<?xml version="1.0" encoding="utf-8"?>
		<rss version="2.0">
		  <channel>
				<title><![CDATA[Janco Blog and News Site - Articles - Security]]></title>
				<link>http://www.psrorders.com</link>
				<description />
				<language>en-us</language>
				<copyright><![CDATA[http://www.psrorders.com]]></copyright>
				<generator>N/A</generator>
				<webMaster>victor@e-janco.com</webMaster>
				<lastBuildDate>Thu, 28 Aug 2008 10:03:59 MDT</lastBuildDate>
			
				<ttl>20</ttl>

					<item>
					  <title><![CDATA[What is ISO 28000?]]></title>
					  <link>http://www.psrorders.com/articles/3109/1/What-is-ISO-28000/Page1.html</link>
					  <description><![CDATA[
<p style="FONT-SIZE: 8pt"><a href="http://www.e-janco.com/SecurityAudit.html"><img title="" height="110" alt="Security Audit" hspace="2" src="http://www.psrorders.com/content_images/1/audit.gif" width="85" align="right" vspace="2" border="0"/></a>ISO 28000 is a management system specification which has been developed and introduced in response to a demand from the transportation and logistics industry for a common security management standard, with the ultimate objective of improving the overall security of supply chains. </p>]]></description>
					  <author>no@spam.com (Site Administrator)</author>
					  <pubDate>Wed, 06 Feb 2008 14:49:26 MST</pubDate>
					 <guid isPermaLink="true">http://www.psrorders.com/articles/3109/1/What-is-ISO-28000/Page1.html</guid>
					</item>

				

					<item>
					  <title><![CDATA[Top 10 Securtiy Menaces for 2008]]></title>
					  <link>http://www.psrorders.com/articles/2883/1/Top-10-Securtiy-Menaces-for-2008/Page1.html</link>
					  <description><![CDATA[<span style="FONT-SIZE: 8pt; FONT-FAMILY: ">
<p><a href="http://www.e-janco.com/Security.php" target="_blank"><img title="" height="110" alt="Security Policies" hspace="5" src="http://www.psrorders.com/content_images/1/Security.gif" width="85" align="right" vspace="5" border="0"/></a>Twelve cyber security veterans, with significant knowledge about emerging attack patterns, worked together to compile a list of the attacks most likely to <span style="FONT-SIZE: 8pt">cause substantial damage during 2008. </span></p><span style="FONT-SIZE: 8pt">
<p>Participants included Stephen Northcutt, Ed Skoudis, Marc Sachs, Johannes Ullrich, Tom Liston, Eric Cole, Eugene Schultz, Rohit Dhamankar, Amit Yoran, Howard Schmidt, Will Pelgrin, and Alan Paller.</p></span></span>]]></description>
					  <author>no@spam.com (Site Administrator)</author>
					  <pubDate>Mon, 28 Jan 2008 17:05:39 MST</pubDate>
					 <guid isPermaLink="true">http://www.psrorders.com/articles/2883/1/Top-10-Securtiy-Menaces-for-2008/Page1.html</guid>
					</item>

				

					<item>
					  <title><![CDATA[What is VoIP and How Does it Work?]]></title>
					  <link>http://www.psrorders.com/articles/1110/1/What-is-VoIP-and-How-Does-it-Work/Page1.html</link>
					  <description><![CDATA[<a href="http://www.e-janco.com/VoIPRKt.htm" target="_blank">VoIP technology</a> is a one way of sending a voice signal using your Internet connection (IP).&nbsp; This is also known as an analog signal in a medium which is digital, ie, the internet]]></description>
					  <author>no@spam.com (Site Administrator)</author>
					  <pubDate>Thu, 06 Dec 2007 23:23:48 MST</pubDate>
					 <guid isPermaLink="true">http://www.psrorders.com/articles/1110/1/What-is-VoIP-and-How-Does-it-Work/Page1.html</guid>
					</item>

				

					<item>
					  <title><![CDATA[PCI-DSS Security Audit Is Driven by Infrastructure Weaknessess]]></title>
					  <link>http://www.psrorders.com/articles/1055/1/PCI-DSS-Security-Audit-Is-Driven-by-Infrastructure-Weaknessess/Page1.html</link>
					  <description><![CDATA[The reasons why a security audit needs to be implemented to <img title="PCI-DSS Audit program" height="110" alt="PCI-DSS Audit program" hspace="10" src="http://www.psrorders.com/content_images/1/audit.gif" width="85" align="right" vspace="10" border="0"/>meet PCI-DSS requirements are based on the need to fix weakness in the existing infrastructure that many enterprises have.]]></description>
					  <author>no@spam.com (Site Administrator)</author>
					  <pubDate>Wed, 05 Dec 2007 14:49:24 MST</pubDate>
					 <guid isPermaLink="true">http://www.psrorders.com/articles/1055/1/PCI-DSS-Security-Audit-Is-Driven-by-Infrastructure-Weaknessess/Page1.html</guid>
					</item>

