<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cisco Blog &#187; Gavin Reid</title>
	<atom:link href="http://blogs.cisco.com/author/GavinReid/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.cisco.com</link>
	<description></description>
	<lastBuildDate>Mon, 20 May 2013 21:55:35 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Security Logging in an Enterprise, Part 2 of 2</title>
		<link>http://blogs.cisco.com/security/security-logging-in-an-enterprise-part-2-of-2/</link>
		<comments>http://blogs.cisco.com/security/security-logging-in-an-enterprise-part-2-of-2/#comments</comments>
		<pubDate>Mon, 06 May 2013 14:30:26 +0000</pubDate>
		<dc:creator>Gavin Reid</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[logging]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[TRAC]]></category>

		<guid isPermaLink="false">http://blogs.cisco.com/?p=112383</guid>
		<description><![CDATA[We first logged IDS, some syslog from some UNIX hosts, and firewall logs (circa 1999). We went from there to dropping firewall logging as it introduced some overhead and we didn’t have any really good uses for it. (We still don’t.) Where did we go next?]]></description>
		<wfw:commentRss>http://blogs.cisco.com/security/security-logging-in-an-enterprise-part-2-of-2/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Security Logging in an Enterprise, Part 1 of 2</title>
		<link>http://blogs.cisco.com/security/security-logging-in-an-enterprise-part-1-of-2/</link>
		<comments>http://blogs.cisco.com/security/security-logging-in-an-enterprise-part-1-of-2/#comments</comments>
		<pubDate>Fri, 03 May 2013 14:30:34 +0000</pubDate>
		<dc:creator>Gavin Reid</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[logging]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[TRAC]]></category>

		<guid isPermaLink="false">http://blogs.cisco.com/?p=112317</guid>
		<description><![CDATA[Logging is probably both one of the most useful and least used of all security forensic capabilities. In large enterprises many security teams rely on their IT counterparts to do the logging and then turn to the IT logging infra when they need log information. That in itself isn’t bad; however, the needs/requirements for IT may not be a 100% fit for a CIRT. Read on to find out how we handled it.]]></description>
		<wfw:commentRss>http://blogs.cisco.com/security/security-logging-in-an-enterprise-part-1-of-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco Hosting Amsterdam 2013 FIRST Technical Colloquium</title>
		<link>http://blogs.cisco.com/security/cisco-hosting-amsterdam-2013-first-technical-colloquium/</link>
		<comments>http://blogs.cisco.com/security/cisco-hosting-amsterdam-2013-first-technical-colloquium/#comments</comments>
		<pubDate>Fri, 22 Mar 2013 16:03:45 +0000</pubDate>
		<dc:creator>Gavin Reid</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[CSIRT]]></category>
		<category><![CDATA[FIRST]]></category>
		<category><![CDATA[Gavin Reid]]></category>
		<category><![CDATA[KPN-CERT]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[MyCert]]></category>
		<category><![CDATA[NATO]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security intelligence operations]]></category>
		<category><![CDATA[sio]]></category>
		<category><![CDATA[TRAC]]></category>

		<guid isPermaLink="false">http://blogs.cisco.com/?p=106900</guid>
		<description><![CDATA[There is still time to register for the upcoming  <a title="FIRST TC" href="http://www.first.org/events/colloquia/amsterdam2013/program" target="_blank">FIRST Technical Colloquium</a> April 2-3 2013. The event has a very exciting program covering, [...]]]></description>
		<wfw:commentRss>http://blogs.cisco.com/security/cisco-hosting-amsterdam-2013-first-technical-colloquium/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>CSIRT Monitoring for Cisco House at the London 2012 Olympic Games</title>
		<link>http://blogs.cisco.com/security/csirt-monitoring-for-the-cisco-house-at-the-london-2012-olympic-games/</link>
		<comments>http://blogs.cisco.com/security/csirt-monitoring-for-the-cisco-house-at-the-london-2012-olympic-games/#comments</comments>
		<pubDate>Mon, 07 May 2012 13:30:57 +0000</pubDate>
		<dc:creator>Gavin Reid</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[2012_Olympics]]></category>
		<category><![CDATA[CSIRT]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[Ironport]]></category>
		<category><![CDATA[it security]]></category>
		<category><![CDATA[London Olympics]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[olympics]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[TRAC]]></category>
		<category><![CDATA[web security appliance]]></category>

