<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for The Security Sangoma</title>
	<atom:link href="http://www.isgafrica.org/blog/?feed=comments-rss2" rel="self" type="application/rss+xml" />
	<link>http://www.isgafrica.org/blog</link>
	<description>The Information Security Group of Africa is a registered non-profit company established in 2005 and is not biased toward any single vendor, technology or company. The Security Sangoma is the Group&#039;s leader &#38; together with his 3000 strong impi are the unofficial cyber-protectors of Africa.</description>
	<lastBuildDate>Thu, 08 Apr 2010 12:04:35 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>Comment on International CSIRT / Incident Response training in South Africa by Ramiah</title>
		<link>http://www.isgafrica.org/blog/?p=325&#038;cpage=1#comment-476</link>
		<dc:creator>Ramiah</dc:creator>
		<pubDate>Thu, 08 Apr 2010 12:04:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.isgafrica.org/blog/?p=325#comment-476</guid>
		<description>Why the name; Computer Security Incident Response Team? as I see this bigger than identifying and reacting to a &quot;computer security incident&quot;. It again creates a perception to organisations of ot being IT driven initiative - Which it is not!</description>
		<content:encoded><![CDATA[<p>Why the name; Computer Security Incident Response Team? as I see this bigger than identifying and reacting to a &#8220;computer security incident&#8221;. It again creates a perception to organisations of ot being IT driven initiative &#8211; Which it is not!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on UK Government details its Cyber Crime Strategy by Security_Sangoma</title>
		<link>http://www.isgafrica.org/blog/?p=481&#038;cpage=1#comment-475</link>
		<dc:creator>Security_Sangoma</dc:creator>
		<pubDate>Wed, 07 Apr 2010 20:00:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.isgafrica.org/blog/?p=481#comment-475</guid>
		<description>It seems the governments of the world are putting serious resources into fighting cybercrime. SA&#039;s reponse - we now have a draft cybersecurity policy! oh well - at least its a start!</description>
		<content:encoded><![CDATA[<p>It seems the governments of the world are putting serious resources into fighting cybercrime. SA&#8217;s reponse &#8211; we now have a draft cybersecurity policy! oh well &#8211; at least its a start!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Draft SA CyberSecurity Policy released for comment by Joey Hernandez</title>
		<link>http://www.isgafrica.org/blog/?p=419&#038;cpage=1#comment-471</link>
		<dc:creator>Joey Hernandez</dc:creator>
		<pubDate>Thu, 25 Mar 2010 14:20:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.isgafrica.org/blog/?p=419#comment-471</guid>
		<description>The International Society of Cyber Security Professionals provided their input, and we look forward to working with the leadership to institutionalize the framework.

Joey Hernandez
iSCSP.org</description>
		<content:encoded><![CDATA[<p>The International Society of Cyber Security Professionals provided their input, and we look forward to working with the leadership to institutionalize the framework.</p>
<p>Joey Hernandez<br />
iSCSP.org</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on 2 new positions available in Gauteng, South Africa by Mike Danker</title>
		<link>http://www.isgafrica.org/blog/?p=255&#038;cpage=1#comment-467</link>
		<dc:creator>Mike Danker</dc:creator>
		<pubDate>Wed, 24 Mar 2010 10:07:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.isgafrica.org/blog/?p=255#comment-467</guid>
		<description>I conduct Professional SEARCH for candidates

I sent the HR Manager a mail

Kindly contact me on 0836809222 anytime

Regards Mike Danker

SEARCHWORX</description>
		<content:encoded><![CDATA[<p>I conduct Professional SEARCH for candidates</p>
<p>I sent the HR Manager a mail</p>
<p>Kindly contact me on 0836809222 anytime</p>
<p>Regards Mike Danker</p>
<p>SEARCHWORX</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Draft SA CyberSecurity Policy released for comment by Security_Sangoma</title>
		<link>http://www.isgafrica.org/blog/?p=419&#038;cpage=1#comment-431</link>
		<dc:creator>Security_Sangoma</dc:creator>
		<pubDate>Fri, 26 Feb 2010 12:38:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.isgafrica.org/blog/?p=419#comment-431</guid>
		<description>Quotable mentions:

