• 01 Jul 2008

    Getting the IT blues because of gas prices…watch this.

    So many of us here in the U.S. are being affected - both personally and professionally - but these outrageous gas prices we have....I'm seeing stories about IT job losses and IT budget cuts in the name of ridiculous fuel costs. This is especially true when you have ignorant and controlling managers who won't let you telecommute. Heck, I'm cutting back on the number of networking events and lunch meetings ...

    Continue Reading...
  • 30 Jun 2008

    My new Security On Wheels audio program is out

    I wanted to let you know that my new Security On Wheels mini audio program is now produced and ready to go. It's called Certifications, Degrees, or Experience - What's Best for Your Security Career? This audio program (which comes packaged in a 24 minute MP3 file) addresses what you need to focus on in order to properly educate yourself and stay sharp so you can work more effectively, earn ...

    Continue Reading...
  • 27 Jun 2008

    What does “qualified third party” mean in PCI 6.6?

    There's been a lot of hoopla surrounding the PCI DSS requirement 6.6 compliance next week. Even with all the noise, there is some good news for both covered entities and independent security professionals such as yours truly. In the PCI DSS requirement 6.6 Information Supplement document, the first sentence at the top of page 3 states "Manual reviews/assessments may be performed by a qualified internal resource or a qualified third ...

    Continue Reading...
  • 26 Jun 2008

    Does FACTA really exist? Send up a Red Flag!

    I spoke recently for a group of technically-savvy accountants. Out of the 120 or so people in the audience, 2 raised their hands when I asked if anyone was aware of the impending FACTA requirements for identity theft protection measures for financial institutions. Two people folks! OUCH.Sign of the times in information security I suppose......

    Continue Reading...
  • 26 Jun 2008

    Good management yet bad results? No way!

    I was watching my favorite TV channel yesterday (SPEED) and heard well-known racer Tommy Kendall say something that struck a cord. He was actually quoting Carlos Ghosn, head of Renault, who said:"There's no such thing as good management with bad results."I immediately thought, hey, this ties into what I do for a living.Many, many people believe they have information security under control yet time and time again they come up ...

    Continue Reading...
  • 25 Jun 2008

    Ignorance is bliss when it comes to patching database servers

    I just saw this bit today on SearchSecurity.com about admins not patching database servers. So, it's not just me that sees ignorance in action when it comes to admins not wanting to patch their database servers. I can't tell you how many times I've found database flaws directly-exploitable from the inside all because an admin didn't want to patch the system. I'm talking about full command prompt access to database ...

    Continue Reading...
  • 24 Jun 2008

    Good security resource worthing checking out

    If you haven't been over to NIST's National Vulnerability Database site lately, it's worth checking out. There's tons of good info on system hardening, vulnerability research, and more. If you're here in the U.S., you helped fund it so you might as well use it, right?...

    Continue Reading...
  • 23 Jun 2008

    You don’t say…A new Mac Trojan?

    They haven't had one in a while....so it's about time again.New Mac Trojan Disables Security, Steals Passwords...

    Continue Reading...
  • 23 Jun 2008

    My security content from last week

    I was out the latter part of last week so I missed my 'deadline'. Here's an article hot off the press that you may be interested in:The realities of using WAFs for PCI DSS 6.6 complianceEnjoy!As always, check out www.principlelogic.com/resources.html for all of my past articles, webcasts, podcasts, and more.Publish Post...

    Continue Reading...
  • 17 Jun 2008

    One more thing Representative Wolf…

    In regards to my post yesterday about your calling out for better computer security at the Federal level, you may want to consider hardening your systems with the OMB Federal Desktop Core Configuration Checklists found at the following link:http://nvd.nist.gov/ncp.cfm?fdcc_chklstUs taxpayers have funded this and other great security documents for people just like you....

    Continue Reading...