<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Ethical Questions&#8230;</title>
	<atom:link href="http://www.liquidmatrix.org/blog/2008/04/18/ethical-questions/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.liquidmatrix.org/blog/2008/04/18/ethical-questions/</link>
	<description>Bringing Fire To The Village: Your Source For Computer, Network &#38; Information Security News from Dave Lewis, Security Blogger</description>
	<pubDate>Mon, 08 Sep 2008 15:34:45 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: CJ</title>
		<link>http://www.liquidmatrix.org/blog/2008/04/18/ethical-questions/#comment-69096</link>
		<dc:creator>CJ</dc:creator>
		<pubDate>Fri, 18 Apr 2008 20:03:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/?p=2912#comment-69096</guid>
		<description>My bad.  "When a man lies, he murders some part of the world".  That better?  ;-)

Caveman me:  "Common ground good.  Compromise bad."</description>
		<content:encoded><![CDATA[<p>My bad.  &#8220;When a man lies, he murders some part of the world&#8221;.  That better?  <img src='http://www.liquidmatrix.org/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>Caveman me:  &#8220;Common ground good.  Compromise bad.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Myrcurial</title>
		<link>http://www.liquidmatrix.org/blog/2008/04/18/ethical-questions/#comment-69093</link>
		<dc:creator>Myrcurial</dc:creator>
		<pubDate>Fri, 18 Apr 2008 17:27:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/?p=2912#comment-69093</guid>
		<description>Alex - I bow - I'm 26138 - bumbled again!

CJ - ass kicking comment, and yet, you quote country music at me!</description>
		<content:encoded><![CDATA[<p>Alex - I bow - I&#8217;m 26138 - bumbled again!</p>
<p>CJ - ass kicking comment, and yet, you quote country music at me!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CJ</title>
		<link>http://www.liquidmatrix.org/blog/2008/04/18/ethical-questions/#comment-69092</link>
		<dc:creator>CJ</dc:creator>
		<pubDate>Fri, 18 Apr 2008 15:40:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/?p=2912#comment-69092</guid>
		<description>Generally, I like rain forest puppy's responsible disclosure policy, though security ethics is a much larger question than one of "To disclose, or not to disclose".  Glory-hawks will never disclose responsibly, and are never hired by me.

That being said, there are times when public disclosure outside the bounds of responsible disclosure is necessary.  If one is to go that route and is in the profession, they'd better have a pre-published exception process to their normal responsible disclosure.  If they aren't "in the biz" and making money from disclosure, then it doesn't much matter what ethics they follow as arguing it is as productive as Chevy vs. Ford, or Tastes Great; Less Filling.

As my organization's ISO, ethics drive everything I do.  In a position of enacting sometimes controversial standards and controls around them, it is imperative that we eat our own dog food lest we fritter what little credibility we have away.

I'm one of the lucky few that aren't beholden to any specific code as part of belonging to a particular credentialed society such as ISACA, (ISC)2, etc., and can ensure that my personal ethics, which I (of course) believe to be substantial, are employed in full force.  Given my upbringing, those personal ethics are fairly black and white.  Having that kind of clarity is vital when conveying objective risks to the business when you have to buck the trend of convenience and least cost.

To quote Toby Keith, "You may not like where I'm going, but you sure know where I stand".  Reasonable minds can disagree.  If you are consistently ethical (whatever that means to you) and don't compromise, you can speak from a position of authority when challenged.</description>
		<content:encoded><![CDATA[<p>Generally, I like rain forest puppy&#8217;s responsible disclosure policy, though security ethics is a much larger question than one of &#8220;To disclose, or not to disclose&#8221;.  Glory-hawks will never disclose responsibly, and are never hired by me.</p>
<p>That being said, there are times when public disclosure outside the bounds of responsible disclosure is necessary.  If one is to go that route and is in the profession, they&#8217;d better have a pre-published exception process to their normal responsible disclosure.  If they aren&#8217;t &#8220;in the biz&#8221; and making money from disclosure, then it doesn&#8217;t much matter what ethics they follow as arguing it is as productive as Chevy vs. Ford, or Tastes Great; Less Filling.</p>
<p>As my organization&#8217;s ISO, ethics drive everything I do.  In a position of enacting sometimes controversial standards and controls around them, it is imperative that we eat our own dog food lest we fritter what little credibility we have away.</p>
<p>I&#8217;m one of the lucky few that aren&#8217;t beholden to any specific code as part of belonging to a particular credentialed society such as ISACA, (ISC)2, etc., and can ensure that my personal ethics, which I (of course) believe to be substantial, are employed in full force.  Given my upbringing, those personal ethics are fairly black and white.  Having that kind of clarity is vital when conveying objective risks to the business when you have to buck the trend of convenience and least cost.</p>
<p>To quote Toby Keith, &#8220;You may not like where I&#8217;m going, but you sure know where I stand&#8221;.  Reasonable minds can disagree.  If you are consistently ethical (whatever that means to you) and don&#8217;t compromise, you can speak from a position of authority when challenged.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://www.liquidmatrix.org/blog/2008/04/18/ethical-questions/#comment-69091</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Fri, 18 Apr 2008 14:34:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/?p=2912#comment-69091</guid>
		<description>Oh, Oh, Low /. uid fight!

I got 8900</description>
		<content:encoded><![CDATA[<p>Oh, Oh, Low /. uid fight!</p>
<p>I got 8900</p>
]]></content:encoded>
	</item>
</channel>
</rss>