		<guid isPermaLink="false">http://blogs.cisco.com/?p=68201</guid>
		<description><![CDATA[As part of CSIRT’s mobile monitoring offering for special events, we undertook monitoring of the corporate and customer traffic of [...]]]></description>
		<wfw:commentRss>http://blogs.cisco.com/security/csirt-monitoring-for-the-cisco-house-at-the-london-2012-olympic-games/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco&#8217;s Global WSA deployment &#8211; Update</title>
		<link>http://blogs.cisco.com/security/ciscos-global-wsa-deployment-update/</link>
		<comments>http://blogs.cisco.com/security/ciscos-global-wsa-deployment-update/#comments</comments>
		<pubDate>Wed, 21 Mar 2012 09:53:54 +0000</pubDate>
		<dc:creator>Gavin Reid</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Ironport]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[TRAC]]></category>
		<category><![CDATA[web security]]></category>

		<guid isPermaLink="false">http://blogs.cisco.com/?p=64057</guid>
		<description><![CDATA[This is an update for our original video/blog post (http://blogs.cisco.com/security/cisco-ironport-web-security-appliance-deployment/) on Cisco's CSIRT deployment of the Web Security Appliance.]]></description>
		<wfw:commentRss>http://blogs.cisco.com/security/ciscos-global-wsa-deployment-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Primer on the Common Vulnerability Scoring System CVSS</title>
		<link>http://blogs.cisco.com/security/primer-on-the-common-vulnerability-scoring-system-cvss/</link>
		<comments>http://blogs.cisco.com/security/primer-on-the-common-vulnerability-scoring-system-cvss/#comments</comments>
		<pubDate>Mon, 18 Jul 2011 13:00:05 +0000</pubDate>
		<dc:creator>Gavin Reid</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[CVSS]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[TRAC]]></category>
		<category><![CDATA[vulnerability scoring]]></category>

		<guid isPermaLink="false">http://blogs.cisco.com/?p=36637</guid>
		<description><![CDATA[What is CVSS - (the Common Vulnerability Scoring System)? How can it help me manage risk - and why is it an important step forward in security research? In this short video Gavin Reid CVSS Program Chair share's his perspective on the vulnerability scoring standard
]]></description>
		<wfw:commentRss>http://blogs.cisco.com/security/primer-on-the-common-vulnerability-scoring-system-cvss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco CSIRT on Advanced Persistent Threat</title>
		<link>http://blogs.cisco.com/security/cisco-csirt-on-advanced-persistent-threat/</link>
		<comments>http://blogs.cisco.com/security/cisco-csirt-on-advanced-persistent-threat/#comments</comments>
		<pubDate>Wed, 23 Mar 2011 17:32:54 +0000</pubDate>
		<dc:creator>Gavin Reid</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[advanced persistent threat]]></category>
		<category><![CDATA[APT]]></category>
		<category><![CDATA[CSIRT]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[TRAC]]></category>

		<guid isPermaLink="false">http://blogs.cisco.com/?p=24642</guid>
		<description><![CDATA[For corporations, Advanced Persistent Threat (APT) is a widely publicized yet little understood topic.  Does it exist?  Is it a real threat?  How can an organization tell if it is impacted? The Cisco Computer Security Incident Response Team (CSIRT) is a global team of information security professionals responsible for the 24/7 monitoring, investigation and response to cyber security incidents for Cisco-owned businesses. CSIRT engages in proactive threat assessment, mitigation planning, incident detection and response, incident trending with analysis, and the development of security architecture. This article will provide the Cisco CSIRT team’s perspective on APT, and is the fifth in a series of blog posts on related issues from CSIRT’s point of view.  As with the other posts, provided here are some real-world examples and techniques that will hopefully help organizations utilize existing tools and processes, or even understand gaps in security infrastructure.  Read on to find out more.]]></description>
		<wfw:commentRss>http://blogs.cisco.com/security/cisco-csirt-on-advanced-persistent-threat/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Netflow for Incident Response</title>
		<link>http://blogs.cisco.com/security/netflow-for-incident-response/</link>
		<comments>http://blogs.cisco.com/security/netflow-for-incident-response/#comments</comments>
		<pubDate>Fri, 07 Jan 2011 21:37:09 +0000</pubDate>
		<dc:creator>Gavin Reid</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[APT]]></category>
		<category><![CDATA[CSIRT]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[TRAC]]></category>

