<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><description>Hi.  This is my weblog.</description><title>Alex Hutton</title><generator>Tumblr (3.0; @alexhutton)</generator><link>http://alexhutton.com/</link><item><title>Gartner’s worst case for 2009 IT budgets isn’t so bad | Between the Lines | ZDNet.com</title><description>&lt;a href="http://blogs.zdnet.com/BTL/?p=10403"&gt;Gartner’s worst case for 2009 IT budgets isn’t so bad | Between the Lines | ZDNet.com&lt;/a&gt;</description><link>http://alexhutton.com/post/54528483</link><guid>http://alexhutton.com/post/54528483</guid><pubDate>Tue, 14 Oct 2008 12:13:08 -0400</pubDate></item><item><title>AESRM - Projects and Publications</title><description>&lt;a href="http://www.aesrm.org/projects_and_publications.html"&gt;AESRM - Projects and Publications&lt;/a&gt;</description><link>http://alexhutton.com/post/54528479</link><guid>http://alexhutton.com/post/54528479</guid><pubDate>Tue, 14 Oct 2008 12:13:07 -0400</pubDate></item><item><title>Our Blog Got High Ratings!</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=482"&gt;Our Blog Got High Ratings!&lt;/a&gt;: &lt;p&gt;Tooting our own horn on Monday morning, the excellent &lt;em&gt;&lt;strong&gt;Thinking Problem Management&lt;/strong&gt;&lt;/em&gt; blog gave us their &lt;strong&gt;&lt;a href="http://thinkingproblemmanagement.blogspot.com/2008/10/blogs-that-rock-october-2008.html"&gt;coveted “5 pineapple” rating!&lt;/a&gt; &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;img class="alignnone" title="Pineapples With Sunglasses" src="http://1.bp.blogspot.com/_AVODjjM-COk/SPIXUQQXGLI/AAAAAAAAIKg/SHOqWZKa9rk/s400/5pis.jpg" alt="" width="400" height="101"/&gt;&lt;/p&gt;
&lt;p&gt;In your face, RISKS Digest! &lt;img src="http://riskmanagementinsight.com/riskanalysis/wp-includes/images/smilies/icon_wink.gif" alt=";)" class="wp-smiley"/&gt;&lt;/p&gt;</description><link>http://alexhutton.com/post/54353462</link><guid>http://alexhutton.com/post/54353462</guid><pubDate>Mon, 13 Oct 2008 11:37:43 -0400</pubDate></item><item><title>Why Risk Management Doesn’t Work (?!)</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=459"&gt;Why Risk Management Doesn’t Work (?!)&lt;/a&gt;: Several folks (Hi &lt;a href="http://dmiessler.com/"&gt;Daniel&lt;/a&gt;, &lt;a href="http://stateofsecurity.com/"&gt;Brent&lt;/a&gt;, &lt;a href="http://www.twitter.com/debix"&gt;David&lt;/a&gt;!) sent email &amp; twitters asking us our opinion on a Dark Reading article called “&lt;a href="http://www.darkreading.com/document.asp?doc_id=165107"&gt;Why Risk Management Doesn’t Work&lt;/a&gt;” which if you click on the link should…</description><link>http://alexhutton.com/post/53661692</link><guid>http://alexhutton.com/post/53661692</guid><pubDate>Wed, 08 Oct 2008 15:07:02 -0400</pubDate></item><item><title>Around The Web For Friday</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=450"&gt;Around The Web For Friday&lt;/a&gt;: &lt;p&gt;We’re frequently asked what we’re reading and what we like in blog posts, so here are some interesting things that hit our RSS readers that you may have missed:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.itskeptic.org/node/692"&gt;&lt;strong&gt;COBIT rivals ITIL from The IT…&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;</description><link>http://alexhutton.com/post/51870341</link><guid>http://alexhutton.com/post/51870341</guid><pubDate>Fri, 26 Sep 2008 10:27:01 -0400</pubDate></item><item><title>One Man’s Frustrations With “Risk Management”</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=447"&gt;One Man’s Frustrations With “Risk Management”&lt;/a&gt;: &lt;p&gt;Chris, who is a male in Government C&amp;A has a blog with a wonderful title:&lt;a href="http://howisthatassuranceevidence.blogspot.com/"&gt; How is that Assurance Evidence? &lt;/a&gt;&lt;/p&gt;
