<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.1" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments for The Revelator</title>
	<link>http://whatisopsec.com</link>
	<description>"That's Not OPSEC"</description>
	<pubDate>Sat, 22 Nov 2008 04:54:04 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.1</generator>

	<item>
		<title>Comment on Me &#038; Mrs. Jones by Revelator</title>
		<link>http://whatisopsec.com/2008/10/28/me-mrs-jones/#comment-1404</link>
		<author>Revelator</author>
		<pubDate>Wed, 29 Oct 2008 21:59:19 +0000</pubDate>
		<guid>http://whatisopsec.com/2008/10/28/me-mrs-jones/#comment-1404</guid>
		<description>You're an angel Karen.  Keep spreading the Gospel of OPSEC!
Revelator.</description>
		<content:encoded><![CDATA[<p>You&#8217;re an angel Karen.  Keep spreading the Gospel of OPSEC!<br />
Revelator.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Me &#038; Mrs. Jones by Karen Brown</title>
		<link>http://whatisopsec.com/2008/10/28/me-mrs-jones/#comment-1384</link>
		<author>Karen Brown</author>
		<pubDate>Wed, 29 Oct 2008 16:29:47 +0000</pubDate>
		<guid>http://whatisopsec.com/2008/10/28/me-mrs-jones/#comment-1384</guid>
		<description>That was excellent!  I'm posting copies in our Break Rooms. It shines an entertaining light on OPSEC!</description>
		<content:encoded><![CDATA[<p>That was excellent!  I&#8217;m posting copies in our Break Rooms. It shines an entertaining light on OPSEC!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Won&#8217;t Get Fooled Again by Revelator</title>
		<link>http://whatisopsec.com/2008/10/17/wont-get-fooled-again/#comment-816</link>
		<author>Revelator</author>
		<pubDate>Tue, 21 Oct 2008 14:20:08 +0000</pubDate>
		<guid>http://whatisopsec.com/2008/10/17/wont-get-fooled-again/#comment-816</guid>
		<description>Thanks Numlock.  Keep fighting the good fight brother!</description>
		<content:encoded><![CDATA[<p>Thanks Numlock.  Keep fighting the good fight brother!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Won&#8217;t Get Fooled Again by Frank Koza</title>
		<link>http://whatisopsec.com/2008/10/17/wont-get-fooled-again/#comment-814</link>
		<author>Frank Koza</author>
		<pubDate>Tue, 21 Oct 2008 13:57:54 +0000</pubDate>
		<guid>http://whatisopsec.com/2008/10/17/wont-get-fooled-again/#comment-814</guid>
		<description>Yay!!!  Great post.  You finally hit the nail on the head, Rainman.  :)

I keep having folks tell me that leadership doesn't 'get it' about the importance of OPSEC and that they have no support or advocacy.  I just tell them that we do a horrible job of teaching people how to properly qualitatively and quantitatively assess risk and how to do a cost/benefit analysis on measures.  When you give your bosses crap, then expect crap back.

