<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://community.ca.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>CA Community</title><link>http://community.ca.com/blogs/</link><description>Read submissions from a number of CA industry experts on topical subjects that can impact your bottom line</description><dc:language>en-US</dc:language><generator>CommunityServer 2007.1 (Build: 20917.1142)</generator><item><title>Who owns IT Governance, the Business or IT? </title><link>http://community.ca.com/blogs/theitgovernanceevangelist/archive/2008/05/09/who-owns-it-governance-the-business-or-it.aspx</link><pubDate>Fri, 09 May 2008 14:18:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1207</guid><dc:creator>Steve Romero</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Is IT Governance primarily a function of the business, or a function of IT?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Many organizations are misled by the label. Sure, IT enables IT Governance, but the ITG discipline is a means for the business to govern IT, to ensure IT is aligned, delivering value and appropriately managing risk, resources and performance. The business must govern IT just as it must govern every other important business function, such as Finance or Human Resources.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Recently I received affirmation that some organizations are coming around to this way of thinking.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;During a trip to Australia, I spent five days in three cities as the featured speaker in a seminar series entitled &amp;quot;Critical Components of Effective Project Management Offices (PMOs)&amp;quot;. While there, I visited with several organizations to discuss their IT Governance challenges.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;My very first meeting was with an IT leader from one of the government agencies located in Sydney. He wanted to meet with me to obtain a greater understanding of IT Governance. As he introduced me to his four colleagues, I was amazed to find that not one of them was from IT! They were all from the &amp;quot;business side&amp;quot; of the organization!&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This IT leader recognized the role of the business as a partner--if not leader--of IT Governance in their organization. He was hosting this discussion to provide his peers with critical insight into their IT Governance roles and responsibilities. We had a great meeting and they are now eager to work together to achieve the enterprise-wide goals of IT Governance.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;As I continue my travels evangelizing IT Governance, I expect the overwhelming majority of my audience will be members of IT. I look forward to the day when they are outnumbered by the real owners of IT Governance--the business partners IT serves.&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Who+owns+IT+Governance%2c+the+Business+or+IT%3f+" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/theitgovernanceevangelist/archive/2008/05/09/who-owns-it-governance-the-business-or-it.aspx&amp;subject=Who+owns+IT+Governance%2c+the+Business+or+IT%3f+"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/theitgovernanceevangelist/archive/2008/05/09/who-owns-it-governance-the-business-or-it.aspx&amp;title=Who+owns+IT+Governance%2c+the+Business+or+IT%3f+" title="Submit Who+owns+IT+Governance%2c+the+Business+or+IT%3f+ to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/theitgovernanceevangelist/archive/2008/05/09/who-owns-it-governance-the-business-or-it.aspx&amp;phase=2" title="Submit Who+owns+IT+Governance%2c+the+Business+or+IT%3f+ to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/theitgovernanceevangelist/archive/2008/05/09/who-owns-it-governance-the-business-or-it.aspx&amp;title=Who+owns+IT+Governance%2c+the+Business+or+IT%3f+" title="Submit Who+owns+IT+Governance%2c+the+Business+or+IT%3f+ to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=1207" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/theitgovernanceevangelist/archive/tags/IT+Governance/default.aspx">IT Governance</category><category domain="http://community.ca.com/blogs/theitgovernanceevangelist/archive/tags/Project+Portfolio+Management/default.aspx">Project Portfolio Management</category><category domain="http://community.ca.com/blogs/theitgovernanceevangelist/archive/tags/PPM/default.aspx">PPM</category></item><item><title>Mainframe = Kicking Technology??</title><link>http://community.ca.com/blogs/execio/archive/2008/05/07/mainframe-kicking-technology.aspx</link><pubDate>Wed, 07 May 2008 12:46:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1202</guid><dc:creator>Marcel Hartog</dc:creator><slash:comments>0</slash:comments><description>&lt;p class="MsoNormal" style="MARGIN:0cm 0cm 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;In an New York Times article of March 28&lt;sup&gt;th&lt;/sup&gt;, the words of Steward Alsop, who predicted that the last mainframe would be unplugged in 1996 were put in context.&lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0cm 0cm 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;The mainframe was use as one example how “old” technology proved to be a strong survivor together with Radio, railways and the most modern one, print media. All these “old” technologies were supposed to be replaced by new ones like television, cars &amp;amp; trucks and the Web respectively.&lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0cm 0cm 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;One of the conclusions is that, to survive, these “old” technologies all have some sort of enduring advantage that is not replaced by its “successor”. And for the mainframe, this typically was the rock-solid stability and security to run vital transactions, while at the same time it allowed companies to integrate “new technology” like the Web &amp;amp; SOA transactions.&lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0cm 0cm 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;The most important conclusion was that the business decisions matter most. People tend to overestimate the importance of technological innovation and underestimate the role of business judgment. “The rise and fall of technologies is mainly about business and not technological determinism”.&lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0cm 0cm 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;Too often, we allow ourselves to get overexcited about new technology, and so do our clients. As a software vendor, it is our responsibility to talk about that. With more than 30 years of experience, we need to demonstrate that we understand that it IS about the business. That is what sets CA apart as a company. We lived through the “near death experience” of the mainframe and we have seen the revival. We all understand why this happened, but we need to talk about it with our clients. Share our experience, talk business and become the advisor our clients expect us to be.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0cm 0cm 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;&lt;/font&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0cm 0cm 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;Like many, you are probably convinced that dinosaurs were wiped out long ago. The &amp;quot;new&amp;quot; climate better suited mammals, right? But smaller dino&amp;#39;s adapted and survived and today, more than 8,000 species of reptiles still exist, compared to about 5,400 species of mammals...&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0cm 0cm 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;&lt;/font&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0cm 0cm 0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;Like many, some of you are still convinced that the IBM mainframe is in it&amp;#39;s final days. But today, 90% of the Fortune 500 still runs their most important transactions on an IBM mainframe, using CA software to Manage &amp;amp; Secure it. &lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0cm 0cm 0pt;"&gt;&lt;a href="http://www.nytimes.com/2008/03/23/technology/23digi.html?_r=2&amp;amp;scp=2&amp;amp;sq=mainframe&amp;amp;st=nyt&amp;amp;oref=slogin&amp;amp;oref=slogin"&gt;&lt;font face="Times New Roman" size="3"&gt;http://www.nytimes.com/2008/03/23/technology/23digi.html?_r=2&amp;amp;scp=2&amp;amp;sq=mainframe&amp;amp;st=nyt&amp;amp;oref=slogin&amp;amp;oref=slogin&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Mainframe+%3d+Kicking+Technology%3f%3f" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/execio/archive/2008/05/07/mainframe-kicking-technology.aspx&amp;subject=Mainframe+%3d+Kicking+Technology%3f%3f"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/execio/archive/2008/05/07/mainframe-kicking-technology.aspx&amp;title=Mainframe+%3d+Kicking+Technology%3f%3f" title="Submit Mainframe+%3d+Kicking+Technology%3f%3f to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/execio/archive/2008/05/07/mainframe-kicking-technology.aspx&amp;phase=2" title="Submit Mainframe+%3d+Kicking+Technology%3f%3f to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/execio/archive/2008/05/07/mainframe-kicking-technology.aspx&amp;title=Mainframe+%3d+Kicking+Technology%3f%3f" title="Submit Mainframe+%3d+Kicking+Technology%3f%3f to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=1202" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/execio/archive/tags/Mainframe/default.aspx">Mainframe</category></item><item><title>Run Book Automation (RBA) - A Crucial Component to any DCA Initiative</title><link>http://community.ca.com/blogs/cadatacenterautomationblog/archive/2008/05/02/run-book-automation-rba-a-crucial-component-of-any-dca-initiative.aspx</link><pubDate>Fri, 02 May 2008 17:38:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1196</guid><dc:creator>Ben Scheerer</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;When talking about automation in the data center we think about the use of tools and processes to coordinate and execute on activities with hopes to reduce complexity, errors, labor, and costs while increasing productivity.&amp;nbsp; To further automation goals, we have to consider outside influences to the data center as well as existing software tools and processes that are already in place.&amp;nbsp; It is likely that any given data center environment consists of a spattering of technologies across multiple platforms and vendors.&amp;nbsp; This platform/vendor mix results in increased data center complexity and can best be dealt with by the proper tools for integrating and orchestrating IT processes across IT silos, regardless of the vendor or vendor specific platforms.&amp;nbsp; Integration is the key concept and Run Book Automation (RBA), aka IT Process Automation (ITPA), is a critical component in any automation initiative.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Recently CA &lt;a href="http://ca.com/us/press/release.aspx?cid=174301" target="_blank" title="CA and Opalis Partner to Deliver IT Process Automation Solutions for the Data Center"&gt;announced an OEM agreement&lt;/a&gt; with Opalis, a leader in RBA tools.&amp;nbsp; This partnership will allow CA to take advantage of an already established, industry leading technology as well as to further enhance its integration points for CA software.&amp;nbsp; But, this does not preclude the existing integration points across other vendor platforms, nor Opalis&amp;#39; continued R&amp;amp;D efforts as a vendor neutral solution.&lt;/p&gt;&lt;p&gt;So what does RBA bring to the table?&amp;nbsp; &amp;quot;IT process automation provides the ability to launch a process in context and pass information from one process to the next with a level of accuracy far superior to that of any entry into an administrator interface. Solutions in this space replace the scripting of application production rules (run book).&amp;quot;&amp;nbsp; The demand for process automation is driven from senior IT leadership looking to: Increase IT operations efficiencies, especially around the adoption of best practices, increase IT agility and proving IT operations&amp;#39; accountability to the business. &amp;nbsp;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;You may have noticed a theme of process automation, coupled with best practices?&amp;nbsp; Yes, RBA/ITPA can help achieve higher levels of process maturity, notably those specified in best practices frameworks, such as ITIL.&amp;nbsp; IT process automation can easily assist IT Operations in automating those processes that are established and repeatable, while setting the stage for future process design and improvements.&amp;nbsp; As IT Operations continues to identify, define and improve on IT processes, ITPA serves as a fundamental step in furthering their goals.&lt;br /&gt;

&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Run+Book+Automation+(RBA)+-+A+Crucial+Component+to+any+DCA+Initiative" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/cadatacenterautomationblog/archive/2008/05/02/run-book-automation-rba-a-crucial-component-of-any-dca-initiative.aspx&amp;subject=Run+Book+Automation+(RBA)+-+A+Crucial+Component+to+any+DCA+Initiative"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/cadatacenterautomationblog/archive/2008/05/02/run-book-automation-rba-a-crucial-component-of-any-dca-initiative.aspx&amp;title=Run+Book+Automation+(RBA)+-+A+Crucial+Component+to+any+DCA+Initiative" title="Submit Run+Book+Automation+(RBA)+-+A+Crucial+Component+to+any+DCA+Initiative to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/cadatacenterautomationblog/archive/2008/05/02/run-book-automation-rba-a-crucial-component-of-any-dca-initiative.aspx&amp;phase=2" title="Submit Run+Book+Automation+(RBA)+-+A+Crucial+Component+to+any+DCA+Initiative to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/cadatacenterautomationblog/archive/2008/05/02/run-book-automation-rba-a-crucial-component-of-any-dca-initiative.aspx&amp;title=Run+Book+Automation+(RBA)+-+A+Crucial+Component+to+any+DCA+Initiative" title="Submit Run+Book+Automation+(RBA)+-+A+Crucial+Component+to+any+DCA+Initiative to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=1196" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/cadatacenterautomationblog/archive/tags/automation/default.aspx">automation</category><category domain="http://community.ca.com/blogs/cadatacenterautomationblog/archive/tags/data+center+complexity/default.aspx">data center complexity</category><category domain="http://community.ca.com/blogs/cadatacenterautomationblog/archive/tags/data+center+automation/default.aspx">data center automation</category><category domain="http://community.ca.com/blogs/cadatacenterautomationblog/archive/tags/DCA/default.aspx">DCA</category><category domain="http://community.ca.com/blogs/cadatacenterautomationblog/archive/tags/ca+dca/default.aspx">ca dca</category><category domain="http://community.ca.com/blogs/cadatacenterautomationblog/archive/tags/ITIL/default.aspx">ITIL</category><category domain="http://community.ca.com/blogs/cadatacenterautomationblog/archive/tags/RBA/default.aspx">RBA</category><category domain="http://community.ca.com/blogs/cadatacenterautomationblog/archive/tags/run+book+automation/default.aspx">run book automation</category><category domain="http://community.ca.com/blogs/cadatacenterautomationblog/archive/tags/IT+Process+Management/default.aspx">IT Process Management</category></item><item><title>Straight Talk About Project Failures  </title><link>http://community.ca.com/blogs/theitgovernanceevangelist/archive/2008/04/28/straight-talk-about-project-failures.aspx</link><pubDate>Mon, 28 Apr 2008 16:46:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1150</guid><dc:creator>Steve Romero</dc:creator><slash:comments>2</slash:comments><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I recently recorded a &lt;a href="http://go.techtarget.com/r/3514348/521899"&gt;podcast&lt;/a&gt; with Tim Jennings, Research Director with the Butler Group. The Butler group completed a study finding that 50% of IT projects fail. My brief discussion with Tim focuses on this issue and highlights best practices for guidance on implementing successful project management initiatives in IT organizations.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I find the topic of IT project failure rates interesting and compelling. I speak frequently on the topic, citing numerous studies with varying conclusions. The most optimistic figure I have encountered is 40% and the most pessimistic came from a major analyst study in 2006 that put the IT Project failure rate at 78%!&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I thought the 78% number was a bit sensationalistic. I think the number is closer to 60%, which is still quite alarming. Regardless of the number, whenever I talk about the rate of project failures, I think it is necessary to define what I mean by project failure. I do so in the Podcast and was surprised to find that Tim Jennings and the Butler Group agreed with my characterization because, frankly, I thought I was being militant about the subject.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I contend if a project takes longer than we scheduled, it is a failure. If a project costs more than we said it was going to cost, it is a failure. If a project does not deliver the value we said it was going to deliver, then it is a failure. Keep in mind, I am allowing for the variance thresholds agreed upon at the onset of the project. If a project is not completed within those thresholds, it is a failure. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I have shared this view with countless people in my travels. I have found the majority of them find my definition of project failure to be too harsh and uncompromising. I am not surprised by their reaction. In fact, it is their reaction that provides some insight as to why so many IT projects fail in the first place.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;We take for granted that IT projects take longer than we think they will. We expect them to cost more than we thought they would cost. It is not realistic to believe we can deliver everything we said the project would deliver. In fact, we have the reasons for this at the ready. Do any of these statements sound familiar?&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;It is too hard to estimate the time and cost&lt;/li&gt;
