<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Observations from ObserveIT</title>
	<atom:link href="http://blog.observeit.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.observeit.com</link>
	<description>Thoughts on User Activity Monitoring and ObserveIT products</description>
	<lastBuildDate>Tue, 15 May 2012 09:42:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>ObserveIT supports AIX now!</title>
		<link>http://blog.observeit.com/2012/05/15/observeit-supports-aix-now/</link>
		<comments>http://blog.observeit.com/2012/05/15/observeit-supports-aix-now/#comments</comments>
		<pubDate>Tue, 15 May 2012 09:42:27 +0000</pubDate>
		<dc:creator>Danny David</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.observeit.com/?p=656</guid>
		<description><![CDATA[I happy to announce that ObserveIT supports IBM AIX 5.3 platform now! For more details, please contact ObserveIT at sales@observeit.com. Regards, Danny David &#124; Product Manager ObserveIT Tel. +972 3 5438306 danny@observeit.com  &#124;  www.observeit.com &#160;]]></description>
			<content:encoded><![CDATA[<p>I happy to announce that ObserveIT supports IBM AIX 5.3 platform now!</p>
<p>For more details, please contact ObserveIT at sales@observeit.com.</p>
<p><strong>Regards,</strong></p>
<p><strong>Danny David</strong> | Product Manager</p>
<p><strong>ObserveIT</strong></p>
<p>Tel. +972 3 5438306</p>
<p><a href="mailto:danny@observeit.com">danny@observeit.com</a>  |  <a href="http://www.observeit-sys.com/" target="_blank">www.observeit.com</a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.observeit.com/2012/05/15/observeit-supports-aix-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ObserveIT adds HP Arcsight CEF Certification for standards-based SIEM integration</title>
		<link>http://blog.observeit.com/2012/05/09/observeit-adds-hp-arcsight-cef-certification-for-standards-based-siem-integration/</link>
		<comments>http://blog.observeit.com/2012/05/09/observeit-adds-hp-arcsight-cef-certification-for-standards-based-siem-integration/#comments</comments>
		<pubDate>Wed, 09 May 2012 16:47:39 +0000</pubDate>
		<dc:creator>Brad Young</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.observeit.com/?p=649</guid>
		<description><![CDATA[We&#8217;re proud to announce that we have recently been certified as ArcSight CEF compliant partners.  This is an important step for us. It expands the ways that ObserveIT User Activity log data can be utilized for building insightful security reports &#8230; <a href="http://blog.observeit.com/2012/05/09/observeit-adds-hp-arcsight-cef-certification-for-standards-based-siem-integration/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.observeit.com/wp-content/uploads/2012/05/HP_ArcSight_CEF_Certified_BL_RGB.png"><img class=" wp-image-650 alignleft" title="HP_ArcSight_CEF_Certified_BL_RGB" src="http://blog.observeit.com/wp-content/uploads/2012/05/HP_ArcSight_CEF_Certified_BL_RGB-300x139.png" alt="" width="240" height="111" /></a></p>
<p>We&#8217;re proud to announce that we have recently been certified as ArcSight CEF compliant partners.  This is an important step for us. It expands the ways that ObserveIT User Activity log data can be utilized for building insightful security reports and dashboards.</p>
<p>After completing an extensive certification process, we now are integrated tightly into the HP Arcsight platform, using standards-based CEF log file communications structure.  This means that any Arcsight installation can easily display ObserveIT&#8217;s user-oriented logs, including launching  a video replay that shows user actions.</p>
<p>What&#8217;s more, these video replays can be automatically correlated with ANY log data, whether it comes from OS system logs, DB logs or any other source. A simple UID/server/timestamp correlation will automatically tie any system event to a video replay which shows what triggered that event.</p>
<p>For more information about the integration, read the <a href="http://blog.observeit.com/wp-content/uploads/2012/05/ObserveIT_Enterprise_v5-6_CEF_Config-Guide_2012.pdf">technical config guide here</a>. If you are an Arcsight user, you can also get information on the HP Arcsight user forum: <a href="https://protect724.arcsight.com/groups/cef-connectors">https://protect724.arcsight.com/groups/cef-connectors</a></p>
