20100819haller-full.mp3" length="6700536" type="audio/mp3" />
</item>
<item>
<title>Securing Industrial Control Systems</title>
<itunes:author>Art Manion</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20100727manion-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20100727manion-full.mp3></guid>
<description>Securing systems that control physical switches, valves, pumps, meters, and manufacturing lines as these systems connect to the internet is critical for service continuity.</description>
<pubDate>Tue, 27 Jul 2010 10:32:02 -0400</pubDate>
<itunes:duration>23:08</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20100727manion-full.mp3" length="5558118" type="audio/mp3" />
</item>
<item>
<title>TJX, Heartland, and CERT's Forensics Analysis Capabilities</title>
<itunes:author>Kevin Moore</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20100629kmoore-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20100629kmoore-full.mp3></guid>
<description>Complex, distributed, multi-year investigations of computer crimes require sophisticated methods, techniques, and tools.</description>
<pubDate>Tue, 29 Jun 2010 10:34:31 -0400</pubDate>
<itunes:duration>35:13</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20100629kmoore-full.mp3" length="8454798" type="audio/mp3" />
</item>
<item>
<title>The Power of Fuzz Testing to Reduce Security Vulnerabilities</title>
<itunes:author>Will Dormann</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20100525dormann-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20100525dormann-full.mp3></guid>
<description>To help identify and eliminate security vulnerabilities, subject all software that you build and buy to fuzz testing.</description>
<pubDate>Tue, 25 May 2010 14:18:39 -0400</pubDate>
<itunes:duration>26:01</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20100525dormann-full.mp3" length="6247798" type="audio/mp3" />
</item>
<item>
<title>Protect Your Business from Money Mules</title>
<itunes:author>Chad Dougherty</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20100427dougherty-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20100427dougherty-full.mp3></guid>
<description>Organized criminals recruit unsuspecting intermediaries to help steal funds from small businesses.</description>
<pubDate>Tue, 27 Apr 2010 10:14:14 -0400</pubDate>
<itunes:duration>19:01</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20100427dougherty-full.mp3" length="4567220" type="audio/mp3" />
</item>
<item>
<title>Train for the Unexpected</title>
<itunes:author>Matthew Meyer</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20100330meyer-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20100330meyer-full.mp3></guid>
<description>Being able to respond effectively when faced with a disruptive event requires that staff members learn to become more resilient. </description>
<pubDate>Tue, 30 Mar 2010 10:39:24 -0400</pubDate>
<itunes:duration>25:31</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20100330meyer-full.mp3" length="6126248" type="audio/mp3" />
</item>
<item>
<title>The Role of the CISO in Developing More Secure Software</title>
<itunes:author>Pravir Chandra</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20100302chandra-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20100302chandra-full.mp3></guid>
<description>CISOs must leave no room for anyone to deny that they understand what is expected of them when developing secure software. </description>
<pubDate>Tue, 02 Mar 2010 09:37:05 -0500</pubDate>
<itunes:duration>26:55</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20100302chandra-full.mp3" length="6464840" type="audio/mp3" />
</item>
<item>
<title>Computer and Network Forensics: A Master's Level Curriculum</title>
<itunes:author>Kristopher Rush</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20100202rush-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20100202rush-full.mp3></guid>
<description>Students learn how to combine multiple facets of digital forensics and draw conclusions to support full-scale investigations. </description>
<pubDate>Tue, 02 Feb 2010 09:12:08 -0500</pubDate>
<itunes:duration>24:45</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20100202rush-full.mp3" length="5944002" type="audio/mp3" />
</item>
<item>
<title>Introducing the Smart Grid Maturity Model (SGMM)</title>
<itunes:author>Ray Jones</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20100112jones-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20100112jones-full.mp3></guid>
<description>The SGMM provides a roadmap to guide an organization's transformation to the smart grid. </description>
<pubDate>Tue, 12 Jan 2010 09:47:58 -0500</pubDate>
<itunes:duration>25:55</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20100112jones-full.mp3" length="6225406" type="audio/mp3" />
</item>
<item>
<title>Integrating Privacy Practices into the Software Development Life Cycle</title>
<itunes:author>Ralph Hood</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20091222hood-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20091222hood-full.mp3></guid>
<description>Addressing privacy during software development is just as important as addressing security. </description>
<pubDate>Tue, 22 Dec 2009 09:36:04 -0500</pubDate>
<itunes:duration>17:27</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20091222hood-full.mp3" length="4192796" type="audio/mp3" />
</item>
<item>
<title>Using the Facts to Protect Enterprise Networks: CERT's NetSA Team</title>
<itunes:author>Timothy Shimeall</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20091201shimeall-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20091201shimeall-full.mp3></guid>
<description>Network defenders and business leaders can use NetSA measures and evidence to better protect their networks. </description>
<pubDate>Tue, 01 Dec 2009 09:42:22 -0500</pubDate>
<itunes:duration>22:00</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20091201shimeall-full.mp3" length="5284104" type="audio/mp3" />
</item>
<item>
<title>Ensuring Continuity of Operations When Business Is Disrupted</title>
<itunes:author>Gary Daniels</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20091110daniels-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20091110daniels-full.mp3></guid>
<description>Providing critical services during times of stress depends on documented, tested business continuity plans.</description>
<pubDate>Tue, 10 Nov 2009 10:17:41 -0500</pubDate>
<itunes:duration>21:22</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20091110daniels-full.mp3" length="5131148" type="audio/mp3" />
</item>
<item>
<title>Managing Relationships with Business Partners to Achieve Operational Resiliency</title>
<itunes:author>David White</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20091020white-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20091020white-full.mp3></guid>
<description>A defined, managed process for third party relationships is essential, particularly when business is disrupted. </description>
<pubDate>Tue, 20 Oct 2009 14:44:42 -0400</pubDate>
<itunes:duration>27:07</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20091020white-full.mp3" length="6513317" type="audio/mp3" />
</item>
<item>
<title>The Smart Grid: Managing Electrical Power Distribution and Use</title>
<itunes:author>James Stevens</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20090929stevens-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20090929stevens-full.mp3></guid>
<description>The smart grid is the use of digital technology to modernize the power grid, which comes with some new privacy and security challenges.</description>
