<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://community.ca.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>CA Community</title><link>http://community.ca.com/blogs/</link><description>Read submissions from a number of CA industry experts on topical subjects that can impact your bottom line</description><dc:language>en-US</dc:language><generator>CommunityServer 2007 SP2 (Build: 20611.960)</generator><item><title>Ajusting the Project Portfolio to Survive Turbluent Times  </title><link>http://community.ca.com/blogs/ppm/archive/2009/07/03/ajusting-the-project-portfolio-to-survive-turbluent-times.aspx</link><pubDate>Fri, 03 Jul 2009 15:26:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2630</guid><dc:creator>Pradeep Bhanot</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Today I came across an article at &lt;a class="" href="http://www.itpro.co.uk/612271/ba-shelves-erp-roll-out-as-airlines-slash-it" target="_blank"&gt;itpro.co.uk&lt;/a&gt; that discusses the severe impact on the airline industry of the current recession.&amp;nbsp;This is a good example of balancing the business portfolio to better&amp;nbsp;address the margin pressure being imposed by the current business climate. British Airways is not alone in this situation; many industries are deferring cash hungry projects with long lead times to value in favor of projects that promise faster returns that are needed now, as that can help carry them through the current economic turbulence. In this case BA cut an ERP project with returns expected in 2011 in order to favor a customer facing in-flight wireless communications project that will provide payback in a much shorter time.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;It is interesting to compare&amp;nbsp;the&amp;nbsp;case above to a more optimistic view, featuring Lean IT, expressed in the a recently published paper on preparing for the upturn from this recession, which you can&amp;nbsp;download by clicking &lt;a class="" href="http://www.ca.com/Files/SupportingPieces/preparing-renewed-growth_211043.pdf" target="_blank"&gt;here&lt;/a&gt;. It does resonate with the ITPro article in that does underline&amp;nbsp;the need for&amp;nbsp;companies to set frivolous projects aside and focus only on those that clearly produce value for customers and shareholders. &lt;/p&gt;
&lt;p&gt;The customer centricity and eliminating wasted effort are&amp;nbsp;central&amp;nbsp;elements of Lean thinking which both the paper and article are&amp;nbsp;touch upon and are worth a read. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://community.ca.com/blogs/ppm/DSC_0019-1-3.JPG"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://community.ca.com/blogs/ppm/DSC_0019-1-3.JPG"&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Ajusting+the+Project+Portfolio+to+Survive+Turbluent+Times++" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/ppm/archive/2009/07/03/ajusting-the-project-portfolio-to-survive-turbluent-times.aspx&amp;subject=Ajusting+the+Project+Portfolio+to+Survive+Turbluent+Times++"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/ppm/archive/2009/07/03/ajusting-the-project-portfolio-to-survive-turbluent-times.aspx&amp;title=Ajusting+the+Project+Portfolio+to+Survive+Turbluent+Times++" title="Submit Ajusting+the+Project+Portfolio+to+Survive+Turbluent+Times++ to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/ppm/archive/2009/07/03/ajusting-the-project-portfolio-to-survive-turbluent-times.aspx&amp;phase=2" title="Submit Ajusting+the+Project+Portfolio+to+Survive+Turbluent+Times++ to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/ppm/archive/2009/07/03/ajusting-the-project-portfolio-to-survive-turbluent-times.aspx&amp;title=Ajusting+the+Project+Portfolio+to+Survive+Turbluent+Times++" title="Submit Ajusting+the+Project+Portfolio+to+Survive+Turbluent+Times++ to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2630" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/ppm/archive/tags/PPM+Lean+IT+Portfolio/default.aspx">PPM Lean IT Portfolio</category></item><item><title>Happy with Crappy</title><link>http://community.ca.com/blogs/theitgovernanceevangelist/archive/2009/07/02/happy-with-crappy.aspx</link><pubDate>Thu, 02 Jul 2009 16:22:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2625</guid><dc:creator>Steve Romero</dc:creator><slash:comments>1</slash:comments><description>&lt;p&gt;I have written a number of posts discussing the rate of IT project failure. According to every study I have seen over the past 10 years, at least half of all IT projects fail. I believe there are many factors that contribute to this trend but during a recent interview with SearchCIO &lt;a href="http://bit.ly/3w5S3"&gt;http://bit.ly/3w5S3&lt;/a&gt;, Kristen Caretta asked me to choose one. Whenever I am asked this question I always cite the lack of sound Project and Portfolio Management (PPM). I have seen few organizations that have the appropriate decision-making processes and relationships to ensure their IT investments are reasoned and rational.&lt;/p&gt;
&lt;p&gt;Sound PPM enables enterprises to determine the optimal mix and sequencing of proposed programs and projects to best achieve the organization&amp;#39;s overall goals. PPM enables investments to be expressed in terms of hard economic measures, aligned to business strategy goals, while honoring constraints imposed by management or external real-world factors. Without this capability, I argue many projects are doomed before they begin.&lt;/p&gt;
&lt;p&gt;My discussion with Kristen reminded me of a recent visit I had with a CIO who is in the beginning stages of revamping an IT organization for a major insurance provider. We talked about many things in our two hours together, including IT investment governance in his organization. In our conversation, he offered a much simpler explanation for the rate of IT project failures. He contended enterprises are &amp;quot;Happy with crappy.&amp;quot; He said so with a mischievous grin and I couldn&amp;#39;t help but laugh. &lt;/p&gt;
&lt;p&gt;I am sure you have heard that there is an element of truth in every joke, and his clever comment caused me pause. In the past, I have theorized that our inability to correct this disturbing trend was partially due to a complacency born of a belief that technology projects inherently:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Take longer than we plan&lt;/li&gt;
&lt;li&gt;Cost more than we anticipate&lt;/li&gt;
&lt;li&gt;Don&amp;#39;t usually deliver what the user wants - the first time (for a variety of rationalized reasons)&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;Did his comment provide more insight into my theory? Are we happy with crappy based on our rationalization that technology projects are inherently difficult to estimate and deliver successfully? Let me know what you think.&lt;/p&gt;
&lt;p&gt;Steve Romero, IT Governance Evangelist&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Happy+with+Crappy" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/theitgovernanceevangelist/archive/2009/07/02/happy-with-crappy.aspx&amp;subject=Happy+with+Crappy"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/theitgovernanceevangelist/archive/2009/07/02/happy-with-crappy.aspx&amp;title=Happy+with+Crappy" title="Submit Happy+with+Crappy to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/theitgovernanceevangelist/archive/2009/07/02/happy-with-crappy.aspx&amp;phase=2" title="Submit Happy+with+Crappy to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/theitgovernanceevangelist/archive/2009/07/02/happy-with-crappy.aspx&amp;title=Happy+with+Crappy" title="Submit Happy+with+Crappy to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2625" width="1" height="1"&gt;</description></item><item><title>Economic Crisis and Service Management - Part II</title><link>http://community.ca.com/blogs/itil/archive/2009/07/01/igworld-economic-crisis-and-service-management-part-ii.aspx</link><pubDate>Wed, 01 Jul 2009 15:12:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2621</guid><dc:creator>Robert Stroud</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Part I can be viewed &lt;a class="" href="http://community.ca.com/blogs/itil/archive/2009/06/24/world-economic-crisis-and-service-management.aspx" target="_blank"&gt;here&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;As I mentioned previously, I spoke last week at a joint Korean itSMF and ISACA conference. This post continues with additional&amp;nbsp;answers&amp;nbsp;I prepared, answering excellent questions raised by the facilitator of the closing panel session.&lt;/p&gt;
&lt;p&gt;The second question asked at the panel&amp;nbsp;was an interesting one about inhibitors and accelerators for service management.&amp;nbsp; As many of you know I spend a good amount of time with large IT organizations globally so this allowed me to share some practical advice from a large Bank.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Question 2&lt;/strong&gt;: How do we drive IT governance through ITSM or IT governance frameworks such as COBIT, VALIT? What are key accelerators and critical inhibitors? How these frameworks fit with IT organization of the future? &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;When I met recently with the CIO and CTO of a large global Bank, she mentioned that one&amp;nbsp;thing happening today is the rate of change and the fact that more change is being generated by the business rather than IT.&amp;nbsp; She quoted the example of interest rate changes that are controlled by the business and executed automatically by IT as a good example of IT automating Business As Usual (BAU) and collecting the relevant audit check points and approvals.&amp;nbsp; She also&amp;nbsp;mentioned that social media and collaboration is transitioning business - staff are dynamically communicating and searching for resolutions to problems or knowledge for &amp;quot;how to scenarios&amp;quot; using&amp;nbsp;technologies like Twitter and Facebook.&amp;nbsp;Sales&amp;nbsp;is using LinkedIn connections to drive business relationships. Web 2.0 is changing again, accelerating the rate of change&amp;nbsp;and the way that functionality is delivered to our working environment.This is the perfect catalyst for changing the&amp;nbsp;manner that we deliver technology to support the business.&amp;nbsp; &lt;/li&gt;
&lt;li&gt;The best accelerator is for IT to acknowledge it is part of the business and for the business to acknowledge that it is dependent on IT. There are few industries or even business processes today where IT is not on the critical path to service delivery. This mandates a phase in enterprise change and that the processes that IT employs are NOT onerous but appropriate based on business risk.&amp;nbsp; &lt;/li&gt;
&lt;li&gt;The risk here is that we become so focused on the process and not the risk to the business that we unnecessarily add delays to delivery of service. Thus like the little boy who cried wolf, when the real risk is exposed IT, it&amp;nbsp;will not be believed and we will again fail, further increasing the divide between IT and the business.&lt;/li&gt;&lt;/ul&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Economic+Crisis+and+Service+Management+-+Part+II" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/itil/archive/2009/07/01/igworld-economic-crisis-and-service-management-part-ii.aspx&amp;subject=Economic+Crisis+and+Service+Management+-+Part+II"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/itil/archive/2009/07/01/igworld-economic-crisis-and-service-management-part-ii.aspx&amp;title=Economic+Crisis+and+Service+Management+-+Part+II" title="Submit Economic+Crisis+and+Service+Management+-+Part+II to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/itil/archive/2009/07/01/igworld-economic-crisis-and-service-management-part-ii.aspx&amp;phase=2" title="Submit Economic+Crisis+and+Service+Management+-+Part+II to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/itil/archive/2009/07/01/igworld-economic-crisis-and-service-management-part-ii.aspx&amp;title=Economic+Crisis+and+Service+Management+-+Part+II" title="Submit Economic+Crisis+and+Service+Management+-+Part+II to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2621" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/itil/archive/tags/Best+Practices+Guidance/default.aspx">Best Practices Guidance</category><category domain="http://community.ca.com/blogs/itil/archive/tags/Business+and+IT+Integration/default.aspx">Business and IT Integration</category><category domain="http://community.ca.com/blogs/itil/archive/tags/COBIT/default.aspx">COBIT</category><category domain="http://community.ca.com/blogs/itil/archive/tags/ISACA/default.aspx">ISACA</category><category domain="http://community.ca.com/blogs/itil/archive/tags/ITIL/default.aspx">ITIL</category><category domain="http://community.ca.com/blogs/itil/archive/tags/ITIL+V3/default.aspx">ITIL V3</category><category domain="http://community.ca.com/blogs/itil/archive/tags/itSMF+International/default.aspx">itSMF International</category><category domain="http://community.ca.com/blogs/itil/archive/tags/world+economic+crisis/default.aspx">world economic crisis</category></item><item><title>Service Definition:  What do "My Cousin Vinny" and Song Airlines have in common?</title><link>http://community.ca.com/blogs/itil/archive/2009/06/30/service-definition-what-do-quot-my-cousin-vinny-quot-and-song-airlines-have-in-common.aspx</link><pubDate>Tue, 30 Jun 2009 21:10:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2616</guid><dc:creator>Eric Feldman</dc:creator><slash:comments>4</slash:comments><description>&lt;p&gt;Many companies adopting a Service Catalog are faced with a dilemma. How do they define their services? Actually, there are two components to service definition. One is the processes employed to deliver or enable the service. These can be documented in a process modeling application, or made actionable using a tool, such as CA Workflow or CA IT Process Automation Manager. This is the &amp;quot;behind the scenes&amp;quot; part of a service definition. &lt;/p&gt;
&lt;p&gt;While this is important from the Service Definition and Lifecycle perspective, I wanted to focus this time on the specific definition that is published in a catalog. If you think about it, most customers and department managers are concerned with what they are choosing from a catalog, not how it will be delivered to them. &lt;/p&gt;
&lt;p&gt;Ever shop online? Many online merchants have setup elaborate systems to help you choose a product or service. There are glowing descriptions, photos, videos, customer testimonials, and rating systems. You may even see a service level listed, representing the time frame where the product will be delivered.&lt;/p&gt;
&lt;p&gt;On the other hand, do you see an activity diagram detailing how your credit card will be authorized, how the product will be picked from the warehouse, and how shipper routing decisions will be made? You don&amp;#39;t. While this information is important from the provider point of view, it is almost irrelevant from the customer&amp;#39;s perspective. They certainly care about receiving their product within a specified or reasonable time. How that product arrives is typically of no concern.&lt;/p&gt;
&lt;p&gt;To establish a Service Catalog, you must follow a similar mindset. The process behind the service definition is important, but primarily from the IT or service provider perspective. The backend, if you will. It is the technique and style you use to define the service from the customer or end user&amp;#39;s point of view that becomes crucial, especially when acceptance or adoption of the Catalog is of concern.&lt;/p&gt;
&lt;p&gt;But how does an IT organization actually describe their offerings? The technique is easy to describe from a high level:&amp;nbsp; Keep it informative, yet simple to describe. Think outcomes, not components. And use value added language that is meaningful to the appropriate user community. For example, a storage service could be described as “300 Gb logical volume size using SAS hard drives in a Raid 5 array. This description may be suitable for a technical user audience. For many business users, however, this information is inappropriate. A far more meaningful description may be “Reliable and secure data storage.&amp;quot;&lt;/p&gt;
&lt;p&gt;The Service Catalog is the publishing vehicle where IT does not just define their offerings. It also communicates their value to the business community.&lt;/p&gt;
&lt;p&gt;Which brings us back to the original question. &amp;quot;My Cousin Vinny&amp;quot; and &amp;quot;Song Airlines&amp;quot; both can show us examples of how a Service Catalog was deployed. Each illustrates the parameters I described above, in entirely different ways.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://community.ca.com/blogs/itil/menu.jpg"&gt;&lt;/a&gt;In &amp;quot;&lt;a class="" href="http://www.imdb.com/title/tt0104952/" target="_blank"&gt;My Cousin Vinny&lt;/a&gt;&amp;quot; the characters played by Joe Pesci and Marisa Tomei go to a diner and are handed a menu. It says simply &amp;quot;Breakfast,&amp;quot; &amp;quot;Lunch,&amp;quot; and &amp;quot;Dinner.&amp;quot; &lt;/p&gt;
&lt;p&gt;&lt;a class="" href="http://en.wikipedia.org/wiki/Song_Airlines" target="_blank"&gt;Song Airlines&lt;/a&gt; was a former division of Delta Airlines that featured an &amp;quot;upscale bistro&amp;quot; menu of food for purchase. It detailed elaborate descriptions of offerings more gourmet than geek. Here is an actual description taken from a Song menu: &amp;quot;Asian Chicken Salad. No, you don&amp;#39;t have to eat it with chopsticks: Ginger-marinated chicken *** with romaine, napa cabbage, shredded carrots, water chestnuts and mandarin oranges. Served with chow mein noodles for crunch and a sesame-ginger vinaigrette for kick.&amp;quot;&lt;/p&gt;
&lt;p&gt;So, which method are you using to represent your organization&amp;#39;s value? Do you use the &amp;quot;My Cousin Vinny&amp;quot; or the &amp;quot;Song Airlines&amp;quot; technique?&lt;/p&gt;