				

					<item>
					  <title><![CDATA[The Hard Disk Wipe Process]]></title>
					  <link>http://www.psrorders.com/articles/1054/1/The-Hard-Disk-Wipe-Process/Page1.html</link>
					  <description><![CDATA[<a href="http://www.e-janco.com/DRP_BCP_Audit.html" target="_blank"><img title="DRP Audit Program" height="110" alt="DRP Audit Program" hspace="10" src="http://www.psrorders.com/content_images/1/DRP_BCP_Audit.gif" width="85" align="left" vspace="10" border="0"/></a>One of the biggest possible security leaks, both for private individuals and companies, lies in not being thorough about removing data from old hard disks When data is not wiped or securely deleted from a given hard disk, it becomes possible (if not always easy) for people to attempt and recover the data]]></description>
					  <author>no@spam.com (Site Administrator)</author>
					  <pubDate>Wed, 05 Dec 2007 14:31:29 MST</pubDate>
					 <guid isPermaLink="true">http://www.psrorders.com/articles/1054/1/The-Hard-Disk-Wipe-Process/Page1.html</guid>
					</item>

				

					<item>
					  <title><![CDATA[Risk to PCs, PDAs, and SmartPhone is high on the Internet]]></title>
					  <link>http://www.psrorders.com/articles/811/1/Risk-to-PCs-PDAs-and-SmartPhone-is-high-on-the-Internet/Page1.html</link>
					  <description><![CDATA[
<p style="FONT-SIZE: 8pt"><a href="http://www.e-janco.com/audit_template.html" target="_blank"><img title="Internet Security" style="WIDTH: 127px; HEIGHT: 153px" height="250" alt="Internet Security" hspace="10" src="http://www.psrorders.com/content_images/1/templateaudit.gif" width="200" align="right" vspace="10" border="0"/></a>When&nbsp;your users&nbsp;go on the internet,&nbsp;they have to give&nbsp;provide bits of <a href="http://www.e-janco.com/browser.htm" target="_blank"><img title="Browser & OS Market Share" height="110" alt="Browser & OS Market Share" hspace="5" src="http://www.psrorders.com/content_images/1/Browser_market_Share.gif" width="85" align="left" vspace="5" border="0"/></a>information to be authenticated by the protocols that make the web work; this makes it possible to advertise who your users&nbsp;are, where&nbsp;they are&nbsp;connecting from, and if your users are not careful, a lot more.&nbsp;&nbsp;Some of&nbsp;the information that is &nbsp;handed out freely is your user's IP (Internet Protocol) address, generally in the form of four sets of numbers separated by periods, the country your user's&nbsp;ISP is located in, often times the origination of your user's TCPIP stack, which tells someone if your user is &nbsp;on a Mac, PC or Linux box, your user's browser type, and, because of browser caching for speedy access to previously hit sites, your usr's browser history. </p>]]></description>
					  <author>no@spam.com (Site Administrator)</author>
					  <pubDate>Wed, 28 Nov 2007 10:25:38 MST</pubDate>
					 <guid isPermaLink="true">http://www.psrorders.com/articles/811/1/Risk-to-PCs-PDAs-and-SmartPhone-is-high-on-the-Internet/Page1.html</guid>
					</item>

				

					<item>
					  <title><![CDATA[Network managers need to know about ITIL]]></title>
					  <link>http://www.psrorders.com/articles/688/1/Network-managers-need-to-know-about-ITIL/Page1.html</link>
					  <description><![CDATA[<span style="FONT-SIZE: 8pt">
<p>If you're a network manager, you may have heard some interest from upper management in implementing ITIL. Here's why you shouldn't be afraid...</p>
<p>In its third iteration, IT Infrastructure Library (ITIL) is an IT service management framework surrounded by industry best practices. Developed in the late 1980s by the British government in conjunction with a number of industry experts, ITIL is now considered the industry standard for IT best practices. </p></span>]]></description>
					  <author>no@spam.com (Site Administrator)</author>
					  <pubDate>Sat, 24 Nov 2007 08:03:22 MST</pubDate>
					 <guid isPermaLink="true">http://www.psrorders.com/articles/688/1/Network-managers-need-to-know-about-ITIL/Page1.html</guid>
					</item>

