<?xml version="1.0"?><?xml-stylesheet type="text/xsl" href="/rss.xsl"?><rss version="2.0"><channel><title>Risk Tracker</title><link>http://risktracker.codeplex.com/project/feeds/rss</link><description>Risk Tracker is a application built using the CISF to track corporate information security risk. </description><item><title>Source code checked in, #80132</title><link>http://risktracker.codeplex.com/SourceControl/changeset/changes/80132</link><description>Upgrade&amp;#58; New Version of LabDefaultTemplate.xaml. To upgrade your build definitions, please visit the following link&amp;#58; http&amp;#58;&amp;#47;&amp;#47;go.microsoft.com&amp;#47;fwlink&amp;#47;&amp;#63;LinkId&amp;#61;254563</description><author>Project Collection Service Accounts</author><pubDate>Mon, 01 Oct 2012 21:49:39 GMT</pubDate><guid isPermaLink="false">Source code checked in, #80132 20121001094939P</guid></item><item><title>Source code checked in, #80131</title><link>http://risktracker.codeplex.com/SourceControl/changeset/changes/80131</link><description>Checked in by server upgrade</description><author>Project Collection Service Accounts</author><pubDate>Mon, 01 Oct 2012 21:43:10 GMT</pubDate><guid isPermaLink="false">Source code checked in, #80131 20121001094310P</guid></item><item><title>New Post: Load Users &amp; Roles</title><link>http://risktracker.codeplex.com/Thread/View.aspx?ThreadId=69365</link><description>&lt;div style="line-height: normal;"&gt;
&lt;p&gt;Solved...I worked with the source code and I was able to understand how it works...if anyone need help, please let me know...the guide is not enough to run the application!!&lt;/p&gt;
&lt;/div&gt;</description><author>securitydev</author><pubDate>Thu, 16 Dec 2010 10:45:30 GMT</pubDate><guid isPermaLink="false">New Post: Load Users &amp; Roles 20101216104530A</guid></item><item><title>Commented Issue: AuthZCachManager is not working [7767]</title><link>http://risktracker.codeplex.com/workitem/7767</link><description>Some one to post what initial data to fill in the tables please...&lt;br /&gt;Comments: ** Comment from web user: securitydev ** &lt;p&gt;Solved&amp;#33;&amp;#33;&amp;#33;&amp;#33; if you think you can go with the guide, then you would never instal the application, you should work directly with the source code...if anyone need help in installation, just tell me&lt;/p&gt;</description><author>securitydev</author><pubDate>Thu, 16 Dec 2010 10:44:01 GMT</pubDate><guid isPermaLink="false">Commented Issue: AuthZCachManager is not working [7767] 20101216104401A</guid></item><item><title>Created Issue: AuthZCachManager is not working [7767]</title><link>http://risktracker.codeplex.com/workitem/7767</link><description>Some one to post what initial data to fill in the tables please...&lt;br /&gt;</description><author>securitydev</author><pubDate>Tue, 14 Dec 2010 11:27:42 GMT</pubDate><guid isPermaLink="false">Created Issue: AuthZCachManager is not working [7767] 20101214112742A</guid></item><item><title>New Post: Load Users &amp; Roles</title><link>http://risktracker.codeplex.com/Thread/View.aspx?ThreadId=69365</link><description>&lt;div style="line-height: normal;"&gt;
&lt;p&gt;This is a real pain, and I can't figure it out, why there is no one to answer this?!!&lt;/p&gt;
&lt;p&gt;We need to know how to &amp;quot;MANUALLY&amp;quot; fill the tables initially so we are able to run AuthZCachManager&lt;/p&gt;
&lt;/div&gt;</description><author>securitydev</author><pubDate>Tue, 14 Dec 2010 11:26:26 GMT</pubDate><guid isPermaLink="false">New Post: Load Users &amp; Roles 20101214112626A</guid></item><item><title>Source code checked in, #55373</title><link>http://risktracker.codeplex.com/SourceControl/changeset/changes/55373</link><description>Checked in by server upgrade</description><author>_TFSSERVICE</author><pubDate>Mon, 02 Aug 2010 22:49:34 GMT</pubDate><guid isPermaLink="false">Source code checked in, #55373 20100802104934P</guid></item><item><title>Updated Release: Risk Tracker  Release Notes - Sep 2009 (CTP) (Sep 15, 2009)</title><link>http://risktracker.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=33039</link><description>&lt;div class="wikidoc"&gt;This is release for Risk Tracker V1.0.&lt;br /&gt;&lt;br /&gt;Risk Tracker Deployment Guide V1.0.docx - This setup document will explain in detail the steps required to deploy Risk Tracker in your organization.&lt;br /&gt;DataBase.zip - This contains all the script/bat files for installing ISRM database &amp;amp; CISFPortal database.&lt;br /&gt;WebSite.zip - This contains the MSI installer for Risk Tracker Web site.