<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Insights: the Aveksa Blog</title>
	<atom:link href="http://blog.aveksa.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.aveksa.com</link>
	<description>Thoughts and Discussions on Access Governance</description>
	<lastBuildDate>Mon, 09 Jan 2012 02:44:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.aveksa.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Insights: the Aveksa Blog</title>
		<link>http://blog.aveksa.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.aveksa.com/osd.xml" title="Insights: the Aveksa Blog" />
	<atom:link rel='hub' href='http://blog.aveksa.com/?pushpress=hub'/>
		<item>
		<title>Aveksa Named a Leader in Gartner Magic Quadrant</title>
		<link>http://blog.aveksa.com/2012/01/08/aveksa-named-a-leader-in-gartner-magic-quadrant/</link>
		<comments>http://blog.aveksa.com/2012/01/08/aveksa-named-a-leader-in-gartner-magic-quadrant/#comments</comments>
		<pubDate>Mon, 09 Jan 2012 02:44:26 +0000</pubDate>
		<dc:creator>Jason Garbis</dc:creator>
				<category><![CDATA[Access Governance]]></category>
		<category><![CDATA[Analyst Reports]]></category>
		<category><![CDATA[access governance]]></category>
		<category><![CDATA[analyst reports]]></category>

		<guid isPermaLink="false">http://blog.aveksa.com/?p=463</guid>
		<description><![CDATA[We’re pleased to announce that Aveksa was named a Leader in the new &#8220;Magic Quadrant for Identity and Access Governance”, published last month by Gartner. In the report, the authors (Gartner Analysts Earl Perkins and Perry Carpenter) state: &#8220;managing identity &#8230; <a href="http://blog.aveksa.com/2012/01/08/aveksa-named-a-leader-in-gartner-magic-quadrant/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.aveksa.com&amp;blog=22100103&amp;post=463&amp;subd=aveksablog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>We’re pleased to announce that Aveksa was named a <em>Leader</em> in the new &#8220;Magic Quadrant for Identity and Access Governance”, published last month by Gartner. In the report, the authors (Gartner Analysts Earl Perkins and Perry Carpenter) state: &#8220;managing identity and access is more than an operational concern. Rather, it requires governance of identity and entitlement life cycles in the enterprise.&#8221;</p>
<p>They also note that the need for (and recognition of the need for) identity and access management governance is growing – they estimate that IAG-led projects will double from one-third of all IAM projects, to two-thirds by 2013.</p>
<p>We’re happy to have been named a leader in this report, and are grateful to our customers &#8212; the reason for our success.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/aveksablog.wordpress.com/463/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/aveksablog.wordpress.com/463/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/aveksablog.wordpress.com/463/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/aveksablog.wordpress.com/463/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/aveksablog.wordpress.com/463/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/aveksablog.wordpress.com/463/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/aveksablog.wordpress.com/463/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/aveksablog.wordpress.com/463/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/aveksablog.wordpress.com/463/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/aveksablog.wordpress.com/463/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/aveksablog.wordpress.com/463/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/aveksablog.wordpress.com/463/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/aveksablog.wordpress.com/463/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/aveksablog.wordpress.com/463/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.aveksa.com&amp;blog=22100103&amp;post=463&amp;subd=aveksablog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.aveksa.com/2012/01/08/aveksa-named-a-leader-in-gartner-magic-quadrant/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/be5b50eb8fafc77ef42f78e99e7d11fc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aveksablog</media:title>
		</media:content>
	</item>
		<item>
		<title>SharePoint Access a Key Factor in Bradley Manning Leaks</title>
		<link>http://blog.aveksa.com/2011/12/18/sharepoint-access-a-key-factor-in-bradley-manning-leaks/</link>
		<comments>http://blog.aveksa.com/2011/12/18/sharepoint-access-a-key-factor-in-bradley-manning-leaks/#comments</comments>
		<pubDate>Mon, 19 Dec 2011 03:31:25 +0000</pubDate>
		<dc:creator>Jason Garbis</dc:creator>
				<category><![CDATA[Bradley Manning]]></category>
		<category><![CDATA[Data Access Governance]]></category>
		<category><![CDATA[SharePoint]]></category>
		<category><![CDATA[WikiLeaks]]></category>
		<category><![CDATA[data access governance]]></category>
		<category><![CDATA[SharePoint Security]]></category>

		<guid isPermaLink="false">http://aveksablog.wordpress.com/?p=458</guid>
