• 13 Apr 2009

    I’m back…

    Well, Spring Break is over (boohoo) and I'm back in full swing. My mind had a chance to clear while I was out and I thought of some new blog ideas that I'll be posting soon. Plus I have some content that was recently published that I'll be linking to. Also, I'm now writing for SearchCompliance.com (a great resource for us given how compliance is driving a lot of what ...

    Continue Reading...
  • 03 Apr 2009

    Restating the obvious?

    This just in (OK, it's really from a couple of days ago): Cybersecurity hearing highlights inadequacy of PCI DSS.But I thought compliance = security!? And anything forced down our throats at the hand of industry bodies and government goons is all we need to manage business risks!? Seriously...how long do you think we'll continue to hear about this...ay yay yay?...

    Continue Reading...
  • 01 Apr 2009

    WebInspect – the Mac Daddy Web app scanner?

    I've recently covered two of my favorite, yet lesser-known, Web vulnerability scanners: Acunetix Web Vulnerability Scanner and N-Stalker Web Application Security Scanner. Two worthy products indeed. Now I'd like to shed some light on HP's WebInspect. I've been using WebInspect since before testing Web sites/apps was cool. In fact, WebInspect was one the original commercial Web scanners. It may have even been the first. Anyway, I started a relationship with ...

    Continue Reading...
  • 31 Mar 2009

    Goofy “feature” in GoToMyPC that can put you at risk

    I use GoToMyPC for remote access occasionally and came across a situation you may want to know about....Before I left the office last night I made sure my Windows screen was locked. My locking screensaver kicks in after a few minutes but I just wanted to make sure. While at home I accessed my laptop a few times logging on and off of GoToMyPC. When I returned to the office ...

    Continue Reading...
  • 31 Mar 2009

    Coping site for security breaches?

    This just in: from the government agency that brought us HIPAA we now have a new site to help us all deal with the troubling economy. Maybe one day the site can be expanded to include those of us who are affected - both personally and professionally - by security breaches. At least there's hope....and when there's hope, there will be "change". ;)Funny how government creates a crisis and then ...

    Continue Reading...
  • 27 Mar 2009

    Interesting new technology dilemma arising

    Here's an interesting bit about something our legal system is going to have to try to get its arms around. In essence it's jurors using mobile phones to access the Internet to learn more about the trials they're currently serving on. Wow - talk about unintended consequences.I suspect that one of these days, in a few more years once Big Brother has really established himself, we'll have some really advanced ...

    Continue Reading...
  • 26 Mar 2009

    How long will we be talking about this?

    I saw this bit and wondered to myself: how long will we be talking about the basics of security and the ramifications when they're ignored? 10, 20 years more maybe?...

    Continue Reading...
  • 26 Mar 2009

    So, policies are important?

    I had the privilege and pleasure of having lunch with security maven - and policy king - Charles Cresson Wood last week while he was in town speaking at a show. Here's a good read I just came across on some more of his thoughts regarding what many think of as a drab subject that doesn't really matter in the grand scheme of things. It'll get you thinking...Maybe time for ...

    Continue Reading...
  • 25 Mar 2009

    Great quote for these times…

    Here's something for you to ponder when it comes to thinking about the world economy, your career, your job:"When written in Chinese, the word 'crisis' is composed of two characters - one represents danger and the other represents opportunity." - John F. Kennedy...

    Continue Reading...
  • 20 Mar 2009

    Had a great time with ISACA yesterday

    The South Carolina chapter of ISACA brought me in for a seminar yesterday that was chock full of fun. My main contact with the chapter, Sue Rusher, was a real gem to work with. She and her team made me feel right at home and they hosted the event at a great facility.I'm seeing more and more businesses and organizations like ISACA do seminars like this. The content comes to ...

    Continue Reading...