&lt;p&gt;Or to ask this question in a different way, are you using relevant value oriented language in your Service Catalog, or do you get by with just a simple two word description such as &amp;quot;request access?&amp;quot;&lt;br /&gt;&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Service+Definition%3a++What+do+%26quot%3bMy+Cousin+Vinny%26quot%3b+and+Song+Airlines+have+in+common%3f" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/itil/archive/2009/06/30/service-definition-what-do-quot-my-cousin-vinny-quot-and-song-airlines-have-in-common.aspx&amp;subject=Service+Definition%3a++What+do+%26quot%3bMy+Cousin+Vinny%26quot%3b+and+Song+Airlines+have+in+common%3f"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/itil/archive/2009/06/30/service-definition-what-do-quot-my-cousin-vinny-quot-and-song-airlines-have-in-common.aspx&amp;title=Service+Definition%3a++What+do+%26quot%3bMy+Cousin+Vinny%26quot%3b+and+Song+Airlines+have+in+common%3f" title="Submit Service+Definition%3a++What+do+%26quot%3bMy+Cousin+Vinny%26quot%3b+and+Song+Airlines+have+in+common%3f to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/itil/archive/2009/06/30/service-definition-what-do-quot-my-cousin-vinny-quot-and-song-airlines-have-in-common.aspx&amp;phase=2" title="Submit Service+Definition%3a++What+do+%26quot%3bMy+Cousin+Vinny%26quot%3b+and+Song+Airlines+have+in+common%3f to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/itil/archive/2009/06/30/service-definition-what-do-quot-my-cousin-vinny-quot-and-song-airlines-have-in-common.aspx&amp;title=Service+Definition%3a++What+do+%26quot%3bMy+Cousin+Vinny%26quot%3b+and+Song+Airlines+have+in+common%3f" title="Submit Service+Definition%3a++What+do+%26quot%3bMy+Cousin+Vinny%26quot%3b+and+Song+Airlines+have+in+common%3f to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2616" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/itil/archive/tags/CA+IT+Process+Automation+Manager/default.aspx">CA IT Process Automation Manager</category><category domain="http://community.ca.com/blogs/itil/archive/tags/CA+Workflow/default.aspx">CA Workflow</category><category domain="http://community.ca.com/blogs/itil/archive/tags/Service+Catalog/default.aspx">Service Catalog</category><category domain="http://community.ca.com/blogs/itil/archive/tags/Service+Lifecycle/default.aspx">Service Lifecycle</category></item><item><title>What Part of DLP Should I Implement First?</title><link>http://community.ca.com/blogs/iam/archive/2009/06/29/what-part-of-dlp-should-i-implement-first.aspx</link><pubDate>Mon, 29 Jun 2009 16:18:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2608</guid><dc:creator>David Miller</dc:creator><slash:comments>0</slash:comments><description>&lt;font face="Calibri"&gt;Data Loss Prevention (DLP) solutions secure a company’s sensitive data and critical digital assets on endpoints (desktops and laptops), the network, message servers, and even stored data.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/font&gt;&lt;font face="Calibri"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;/span&gt;Comprehensive DLP solutions create a dilemma for organizations: what aspect of data loss do they address first?&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/font&gt;&lt;font face="Calibri"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;/span&gt;This query may seem commonplace.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;But because DLP identifies and controls highly sensitive data across the enterprise, this question is very important.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/font&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;font face="Calibri"&gt;
&lt;p class="MsoNormal" style="MARGIN:0in 0in 10pt;"&gt;As expected, the answer depends on various characteristics and goals of the firm asking the question.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;A few considerations:&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;div class="MsoNormal" style="MARGIN:0in 0in 10pt;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;/span&gt;&lt;i style="mso-bidi-font-style:normal;"&gt;Do you know of data that you must protect now?&lt;/i&gt;&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;If you need to protect something specific – such as product design documents, proprietary models, or your customers’ personal information, you may decide to start using DLP to control the use or transmission of that particular data. &lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div class="MsoNormal" style="MARGIN:0in 0in 10pt;"&gt;Then, &lt;i style="mso-bidi-font-style:normal;"&gt;which type of use must you control?&lt;/i&gt;&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;There is email, Web, IM, FTP, moving data to removable media, printing data, and many other methods available to your end users that can result in data misuse and leakage.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;To understand what to protect, you need to evaluate these against existing procedures.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;If you’ve locked down USB ports, then perhaps you should first protect network-based transmissions or emails at the message server.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;If the use of removable media is permissible, consider protecting against saving your high-risk data to them.&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div class="MsoNormal" style="MARGIN:0in 0in 10pt;"&gt;&lt;i style="mso-bidi-font-style:normal;"&gt;Do you have high-risk users?&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/i&gt;These can be executives with insider information, engineers with next-generation product designs, and even outsourced employees.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;If so, consider using your DLP solution to focus on controlling their activity first, or at least differently than for other users.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div class="MsoNormal" style="MARGIN:0in 0in 10pt;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;/span&gt;&lt;i style="mso-bidi-font-style:normal;"&gt;Do you need to discover your data risks?&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/i&gt;If so, that’s ok – and you’re not alone.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;Here, DLP should be used to identify and discover sensitive data across the enterprise.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;You must determine what systems to scan – content repositories (such as Microsoft SharePoint), network folders, and/or end-user desktops.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;This can depend on how your end-users collaborate.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div class="MsoNormal" style="MARGIN:0in 0in 10pt;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;/span&gt;&lt;i style="mso-bidi-font-style:normal;"&gt;How will you support your DLP system&lt;/i&gt;?&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;If you will control use and transmission straight away, be prepared to handle the activity the system will detect.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;This calls for the highest levels of detection accuracy so that your security and compliance resources will be used efficiently.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;Keep in mind – a DLP solution must be able to accommodate expansion&amp;nbsp;beyond your initial deployment.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;/span&gt;How have you approached your DLP deployment? &lt;/font&gt;&lt;/font&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email What+Part+of+DLP+Should+I+Implement+First%3f" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/iam/archive/2009/06/29/what-part-of-dlp-should-i-implement-first.aspx&amp;subject=What+Part+of+DLP+Should+I+Implement+First%3f"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/iam/archive/2009/06/29/what-part-of-dlp-should-i-implement-first.aspx&amp;title=What+Part+of+DLP+Should+I+Implement+First%3f" title="Submit What+Part+of+DLP+Should+I+Implement+First%3f to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/iam/archive/2009/06/29/what-part-of-dlp-should-i-implement-first.aspx&amp;phase=2" title="Submit What+Part+of+DLP+Should+I+Implement+First%3f to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/iam/archive/2009/06/29/what-part-of-dlp-should-i-implement-first.aspx&amp;title=What+Part+of+DLP+Should+I+Implement+First%3f" title="Submit What+Part+of+DLP+Should+I+Implement+First%3f to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2608" width="1" height="1"&gt;</description></item><item><title>Italy: Prime Minister Subject of Spam?</title><link>http://community.ca.com/blogs/securityadvisor/archive/2009/06/29/italy-prime-minister-subject-of-spam.aspx</link><pubDate>Mon, 29 Jun 2009 09:42:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2605</guid><dc:creator>Rossano Ferraris</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Spammers have used the recent political controversy that surrounds the Italian Prime Minister&lt;br /&gt;Silvio Berlusconi to lure and trap Italian speaking people via an email spam (see Figure 1 and&lt;br /&gt;Figure 2). Italian people who love gossip about public people may be particularly susceptible to&lt;br /&gt;this type of email.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Rossano/Email.gif"&gt;&lt;img border="0" src="http://community.ca.com/blogs/securityadvisor/Rossano/Email.gif" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;Figure 1 - Spammed Email&lt;br /&gt;&lt;br /&gt;The English translation is:&lt;br /&gt;&lt;br /&gt;&lt;em&gt;“Have you seen what our Prime Minister Silvio Berlusconi is doing? Have you followed his story&lt;br /&gt;with the escort?&lt;br /&gt;Thanks to a journalist of LEGGO, we have got the opportunity to see our Premier together with&lt;br /&gt;his escort girl recently appeared on newspapers. If you want to see them, click on the link below:&lt;br /&gt;hxxp://you[BLOCKED].com/watchv=W3k9pMtrccQ.html&lt;br /&gt;&lt;br /&gt;TO SEE THE VIDEO YOU NEED TO INSTALL THE FOLLOWING CODEC…”&lt;br /&gt;&lt;br /&gt;&lt;/em&gt;If we examine the email closely, we see that the email pretends to come from Youtube.&lt;br /&gt;However, the email really comes from a certain Youtorube.com (see Figure 1 and Figure 2) which&lt;br /&gt;is hosted on a web server located in Florida with IP address 64.71.35.20.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Rossano/Email_Header.gif"&gt;&lt;img border="0" src="http://community.ca.com/blogs/securityadvisor/Rossano/Email_Header.gif" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;Figure 2 - Email Header&lt;/p&gt;
&lt;p&gt;A link in the email will redirect us to a malicious website “youtorube.com” that asks the user to&lt;br /&gt;install a new codec to view the video (Figure 3):&lt;br /&gt;&lt;br /&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Rossano/website.gif"&gt;&lt;img border="0" src="http://community.ca.com/blogs/securityadvisor/Rossano/website.gif" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;Figure 3 - Host website&lt;br /&gt;&lt;br /&gt;The new codec is called “wmpcodec.exe,” and CA AV detects this file as the worm&lt;br /&gt;“Win32/IRCBot.OQ”, and blocks it from running.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Additional Information on Win32/IRCBot.OQ&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;We managed to follow the communication between the malware file and its IRC server, from&lt;br /&gt;there we found that the bot malware is monitoring keystrokes, passwords, websites visited and&lt;br /&gt;windows opened in the infected system.&lt;br /&gt;&lt;br /&gt;Win32/IRCBot.OQ sends a log of computing activities of an infected system in the IRC server. It&lt;br /&gt;makes the activity log visible to the malware author and also to other infected systems.&lt;br /&gt;The IRC channel becomes a log file of activities of all infected machines.&lt;br /&gt;&lt;br /&gt;Figure 4 shows how each activity was logged in the IRC channel:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Rossano/bot_log_irc_edit2.gif"&gt;&lt;img border="0" src="http://community.ca.com/blogs/securityadvisor/Rossano/bot_log_irc_edit2.gif" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;Figure 4 - Communication capture in the IRC channel&lt;br /&gt;&lt;br /&gt;It logs usernames and passwords when an infected system accesses a website that contains&lt;br /&gt;&amp;#39;login.php&amp;#39; in the URL.&lt;br /&gt;&lt;br /&gt;In addition, it attempts to download other malware to the infected system, which CA detects as&lt;br /&gt;Win32/PolyCrypt!packed.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&amp;nbsp;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Thanks to Zarestel Ferrer for his contribution to the description of Win32/IRCBot.OQ malware&lt;/em&gt;&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Italy%3a+Prime+Minister+Subject+of+Spam%3f" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/securityadvisor/archive/2009/06/29/italy-prime-minister-subject-of-spam.aspx&amp;subject=Italy%3a+Prime+Minister+Subject+of+Spam%3f"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/securityadvisor/archive/2009/06/29/italy-prime-minister-subject-of-spam.aspx&amp;title=Italy%3a+Prime+Minister+Subject+of+Spam%3f" title="Submit Italy%3a+Prime+Minister+Subject+of+Spam%3f to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/securityadvisor/archive/2009/06/29/italy-prime-minister-subject-of-spam.aspx&amp;phase=2" title="Submit Italy%3a+Prime+Minister+Subject+of+Spam%3f to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/securityadvisor/archive/2009/06/29/italy-prime-minister-subject-of-spam.aspx&amp;title=Italy%3a+Prime+Minister+Subject+of+Spam%3f" title="Submit Italy%3a+Prime+Minister+Subject+of+Spam%3f to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2605" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/antimalware/default.aspx">antimalware</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/Anti-Spyware/default.aspx">Anti-Spyware</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/Anti-Virus/default.aspx">Anti-Virus</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/CA/default.aspx">CA</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/CA+Anti-Spyware+Scorecard/default.aspx">CA Anti-Spyware Scorecard</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/CA+Anti-Virus/default.aspx">CA Anti-Virus</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/internet+threats/default.aspx">internet threats</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/IRCBot/default.aspx">IRCBot</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/malware/default.aspx">malware</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/Passwords/default.aspx">Passwords</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/rossano/default.aspx">rossano</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/Rossano+Ferraris/default.aspx">Rossano Ferraris</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/Silvio+Berlusconi/default.aspx">Silvio Berlusconi</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/social+networking/default.aspx">social networking</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/spam/default.aspx">spam</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/spyware/default.aspx">spyware</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/worm/default.aspx">worm</category></item><item><title>Malware finds refuge in school</title><link>http://community.ca.com/blogs/securityadvisor/archive/2009/06/29/malware-finds-refuge-in-school.aspx</link><pubDate>Mon, 29 Jun 2009 03:37:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2601</guid><dc:creator>Aaron Faloon</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;This week in CA Research Labs as we were receiving new variants of the popular Bancos Trojan we were able to make a successful attempt at tracing one of these variants back to its distribution point. &lt;/p&gt;
&lt;p&gt;This distribution point is a web server located in the state of New Jersey in the United States of America. The web server is associated with a local school in the area and is used to host it’s website to the public. &lt;/p&gt;
&lt;p&gt;An interesting point to note is that the school is presently closed for maintenance and equally important the school has dismissed for the summer. &lt;/p&gt;
&lt;p&gt;Was this timing intentional by the malware authors in order to go undetected by the people involved with monitoring the schools website and network or purely just coincidence? &lt;/p&gt;
&lt;p&gt;
&lt;div id="ms__id135" align="center"&gt;&lt;a class="" href="http://community.ca.com/blogs/securityadvisor/Aaron/Malware_finds_refuge_GCCS%20HomePage.gif" target="_blank"&gt;&lt;img title="School Website" style="WIDTH:560px;HEIGHT:341px;" height="341" alt="School Website" src="http://community.ca.com/blogs/securityadvisor/Aaron/Malware_finds_refuge_GCCS%20HomePage.gif" width="560" align="middle" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;blockquote&gt;
&lt;blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;
&lt;div id="ms__id146" align="center"&gt;[Figure 1 - School Website hosted on web server]&lt;/div&gt;
&lt;div id="ms__id166" align="center"&gt;&amp;nbsp;&lt;/div&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;
&lt;p&gt;
&lt;div id="ms__id147" align="center"&gt;&lt;a class="" href="http://community.ca.com/blogs/securityadvisor/Aaron/Malware_finds_refuge_Bancos%20Files.gif" target="_blank"&gt;&lt;img title="Malware on compromised web server" style="WIDTH:560px;HEIGHT:482px;" height="482" alt="Malware on compromised web server" src="http://community.ca.com/blogs/securityadvisor/Aaron/Malware_finds_refuge_Bancos%20Files.gif" width="560" align="middle" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;blockquote&gt;
&lt;blockquote&gt;
&lt;blockquote&gt;
&lt;div id="ms__id127" align="center"&gt;[Figure 2 –Bancos Malware stored on compromised web server]&lt;/div&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;
&lt;p&gt;As well as hosting the schools website we can see that the compromised web server is also hosting Bancos malware. Here we can see the malware files that are stored in the directory on the compromised web server. These files are used to resemble legitimate banking applications in order to fool the user into entering their banking information which is then stolen by the attackers. &lt;/p&gt;
&lt;p&gt;&lt;u&gt;Anatomy of the Attack&lt;/u&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;
&lt;div id="ms__id198" align="center"&gt;&lt;a class="" href="http://community.ca.com/blogs/securityadvisor/Aaron/Malware_finds_refuge_anatomy.gif" target="_blank"&gt;&lt;img title="Anatomy of the attack" style="WIDTH:560px;HEIGHT:341px;" height="341" alt="Anatomy of the attack" src="http://community.ca.com/blogs/securityadvisor/Aaron/Malware_finds_refuge_anatomy.gif" width="560" align="middle" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;blockquote&gt;
&lt;blockquote&gt;
&lt;blockquote&gt;
&lt;div id="ms__id129" align="center"&gt;[Figure 3 – Anatomy of the attack]&lt;/div&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;blockquote&gt;
&lt;blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;
&lt;p&gt;&lt;u&gt;Step 1&lt;/u&gt; - The Users machine gets infected by one of the Bancos download agents. These agents are detected by CA as Win32/Bancos.ORU and Win32/Bancos.ORV. &lt;/p&gt;
&lt;p&gt;&lt;u&gt;Step 2&lt;/u&gt; - The infected machine will now automatically connect to the compromised web server under control&amp;nbsp;of the download agents. &lt;/p&gt;
&lt;p&gt;&lt;u&gt;Step 3&lt;/u&gt; - Once connected to the compromised web server the download agents will download Win32/Bancos.ONW onto the user’s machine. &lt;/p&gt;
&lt;p&gt;The system is now infected with a &lt;a class="" href="http://www.ca.com/securityadvisor/virusinfo/virus.aspx?id=53476" target="_blank"&gt;Bancos&lt;/a&gt; Trojan which can steal sensitive information relating to the users banking habits.&lt;/p&gt;
&lt;p&gt;Here we can see the download agents (Win32/Bancos.ORU and Win32/Bancos.ORV) contacting the compromised web server in order to download the Bancos Trojan onto the users system. &lt;/p&gt;
&lt;p&gt;
&lt;div id="ms__id199" align="center"&gt;&lt;a class="" href="http://community.ca.com/blogs/securityadvisor/Aaron/Malware_finds_refuge_TcpStream.gif" target="_blank"&gt;&lt;img title="Bancos TcpStream" style="WIDTH:560px;HEIGHT:353px;" height="353" alt="Bancos TcpStream" src="http://community.ca.com/blogs/securityadvisor/Aaron/Malware_finds_refuge_TcpStream.gif" width="560" align="middle" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;blockquote&gt;
&lt;blockquote&gt;
&lt;blockquote&gt;
&lt;div id="ms__id128" align="center"&gt;[Figure 4 – Contacting the web server and downloading files]&lt;/div&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;
