<?xml version="1.0" encoding="UTF-8" standalone="yes"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xml:base="http://blog.solidcore.com/public/" version="2.0"><!--

MySmartChannels™ RSS Feed

MySmartChannels is a service of MyST Technology Partners, Inc.
For more information, including standard terms of service, see:
http://myst-technology.com
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Customize this feed by adding any of the following URL parameters.

  description=none|summary|full (default=full)
  channelDescription=none|summary|full (default=value of 'description' parameter)
  itemDescription=none|summary|full (default=value of 'description' parameter)

  enhanced=true|false (default=false)

  limit=n (default=15)

  score=none|emoticon|simple|stars|text (default=text)

  smartPoints=true|false (default=true)

  sortKey=CreateTime|ModifyTime|Name|...any MyST-ML child element... (default=CreateTime)

  sortOrder=ascending|descending (default=descending)
--><channel>
     <title>ITIL | Solidcore Blog</title><link>http://blog.solidcore.com/public/blog/183011</link><description>ITIL for IT Change Control Management
        &lt;p&gt;This weblog provides information on how IT companies are implementing and achieving return on investment (ROI) from their ITIL investments.  Read how companies are leveraging the ITIL framework to support best practices, and using change control software to maximize efficiency and automation.&lt;/p&gt;
        &lt;p&gt;Subjects covered include:  ITIL, information technology infrastructure library, ITIL framework, ITIL best practices, IT operations best practices, ITIL implementation, ITIL ROI, ITIL return on investment, ITIL training, ITIL service management, ITSM, ITIL application management, BSM, business service management, file integrity monitoring, and how a controlled change environment can achieve quick returns on your ITIL investment.&lt;/p&gt;
    </description><atom:link type="application/rss+xml" rel="self" href="http://blog.solidcore.com/public/rss/183011?"/><language>en-us</language><copyright>Copyright (C) 2008 Solidcore--All Rights Reserved -- This channel is part of the Solidcore Blog blogsite--Powered by MyST Blogsite®.</copyright><pubDate>Thu, 13 Sep 2007 23:45:18 -0400</pubDate><lastBuildDate>Mon, 21 Jul 2008 16:48:55 -0400</lastBuildDate><generator>MySmartChannels V3.0 (MyST Web Service Platform V5.00.0717)</generator><image><url>http://blog.solidcore.com/styles/blogsite/SolidCore/images/rss.jpg</url><height>31</height><width>88</width><link>http://blog.solidcore.com/public/blog/183011</link><title>ITIL | Solidcore Blog</title><description>Solidcore: Change Management and Change Control Solutions</description></image>
       <category>ITIL</category><category>ITIL automation</category><category>Change control</category><category>IT change control</category><category>ITIL change control</category><category>Change management</category><category>Change control software</category><category>tripwire</category><category>ITIL framework</category><category>solidcore</category>
       
       
      