<pubDate>Tue, 29 Sep 2009 10:23:08 -0400</pubDate>
<itunes:duration>20:15</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20090929stevens-full.mp3" length="4862832" type="audio/mp3" />
</item>
<item>
<title>Electronic Health Records: Challenges for Patient Privacy and Security</title>
<itunes:author>Robert Charette</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20090908charette-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20090908charette-full.mp3></guid>
<description>Electronic health records (EHRs) are possibly the most complicated area of IT  today, more difficult than defense.</description>
<pubDate>Tue, 08 Sep 2009 10:46:07 -0400</pubDate>
<itunes:duration>26:01</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20090908charette-full.mp3" length="6247080" type="audio/mp3" />
</item>
<item>
<title>Mitigating Insider Threat: New and Improved Practices</title>
<itunes:author>Dawn Cappelli</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20090818cappelli-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20090818cappelli-full.mp3></guid>
<description>Preventing and detecting insider threat is greatly improved by implementing 16 best practices based on 282 cases.</description>
<pubDate>Tue, 18 Aug 2009 11:08:53 -0400</pubDate>
<itunes:duration>36:21</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20090818cappelli-full.mp3" length="8728248" type="audio/mp3" />
</item>
<item>
<title>Analyzing Internet Traffic for Better Cyber Situational Awareness</title>
<itunes:author>Derek Gabbard</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20090728gabbard-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20090728gabbard-full.mp3></guid>
<description>Automation, innovation, reaction, and expansion are the foundation for obtaining meaningful network traffic intelligence in today's extended enterprise.</description>
<pubDate>Tue, 28 Jul 2009 09:51:58 -0400</pubDate>
<itunes:duration>29:33</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20090728gabbard-full.mp3" length="7095408" type="audio/mp3" />
</item>
<item>
<title>Rethinking Risk Management</title>
<itunes:author>Chris Alberts</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20090707alberts-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20090707alberts-full.mp3></guid>
<description>Business leaders need new approaches to address multi-enterprise, systems of systems risks across the life cycle and supply chain.</description>
<pubDate>Tue, 07 Jul 2009 12:23:43 -0400</pubDate>
<itunes:duration>29:36</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20090707alberts-full.mp3" length="7108057" type="audio/mp3" />
</item>
<item>
<title>The Upside and Downside of Security in the Cloud</title>
<itunes:author>Tim Mather</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20090616mather-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20090616mather-full.mp3></guid>
<description>When considering cloud services, business leaders need to weigh the economic benefits against the security and privacy risks.</description>
<pubDate>Tue, 16 Jun 2009 10:31:19 -0400</pubDate>
<itunes:duration>27:40</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20090616mather-full.mp3" length="6645256" type="audio/mp3" />
</item>
<item>
<title>More Targeted, Sophisticated Attacks: Where to Pay Attention</title>
<itunes:author>Marty Lindner</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20090526lindner-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20090526lindner-full.mp3></guid>
<description>Business leaders need to take action to better mitigate sophisticated social engineering attacks.</description>
<pubDate>Tue, 26 May 2009 10:16:34 -0400</pubDate>
<itunes:duration>20:40</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20090526lindner-full.mp3" length="4819566" type="audio/mp3" />
</item>
<item>
<title>Is There Value in Identifying Software Security "Never Events?"</title>
<itunes:author>Robert Charette</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20090505charette-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20090505charette-full.mp3></guid>
<description>Now may be the time to examine our responsibilities when developing software with known, preventable errors - along with some possible consequences.</description>
<pubDate>Tue, 05 May 2009 09:46:59 -0400</pubDate>
<itunes:duration>20:21</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20090505charette-full.mp3" length="4887967" type="audio/mp3" />
</item>
<item>
<title>Cyber Security, Safety, and Ethics for the Net Generation</title>
<itunes:author>Rodney Petersen</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20090414petersen-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20090414petersen-full.mp3></guid>
<description>Capitalizing on the cultural norms of the Net Generation is essential when developing security awareness programs.</description>
<pubDate>Tue, 14 Apr 2009 09:24:12 -0400</pubDate>
<itunes:duration>20:13</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20090414petersen-full.mp3" length="4855150" type="audio/mp3" />
</item>
<item>
<title>An Experienced-Based Maturity model for Software Security</title>
<itunes:author>Gary McGraw</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20090331mcgraw-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20090331mcgraw-full.mp3></guid>
<description>Observed practice, represented as a maturity model, can serve as a basis for developing more secure software.</description>
<pubDate>Tue, 31 Mar 2009 14:06:33 -0400</pubDate>
<itunes:duration>21:48</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20090331mcgraw-full.mp3" length="5234568" type="audio/mp3" />
</item>
<item>
<title>Mainstreaming Secure Coding Practices</title>
<itunes:author>Robert Seacord</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20090317seacord-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20090317seacord-full.mp3></guid>
<description>Requiring secure coding practices when building of</description>
<pubDate>Tue, 17 Mar 2009 10:38:38 -0400</pubDate>
<itunes:duration>20:02</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20090317seacord-full.mp3" length="4812675" type="audio/mp3" />
</item>
<item>
<title>Security: A Key Enabler of Business Innovation</title>
<itunes:author>Roland Cloutier</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20090303cloutier-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20090303cloutier-full.mp3></guid>
<description>Making security strategic to business innovation involves seven strategies and calculating risk-reward based on risk appetite.</description>
<pubDate>Tue, 03 Mar 2009 10:24:41 -0500</pubDate>
<itunes:duration>23:53</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20090303cloutier-full.mp3" length="5734467" type="audio/mp3" />
</item>
<item>
<title>Better Incident Response Through Scenario Based Training</title>
<itunes:author>Chris May</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20090217may-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20090217may-full.mp3></guid>
<description>Teams are better prepared to respond to incidents if realistic, hands-on training is part of their normal routine.</description>
<pubDate>Tue, 17 Feb 2009 11:00:34 -0500</pubDate>
<itunes:duration>22:55</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20090217may-full.mp3" length="5502393" type="audio/mp3" />
</item>
<item>
<title>An Alternative to Risk Management for Information and Software Security</title>
<itunes:author>Brian Chess</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20090203chess-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20090203chess-full.mp3></guid>
