<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Blackfoot UK</title>
	<atom:link href="http://www.blackfootuk.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.blackfootuk.com</link>
	<description>Information security consultants</description>
	<lastBuildDate>Sun, 14 Nov 2010 15:59:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>An interview with Alberto Gonzalez</title>
		<link>http://www.blackfootuk.com/2010/11/an-interview-with-gonzalez/</link>
		<comments>http://www.blackfootuk.com/2010/11/an-interview-with-gonzalez/#comments</comments>
		<pubDate>Sun, 14 Nov 2010 15:42:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://blackfoot.instdp.com/?p=139</guid>
		<description><![CDATA[New York Times magazine has a great interview with Alberto Gonzalez who was the mastermind behind the infamous TJX theft of millions of card numbers. It’s really worth reading to understand the mindset of Gonzalez and the black-hat community, and to see how easy it was to break into many retail networks.
]]></description>
			<content:encoded><![CDATA[<p>New York Times magazine has a <a href="http://www.nytimes.com/2010/11/14/magazine/14Hacker-t.html">great interview with Alberto Gonzalez</a> who was the mastermind behind the infamous TJX theft of millions of card numbers. It’s really worth reading to understand the mindset of Gonzalez and the black-hat community, and to see how easy it was to break into many retail networks.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.blackfootuk.com/2010/11/an-interview-with-gonzalez/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Monetary Penalty Notices</title>
		<link>http://www.blackfootuk.com/2010/11/monetary-penalty-notices/</link>
		<comments>http://www.blackfootuk.com/2010/11/monetary-penalty-notices/#comments</comments>
		<pubDate>Sun, 14 Nov 2010 15:40:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://blackfoot.instdp.com/?p=136</guid>
		<description><![CDATA[There’s been a deal of FUD (fear, uncertainty and doubt) about the Information Commissioner’s new powers to fine companies, and it’s something that we’ve been asked about a few times. The ICO now has the power to levy a monetary penalty notice (a fine) on an organisation that: 
“has seriously contravened the data protection principles [...]]]></description>
			<content:encoded><![CDATA[<p>There’s been a deal of FUD (fear, uncertainty and doubt) about the Information Commissioner’s new powers to fine companies, and it’s something that we’ve been asked about a few times. The ICO now has the power to levy a monetary penalty notice (a fine) on an organisation that: </p>
<blockquote><p>“has seriously contravened the data protection principles and the contravention was of a kind likely to cause substantial damage or substantial distress.”</p></blockquote>
<p>additionally &#8230;</p>
<blockquote><p>“the contravention must either have been deliberate or the data controller must have known or ought to have known that there was a risk that a contravention would occur and failed to take reasonable steps to prevent it.”</p></blockquote>
<p>Last year Christopher Graham, the Information Commissioner, described the types of organisation that would fall foul of his fining powers as the <em>“serially incompetent and wicked&#8221;</em> and estimated that there would be around twenty fines issues in the first year of operation. The power to fine has been in force for nearly nine months and the Commissioner’s is yet to use his powers although it is widely known that there are two fines “on the way”.</p>
<p>Our key message is that you won’t get fined for accidentally contravening the Data Protection Act, but you will be at risk of you do it knowingly or you are careless with lots of people’s personal data.</p>
<p><a href="http://www.ico.gov.uk/upload/documents/library/data_protection/detailed_specialist_guides/ico_guidance_monetary_penalties.pdf">The Commissioner’s guidance notes</a> makes it clear the circumstances in which you could get a fine, and it is required reading. Our advice is that the best protection is to undertake a risk assessment that looks at how you acquire, process, store and share personal data.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.blackfootuk.com/2010/11/monetary-penalty-notices/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What should a QSA know?</title>
		<link>http://www.blackfootuk.com/2010/11/what-should-a-qsa-know/</link>
		<comments>http://www.blackfootuk.com/2010/11/what-should-a-qsa-know/#comments</comments>
		<pubDate>Sun, 14 Nov 2010 15:36:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://blackfoot.instdp.com/?p=133</guid>
		<description><![CDATA[At Blackfoot we believe a QSA should be a consultant first, and a QSA second. Our role is to help you navigate the sometimes contradictory requirements of the PCI standard and work out how to align compliance with your business.
Our QSAs have at least five year’s experience in general information security consulting as well as [...]]]></description>
			<content:encoded><![CDATA[<p>At Blackfoot we believe a QSA should be a consultant first, and a QSA second. Our role is to help you navigate the sometimes contradictory requirements of the PCI standard and work out how to align compliance with your business.</p>
<p>Our QSAs have at least five year’s experience in general information security consulting as well as experience in PCI. Blackfoot is a business enabler, not a compliance auditor and our approach is usually to determine how to minimise the amount of cardholder data our client’s retain.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.blackfootuk.com/2010/11/what-should-a-qsa-know/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

