<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.gsihosting.com/~d/styles/itemcontent.css"?><rss xmlns:blogChannel="http://backend.userland.com/blogChannelModule" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:pingback="http://madskills.com/public/xml/rss/module/pingback/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
  <channel>
    <title>GSI Blog: The Nest</title>
    <description>The official GSI Blog</description>
    <link>http://www.gsihosting.com/blog/</link>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>BlogEngine.NET 1.5.1.0</generator>
    <language>en-US</language>
    <blogChannel:blogRoll>http://www.gsihosting.com/blog/opml.axd</blogChannel:blogRoll>
    <blogChannel:blink>http://www.dotnetblogengine.net/syndication.axd</blogChannel:blink>
    <dc:creator>GSI</dc:creator>
    <dc:title>GSI Blog: The Nest</dc:title>
    <geo:lat>0.000000</geo:lat>
    <geo:long>0.000000</geo:long>
    <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.gsihosting.com/gsihosting" /><feedburner:info uri="gsihosting" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
      <title>Join GSI at the Kansas City Interface 2010 Conference... Because the Threat Never Sleeps</title>
      <description>&lt;p&gt;We hope you can join GSI at Interface 2010, the industry's leading security and disaster recovery conference offered today. Interface is a single-day IT conference addressing the advances in information security, disaster recovery, business continuity, data storage and regulatory compliance. The conference is put on by Face-to-Face Events, and will truly hold up to that name. Interface prides itself on educating, as opposed to selling, and provides the optimal setting for &amp;ldquo;B2B matchmaking&amp;rdquo; and quality face-to-face time.&lt;/p&gt;
&lt;p&gt;GSI will be exhibiting at the conference, so please stop by our booth to learn how we can help with your security and business needs. GSI's security and disaster recovery expertise is second to none. We were the first hosting company in the world to meet the stringent security criteria imposed by the payment card industry (PCI) in 2004, by becoming 100% PCI DSS compliant for managed services. Since then, we have helped numerous clients achieve and maintain their own security compliance, and we continue to perfect our processes and ability to address the critical security needs of our clients.&lt;/p&gt;
&lt;p&gt;Interface will be held Thursday, May 13, at the Kansas City Downtown Marriott from 9:00 a.m. to 4:30 p.m. &lt;strong&gt;The event is by invitation only, so please contact Kristine Hansen, our business development manager, to RSVP.&lt;/strong&gt; She can be reached at &lt;a href="mailto:khansen@gsihosting.com"&gt;khansen@gsihosting.com&lt;/a&gt; or (816) 222-1210. Also, you can check out the events page on our website to RSVP: &lt;a href="http://www.gsihosting.com/events/"&gt;http://www.gsihosting.com/events&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;For more information about Interface 2010, you can visit &lt;a href="http://www.f2fevents.com/"&gt;http://www.f2fevents.com/&lt;/a&gt;. We look forward to seeing you there and hope everyone has a safe and secure day!&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=yGQ-zKtUZsc:k61_vOEBmwc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=yGQ-zKtUZsc:k61_vOEBmwc:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=yGQ-zKtUZsc:k61_vOEBmwc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=yGQ-zKtUZsc:k61_vOEBmwc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=yGQ-zKtUZsc:k61_vOEBmwc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=yGQ-zKtUZsc:k61_vOEBmwc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=yGQ-zKtUZsc:k61_vOEBmwc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=yGQ-zKtUZsc:k61_vOEBmwc:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=yGQ-zKtUZsc:k61_vOEBmwc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=yGQ-zKtUZsc:k61_vOEBmwc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=yGQ-zKtUZsc:k61_vOEBmwc:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/gsihosting/~4/yGQ-zKtUZsc" height="1" width="1"/&gt;</description>
      <link>http://feeds.gsihosting.com/~r/gsihosting/~3/yGQ-zKtUZsc/post.aspx</link>
      <author>ckephart</author>
      <comments>http://www.gsihosting.com/blog/post/2010/05/10/Join-GSI-at-the-Kansas-City-Interface-2010-Conference-Because-the-Threat-Never-Sleeps.aspx#comment</comments>
      <guid isPermaLink="false">http://www.gsihosting.com/blog/post.aspx?id=f594fbf4-cc3d-41fb-89d0-d7fa86e76fc0</guid>
      <pubDate>Mon, 10 May 2010 13:04:00 -0500</pubDate>
      <category>Events &amp; Marketing</category>
      <dc:publisher>ckephart</dc:publisher>
      <pingback:server>http://www.gsihosting.com/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.gsihosting.com/blog/post.aspx?id=f594fbf4-cc3d-41fb-89d0-d7fa86e76fc0</pingback:target>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.gsihosting.com/blog/trackback.axd?id=f594fbf4-cc3d-41fb-89d0-d7fa86e76fc0</trackback:ping>
      <wfw:comment>http://www.gsihosting.com/blog/post/2010/05/10/Join-GSI-at-the-Kansas-City-Interface-2010-Conference-Because-the-Threat-Never-Sleeps.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.gsihosting.com/blog/syndication.axd?post=f594fbf4-cc3d-41fb-89d0-d7fa86e76fc0</wfw:commentRss>
    <feedburner:origLink>http://www.gsihosting.com/blog/post.aspx?id=f594fbf4-cc3d-41fb-89d0-d7fa86e76fc0</feedburner:origLink></item>
    <item>
      <title>GSI Hosting Gets Fit</title>
      <description>&lt;p&gt;Congratulations to GSI's own Candace Sheldon, who was honored with being the "Most improved woman 50 or older" in Ingram's 2009-2010 Fittest Executives and Fittest Companies Challenge.&lt;/p&gt;
&lt;p&gt;&lt;img style="float:right;margin:10px 0 0 10px;" src="http://image.gsihosting.com/images/blog/candace-ingrams.jpg" alt="Candace Sheldon, winner of the 'most improved' award in Ingram's 2009-2010 Fittest Executives and Fittest Companies Challenge." width="209" height="400" /&gt;&lt;/p&gt;
&lt;p&gt;Candace joined up with three other GSI folks &amp;ndash; Mark Hotalling, Jerad Riggin and Adam Ward &amp;ndash; to compete in Ingram's challenge, which ran from October 1 through the end of 2009. The competition was based on the belief that a "top-down corporate emphasis on employee fitness could help achieve bottom-line results with a fitter work force." During the three-month challenge, participants were armed with detailed measurements of their own health metrics, and focused on their primary areas of concern, such as losing weight, or improving blood pressure and cholesterol levels, aerobic capacities, strength and flexibility measurements.&lt;/p&gt;
&lt;p&gt;Candace earned the "most improved" stature due to her improvement in all categories. She attributes her success in the program to both eating healthier and exercising regularly. She and her teammates committed themselves to working out in GSI's exercise facility 4-5 days a week &amp;ndash; specifically following the P90X workout regimen. Candace also eliminated sugar, flour products, and alcohol from her diet &amp;ndash; instead snacking on fruits, vegetables and more protein-rich foods. She followed the guidance of a nutritionist and also hit the tread mill every evening after work. And the results were great &amp;ndash; she lost 9 pounds during the competition (even including the holidays) and another 6 since then. Not only that, but Candace is now seriously motivated to continue her fitness routine.&lt;/p&gt;