<description>Standard, compliance, and process are more effective than risk management for ensuring an adequate level of information and software security.</description>
<pubDate>Tue, 03 Feb 2009 10:58:03 -0500</pubDate>
<itunes:duration>25:52</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20090203chess-full.mp3" length="6213938" type="audio/mp3" />
</item>
<item>
<title>Tackling Tough Challenges: Insights from CERT's Director Rich Pethia</title>
<itunes:author>Rich Pethia</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20090120pethia-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20090120pethia-full.mp3></guid>
<description>Rich Pethia reflects on CERT's 20-year history and discusses how he is positioning the program to tackle future IT and security challenges.</description>
<pubDate>Tue, 20 Jan 2009 10:44:14 -0500</pubDate>
<itunes:duration>17:32</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20090120pethia-full.mp3" length="4214015" type="audio/mp3" />
</item>
<item>
<title>Leveraging Security Policies and Procedures for Electronic Evidence Discovery</title>
<itunes:author>John Christiansen</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20090106christiansen-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20090106christiansen-full.mp3></guid>
<description>Being able to effectively respond to e-discovery requests depends on well-defined, enatcted policies, procedures, and processes.</description>
<pubDate>Tue, 06 Jan 2009 11:22:14 -0500</pubDate>
<itunes:duration>25:44</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20090106christiansen-full.mp3" length="6179033" type="audio/mp3" />
</item>
<item>
<title>Climate Change: Implications for Information Technology and Security</title>
<itunes:author>Richard Power</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20081209power-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20081209power-full.mp3></guid>
<description>Climate change requires new strategies for dealing with traditional IT and information security risks.</description>
<pubDate>Tue, 09 Dec 2008 10:37:35 -0500</pubDate>
<itunes:duration>23:44</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20081209power-full.mp3" length="5701249" type="audio/mp3" />
</item>
<item>
<title>Using High Fidelity, Online Training to Stay Sharp</title>
<itunes:author>James Wrubel</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20081125wrubel-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20081125wrubel-full.mp3></guid>
<description>Virtual training environments can deliver high quality content to security professionals on-demand, anywhere, anytime.</description>
<pubDate>Tue, 25 Nov 2008 14:52:26 -0500</pubDate>
<itunes:duration>26:38</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20081125wrubel-full.mp3" length="6392639" type="audio/mp3" />
</item>
<item>
<title>Integrating Security Incident Response and e-Discovery</title>
<itunes:author>David Matthews</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20081111matthews-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20081111matthews-full.mp3></guid>
<description>Responding to an e-discovery request involves many of the same steps and roles as responding to a security incident.</description>
<pubDate>Tue, 11 Nov 2008 10:05:05 -0500</pubDate>
<itunes:duration>25:33</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20081111matthews-full.mp3" length="6136283" type="audio/mp3" />
</item>
<item>
<title>Concrete Steps for Implementing an Information Security Program</title>
<itunes:author>Jennifer Bayuk</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20081028bayuk-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20081028bayuk-full.mp3></guid>
<description>A sustainable security program is based on business-aligned strategy, policy, awareness, implementation, monitoring, and remediation.</description>
<pubDate>Tue, 28 Oct 2008 12:08:48 -0400</pubDate>
<itunes:duration>21:28</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20081028bayuk-full.mp3" length="5154315" type="audio/mp3" />
</item>
<item>
<title>Virtual Communities: Risks and Opportunities</title>
<itunes:author>Jan Wolynski</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20081014wolynski-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20081014wolynski-full.mp3></guid>
<description>When considering whether to conduct business in online, virtual communities, business leaders need to evaluate risks and opportunities.</description>
<pubDate>Tue, 14 Oct 2008 10:56:54 -0400</pubDate>
<itunes:duration>18:05</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20081014wolynski-full.mp3" length="4345674" type="audio/mp3" />
</item>
<item>
<title>Developing Secure Software: Universities as Supply Chain Partners</title>
<itunes:author>Mary Ann Davidson</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080930davidson-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080930davidson-full.mp3></guid>
<description>Integrating security into university curricula is one of the key solutions to developing more secure software.</description>
<pubDate>Tue, 30 Sep 2008 15:20:45 -0400</pubDate>
<itunes:duration>23:21</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080930davidson-full.mp3" length="5608744" type="audio/mp3" />
</item>
<item>
<title>Security Risk Assessment Using OCTAVE Allegro</title>
<itunes:author>Lisa Young</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080916young-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080916young-full.mp3></guid>
<description>OCTAVE Allegro provides a streamlined assessment method that focuses on risks to information used by critical business services.</description>
<pubDate>Tue, 16 Sep 2008 10:17:33 -0400</pubDate>
<itunes:duration>18:09</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080916young-full.mp3" length="4359226" type="audio/mp3" />
</item>
<item>
<title>Getting to a Useful Set of Security Metrics</title>
<itunes:author>Clint Kreitner</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080902kreitner-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080902kreitner-full.mp3></guid>
<description>Well-defined metrics are essential to determine which security practices are worth the investment.</description>
<pubDate>Tue, 02 Sep 2008 10:11:12 -0400</pubDate>
<itunes:duration>18:49</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080902kreitner-full.mp3" length="4516686" type="audio/mp3" />
</item>
<item>
<title>How to Start a Software Development Program</title>
<itunes:author>Gary McGraw</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080820mcgraw-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080820mcgraw-full.mp3></guid>
<description>Software security is accomplished by thinking like an attacker and integrating security practices into your software development lifecycle.</description>
<pubDate>Wed, 20 Aug 2008 09:48:58 -0400</pubDate>
<itunes:duration>20:01</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080820mcgraw-full.mp3" length="4804878" type="audio/mp3" />
</item>
<item>
<title>Managing Risk to Critical Infrastructures at the National Level</title>
<itunes:author>Bradford Willke</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080805willke-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080805willke-full.mp3></guid>
<description>Protecting critical infrastructures and the information they use are essential for preserving our way of life.</description>
<pubDate>Tue, 05 Aug 2008 13:14:01 -0400</pubDate>
<itunes:duration>22:12</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080805willke-full.mp3" length="5331888" type="audio/mp3" />
</item>

