<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for Risktical Ramblings</title>
	<atom:link href="http://risktical.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://risktical.com</link>
	<description>Assessing, Articulating &#38; Quantifying Information Security Risk</description>
	<lastBuildDate>Fri, 04 Jun 2010 19:07:42 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>Comment on Risk Vernacular by Collective Results &#171; Behavioral Security</title>
		<link>http://risktical.com/risk-vernacular/#comment-530</link>
		<dc:creator>Collective Results &#171; Behavioral Security</dc:creator>
		<pubDate>Fri, 04 Jun 2010 19:07:42 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.wordpress.com/?page_id=38#comment-530</guid>
		<description>[...] a nod to Chris Hayes and his risk vernacular (that may be a great starting point).&#160; I’d like to create a reference for terminologies and [...]</description>
		<content:encoded><![CDATA[<p>[...] a nod to Chris Hayes and his risk vernacular (that may be a great starting point).&#160; I’d like to create a reference for terminologies and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Impromtu IT Risk Assessment Poll by It&#8217;s Your Methods, Not Your Madness — Security Bloggers Network</title>
		<link>http://risktical.com/2010/05/25/impromtu-it-risk-assessment-poll/#comment-522</link>
		<dc:creator>It&#8217;s Your Methods, Not Your Madness — Security Bloggers Network</dc:creator>
		<pubDate>Tue, 01 Jun 2010 21:01:26 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.com/?p=299#comment-522</guid>
		<description>[...] methods, and they&#039;re not necessarily all the same or equal. Check out Chris Hayes&#039; quick poll &quot;Impromtu IT Risk Assessment Poll&quot; for a quick list of a couple approaches. Also note the results and just how many people have no [...]</description>
		<content:encoded><![CDATA[<p>[...] methods, and they&#039;re not necessarily all the same or equal. Check out Chris Hayes&#039; quick poll &quot;Impromtu IT Risk Assessment Poll&quot; for a quick list of a couple approaches. Also note the results and just how many people have no [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Heat Map Love by More Heat Map Love &#171; Risktical Ramblings</title>
		<link>http://risktical.com/2010/05/06/heat-map-love/#comment-489</link>
		<dc:creator>More Heat Map Love &#171; Risktical Ramblings</dc:creator>
		<pubDate>Tue, 11 May 2010 13:50:01 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.com/?p=276#comment-489</guid>
		<description>[...] Heat Map&#160;Love  In my previous post “Heat Map Love” I attempted to illustrate the relationship between plots on a heat map and a loss distribution. [...]</description>
		<content:encoded><![CDATA[<p>[...] Heat Map&nbsp;Love  In my previous post “Heat Map Love” I attempted to illustrate the relationship between plots on a heat map and a loss distribution. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Rainbow Risk by Heat Map Love &#171; Risktical Ramblings</title>
		<link>http://risktical.com/2010/04/01/rainbow-risk/#comment-482</link>
		<dc:creator>Heat Map Love &#171; Risktical Ramblings</dc:creator>
		<pubDate>Thu, 06 May 2010 16:19:31 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.com/?p=267#comment-482</guid>
		<description>[...] in my “Rainbow Risk” post I shared an example of a “rainbow chart”; a 100% stacked bar chart representing the [...]</description>
		<content:encoded><![CDATA[<p>[...] in my “Rainbow Risk” post I shared an example of a “rainbow chart”; a 100% stacked bar chart representing the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Risk and CVSS (Post 1) by HyunChul</title>
		<link>http://risktical.com/2008/08/24/risk-and-cvss-post-1/#comment-435</link>
		<dc:creator>HyunChul</dc:creator>
		<pubDate>Fri, 19 Feb 2010 10:26:51 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.wordpress.com/?p=48#comment-435</guid>
		<description>By the way, a vulnerability in CVSS is defined as a software defect which can be exploited by malicious users so that it can potentially cause negative impact.</description>
		<content:encoded><![CDATA[<p>By the way, a vulnerability in CVSS is defined as a software defect which can be exploited by malicious users so that it can potentially cause negative impact.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Risk and CVSS (Post 1) by HyunChul</title>
		<link>http://risktical.com/2008/08/24/risk-and-cvss-post-1/#comment-434</link>
		<dc:creator>HyunChul</dc:creator>
		<pubDate>Fri, 19 Feb 2010 10:24:02 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.wordpress.com/?p=48#comment-434</guid>
		<description>The main goal of CVSS is to standardize software related vulnerabilities mainly , so that we can make it sure that when we say vulnerability A, it is not the same one with vulnerability B among the people. 
Also, it can prioritize severity of vulnerabilities. It can help for the administrators which one should be first to be cure. Of course, as you said, it should not be panacea, but still it provides a tremendous services, especially for quantitative software risk analyzes.</description>
		<content:encoded><![CDATA[<p>The main goal of CVSS is to standardize software related vulnerabilities mainly , so that we can make it sure that when we say vulnerability A, it is not the same one with vulnerability B among the people.<br />
Also, it can prioritize severity of vulnerabilities. It can help for the administrators which one should be first to be cure. Of course, as you said, it should not be panacea, but still it provides a tremendous services, especially for quantitative software risk analyzes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Working With External Data (Part 1 of X) by Working With External Data (Part 2 of X) &#171; Risktical Ramblings</title>
		<link>http://risktical.com/2009/11/21/working-with-external-data-part-1-of-x/#comment-421</link>
		<dc:creator>Working With External Data (Part 2 of X) &#171; Risktical Ramblings</dc:creator>
		<pubDate>Tue, 02 Feb 2010 17:26:27 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.com/?p=246#comment-421</guid>
		<description>[...] to working with external data for analysis or modeling purposes. You can read the first post HERE or read the “cliff notes” summary [...]</description>
		<content:encoded><![CDATA[<p>[...] to working with external data for analysis or modeling purposes. You can read the first post HERE or read the “cliff notes” summary [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on What’s In Your Wallet? by Patrick Florer</title>
		<link>http://risktical.com/2009/12/28/what%e2%80%99s-in-your-wallet/#comment-408</link>
		<dc:creator>Patrick Florer</dc:creator>
		<pubDate>Mon, 28 Dec 2009 22:01:47 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.com/?p=259#comment-408</guid>
		<description>Very nice blog, Chris!