<p>And go <a href="http://www.observeit-sys.com/Products/Features/SIEMIntegration">here for more details about how ObserveIT empowers your SIEM platform</a>.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.observeit.com/2012/05/09/observeit-adds-hp-arcsight-cef-certification-for-standards-based-siem-integration/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Verizon data breach investigation report shows exactly why User Activity Monitoring is a MUST</title>
		<link>http://blog.observeit.com/2012/04/05/verizon-data-breach-investigation-report-shows-exactly-why-user-activity-monitoring-is-a-must/</link>
		<comments>http://blog.observeit.com/2012/04/05/verizon-data-breach-investigation-report-shows-exactly-why-user-activity-monitoring-is-a-must/#comments</comments>
		<pubDate>Thu, 05 Apr 2012 16:15:56 +0000</pubDate>
		<dc:creator>Amy Marion</dc:creator>
				<category><![CDATA[Headline]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[User Activity Monitoring]]></category>
		<category><![CDATA[Verizon]]></category>

		<guid isPermaLink="false">http://blog.observeit.com/?p=638</guid>
		<description><![CDATA[The Verizon RISK Team has recently released the 2012 update to their Data Breach Investigations Report. More and more, it&#8217;s looking like User Activity Monitoring is rapidly becoming the best approach for Data Breach detection and prevention. If you haven’t &#8230; <a href="http://blog.observeit.com/2012/04/05/verizon-data-breach-investigation-report-shows-exactly-why-user-activity-monitoring-is-a-must/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>The Verizon RISK Team has recently released the 2012 update to their <a title="Verizon Data Breach Investigations Report" href="http://www.verizonbusiness.com/resources/reports/rp_data-breach-investigations-report-2012_en_xg.pdf" target="_blank">Data Breach Investigations Report</a>. More and more, it&#8217;s looking like <strong>User Activity Monitoring</strong> is rapidly becoming <strong>the best approach for Data Breach detection and prevention</strong>.</p>
<p>If you haven’t yet had a chance to dive into this 80 page report, I’ve summarized much of the good…er..actually…bad stuff here.</p>
<p>The big bummer is that 2011 had the <strong>2nd highest data loss total</strong> since the Verizon team started publishing the Data Breach Investigations Report in 2004.</p>
<p>The study also finds that when attacks happen, it’s <strong>weeks or months before they are detected</strong>. That’s bad enough, but what really makes this freakout-worthy is that when these breaches do get detected, it’s <strong>by external parties</strong> (i.e. not the victimized company). 92% of breaches are MADE PUBLIC by a someone other than the one who’s been breached. Reading about yourself in the headlines is a pretty crummy way to discover you’ve got a data breach.  Point being?  We need help identifying identity theft.</p>
<p><strong>Only 1% of breaches are detected by log analysis</strong>. (In large orgs the number is still very small at 8%). Clearly Log Analysis is not sufficient on its own. Even with all the dynamite SIEM products that are out there today, it’s time to re-evaluate which logs we are analyzing. Why? Because <strong>system logs are built for developers for debug</strong>, and not by security admins for security auditing.</p>
<p>Another frightening stat is that <strong>88% of hacking incidents are done using remote access</strong> or remote desktop services. This again points to the fact that monitoring user sessions is the main line for security auditing.</p>
<p>ObserveIT provides video recordings and video analysis of every user session (whether authorized or unauthorized) that occurs on your servers. For more details, please visit <a title="ObserveIT" href="www.observeit.com" target="_blank">observeit.com</a> or <a href="mailto:productdemo@observeit.com">send us an email</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.observeit.com/2012/04/05/verizon-data-breach-investigation-report-shows-exactly-why-user-activity-monitoring-is-a-must/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Make your SIEM Sing &#8211; Free Webinar</title>
		<link>http://blog.observeit.com/2012/03/20/make-your-siem-sing-free-webinar/</link>
		<comments>http://blog.observeit.com/2012/03/20/make-your-siem-sing-free-webinar/#comments</comments>
		<pubDate>Tue, 20 Mar 2012 17:08:12 +0000</pubDate>
		<dc:creator>Brad Young</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.observeit.com/?p=633</guid>
