<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/online/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title>Research on Security and Identity Management (by Marco Casassa Mont) : risk management</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/tags/risk+management/default.aspx</link><description>Tags: risk management</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>ENISA Cloud Computing Risk Assessment Report</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2009/11/21/120138.aspx</link><pubDate>Fri, 20 Nov 2009 18:35:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:120138</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/11/21/120138.aspx#comments</comments><description>&lt;p&gt;&lt;a href="http://www.enisa.europa.eu/"&gt;ENISA&lt;/a&gt; has recently released three documents related to Cloud Computing, all of them available online:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.enisa.europa.eu/act/rm/files/deliverables/cloud-computing-risk-assessment/"&gt;Cloud Computing Risk Assessment&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.enisa.europa.eu/act/rm/files/deliverables/cloud-computing-information-assurance-framework/"&gt;Cloud Computing Information Assurance&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.enisa.europa.eu/act/rm/files/deliverables/cloud-computing-sme-survey"&gt;Cloud Computing SME Perspective Survey&lt;/a&gt; &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Enjoy.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=120138" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/risk+management/default.aspx">risk management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Cloud+computing/default.aspx">Cloud computing</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Enisa/default.aspx">Enisa</category></item><item><title>Article: Changing business landscape makes IAM key to IT Security</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/20/article-changing-business-landscape-makes-iam-key-to-it-security.aspx</link><pubDate>Wed, 19 Nov 2008 17:24:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:86687</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/20/article-changing-business-landscape-makes-iam-key-to-it-security.aspx#comments</comments><description>&lt;p&gt;Here is a recent, interesting article, called &amp;quot;&lt;a href="http://blogs.zdnet.com/Gardner/?p=2758"&gt;Changing business landscape makes identity and access management key to IT security&lt;/a&gt;&amp;quot;:&lt;/p&gt;
&lt;p&gt;&amp;quot;In an age of significant layoffs and corporate restructuring, the burgeoning problem of identity and access management for IT operations and data centers has escalated into a critical security issue. Managing who gets access to which resources for how long - and under what circumstances - has become a huge and thorny problem. Improper and overextended access to sensitive data and powerful applications can cause massive risk as many employees find themselves in flux.&amp;quot;&lt;/p&gt;
&lt;p&gt;This article provides some excerpts from a discussion with Dan Rueckert (worldwide practice director for security and risk management in HP&amp;#39;s Consulting and Integration group); Archie Reed (distinguished technologist in HP&amp;#39;s security office in the Enterprise Storage and Server Group), and Mark Tice (vice president of identity management at Oracle).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=86687" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/risk+management/default.aspx">risk management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/IAM/default.aspx">IAM</category></item><item><title>Part II: Risk Management for Unstructured Data in Enterprises</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/09/04/part-ii-risk-management-for-unstructured-data-in-enterprises.aspx</link><pubDate>Thu, 04 Sep 2008 13:09:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:84600</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>2</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/09/04/part-ii-risk-management-for-unstructured-data-in-enterprises.aspx#comments</comments><description>&lt;p&gt;In a recent post published on the &lt;a href="http://sgciam.wordpress.com/2008/09/04/risk-management-and-information/"&gt;Netweaver Identity Manager Weblog&lt;/a&gt;, the author&amp;nbsp; has made a few comments about my post on &lt;a href="http://www.communities.hp.com/online/blogs/mcm/archive/2008/09/02/risk-management-for-unstructured-data-in-enterprises.aspx"&gt;&amp;quot;Risk Management for Unstructured Data in Enterprises&amp;quot;&lt;/a&gt; (well, actually the published URL to my post is apparently broken ...). &lt;/p&gt;
&lt;p&gt;Thanks for this input, in particular about three main points that I (tried to) summarise as it follows:&lt;/p&gt;
&lt;p&gt;1) Meaning of unstructured data (or the fact that unstructured data does not exist by definition ...)&lt;/p&gt;
&lt;p&gt;2) Narrowness of perception of approaches and incompleteness of my list of required solutions&lt;/p&gt;
&lt;p&gt;3) Availability of comprehensive methodology for implementing enterprise wide risk management&lt;/p&gt;