&lt;p&gt;Candace signed up for the Ingram's challenge as part of GSI's corporate team, motivated by the thought of getting in better shape and losing a little weight, as well as the desire to set a good example for her GSI co-workers in promoting wellness. The support of her teammates, she says, made it easier to achieve positive results. Just like the premise GSI stands on as a company &amp;ndash; that the support our GSI ServerHeroes lend one another enables us to collectively achieve great things for our clients.&lt;/p&gt;
&lt;p&gt;"If you really decide you want to do something and are diligent in your approach, you can achieve anything," says Candace. Simply enough said, but a lesson for all of us in our personal and professional lives. Candace's success brings home the reason why I'm proud to work for a company like GSI with dedicated co-workers like her &amp;ndash; true to GSI's tagline, "Let's get it done right," we have the desire to achieve, and we take the extra measures to do so.&lt;/p&gt;
&lt;h2&gt;Further Reading&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel="nofollow" href="http://www.ingramsonline.com/Feb_2010/Images%20and%20Articles/Fittest%20Execs/FE%20Intro.html" target="_blank"&gt;Ingram's Magazine, Feb 2010 &amp;gt; Fittest Execs/Companies&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a rel="nofollow" href="http://www.ingramsonline.com/Feb_2010/Images%20and%20Articles/Fittest%20Execs/FE6.html" target="_blank"&gt;Ingram's Magazine, Feb 2010 &amp;gt; Fittest Execs/Companies &amp;gt; Most Improved Individuals&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=lq6wLchs3VU:ZFQZp3L6v7E:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=lq6wLchs3VU:ZFQZp3L6v7E:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=lq6wLchs3VU:ZFQZp3L6v7E:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=lq6wLchs3VU:ZFQZp3L6v7E:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=lq6wLchs3VU:ZFQZp3L6v7E:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=lq6wLchs3VU:ZFQZp3L6v7E:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=lq6wLchs3VU:ZFQZp3L6v7E:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=lq6wLchs3VU:ZFQZp3L6v7E:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=lq6wLchs3VU:ZFQZp3L6v7E:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=lq6wLchs3VU:ZFQZp3L6v7E:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=lq6wLchs3VU:ZFQZp3L6v7E:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/gsihosting/~4/lq6wLchs3VU" height="1" width="1"/&gt;</description>
      <link>http://feeds.gsihosting.com/~r/gsihosting/~3/lq6wLchs3VU/post.aspx</link>
      <author>ckephart</author>
      <comments>http://www.gsihosting.com/blog/post/2010/03/30/GSI-Hosting-Gets-Fit.aspx#comment</comments>
      <guid isPermaLink="false">http://www.gsihosting.com/blog/post.aspx?id=2b2cda98-438f-4329-8805-f927dd52a0f5</guid>
      <pubDate>Tue, 30 Mar 2010 18:28:00 -0500</pubDate>
      <category>Events &amp; Marketing</category>
      <dc:publisher>ckephart</dc:publisher>
      <pingback:server>http://www.gsihosting.com/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.gsihosting.com/blog/post.aspx?id=2b2cda98-438f-4329-8805-f927dd52a0f5</pingback:target>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.gsihosting.com/blog/trackback.axd?id=2b2cda98-438f-4329-8805-f927dd52a0f5</trackback:ping>
      <wfw:comment>http://www.gsihosting.com/blog/post/2010/03/30/GSI-Hosting-Gets-Fit.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.gsihosting.com/blog/syndication.axd?post=2b2cda98-438f-4329-8805-f927dd52a0f5</wfw:commentRss>
    <feedburner:origLink>http://www.gsihosting.com/blog/post.aspx?id=2b2cda98-438f-4329-8805-f927dd52a0f5</feedburner:origLink></item>
    <item>
      <title>Comparing managed service providers: SERVICES vs services</title>
      <description>&lt;p&gt;Part of selling GSI's managed services is dealing with the competitive comparison issue, as prospective clients attempt to determine which managed service provider is the best fit for their IT management needs. The need to compare GSI versus our competition is understandable, but what do you do when there is little to compare us against?&lt;/p&gt;
&lt;p&gt;The old and overused idiom, "Apples to Oranges" comes to mind, but does not accurately describe the situation. GSI is most often compared to "hosting" companies because we have hosting capabilities, but to say we are just a hosting company is grossly inaccurate. GSI is a managed services company with hosting capabilities. We provide the entire service &amp;ndash; soup to nuts. Most competitors, while they claim to offer a total solution, barely get to the soup.&lt;/p&gt;
&lt;p&gt;Maybe a metaphor using the auto repair industry can help clarify our situation as it relates to comparison shopping.&lt;/p&gt;
&lt;p style="text-align:center;"&gt;&lt;img src="http://www.gsihosting.com/images/blog/managed-services.jpg" alt="Comparing managed services versus MANAGED SERVICES" width="425" /&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Space.&lt;/strong&gt; Every auto repair shop must have a garage in which to put the equipment and vehicles involved. Much like IT hosting companies must have data centers. It is a given that one garage looks much like another. Picking an auto repair shop solely on the presence of a garage would not be prudent. The need for them to have a workable and available garage is a requirement, but you need more criteria to narrow down your comparison. The same goes for hosting companies and their data centers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Range of services.&lt;/strong&gt; Another area of comparison is the type of auto repair services and the expertise with which they are provided. A lot of shops provide standard services and have qualified technicians to provide those standard services on the most common vehicles. These services work fine for a standard high-production vehicle. What happens if your vehicle is a specialized, custom-built unit? The number of auto repair shops that can provide you services drastically decreases. Your selection now depends on the unique traits of the specialized services you require. This applies to IT services, as well. IT systems requiring advanced security and regulatory compliance necessitate specialized services, and narrow your service provider options.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Who performs the actual work?&lt;/strong&gt; Let's muddy the waters a bit and carry the metaphor further. Say you have narrowed your auto repair provider selection down to three shops. They all three advertise knowledge of your specialized vehicle. Each shop defines their services using similar terms. Even so, as you dig into one shop's methods, you find that they provide work space and tools, but do not actually do the work. You and your brother-in-law will need to be available to actually perform any work. This kind of discrepancy can be very difficult to discover when picking an IT services provider, and it is painful to realize it after contracts have been signed with an auditor breathing down your neck.