<item>
<title>Managing Security Vulnerabilites Based on What Matters Most</title>
<itunes:author>Art Manion</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080722manion-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080722manion-full.mp3></guid>
<description>Determining which security vulnerabilities to address should be based on the importance of the information asset.</description>
<pubDate>Tue, 22 Jul 2008 11:37:06 -0400</pubDate>
<itunes:duration>23:27</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080722manion-full.mp3" length="5630664" type="audio/mp3" />
</item>

<item>
<title>Identifying Software Security Requirements Early, Not After the Fact</title>
<itunes:author>Nancy Mead</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080708mead-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080708mead-full.mp3></guid>
<description>During requirements engineering, software engineers need to think deeply about (and document) how software should behave when under attack.</description>
<pubDate>Tue, 08 Jul 2008 10:49:09 -0400</pubDate>
<itunes:duration>22:57</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080708mead-full.mp3" length="5508480" type="audio/mp3" />
</item>
<item>
<title>Making Information Security Policy Happen</title>
<itunes:author>Paul Love</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080624love-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080624love-full.mp3></guid>
<description>Targeted, innovative communications and a robust life cycle are keys for security policy success.</description>
<pubDate>Tue, 24 Jun 2008 10:47:32 -0400</pubDate>
<itunes:duration>24:17</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080624love-full.mp3" length="5831091" type="audio/mp3" />
</item>
<item>
<title>Becoming a Smart Buyer of Software</title>
<itunes:author>Brian Gallagher</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080610gallagher-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080610gallagher-full.mp3></guid>
<description>Managing software that is developed by an outside organization can be more challenging than building it yourself.</description>
<pubDate>Tue, 10 Jun 2008 11:12:49 -0400</pubDate>
<itunes:duration>21:11</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080610gallagher-full.mp3" length="5085766" type="audio/mp3" />
</item>
<item>
<title>Building More Secure Software</title>
<itunes:author>Julia Allen</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080527allen-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080527allen-full.mp3></guid>
<description>Software security is about building better, more defect-free software to reduce vulnerabilities that are targeted by attackers.</description>
<pubDate>Tue, 27 May 2008 11:47:16 -0400</pubDate>
<itunes:duration>16:43</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080527allen-full.mp3" length="4014787" type="audio/mp3" />
</item>
<item>
<title>Connecting the Dots Between IT Operations and Security</title>
<itunes:author>Gene Kim</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080513kim-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080513kim-full.mp3></guid>
<description>High performing organizations effectively integrate information security controls into mainstream IT operational processes.</description>
<pubDate>Tue, 13 May 2008 11:02:16 -0400</pubDate>
<itunes:duration>24:39</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080513kim-full.mp3" length="5918491" type="audio/mp3" />
</item>
<item>
<title>Getting in Front of Social Engineering</title>
<itunes:author>Gary Hinson</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080429hinson-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080429hinson-full.mp3></guid>
<description>Helping your staff learn how to identify social engineering attempts is the first step in thwarting them.</description>
<pubDate>Tue, 29 Apr 2008 14:27:50 -0400</pubDate>
<itunes:duration>23:33</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080429hinson-full.mp3" length="11486485" type="audio/mp3" />
</item>
<item>
<title>Using Benchmarks to Make Better Security Decisions</title>
<itunes:author>Betsy Nichols</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080415nichols-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080415nichols-full.mp3></guid>
<description>Benchmark results can be used to compare with peers, drive performance, and help determine how much security is enough.</description>
<pubDate>Tue, 15 Apr 2008 12:42:50 -0400</pubDate>
<itunes:duration>20:07</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080415nichols-full.mp3" length="4829542" type="audio/mp3" />
</item>
<item>
<title>Protecting Information Privacy - How To and Lessons Learned</title>
<itunes:author>Kim Hargraves</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080401hargraves-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080401hargraves-full.mp3></guid>
<description>Aligning with business objectives, integrating with enterprise risks, and collaborating with stakeholders are key to ensuring information privacy.</description>
<pubDate>Tue, 01 Apr 2008 12:35:48 -0400</pubDate>
<itunes:duration>22:12</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080401hargraves-full.mp3" length="5329260" type="audio/mp3" />
</item>
<item>
<title>Initiating a Security Metrics Program: Key Points to Consider</title>
<itunes:author>Sam Merrell</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080318merrell-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080318merrell-full.mp3></guid>
<description>A sound security metrics program is grounded in selecting data that is relevant to consumers and collecting it from repeatable processes.</description>
<pubDate>Tue, 18 Mar 2008 09:54:13 -0400</pubDate>
<itunes:duration>12:04</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080318merrell-full.mp3" length="2902020" type="audio/mp3" />
</item>
<item>
<title>Insider Threat and the Software Development Life Cycle</title>
<itunes:author>Dawn Cappelli</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080304cappelli-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080304cappelli-full.mp3></guid>
<description>Significant insider threat vulnerabilities can be introduced (and mitigated) during all phases of the software development life cycle.</description>
<pubDate>Tue, 04 Mar 2008 10:21:53 -0500</pubDate>
<itunes:duration>23:33</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080304cappelli-full.mp3" length="5652810" type="audio/mp3" />
</item>
<item>
<title>Tackling the Growing Botnet Threat</title>
<itunes:author>Nicholas Ianelli</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080219ianelli-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080219ianelli-full.mp3></guid>
<description>Business leaders need to understand the risks to their organizations caused by the proliferation of botnets.</description>
<pubDate>Tue, 19 Feb 2008 11:15:36 -0500</pubDate>
<itunes:duration>20:33</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080219ianelli-full.mp3" length="4935584" type="audio/mp3" />
</item>
<item>
<title>Building a Security Metrics Program</title>
<itunes:author>Betsy Nichols</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080205nichols-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080205nichols-full.mp3></guid>
<description>Selecting and reporting meaningful security metrics depend on picking topics of great interest, defining the business context, and having access to sound data.</description>
<pubDate>Tue, 05 Feb 2008 10:44:57 -0500</pubDate>
<itunes:duration>22:33</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080205nichols-full.mp3" length="5417004" type="audio/mp3" />
</item>