&lt;p&gt;About point 1), this looks pretty much a philosophical discussion. No doubt that, at the end, we talk about information that has some sort of structure (well, an email has a header, a body with some texts and attachments; a document is made of paragraphs or lines of text; ...). However, the (maybe over-hyped) &amp;quot;unstructured data&amp;quot; term is currently used to (a) identify specific types of information and (b) contrast it against classic &amp;quot;structured data&amp;quot; (e.g. information stored in RDBMS repositories, etc.).&amp;nbsp; I think I will stick with this terminology ...&lt;/p&gt;
&lt;p&gt;Back to the key point, recent reports (including the Ponemon Institute&amp;#39;s survey on &amp;quot;Governance of Unstructured Data&amp;quot; and other market and research reports) indeed highlight that the management of unstructured data in enterprises is a raising concern for enterprises, both in terms of governance and risk management. I think this is what really matters - independently from the terminology.&lt;/p&gt;
&lt;p&gt;No doubt that classification of data is an important point, especially if you ever manage to &amp;quot;find&amp;quot; where this &amp;quot;unstructured data&amp;quot; is, within a complex enterprise environment ... I would say that, given the particular nature of &amp;quot;unstructured data&amp;quot;, a preliminary &amp;quot;data discovery&amp;quot; phase might be required, indeed followed by a classification and assessment of its value (considering though, that the value of some of this information might also come from aggregations and correlations ...).&lt;/p&gt;
&lt;p&gt;About point 2), by no means my post was meant to provide a definitive or comprehensive assessment and answer to the problem of information risk management or, more specifically, on &amp;quot;unstructured&amp;quot; information risk management. It was just a statement of some &amp;quot;desirable&amp;quot; properties and capabilities that I would like to see (and I know it would be of some help to customers ...).&lt;/p&gt;
&lt;p&gt;I am well aware of the complexity of the overall &amp;nbsp;(security) &amp;quot;enterprise risk assessment and management&amp;quot; problem, its extent and the fact that, when assessing and managing (security) risks, many factors are involved, including business goals, IT, other assets, people, processes, awareness/education, etc.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;(Security) risk assessment and management techniques/methodologies/frameworks and standards/etc. are indeed out there (e.g. ISO 27005/2700x, CoBIT, etc.). These &amp;quot;standards&amp;quot; provide guidelines and criteria to be carefully refined, grounded and contextualized in various &amp;quot;operational&amp;quot; realities, along with some good, common sense ...&lt;/p&gt;
&lt;p&gt;So, no doubt that there are already &amp;quot;comprehensive methodology for implementing enterprise wide risk management&amp;quot;, at least from a consulting perspective, but this was not my main point. &lt;/p&gt;
&lt;p&gt;My main point was not so focused on these methodologies but rather on the need to better understand and possibly improve the process of exploring, explaining and predicting the consequences and impacts of strategic (policy) choices and decisions in enterprise contexts and environments, in particular when dealing with security matters. &lt;/p&gt;
&lt;p&gt;An approach that we are currently exploring is based on modeling and simulation techniques in the security field, coupled with economic theory and social science. Please have a look at the &lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-84.html"&gt;HPL Technical Report on &amp;quot;Identity Analytics&amp;quot;&lt;/a&gt; that I mentioned a few times - to see what I mean, in more details (at least from an &amp;quot;IdM perspective&amp;quot;). &lt;/p&gt;
&lt;p&gt;Specifically, one of my R&amp;amp;D interests is in &amp;quot;(semi-) automation&amp;quot; tools and solutions in this space that can indeed help and support professional and consulting services in their risk assessment &amp;amp; management activities. This includes providing decision support and &amp;quot;what-if analysis&amp;quot;, involving modeling and simulation, providing trade-off analysis, etc. &lt;/p&gt;
&lt;p&gt;Given the complexity of this space, I deliberately focused on the aspect of &amp;quot;management of unstructured data&amp;quot; and the IdM perspective, well conscious this is just a part of the overall problem and space. &lt;/p&gt;
&lt;p&gt;I hope I clarified this point.&lt;/p&gt;
&lt;p&gt;About point 3), no doubt about this, as I mentioned above.&lt;/p&gt;
&lt;p&gt;However the statement that &amp;quot;comprehensive methodology for implementing enterprise wide risk management is done&amp;quot; sounds (at least to me) sounds a little bit abstract to me ... &lt;/p&gt;