&lt;li&gt;We didn&amp;#39;t have enough time to plan&lt;/li&gt;
&lt;li&gt;IT projects are very complex and inherently unpredictable&lt;/li&gt;
&lt;li&gt;The customer didn&amp;#39;t know what they wanted&lt;/li&gt;
&lt;li&gt;Our requirements process is terrible&lt;/li&gt;
&lt;li&gt;We don&amp;#39;t have enough resources to get the work done&lt;/li&gt;
&lt;li&gt;Production emergencies adversely affected project progress&lt;/li&gt;
&lt;li&gt;We didn&amp;#39;t have the information we needed&lt;/li&gt;
&lt;li&gt;Scope creep!!!&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I am sure you have heard all of these and more. We have grown accustomed, if not complacent to IT projects taking too long, costing too much, and not delivering as expected. Couple that with the human tendency to wince at the word &amp;quot;failure&amp;quot; and it is easy to understand why people judge my interpretation of project failure to be too harsh if not outright unreasonable.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;So how do we change the project failure rate? Anyone who has met me or read my blog knows my answer is good IT Governance and more specifically, good Project and Portfolio Management. Tim Jennings of the Butler Group offers some great insights and ideas so I urge you to listen to our podcast. But first, let&amp;#39;s get everyone to agree on our definition of project failure. Let&amp;#39;s call the slipped schedules, cost overruns, and missed deliverables what they are - failures. Only then will we aggressively and relentlessly pursue the solutions that will ultimately ensure project success. &lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Straight+Talk+About+Project+Failures++" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/theitgovernanceevangelist/archive/2008/04/28/straight-talk-about-project-failures.aspx&amp;subject=Straight+Talk+About+Project+Failures++"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/theitgovernanceevangelist/archive/2008/04/28/straight-talk-about-project-failures.aspx&amp;title=Straight+Talk+About+Project+Failures++" title="Submit Straight+Talk+About+Project+Failures++ to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/theitgovernanceevangelist/archive/2008/04/28/straight-talk-about-project-failures.aspx&amp;phase=2" title="Submit Straight+Talk+About+Project+Failures++ to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/theitgovernanceevangelist/archive/2008/04/28/straight-talk-about-project-failures.aspx&amp;title=Straight+Talk+About+Project+Failures++" title="Submit Straight+Talk+About+Project+Failures++ to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=1150" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/theitgovernanceevangelist/archive/tags/IT+Governance/default.aspx">IT Governance</category><category domain="http://community.ca.com/blogs/theitgovernanceevangelist/archive/tags/Project+Portfolio+Management/default.aspx">Project Portfolio Management</category><category domain="http://community.ca.com/blogs/theitgovernanceevangelist/archive/tags/PPM/default.aspx">PPM</category></item><item><title>The Invisible Mainframe</title><link>http://community.ca.com/blogs/execio/archive/2008/04/25/the-invisible-mainframe.aspx</link><pubDate>Fri, 25 Apr 2008 13:53:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1144</guid><dc:creator>Reg Harbeck</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&amp;quot;Housework is something nobody notices unless you don&amp;#39;t do it.&amp;quot;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;quot;The squeaky wheel gets the grease.&amp;quot;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;quot;Out of sight, out of mind.&amp;quot;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;What do all of these quotes have to do with the mainframe? Two words: It works.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Who&amp;#39;d have ever thought that would be a problem?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Just think: over four decades of building and refining the ultimate business machine, and very few people seem to know or care that it even exists, let alone that it&amp;#39;s still effectively running the world economy.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;After all, 70% of organizations and governments are still running critical applications on the mainframe per the Butler Group (see &lt;a href="http://www.informationweek.com/story/showArticle.jhtml?articleID=196900665"&gt;http://www.informationweek.com/story/showArticle.jhtml?articleID=196900665&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;That&amp;#39;s a pretty spectacular number for a machine that doesn&amp;#39;t appear to exist.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The funny thing is, it actually could have been argued to be a good strategy to keep the mainframe out of sight - less threat of being a target, given how important it is.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The only problem is, the strategy (if that&amp;#39;s what it was) worked so well that the management of many organizations that rely on mainframes don&amp;#39;t seem to realize its importance either. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;And that&amp;#39;s a problem - after all, the cost of the mainframe can seem quite large when its value is not apparent.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Fortunately, some of the largest organizations on earth seem to have recognized the value of their mainframes and increased their commitment to this platform in a very big way. That would certainly explain its spectacular growth over the past decade.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;But what about the rest of the mainframe world - those organizations that haven&amp;#39;t &amp;quot;seen the light&amp;quot;? Often, they&amp;#39;ve curtailed investment in this &amp;quot;goose that lays the golden egg&amp;quot; and even tried to move to narrower platforms for the sake of perceived savings.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I think the time has come to wake them up. In fact, if the management of an organization doesn&amp;#39;t see the value of their mainframe, they don&amp;#39;t have the information necessary to run their businesses properly.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;So, the question is: who&amp;#39;s going to do it?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The answer? Us! You and me. It&amp;#39;s time for us to stop being apologetic about the mainframe and stand up and let people know how important and valuable it is - and particularly people who ought to know in order to do their jobs properly.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;So, my question for you is: what can you do to help your management appreciate the critical importance of your mainframe to your organization&amp;#39;s success?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I look forward to your thoughts!&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email The+Invisible+Mainframe" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/execio/archive/2008/04/25/the-invisible-mainframe.aspx&amp;subject=The+Invisible+Mainframe"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/execio/archive/2008/04/25/the-invisible-mainframe.aspx&amp;title=The+Invisible+Mainframe" title="Submit The+Invisible+Mainframe to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/execio/archive/2008/04/25/the-invisible-mainframe.aspx&amp;phase=2" title="Submit The+Invisible+Mainframe to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/execio/archive/2008/04/25/the-invisible-mainframe.aspx&amp;title=The+Invisible+Mainframe" title="Submit The+Invisible+Mainframe to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=1144" width="1" height="1"&gt;</description></item><item><title>Automatic Patch-Based Exploit Generation</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/24/automatic-patch-based-exploit-generation.aspx</link><pubDate>Thu, 24 Apr 2008 20:27:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1143</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;The &lt;a href="http://lists.grok.org.uk/pipermail/full-disclosure/" target="_blank"&gt;Full-Disclosure mailing list&lt;/a&gt; is good for interesting, and often humorous, content on a daily basis.&amp;nbsp; The highlight of the week last week was a link to a paper entitled &lt;a href="http://www.cs.cmu.edu/%7Edbrumley/pubs/apeg.html" target="_blank"&gt;&amp;quot;Automatic Patch-Based Exploit Generation&amp;quot;&lt;/a&gt;, by David Brumley, Pongsin Poosankam, Dawn Song, and Jiang Zheng.&amp;nbsp; From the abstract ... &amp;quot;In this paper, we propose techniques for automatic patch-based exploit generation, and show that our techniques can automatically generate exploits for vulnerable programs based upon patches provided via Windows Update. [...] Attackers can simply wait for a patch to be released, use these techniques, and with reasonable chance, produce a working exploit within seconds. Coupled with a worm, all vulnerable hosts could be compromised before most are even aware a patch is available, let alone download it.&amp;quot;&amp;nbsp; 2008 is going to be an interesting year for security enthusiasts.&lt;/p&gt;&lt;p&gt;Edited to add:&amp;nbsp; Halvar.Flake has &lt;a href="http://addxorrol.blogspot.com/2008/04/patch-obfuscation-etc.html" target="_blank"&gt;a blog post with very insightful commentary&lt;/a&gt; on the paper.&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Automatic+Patch-Based+Exploit+Generation" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/24/automatic-patch-based-exploit-generation.aspx&amp;subject=Automatic+Patch-Based+Exploit+Generation"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/24/automatic-patch-based-exploit-generation.aspx&amp;title=Automatic+Patch-Based+Exploit+Generation" title="Submit Automatic+Patch-Based+Exploit+Generation to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/24/automatic-patch-based-exploit-generation.aspx&amp;phase=2" title="Submit Automatic+Patch-Based+Exploit+Generation to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/24/automatic-patch-based-exploit-generation.aspx&amp;title=Automatic+Patch-Based+Exploit+Generation" title="Submit Automatic+Patch-Based+Exploit+Generation to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=1143" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/exploit/default.aspx">exploit</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/patch/default.aspx">patch</category></item><item><title>Recent news and how IAM could have helped</title><link>http://community.ca.com/blogs/iam/archive/2008/04/23/recent-news-and-how-iam-could-have-helped.aspx</link><pubDate>Wed, 23 Apr 2008 15:27:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1142</guid><dc:creator>Merritt Maxim</dc:creator><slash:comments>3</slash:comments><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;As information security professionals, we are always interested in finding stories or anecdotes to help make a point or to further educate people on the importance and need for strong information security. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;An item grabbing US headlines recently was the story concerning the inappropriate access to the passport files of the 3 major US presidential candidates, Barack Obama, Hillary Clinton, and John McCain:&amp;nbsp; &lt;a title="http://www.cnn.com/2008/POLITICS/03/21/obama.passport/index.html" href="http://www.cnn.com/2008/POLITICS/03/21/obama.passport/index.html"&gt;http://www.cnn.com/2008/POLITICS/03/21/obama.passport/index.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;At first glance, this story did not seem particularly interesting, especially when I realized that a passport file contains basic statistics such as birth date, height, weight and eye color-information that is already widely available for such public figures as these. &amp;nbsp;Other than the applicant&amp;#39;s social security number, there is no real significant private data in these files. &amp;nbsp;Clearly, this was purely a case of random snooping by curious employees, much like the similar incident when people accessed the medical files of actor George Clooney&amp;#39;s and Britney Spears. &lt;a title="http://abcnews.go.com/US/story?id=4498155&amp;amp;page=1" href="http://abcnews.go.com/US/story?id=4498155&amp;amp;page=1"&gt;http://abcnews.go.com/US/story?id=4498155&amp;amp;page=1&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;But, as more details around this story emerged this week, my interest in the story evolved from that of a concerned citizen to that of an information security professional.&amp;nbsp; According to State Department spokesman Sean McCormack, Senator Obama&amp;#39;s files had been viewed three times by contractors working for the agency starting in January.&amp;nbsp; In Clinton&amp;#39;s case, a trainee accessed her files in 2007.&amp;nbsp; McCormack said two of the contractors in the Obama case were &amp;quot;low-level&amp;quot; personnel and the other was in a mid-level position with no management role.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Now, let&amp;#39;s reconsider this situation. &amp;nbsp;These were not full-time employees doing this, but contractors and trainees who do not even work for the State Department. &amp;nbsp;And while there is nothing wrong with hiring contractors (we have since learned that the State Department hires contractors to design, build and maintain their systems), this incident raises questions about how well (or not) the State Department is provisioning access to data, application and systems. &amp;nbsp;In this situation, it is not just that it was contractors that accessed the files, but that the contractors themselves were ‘low-level&amp;#39; personnel. &amp;nbsp;Unfortunately, we do not know the specific IT architectural details of the passport system, but the fact that contractors in non-management roles were able to access any and all data for highly public figures suggests that the passport system suffers from a monolithic &amp;quot;access for all&amp;quot; security model.