<item>
<title>Inadvertent Data Disclosure on Peer-to-Peer Networks</title>
<itunes:author>M. Eric Johnson</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080122johnson-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080122johnson-full.mp3></guid>
<description>Peer-to-peer networks are being used today to unintentionally disclose government, commercial, and personal information.</description>
<pubDate>Tue, 22 Jan 2008 10:12:16 -0500</pubDate>
<itunes:duration>20:13</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080122johnson-full.mp3" length="9710220" type="audio/mp3" />
</item>
<item>
<title>Information Compliance: A Growing Challenge for Business Leaders</title>
<itunes:author>Tom Smedinghoff</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20080108smedinghoff-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20080108smedinghoff-full.mp3></guid>
<description>Directors and senior executives are personally accountable for protecting information entrusted to their care.</description>
<pubDate>Tue, 08 Jan 2008 10:17:09 -0500</pubDate>
<itunes:duration>21:53</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20080108smedinghoff-full.mp3" length="5256594" type="audio/mp3" />
</item>
<item>
<title>Internal Audit's Role in Information Security: An Introduction</title>
<itunes:author>Dan Swanson</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20071210swanson-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20071210swanson-full.mp3></guid>
<description>Internal Audit can serve a key role in putting an effective information security program in place, and keeping it there.</description>
<pubDate>Mon, 10 Dec 2007 22:16:22 -0500</pubDate>
<itunes:duration>14:25</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20071210swanson-full.mp3" length="3464350" type="audio/mp3" />
</item>
<item>
<title>What Business Leaders Can Expect from Security Degree Programs</title>
<itunes:author>Sean Beggs</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20071127beggs-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20071127beggs-full.mp3></guid>
<description>Information security degree programs are proliferating, but what do they really offer business leaders who are seeking knowledgeable employees?</description>
<pubDate>Tue, 27 Nov 2007 12:10:19 -0500</pubDate>
<itunes:duration>18:29</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20071127beggs-full.mp3" length="4440284" type="audio/mp3" />
</item>
<item>
<title>The Path from Information Security Risk Assessment to Compliance</title>
<itunes:author>Bill Wilson</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20071113wilson-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20071113wilson-full.mp3></guid>
<description>Information security risk assessment, performed in concert with operational risk management, can contribute to compliance as an outcome.</description>
<pubDate>Tue, 13 Nov 2007 12:03:01 -0500</pubDate>
<itunes:duration>26:17</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20071113wilson-full.mp3" length="6312706" type="audio/mp3" />
</item>
<item>
<title>Computer Forensics for Business Leaders: Building Robust Policies and Processes</title>
<itunes:author>Cal Waits</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20071030waits-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20071030waits-full.mp3></guid>
<description>Business Leaders can play a key role in computer forensics by establishing strong policies and proactively testing to ensure those policies work in tough situations.</description>
<pubDate>Tue, 30 Oct 2007 11:50:34 -0400</pubDate>
<itunes:duration>12:21</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20071030waits-full.mp3" length="2970123" type="audio/mp3" />
</item>
<item>
<title>Business Resilience: A More Compelling Argument for Information Security</title>
<itunes:author>Scott Dynes</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20071016dynes-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20071016dynes-full.mp3></guid>
<description>A business resilience argument can bridge the communication gap that often exists between information security officers and business leaders.</description>
<pubDate>Tue, 16 Oct 2007 11:02:38 -0400</pubDate>
<itunes:duration>24:33</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20071016dynes-full.mp3" length="5895409" type="audio/mp3" />
</item>
<item>
<title>Resiliency Engineering: Integrating Security, IT Operations, and Business Continuity</title>
<itunes:author>Lisa Young</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20071015young-full.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/20071015young-full.mp3></guid>
<description>By taking a holistic view of business resilience - similar in many ways to classical engineering - business leaders can help their organizations stand up to known and unknown threats.</description>
<pubDate>Mon, 15 Oct 2007 15:42:04 -0400</pubDate>
<itunes:duration>18:23</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20071015young-full.mp3" length="4415240" type="audio/mp3" />
</item>
<item>
<title>The Human Side of Security Trade-Offs</title>
<itunes:author>G. Newby, S. Losi</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/28Newby.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/28Newby.mp3</guid>
<description>It's easy to think of security as a collection of technologies and tools - but people are the real key to any security effort.</description>
<pubDate>Tue, 18 Sep 2007 11:30:00 -0400</pubDate>
<itunes:duration>27:14</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/28Newby.mp3" length="6541606" type="audio/mp3"/>
</item>