Patrick</description>
		<content:encoded><![CDATA[<p>Very nice blog, Chris!</p>
<p>Patrick</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Risk Vernacular by David Vose</title>
		<link>http://risktical.com/risk-vernacular/#comment-398</link>
		<dc:creator>David Vose</dc:creator>
		<pubDate>Wed, 09 Dec 2009 14:32:45 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.wordpress.com/?page_id=38#comment-398</guid>
		<description>Hi Chris

I see you read my book. I&#039;m curious to know what you thought of it.

Best wishes

David</description>
		<content:encoded><![CDATA[<p>Hi Chris</p>
<p>I see you read my book. I&#8217;m curious to know what you thought of it.</p>
<p>Best wishes</p>
<p>David</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Working With External Data (Part 1 of X) by Interesting Information Security Bits for 11/23/2009 &#124; Infosec Ramblings</title>
		<link>http://risktical.com/2009/11/21/working-with-external-data-part-1-of-x/#comment-379</link>
		<dc:creator>Interesting Information Security Bits for 11/23/2009 &#124; Infosec Ramblings</dc:creator>
		<pubDate>Mon, 23 Nov 2009 23:03:41 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.com/?p=246#comment-379</guid>
		<description>[...] scoped desire to build a &#8220;loss model.&#8221; This series looks to be very interesting. Working With External Data (Part 1 of X) &lt;&lt; Risktical Ramblings Tags: ( general [...]</description>
		<content:encoded><![CDATA[<p>[...] scoped desire to build a &#8220;loss model.&#8221; This series looks to be very interesting. Working With External Data (Part 1 of X) &lt;&lt; Risktical Ramblings Tags: ( general [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