&lt;p&gt;We can see from Figure 4 that an executable (sidebr.exe) and an image file (c1.bmp) are downloaded to the infected user’s machine. Many more files are downloaded to create the Bancos Trojan application. A few of these files can be seen in Figure 2. &lt;/p&gt;
&lt;p&gt;CA currently detects the downloaded Bancos Trojan as Win32/Bancos.ONW. &lt;/p&gt;
&lt;p&gt;CA also recommends keeping your security software up to date in an attempt to avoid this infection of Bancos Malware taking place on your system. &lt;/p&gt;
&lt;p&gt;We have also notified the administrator of the compromised web server regarding this issue. &lt;/p&gt;
&lt;p&gt;Please read our blog on &lt;a class="" href="http://community.ca.com/blogs/securityadvisor/archive/2009/04/22/banking-trojans-tips-and-tricks.aspx" target="_blank"&gt;Banking Trojans - Tips and Tricks&lt;/a&gt; for more information on the Bancos Trojan. &lt;/p&gt;
&lt;div&gt;&lt;/div&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Malware+finds+refuge+in+school" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/securityadvisor/archive/2009/06/29/malware-finds-refuge-in-school.aspx&amp;subject=Malware+finds+refuge+in+school"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/securityadvisor/archive/2009/06/29/malware-finds-refuge-in-school.aspx&amp;title=Malware+finds+refuge+in+school" title="Submit Malware+finds+refuge+in+school to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/securityadvisor/archive/2009/06/29/malware-finds-refuge-in-school.aspx&amp;phase=2" title="Submit Malware+finds+refuge+in+school to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/securityadvisor/archive/2009/06/29/malware-finds-refuge-in-school.aspx&amp;title=Malware+finds+refuge+in+school" title="Submit Malware+finds+refuge+in+school to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2601" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/Aaron+Faloon/default.aspx">Aaron Faloon</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/Anatomy+of+Attack/default.aspx">Anatomy of Attack</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/CA/default.aspx">CA</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/CA+Anti-Spam/default.aspx">CA Anti-Spam</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/CA+Anti-Virus/default.aspx">CA Anti-Virus</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/compromised+web+server/default.aspx">compromised web server</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/downloaders/default.aspx">downloaders</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/fake/default.aspx">fake</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/fake+login/default.aspx">fake login</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/infection/default.aspx">infection</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/malicious/default.aspx">malicious</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/malware/default.aspx">malware</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/security/default.aspx">security</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/trojan+downloaders/default.aspx">trojan downloaders</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/trojans/default.aspx">trojans</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/Win32_2F00_Bancos/default.aspx">Win32/Bancos</category></item><item><title>What Makes You Think You Are An ITIL V3 Shop?</title><link>http://community.ca.com/blogs/itil/archive/2009/06/27/what-makes-you-think-you-are-an-itil-v3-shop.aspx</link><pubDate>Sat, 27 Jun 2009 09:23:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2595</guid><dc:creator>Peter Doherty</dc:creator><slash:comments>6</slash:comments><description>&lt;p&gt;At &lt;a class="" href="http://www.ca.com/au/content/campaign.aspx?cid=193384" target="_blank"&gt;CA Expo&lt;/a&gt; here in Oz I asked the 200 people in my session who thought they were an ITIL V3 shop and probably 20 or so hands went up sheepishly. Maybe the reason for this is that they have seen what happens to people who put their hands up in response to my questions or maybe they were unsure.&lt;/p&gt;
&lt;p&gt;Word out of the latest Gartner conference is that lots of IT organisations are adopting V3.&amp;nbsp; Now for the record, I think they should. But just because I think they should does not mean that they are. So here in Oz, which is a very mature Service Management market, I get mixed feedback about the adoption of V3. When I asked the same question in the Sydney Expo I told some of the people to put their hands down (see what I meant about putting your hand up in my sessions!). So why did I ask them to put their hands down? For&amp;nbsp;the same reason that I do not think there is the ITIL V3 uptake that the analysts are quoting. &lt;/p&gt;
&lt;p&gt;And that reason is that if you are just doing Incident, Problem, Change, don’t kid yourself that you are a V3 shop. It is really good that you are doing those things, don’t get me wrong. It is just that IT is so bad at managing expectations and here is another example:&lt;/p&gt;
&lt;p&gt;You need to be doing more than the old Service Support processes.&lt;/p&gt;
&lt;p&gt;So are the analysts wrong? And if so where are they getting the data? Or are they asking the wrong questions? I think it is a combination of things. I twitter on Service Management (@&lt;a class="" href="http://www.twitter.com/ITILNinja" target="_blank"&gt;ITILNinja&lt;/a&gt;)&amp;nbsp;and David Ratcliff of Pink Elephant (&lt;a class="" href="http://www.twitter.com/pinkerdavid" target="_blank"&gt;@pinkerdavid&lt;/a&gt;)&amp;nbsp;asked the question about why are we twittering on advanced topics when most people are still crawling? And he is so right. &lt;br /&gt;&lt;br /&gt;There are so many shops out there still implementing the SS processes and here I am talking about Service Portfolio Management. If you are struggling with Incident and Change, SPM is fantasyland. But I want people to start thinking about how good fantasyland could be!&lt;/p&gt;
&lt;p&gt;And this is how I think you can define yourself as an ITIL V3 shop – you have started to think and plan to eventually get to Peter’s fantasyland and it is a good place!&lt;br /&gt;&amp;nbsp; &lt;br /&gt;You are an ITIL V3 shop if you have started to embrace some of the new processes and are talking about a Service Lifecycle. Sorry, not just talking about it but it is starting to become part of the culture. When you start appointing Service owners and Business Relationship Managers that actually talk to the business, not just other parts of IT. &lt;/p&gt;
&lt;p&gt;So if an analyst asks you whether you are a V3 shop or not, forget about the pressure for you to say yes and ask yourself how you stack up against some of my basic criteria and also ask yourself whether your CIO talks about this as well. &lt;/p&gt;
&lt;p&gt;As I always like to do – if you think you are a V3 shop, leave a comment and tell me why.&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email What+Makes+You+Think+You+Are+An+ITIL+V3+Shop%3f" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/itil/archive/2009/06/27/what-makes-you-think-you-are-an-itil-v3-shop.aspx&amp;subject=What+Makes+You+Think+You+Are+An+ITIL+V3+Shop%3f"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/itil/archive/2009/06/27/what-makes-you-think-you-are-an-itil-v3-shop.aspx&amp;title=What+Makes+You+Think+You+Are+An+ITIL+V3+Shop%3f" title="Submit What+Makes+You+Think+You+Are+An+ITIL+V3+Shop%3f to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/itil/archive/2009/06/27/what-makes-you-think-you-are-an-itil-v3-shop.aspx&amp;phase=2" title="Submit What+Makes+You+Think+You+Are+An+ITIL+V3+Shop%3f to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/itil/archive/2009/06/27/what-makes-you-think-you-are-an-itil-v3-shop.aspx&amp;title=What+Makes+You+Think+You+Are+An+ITIL+V3+Shop%3f" title="Submit What+Makes+You+Think+You+Are+An+ITIL+V3+Shop%3f to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2595" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/itil/archive/tags/ITIL+V3/default.aspx">ITIL V3</category><category domain="http://community.ca.com/blogs/itil/archive/tags/Service+Lifecycle/default.aspx">Service Lifecycle</category><category domain="http://community.ca.com/blogs/itil/archive/tags/service+portfolio+management/default.aspx">service portfolio management</category><category domain="http://community.ca.com/blogs/itil/archive/tags/SPM/default.aspx">SPM</category></item><item><title>IT Uncommon: The Ties that Bind</title><link>http://community.ca.com/blogs/itil/archive/2009/06/26/it-uncommon-the-ties-that-bind.aspx</link><pubDate>Fri, 26 Jun 2009 17:18:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2594</guid><dc:creator>Jeff Foucher</dc:creator><slash:comments>2</slash:comments><description>&lt;p&gt;&lt;a href="http://community.ca.com/blogs/itil/Knot.jpg"&gt;&lt;img style="WIDTH:211px;HEIGHT:232px;" height="732" hspace="10" src="http://community.ca.com/blogs/itil/Knot.jpg" width="221" align="right" border="1" alt="" /&gt;&lt;/a&gt;I&amp;#39;m pretty amazed at the seemingly endless discussion and un-evolved thinking around &amp;quot;aligning&amp;nbsp;IT with the business.&amp;quot;&amp;nbsp;Various machinations have surfaced (&amp;quot;it&amp;#39;s about IT being part of the business&amp;quot; or &amp;quot;it&amp;#39;s about aligning IT and business&amp;quot;) and at least a dozen vendor-driven acronyms have emerged all purporting to put IT &amp;amp; business on the same page.&amp;nbsp;However, I&amp;#39;ve yet to see a more detailed, behavioral analysis applied to better understanding the underlying human factors which still make this a relevant discourse and one that still appears to keep executives up at night.&lt;/p&gt;
&lt;p&gt;As an IT outsider, it seems that this is no different than any other inter-departmental cultural divide hindered by a general misunderstanding of what one party perceives to be of value, exacerbated by disparate metrics and measures, and undermined by intra-departmental silos of dysfunction.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;u&gt;Finding Common Ground&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;As with any cultural divide, there are fundamental steps which can be taken to ensure that both parties find mutual benefit and success.&amp;nbsp;And of course, technology can help play a part.&amp;nbsp;Hence, a&amp;nbsp;four part plan for IT:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; &lt;b&gt;Common Goals:&lt;/b&gt; As with any business, &lt;a href="http://www.ca.com/files/WhitePapers/case-for-leanit-wp_204130.pdf"&gt;this is all about IT getting lean&lt;/a&gt; and orienting itself around a value/cost/risk axis. Starting with a firm (documented) understanding of business goals and priorities, IT then can establish a customer-centric beacon upon which all activities are then managed, executed and measured. If it&amp;#39;s not on the business agenda, it should never get onto the IT agenda.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. Common Language&lt;/strong&gt;: In most areas of business, and certainly all areas of the public domain (government, education, healthcare), the value orientation is predicated upon the services being delivered to customers. Even manufacturing ‘output&amp;#39; can be considered a service since without the underlying orchestration of the supply chain, nothing would ever be built. Likewise, &lt;a href="http://www.ca.com/files/WhitePapers/metrics-that-matter-us-en.pdf"&gt;IT should start with the ‘language of business&amp;#39;&lt;/a&gt;&amp;nbsp;and ground itself in the management of its own IT service portfolio. This requires a full understanding of IT cost, quality &amp;amp; function packaged in terms of the services being delivered or supported. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3. Common Currency&lt;/strong&gt;: While business is based upon a service orientation, the way the business operates is actually quite different. Accounting principles require a more detailed view beyond just the ‘cost of the service&amp;#39; - for purposes of depreciation, tax, operating margins and capital expense. A service oriented view of IT &amp;quot;cost&amp;quot; is absolutely needed to establish a common language with the business around value, but the currency of business is more rigorous and requires cost accounting principles applied to asset expenses, labor expenses, application costs, license costs, maintenance on hardware, communications, infrastructure. Similarly, &lt;a href="http://www.ca.com/files/IndustryAnalystReports/market_overview_it_financial_207750.pdf"&gt;IT Financial Management&lt;/a&gt; must be able to plan, actualize and optimize its expense base against these same principles and detail&amp;nbsp;-- whether they are IT assets or projects or telecom expenses or software contracts.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4. Common Knowledge&lt;/strong&gt;: Underpinning all of this is the ability for organizations to create a shared sense of purpose, allowing them to galvanize against common goals with a unified language and currency system. In IT, this is essential to breaking down the long-standing silos of disconnect which have undermined IT for years. &lt;a href="http://www.ca.com/files/WhitePapers/essential-itil-what-you-need-to-succeed.pdf"&gt;ITIL plays an essential role here&lt;/a&gt;, by focusing on processes, which quickly afford one function to realize their own role in the context of the broader organization. &lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;&lt;b&gt;&lt;u&gt;Building A Common Culture&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;In the end, business may or may not care to engage fruitfully in an ‘alignment&amp;#39; discussion with IT.&amp;nbsp;But they are forever connected to IT as their lifeline to innovation and competitive advantage.&amp;nbsp;But by establishing a common framework for success based on shared goals, a language everyone understands, a single currency system and a shared knowledge base, IT leaders can indeed become business leaders and along the way, improve the way the business itself operates by embracing and driving toward a common culture of success.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;i&gt;How has Technology helped you bridge the divide?&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email IT+Uncommon%3a+The+Ties+that+Bind" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/itil/archive/2009/06/26/it-uncommon-the-ties-that-bind.aspx&amp;subject=IT+Uncommon%3a+The+Ties+that+Bind"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/itil/archive/2009/06/26/it-uncommon-the-ties-that-bind.aspx&amp;title=IT+Uncommon%3a+The+Ties+that+Bind" title="Submit IT+Uncommon%3a+The+Ties+that+Bind to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/itil/archive/2009/06/26/it-uncommon-the-ties-that-bind.aspx&amp;phase=2" title="Submit IT+Uncommon%3a+The+Ties+that+Bind to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/itil/archive/2009/06/26/it-uncommon-the-ties-that-bind.aspx&amp;title=IT+Uncommon%3a+The+Ties+that+Bind" title="Submit IT+Uncommon%3a+The+Ties+that+Bind to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2594" width="1" height="1"&gt;</description></item><item><title>“Amp up the ‘folio”: Reasons for Tuning a Project Portfolio </title><link>http://community.ca.com/blogs/ppm/archive/2009/06/25/amp-up-the-folio-reasons-for-tuning-a-project-portfolio.aspx</link><pubDate>Thu, 25 Jun 2009 12:54:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2590</guid><dc:creator>Pradeep Bhanot</dc:creator><slash:comments>0</slash:comments><description>&lt;p class="MsoNormal" style="MARGIN:0in 0in 10pt;"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Creating a perfect portfolio may be a dream, but striving for one should not be. Lean thinking encourages incremental measures that focus on the customer, improve processes, amplifying good projects and eliminating waste by switching off or deferring non-strategic ones. &lt;/p&gt;
&lt;p&gt;What makes one portfolio better than another? One popular view would be of a portfolio that manages to balance risk with return is perfect. A conservative company in a highly regulated market with minimal competition may be happy with a high percentage of its projects focused on customer retention and maintenance of existing services. &amp;nbsp;This approach would protect top line revenue while trimming the bottom line by increasing efficiencies. &lt;/p&gt;
&lt;p&gt;For an aggressive business that is in a growth market with a high tolerance for risk may consider an optimal portfolio to be one that supports a handful of ambitious &amp;quot;game changing&amp;quot; initiatives while mitigating essential regulatory exposures. A secondary focus on maintenance and customer retention may be tolerated if there is high demand from an emerging market. This might be the case for a vendor of GPS devices where the vast majority of the revenue from new customers. &amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Another definition of an optimum portfolio is one that is well aligned to the company&amp;#39;s strategy and business climate. The current economic reality is favoring measures that cut or contain costs, a scale back on large cost intensive projects and a focus on projects that offer fast payback to sustain the company through the recession. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;In the absence of facts and metrics around business alignment, cost, value and risk factors, balancing a real portfolio becomes an art. PPM solutions provide some clarity by providing a decision making framework for making informed portfolio decisions, which makes the process less subjective and more of a science.&amp;nbsp; When facing a cost cutting requirement from executive management, being able to quickly identify candidate projects based on cost, value or strategic fit can be pretty handy. &lt;/p&gt;
&lt;p&gt;A project portfolio can be a pretty dynamic thing. Tuning the portfolio is an exercise that needs to be done at on ongoing manner to keep pace with changes in the market and business climate. &lt;/p&gt;