&amp;nbsp; Unfortunately, this is often the case in legacy systems that were designed and deployed decades ago with no elaborate security access control mechanisms.&amp;nbsp; In the initial years of operation, such systems are only accessed by a small defined group of individuals. &amp;nbsp;Thus, auditing and controlling access to information is easy. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;But, as such systems become more widespread, the number of users requesting access increases rapidly. &amp;nbsp;And in the case of a high value application like the passport application system, it cannot be taken off-line over an extended period of time so that developers can create a more robust security model for the application.&amp;nbsp; As a result, this &amp;quot;access for all&amp;quot; model becomes the standard, meaning that everyone ends up with the same level of access, regardless of responsibility, title or function.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Situations like this scream out for identity and role management. &amp;nbsp;These types of systems empower organizations to create security and access models specific for individual roles and functions. &amp;nbsp;In the State Department case, a separate role category of ‘contractor&amp;#39; could be created and within the contractor category, certain roles such as trainee, manager etc. could be created with the level of security access commensurate with each role.&amp;nbsp; Such systems deliver two levels of benefits.&amp;nbsp; One, they greatly simplify management and administrative operations because the IT team only needs to manage dozens of roles instead of hundreds of individuals. &amp;nbsp;And secondly, identity management systems can reduce risk by ensuring that users&amp;#39; access to information is limited to their actual business function. &amp;nbsp;Had such systems been in place at the State Department, it is unlikely that these kinds of breaches would have even happened.&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Recent+news+and+how+IAM+could+have+helped" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/iam/archive/2008/04/23/recent-news-and-how-iam-could-have-helped.aspx&amp;subject=Recent+news+and+how+IAM+could+have+helped"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/iam/archive/2008/04/23/recent-news-and-how-iam-could-have-helped.aspx&amp;title=Recent+news+and+how+IAM+could+have+helped" title="Submit Recent+news+and+how+IAM+could+have+helped to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/iam/archive/2008/04/23/recent-news-and-how-iam-could-have-helped.aspx&amp;phase=2" title="Submit Recent+news+and+how+IAM+could+have+helped to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/iam/archive/2008/04/23/recent-news-and-how-iam-could-have-helped.aspx&amp;title=Recent+news+and+how+IAM+could+have+helped" title="Submit Recent+news+and+how+IAM+could+have+helped to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=1142" width="1" height="1"&gt;</description></item><item><title>CA ARCserve Backup r12 and CA Secure Content Manager r8 vulnerabilities</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/21/ca-arcserve-backup-r12-and-ca-secure-content-manager-r8-vulnerabilities.aspx</link><pubDate>Mon, 21 Apr 2008 23:10:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1134</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;CA is currently investigating vulnerability reports concerning CA ARCserve Backup r12 and CA Secure Content Manager r8 that were published publicly on 4/17/08 and 4/18/08 respectively. CA will issue an advisory if and when the reports have been verified.&amp;nbsp;&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email CA+ARCserve+Backup+r12+and+CA+Secure+Content+Manager+r8+vulnerabilities" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/21/ca-arcserve-backup-r12-and-ca-secure-content-manager-r8-vulnerabilities.aspx&amp;subject=CA+ARCserve+Backup+r12+and+CA+Secure+Content+Manager+r8+vulnerabilities"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/21/ca-arcserve-backup-r12-and-ca-secure-content-manager-r8-vulnerabilities.aspx&amp;title=CA+ARCserve+Backup+r12+and+CA+Secure+Content+Manager+r8+vulnerabilities" title="Submit CA+ARCserve+Backup+r12+and+CA+Secure+Content+Manager+r8+vulnerabilities to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/21/ca-arcserve-backup-r12-and-ca-secure-content-manager-r8-vulnerabilities.aspx&amp;phase=2" title="Submit CA+ARCserve+Backup+r12+and+CA+Secure+Content+Manager+r8+vulnerabilities to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/21/ca-arcserve-backup-r12-and-ca-secure-content-manager-r8-vulnerabilities.aspx&amp;title=CA+ARCserve+Backup+r12+and+CA+Secure+Content+Manager+r8+vulnerabilities" title="Submit CA+ARCserve+Backup+r12+and+CA+Secure+Content+Manager+r8+vulnerabilities to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=1134" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Secure+Content+Manager/default.aspx">Secure Content Manager</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/ARCserve+Backup/default.aspx">ARCserve Backup</category></item><item><title>Liberty Alliance Workshop at the RSA Conference Drives Home the Point that Identity Federation is Entering the IT Security Mainstream</title><link>http://community.ca.com/blogs/iam/archive/2008/04/17/liberty-alliance-workshop-at-the-rsa-conference-drives-home-the-point-that-identity-federation-is-entering-the-it-security-mainstream.aspx</link><pubDate>Thu, 17 Apr 2008 13:31:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1123</guid><dc:creator>Matthew Gardiner</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I recently returned from a week at the RSA Conference which is somewhat of an annual pilgrimage for IT security people that takes place in the heart of San Francisco in the Moscone Center.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.rsaconference.com/2008/US/home.aspx"&gt;http://www.rsaconference.com/2008/US/home.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Even though the Olympic flame relay was also in town on its only stop in North America on its worldwide tour, we RSA Conference attendees stayed focused on IT security. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://edition.cnn.com/2008/US/04/08/us.olympic.torch/index.html"&gt;http://edition.cnn.com/2008/US/04/08/us.olympic.torch/index.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;As I arrived in San Francisco on the Sunday before the start of the conference, one question on my mind was where are we in the adoption of identity federation?&amp;nbsp; This is a question I get asked a lot so I am always looking for evidence supporting one view or another. &amp;nbsp;So I wanted to find out how interested the average RSA Conference attendee was in the topic of federation?&amp;nbsp; This would certainly be a valid data point to help answer the larger question.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Fortunately I had a great way to gauge that because the very next day on the afternoon of &amp;quot;workshop monday&amp;quot; at the start of the RSA Conference, the Liberty Alliance was having a half-day workshop entitled, &amp;quot;Identity Federation &amp;amp; Web Services: Happening Today - Enabling Tomorrow&amp;quot;.&amp;nbsp; Certainly one measure of interest and adoption can be taken from the nearly 500 people who registered and attended this workshop.&amp;nbsp; To see the slides from all of the presentations from this workshop please go to the Liberty Alliance Web site here:&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://projectliberty.org/liberty/resource_center/presentations_webcasts"&gt;http://projectliberty.org/liberty/resource_center/presentations_webcasts&lt;/a&gt;.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;One of the key points of this workshop was to show interested RSA Conference attendees how the use of standards-based identity federation technologies can provide immediate business value as well as prepare the organization to thrive in a heavily federated and trust-based world that is rapidly descending on us in the form of SaaS, identity as a service, application outsourcing, user centric identity or whatever terminology or perspective fits your view of the world.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;CA was fortunate to have two excellent federation customer case studies presented during the event, the first one from BT&amp;#39;s Chief Security Architect, Robert Temple, in which he discussed their success in extending their Web security infrastructure to enable browser-federation with many partners of BT.&amp;nbsp; The second CA customer case study session was from Chris Sharp of MEDecision in which he discussed the key enabling role of a centralized, policy-based security service for SOA &amp;amp; Web services based applications.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;My personal perspective is that federation in its broadest sense is now entering mainstream usage.&amp;nbsp; Will it solve all identity related problems that came before it?&amp;nbsp; Of course not.&amp;nbsp; But it has proven itself to be a valuable tool when applied by experienced practitioners to the right project.&amp;nbsp; To me that is a sign that mainstream, thought not necessarily ubiquitous usage, is currently unfolding.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Liberty+Alliance+Workshop+at+the+RSA+Conference+Drives+Home+the+Point+that+Identity+Federation+is+Entering+the+IT+Security+Mainstream" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/iam/archive/2008/04/17/liberty-alliance-workshop-at-the-rsa-conference-drives-home-the-point-that-identity-federation-is-entering-the-it-security-mainstream.aspx&amp;subject=Liberty+Alliance+Workshop+at+the+RSA+Conference+Drives+Home+the+Point+that+Identity+Federation+is+Entering+the+IT+Security+Mainstream"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/iam/archive/2008/04/17/liberty-alliance-workshop-at-the-rsa-conference-drives-home-the-point-that-identity-federation-is-entering-the-it-security-mainstream.aspx&amp;title=Liberty+Alliance+Workshop+at+the+RSA+Conference+Drives+Home+the+Point+that+Identity+Federation+is+Entering+the+IT+Security+Mainstream" title="Submit Liberty+Alliance+Workshop+at+the+RSA+Conference+Drives+Home+the+Point+that+Identity+Federation+is+Entering+the+IT+Security+Mainstream to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/iam/archive/2008/04/17/liberty-alliance-workshop-at-the-rsa-conference-drives-home-the-point-that-identity-federation-is-entering-the-it-security-mainstream.aspx&amp;phase=2" title="Submit Liberty+Alliance+Workshop+at+the+RSA+Conference+Drives+Home+the+Point+that+Identity+Federation+is+Entering+the+IT+Security+Mainstream to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/iam/archive/2008/04/17/liberty-alliance-workshop-at-the-rsa-conference-drives-home-the-point-that-identity-federation-is-entering-the-it-security-mainstream.aspx&amp;title=Liberty+Alliance+Workshop+at+the+RSA+Conference+Drives+Home+the+Point+that+Identity+Federation+is+Entering+the+IT+Security+Mainstream" title="Submit Liberty+Alliance+Workshop+at+the+RSA+Conference+Drives+Home+the+Point+that+Identity+Federation+is+Entering+the+IT+Security+Mainstream to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=1123" width="1" height="1"&gt;</description></item><item><title>Manage IT Governance Components in an IT Governance Context </title><link>http://community.ca.com/blogs/theitgovernanceevangelist/archive/2008/04/16/manage-it-governance-components-in-an-it-governance-context.aspx</link><pubDate>Wed, 16 Apr 2008 19:45:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1120</guid><dc:creator>Steve Romero</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I just finished studying an analyst report entitled &amp;quot;The State of IT Governance In North American and European Enterprises.&amp;quot; You already know that almost anything about IT Governance excites me, with an analyst report about my favorite topic high on the list. But, while there was certainly a lot of compelling data in the report, I was left wanting more. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The study focused on 8 areas: Strategic Positioning, The Perception of IT In The Enterprise, Standardization, How IT Is Structured, IT Planning, Architecture and The Role Of R&amp;amp;D In IT, Managing Vendors, and Managing Projects. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;While these areas do fall within IT Governance, what I was looking for was information on enterprise efforts to establish IT Governance, or enterprise progress in regards to IT Governance initiatives. I was interested in the 8 areas, but more interested in how they were managed as part of a larger IT Governance initiative. Were the enterprises surveyed even aware that these were the major areas of IT Governance?&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I continue to believe very few organizations adequately understand the nature and discipline of IT Governance. Until enterprises recognize the areas of the Forrester report as subsets of IT Governance, they have little chance of fully achieving the very specific goals, and realizing the very specific benefits, of IT Governance.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;But I am hopeful that the day will come. And I am anxiously awaiting the next IT Governance analyst report in my inbox. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Manage+IT+Governance+Components+in+an+IT+Governance+Context+" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/theitgovernanceevangelist/archive/2008/04/16/manage-it-governance-components-in-an-it-governance-context.aspx&amp;subject=Manage+IT+Governance+Components+in+an+IT+Governance+Context+"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/theitgovernanceevangelist/archive/2008/04/16/manage-it-governance-components-in-an-it-governance-context.aspx&amp;title=Manage+IT+Governance+Components+in+an+IT+Governance+Context+" title="Submit Manage+IT+Governance+Components+in+an+IT+Governance+Context+ to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/theitgovernanceevangelist/archive/2008/04/16/manage-it-governance-components-in-an-it-governance-context.aspx&amp;phase=2" title="Submit Manage+IT+Governance+Components+in+an+IT+Governance+Context+ to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/theitgovernanceevangelist/archive/2008/04/16/manage-it-governance-components-in-an-it-governance-context.aspx&amp;title=Manage+IT+Governance+Components+in+an+IT+Governance+Context+" title="Submit Manage+IT+Governance+Components+in+an+IT+Governance+Context+ to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=1120" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/theitgovernanceevangelist/archive/tags/IT+Governance/default.aspx">IT Governance</category></item><item><title>CA DSM gui_cm_ctrls ActiveX Control Vulnerability</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/16/ca-dsm-gui-cm-ctrls-activex-control-vulnerability.aspx</link><pubDate>Wed, 16 Apr 2008 15:34:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1118</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;On April 15th, 2008 CA published a security notice to address a vulnerability in CA products that implement the DSM gui_cm_ctrls ActiveX control.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Title: CA DSM gui_cm_ctrls ActiveX Control Vulnerability&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;CA Advisory Date: 2008-04-15&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Reported By: Greg Linares of eEye Digital Security&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Impact: A remote attacker can execute arbitrary code or cause a denial of service condition.