There's a Japanese proverb that fits nicely into infosec:"If you believe everything you read, perhaps it's better not to read."Be it F.U.D., vendor hype, or "experts" who claim the sky is falling with every new exploit they uncover - you ultimately need to focus on doing what's best in your environment under your terms....
Continue Reading...I'm back from my last break of the summer and thought I'd share this quote I came across for a bit of inspiration:"A successful life is one that is lived through understanding and pursuing one's own path, not chasing after the dreams of others." -- Chin-Ning ChuThis reminds me of another great quote which says "If you don't have goals for yourself you're doomed forever to achieve the goals of ...
Continue Reading...Here's a funny - and ironic - pic a friend of mine just forwarded me.Need I say more?Also, I have on my desk the March 8, 2010 edition of InformationWeek (great mag by the way) that has BP as its cover story. A call out quote says:"Two years ago, BP CEO Tony Hayward laid some very tough love on his 500 top managers. Despite revenue of about $300 billion, the ...
Continue Reading...I believe it was my colleague Kevin Bocek who once said: "Security done right will yield compliance for free. Compliance for compliance sake will always deliver more problems in the end."Why is it so many business leaders keep ignoring this reality?It's funny, I was just thinking about an article I co-authored for CSO Online with Charles Cresson Wood nearly a year ago entitled The Dangers of Over-Reliance on Compliance. Those ...
Continue Reading...I love what Michelangelo said:"The greater danger for most of us lies not in setting our aim too high and falling short, but in setting our aim too low and achieving our mark."...reminds me of how easy it is to fall into the trap of complacency and principle of "good enough" with information security....
Continue Reading...Bill Cosby said it best: "I don't know the key to success, but the key to failure is trying to please everybody." Be it your current job, your career, information security, IT, whatever - you cannot forget this sage advice....
Continue Reading...Socrates said it best: "The more you know, the more you realize you know nothing." How true this is in the context of information security.Funny how we start out knowing everything in our teens, think we know everything in our 20s, and, in our 30s and beyond, come to the realization that things are much more complex than we originally thought.Common sense - and humility - are the key ingredients ...
Continue Reading..."I am more afraid of an army of 100 sheep led by a lion than an army of 100 lions led by a sheep." -Charles TalleyrandApplies nicely to the management of information security and amazingly well to our government "leaders" today....
Continue Reading...Michael Eisner once said "Succeeding is not really a life experience that does much good. Failing is a much more sobering and enlightening experience."This is something we often take for granted...and something that's facilitated by our society of not wanting people (especially our kids) to fail.I wouldn't trade my failures in life for anything...they've gotten me to where I am today. Failure's always an option and not something to be ...
Continue Reading...This sends a message, huh?:"All that is necessary for the triumph of evil is that good men do nothing." -Edmund BurkeIt's not just applicable to information security - it also applies to the War on Islamic Terrorism...uhum, I mean "Man-Caused Disaster"....
Continue Reading...