&lt;p&gt;&lt;a href="http://community.ca.com/blogs/ppm/CJ.JPG"&gt;&lt;img style="WIDTH:348px;HEIGHT:157px;" height="242" src="http://community.ca.com/blogs/ppm/CJ.JPG" width="348" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://community.ca.com/blogs/ppm/CJA10L.JPG"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email %e2%80%9cAmp+up+the+%e2%80%98folio%e2%80%9d%3a+Reasons+for+Tuning+a+Project+Portfolio+" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/ppm/archive/2009/06/25/amp-up-the-folio-reasons-for-tuning-a-project-portfolio.aspx&amp;subject=%e2%80%9cAmp+up+the+%e2%80%98folio%e2%80%9d%3a+Reasons+for+Tuning+a+Project+Portfolio+"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/ppm/archive/2009/06/25/amp-up-the-folio-reasons-for-tuning-a-project-portfolio.aspx&amp;title=%e2%80%9cAmp+up+the+%e2%80%98folio%e2%80%9d%3a+Reasons+for+Tuning+a+Project+Portfolio+" title="Submit %e2%80%9cAmp+up+the+%e2%80%98folio%e2%80%9d%3a+Reasons+for+Tuning+a+Project+Portfolio+ to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/ppm/archive/2009/06/25/amp-up-the-folio-reasons-for-tuning-a-project-portfolio.aspx&amp;phase=2" title="Submit %e2%80%9cAmp+up+the+%e2%80%98folio%e2%80%9d%3a+Reasons+for+Tuning+a+Project+Portfolio+ to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/ppm/archive/2009/06/25/amp-up-the-folio-reasons-for-tuning-a-project-portfolio.aspx&amp;title=%e2%80%9cAmp+up+the+%e2%80%98folio%e2%80%9d%3a+Reasons+for+Tuning+a+Project+Portfolio+" title="Submit %e2%80%9cAmp+up+the+%e2%80%98folio%e2%80%9d%3a+Reasons+for+Tuning+a+Project+Portfolio+ to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2590" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/ppm/archive/tags/ppm+lean+portfolio/default.aspx">ppm lean portfolio</category></item><item><title>World Economic Crisis and Service Management </title><link>http://community.ca.com/blogs/itil/archive/2009/06/24/world-economic-crisis-and-service-management.aspx</link><pubDate>Wed, 24 Jun 2009 20:30:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2588</guid><dc:creator>Robert Stroud</dc:creator><slash:comments>1</slash:comments><description>&lt;p&gt;This week I was in Korea for the joint Korean itSMF and ISACA conference. Understanding the issues surrounding the business climate and the demands on their members&amp;#39; time and finances, these two organizations worked together for a single event instead of their usual independent events.&amp;nbsp;The event was a huge success based on the attendance, attendee comments, press comments and the smiles on the organizers&amp;#39; faces.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;I spoke about Governance for your ITSM environment--more on that next week--and I wanted to share with you my prepared comments to the excellent questions raised by the facilitator of the closing panel session.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Questions:&lt;/b&gt; As you may know, we are facing a world economic crisis and many leading firms demand to sustain their businesses. What&amp;#39;s your perspective on the role of ITSM and IT governance to sustain our business (in terms of efficiency) in this crisis? What can you suggest based on your global experiences, providing recent case examples? Will ITIL-based ITSM solutions or VAL IT enable us to sustain our businesses during this particular period? &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;At the moment, the global focus is clearly on cost reduction. Unfortunately much of this is based on simply cutting people, deferring investments, wholesale removal of a service or introduction of service delays.&amp;nbsp;Instead, focus needs to be on real immediate savings and this needs to be linked to business demands.&amp;nbsp; &lt;/li&gt;
&lt;li&gt;Frameworks, including ITIL or COBIT, give us the opportunity to deliver efficiencies but only where they are delivered through automation of process with a focus on the reduction in complexity - these must be linked to the demand side and the organization&amp;#39;s strategy. &lt;/li&gt;
&lt;li&gt;We must balance supply and demand.&amp;nbsp; &lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;One of the real opportunities here is to expose the business to the operational services that are being delivered and the costs associated with their delivery, proactively providing information on how to reduce these costs.&amp;nbsp; &lt;/li&gt;
&lt;li&gt;&amp;nbsp;The Service Catalog is an good example of this - where the business consumes services expressed in business terms with business based service levels. IT has to opportunity to associate costs with the various service levels.&amp;nbsp; &lt;/li&gt;
&lt;li&gt;These services must be reviewed on a regular basis with efficiencies reviewed with the business - not just evaluated by IT. &lt;/li&gt;&lt;/ul&gt;
&lt;li&gt;One example of this is a power company in the U.S. that is using COBIT for Governance and setting controls for risks and exposures. It also is linking IT strategy to the business strategy.&amp;nbsp; This organization uses ITIL for Service Management, uses PMBOK for project management and currently is implementing the Investment Management domain within VALIT.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;The company has implemented a Service Catalog that defines business services. It has implemented self help for issue resolution, and the service catalog allows users to consume services acknowledging cost and all investments are linked to business strategy. &lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;This organization has been dictated a 10% overall cost reduction &lt;/li&gt;
&lt;li&gt;Immediately the investments could be prioritized for relevance to the new strategy of cost reduction. Projects were all reviewed and by slowing down several and completely removing two, a 15% saving was made.&lt;/li&gt;
&lt;li&gt;Operations wrote to all users of services that leveraged consumption-based third parties and advised them of the opportunity to cut costs.&lt;/li&gt;
&lt;li&gt;IT identified that by accelerating the VOIP initiative they could save 3% from the total IT budget in the first partial year of operation after all costs. Because of the near-term cost-savings, this project was accelerated.&lt;/li&gt;
&lt;li&gt;Self-service Catalog automation increased and provided another 2% saving.&lt;/li&gt;
&lt;li&gt;Overall the 11% of real savings were delivered.&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;
&lt;p&gt;What do you think?&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email World+Economic+Crisis+and+Service+Management+" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/itil/archive/2009/06/24/world-economic-crisis-and-service-management.aspx&amp;subject=World+Economic+Crisis+and+Service+Management+"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/itil/archive/2009/06/24/world-economic-crisis-and-service-management.aspx&amp;title=World+Economic+Crisis+and+Service+Management+" title="Submit World+Economic+Crisis+and+Service+Management+ to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/itil/archive/2009/06/24/world-economic-crisis-and-service-management.aspx&amp;phase=2" title="Submit World+Economic+Crisis+and+Service+Management+ to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/itil/archive/2009/06/24/world-economic-crisis-and-service-management.aspx&amp;title=World+Economic+Crisis+and+Service+Management+" title="Submit World+Economic+Crisis+and+Service+Management+ to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2588" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/itil/archive/tags/COBIT/default.aspx">COBIT</category><category domain="http://community.ca.com/blogs/itil/archive/tags/Governance/default.aspx">Governance</category><category domain="http://community.ca.com/blogs/itil/archive/tags/ISACA/default.aspx">ISACA</category><category domain="http://community.ca.com/blogs/itil/archive/tags/IT+Governance/default.aspx">IT Governance</category><category domain="http://community.ca.com/blogs/itil/archive/tags/ITSM/default.aspx">ITSM</category><category domain="http://community.ca.com/blogs/itil/archive/tags/itSMF/default.aspx">itSMF</category><category domain="http://community.ca.com/blogs/itil/archive/tags/Service+Catalog/default.aspx">Service Catalog</category><category domain="http://community.ca.com/blogs/itil/archive/tags/world+economic+crisis/default.aspx">world economic crisis</category></item><item><title>Verified Identity Pass Goes Kaput - Where is the Data Now?</title><link>http://community.ca.com/blogs/iam/archive/2009/06/24/verified-identity-pass-goes-kaput-where-is-the-data-now.aspx</link><pubDate>Wed, 24 Jun 2009 16:15:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2587</guid><dc:creator>Merritt Maxim</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;On Monday, Verified Identity Pass &lt;a class="" href="http://news.cnet.com/8301-13505_3-10270837-16.html" target="_blank"&gt;announced&lt;/a&gt; that it will cease operation of its Clear program at 18 airports throughout the U.S.&amp;nbsp; To the estimated 250,000 frequent fliers who had signed up for Clear Pass program and shelled out $200 annually for the privilege, this news was sudden and unexpected.&amp;nbsp;&amp;nbsp; &lt;/p&gt;
&lt;p&gt;The Clear program was one of three registered traveler programs that enabled travelers to obtain priority at airport security.&amp;nbsp; In light of the extra waits often encountered at airport security following the new post-9/11 rules, these registered programs seemed attractive.&amp;nbsp; With Verified Identity Pass&amp;#39; announcement, the viability of such services is now in doubt.&lt;/p&gt;
&lt;p&gt;The initial &lt;a class="" href="http://www.usatoday.com/travel/news/2009-06-23-registered-flights-travel_N.htm?obref=obinsite" target="_blank"&gt;news&lt;/a&gt; on getting refunds back is not promising.&amp;nbsp; Disregarding the financial impact of not getting a refund, there is a much more important identity question to ask, &amp;quot;What happens to the biometric data of the registered travelers?&amp;quot;&lt;/p&gt;
&lt;p&gt;Biometrics are the one credential that cannot be revoked.&amp;nbsp; Passwords can be changed, users can be removed from directories, smart cards can be locked, and certificates can expire, but your fingers, eyes and face are with you.&amp;nbsp; And while most biometric systems only store a digital interpretation of this data, the point is that Clear possesses some unique data about 250,000 people and the future of that data is in some doubt.&amp;nbsp; The FlyClear &lt;a class="" href="http://www.flyclear.com/" target="_blank"&gt;website&lt;/a&gt; has this short statement &lt;/p&gt;
&lt;p&gt;&amp;quot;Applicant and Member data is currently secured in accordance with the Transportation Security Administration&amp;#39;s Security, Privacy and Compliance Standards. Verified Identity Pass, Inc.&amp;nbsp; will continue to secure such information and will take appropriate steps to delete the information.&amp;quot;&lt;/p&gt;
&lt;p&gt;On the surface, this sounds good, but given that the company is having financial difficulties, what assurances do we have that their systems are safe from attack and that personal data will not be compromised now? If the data is going to be deleted, what assurances are there that the data will be destroyed completely?&lt;/p&gt;
&lt;p&gt;I don&amp;#39;t mean to be an alarmist and all data may be handled correctly, but this business failure raises some important policy questions about ownership and protection of personal biometric data by third parties.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;This will be an interesting case to monitor going forward.&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Verified+Identity+Pass+Goes+Kaput+-+Where+is+the+Data+Now%3f" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/iam/archive/2009/06/24/verified-identity-pass-goes-kaput-where-is-the-data-now.aspx&amp;subject=Verified+Identity+Pass+Goes+Kaput+-+Where+is+the+Data+Now%3f"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/iam/archive/2009/06/24/verified-identity-pass-goes-kaput-where-is-the-data-now.aspx&amp;title=Verified+Identity+Pass+Goes+Kaput+-+Where+is+the+Data+Now%3f" title="Submit Verified+Identity+Pass+Goes+Kaput+-+Where+is+the+Data+Now%3f to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/iam/archive/2009/06/24/verified-identity-pass-goes-kaput-where-is-the-data-now.aspx&amp;phase=2" title="Submit Verified+Identity+Pass+Goes+Kaput+-+Where+is+the+Data+Now%3f to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/iam/archive/2009/06/24/verified-identity-pass-goes-kaput-where-is-the-data-now.aspx&amp;title=Verified+Identity+Pass+Goes+Kaput+-+Where+is+the+Data+Now%3f" title="Submit Verified+Identity+Pass+Goes+Kaput+-+Where+is+the+Data+Now%3f to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2587" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/iam/archive/tags/biometrics/default.aspx">biometrics</category><category domain="http://community.ca.com/blogs/iam/archive/tags/data+loss+prevention/default.aspx">data loss prevention</category><category domain="http://community.ca.com/blogs/iam/archive/tags/DLP/default.aspx">DLP</category><category domain="http://community.ca.com/blogs/iam/archive/tags/FlyClear/default.aspx">FlyClear</category><category domain="http://community.ca.com/blogs/iam/archive/tags/IAM+Trends/default.aspx">IAM Trends</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Identity+Management/default.aspx">Identity Management</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Privacy/default.aspx">Privacy</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Security/default.aspx">Security</category><category domain="http://community.ca.com/blogs/iam/archive/tags/TSA/default.aspx">TSA</category></item><item><title>Security Management in a Hybrid Application Deployment World</title><link>http://community.ca.com/blogs/iam/archive/2009/06/23/security-management-in-a-hybrid-application-deployment-world.aspx</link><pubDate>Tue, 23 Jun 2009 19:20:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2584</guid><dc:creator>Matthew Gardiner</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;A recent Wall Street Journal &lt;a class="" href="http://online.wsj.com/article/SB124562830113035785.html" target="_blank"&gt;article&lt;/a&gt; discussed the challenges and opportunities around the emerging business model of software vendors offering both &amp;quot;online applications&amp;quot; (SaaS) in addition to the traditional mode of providing software as on-premise applications.&amp;nbsp; I am not going to wade into the merits of one approach of the other here, other than to say that some applications are well-suited to SaaS and will be provided as a service - many already are.&amp;nbsp; The question I want to ask and partially answer is, where does this leave enterprises with security management?&amp;nbsp; The fact that applications and their associated data are outsourced certainly doesn&amp;#39;t mean that organizations also can outsource ultimate responsibility for the security of these applications.&amp;nbsp; Who do you think will get blamed if there is a data leak? &lt;/p&gt;
&lt;p&gt;If IT security organizations think that they have a heterogeneous IT security management challenge now, just wait until more of their applications are provided via SaaS - and thus delivered via the Internet and hosted who knows where.&amp;nbsp; What enterprises are going to need is an approach to security management that automates the management of security without regard to whether the applications are deployed via the traditional on-premise mode or via the SaaS mode (what I call the hybrid application deployment world).&amp;nbsp; In addition they will need an approach to security management which is nearly instantly re-configurable so that what is outsourced one-day can be in-sourced the next, and vice versa.&amp;nbsp; While there is no perfect solution yet to this hybrid security management challenge, many of the problems are well understood and at least partially solved in the world of identity and access management, Web access management, federation, and Web services security as well as through the use of associated standards such as SAML , XACML, and SPML.&amp;nbsp; Vendors, like CA, have been providing solutions to the management challenges of cross-domain, Web security management for many years now.&amp;nbsp; It is only natural that CA, and vendors like us, will do so for this hybrid application deployment world as well.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;One certainty is that the Web security industry needs to work together at many levels such as technology to policy, interoperability to privacy, and other areas to make this all work from a security management point of view.&amp;nbsp; And that is exactly what we are doing.&amp;nbsp; For two very timely proof points, take a &lt;a class="" href="http://www.burtongroup.com/AboutUs/newsdetail.aspx?id=27" target="_blank"&gt;look at the SaaS interoperability demonstration&lt;/a&gt; that is on tap at July&amp;#39;s &lt;a class="" href="http://www.catalyst.burtongroup.com/NA09/" target="_blank"&gt;Burton Catalyst Conference&lt;/a&gt;.&amp;nbsp; For another proof point on how the industry is working together to make security work in this model, take a look at the newly launched industry consortium, the &lt;a class="" href="http://kantarainitiative.org/" target="_blank"&gt;Kantara Initiative&lt;/a&gt;.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;While the particular business viability of one application deployment mode over another is still pretty foggy right now, it isn&amp;#39;t foggy that security will need to be managed in a hybrid mode for as far as one can see ... and solutions to this problem have and will primarily come out of the Web security management software world.&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Security+Management+in+a+Hybrid+Application+Deployment+World" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/iam/archive/2009/06/23/security-management-in-a-hybrid-application-deployment-world.aspx&amp;subject=Security+Management+in+a+Hybrid+Application+Deployment+World"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/iam/archive/2009/06/23/security-management-in-a-hybrid-application-deployment-world.aspx&amp;title=Security+Management+in+a+Hybrid+Application+Deployment+World" title="Submit Security+Management+in+a+Hybrid+Application+Deployment+World to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/iam/archive/2009/06/23/security-management-in-a-hybrid-application-deployment-world.aspx&amp;phase=2" title="Submit Security+Management+in+a+Hybrid+Application+Deployment+World to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/iam/archive/2009/06/23/security-management-in-a-hybrid-application-deployment-world.aspx&amp;title=Security+Management+in+a+Hybrid+Application+Deployment+World" title="Submit Security+Management+in+a+Hybrid+Application+Deployment+World to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2584" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/iam/archive/tags/IAM+Trends/default.aspx">IAM Trends</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Identity+Management/default.aspx">Identity Management</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Kantara+Initiative/default.aspx">Kantara Initiative</category><category domain="http://community.ca.com/blogs/iam/archive/tags/SaaS+Security/default.aspx">SaaS Security</category><category domain="http://community.ca.com/blogs/iam/archive/tags/SAML/default.aspx">SAML</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Secure+Web+Business/default.aspx">Secure Web Business</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Security/default.aspx">Security</category><category domain="http://community.ca.com/blogs/iam/archive/tags/SOA+Security/default.aspx">SOA Security</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Web+Access+Management/default.aspx">Web Access Management</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Web+Services+Security/default.aspx">Web Services Security</category></item><item><title>The Challenges of CMDB Federation without a Standard</title><link>http://community.ca.com/blogs/itil/archive/2009/06/23/the-challenges-of-cmdb-federation-without-a-standard.aspx</link><pubDate>Tue, 23 Jun 2009 15:50:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2582</guid><dc:creator>Marvin Waschke</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;There are many difficulties involved in CMDB federation that the CMDBf specification helps address. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;When you set out to integrate a CMDB product with another data source, such as another CMDB or a specialized device monitor, there are several steps that you must take and with each step there are choices to make. &lt;/p&gt;
