<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><atom:link rel="hub" href="http://tumblr.superfeedr.com/" xmlns:atom="http://www.w3.org/2005/Atom"/><description>Hi.  This is my personal weblog.  I also write at:

http://www.newschoolsecurity.com
http://securityblog.verizonbusiness.com</description><title>Alex Hutton</title><generator>Tumblr (3.0; @alexhutton)</generator><link>http://alexhutton.com/</link><item><title>My 5 Things</title><description>&lt;p&gt;Ed Bellis tagged me.  Jerk :-)&lt;/p&gt;
&lt;p&gt;So here goes:&lt;/p&gt;
&lt;p&gt;1.)  I spent my 1-12 years outside of Charlottesville, Virginia.  And coming out here to Purcellville, I realize that I &lt;i&gt;&lt;b&gt;like&lt;/b&gt;&lt;/i&gt; the country.&lt;/p&gt;
&lt;p&gt;2.)  I’m a political independent.  This tends to surprise people with whom I align on one or two issues and then find that I don’t tote their party line.  Why am I independent?  What are the chances that one parties positions on every.single.issue is correct?  What are the chances that sometimes, situations dictate that our policies lean one way or the other only to be reversed when the domestic or foreign policy landscape changes?  What are the chances that, really, it doesn’t matter who you vote for because there’s a non-elected bureaucratic class that actually creates the majority of public policy for their interest and the interest of longevity and power for the agency they serve?&lt;/p&gt;
&lt;p&gt;3.)  Similarly, I’m not an atheist or agnostic, but acknowledge the difference between uncertainty and doubt in belief/faith.&lt;/p&gt;
&lt;p&gt;4.)  My music collection could quite possibly be the most Caucasian 60gb you might encounter.  There’s also more classical, be-bop, and latin than most people would suppose.  It’s not constructed that way with intention, or to say that it’s not diverse in the genetic make-up of the artists represented, it’s just that when I think about it, the hip-hop/rap I &lt;i&gt;do&lt;/i&gt; have is, like, 17 years old or more.  &lt;i&gt;Actually, while you probably didn’t know that about me, you probably could have guessed.&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;5.)  If I had to do it all over again, I would be an architect.  Or a landscape architect.  In fact, I’d be very happy and content doing manual labor for a living.’&lt;/p&gt;
&lt;p&gt;6.)  There is no sixth thing.&lt;/p&gt;</description><link>http://alexhutton.com/post/183105211</link><guid>http://alexhutton.com/post/183105211</guid><pubDate>Tue, 08 Sep 2009 17:35:00 -0400</pubDate></item><item><title>"“Backpack, you need to know everything we’re going to need for the trip, despite my not..."</title><description>“&lt;p&gt;“Backpack, you need to know everything we’re going to need for the trip, despite my not telling you where we’re going until we’ve already left.&lt;/p&gt;

&lt;p&gt;Boots, you’re going to do all work and never get to provide any input.&lt;/p&gt;

&lt;p&gt;I’ll just make a list of the three problems you’re going to solve, and hire Tico the contracting squirrel to drive us around…. &lt;/p&gt;

&lt;p&gt;Then, once it’s complete, I’ll dance, take the credit, and ask each of what you liked best during the wrap-up call.”&lt;/p&gt;”&lt;br/&gt;&lt;br/&gt; - &lt;em&gt;Chandler Howell on Dora The Explorer as Project Manager.&lt;/em&gt;</description><link>http://alexhutton.com/post/174780450</link><guid>http://alexhutton.com/post/174780450</guid><pubDate>Sat, 29 Aug 2009 12:40:00 -0400</pubDate></item><item><title>Exploration in (New) Media Center Building</title><description>&lt;p&gt;So we’ll be moving to a rural area of Virginia in a couple of weeks, and as part of trying to figure out what utilities to move and when, I decided to revisit how we, as a family, will entertain ourselves.  Our family of five includes my wife, myself, my two sons (age 7 &amp; 11), &amp; my 17 month old daughter.&lt;/p&gt;
&lt;p&gt;Currently, we have basic cable from Time Warner, with Road Runner basic service.  I have a series 2 Tivo With a DvD recorder and a Wii.  I’m paying about $100 per month for cable, Internet, &amp; TiVo.  &lt;/p&gt;