		<description><![CDATA[According to the Army’s digital forensic expert, accused WikiLeaker Bradley Manning obtained classified Guantanamo Bay detainee assessments from a SharePoint site, and subsequently leaked them to WikiLeaks. Wired magazine states that the forensic analyst discovered “scripts on Manning’s computer that &#8230; <a href="http://blog.aveksa.com/2011/12/18/sharepoint-access-a-key-factor-in-bradley-manning-leaks/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.aveksa.com&amp;blog=22100103&amp;post=458&amp;subd=aveksablog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>According to the Army’s digital forensic expert, accused WikiLeaker Bradley Manning obtained classified Guantanamo Bay detainee assessments from a SharePoint site, and subsequently leaked them to WikiLeaks. <a title="Wired Magazine" href="http://www.wired.com/threatlevel/2011/12/cables-scripts-manning/" target="_blank">Wired magazine</a> states that the forensic analyst discovered “scripts on Manning’s computer that pointed to a Microsoft SharePoint server holding the Gitmo documents. He ran the scripts to download the documents, then downloaded the ones that WikiLeaks had published and found they were the same” [1]</p>
<p>Unauthorized SharePoint access is a common security gap, in many organizations.  We’ve seen numerous customers struggling with this, unable to get their arms around who has access to which SharePoint site, and what types of data (classification, risk level, and content) are thus accessible.</p>
<p>While most organizations don’t need to worry about employee access to classified information, rogue access to confidential corporate information can nonetheless be damaging and expensive – as clearly demonstrated by the RSA and Sony incidents this year.</p>
<p>I’m sure there will be additional Information Security-related aspects of the ongoing Manning hearing, and we’ll continue to cover them here.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/aveksablog.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/aveksablog.wordpress.com/458/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/aveksablog.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/aveksablog.wordpress.com/458/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/aveksablog.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/aveksablog.wordpress.com/458/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/aveksablog.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/aveksablog.wordpress.com/458/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/aveksablog.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/aveksablog.wordpress.com/458/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/aveksablog.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/aveksablog.wordpress.com/458/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/aveksablog.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/aveksablog.wordpress.com/458/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.aveksa.com&amp;blog=22100103&amp;post=458&amp;subd=aveksablog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.aveksa.com/2011/12/18/sharepoint-access-a-key-factor-in-bradley-manning-leaks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/be5b50eb8fafc77ef42f78e99e7d11fc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aveksablog</media:title>
		</media:content>
	</item>
		<item>
		<title>Bradley Manning Hearing Starts Today</title>
		<link>http://blog.aveksa.com/2011/12/16/bradley-manning-hearing-starts-today/</link>
		<comments>http://blog.aveksa.com/2011/12/16/bradley-manning-hearing-starts-today/#comments</comments>
		<pubDate>Fri, 16 Dec 2011 14:38:32 +0000</pubDate>
		<dc:creator>Jason Garbis</dc:creator>
				<category><![CDATA[Bradley Manning]]></category>
		<category><![CDATA[WikiLeaks]]></category>

		<guid isPermaLink="false">http://aveksablog.wordpress.com/?p=452</guid>
		<description><![CDATA[The much-anticipated hearing for accused leaker Bradley Manning starts today. This is not a trial for establishing guilt or innocence, but rather the military equivalent of a grand jury hearing &#8212; giving prosecutors and defense the opportunity to present information, intended &#8230; <a href="http://blog.aveksa.com/2011/12/16/bradley-manning-hearing-starts-today/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.aveksa.com&amp;blog=22100103&amp;post=452&amp;subd=aveksablog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The much-anticipated hearing for accused leaker Bradley Manning starts today. This is not a trial for establishing guilt or innocence, but rather the military equivalent of a grand jury hearing &#8212; giving prosecutors and defense the opportunity to present information, intended to convince a judge that there is enough to proceed to a trial.</p>
<p>There&#8217;s been a tremendous amount of media coverage and protest around this, related to both Manning&#8217;s actions, as well as the government&#8217;s treatment of the accused.  Staying away from the political aspects of these,  we&#8217;ll be monitoring the Information Security aspects of the hearing.  Portions of the hearing will be open to journalists, while some will be closed to the public, due to security considerations.</p>