Now if ye can just convince them that it's more than just protecting against communications intercept, open source, and social engineering.</description>
		<content:encoded><![CDATA[<p>Yay!!!  Great post.  You finally hit the nail on the head, Rainman.  <img src='http://whatisopsec.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I keep having folks tell me that leadership doesn&#8217;t &#8216;get it&#8217; about the importance of OPSEC and that they have no support or advocacy.  I just tell them that we do a horrible job of teaching people how to properly qualitatively and quantitatively assess risk and how to do a cost/benefit analysis on measures.  When you give your bosses crap, then expect crap back.</p>
<p>Now if ye can just convince them that it&#8217;s more than just protecting against communications intercept, open source, and social engineering.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on I Wanna Be Sedated by Revelator</title>
		<link>http://whatisopsec.com/2008/10/06/i-wanna-be-sedated/#comment-734</link>
		<author>Revelator</author>
		<pubDate>Thu, 09 Oct 2008 17:42:17 +0000</pubDate>
		<guid>http://whatisopsec.com/2008/10/06/i-wanna-be-sedated/#comment-734</guid>
		<description>Thanks for the kind words John.  Of course you can use anything you find here - and please accept my thanks for spreading the Gospel of OPSEC.  Revelator.</description>
		<content:encoded><![CDATA[<p>Thanks for the kind words John.  Of course you can use anything you find here - and please accept my thanks for spreading the Gospel of OPSEC.  Revelator.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on I Wanna Be Sedated by John Waller</title>
		<link>http://whatisopsec.com/2008/10/06/i-wanna-be-sedated/#comment-733</link>
		<author>John Waller</author>
		<pubDate>Thu, 09 Oct 2008 17:13:07 +0000</pubDate>
		<guid>http://whatisopsec.com/2008/10/06/i-wanna-be-sedated/#comment-733</guid>
		<description>Sir: I really thought your "Anvils Awards" were excellent and creative and true. I will be teaching a Physical Security class at the Centers for Disease Control (CDC) in a few weeks and I wonder if you would let me use those in my classes (with attribution of course). In return, I will steer my students to your blog as an excellent source of OPSEC information.......John Waller</description>
		<content:encoded><![CDATA[<p>Sir: I really thought your &#8220;Anvils Awards&#8221; were excellent and creative and true. I will be teaching a Physical Security class at the Centers for Disease Control (CDC) in a few weeks and I wonder if you would let me use those in my classes (with attribution of course). In return, I will steer my students to your blog as an excellent source of OPSEC information&#8230;&#8230;.John Waller</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on You Ain&#8217;t Seen Nothing Yet by Revelator</title>
		<link>http://whatisopsec.com/2008/08/01/you-aint-seen-nothing-yet/#comment-423</link>
		<author>Revelator</author>
		<pubDate>Fri, 22 Aug 2008 16:58:21 +0000</pubDate>
		<guid>http://whatisopsec.com/2008/08/01/you-aint-seen-nothing-yet/#comment-423</guid>
		<description>There are many ways to handle that based on the significance of the compromise but I think the most important thing is that you know...that you are aware of the compromise and can now deal with the assumption that your adversary has this information.</description>
		<content:encoded><![CDATA[<p>There are many ways to handle that based on the significance of the compromise but I think the most important thing is that you know&#8230;that you are aware of the compromise and can now deal with the assumption that your adversary has this information.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on You Ain&#8217;t Seen Nothing Yet by bigbeebopper</title>
		<link>http://whatisopsec.com/2008/08/01/you-aint-seen-nothing-yet/#comment-416</link>
		<author>bigbeebopper</author>
		<pubDate>Thu, 21 Aug 2008 04:57:44 +0000</pubDate>
		<guid>http://whatisopsec.com/2008/08/01/you-aint-seen-nothing-yet/#comment-416</guid>
		<description>So then what do you do if there's already been a compromise??</description>
		<content:encoded><![CDATA[<p>So then what do you do if there&#8217;s already been a compromise??</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on You Ain&#8217;t Seen Nothing Yet by Chris Cox</title>
		<link>http://whatisopsec.com/2008/08/01/you-aint-seen-nothing-yet/#comment-396</link>
		<author>Chris Cox</author>
		<pubDate>Tue, 05 Aug 2008 21:37:50 +0000</pubDate>
		<guid>http://whatisopsec.com/2008/08/01/you-aint-seen-nothing-yet/#comment-396</guid>
		<description>Great point, Revelator. You're absolutely right, and it's clear that an OPSEC program is most effective (some would say ONLY effective!) when all of the entities are aware of it and understand how it applies to them.</description>
		<content:encoded><![CDATA[<p>Great point, Revelator. You&#8217;re absolutely right, and it&#8217;s clear that an OPSEC program is most effective (some would say ONLY effective!) when all of the entities are aware of it and understand how it applies to them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on You Ain&#8217;t Seen Nothing Yet by Revelator</title>
		<link>http://whatisopsec.com/2008/08/01/you-aint-seen-nothing-yet/#comment-395</link>
		<author>Revelator</author>
		<pubDate>Tue, 05 Aug 2008 19:35:00 +0000</pubDate>
		<guid>http://whatisopsec.com/2008/08/01/you-aint-seen-nothing-yet/#comment-395</guid>
		<description>I don't ask for management support right off the bat.  I get with the webmaster or senior IT person to discuss how OPSEC can support network security.  Once I've concvinced them that this is actually possible then we can find ways to mutually support each other.  If we get to this point then we hit up leadership as a united front and increase our success rate (for whatever it is we want) exponentially.  I realize there are 1,001 different scenarios for this and I've just touched on one.  If you'll go to the OPSEC Professionals Association web site you can ask any question you want to their bank of Subject Matter Experts.  In this way you can be very specific and get back a very specific answer that should help you immediately.
Revalator</description>
		<content:encoded><![CDATA[<p>I don&#8217;t ask for management support right off the bat.  I get with the webmaster or senior IT person to discuss how OPSEC can support network security.  Once I&#8217;ve concvinced them that this is actually possible then we can find ways to mutually support each other.  If we get to this point then we hit up leadership as a united front and increase our success rate (for whatever it is we want) exponentially.  I realize there are 1,001 different scenarios for this and I&#8217;ve just touched on one.  If you&#8217;ll go to the OPSEC Professionals Association web site you can ask any question you want to their bank of Subject Matter Experts.  In this way you can be very specific and get back a very specific answer that should help you immediately.<br />
Revalator</p>
]]></content:encoded>
	</item>
</channel>
</rss>