<item>
<title>Dual Perspectives: A CIO's and CISO's Take on Security</title>
<itunes:author>P. Morrison, B. Boni, J. Allen</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/27MorrisonBoni.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/27MorrisonBoni.mp3</guid>
<description>Given that you can't secure everything, managing security risk to a "commercially reasonable degree" can lead to the best possible solution.</description>
<pubDate>Tue, 04 Sep 2007 15:45:00 -0400</pubDate>
<itunes:duration>26:20</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/27MorrisonBoni.mp3" length="6322700" type="audio/mp3" />
</item>


<item>
<title>Tackling Security at the National Level: A Resource for Leaders</title>
<itunes:author>J. Carpenter, J. Allen</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/26Carpenter.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/26Carpenter.mp3</guid>
<description>Business leaders can use national CSIRTs (Computer Security Incident Response Teams) as a key resource when dealing with incidents with a national or worldwide scope.</description>
<pubDate>Tue, 21 Aug 2007 11:45:00 -0400</pubDate>
<itunes:duration>22:18</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/26Carpenter.mp3" length="5358070" type="audio/mp3" />
</item>


<item>
<title>Reducing Security Costs with Standard Configurations: U.S. Government Initiatives</title>
<itunes:author>C. Kreitner, J. Allen</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/25Kreitner.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/25Kreitner.mp3</guid>
<description>Information security costs can be significantly reduced by enforcing standard configurations for widely deployed systems.</description>
<pubDate>Tue, 07 Aug 2007 11:30:00 -0400</pubDate>
<itunes:duration>25:08</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/25Kreitner.mp3" length="6037262" type="audio/mp3" />
</item>


<item>
<title>Real-World Security for Business Leaders</title>
<itunes:author>P. Fusco, W. Pollak</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/24Fusco.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/24Fusco.mp3</guid>
<description>Security is not an option - but it may be time to start viewing it as a business enabler, rather than just a cost of doing business.</description>
<pubDate>Tue, 24 Jul 2007 15:30:00 -0400</pubDate>
<itunes:duration>20:26</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/24Fusco.mp3" length="4907902" type="audio/mp3" />
</item>


<item>
<title>Using Standards to Build an Information Security Program</title>
<itunes:author>W. Wilson, J. Allen</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/23WilsonAllen.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/23WilsonAllen.mp3</guid>
<description>Business leaders can use international standards to create a business- and risk-based information security program.</description>
<pubDate>Tue, 10 Jul 2007 11:30:00 -0400</pubDate>
<itunes:duration>27:51</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/23WilsonAllen.mp3" length="6689250" type="audio/mp3" />
</item>


<item>
<title>Getting Real About Security Governance</title>
<itunes:author>J. Allen, S. Losi</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/22LosiAllen.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/22LosiAllen.mp3</guid>
<description>Enterprise security governance is not just a vague idea - it can be achieved by implementing a defined, repeatable process with specific activities.</description>
<pubDate>Tue, 26 Jun 2007 11:30:00 -0400</pubDate>
<itunes:duration>19:23</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/22LosiAllen.mp3" length="4655180" type="audio/mp3" />
</item>


