<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cloud &#38; Telecom Security &#187; Security</title>
	<atom:link href="http://sbin.cn/blog/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://sbin.cn/blog</link>
	<description>Technologies and comments on cloud and telecom security, bridging China and the world!</description>
	<lastBuildDate>Fri, 17 Feb 2012 06:43:02 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>GRC Regulatory Landscape</title>
		<link>http://sbin.cn/blog/2010/11/24/grc-regulatory-landscape/</link>
		<comments>http://sbin.cn/blog/2010/11/24/grc-regulatory-landscape/#comments</comments>
		<pubDate>Wed, 24 Nov 2010 05:38:11 +0000</pubDate>
		<dc:creator>Richard</dc:creator>
				<category><![CDATA[-English-]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[GRC]]></category>
		<category><![CDATA[Risk]]></category>

		<guid isPermaLink="false">http://sbin.cn/blog/?p=1928</guid>
		<description><![CDATA[Global and local regulations are evolving across all industries and sectors. Here is a selection of the ever-increasing number of regulatory frameworks: All sectors and industries – Enterprise Risk Management (ERM), Electronic discovery (e-discovery), Financial Statements (IFRS,GAAP), Sarbanes Oxley (SOX), EuroSox, Customer Data Privacy and Protection (EU e-privacy), Business Continuity Management, Data Protection Act (EU, [...]]]></description>
		<wfw:commentRss>http://sbin.cn/blog/2010/11/24/grc-regulatory-landscape/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>安全从孩子们抓起与美国安全意识月</title>
		<link>http://sbin.cn/blog/2010/10/07/security-awareness-hackid/</link>
		<comments>http://sbin.cn/blog/2010/10/07/security-awareness-hackid/#comments</comments>
		<pubDate>Thu, 07 Oct 2010 06:31:36 +0000</pubDate>
		<dc:creator>Richard</dc:creator>
				<category><![CDATA[-Chinese-]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CSA]]></category>
		<category><![CDATA[Hackid]]></category>

		<guid isPermaLink="false">http://sbin.cn/blog/?p=1889</guid>
		<description><![CDATA[在云计算时代，基于IP的安全策略效用将大打折扣，随时随地的数据和服务访问要求安全访问控制要能够基于“用户”和“数据”。同时，为了强化“用户”和“数据”的访问控制，双因子认证将会变得更加普遍，甚至成为缺省设置，例如网络访问与下一代身份证ID之类的硬Token结合在一起。当然，为了保护公民隐私，在实名制的ID认证和实际的网络身份之间有必要在技术上实现一种匿名层（Anonymization）&#8230; 上面都是技术层面上的讨论，事实上，最为脆弱的部分并不在于技术，而是在于社会工程打击的目标 &#8211; 缺少安全意识和技能的“人”。就如同大家在车站机场商场等公开场合到处可见的“注意保管您的随身物品”提醒牌，互联网上要安全冲浪、保护隐私最重要的就是要有“意识”。撇开普通老百姓，从政府、企业、组织等高度来看，就是要让安全意识从安全经理和安全主管那里，外延到最高管理层、财务和业务负责人、所有的普通员工等。 这是个典型的“说起来容易做起来难”的事，难在有钱有权的没有动力，有动力没有资源。大洋对岸从去年开始设立了全国的安全月 &#8211; 十月份。今年的主题是 &#8211; 我们共同的责任 （Our Shared Responsibility）。这个事情值得我们借鉴。 今天在浏览Beaker的博客时，看到一则很有趣的活动。Beaker在推动一个叫做Hackid的公益项目 &#8211; 安全从孩子们抓起。 Hackid通过举办以孩子们为主的技术沙龙和动手活动，来激发孩子们对于基础电子、互联网、创新等的兴趣，提高孩子们的动手能力，提升孩子们对于互联网基础知识的了解&#8230;下面是其官方页面中的活动内容介绍： # Staying Safe Online # Dealing with CyberBullies # Online gaming safety # Building Medieval Trebuchets # Interactive robot building # How the Internet works # Food Hacking # Hair Hacking # Lego Derby racing # Manipulating hardware and [...]]]></description>
		<wfw:commentRss>http://sbin.cn/blog/2010/10/07/security-awareness-hackid/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>盘点近几年美国IT巨头在安全领域的并购</title>
		<link>http://sbin.cn/blog/2010/08/26/%e7%9b%98%e7%82%b9%e8%bf%91%e5%87%a0%e5%b9%b4%e7%be%8e%e5%9b%bdit%e5%b7%a8%e5%a4%b4%e5%9c%a8%e5%ae%89%e5%85%a8%e9%a2%86%e5%9f%9f%e7%9a%84%e5%b9%b6%e8%b4%ad/</link>
		<comments>http://sbin.cn/blog/2010/08/26/%e7%9b%98%e7%82%b9%e8%bf%91%e5%87%a0%e5%b9%b4%e7%be%8e%e5%9b%bdit%e5%b7%a8%e5%a4%b4%e5%9c%a8%e5%ae%89%e5%85%a8%e9%a2%86%e5%9f%9f%e7%9a%84%e5%b9%b6%e8%b4%ad/#comments</comments>
		<pubDate>Thu, 26 Aug 2010 23:49:45 +0000</pubDate>
		<dc:creator>Clement</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Acquisition]]></category>