<p>The Guardian has a good overview, <a href="http://www.guardian.co.uk/world/2011/dec/16/bradley-manning-military-hearing-wikileaks">here</a> , and their journalist @Edpilkington  is live tweeting the trial.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/aveksablog.wordpress.com/452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/aveksablog.wordpress.com/452/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/aveksablog.wordpress.com/452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/aveksablog.wordpress.com/452/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/aveksablog.wordpress.com/452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/aveksablog.wordpress.com/452/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/aveksablog.wordpress.com/452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/aveksablog.wordpress.com/452/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/aveksablog.wordpress.com/452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/aveksablog.wordpress.com/452/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/aveksablog.wordpress.com/452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/aveksablog.wordpress.com/452/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/aveksablog.wordpress.com/452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/aveksablog.wordpress.com/452/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.aveksa.com&amp;blog=22100103&amp;post=452&amp;subd=aveksablog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.aveksa.com/2011/12/16/bradley-manning-hearing-starts-today/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/be5b50eb8fafc77ef42f78e99e7d11fc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aveksablog</media:title>
		</media:content>
	</item>
		<item>
		<title>Questions in Advance of the Bradley Manning Hearing</title>
		<link>http://blog.aveksa.com/2011/12/09/questions-in-advance-of-the-bradley-manning-hearing/</link>
		<comments>http://blog.aveksa.com/2011/12/09/questions-in-advance-of-the-bradley-manning-hearing/#comments</comments>
		<pubDate>Fri, 09 Dec 2011 03:08:49 +0000</pubDate>
		<dc:creator>Jason Garbis</dc:creator>
				<category><![CDATA[Bradley Manning]]></category>
		<category><![CDATA[WikiLeaks]]></category>

		<guid isPermaLink="false">http://blog.aveksa.com/?p=449</guid>
		<description><![CDATA[Next week’s military assignment of accused leaker Bradley Manning promises to be interesting at many different levels, with defense and prosecution sparring in the press over witnesses and legal strategies. Putting aside the political and legal aspects, we will be &#8230; <a href="http://blog.aveksa.com/2011/12/09/questions-in-advance-of-the-bradley-manning-hearing/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.aveksa.com&amp;blog=22100103&amp;post=449&amp;subd=aveksablog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Next week’s military assignment of accused leaker Bradley Manning promises to be interesting at many different levels, with defense and prosecution sparring in the press over witnesses and legal strategies. Putting aside the political and legal aspects, we will be watching this closely to see how much of a role access management plays, and to find some answers to questions that are relevant to us as practitioners in this space.  Specifically, did the Army know what classified information Private Manning had access to? Would they have been able to effectively restrict his access to it, had they chosen to do so? Did they try, and fail to prevent this? Was there a sufficiently well-thought out and well-executed data security strategy in place, for this sensitive information?</p>
<p>According to publicly released defense documents[1], the Army was not doing an at-all adequate job in securing the data resources on shared, secure systems  – one of the witnesses “will testify that the information assurance procedures were not being followed by the brigade” and that “the brigade did not have an Approval to Operate (ATO) or an Interim Approval to Operate (IATO) for their network. Additionally, the brigade did not receive a formal IA [Information Assurance] certification and accreditation inspection during its tour, contrary to the guidance in MNF-I Directives”[2].</p>
<p>Like many of the enterprises I speak with, this organization had both internal and external information security guidelines, and was not doing a good-enough job meeting them. Could an effective Access Governance solution have prevented these leaks from occurring?  This certainly appears to be the case, and we look forward to learning more next week, as the hearing begins.</p>
<p>[1] DEFENSE REQUEST FOR ARTICLE 32 WITNESSES http://www.wired.com/images_blogs/threatlevel/2011/12/Defense-Article-32-Witness-List.pdf<br />
