<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:clearspace="http://www.jivesoftware.com/xmlns/clearspace/rss" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>IT@Intel Blog</title>
    <link>http://communities.intel.com/openport/blogs/it</link>
    <description>IT@Intel</description>
    <pubDate>Fri, 26 Sep 2008 21:01:18 GMT</pubDate>
    <generator>Clearspace 1.7.0 (http://jivesoftware.com/products/clearspace/)</generator>
    <dc:date>2008-09-26T21:01:18Z</dc:date>
    <item>
      <title>Is it time for "Radical Change" in IT?</title>
      <link>http://communities.intel.com/openport/blogs/it/2008/09/26/is-it-time-for-radical-change-in-it</link>
      <description>As I sit here fresh from a leadership conference for IT employees, I find myself thinking about that. Does IT need radical change? After hearing several examples of how people engineered solutions to solve specific problems or reviewed projects they had developed over the past year, I can answer with a definite yes. While it wasn't simply this experience that pushed me to realization, it definitely helped complete the pattern I had noticed in today's IT. &lt;br /&gt;
&lt;br /&gt;
I spend most of my normal role investigating and researching emerging and next generation technologies. With this role came many headaches from pounding my head against the wall of established processes, procedures and preconceived notions. But to borrow an idea from Gene Meieran, that is simply the toll I am paying on this road to my success. But I look at this and ask a simple question, why? &lt;br /&gt;
&lt;br /&gt;
When pushing to adopt a new technology, why do we have to wait until it meets all of our established requirements? Why do we try to make vendor's products adapt to us, versus us considering the possibility to adapt to them? Why does it take us 2 years to adopt a new operating system or major product? Why do we run projects for 18-24 months to implement a product that exists out on the shelf today? In looking at several examples of what people consider successful products today, I look to see what makes them different, attractive, and a must have. I then ask what would it take to make IT different, attractive and a must have for any corporation.&lt;br /&gt;
&lt;br /&gt;
Five or six years ago, people came to work and looked to IT to get the latest hardware, OS and innovations, because we had it here. We spent the dollars and time to solve problems and innovate. But in the last few years, people have adopted technology must faster at home than we do at work. They use the iPhone, a Wii, social networking tools, cloud based services, etc. They are enabled at home with more options than we provide as an IT shop. We use instant messaging in IT, not because we developed it as a way to eliminate small emails, but because instant messaging was a consumer product that grew so fast, that IT had to adopt it. Social networking is doing the same thing. So I wonder, what would it take to get IT back ahead of the curve and become an enabler of new ideas and solutions, rather than an implementer &amp; reinventer of existing technology?&lt;br /&gt;
&lt;br /&gt;
We need to get back to freethinking and innovation that is core to our roots. Companies like Intel were founded on thoughts like the famous quote from Robert Noyce - "Don't be encumbered by the past, go out and do something wonderful" yet in our day to day life I see many encumbered by the past and am waiting for the wonderful. We choose solutions that have more of the one size fits all. Instead of picking the best solutions for the roles that exist; we try to find the one item that can solve all of our problems. Rather than choosing the optimal product for the "one size", we should look at the product that enables the end user to perform optimally. Imagined if corporations took this approach with their products. Image a shoe manufacture that developed the one size fits all. It would be an opened toe, &amp;frac34; shank athletic tread, men's size 10, 3-inch heel, sneaker pump. It would meet most of the needs of the shoe-wearing world, but wouldn't be the right shoe for many, if anyone. So why do we settle for the same model in IT? We need to be innovative. We need to look at Apple, Google, Nintendo and others. They didn't just develop products that do what everyone else's products do today, but they did them differently &amp; in many cases better. What does it take to make your part of IT the next iPod, iPhone or Wii? How can we enable our partners to perform optimally? What does it take to just go out and do something without worrying about how many existing committees; review boards, processes and groups have to be engaged to just get it going? The answer is radical change. We need to change how we work. We need to change the level of control we have today. We need to shrink what we try to manage. We need to strive to enable the partners versus totally control their work life. We need to ask so what every once in a while. When someone says if we do A then B might happen. Ask the question, so what? We spend all this time doing the day-to-day moving from spot to spot, never worrying about the resources, costs and effort put into the status quo. When we try to implement something new, it goes under the microscope and quite often is held to a different standard than existing solutions. Requirements seem to be a never-ending monster of growth, instead of the simple point-by-point items they should be for solutions. Many times the solutions themselves are actually listed as the requirements. So I challenge us all to start a process of Radical Change. Start asking the question So What? Start pushing back on the status quo, quit being encumbered and start a process of innovation. Help your partners perform optimally and be a key part of their success rather than just one of their suppliers. It won't be easy, it won't always be fun, but it will be rewarding.</description>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">business_value</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">alternate_compute_models</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">manageability</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">management</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">next_generation</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">forward</category>
      <pubDate>Fri, 26 Sep 2008 21:03:07 GMT</pubDate>
      <author>VirtualDave</author>
      <guid>http://communities.intel.com/openport/blogs/it/2008/09/26/is-it-time-for-radical-change-in-it</guid>
      <dc:date>2008-09-26T21:03:07Z</dc:date>
      <clearspace:dateToText>1 week, 3 days ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/openport/blogs/it/comment/is-it-time-for-radical-change-in-it</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/it/feeds/comments?blogPostID=11580</wfw:commentRss>
    </item>
    <item>
      <title>Microsoft Hyper-V Updated to Support Intel's Xeon 7400</title>
      <link>http://communities.intel.com/openport/blogs/it/2008/09/25/microsoft-hyperv-updated-to-support-intels-xeon-7400</link>
      <description>I'm sure you've already seen press on the new &lt;a class="jive-link-external" href="http://www3.intel.com/cd/channel/reseller/asmo-na/eng/products/server/processors/7400/feature/index.htm"&gt;7400&lt;/a&gt; series of processes. It is a really exciting time to see 6 core procs coming out. Being an engineer that supports enterprise applications and technologies this should provide a lot of extra power to apps that were CPU bound to 4 procs. One such technology is virtualization and Microsoft's &lt;a class="jive-link-external" href="http://www.microsoft.com/windowsserver2008/en/us/hyperv.aspx"&gt;Hyper-V&lt;/a&gt;. Previously the limit of Hyper-V was 128 physical procs and 16 logical procs. Microsoft just released an &lt;a class="jive-link-external" href="http://support.microsoft.com/?kbid=956710"&gt;update&lt;/a&gt; that will increase those previous limits to support up to 192 physical procs and 24 logical procs! WOW, I can't wait to see that in action. This should definitely help organizations that need to limit their physical footprint of servers with their consolidation efforts. &lt;br /&gt;
&lt;br /&gt;
This is a great example of two companies combining their technology in ways that really benefit the customer. Very exciting times...I can't wait for even more cores!!!</description>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">xeon</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">xeon_7400</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">hyper-v</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">virtualization</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">brian_mccann</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">green_data_centers</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">server_consolidation</category>
