<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Follow-On: The Audit, Assertion, Assessment, and Assurance API (A6)</title>
	<atom:link href="http://www.rationalsurvivability.com/blog/?feed=rss2&#038;p=1276" rel="self" type="application/rss+xml" />
	<link>http://www.rationalsurvivability.com/blog/?p=1276</link>
	<description>Hoff&#039;s Ramblings about Information Survivability, Information Centricity, Risk Management and Disruptive Innovation. Oh, I have a fondness for virtualization and cloud computing security, too...</description>
	<lastBuildDate>Thu, 09 Sep 2010 02:54:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: The Automated Audit, Assertion, Assessment, and Assurance API (A6) Becomes: CloudAudit &#124; JK Technologies</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1276&#038;cpage=1#comment-37801</link>
		<dc:creator>The Automated Audit, Assertion, Assessment, and Assurance API (A6) Becomes: CloudAudit &#124; JK Technologies</dc:creator>
		<pubDate>Sat, 13 Feb 2010 19:26:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1276#comment-37801</guid>
		<description>[...] Follow-On: The Audit, Assertion, Assessment, and Assurance API (A6) (rationalsurvivability.com) [...]</description>
		<content:encoded><![CDATA[<p>[...] Follow-On: The Audit, Assertion, Assessment, and Assurance API (A6) (rationalsurvivability.com) [...]</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-37801" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('37801', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-37801-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-37801" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('37801', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-37801-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Extending the Concept: A Security API for Cloud Stacks &#124; Rational Survivability</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1276&#038;cpage=1#comment-37733</link>
		<dc:creator>Extending the Concept: A Security API for Cloud Stacks &#124; Rational Survivability</dc:creator>
		<pubDate>Fri, 12 Feb 2010 22:27:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1276#comment-37733</guid>
		<description>[...] Follow-On: The Audit, Assertion, Assessment, and Assurance API (A6) (rationalsurvivability.com) [...]</description>
		<content:encoded><![CDATA[<p>[...] Follow-On: The Audit, Assertion, Assessment, and Assurance API (A6) (rationalsurvivability.com) [...]</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-37733" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('37733', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-37733-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-37733" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('37733', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-37733-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Transparency: I Do Not Think That Means What You Think That Means... &#124; Rational Survivability</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1276&#038;cpage=1#comment-24113</link>
		<dc:creator>Transparency: I Do Not Think That Means What You Think That Means... &#124; Rational Survivability</dc:creator>
		<pubDate>Tue, 13 Oct 2009 13:06:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1276#comment-24113</guid>
		<description>[...] opportunity to quietly remind folks about the Audit, Assertion, Assessment and Assurance API (A6) API that is being brought to life; there will hopefully be some exciting news here shortly about [...]</description>
		<content:encoded><![CDATA[<p>[...] opportunity to quietly remind folks about the Audit, Assertion, Assessment and Assurance API (A6) API that is being brought to life; there will hopefully be some exciting news here shortly about [...]</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-24113" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('24113', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-24113-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-24113" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('24113', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-24113-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1276&#038;cpage=1#comment-13633</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Fri, 28 Aug 2009 00:27:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1276#comment-13633</guid>
		<description>I guess I am still fuzzy on how can we trust the provider to implement the API correctly.  Maybe I am being pessimistic, but what would keep vendors from crafting fake responses?  I wouldn&#039;t want a certification process, but would an SLA that says &quot;Yeah, we&#039;re good for it&quot; be enough?  

Because they are essentially self-certifying, and the current many compliance frameworks have an independent validation requirement.  Many authorizing officials aren&#039;t going to accept output from A6 as a certification artifact.