&lt;p&gt;I’d love to have another blog even more specific - “Ok, that Assurance is Evidence &lt;em&gt;&lt;strong&gt;Of…&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;</description><link>http://alexhutton.com/post/51433894</link><guid>http://alexhutton.com/post/51433894</guid><pubDate>Tue, 23 Sep 2008 15:11:08 -0400</pubDate></item><item><title>So Logically, If She Weighs The Same As A Duck…She’s A Witch!</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=420"&gt;So Logically, If She Weighs The Same As A Duck…She’s A Witch!&lt;/a&gt;: I usually try to stay far away from politics and current events, but my friend &lt;strong&gt;&lt;a href="http://securosis.com/2008/09/17/the-fallacy-of-complete-and-accurate-risk-quantification/"&gt;Rich has put up a blog post&lt;/a&gt;&lt;/strong&gt; blaming the credit crisis on quantitative analysis, and then positing that because the…</description><link>http://alexhutton.com/post/50710909</link><guid>http://alexhutton.com/post/50710909</guid><pubDate>Thu, 18 Sep 2008 11:02:54 -0400</pubDate></item><item><title>Hansei and the CISO</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=411"&gt;Hansei and the CISO&lt;/a&gt;: Continuing our series on Hansei-Kaizen, you’ll recall that my thoughts are about applying the concept of relentless reflection (Hansei) and continuous improvement (Kaizen) to security management. …</description><link>http://alexhutton.com/post/50429735</link><guid>http://alexhutton.com/post/50429735</guid><pubDate>Tue, 16 Sep 2008 13:52:39 -0400</pubDate></item><item><title>Best, Good, Standard Practices</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=409"&gt;Best, Good, Standard Practices&lt;/a&gt;: &lt;p&gt;&lt;a title="Dilbert.com" href="http://dilbert.com/strips/comic/2008-09-03/"&gt;&lt;img src="http://dilbert.com/dyn/str_strip/000000000/00000000/0000000/000000/20000/2000/200/23259/23259.strip.gif" border="0" alt="Dilbert.com"/&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;It’s like Scott knew it was my birthday and wrote a special comic just for me!&lt;/p&gt;</description><link>http://alexhutton.com/post/48553795</link><guid>http://alexhutton.com/post/48553795</guid><pubDate>Wed, 03 Sep 2008 08:43:51 -0400</pubDate></item><item><title>Risk and CVSS</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=407"&gt;Risk and CVSS&lt;/a&gt;: Chris Hayes is taking me to town in terms of risk content with his last two &lt;a href="http://risktical.com/2008/09/01/risk-and-cvss-post-2/"&gt;&lt;strong&gt;posts on Risk &amp; CVSS&lt;/strong&gt;&lt;/a&gt;.  I told you his blog was going to be a good one.</description><link>http://alexhutton.com/post/48438089</link><guid>http://alexhutton.com/post/48438089</guid><pubDate>Tue, 02 Sep 2008 13:43:21 -0400</pubDate></item><item><title>Gemba &amp; The Journey</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=404"&gt;Gemba &amp; The Journey&lt;/a&gt;: Couple of things first before we get to the next post in the Hansei series.  First, &lt;a href="http://jonrobinson.tumblr.com/post/47570999/alexs-post-got-me-thinking-about-reputation"&gt;Jon Robinson was thinking about reputation damage and stock price&lt;/a&gt; and wrote a very lucid and smart post on the…</description><link>http://alexhutton.com/post/47799357</link><guid>http://alexhutton.com/post/47799357</guid><pubDate>Thu, 28 Aug 2008 13:29:00 -0400</pubDate></item><item><title>Relentless Reflection - What it Means in Risk Management</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=393"&gt;Relentless Reflection - What it Means in Risk Management&lt;/a&gt;: &lt;p&gt;Picking up from yesterday, Today I’d like to talk about:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;HANSEI - WHAT IS “RELENTLESS REFLECTION?”&lt;/strong&gt; - And why we’re talking about it in the context of Risk Analysis.&lt;/p&gt;
&lt;p&gt;Recall from yesterday’s post…&lt;/p&gt;</description><link>http://alexhutton.com/post/47496228</link><guid>http://alexhutton.com/post/47496228</guid><pubDate>Tue, 26 Aug 2008 14:09:03 -0400</pubDate></item><item><title>Hansei-Kaizen &amp; Risk Management Practices</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=391"&gt;Hansei-Kaizen &amp; Risk Management Practices&lt;/a&gt;: &lt;p&gt;You might consider this a follow on to the &lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=331"&gt;Deming&lt;/a&gt; in &lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=337"&gt;Risk Management&lt;/a&gt; &lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=335"&gt;series&lt;/a&gt; I did this spring.&lt;/p&gt;