      <pubDate>Thu, 25 Sep 2008 15:27:21 GMT</pubDate>
      <author>BrianMcCann</author>
      <guid>http://communities.intel.com/openport/blogs/it/2008/09/25/microsoft-hyperv-updated-to-support-intels-xeon-7400</guid>
      <dc:date>2008-09-25T15:27:21Z</dc:date>
      <clearspace:dateToText>1 week, 5 days ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/openport/blogs/it/comment/microsoft-hyperv-updated-to-support-intels-xeon-7400</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/it/feeds/comments?blogPostID=11573</wfw:commentRss>
    </item>
    <item>
      <title>Defeating malware infections with Intel system defense part 3 - automation</title>
      <link>http://communities.intel.com/openport/blogs/it/2008/09/17/defeating-malware-infections-with-intel-system-defense-part-3-automation</link>
      <description>The third and last part of the video series discussing how you can make use of the vPro system defense capabilities the easy way is out, this video shows an example of how your existing security server can implement network quarantine using system defense on provisioned devices without having to know a thing about AMT.&lt;br /&gt;
The video follows on the second video which showed an example of using system defense through the Microsoft SCOM GUI and shows a proof of concept implementation that only requires the security server to input an event into the local windows event log which is easily doable with almost any programming/script language. Behind the scene the SCOM agent installed on the security server intercepts this event, sends notification to the SCOM server and as a result the SCOM server implements the blocking policy on the offending host.&lt;br /&gt;
&lt;br&gt;
&lt;script type="text/javascript" src="http://www.podtech.net/player/popup.js"&gt;&lt;/script&gt;&lt;object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0" width="320" height="269" id="player6608b349ef9b4c928ca8b02b50a4c732" align="middle"&gt;&lt;param name="allowScriptAccess" value="always" /&gt;&lt;param name="FlashVars" value="content=http://media1.podtech.net/media/2008/09/PID_013739/Podtech_Intel_vPro_AMT3.flv&amp;totalTime=273000&amp;permalink=http://www.podtech.net/home/5355/isolation-of-infected-pcs-and-remediation-with-intel-vpro-technology-part-3-of-3&amp;breadcrumb=6608b349ef9b4c928ca8b02b50a4c732" height="269" width="320" /&gt;&lt;param name="movie" value="http://www.podtech.net/player/podtech-player.swf?bc=6608b349ef9b4c928ca8b02b50a4c732" /&gt;&lt;param name="quality" value="high" /&gt;&lt;param name="scale" value="noscale" /&gt;&lt;param name="bgcolor" value="#000000" /&gt;&lt;embed name="player6608b349ef9b4c928ca8b02b50a4c732" type="application/x-shockwave-flash" src="http://www.podtech.net/player/podtech-player.swf?bc=6608b349ef9b4c928ca8b02b50a4c732" flashvars="content=http://media1.podtech.net/media/2008/09/PID_013739/Podtech_Intel_vPro_AMT3.flv&amp;totalTime=273000&amp;permalink=http://www.podtech.net/home/5355/isolation-of-infected-pcs-and-remediation-with-intel-vpro-technology-part-3-of-3&amp;breadcrumb=6608b349ef9b4c928ca8b02b50a4c732" height="269" width="320" allowScriptAccess="always" /&gt;&lt;/object&gt;&lt;noscript&gt;Your browser does not support JavaScript. This media can be viewed at &lt;a href="http://www.podtech.net/home/5355/isolation-of-infected-pcs-and-remediation-with-intel-vpro-technology-part-3-of-3"&gt;http://www.podtech.net/home/5355/isolation-of-infected-pcs-and-remediation-with-intel-vpro-technology-part-3-of-3&lt;/a&gt;&lt;/noscript&gt;
&lt;br&gt;&lt;br&gt;
The beauty of this is that now you can choose any server to collect and correlate your security events and take quarantine decisions and all that without this server having to be an AMT management server. the existing AMT manager (SCOM in this example) is doing the hard work for you.&lt;br&gt;
as before I hope you find this useful, I would love to hear comments and answer any questions.&lt;br /&gt;
Cheers &lt;br&gt;
Omer.</description>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">amt</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">event_manager</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">filtering</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">it@intel</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">management</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">network_quarantine</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">omer_ben_shalom</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">quarantine</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">ron_miller</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">security</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">system_defense</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">video</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">virus</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">vpro</category>
      <pubDate>Thu, 18 Sep 2008 04:50:52 GMT</pubDate>
      <author>Omer Ben-Shalom</author>
      <guid>http://communities.intel.com/openport/blogs/it/2008/09/17/defeating-malware-infections-with-intel-system-defense-part-3-automation</guid>
      <dc:date>2008-09-18T04:50:52Z</dc:date>
      <clearspace:dateToText>2 weeks, 5 days ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/openport/blogs/it/comment/defeating-malware-infections-with-intel-system-defense-part-3-automation</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/it/feeds/comments?blogPostID=11536</wfw:commentRss>
    </item>
    <item>
      <title>Fortune Cookie Security Advice - September 2008</title>
      <link>http://communities.intel.com/openport/blogs/it/2008/09/17/fortune-cookie-security-advice-september-2008</link>
      <description>Everyone wants information security to be easy. Wouldn't it be nice if it were simple enough to fit snugly inside a fortune cookie? Well, although I don't try to promote such foolish nonsense, I do on occasion pass on readily digestible nuggets to reinforce security principles and get people thinking how security applies to their environment. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Common Sense&lt;/b&gt;&lt;br /&gt;
I think the key to fortune cookie advice is &amp;lsquo;common sense' in the context of security. It must be simple, succinct, and make sense to everyone, while conveying important security aspects.&lt;br /&gt;
&lt;br /&gt;
Here is my Fortune Cookie advice for September: &lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;&lt;b&gt;&lt;span style="color:#0000ff"&gt;In information security, like in sports, knowing your adversary is far more important than knowing the condition of the field.&lt;/span&gt;&lt;/b&gt;&lt;/blockquote&gt;
&lt;p /&gt;
&lt;p /&gt;
Information security is an adversarial pursuit. It all begins with threat agents, those people who will negatively affect your organization. Some are malicious, others are not. The key is they are living, breathing opponents whose motivations drive actions which cause loss. They learn, adapt, and change as they seek their objectives.&lt;br /&gt;
&lt;br /&gt;
Know your threats. This is an important first step. Knowing all your vulnerabilities is fine, but secondary in importance. &lt;br /&gt;
&lt;br /&gt;
For those who are malicious, understand what they target and the likely methods they will employ. Only then can the vulnerabilities be narrowed to show the most probable exposures. This prediction gives the security professional a focus on what to protect, how best to monitor, and preparations necessary to respond when needed. &lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
So am I contributing to the problem of over simplifying security? Or am I reaching out to those who might not take an inordinate amount of time necessary to understand the complexities and nuances of our industry? You decide and feel free to share your knowledge-nuggets. &lt;br /&gt;
&lt;p /&gt;
&lt;a class="jive-link-blogpost" href="http://communities.intel.com/openport/blogs/it/2008/08/25/fortune-cookie-security-advice-august-2008"&gt;Fortune Cookie Security Advice - August 2008&lt;/a&gt; &lt;br /&gt;
&lt;p /&gt;
&lt;a class="jive-link-blogpost" href="http://communities.intel.com/openport/blogs/it/2008/06/30/fortune-cookie-security-advice-june-2008"&gt;Fortune Cookie Security Advice - June 2008&lt;/a&gt; &lt;br /&gt;
&lt;p /&gt;
&lt;a class="jive-link-blogpost" href="http://communities.intel.com/openport/blogs/it/2008/05/27/fortune-cookie-security-advice-may-2008"&gt;Fortune Cookie Security Advice - May 2008&lt;/a&gt; &lt;br /&gt;
&lt;p /&gt;
&lt;a class="jive-link-blogpost" href="http://communities.intel.com/openport/blogs/it/2007/11/19/deconstructing-cyber-security-attacks-threat-model"&gt;Deconstructing Cyber Security Attacks - Threat Model&lt;/a&gt; &lt;br /&gt;
&lt;p /&gt;