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Summary: CA products that implement the DSM gui_cm_ctrls ActiveX control contain a vulnerability that can allow a remote attacker to cause a denial of service or execute arbitrary code. The vulnerability, CVE-2008-1786, is due to insufficient verification of function arguments by the gui_cm_ctrls control. An attacker can execute arbitrary code under the context of the user running the web browser.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Mitigating Factors: For BrightStor ARCserve Backup for Laptops &amp;amp; Desktops, only the server installation is affected. Client installations are not affected. For CA Desktop Management Suite, Unicenter Desktop Management Bundle, Unicenter Asset Management, Unicenter Software Delivery and Unicenter Remote Control, only the Managers and DSM Explorers are affected. Scalability Servers and Agents are not affected.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Severity: CA has given these vulnerabilities a maximum risk rating of High.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Affected Products:&lt;br /&gt;BrightStor ARCServe Backup for Laptops and Desktops r11.5&lt;br /&gt;CA Desktop Management Suite r11.2 C2&lt;br /&gt;CA Desktop Management Suite r11.2 C1&lt;br /&gt;CA Desktop Management Suite r11.2a&lt;br /&gt;CA Desktop Management Suite r11.2&lt;br /&gt;CA Desktop Management Suite r11.1 (GA, a, C1)&lt;br /&gt;Unicenter Desktop Management Bundle r11.2 C2&lt;br /&gt;Unicenter Desktop Management Bundle r11.2 C1&lt;br /&gt;Unicenter Desktop Management Bundle r11.2a&lt;br /&gt;Unicenter Desktop Management Bundle r11.2&lt;br /&gt;Unicenter Desktop Management Bundle r11.1 (GA, a, C1)&lt;br /&gt;Unicenter Asset Management r11.2 C2&lt;br /&gt;Unicenter Asset Management r11.2 C1&lt;br /&gt;Unicenter Asset Management r11.2a&lt;br /&gt;Unicenter Asset Management r11.2 &lt;br /&gt;Unicenter Asset Management r11.1 (GA, a, C1)&lt;br /&gt;Unicenter Software Delivery r11.2 C2&lt;br /&gt;Unicenter Software Delivery r11.2 C1&lt;br /&gt;Unicenter Software Delivery r11.2a&lt;br /&gt;Unicenter Software Delivery r11.2 &lt;br /&gt;Unicenter Software Delivery r11.1 (GA, a, C1)&lt;br /&gt;Unicenter Remote Control r11.2 C2&lt;br /&gt;Unicenter Remote Control r11.2 C1&lt;br /&gt;Unicenter Remote Control r11.2a&lt;br /&gt;Unicenter Remote Control r11.2 &lt;br /&gt;Unicenter Remote Control r11.1 (GA, a, C1)&lt;br /&gt;CA Desktop and Server Management r11.2 C2&lt;br /&gt;CA Desktop and Server Management r11.2 C1&lt;br /&gt;CA Desktop and Server Management r11.2a&lt;br /&gt;CA Desktop and Server Management r11.2&lt;br /&gt;CA Desktop and Server Management r11.1 (GA, a, C1)&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Affected Platforms:&lt;br /&gt;Windows&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Status and Recommendation:&lt;br /&gt;&lt;br /&gt;CA has provided the following updates to address the vulnerabilities. &lt;br /&gt;&lt;br /&gt;BrightStor ARCserve Backup for Laptops and Desktops r11.5:&lt;br /&gt;QI96333&lt;br /&gt;&lt;br /&gt;CA Desktop Management Suite for Windows r11.1 (GA, a, C1),&lt;br /&gt;Unicenter Desktop Management Bundle r11.1 (GA, a, C1),&lt;br /&gt;Unicenter Asset Management r11.1 (GA, a, C1),&lt;br /&gt;Unicenter Software Delivery r11.1 (GA, a, C1),&lt;br /&gt;Unicenter Remote Control r11.1 (GA, a, C1):&lt;br /&gt;QO96283&lt;br /&gt;&lt;br /&gt;CA Desktop Management Suite for Windows r11.2a,&lt;br /&gt;Unicenter Desktop Management Bundle r11.2a,&lt;br /&gt;Unicenter Asset Management r11.2a,&lt;br /&gt;Unicenter Software Delivery r11.2a,&lt;br /&gt;Unicenter Remote Control r11.2a:&lt;br /&gt;QO96286&lt;br /&gt;&lt;br /&gt;CA Desktop Management Suite for Windows r11.2,&lt;br /&gt;Unicenter Desktop Management Bundle r11.2,&lt;br /&gt;Unicenter Asset Management r11.2,&lt;br /&gt;Unicenter Software Delivery r11.2,&lt;br /&gt;Unicenter Remote Control r11.2:&lt;br /&gt;QO96285&lt;br /&gt;&lt;br /&gt;CA Desktop Management Suite for Windows r11.2 C1,&lt;br /&gt;Unicenter Desktop Management Bundle r11.2 C1,&lt;br /&gt;Unicenter Asset Management r11.2 C1,&lt;br /&gt;Unicenter Software Delivery r11.2 C1,&lt;br /&gt;Unicenter Remote Control r11.2 C1:&lt;br /&gt;QO96284&lt;br /&gt;&lt;br /&gt;CA Desktop Management Suite for Windows r11.2 C2,&lt;br /&gt;Unicenter Desktop Management Bundle r11.2 C2,&lt;br /&gt;Unicenter Asset Management r11.2 C2,&lt;br /&gt;Unicenter Software Delivery r11.2 C2,&lt;br /&gt;Unicenter Remote Control r11.2 C2:&lt;br /&gt;QO99084&lt;br /&gt;&lt;br /&gt;CA Desktop and Server Management r11.2 C2:&lt;br /&gt;QO99080&lt;br /&gt;&lt;br /&gt;CA Desktop and Server Management r11.2 C1:&lt;br /&gt;QO96288&lt;br /&gt;&lt;br /&gt;CA Desktop and Server Management r11.2a:&lt;br /&gt;QO96290&lt;br /&gt;&lt;br /&gt;CA Desktop and Server Management r11.2:&lt;br /&gt;QO96289&lt;br /&gt;&lt;br /&gt;CA Desktop and Server Management r11.1 (GA, a, C1):&lt;br /&gt;QO96287&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;How to determine if you are affected:&lt;br /&gt;&lt;br /&gt;For products on Windows:&lt;br /&gt;1. Using Windows Explorer, locate the file “gui_cm_ctrls.ocx”. By default, the file is in the “C:\Program Files\CA\DSM\bin\” directory.&lt;br /&gt;2. Right click on the file and select Properties.&lt;br /&gt;3. Select the Version tab.&lt;br /&gt;4. If the file version is earlier than indicated in the list below, the installation is vulnerable.&lt;br /&gt;

&lt;/p&gt;&lt;table cellpadding="3" cellspacing="0"&gt;&lt;tr&gt;&lt;td class="techhead3"&gt;Product&lt;/td&gt;&lt;td class="techhead3"&gt;File Name&lt;/td&gt;&lt;td class="techhead3"&gt;File Version&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;CA Desktop Management Suite for Windows r11.1 (GA, a, C1),&lt;br /&gt;Unicenter Desktop Management Bundle r11.1 (GA, a, C1),&lt;br /&gt;Unicenter Asset Management r11.1 (GA, a, C1),&lt;br /&gt;Unicenter Software Delivery r11.1 (GA, a, C1),&lt;br /&gt;Unicenter Remote Control r11.1 (GA, a, C1),&lt;br /&gt;CA Desktop and Server Management r11.1 (GA, a, C1)&lt;/td&gt;&lt;td&gt;gui_cm_ctrls.ocx&lt;/td&gt;&lt;td&gt;11.1.8124.2517&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;CA Desktop Management Suite for Windows r11.2,&lt;br /&gt;Unicenter Desktop Management Bundle r11.2,&lt;br /&gt;Unicenter Asset Management r11.2,&lt;br /&gt;Unicenter Software Delivery r11.2,&lt;br /&gt;Unicenter Remote Control r11.2,&lt;br /&gt;CA Desktop and Server Management r11.2&lt;/td&gt;&lt;td&gt;gui_cm_ctrls.ocx&lt;/td&gt;&lt;td&gt;11.2.2.4332&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;CA Desktop Management Suite for Windows r11.2a,&lt;br /&gt;Unicenter Desktop Management Bundle r11.2a,&lt;br /&gt;Unicenter Asset Management r11.2a,&lt;br /&gt;Unicenter Software Delivery r11.2a,&lt;br /&gt;Unicenter Remote Control r11.2a,&lt;br /&gt;CA Desktop and Server Management r11.2a&lt;/td&gt;&lt;td&gt;gui_cm_ctrls.ocx&lt;/td&gt;&lt;td&gt;11.2.3.1896&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;CA Desktop Management Suite for Windows r11.2 C1,&lt;br /&gt;Unicenter Desktop Management Bundle r11.2 C1,&lt;br /&gt;Unicenter Asset Management r11.2 C1,&lt;br /&gt;Unicenter Software Delivery r11.2 C1,&lt;br /&gt;Unicenter Remote Control r11.2 C1,&lt;br /&gt;BrightStor ARCserve Backup for Laptops and Desktops r11.5,&lt;br /&gt;CA Desktop and Server Management r11.2 C1&lt;/td&gt;&lt;td&gt;gui_cm_ctrls.ocx&lt;/td&gt;&lt;td&gt;11.2.1000.17&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;CA Desktop Management Suite for Windows r11.2 C2,&lt;br /&gt;Unicenter Desktop Management Bundle r11.2 C2,&lt;br /&gt;Unicenter Asset Management r11.2 C2,&lt;br /&gt;Unicenter Software Delivery r11.2 C2,&lt;br /&gt;Unicenter Remote Control r11.2 C2,&lt;br /&gt;CA Desktop and Server Management r11.2 C2&lt;/td&gt;&lt;td&gt;gui_cm_ctrls.ocx&lt;/td&gt;&lt;td&gt;11.2.2000.4&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Workaround: As a temporary workaround solution, disable the gui_cm_ctrls ActiveX control in the registry by setting the kill bit on CLSID {E6239EB3-E0B0-46DA-A215-CFA9B3B740C5}. Disabling the control may prevent the GUI from functioning correctly. Refer to &lt;a href="http://support.microsoft.com/kb/240797" target="_blank"&gt;Microsoft KB article 240797&lt;/a&gt; for information on how to disable an ActiveX control.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;References (URLs may wrap):&lt;br /&gt;CA Support:&lt;br /&gt;&lt;a href="http://support.ca.com/"&gt;http://support.ca.com/&lt;/a&gt;&lt;br /&gt;Security Notice for CA products using the DSM gui_cm_ctrls ActiveX control&lt;br /&gt;&lt;a href="https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=174256"&gt;https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=174256&lt;/a&gt;&lt;br /&gt;Solution Document Reference APARs:&lt;br /&gt;QI96333, QO96283, QO96286, QO96285, QO96284, QO99084, QO99080, QO96288, QO96290, QO96289, QO96287&lt;br /&gt;CA Security Response Blog posting:&lt;br /&gt;CA DSM gui_cm_ctrls ActiveX Control Vulnerability&lt;br /&gt;&lt;a href="http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/16/ca-dsm-gui-cm-ctrls-activex-control-vulnerability.aspx"&gt;http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/16/[...]vulnerability.aspx&lt;/a&gt;&lt;br /&gt;Reported By: &lt;br /&gt;Greg Linares of eEye Digital Security&lt;br /&gt;CVE Reference:&lt;br /&gt;CVE-2008-1786&lt;br /&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1786" target="_blank"&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1786&lt;/a&gt;&lt;br /&gt;OSVDB References: Pending&lt;br /&gt;&lt;a href="http://osvdb.org/" target="_blank"&gt;http://osvdb.org/&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Changelog for this advisory:&lt;br /&gt;v1.0 - Initial Release&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Customers who require additional information should contact CA Technical Support at &lt;a href="http://support.ca.com"&gt;http://support.ca.com&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;For technical questions or comments related to this advisory, please send email to vuln AT ca DOT com.&lt;br /&gt;&lt;br /&gt;If you discover a vulnerability in CA products, please report your findings to vuln AT ca DOT com, or utilize our &amp;quot;Submit a Vulnerability&amp;quot; form.&lt;/p&gt;&lt;p&gt;URL: &lt;a href="http://www.ca.com/us/securityadvisor/vulninfo/submit.aspx"&gt;http://www.ca.com/us/securityadvisor/vulninfo/submit.aspx&lt;/a&gt;&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email CA+DSM+gui_cm_ctrls+ActiveX+Control+Vulnerability" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/16/ca-dsm-gui-cm-ctrls-activex-control-vulnerability.aspx&amp;subject=CA+DSM+gui_cm_ctrls+ActiveX+Control+Vulnerability"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/16/ca-dsm-gui-cm-ctrls-activex-control-vulnerability.aspx&amp;title=CA+DSM+gui_cm_ctrls+ActiveX+Control+Vulnerability" title="Submit CA+DSM+gui_cm_ctrls+ActiveX+Control+Vulnerability to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/16/ca-dsm-gui-cm-ctrls-activex-control-vulnerability.aspx&amp;phase=2" title="Submit CA+DSM+gui_cm_ctrls+ActiveX+Control+Vulnerability to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/16/ca-dsm-gui-cm-ctrls-activex-control-vulnerability.aspx&amp;title=CA+DSM+gui_cm_ctrls+ActiveX+Control+Vulnerability" title="Submit CA+DSM+gui_cm_ctrls+ActiveX+Control+Vulnerability to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=1118" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/ActiveX/default.aspx">ActiveX</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Unicenter/default.aspx">Unicenter</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2008-1786/default.aspx">CVE-2008-1786</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/gui_5F00_cm_5F00_ctrls/default.aspx">gui_cm_ctrls</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/eEye/default.aspx">eEye</category></item><item><title>Automating the Data Center - Where to Start</title><link>http://community.ca.com/blogs/cadatacenterautomationblog/archive/2008/04/15/automating-the-data-center-where-to-start.aspx</link><pubDate>Tue, 15 Apr 2008 17:33:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1116</guid><dc:creator>Ben Scheerer</dc:creator><slash:comments>1</slash:comments><description>&lt;p&gt;Data center automation (DCA) is designed to deliver value back to the business through increased levels of service and flexibility to meet business needs and demands.&amp;nbsp; With increasing complexity within the data center, including but not limited to: a growing number of applications, bare metal and virtual server sprawl, security and regulatory requirements, there is an increased need for effective management in minimizing its effects. &amp;nbsp;&lt;br /&gt;In a recent independent study on data center automation sponsored by CA (&lt;a href="http://www.ca.com/dca/survey" title="Results of Global Data Center Automation Study" target="_blank"&gt;http://www.ca.com/dca/survey&lt;/a&gt;), the majority (46%) of the respondents identified business compliance/ uptime as the number one challenge that they hope to address with automation. However, the survey respondents also indicated that those who have already implemented some sort of automation (an average of 48% of their data center tasks) saw that only 12% had seen these efforts as highly effective.&lt;br /&gt;This brings into question where to begin an automation effort?&amp;quot;&amp;nbsp; The right tools are essential in obtaining your automation goals, and tools that are flexible enough support your organization&amp;#39;s unique processes and capabilities are an absolute necessity.&amp;nbsp; Begin by identifying and defining your current and repeatable processes.&amp;nbsp; This task could present some difficulty depending on where you are in establishing a best practices approach to IT service management (ITSM).&amp;nbsp; Of course the IT Infrastructure Library (ITIL), takes the lead as an approach to define and map these processes as part of the overall IT services lifecycle. &amp;nbsp;&lt;br /&gt;In the event that you have not introduced any of these process frameworks or best practices in your environment, simply identify the existing approaches to the routine tasks currently undertaken in the data center such as patch management, maintaining consistency through gold standards, workload automation and/or server provisioning.&amp;nbsp; Once your routine and repeatable processes have been successfully identified and automated, be sure to continuously measure their effectiveness and implement any changes as needed for improvement. &amp;nbsp;&lt;br /&gt;Next in your quest for automation, begin to identify and define more complex processes that can bring additional value from IT services to the business.&amp;nbsp; At this point you may have already experienced a level of &amp;quot;enlightenment&amp;quot; in the quest for data center automation, meaning that you have already freed-up resources (both human and technology), allowing more time to focus on more strategic efforts.&amp;nbsp; Examples of more complex processes include intricate workloads and policy based provisioning (based on business policy). &lt;br /&gt;Data center automation has many points of entry and is only limited by your organization&amp;#39;s ability to plan and execute where it makes sense to the business (cost vs. value).&amp;nbsp;&amp;nbsp; Take a careful look at what your situation has to offer and evaluate the best course of action for automation in your unique environment.&lt;br /&gt;&amp;nbsp;

