<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Clear Insights &#187; Opinion</title>
	<atom:link href="http://clearskies.net/blog/category/opinion/feed/" rel="self" type="application/rss+xml" />
	<link>http://clearskies.net/blog</link>
	<description>Security News You Can Use</description>
	<lastBuildDate>Mon, 12 Apr 2010 20:06:26 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Scan This! Web Application Security Statistics Released</title>
		<link>http://clearskies.net/blog/2009/10/30/a-web-of-numbers-web-application-security-statistics-released/</link>
		<comments>http://clearskies.net/blog/2009/10/30/a-web-of-numbers-web-application-security-statistics-released/#comments</comments>
		<pubDate>Fri, 30 Oct 2009 22:36:02 +0000</pubDate>
		<dc:creator>Rick B.</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[pen testing]]></category>

		<guid isPermaLink="false">http://clearskies.net/blog/?p=222</guid>
		<description><![CDATA[WASC 2008 results of Web Application Security Statistics shows manual testing finds double the vulnerabilities automated scanning would!]]></description>
		<wfw:commentRss>http://clearskies.net/blog/2009/10/30/a-web-of-numbers-web-application-security-statistics-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sears.com Vulnerability Reinforces Need for Manual Testing</title>
		<link>http://clearskies.net/blog/2009/09/02/sears-com-vuln-reinforces-need-for-manual-testing/</link>
		<comments>http://clearskies.net/blog/2009/09/02/sears-com-vuln-reinforces-need-for-manual-testing/#comments</comments>
		<pubDate>Thu, 03 Sep 2009 01:18:05 +0000</pubDate>
		<dc:creator>Rick B.</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[pen testing]]></category>
		<category><![CDATA[software development]]></category>

		<guid isPermaLink="false">http://clearskies.net/blog/?p=198</guid>
		<description><![CDATA[New vulnvulnerability in Sears.com website reinforces the need for manual pen testing.]]></description>
		<wfw:commentRss>http://clearskies.net/blog/2009/09/02/sears-com-vuln-reinforces-need-for-manual-testing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DHS’ Software Assurance Efforts Can Help You</title>
		<link>http://clearskies.net/blog/2009/03/19/dhs-software-assurance-efforts-can-help-you/</link>
		<comments>http://clearskies.net/blog/2009/03/19/dhs-software-assurance-efforts-can-help-you/#comments</comments>
		<pubDate>Thu, 19 Mar 2009 16:36:46 +0000</pubDate>
		<dc:creator>Scott M.</dc:creator>
				<category><![CDATA[Discussion]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[DHS]]></category>
		<category><![CDATA[Software Assurance]]></category>

		<guid isPermaLink="false">http://clearskies.net/blog/?p=74</guid>
		<description><![CDATA[DHS' "Build Security In" effort is a great example of a government initiative that has a lot of potential to improve software security everywhere. They are providing a lot of great resources you can use, regardless of your business.]]></description>
		<wfw:commentRss>http://clearskies.net/blog/2009/03/19/dhs-software-assurance-efforts-can-help-you/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Insecure SSL and How PCI &#8220;Nearly&#8221; gets it Right</title>
		<link>http://clearskies.net/blog/2009/03/01/insecure-ssl-and-how-pci-nearly-gets-it-right/</link>
		<comments>http://clearskies.net/blog/2009/03/01/insecure-ssl-and-how-pci-nearly-gets-it-right/#comments</comments>
		<pubDate>Mon, 02 Mar 2009 01:27:40 +0000</pubDate>
		<dc:creator>Brad M.</dc:creator>
				<category><![CDATA[Discussion]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[SSL]]></category>

		<guid isPermaLink="false">http://clearsecurity.org/blog/?p=59</guid>
		<description><![CDATA[Insecure ciphers and protocols are still supported on a very large percentage servers we assess. We strongly advocate removing all insecure ciphers and protocols. The PCI Council nearly made it a requirement to disable SSLv2 – In the words of Maxwell Smart, "They missed it by THAT much".]]></description>
		<wfw:commentRss>http://clearskies.net/blog/2009/03/01/insecure-ssl-and-how-pci-nearly-gets-it-right/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top Vuln Lists – To be or not to be…</title>
		<link>http://clearskies.net/blog/2009/01/30/top-vuln-lists-%e2%80%93-to-be-or-not-to-be%e2%80%a6/</link>
		<comments>http://clearskies.net/blog/2009/01/30/top-vuln-lists-%e2%80%93-to-be-or-not-to-be%e2%80%a6/#comments</comments>
		<pubDate>Fri, 30 Jan 2009 16:52:32 +0000</pubDate>
		<dc:creator>Rick B.</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[CWE]]></category>
		<category><![CDATA[Vuln List]]></category>

		<guid isPermaLink="false">http://clearsecurity.org/blog/?p=17</guid>
		<description><![CDATA[Provides a personal opinion on the value and need for Top Vuln Lists within the security community.]]></description>
		<wfw:commentRss>http://clearskies.net/blog/2009/01/30/top-vuln-lists-%e2%80%93-to-be-or-not-to-be%e2%80%a6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Do you use &#8220;traditional&#8221; penetration testing?</title>
		<link>http://clearskies.net/blog/2009/01/16/do-you-use-traditional-penetration-testing/</link>
		<comments>http://clearskies.net/blog/2009/01/16/do-you-use-traditional-penetration-testing/#comments</comments>
		<pubDate>Fri, 16 Jan 2009 18:53:47 +0000</pubDate>
		<dc:creator>Scott M.</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[pen testing]]></category>
		<category><![CDATA[requirements]]></category>
		<category><![CDATA[software development]]></category>

		<guid isPermaLink="false">http://clearsecurity.org/blog/?p=7</guid>
		<description><![CDATA[A recent article goes deep into explaining penetration testing and how it should be adapted to focus on software development issues.  Hopefully the penetration testing services you are getting are ahead of the curve and are already tailored to provide you this value.]]></description>
		<wfw:commentRss>http://clearskies.net/blog/2009/01/16/do-you-use-traditional-penetration-testing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