&lt;p&gt;Recently, &lt;a href="http://thinkingproblemmanagement.blogspot.com/2008/08/genchi-genbutsu-hansei-and-kaizen.html"&gt;Thinking Problem Management wrote&lt;/a&gt; on the concept of&lt;a href="http://209.85.141.104/search?q=cache:egQa2oLaSeUJ:www.technologyforge.net/enma284/ENMA284LecturesHomework/ENMA284CourseOverview/ENMA284CourseOverview.ppt+relentless+reflection&amp;hl=en&amp;ct=clnk&amp;cd=8&amp;gl=us&amp;client=firefox-a"&gt; &lt;strong&gt;Hansei-Kaizen&lt;/strong&gt;&lt;/a&gt;.  That started…&lt;/p&gt;</description><link>http://alexhutton.com/post/47330787</link><guid>http://alexhutton.com/post/47330787</guid><pubDate>Mon, 25 Aug 2008 11:30:46 -0400</pubDate></item><item><title>Reputation Damage &amp; Measurement</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=387"&gt;Reputation Damage &amp; Measurement&lt;/a&gt;: Reputation damage can be one of the most difficult concepts to build measurements around.  In fact, it can be difficult to develop the actual metrics for the measurements, as well.  Damage to things…</description><link>http://alexhutton.com/post/46988142</link><guid>http://alexhutton.com/post/46988142</guid><pubDate>Fri, 22 Aug 2008 12:28:04 -0400</pubDate></item><item><title>Server Upgrade</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=385"&gt;Server Upgrade&lt;/a&gt;: &lt;p&gt;So our server was upgraded by our hosting provider.  Unfortunately, in the upgrade, a comment from Christian was lost amidst the shuffle. Sorry Christian!&lt;/p&gt;
&lt;p&gt;Please take a second and verify your RSS…&lt;/p&gt;</description><link>http://alexhutton.com/post/46222773</link><guid>http://alexhutton.com/post/46222773</guid><pubDate>Sat, 16 Aug 2008 16:22:22 -0400</pubDate></item><item><title>Is Your Firewall a “High Risk Entity”</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=383"&gt;Is Your Firewall a “High Risk Entity”&lt;/a&gt;: Not trying to be overly snarky here, but I was reviewing some GRC product literature recently.  And there was a screenshot of an application window showing how the software helps identify “high risk…</description><link>http://alexhutton.com/post/46097700</link><guid>http://alexhutton.com/post/46097700</guid><pubDate>Fri, 15 Aug 2008 13:20:48 -0400</pubDate></item><item><title>UPDATES GALORE!  or,  THE PRONOUN “WE” MEANS YOU AND ME!</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=381"&gt;UPDATES GALORE!  or,  THE PRONOUN “WE” MEANS YOU AND ME!&lt;/a&gt;: &lt;p&gt;So much traveling, so little blogging.  Sorry everyone.  I’ve gotta say first that I really enjoyed meeting readers and friends of the blog this past two weeks.&lt;/p&gt;
&lt;p&gt;Today, allow me to update you on…&lt;/p&gt;</description><link>http://alexhutton.com/post/45834250</link><guid>http://alexhutton.com/post/45834250</guid><pubDate>Wed, 13 Aug 2008 13:21:04 -0400</pubDate></item><item><title>New Weblog - It’s Gonna Be Good:  Risktical.Com</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=380"&gt;New Weblog - It’s Gonna Be Good:  Risktical.Com&lt;/a&gt;: &lt;p&gt;From Chris Hayes at &lt;strong&gt;&lt;a href="http://risktical.com/"&gt;&lt;a href="http://risktical.com/"&gt;http://risktical.com/&lt;/a&gt;&lt;/a&gt;.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;I have the utmost respect for Chris as a risk analyst.  He’s big in (started?) the Columbus OWASP chapter (and I have to admit to not getting to a…&lt;/p&gt;</description><link>http://alexhutton.com/post/44330393</link><guid>http://alexhutton.com/post/44330393</guid><pubDate>Fri, 01 Aug 2008 08:29:42 -0400</pubDate></item><item><title>Mathematicians, The French, &amp; Risk Analysts</title><description>Goethe: “Mathematicians are like Frenchmen: whatever you say to them they translate into their own language and forthwith it is something entirely different.”</description><link>http://alexhutton.com/post/44071442</link><guid>http://alexhutton.com/post/44071442</guid><pubDate>Wed, 30 Jul 2008 09:25:33 -0400</pubDate></item><item><title>Reminder:  WebEx Seminar on Risk Analysis</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=379"&gt;Reminder:  WebEx Seminar on Risk Analysis&lt;/a&gt;: Hey everybody!  Quick post this morning to remind you guys that Cisco has been kind enough to let us give a follow on WebEx presentation on  July 31, 2008 at 11:30 a.m. EDT.  The link to sign up is &lt;a&gt;&lt;/a&gt;</description><link>http://alexhutton.com/post/43975294</link><guid>http://alexhutton.com/post/43975294</guid><pubDate>Tue, 29 Jul 2008 15:08:19 -0400</pubDate></item></channel></rss>