[2] ibid, page 9</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/aveksablog.wordpress.com/449/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/aveksablog.wordpress.com/449/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/aveksablog.wordpress.com/449/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/aveksablog.wordpress.com/449/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/aveksablog.wordpress.com/449/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/aveksablog.wordpress.com/449/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/aveksablog.wordpress.com/449/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/aveksablog.wordpress.com/449/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/aveksablog.wordpress.com/449/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/aveksablog.wordpress.com/449/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/aveksablog.wordpress.com/449/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/aveksablog.wordpress.com/449/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/aveksablog.wordpress.com/449/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/aveksablog.wordpress.com/449/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.aveksa.com&amp;blog=22100103&amp;post=449&amp;subd=aveksablog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.aveksa.com/2011/12/09/questions-in-advance-of-the-bradley-manning-hearing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/be5b50eb8fafc77ef42f78e99e7d11fc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aveksablog</media:title>
		</media:content>
	</item>
		<item>
		<title>Account versus Entitlement Reviews (part 2)</title>
		<link>http://blog.aveksa.com/2011/12/06/account-versus-entitlement-reviews-part-2/</link>
		<comments>http://blog.aveksa.com/2011/12/06/account-versus-entitlement-reviews-part-2/#comments</comments>
		<pubDate>Tue, 06 Dec 2011 03:24:33 +0000</pubDate>
		<dc:creator>Jason Garbis</dc:creator>
				<category><![CDATA[Access Governance]]></category>
		<category><![CDATA[access governance]]></category>

		<guid isPermaLink="false">http://aveksablog.wordpress.com/?p=447</guid>
		<description><![CDATA[Continuing from my previous entryon this topic, I’m continuing the discussion  about different approaches toward capturing user entitlement information, specifically considering the merits of doing so at the account level versus at the entitlement level. Typically, having a system that provides &#8230; <a href="http://blog.aveksa.com/2011/12/06/account-versus-entitlement-reviews-part-2/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.aveksa.com&amp;blog=22100103&amp;post=447&amp;subd=aveksablog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Continuing from my <a href="http://blog.aveksa.com/2011/11/03/account-versus-entitlement-reviews/">previous entry</a>on this topic, I’m continuing the discussion  about different approaches toward capturing user entitlement information, specifically considering the merits of doing so at the account level versus at the entitlement level. Typically, having a system that provides <em>more</em> insight into the details of which application (or data) entitlements a user has is <em>better</em> – so that the appropriate people in the organization can make better, more informed, and more granular access decisions.</p>
<p>But, in two scenarios, it does make sense to capture and use data just at an account level. The first situation is in a period of transition – where the organization may not yet have the infrastructure or capability to capture, normalize, process, and present detailed entitlements to reviewers (or to users requesting access).  This is a perfectly fine approach, and can be quite useful as a way to put in place business processes for review or access request, and to begin to familiarize end users with them – as long as there’s a concrete plan to ultimately move to reviewing and requesting at an entitlement level. These shouldn&#8217;t be left indefinitely at an account level – it simply doesn&#8217;t provide enough visibility or control, isn’t audit-proof, and will likely lead to a false sense of security.</p>
<p>The second scenario is when the information about an account’s existence is in fact sufficient for its designated purpose.  For example, one of our customers keeps track of which employees have accounts on their mainframe system. None of the applications on the mainframe are subject to entitlement reviews, so they don’t need to capture the entitlement details. Instead, they use the account information as part of their <em>Leaver</em> process – so that when a person departs the organization, IT has a clear view of whether or not a mainframe account needs to be deprovisioned, and can act accordingly. This is a simple, yet effective scenario, and a great example of the value of having an Access Management Database (XMDB) with complete information about identities and access, even beyond traditional focus of access governance systems</p>