&lt;br /&gt;.RiskTrackerServices.zip - This contains setup files for deploying WCF services that are required for Risk Tracker Application. This also includes Windows Service for notification.&lt;br /&gt;&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>vineetbatta</author><pubDate>Mon, 21 Sep 2009 05:11:23 GMT</pubDate><guid isPermaLink="false">Updated Release: Risk Tracker  Release Notes - Sep 2009 (CTP) (Sep 15, 2009) 20090921051123A</guid></item><item><title>Released: Risk Tracker  Release Notes - Sep 2009 (CTP) (Sep 15, 2009)</title><link>http://risktracker.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=33039</link><description>&lt;div&gt;This is release for Risk Tracker V1.0.&lt;br&gt;&lt;br&gt;Risk Tracker Deployment Guide V1.0.docx - This setup document will explain in detail the steps required to deploy Risk Tracker in your organization.&lt;br&gt;DataBase.zip - This contains all the script/bat files for installing ISRM database &amp;amp; CISFPortal database.&lt;br&gt;WebSite.zip - This contains the MSI installer for Risk Tracker Web site.&lt;br&gt;.RiskTrackerServices.zip - This contains setup files for deploying WCF services that are required for Risk Tracker Application. This also includes Windows Service for notification.&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;</description><author></author><pubDate>Mon, 21 Sep 2009 05:11:23 GMT</pubDate><guid isPermaLink="false">Released: Risk Tracker  Release Notes - Sep 2009 (CTP) (Sep 15, 2009) 20090921051123A</guid></item><item><title>Commented Issue: SQL Authentication and wrong password in documentation [4271]</title><link>http://risktracker.codeplex.com/WorkItem/View.aspx?WorkItemId=4271</link><description>Why do you use SQL authentication for the CISFPortal &amp;#40;and windows for all other services&amp;#41;, isn&amp;#39;t that an extra security risk&amp;#63;&lt;br /&gt;&lt;br /&gt;Also in the documentation there is a mismatch between the &amp;#34;portal&amp;#34; user&amp;#40;page 8&amp;#41; with a password of &amp;#34;123&amp;#64;abc&amp;#34; but at the end &amp;#40;page 54&amp;#41; the password is &amp;#34;abc&amp;#64;123&amp;#34;&lt;br /&gt;Comments: ** Comment from web user: VineetBatta ** &lt;p&gt;1&amp;#41;&lt;br /&gt;The userId and password should be one specified by the person deploying this instance of the application. &amp;#34;portal&amp;#47;abc&amp;#64;123&amp;#34; are just place holders to help user understand the step.&lt;/p&gt;&lt;p&gt;2&amp;#41;&lt;br /&gt;To encrpypt sql connection string please refer section 4.9.3 in the same document. You should never have userid&amp;#47;password as plain text.&lt;br /&gt;msdn documnetation link &amp;#58; http&amp;#58;&amp;#47;&amp;#47;msdn.microsoft.com&amp;#47;en-us&amp;#47;library&amp;#47;ms998292.aspx&lt;/p&gt;&lt;p&gt;This was required for Widget functionality for now.&lt;/p&gt;&lt;p&gt;To use Windows Authentication for Widgets is very much on our list of things to do and likely to be there by RC build.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</description><author>VineetBatta</author><pubDate>Mon, 21 Sep 2009 04:46:17 GMT</pubDate><guid isPermaLink="false">Commented Issue: SQL Authentication and wrong password in documentation [4271] 20090921044617A</guid></item><item><title>New Post: Load Users &amp; Roles</title><link>http://risktracker.codeplex.com/Thread/View.aspx?ThreadId=69365</link><description>&lt;div style="line-height: normal;"&gt;&lt;p&gt;I'm trying to get everything working, the portal site is running, but I'm having problems with the users and roles.&lt;/p&gt;
&lt;p&gt;these are the steps:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Create AD with group and user&lt;/li&gt;
&lt;li&gt;AuthorizationGroup, filled with domain group name (e.g. CONTOSO\MYGROUP, but alos tried MYGROUP)&lt;/li&gt;
&lt;li&gt;RoleMapping, made a map between the above group and one of the roles (0, sysadmin)&lt;/li&gt;
&lt;li&gt;Person, unsure what to enter exactly, so entered also email and displayname, etc&lt;/li&gt;
&lt;li&gt;Run AuthzCachemanager, it recognizes the groups, but the AuthZUser and AuthzRoleMapping tables stay empty&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;So what's the trick to get this working?&lt;/p&gt;
