• 18 Apr 2011

    From each according to his ability to each according to his need

    I thought this Marxist/Obama philosophy was very fitting for our symbolic day today here in the U.S. The general belief that the government should decide what the people need is what's driving our country...and the world. And we wonder why we can't get out of this economic mess! The reality is that the economy cannot be taxed into prosperity but that's what the politicians want to make us believe...especially if ...

    Continue Reading...
  • 15 Apr 2011

    Be wary of the well-certified IT pro

    You may have read that Gartner projects IT spending to increase in 2011. It's great news that may lead to hiring new staff or at least new consultants for your IT and information security projects....Just proceed with caution and don't fall for the "I'm certified therefore I'm all you need" persona that's rampant in our industry.There are a lot of people out there looking for work - many of which ...

    Continue Reading...
  • 12 Apr 2011

    Have no fear and be free

    "The whole secret of existence is to have no fear. Never fear what will become of you, depend on no one. Only the moment you reject all help are you freed." -BuddhaThis is great for personal power, personal responsibility and, of course, information security - just be careful with that "reject all help" bit. ;)...

    Continue Reading...
  • 01 Apr 2011

    Web security tidbits on developers, leadership, weak passwords & more

    Here are a few pieces I've written recently on Web application security you may be interested in...things that affect each and every one of us working in IT and infosec:I wouldn’t want to be a developer these daysDon’t overlook the importance of authenticated testingYou can’t change what you tolerateTesting for weak passwords: a common oversight without a great solutionHow often should you test your web applications?Notable changes in the PCI ...

    Continue Reading...
  • 01 Apr 2011

    Time management + getting over your job title in IT

    Here are some IT career bits I wrote for TechTarget's SearchWinIT.com that you may be interested in:Time management strategies for the IT proYour title is worthless; your value is priceless This is the best time ever to focus on these things.Enjoy!Also, be sure to check out www.principlelogic.com/resources.html for all of my information security articles, podcasts, webcasts, screencasts and more....

    Continue Reading...
  • 28 Mar 2011

    A quick review of WebInspect 9 shows HP’s still got it

    It's been a long time coming but it's finally here: HP's WebInspect version 9. I've been using WebInspect for nearly 10 years now and I believe this new version of WebInspect is one of the most significant upgrades they've put out. They've essentially taken what was already one of the best Web vulnerability scanners and have made it better, especially when it comes to workflow and streamlined usability.A few things ...

    Continue Reading...
  • 26 Mar 2011

    Viewfinity’s latest privilege management offering

    I had the opportunity to meet up with my colleague Matt Stubbs with SnappConner on a recent visit to Salt Lake City. One of the things we discussed was Viewfinity's new privilege management software release.Viewfinity provides a public or private cloud solution to locking down Windows desktops including:getting your arms around administrator-level privileges (perhaps once and for all?)allowing users to install permitted applications, printers, etc.blocking/whitelisting of applicationsCheck out this screencast ...

    Continue Reading...
  • 20 Mar 2011

    Getting your ducks in a row with cloud compliance

    Cloud, cloud, cloud - it's all we're hearing about these days. Frankly I'm over the hype - have been for a while...But whether or not we buy into all this hoopla over "the cloud", the technologies and associated security risks and compliance headaches aren't going anywhere. With that here are a couple of new pieces I've written for SearchCompliance.com that you may be interested in:The cloud’s compliance complexities you cannot ...

    Continue Reading...
  • 15 Mar 2011

    Discount code for SecureWorld Expo Atlanta

    Have you ever attended SecureWorld Expo? It's a neat security conference that travels around the U.S. bringing content to you. I traveled around and spoke at their shows for years and can attest that it's a very good value - especially when you can't afford or otherwise justify going to RSA, CSI and related shows.The folks that run SecureWorld Expo have setup a discount code for me (SWEBEAV) that will ...

    Continue Reading...
  • 15 Mar 2011

    Perhaps the goofing off is justified

    I've written in the past about how little we utilize our brain capacity - especially at it relates to goofing off on the job...Well perhaps those folks goofing off know something that I didn't. According to the Department of Labor and BTN Research:The average productivity of the American worker (defined as output per hour of work) has increased 30 percent over the past decade (i.e., 2001-2010). Mathematically this means the ...

    Continue Reading...