• 17 Sep 2010

    Unique new book on least privilege security in Windows

    I've been reading through Russell Smith's new book Least Privilege Security for Windows 7, Vista and XP and I've realized it's about time for a book on this subject. I've covered some of the material in the past including in my recent SearchWinIT.com tip Should Windows users have full administrative rights? and I know there's content on this topic scattered across various books, articles, etc. but I've never seen a ...

    Continue Reading...
  • 17 Sep 2010

    Are your high-tech devices enslaving you?

    I saw a recent Don't Sweat the Small Stuff calendar quote where Richard Carlson said:"It's important to see when your high-tech communication devices actually limit your freedom, enslaving you instead of providing new opportunities for growth." Wow, how true that is! Ever tried to not look at your emails or answer phone calls when you're out and about with your family or taking some time to yourself? Especially when you're ...

    Continue Reading...
  • 16 Sep 2010

    Article 2, Section 1: Employees shall not be allowed to defend themselves

    Here's an interesting scenario of company policy versus state law. Regardless of the interpretation and how it turns out, way to go Iron Mountain for making it known your employees are unarmed!In the same spirit of those "zero tolerance" school zones that tell the bad guys that there's no one there to defend themselves, this kind of stuff is absolutely mindless....

    Continue Reading...
  • 15 Sep 2010

    New content on data protection & compliance

    Here's the full download of the CSO Executive series I wrote recently for Realtimepublishers.com on data protection and compliance in the enterprise:The series consists of the following: Article 1:Primary Concerns of Regulatory Compliance and Data Classification Article 2:Finding, Classifying and Assessing Data in the Enterprise Article 3:Data Protection Reporting and Follow UpEnjoy!...

    Continue Reading...
  • 15 Sep 2010

    Hacking Methodology chapter available for download

    Chapter 4 of the latest edition of my book Hacking For Dummies is now available for download on TechTarget's SearchWindowsServer.com.If you like what you see, here's a direct link to the book on Amazon where you can save 34% off the cover price: Happy ethical hacking!...

    Continue Reading...
  • 14 Sep 2010

    Preventing email denial of service when scanning Web apps

    Here's a new piece I've written that outlines one of those pesky Web scanning problems most of us have been affected by in some way or another:Ways to avoid email floods when running Web vulnerability scansHope this helps!...

    Continue Reading...
  • 12 Sep 2010

    You cannot secure what you don’t acknowledge

    Here's a piece I wrote for SearchSMBStorage.com on storage security...specifically some must-have tools for finding storage-related security flaws in small business.Five must-have data storage security tools for smaller businessesIf you don't know what's where it'll be impossible to keep it secure....

    Continue Reading...
  • 08 Sep 2010

    Security’s not just an executive decision

    I recently came across this quote by Peter Drucker that struck a chord:"Most discussions of decision making assume that only senior executives make decisions or that only senior executives' decisions matter. This is a dangerous mistake."It reminds of how certain executives decide that information security is something that doesn't affect their business regardless of what others are telling them. I'm sure many of these executives' subordinates are ready and willing ...

    Continue Reading...
  • 08 Sep 2010

    What’s Better for Your Information Security Career – Certifications, a Degree, or Good Old-Fashioned Experience?

    Here's a piece I wrote on information security careers and what's best for getting ahead:What’s Better for Your Information Security Career – Certifications, a Degree, or Good Old-Fashioned Experience?If you want to learn more on the go, I also have a Security On Wheels audio program on this topic that picks up where my article leaves off:Certifications, Degrees, or Experience - What's Best for Your Security Career?...

    Continue Reading...
  • 08 Sep 2010

    Good rule of thumb for information security

    Thomas Jefferson once said:"Learn to see in another's calamity the ills that you should avoid." If you want to manage information risks and keep your business out of hot water I can't think of a better principle to work by....

    Continue Reading...