&lt;p&gt;How is the mapping between Person and AD?&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Erik&lt;/p&gt;&lt;/div&gt;</description><author>erik_oppedijk</author><pubDate>Fri, 18 Sep 2009 11:25:11 GMT</pubDate><guid isPermaLink="false">New Post: Load Users &amp; Roles 20090918112511A</guid></item><item><title>Created Issue: SQL Authentication and wrong password in documentation [4271]</title><link>http://risktracker.codeplex.com/WorkItem/View.aspx?WorkItemId=4271</link><description>Why do you use SQL authentication for the CISFPortal &amp;#40;and windows for all other services&amp;#41;, isn&amp;#39;t that an extra security risk&amp;#63;&lt;br /&gt;&lt;br /&gt;Also in the documentation there is a mismatch between the &amp;#34;portal&amp;#34; user&amp;#40;page 8&amp;#41; with a password of &amp;#34;123&amp;#64;abc&amp;#34; but at the end &amp;#40;page 54&amp;#41; the password is &amp;#34;abc&amp;#64;123&amp;#34;&lt;br /&gt;</description><author>erik_oppedijk</author><pubDate>Thu, 17 Sep 2009 14:21:52 GMT</pubDate><guid isPermaLink="false">Created Issue: SQL Authentication and wrong password in documentation [4271] 20090917022152P</guid></item><item><title>Updated Wiki: Home</title><link>http://risktracker.codeplex.com/Wiki/View.aspx?title=Home&amp;version=6</link><description>&lt;div class="wikidoc"&gt;Risk Tracker v1.0 (CTP) is a sample application built using CISF. This custom application was created to help the Microsoft Information Security Team track information security risk across the company. Eventually the solution will move to use the Microsoft GRC as the core risk engine and integrate into Systems Center. We are providing the source code and sharing the application now so our customers can share from our learning’s and adopt and extend the system for themselves. Risk Tracker serves as an example of how to build a custom security application using the Connected Information Security Framework. &lt;br /&gt;&lt;br /&gt;Risk Tracker key features -&lt;br /&gt;&lt;br /&gt;•	Integrate into Key Business Systems like HR and Portfolio / Asset Management Systems.&lt;br /&gt;•	Enter and Track Risks associated with business groups, geographies and projects.&lt;br /&gt;•	Enter and Track Tasks Associated with Remediating or Tracking Risks.&lt;br /&gt;•	Perform Basic Risk Calculations.&lt;br /&gt;•	Track The History of changes made by user/system to Risks.&lt;br /&gt;&lt;br /&gt;Note: Soon the Information Security Tools team will release a Business Intelligence solution based on SQL Server 2008 that provides data warehousing, reporting and data analytics for risk data. &lt;br /&gt;&lt;br /&gt;To keep up to date with The Information Security Tools Team follow &lt;a href="http://blogs.msdn.com/securitytools/" class="externalLink"&gt;http://blogs.msdn.com/securitytools/&lt;span class="externalLinkIcon"&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>VineetBatta</author><pubDate>Wed, 16 Sep 2009 07:09:11 GMT</pubDate><guid isPermaLink="false">Updated Wiki: Home 20090916070911A</guid></item><item><title>Updated Release: Risk Tracker  Release Notes - Sep 2009 (CTP) (Sep 15, 2009)</title><link>http://risktracker.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=33039</link><description>&lt;div class="wikidoc"&gt;This is release for Risk Tracker V1.0.&lt;br /&gt;&lt;br /&gt;Risk Tracker Deployment Guide V1.0.docx - This setup document will explain in detail the steps required to deploy Risk Tracker in your organization.&lt;br /&gt;DataBase.zip - This contains all the script/bat files for installing ISRM database &amp;amp; CISFPortal database.&lt;br /&gt;WebSite.zip - This contains the MSI installer for Risk Tracker Web site.&lt;br /&gt;.RiskTrackerServices.zip - This contains setup files for deploying WCF services that are required for Risk Tracker Application. This also includes Windows Service for notification.&lt;br /&gt;&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>vineetbatta</author><pubDate>Wed, 16 Sep 2009 03:23:39 GMT</pubDate><guid isPermaLink="false">Updated Release: Risk Tracker  Release Notes - Sep 2009 (CTP) (Sep 15, 2009) 20090916032339A</guid></item><item><title>Released: Risk Tracker  Release Notes - Sep 2009 (CTP) (Sep 15, 2009)</title><link>http://risktracker.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=33039</link><description>&lt;div&gt;This is release for Risk Tracker V1.0.&lt;br&gt;&lt;br&gt;Risk Tracker Deployment Guide V1.0.docx - This setup document will explain in detail the steps required to deploy Risk Tracker in your organization.&lt;br&gt;DataBase.zip - This contains all the script/bat files for installing ISRM database &amp;amp; CISFPortal database.&lt;br&gt;WebSite.zip - This contains the MSI installer for Risk Tracker Web site.&lt;br&gt;.RiskTrackerServices.zip - This contains setup files for deploying WCF services that are required for Risk Tracker Application. This also includes Windows Service for notification.