&lt;p&gt;The boys mainly want to see baseball, Star Wars clone wars, and they play Wii.  My daughter couldn’t care less about TV, but loves it when we play Wii fit.  My wife enjoys reality TV, mainly on CBS/NBC, but also some programming on Bravo &amp; FoodTV.  We both enjoy baseball, and I enjoy Tennis programming.  We don’t really watch too many movies, and when we do, they usually are classics rather than last years releases.  &lt;/p&gt;
&lt;p&gt;There is no Cable at the new place in Virginia.  But there is serious Wireless (not Satellite) Internet.  Like 1.5 mbps low-latency Internet.  So rather than just buy a bunhc of things that DirecTV or Dish Network was going to charge me for, I figured I’d take a look at the various new options in programming that are available.  &lt;/p&gt;
&lt;p&gt;I thought it would be great to stop using DVDs and to stream music and video and so forth all around and just generally see if I could build a new media solution that fits our basic needs, and perhaps spoils us in simplicity and even price over the long term.&lt;/p&gt;
&lt;p&gt;Not having a need to really use this blog space for work stuff, and finding a total lack of real experience and review in all the online stuff during my research, I thought I’d make a diary of it here.&lt;/p&gt;</description><link>http://alexhutton.com/post/119520835</link><guid>http://alexhutton.com/post/119520835</guid><pubDate>Sun, 07 Jun 2009 14:16:11 -0400</pubDate><category>appletv</category><category>hulu</category><category>wii</category><category>newmedia</category><category>xbmc</category><category>boxee</category><category>xbox</category><category>ps3</category><category>macmini</category></item><item><title>Facebook &lt;-&gt; Tumblr Link</title><description>&lt;p&gt;So with me not blogging at RiskAnalys.is anymore, I thought I’d try to figure out what I should do about this website.  So far, I’ve linked Tumblr (this site) to my Facebook account.&lt;/p&gt;
&lt;p&gt;&lt;br/&gt;They *seem* to be serving a similar purpose.  Honestly, I think I’d like an OS X app to blog more here about stuff that is more than twitter, and not risk management related.&lt;/p&gt;</description><link>http://alexhutton.com/post/107380033</link><guid>http://alexhutton.com/post/107380033</guid><pubDate>Wed, 13 May 2009 18:01:54 -0400</pubDate></item><item><title>Pair of Jacks</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=626"&gt;Pair of Jacks&lt;/a&gt;: &lt;p&gt;Please join me in welcoming Jack Freund as a contributor to this blog.  Jack is a certified FAIR analyst and has a boatload of experience in the information security profession.  Welcome Jack!&lt;/p&gt;</description><link>http://alexhutton.com/post/101834987</link><guid>http://alexhutton.com/post/101834987</guid><pubDate>Thu, 30 Apr 2009 08:18:03 -0400</pubDate></item><item><title>It’s a FAIR Pandemic…</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=623"&gt;It’s a FAIR Pandemic…&lt;/a&gt;: &lt;p&gt;RMI welcomes Jack Freund to the RiskAnalys.is blog…&lt;/p&gt;
&lt;p&gt;Once again the 24-hour news cycle is buffeting us with “information” about the new risk that will surely end us all. I’ve received several…&lt;/p&gt;</description><link>http://alexhutton.com/post/101834986</link><guid>http://alexhutton.com/post/101834986</guid><pubDate>Thu, 30 Apr 2009 08:18:03 -0400</pubDate></item><item><title>Aggregate analysis (or measuring the surface area of Long Island)</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=601"&gt;Aggregate analysis (or measuring the surface area of Long Island)&lt;/a&gt;: &lt;p&gt;&lt;span&gt;One of the questions I commonly encounter is “How do you take something like FAIR and apply it to a big problem, like measuring the aggregate risk within an entire organization?”  In order to keep…&lt;/span&gt;&lt;/p&gt;</description><link>http://alexhutton.com/post/97643567</link><guid>http://alexhutton.com/post/97643567</guid><pubDate>Sat, 18 Apr 2009 20:03:58 -0400</pubDate></item><item><title>Load of Tosh?</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=590"&gt;Load of Tosh?&lt;/a&gt;: &lt;p&gt;Long time no post…  My sincere apologies, and I hope someone out there is still interested.  I guess I needed a little prodding, which Stuart King so kindly &lt;a href="http://www.computerweekly.com/blogs/stuart_king/2009/03/top-annoyances.html"&gt;provided&lt;/a&gt;.  