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Do they need direction from you?&lt;/strong&gt; So, now you are down to two shops that may be able to perform work on your specialized vehicle. As you question the two, you again find a deficiency in one of them. They have the capabilities, the tools and the space, but they can only do exactly what you tell them to. They cannot or will not assist with designing your solution, and cannot point out issues you will encounter, much less account for them. This, again, puts you in a hot seat. Your services contract has turned into space and tools for you to implement.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Finally ... the needle in the haystack.&lt;/strong&gt; The last shop you review meets all the requirements and represents the complete solution. Almost like having a dedicated race crew to work on your specialized vehicle. Clearly this is the best choice for the services you need, but it was not easy to identify them. There were not many clues to lead you to them. All the same terminology was used to describe the services, and all three shops were giving assurances that you would get the services you expect.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;There are only a small handful of managed security service providers that actually take on the specialized tasks for regulatory compliance, yet you will find many claiming to do so. They all use the same language to describe what they provide, but many simply provide the tools. Since most regulatory requirements include an analysis component, any service provider that is not doing analysis along with data collection will not meet the requirements. Yet they will advertise a fully compliant service offering by assuming the client will spend the time necessary to cover the analysis needs.&lt;/p&gt;
&lt;p&gt;When GSI states that a service we provide can meet a requirement, we mean that the service fully meets the requirement. Just as if a full IT team were hired on. The challenge is educating prospective clients on the difference when being compared to providers with less-developed ideas about services.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=H_fN63Agky4:zhhLPc-pCIE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=H_fN63Agky4:zhhLPc-pCIE:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=H_fN63Agky4:zhhLPc-pCIE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=H_fN63Agky4:zhhLPc-pCIE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=H_fN63Agky4:zhhLPc-pCIE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=H_fN63Agky4:zhhLPc-pCIE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=H_fN63Agky4:zhhLPc-pCIE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=H_fN63Agky4:zhhLPc-pCIE:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=H_fN63Agky4:zhhLPc-pCIE:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=H_fN63Agky4:zhhLPc-pCIE:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=H_fN63Agky4:zhhLPc-pCIE:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/gsihosting/~4/H_fN63Agky4" height="1" width="1"/&gt;</description>
      <link>http://feeds.gsihosting.com/~r/gsihosting/~3/H_fN63Agky4/post.aspx</link>
      <author>ewelsh</author>
      <comments>http://www.gsihosting.com/blog/post/2010/02/22/Comparing-managed-service-providers-SERVICES-vs-services.aspx#comment</comments>
      <guid isPermaLink="false">http://www.gsihosting.com/blog/post.aspx?id=6259ce3d-f598-4ab3-a602-57f3bc26b74e</guid>
      <pubDate>Mon, 22 Feb 2010 10:50:00 -0500</pubDate>
      <category>Services &amp; Solutions</category>
      <dc:publisher>ewelsh</dc:publisher>
      <pingback:server>http://www.gsihosting.com/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.gsihosting.com/blog/post.aspx?id=6259ce3d-f598-4ab3-a602-57f3bc26b74e</pingback:target>
      <slash:comments>1</slash:comments>
      <trackback:ping>http://www.gsihosting.com/blog/trackback.axd?id=6259ce3d-f598-4ab3-a602-57f3bc26b74e</trackback:ping>
      <wfw:comment>http://www.gsihosting.com/blog/post/2010/02/22/Comparing-managed-service-providers-SERVICES-vs-services.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.gsihosting.com/blog/syndication.axd?post=6259ce3d-f598-4ab3-a602-57f3bc26b74e</wfw:commentRss>
    <feedburner:origLink>http://www.gsihosting.com/blog/post.aspx?id=6259ce3d-f598-4ab3-a602-57f3bc26b74e</feedburner:origLink></item>
    <item>
      <title>The Rising Costs of Data Breaches</title>
      <description>&lt;h2&gt;When a company fails to show even basic security capabilities, causing a breach, a knowledgeable public takes their business elsewhere.&lt;/h2&gt;
&lt;p&gt;An interesting site to read through is the &lt;a rel="nofollow" href="http://www.ponemon.org/index.php" target="_blank"&gt;Ponemon Institute&lt;/a&gt;, which includes independent research on privacy and IT security issues.&lt;/p&gt;
&lt;p&gt;One of studies that caught my eye involved the &lt;a rel="nofollow" href="http://www.ponemon.org/local/upload/fckjail/generalcontent/18/file/2008-2009%20US%20Cost%20of%20Data%20Breach%20Report%20Final.pdf" target="_blank"&gt;cost of data breach&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The study I reviewed dealt with data from 2008, and compared the data to 2007. It also reviewed the impact of both direct and indirect costs. Direct costs are the efforts taken to remediate the direct causes and cleanup of a breach. Examples would be: hiring consultants, implementing technologies, or providing credit protection. Indirect costs tend to be costs to business that are not directly attributable to a breach, yet still feel the impact of a breach. Examples would be: customer churn, lost prospects, reputational impacts, or additional support costs.&lt;/p&gt;
&lt;p&gt;The overall result of the study shows that direct and indirect costs are rising. This reflects the vast amount of attention that has been given to breaches -- even as far as state governments legislating how the breach victims must be notified. As companies involved in data breaches learn the proper ways to handle the event, the costs will rise due to their increased engagement. In the past, a breach could be handled internally with little external involvement. No longer is this the case. A company with a breach had better be able to show due diligence by engaging professionals to remediate.&lt;/p&gt;
&lt;p&gt;Additionally, the general public, which is increasingly plugged in and online, has become savvier regarding how their data should be handled and protected. When a company fails to show even basic security capabilities, causing a breach, a knowledgeable public takes their business elsewhere.&lt;/p&gt;
&lt;p&gt;Something to note is that customer churn rates due to a breach event were highest in the healthcare industry. It seems folks care more about their doctors/hospitals losing their information than they do their financial institutions.&lt;/p&gt;