&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;</description><author></author><pubDate>Wed, 16 Sep 2009 03:23:39 GMT</pubDate><guid isPermaLink="false">Released: Risk Tracker  Release Notes - Sep 2009 (CTP) (Sep 15, 2009) 20090916032339A</guid></item><item><title>Updated Wiki: Home</title><link>http://risktracker.codeplex.com/Wiki/View.aspx?title=Home&amp;version=5</link><description>&lt;div class="wikidoc"&gt;Risk Tracker v1.0 (CTP) is a sample application built using CISF. This custom application was created to help the Microsoft Information Security Team track information security risk across the company. Eventually the solution will move to use the Microsoft GRC as the core risk engine and integrate into Systems Center. We are providing the source code and sharing the application now so our customers can share from our learning’s and adopt and extend the system for themselves. Risk Tracker serves as an example of how to build a custom security application using the Connected Information Security Framework. &lt;br /&gt;&lt;br /&gt;Risk Tracker key features -&lt;br /&gt;&lt;br /&gt;•	Integrate into Key Business Systems like HR and Portfolio / Asset Management Systems&lt;br /&gt;•	Enter and Track Risks associated with business groups, geographies and projects&lt;br /&gt;•	Enter and Track Tasks Associated with Remediating or Tracking Risks&lt;br /&gt;•	Perform Basic Risk Calculations&lt;br /&gt;•	Track The History of changes made by user/system to Risks.&lt;br /&gt;&lt;br /&gt;Note: Soon the Information Security Tools team will release a Business Intelligence solution based on SQL Server 2008 that provides data warehousing, reporting and data analytics for risk data. &lt;br /&gt;&lt;br /&gt;To keep up to date with The Information Security Tools Team follow &lt;a href="http://blogs.msdn.com/securitytools/" class="externalLink"&gt;http://blogs.msdn.com/securitytools/&lt;span class="externalLinkIcon"&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>mcurphey</author><pubDate>Tue, 15 Sep 2009 22:21:02 GMT</pubDate><guid isPermaLink="false">Updated Wiki: Home 20090915102102P</guid></item><item><title>Updated Release: Risk Tracker  Release Notes - Sep 2009 (CTP) (Sep 15, 2009)</title><link>http://risktracker.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=33039</link><description>&lt;div class="wikidoc"&gt;This is release for Risk Tracker V1.0.&lt;br /&gt;&lt;br /&gt;Risk Tracker Deployment Guide V1.0.docx - This setup document which will explain in detail the steps required to deploy Risk Tracker.&lt;br /&gt;DataBase.zip - This contains all the script files for installing ISRM database &amp;amp; CISFPortal database.&lt;br /&gt;WebSite.zip - This contains the MSI installer for Risk Tracker Web site.&lt;br /&gt;.RiskTrackerServices.zip - This contains setup is for deploying WCF services required for Risk Tracker application and Windows Service (for notification).&lt;br /&gt;&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>mcurphey</author><pubDate>Tue, 15 Sep 2009 22:17:32 GMT</pubDate><guid isPermaLink="false">Updated Release: Risk Tracker  Release Notes - Sep 2009 (CTP) (Sep 15, 2009) 20090915101732P</guid></item><item><title>Released: Risk Tracker  Release Notes - Sep 2009 (CTP) (Sep 15, 2009)</title><link>http://risktracker.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=33039</link><description>&lt;div&gt;This is release for Risk Tracker V1.0.&lt;br&gt;&lt;br&gt;Risk Tracker Deployment Guide V1.0.docx - This setup document which will explain in detail the steps required to deploy Risk Tracker.&lt;br&gt;DataBase.zip - This contains all the script files for installing ISRM database &amp;amp; CISFPortal database.&lt;br&gt;WebSite.zip - This contains the MSI installer for Risk Tracker Web site.&lt;br&gt;.RiskTrackerServices.zip - This contains setup is for deploying WCF services required for Risk Tracker application and Windows Service (for notification).&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;</description><author></author><pubDate>Tue, 15 Sep 2009 22:17:32 GMT</pubDate><guid isPermaLink="false">Released: Risk Tracker  Release Notes - Sep 2009 (CTP) (Sep 15, 2009) 20090915101732P</guid></item><item><title>Source code checked in, #29769</title><link>http://risktracker.codeplex.com/SourceControl/changeset/view/29769</link><description>This is Risk Tracker code base for version 1.0. &amp;#40;CTP&amp;#41;</description><author>VineetBatta</author><pubDate>Tue, 15 Sep 2009 21:50:23 GMT</pubDate><guid isPermaLink="false">Source code checked in, #29769 20090915095023P</guid></item></channel></rss>