<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Assurance Levels calculator in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Security-Assurance-Levels-calculator/m-p/30016#M1961</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/136236425"&gt;@ericgeater&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Who are the CISSPs?&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I looked at the linked site and read the FAQ on that site. I do not mean to accuse either Bruce or the two "honorable US military veterans"&amp;nbsp; of anything untoward, but I must say the minimal information available and the lack of transparency on the site, along with the implied sort of questions users of the SALculator will answer about their organizations make me think the site would be a useful tool for gathering business intelligence and cybersec vulnerability clues on the participating organizations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interesting that &lt;A href="https://www.heroku.com/" target="_blank" rel="noopener"&gt;Herokuapp.com&lt;/A&gt; is a an app development environment site, with the domain &lt;A href="https://www.whois.com/whois/herokuapp.com" target="_blank" rel="noopener"&gt;owned by Salesforce&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Nov 2019 18:17:18 GMT</pubDate>
    <dc:creator>CraginS</dc:creator>
    <dc:date>2019-11-19T18:17:18Z</dc:date>
    <item>
      <title>Security Assurance Levels calculator</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Security-Assurance-Levels-calculator/m-p/29751#M1938</link>
      <description>&lt;P&gt;&lt;A href="https://salculator.herokuapp.com" target="_blank" rel="noopener"&gt;https://salculator.herokuapp.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV class="qQVYZb"&gt;&lt;SPAN&gt;Security Control election criteria are often driven by InfoSec or Compliance requirements. That seems good, right? Until business leadership must be convinced to purchase costly tools, or support a restrictive process. We all know how difficult that can be. But why is that? Current approaches and facilitative tools may not include business stakeholders. This often results in a control set that doesn’t consider the business need for the IT systems and the services these systems provide. This is where the trouble begins. Involving business stakeholders earlier in the prioritization &amp;amp; selection process is a step towards mitigating that disconnect. The DHS CSET is a good example of a free tool that helps with prioritization, but it still does not focus on business need. Plus, there may be some hesitation to download it into your environment. Two CISSPs - both US Military Veterans &amp;amp; one also happens to be a full stack developer – decided (initially as a hobby project) to develop a simple (cloud hosted) tool introducing the concept; intending to provoke additional thought in this area.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="utdU2e"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="btm"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class="aHl"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="ii gt"&gt;&lt;DIV class="a3s aXjCH "&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 08 Nov 2019 23:27:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Security-Assurance-Levels-calculator/m-p/29751#M1938</guid>
      <dc:creator>bcb13</dc:creator>
      <dc:date>2019-11-08T23:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: Security Assurance Levels calculator</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Security-Assurance-Levels-calculator/m-p/29971#M1960</link>
      <description>&lt;P&gt;Who are the CISSPs?&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Mon, 18 Nov 2019 19:32:10 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Security-Assurance-Levels-calculator/m-p/29971#M1960</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2019-11-18T19:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: Security Assurance Levels calculator</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Security-Assurance-Levels-calculator/m-p/30016#M1961</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/136236425"&gt;@ericgeater&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Who are the CISSPs?&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I looked at the linked site and read the FAQ on that site. I do not mean to accuse either Bruce or the two "honorable US military veterans"&amp;nbsp; of anything untoward, but I must say the minimal information available and the lack of transparency on the site, along with the implied sort of questions users of the SALculator will answer about their organizations make me think the site would be a useful tool for gathering business intelligence and cybersec vulnerability clues on the participating organizations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interesting that &lt;A href="https://www.heroku.com/" target="_blank" rel="noopener"&gt;Herokuapp.com&lt;/A&gt; is a an app development environment site, with the domain &lt;A href="https://www.whois.com/whois/herokuapp.com" target="_blank" rel="noopener"&gt;owned by Salesforce&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 18:17:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Security-Assurance-Levels-calculator/m-p/30016#M1961</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2019-11-19T18:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: Security Assurance Levels calculator</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Security-Assurance-Levels-calculator/m-p/30164#M1962</link>
      <description>&lt;P&gt;Where is the backend?&amp;nbsp; In the cloud, USA?&amp;nbsp; China?&amp;nbsp; How is the data being collected and protected?&amp;nbsp;&amp;nbsp; Do they adhere to GDPR, CCPA and other regulatory requirements?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 19:52:27 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Security-Assurance-Levels-calculator/m-p/30164#M1962</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2019-11-25T19:52:27Z</dc:date>
    </item>
  </channel>
</rss>