&lt;p&gt;One of the most relevant discoveries in this report is that breaches involving third-party or partner mistakes are the most expensive to remediate, and that 44% of the breaches reviewed involved third-parties. There is not really a good reason as to why third-party involvement causes a breach to be more expensive, but we can guess that inefficiencies are introduced when a third-party must be taken into account. The lesson is to only share data with third-parties you are sure have a good security program that includes event handling capabilities.&lt;/p&gt;
&lt;p&gt;Below are some statements directly from the report that I found relevant. These do not represent the full report, and an interested person should read directly from the links provided below.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Over the past four years, lost business cost component grew by more than $64 on a per-victim basis, or a 38% overall percentage increase. Our research finds organizations in highly trusted industries, such as banking, pharmaceuticals and healthcare, are more likely to experience a data breach with high abnormal churn rates. In contrast, retailers and companies with less direct consumer contact seem to experience a lower overall data breach cost.&lt;/p&gt;
&lt;p&gt;The most significant cost decrease concerns ex-post response, which implies organizations are becoming more cost-efficient in their management of the data breach. Despite efficiency gains, consulting, legal defense and, as mentioned previously, lost customer business have increased in this year&amp;rsquo;s study.&lt;/p&gt;
&lt;p&gt;The range of total cost among the 43 data breach incidents contained in this year&amp;rsquo;s study is a minimum of $613k to more than $32 million. The magnitude of the breach event ranged from 4,200 to 113,000 lost or stolen records. As in prior years, data breach cost appears to be linearly related to the size or magnitude of the breach event.&lt;/p&gt;
&lt;p&gt;In this year&amp;rsquo;s study, average abnormal churn rates across all 43 incidents is 3.6%, which was measured by the loss of customers who were directly affected by the data breach event (i.e., typically those receiving notification). The abnormal churn or turnover rate in 2007 for customers receiving notification was 2.7%.&lt;/p&gt;
&lt;p&gt;Healthcare and financial service companies have the &lt;strong&gt;highest&lt;/strong&gt; average rate of churn at 6.5% and 5.5%, respectively. High churn rates reflect the fact that these industries manage and collect consumers&amp;rsquo; most sensitive data. Thus, consumers may have a higher expectation for the protection and privacy of their financial and healthcare records.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Over 44% of all cases in this year&amp;rsquo;s study involved third-party mistakes or flubs.&lt;/strong&gt; Data breaches involving outsourced data to third parties are the most costly. This could be due to additional investigation and consulting fees. As shown in Bar Chart 5, per victim cost for data breaches involving third parties is $231 versus $179, more than a $52 difference.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;Further Reading&lt;/h2&gt;
&lt;ul class="tight"&gt;
&lt;li&gt;&lt;a rel="nofollow" href="http://www.ponemon.org/index.php" target="_blank"&gt;Ponemon Institute&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a rel="nofollow" href="http://www.ponemon.org/local/upload/fckjail/generalcontent/18/file/2008-2009%20US%20Cost%20of%20Data%20Breach%20Report%20Final.pdf" target="_blank"&gt;Ponemon Institute's Fourth Annual US Cost of Data Breach Study&lt;/a&gt; (PDF)&lt;/li&gt;
&lt;/ul&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=jkuJA2Dno08:FYHgYNOp72s:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=jkuJA2Dno08:FYHgYNOp72s:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=jkuJA2Dno08:FYHgYNOp72s:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=jkuJA2Dno08:FYHgYNOp72s:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=jkuJA2Dno08:FYHgYNOp72s:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=jkuJA2Dno08:FYHgYNOp72s:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=jkuJA2Dno08:FYHgYNOp72s:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=jkuJA2Dno08:FYHgYNOp72s:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=jkuJA2Dno08:FYHgYNOp72s:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=jkuJA2Dno08:FYHgYNOp72s:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=jkuJA2Dno08:FYHgYNOp72s:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/gsihosting/~4/jkuJA2Dno08" height="1" width="1"/&gt;</description>
      <link>http://feeds.gsihosting.com/~r/gsihosting/~3/jkuJA2Dno08/post.aspx</link>
      <author>ewelsh</author>
      <comments>http://www.gsihosting.com/blog/post/2010/02/12/The-Rising-Costs-of-Data-Breaches.aspx#comment</comments>
      <guid isPermaLink="false">http://www.gsihosting.com/blog/post.aspx?id=45218fe1-0af4-428f-b868-347af1f71b1e</guid>
      <pubDate>Fri, 12 Feb 2010 10:58:00 -0500</pubDate>
      <category>Security &amp; PCI</category>
      <dc:publisher>ewelsh</dc:publisher>
      <pingback:server>http://www.gsihosting.com/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.gsihosting.com/blog/post.aspx?id=45218fe1-0af4-428f-b868-347af1f71b1e</pingback:target>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.gsihosting.com/blog/trackback.axd?id=45218fe1-0af4-428f-b868-347af1f71b1e</trackback:ping>
      <wfw:comment>http://www.gsihosting.com/blog/post/2010/02/12/The-Rising-Costs-of-Data-Breaches.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.gsihosting.com/blog/syndication.axd?post=45218fe1-0af4-428f-b868-347af1f71b1e</wfw:commentRss>
    <feedburner:origLink>http://www.gsihosting.com/blog/post.aspx?id=45218fe1-0af4-428f-b868-347af1f71b1e</feedburner:origLink></item>
    <item>
      <title>Internal Penetration Testing: Server Only Environments</title>
      <description>&lt;p&gt;PCI DSS requirement 11.3.1 indicates the need for annual network penetration testing, which includes an "internal" penetration test by an experienced security tester. GSI has always supported this activity by working with whomever our clients ask to perform the testing. This requirement can be met by using experienced internal staff or third-party professionals (see 11.3 Supplement), and we have seen both. Even though the selection of who does the testing is easy to make, the location in the network from which to perform the internal testing is another matter.&lt;/p&gt;
&lt;p&gt;The environments GSI manages at PCI levels of security are particularly isolated with strong two-factor controls required for all administrative entry points. These environments are characterized by strict firewall change-control procedures and system hardening with accompanying audits. Another feature of these secure environments is the complete lack of desktop-level systems. Environments meant to house highly secure single-function payment processing systems do not require the abundance of services seen in systems that support desktop access for users. There are not any personal directory shares, email clients, productivity packages, or Internet user communication technologies present on these systems.&lt;/p&gt;