<p>In general, of course, organizations need to capture and operationalize with a detailed view of user entitlements, in order to meet their access-related security and compliance goals.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/aveksablog.wordpress.com/447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/aveksablog.wordpress.com/447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/aveksablog.wordpress.com/447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/aveksablog.wordpress.com/447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/aveksablog.wordpress.com/447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/aveksablog.wordpress.com/447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/aveksablog.wordpress.com/447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/aveksablog.wordpress.com/447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/aveksablog.wordpress.com/447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/aveksablog.wordpress.com/447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/aveksablog.wordpress.com/447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/aveksablog.wordpress.com/447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/aveksablog.wordpress.com/447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/aveksablog.wordpress.com/447/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.aveksa.com&amp;blog=22100103&amp;post=447&amp;subd=aveksablog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.aveksa.com/2011/12/06/account-versus-entitlement-reviews-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/be5b50eb8fafc77ef42f78e99e7d11fc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aveksablog</media:title>
		</media:content>
	</item>
		<item>
		<title>Great Reporting by Wired Magazine on How False Illinois SCADA Attack Came To Be</title>
		<link>http://blog.aveksa.com/2011/12/01/great-reporting-by-wired-magazine-on-how-false-illinois-scada-attack-came-to-be/</link>
		<comments>http://blog.aveksa.com/2011/12/01/great-reporting-by-wired-magazine-on-how-false-illinois-scada-attack-came-to-be/#comments</comments>
		<pubDate>Thu, 01 Dec 2011 15:17:43 +0000</pubDate>
		<dc:creator>Jason Garbis</dc:creator>
				<category><![CDATA[SCADA]]></category>
		<category><![CDATA[Security Breaches]]></category>

		<guid isPermaLink="false">http://blog.aveksa.com/?p=444</guid>
		<description><![CDATA[Here&#8217;s a terrific, clear article from Wired Magazine, explaining the series of events and mis-steps behind last week&#8217;s erroneous report and subsequent news maelstrom on the (fictional) Cyber-attack on the Illinois water-control system. Even though this turned out to be &#8230; <a href="http://blog.aveksa.com/2011/12/01/great-reporting-by-wired-magazine-on-how-false-illinois-scada-attack-came-to-be/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.aveksa.com&amp;blog=22100103&amp;post=444&amp;subd=aveksablog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.wired.com/threatlevel/2011/11/water-pump-hack-mystery-solved/" target="_blank">Here&#8217;s</a> a terrific, clear article from Wired Magazine, explaining the series of events and mis-steps behind last week&#8217;s erroneous report and subsequent news maelstrom on the (fictional) Cyber-attack on the Illinois water-control system.</p>
<p>Even though this turned out to be a simple mechanical failure, and not a cyber-attack, we <strong>must</strong> keep in mind that these SCADA systems have in fact been breached successfully (see my blog posting below), and must strengthen our security accordingly.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/aveksablog.wordpress.com/444/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/aveksablog.wordpress.com/444/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/aveksablog.wordpress.com/444/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/aveksablog.wordpress.com/444/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/aveksablog.wordpress.com/444/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/aveksablog.wordpress.com/444/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/aveksablog.wordpress.com/444/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/aveksablog.wordpress.com/444/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/aveksablog.wordpress.com/444/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/aveksablog.wordpress.com/444/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/aveksablog.wordpress.com/444/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/aveksablog.wordpress.com/444/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/aveksablog.wordpress.com/444/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/aveksablog.wordpress.com/444/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.aveksa.com&amp;blog=22100103&amp;post=444&amp;subd=aveksablog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.aveksa.com/2011/12/01/great-reporting-by-wired-magazine-on-how-false-illinois-scada-attack-came-to-be/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/be5b50eb8fafc77ef42f78e99e7d11fc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aveksablog</media:title>
		</media:content>
	</item>
		<item>
		<title>FBI: Hackers *Have* Accessed City Infrastructures via Compromised SCADA Systems</title>
		<link>http://blog.aveksa.com/2011/11/29/fbi-hackers-have-accessed-city-infrastructures-via-compromised-scada-systems/</link>
		<comments>http://blog.aveksa.com/2011/11/29/fbi-hackers-have-accessed-city-infrastructures-via-compromised-scada-systems/#comments</comments>