Just thinking out loud, is there a consideration for providing the control reference as part of the response?  You may have already considered that, but it wasn&#039;t discussed and it may conflict with one or more of the design philosophy item 3.</description>
		<content:encoded><![CDATA[<p>I guess I am still fuzzy on how can we trust the provider to implement the API correctly.  Maybe I am being pessimistic, but what would keep vendors from crafting fake responses?  I wouldn&#8217;t want a certification process, but would an SLA that says &#8220;Yeah, we&#8217;re good for it&#8221; be enough?  </p>
<p>Because they are essentially self-certifying, and the current many compliance frameworks have an independent validation requirement.  Many authorizing officials aren&#8217;t going to accept output from A6 as a certification artifact.</p>
<p>Just thinking out loud, is there a consideration for providing the control reference as part of the response?  You may have already considered that, but it wasn&#8217;t discussed and it may conflict with one or more of the design philosophy item 3.</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-13633" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('13633', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-13633-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-13633" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('13633', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-13633-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Erik</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1276&#038;cpage=1#comment-13470</link>
		<dc:creator>Erik</dc:creator>
		<pubDate>Wed, 26 Aug 2009 03:19:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1276#comment-13470</guid>
		<description>I&#039;m a fan of this idea and fully support it but only as a part of the solution, A6 alone won&#039;t solve the problem. In much the same way TV viewers are not the actual customers (the advertisers are) the cloud computing consumers are not going to be the actual users of A6, an intermediary that aggregates information on cloud providers (using A6 and other means) will be the true customer of ideas like A6. The more pressing issue that needs to be addressed is the lack of trusted intermediaries for cloud computing that give consumers the ability to keep watch over their providers and find new services according to terms they define specifically for their business. I coined the term &quot;cloud computing security referee&quot; and talk a little bit about it here: http://silvexis.com/blog/2009/08/24/referee-for-cloud-computing/ I would be interested in what your take is.</description>
		<content:encoded><![CDATA[<p>I&#8217;m a fan of this idea and fully support it but only as a part of the solution, A6 alone won&#8217;t solve the problem. In much the same way TV viewers are not the actual customers (the advertisers are) the cloud computing consumers are not going to be the actual users of A6, an intermediary that aggregates information on cloud providers (using A6 and other means) will be the true customer of ideas like A6. The more pressing issue that needs to be addressed is the lack of trusted intermediaries for cloud computing that give consumers the ability to keep watch over their providers and find new services according to terms they define specifically for their business. I coined the term &#8220;cloud computing security referee&#8221; and talk a little bit about it here: <a href="http://silvexis.com/blog/2009/08/24/referee-for-cloud-computing/" rel="nofollow">http://silvexis.com/blog/2009/08/24/referee-for-cloud-computing/</a> I would be interested in what your take is.</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-13470" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('13470', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-13470-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-13470" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('13470', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-13470-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: A6 Workgroup On The Way Soon &#124; CloudAve</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1276&#038;cpage=1#comment-12717</link>
		<dc:creator>A6 Workgroup On The Way Soon &#124; CloudAve</dc:creator>
		<pubDate>Wed, 19 Aug 2009 17:58:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1276#comment-12717</guid>
		<description>[...] a security guru with interests in Clouds and want to contribute to A6 Working Group, please contact Christofer Hoff. If you are a Cloud Vendor interested in playing a role in working out the details, you should be [...]</description>
		<content:encoded><![CDATA[<p>[...] a security guru with interests in Clouds and want to contribute to A6 Working Group, please contact Christofer Hoff. If you are a Cloud Vendor interested in playing a role in working out the details, you should be [...]</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-12717" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('12717', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-12717-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-12717" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('12717', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-12717-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Sam Johnston</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1276&#038;cpage=1#comment-12629</link>
		<dc:creator>Sam Johnston</dc:creator>
		<pubDate>Wed, 19 Aug 2009 06:31:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1276#comment-12629</guid>
		<description>Sounds interesting. I&#039;m all full up right now but I like to watch...