&lt;p&gt;All of this culminates into a distinct lack of what the PCI DSS would determine to be an "internal" network.&lt;/p&gt;
&lt;p&gt;So where does that leave us regarding internal penetration testing for requirement 11.3?&lt;/p&gt;
&lt;p&gt;There are two scenarios that can play out:&lt;/p&gt;
&lt;p&gt;One is for the client tester to be placed directly into the cardholder environment. This type of test assumes the attacker has compromised at least one system in the environment. The result of this test reflects how much information could be accessed post-compromise. Many QSAs will accept this as a proper internal test of the environment even though it is not strictly adhering to the intent of 11.3. In my opinion, it is not a valid test of risk exposure for the environment, because it completely disregards the security protections it is meant to test.&lt;/p&gt;
&lt;p&gt;The second scenario is for the client's QSA to give them a "pass" on the internal penetration test requirement with the knowledge that, by definition, an internal penetration test is not possible. There is not an internal network to test from. We are starting to see more of this as QSAs better understand how the environments are managed at GSI. This decision is not arrived at lightly and even when the QSA gives a pass for an internal penetration test, it is only after the environment meets specific criteria. We must prove that administrative access is strictly protected by two-factor authentication and VPN connectivity. We also must show that there are not any desktop networks directly connected to access shares or services. At GSI, this is easily done with configuration diagrams and firewall configurations.&lt;/p&gt;
&lt;p&gt;I have stated in a &lt;a href="http://www.gsihosting.com/blog/post/2009/10/08/PCI-Council-Meeting-Reveals-Challenges-with-Standards-Interest-in-Risk.aspx"&gt;previous article&lt;/a&gt; that the PCI standards will inevitably lead to risk-based implementations. The ability for highly protected environments to forgo an internal penetration test is an excellent example of how a QSA can take the risk approach into their own hands and utilize the PCI standard in a flexible way to meet the intent, save clients money, and concentrate security where needed -- all at the same time.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=9_QQ0_2faQo:Oj2ShZZVDJY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=9_QQ0_2faQo:Oj2ShZZVDJY:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=9_QQ0_2faQo:Oj2ShZZVDJY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=9_QQ0_2faQo:Oj2ShZZVDJY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=9_QQ0_2faQo:Oj2ShZZVDJY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=9_QQ0_2faQo:Oj2ShZZVDJY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=9_QQ0_2faQo:Oj2ShZZVDJY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=9_QQ0_2faQo:Oj2ShZZVDJY:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=9_QQ0_2faQo:Oj2ShZZVDJY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=9_QQ0_2faQo:Oj2ShZZVDJY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=9_QQ0_2faQo:Oj2ShZZVDJY:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/gsihosting/~4/9_QQ0_2faQo" height="1" width="1"/&gt;</description>
      <link>http://feeds.gsihosting.com/~r/gsihosting/~3/9_QQ0_2faQo/post.aspx</link>
      <author>ewelsh</author>
      <comments>http://www.gsihosting.com/blog/post/2010/02/01/Internal-Penetration-Testing-Server-Only-Environments.aspx#comment</comments>
      <guid isPermaLink="false">http://www.gsihosting.com/blog/post.aspx?id=14544e8d-e97c-48a4-9fe9-15e4830de796</guid>
      <pubDate>Mon, 01 Feb 2010 14:14:00 -0500</pubDate>
      <category>Security &amp; PCI</category>
      <dc:publisher>ewelsh</dc:publisher>
      <pingback:server>http://www.gsihosting.com/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.gsihosting.com/blog/post.aspx?id=14544e8d-e97c-48a4-9fe9-15e4830de796</pingback:target>
      <slash:comments>3</slash:comments>
      <trackback:ping>http://www.gsihosting.com/blog/trackback.axd?id=14544e8d-e97c-48a4-9fe9-15e4830de796</trackback:ping>
      <wfw:comment>http://www.gsihosting.com/blog/post/2010/02/01/Internal-Penetration-Testing-Server-Only-Environments.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.gsihosting.com/blog/syndication.axd?post=14544e8d-e97c-48a4-9fe9-15e4830de796</wfw:commentRss>
    <feedburner:origLink>http://www.gsihosting.com/blog/post.aspx?id=14544e8d-e97c-48a4-9fe9-15e4830de796</feedburner:origLink></item>
    <item>
      <title>Expand your business network at the upcoming Accelerent breakfast!</title>
      <description>&lt;p&gt;If you aren&amp;rsquo;t already familiar with Accelerent, but you are interested in a fantastic avenue for getting to know the KC business community, I&amp;rsquo;d like to share some information with you.&amp;nbsp; GSI is a member of Accelerent, which is essentially a corporate business development organization made up of C-level execs in the Kansas City area.&amp;nbsp; Currently, the organization has about 35 members, consisting of a wide variety of companies in the KC area.&amp;nbsp; While they continue to recruit new member companies, they are also diligent about making sure that no two member companies are from the same industry.&amp;nbsp; This is a great practice as it means that the group represents a broad spectrum of industries -- and also creates a tighter relationship among member companies without the presence of a competitive factor.&lt;/p&gt;
&lt;p&gt;The organization hosts about 9 or 10 breakfasts throughout the year for its members and guests.&amp;nbsp; We get together, listen to a featured speaker (always someone truly inspirational with their amazing achievements) and spend time meeting corporate executives from our area &amp;ndash; an excellent opportunity to learn more about their businesses, as well as educate others about our own.&amp;nbsp; At the last breakfast, we had more than 300 attendees &amp;ndash; a prime opportunity for corporate networking and opening up doors for new business!&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The next Accelerent breakfast is Friday, January 22, at 7:00 a.m. in Overland Park, KS.&amp;nbsp; Peter Vidmar, the former Olympic gymnast, will be the featured speaker &amp;ndash; and I&amp;rsquo;ve been told he is wonderful.&amp;nbsp; You have to be either an Accelerant member or an invited guest to attend.&amp;nbsp; So if you have even the slightest interest in coming, please do so, as my guest. (Please &lt;a href="mailto:khansen@gsihosting.com"&gt;email me&lt;/a&gt; to RSVP.)&lt;/p&gt;
&lt;p&gt;Now for the particulars.&amp;nbsp; Prior to the actual breakfast, there is an Expo from 7 a.m. to 8 a.m.&amp;nbsp; This is where introductions take place.&amp;nbsp; If you&amp;rsquo;d like to see a list of attendees, let me know and I can send you a list of those who have RSVP&amp;rsquo;d so far.&amp;nbsp; The next step would be for you to let me know if there is anyone on the list that you would like to meet (yes, I&amp;rsquo;ll make sure that happens!).&amp;nbsp; Obviously, you are welcome to roam the room and make your own introductions, which I also suggest.&lt;/p&gt;