		<pubDate>Tue, 29 Nov 2011 19:48:54 +0000</pubDate>
		<dc:creator>Jason Garbis</dc:creator>
				<category><![CDATA[SCADA]]></category>
		<category><![CDATA[Security Breaches]]></category>
		<category><![CDATA[security breaches]]></category>

		<guid isPermaLink="false">http://blog.aveksa.com/?p=442</guid>
		<description><![CDATA[According to the FBI Cyber Division, hackers have accessed the SCADA (Supervisory Control and Data Acquisition) infrastructures in 3 major US cities. As reported today in Information Age, the FBI&#8217;s deputy assistant director stated that 3 US cities have recently &#8230; <a href="http://blog.aveksa.com/2011/11/29/fbi-hackers-have-accessed-city-infrastructures-via-compromised-scada-systems/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.aveksa.com&amp;blog=22100103&amp;post=442&amp;subd=aveksablog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>According to the FBI Cyber Division, hackers have accessed the SCADA (Supervisory Control and Data Acquisition) infrastructures in 3 major US cities. As reported today in <a href="http://www.information-age.com/channels/security-and-continuity/news/1676243/hackers-accessed-city-infrastructure-via-scada-fbi.thtml">Information Age</a>, the FBI&#8217;s deputy assistant director stated that 3 US cities have recently had SCADA systems taken over by hackers.</p>
<p>Fortunately these hackers did not cause any damage, but this certainly does raise the profile and the risk associated with such industrial control systems.  Please, take the time to make a baseline assessment of your infrastructure, and get clear visibility into whether you have these kinds of industrial control systems, and who has access to them.</p>
<p>Was this related to the alleged Illinois SCADA compromise? According to Information Age, the FBI speaker &#8220;would not clarify&#8221; whether it was related.  However, I believe that we need to take at face value yesterday&#8217;s assertion from the FBI and the US Department of Homeland Security that no intrusion  occurred in Illinois, at the Curran-Gardner Public Water District.</p>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/aveksablog.wordpress.com/442/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/aveksablog.wordpress.com/442/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/aveksablog.wordpress.com/442/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/aveksablog.wordpress.com/442/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/aveksablog.wordpress.com/442/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/aveksablog.wordpress.com/442/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/aveksablog.wordpress.com/442/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/aveksablog.wordpress.com/442/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/aveksablog.wordpress.com/442/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/aveksablog.wordpress.com/442/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/aveksablog.wordpress.com/442/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/aveksablog.wordpress.com/442/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/aveksablog.wordpress.com/442/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/aveksablog.wordpress.com/442/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.aveksa.com&amp;blog=22100103&amp;post=442&amp;subd=aveksablog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.aveksa.com/2011/11/29/fbi-hackers-have-accessed-city-infrastructures-via-compromised-scada-systems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/be5b50eb8fafc77ef42f78e99e7d11fc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aveksablog</media:title>
		</media:content>
	</item>
		<item>
		<title>Take a Deep Breath – The Alleged Illinois Water District SCADA Hack Did Not Occur (But, Put In Place a Thoughtful Security Program &#8212; Now)</title>
		<link>http://blog.aveksa.com/2011/11/28/take-a-deep-breath-the-alleged-illinois-water-district-scada-hack-did-not-occur-but-put-in-place-a-thoughtful-security-program-now/</link>
		<comments>http://blog.aveksa.com/2011/11/28/take-a-deep-breath-the-alleged-illinois-water-district-scada-hack-did-not-occur-but-put-in-place-a-thoughtful-security-program-now/#comments</comments>
		<pubDate>Mon, 28 Nov 2011 18:49:37 +0000</pubDate>
		<dc:creator>Jason Garbis</dc:creator>
				<category><![CDATA[Security Breaches]]></category>

		<guid isPermaLink="false">http://blog.aveksa.com/?p=439</guid>
		<description><![CDATA[According to the US Department of Homeland Security’s ICS-CERT (Industrial Control Systems Cyber Emergency Response Team), “ICS-CERT and the FBI found no evidence of a cyber intrusion” and that “there is no evidence to support claims made in the initial &#8230; <a href="http://blog.aveksa.com/2011/11/28/take-a-deep-breath-the-alleged-illinois-water-district-scada-hack-did-not-occur-but-put-in-place-a-thoughtful-security-program-now/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.aveksa.com&amp;blog=22100103&amp;post=439&amp;subd=aveksablog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>According to the US Department of Homeland Security’s ICS-CERT (Industrial Control Systems Cyber Emergency Response Team), “ICS-CERT and the FBI found no evidence of a cyber intrusion” and that “there is no evidence to support claims made in the initial Illinois STIC report&#8230;that any credentials were stolen, or that the vendor was involved in any malicious activity” [1]</p>