Sam</description>
		<content:encoded><![CDATA[<p>Sounds interesting. I&#8217;m all full up right now but I like to watch&#8230;</p>
<p>Sam</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-12629" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('12629', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-12629-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-12629" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('12629', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-12629-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: I&#8217;m really surprised you don&#8217;t see mor&#8230; &#171; /SAbackchan</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1276&#038;cpage=1#comment-12551</link>
		<dc:creator>I&#8217;m really surprised you don&#8217;t see mor&#8230; &#171; /SAbackchan</dc:creator>
		<pubDate>Tue, 18 Aug 2009 20:19:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1276#comment-12551</guid>
		<description>[...] http://www.rationalsurvivability.com/blog/?p=1276   &#160; [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://www.rationalsurvivability.com/blog/?p=1276" rel="nofollow">http://www.rationalsurvivability.com/blog/?p=1276</a>   &nbsp; [...]</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-12551" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('12551', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-12551-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-12551" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('12551', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-12551-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: beaker</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1276&#038;cpage=1#comment-12525</link>
		<dc:creator>beaker</dc:creator>
		<pubDate>Tue, 18 Aug 2009 18:21:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1276#comment-12525</guid>
		<description>&lt;a href=&quot;#comment-12468&quot; rel=&quot;nofollow&quot;&gt;@Srijith &lt;/a&gt; 

That&#039;s what the working group with various provider participants aims to address.

/Hoff</description>
		<content:encoded><![CDATA[<p><a href="#comment-12468" rel="nofollow">@Srijith </a> </p>
<p>That&#8217;s what the working group with various provider participants aims to address.</p>
<p>/Hoff</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-12525" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('12525', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-12525-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-12525" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('12525', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-12525-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Srijith</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1276&#038;cpage=1#comment-12468</link>
		<dc:creator>Srijith</dc:creator>
		<pubDate>Tue, 18 Aug 2009 14:42:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1276#comment-12468</guid>
		<description>This question rose out of a discussion which started in a (private) mailing list. While this previous posts explain the need for A6, how to query for one etc., what is left out is the actual way in which the results are produced within the beast. 

Without some form of verifiable, non-doctorable mechanism to produce these results, wouldn&#039;t they be only as useful (or useless) as a white paper from the cloud provider?

If the underlying layer within the beast uses the latest and greatest tamper-proof technology like processor powered (like skinit(AMD)/senter (Intel)) guarantee of externally-verifiable code execution that actually performs the audit/compliance tests, then we are talking something.</description>
		<content:encoded><![CDATA[<p>This question rose out of a discussion which started in a (private) mailing list. While this previous posts explain the need for A6, how to query for one etc., what is left out is the actual way in which the results are produced within the beast. </p>
<p>Without some form of verifiable, non-doctorable mechanism to produce these results, wouldn&#8217;t they be only as useful (or useless) as a white paper from the cloud provider?</p>
<p>If the underlying layer within the beast uses the latest and greatest tamper-proof technology like processor powered (like skinit(AMD)/senter (Intel)) guarantee of externally-verifiable code execution that actually performs the audit/compliance tests, then we are talking something.</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-12468" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('12468', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-12468-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-12468" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('12468', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-12468-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Doug Neal</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1276&#038;cpage=1#comment-12467</link>
		<dc:creator>Doug Neal</dc:creator>
		<pubDate>Tue, 18 Aug 2009 14:34:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1276#comment-12467</guid>
		<description>Very cool and very timely.  Congrats to you and Ben.

It seems to me that vendors at every layer in the stack will be looking to add new pay per use, on demand services.  Why not add various aspects of security to the list?  Bring the costs of security monitoring  out in the  open rather than extort it out of the  vendor during contract negotiation.

I really like the idea of a XSRL, a security version of XBRL.

You have commented before about &quot;Right to Audit&quot;.  That too, should be available as an extra cost option.  It seems to me that requiring companies to pay for the amount  of assurance they feel they need is the right way to go.</description>
		<content:encoded><![CDATA[<p>Very cool and very timely.  Congrats to you and Ben.</p>
<p>It seems to me that vendors at every layer in the stack will be looking to add new pay per use, on demand services.  Why not add various aspects of security to the list?  Bring the costs of security monitoring  out in the  open rather than extort it out of the  vendor during contract negotiation.</p>
<p>I really like the idea of a XSRL, a security version of XBRL.</p>
<p>You have commented before about &#8220;Right to Audit&#8221;.  That too, should be available as an extra cost option.  It seems to me that requiring companies to pay for the amount  of assurance they feel they need is the right way to go.</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-12467" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('12467', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-12467-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-12467" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('12467', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-12467-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
</channel>
</rss>