&lt;p&gt;If this is of any interest to you, email me at &lt;a href="mailto:khansen@gsihosting.com"&gt;khansen@gsihosting.com&lt;/a&gt; and I can do the registration for you.&amp;nbsp; In addition, you are welcome to invite up to three clients of your own.&lt;/p&gt;
&lt;p&gt;I sincerely hope that you &amp;ndash; or any of your coworkers or clients you invite &amp;ndash; decide to join us.&amp;nbsp; I promise you won&amp;rsquo;t be disappointed!&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=GPdRaWwunXA:lh8_wxPMez4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=GPdRaWwunXA:lh8_wxPMez4:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=GPdRaWwunXA:lh8_wxPMez4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=GPdRaWwunXA:lh8_wxPMez4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=GPdRaWwunXA:lh8_wxPMez4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=GPdRaWwunXA:lh8_wxPMez4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=GPdRaWwunXA:lh8_wxPMez4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=GPdRaWwunXA:lh8_wxPMez4:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=GPdRaWwunXA:lh8_wxPMez4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=GPdRaWwunXA:lh8_wxPMez4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=GPdRaWwunXA:lh8_wxPMez4:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/gsihosting/~4/GPdRaWwunXA" height="1" width="1"/&gt;</description>
      <link>http://feeds.gsihosting.com/~r/gsihosting/~3/GPdRaWwunXA/post.aspx</link>
      <author>khansen</author>
      <comments>http://www.gsihosting.com/blog/post/2010/01/13/Accelerent-Breakfast-Kansas-City-January-22-2010.aspx#comment</comments>
      <guid isPermaLink="false">http://www.gsihosting.com/blog/post.aspx?id=64735407-cbe5-43bc-a2e5-45cc841f6473</guid>
      <pubDate>Wed, 13 Jan 2010 15:25:00 -0500</pubDate>
      <category>Events &amp; Marketing</category>
      <dc:publisher>khansen</dc:publisher>
      <pingback:server>http://www.gsihosting.com/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.gsihosting.com/blog/post.aspx?id=64735407-cbe5-43bc-a2e5-45cc841f6473</pingback:target>
      <slash:comments>1</slash:comments>
      <trackback:ping>http://www.gsihosting.com/blog/trackback.axd?id=64735407-cbe5-43bc-a2e5-45cc841f6473</trackback:ping>
      <wfw:comment>http://www.gsihosting.com/blog/post/2010/01/13/Accelerent-Breakfast-Kansas-City-January-22-2010.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.gsihosting.com/blog/syndication.axd?post=64735407-cbe5-43bc-a2e5-45cc841f6473</wfw:commentRss>
    <feedburner:origLink>http://www.gsihosting.com/blog/post.aspx?id=64735407-cbe5-43bc-a2e5-45cc841f6473</feedburner:origLink></item>
    <item>
      <title>Clients, Not Customers</title>
      <description>&lt;p&gt;I insist that our GSI associates refer to the people and companies who favor us with their business as clients. I admit...it's an obsession with me. I am so passionate about the client reference that when someone utters "customer" within earshot of me, the offending speaker generally knows that a well-placed rebuke will shortly follow. I've never sentenced anyone to spend an hour in time-out or put their nose in a circle on the wall; however, most everyone understands that employing "customer" in a conversation at GSI will generate a correction.&lt;/p&gt;
&lt;p&gt;My devotion to client is all about respect &amp;ndash; respect for the people who have trusted us with their mission-critical processes, respect for the close relationships that we have developed in supporting those processes, and respect for caliber of service delivery our ServerHeroes teams provide 24/7. We are not selling hamburgers or tanks of gas where one source is just about as good as the other. Nor are our associates manning the drive-thru lane or considering "have a nice day" as the ultimate measure of service at check-out. We are important components of our clients' businesses, and in order for GSI to exceed expectations, our associates need to understand and respect the confidence that our clients have placed in us.&lt;/p&gt;
&lt;p&gt;Customers produce revenue &amp;ndash; clients produce relationships. GSI is so devoted to getting the relationship right that we diligently work to know our clients' businesses, and the business processes that we are supporting. We employ our &lt;a href="http://www.gsihosting.com/services/managed/service-quality-framework.aspx"&gt;Service Quality Framework&lt;/a&gt; to not just define monitoring, management and escalation requirements, but to summarize the business functions and underlying dependencies that will allow our ServerHeroes to support those critical processes as if we were the clients' employees. We assign dedicated teams to specific clients in order to develop a deep knowledge of the clients' businesses, as well as their IT environments. We respond to requests and issues with haste, knowing that our clients depend upon us to do so around-the-clock. We do all of this because we desire to have long-term relationships built upon mutual respect and trust &amp;ndash; it's about more than just the revenue.&lt;/p&gt;
&lt;p&gt;So if you don't have a satisfactory relationship with your current service provider, go to their web site and see if you find "customer service" or "customer portal." That might indicate they are more interested in your revenue than your relationship. And then contact GSI and explore what a real service provider relationship can be.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=0tXHyXRuofQ:tcbjcamJmyg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=0tXHyXRuofQ:tcbjcamJmyg:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=0tXHyXRuofQ:tcbjcamJmyg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=0tXHyXRuofQ:tcbjcamJmyg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=0tXHyXRuofQ:tcbjcamJmyg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=0tXHyXRuofQ:tcbjcamJmyg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=0tXHyXRuofQ:tcbjcamJmyg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=0tXHyXRuofQ:tcbjcamJmyg:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=0tXHyXRuofQ:tcbjcamJmyg:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=0tXHyXRuofQ:tcbjcamJmyg:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=0tXHyXRuofQ:tcbjcamJmyg:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/gsihosting/~4/0tXHyXRuofQ" height="1" width="1"/&gt;</description>
      <link>http://feeds.gsihosting.com/~r/gsihosting/~3/0tXHyXRuofQ/post.aspx</link>
      <author>kkephart</author>
      <comments>http://www.gsihosting.com/blog/post/2010/01/12/Clients-Not-Customers.aspx#comment</comments>
      <guid isPermaLink="false">http://www.gsihosting.com/blog/post.aspx?id=7ebc865f-2295-440d-99d3-5143f5331ccc</guid>
      <pubDate>Tue, 12 Jan 2010 11:48:00 -0500</pubDate>
      <category>Editorial</category>
      <dc:publisher>kkephart</dc:publisher>
      <pingback:server>http://www.gsihosting.com/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.gsihosting.com/blog/post.aspx?id=7ebc865f-2295-440d-99d3-5143f5331ccc</pingback:target>