		<description><![CDATA[Want to learn how to get the most out of your SIEM Platform? Whether you use ArcSight, Splunk, CA UARM, RSA enVision or any other SIEM, you can easily generate reports, dashboards and correlations that show exact user actions (including video &#8230; <a href="http://blog.observeit.com/2012/03/20/make-your-siem-sing-free-webinar/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Want to learn how to get the most out of your SIEM Platform?</p>
<p>Whether you use ArcSight, Splunk, CA UARM, RSA enVision or any other SIEM, you can easily generate reports, dashboards and correlations that show exact user actions (including video replay!) &#8211; not just system log reports.</p>
<p>Join our security audit specialists this Wednesday (March 21st) at 12:00 ET (9AM PT, 4PM GMT) for a free webinar. Sign up here:  <a href="http://gurl.im/1c8e2Np">http://gurl.im/1c8e2Np</a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.observeit.com/2012/03/20/make-your-siem-sing-free-webinar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ObserveIT v5.6 EA is around the corner!</title>
		<link>http://blog.observeit.com/2012/03/18/observeit-v5-6-ea-is-around-the-corner/</link>
		<comments>http://blog.observeit.com/2012/03/18/observeit-v5-6-ea-is-around-the-corner/#comments</comments>
		<pubDate>Sun, 18 Mar 2012 14:38:30 +0000</pubDate>
		<dc:creator>Danny David</dc:creator>
				<category><![CDATA[Headline]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[5.6]]></category>
		<category><![CDATA[EA]]></category>

		<guid isPermaLink="false">http://blog.observeit.com/?p=625</guid>
		<description><![CDATA[ObserveIT v5.6 EA (Early Availability), will be released by the end of March! ObserveIT Enterprise v5.6 includes many new levels of protection. The most noteworthy new capability is a groundbreaking solution for catching incidents of identity theft, which lets you turn &#8230; <a href="http://blog.observeit.com/2012/03/18/observeit-v5-6-ea-is-around-the-corner/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>ObserveIT v5.6 EA (Early Availability), will be released by the end of March!</p>
<p>ObserveIT Enterprise v5.6 includes many new levels of protection. The most noteworthy new capability is a groundbreaking solution for catching incidents of identity theft, which lets you turn your thousands of users into your security detection network.</p>
<p>v5.6 also brings live-session messaging and remote locking, more functionality in our policy messaging module, even deeper self-auditing mechanisms and added archiving functionality.</p>
<p><a href="http://www.observeit-sys.com/Products/Whats_New_5_6">Full details can be found here</a>.</p>
<p>Want to get Early Availability release later this month? Send an email to me: danny@observeit.com</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.observeit.com/2012/03/18/observeit-v5-6-ea-is-around-the-corner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What can Slick Willie teach us about Application Security Monitoring?</title>
		<link>http://blog.observeit.com/2012/03/15/what-can-slick-willie-teach-us-about-application-security-monitoring/</link>
		<comments>http://blog.observeit.com/2012/03/15/what-can-slick-willie-teach-us-about-application-security-monitoring/#comments</comments>
		<pubDate>Thu, 15 Mar 2012 11:08:07 +0000</pubDate>
		<dc:creator>Brad Young</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Headline]]></category>

		<guid isPermaLink="false">http://blog.observeit.com/?p=616</guid>
		<description><![CDATA[When famed bank robber “Slick Willie&#8221; Sutton was asked &#8216;Why do you rob banks?&#8217;, his reply was taken as humor, but it also the most ultimate truth: &#8216;Because that&#8217;s where the money is.&#8217; If you ever wonder why you and &#8230; <a href="http://blog.observeit.com/2012/03/15/what-can-slick-willie-teach-us-about-application-security-monitoring/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" title="Slick Willie Sutton" src="https://encrypted-tbn1.google.com/images?q=tbn:ANd9GcQ0pN8LMazogXRYBfoxcoHvpmPvtysxmlMBt1XOXfe-JUDunHnf8g" alt="" width="236" height="137" />When famed bank robber “Slick Willie&#8221; Sutton was asked <strong><em>&#8216;Why do you rob banks?&#8217;</em></strong>, his reply was taken as humor, but it also the most ultimate truth: <strong><em>&#8216;Because that&#8217;s where the money is.&#8217;</em></strong></p>