&lt;p&gt;Perhaps the most important architectural choice is the level on which to federate. You can choose to federate on a database to database level. That involves a detailed knowledge of the schema of both the target and the source system, and the federation is likely to break if the schema of either system changes. Because the schema is intimately tied to the internal operation of the applications, schema changes occur frequently when either the data source or target changes. Often, schemas are not designed with federation in mind and so data that is not relevant to federation may appear as columns in the same tables as federation data. This can complicate transactions and cause the federation to break when an unrelated feature in the federation source changes. In addition, exchanging schema information can become a thorny intellectual property problem, especially when the source and target are from rival vendors.&lt;/p&gt;
&lt;p&gt;Due to the difficulties of database to database integration, APIs are often used instead. Using this strategy two products communicate by each calling the published APIs instead of reading or updating a database. These APIs are usually designed and published to support integration. Consequently, they do not require intimate knowledge of the products that support them and they tend to change less often than database schemas that often change to support new features and efficiencies. And finally, APIs are better documented than schemas. &lt;/p&gt;
&lt;p&gt;API to API integrations are a distinct improvement, but they still have problems. For example, they still are subject to breaking if either party changes their API with a product change. Sometimes, good engineering rules are followed and the APIs are backward compatible so that existing integrations do not break, but this is not guaranteed. In addition, as new features are incorporated into products, new APIs are often added and integrations must change in order to take advantage of new capabilities. There is often little incentive to vendors to roll new features into existing APIs, which is often much more difficult than inventing a new API. This means that new releases always threaten the federation and adds an element of unreliability. Not only is there danger of&amp;nbsp; downtime and recoding costs, remediation for the unreliability also incurs more cost in the form of extended testing and more elaborate transition plans with new releases.&lt;/p&gt;
&lt;p&gt;Most seriously, the APIs for every MDR and federating CMDB are all different. That means each integration project has to be designed and engineered individually. Not only is development of this form of federation expensive, each integration must be supported individually by engineers specially trained on the specific federation, which eliminates economies of scale in support. &lt;/p&gt;
&lt;p&gt;In a word, API to API federation is expensive to the supplier of the federation and inconvenient to the user of the federation.&lt;/p&gt;
&lt;p&gt;The CMDBf is a public specification for API to API integration and addresses two of the substantial problems involved with that type of federation. First, it puts everyone on the same API. Second, by placing changes to the specification in the hands of an organization like the DMTF, the change process is stabilized and the specification undergoes industry-wide scrutiny before it changes. Like code reviews in software development, this scrutiny can eliminate a large share of the problems with federation breakage. &lt;/p&gt;
&lt;p&gt;When the specification becomes widely accepted, basically the same integration can be repeated and supported over and over again. The process of building a federation between an MDR and a CMDB requires a thorough understanding of the APIs of both the MDR and the CMDB.&amp;nbsp; Typically, the developer is only familiar with one of the two and has to fight a learning curve to master the unknown API. Then the federation must be designed, implemented and tested at considerable expense. If standard APIs are used, which apply to both MDRs and federating CMDBs, the expense and risk is not eliminated, but they are both reduced. The learning curve is diminished because the developer is experienced in the standard API, and much of the code will be identical to that used in previous CMDBf-based projects. Although specialized data may be unfamiliar and require some special processing, that is a small part of the entire undertaking. The bulk of the work and risk is eliminated by using the standard interface.&lt;/p&gt;
&lt;p&gt;It is hard to over-estimate the importance of these basic improvements that come from standardization. There are other improvements that can be made to CMDB integration, but they all depend upon a well-defined and standardized API. &lt;/p&gt;
&lt;p&gt;This is not the whole CMDBf story, but it is an important part. I&amp;#39;ll be blogging more on this.&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email The+Challenges+of+CMDB+Federation+without+a+Standard" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/itil/archive/2009/06/23/the-challenges-of-cmdb-federation-without-a-standard.aspx&amp;subject=The+Challenges+of+CMDB+Federation+without+a+Standard"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/itil/archive/2009/06/23/the-challenges-of-cmdb-federation-without-a-standard.aspx&amp;title=The+Challenges+of+CMDB+Federation+without+a+Standard" title="Submit The+Challenges+of+CMDB+Federation+without+a+Standard to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/itil/archive/2009/06/23/the-challenges-of-cmdb-federation-without-a-standard.aspx&amp;phase=2" title="Submit The+Challenges+of+CMDB+Federation+without+a+Standard to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/itil/archive/2009/06/23/the-challenges-of-cmdb-federation-without-a-standard.aspx&amp;title=The+Challenges+of+CMDB+Federation+without+a+Standard" title="Submit The+Challenges+of+CMDB+Federation+without+a+Standard to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2582" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/itil/archive/tags/change+management/default.aspx">change management</category><category domain="http://community.ca.com/blogs/itil/archive/tags/CMDB/default.aspx">CMDB</category><category domain="http://community.ca.com/blogs/itil/archive/tags/CMDB+federation/default.aspx">CMDB federation</category><category domain="http://community.ca.com/blogs/itil/archive/tags/ITIL/default.aspx">ITIL</category><category domain="http://community.ca.com/blogs/itil/archive/tags/ITSM/default.aspx">ITSM</category></item><item><title>Malware using the _OLD_ New Executable file format </title><link>http://community.ca.com/blogs/securityadvisor/archive/2009/06/23/malware-using-the-old-new-executable-file-format.aspx</link><pubDate>Tue, 23 Jun 2009 05:20:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2577</guid><dc:creator>Zarestel Ferrer</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;It is surprising to see 16-bit Windows-based malware now that we have 64-bit technology. &lt;br /&gt;Recently we encountered a malware that uses the 16-bit New Executable file format and we detect it as Win16/Tanglinko.A.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Zarestel/Tanglinko/file_format.gif"&gt;&lt;/a&gt;&amp;nbsp; &lt;a href="http://community.ca.com/blogs/securityadvisor/Zarestel/Tanglinko/file_format.gif"&gt;&lt;img border="0" src="http://community.ca.com/blogs/securityadvisor/Zarestel/Tanglinko/file_format.gif" alt="" /&gt;&lt;/a&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [Figure 1 – IDA Pro Analysis of the file format]&lt;/p&gt;
&lt;p&gt;As you can see in Figure 1, IDA Pro identified the File Format to be “New Executable (NE) Windows”, the Application type as “Console GUI Executable DLL 16 bit” and the file’s Expected Windows Version as “3.0”. Currently the version for new Windows Operating systems such as&amp;nbsp; Windows Vista is 6.0 and Windows 7 is 6.1 so you can see how old the file format is!&lt;/p&gt;
&lt;p&gt;Does this mean the malware is old just because it uses an old file type? Not at all, this is new malware. However, malware authors just can’t leave the past behind and use old tricks when developing new malware. Here is the &lt;a href="http://www.virustotal.com/analisis/6328fe08af5c3c00af0a0fa034b7f97222966df6a9ad53da3eca9a7ed3146c94-1245583336" target="_blank"&gt;Virus Total scan result&lt;/a&gt; of 21st June, 2009. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;a href="http://community.ca.com/blogs/securityadvisor/Zarestel/Tanglinko/icon.gif"&gt;&lt;img border="0" src="http://community.ca.com/blogs/securityadvisor/Zarestel/Tanglinko/icon.gif" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; [Figure 2 – Malware dropping files with directory names]&lt;/p&gt;
&lt;p&gt;Now, what does this malware do? Apart from its file format, nothing fancy really. However, it is just as annoying as any other average malware that we encounter at present. It disables the clipboard, which means a user cannot perform a Copy/Paste operation, and terminates some Windows applications if they have any of the following strings in their Window title.&lt;/p&gt;
&lt;p&gt;•&amp;nbsp;Run&lt;br /&gt;•&amp;nbsp;Search Results&lt;br /&gt;•&amp;nbsp;Select Files and Folders&lt;br /&gt;•&amp;nbsp;System Configuration Utility&lt;br /&gt;•&amp;nbsp;Folder Options&lt;br /&gt;•&amp;nbsp;Display Properties&lt;br /&gt;•&amp;nbsp;Registry Editor&lt;br /&gt;•&amp;nbsp;Command Prompt&lt;br /&gt;•&amp;nbsp;C:\Windows\System32&lt;/p&gt;
&lt;p&gt;In case your system has been infected and you want to manually remove the infection, a simple search, using Process Explorer, for the malware file (usually is SYSTIM32.EXE) can help you identify the malware. Please make sure you terminate the NTVDM.EXE containing SYSTIM32.exe, terminating the wrong process may give you&amp;nbsp;unwanted results. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;a href="http://community.ca.com/blogs/securityadvisor/Zarestel/Tanglinko/Process%20Explorer%20Search.gif"&gt;&lt;img border="0" src="http://community.ca.com/blogs/securityadvisor/Zarestel/Tanglinko/Process%20Explorer%20Search.gif" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [Figure 3 – Malware Search]&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;As you can see it runs under NTVDM.EXE (NT Virtual DOS Machine), which is a Win16 subsystem process under NT-based Windows Operating Systems.&lt;/p&gt;
&lt;p&gt;To be on the safe side always keep your CA security software updated.&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Malware+using+the+_OLD_+New+Executable+file+format+" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/securityadvisor/archive/2009/06/23/malware-using-the-old-new-executable-file-format.aspx&amp;subject=Malware+using+the+_OLD_+New+Executable+file+format+"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/securityadvisor/archive/2009/06/23/malware-using-the-old-new-executable-file-format.aspx&amp;title=Malware+using+the+_OLD_+New+Executable+file+format+" title="Submit Malware+using+the+_OLD_+New+Executable+file+format+ to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/securityadvisor/archive/2009/06/23/malware-using-the-old-new-executable-file-format.aspx&amp;phase=2" title="Submit Malware+using+the+_OLD_+New+Executable+file+format+ to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/securityadvisor/archive/2009/06/23/malware-using-the-old-new-executable-file-format.aspx&amp;title=Malware+using+the+_OLD_+New+Executable+file+format+" title="Submit Malware+using+the+_OLD_+New+Executable+file+format+ to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2577" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/16-bit+malware/default.aspx">16-bit malware</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/NE+file+format/default.aspx">NE file format</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/NTVDM_7B00_dot_7D00_EXE/default.aspx">NTVDM{dot}EXE</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/SYSTIM32_7B00_dot_7D00_EXE/default.aspx">SYSTIM32{dot}EXE</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/Win16/default.aspx">Win16</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/Win16_2F00_Tanglinko.A/default.aspx">Win16/Tanglinko.A</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/WINDOWS_7B00_dot_7D00_EXE/default.aspx">WINDOWS{dot}EXE</category></item><item><title>Recap of Three Interop Panels on Virtualization and Automation</title><link>http://community.ca.com/blogs/automation/archive/2009/06/22/recap-of-three-interop-panels.aspx</link><pubDate>Mon, 22 Jun 2009 12:24:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2573</guid><dc:creator>Stephen Elliot</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;I participated in three panels at the recent Interop in Las Vegas.&amp;nbsp; These were:&lt;/p&gt;
&lt;p&gt;1) The Impact of IT Virtualization on Applications and Networks, moderated by Jim Metzler.&amp;nbsp; Additional executive panelists were from F5 and Cisco.&lt;/p&gt;
&lt;p&gt;2) Technologies that Data Center Managers Can&amp;#39;t Live Without, moderated by Forrester analyst Doug Washburn.&amp;nbsp; Additional executive panelists were from APC/ Schneider Electric and Perot Systems.&lt;/p&gt;
&lt;p&gt;3) Virtualization Management Futures:&amp;nbsp; the Final Frontier?, moderated by Barb Goldworm of Focus.&amp;nbsp; Additional executive panelists were from VMware, Microsoft, and BMC.&lt;/p&gt;
&lt;p&gt;The first two panels had about 80-100 attendees, while the third had about 40 or so who have network related titles at the manager level or above.&amp;nbsp;Following are the key points of interest and discussion from each session.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;The Impact of IT Virtualization on Applications and Networks&lt;/b&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Management is going to be a key requirement for network teams and NOCs to understand. The importance of end-to-end service availability and visibility into both the physical and virtual infrastructures are critical to success in emerging next generation data centers.&lt;/li&gt;
&lt;li&gt;The emergence of automation is a critical requirement, which many IT organizations are adopting, often in incremental steps. &lt;/li&gt;
&lt;li&gt;Virtualization is accelerating the need for automation; existing management processes can be incorporated into ITIL v2 and ITILv3; process standardization is a key requirement for automation.&lt;/li&gt;
&lt;li&gt;&amp;quot;Old school&amp;quot; management technologies will not scale with the pace that virtualization brings to IT organizations in areas such as provisioning. Key management technologies that enable both physical and virtual management scalability include patented root cause analytics, models-based management, and automated thresholding. Scalability of virtualization application infrastructures will become a common theme for IT organizations over next 5-10 years. &lt;/li&gt;
&lt;li&gt;The discussion of the idea of internal private clouds and external public clouds continues to garner IT&amp;#39;s attention; however, management of the cloud continues to require attention to deliver SLA visibility. &lt;/li&gt;
&lt;li&gt;Virtualization is impacting most aspects of IT from application deployment to networking. Many teams are experiencing VM sprawl as VMs propagate the &amp;quot;IT silos&amp;quot;; management is a key requirement for on-going virtualization success. &lt;/li&gt;
&lt;li&gt;End-to-end service availability and granular performance visibility between the application and network flows are increasingly a requirement for problem identification and resolution. &lt;/li&gt;
&lt;li&gt;Element or platform management solutions are a good start, but not enough for IT organizations to provide the required visibility and end-to-end service visibility. &lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;There is no doubt that IT organizations are facing new dynamic requirements that virtualization is forcing onto networks, storage, and server infrastructures. Automation and technologies such as root cause analytics, models-based management, automation, and process encapsulation will be critical to the success, and business alignment of IT in the future.&amp;nbsp;To learn more about how CA is helping clients adjust to these new demands on performance visibility, please go to www.ca.com/virtualization.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Technologies that Data Center Managers Can&amp;#39;t Live Without&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;This panel had several interesting key points of discussion, with audience members a mix of data center facilities management and IT operations.&amp;nbsp; The critical points were: &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Physical data center planning is more important now than ever before; the idea of KW/sq foot is no longer a reliable benchmark metric as hardware density and performance improves. &lt;/li&gt;
&lt;li&gt;The average temperature in the data center will likely continue to go up as hardware resiliency improves.&amp;nbsp; &lt;/li&gt;
&lt;li&gt;It is increasingly critical that power and cooling metrics be imported into management systems to drive improved automated actions. This is important as facilities managers and IT operations teams learn to collaborate over time.&amp;nbsp; &lt;/li&gt;
&lt;li&gt;Automation is increasingly a key part of data center transformations; IT organizations are adopting technologies that utilize automation to increase efficiencies and cost savings opportunities. &lt;/li&gt;
&lt;li&gt;Process standardization, power and cooling, capacity planning, virtualization, enterprise management, automation, and tighter business-to-IT alignment are now requirements for data center transformation projects.&amp;nbsp; &lt;/li&gt;
&lt;li&gt;End-to-end service level management is a key concern for customers, across physical and virtual infrastructures. &amp;nbsp;&amp;nbsp;It requires granular performance metrics across the domains; increasingly the value will come from the analysis of the data. &lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;This panel really took a deep look at how the IT organization and related technologies are changing.&amp;nbsp; While there is a chasm between IT operations and facilities management teams today, the general agreement was that the most effective and efficient organizations will bring these two groups together to drive impactful business decisions.&amp;nbsp; As energy costs continue to be a key concerns for the CIO, collaboration across the data center can drive further cost reductions, and beyond that impact business strategies that drive new lines of business.&amp;nbsp;&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&lt;b&gt;Virtualization Management Futures:&amp;nbsp; the Final Frontier?&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;This session featured a dynamic discussion among panelists from CA, BMC, Microsoft, and VMware.&amp;nbsp; The group addressed may of the leading topics of the day, including automation, partnerships, virtualization, and management.&amp;nbsp; Some of the key points of this discussion included:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Vendors should continue to improve third party integrations; emerging standards will help but are not the &amp;quot;holy grail&amp;quot; of integrated management requirements. &lt;/li&gt;
&lt;li&gt;Virtualization is another architecture that must be managed and will become part of the data center fabric with critical applications residing on it.&amp;nbsp; &lt;/li&gt;