      <slash:comments>1</slash:comments>
      <trackback:ping>http://www.gsihosting.com/blog/trackback.axd?id=7ebc865f-2295-440d-99d3-5143f5331ccc</trackback:ping>
      <wfw:comment>http://www.gsihosting.com/blog/post/2010/01/12/Clients-Not-Customers.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.gsihosting.com/blog/syndication.axd?post=7ebc865f-2295-440d-99d3-5143f5331ccc</wfw:commentRss>
    <feedburner:origLink>http://www.gsihosting.com/blog/post.aspx?id=7ebc865f-2295-440d-99d3-5143f5331ccc</feedburner:origLink></item>
    <item>
      <title>Managed Hosting Compensating Controls</title>
      <description>&lt;h2&gt;Briefly: What is a Compensating Control?&lt;/h2&gt;
&lt;p&gt;The Payment Card Industry Data Security Standard (PCI DSS) roughly defines compensating controls as a method to meet the intent of a DSS requirement, while not implementing the control as written by the PCI Security Standards Council. This was a smart move on the part of the Council. They are saying that the prescriptive requirements may not be the best way for all situations and allow implementers to work outside the box, as long as the intent of the standard is being met.&lt;/p&gt;
&lt;p&gt;Compensating controls have become necessary for situations where the combination of technical and business constraints prevent a control from being implemented. The typical reason for implementing compensating controls is the inherent expense involved with implementing the original DSS controls. This is not surprising considering the requirements for such things as automatic access control management, centralized logging, integrity monitoring, and all the vulnerability management technologies.&lt;/p&gt;
&lt;h2&gt;QSA's Perspective on Compensating Controls&lt;/h2&gt;
&lt;p&gt;QSAs (Qualified Security Assessors) really dislike compensating controls. It has been my experience that the dislike is due to the additional effort required to report compensating controls. For a QSA, the DSS is a list of requirements for which they test the controls. A compensating control does not have a clean pass/fail and must be fully documented in the Report on Compliance (RoC) in such a way to fully explain how it meets the intent of the requirement it replaces. Further, the QSA cannot simply use documentation provided by the merchant/service provider. The QSA must fully understand the new control so that they can make a judgment call as to whether it meets the original intent, as well as document it for the RoC. An assessment that involves multiple compensating controls will drag out much longer than one without them. Many assessment engagements use a fixed project pricing method, which means the longer an assessment takes, the thinner the profit margin for the assessment company.&lt;/p&gt;
&lt;h2&gt;Managed Hosting Impact on Compensating Controls&lt;/h2&gt;
&lt;p&gt;Compensating controls all by themselves are a wrench in the PCI DSS assessment process. Add in a third-party managed hosting provider and things get real sticky. Especially if the hosting provider does not fully support the PCI requirements, leaving the client to dig details out of a set of offsite tools that only partially describe an environment. A managed hosting provider utilized for systems requiring PCI DSS compliance will need a capability to deal with compensating controls. It means providing reasonable customization with the expertise to understand how that customization will affect a PCI DSS assessment.&lt;/p&gt;
&lt;p&gt;Being a managed services provider, GSI must deal with the engineering, documenting, and implementation of compensating controls for client PCI DSS environments. It is not easy and there are many challenges. Any customization that pushes the boundaries of our standard operating procedures risks failure, and we must be vigilant with our audits and reporting to catch any discrepancies. Still, without doubt, it is worth having the capability to do it. Having that flexibility really tells the story when our clients continually pass PCI DSS assessments year after year.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=JUkU6Z-qfsE:YYgGf6e8Vfw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=JUkU6Z-qfsE:YYgGf6e8Vfw:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=JUkU6Z-qfsE:YYgGf6e8Vfw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=JUkU6Z-qfsE:YYgGf6e8Vfw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=JUkU6Z-qfsE:YYgGf6e8Vfw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=JUkU6Z-qfsE:YYgGf6e8Vfw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=JUkU6Z-qfsE:YYgGf6e8Vfw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=JUkU6Z-qfsE:YYgGf6e8Vfw:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=JUkU6Z-qfsE:YYgGf6e8Vfw:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=JUkU6Z-qfsE:YYgGf6e8Vfw:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=JUkU6Z-qfsE:YYgGf6e8Vfw:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/gsihosting/~4/JUkU6Z-qfsE" height="1" width="1"/&gt;</description>
      <link>http://feeds.gsihosting.com/~r/gsihosting/~3/JUkU6Z-qfsE/post.aspx</link>
      <author>ewelsh</author>
      <comments>http://www.gsihosting.com/blog/post/2009/12/28/Managed-Hosting-Compensating-Controls.aspx#comment</comments>
      <guid isPermaLink="false">http://www.gsihosting.com/blog/post.aspx?id=03756dbf-67b5-4fa7-a2b2-14cfadf53b9d</guid>
      <pubDate>Mon, 28 Dec 2009 10:27:00 -0500</pubDate>
      <category>Security &amp; PCI</category>
      <dc:publisher>ewelsh</dc:publisher>
      <pingback:server>http://www.gsihosting.com/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.gsihosting.com/blog/post.aspx?id=03756dbf-67b5-4fa7-a2b2-14cfadf53b9d</pingback:target>
      <slash:comments>1</slash:comments>
      <trackback:ping>http://www.gsihosting.com/blog/trackback.axd?id=03756dbf-67b5-4fa7-a2b2-14cfadf53b9d</trackback:ping>
      <wfw:comment>http://www.gsihosting.com/blog/post/2009/12/28/Managed-Hosting-Compensating-Controls.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.gsihosting.com/blog/syndication.axd?post=03756dbf-67b5-4fa7-a2b2-14cfadf53b9d</wfw:commentRss>
    <feedburner:origLink>http://www.gsihosting.com/blog/post.aspx?id=03756dbf-67b5-4fa7-a2b2-14cfadf53b9d</feedburner:origLink></item>
    <item>
      <title>False Positives and Data Security</title>
      <description>&lt;p&gt;This came up as a rather entertaining political science question the other day. "It is better for N many criminals to go free than for 1 innocent person to be punished." This concept goes way back to the 18th century, originated by English judge William Blackstone. It is now known as Blackstone's Ratio in criminal law.&lt;/p&gt;
&lt;img style="float:right;margin:10px 0 0 10px;" src="http://www.gsihosting.com/images/blog/true-false.jpg" alt="True/False sign - False Positives and Data Security" /&gt;