<p>If you ever wonder why you and so many other IT Security professionals are spending so much time <em><strong>looking at layers of applications</strong></em>, well the answer is equally obvious.  <em><strong>&#8216;Because that&#8217;s where the threats are.&#8217;</strong></em></p>
<p>Over the past 18 months, IT has collectively woken up to the fact that security issues are penetrating much deeper than the network level. (Learn more <a href="http://www.darkreading.com/security-monitoring/167901086/security/security-management/227701138/six-tips-for-application-security-monitoring-success.html">here</a> and <a href="http://blogs.gartner.com/anton-chuvakin/2012/02/02/many-faces-of-application-security-monitoring/">here</a>.)</p>
<p>Network Security Monitoring still matters of course, but it has become almost a commodity. Firewalls work. Packet-based threat detection works. End of conversation.</p>
<p>Then why do we feel even less safe than ever? We all know why, deep in our bones: Because applications are now the primary platform for tomorrow&#8217;s security threats. That is why <em><strong>Application Security Monitoring is landing smack-dab in the middle of the CISO&#8217;s agenda.</strong></em></p>
<p>Now, the question must turn to the question of “How”.  How can we accomplish Application Security Monitoring, <em><strong>without rebuilding our entire app infrastructure</strong></em>?</p>
<p>Well, the answer is easier than you think: ASM tools that literally record all user activity (i.e. recording what they do when using the applications) give you the clarity you need for auditing and investigating threats that occur within those apps.</p>
<p>In other words, you don&#8217;t need a 12-step program to achieve Application Security Monitoring.</p>
<ul>
<li><img class="alignright" title="bad re-architecture" src="http://farm3.static.flickr.com/2152/2540588857_8003a7c98a_o.jpg" alt="" width="210" height="284" />Don’t get stuck in the (Re)Design-(Re)Code-(Re)Test cycle trying to improve the security within your apps.</li>
<li>Don’t drive yourself batty trying to interpret insufficient security logs that your apps produce today. Remember that those logs were built by developers, for the purpose of debugging. They were not built by auditors for the purpose of investigating security.</li>
<li>And most importantly, don’t assume that just having access control in place does enough. With distributed, mobile and modular application usage growing exponentially, the gatekeeper alone can’t keep track of what is really happening.</li>
</ul>
<p>Just like Slick Willie’s surprisingly obvious explanation, you can also use a surprisingly obvious explanation for how to instantly ramp up your Application Security Monitoring: Just put a monitor around your applications.  Learn more about <a href="http://www.observeit-sys.com/Products">ObserveIT’s surprisingly obvious solution here</a>.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.observeit.com/2012/03/15/what-can-slick-willie-teach-us-about-application-security-monitoring/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IDC IT Security Roadshow highlights with ObserveIT and Komtera</title>
		<link>http://blog.observeit.com/2012/02/27/idc-it-security-roadshow-highlights-with-observeit-and-komtera/</link>
		<comments>http://blog.observeit.com/2012/02/27/idc-it-security-roadshow-highlights-with-observeit-and-komtera/#comments</comments>
		<pubDate>Mon, 27 Feb 2012 08:25:45 +0000</pubDate>
		<dc:creator>Brad Young</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Headline]]></category>
		<category><![CDATA[Partners]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://blog.observeit.com/?p=592</guid>
		<description><![CDATA[On Feb 23, ObserveIT and our partner Komtera had an eye opening  experience at the IDC Security Roadshow in Istanbul, Turkey. Beyond the in-depth conference agenda, we spent many hours speaking with Security Officers, and were interested to discover how much &#8230; <a href="http://blog.observeit.com/2012/02/27/idc-it-security-roadshow-highlights-with-observeit-and-komtera/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" src="http://aiesec.ca/uploads/toronto/IDC_logo.png" alt="" width="360" height="170" />On Feb 23, ObserveIT and our partner <a href="http://www.komtera.com">Komtera</a> had an eye opening  experience at the <a href="http://events.idc-cema.com/eng/events/41817-idc-it-security-roadshow-2012/10-agenda">IDC Security Roadshow </a>in Istanbul, Turkey.</p>