&lt;li&gt;Management and automation are ways that IT organizations can extend the value of virtualization deployments; the consideration of management and automation prior to rollout is delivering improved cost savings and an application service perspective.&lt;/li&gt;
&lt;li&gt;Customers want an integrated view of both their physical and virtual infrastructures to reduce costs and drive more management efficiencies. &lt;/li&gt;
&lt;li&gt;Process standardization is a key requirement for virtualization deployments as ITIL moves towards the broader definition of standards in version 3.&amp;nbsp; &lt;/li&gt;
&lt;li&gt;Virtualization and the idea of a cloud are interconnected; management from the application perspective will be a critical business differentiator and a key consideration for customers as it relates to tiered service level agreements and performance visibility. &lt;/li&gt;
&lt;li&gt;The real focus of management should be the service layer, whereby the consolidation, analysis, and automated actions taken by management solutions deliver insight to the service layer. &lt;/li&gt;
&lt;li&gt;Technology is getting more complex driving up the need for end-to-end service management; virtualization does not solve traditional management challenges, it asks for more focus on management and automation.&amp;nbsp; &lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;The general take away was that management at the element level (i.e. hypervisor platform providers) and the end-to-end service level (i.e., CA solutions) are what customers require to deliver business outcomes.&amp;nbsp; IT is increasingly critical that customers recognize the need for both types of solutions.&amp;nbsp; Integrations betweens the element and service management solutions will be important, with a driving need to have an integrated console /solutions that do both physical and virtual analysis and present the data at the service level.&amp;nbsp; In the future, it won&amp;#39;t matter if the application is on virtual or physical infrastructure; what matters will be how IT and LOB managers manage the infrastructures to optimize their business goals.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Recap+of+Three+Interop+Panels+on+Virtualization+and+Automation" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/automation/archive/2009/06/22/recap-of-three-interop-panels.aspx&amp;subject=Recap+of+Three+Interop+Panels+on+Virtualization+and+Automation"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/automation/archive/2009/06/22/recap-of-three-interop-panels.aspx&amp;title=Recap+of+Three+Interop+Panels+on+Virtualization+and+Automation" title="Submit Recap+of+Three+Interop+Panels+on+Virtualization+and+Automation to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/automation/archive/2009/06/22/recap-of-three-interop-panels.aspx&amp;phase=2" title="Submit Recap+of+Three+Interop+Panels+on+Virtualization+and+Automation to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/automation/archive/2009/06/22/recap-of-three-interop-panels.aspx&amp;title=Recap+of+Three+Interop+Panels+on+Virtualization+and+Automation" title="Submit Recap+of+Three+Interop+Panels+on+Virtualization+and+Automation to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2573" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/automation/archive/tags/Automation/default.aspx">Automation</category><category domain="http://community.ca.com/blogs/automation/archive/tags/Cloud/default.aspx">Cloud</category><category domain="http://community.ca.com/blogs/automation/archive/tags/Data+Center/default.aspx">Data Center</category><category domain="http://community.ca.com/blogs/automation/archive/tags/ITIL/default.aspx">ITIL</category><category domain="http://community.ca.com/blogs/automation/archive/tags/Processes/default.aspx">Processes</category><category domain="http://community.ca.com/blogs/automation/archive/tags/Service+Management/default.aspx">Service Management</category><category domain="http://community.ca.com/blogs/automation/archive/tags/Virtualization/default.aspx">Virtualization</category></item><item><title>IT is not on the Menu</title><link>http://community.ca.com/blogs/itil/archive/2009/06/19/it-is-not-on-the-menu.aspx</link><pubDate>Fri, 19 Jun 2009 17:38:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2568</guid><dc:creator>Eric Feldman</dc:creator><slash:comments>1</slash:comments><description>&lt;p&gt;I know of a company that has a very large user community. Most of the entry pathway to IT was via telephone. While there also were a significant number of email requests for services, their process required a help desk analyst to call the requestor back.&lt;/p&gt;
&lt;p&gt;The company knew that a Service Catalog would enable a massive reduction in the number of phone calls to or from IT. This alone would help them down their path to Lean IT and a reduction in costly manual touch points.&lt;/p&gt;
&lt;p&gt;There was another issue. Besides a minimal amount of IT process automation, the company offers unlimited IT support, for unlimited cost. Support and IT offerings were so widespread, that people were even phoning the help desk to open issues about their personal IPods and cell phones. As a service organization, there was a perception that it was their job to fix anything. Hence, it was often difficult denying these requests for services that would not be supported in most other organizations.&lt;/p&gt;
&lt;p&gt;The IT department realized that offering unlimited support for anything the user wanted was an unsustainable model.&lt;/p&gt;
&lt;p&gt;Yet they had a challenge. How could they reduce the need to provide unlimited support for personal items or systems outside of their domain, without the appearance of saying &amp;quot;no?&amp;quot;&lt;/p&gt;
&lt;p&gt;How many of you find this situation familiar?&lt;/p&gt;
&lt;p&gt;This is where a Service Catalog is of value, by changing perceptions and &amp;quot;reframing the conversation&amp;quot; around what IT does offer, not what it does not.&lt;/p&gt;
&lt;p&gt;There are parallels to this concept found within virtually any other industry. An airline will not fly you to any city. They have routes and schedules -- not that they actually meet those schedules. A movie theatre does not show whatever film you desire at the moment. They have movie times and distribution agreements for only the latest releases. And you cannot go into a restaurant and order anything you like. It must be on the menu.&lt;/p&gt;
&lt;p&gt;When IT or another provider organization within the enterprise, establishes a Service Catalog, they create a publishing vehicle. This enables them to define their offerings in descriptive terms, with associated costs, service levels, deliverables, and metrics for performance. A Service Catalog enables IT to illustrate the value of its offerings. &lt;/p&gt;
&lt;p&gt;And by listing only what services are offered from IT, you can naturally provide a reduction in non-supported service requests, without the need to say &amp;quot;no.&amp;quot; How?&lt;/p&gt;
&lt;p&gt;Think about the next time you go out to eat. You do not go to a pizzeria and order Chinese food. You do not typically enter a seafood restaurant and order a cheeseburger. Why not? &lt;/p&gt;
&lt;p&gt;It is not on the menu.&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email IT+is+not+on+the+Menu" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/itil/archive/2009/06/19/it-is-not-on-the-menu.aspx&amp;subject=IT+is+not+on+the+Menu"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/itil/archive/2009/06/19/it-is-not-on-the-menu.aspx&amp;title=IT+is+not+on+the+Menu" title="Submit IT+is+not+on+the+Menu to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/itil/archive/2009/06/19/it-is-not-on-the-menu.aspx&amp;phase=2" title="Submit IT+is+not+on+the+Menu to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/itil/archive/2009/06/19/it-is-not-on-the-menu.aspx&amp;title=IT+is+not+on+the+Menu" title="Submit IT+is+not+on+the+Menu to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2568" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/itil/archive/tags/Best+Practices+Guidance/default.aspx">Best Practices Guidance</category><category domain="http://community.ca.com/blogs/itil/archive/tags/IT+Service+Management/default.aspx">IT Service Management</category><category domain="http://community.ca.com/blogs/itil/archive/tags/ITIL/default.aspx">ITIL</category><category domain="http://community.ca.com/blogs/itil/archive/tags/Lean+IT/default.aspx">Lean IT</category><category domain="http://community.ca.com/blogs/itil/archive/tags/Service+Catalog/default.aspx">Service Catalog</category></item><item><title>Death to the Penguin!</title><link>http://community.ca.com/blogs/execio/archive/2009/06/19/death-to-the-penguin.aspx</link><pubDate>Fri, 19 Jun 2009 12:12:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2566</guid><dc:creator>Reg Harbeck</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;If the title of this blog entry got your attention, I hope it also gets the attention of everyone that has been saying &amp;quot;death to the mainframe&amp;quot; for the past three decades.&lt;/p&gt;
&lt;p&gt;After all, given the number of people who have been trying to portray the mainframe&amp;#39;s invisibility as some sort of demise over the years, it seems like that&amp;#39;s actually a good indicator of something that works - so well that nobody notices it. Just like that old saying, &amp;quot;housework is something nobody notices unless you don&amp;#39;t do it.&amp;quot; &lt;/p&gt;
&lt;p&gt;So, now, Linux, that friendly operating system with the penguin mascot (named &amp;quot;&lt;a href="http://en.wikipedia.org/wiki/Tux"&gt;Tux&lt;/a&gt;&amp;quot; as it turns out), has arrived on the invisible platform. Actually, it&amp;#39;s been there for nearly a decade - but, as I mentioned in my &lt;a href="http://community.ca.com/blogs/execio/archive/2009/03/12/the-iron-penguin.aspx"&gt;blog entry from March 12, 2009&lt;/a&gt;, its progress has also been somewhat invisible.&lt;/p&gt;
&lt;p&gt;As &lt;a href="http://wikipedia.org/"&gt;Wikipedia&lt;/a&gt; reminds us, &lt;a href="http://en.wikipedia.org/wiki/Linux_on_zseries"&gt;IBM first announced mainframe Linux in 2000&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;And, ever since then, everyone&amp;#39;s been waiting and watching and trying to figure out what has happened to this penguin on its journey into the world of mainframe.&lt;/p&gt;
&lt;p&gt;Well, someone has finally found the answer - and it&amp;#39;s good news!&lt;/p&gt;
&lt;p&gt;According to a &lt;a href="http://www.ca.com/us/press/release.aspx?cid=209611"&gt;Press Release&lt;/a&gt; that CA issued this past Wednesday, the folks at TheInfoPro have done a survey of large mainframe shops that have or are getting mainframe Linux, in order to find out what people are doing (see &lt;a href="http://ca.com/mainframe/linuxresearch"&gt;http://ca.com/mainframe/linuxresearch&lt;/a&gt;). The answer? They&amp;#39;re growing it, and moving both new and existing (especially distributed) applications to it, in order to take advantage of the significant strengths (virtualization, security, scalability...) and cost savings available on the mainframe.&lt;/p&gt;
&lt;p&gt;Since CA has a large and growing stable of products for managing mainframe Linux (see &lt;span style="FONT-SIZE:11pt;COLOR:#1f497d;FONT-FAMILY:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;mso-fareast-font-family:Calibri;mso-fareast-theme-font:minor-latin;mso-bidi-font-family:&amp;#39;Times New Roman&amp;#39;;mso-ansi-language:EN-US;mso-fareast-language:EN-US;mso-bidi-language:AR-SA;"&gt;&lt;a href="http://www.ca.com/mainframe/linux"&gt;&lt;font color="#800080"&gt;ca.com/mainframe/linux&lt;/font&gt;&lt;/a&gt;&lt;/span&gt;), this is good news for CA and the rest of the mainframe world, as it affirms the choice to join this penguin on its sojourn.&lt;/p&gt;
&lt;p&gt;So, what about the death of the penguin? Just as with the mainframe, nothing could be further from the truth. It&amp;#39;s just been too busy taking root under the surface (if I may mix metaphors), and taking on many of the same production qualities that we&amp;#39;ve come to take for granted on the mainframe.&lt;/p&gt;
&lt;p&gt;Something tells me we&amp;#39;ll be hearing plenty more about this before long.&lt;/p&gt;
&lt;p&gt;What do you think? Are you or your organization using or considering Linux on the mainframe? What do you have in mind for it?&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Death+to+the+Penguin!" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/execio/archive/2009/06/19/death-to-the-penguin.aspx&amp;subject=Death+to+the+Penguin!"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/execio/archive/2009/06/19/death-to-the-penguin.aspx&amp;title=Death+to+the+Penguin!" title="Submit Death+to+the+Penguin! to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/execio/archive/2009/06/19/death-to-the-penguin.aspx&amp;phase=2" title="Submit Death+to+the+Penguin! to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/execio/archive/2009/06/19/death-to-the-penguin.aspx&amp;title=Death+to+the+Penguin!" title="Submit Death+to+the+Penguin! to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2566" width="1" height="1"&gt;</description></item><item><title>Why CA Supports the Kantara Initiative</title><link>http://community.ca.com/blogs/iam/archive/2009/06/17/why-ca-supports-the-kantara-initiative.aspx</link><pubDate>Wed, 17 Jun 2009 20:53:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2561</guid><dc:creator>Matthew Gardiner</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Over the past year or so, I have been&amp;nbsp;CA&amp;#39;s representative involved in the structuring and birth of the &lt;a class="" href="http://kantarainitiative.org/" target="_blank"&gt;Kantara Initiative&lt;/a&gt;.&amp;nbsp; Now that the Kantara Initative is officially launched, I thought it made sense to blog about why CA believes the creation of the Kantara Initiative is so important.&amp;nbsp; In no particular order, here are my thoughts on &amp;quot;why Kantara.&amp;quot;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The challenges around identity go beyond just technology. Over the years the industry has done a pretty good job inventing technologies and establishing standards to address identity challenges (too well really), only to discover that the real challenges to identity and security on the Internet are around softer issues like privacy and trust. The Kantara Initiative will focus on this in a way that is neutral to the underlying technologies.&lt;/li&gt;
&lt;li&gt;Along the same lines, to date technologists have invented many technologies/standards that are at least somewhat overlapping and certainly not interoperable (example SAML, Information Cards, OpenID) which complicates matters for both deploying organizations and end-users. The Kantara Initiative will focus on this. The identity community cannot afford to create new, incompatible silos of identity on the Internet.&lt;/li&gt;
&lt;li&gt;Certification of interoperability of vendor implementations is critical to eased deployments in the real world. Inventing new technologies/standards without sustained vendor certification testing is a recipe for slow and painful adoption. The Kantara Initiative will focus on this.&lt;/li&gt;
&lt;li&gt;Creating and promoting identity technologies and best practices is a global challenge and opportunity. Technology invention is only part of what is needed for adoption. Thus the Kantara Initiative will focus on both bringing the global community in on the debate as well as be the focus of the related communication and promotion.&lt;/li&gt;
&lt;li&gt;Combining open participation with a serious and well-funded organization is unique. Traditionally you could have one or the other of these, but not both. We have typically seen many organizations where &amp;quot;all are welcome,&amp;quot; but it is hard to get things done since everyone is a volunteer with day jobs. Or organizations which are well-funded but are correspondingly exclusive based on the need to pay - so that staff and expert consultants can be hired. The Kantara Initiative is covering both bases partially based on its unique bicameral governance model.&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;I will certainly blog more about the Kantara Initiative as it develops and starts making an impact, but if any of these points hit home for you, please consider participating and/or &lt;a class="" href="http://kantarainitiative.org/wordpress/?page_id=8" target="_blank"&gt;joining&lt;/a&gt; the Kantara Initative yourself.&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Why+CA+Supports+the+Kantara+Initiative" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/iam/archive/2009/06/17/why-ca-supports-the-kantara-initiative.aspx&amp;subject=Why+CA+Supports+the+Kantara+Initiative"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/iam/archive/2009/06/17/why-ca-supports-the-kantara-initiative.aspx&amp;title=Why+CA+Supports+the+Kantara+Initiative" title="Submit Why+CA+Supports+the+Kantara+Initiative to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/iam/archive/2009/06/17/why-ca-supports-the-kantara-initiative.aspx&amp;phase=2" title="Submit Why+CA+Supports+the+Kantara+Initiative to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/iam/archive/2009/06/17/why-ca-supports-the-kantara-initiative.aspx&amp;title=Why+CA+Supports+the+Kantara+Initiative" title="Submit Why+CA+Supports+the+Kantara+Initiative to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2561" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/iam/archive/tags/Federation/default.aspx">Federation</category><category domain="http://community.ca.com/blogs/iam/archive/tags/IAM+Trends/default.aspx">IAM Trends</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Identity+Management/default.aspx">Identity Management</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Kantara+Initiative/default.aspx">Kantara Initiative</category><category domain="http://community.ca.com/blogs/iam/archive/tags/SAML/default.aspx">SAML</category></item><item><title>Another Organization Using Service Catalog as a Key Component of Lean IT Service Management </title><link>http://community.ca.com/blogs/itil/archive/2009/06/17/another-organization-using-service-catalog-as-a-key-component-of-lean-it-service-management.aspx</link><pubDate>Wed, 17 Jun 2009 07:43:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2559</guid><dc:creator>Robert Stroud</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;The last few weeks meeting&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;with organizations in New Zealand, Australia, India, France, Denmark, UK and the U.S. reinforced that the current economic climate is forcing IT organizations to get lean.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;Lean for IT does not mean slim and trim; lean in IT is about maximizing IT value while minimizing cost. For lean IT service management it requires focusing on the components that matter to the business to ensure that IT can deliver what the business needs at the right time and optimize service supply and demand.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;In my &lt;a class="" href="http://community.ca.com/blogs/itil/archive/2009/06/08/leveraging-the-service-catalog-to-drive-lean-it.aspx" target="_blank"&gt;June 8 blog&lt;/a&gt; I discussed a conversation I had in India with a CIO and his approach to &amp;quot;leaning up&amp;quot; his IT organization by using a service catalog.&amp;nbsp; Not surprising, I am finding this approach is being applied by other organizations globally. &lt;/p&gt;
