Yesterday I had lunch with some colleagues who are lawyers that focus their work in/around compliance, intellectual property and cloud computing. It was neat to hear their perspective on where things are headed in IT. We came to the conclusion that IT professionals are going to have to learn as much as they can about the legal side of what we do.I'm not talking compliance in general but also contracts, ...
Continue Reading...I attended this week's SecureWorld Expo in Atlanta and must say that the show is better now than ever before. I cut my professional speaking teeth with these guys speaking at dozens of their events between 2003 and 2007. I've taken some time off since but going back and seeing some of the same friendly faces brought back good memories.The best session I attended was William Hugh Murray's keynote on ...
Continue Reading...Today I'm prepping and practicing for my Predictive Security event with TechTarget and CDW in Los Angeles this week. Really psyched about the show and visiting LA - I've never been.How I feel reminds me of the following quote from Whit Hobbs:"Success is waking up in the morning and bounding out of bed because there's something out there that you love to do, that you believe in, that you're good ...
Continue Reading..."Have you ever, even once, stopped to marvel at just how often things go right? It's amazing." -Richard CarlsonWith all of the smack talk and negative approaches so many of us (myself included) take regarding IT and information security, this'll make you realize that it's not all bad. I we could all benefit from stopping to smell the roses and seeing the bright side of our field every now and ...
Continue Reading..."If your intent is to learn, you almost always do learn." - Richard CarlsonLike when we see what we want to see, we learn what we want to learn. This is important for our careers in IT and infosec but also provides a great way for us to become better people....
Continue Reading...Here are a few pieces I've written recently on Web application security you may be interested in...things that affect each and every one of us working in IT and infosec:I wouldn’t want to be a developer these daysDon’t overlook the importance of authenticated testingYou can’t change what you tolerateTesting for weak passwords: a common oversight without a great solutionHow often should you test your web applications?Notable changes in the PCI ...
Continue Reading...Here are some IT career bits I wrote for TechTarget's SearchWinIT.com that you may be interested in:Time management strategies for the IT proYour title is worthless; your value is priceless This is the best time ever to focus on these things.Enjoy!Also, be sure to check out www.principlelogic.com/resources.html for all of my information security articles, podcasts, webcasts, screencasts and more....
Continue Reading...Join me and my colleagues/friends Becky Herold (The Privacy Professor) and Scott Woodison (security manager extraordinaire) on Focus.com tomorrow at 2pm ET where we'll be talking about:Compliance vs. managing information risks - there is a differenceCommon compliance-related mistakesRecent changes to information security and privacy regulations and how they affect youRecommendations on what your business can do to get its arms around the compliance beastIt'll be laid back yet informative...we'll no ...
Continue Reading...Here's one of those great quotes that applies directly to infosec:“Talent is cheaper than table salt. What separates the talented individual from the successful one is a lot of hard work.” -Stephen KingThere are plenty of people who understand security architecture, hacking and related technical issues but few who really get the essence of risk and have taken the necessary steps to make information security work in support of the ...
Continue Reading...Here's a good read from @arstechnica on the HBGary story. It's a fascinating story in and of itself. But the oversights related to information security "best practices" is amazing. What is it going to take to get people to focus on the basics? Seriously, folks...Forget about all the fancy hack attacks and complex exploits for now and fix the low-hanging fruit. It's basic triage - stop the bleeding first. Focus ...
Continue Reading...