&lt;a class="jive-link-blogpost" href="http://communities.intel.com/openport/blogs/it/2007/10/29/defense-in-depth-information-security-strategy"&gt;Defense in Depth Information Security Strategy&lt;/a&gt;</description>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">threat</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">security</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">roi</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">value</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">rosi</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">information_security</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">optimal_security</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">model</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">risk</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">matthew_rosenquist</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">rosenquist</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">policy</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">defense_in_depth</category>
      <pubDate>Wed, 17 Sep 2008 18:12:10 GMT</pubDate>
      <author>Matthew Rosenquist</author>
      <guid>http://communities.intel.com/openport/blogs/it/2008/09/17/fortune-cookie-security-advice-september-2008</guid>
      <dc:date>2008-09-17T18:12:10Z</dc:date>
      <clearspace:dateToText>2 weeks, 6 days ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/openport/blogs/it/comment/fortune-cookie-security-advice-september-2008</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/it/feeds/comments?blogPostID=11529</wfw:commentRss>
    </item>
    <item>
      <title>Defeating malware infections with Intel system defense</title>
      <link>http://communities.intel.com/openport/blogs/it/2008/08/26/defeating-malware-infections-with-intel-system-defense</link>
      <description>I'm Omer Ben-Shalom and I am a principal engineer with Intel information technology (IT) focusing on mobility and client platforms. I have had the pleasure of working with the Intel development teams on the vPro AMT system defense and decided to share my experiences via a three part video series showing how system defense can help in active response to infected PCs.&lt;br&gt;
There are many threats to the environment. the 'classical' threats originate from the outside and it is the job of the perimeter defenses such as firewalls, IPS and others to block them but the more problematic ones are those that originate from inside the perimeter, these type of attacks are mostly conducted from legitimate machines owned by the business and are quite often carried inside the perimeter unknowingly by employees especially when using mobile platforms such as notebooks which are carried outside the business and back in.&lt;br&gt;Detecting infected PCs and other malicious activity is done with the help of the various intrusion detections systems and the alerts generated can be collected and aggregated to provide a very good picture of the existing threats. A much more difficult task is the ability to quarantine the hosts carrying out the malicious activity and perform remediation. there are solutions involving both host software and network side blocking but with the host possibly compromised and the network location of the offending host subject to change with mobile platforms effective quarantine and remediation is very complex.&lt;br /&gt;
This is where the Intel vPro system defense capabilities come into play by allowing selective network access restrictions on a host, these restrictions can allow only the connectivity necessary to fix the problem and being implemented on the host platform itself cannot be escaped just by changing the network location.&lt;br&gt;
This week we are publishing the first of a three part video series on how to use system defense for this purpose both manually and via integration to existing AMT management. I hope you will all take the time to view the introduction video below. any comments are welcome. I would love to hear your views about the problem as well as the solution.&lt;br /&gt;
&lt;br&gt;
&lt;br&gt;
&lt;script type="text/javascript" src="http://www.podtech.net/player/popup.js"&gt;&lt;/script&gt;&lt;object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0" width="480" height="299" id="player14a7fa333c9d40418ea589c1ac736cbf" align="middle"&gt;&lt;param name="allowScriptAccess" value="always" /&gt;&lt;param name="FlashVars" value="content=http://media1.podtech.net/media/2008/08/PID_013712/Podtech_Intel_vPro_AMT1.flv&amp;totalTime=214000&amp;permalink=http://www.podtech.net/home/5329/vpro-technology-system-defense-nar-videos-part-1-of-3&amp;breadcrumb=14a7fa333c9d40418ea589c1ac736cbf" height="299" width="480" /&gt;&lt;param name="movie" value="http://www.podtech.net/player/podtech-player.swf?bc=14a7fa333c9d40418ea589c1ac736cbf" /&gt;&lt;param name="quality" value="high" /&gt;&lt;param name="scale" value="noscale" /&gt;&lt;param name="bgcolor" value="#000000" /&gt;&lt;embed name="player14a7fa333c9d40418ea589c1ac736cbf" type="application/x-shockwave-flash" src="http://www.podtech.net/player/podtech-player.swf?bc=14a7fa333c9d40418ea589c1ac736cbf" flashvars="content=http://media1.podtech.net/media/2008/08/PID_013712/Podtech_Intel_vPro_AMT1.flv&amp;totalTime=214000&amp;permalink=http://www.podtech.net/home/5329/vpro-technology-system-defense-nar-videos-part-1-of-3&amp;breadcrumb=14a7fa333c9d40418ea589c1ac736cbf" height="299" width="480" allowScriptAccess="always" /&gt;&lt;/object&gt;&lt;noscript&gt;Your browser does not support JavaScript. This media can be viewed at &lt;a href="http://www.podtech.net/home/5329/vpro-technology-system-defense-nar-videos-part-1-of-3"&gt;http://www.podtech.net/home/5329/vpro-technology-system-defense-nar-videos-part-1-of-3&lt;/a&gt;&lt;/noscript&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
I hope you enjoyed this video, parts two and three should post by next week, stay tuned</description>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">it@intel</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">ron_miller</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">omer_ben_shalom</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">vpro</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">system_defense</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">security</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">event_manager</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">virus</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">network_quarantine</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">quarantine</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">management</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">video</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">filtering</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">amt</category>
      <pubDate>Tue, 26 Aug 2008 22:11:00 GMT</pubDate>
      <author>Omer Ben-Shalom</author>
      <guid>http://communities.intel.com/openport/blogs/it/2008/08/26/defeating-malware-infections-with-intel-system-defense</guid>
      <dc:date>2008-08-26T22:11:00Z</dc:date>
      <clearspace:dateToText>1 month, 1 week ago</clearspace:dateToText>
      <clearspace:replyCount>2</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/openport/blogs/it/comment/defeating-malware-infections-with-intel-system-defense</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/it/feeds/comments?blogPostID=11466</wfw:commentRss>
    </item>
    <item>
      <title>Data goes bye bye -- do you backup your personal stuff?</title>
      <link>http://communities.intel.com/openport/blogs/it/2008/08/25/data-goes-bye-bye-do-you-backup-your-personal-stuff</link>
      <description>The loud crash from upstairs brought me out of my restful state with a surge of adrenalin. As this wonder-drug coursed through my veins I immediately became aware of everything. The Tick-tock of the clock, the dog breathing in the corner and floorboard creaks from upstairs. I kept telling myself that the storm outside must have caused something to shift -- something simple and not so scary. Starting up the stairs, eyes darting, the beat of my heart drowned out my adrenalin edge. Near the top of the landing there was a flash of lighting, a large boom, and the lights went out as I saw a figure lunge at me, knocking me down to the landing below.&lt;br /&gt;
&lt;br /&gt;
Nightmares can manifest themselves in many forms. I'll leave the ending up to you, however, I am currently living a nightmare with regards to my personal data at home.&lt;br /&gt;
&lt;br /&gt;
