<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Akshay on the business of security : Management</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/tags/Management/default.aspx</link><description>Tags: Management</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Akshay’s Uncertainty Principle: Observing Some Metrics Changes Them</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2009/03/26/akshay-s-uncertainty-principle-observing-some-metrics-changes-them.aspx</link><pubDate>Fri, 27 Mar 2009 04:12:45 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9512574</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/9512574.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=9512574</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=9512574</wfw:comment><description>You’ve probably heard of the famous&amp;#160; Heisenberg Uncertainty Principle&amp;#160; in Quantum physics. It states “The more precisely the position is determined, the less precisely the momentum is known in this instant, and vice versa.” --Heisenberg, uncertainty...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2009/03/26/akshay-s-uncertainty-principle-observing-some-metrics-changes-them.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9512574" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Management/default.aspx">Management</category></item><item><title>Business During Downturn: The Chain Of Trust</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2009/01/21/business-during-downturn-the-chain-of-trust.aspx</link><pubDate>Thu, 22 Jan 2009 06:48:43 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9362282</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/9362282.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=9362282</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=9362282</wfw:comment><description>Business during economic downturns brings to the surface the tiny fractures that were unnoticeable during the good times. It is a fertile ground to relearn some of the lessons of the past &amp;amp; form wisdom for the future. I am going to try and capture...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2009/01/21/business-during-downturn-the-chain-of-trust.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9362282" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Business/default.aspx">Business</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Leadership/default.aspx">Leadership</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Management/default.aspx">Management</category></item><item><title>Application Security Development Lifecycle 5A: Is Threat Modeling Right For You?</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/11/application-security-development-lifecycle-5a-is-threat-modeling-right-for-you.aspx</link><pubDate>Wed, 11 Jun 2008 18:06:24 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8590916</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>6</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/8590916.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=8590916</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=8590916</wfw:comment><description>Several enterprises are increasingly investing time and money in building application security tasks into their existing SDLCs. Some of them have also reached the conclusion that proactive approaches , like threat modeling, have more ROI than reactive...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/11/application-security-development-lifecycle-5a-is-threat-modeling-right-for-you.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8590916" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Business/default.aspx">Business</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Governance+Series/default.aspx">Governance Series</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Management/default.aspx">Management</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category></item><item><title>Application Security development Lifecycle 4: Finding the right security talent</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/01/application-security-development-lifecycle-4-finding-the-right-security-talent.aspx</link><pubDate>Sun, 01 Jun 2008 22:45:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8551936</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/8551936.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=8551936</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=8551936</wfw:comment><description>After about an hour of nodding his head vigorously in agreement with some of our lessons learnt, my customer jumped up and exclaimed, " Great!! Now where do I find another 20 people like these?" (pointing to my team)... I thought about it a while and...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/01/application-security-development-lifecycle-4-finding-the-right-security-talent.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8551936" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Process/default.aspx">Process</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Management/default.aspx">Management</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Education/default.aspx">Education</category></item><item><title>Application Security Development Lifecycle 2: Mandatory or Not?</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/04/22/application-security-governance-2-mandatory-or-not.aspx</link><pubDate>Tue, 22 Apr 2008 10:36:21 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8416189</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/8416189.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=8416189</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=8416189</wfw:comment><description>Large enterprises tend to have a number of line of business (LOB) applications supporting business operations. It becomes key for an application security program to help the organization manage the risk posed by each of these applications. Applications...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/04/22/application-security-governance-2-mandatory-or-not.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8416189" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Strategy/default.aspx">Strategy</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Management/default.aspx">Management</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category></item><item><title>Application Security Development Lifecycle 1: Understanding your portfolio</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/04/07/application-security-governance-1-understanding-your-portfolio.aspx</link><pubDate>Mon, 07 Apr 2008 19:45:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:6397859</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/6397859.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=6397859</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=6397859</wfw:comment><description>"How many applications do you have and what do they do?" It seems simple enough yet this questions seems to perplex many a smart mind. Having posed it to over a hundred and fifty CSO/CIOs over the last year, I have rarely received a clear answer that...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/04/07/application-security-governance-1-understanding-your-portfolio.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=6397859" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Process/default.aspx">Process</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Strategy/default.aspx">Strategy</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Management/default.aspx">Management</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category></item><item><title>Application Security Development Lifecycle Series</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/04/02/application-security-governance-series.aspx</link><pubDate>Thu, 03 Apr 2008 09:54:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:6395326</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/6395326.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=6395326</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=6395326</wfw:comment><description>After several requests from customers about information on how enterprise class application security programs are set up, I am writing a series of blogs about my experience helping some large enterprises set up application security teams similar to the...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/04/02/application-security-governance-series.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=6395326" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Process/default.aspx">Process</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Strategy/default.aspx">Strategy</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Management/default.aspx">Management</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category></item></channel></rss>