<?xml version="1.0" encoding="UTF-8"?><xml><records><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Chris McPhee</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Editorial: Innovation Strategy and Practice (November 2018)</style></title><secondary-title><style face="normal" font="default" size="100%">Technology Innovation Management Review</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">best practice</style></keyword><keyword><style  face="normal" font="default" size="100%">collaboration</style></keyword><keyword><style  face="normal" font="default" size="100%">creativity</style></keyword><keyword><style  face="normal" font="default" size="100%">cybersecurity</style></keyword><keyword><style  face="normal" font="default" size="100%">framework</style></keyword><keyword><style  face="normal" font="default" size="100%">information security</style></keyword><keyword><style  face="normal" font="default" size="100%">innovation</style></keyword><keyword><style  face="normal" font="default" size="100%">innovation ecosystems</style></keyword><keyword><style  face="normal" font="default" size="100%">maturity model</style></keyword><keyword><style  face="normal" font="default" size="100%">method</style></keyword><keyword><style  face="normal" font="default" size="100%">model</style></keyword><keyword><style  face="normal" font="default" size="100%">practice</style></keyword><keyword><style  face="normal" font="default" size="100%">research</style></keyword><keyword><style  face="normal" font="default" size="100%">research institutions</style></keyword><keyword><style  face="normal" font="default" size="100%">strategy</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2018</style></year><pub-dates><date><style  face="normal" font="default" size="100%">11/2018</style></date></pub-dates></dates><urls><web-urls><url><style face="normal" font="default" size="100%">https://timreview.ca/article/1194</style></url></web-urls></urls><publisher><style face="normal" font="default" size="100%">Talent First Network</style></publisher><pub-location><style face="normal" font="default" size="100%">Ottawa</style></pub-location><volume><style face="normal" font="default" size="100%">8</style></volume><pages><style face="normal" font="default" size="100%">3-3</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><issue><style face="normal" font="default" size="100%">11</style></issue><custom1><style face="normal" font="default" size="100%">Technology Innovation Management Review
Chris McPhee is Editor-in-Chief of the &lt;em&gt;Technology Innovation Management Review.&lt;/em&gt; Chris holds an MASc degree in Technology Innovation Management from Carleton University in Ottawa, Canada, and BScH and MSc degrees in Biology from Queen’s University in Kingston, Canada. He has nearly 20 years of management, design, and content-development experience in Canada and Scotland, primarily in the science, health, and education sectors. As an advisor and editor, he helps entrepreneurs, executives, and researchers develop and express their ideas.</style></custom1></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Urpo Kaila</style></author><author><style face="normal" font="default" size="100%">Linus Nyman</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Information Security Best Practices: First Steps for Startups and SMEs</style></title><secondary-title><style face="normal" font="default" size="100%">Technology Innovation Management Review</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">best practices</style></keyword><keyword><style  face="normal" font="default" size="100%">cybersecurity</style></keyword><keyword><style  face="normal" font="default" size="100%">information security</style></keyword><keyword><style  face="normal" font="default" size="100%">risk management</style></keyword><keyword><style  face="normal" font="default" size="100%">SMEs</style></keyword><keyword><style  face="normal" font="default" size="100%">startups</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2018</style></year><pub-dates><date><style  face="normal" font="default" size="100%">11/2018</style></date></pub-dates></dates><urls><web-urls><url><style face="normal" font="default" size="100%">https://timreview.ca/article/1198</style></url></web-urls></urls><publisher><style face="normal" font="default" size="100%">Talent First Network</style></publisher><pub-location><style face="normal" font="default" size="100%">Ottawa</style></pub-location><volume><style face="normal" font="default" size="100%">8</style></volume><pages><style face="normal" font="default" size="100%">32-42</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">This article identifies important first steps toward understanding and implementing information security. From the broad selection of existing best practices, we introduce a lightweight yet comprehensive security framework with four useful first steps: identifying assets and risks; protecting accounts, systems, clouds, and data; implementing a continuity plan; and monitoring and reviewing. This article is intended primarily for startups and less mature companies, but it is likely to be of interest to any reader seeking an introduction to basic information security concepts and principles as well as their implementation.</style></abstract><issue><style face="normal" font="default" size="100%">11</style></issue><custom1><style face="normal" font="default" size="100%">Finnish IT Center for Science (CSC)
Urpo Kaila is the Head of Security for CSC – the Finnish IT Center for Science. His background in the information security industry, with long experience in handling security incidents as well as developing solutions for information security and data protection. He has been responsible to achieve the valued ISO/IEC 27001 information security management certification for CSC and is a steering committee member in security groups for some European Research Infrastructures, such as WISE and GÉANT SIG-ISM. Urpo holds the professional international information security certificates CISSP, GCIH, GCED, CISM, and ISO 27001 Lead Auditor. He also holds a Master’s degree from the Hanken School of Economics. His research focuses on best practices in information security and data protection.</style></custom1><custom2><style face="normal" font="default" size="100%">Hanken School of Economics