<p>While this is a relief, it’s distressing to see, based on commentary and media coverage, how vulnerable these industrial control systems apparently are.  And, in a bitter irony, the coverage and attention raised by what turned out to be a media event (as opposed to an actual security event), will in fact raise the likelihood of future attacks on industrial control systems.</p>
<p>So, organizations with these kinds of control systems in place &#8212; please, do two things, immediately:</p>
<ol>
<li>Read through the Department of Homeland Security document <a href="http://www.us-cert.gov/control_systems/practices/documents/Defense_in_Depth_Oct09.pdf">Recommended Practice: Improving Industrial Control Systems Cybersecurity with Defense-In-Depth Strategies</a></li>
<li>Evaluate and improve your access management systems, to ensure that you have an effective program enforcing the principle of least access.</li>
</ol>
<p>[1] <a href="http://www.us-cert.gov/control_systems/pdf/ICSB-11-327-01.pdf">http://www.us-cert.gov/control_systems/pdf/ICSB-11-327-01.pdf</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/aveksablog.wordpress.com/439/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/aveksablog.wordpress.com/439/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/aveksablog.wordpress.com/439/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/aveksablog.wordpress.com/439/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/aveksablog.wordpress.com/439/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/aveksablog.wordpress.com/439/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/aveksablog.wordpress.com/439/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/aveksablog.wordpress.com/439/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/aveksablog.wordpress.com/439/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/aveksablog.wordpress.com/439/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/aveksablog.wordpress.com/439/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/aveksablog.wordpress.com/439/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/aveksablog.wordpress.com/439/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/aveksablog.wordpress.com/439/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.aveksa.com&amp;blog=22100103&amp;post=439&amp;subd=aveksablog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.aveksa.com/2011/11/28/take-a-deep-breath-the-alleged-illinois-water-district-scada-hack-did-not-occur-but-put-in-place-a-thoughtful-security-program-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/be5b50eb8fafc77ef42f78e99e7d11fc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aveksablog</media:title>
		</media:content>
	</item>
		<item>
		<title>Upcoming Trial for Accused WikiLeaks Source Bradley Manning</title>
		<link>http://blog.aveksa.com/2011/11/23/upcoming-trial-for-accused-wikileaks-source-bradley-manning/</link>
		<comments>http://blog.aveksa.com/2011/11/23/upcoming-trial-for-accused-wikileaks-source-bradley-manning/#comments</comments>
		<pubDate>Wed, 23 Nov 2011 04:03:36 +0000</pubDate>
		<dc:creator>Jason Garbis</dc:creator>
				<category><![CDATA[Bradley Manning]]></category>
		<category><![CDATA[WikiLeaks]]></category>

		<guid isPermaLink="false">http://blog.aveksa.com/?p=436</guid>
		<description><![CDATA[Private Bradley Manning, who has been charged with 22 counts associated with the leaks of classified information to WikiLeaks, will be facing a pre-trial hearing starting December 16, during which his defense attorneys plan to call 50 witnesses to testify. &#8230; <a href="http://blog.aveksa.com/2011/11/23/upcoming-trial-for-accused-wikileaks-source-bradley-manning/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.aveksa.com&amp;blog=22100103&amp;post=436&amp;subd=aveksablog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Private Bradley Manning, who has been charged with 22 counts associated with the leaks of classified information to WikiLeaks, will be facing a pre-trial hearing starting December 16, during which his defense attorneys plan to call 50 witnesses to testify. Most of this will be open to the public, and will likely be covered in-depth by the media.</p>
<p>From an information security perspective, I’m particularly interested in seeing how much of a role access management plays in both the prosecution and defense arguments. According to a <a title="Wired Magazine article" href="http://www.wired.com/threatlevel/2011/11/manning-50-witnesses/" target="_blank">Wired Magazine article</a>, expert testimony “might include assessments of forensic evidence from classified networks and databases that contained the sensitive documents Manning is charged with downloading and leaking.”</p>