		<guid isPermaLink="false">http://blogs.cisco.com/?p=17100</guid>
		<description><![CDATA[This is the Forth part in the series “Missives from the Trenches.” In today's blog post we will be discussing Cisco IOS Netflow. Netflow has an interesting position as being both the most useful and least used tool. When meeting with other companies I often ask them “do you use Netflow?” By asking this question I am actually asking several different questions--Do you care about the security of your site? Or do you have any hopes in managing/responding to events at your site? Answers to these questions unfortunately tend to be as follows: What is Netflow? The network guys use it but we don’t. I think we capture it somewhere but not really sure where - and so on. I then mention that Netflow is free, they don’t have to buy anything to start using it, and it’s used for every large case we do. At that point they start looking angrily at the sales engineer asking why this is the first they are hearing about it. So what is Netflow and why does Ciscos’s CSIRT say its critical to daily event management? Read on to find out!

]]></description>
		<wfw:commentRss>http://blogs.cisco.com/security/netflow-for-incident-response/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Call for Speakers &#8211; FIRST Security Conference 2011, Vienna</title>
		<link>http://blogs.cisco.com/security/call-for-speakers-first-security-conference-2011-vienna/</link>
		<comments>http://blogs.cisco.com/security/call-for-speakers-first-security-conference-2011-vienna/#comments</comments>
		<pubDate>Thu, 11 Nov 2010 19:58:07 +0000</pubDate>
		<dc:creator>Gavin Reid</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[CFP]]></category>
		<category><![CDATA[CSIRT]]></category>
		<category><![CDATA[FIRST]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[TRAC]]></category>

		<guid isPermaLink="false">http://blogs.cisco.com/?p=13016</guid>
		<description><![CDATA[Cisco has had a long history of supporting the Forum of Incident Response Teams (FIRST),  as members in the organization, as chairs of various programs, steering committee members, and conference organizers. Cisco has also been providing the <a href="http://www.cisco.com/web/about/ciscoitatwork/highlights/053120071.html" target="_blank">network</a> for the global conference for many years. This year I am chairing the conference that will be held in Vienna on June 12-17, 2011. To that end, I am asking for some good security presentations for this year's conference.]]></description>
		<wfw:commentRss>http://blogs.cisco.com/security/call-for-speakers-first-security-conference-2011-vienna/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://media.first.org/podcasts/FIRST2010-GavinReid.mp3" length="6706642" type="audio/mpeg" />
		</item>
		<item>
		<title>Cisco Ironport Web Security Appliance Deployment</title>
		<link>http://blogs.cisco.com/security/cisco-ironport-web-security-appliance-deployment/</link>
		<comments>http://blogs.cisco.com/security/cisco-ironport-web-security-appliance-deployment/#comments</comments>
		<pubDate>Tue, 26 Oct 2010 13:30:25 +0000</pubDate>
		<dc:creator>Gavin Reid</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[CSIRT]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[TRAC]]></category>

		<guid isPermaLink="false">http://blogs.cisco.com/?p=11665</guid>
		<description><![CDATA[How does Cisco deal with cyber threats from the web? How does Cisco protect any device on a network? The following video will give you an update from Cisco CSIRT's Gavin Reid on how Cisco is combating this increasing threat.]]></description>
		<wfw:commentRss>http://blogs.cisco.com/security/cisco-ironport-web-security-appliance-deployment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