Linus Nyman is an Assistant Professor at the Hanken School of Economics in Helsinki, Finland, and an Adjunct Research Professor in the Technology Innovation Management (TIM) program at Carleton University in Ottawa, Canada. He has lectured on a range of topics, including information security and privacy, information systems science, corporate strategy, and open source software development. His current research focuses on information security and privacy, which are topics he also covers in a blog for the Finnish daily newspaper &lt;em&gt;HBL.&lt;/em&gt; Linus holds a PhD and a Master’s degree, both from the Hanken School of Economics.</style></custom2></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">David Grau</style></author><author><style face="normal" font="default" size="100%">Charles Kennedy</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">TIM Lecture Series – The Business of Cybersecurity</style></title><secondary-title><style face="normal" font="default" size="100%">Technology Innovation Management Review</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">analytics</style></keyword><keyword><style  face="normal" font="default" size="100%">banking</style></keyword><keyword><style  face="normal" font="default" size="100%">cybersecurity</style></keyword><keyword><style  face="normal" font="default" size="100%">hacking</style></keyword><keyword><style  face="normal" font="default" size="100%">incident response</style></keyword><keyword><style  face="normal" font="default" size="100%">information security</style></keyword><keyword><style  face="normal" font="default" size="100%">intelligence</style></keyword><keyword><style  face="normal" font="default" size="100%">targets</style></keyword><keyword><style  face="normal" font="default" size="100%">threats</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2014</style></year><pub-dates><date><style  face="normal" font="default" size="100%">04/2014</style></date></pub-dates></dates><urls><web-urls><url><style face="normal" font="default" size="100%">http://timreview.ca/article/785</style></url></web-urls></urls><publisher><style face="normal" font="default" size="100%">Talent First Network</style></publisher><pub-location><style face="normal" font="default" size="100%">Ottawa</style></pub-location><volume><style face="normal" font="default" size="100%">4</style></volume><pages><style face="normal" font="default" size="100%">53-57</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><issue><style face="normal" font="default" size="100%">4</style></issue><custom1><style face="normal" font="default" size="100%">TD Bank Group
David Grau is Vice President and Head of Threat Response, Intelligence, and Defensive Technologies at TD Bank Group. David has more than 20 years of professional information security experience and leads a multi-national team of information security specialists, with a global responsibility for providing TD Bank Group's Security Incident Response, Threat Intelligence, and Defensive Technologies programs.</style></custom1><custom2><style face="normal" font="default" size="100%">TD Bank Group
Chuck Kennedy is the VP for Credit Card Technology for North American Credit Card for TD Bank Group. He is responsible for technology service delivery, project management, and technology innovation for the credit card businesses for TD. Chuck has been a member of the CIO Association of Canada and has served on the Canadian Banker’s Association’s (CBA), Canadian Financial Institution – Computer Incident Response Team (CFI-CIRT). Chuck holds the CRISC designation (Certified In Risk and Systems Control) and was educated in the United States, Europe, and Canada. He holds a BA in Political Science (Business minor) from the University of Calgary and an MSc in Information Technology (Information Assurance) from the University of Maryland – University College. His graduate work involved the study of geo-spatial intrusion detection and its integration with complex event processing.</style></custom2></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Brian Ritchot</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">An Enterprise Security Program and Architecture to Support Business Drivers</style></title><secondary-title><style face="normal" font="default" size="100%">Technology Innovation Management Review</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">cybersecurity</style></keyword><keyword><style  face="normal" font="default" size="100%">cyberthreats</style></keyword><keyword><style  face="normal" font="default" size="100%">information assurance</style></keyword><keyword><style  face="normal" font="default" size="100%">information risk</style></keyword><keyword><style  face="normal" font="default" size="100%">information security</style></keyword><keyword><style  face="normal" font="default" size="100%">risk</style></keyword><keyword><style  face="normal" font="default" size="100%">security architecture</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2013</style></year><pub-dates><date><style  face="normal" font="default" size="100%">08/2013</style></date></pub-dates></dates><urls><web-urls><url><style face="normal" font="default" size="100%">http://timreview.ca/article/713</style></url></web-urls></urls><publisher><style face="normal" font="default" size="100%">Talent First Network</style></publisher><pub-location><style face="normal" font="default" size="100%">Ottawa</style></pub-location><volume><style face="normal" font="default" size="100%">3</style></volume><pages><style face="normal" font="default" size="100%">25-33</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">This article presents a business-focused approach to developing and delivering enterprise security architecture that is focused on enabling business objectives while providing a sensible and balanced approach to risk management. A balanced approach to enterprise security architecture can create the important linkages between the goals and objectives of a business, and it provides appropriate measures to protect the most critical assets within an organization while accepting risk where appropriate. Through a discussion of information assurance, this article makes a case for leveraging enterprise security architectures to meet an organizations' need for information assurance. The approach is derived from the Sherwood Applied Business Security Architecture (SABSA) methodology, as put into practice by Seccuris Inc., an information assurance integrator. An understanding of Seccuris’ approach will illustrate the importance of aligning security activities with high-level business objectives while creating increased awareness of the duality of risk. This business-driven approach to enterprise security architecture can help organizations change the perception of IT security, positioning it as a tool to enable and assure business success, rather than be perceived as an obstacle to be avoided.</style></abstract><issue><style face="normal" font="default" size="100%">8</style></issue><custom1><style face="normal" font="default" size="100%">Seccuris 
Brian Ritchot is a Senior Information Security Consultant with Seccuris Inc, specializing in the implementation and delivery of intrusion-detection solutions, vulnerability assessment, network analysis, and security architecture. With 11 years of prior experience in the federal government, Brian has developed skills and expertise to support the detection, discovery, and mitigation of cyberthreat activity. Brian has led and managed several high-profile teams and projects to deliver operational security solutions that monitor and protect systems of importance to the Government of Canada. Brian now focuses his time in the private sector, helping a variety of customers across the critical infrastructure sector with their IT security needs. These activities span enterprise security architecture development, incident response and handling, vulnerability assessments, forensic investigations, and specialized IT security expertise to mitigate sophisticated cyberintrusions. </style></custom1></record></records></xml>