About ten months ago I took the plunge into the terabyte (TB) arena and bought an external drive. This enabled me to pull information from many sources in order to supply a consolidated view of different media (movies, pictures and music) to the family. As I was going through this evolution I started removing data from internal drives, and making neat and organized structures on the external drive. It was fast and friendly and up until a few weeks ago, it was also reliable.&lt;br /&gt;
&lt;br /&gt;
That's when the nightmare began.&lt;br /&gt;
&lt;br /&gt;
One day I turned on my home system and noticed that the external drive would no longer connect (it actually connected and disconnected about five times a minute). This was the one time I had turned off the computer and forgot to turn off the external drive, so I figured it had just gotten hot and was in some self-protection mode with a thermal overload. No such luck.&lt;br /&gt;
&lt;br /&gt;
The enclosure (device containing he hard-drives) had failed.&lt;br /&gt;
&lt;br /&gt;
I contained my anxiety because it was obvious it was the enclosure and not the drives (through some hardware diagnostics). So I figured I would simply mount the drives and extract the data that was not backed-up on DVD (about 8 months of video and photos).&lt;br /&gt;
&lt;br /&gt;
Again, no luck. The problem was caused by the type of enclosure I had purchased.&lt;br /&gt;
&lt;br /&gt;
There are multiple types of drive configurations on the market, and if you are not aware of what type your enclosure uses, you could find yourself in the same boat I'm in. The specific one I had was configured (from the factory) as a RAID-0. For the unaware, RAID (redundant array of inexpensive disks, &lt;a class="jive-link-external" href="http://en.wikipedia.org/wiki/Redundant_array_of_independent_disks"&gt;http://en.wikipedia.org/wiki/Redundant_array_of_independent_disks&lt;/a&gt;) has different settings (or levels), which are configured based on the level of security and speed you want for your data.&lt;br /&gt;
&lt;br /&gt;
The vendor had configured this as a RAID-0 to maximize the space available and maximize speed. The benefits of a RAID-0 come at a price. This array configuration (with two drives) basically splits the data in half and writes each half, simultaneously, to each drive. Half the time to write, half the time to read, makes it very fast. The basic problem is that only half the data exists on each drive meaning no drive is of use without the other. And when there is corruption of a logical disk or you want to switch to a new enclosure, you are stopped by the fact that most hardware RAID controllers use proprietary disk layouts.&lt;br /&gt;
&lt;br /&gt;
I know they are proprietary since I've tried reading these drives with three different RAID-0 arrays (which is also why I know the drives work fine, through diagnostics).&lt;br /&gt;
&lt;br /&gt;
My next step is to try and perform a soft-RAID setup internally to my computer.&lt;br /&gt;
This involves creating an image of each drive and using software to try and detect the different parameters of the RAID setup, in order to emulate the hardware configuration. If this works I should be able to pull my data off of the drives.&lt;br /&gt;
&lt;br /&gt;
What do I do with the data?&lt;br /&gt;
Well, I have sufficient internal storage to keep it while I catch up on 8-months worth of DVD back-ups. Long-term I am looking to a RAID-5 setup in hopes of solving my data storage, security and hardware failure worries.&lt;br /&gt;
&lt;br /&gt;
Bottom line.&lt;br /&gt;
Be aware how your external (or internal) setup is configured. If you see RAID-0 or JBOD, then you have zero protection and must have a way to perform back-ups. Yes, I could try to have some external data recovery company perform the data restoration, however, I would rather do it myself and save the cash for a back-up system.&lt;br /&gt;
&lt;br /&gt;
How do you ensure you don't lose anything of value?&lt;br /&gt;
Have you encountered a similar issue?</description>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">personal_data</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">back_up</category>
      <pubDate>Mon, 25 Aug 2008 21:07:14 GMT</pubDate>
      <author>John Simpson</author>
      <guid>http://communities.intel.com/openport/blogs/it/2008/08/25/data-goes-bye-bye-do-you-backup-your-personal-stuff</guid>
      <dc:date>2008-08-25T21:07:14Z</dc:date>
      <clearspace:dateToText>1 month, 1 week ago</clearspace:dateToText>
      <clearspace:replyCount>4</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/openport/blogs/it/comment/data-goes-bye-bye-do-you-backup-your-personal-stuff</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/it/feeds/comments?blogPostID=11465</wfw:commentRss>
    </item>
    <item>
      <title>Fortune Cookie Security Advice - August 2008</title>
      <link>http://communities.intel.com/openport/blogs/it/2008/08/25/fortune-cookie-security-advice-august-2008</link>
      <description>Everyone wants information security to be easy. Wouldn&amp;rsquo;t it be nice if it were simple enough to fit snugly inside a fortune cookie? Well, although I don&amp;rsquo;t try to promote such foolish nonsense, I do on occasion pass on readily digestible nuggets to reinforce security principles and get people thinking how security applies to their environment. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Common Sense&lt;/b&gt;&lt;br /&gt;
I think the key to fortune cookie advice is &amp;lsquo;common sense&amp;rsquo; in the context of security. It must be simple, succinct, and make sense to everyone, while conveying important security aspects.&lt;br /&gt;
&lt;br /&gt;
Here is my Fortune Cookie advice for August: &lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;&lt;span style="color:#0000ff"&gt;&lt;b&gt;Security policy is like a seatbelt. It will not protect you every time, but it is guaranteed to fail if you choose not to use it.&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;
&lt;br /&gt;
No security policy is perfect. In fact, it should be a continuously evolving body of work which is improved as the industry changes and learns. The biggest challenge is not the exactness of the policies; rather it is the awareness and consistent adoption by the employees. An appropriate level of effort must be directed at the successful marketing and support by the target audience.&lt;br /&gt;
&lt;br /&gt;
It may not be sexy, but policy can empower the Management support and maintenance of policy are key factors in leveraging this tool. Clear and straightforward verbiage coupled with sufficient marketing saturation can deliver necessary awareness to affect behaviors. With employee support of security principles, an organization takes a great step forward in achieving an optimal security posture. &lt;br /&gt;
&lt;p /&gt;
So am I contributing to the problem of over simplifying security? Or am I reaching out to those who might not take an inordinate amount of time necessary to understand the complexities and nuances of our industry? You decide and feel free to share your knowledge-nuggets.&lt;br /&gt;
&lt;p /&gt;
&lt;a class="jive-link-blogpost" href="http://communities.intel.com/openport/blogs/it/2008/08/20/a-company-s-greatest-security-threat-and-asset"&gt;A Company&amp;rsquo;s Greatest Security Threat and Asset&lt;/a&gt;&lt;br /&gt;
&lt;p /&gt;
&lt;a class="jive-link-blogpost" href="http://communities.intel.com/openport/blogs/it/2008/06/30/fortune-cookie-security-advice-june-2008"&gt;Fortune Cookie Security Advice - June 2008&lt;/a&gt;&lt;br /&gt;
&lt;p /&gt;
&lt;a class="jive-link-blogpost" href="http://communities.intel.com/openport/blogs/it/2008/05/27/fortune-cookie-security-advice-may-2008"&gt;Fortune Cookie Security Advice - May 2008&lt;/a&gt;</description>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">security</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">roi</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">value</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">rosi</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">information_security</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">optimal_security</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">model</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">risk</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">matthew_rosenquist</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">rosenquist</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">policy</category>
      <pubDate>Mon, 25 Aug 2008 17:27:54 GMT</pubDate>
      <author>Matthew Rosenquist</author>
      <guid>http://communities.intel.com/openport/blogs/it/2008/08/25/fortune-cookie-security-advice-august-2008</guid>
      <dc:date>2008-08-25T17:27:54Z</dc:date>
      <clearspace:dateToText>1 month, 1 week ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/openport/blogs/it/comment/fortune-cookie-security-advice-august-2008</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/it/feeds/comments?blogPostID=11464</wfw:commentRss>
    </item>