<p>Beyond the in-depth conference agenda, we spent many hours speaking with Security Officers, and were interested to discover how much interest there is in plugging the &#8216;<strong>remote vendors</strong>&#8216; hole in the wall.</p>
<p>What especially surprised us was the number of times that this concern was coming specifically as a result of<strong> PCI audits that already have taken place</strong>. If you&#8217;ve been waiting for the day that PCI requirements would turn the corner from &#8216;something we&#8217;ll need to deal with&#8217; to &#8216;it&#8217;s on your plate right now&#8217;&#8230;. It seems that the future is now!</p>
<p>The folks at Komtera, our very effective partners in Instanbul, have been monitoring these developments for quite a while now, and that probably explains why so many of Istanbul&#8217;s largest financial and logistics companies are already counting on them for boosting their  security audit infrastructure.</p>
<p><a href="http://blog.observeit.com/wp-content/uploads/2012/02/komtera.jpg"><img class="alignnone size-medium wp-image-609" title="komtera" src="http://blog.observeit.com/wp-content/uploads/2012/02/komtera-300x225.jpg" alt="" width="300" height="225" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.observeit.com/2012/02/27/idc-it-security-roadshow-highlights-with-observeit-and-komtera/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Congrats to iPad Winner, Todd LeBloch!</title>
		<link>http://blog.observeit.com/2012/02/20/congrats-to-ipad-winner-todd-lebloch/</link>
		<comments>http://blog.observeit.com/2012/02/20/congrats-to-ipad-winner-todd-lebloch/#comments</comments>
		<pubDate>Mon, 20 Feb 2012 12:30:11 +0000</pubDate>
		<dc:creator>Amy Marion</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Headline]]></category>
		<category><![CDATA[Product Info]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.observeit.com/?p=597</guid>
		<description><![CDATA[Congratulation to our first Apple® iPad® 2.0 contest winner, Todd LeBloch. To get entered in the raffle, all Todd did had to do was schedule a 15min product demo for himself at two of his colleagues, then answer a short (5 &#8230; <a href="http://blog.observeit.com/2012/02/20/congrats-to-ipad-winner-todd-lebloch/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.observeit.com/wp-content/uploads/2012/02/ipad1.jpg"><img class="alignleft  wp-image-600" title="ipad" src="http://blog.observeit.com/wp-content/uploads/2012/02/ipad1.jpg" alt="" width="74" height="95" /></a>Congratulation to our first Apple® iPad® 2.0 contest winner, Todd LeBloch. To get entered in the raffle, all Todd did had to do was schedule a 15min product demo for himself at two of his colleagues, then answer a short (5 question) product feedback survey.</p>
<p>The next drawing will  be held on Friday, March 30th. To be entered, please <a href="mailto:productdemo@observeit.com">send us an email</a> and schedule a 15 minute product demonstration.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.observeit.com/2012/02/20/congrats-to-ipad-winner-todd-lebloch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RSA Conference Sneak-Peak: CA Session Recording &#8211; See it now!</title>
		<link>http://blog.observeit.com/2012/02/13/rsa-conference-sneak-peak-ca-session-recording-see-it-now/</link>
		<comments>http://blog.observeit.com/2012/02/13/rsa-conference-sneak-peak-ca-session-recording-see-it-now/#comments</comments>
		<pubDate>Mon, 13 Feb 2012 11:15:49 +0000</pubDate>
		<dc:creator>Brad Young</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Headline]]></category>
		<category><![CDATA[Partners]]></category>

		<guid isPermaLink="false">http://blog.observeit.com/?p=585</guid>
		<description><![CDATA[The RSA Conference is coming up soon! We&#8217;ll be there, as part of the CA Technologies booth, unveiling the latest in our groundbreaking Session Recording integration with CA. Want a sneak preview? Can&#8217;t make it to SF? Join us for this &#8230; <a href="http://blog.observeit.com/2012/02/13/rsa-conference-sneak-peak-ca-session-recording-see-it-now/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong><img class="alignright" src="https://calearning.ca.com/static_ca_web/styles/user/images/logo.gif" alt="CA " width="111" height="111" /></strong>The RSA Conference is coming up soon! We&#8217;ll be there, as part of the CA Technologies booth, unveiling the latest in our groundbreaking Session Recording integration with CA.</p>