<item>
<title>Convergence: Integrating Physical and IT Security</title>
<itunes:author>B. Crowell, B. Contos</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/21CrowellContos.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/21CrowellContos.mp3</guid>
<description>Deploying common solutions for physical and IT security is a cost-effective way to reduce risk and save money.</description>
<pubDate>Tue, 12 Jun 2007 11:30:00 -0400</pubDate>
<itunes:duration>28:43</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/21CrowellContos.mp3" length="6895812" type="audio/mp3" />
</item>


<item>
<title>IT Infrastructure: Tips for Navigating Tough Spots</title>
<itunes:author>S. Huth</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/20HuthKalinowski.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/20HuthKalinowski.mp3</guid>
<description>Organizations occasionally may need to redefine their IT infrastructures - but to succeed, they must be prepared to handle tricky situations.</description>
<pubDate>Tue, 29 May 2007 10:30:00 -0400</pubDate>
<itunes:duration>22:33</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/20HuthKalinowski.mp3" length="5416484" type="audio/mp3" />
</item>


<item>
<title>The Value of De-Identified Personal Data</title>
<itunes:author>S. Ganow</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/19Ganow.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/19Ganow.mp3</guid>
<description>As the legal compliance landscape grows increasingly complex, de-identification can help organizations share data more securely.</description>
<pubDate>Tue, 15 May 2007 10:30:00 -0400</pubDate>
<itunes:duration>31:24</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/19Ganow.mp3" length="7539480" type="audio/mp3" />
</item>


<item>
<title>Adapting to Changing Risk Environments: Operational Resilience</title>
<itunes:author>R. Caralli</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/18Caralli.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/18Caralli.mp3</guid>
<description>Business leaders need to ensure that their organizations can keep critical business processes and services up and running in the face of the unexpected.</description>
<pubDate>Tue, 1 May 2007 10:30:00 -0400</pubDate>
<itunes:duration>24:44</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/18Caralli.mp3" length="5942024" type="audio/mp3" />
</item>


<item>
<title>Computer Forensics for Business Leaders: A Primer</title>
<itunes:author>R. Nolan</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/17Nolan.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/17Nolan.mp3</guid>
<description>Computer forensics is often overlooked when planning an incident response strategy; however, it is a critical part of incident response, and business leaders need to understand how to tackle it.</description>
<pubDate>Tue, 17 Apr 2007 10:30:00 -0400</pubDate>
<itunes:duration>16:31</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/17Nolan.mp3" length="3966520" type="audio/mp3" />
</item>


<item>
<title>The Real Secrets of Incident Management</title>
<itunes:author>G. Killcrece</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/16KillcreceRuefle.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/16KillcreceRuefle.mp3</guid>
<description>Incident management is not just about technical response. It is a cross-enterprise effort that requires good communication and informed risk management.</description>
<pubDate>Tue, 3 Apr 2007 10:30:00 -0400</pubDate>
<itunes:duration>21:16</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/16KillcreceRuefle.mp3" length="5107002" type="audio/mp3" />
</item>


<item>
<title>The Legal Side of Global Security</title>
<itunes:author>J. Westby</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/15Westby.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/15Westby.mp3</guid>
<description>Business leaders, including legal counsel, need to understand how to tackle complex security issues for a global enterprise.</description>
<pubDate>Tue, 20 Mar 2007 10:30:00 -0400</pubDate>
<itunes:duration>25:55</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/15Westby.mp3" length="6223700" type="audio/mp3" />
</item>


<item>
<title>A New Look at the Business of IT Education</title>
<itunes:author>L. Rogers</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/14Rogers.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/14Rogers.mp3</guid>
<description>System administrators increasingly need business savvy in addition to technical skills, and IT training courses must try to keep pace with this trend.</description>
<pubDate>Tue, 6 Mar 2007 10:30:00 -0400</pubDate>
<itunes:duration>17:51</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/14Rogers.mp3" length="4288280" type="audio/mp3" />
</item>


<item>
<title>Crisis Communications During a Security Incident</title>
<itunes:author>K. Kimberland</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/13Kimberland.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/13Kimberland.mp3</guid>
<description>Business leaders need to be prepared to communicate with the media and their staff during a high-profile security incident or crisis.</description>
<pubDate>Tue, 20 Feb 2007 10:30:00 -0400</pubDate>
<itunes:duration>13:41</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/13Kimberland.mp3" length="3288132" type="audio/mp3" />
</item>


<item>
<title>Assuring Mission Success in Complex Environments</title>
<itunes:author>C. Alberts</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/12Alberts.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/12Alberts.mp3</guid>
<description>Analysis tools are needed for assessing complex organizational and technological issues that are well beyond traditional approaches.</description>
<pubDate>Tue, 6 Feb 2007 10:30:00 -0400</pubDate>
<itunes:duration>17:48</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/12Alberts.mp3" length="4275514" type="audio/mp3" />
</item>



<item>
<title>Privacy: The Slow Tipping Point</title>
<itunes:author>A. Acquisti</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/11Acquisti.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/11Acquisti.mp3</guid>
<description>A trend toward more and more data disclosure, as seen in online social networks, may be causing users to become desensitized to privacy breaches in general.</description>
<pubDate>Tue, 23 Jan 2007 10:30:00 -0400</pubDate>
<itunes:duration>17:41</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/11Acquisti.mp3" length="4249520" type="audio/mp3" />
</item>