(Iain Campbell – ISG CSIRT lead)
 A good analogy would be along the lines of road safety. How many people would drive at 60 if there was no speed limit?
In SA there is currently no &quot;speed limit&quot; for cybersecurity. More importantly, because there are no standards/regulations many people who are aware that they have a problem do not know how to address it aka &quot;who you gonna call?&quot;. This policy goes a long way to address these issues by making it crystal clear who is ultimately responsible (i.e. the DoC), and by enabling the private sector to assist in setting relevant standards.
Ultimately you want to avoid a situation where a bank is getting their &quot;exhaust repaired at the side of the road&quot;
At the end of the day policy needs to have two elements in order to be successful:
1. Legal teeth to ensure compliance (it can be argued whether the likes of King 3 goes far enough)
2. Ability to execute, which should be possible via PPP as recommended 
Dominic White – Sensepost Security consultant)
This will hopefully not only become a paper based exercise (similar to the FISMA exercise in the USA) but allow use to track a “scoreboard” of tangible actions / deliverables. It is also vital to ensure that breach disclosures are covered.</description>
		<content:encoded><![CDATA[<p>Quotable mentions:</p>
<p>(Iain Campbell – ISG CSIRT lead)<br />
 A good analogy would be along the lines of road safety. How many people would drive at 60 if there was no speed limit?<br />
In SA there is currently no &#8220;speed limit&#8221; for cybersecurity. More importantly, because there are no standards/regulations many people who are aware that they have a problem do not know how to address it aka &#8220;who you gonna call?&#8221;. This policy goes a long way to address these issues by making it crystal clear who is ultimately responsible (i.e. the DoC), and by enabling the private sector to assist in setting relevant standards.<br />
Ultimately you want to avoid a situation where a bank is getting their &#8220;exhaust repaired at the side of the road&#8221;<br />
At the end of the day policy needs to have two elements in order to be successful:<br />
1. Legal teeth to ensure compliance (it can be argued whether the likes of King 3 goes far enough)<br />
2. Ability to execute, which should be possible via PPP as recommended<br />
Dominic White – Sensepost Security consultant)<br />
This will hopefully not only become a paper based exercise (similar to the FISMA exercise in the USA) but allow use to track a “scoreboard” of tangible actions / deliverables. It is also vital to ensure that breach disclosures are covered.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Draft SA CyberSecurity Policy released for comment by Security_Sangoma</title>
		<link>http://www.isgafrica.org/blog/?p=419&#038;cpage=1#comment-430</link>
		<dc:creator>Security_Sangoma</dc:creator>
		<pubDate>Fri, 26 Feb 2010 12:38:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.isgafrica.org/blog/?p=419#comment-430</guid>
		<description>Anon feedback received from security folk at banks / gov depts:

Main Concern - that it be implemented speedily and given high enough mandate in government to make it effective in implementation. Most developed countries in the world have given this serious attention recently, and they are already miles ahead of us.
Second Concern - that we will first have to face a major cyber attack before the urgent need for a coordinated, national response and structures are agreed and implemented.
I support the initiative, and can only add that the focus will also be to identify, assess and protect Critical Communication Infrastructures – which are not only held by public entities (which will be covered by Government CSIRT ito assessment and monitoring), but the private sector as well (specifically banking).  Hence the focus in the cyber security policy on public-private sectors working together and the focus on a national CISRT to oversee public and private sector incidents relating to critical communication infrastructures and cyber incidents.
I believe ISGA is perfectly positioned to play a major role in the DOCs vision, thanks to the CSIRT training and eCrime initiatives. We should put in every effort to ensure that it succeeds.
Moreover, groups such as the ISG should be recognised for its efforts with this and could be engaged by the minister for its in depth knowledge, passion for IT security and willingness to commit time and resources to this mission.
Frankly, it would be ideal if the big corporates would participate through membership of ISG Africa, rather than independently.</description>
		<content:encoded><![CDATA[<p>Anon feedback received from security folk at banks / gov depts:</p>
<p>Main Concern &#8211; that it be implemented speedily and given high enough mandate in government to make it effective in implementation. Most developed countries in the world have given this serious attention recently, and they are already miles ahead of us.<br />
Second Concern &#8211; that we will first have to face a major cyber attack before the urgent need for a coordinated, national response and structures are agreed and implemented.<br />
I support the initiative, and can only add that the focus will also be to identify, assess and protect Critical Communication Infrastructures – which are not only held by public entities (which will be covered by Government CSIRT ito assessment and monitoring), but the private sector as well (specifically banking).  Hence the focus in the cyber security policy on public-private sectors working together and the focus on a national CISRT to oversee public and private sector incidents relating to critical communication infrastructures and cyber incidents.<br />
I believe ISGA is perfectly positioned to play a major role in the DOCs vision, thanks to the CSIRT training and eCrime initiatives. We should put in every effort to ensure that it succeeds.<br />
Moreover, groups such as the ISG should be recognised for its efforts with this and could be engaged by the minister for its in depth knowledge, passion for IT security and willingness to commit time and resources to this mission.<br />
Frankly, it would be ideal if the big corporates would participate through membership of ISG Africa, rather than independently.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on International CSIRT / Incident Response training in South Africa by Mlandeli Zweni</title>
		<link>http://www.isgafrica.org/blog/?p=325&#038;cpage=1#comment-424</link>
		<dc:creator>Mlandeli Zweni</dc:creator>
		<pubDate>Wed, 24 Feb 2010 15:29:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.isgafrica.org/blog/?p=325#comment-424</guid>
		<description>PLZ send Dates &amp; Fees for the Course.</description>
		<content:encoded><![CDATA[<p>PLZ send Dates &amp; Fees for the Course.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Information Security positions available in Australia by Eric</title>
		<link>http://www.isgafrica.org/blog/?p=410&#038;cpage=1#comment-423</link>
		<dc:creator>Eric</dc:creator>
		<pubDate>Wed, 24 Feb 2010 14:23:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.isgafrica.org/blog/?p=410#comment-423</guid>
		<description>Hi 

Sorry to have to post this here, but your registration form does not work. It asks for &#039;country&#039; but no drop-down list comes through.

Pls investigate &amp; let me know so that I can register?

Regards
Eric</description>
		<content:encoded><![CDATA[<p>Hi </p>
<p>Sorry to have to post this here, but your registration form does not work. It asks for &#8216;country&#8217; but no drop-down list comes through.</p>
<p>Pls investigate &amp; let me know so that I can register?</p>
<p>Regards<br />
Eric</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Gauteng February 2010 chapter meeting by Security_Sangoma</title>
		<link>http://www.isgafrica.org/blog/?p=398&#038;cpage=1#comment-398</link>
		<dc:creator>Security_Sangoma</dc:creator>
		<pubDate>Sun, 31 Jan 2010 20:33:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.isgafrica.org/blog/?p=398#comment-398</guid>
		<description>What questions would you like asked to the panel of 4 experts?

For now we have the following:

-How IT Governance &amp; Information Security are structured?
- Frameworks they are adopting?
- Challenges faced?
- Key focus projects for 2010?

What else?

Craig</description>
		<content:encoded><![CDATA[<p>What questions would you like asked to the panel of 4 experts?</p>
<p>For now we have the following:</p>
<p>-How IT Governance &#038; Information Security are structured?<br />
- Frameworks they are adopting?<br />
- Challenges faced?<br />
- Key focus projects for 2010?</p>
<p>What else?</p>
<p>Craig</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Information Security positions available in Australia by Security_Sangoma</title>
		<link>http://www.isgafrica.org/blog/?p=410&#038;cpage=1#comment-397</link>
		<dc:creator>Security_Sangoma</dc:creator>
		<pubDate>Sun, 31 Jan 2010 20:30:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.isgafrica.org/blog/?p=410#comment-397</guid>
		<description>Please contact me if you have any queries:

craig@isgafrica.org

Thanks

Craig</description>
		<content:encoded><![CDATA[<p>Please contact me if you have any queries:</p>
<p><a href="mailto:craig@isgafrica.org">craig@isgafrica.org</a></p>
<p>Thanks</p>
<p>Craig</p>
]]></content:encoded>
	</item>
</channel>
</rss>