		<guid isPermaLink="false">http://sbin.cn/blog/?p=1865</guid>
		<description><![CDATA[最近美国IT企业并购可谓遍地开花，这边Intel刚刚宣布购买McAfee，那边Dell和HP还在为存储服务商3PAR打的不可开交（让我想起去年NetApp和EMC争夺Data Domain的案例），3PAR的股票从两个星期前的10美元不到已经涨到接近28美元。今天华尔街日报又传出安全厂商ArcSight正在和Oracle, IBM, HP, EMC和CA等潜在买家接洽，消息传出后ArcSight的股票(ARST)应声涨了30%。 Arcsight的潜在买家中没有Cisco，这让我比较吃惊。ArcSight是做SIEM (Security Information and Event Management)的，和Cisco的MARS直接竞争，我一直觉得Cisco是ArcSight最合适的买家。Symantec的产品和ArcSight也有很好的整合度，本来也是一个潜在的买家，不过在Mcafee被收购后，它自身可能也难逃最终被收购的命运。相对而言，ArcSight产品的整合度和Oracle的Enterprise Manager或者HP的OpenView就没有那么高。 信息安全这几年来一直是一个增长很快的领域，并且正在成为企业整体解决方案中不可或缺的一部分，这也是为什么近几年IT巨头纷纷出手收购安全公司。此外，独立的安全公司规模往往较小，比较容易被收购。比如安全行业的&#8221;巨头&#8221; Symantec的市值也不过110亿美元，为IBM的1/15，HP的1/9，Oracle和Cisco的1/10。抚今追昔，下面我们来看看最近几年美国的IT巨头们都收购了哪些安全企业: IBM: 2010年7月：BigFix (Security Management) 2009年11月：Guardium (Database Security) 2007年6月：Watchfire (security testing) 2006年 8月：ISS Cisco: 2009年12 月：Scansafe (Saas WebSecurity) 2007年11 月：Securent (Entitlement Management) 2007年1月： IronPort (Email and Web Security) HP: 2010 年8月： Fortify (Software Security) 2009年11月：3Com (Tippingpoint) 2007年6月：SPI Dynamics (Web Security Testing) Intel: [...]]]></description>
		<wfw:commentRss>http://sbin.cn/blog/2010/08/26/%e7%9b%98%e7%82%b9%e8%bf%91%e5%87%a0%e5%b9%b4%e7%be%8e%e5%9b%bdit%e5%b7%a8%e5%a4%b4%e5%9c%a8%e5%ae%89%e5%85%a8%e9%a2%86%e5%9f%9f%e7%9a%84%e5%b9%b6%e8%b4%ad/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Strategic Thinking on Symantec Acquisition</title>
		<link>http://sbin.cn/blog/2010/05/27/strategic-thinking-on-symantec-acquisition/</link>
		<comments>http://sbin.cn/blog/2010/05/27/strategic-thinking-on-symantec-acquisition/#comments</comments>
		<pubDate>Thu, 27 May 2010 14:28:36 +0000</pubDate>
		<dc:creator>Richard</dc:creator>
				<category><![CDATA[-English-]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CA]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[MSSP]]></category>
		<category><![CDATA[Symantec]]></category>