<item>
<title>Building Staff Competence in Security</title>
<itunes:author>B. Laswell</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/10Laswell.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/10Laswell.mp3</guid>
<description>Practical specifications and guidelines now exist that define necessary knowledge, skills, and competencies for staff members in a range of security positions - from practitioners to managers.</description>
<pubDate>Tue, 9 Jan 2007 10:30:00 -0400</pubDate>
<itunes:duration>21:55</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/10Laswell.mp3" length="5265456" type="audio/mp3" />
</item>



<item>
<title>Inside Defense-in-Depth</title>
<itunes:author>K. Rush</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/9Rush.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/9Rush.mp3</guid>
<description>Defense-in-Depth is one path toward enterprise resilience - the ability to withstand threats and failures. The foundational aspects of compliance management and risk management serve as stepping-stones to and supports for other, more technical aspects.</description>
<pubDate>Tue, 19 Dec 2006 10:30:00 -0400</pubDate>
<itunes:duration>15:43</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/9Rush.mp3" length="3776784" type="audio/mp3" />
</item>


<item>
<title>Evolving Business Models, Threats, and Technologies: A Conversation with CERT's Deputy Director for Technology</title>
<itunes:author>T. Longstaff</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/8Longstaff.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/8Longstaff.mp3</guid>
<description>Business models are evolving. This has challenging implications as security threats become more covert and technologies facilitate information migration.</description>
<pubDate>Tue, 12 Dec 2006 10:30:00 -0400</pubDate>
<itunes:duration>21:39</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/8Longstaff.mp3" length="5201936" type="audio/mp3" />
</item>


<item>
<title>Protecting Against Insider Threat</title>
<itunes:author>D. Cappelli</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/7Cappelli.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/7Cappelli.mp3</guid>
<description>The threat of attack from insiders is real and substantial. Insiders have a significant advantage over others who might want to harm an organization.</description>
<pubDate>Tue, 28 Nov 2006 10:30:00 -0400</pubDate>
<itunes:duration>27:08</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/7Cappelli.mp3" length="6516772" type="audio/mp3" />
</item>



<item>
<title>Change Management: The Security 'X' Factor</title>
<itunes:author>G. Kim</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/6Losi_Kim.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/6Losi_Kim.mp3</guid>
<description>In a recent survey of organizations' security posture, one factor separated high performers from the rest of the pack: change management.</description>
<pubDate>Tue, 14 Nov 2006 10:30:00 -0400</pubDate>
<itunes:duration>18:37</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/6Losi_Kim.mp3" length="4472206" type="audio/mp3" />
</item>



<item>
<title>CERT Lessons Learned: A Conversation with Rich Pethia, Director of CERT</title>
<itunes:author>R. Pethia</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/5Pethia_Discussion.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/5Pethia_Discussion.mp3</guid>
<description>Learn more about the future of CERT and Rich Pethia's view of the Internet security landscape.</description>
<pubDate>Tue, 31 Oct 2006 10:30:00 -0400</pubDate>
<itunes:duration>23:34</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/5Pethia_Discussion.mp3" length="5661472" type="audio/mp3" />
</item>


<item>
<title>Why Leaders Should Care About Security</title>
<itunes:author>J. Allen</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/1Why_Leaders_Should_Care_About_Security.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/1Why_Leaders_Should_Care_About_Security.mp3</guid>
<description>Leaders need to be security conscious and to treat adequate security as a non-negotiable requirement of being in business.</description>
<pubDate>Tue, 17 Oct 2006 12:58:20 -0400</pubDate>
<itunes:duration>17:52</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/1Why_Leaders_Should_Care_About_Security.mp3" length="4191096" type="audio/mp3" />
</item>

<item>
<title>The ROI of Security</title>
<itunes:author>S. Losi</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/2The_ROI_of_Security.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/2The_ROI_of_Security.mp3</guid>
<description>ROI is a useful tool because it enables comparison among investments in a consistent way.</description>
<pubDate>Tue, 17 Oct 2006 12:58:20 -0400</pubDate>
<itunes:duration>21:19</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/2The_ROI_of_Security.mp3" length="5117736" type="audio/mp3" />
</item>

<item>
<title>Proactive Remedies for Rising Threats</title>
<itunes:author>M. Lindner</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/3Proactive_Remedies_for_Rising_Threats.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/3Proactive_Remedies_for_Rising_Threats.mp3</guid>
<description>Threats to information security are increasingly stealthy, but they are on the rise and must be mitigated through sound policy and strategy.</description>
<pubDate>Tue, 17 Oct 2006 12:58:20 -0400</pubDate>
<itunes:duration>19:32</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/3Proactive_Remedies_for_Rising_Threats.mp3" length="4703712" type="audio/mp3" />
</item>


<item>
<title>Compliance vs. Buy-in</title>
<itunes:author>J. Allen</itunes:author>
<link>http://www.cert.org/podcast/mp3/2/4Compliance_vs_Buy-In.mp3</link>
<guid isPermaLink="false">http://www.cert.org/podcast/mp3/2/4Compliance_vs_Buy-In.mp3</guid>
<description>Integrating security into standard business operating processes and procedures is more effective than treating security as a compliance exercise.
</description>
<pubDate>Tue, 17 Oct 2006 12:58:20 -0400</pubDate>
<itunes:duration>8:41</itunes:duration>
<enclosure url="http://www.cert.org/podcast/mp3/2/4Compliance_vs_Buy-In.mp3" length="2082600" type="audio/mp3" />
</item>

  
</channel>
</rss>