    <item>
      <title>Are Security ROI Figures Meaningless?</title>
      <link>http://communities.intel.com/openport/blogs/it/2008/08/25/are-security-roi-figures-meaningless</link>
      <description>Recently, security expert Bruce Schneier expounded security ROI figures were meaningless! Is it true? Well, yes and no. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;The brutal truth.&lt;/b&gt;&lt;br /&gt;
Well respected information security expert Bruce Schneier recently provided a stark opinion regarding the value of ROI's.&lt;br /&gt;
Follow this link to see the story: &lt;br /&gt;
&lt;a class="jive-link-external" href="http://www.zdnetasia.com/news/security/0,39044215,62037905,00.htm"&gt;http://www.zdnetasia.com/news/security/0,39044215,62037905,00.htm&lt;/a&gt; &lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
In brief, Bruce stated security because numbers can be manipulated to justify anything.&lt;br /&gt;
&lt;blockquote&gt;He explained that the amount spent on a product can change significantly by simply playing with the equation. &lt;br clear="all" /&gt;	"If the chance of you being attacked is one in a million and I change it to one in two million... I have halved the amount of money you should spend. &lt;br clear="all" /&gt;	"I can make an ROI model say whatever I want. I could justify or not justify anything based on these very, very rare and very, very damaging events," he said.&lt;/blockquote&gt;
&lt;br /&gt;
&lt;b&gt;Tell me it is not true!&lt;/b&gt;&lt;br /&gt;
I believe Bruce is both right and is delivering a message which is a little incomplete. His general message is accurate and shocking enough to garner the right level of attention. Most of the information security ROI's I have read were speculative, could not be validated, were impossible to reproduce, and had great latitude to provide results which benefit the desires of the author. Nowadays audiences are being provided &amp;lsquo;information' under the auspices of &amp;lsquo;fact', when in reality they are more of an opinion. Such valuation assessments are based on qualitative data versus quantitative metrics. &lt;br /&gt;
&lt;br /&gt;
I blogged about the &lt;a class="jive-link-blogpost" href="http://communities.intel.com/openport/blogs/it/2007/08/14/the-problem-of-measuring-information-security"&gt;The Problem of Measuring Information Security&lt;/a&gt; back in August 2007 &lt;br /&gt;
&lt;br /&gt;
Awareness must be raised. I applaud Bruce in helping to make this happen. His message, as brutal as it sounds, is bringing to light a shadowy area in our industry. I think the follow-up message for audiences is to scrutinize and apply common sense to any ROI they come across. Understand the methodology and if it makes sense in their context. Lifting the curtain can quickly reveal a puppet master pulling the strings to artificially show value. &lt;br /&gt;
&lt;br /&gt;
Like Bruce, I too have a jaded perspective. I have seen some WILD ROI's. Much of what I have read from security vendors is pure folly. However, just because most are fiction, it does not mean all methodologies are without merit. &lt;br /&gt;
&lt;br /&gt;
Intel published a &lt;a class="jive-link-blogpost" href="http://communities.intel.com/openport/blogs/it/2007/12/11/whitepaper-measuring-the-return-on-it-security-investments"&gt;Whitepaper - Measuring the Return on IT Security Investments&lt;/a&gt; which is applicable to some situations. This method, far from being a silver-bullet, is a good start and has proven its truthfulness. &lt;br /&gt;
&lt;br /&gt;
For any method, the accuracy should be scrutinized. Can it be validated, repeated? Was the method exclusively developed solely for self serving purposes from someone trying to sell something shiny? Does it make sense? These are the questions I ask myself. &lt;br /&gt;
&lt;br /&gt;
On the bright side, many bright sharp people are working very hard to make the industry better and develop more rigid processes to insure both accuracy and confidence. &lt;br /&gt;
&lt;br /&gt;
In the end, there is much work to be done in the information security valuation space. In the meanwhile, savvy consumers should be aware of the challenges and dive deeper into prospective ROI's and determine if they are &amp;lsquo;meaningless'.</description>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">security</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">roi</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">value</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">rosi</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">information_security</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">optimal_security</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">model</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">risk</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">matthew_rosenquist</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">rosenquist</category>
      <pubDate>Mon, 25 Aug 2008 14:56:19 GMT</pubDate>
      <author>Matthew Rosenquist</author>
      <guid>http://communities.intel.com/openport/blogs/it/2008/08/25/are-security-roi-figures-meaningless</guid>
      <dc:date>2008-08-25T14:56:19Z</dc:date>
      <clearspace:dateToText>5 months, 3 days ago</clearspace:dateToText>
      <clearspace:replyCount>7</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/openport/blogs/it/comment/are-security-roi-figures-meaningless</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/it/feeds/comments?blogPostID=11138</wfw:commentRss>
    </item>
    <item>
      <title>Are today’s IT shops doomed to repeat the never ending cycle of re-inventing the wheel?</title>
      <link>http://communities.intel.com/openport/blogs/it/2008/08/21/are-today-s-it-shops-doomed-to-repeat-the-never-ending-cycle-of-reinventing-the-wheel</link>
      <description>As I sit back and think of some of the newer technologies we have looked at recently, I find myself wondering if IT is in the never ending cycle of re-inventing the wheel.  What I mean by this is sometimes it seems as if we continue to try and re-engineer everything to make it fit our environment or how we think it should work.  When viewing newer technologies, usage models and trying to pass data off to other groups the phrases I think I hear the most are, “That will never work in our environment,” or “If we can get them to change this, this and this, we may be able to use it here” or my favorite, “This will never be secure enough for us to use it as it exists”.  While these may be valid assessments against the way we do things today, the big question is: should we be pushing ourselves to look for new ways of doing things?  Five years ago, employees preferred to use their machines and software loads supplied by IT because they were more powerful or feature rich than anything they had at home.  But in today’s society, people have higher end machines at home than IT supplies them.  They also use newer technologies that are usually off limits or not supported by IT.  Think of some of the tools we use today, such as this blog or even instant messaging.  These technologies exist in our corporate environment because we saw people using them at home and brought them into our corporate environment.  It wasn’t something that IT created and people took home to use.  So with so many of these newer technologies out there, should we keep pushing to make them adapt to our IT world, or should we start pushing IT to start adapting to new models.  We take umbrella approaches to everything today.  Total security of the platform, instead of trying to reduce the footprint we have to manage.  We look for solutions that will cover the majority of the users, versus what may be right for smaller enclaves.  We place several management clients on the platform to perform numerous tasks instead of using native components or reducing some of the redundant requirements we have.  Moving forward, the next generation of workers will expect businesses to offer familiar technology and won’t accept tradition as an excuse. IT shops need to provide workers with “cool” ways to work. If they don’t, they risk becoming obsolete.</description>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">it</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">value</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">innovation</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">generation</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">usage</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">model</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">alternate_compute_models</category>
      <pubDate>Thu, 21 Aug 2008 18:32:55 GMT</pubDate>
      <author>VirtualDave</author>
      <guid>http://communities.intel.com/openport/blogs/it/2008/08/21/are-today-s-it-shops-doomed-to-repeat-the-never-ending-cycle-of-reinventing-the-wheel</guid>