I’ve provided a response on…&lt;/p&gt;</description><link>http://alexhutton.com/post/89024544</link><guid>http://alexhutton.com/post/89024544</guid><pubDate>Mon, 23 Mar 2009 09:20:53 -0400</pubDate></item><item><title>Alex</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=583"&gt;Alex&lt;/a&gt;: &lt;p&gt;Those of you who are familiar with this blog probably recognize Alex Hutton as THE voice of RMI and FAIR, and for good reason.  For over two years now, Alex has earned a reputation as a spirited and…&lt;/p&gt;</description><link>http://alexhutton.com/post/81375338</link><guid>http://alexhutton.com/post/81375338</guid><pubDate>Wed, 25 Feb 2009 07:38:51 -0500</pubDate></item><item><title>Sweet Giveaway: Personal Honey Point License</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=581"&gt;Sweet Giveaway: Personal Honey Point License&lt;/a&gt;: &lt;p&gt;I have Five licenses for &lt;a href="http://microsolved.com/"&gt;MicroSolved&lt;/a&gt;’s Personal Honeypoint Honeypot product to give away.  I’m using the OSX version right now at a coffee shop.  From what &lt;a href="http://stateofsecurity.com/"&gt;Brent Huston&lt;/a&gt; tells me, you can even…&lt;/p&gt;</description><link>http://alexhutton.com/post/75883711</link><guid>http://alexhutton.com/post/75883711</guid><pubDate>Thu, 05 Feb 2009 10:20:46 -0500</pubDate></item><item><title>Potpurri: Ponemon, Payment Professionals, Perimeters, &amp; Pete Lindstrom</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=578"&gt;Potpurri: Ponemon, Payment Professionals, Perimeters, &amp; Pete Lindstrom&lt;/a&gt;: &lt;p&gt;Today’s blog post is a quick catch up post on several fronts.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;I LIKE PROFESSIONAL ASSOCIATIONS&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;First, &lt;a href="http://www.risktical.com"&gt;Chris Hayes&lt;/a&gt;, &lt;a href="http://www.emergentchaos.com"&gt;David Mortman&lt;/a&gt; and I had the honor of being bought dinner by Mike Dahn. …&lt;/p&gt;</description><link>http://alexhutton.com/post/75673051</link><guid>http://alexhutton.com/post/75673051</guid><pubDate>Wed, 04 Feb 2009 15:20:00 -0500</pubDate></item><item><title>A BRIEF ARGUMENT FOR PCI DSS (OR ALEX’S 5S’S FOR LEAN INFORMATION SECURITY MANAGEMENT)</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=568"&gt;A BRIEF ARGUMENT FOR PCI DSS (OR ALEX’S 5S’S FOR LEAN INFORMATION SECURITY MANAGEMENT)&lt;/a&gt;: &lt;p&gt;&lt;em&gt;real quick:  It might be worth noting that I wrote this the weekend before Heartland was announced. &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;So I was reading &lt;a href="http://www.gembapantarei.com/2009/01/the_toyota_production_system_by_taiichi_ohno_chapt_2.html"&gt;this excellent article on Taiichi Ohno and the Toyota Production System&lt;/a&gt; over…&lt;/p&gt;</description><link>http://alexhutton.com/post/73502673</link><guid>http://alexhutton.com/post/73502673</guid><pubDate>Tue, 27 Jan 2009 10:04:12 -0500</pubDate></item><item><title>The Source of PCI DSS “Failure”</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=572"&gt;The Source of PCI DSS “Failure”&lt;/a&gt;: &lt;p&gt;This is somewhat of a follow up from &lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=530"&gt;my post&lt;/a&gt; on changing our attitude towards how we might best protect consumers that use credit cards.&lt;/p&gt;
&lt;p&gt;In FAIR, there are three types of contact that drive the…&lt;/p&gt;</description><link>http://alexhutton.com/post/72612290</link><guid>http://alexhutton.com/post/72612290</guid><pubDate>Fri, 23 Jan 2009 12:47:49 -0500</pubDate></item><item><title>Maturity &amp; Measurement Redux</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=566"&gt;Maturity &amp; Measurement Redux&lt;/a&gt;: &lt;p&gt;My friend Mike Rothman had &lt;a href="http://securityincite.com/blog/mike-rothman/the-daily-incite-1-20-09-fight-for-your-right"&gt;some fun things to say&lt;/a&gt; about &lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=541"&gt;this post&lt;/a&gt; I made last year in his recent insight. Love ya Mike, but I have to respond in kind.&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;“I’ve used the saying, “when all you have…&lt;/p&gt;&lt;/blockquote&gt;</description><link>http://alexhutton.com/post/72096787</link><guid>http://alexhutton.com/post/72096787</guid><pubDate>Wed, 21 Jan 2009 11:44:26 -0500</pubDate></item><item><title>Using The Compliance Stick Actually Weakens You</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=558"&gt;Using The Compliance Stick Actually Weakens You&lt;/a&gt;: &lt;p&gt;Anton is the “PCI Guy” (sorry, not sure of his real title) at Qualys.  