&lt;p&gt;It would be of some interest to the readers of this blog if this statement could be elaborated (specifically in the space of IdM and information management) along with providing some recommendations/input/directions (hopefully beyond having to hire a consulting company ...:-)).&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;--- NOTE:&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;use this &lt;/font&gt;&lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;&lt;font face="Times New Roman" size="3"&gt;mirror blog&lt;/font&gt;&lt;/a&gt;&lt;font face="Times New Roman" size="3"&gt; if you prefer posting on an external blog site &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;---&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=84600" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/risk+management/default.aspx">risk management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Security+Analytics/default.aspx">Security Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Unstructured+Data/default.aspx">Unstructured Data</category></item><item><title>Risk Management for Unstructured Data in Enterprises</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/09/02/risk-management-for-unstructured-data-in-enterprises.aspx</link><pubDate>Mon, 01 Sep 2008 16:21:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:84551</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/09/02/risk-management-for-unstructured-data-in-enterprises.aspx#comments</comments><description>&lt;p&gt;In the context of the HP Labs&amp;#39; Security and &lt;a href="http://www.hpl.hp.com/personal/Marco_Casassa_Mont/Projects/IdentityAnalytics/IdentityAnalytics.htm"&gt;Identity Analytics&lt;/a&gt; project I have been investigating the implications of &amp;quot;unstructured data&amp;quot; (i.e. emails, documents, multimedia files, pages in data sharing sites, messages exchanged with Instant Messaging tools, blog posts, data mash-ups, etc.) within organizations, along with how to explain and predict involved risks and explore the consequences of related security (policy) choices.&lt;/p&gt;
&lt;p&gt;Is &amp;quot;unstructured data&amp;quot; really a problem for organizations? If so, where is this problem? Well, the content of unstructured data (and/or an aggregation of it) can be confidential as it might include personal, financial and business-critical information. Because of the nature of unstructured data (and associated, emerging tools to handle and share it), there are many ways this data could leak and/or be misused, ranging from accidental disclosures to aggregations of information posted in public areas.&lt;/p&gt;
&lt;p&gt;The threat landscape (including threats to data confidentiality, integrity and availability) is potentially broad as many contextual elements, IT components, processes and behavioral aspects are involved.&lt;/p&gt;
&lt;p&gt;Most of the current approaches (I am aware of), that mitigate some of the involved risks, are based on traditional IT security and identity &amp;quot;control points&amp;quot; (such as access control, interception points, complex document lifecycle management tools, etc.), addressing &amp;quot;point problems&amp;quot;.&lt;/p&gt;
&lt;p&gt;I believe this is not enough. Solutions are required to help organizations (and decision makers) to: (1) fully understand the nature of the problem, based on their specific context and environment; (2) have a picture of their overall risk exposure; (3) make informed decisions on which approaches to follow, explain and predict the consequences and define appropriate policies; (3) explore trade-offs.&lt;/p&gt;
&lt;p&gt;So far I have found no comprehensive approach/solution providing these features. Is anybody aware of any? &lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=84551" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/risk+management/default.aspx">risk management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Unstructured+Data/default.aspx">Unstructured Data</category></item><item><title>The Future of Identity Management? It is all about Managing Risk …</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/06/29/the-future-of-identity-management-it-is-all-about-managing-risk.aspx</link><pubDate>Sat, 28 Jun 2008 17:57:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83491</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>2</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/06/29/the-future-of-identity-management-it-is-all-about-managing-risk.aspx#comments</comments><description>&lt;p&gt;&lt;font face="times new roman,times" size="3"&gt;As I have been posting for a while, I believe that Identity Management will evolve, during the next few years, from a pure “control point and compliance”-based approach towards an approach that will increasingly factor in the management of Risk.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="times new roman,times" size="3"&gt;Decision makers (CIOs, CISOs, etc.) are shifting from a “compliance management” mentality to a “risk management” mentality, when making investment decisions on IT security solutions. Their investment decisions (including the ones on Identity Management) are going to be increasingly questioned, due to the shrinking of resources available. Hence the need to prioritise based on real business objectives and needs.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="times new roman,times" size="3"&gt;I am glad that Burton Group is now making some statements in the same direction, as it is possible to evince from &lt;span style="FONT-SIZE:12pt;FONT-FAMILY:&amp;#39;Times New Roman&amp;#39;;mso-ansi-language:EN-GB;mso-fareast-font-family:&amp;#39;Times New Roman&amp;#39;;mso-fareast-language:EN-GB;mso-bidi-language:AR-SA;"&gt;&lt;span style="FONT-SIZE:12pt;FONT-FAMILY:&amp;#39;Times New Roman&amp;#39;;mso-ansi-language:EN-US;mso-fareast-font-family:&amp;#39;Times New Roman&amp;#39;;mso-fareast-language:EN-GB;mso-bidi-language:AR-SA;"&gt;&lt;a href="http://www.networkworld.com/news/2008/062608-catalyst-risk-id-management.html?page=1"&gt;this article&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;:&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="times new roman,times" size="3"&gt;“Identity management is evolving to include a closer recognition of risk and how to manage it rather than trying to eliminate it using technology, according to the head of the Burton Group consulting firm. &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="times new roman,times" size="3"&gt;“Companies are looking at controls from a risk perspective instead of trying to control everything,” said Jamie Lewis, CEO of the Burton Group during the opening day of the firm’s annual Catalyst Conference. “It is about people managing risk and not about technology trying to make risk disappear.””