      <dc:date>2008-08-21T18:32:55Z</dc:date>
      <clearspace:dateToText>1 month, 2 weeks ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/openport/blogs/it/comment/are-today-s-it-shops-doomed-to-repeat-the-never-ending-cycle-of-reinventing-the-wheel</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/it/feeds/comments?blogPostID=11457</wfw:commentRss>
    </item>
    <item>
      <title>Community building around software developers</title>
      <link>http://communities.intel.com/openport/blogs/it/2008/08/21/community-building-around-software-developers</link>
      <description>The early morning dew glistens as the light of dawn wakens the cactus blossoms of the Arizona desert. Of course, at this time of the year, it never gets cool enough for dew to build or blossoms to go to sleep. During the late summer there are winds that blow through the sands, kicking up dust, and filling the maddening clouds with thick rain. These winds blow hard. These winds cause the desert to change.&lt;br /&gt;
&lt;br /&gt;
There are other winds that have been blowing through the business world enabling a convergence of technology and usage patterns. What was once firmly outside the firewall, and considered only for those on the fringe, is now being embraced and pulled inside. &lt;br /&gt;
&lt;br /&gt;
Social Media (corporately named Professional Media) can be used to enhance your work force like no other tool/technology/use ever has. In the past, when you were looking for an expert, trying to solve a problem, or interested in posting a solution, you did so within the confines of your close personal network. Today, as many of the common social media tools embraced by the business world, that personal network is expanding to involve the whole company. In my case that number approaches 100,000 people.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;My specific opportunity involves the forming of a company-based, professional society of software developers.&lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
Why is this important or even needed? Let's say you are starting a new project to create a web-based sales system. While going through the design process you decide upon a certain software platform, specific languages and messaging mechanisms. After the design is approved you then need to setup your development and testing environments as well as any compilation/deployment mechanisms necessary to manage your processes. For just about every project, this has been a large chunk of time and effort because each individual group had become their own pocket of excellence.&lt;br /&gt;
&lt;br /&gt;
What is a pocket of excellence? This would be the team, or individual, who does their job really well, because the processes (and tools) they have in place correspond to the needs and expectations of their immediate team. It is the single person doing it the same way because that way works and meets the customer&amp;rsquo;s needs.&lt;br /&gt;
&lt;br /&gt;
A pocket of excellence is a personal (or private) network based solution to their local problem (software development).&lt;br /&gt;
&lt;br /&gt;
My goal is to start a society of loosely coupled software developers willing to share their thoughts and ideas in order to allow those private networks to become global in scale. In sharing their data from their pocket of excellence, they begin to gain a wider insight regarding their approach. They may get input to improve it or in turn may see something which makes sense and simplifies their own solution. It should resolve itself into a library of processes and a network of people, in order to help make their jobs better.&lt;br /&gt;
&lt;br /&gt;
Some of the focus areas that I have targeted in our society are:&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;Education&lt;/li&gt;
&lt;li&gt;Standards&lt;/li&gt;
&lt;li&gt;Technologies&lt;/li&gt;
&lt;li&gt;Tools/Utilities&lt;/li&gt;
&lt;li&gt;Design&lt;/li&gt;
&lt;li&gt;Testing&lt;/li&gt;
&lt;li&gt;Deployment&lt;/li&gt;
&lt;li&gt;Supportability&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
I will follow up with some expansion of this and further explanations of how social (professional) media can help to enable this on a company scale. I would love to hear about any efforts in your company, or feedback on what we are attempting to do.</description>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">social_media</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">software_development</category>
      <pubDate>Thu, 21 Aug 2008 13:54:53 GMT</pubDate>
      <author>John Simpson</author>
      <guid>http://communities.intel.com/openport/blogs/it/2008/08/21/community-building-around-software-developers</guid>
      <dc:date>2008-08-21T13:54:53Z</dc:date>
      <clearspace:dateToText>1 month, 2 weeks ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/openport/blogs/it/comment/community-building-around-software-developers</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/it/feeds/comments?blogPostID=11452</wfw:commentRss>
    </item>
    <item>
      <title>Can Client Virtualization lead to a simpler IT environment?</title>
      <link>http://communities.intel.com/openport/blogs/it/2008/08/20/can-client-virtualization-lead-to-a-simpler-it-environment</link>
      <description>For the past year I have been working with several client technologies that revolve around the area of Client Virtualization. As I looked into these technologies and benchmarked them, I began to realize several key things. &lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;These technologies are finally mature enough to start using mainstream&lt;/b&gt;. True they may not all fit your current IT model, security rules or management framework, but that is another discussion. The pure fact is with hardware virtualization now enabled in chipsets, we can expect virtualized environments that perform faster than yesterday's systems and almost as fast as the host OS. Moving forward, technologies will be released that will support side by side OS or multiple instance virtual machines. Imagine a world where IT can manage something as simple as a virtual environment and get out of the platform support and enterprise OS business. There are tools there today that allow this to happen and we have done some work in this area and released a white paper recently with our results, it is called Client Computing with a VUE and can be found at (&lt;a class="jive-link-external" href="http://communities.intel.com/docs/DOC-1638"&gt;http://communities.intel.com/docs/DOC-1638&lt;/a&gt;). The key is to make sure you start planning around these technologies now, versus scrambling to support them later.&lt;/li&gt;
&lt;/ul&gt;
&lt;p /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Some of these technologies are flexible enough, they can be used to enable our users in ways we never could before&lt;/b&gt; - Imagine going home at night and not having to carry a laptop. Simply carrying a USB stick that has your IT build on it and being able to plug it into your home system to check email, review documents etc. Imagine users having a choice in the platforms they use. No longer is getting a system in IT like picking the first Model T, do you want black or black? We could enable our users today to be able to simply go to any computer access a website, log in and authenticate, and a few moments later, they can have corporate apps streamed to the system they are on and access their data from cloud storage.&lt;/li&gt;
&lt;/ul&gt;
&lt;p /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;IT can sometimes be more than a cost center&lt;/b&gt; - After reviewing some of these technologies, I realized we as IT could use some of these to provide more than standard services to the corporate environments we support. Imagine a corporate environment with thousands of desktops that users use day to day but don't fully utilize. Using some of these technologies, we can take processor and memory slices off these machines and add them to a grid computing environment. Allowing our corporation several thousand more process cycles without having to expand their server or data center space.&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
Again, not all of these can drop right into your environment today. Some things may need to change on the technology or your IT side. But the key is this area is changing fast. Let's stop thinking about how we have always done it and instead ask how we should do this tomorrow. &lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;br /&gt;
Feel free to comment and leave your thoughts!</description>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">client</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">virtualization</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">streaming</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">operating_sytems</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">application</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">saas</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">innovation</category>
