<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="http://community.norton.com/norton/styledfeed_xsl?board.id=npb1&amp;message.id=235" ?>
<?xml-stylesheet type="text/css" href="http://community.norton.com/norton/styledfeed_css" ?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>AMTSO: Reviewing the Reviews</title>
    <link>http://community.norton.com/t5/Norton-Protection-Blog/AMTSO-Reviewing-the-Reviews/ba-p/40155</link>
    <description>In January of this year, Symantec became a founding member of the &lt;a href="http://www.amtso.org/" target="_blank"&gt;Anti-Malware Testing Standards Organization&lt;/a&gt; (AMTSO). Symantec and about 40 of the leading academics, reviewers, testers and vendors in the security industry joined forces to form the organization dedicated to helping improve the objectivity, quality and relevance of anti-malware technology testing. Since then, we&amp;rsquo;ve met several times and shared numerous spirited debates, but something we have agreed upon since our inception is the charter of the organization: &lt;p&gt;&lt;span style="font-size: 10pt; font-family: Symbol"&gt;&lt;span&gt;&amp;middot;&lt;span style="font: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9pt; font-family: 'Arial','sans-serif'"&gt;Providing a forum for discussions related to the testing of anti-malware and related products; &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt; font-family: Symbol"&gt;&lt;span&gt;&amp;middot;&lt;span style="font: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9pt; font-family: 'Arial','sans-serif'"&gt;Developing and publicizing objective standards and best practices for testing of anti-malware and related products; &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt; font-family: Symbol"&gt;&lt;span&gt;&amp;middot;&lt;span style="font: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9pt; font-family: 'Arial','sans-serif'"&gt;Promoting education and awareness of issues related to the testing of anti-malware and related products;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt; font-family: Symbol"&gt;&lt;span&gt;&amp;middot;&lt;span style="font: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9pt; font-family: 'Arial','sans-serif'"&gt;Providing tools and resources to aid standards-based testing methodologies; and,&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt; font-family: Symbol"&gt;&lt;span&gt;&amp;middot;&lt;span style="font: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9pt; font-family: 'Arial','sans-serif'"&gt;Providing analysis and review of current and future testing of anti-malware and related products.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;Now that the first two official documents for the AMTSO have been adopted and published (&lt;a href="http://www.amtso.org/documents/cat_view/13-amtso-principles-and-guidelines.html" target="_blank" title="blocked::http://www.amtso.org/documents/cat_view/13-amtso-principles-and-guidelines.html"&gt;&lt;span style="color: windowtext"&gt;http://www.amtso.org/documents/cat_view/13-amtso-principles-and-guidelines.html&lt;/span&gt;&lt;/a&gt;) the next step will be to put these principles into practice.&amp;nbsp; AMTSO is now working on a process to Review the Reviews.&amp;nbsp; This will be a process whereby a published review can be critiqued to see where it did or did not follow the AMTSO principles and guidelines &amp;ndash; and for the latter give specific feedback as to why.&amp;nbsp; This is understandably a potentially very controversial thing to do.&amp;nbsp; &lt;/span&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;I&amp;rsquo;d like to share my personal views on how this process should be conducted.&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;The two main concerns people have about &amp;ldquo;reviewing the reviews&amp;rdquo; are that the process will seem to be AV vendors &amp;ldquo;whining&amp;rdquo; about losing a review and that a thorough analysis of a review cannot be done in a timely enough manner to blunt the damage caused by a problematic review.&amp;nbsp; To address the former several specific steps have been outlined.&amp;nbsp; For the second point this process will be explicitly understood not to attempt to prevent any damage from such a review, but rather to help improve future reviews.&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;The general outline of the &amp;ldquo;Review Analysis&amp;rdquo; would be as follows.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt; font-family: Symbol"&gt;&lt;span&gt;&amp;middot;&lt;span style="font: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;Process must be impartial&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt; font-family: Symbol"&gt;&lt;span&gt;&amp;middot;&lt;span style="font: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;Process must be transparent&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt; font-family: Symbol"&gt;&lt;span&gt;&amp;middot;&lt;span style="font: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;Process is analytical only&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt; font-family: Symbol"&gt;&lt;span&gt;&amp;middot;&lt;span style="font: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;Review analysis is not intended nor will it be able to &amp;ldquo;unring the bell.&amp;rdquo;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;Process must be impartial&lt;/span&gt;&lt;/strong&gt;&lt;strong&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;&amp;nbsp;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;Steps should be taken to ensure that first there is a consensus that the review should be analyzed.&amp;nbsp; It is important that an entity not simply request the analysis because they lost, or did not like something that was done.&amp;nbsp; Two specific steps should be included.&amp;nbsp; First, specific examples of violations of the Principles and Guidelines must be identified.&amp;nbsp; Second, multiple entities must agree with those violations.&amp;nbsp; These two steps should help ensure that there is solid ground for the request.