				

					<item>
					  <title><![CDATA[Cellular versus Land Lines After a Disaster]]></title>
					  <link>http://www.psrorders.com/articles/180/1/Cellular-versus-Land-Lines-After-a-Disaster/Page1.html</link>
					  <description><![CDATA[
<p>As more and more individuals opt out of traditional telephone services in favor of cellular phones, the undeniable trend in the telecommunications industry is the development of the ability&nbsp;&nbsp;to allow cell phones to seamlessly switch from the cellular network to a landline network infrastructure, and back again.&nbsp; When a <a href="http://www.e-janco.com/drp.htm" target="_blank">disaster</a> occcurs this can be both a blesssing and a curese.</p>
<p>The dwindling revenues and loss of market share by the traditional telephone companies, along with the growing use of IP networks to carry data <em>and </em>voice, are spurring a business model that is transitioning from distance calling, to a model based on calling a person. For a business this means the ability to communicate via a WiFi network that does not depend on traditional land lines.</p>
<p>In this environment, users have the advantage of utilizing the cellular networks outside, never having to sacrifice connectivity for mobility. As the caller enters an indoor environment, a place where many cell calls get dropped, the converged handset would detect the presence of a wireless network and automatically switch to the lower frequency, preserving call quality throughout the transition. </p>
<p>The result of this would be the emergence of one caller, one phone, and one phone number for the transmission of data and voice. In a business environment, the transition could be made wirelessly through the corporate LANs PBX, whereas in a residential situation, the phone would detect wireless access points that connect directly to a broadband Internet connection, or the PSTN.</p>
<p>The key to the success of&nbsp;this technology&nbsp;is the hand set. While there are many models available today that are capable of switching from cellular to WiFi networks, widespread acceptance is presumed to be contingent on the dropping prices of the handsets, and the types of plans offered by the carriers.</p>
<p>With the release of the Apple iPhone, it was announced that&nbsp; AT&T wireless&nbsp;is the carrier responsible for cellular communication, and presumably, the implementer of cell to WiFi calling plans. </p>
<p>One current example of fixed to mobile convergence is the new AT&T unity plan. With the acquisition of the Cingular, by AT&T,&nbsp;wireless network and all its subscribers, AT&T is offering a community calling plan that allows users to call nationwide to any of AT&T&#8217;s wireless or wireline numbers free of charge.</p>
<p>&nbsp;</p>]]></description>
					  <author>no@spam.com (Site Administrator)</author>
					  <pubDate>Wed, 14 Nov 2007 09:24:19 MST</pubDate>
					 <guid isPermaLink="true">http://www.psrorders.com/articles/180/1/Cellular-versus-Land-Lines-After-a-Disaster/Page1.html</guid>
					</item>

				

					<item>
					  <title><![CDATA[Disaster Recovery / Business Continutiy Template Updated]]></title>
					  <link>http://www.psrorders.com/articles/94/1/Disaster-Recovery--Business-Continutiy-Template-Updated/Page1.html</link>
					  <description><![CDATA[
<p class="MsoNormal" style="MARGIN: 0in 0in 10pt"><span style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'"><a href="http://www.e-janco.com/drp.htm"><img alt="Disaster Planning" src="http://www.e-janco.com/images/Disaster_Recovery.gif" align="left"/></a>The Disaster Recovery / Business Continuity Template version 4.5 has just been released.<span>&nbsp; Janco contiues to update its templates to meet the ever changing requirements of the business environment.</span></span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 10pt"><span style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'"><span></span>With this new version a fully indexed PDF copy of the template is now provided in addition to the two versions of WORD (2003 and 2007).<span>&nbsp; </span></span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 10pt"><span style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'"><span></span>The updates to the template included:</span></p>
<p class="Indent2CharCharChar" style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; tab-stops: list .5in"><span style="FONT-SIZE: 11pt"><span>1.<span style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'">Defined generic metrics for DR/BC success</span></p>
<p class="Indent2CharCharChar" style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; tab-stops: list .5in"><span style="FONT-SIZE: 11pt"><span>2.<span style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'">Business & IT Impact Analysis Questionnaire Updated</span></p>
<p class="Indent2CharCharChar" style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; tab-stops: list .5in"><span style="FONT-SIZE: 11pt"><span>3.<span style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'">Updated references to DRP card</span></p>
<p class="Indent2CharCharChar" style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; tab-stops: list .5in"><span style="FONT-SIZE: 11pt"><span>4.<span style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'">Updated formatting to meet WORD 2007 requirements</span></p>
<p class="Indent2CharCharChar" style="MARGIN: 0in 0in 0pt"><span style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"></span>&nbsp;</p>
<p class="MsoNormal" style="MARGIN: 0in 0in 10pt"><span style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'">The version history for updates to template can be seen at <a href="http://www.e-janco.com/drpversion.htm">http://www.e-janco.com/drpversion.htm</a> and the full Table of Contents with sample pages can be downloaded at <a href="http://www.e-janco.com/Register_drp.asp">http://www.e-janco.com/Register_drp.asp</a> .</span></p>]]></description>
					  <author>no@spam.com (Site Administrator)</author>
					  <pubDate>Mon, 12 Nov 2007 17:42:28 MST</pubDate>
					 <guid isPermaLink="true">http://www.psrorders.com/articles/94/1/Disaster-Recovery--Business-Continutiy-Template-Updated/Page1.html</guid>
					</item>