		<guid isPermaLink="false">http://sbin.cn/blog/?p=1754</guid>
		<description><![CDATA[Last week, Symantec(NASDAQ:SYMC) acquired the security businesses of VeriSign (excluding iDefense). There have been tons of news reports and comments by market observers and analysts.  In general, given that both negative and positive comments are valid, the below chart gave a different perspective to evaluate the acquisition strategy of Symantec. It&#8217;s a 5 year stock [...]]]></description>
		<wfw:commentRss>http://sbin.cn/blog/2010/05/27/strategic-thinking-on-symantec-acquisition/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Quote of Security – 11</title>
		<link>http://sbin.cn/blog/2010/03/25/quote-of-security-%e2%80%93-11/</link>
		<comments>http://sbin.cn/blog/2010/03/25/quote-of-security-%e2%80%93-11/#comments</comments>
		<pubDate>Fri, 26 Mar 2010 00:50:15 +0000</pubDate>
		<dc:creator>Richard</dc:creator>
				<category><![CDATA[-English-]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SecurityMetrics]]></category>

		<guid isPermaLink="false">http://sbin.cn/blog/?p=1673</guid>
		<description><![CDATA[Another way of thinking about it, speciﬁcally that if you want security then you must control the future, if you want to control the future then you must be able to draw conclusions from what you know, if you want to draw conclusions then the basis for those conclusions must be reproducible, and if you [...]]]></description>
		<wfw:commentRss>http://sbin.cn/blog/2010/03/25/quote-of-security-%e2%80%93-11/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Quote of Security – 10</title>
		<link>http://sbin.cn/blog/2010/03/25/quote-of-security-10/</link>
		<comments>http://sbin.cn/blog/2010/03/25/quote-of-security-10/#comments</comments>
		<pubDate>Thu, 25 Mar 2010 20:57:49 +0000</pubDate>
		<dc:creator>Richard</dc:creator>
				<category><![CDATA[-English-]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SecurityMetrics]]></category>

		<guid isPermaLink="false">http://sbin.cn/blog/?p=1669</guid>
		<description><![CDATA[- Good enough is good enough. - Good enough always beats perfect. - The really hard part is determining what is good enough. - by Ravi Sandhu You can download the whole paper here.]]></description>
		<wfw:commentRss>http://sbin.cn/blog/2010/03/25/quote-of-security-10/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Title changed to &#8220;Cloud &amp; Telecom Security&#8221;</title>
		<link>http://sbin.cn/blog/2010/03/08/title-changed-to-cloud-telecom-security/</link>
		<comments>http://sbin.cn/blog/2010/03/08/title-changed-to-cloud-telecom-security/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 14:00:59 +0000</pubDate>
		<dc:creator>Richard</dc:creator>
				<category><![CDATA[-English-]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Telecom]]></category>

		<guid isPermaLink="false">http://sbin.cn/blog/?p=1625</guid>
		<description><![CDATA[This morning, you might have noticed that the blog title was changed to &#8220;Cloud &#38; Telecom Security&#8221;. Yes, it&#8217;s true. From one or two years ago, my interests and focus have changed to around cloud computing and telecom or ICT security, while P2P was touched very occasionally.  I believe the new title can reflect the [...]]]></description>
		<wfw:commentRss>http://sbin.cn/blog/2010/03/08/title-changed-to-cloud-telecom-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>著名安全媒体SCMagzine公布2010年各安全奖项入围名单</title>
		<link>http://sbin.cn/blog/2009/12/08/scaward-2010-finalist/</link>
		<comments>http://sbin.cn/blog/2009/12/08/scaward-2010-finalist/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 21:41:07 +0000</pubDate>
		<dc:creator>Richard</dc:creator>
				<category><![CDATA[-Chinese-]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[2009]]></category>
		<category><![CDATA[2010]]></category>
		<category><![CDATA[CISO]]></category>
		<category><![CDATA[CSO]]></category>
		<category><![CDATA[SCAward]]></category>