&lt;p&gt;While attending the CA Expo in France earlier this month, another CIO commented that his business is now demanding to see a list of the services that IT can deliver with business related service levels and costs.&amp;nbsp; Users (or consumers as I like to call them) of IT-enabled business services are becoming more IT savvy. Just think about the growth in sales of goods and services over the internet such as books, airline tickets or satellite television.&amp;nbsp; Consumers are now very used to identification, negotiation, ordering and tracking goods and services electronically with the expressed service level agreement and cost clearly outlined. In business this is achieved using a business service catalog.&amp;nbsp; The business expectations are set, the business is engaged and understands the implications of its choice, and the decisions for cost reduction are transferred to the business rather than IT. This helps ensure IT support is directly aligned to business need - helping optimize service supply and demand. &amp;nbsp;&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Another+Organization+Using+Service+Catalog+as+a+Key+Component+of+Lean+IT+Service+Management+" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/itil/archive/2009/06/17/another-organization-using-service-catalog-as-a-key-component-of-lean-it-service-management.aspx&amp;subject=Another+Organization+Using+Service+Catalog+as+a+Key+Component+of+Lean+IT+Service+Management+"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/itil/archive/2009/06/17/another-organization-using-service-catalog-as-a-key-component-of-lean-it-service-management.aspx&amp;title=Another+Organization+Using+Service+Catalog+as+a+Key+Component+of+Lean+IT+Service+Management+" title="Submit Another+Organization+Using+Service+Catalog+as+a+Key+Component+of+Lean+IT+Service+Management+ to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/itil/archive/2009/06/17/another-organization-using-service-catalog-as-a-key-component-of-lean-it-service-management.aspx&amp;phase=2" title="Submit Another+Organization+Using+Service+Catalog+as+a+Key+Component+of+Lean+IT+Service+Management+ to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/itil/archive/2009/06/17/another-organization-using-service-catalog-as-a-key-component-of-lean-it-service-management.aspx&amp;title=Another+Organization+Using+Service+Catalog+as+a+Key+Component+of+Lean+IT+Service+Management+" title="Submit Another+Organization+Using+Service+Catalog+as+a+Key+Component+of+Lean+IT+Service+Management+ to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2559" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/itil/archive/tags/Best+Practices+Guidance/default.aspx">Best Practices Guidance</category><category domain="http://community.ca.com/blogs/itil/archive/tags/Business+and+IT+Integration/default.aspx">Business and IT Integration</category><category domain="http://community.ca.com/blogs/itil/archive/tags/IT+Service+Management/default.aspx">IT Service Management</category><category domain="http://community.ca.com/blogs/itil/archive/tags/ITIL/default.aspx">ITIL</category><category domain="http://community.ca.com/blogs/itil/archive/tags/Lean+IT/default.aspx">Lean IT</category><category domain="http://community.ca.com/blogs/itil/archive/tags/Service+Catalog/default.aspx">Service Catalog</category></item><item><title>No "One size fits all"</title><link>http://community.ca.com/blogs/theitgovernanceevangelist/archive/2009/06/16/no-quot-one-size-fits-all-quot.aspx</link><pubDate>Tue, 16 Jun 2009 17:32:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2554</guid><dc:creator>Steve Romero</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Are you looking for &amp;quot;the&amp;quot; solution to a specific problem in IT? Are you looking for a single solution for &lt;i&gt;all&lt;/i&gt; of your problems in IT? Do you seek the &amp;quot;one&amp;quot; best practice that will make things better? Do you want that silver-bullet?&lt;/p&gt;
&lt;p&gt;Don&amp;#39;t look here, because I can&amp;#39;t give it to you.&lt;/p&gt;
&lt;p&gt;I have said this, time and time again. And there have been occasions when it was not well received at all. In fact, you might be wondering why you should even continue reading this post. You likely know plenty of sources to which you can turn that are more than willing to give you &amp;quot;the&amp;quot; answer.&lt;/p&gt;
&lt;p&gt;I have been working as CA&amp;#39;s IT Governance Evangelist for more than 2½ years now. I have had the honor to present and speak to thousands of people around the world. In those interactions I have been asked over and over, &amp;quot;Steve, here is our situation, what do we do?&amp;quot; My answer (though it makes my stomach hurt each and every time I say it) is always the same, &amp;quot;It depends.&amp;quot; Even in those cases where there is a single solution, the approach, starting point, sequence and implementation roadmap will vary greatly from instance to instance.&lt;/p&gt;
&lt;p&gt;I am certain this is not what they want to hear. Some are openly frustrated by my response. A few dismiss me outright and turn quickly towards others who will be delighted to tell them exactly what to do. Thankfully, most folks let me explain.&lt;/p&gt;
&lt;p&gt;I am sure I don&amp;#39;t need to convince you that the world of IT is incredibly complex. This intricate atmosphere creates multifaceted challenges, problems, issues and opportunities. The circumstances and variables are countless. Given this complexity, how can there be any single or simple answer? In fact, it will be a series and sequence of integrated solutions that will simplify and unify their complex IT environments, ultimately reduce its complexity, and make it far more manageable.&lt;/p&gt;
&lt;p&gt;I tell everyone they have some homework to do before they can adequately answer their question. I provide them a laundry list of things they need to understand:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Business problem or opportunity and related risks&lt;/li&gt;
&lt;li&gt;Industry and business sector&lt;/li&gt;
&lt;li&gt;Current capacity and capability&lt;/li&gt;
&lt;li&gt;Strengths and weaknesses&lt;/li&gt;
&lt;li&gt;Culture and organizational constructs&lt;/li&gt;
&lt;li&gt;Governance and decision-making mechanisms&lt;/li&gt;
&lt;li&gt;Policies, Standards, Processes and Procedures&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;In addition to understanding the elements I list above, they then need investigate:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Disciplines and frameworks&lt;/li&gt;
&lt;li&gt;Approaches and Best Practices&lt;/li&gt;
&lt;li&gt;Standards and conventions&lt;/li&gt;
&lt;li&gt;Solutions, systems and tools&lt;/li&gt;
&lt;li&gt;External resources and potential Partners&lt;/li&gt;
&lt;li&gt;Mountains of research&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;Confronted with these lists (and please, I entice you to add to them) they will find they have a sometimes overwhelming myriad of choices and alternatives. This approach requires acute understanding, in-depth analysis, accurate interpretation and courageous decision. Most importantly, it requires time. If you don&amp;#39;t have sufficient and adequate time then you must understand, mitigate and potentially accept the risk of not taking the time.&lt;/p&gt;
&lt;p&gt;I was inspired to broach this subject because in addition to being asked what to do, I have had the luxury of immersing myself in research and interacting with countless brilliant and astute people in my profession. I enjoy their ideas, insights and theories. At the same time, I am bothered by some of their conclusions. I have witnessed a propensity if not an obligation to accompany investigation with one-size-fits-all recommendation. Why? Go back to the first paragraph of this post. Too many of us want &amp;quot;the&amp;quot; answer. We want the solution to be singular, simple, and even easy. As I have said countless times, if it was easy, we would already be doing it.&lt;/p&gt;
&lt;p&gt;I urge caution in those instances when specific recommendations follow research. I will give said researchers the benefit of the doubt that these recommendations are based on their devoted and fervent desire to help others succeed. It is quite reasonable to accept the notion that following the singular recommendation is better than doing nothing. Enterprises are likely subscribing to the 80/20 rule, which is many cases is adequate. My hope is that those adopting this approach are doing so due to reasoned and rational necessity as opposed to expediency or worse, recklessness. I also hope they luckily if not accidentally select a recommendation that is &amp;quot;coincidently&amp;quot; appropriate for them.&lt;/p&gt;
&lt;p&gt;Whatever the case may be, I will continue my quest to evangelize IT Governance and resist the urge to downplay its complexity. I will try to persuade folks there is power and promise in the discipline when it is applied thoughtfully and appropriately. I will try to convince them to take the time to do the right things, and to do them right. I will inform them that their approaches and paths to success will vary greatly from their contemporaries as well as their counterparts. I will tell them it is a journey that requires audacity, courage, perseverance and resilience. I will continue to insist there are no easy answers, and I will warn everyone to question any &amp;quot;one size fits all&amp;quot; recommendation or solution.&lt;/p&gt;
&lt;p&gt;One last note, I drafted this post on my flight to Boston to attend MIT&amp;#39;s CISR Executive Summer Session. This is my third trip to MIT and I don&amp;#39;t want to give you the impression my time with these incredible minds (led by Peter Weill and Jeanne Ross - both heroes of mine) inspired this post, quite the contrary. I have never seen them oversimplify the answers to the incredibly complex question of how enterprises derive value from technology. MIT CISR has been addressing that question for 35 years and they are the first to admit, there are no easy answers.&lt;/p&gt;
&lt;p&gt;Steve Romero, IT Governance Evangelist&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email No+%26quot%3bOne+size+fits+all%26quot%3b" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/theitgovernanceevangelist/archive/2009/06/16/no-quot-one-size-fits-all-quot.aspx&amp;subject=No+%26quot%3bOne+size+fits+all%26quot%3b"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/theitgovernanceevangelist/archive/2009/06/16/no-quot-one-size-fits-all-quot.aspx&amp;title=No+%26quot%3bOne+size+fits+all%26quot%3b" title="Submit No+%26quot%3bOne+size+fits+all%26quot%3b to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/theitgovernanceevangelist/archive/2009/06/16/no-quot-one-size-fits-all-quot.aspx&amp;phase=2" title="Submit No+%26quot%3bOne+size+fits+all%26quot%3b to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/theitgovernanceevangelist/archive/2009/06/16/no-quot-one-size-fits-all-quot.aspx&amp;title=No+%26quot%3bOne+size+fits+all%26quot%3b" title="Submit No+%26quot%3bOne+size+fits+all%26quot%3b to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2554" width="1" height="1"&gt;</description></item><item><title>Gartner MQ for IT PPM Published </title><link>http://community.ca.com/blogs/ppm/archive/2009/06/16/gartner-mq-for-it-ppm-published.aspx</link><pubDate>Tue, 16 Jun 2009 17:02:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2553</guid><dc:creator>Pradeep Bhanot</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;In the latest Magic Quadrant for IT Project and Portfolio Management report, Gartner has raised the bar for the PPM market by Increasing the emphasis on the integrations to support broader use cases such as IT Planning and Control, Application Portfolio Management and use with ERP systems. CA was placed in the Leaders Quadrant. The full report is available at &lt;a href="http://mediaproducts.gartner.com/reprints/ca/article3/article3.html"&gt;http://mediaproducts.gartner.com/reprints/ca/article3/article3.html&lt;/a&gt; This report has encouraged CA to further evolve its capabilities for enabling true service portfolio management through improved interoperability of PPM and IT Service Management.&amp;nbsp;About the Magic Quadrant The Magic Quadrant is copyrighted 2 June 2009 by Gartner, Inc. and is reused with permission. &lt;/p&gt;
&lt;p&gt;The Magic Quadrant is a graphical representation of a marketplace at and for a specific time period. It depicts Gartner&amp;#39;s analysis of how certain vendors measure against criteria for that marketplace, as defined by Gartner. Gartner does not endorse any vendor, product or service depicted in the Magic Quadrant, and does not advise technology users to select only those vendors placed in the &amp;quot;Leaders&amp;quot; quadrant. The Magic Quadrant is intended solely as a research tool, and is not meant to be a specific guide to action. Gartner disclaims all warranties, express or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Gartner+MQ+for+IT+PPM+Published+" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/ppm/archive/2009/06/16/gartner-mq-for-it-ppm-published.aspx&amp;subject=Gartner+MQ+for+IT+PPM+Published+"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/ppm/archive/2009/06/16/gartner-mq-for-it-ppm-published.aspx&amp;title=Gartner+MQ+for+IT+PPM+Published+" title="Submit Gartner+MQ+for+IT+PPM+Published+ to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/ppm/archive/2009/06/16/gartner-mq-for-it-ppm-published.aspx&amp;phase=2" title="Submit Gartner+MQ+for+IT+PPM+Published+ to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/ppm/archive/2009/06/16/gartner-mq-for-it-ppm-published.aspx&amp;title=Gartner+MQ+for+IT+PPM+Published+" title="Submit Gartner+MQ+for+IT+PPM+Published+ to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2553" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/ppm/archive/tags/Gartner+PPM+Clarity/default.aspx">Gartner PPM Clarity</category></item><item><title>Fake Microsoft Updates coming back?</title><link>http://community.ca.com/blogs/securityadvisor/archive/2009/06/16/fake-microsoft-updates-coming-back.aspx</link><pubDate>Tue, 16 Jun 2009 09:22:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2548</guid><dc:creator>Rossano Ferraris</dc:creator><slash:comments>2</slash:comments><description>&lt;p&gt;It’s been awhile since I saw a fake update email which looked like it came from Microsoft security laboratories.&amp;nbsp; Some people complained to me about a strange email that asked the user to update their machines because of a recent outbreak of the well-known Conficker worm (see Figure 1 and Figure 2).&lt;/p&gt;
&lt;p&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Rossano/fig05.gif"&gt;&lt;/a&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Rossano/figure1.bmp"&gt;&lt;img src="http://community.ca.com/blogs/securityadvisor/Rossano/figure1.bmp" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;Figure 1 - Fake Email (part 1)&lt;/p&gt;
&lt;p&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Rossano/fig06.gif"&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Rossano/fig06.gif"&gt;&lt;/a&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Rossano/figure2.bmp"&gt;&lt;img src="http://community.ca.com/blogs/securityadvisor/Rossano/figure2.bmp" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;Figure 2 - Fake Email (part 2)&lt;/p&gt;
&lt;p&gt;Let’s take a look at the body of this email, which is very well written and uses persuasive language.&amp;nbsp;The lure in the message is a Microsoft removal tool that will scan and clean the user’s machine.&amp;nbsp;&lt;br /&gt;However, I notice a phrase that says “you are advised to disable your already existing antivirus software.”&amp;nbsp; My spam email reveals itself when I move my mouse pointer over the link “click here to download the removal tool” and I discover that the URL redirects the browser to a Russian server (windowsupdate.microsoft.com.ssl3.pop3.&lt;strong&gt;ru&lt;/strong&gt;), which hosts the remtool_conf.exe.&lt;/p&gt;
&lt;p&gt;If we look at the header, we see the following:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Rossano/fig04.gif"&gt;&lt;img src="http://community.ca.com/blogs/securityadvisor/Rossano/fig04.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;Figure 3 - Email Header&lt;/p&gt;
&lt;p&gt;The email comes from a certain Microsoft[dot]ssl[dot]com whose IP address is 38.100.66.185. This IP address originates from a server which is located in Texas and is not a Microsoft server.&lt;/p&gt;
&lt;p&gt;During the analysis, I download and install remtool_conf.exe:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Rossano/fig01.gif"&gt;&lt;img src="http://community.ca.com/blogs/securityadvisor/Rossano/fig01.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;Figure 4 - Removal Tool License&lt;/p&gt;
&lt;p&gt;Then I click on “Accept” and the tool - which seems to belong to Symantec - starts to scan my machine:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Rossano/fig02.gif"&gt;&lt;img src="http://community.ca.com/blogs/securityadvisor/Rossano/fig02.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;Figure 5 - Removal Tool Software&lt;/p&gt;
&lt;p&gt;The fake software scans the entire machine, and establishes a hidden connection to the host &lt;strong&gt;makemymoneys.com&lt;/strong&gt; (Figure 6) from which it attempts to download and install the malicious file &lt;strong&gt;winupdate.exe&lt;/strong&gt;, which is detected by CA Security products as “DelfInject CX.”&lt;/p&gt;
&lt;p&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Rossano/fig03.gif"&gt;&lt;/a&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Rossano/figure6.bmp"&gt;&lt;/a&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Rossano/figure6.bmp"&gt;&lt;/a&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Rossano/figure61.bmp"&gt;&lt;img src="http://community.ca.com/blogs/securityadvisor/Rossano/figure61.bmp" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;Figure 6 - makemymoneys.com host hidden connection&lt;/p&gt;
&lt;p&gt;CA Security products detect the fake removal tool as “FakeScan A” warning against it and have the ability to remove it. &lt;/p&gt;
