![]() |
![]() |
|
March 16, 2006Follow up to my Small Business Summit presentation on the 5 Rules of the Regulatory ProcessIn what had to be my worst presentation in YEARS I just finished presenting on the 5 Rules of the Regulatory Process for Microsoft at the Small Business Summit. I swear I was rambling incoherently at times as I tried to keep LiveMeeting going. *sigh* Sorry about that. I really should have practiced using LiveMeeting before I went and did this in front of an audience of over 300 people. Not as much a technical problem as trying to keep a Level 100 presentation on track without diving into detail while keeping the slides in sync. I found myself spending more time refraining from using infosec terms in an effort to keep it focused on the BDM (business decision makers) of small business rather than IT professionals who have experience in infosec. And stupid me should have used my own slides instead of worrying about LiveMeeting. Anyways, I promised I would provide the Q and A on my blog, and to not disappoint... that is what this post is about. Susan was AWESOME in answering much of this as I presented... so you will find her common theme as the SBS diva throughout :) In some places where we didn't get to respond to the question, I hope I am able to do that now. If I missed anything... feel free to leave a comment. I also promised to provide some more info on some of the standards, and I will do that in a follow up post. I would have posted the raw QA logs, but a LOT of the questions were really about technical difficulties that attendees were having at the Small Business Summit. Apparently some people were getting HUNDREDS of survey questions via email from previous presentations and felt that my presentation was the time to vent their frustration. Luckily Maryamie (Robert Scoble's wife) was the moderator and took care of all those questions for me! Thanks Maryamie! I'll make sure I bring down a bottle of Gwertztraminer and some applewood smoked cheese when I come down to see you and Robert next time. :) As promised here are the highlights from the QA session: Questions >>> Q: How many have joined the seminar ? I don's see the listing Q: Can you cover a little bit about PCI (Payment Card Industry) Compliance and how it affects small businesses? Q: Would you elaborate on steps to establish a full GLBA compliance program for bank? Q: Is there a site to go to to find out want the rules are for a web business. Q: With todays hackers why not have more security than need is more better? Q: Is Sharepoint a program that works with Microsoft Office? I am trying to set up a document control system in accordance with an aerospace quality standard Q: What medium works best with Shadow Copy? HD? USB-HD? Tape? Q: Where could I go to get more info on how to audit using GPO's? Q: What products should we use for authentication? Q: I use Office Professional, not SBS 2003. Can I still get it? Q: Will Office Live provide something like Remote Web Workplace as a way to have secure Information Availability? Q: What size HD best with Shadow Copy? 200GB+? Q: What is Remote Web Workplace? Q: Could I operate with SBS 2003 as my only server in a SOHO LAN? Would that be the place to add Active Directory? Q: Where would I find the risk assessment tool he just mentioned? Q: When is SBS R2 available? Q: How can I request to BETA or Community Test the R2? Q: Is there a site I can go to that will tell me what regulatory practices or laws I should be checking my system against? Q: Are there overviews of how to be hippa and sox compliant? Q: Does SBS have auto backup capabilities? Q: Can you discuss what you know about Law Firm compliance ? Q: What kind firewall and anti-virus is the best to use Q: Does Microsoft have a testing site to actively test whether or not encryption/sercuity meets certain standards? Q: Can you back up to other things besides tape? Q: Is there anyplace to get any good risk assessment templates? Q: Is there one list that can be used to find out what regulations apply to an organization or industry? Q: Our company recently had to become PCI compliant to be able to continue to process transactions online, it required a total overhaul of our server to keep up to date and the standards are changing every couple of months. I thought maybe the audience would like a heads up that this does affect the way small business do ecommerce. Yes I mentioned this earlier, I just think that it really can be a surprise for those considering going online with their business. Q: What can you tell us about the new Visa/Mastercard/Discover certification initiative? I understand it would require data incription. What is the MS solution for small businesses? Q: What products work over a VPN? Q: What type of anti virus do you use on sbs 2003 norton dose not work Q: RWW requires a server which I do not have Q: Does using encryption on your business server mean that all files are encrypted? ..or are only certain folders encrytable with encoders only on your LAN or WLAN? Q: Sounds like multiplicity is the watch-word to data protection? I use USB-HD plus copy to backup HD on desktop, plus use NTI Shadow Backup to backup to other desktop on network. What else would you add (on-site)? Q: How does the BizTalk Server for HIPAA transactions help an organization meet both HIPAA and SOX compliance? Q: I heard that there is a flash-drive based encryption product that basically encrypts your whole hard drive. Have you heard of it? Seems this might be useful to laptops on the road. If you have heard of it, what's your (personal) take? Q: Windows Storage Server. Where can I go for the communities and newsgroups? Q: Is current version of RMS forward compatible with SBS R2? <<< End Questions As I went through the question log, I noticed a lot of praise. I do appreciate that. And I apologize it wasn't smoother. Thanks for coming out and listening to my rambling! Posted by SilverStr at March 16, 2006 01:17 PM | TrackBackComments
If you hadn't told us that you felt you were rambling all over the place, I don't think we'd have known. Look at it on demand when you get a chance. I can sympathize with it being awkward using LiveMeeting without some kind of practice first. I was also going to complement you for ending early and leaving lots of room for Q&A (something that has been characteristic of the SB Summit sessions I've seen). Of course, SBSdiva had done such a good job (and it was weird to get such solid answered while you were talking about we didn't know who was responding -- Maryam's good, but I don't think she's a compliance person, heh [;If you hadn't told us that you felt you were rambling all over the place, I don't think we'd have known. Look at it on demand when you get a chance. I can sympathize with it being awkward using LiveMeeting without some kind of practice first. I was also going to complement you for ending early and leaving lots of room for Q&A (something that has been characteristic of the SB Summit sessions I've seen). Of course, SBSdiva had done such a good job (and it was weird to get such solid answered while you were talking about we didn't know who was responding -- Maryam's good, but I don't think she's a compliance person, heh [;<). If you think this was one of your worst presentations, I really want to see one that you think is your best. I'll have to find a button higher than 9 on the evaluation. Posted by: orcmid at March 16, 2006 07:27 PMI really didn't type all that stuff twice. Posted by: orcmid at March 16, 2006 07:28 PM |
![]() ![]()
My 5 Favorite Books
Writing Secure Code
Secure Programming Cookbook Security Engineering Secure Coding Principles & Practice Inside the Security Mind ![]()
My 5 Favorite Papers
Smashing the Stack
Penetration Studies Covert Channel Analysis of Trusted Systems DoD Trusted Computer System Evaluation Criteria NSA Security Recommendation Guides ![]()
Archives
June 2006
May 2006 April 2006 March 2006 February 2006 January 2006 December 2005 November 2005 October 2005 September 2005 August 2005 July 2005 June 2005 May 2005 April 2005 March 2005 February 2005 January 2005 December 2004 November 2004 October 2004 September 2004 August 2004 July 2004 June 2004 May 2004 April 2004 March 2004 February 2004 January 2004 December 2003 November 2003 October 2003 September 2003 August 2003 July 2003 June 2003 May 2003 April 2003 March 2003 February 2003 January 2003 December 2002 November 2002 October 2002 September 2002 August 2002 July 2002 ![]() |
|