<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Recent Readings (and listenings)</title>
	<atom:link href="http://edbellis.com/2007/08/06/recent-readings-and-listening/feed/" rel="self" type="application/rss+xml" />
	<link>http://edbellis.com/2007/08/06/recent-readings-and-listening/</link>
	<description>converting black signals to red</description>
	<lastBuildDate>Tue, 11 May 2010 20:09:28 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Andrew Law</title>
		<link>http://edbellis.com/2007/08/06/recent-readings-and-listening/#comment-534</link>
		<dc:creator>Andrew Law</dc:creator>
		<pubDate>Wed, 19 Sep 2007 18:40:10 +0000</pubDate>
		<guid isPermaLink="false">http://cleartext.wordpress.com/2007/08/06/recent-readings-and-listening/#comment-534</guid>
		<description>Hi,
At Microsoft, we use a tool called SPIDER, to scan systems and map business compliance requirements to control objectives and different types of &#039;evidence&#039; on a box. This evidence can range from patches, to certain revs of software or services running on a box.
Here is a reference to the tool
http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9004738

however, it hasn&#039;t been &quot;productized&quot;. It is used in some of our consulting engagements for other customers.

The article doesn&#039;t do the tool justice, as it looks just like some kind of host scanner.

The magic of the tool is that it lets you define any compliance metrics you like (SOX, HIPPA, PCI, etc) in the tool. 
Every company is different here, so you can define your own complaince metrics as you like.

When the scan is complete, you get a report showing the results, and how many systems meet the compliance requirements you defined. 
We currently license this tool through our ACE Security Services division.

BTW - I don&#039;t represent Microsoft in this post (and I&#039;m not a SalesGuy!)</description>
		<content:encoded><![CDATA[<p>Hi,<br />
At Microsoft, we use a tool called SPIDER, to scan systems and map business compliance requirements to control objectives and different types of &#8216;evidence&#8217; on a box. This evidence can range from patches, to certain revs of software or services running on a box.<br />
Here is a reference to the tool<br />
<a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9004738" rel="nofollow">http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9004738</a></p>
<p>however, it hasn&#8217;t been &#8220;productized&#8221;. It is used in some of our consulting engagements for other customers.</p>
<p>The article doesn&#8217;t do the tool justice, as it looks just like some kind of host scanner.</p>
<p>The magic of the tool is that it lets you define any compliance metrics you like (SOX, HIPPA, PCI, etc) in the tool.<br />
Every company is different here, so you can define your own complaince metrics as you like.</p>
<p>When the scan is complete, you get a report showing the results, and how many systems meet the compliance requirements you defined.<br />
We currently license this tool through our ACE Security Services division.</p>
<p>BTW &#8211; I don&#8217;t represent Microsoft in this post (and I&#8217;m not a SalesGuy!)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