&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="times new roman,times" size="3"&gt;I believe there is a whole new set of research and commercial opportunities in this space (i.e. beyond compliance management and control points), whilst traditional Identity Management solutions are becoming more and more a commodity.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;font face="times new roman,times" size="3"&gt;--- NOTE:&amp;nbsp; use this &lt;span style="FONT-SIZE:12pt;FONT-FAMILY:&amp;#39;Times New Roman&amp;#39;;mso-ansi-language:EN-GB;mso-fareast-font-family:&amp;#39;Times New Roman&amp;#39;;mso-fareast-language:EN-GB;mso-bidi-language:AR-SA;"&gt;&lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt;&amp;nbsp;&lt;/span&gt;if you prefer posting on an external blog site&amp;nbsp; ---&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83491" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/risk+management/default.aspx">risk management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category></item><item><title>Article: “50 Ways to Take Back Control of Your Personal Data”</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/06/11/article-50-ways-to-take-back-control-of-your-personal-data.aspx</link><pubDate>Wed, 11 Jun 2008 15:56:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83217</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/06/11/article-50-ways-to-take-back-control-of-your-personal-data.aspx#comments</comments><description>&lt;span style="COLOR:black;"&gt;&lt;font face="Times New Roman" size="3"&gt;Have a look at this very interesting article, called “&lt;/font&gt;&lt;a href="http://www.insidecrm.com/features/50-ways-take-control-data061008/"&gt;&lt;font face="Times New Roman" size="3"&gt;50 Ways to Take Back Control of Your Personal Data&lt;/font&gt;&lt;/a&gt;&lt;font face="Times New Roman" size="3"&gt;”, by&lt;/font&gt;&lt;a href="http://www.insidecrm.com/"&gt;&lt;font face="Times New Roman" size="3"&gt; InsideCRM&lt;/font&gt;&lt;/a&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt; providing a useful list of tips and “common sense” (but quite often forgotten …) ways to protect your personal data, maintaining degrees of control on it and reduce your risk exposure to identity thefts, financial losses and other crimes.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;span style="COLOR:black;"&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt;&lt;span style="COLOR:black;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;These tips are organised by categories, in terms of:&lt;/font&gt;&lt;/font&gt;&lt;/span&gt; 
&lt;ul style="MARGIN-TOP:0pt;"&gt;
&lt;li class="MsoNormal" style="MARGIN:0pt;COLOR:black;mso-list:l0 level1 lfo1;tab-stops:list 36.0pt;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;Web Privacy&lt;/font&gt;&lt;/font&gt;&lt;/li&gt;
&lt;li class="MsoNormal" style="MARGIN:0pt;COLOR:black;mso-list:l0 level1 lfo1;tab-stops:list 36.0pt;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;Credit and Finance&lt;/font&gt;&lt;/font&gt;&lt;/li&gt;
&lt;li class="MsoNormal" style="MARGIN:0pt;COLOR:black;mso-list:l0 level1 lfo1;tab-stops:list 36.0pt;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;General Privacy&lt;/font&gt;&lt;/font&gt;&lt;/li&gt;
&lt;li class="MsoNormal" style="MARGIN:0pt;COLOR:black;mso-list:l0 level1 lfo1;tab-stops:list 36.0pt;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;Cell Phones and Online Phone Services&lt;/font&gt;&lt;/font&gt;&lt;/li&gt;
&lt;li class="MsoNormal" style="MARGIN:0pt;COLOR:black;mso-list:l0 level1 lfo1;tab-stops:list 36.0pt;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;Rules to follow to Protect Your Privacy &lt;/font&gt;&lt;/font&gt;&lt;/li&gt;
&lt;li class="MsoNormal" style="MARGIN:0pt;mso-list:l0 level1 lfo1;tab-stops:list 36.0pt;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;span style="COLOR:black;"&gt;Tools and tips &lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font face="Times New Roman" size="3"&gt;&lt;/font&gt;&lt;/span&gt;
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;--- NOTE:&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;use this &lt;/font&gt;&lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;&lt;font face="Times New Roman" size="3"&gt;mirror blog&lt;/font&gt;&lt;/a&gt;&lt;font face="Times New Roman" size="3"&gt; if you prefer posting on an external blog site &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;---&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83217" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Privacy/default.aspx">Privacy</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/risk+management/default.aspx">risk management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/privacy+tips/default.aspx">privacy tips</category></item></channel></rss>