If you haven’t seen them yet, he’s got some pretty ranty posts about PCI up.  Which are awesome.  In his most recent post he…&lt;/p&gt;</description><link>http://alexhutton.com/post/70663786</link><guid>http://alexhutton.com/post/70663786</guid><pubDate>Thu, 15 Jan 2009 08:26:20 -0500</pubDate></item><item><title>A Couple of Links on Risk &amp; Decision Making</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=554"&gt;A Couple of Links on Risk &amp; Decision Making&lt;/a&gt;: &lt;p&gt;First, I wanted to point you over to &lt;a href="http://risktical.com/2009/01/12/risk-scenario-%E2%80%93-hidden-field-sensitive-information-part-1-of-4-%E2%80%93-the-scenario/"&gt;Chris’ Risktical blog&lt;/a&gt;.  He’ll be doing a FAIR analysis over there that looks interesting.  It’s nice that Chris is dedicating his time on this, given the…&lt;/p&gt;</description><link>http://alexhutton.com/post/70217391</link><guid>http://alexhutton.com/post/70217391</guid><pubDate>Tue, 13 Jan 2009 11:03:00 -0500</pubDate></item><item><title>Thoughts on ISO 27005</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=544"&gt;Thoughts on ISO 27005&lt;/a&gt;: &lt;p&gt;First, many readers sent us the New York Times/Slashdot “Risk Management” link.  Thank you!&lt;/p&gt;
&lt;p&gt;The beginning of a reasoned response was written by Aleks  on Andrew Gelman’s blog (&lt;a href="http://www.stat.columbia.edu/~cook/movabletype/archives/2009/01/dont-blame-it-o.html"&gt;…&lt;/a&gt;&lt;/p&gt;</description><link>http://alexhutton.com/post/68756153</link><guid>http://alexhutton.com/post/68756153</guid><pubDate>Tue, 06 Jan 2009 13:31:25 -0500</pubDate></item><item><title>Moving Towards A Mature Security Organization Using A Measured Approach to Risk Management</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=541"&gt;Moving Towards A Mature Security Organization Using A Measured Approach to Risk Management&lt;/a&gt;: &lt;p&gt;Over the past couple years of blogging, I’ve found that about once or twice a month I’ll write a really long blog post on a subject, only to scrap it before publication.   It might be because my…&lt;/p&gt;</description><link>http://alexhutton.com/post/66268045</link><guid>http://alexhutton.com/post/66268045</guid><pubDate>Mon, 22 Dec 2008 14:12:25 -0500</pubDate></item><item><title>Fun From FAIR Training</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=536"&gt;Fun From FAIR Training&lt;/a&gt;: &lt;p&gt;Sorry for the slow week. We had two sets of training that went (we thought) really, really well.&lt;/p&gt;
&lt;p&gt;One of the things we do is ask learners to bring in scenarios that they want to run through FAIR….&lt;/p&gt;</description><link>http://alexhutton.com/post/64534051</link><guid>http://alexhutton.com/post/64534051</guid><pubDate>Fri, 12 Dec 2008 15:06:32 -0500</pubDate></item><item><title>Penetration Testing Not Dead, Probably Just Pining for the Fjord</title><description>&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=532"&gt;Penetration Testing Not Dead, Probably Just Pining for the Fjord&lt;/a&gt;: &lt;p&gt;&lt;object width="320" height="265"&gt;&lt;param name="movie" value="http://www.youtube.com/v/-IQqd17p9_0&amp;hl=en&amp;fs=1"&gt;
&lt;param name="allowFullScreen" value="true"&gt;
&lt;param name="allowscriptaccess" value="always"&gt;
&lt;embed src="http://www.youtube.com/v/-IQqd17p9_0&amp;hl=en&amp;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="320" height="265"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/p&gt;
&lt;p&gt;Bill Brenner has an article in CSO magazine in which “Fortify Co-Founder and Chief Scientist Brian Chess says:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p style="text-align: center;"&gt;&lt;strong&gt;&lt;em&gt; “2009 will mark the end of pen tests as we know them.” &lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;…&lt;/p&gt;</description><link>http://alexhutton.com/post/63708056</link><guid>http://alexhutton.com/post/63708056</guid><pubDate>Mon, 08 Dec 2008 10:34:04 -0500</pubDate></item></channel></rss>