    
     <item><title>Insider IT Sabotage - Super Villain of the Digital World?</title><link>http://blog.solidcore.com/public/item/209449</link><description>San Francisco network sabotage leaves administrators feeling helpless&lt;p&gt;&lt;img style="WIDTH: 69px; HEIGHT: 97px" height="97" alt="Hancock mirrors IT sabotage as super villain" hspace="0" src="http://larryfire.files.wordpress.com/2008/04/hancock1.jpg" width="69" align="baseline" border="0" /&gt;It's still &amp;quot;dark&amp;quot; within the city of &lt;a title="ChannelWeb story on San Francisco network lock-out" href="http://www.crn.com/security/209101383?cid=ChannelWebBreakingNews" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;San Francisco's network&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; and IT organization after it was determined one of its own&amp;nbsp;network administrators went rogue and changed passwords and allegedly enabled lock-out code preventing any others from accessing the key components. He is still&amp;nbsp;holding the master password for ransom.&lt;/p&gt;&lt;p&gt;According to Insider &lt;a href="www.cert.org/insider_threat"&gt;&lt;strong&gt;&lt;u&gt;Threat Research&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; from CERT there most likely would have been pre-cursory warning signs:&lt;/p&gt;&lt;p&gt;Summary of Observations made within a study conducted by CERT, US Secret Service and the National Threat Assessment Center&lt;/p&gt;&lt;p&gt;- 90% of Insiders were granted system administrator or privileged system access when hired by the organization&lt;/p&gt;&lt;p&gt;- 57% of Insiders were perceived as being disgruntled due to unmet expectations&lt;/p&gt;&lt;p&gt;- 92% of Insiders attacked following&amp;nbsp;a negative work-related situation such as termination, dispute with employer, demotion or transfer&lt;/p&gt;&lt;p&gt;- 87% of Insiders performed technical precursors prior to the attack that were undetected by the organization&lt;/p&gt;&lt;p&gt;- 75% of Insiders created access paths unknown to the organization, 57% did not have authorized system access at the time of the attack&lt;/p&gt;&lt;p&gt;- 93% of Insiders exploited insufficient access controls&lt;/p&gt;&lt;p&gt;This should be chapter one in the &amp;quot;Worst Case Scenario&amp;quot; book for CIOs and corporate boards.&lt;/p&gt;&lt;p&gt;Ensure that controls are in place to allow IT administrators (role) to perform their duties (responsibilities) within their job function and scope (segmentation). However monitor, track and alert on all password changes to ensure that the keys to the digital foundation of your organization are not enabling IT Sabotage and or malicious hi-jinks.&lt;/p&gt;&lt;p&gt;This type of drama is unfolding like a comic book, similar to the Marvel comic character Rogue, who at times is good, at times is evil but shares one trait with today's Digital Super Villain&amp;nbsp;- the ability to absorb the powers of others. This could even be exemplifed by the modern day boxoffice thriller &lt;a title="Sony pictures Hancock official site" href="http://www.sonypictures.com/movies/hancock/" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Hancock&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;.&amp;nbsp; &lt;/p&gt;&lt;p&gt;Bottom line: Don't let your controls only be policies on paper.&amp;nbsp;Make sure you have the power of enforcement!&lt;/p&gt;&lt;p&gt;&lt;b&gt;Kim Singletary&lt;br /&gt;&lt;/b&gt;Director of Embedded Solutions&lt;br /&gt;&lt;a href="mailto:ksingletary@solidcore.com"&gt;ksingletary@solidcore.com&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Rajesh Rajamani&lt;br /&gt;&lt;/b&gt;Product Manager&lt;br /&gt;&lt;a href="mailto:raj@solidcore.com"&gt;raj@solidcore.com&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.crn.com/security/209101383?cid=ChannelWebBreakingNews" target=%quot;_blank%quot;&gt;San Francisco Network Hijack&lt;/a&gt;&lt;br/&gt;ChannelWeb news story on the San Francisco network lock-out&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.cert.org/insider_threat/" target=%quot;_blank%quot;&gt;CERT Research on Insider Threat&lt;/a&gt;&lt;br/&gt;Insider threat research from CERT&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.sonypictures.com/movies/hancock/" target=%quot;_blank%quot;&gt;Hancock&lt;/a&gt;&lt;br/&gt;Sony pictures Hancock page&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.solidcore.com/public/item/209449</guid><pubDate>Mon, 21 Jul 2008 14:29:13 -0400</pubDate>
        <category>change control</category><category>Hancock</category><category>network hijack</category><category>San Francisco hack</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>CRN Names Solidcore Emerging Tech Vendor</title><link>http://blog.solidcore.com/public/item/208724</link><description>Solidcore honored for innovative and easy-to-use technology that goes beyond industry giants&lt;p class="normal"&gt;&lt;a href="http://www.solidcore.com/news_events/release91.html"&gt;&lt;img alt="CRN names Solidcore Emerging Tech Vendor" hspace="0" src="http://www.solidcore.com/images/crn_emerg_tech.jpg" align="baseline" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p class="normal"&gt;Solidcore has been selected as a &lt;a href="http://www.crn.com/security/208802316;jsessionid=X0ECOZ34HQSKYQSNDLRSKHSCJUNN2JVN?pgno=32"&gt;&lt;strong&gt;&lt;u&gt;CRN Emerging Tech vendor&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; for its S3 Control software. CRN's Emerging Tech list captures companies that are delivering high margins for solution providers with innovative and easy-to-use &lt;a href="http://www.solidcore.com/products/s3control.html"&gt;&lt;strong&gt;&lt;u&gt;technology&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; that goes beyond the technology of industry giants.&lt;/p&gt;&lt;p class="normal"&gt;According to the CRN Emerging Tech Survey, the top reasons solution providers add emerging technologies include: The technology is superior to other products in the market segment; the technology complements a solution providers' existing practice areas; emerging vendors provide better services opportunities; emerging vendors pay better attention to partners; emerging vendors offer higher margins; customers want alternative product choices; and emerging vendors have better joint marketing programs. In addition, 61 percent of solution providers surveyed plan to increase the number of emerging technology vendors they partner with in the next 12 months. &lt;/p&gt;&lt;p class="normal"&gt;&amp;quot;New and innovative vendor partners can help spur profitable new ideas that solution providers can use to build revenue and customer loyalty, and the CRN Emerging Tech list is where Solution Providers go to find these vendors,&amp;quot; said Robert C. Demarzo, senior vice president and editorial director, Everything Channel editorial. &lt;/p&gt;&lt;p class="normal"&gt;Tony Thompson&lt;br /&gt;Corp. Marketing &amp;amp; Communications&lt;br /&gt;&lt;a href="mailto:tthompson@solidcore.com"&gt;tthompson@solidcore.com&lt;/a&gt;&lt;/p&gt;&lt;p class="normal" /&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.crn.com/security/208802316;jsessionid=X0ECOZ34HQSKYQSNDLRSKHSCJUNN2JVN?pgno=32" target=%quot;_blank%quot;&gt;Solidcore named Emerging Tech Vendor&lt;/a&gt;&lt;br/&gt;CRN Web page about Solidcore being Emerging Tech Vendor&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.solidcore.com/products/s3control.html" target=%quot;_blank%quot;&gt;Solidcore S3 Control&lt;/a&gt;&lt;br/&gt;Solidcore Web page about the S3 Control product&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.solidcore.com/news_events/release91.html" target=%quot;_blank%quot;&gt;CRN names Solidcore Emerging Tech Vendor&lt;/a&gt;&lt;br/&gt;Press release about Solidcore being named an Emerging Tech Vendor by CRN&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.solidcore.com/public/item/208724</guid><pubDate>Tue, 08 Jul 2008 16:30:15 -0400</pubDate>
        <category>change control</category><category>CRN</category><category>Emerging Tech Vendor</category>
        
        
        
        
       
        
        
        
        
        
       </item>
    </channel></rss>