&lt;br /&gt;&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Automating+the+Data+Center+-+Where+to+Start" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/cadatacenterautomationblog/archive/2008/04/15/automating-the-data-center-where-to-start.aspx&amp;subject=Automating+the+Data+Center+-+Where+to+Start"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/cadatacenterautomationblog/archive/2008/04/15/automating-the-data-center-where-to-start.aspx&amp;title=Automating+the+Data+Center+-+Where+to+Start" title="Submit Automating+the+Data+Center+-+Where+to+Start to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/cadatacenterautomationblog/archive/2008/04/15/automating-the-data-center-where-to-start.aspx&amp;phase=2" title="Submit Automating+the+Data+Center+-+Where+to+Start to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/cadatacenterautomationblog/archive/2008/04/15/automating-the-data-center-where-to-start.aspx&amp;title=Automating+the+Data+Center+-+Where+to+Start" title="Submit Automating+the+Data+Center+-+Where+to+Start to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=1116" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/cadatacenterautomationblog/archive/tags/automation/default.aspx">automation</category><category domain="http://community.ca.com/blogs/cadatacenterautomationblog/archive/tags/data+center+automation/default.aspx">data center automation</category><category domain="http://community.ca.com/blogs/cadatacenterautomationblog/archive/tags/DCA/default.aspx">DCA</category><category domain="http://community.ca.com/blogs/cadatacenterautomationblog/archive/tags/ca+dca/default.aspx">ca dca</category><category domain="http://community.ca.com/blogs/cadatacenterautomationblog/archive/tags/ITSM/default.aspx">ITSM</category><category domain="http://community.ca.com/blogs/cadatacenterautomationblog/archive/tags/ITIL/default.aspx">ITIL</category></item><item><title>CSI: Crime Scene Investigation or Continual Service Improvement – You decide </title><link>http://community.ca.com/blogs/itservice/archive/2008/04/14/csi-crime-scene-investigation-or-continual-service-improvement-you-decide.aspx</link><pubDate>Mon, 14 Apr 2008 12:11:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1114</guid><dc:creator>Marvin Waschke</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Most of the country thinks CSI stands for &amp;quot;Crime Scene Investigation,&amp;quot; as popularized on TV. In a convoluted sort of way, the acronym means something similar in ITIL® v3. This is a stretch, but bear with me. &amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In v3, CSI stands for Continual Service Improvement and it is the fifth volume of the v3 publication. In the v3 scheme of things, CSI is the culmination of Strategy, Design, Transition, and Operation and is the phase in the service lifecycle that actually is part of all of the previous four phases. But too often, CSI becomes Crime Scene Investigation when we in IT mess up. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;On TV, the ensuing activity takes place in Las Vegas, Miami and New York. In this blog, we visit Washington DC...&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Recently, the Census Bureau announced that they are &lt;i&gt;abandoning&lt;/i&gt; a plan to replace paper and pencil with wireless handheld computers for the 2010 census, a move that will add 3 billion dollars to the cost of conducting the census according to the &lt;i&gt;New York Times &lt;/i&gt;in an article entitled &amp;quot;&lt;a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/04/03/AR2008040302068.html?sub=AR"&gt;Dust Off the Pencils: Plans for High-Tech Census Collapse.&amp;quot; &lt;/a&gt;The &lt;i&gt;Washington Post&lt;/i&gt; article is entitled &lt;a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/04/03/AR2008040302068.html?sub=AR"&gt;Census Back to Pen and Paper&lt;/a&gt;. I&amp;#39;m not sure what bothers me more, overlooking industry best practices, the $3 billion, or sharpening all those pencils.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;As a student of ITIL, the phase &amp;quot;crime scene&amp;quot; might come to mind when reading the details. I don&amp;#39;t want to point fingers or try to second guess the participants based only on a couple of news items, but this is an example of a failure in service management that ITIL good practices are designed to prevent.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Apparently, the problem began in the strategy phase when the requirements for a projected service are formulated based on the strategic goals. I infer from the news reports that the strategic goal of this service was to increase the accuracy and decrease the cost of the census. The strategic plan was a reasonable, even modest, extension of commonly used inventory technology: use GPS enabled handheld computers to record the exact location of each canvassed household and wirelessly transmit the collected data to regional accumulation centers. According to the reports, the requirements for implementing this plan were not thoroughly understood or communicated to the partner who was to supply the devices. As the project proceeded, more and more requirements were added, under-estimates were revealed, and costs ballooned, eventually resulting in the cancellation of plans to implement the service.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;It is not clear whether the service ever got beyond the design phase and into transition where it would have been tested and deployed into the production environment, and it certainly never reached the operation.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In the ITIL v3 service lifecycle, CSI plays a role in every phase. Experience with the service in each phase is collected and analyzed to discover ways to improve the service. In the case of a failed service, this is a lot like Crime Scene Investigation, looking for the mistakes made and tracing flaws so that the service can be improved in the future. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Census takers may still use pen and paper in 2010, but if the Census Bureau applies CSI properly, there is a good chance that the 2020 census will be automated.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;ITIL® is a Registered Trade Mark, and a Registered Community Trade Mark of the Office of Government Commerce, and is Registered in the U.S. Patent and Trademark Office.&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email CSI%3a+Crime+Scene+Investigation+or+Continual+Service+Improvement+%e2%80%93+You+decide+" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/itservice/archive/2008/04/14/csi-crime-scene-investigation-or-continual-service-improvement-you-decide.aspx&amp;subject=CSI%3a+Crime+Scene+Investigation+or+Continual+Service+Improvement+%e2%80%93+You+decide+"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/itservice/archive/2008/04/14/csi-crime-scene-investigation-or-continual-service-improvement-you-decide.aspx&amp;title=CSI%3a+Crime+Scene+Investigation+or+Continual+Service+Improvement+%e2%80%93+You+decide+" title="Submit CSI%3a+Crime+Scene+Investigation+or+Continual+Service+Improvement+%e2%80%93+You+decide+ to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/itservice/archive/2008/04/14/csi-crime-scene-investigation-or-continual-service-improvement-you-decide.aspx&amp;phase=2" title="Submit CSI%3a+Crime+Scene+Investigation+or+Continual+Service+Improvement+%e2%80%93+You+decide+ to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/itservice/archive/2008/04/14/csi-crime-scene-investigation-or-continual-service-improvement-you-decide.aspx&amp;title=CSI%3a+Crime+Scene+Investigation+or+Continual+Service+Improvement+%e2%80%93+You+decide+" title="Submit CSI%3a+Crime+Scene+Investigation+or+Continual+Service+Improvement+%e2%80%93+You+decide+ to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=1114" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/itservice/archive/tags/ITIL/default.aspx">ITIL</category></item><item><title>Some thoughts on e-ID</title><link>http://community.ca.com/blogs/iam/archive/2008/04/11/some-thoughts-on-e-id.aspx</link><pubDate>Fri, 11 Apr 2008 13:22:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1107</guid><dc:creator>Mike Small</dc:creator><slash:comments>0</slash:comments><description>In late February I gave a talk at a conference on e-ID in Belgium organized by L-SEC  http://www.lsec.be.  Belgium is one of the first countries in the world where all citizens will have their identity supported by a digital identity card.  Unlike Finland, where the e-ID card is optional, in Belgium it is a legal requirement that every resident registers their address.  This registration process is performed at the local town hall and delivers an e-ID identity card at a cost of around 10 Euros.  Up to date around 7 million e-ID cards have been distributed; by the end of the year all 8.3 million citizens older than 12 years of age should be in possession of their e-ID.   It is no surprise that Belgium is looking for ways to exploit this card.
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;
 

One example of this is eBay who recently entered into an agreement to integrate e-ID as one of the verification options for its users in Belgium. This new functionality allows new and existing eBay-users to (re)register on the site by having their identity confirmed quickly, and safely. On top of that, eBay-sellers who use this verification method will get an ‘e-ID Verified’ label next to their username. Next to the seller’s profile and feedback score, this will be an additional indicator to that the buyer or seller is trustworthy.
&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;
 

The three basic functionalities of e-ID are data capture, authentication and electronic signature. Around 40 to 50% of all e-ID applications in Belgium relate to data capture and 40 to 45% are for authentication.  Together data capture and authentication cover 90 to 95% of all the current applications.  The much smaller number around 5% to 10% relate to electronic signature.  ‘Data capture’ is when the card is put into the reader in the library, a hotel or in the city hall and the application reads the name and some other data on the e-ID card. ‘Authentication’ is used in all kinds of web applications (and incidentally CA’s SiteMinder is used by the Flemish Government MVG for this). The e-ID card is also well suited as authentication mechanism for PC banking.
&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;
 

The card stores a visible and digital picture but also allows to log on to the National Register, the government database.  The e-ID card is used to authenticate the citizen for access to public services. The resident can also consult the Register and see what the authorities have stored and who has accessed that information (except for State Security).  For example a user can use the card to borrow books from the library and later check which books he has borrowed and when they are due to be returned.  A more mundane side effect of this is that access to municipal garbage dumps is now controlled by your e-ID card.  If you try to dump your garbage at a dump that is outside of the commune where your address is registered you will not be allowed access!  

&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Some+thoughts+on+e-ID" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/iam/archive/2008/04/11/some-thoughts-on-e-id.aspx&amp;subject=Some+thoughts+on+e-ID"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/iam/archive/2008/04/11/some-thoughts-on-e-id.aspx&amp;title=Some+thoughts+on+e-ID" title="Submit Some+thoughts+on+e-ID to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/iam/archive/2008/04/11/some-thoughts-on-e-id.aspx&amp;phase=2" title="Submit Some+thoughts+on+e-ID to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/iam/archive/2008/04/11/some-thoughts-on-e-id.aspx&amp;title=Some+thoughts+on+e-ID" title="Submit Some+thoughts+on+e-ID to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=1107" width="1" height="1"&gt;</description></item><item><title>ITIL v3 – You’re doing it whether you know it or not   </title><link>http://community.ca.com/blogs/itil/archive/2008/04/08/itil-v3-you-re-doing-it-whether-you-know-it-or-not.aspx</link><pubDate>Tue, 08 Apr 2008 18:36:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1100</guid><dc:creator>Robert Stroud</dc:creator><slash:comments>5</slash:comments><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I&amp;#39;d like to make a quick point. There are times when I find the discussions surrounding ITIL® v3 popularity to be superfluous. That&amp;#39;s because whether or not people are &amp;quot;for&amp;quot; ITIL v3, if they want to work for successful organizations, they have probably already put several aspects of ITIL v3 into practice -- whether they realize it or not. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I recently visited several European ITIL practitioners who are in process of transforming their ITSM implementations to support their dynamic business environments -- the objective, to innovate as the market demands. As the head of the ITSM team at a large manufacturer commented, &amp;quot;any ITIL implementation that is service aligned is doing much of v3 already.&amp;quot; I concur. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his case, Knowledge Management, Self Help and Access Management have been part of his culture for the last 12 months and pre-date the launch of v3. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;So please. There is no &amp;quot;for&amp;quot; or &amp;quot;against.&amp;quot; You &lt;i&gt;are &lt;/i&gt;going to adopt some practices that are suspiciously reminiscent of ITIL v3. If you choose not to label them as such, so be it. Or, to paraphrase Chelsea Clinton, &amp;quot;that&amp;#39;s absolutely none of my business.&amp;quot; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;ITIL® is a Registered Trade Mark, and a Registered Community Trade Mark of the Office of Government Commerce, and is Registered in the U.S. Patent and Trademark Office.&lt;/i&gt;&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email ITIL+v3+%e2%80%93+You%e2%80%99re+doing+it+whether+you+know+it+or+not+++" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/itil/archive/2008/04/08/itil-v3-you-re-doing-it-whether-you-know-it-or-not.aspx&amp;subject=ITIL+v3+%e2%80%93+You%e2%80%99re+doing+it+whether+you+know+it+or+not+++"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/itil/archive/2008/04/08/itil-v3-you-re-doing-it-whether-you-know-it-or-not.aspx&amp;title=ITIL+v3+%e2%80%93+You%e2%80%99re+doing+it+whether+you+know+it+or+not+++" title="Submit ITIL+v3+%e2%80%93+You%e2%80%99re+doing+it+whether+you+know+it+or+not+++ to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/itil/archive/2008/04/08/itil-v3-you-re-doing-it-whether-you-know-it-or-not.aspx&amp;phase=2" title="Submit ITIL+v3+%e2%80%93+You%e2%80%99re+doing+it+whether+you+know+it+or+not+++ to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/itil/archive/2008/04/08/itil-v3-you-re-doing-it-whether-you-know-it-or-not.aspx&amp;title=ITIL+v3+%e2%80%93+You%e2%80%99re+doing+it+whether+you+know+it+or+not+++" title="Submit ITIL+v3+%e2%80%93+You%e2%80%99re+doing+it+whether+you+know+it+or+not+++ to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=1100" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/itil/archive/tags/ITIL/default.aspx">ITIL</category><category domain="http://community.ca.com/blogs/itil/archive/tags/ITIL_26002300_174_3B00_+V3+Launch/default.aspx">ITIL&amp;#174; V3 Launch</category><category domain="http://community.ca.com/blogs/itil/archive/tags/Best+Practices+Guidance/default.aspx">Best Practices Guidance</category></item><item><title>User-centric Identity - a joint CA/Microsoft effort</title><link>http://community.ca.com/blogs/iam/archive/2008/04/08/user-centric-identity-a-joint-ca-microsoft-effort.aspx</link><pubDate>Tue, 08 Apr 2008 15:29:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1098</guid><dc:creator>Jeffrey Broberg</dc:creator><slash:comments>0</slash:comments><description>The Identity Metasystem offers a new way to think about the relationship between parties that are interested in either consuming or producing identity information. Sometimes this is referred to as Identity 2.0, or more correctly as User Centric Identity. This new paradigm offers many benefits, from increased security, enhanced privacy, and the opportunity for new business models. It is sometimes misinterpreted as a technology that nullifies the current identity practices that many enterprises have in place. This is most likely due to the technical nature of most literature available on User Centric Identity, and on the focus of standards and interoperability. But it could not be farther from the truth. 