      <pubDate>Wed, 20 Aug 2008 21:00:06 GMT</pubDate>
      <author>VirtualDave</author>
      <guid>http://communities.intel.com/openport/blogs/it/2008/08/20/can-client-virtualization-lead-to-a-simpler-it-environment</guid>
      <dc:date>2008-08-20T21:00:06Z</dc:date>
      <clearspace:dateToText>1 month, 2 weeks ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/openport/blogs/it/comment/can-client-virtualization-lead-to-a-simpler-it-environment</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/it/feeds/comments?blogPostID=11451</wfw:commentRss>
    </item>
    <item>
      <title>A Company’s Greatest Security Threat and Asset</title>
      <link>http://communities.intel.com/openport/blogs/it/2008/08/20/a-company-s-greatest-security-threat-and-asset</link>
      <description>Can an organizations greatest security asset also be its most serious threat?  Yes it can.&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;br /&gt;
&lt;b&gt;The Greatest Asset&lt;/b&gt;&lt;br /&gt;
I manage information security for Intel’s mergers and acquisitions.  Recently, I was evaluating an acquired company and delivering information security training to our newest employees on their collective hire date.  As I was presenting the fundamentals of how to keep the company, their work, and our industry safe from cyber threats, an important security maxim was exemplified.  &lt;br /&gt;
&lt;br /&gt;
In interacting with the audience, I understood how they were accustomed to conduct business, the scope of information they handle on a daily basis, and their views on the value of security.  I began to emphasize how the employee base was the greatest asset to information security and the combined force of a well informed, properly trained, and security savvy workforce dwarfs the efforts of the dedicated security staff.  My recruitment speech sunk in and their faces glowed with pride.  I saw a bit of excitement from the audience, that of empowerment and newfound responsibility.  I was setting them up.  Although absolutely true, a few slides later in my presentation I unveiled the stark reality.    &lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
&lt;b&gt;The Greatest Threat&lt;/b&gt;&lt;br /&gt;
I asked to my newly recruited security champions what the greatest threat to the company was.  Amid different answers, I revealed that &lt;i&gt;THEY&lt;/i&gt; were the greatest threat.  Not just them, but the entire workforce.  The glow in their faces dimmed a bit.  How can this be?  How can our employees be both the greatest asset and the worst enemy in the cyber warfare trenches?  They were shocked.  They were dumbfounded.  They were intrigued.  I gave a dramatic pause.  It is not often people are captivated by the boring and bothersome topic of information security.  I savored the moment.    &lt;br /&gt;
&lt;br /&gt;
The real battlefield is in hearts and minds of employees.  These new employees, more than any, represent the greatest challenge.  They are accustomed to their previous ways, inundated with new-hire information, and are not familiar with the security expectations of their new corporate parent.  Security policy is a distant concern on their first day.  Every subsequent day, the separated cluster of workers will not benefit from the social reinforcement of good security practices as they are distanced from the collective body of experienced employees who exhibit secure behaviors.&lt;br /&gt;
&lt;br /&gt;
We discussed how apathy, laziness, and circumventing policy for a quick gain, can cause significant weaknesses in security.  Every employee has a responsibility to be secure and reinforce those fundamentals with their peers.  A single employee through malice or carelessness can cause more damage than a legion of hackers.  They must decide, through their actions, if they are the security marshals or the villains of the story.  The battle is with the mindset of the employees.  The finest security policy is worthless in the hands of an apathetic workforce.  &lt;br /&gt;
&lt;br /&gt;
In the end, the discussion was a success.  It was not just training; it was an interactive dialogue talking to what is important and how every employee, now including them, work as a team to be Intel’s greatest security asset. &lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
So, who do you market to?</description>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">security</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">value</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">policy</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">threat</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">security_threat</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">information_security</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">optimal_security</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">model</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">risk</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">matthew_rosenquist</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">rosenquist</category>
      <pubDate>Wed, 20 Aug 2008 18:03:49 GMT</pubDate>
      <author>Matthew Rosenquist</author>
      <guid>http://communities.intel.com/openport/blogs/it/2008/08/20/a-company-s-greatest-security-threat-and-asset</guid>
      <dc:date>2008-08-20T18:03:49Z</dc:date>
      <clearspace:dateToText>1 month, 2 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/openport/blogs/it/comment/a-company-s-greatest-security-threat-and-asset</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/it/feeds/comments?blogPostID=11449</wfw:commentRss>
    </item>
    <item>
      <title>Intel Developer Forum Demo: Streaming Media over WiMax</title>
      <link>http://communities.intel.com/openport/blogs/it/2008/08/19/intel-developer-forum-demo-streaming-media-over-wimax</link>
      <description>If you are at the Intel Developer Forum in San Francisco this week you might want to visit the System-on-a-Chip Community for a very cool demonstration of streaming media over WiMax. Our Intel IT Team put this demostration together working with the Intel product developers and their ecosystem partners.&lt;br /&gt;
&lt;br /&gt;
This demonstration shows a connection between a corporate office and a remote branch office via WiMax. The branch office uses an all-in-one appliance (a secure mesh router) containing a WiMax radio. The corporate office has a WiMax basestation and streams multimedia content over the network connection back to the branch office. &lt;br /&gt;
&lt;br /&gt;
The secure mesh router in the demonstration is built using an Intel(R) EP80579 Integrated Processor formerly known as Tolapai. EP80579 is the first integrated processor that is a system-on-a-chip (SOC). This is important because it hails a new generation of smart, flexible, light and simple devices for the embedded internet. As an IT Researcher I'm no product expert so check out the full official &lt;a class="jive-link-external" href="http://www.intel.com/pressroom/kits/soc/?iid=SEARCH"&gt;SOC Press Kit&lt;/a&gt; for more details. &lt;br /&gt;
&lt;br /&gt;
Here are some pictures from IDF: &lt;br /&gt;
&lt;br /&gt;
&lt;img src="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1778/BoothImage014.jpg" alt="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1778/BoothImage014.jpg" class="jive-image"  /&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;img src="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1779/RouterImage011.jpg" alt="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1779/RouterImage011.jpg" class="jive-image"  /&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;img src="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1780/FullDemoWorkloadImage017.jpg" alt="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1780/FullDemoWorkloadImage017.jpg" class="jive-image"  /&gt; &lt;br /&gt;
&lt;br /&gt;
Stop in and say 'hi' to Bruce!</description>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">wimax</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">tolapai</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">soc</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">streaming</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">multimedia</category>
      <pubDate>Tue, 19 Aug 2008 19:42:32 GMT</pubDate>
      <author>Catherine Spence</author>
      <guid>http://communities.intel.com/openport/blogs/it/2008/08/19/intel-developer-forum-demo-streaming-media-over-wimax</guid>
      <dc:date>2008-08-19T19:42:32Z</dc:date>
