• 02 Oct 2008

    The gaping hole that most organizations have

    Certain organizations have an incident response plan...And many people in management know that one needs to be in place. Of those that do have a plan, I have YET to see one that has a public relations component. You know those pesky news ferrets that will no doubt be calling, emailing, and worse shoving a microphone in your face when a breach occurs??Well, here's a good little piece on this ...

    Continue Reading...
  • 02 Oct 2008

    Yet another law protecting patient privacy

    I'm all for holding businesses and their employees accountable for their actions. But is this new law in California just another case of not enforcing existing laws?? I know this is a state law but what about HIPAA too?...

    Continue Reading...
  • 01 Oct 2008

    Cool site for tracking impending disasters

    During Hurricane Ike I came across a really neat site for tracking storms in the tropics and onto our soil here in the U.S. It's called Stormpulse. It has an awesome interface and lots of good information to help you plan and execute emergency procedures if your organization is going to be affected. Certainly a worthy tool in any DR/BC toolbox....

    Continue Reading...
  • 01 Oct 2008

    Wonder how much Cisco spent on this study…

    Alert, Alert! Cisco has finally found the cause of information security problems! Apparently *employees* are the culprit. So...humans are the root cause of all this stuff we live and breath every day after all. Oh and apparently we need to focus more on awareness...You think??I believe this was a case of some Cisco employees needing to do some busy work to justify their existence in the company. Amazing use of ...

    Continue Reading...
  • 30 Sep 2008

    Use wisely your power of choice

    In reference to my post from yesterday about the human desire for instant gratification and our government rewarding failure with this attempt at economic bailout I thought of another thing that has really helped me over the years. It's Og Mandino's short and sweet quote: "Use wisely your power choice."These five words - when taken to heart and followed closely - can help drive every decision you make towards a ...

    Continue Reading...
  • 30 Sep 2008

    Free CISSP training

    For those of you looking into obtaining the CISSP certification, here's a link to some free CISSP exam prep offered up by SearchSecurity.com and taught by Shon Harris - a well-known expert in this area. It's not all you'll need in preparing for the exam but it's a good start and the price is right....

    Continue Reading...
  • 30 Sep 2008

    Job sites focused on MCPs

    If you're a Microsoft Certified Professional, here's a list of job sites tailored for you...Also be sure to check this link for previous posts of mine about security-related job sites....

    Continue Reading...
  • 29 Sep 2008

    Fight the desire for instant gratification

    Here in Atlanta we have a pretty serious situation with gas. Some refineries in Louisiana and Texas (where Georgia gets approx. 85% of its fuel) are still out of commission from Hurricane Ike. There are numerous other issues contributing to the problem as well including the Federal Clean-Air Act requiring gasoline sold in our local market to meet stringent EPA enforced air quality standards which makes it more difficult for ...

    Continue Reading...
  • 29 Sep 2008

    ISC2’s new CSSLP to the rescue?

    Well, ISC2 is at it again with yet another security certification - this time focused on application security. The CSSLP (Certified Secure Software Lifecycle Professional) focuses on security where it's often the weakest...at the source code level.Not a bad idea in general. I just don't foresee someone getting such a certification and then suddenly being a development expert much less someone being able to lock down the software lifecycle. These ...

    Continue Reading...
  • 26 Sep 2008

    My latest security content

    Here's an article I just wrote for SearchEnterpriseDesktop.com:The 10 most common Windows security vulnerabilities And also a series of articles I recently completed for Realtimepublishers.com on compliance:The Essentials Series: The Business Imperatives of Compliance in the UK [note: These articles have a U.K. focus but the concepts can be applied anywhere around the world...And no, those aren't my British-isms in the writing (thanks to the wonder of editing). It is ...

    Continue Reading...