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;What is really important about the Identity Metasystem is that it defines an “Identity Dial Tone” that prescribes how identity can flow seamlessly through enterprise websites, web services, and the ever growing social networking and collaboration services, spanning both high and low trust situations. For the potential opportunity of this new ecosystem to thrive, it is important that it is embraced and delivered to enterprise customers in a way that allows them to incorporate the concepts in their existing infrastructures, without the fear that large portions of the solutions will need to be replaced or significantly modified. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;CA and Microsoft are committed to the Identity Metasystem and on helping customers realize the benefits of the Identity Metasystem, while protecting their current investments. To focus the discussion on business objectives, and less on technical practices, CA and Microsoft have jointly developed a White paper “&lt;a class="" href="http://www.ca.com/files/whitepapers/ca_microsoft_usercentric_identity_wp.pdf" target="_blank"&gt;CA and Microsoft Support for User-Centric Identity and the Identity Metasystem&lt;/a&gt;” that describes the Identity Metasystem, InfoCards and how they can be incorporated into existing solutions where CA and Microsoft technologies are being used.&lt;/p&gt;&lt;br /&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email User-centric+Identity+-+a+joint+CA%2fMicrosoft+effort" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/iam/archive/2008/04/08/user-centric-identity-a-joint-ca-microsoft-effort.aspx&amp;subject=User-centric+Identity+-+a+joint+CA%2fMicrosoft+effort"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/iam/archive/2008/04/08/user-centric-identity-a-joint-ca-microsoft-effort.aspx&amp;title=User-centric+Identity+-+a+joint+CA%2fMicrosoft+effort" title="Submit User-centric+Identity+-+a+joint+CA%2fMicrosoft+effort to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/iam/archive/2008/04/08/user-centric-identity-a-joint-ca-microsoft-effort.aspx&amp;phase=2" title="Submit User-centric+Identity+-+a+joint+CA%2fMicrosoft+effort to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/iam/archive/2008/04/08/user-centric-identity-a-joint-ca-microsoft-effort.aspx&amp;title=User-centric+Identity+-+a+joint+CA%2fMicrosoft+effort" title="Submit User-centric+Identity+-+a+joint+CA%2fMicrosoft+effort to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=1098" width="1" height="1"&gt;</description></item><item><title>CA ARCserve Backup for Laptops and Desktops Server and CA Desktop Management Suite Multiple Vulnerabilities</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/04/ca-arcserve-backup-for-laptops-and-desktops-server-and-ca-desktop-management-suite-multiple-vulnerabilities.aspx</link><pubDate>Fri, 04 Apr 2008 12:47:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1091</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;On April 3rd, 2008, CA published a security notice to address multiple vulnerabilities in CA ARCserve Backup for Laptops and Desktops Server and CA Desktop Management Suite.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Title: CA ARCserve Backup for Laptops and Desktops Server and CA Desktop Management Suite Multiple Vulnerabilities&lt;br /&gt;&lt;br /&gt;CA Advisory Date: 2008-04-03&lt;br /&gt;&lt;br /&gt;Reported By: Dyon Balding of Secunia Research&lt;br /&gt;&lt;br /&gt;Impact: A remote attacker can execute arbitrary code or cause a denial of service condition.&lt;br /&gt;&lt;br /&gt;Summary: CA ARCserve Backup for Laptops and Desktops Server contains multiple vulnerabilities that can allow a remote attacker to execute arbitrary code or cause a denial of service condition. CA has issued updates to address the vulnerabilities. The first issue, CVE-2008-1328, occurs due to insufficient bounds checking on command arguments by the LGServer service. The second issue, CVE-2008-1329, occurs due to insufficient verification of file uploads by the NetBackup service. The NetBackup service is a component of CA ARCserve Backup for Laptops and 
Desktops Server. In most cases, an attacker can potentially gain complete control of an affected installation. Additionally, only a server installation of BrightStor ARCserve Backup for Laptops and Desktops is affected. The client installation is not affected.&lt;br /&gt;&lt;br /&gt;Note: the previously published patches for CVE-2007-3216 and CVE-2007-5005 did not fully address some issues.&lt;br /&gt;&lt;br /&gt;Mitigating Factors: Client installations are not affected.&lt;br /&gt;&lt;br /&gt;Severity: CA has given these vulnerabilities a maximum risk rating of High.&lt;br /&gt;&lt;br /&gt;Affected Products:&lt;br /&gt;CA ARCserve Backup for Laptops and Desktops r11.5&lt;br /&gt;CA ARCserve Backup for Laptops and Desktops r11.1 SP2&lt;br /&gt;CA ARCserve Backup for Laptops and Desktops r11.1 SP1&lt;br /&gt;CA ARCserve Backup for Laptops and Desktops r11.1&lt;br /&gt;CA ARCserve Backup for Laptops and Desktops r11.0&lt;br /&gt;CA Desktop Management Suite 11.2 English&lt;br /&gt;CA Desktop Management Suite 11.2 localized&lt;br /&gt;CA Desktop Management Suite 11.1&lt;br /&gt;&lt;br /&gt;Affected Platforms:&lt;br /&gt;Windows&lt;br /&gt;&lt;br /&gt;Status and Recommendation:&lt;br /&gt;CA has provided updates to address the vulnerabilities.&lt;br /&gt;CA ARCserve Backup for Laptops and Desktops 11.1, 11.1 SP1, 11.2 SP2:&amp;nbsp; QO95512&lt;br /&gt;CA ARCserve Backup for Laptops and Desktops 11.5:&amp;nbsp; QO95513&lt;br /&gt;CA Desktop Management Suite 11.2 English:&amp;nbsp; QO95513&lt;br /&gt;CA Desktop Management Suite 11.2 localized:&amp;nbsp; QO95513&lt;br /&gt;CA Desktop Management Suite 11.1:&amp;nbsp; Upgrade to 11.1 C1.&lt;br /&gt;CA ARCserve Backup for Laptops and Desktops 11.0:&amp;nbsp; Upgrade to ARCserve Backup for Laptops and Desktops version 11.1 and apply the latest patches.&amp;nbsp; QI85497&lt;br /&gt;&lt;br /&gt;How to determine if you are affected:&lt;br /&gt;&lt;br /&gt;For Windows:&lt;br /&gt;1. Using Windows Explorer, locate the file&amp;quot;rxRPC.dll&amp;quot;. The file can be found in the following default locations:&lt;br /&gt;Product:&amp;nbsp; CA ARCserve Backup for Laptops and Desktops 11.5&lt;br /&gt;Directory Path:&amp;nbsp; C:\Program Files\CA\BrightStor ARCserve Backup for Laptops &amp;amp; Desktops\Explorer&lt;br /&gt;Product:&amp;nbsp; CA ARCserve Backup for Laptops and Desktops 11.1&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;Directory Path:&amp;nbsp; C:\Program Files\CA\BrightStor ARCserve Backup for Laptops &amp;amp; Desktops\server&lt;br /&gt;Product:&amp;nbsp; CA Desktop Management Suite 11.2 English&lt;br /&gt;Directory Path:&amp;nbsp; C:\Program Files\CA\DSM\BABLD\MGUI&lt;br /&gt;Product:&amp;nbsp; CA Desktop Management Suite 11.2 localized&lt;br /&gt;Directory Path:&amp;nbsp; C:\Program Files\CA\DSM\BABLD\MGUI&lt;br /&gt;2. Right click on the files and select Properties.&lt;br /&gt;3. Select the General tab.&lt;br /&gt;4. If the file date is earlier than indicated in the below table, the installation is vulnerable.&lt;br /&gt;&lt;br /&gt;
&lt;/p&gt;&lt;table&gt;&lt;tr&gt;&lt;td&gt;Product&lt;/td&gt;&lt;td&gt;File Name&lt;/td&gt;&lt;td&gt;File Date / Size&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;CA ARCserve Backup for Laptops and Desktops 11.5&lt;/td&gt;&lt;td&gt;rxRPC.dll&lt;/td&gt;&lt;td&gt;February 18 2008 / 126976&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;CA ARCserve Backup for Laptops and Desktops 11.1&lt;/td&gt;&lt;td&gt;rxRPC.dll&lt;/td&gt;&lt;td&gt;February 18 2008 / 114688&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;CA Desktop Management Suite 11.2 English&lt;/td&gt;&lt;td&gt;rxRPC.dll&lt;/td&gt;&lt;td&gt;February 18 2008 / 126976&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;CA Desktop Management Suite 11.2 localized&lt;/td&gt;&lt;td&gt;rxRPC.dll&lt;/td&gt;&lt;td&gt;February 18 2008 / 126976&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;br /&gt;&lt;br /&gt;Workaround: None&lt;br /&gt;&lt;br /&gt;References (URLs may wrap):&lt;br /&gt;CA Support:&lt;br /&gt;&lt;a href="http://support.ca.com/"&gt;http://support.ca.com/&lt;/a&gt;&lt;br /&gt;Security Notice for CA ARCserve Backup for Laptops and Desktops Server and CA Desktop Management Suite&lt;br /&gt;&lt;a href="https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=173105"&gt;https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=173105&lt;/a&gt;&lt;br /&gt;Solution Document Reference APARs:&lt;br /&gt;QO95512, QO95513, QI85497&lt;br /&gt;CA Security Response Blog posting:&lt;br /&gt;CA ARCserve Backup for Laptops and Desktops Server and CA Desktop Management Suite Multiple Vulnerabilities&lt;br /&gt;&lt;a href="http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/04/ca-arcserve-backup-for-laptops-and-desktops-server-and-ca-desktop-management-suite-multiple-vulnerabilities.aspx"&gt;http://community.ca.com/blogs/[...]-vulnerabilities.aspx&lt;/a&gt;&lt;br /&gt;Reported By: &lt;br /&gt;Dyon Balding of Secunia Research&lt;br /&gt;CVE References:&lt;br /&gt;CVE-2008-1328 and CVE-2008-1329&lt;br /&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1328" target="_blank"&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1328&lt;/a&gt;&lt;br /&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1329" target="_blank"&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1329&lt;/a&gt;&lt;br /&gt;OSVDB References: Pending&lt;br /&gt;&lt;a href="http://osvdb.org/" target="_blank"&gt;http://osvdb.org/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Changelog for this advisory:&lt;br /&gt;v1.0 - Initial Release&lt;br /&gt;&lt;br /&gt;Customers who require additional information should contact CA Technical Support at &lt;a href="http://support.ca.com"&gt;http://support.ca.com&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;For technical questions or comments related to this advisory, please send email to vuln AT ca DOT com.&lt;br /&gt;&lt;br /&gt;If you discover a vulnerability in CA products, please report your findings to vuln AT ca DOT com, or utilize our &amp;quot;Submit a Vulnerability&amp;quot; form. &lt;br /&gt;URL: &lt;a href="http://www.ca.com/us/securityadvisor/vulninfo/submit.aspx"&gt;http://www.ca.com/us/securityadvisor/vulninfo/submit.aspx&lt;/a&gt; &lt;br /&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email CA+ARCserve+Backup+for+Laptops+and+Desktops+Server+and+CA+Desktop+Management+Suite+Multiple+Vulnerabilities" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/04/ca-arcserve-backup-for-laptops-and-desktops-server-and-ca-desktop-management-suite-multiple-vulnerabilities.aspx&amp;subject=CA+ARCserve+Backup+for+Laptops+and+Desktops+Server+and+CA+Desktop+Management+Suite+Multiple+Vulnerabilities"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/04/ca-arcserve-backup-for-laptops-and-desktops-server-and-ca-desktop-management-suite-multiple-vulnerabilities.aspx&amp;title=CA+ARCserve+Backup+for+Laptops+and+Desktops+Server+and+CA+Desktop+Management+Suite+Multiple+Vulnerabilities" title="Submit CA+ARCserve+Backup+for+Laptops+and+Desktops+Server+and+CA+Desktop+Management+Suite+Multiple+Vulnerabilities to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/04/ca-arcserve-backup-for-laptops-and-desktops-server-and-ca-desktop-management-suite-multiple-vulnerabilities.aspx&amp;phase=2" title="Submit CA+ARCserve+Backup+for+Laptops+and+Desktops+Server+and+CA+Desktop+Management+Suite+Multiple+Vulnerabilities to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/04/ca-arcserve-backup-for-laptops-and-desktops-server-and-ca-desktop-management-suite-multiple-vulnerabilities.aspx&amp;title=CA+ARCserve+Backup+for+Laptops+and+Desktops+Server+and+CA+Desktop+Management+Suite+Multiple+Vulnerabilities" title="Submit CA+ARCserve+Backup+for+Laptops+and+Desktops+Server+and+CA+Desktop+Management+Suite+Multiple+Vulnerabilities to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=1091" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2008-1328/default.aspx">CVE-2008-1328</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Desktop+Management+Suite/default.aspx">Desktop Management Suite</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2008-1329/default.aspx">CVE-2008-1329</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/ARCserve+Backup+for+Laptops+and+Desktops/default.aspx">ARCserve Backup for Laptops and Desktops</category></item><item><title>CA Alert Notification Server Multiple Vulnerabilities</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/04/ca-alert-notification-server-multiple-vulnerabilities.aspx</link><pubDate>Fri, 04 Apr 2008 11:55:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1089</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;On April 3rd, 2008 CA published a security notice to address a vulnerability in CA Alert Notification Server.