				

					<item>
					  <title><![CDATA[Wireless opens new vulnerabilities]]></title>
					  <link>http://www.psrorders.com/articles/54/1/Wireless-opens-new-vulnerabilities/Page1.html</link>
					  <description><![CDATA[
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><font size="2"><span style="FONT-FAMILY: 'Frutiger-LightCn','sans-serif'; mso-bidi-font-family: Frutiger-LightCn"><a href="http://www.e-janco.com/Security.htm"></a>Wireless networking lets employees roam around the office with their mobile devices, moving seamlessly from conference room to office to common area without ever losing access to network data, e</span><font face="Arial"><span style="FONT-FAMILY: 'MS Gothic'; mso-bidi-font-family: 'MS Gothic'">‑</span><span style="FONT-FAMILY: 'Frutiger-LightCn','sans-serif'; mso-bidi-font-family: Frutiger-LightCn">mail and the Internet.<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p></o:p></span></font></font></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><span style="FONT-FAMILY: 'Frutiger-LightCn','sans-serif'; mso-bidi-font-family: Frutiger-LightCn"><font size="2"></font></span>&nbsp;</p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><span style="FONT-FAMILY: 'Frutiger-LightCn','sans-serif'; mso-bidi-font-family: Frutiger-LightCn"><font size="2">The problem with this is wireless signals can be picked up by outside parties. Internal devices that exchange data with the wireless hardware are already behind the gateway firewall, so intrusions that exploit a wireless signal can have devastating results in terms of data theft.<o:p></o:p></font></span></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><font size="2"><span style="FONT-FAMILY: 'Frutiger-LightCn','sans-serif'; mso-bidi-font-family: Frutiger-LightCn"></span></font>&nbsp;</p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><font size="2"><span style="FONT-FAMILY: 'Frutiger-LightCn','sans-serif'; mso-bidi-font-family: Frutiger-LightCn">Wireless encryption standards include Wired Equivalent Privacy (WEP) and Wi</span><font face="Arial"><span style="FONT-FAMILY: 'MS Gothic'; mso-bidi-font-family: 'MS Gothic'">‑</span><span style="FONT-FAMILY: 'Frutiger-LightCn','sans-serif'; mso-bidi-font-family: Frutiger-LightCn">Fi Protected Access (WPA), the former is an old protocol that is fairly easy to crack with readily available tools; the latter is a more flexible and powerful technology.<o:p></o:p></span></font></font></p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><span style="FONT-FAMILY: 'Frutiger-LightCn','sans-serif'; mso-bidi-font-family: Frutiger-LightCn"><font size="2"></font></span>&nbsp;</p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><span style="FONT-FAMILY: 'Frutiger-LightCn','sans-serif'; mso-bidi-font-family: Frutiger-LightCn"><font size="2">The latest wireless networking products support both and include firewall and other security features, too.<o:p></o:p></font></span></p>]]></description>
					  <author>no@spam.com (Site Administrator)</author>
					  <pubDate>Sat, 10 Nov 2007 16:22:27 MST</pubDate>
					 <guid isPermaLink="true">http://www.psrorders.com/articles/54/1/Wireless-opens-new-vulnerabilities/Page1.html</guid>
					</item>

				
				  </channel>
				</rss>
			