&lt;p&gt;A few years ago, the National Center for State Courts ran an experiment where they compared cases when both the judge and the jury could submit guilty/not-guilty verdicts. Through signal analysis, they could predict not only what percentage of the time they disagreed, but predict who was wrong. The results pointed to approximately 17% of the jury verdicts being incorrect and "N" equaling roughly 1.43 guilty parties let go per innocent punished. On the other hand, about 12% of the judge's verdicts were incorrect leading to an N of 0.1 (1 guilty person let go for every 10 punished innocent people).&lt;sup&gt;1&lt;/sup&gt;&lt;/p&gt;
&lt;p&gt;Blackstone's pick for N was 10. My assumption for the reason behind the change in this ratio is that in the last 200 years, with tools such as modern forensic evidence, DNA sampling, fiber testing and omnipresent video cameras, we have made significant strides in being able to exonerate innocent people before the fact, and only bring guilty parties before the court.&lt;/p&gt;
&lt;p&gt;In data security, we're continually bombarded with "false positives." We get false positives when our tools are set to be too sensitive &amp;ndash; but most admins prefer this to the alternative of having them not be sensitive enough and miss an event entirely! This is not a new problem &amp;ndash; what is new is that our tools are evolving in a way to reduce the amount of alerts we receiving, letting us take more time to analyze the ones that really need our attention.&lt;/p&gt;
&lt;p&gt;As technology advances, we'll continue to lower the number of false positives we get, improving our organization's Blackstone Ratio &amp;ndash; and this ratio is something that you can measure and prove to others that your security is improving over time. In the last year at GSI, we've dropped our false positives by 73.6% through reconfiguring and tuning our current monitoring systems. Additionally, we recently installed more security appliances that are even more accurate, so I expect this trend to continue. All of this adds up to data center security that's more accurate, more effective &amp;ndash; and more measurable.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Footnotes&lt;/b&gt;&lt;br/&gt;
1. Spencer, Bruce, On Measuring the Balance between Wrongful Convictions and Wrongful Acquittals in Criminal Trials (November 7, 2007). 2nd Annual Conference on Empirical Legal Studies Paper. Available at SSRN: &lt;a href="http://ssrn.com/abstract=997188" rel="nofollow"&gt;http://ssrn.com/abstract=997188&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=W3bWH0UYpb8:cLB9-ZTZ45I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=W3bWH0UYpb8:cLB9-ZTZ45I:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=W3bWH0UYpb8:cLB9-ZTZ45I:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=W3bWH0UYpb8:cLB9-ZTZ45I:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=W3bWH0UYpb8:cLB9-ZTZ45I:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=W3bWH0UYpb8:cLB9-ZTZ45I:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=W3bWH0UYpb8:cLB9-ZTZ45I:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=W3bWH0UYpb8:cLB9-ZTZ45I:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=W3bWH0UYpb8:cLB9-ZTZ45I:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=W3bWH0UYpb8:cLB9-ZTZ45I:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=W3bWH0UYpb8:cLB9-ZTZ45I:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/gsihosting/~4/W3bWH0UYpb8" height="1" width="1"/&gt;</description>
      <link>http://feeds.gsihosting.com/~r/gsihosting/~3/W3bWH0UYpb8/post.aspx</link>
      <author>crickel</author>
      <comments>http://www.gsihosting.com/blog/post/2009/11/12/False-Positives-and-Data-Security.aspx#comment</comments>
      <guid isPermaLink="false">http://www.gsihosting.com/blog/post.aspx?id=85b31c25-38e1-44db-8138-125f011f7a88</guid>
      <pubDate>Thu, 12 Nov 2009 12:09:00 -0500</pubDate>
      <category>Security &amp; PCI</category>
      <dc:publisher>crickel</dc:publisher>
      <pingback:server>http://www.gsihosting.com/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.gsihosting.com/blog/post.aspx?id=85b31c25-38e1-44db-8138-125f011f7a88</pingback:target>
      <slash:comments>1</slash:comments>
      <trackback:ping>http://www.gsihosting.com/blog/trackback.axd?id=85b31c25-38e1-44db-8138-125f011f7a88</trackback:ping>
      <wfw:comment>http://www.gsihosting.com/blog/post/2009/11/12/False-Positives-and-Data-Security.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.gsihosting.com/blog/syndication.axd?post=85b31c25-38e1-44db-8138-125f011f7a88</wfw:commentRss>
    <feedburner:origLink>http://www.gsihosting.com/blog/post.aspx?id=85b31c25-38e1-44db-8138-125f011f7a88</feedburner:origLink></item>
    <item>
      <title>Hosting Biz Apps Online</title>
      <description>&lt;p&gt;GSI founder Robin Greenhagen discusses cloud computing for small businesses in the November 2009 issue of KC Small Business magazine. The online version is available here: &lt;a title="Hosting Biz Apps Online article by GSI founder Robin Greenhagen - Kansas City Small Business magazine" rel="nofollow" href="http://bit.ly/5nGcBP" target="_blank"&gt;http://bit.ly/5nGcBP&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=7hoqKI9ilG0:hWucLU90nac:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=7hoqKI9ilG0:hWucLU90nac:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=7hoqKI9ilG0:hWucLU90nac:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=7hoqKI9ilG0:hWucLU90nac:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=7hoqKI9ilG0:hWucLU90nac:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=7hoqKI9ilG0:hWucLU90nac:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=7hoqKI9ilG0:hWucLU90nac:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=7hoqKI9ilG0:hWucLU90nac:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=7hoqKI9ilG0:hWucLU90nac:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?i=7hoqKI9ilG0:hWucLU90nac:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.gsihosting.com/~ff/gsihosting?a=7hoqKI9ilG0:hWucLU90nac:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/gsihosting?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/gsihosting/~4/7hoqKI9ilG0" height="1" width="1"/&gt;</description>
      <link>http://feeds.gsihosting.com/~r/gsihosting/~3/7hoqKI9ilG0/post.aspx</link>
      <author>rgreenhagen</author>
      <comments>http://www.gsihosting.com/blog/post/2009/11/05/Hosting-Biz-Apps-Online.aspx#comment</comments>
      <guid isPermaLink="false">http://www.gsihosting.com/blog/post.aspx?id=87ccfc2b-7211-4dac-b0ba-3ce5fc306535</guid>
      <pubDate>Thu, 05 Nov 2009 14:01:00 -0500</pubDate>
      <category>Editorial</category>
      <dc:publisher>rgreenhagen</dc:publisher>
      <pingback:server>http://www.gsihosting.com/blog/pingback.axd</pingback:server>
      <pingback:target>http://www.gsihosting.com/blog/post.aspx?id=87ccfc2b-7211-4dac-b0ba-3ce5fc306535</pingback:target>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.gsihosting.com/blog/trackback.axd?id=87ccfc2b-7211-4dac-b0ba-3ce5fc306535</trackback:ping>
      <wfw:comment>http://www.gsihosting.com/blog/post/2009/11/05/Hosting-Biz-Apps-Online.aspx#comment</wfw:comment>
      <wfw:commentRss>http://www.gsihosting.com/blog/syndication.axd?post=87ccfc2b-7211-4dac-b0ba-3ce5fc306535</wfw:commentRss>
    <feedburner:origLink>http://www.gsihosting.com/blog/post.aspx?id=87ccfc2b-7211-4dac-b0ba-3ce5fc306535</feedburner:origLink></item>
  </channel>
</rss>