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Title: CA Alert Notification Server Multiple Vulnerabilities&lt;br /&gt;&lt;br /&gt;CA Advisory Date: 2008-04-03&lt;br /&gt;&lt;br /&gt;Reported By: An anonymous researcher working with the iDefense VCP&lt;br /&gt;&lt;br /&gt;Impact: A remote authenticated attacker can execute arbitrary code or cause a denial of service condition.&lt;br /&gt;&lt;br /&gt;Summary: CA Alert Notification Server service contains multiple vulnerabilities that can allow a remote authenticated attacker to execute arbitrary code or cause a denial of service condition. CA has issued updates to address the vulnerabilities. The vulnerabilities, CVE-2007-4620, are due to insufficient bounds checking in multiple procedures. A remote authenticated attacker or local user can exploit a buffer overflow to execute arbitrary code or cause a denial of service.&lt;br /&gt;&lt;br /&gt;Mitigating Factors: Remote attacker must have legitimate authentication credentials.&lt;br /&gt;&lt;br /&gt;Severity: CA has given these vulnerabilities a maximum risk rating of High.&lt;br /&gt;&lt;br /&gt;Affected Products:&lt;br /&gt;CA Anti-Virus for the Enterprise 7.1&lt;br /&gt;CA Threat Manager for the Enterprise (formerly eTrust Integrated Threat Management) r8&lt;br /&gt;CA Threat Manager for the Enterprise (formerly eTrust Integrated Threat Management) r8.1&lt;br /&gt;CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) r8&lt;br /&gt;CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) r8.1&lt;br /&gt;BrightStor ARCserve Backup r11.5&lt;br /&gt;BrightStor ARCserve Backup r11.1&lt;br /&gt;BrightStor ARCserve Backup r11 for Windows&lt;br /&gt;&lt;br /&gt;Affected Platforms:&lt;br /&gt;Windows&lt;br /&gt;&lt;br /&gt;Status and Recommendation:&lt;br /&gt;CA has provided updates to address the vulnerabilities.&lt;br /&gt;CA Anti-Virus for the Enterprise 7.1, CA Anti-Virus for the Enterprise r8:&amp;nbsp; QO96079&lt;br /&gt;CA Threat Manager for the Enterprise r8:&amp;nbsp; QO96387&lt;br /&gt;CA Anti-Virus for the Enterprise r8.1, CA Threat Manager for the Enterprise r8.1:&amp;nbsp; QO96080&lt;br /&gt;BrightStor ARCserve Backup r11.5, BrightStor ARCserve Backup r11.1:&amp;nbsp; QO96079&lt;br /&gt;BrightStor ARCserve Backup r11.0:&amp;nbsp; Upgrade to 11.1 and apply the latest patches.&lt;br /&gt;&lt;br /&gt;How to determine if you are affected:&lt;br /&gt;&lt;br /&gt;For products on Windows:&lt;br /&gt;&amp;nbsp;&amp;nbsp; 1. Using Windows Explorer, locate the file &amp;quot;alert.exe&amp;quot;. By default, the file is located in the &amp;quot;C:\Program Files\CA\SharedComponents\Alert&amp;quot; directory.&lt;br /&gt;&amp;nbsp;&amp;nbsp; 2. Right click on the file and select Properties.&lt;br /&gt;&amp;nbsp;&amp;nbsp; 3. Select the Version tab.&lt;br /&gt;&amp;nbsp;&amp;nbsp; 4. If the file version is earlier than indicated in the below table, the installation is vulnerable.&lt;br /&gt;&lt;br /&gt;
&lt;/p&gt;&lt;table&gt;&lt;tr&gt;&lt;td&gt;Product&lt;/td&gt;&lt;td&gt;File&lt;/td&gt;&lt;td&gt;Version&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;CA Anti-Virus for the Enterprise r8.1&lt;/td&gt;&lt;td&gt;Alert.exe&lt;/td&gt;&lt;td&gt;8.1.586.0&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;CA Threat Manager for the Enterprise 8.1&lt;/td&gt;&lt;td&gt;Alert.exe&lt;/td&gt;&lt;td&gt;8.1.586.0&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;CA Threat Manager for the Enterprise r8&lt;/td&gt;&lt;td&gt;Alert.exe&lt;/td&gt;&lt;td&gt;8.0.450.0&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;CA Anti-Virus for the Enterprise 7.1&lt;/td&gt;&lt;td&gt;Alert.exe&lt;/td&gt;&lt;td&gt;7.1.758.0&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;CA Anti-Virus for the Enterprise r8&lt;/td&gt;&lt;td&gt;Alert.exe&lt;/td&gt;&lt;td&gt;7.1.758.0&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;BrightStor ARCserve Backup r11.5&lt;/td&gt;&lt;td&gt;Alert.exe&lt;/td&gt;&lt;td&gt;7.1.758.0&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;BrightStor ARCserve Backup r11.1&lt;/td&gt;&lt;td&gt;Alert.exe&lt;/td&gt;&lt;td&gt;7.1.758.0&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;Workaround: None&lt;br /&gt;&lt;br /&gt;References (URLs may wrap):&lt;br /&gt;CA Support:&lt;br /&gt;&lt;a href="http://support.ca.com/"&gt;http://support.ca.com/&lt;/a&gt;&lt;br /&gt;Security Notice for Alert Notification Server&lt;br /&gt;&lt;a href="https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=173103"&gt;https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=173103&lt;/a&gt;&lt;br /&gt;Solution Document Reference APARs:&lt;br /&gt;QO96079, QO96387, QO96080, QO96079&lt;br /&gt;CA Security Response Blog posting:&lt;br /&gt;CA Alert Notification Server Multiple Vulnerabilities&lt;br /&gt;&lt;a href="http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/04/ca-alert-notification-server-multiple-vulnerabilities.aspx"&gt;http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/04/ca-alert-notification-server-multiple-vulnerabilities.aspx&lt;/a&gt;&lt;br /&gt;Reported By: &lt;br /&gt;An anonymous researcher working with the iDefense VCP&lt;br /&gt;CVE References:&lt;br /&gt;CVE-2007-4620&lt;br /&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4620" target="_blank"&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4620&lt;/a&gt;&lt;br /&gt;OSVDB References: Pending&lt;br /&gt;&lt;a href="http://osvdb.org/" target="_blank"&gt;http://osvdb.org/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Changelog for this advisory:&lt;br /&gt;v1.0 - Initial Release&lt;br /&gt;&lt;br /&gt;Customers who require additional information should contact CA Technical Support at &lt;a href="http://support.ca.com"&gt;http://support.ca.com&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;For technical questions or comments related to this advisory, please send email to vuln AT ca DOT com.&lt;br /&gt;&lt;br /&gt;If you discover a vulnerability in CA products, please report your findings to vuln AT ca DOT com, or utilize our &amp;quot;Submit a Vulnerability&amp;quot; form. &lt;br /&gt;URL: &lt;a href="http://www.ca.com/us/securityadvisor/vulninfo/submit.aspx"&gt;http://www.ca.com/us/securityadvisor/vulninfo/submit.aspx &lt;/a&gt;&lt;br /&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email CA+Alert+Notification+Server+Multiple+Vulnerabilities" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/04/ca-alert-notification-server-multiple-vulnerabilities.aspx&amp;subject=CA+Alert+Notification+Server+Multiple+Vulnerabilities"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/04/ca-alert-notification-server-multiple-vulnerabilities.aspx&amp;title=CA+Alert+Notification+Server+Multiple+Vulnerabilities" title="Submit CA+Alert+Notification+Server+Multiple+Vulnerabilities to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/04/ca-alert-notification-server-multiple-vulnerabilities.aspx&amp;phase=2" title="Submit CA+Alert+Notification+Server+Multiple+Vulnerabilities to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/04/ca-alert-notification-server-multiple-vulnerabilities.aspx&amp;title=CA+Alert+Notification+Server+Multiple+Vulnerabilities" title="Submit CA+Alert+Notification+Server+Multiple+Vulnerabilities to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=1089" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2007-4620/default.aspx">CVE-2007-4620</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Alert+Notification+Server/default.aspx">Alert Notification Server</category></item><item><title>COBIT and ITIL – Better Together  </title><link>http://community.ca.com/blogs/itil/archive/2008/04/01/cobit-and-itil-better-together.aspx</link><pubDate>Tue, 01 Apr 2008 13:25:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1085</guid><dc:creator>Robert Stroud</dc:creator><slash:comments>2</slash:comments><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Those of you struggling with bringing IT and business alignment to life through your ITIL&lt;em&gt;®&lt;/em&gt; initiative may be surprised to learn that your salvation may lie in a free download. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Even with the improved use of organizational charts and metrics in ITIL v3, some practitioners have commented that the linkage to a sound maturity process is still lacking. This is where COBIT, which is available for free from &lt;a href="http://www.isaca.org/"&gt;http://www.isaca.org/&lt;/a&gt;, can assist.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Many companies that I work with have been using COBIT&amp;#39;s Key Performance Indicators, Maturity Models and RACI Charts (which track&amp;nbsp; Responsible, Accountable, Consulted and Informed persons for every process) to provide metrics and structure for their ITIL processes.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;COBIT is the governance framework that aligns business strategies and objectives with IT deliverables by identifying and analyzing the IT processes and measurements needed to construct processes that deliver desired business results. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;COBIT provides the missing governance capabilities for your ITIL processes, helping you measure and assure performance and roll up the metrics to business requirements to provide a holistic view of your performance.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;While ITIL does offer performance measurements and organizational information, in my opinion these don&amp;#39;t roll up to the business level to the extent COBIT does. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;For example, take a look at COBIT process DS1, Define and Manage Service Levels, which is defined as control over the IT processes of defining and managing service levels with the objective of ensuring the alignment of key IT services with business strategy. COBIT identifies requirements, inputs, outputs, report requirements, organizational impact, metrics and the maturity model (every COBIT process has its own maturity model to show you where you are and where you are going ) -- all of which can assist you in your ITIL journey.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;So go to isaca.org and download COBIT. &amp;nbsp;It&amp;#39;s on me. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;By the way, check back at isaca.org in the next few weeks for mappings of COBIT 4.1 to ITIL v3.&amp;nbsp; We&amp;#39;ll have two versions to choose from depending on whether you have an existing leaning towards COBIT or ITIL. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;ITIL® is a Registered Trade Mark, and a Registered Community Trade Mark of the Office of Government Commerce, and is Registered in the U.S. Patent and Trademark Office.&lt;/i&gt;&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email COBIT+and+ITIL+%e2%80%93+Better+Together++" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/itil/archive/2008/04/01/cobit-and-itil-better-together.aspx&amp;subject=COBIT+and+ITIL+%e2%80%93+Better+Together++"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/itil/archive/2008/04/01/cobit-and-itil-better-together.aspx&amp;title=COBIT+and+ITIL+%e2%80%93+Better+Together++" title="Submit COBIT+and+ITIL+%e2%80%93+Better+Together++ to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/itil/archive/2008/04/01/cobit-and-itil-better-together.aspx&amp;phase=2" title="Submit COBIT+and+ITIL+%e2%80%93+Better+Together++ to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/itil/archive/2008/04/01/cobit-and-itil-better-together.aspx&amp;title=COBIT+and+ITIL+%e2%80%93+Better+Together++" title="Submit COBIT+and+ITIL+%e2%80%93+Better+Together++ to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=1085" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/itil/archive/tags/ITIL/default.aspx">ITIL</category><category domain="http://community.ca.com/blogs/itil/archive/tags/Best+Practices+Guidance/default.aspx">Best Practices Guidance</category><category domain="http://community.ca.com/blogs/itil/archive/tags/COBIT/default.aspx">COBIT</category></item><item><title>Should Service Users Be Tracked as CIs in the CMDB? </title><link>http://community.ca.com/blogs/itservice/archive/2008/04/01/should-service-users-be-tracked-as-cis-in-the-cmdb.aspx</link><pubDate>Tue, 01 Apr 2008 13:17:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1084</guid><dc:creator>Marvin Waschke</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;As CMDB experts go, I have a lot of experience, starting with implementations a decade ago when ITIL was almost unknown in North America. Still, a question posed to me at CA&amp;#39;s recent customer-focused Development Buddy Summit sent me to the books -- the ITIL® books that is -- hunting for an answer. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In a one-on-one conference, a customer asked me if it was appropriate to use &amp;quot;people CIs&amp;quot; in the CMDB to track subscribers to services.