&lt;p&gt;Although there has been a decrease in the number of fake Microsoft update emails, the current fake emails are more sophisticated and use a very high profile social engineering technique to lure and trap people.&amp;nbsp; The CA Research team advises users to be aware of these types of spam message and to update their anti-malware products on a daily basis.&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Fake+Microsoft+Updates+coming+back%3f" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/securityadvisor/archive/2009/06/16/fake-microsoft-updates-coming-back.aspx&amp;subject=Fake+Microsoft+Updates+coming+back%3f"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/securityadvisor/archive/2009/06/16/fake-microsoft-updates-coming-back.aspx&amp;title=Fake+Microsoft+Updates+coming+back%3f" title="Submit Fake+Microsoft+Updates+coming+back%3f to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/securityadvisor/archive/2009/06/16/fake-microsoft-updates-coming-back.aspx&amp;phase=2" title="Submit Fake+Microsoft+Updates+coming+back%3f to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/securityadvisor/archive/2009/06/16/fake-microsoft-updates-coming-back.aspx&amp;title=Fake+Microsoft+Updates+coming+back%3f" title="Submit Fake+Microsoft+Updates+coming+back%3f to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2548" width="1" height="1"&gt;</description></item><item><title>Koobface Re-Activated!</title><link>http://community.ca.com/blogs/securityadvisor/archive/2009/06/16/koobface-re-activated.aspx</link><pubDate>Tue, 16 Jun 2009 05:17:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2544</guid><dc:creator>Ricardo Robielos III</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Social networking sites are extremely popular these days and, not surprisingly, the latest variant of &lt;a class="" href="http://www.ca.com/us/securityadvisor/virusinfo/virus.aspx?id=73167" target="_blank"&gt;Win32/Koobface&lt;/a&gt; is &lt;a class="" href="http://community.ca.com/blogs/securityadvisor/archive/2009/03/05/from-koobface-one-video-message-received.aspx"&gt;still&lt;/a&gt; taking advantage of this popularity by using these sites as an attack vector.&lt;/p&gt;
&lt;p&gt;A variant of Koobface is currently active (as of this posting), sending massive spam messages in several social networking sites such as &lt;strong&gt;FaceBook.com&lt;/strong&gt;, &lt;strong&gt;MySpace.com&lt;/strong&gt;, &lt;strong&gt;Friendster.com&lt;/strong&gt;, &lt;strong&gt;Hi5.com&lt;/strong&gt;, &lt;strong&gt;Bebo.com&lt;/strong&gt;, &lt;strong&gt;Fubar.com&lt;/strong&gt;, &lt;strong&gt;MyYearbook.com&lt;/strong&gt; and &lt;strong&gt;Tagged.com&lt;/strong&gt;.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;This variant connects to the malicious server &amp;quot;&lt;em&gt;UPR15MAY.COM&lt;/em&gt;&amp;quot; to get the information details for its spam messages to be sent to contacts of affected users who access any of the above mentioned social networking sites, with sample messages sent shown below:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;u&gt;For FaceBook.com: &lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;[Sample Facebook Post]&lt;br /&gt;&amp;nbsp;&lt;a href="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_FB_Post.gif"&gt;&lt;img src="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_FB_Post.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;[Sample Facebook Message]&lt;br /&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_FB_Mail.gif"&gt;&lt;img src="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_FB_Mail.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;For Facebook, this malware connects to &amp;quot;&lt;em&gt;upr15may.com/fb&lt;/em&gt;&amp;quot; to generate the spam details to be sent. &lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;For MySpace.com:&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;[Sample MySpace Message]&lt;br /&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_MS.gif"&gt;&lt;img src="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_MS.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;For MySpace, this malware connects to &amp;quot;&lt;em&gt;upr15may.com/ms&lt;/em&gt;&amp;quot; to generate the spam details to be sent. &lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;For Friendster.com:&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;[Sample Friendster Message]&lt;br /&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_FR.gif"&gt;&lt;img src="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_FR.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;For Friendster, this malware connects to &amp;quot;&lt;em&gt;upr15may.com/fr&lt;/em&gt;&amp;quot; to generate the spam details to be sent. &lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;For Hi5.com:&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;[Sample Hi5 Message]&lt;br /&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_Hi5.gif"&gt;&lt;img src="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_Hi5.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;For Hi5, this malware connects to &amp;quot;&lt;em&gt;upr15may.com/hi&lt;/em&gt;&amp;quot; to generate the spam details to be sent. &lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;For Bebo.com:&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;[Sample BeBo Message]&lt;br /&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_BE.gif"&gt;&lt;img src="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_BE.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;For Bebo, this malware connects to &amp;quot;&lt;em&gt;upr15may.com/be&lt;/em&gt;” to generate the spam details to be sent. &lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;For Fubar.com:&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;[Sample Fubar Message]&lt;br /&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_FU.gif"&gt;&lt;img src="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_FU.gif" border="0" alt="" /&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;For Fubar, this malware connects to &amp;quot;&lt;em&gt;upr15may.com/fu&lt;/em&gt;&amp;quot; to generate the spam details to be sent. &lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;For MyYearBook.com:&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;[Sample MyYearbook Message]&lt;br /&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_YB.gif"&gt;&lt;img src="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_YB.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;For MyYearbook, this malware connects to &amp;quot;&lt;em&gt;upr15may.com/yb&lt;/em&gt;&amp;quot; to generate the spam details to be sent. &lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;For Tagged.com:&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;[Sample Tagged Message]&lt;br /&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_TG.gif"&gt;&lt;img src="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_TG.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;For Tagged, this malware connects to &amp;quot;&lt;em&gt;upr15may.com/tg&lt;/em&gt;&amp;quot; to generate the spam details to be sent.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;We did a simple &lt;em&gt;curl&lt;/em&gt; POST command to the malicious server to obtain a list of spam messages that this worm may generate, giving us the following details:&lt;/p&gt;
&lt;p&gt;&lt;u&gt;Title/Subject:&lt;/u&gt; (Any of the following)&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;:)&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;;)&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;HA-HA-HA!!&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;L.O.L.&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;lol&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;OMFG!!!&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;W.O.W.&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;WOW&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&lt;u&gt;Text/Body:&lt;/u&gt; (Any of the following)&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&amp;nbsp;&lt;em&gt;A--ha-ha, i saw yoour ass in the internet!! lol&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;Be more careful next time and get caught again!&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;Can anyone get busted, or is it just you?&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;Dammn! Haaven’t you seeen our secrett caamera?&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;Enjoy your first acting experience in our movie.&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;Got yoou! Ha--ha, now watcch and crry!&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;Hey ddude, yoou’re on candiid cammera!&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;I caan’t beelieve you diddn’t see the ssecret cammera!&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;Laaugh at oother people?? LLook at yoursself!&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;Man, you&amp;#39;re great! See yourself naked, lol XD&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;Oh, what a shame, your ass is on our tape.&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;Prrivate viideo wwith yyou. funnny&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;YYou&amp;#39;re so ppretty ggood on thhis vvideo.&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;… Or see the other list &lt;a class="" href="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_Text.txt" target="_blank"&gt;here&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;u&gt;Malicious redirected Links:&lt;/u&gt; (Any of the following, please do not visit this sites)&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;hxxp://28680.yoyo.pl/extrimevideo/&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;hxxp://anilkapoor.net/amaizingdemonstration/&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;hxxp://baldom.yoyo.pl/privatevids/&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;hxxp://budget.user.kz/uncensoredvideo/&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;hxxp://canibals.ic.cz/coolclips/&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;hxxp://kuzmi4.110mb.com/uncensoredmovie/&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;hxxp://lambord.ic.cz/publicmovie/&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;hxxp://mediawork.ru/uncensoredmovie/&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;hxxp://punks.110mb.com/publicdvd/&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;hxxp://quicksilverr.110mb.com/freefilm/&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;hxxp://topwoman.intway.info/publictube/&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;hxxp://uc2qasimabad.com/freeclips/&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;hxxp://www.tangoballet.com/uncensoredvids/&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;hxxp://yarentextil.com/funnyfilm/&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;hxxp://zbanglabd.com/uncensoredshow/&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;hxxp://zidacilbin.tym.cz/privatefilm/&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;hxxp://zkouskafora.ic.cz/funnyfilm/&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&amp;nbsp;hxxp://zoghetaze.com/amaizingmovie/&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;… Or see the other list &lt;a class="" href="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_Links.txt" target="_blank"&gt;here&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The spam messages contain a malicious link that accesses a Java Script. (&lt;em&gt;See figure below. We detect this Java Script as a &lt;strong&gt;JS/Redirector&lt;/strong&gt; variant&lt;/em&gt;)&lt;/p&gt;
&lt;p&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_JScript.gif"&gt;&lt;img src="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Koobface_JScript.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This JavaScript redirects web browsers to a fake Video site (&amp;quot;&lt;em&gt;YuoTube&lt;/em&gt;&amp;quot; misspelled) to download a file &amp;quot;&lt;em&gt;setup.exe&lt;/em&gt;&amp;quot;, which is also a variant of Win32/Koobface. This other variant may also download other malicious files such as Rogue Antivirus programs.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Youtube.gif"&gt;&lt;img src="http://community.ca.com/blogs/securityadvisor/Ricardo/Koobface/Youtube.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;We advise users to avoid opening these spam messages when visiting their favorite social networking site and to always keep their CA Antivirus Product up-to-date with the latest signature files.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Koobface+Re-Activated!" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/securityadvisor/archive/2009/06/16/koobface-re-activated.aspx&amp;subject=Koobface+Re-Activated!"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/securityadvisor/archive/2009/06/16/koobface-re-activated.aspx&amp;title=Koobface+Re-Activated!" title="Submit Koobface+Re-Activated! to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/securityadvisor/archive/2009/06/16/koobface-re-activated.aspx&amp;phase=2" title="Submit Koobface+Re-Activated! to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/securityadvisor/archive/2009/06/16/koobface-re-activated.aspx&amp;title=Koobface+Re-Activated!" title="Submit Koobface+Re-Activated! to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2544" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/Bebo_7B00_dot_7D00_com/default.aspx">Bebo{dot}com</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/Facebook+spams/default.aspx">Facebook spams</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/Friendster+spam/default.aspx">Friendster spam</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/Fubar/default.aspx">Fubar</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/Hi5/default.aspx">Hi5</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/JS_2F00_Redirector/default.aspx">JS/Redirector</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/koobface/default.aspx">koobface</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/MySpace+worm/default.aspx">MySpace worm</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/MyYearbook/default.aspx">MyYearbook</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/Tagged_7B00_dot_7D00_com/default.aspx">Tagged{dot}com</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/upr15may_7B00_dot_7D00_com/default.aspx">upr15may{dot}com</category><category domain="http://community.ca.com/blogs/securityadvisor/archive/tags/YuoTube/default.aspx">YuoTube</category></item><item><title>CA20090615-02: CA Service Desk Tomcat Cross Site Scripting Vulnerability</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2009/06/15/ca20090615-02-ca-service-desk-tomcat-cross-site-scripting-vulnerability.aspx</link><pubDate>Tue, 16 Jun 2009 02:30:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2550</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;On June 15th, 2009, CA published a security notice to address a vulnerability in CA Service Desk.&lt;/p&gt;&lt;p&gt;Title: CA20090615-02: CA Service Desk Tomcat Cross Site Scripting Vulnerability&lt;br /&gt;&lt;br /&gt;CA Advisory Reference: CA20090615-02&lt;br /&gt;&lt;br /&gt;CA Advisory Date: 2009-06-15&lt;br /&gt;&lt;br /&gt;Impact: A remote attacker can inject arbitrary web script or HTML.&lt;br /&gt;&lt;br /&gt;Summary: The release of Tomcat as included with CA Service Desk r11.2 is potentially susceptible to a cross-site scripting vulnerability.&amp;nbsp; CA has issued a technical document that describes remediation procedures.&lt;br /&gt;&lt;br /&gt;Mitigating Factors: None&lt;br /&gt;&lt;br /&gt;Severity: CA has given this vulnerability a Medium risk rating.&lt;br /&gt;&lt;br /&gt;Affected Products:&lt;br /&gt;CA Service Desk r11.2&lt;br /&gt;&lt;br /&gt;Affected Platforms:&lt;br /&gt;Windows, Unix&lt;br /&gt;&lt;br /&gt;Status and Recommendation:&lt;br /&gt;Follow the instructions in technical document &lt;a href="https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=search&amp;amp;searchID=TEC489643"&gt;TEC489643&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;How to determine if the installation is affected:&lt;br /&gt;Customers can use the instructions in technical document &lt;a href="https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=search&amp;amp;searchID=TEC489643"&gt;TEC489643&lt;/a&gt; to determine if an installation may be affected.&lt;br /&gt;&lt;br /&gt;Workaround: &lt;br /&gt;None&lt;br /&gt;&lt;br /&gt;References (URLs may wrap):&lt;br /&gt;CA Support:&lt;br /&gt;&lt;a href="https://support.ca.com/"&gt;https://support.ca.com/&lt;/a&gt;&lt;br /&gt;CA20090615-02: Security Notice for CA Service Desk&lt;br /&gt;&lt;a href="https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=209500"&gt;https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=209500&lt;/a&gt;&lt;br /&gt;Solution Document Reference APARs:&lt;br /&gt;&lt;a href="https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=search&amp;amp;searchID=TEC489643"&gt;TEC489643&lt;/a&gt;&lt;br /&gt;CA Security Response Blog posting:&lt;br /&gt;CA20090615-02: CA Service Desk Tomcat Cross Site Scripting Vulnerability&lt;br /&gt;&lt;a href="http://community.ca.com/blogs/casecurityresponseblog/archive/2009/06/15.aspx"&gt;http://community.ca.com/blogs/casecurityresponseblog/archive/2009/06/15.aspx&lt;/a&gt;&lt;br /&gt;CVE References:&lt;br /&gt;CVE-2008-1232&lt;br /&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1232" target="_blank"&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1232&lt;/a&gt;&lt;br /&gt;OSVDB References: Pending&lt;br /&gt;&lt;a href="http://osvdb.org/" target="_blank"&gt;http://osvdb.org/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Changelog for this advisory:&lt;br /&gt;v1.0 - Initial Release&lt;br /&gt;&lt;br /&gt;Customers who require additional information should contact CA Technical Support at &lt;a href="https://support.ca.com"&gt;https://support.ca.com&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;For technical questions or comments related to this advisory, please send email to vuln AT ca DOT com.&lt;br /&gt;&lt;br /&gt;If you discover a vulnerability in CA products, please report your findings to the CA Product Vulnerability Response Team.&lt;br /&gt;&lt;a href="https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=177782%20"&gt;https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=177782 &lt;/a&gt;&lt;/p&gt;&lt;p&gt;The opinions and statements on this site are my own and do not necessarily reflect the opinions or policies of CA. &lt;br /&gt;&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email CA20090615-02%3a+CA+Service+Desk+Tomcat+Cross+Site+Scripting+Vulnerability" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/casecurityresponseblog/archive/2009/06/15/ca20090615-02-ca-service-desk-tomcat-cross-site-scripting-vulnerability.aspx&amp;subject=CA20090615-02%3a+CA+Service+Desk+Tomcat+Cross+Site+Scripting+Vulnerability"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/casecurityresponseblog/archive/2009/06/15/ca20090615-02-ca-service-desk-tomcat-cross-site-scripting-vulnerability.aspx&amp;title=CA20090615-02%3a+CA+Service+Desk+Tomcat+Cross+Site+Scripting+Vulnerability" title="Submit CA20090615-02%3a+CA+Service+Desk+Tomcat+Cross+Site+Scripting+Vulnerability to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/casecurityresponseblog/archive/2009/06/15/ca20090615-02-ca-service-desk-tomcat-cross-site-scripting-vulnerability.aspx&amp;phase=2" title="Submit CA20090615-02%3a+CA+Service+Desk+Tomcat+Cross+Site+Scripting+Vulnerability to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/casecurityresponseblog/archive/2009/06/15/ca20090615-02-ca-service-desk-tomcat-cross-site-scripting-vulnerability.aspx&amp;title=CA20090615-02%3a+CA+Service+Desk+Tomcat+Cross+Site+Scripting+Vulnerability" title="Submit CA20090615-02%3a+CA+Service+Desk+Tomcat+Cross+Site+Scripting+Vulnerability to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=2550" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CA20090615-02/default.aspx">CA20090615-02</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2008-1232/default.aspx">CVE-2008-1232</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Service+Desk/default.aspx">Service Desk</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/TEC489643/default.aspx">TEC489643</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category></item></channel></rss>