• 10 Feb 2012

    Video: The one infosec skill you need to be working on

    Develop and maintain this one skill and you'll position yourself to be a much more valuable information security professional:  ...

    Continue Reading...
  • 31 Jan 2012

    Where’s your information security focus?

    You cannot change facts (i.e. the industry your business is in, the regulations it's up against, the type of sensitive information you're responsible for managing, etc.) but you can change problems (i.e. user behavior, wayward goals, management not on board with security, etc. ).As the philosopher James Burnham once said: "If there is no alternative, there is no problem." In the case of information security, there are tons of alternatives to ...

    Continue Reading...
  • 27 Jan 2012

    You cannot multiple security by dividing it – Infosec’s relationship with Socialism

    I'm not much into urban legends and the like but came across this bit the other day and it really made me think. What a great analogy that impacts all of us both personally and professionally with some interesting information security and compliance tie-ins that I see all the time:An economics professor at a local college made a statement that he had never failed a single student before, but had ...

    Continue Reading...
  • 26 Jan 2012

    Evanta CISO event and why St. Jude’s has it right

    This week I had the opportunity and privilege to serve as a panelist on mobile security at the Evanta CISO Executive Summit in Atlanta. What a neat event...it wasn't just another infosec show. It was unique in its focus and well run by Corrine Buchanan and Mitch Evans who always seemed to have a smile on their faces - something we don't see enough of at these types of shows. ...

    Continue Reading...
  • 03 Jan 2012

    Great quote to live by

    Here's one of my favorite #quotes you can apply to your career, regardless of which field you're in:"A successful life is one that is lived through understanding and pursuing one's own path, not chasing after the dreams of others." -Chin-Ning Chu...

    Continue Reading...
  • 12 Dec 2011

    Why uninterruptible power supplies have higher quality than Web apps

    I recently purchased an APC uninterruptible power supply for my office and noticed something peculiar in the packaging. It was a small piece of paper that says "QUALITY ASSURANCE TEST". It has the time, date, operator ID and other identifying information for the specific piece of hardware.As you can see in the image, this QA test sheet has 33 unique tests that were performed on the unit presumably before it ...

    Continue Reading...
  • 08 Dec 2011

    Are CIOs not doing their jobs?

    In the past week I've come across three different articles on how CFOs are getting more involved in IT. For example, in last week's Atlanta Business Chronicle feature CFOs take on increasing roles in IT department stated: "CFO involvement with IT has been largely driving by the need to upgrade reporting functions and the general inability of many legacy systems to provide the kind of data the C-suite needs." According ...

    Continue Reading...
  • 27 Nov 2011

    Don’t get mired striving for perfection

    As we wind down 2011, here's a quote that relates to information security, incident response and overall risk management:“The person who insists upon seeing with perfect clearness before he or she decides, never decides.” -Henri Frederic AmielSo, do something to better your information security program. Any positive step forward - anything - is much better than getting mired in the desire for perfection and doing nothing at all....

    Continue Reading...
  • 01 Nov 2011

    What needs to change?

    The late Richard Carlson once said:Circumstances don't make a person, they reveal him or her. There are times when other people and/or circumstances contribute to our problems, but it is we who must rise to the occasion and take responsibility for our own happiness. Deep.Whether you're caught up in an IT project mess, a data breach or even the #Occupy "movement", keep this in mind. We're the sum of our ...

    Continue Reading...
  • 25 Oct 2011

    Your title really means nothing

    I can't tell you how many times I've met people over the years who have a fancy title like CEO or Director of This and That and it ended up being more of a façade than anything. As John Maxwell talks about in this video, your title really means nothing.I've often told people, I don't care what you call me as long as you pay me what I'm worth. That ...

    Continue Reading...