<p>We’ll be using this blog to discuss the information security aspects of the trial, and explore any implications to the larger identity management industry.</p>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/aveksablog.wordpress.com/436/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/aveksablog.wordpress.com/436/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/aveksablog.wordpress.com/436/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/aveksablog.wordpress.com/436/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/aveksablog.wordpress.com/436/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/aveksablog.wordpress.com/436/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/aveksablog.wordpress.com/436/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/aveksablog.wordpress.com/436/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/aveksablog.wordpress.com/436/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/aveksablog.wordpress.com/436/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/aveksablog.wordpress.com/436/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/aveksablog.wordpress.com/436/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/aveksablog.wordpress.com/436/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/aveksablog.wordpress.com/436/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.aveksa.com&amp;blog=22100103&amp;post=436&amp;subd=aveksablog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.aveksa.com/2011/11/23/upcoming-trial-for-accused-wikileaks-source-bradley-manning/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/be5b50eb8fafc77ef42f78e99e7d11fc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aveksablog</media:title>
		</media:content>
	</item>
		<item>
		<title>IT Business Edge: Making It Easier to Do the Right GRC Thing</title>
		<link>http://blog.aveksa.com/2011/11/22/it-business-edge-making-it-easier-to-do-the-right-grc-thing/</link>
		<comments>http://blog.aveksa.com/2011/11/22/it-business-edge-making-it-easier-to-do-the-right-grc-thing/#comments</comments>
		<pubDate>Tue, 22 Nov 2011 21:36:49 +0000</pubDate>
		<dc:creator>Jason Garbis</dc:creator>
				<category><![CDATA[Access Governance]]></category>
		<category><![CDATA[Media Coverage]]></category>
		<category><![CDATA[access governance]]></category>
		<category><![CDATA[media coverage]]></category>

		<guid isPermaLink="false">http://blog.aveksa.com/?p=434</guid>
		<description><![CDATA[Here&#8217;s a link to a new article in IT Business Edge, summarizing a discussion with Aveksa CEO Vick Vaishnavi.  In this article, the author succinctly explains the challenges around governing user access, and how Aveksa&#8217;s solutions can help improve security &#8230; <a href="http://blog.aveksa.com/2011/11/22/it-business-edge-making-it-easier-to-do-the-right-grc-thing/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.aveksa.com&amp;blog=22100103&amp;post=434&amp;subd=aveksablog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a title="IT Business Edge: Aveksa" href="http://www.itbusinessedge.com/cm/blogs/vizard/making-it-easier-to-do-the-right-grc-thing/?cs=49146" target="_blank">Here&#8217;s a link</a> to a new article in IT Business Edge, summarizing a discussion with Aveksa CEO Vick Vaishnavi.  In this article, the author succinctly explains the challenges around governing user access, and how Aveksa&#8217;s solutions can help improve security and efficiency.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/aveksablog.wordpress.com/434/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/aveksablog.wordpress.com/434/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/aveksablog.wordpress.com/434/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/aveksablog.wordpress.com/434/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/aveksablog.wordpress.com/434/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/aveksablog.wordpress.com/434/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/aveksablog.wordpress.com/434/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/aveksablog.wordpress.com/434/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/aveksablog.wordpress.com/434/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/aveksablog.wordpress.com/434/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/aveksablog.wordpress.com/434/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/aveksablog.wordpress.com/434/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/aveksablog.wordpress.com/434/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/aveksablog.wordpress.com/434/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.aveksa.com&amp;blog=22100103&amp;post=434&amp;subd=aveksablog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.aveksa.com/2011/11/22/it-business-edge-making-it-easier-to-do-the-right-grc-thing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/be5b50eb8fafc77ef42f78e99e7d11fc?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aveksablog</media:title>
		</media:content>
	</item>
	</channel>
</rss>
