• 26 Feb 2009

    My latest security content

    Here's my latest stuff....First off, here's an article I wrote for SearchEnterpriseDesktop.com:Using Sysinternals tools in security management scenarios (a follow-up to my previous Sysinternals article)...and a podcast I recorded for SearchCIO.comMobile data protection options for enterprise CIOs (transcript included!)Enjoy!Also, be sure to check out www.principlelogic.com/resources.html for all of my information security articles, podcasts, webcasts, screencasts and more....

    Continue Reading...
  • 25 Feb 2009

    Great backup solution for laptops

    I haven't mentioned one of my favorite products lately but it deserves repeating. It's Acronis TrueImage Echo Workstation and it's a great way to backup those laptops that no one seems to be backing up. Seriously, from what I can tell in my work, if users aren't backing up their own laptops then no one is doing it. What a shame...what a gaping business continuity hole. [FYI: Acronis makes server ...

    Continue Reading...
  • 23 Feb 2009

    Want to know what a breach is going to cost?

    When writing a HIPAA-related whitepaper last week for the fine folks at Realtimepublishers.com (TONS of free papers and books on IT & security) I came across two good sites for calculating the cost of a data breach...VERY enlightening numbers from tools that have finally come of age. Keep these tools in mind when you're selling security and compliance to management (I know, it's sad you even have to): Becky Herold's ...

    Continue Reading...
  • 19 Feb 2009

    My latest security content

    Here's my latest stuff. First off, here are two articles I wrote for SearchEnterpriseDesktop.com:Sysinternals tools: A must-have for every Windows security toolbox...an article I wrote for SearchSoftwareQuality.com:Web application security gaps not fixed in 2008...and an article I wrote for SearchEnterpriseLinux.com:Five common Linux security vulnerabilities you may be overlookingIn the meantime, be sure to check out www.principlelogic.com/resources.html for all of my information security articles, podcasts, webcasts, screencasts and more....

    Continue Reading...
  • 31 Dec 2008

    Very cool thing about the Sysinternals tools

    OK, I'm a bit late to the punch on this one but just in case you don't know, the awesome Sysinternals tools (a must-have for every security pro) are now available online for immediate access here. No more downloading, unzipping, etc. - just click and run...assuming you can get past your Web browser controls. ;)...

    Continue Reading...
  • 30 Dec 2008

    Interesting solution to the new Red Flags requirements

    I can't vouch for the quality of this offering I recently came across it but it does look interesting. It's called CompliancePal and it helps businesses automate/manage the requirements of the new FTC Red Flags Rules that are intended to help fix the problem we have with identity theft here in the U.S.Heaven knows business managers need help taking the pain out of the compliance process wherever they can!...

    Continue Reading...
  • 10 Dec 2008

    Interesting new technology from Maxell

    Maxell has a new technology that can analyze tape cartridges to determine if they're in good enough condition to use (and rely on) for backups. Pretty neat.Maybe this can help fill the "lack of backup testing" gap pervasive across most businesses. That is if anyone's even paying attention to their backups out there. Apparently they're not....

    Continue Reading...
  • 12 Nov 2008

    New way to crack WPA on wireless networks

    Everything in security is just a matter of time, right? Well, a couple of researchers - one of which is the author of the Aircrack-ng tool that I've covered a lot over the years - have found a new way to crack the WPA TKIP key in a just a few minutes without using a dictionary attack (previously the only way to crack it). Reaffirms the arms race we're mired ...

    Continue Reading...
  • 22 Oct 2008

    A creative customer service mantra

    I just saw this on Webroot's website...Three things we've all experienced in our work and personal lives: At Webroot, we... answer the phonespeak your languagesolve your problem I love it! Hopefully they'll be there when/if I need them. :-)...

    Continue Reading...
  • 03 Sep 2008

    Upcoming PCI updates and the firewall change management disconnect

    I was reading about the upcoming PCI DSS version 1.2 updates and noticed something that struck a chord. It's the requirement to review firewall rules every 6 months instead of every three. Wooo - what a nice break the Council has given everyone. Seriously folks, is anyone really reviewing their firewall rules on a regular basis? I don't mean loading up the PIX or Check Point or whatever interface, scrolling ...

    Continue Reading...