<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: A new idea or a new model?</title>
	<atom:link href="http://sbin.cn/blog/2009/01/04/a-new-idea-or-a-new-model/feed/" rel="self" type="application/rss+xml" />
	<link>http://sbin.cn/blog/2009/01/04/a-new-idea-or-a-new-model/</link>
	<description>Technologies and comments on cloud and telecom security, bridging China and the world!</description>
	<lastBuildDate>Mon, 19 Sep 2011 01:16:15 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Tony Liu</title>
		<link>http://sbin.cn/blog/2009/01/04/a-new-idea-or-a-new-model/comment-page-1/#comment-35418</link>
		<dc:creator>Tony Liu</dc:creator>
		<pubDate>Wed, 07 Jan 2009 08:58:22 +0000</pubDate>
		<guid isPermaLink="false">http://sbin.cn/blog/?p=1005#comment-35418</guid>
		<description>WOW, great topic, i&#039;m always thinking appropriate is the best,
Moderate security for what? for you business.
How to measure moderate or not? 2 measures basically, one is about coverage, another is about depth.

I advise to follow following approach,

1. Think about your business, priotize them into different levels
2. Exclude the least important business from protection scope,
3. Consider the depth of security measures of the left medium-to-highly important business, think about following questions, 
# What&#039;s the expected protection level, on network, system or even application?
# Are there any overlap when choosing security protection measures, for example, deploy network IDS and host IDS together
# On the other side, what&#039;s the tollerance for your business?
4. Finalize your solution, have a communication with your manager and business user as well, get their support,</description>
		<content:encoded><![CDATA[<p>WOW, great topic, i&#8217;m always thinking appropriate is the best,<br />
Moderate security for what? for you business.<br />
How to measure moderate or not? 2 measures basically, one is about coverage, another is about depth.</p>
<p>I advise to follow following approach,</p>
<p>1. Think about your business, priotize them into different levels<br />
2. Exclude the least important business from protection scope,<br />
3. Consider the depth of security measures of the left medium-to-highly important business, think about following questions,<br />
# What&#8217;s the expected protection level, on network, system or even application?<br />
# Are there any overlap when choosing security protection measures, for example, deploy network IDS and host IDS together<br />
# On the other side, what&#8217;s the tollerance for your business?<br />
4. Finalize your solution, have a communication with your manager and business user as well, get their support,</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jack</title>
		<link>http://sbin.cn/blog/2009/01/04/a-new-idea-or-a-new-model/comment-page-1/#comment-35348</link>
		<dc:creator>jack</dc:creator>
		<pubDate>Sun, 04 Jan 2009 06:46:28 +0000</pubDate>
		<guid isPermaLink="false">http://sbin.cn/blog/?p=1005#comment-35348</guid>
		<description>适度防护  加入威慑的概念</description>
		<content:encoded><![CDATA[<p>适度防护  加入威慑的概念</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Why</title>
		<link>http://sbin.cn/blog/2009/01/04/a-new-idea-or-a-new-model/comment-page-1/#comment-35345</link>
		<dc:creator>Why</dc:creator>
		<pubDate>Sun, 04 Jan 2009 02:47:31 +0000</pubDate>
		<guid isPermaLink="false">http://sbin.cn/blog/?p=1005#comment-35345</guid>
		<description>think systematize, action specific.</description>
		<content:encoded><![CDATA[<p>think systematize, action specific.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