		<guid isPermaLink="false">http://sbin.cn/blog/?p=1521</guid>
		<description><![CDATA[今天著名安全媒体SCMagzine公布2010年各安全奖项入围名单，最后的大奖将于2010年3月2日在旧金山公布。 从这次的入围名单上看，安全大厂如Cisco,Juniper,Symantec,等成为最大的赢家，到处闪现他们的身影。功夫不负有心人，这次Cenzic, HyTrust,e-DMZ, Palo-Alto等新秀也终于展露头角。BigFix能够获得优秀安全公司入围，你觉得有些惊奇吗？Dave Cullinane凭借云安全联盟CSA的快速成长和成功，荣获最佳CSO/CISO入围。 希望看到我们中国的企业也成为国际战场的逐鹿者！ Reader Trust Awards Best Anti-Malware Solution Astaro Internet Security for Astaro Security Gateway AVG Technologies for AVG Internet Security Business Edition Cisco for Cisco IronPort S-Series Secure Web Gateway ESET for ESET NOD32 Antivirus 4 McAfee for McAfee Web Gateway Symantec Corp. for Symantec Endpoint Protection Small Business Edition [...]]]></description>
		<wfw:commentRss>http://sbin.cn/blog/2009/12/08/scaward-2010-finalist/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>HP Acquiring 3Com increases the oligopoly of IT arena</title>
		<link>http://sbin.cn/blog/2009/11/11/hp-to-acquire-3com-for-2-7-billion/</link>
		<comments>http://sbin.cn/blog/2009/11/11/hp-to-acquire-3com-for-2-7-billion/#comments</comments>
		<pubDate>Wed, 11 Nov 2009 21:47:21 +0000</pubDate>
		<dc:creator>Richard</dc:creator>
				<category><![CDATA[-English-]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Telecom]]></category>
		<category><![CDATA[3Com]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[Huawei]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[Tippingpoint]]></category>

		<guid isPermaLink="false">http://sbin.cn/blog/?p=1499</guid>
		<description><![CDATA[By this acquisition, HP enters enterprise networking market with strong threat management product line from Tippingpoint. The vulnerability and threats research of DVLabs will greatly improve HP&#8217;s capability and image at these areas, so that HP&#8217;s competition against IBM will become more effective.  X-Force of ISS is one of the critical advantages of IBM over [...]]]></description>
		<wfw:commentRss>http://sbin.cn/blog/2009/11/11/hp-to-acquire-3com-for-2-7-billion/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>True or False: 70% of security incidents are due to insider threats?</title>
		<link>http://sbin.cn/blog/2009/11/10/true-or-false-70-of-security-incidents-are-due-to-insider-threats/</link>
		<comments>http://sbin.cn/blog/2009/11/10/true-or-false-70-of-security-incidents-are-due-to-insider-threats/#comments</comments>
		<pubDate>Tue, 10 Nov 2009 16:54:21 +0000</pubDate>
		<dc:creator>Richard</dc:creator>
				<category><![CDATA[-English-]]></category>
		<category><![CDATA[Architect]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[IDC]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[SecurityMetrics]]></category>

		<guid isPermaLink="false">http://sbin.cn/blog/?p=1491</guid>
		<description><![CDATA[Actually, the whole thread was originated with a message at discuss@securitymetrics.org &#8220;Request for ideas&#8221; by Dimitrios Stergiou. Dimitrios likes to have some recommendations for his master program. By a sudden idea, I dropped him a message to recommend him to work on this true or false problem at security metrics. It&#8217;s true or false: 70% [...]]]></description>
		<wfw:commentRss>http://sbin.cn/blog/2009/11/10/true-or-false-70-of-security-incidents-are-due-to-insider-threats/feed/</wfw:commentRss>
		<slash:comments>26</slash:comments>
		</item>
	</channel>
</rss>

