Well, Spring Break is over (boohoo) and I'm back in full swing. My mind had a chance to clear while I was out and I thought of some new blog ideas that I'll be posting soon. Plus I have some content that was recently published that I'll be linking to. Also, I'm now writing for SearchCompliance.com (a great resource for us given how compliance is driving a lot of what ...
Continue Reading...This just in (OK, it's really from a couple of days ago): Cybersecurity hearing highlights inadequacy of PCI DSS.But I thought compliance = security!? And anything forced down our throats at the hand of industry bodies and government goons is all we need to manage business risks!? Seriously...how long do you think we'll continue to hear about this...ay yay yay?...
Continue Reading...I've recently covered two of my favorite, yet lesser-known, Web vulnerability scanners: Acunetix Web Vulnerability Scanner and N-Stalker Web Application Security Scanner. Two worthy products indeed. Now I'd like to shed some light on HP's WebInspect. I've been using WebInspect since before testing Web sites/apps was cool. In fact, WebInspect was one the original commercial Web scanners. It may have even been the first. Anyway, I started a relationship with ...
Continue Reading...I use GoToMyPC for remote access occasionally and came across a situation you may want to know about....Before I left the office last night I made sure my Windows screen was locked. My locking screensaver kicks in after a few minutes but I just wanted to make sure. While at home I accessed my laptop a few times logging on and off of GoToMyPC. When I returned to the office ...
Continue Reading...This just in: from the government agency that brought us HIPAA we now have a new site to help us all deal with the troubling economy. Maybe one day the site can be expanded to include those of us who are affected - both personally and professionally - by security breaches. At least there's hope....and when there's hope, there will be "change". ;)Funny how government creates a crisis and then ...
Continue Reading...Here's an interesting bit about something our legal system is going to have to try to get its arms around. In essence it's jurors using mobile phones to access the Internet to learn more about the trials they're currently serving on. Wow - talk about unintended consequences.I suspect that one of these days, in a few more years once Big Brother has really established himself, we'll have some really advanced ...
Continue Reading...I saw this bit and wondered to myself: how long will we be talking about the basics of security and the ramifications when they're ignored? 10, 20 years more maybe?...
Continue Reading...I had the privilege and pleasure of having lunch with security maven - and policy king - Charles Cresson Wood last week while he was in town speaking at a show. Here's a good read I just came across on some more of his thoughts regarding what many think of as a drab subject that doesn't really matter in the grand scheme of things. It'll get you thinking...Maybe time for ...
Continue Reading...Here's something for you to ponder when it comes to thinking about the world economy, your career, your job:"When written in Chinese, the word 'crisis' is composed of two characters - one represents danger and the other represents opportunity." - John F. Kennedy...
Continue Reading...The South Carolina chapter of ISACA brought me in for a seminar yesterday that was chock full of fun. My main contact with the chapter, Sue Rusher, was a real gem to work with. She and her team made me feel right at home and they hosted the event at a great facility.I'm seeing more and more businesses and organizations like ISACA do seminars like this. The content comes to ...
Continue Reading...