• 09 Feb 2011

    Is it possible to do more with less?

    In this era of limited budgets and "wait and see" leadership you still have to do something to manage IT and information security. I've always had trouble understanding why people can't focus on the basics and solve these problems using solutions already at their disposal. I guess the marketing machine is just doing its job.Here's a good article about this very thing written by my colleague and publisher Steve Lasky ...

    Continue Reading...
  • 08 Feb 2011

    Principles are not values

    When I started my information security consulting business 10 years ago I believed the words "principle" and "logic" would be a good fit for the way I think and work. The concept and mode of operation has worked out great. I was just reading a quote by Stephen Covey that reminded me of this - and information security leadership in general...he said:"Principles are not values. A gang of thieves can ...

    Continue Reading...
  • 31 Jan 2011

    It’s hard being human

    Cavett Robert once said something about character that resonates within information security - especially regarding ongoing management and leadership. He said:"Character is the ability to carry out a good resolution long after the excitement of the moment has passed." When I saw this I was reminded of how pumped you can get when attending a show like RSA or CSI or how neat certain vendor marketing spiels sound. Another is ...

    Continue Reading...
  • 20 Jan 2011

    Skill to do comes of doing

    Ralph Waldo Emerson once made this statement which completely and totally applies to what you do in your job and how you develop your career over the long haul:"Skill to do comes of doing."As with surgeons, home builders, mechanics, race car drivers and so on...we learn most by doing.I know a lot of people are going back to school and focusing on getting their degrees and certifications right now. There's ...

    Continue Reading...
  • 11 Jan 2011

    What’s holding you back?

    Orison Swett Marden once said:"What keeps so many employees back is simply unwillingness to pay the price, to make the exertion, the effort to sacrifice their ease and comfort." So true...as the saying goes good enough hardly ever is....

    Continue Reading...
  • 10 Jan 2011

    Great quote on information security choices

    Here's a great quote by Fred Smith that says it like it is:"You are the way you are because that's the way you want to be. If you really wanted to be any different, you would be in the process of changing right now."Obviously this also applies to our careers and personal lives...Like calories we ingest, our choices add up dramatically over time....

    Continue Reading...
  • 05 Jan 2011

    Speaking of supererogation, here’s a great quote

    Regarding yesterday's post about the word supererogation and how it can help you in your infosec career, here's a great quote by the poet Ovid that supports such an approach:"Make the workmanship surpass the materials." Spot on...otherwise you just fall in line with the majority. Not good for your career, not good for business....

    Continue Reading...
  • 04 Jan 2011

    Supererogation helps infosec

    I saw a great Word of the Day from Merriam-Webster over the Christmas break: Supererogation It means "the act of performing more than is required by duty, obligation, or need". Said another way it's going the extra mile above and beyond to make things happen.If there's any one underlying component of being successful in everything you do it's doing all the other things that need to be done in security ...

    Continue Reading...
  • 02 Jan 2011

    Security complacency & leadership – focus on both in 2011

    Happy New Year! Here are a couple of recent pieces I wrote for Security Technology Executive magazine I thought would be good to get things rolling for 2011:Don't lose sight of what's importantFour traits of successful information security leadersMy wishes to you and yours for a healthy and prosperous year ahead!...

    Continue Reading...
  • 16 Nov 2010

    Becoming a more refined Web security expert

    Here are some recent pieces I've written on Web application security and testing that you may be interested in. From getting started in your career to cloud security to doing Web application security testing the right way...check 'em out:The secrets to getting started in your software testing careerFour skills that will make you a better web security professionalBuilding solid security requirements Security oversights in the cloud: Asking the tough questionsWhy ...

    Continue Reading...