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Hmmm. Technically, the CA CMDB can support such a practice. After all, it has a CI family representing people that can be connected with applications such as HR and LDAP (Lightweight Directory Access Protocol that helps you locate individuals and other resources on the Internet or on an intranet) that specialize in information about people. Theoretically, those &amp;quot;people CIs&amp;quot; could have a &amp;quot;subscribes to&amp;quot; relationship with service CIs. But maintaining these &amp;quot;people CIs&amp;quot; would be a predominantly manual process that would not scale easily throughout an enterprise.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I suggested that CA Service Catalog could be the solution as it is designed to track and manage subscriptions to services.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Though I had provided an answer, the nagging question followed me back to my hotel room and kept me awake that night. When a customer asks for something, I like to examine the need in depth. If one client perceives a need, then others might as well and that could lead to useful product enhancements.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This question sent me to the ITIL v3 library for an answer. If ITIL suggested using people CIs to represent service subscribers, then perhaps we should consider putting more support for it into the CA CMDB.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;After hours of research that took me through several ITIL v3 volumes, I concluded that ITIL does not suggest using people CIs in this manner.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The ITIL v3 Service Transition publication does list &amp;quot;people&amp;quot; as potential CIs, but only in two types of CIs. The first type of CI that includes people is the Service Capability CI. This represents the intangible capabilities or expertise that organizations, functions, teams, or people have to design, implement, operate, and maintain services. The second type of CI is the Service Resource CI. Service resources are tangible assets that can be drawn upon for services. A person is a service resource when he or she is employed to design implement, operate, or maintain services.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Subscribers, users or customers of a service are neither service resources nor service capabilities. Rather than contributing to a service, they receive value from a service.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;ITIL talks about services as a way for users to assign costs and risks to a service supplier. In other words, service users are seeking to gain the benefits of service capabilities and service resources without taking on the risk of owning these capabilities or resources. Therefore, although ITIL v3 suggests people be included in the CMDB, it does not suggest service subscribers, users or customers should be CIs.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Since ITIL is good practice, not law, I did entertain the notion of including service customers in the CMDB even though this practice was not mentioned by the ITIL authors. Ultimately, I decided against it. SACM (Service Asset and Configuration Management, the processes that own the CMDB) focuses on supporting the implementation of service designs that represent solutions that meet requirements based upon enterprise business strategies. That is a tall order, but it does not include managing the users of services. Loading the CMDB up with subscribers, users and customers is bound to invite confusion and error.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The conclusion I came to after several days of research matched the answer I gave during my client meeting: A service subscription catalog, which is designed to support the customer-to-service relationship, is the right place to house service subscriber, user and customer information.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I don&amp;#39;t regret having invested the time. Researching answers is my favorite way to learn. Plus, I&amp;#39;m sleeping soundly once again.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;ITIL® is a Registered Trade Mark, and a Registered Community Trade Mark of the Office of Government Commerce, and is Registered in the U.S. Patent and Trademark Office.&lt;/i&gt;&lt;/p&gt;
&lt;div class = "shareblock"&gt;&lt;strong&gt;Share this post:&lt;/strong&gt; &lt;a title="Email Should+Service+Users+Be+Tracked+as+CIs+in+the+CMDB%3f+" href = "mailto:?body=Thought you might like this: http://community.ca.com/blogs/itservice/archive/2008/04/01/should-service-users-be-tracked-as-cis-in-the-cmdb.aspx&amp;subject=Should+Service+Users+Be+Tracked+as+CIs+in+the+CMDB%3f+"&gt;Email it!&lt;/a&gt; | &lt;a href = "http://del.icio.us/post?url=http://community.ca.com/blogs/itservice/archive/2008/04/01/should-service-users-be-tracked-as-cis-in-the-cmdb.aspx&amp;title=Should+Service+Users+Be+Tracked+as+CIs+in+the+CMDB%3f+" title="Submit Should+Service+Users+Be+Tracked+as+CIs+in+the+CMDB%3f+ to del.icio.us" &gt;bookmark it!&lt;/a&gt; | &lt;a href = "http://www.digg.com/submit?url=http://community.ca.com/blogs/itservice/archive/2008/04/01/should-service-users-be-tracked-as-cis-in-the-cmdb.aspx&amp;phase=2" title="Submit Should+Service+Users+Be+Tracked+as+CIs+in+the+CMDB%3f+ to digg.com"&gt;digg it!&lt;/a&gt; | &lt;a href = "http://reddit.com/submit?url=http://community.ca.com/blogs/itservice/archive/2008/04/01/should-service-users-be-tracked-as-cis-in-the-cmdb.aspx&amp;title=Should+Service+Users+Be+Tracked+as+CIs+in+the+CMDB%3f+" title="Submit Should+Service+Users+Be+Tracked+as+CIs+in+the+CMDB%3f+ to reddit.com"&gt;reddit!&lt;/a&gt;&lt;/div&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=1084" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/itservice/archive/tags/ITIL/default.aspx">ITIL</category><category domain="http://community.ca.com/blogs/itservice/archive/tags/CMDB/default.aspx">CMDB</category></item><item><title>CA Multiple Products DSM ListCtrl ActiveX Control Buffer Overflow Vulnerability</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/03/28/ca-multiple-products-dsm-listctrl-activex-control-buffer-overflow-vulnerability.aspx</link><pubDate>Fri, 28 Mar 2008 12:39:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1073</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;On March 28th, 2008 CA published a security notice to address a vulnerability in CA products that implement the DSM ListCtrl ActiveX control.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Title: CA Multiple Products DSM ListCtrl ActiveX Control Buffer Overflow Vulnerability&lt;br /&gt;&lt;br /&gt;CVE: CVE-2008-1472&lt;br /&gt;&lt;br /&gt;CA Advisory Date: 2008-03-28&lt;br /&gt;&lt;br /&gt;Reported By: Exploit code posted at milw0rm.com&lt;br /&gt;&lt;br /&gt;Impact: A remote attacker can cause a denial of service or execute arbitrary code.&lt;br /&gt;&lt;br /&gt;Summary: CA products that implement the DSM ListCtrl ActiveX control are vulnerable to a buffer overflow condition that can allow a remote attacker to cause a denial of service or execute arbitrary code with the privileges of the user running the web browser. The vulnerability, CVE-2008-1472, is due to insufficient bounds checking on the ListCtrl AddColumn function.&lt;br /&gt;&lt;br /&gt;Mitigating Factors: For BrightStor ARCserve Backup for Laptops &amp;amp; Desktops, only the server installation is affected. Client installations are not affected. For CA Desktop Management Suite, Unicenter Desktop Management Bundle, Unicenter Asset Management, Unicenter Software Delivery and Unicenter Remote Control, only the Managers and DSM Explorers are affected. Scalability Servers and agents are not affected. &lt;br /&gt;&lt;br /&gt;Severity: CA has given this vulnerability a maximum risk rating of High.&lt;br /&gt;&lt;br /&gt;Affected Products:&lt;br /&gt;BrightStor ARCServe Backup for Laptops and Desktops r11.5&lt;br /&gt;CA Desktop Management Suite r11.2 C1&lt;br /&gt;CA Desktop Management Suite r11.2a&lt;br /&gt;CA Desktop Management Suite r11.2&lt;br /&gt;CA Desktop Management Suite r11.1 (GA, a, C1)&lt;br /&gt;Unicenter Desktop Management Bundle r11.2 C1&lt;br /&gt;Unicenter Desktop Management Bundle r11.2a&lt;br /&gt;Unicenter Desktop Management Bundle r11.2&lt;br /&gt;Unicenter Desktop Management Bundle r11.1 (GA, a, C1)&lt;br /&gt;Unicenter Asset Management r11.2 C1&lt;br /&gt;Unicenter Asset Management r11.2a&lt;br /&gt;Unicenter Asset Management r11.2&lt;br /&gt;Unicenter Asset Management r11.1 (GA, a, C1)&lt;br /&gt;Unicenter Software Delivery r11.2 C1&lt;br /&gt;Unicenter Software Delivery r11.2a&lt;br /&gt;Unicenter Software Delivery r11.2&lt;br /&gt;Unicenter Software Delivery r11.1 (GA, a, C1)&lt;br /&gt;Unicenter Remote Control r11.2 C1&lt;br /&gt;Unicenter Remote Control r11.2a&lt;br /&gt;Unicenter Remote Control r11.2&lt;br /&gt;Unicenter Remote Control r11.1 (GA, a, C1)&lt;br /&gt;&lt;br /&gt;Affected Platforms:&lt;br /&gt;Windows&lt;br /&gt;&lt;br /&gt;Status and Recommendation:&lt;br /&gt;CA has provided the following updates to address the vulnerabilities.&lt;br /&gt;&lt;br /&gt;BrightStor ARCserve Backup for Laptops and Desktops r11.5:&lt;br /&gt;QO96102&lt;br /&gt;&lt;br /&gt;CA Desktop Management Suite for Windows r11.1 (GA, a, C1),&lt;br /&gt;Unicenter Desktop Management Bundle r11.1 (GA, a, C1),&lt;br /&gt;Unicenter Asset Management r11.1 (GA, a, C1),&lt;br /&gt;Unicenter Software Delivery r11.1 (GA, a, C1),&lt;br /&gt;Unicenter Remote Control r11.1 (GA, a, C1):&lt;br /&gt;QO96088&lt;br /&gt;&lt;br /&gt;CA Desktop Management Suite for Windows r11.2a,&lt;br /&gt;Unicenter Desktop Management Bundle r11.2a,&lt;br /&gt;Unicenter Asset Management r11.2a,&lt;br /&gt;Unicenter Software Delivery r11.2a,&lt;br /&gt;Unicenter Remote Control r11.2a:&lt;br /&gt;QO96092&lt;br /&gt;&lt;br /&gt;CA Desktop Management Suite for Windows r11.2,&lt;br /&gt;Unicenter Desktop Management Bundle r11.2,&lt;br /&gt;Unicenter Asset Management r11.2,&lt;br /&gt;Unicenter Software Delivery r11.2,&lt;br /&gt;Unicenter Remote Control r11.2:&lt;br /&gt;QO96091&lt;br /&gt;&lt;br /&gt;CA Desktop Management Suite for Windows r11.2 C1,&lt;br /&gt;Unicenter Desktop Management Bundle r11.2 C1,&lt;br /&gt;Unicenter Asset Management r11.2 C1,&lt;br /&gt;Unicenter Software Delivery r11.2 C1,&lt;br /&gt;Unicenter Remote Control r11.2 C1:&lt;br /&gt;QO96090&lt;br /&gt;&lt;br /&gt;How to determine if you are affected:&lt;br /&gt;For products on Windows:&lt;br /&gt;&amp;nbsp;&amp;nbsp; 1. Using Windows Explorer, locate the file &amp;quot;ListCtrl.ocx&amp;quot;. By default, the file is in the &amp;quot;C:\Program Files\CA\DSM\bin\&amp;quot; directory.&lt;br /&gt;&amp;nbsp;&amp;nbsp; 2. Right click on the file and select Properties.&lt;br /&gt;&amp;nbsp;&amp;nbsp; 3. Select the Version tab.&lt;br /&gt;&amp;nbsp;&amp;nbsp; 4. If the file version is earlier than indicated in the below table, the installation is vulnerable.&lt;br /&gt;&lt;br /&gt;Product:&lt;br /&gt;&amp;nbsp;&amp;nbsp; CA Desktop Management Suite for Windows r11.1 (GA, a, C1),&lt;br /&gt;&amp;nbsp;&amp;nbsp; Unicenter Desktop Management Bundle r11.1 (GA, a, C1),&lt;br /&gt;&amp;nbsp;&amp;nbsp; Unicenter Asset Management r11.1 (GA, a, C1),&lt;br /&gt;&amp;nbsp;&amp;nbsp; Unicenter Software Delivery r11.1 (GA, a, C1),&lt;br /&gt;&amp;nbsp;&amp;nbsp; Unicenter Remote Control r11.1 (GA, a, C1)&lt;br /&gt;File Name: ListCtrl.ocx&lt;br /&gt;File Version: 11.1.8124.0&lt;br /&gt;&lt;br /&gt;Product:&lt;br /&gt;&amp;nbsp;&amp;nbsp; CA Desktop Management Suite for Windows r11.2,&lt;br /&gt;&amp;nbsp;&amp;nbsp; Unicenter Desktop Management Bundle r11.2,&lt;br /&gt;&amp;nbsp;&amp;nbsp; Unicenter Asset Management r11.2,&lt;br /&gt;&amp;nbsp;&amp;nbsp; Unicenter Software Delivery r11.2,&lt;br /&gt;&amp;nbsp;&amp;nbsp; Unicenter Remote Control r11.2 &amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;File Name: ListCtrl.ocx &amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;File Version: 11.2.1000.16&lt;br /&gt;&lt;br /&gt;Product:&lt;br /&gt;&amp;nbsp;&amp;nbsp; CA Desktop Management Suite for Windows r11.2a,&lt;br /&gt;&amp;nbsp;&amp;nbsp; Unicenter Desktop Management Bundle r11.2a,&lt;br /&gt;&amp;nbsp;&amp;nbsp; Unicenter Asset Management r11.2a,&lt;br /&gt;&amp;nbsp;&amp;nbsp; Unicenter Software Delivery r11.2a,&lt;br /&gt;&amp;nbsp;&amp;nbsp; Unicenter Remote Control r11.2a &lt;br /&gt;File Name: ListCtrl.ocx &lt;br /&gt;File Version: 11.2.1000.16&lt;br /&gt;&lt;br /&gt;Product:&lt;br /&gt;&amp;nbsp;&amp;nbsp; CA Desktop Management Suite for Windows r11.2 C1,&lt;br /&gt;&amp;nbsp;&amp;nbsp; Unicenter Desktop Management Bundle r11.2 C1,&lt;br /&gt;&amp;nbsp;&amp;nbsp; Unicenter Asset Management r11.2 C1,&lt;br /&gt;&amp;nbsp;&amp;nbsp; Unicenter