<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for InfoSecMinds</title>
	<atom:link href="http://infosecminds.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosecminds.com</link>
	<description>For like-minded people</description>
	<lastBuildDate>Mon, 12 Dec 2011 06:04:35 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>Comment on ISMS Compliance Checklist by Muhammad Ibrahim Nazish</title>
		<link>http://infosecminds.com/2008/07/07/isms-compliance-checklist/comment-page-1/#comment-133</link>
		<dc:creator>Muhammad Ibrahim Nazish</dc:creator>
		<pubDate>Mon, 12 Dec 2011 06:04:35 +0000</pubDate>
		<guid isPermaLink="false">http://infosecminds.com/?p=32#comment-133</guid>
		<description>can you please send me this file to my email address mnazish@gmail.com, as i cannot download this file. thanks in advance.</description>
		<content:encoded><![CDATA[<p>can you please send me this file to my email address <a href="mailto:mnazish@gmail.com">mnazish@gmail.com</a>, as i cannot download this file. thanks in advance.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Classification and labeling – A double edged sword? by Vinod Puthuseeri</title>
		<link>http://infosecminds.com/2010/05/05/classification-and-labeling-%e2%80%93-a-double-edged-sword/comment-page-1/#comment-132</link>
		<dc:creator>Vinod Puthuseeri</dc:creator>
		<pubDate>Wed, 07 Dec 2011 16:01:56 +0000</pubDate>
		<guid isPermaLink="false">http://infosecminds.com/?p=240#comment-132</guid>
		<description>Hi Joshua,

As you rightly mentioned some of the documents changes its confidentiality classification as time passes. Consider the year end financial information of an organization. What would be the confidentiality before and after publishing their financial results. This would change from confidentiality to public in about a days time.

Similarly over a period of time the information need not be as critical as it is now. Hence by changing the classification level, you can further decide on what kind of security controls that document requires. Eventually, you do not want to put the similar security controls for a confidential document and non-confidential document.</description>
		<content:encoded><![CDATA[<p>Hi Joshua,</p>
<p>As you rightly mentioned some of the documents changes its confidentiality classification as time passes. Consider the year end financial information of an organization. What would be the confidentiality before and after publishing their financial results. This would change from confidentiality to public in about a days time.</p>
<p>Similarly over a period of time the information need not be as critical as it is now. Hence by changing the classification level, you can further decide on what kind of security controls that document requires. Eventually, you do not want to put the similar security controls for a confidential document and non-confidential document.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Risks of Providing Local Admin Privileges to Users by Twinkle</title>
		<link>http://infosecminds.com/2008/09/17/risks-of-providing-local-admin-privileges-to-users/comment-page-1/#comment-131</link>
		<dc:creator>Twinkle</dc:creator>
		<pubDate>Wed, 07 Dec 2011 14:58:41 +0000</pubDate>
		<guid isPermaLink="false">http://vputhuseeri.wordpress.com/?p=44#comment-131</guid>
		<description>This is very true. I like the arguments given for both the issues and risks. But for most companies and their networks, I believe that the issues are nothing compared to the risks. Limiting admin access is advisable.</description>
		<content:encoded><![CDATA[<p>This is very true. I like the arguments given for both the issues and risks. But for most companies and their networks, I believe that the issues are nothing compared to the risks. Limiting admin access is advisable.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Classification and labeling – A double edged sword? by Joshua</title>
		<link>http://infosecminds.com/2010/05/05/classification-and-labeling-%e2%80%93-a-double-edged-sword/comment-page-1/#comment-130</link>
		<dc:creator>Joshua</dc:creator>
		<pubDate>Thu, 01 Dec 2011 17:36:09 +0000</pubDate>
		<guid isPermaLink="false">http://infosecminds.com/?p=240#comment-130</guid>
		<description>Hi Vinod,
Thank you for writing these nice articles . Quite thought provoking . In the first instance, you mentioned the document was of the year 2006, and later said it should have been reclassified . Could you please tell me what did you mean by &quot;Well why the document not re-classified if it was old…?&quot; . 

What I thought was , document no matter old or new, confidentiality remains the same ( there are exceptions though, a confidential document a decade ago may not be equally confidential now ) . Kindly excuse me If that was not a sensible question as I&#039;m just a beginner in this domain . Thanks a lot for your time .</description>
		<content:encoded><![CDATA[<p>Hi Vinod,<br />
Thank you for writing these nice articles . Quite thought provoking . In the first instance, you mentioned the document was of the year 2006, and later said it should have been reclassified . Could you please tell me what did you mean by &#8220;Well why the document not re-classified if it was old…?&#8221; . </p>
<p>What I thought was , document no matter old or new, confidentiality remains the same ( there are exceptions though, a confidential document a decade ago may not be equally confidential now ) . Kindly excuse me If that was not a sensible question as I&#8217;m just a beginner in this domain . Thanks a lot for your time .</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The Faces of Fraud: Fighting Back by card payment POS</title>
		<link>http://infosecminds.com/2010/12/31/the-faces-of-fraud-fighting-back/comment-page-1/#comment-129</link>
		<dc:creator>card payment POS</dc:creator>
		<pubDate>Fri, 25 Nov 2011 22:01:59 +0000</pubDate>
		<guid isPermaLink="false">http://infosecminds.com/?p=280#comment-129</guid>
		<description>&lt;strong&gt;card payment POS...&lt;/strong&gt;

[...]The Faces of Fraud: Fighting Back &#124;Information Security &amp; Risk Assessment Blog &#124; InfoSecMinds[...]...</description>
		<content:encoded><![CDATA[<p><strong>card payment POS&#8230;</strong></p>
<p>[...]The Faces of Fraud: Fighting Back |Information Security &amp; Risk Assessment Blog | InfoSecMinds[...]&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