&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;Process must be transparent&lt;/span&gt;&lt;/strong&gt;&lt;strong&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;&amp;nbsp;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;The process of analyzing the review must be as open and visible as possible.&amp;nbsp; The entities requesting the analysis as well as their arguments for why should be made public.&amp;nbsp; The entity that conducted the review must have an opportunity to respond.&amp;nbsp; Other interested parties &amp;ndash; both supporting and criticizing &amp;ndash; must have an opportunity to comment.&lt;/span&gt;&lt;strong&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;&amp;nbsp;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;Process is analytical only.&lt;/span&gt;&lt;/strong&gt;&lt;strong&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;&amp;nbsp;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;The output of this process should be as objective as possible, and should not contain subjective statements (such as &amp;ldquo;This was a poorly conducted test.&amp;rdquo;).&amp;nbsp; The output should be specific language regarding where the review in question is and is not in compliance with the AMTSO Principles and Guidelines &amp;ndash; and why.&amp;nbsp; It may contain recommendations about specific steps which can be undertaken to gain compliance.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;&amp;nbsp;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;Analysis cannot &amp;ldquo;unring the bell.&amp;rdquo;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;This analysis will naturally take some time, but the larger goal is to improve future reviews, as opposed to responding quickly enough to give press quotes while a story is &amp;ldquo;hot.&amp;rdquo;&amp;nbsp; The committee review should happen in a timely manner, but this process should not be counted on to mitigate damage of a bad review.&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;So what do you think about our goals for Review Analysis? I&amp;rsquo;m very interested in your feedback regarding my opinion of what I&amp;rsquo;d like to see happen, so please leave your comments and questions in the section below.&lt;/span&gt;&lt;/p&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;a href="http://www.addthis.com/bookmark.php" target="_blank" title="Bookmark and Share" onclick="window.open('http://www.addthis.com/bookmark.php?wt=nw&amp;pub=sondrasondra&amp;url='+encodeURIComponent(location.href)+'&amp;title='+encodeURIComponent(document.title), 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no,screenX=200,screenY=100,left=200,top=100'); return false;"&gt;&lt;img src="http://s9.addthis.com/button1-share.gif" border="0" alt="Bookmark and Share" width="125" height="16" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;br /&gt;&lt;div class="message-edit-history"&gt;&lt;/div&gt;&lt;div class='message-edit-history'&gt;&lt;span class='edit-author'&gt;Message Edited by Sondra_Magness on &lt;/span&gt;&lt;span class='local-date'&gt; 11-13-2008&lt;/span&gt;&lt;span class='local-time'&gt; 02:10 PM&lt;/span&gt;&lt;/div&gt;</description>
    <pubDate>Wed, 12 Nov 2008 23:16:54 GMT</pubDate>
    <dc:creator>MarkKennedy</dc:creator>
    <dc:date>2008-11-12T23:16:54Z</dc:date>
    <item>
      <title>AMTSO: Reviewing the Reviews</title>
      <link>http://community.norton.com/t5/Norton-Protection-Blog/AMTSO-Reviewing-the-Reviews/ba-p/40155</link>
      <description>In January of this year, Symantec became a founding member of the Anti-Malware Testing Standards Organization (AMTSO). Symantec and about 40 of the leading academics, reviewers, testers and vendors in the security industry joined forces to form the organization dedicated to helping improve the objectivity, quality and relevance of anti-malware technology testing. Since then, the first two official documents for the AMTSO have been adopted and published. The next step will be to put these principles into practice.  We’re now working on a process to Review the Reviews - a potentially very controversial thing to do. Read on to learn my personal views on how I think this process should be conducted.  &lt;p&gt;&lt;span style="font-size: 10pt; font-family: 'Arial','sans-serif'"&gt;&lt;img src="http://norton.lithium.com/norton/attachments/norton/uploads/52/1/AMTSO.gif" border="0" /&gt;</description>
      <pubDate>Wed, 12 Nov 2008 23:16:54 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Protection-Blog/AMTSO-Reviewing-the-Reviews/ba-p/40155</guid>
      <dc:creator>MarkKennedy</dc:creator>
      <dc:date>2008-11-12T23:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: AMTSO: Reviewing the Reviews</title>
      <link>http://community.norton.com/t5/Norton-Protection-Blog/AMTSO-Reviewing-the-Reviews/bc-p/155306</link>
      <description>&lt;span class="Apple-style-span"&gt;Just wanted to get some info on how to respond to the report that says i have 36 problems. I have quarantined them, the log says they are quarantined but when i run my scan it comes back with 36 infected files. Do i have to do anything more to remove them from my computer or just accept that this virus is out of harms way? I used to have parallels with MS but have since removed that software. The virus says it has infected exe files. I have a mac so i don't know what this means. Help?&lt;/span&gt;</description>
      <pubDate>Mon, 28 Sep 2009 22:40:37 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Protection-Blog/AMTSO-Reviewing-the-Reviews/bc-p/155306</guid>
      <dc:creator>cmiller53</dc:creator>
      <dc:date>2009-09-28T22:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: AMTSO: Reviewing the Reviews</title>
      <link>http://community.norton.com/t5/Norton-Protection-Blog/AMTSO-Reviewing-the-Reviews/bc-p/155421</link>
      <description>&lt;p&gt;Hi cmiller53&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Post your issue to the mac forum and someone should pick it up there.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Thanks&lt;/p&gt;</description>
      <pubDate>Tue, 29 Sep 2009 05:32:37 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Protection-Blog/AMTSO-Reviewing-the-Reviews/bc-p/155421</guid>
      <dc:creator>mdturner</dc:creator>
      <dc:date>2009-09-29T05:32:37Z</dc:date>
    </item>
  </channel>
</rss>