      <clearspace:dateToText>1 month, 2 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/openport/blogs/it/comment/intel-developer-forum-demo-streaming-media-over-wimax</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/it/feeds/comments?blogPostID=11444</wfw:commentRss>
    </item>
    <item>
      <title>How do you record audits against software?</title>
      <link>http://communities.intel.com/openport/blogs/it/2008/08/12/how-do-you-record-audits-against-software</link>
      <description>In the world of effective software inventory management there are audits. Those audits are done comparing the software to physical installations or against budget. There are audits performed when a HFE (Human Factors Engineer) analyzes your usability or those done to ensure that you have sufficient disaster recovery elements in place.&lt;br /&gt;
&lt;p /&gt;
This happens every day against dozens of software applications and I have to ask the question -- where do you record this data? Does everyone have individual approaches and simply has a spreadsheet containing the data? Is it recorded anywhere?&lt;br /&gt;
&lt;br /&gt;
I have to wonder where the value is in gathering data that has no reuse or exposure to the owners of the software solutions.&lt;br /&gt;
&lt;br /&gt;
So I've been bouncing around an enhancement to allow certain groups to register (and report) on audits. Internally some people hate it and some love it.&lt;br /&gt;
&lt;br /&gt;
What do you do?&lt;br /&gt;
Do you have yet another application for capturing software audits?&lt;br /&gt;
Do you do them at all?&lt;br /&gt;
&lt;br /&gt;
Let me know.&lt;br /&gt;
&lt;br /&gt;
Previous topics include &lt;a class="jive-link-blogpost" href="http://communities.intel.com/openport/blogs/it/2008/02/21/application-inventory-what-do-you-capture"&gt;Application inventory, what do you capture?&lt;/a&gt;,  &lt;a class="jive-link-blogpost" href="http://communities.intel.com/openport/blogs/it/2008/02/13/application-inventory-starts-with-a-definition"&gt;Application inventory starts with a definition&lt;/a&gt;, &lt;a class="jive-link-blogpost" href="http://communities.intel.com/openport/blogs/it/2008/02/04/application-inventory-as-a-cost-savings-initiative"&gt;Application inventory as a cost savings initiative&lt;/a&gt;, &lt;a class="jive-link-blogpost" href="http://communities.intel.com/openport/blogs/it/2008/03/19/application-inventory-the-start-of-data-sustainability"&gt;Application Inventory, the start of data sustainability?&lt;/a&gt; and &lt;a class="jive-link-blogpost" href="http://communities.intel.com/openport/blogs/it/2008/06/20/how-do-you-measure-data-quality-in-your-application-inventory"&gt;How do you measure data quality in your Application Inventory?&lt;/a&gt;.</description>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">application_inventory</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">data_quality</category>
      <pubDate>Tue, 12 Aug 2008 17:08:27 GMT</pubDate>
      <author>John Simpson</author>
      <guid>http://communities.intel.com/openport/blogs/it/2008/08/12/how-do-you-record-audits-against-software</guid>
      <dc:date>2008-08-12T17:08:27Z</dc:date>
      <clearspace:dateToText>1 month, 3 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>2</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/openport/blogs/it/comment/how-do-you-record-audits-against-software</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/it/feeds/comments?blogPostID=11420</wfw:commentRss>
    </item>
    <item>
      <title>Keep Your Scary Software Out of the Workplace!</title>
      <link>http://communities.intel.com/openport/blogs/it/2008/07/29/keep-your-scary-software-out-of-the-workplace</link>
      <description>Today is the first day of participating in an IT Consortium around collaboration.  The hot topic seems to be around Enterprise 2.0.  Not surprising. I am speaking tomorrow around how Intel is using social computing tools to transform collaboration.  I will admit that I entered this discussion with a misperception about other company's state of maturity in "going social."  An open conversation began with discussions about whether companies block access behind the firewall to any social media sites.  An unbelieveable 75% said "yes" to sites like Facebook and YouTube but a bit more were receptive to LinkedIn.  I asked "why"?  Answer:  Business groups don't want their employees to "goof off" doing non-business activity during work time.  Also expressed were security and information control concerns.  I followed-up with a question asking of those companies that block social sites, how many have external corporate blog sites. Zero. I think corporations are trying to control something that no longer can be controlled.&lt;br /&gt;
&lt;br /&gt;
I flashed back to a great post on &lt;i&gt;Go Big Always&lt;/i&gt;.  The article captured historical reactions to disruptive software and technologies to corporations.  If you answered "yes" to blocking social sites and not finding business value in social software, then this is a MUST read!  It shows that sometimes reactions to change are more out of fear, than logic.  We are taking it as food for thought as Intel attempts to take our investment and usage of social software to the next level.  Below are the article's key takeaways (re-published):&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Email has no place at work (1994)&lt;/b&gt;&lt;br /&gt;
It’s clearly used for goofing off.  The last thing I want are my employees wasting my money emailing each other.  What’s the use case for email at work? What’s the ROI? Who else is doing it?  See &lt;a class="jive-link-external" href="http://www.bizjournals.com/columbus/stories/1997/10/06/newscolumn2.html"&gt;industry article&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Internet access has no place at work (1996)&lt;/b&gt;&lt;br /&gt;
Giving employees access to the internet would be a massive productivity problem.  Not to mention there are huge security concerns.  What’s the reason employees should be allowed to cybersurf?  See &lt;a class="jive-link-external" href="http://dir.salon.com/story/tech/log/1999/11/24/cyberslacking/"&gt;industry article&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;eCommerce is too high a risk for our company (1998)&lt;/b&gt;&lt;br /&gt;
Our company can’t afford the risk associated with opening ourselves up to new, unproven channels or even hacking.  There are a lot of thieves online.  Why would someone buy our products on the World Wide Web?  See &lt;a class="jive-link-external" href="http://news.cnet.com/Scared-into-e-commerce-Web-sites/2100-1017_3-228743.html"&gt;industry article&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Instant Messaging has no place at work (2002)&lt;/b&gt;&lt;br /&gt;
It’s a massive distraction.  Interruptions cost billions each year.  Employees shouldn’t be allowed to spend time chatting all day work.  Instant messaging has massive productivity loss implications.  See &lt;a class="jive-link-external" href="http://news.cnet.com/Driven-to-distraction-by-technology/2100-1022_3-5797028.html"&gt;industry article&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Social Software has no place at work (2005)&lt;/b&gt;&lt;br /&gt;
It’s clearly used for goofing off.  The last thing I want are my employees wasting my money blogging or networking with each other.  What’s the use case for social software at work? See &lt;a class="jive-link-external" href="http://query.nytimes.com/gst/fullpage.html?res=9400E1D61E3EF936A15751C0A9649C8B63"&gt;industry article&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
If IT is truly a strategic business partner, then let's start advising our businesses that not only can we not stop scary software, but that the software may not be that scary after all.</description>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">social_media</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">social_computing</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">social_productivity</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">social_enterprise</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">social_tools</category>
      <category domain="http://communities.intel.com/openport/blogs/it/tags">laurie_buczek</category>
      <pubDate>Wed, 30 Jul 2008 04:24:54 GMT</pubDate>
      <author>Laurie Buczek</author>
      <guid>http://communities.intel.com/openport/blogs/it/2008/07/29/keep-your-scary-software-out-of-the-workplace</guid>
      <dc:date>2008-07-30T04:24:54Z</dc:date>
      <clearspace:dateToText>2 months, 1 week ago</clearspace:dateToText>
      <clearspace:replyCount>4</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/openport/blogs/it/comment/keep-your-scary-software-out-of-the-workplace</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/it/feeds/comments?blogPostID=11388</wfw:commentRss>
    </item>
  </channel>
</rss>