<p>Want a sneak preview? Can&#8217;t make it to SF? <a href="http://www.observeit.com/LP/Webinar_Register?id=70120000000NjwY">Join us for this sneak-peak webinar</a>! On Tuesday Feb 14, you&#8217;ll learn highlight how it is surprisingly easy to get video replay logs of every user action, directly from within the full CA Access Control platform.</p>
<p>You&#8217;ll see how to:<br />
- Capture detailed user activity logs, including video recordings of every user action<br />
-  Address regulatory challenges, including PCI Requirement 10<br />
- Leverage even more of the CA Access Control to improve security for remote vendor logins</p>
<p><a href="http://www.observeit.com/LP/Webinar_Register?id=70120000000NjwY">Sign up here</a> for the webinar.</p>
<p>&nbsp;</p>
<p>BTW&#8230; Have you seen what  100+ customers are saying <a href="http://www.linkedin.com/company/observeit/products">about Session Recording on LinkedIn</a>? Here’s a few highlights:</p>
<ul>
<li><em>“The product is outstanding. Trust and be able to verify is essential.”</em> – <strong>Dell</strong></li>
<li><em>“When we saw the product kept its promises, we deployed it to all of our server farm. Nowadays compliance is really a challenge. ObserveIT transforms the challenge into a success story.”</em> – <strong>ING</strong></li>
<li><em>“When you have it in production, you see how smart product is. Small product details can solve bigger issues.”</em> – <strong>Siemens</strong></li>
<li><em>“This is an essential tool. I highly recommend this for Monitoring and Auditing.”</em> – <strong>TESCO</strong></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.observeit.com/2012/02/13/rsa-conference-sneak-peak-ca-session-recording-see-it-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to stop Identity Theft at its source</title>
		<link>http://blog.observeit.com/2012/01/31/how-to-stop-identity-theft-at-its-source/</link>
		<comments>http://blog.observeit.com/2012/01/31/how-to-stop-identity-theft-at-its-source/#comments</comments>
		<pubDate>Tue, 31 Jan 2012 09:36:50 +0000</pubDate>
		<dc:creator>Brad Young</dc:creator>
				<category><![CDATA[Headline]]></category>
		<category><![CDATA[Product Info]]></category>

		<guid isPermaLink="false">http://blog.observeit.com/?p=557</guid>
		<description><![CDATA[There are lots of tools and procedures that we arm our users with to protect their identity. (ex: Two Factor Authentication, Password complexity and reset rules, etc.) But once an identity is stolen, no tools can really identify or track &#8230; <a href="http://blog.observeit.com/2012/01/31/how-to-stop-identity-theft-at-its-source/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="It's Not You It's Me" src="http://rumplo.s3.amazonaws.com/images/tees/0000/2699/2699-0.jpg" alt="" width="172" height="173" />There are lots of tools and procedures that we arm our users with to protect their identity. (ex: Two Factor Authentication, Password complexity and reset rules, etc.)</p>
<p>But once an identity is stolen, no tools can really identify or track the incident. The responsibility for detection lies <strong>entirely on the security officer</strong>. Why? Because “<em>That’s the way we always did it!”  </em>With identity theft running rampant, this is just plain dangerous thinking.</p>
<p><strong>Why can’t we bring the user into the responsibility loop???</strong></p>
<p>Consider credit card fraud, as an analogy: How does Visa/MC/Amex capture fraud? (Hint: It’s not from fancy fraud detection security software.)  The vast majority of detection is from the simple feedback loop when cardholders inform about unauthorized purchases. (i.e. Your grandma and a telephone is the ultimate fraud protection tool!)</p>
<p>We must do the same in IT. Identity theft incidents can be detected and neutralized much quicker if we would just give users a way to flag unauthorized logins. After all, the only person who knows what a user did is the user himself/herself!</p>
<p>Let’s stop doing it the old way, just cuz that’s how we always did it. Let your users be your scouts. Your grandma will be very proud of you.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.observeit.com/2012/01/31/how-to-stop-identity-theft-at-its-source/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

