Archive for the ‘Information Security’ Category

DHS Secretary Chertoff Calls For Better Computer Security

Wednesday, October 22nd, 2008

It is good to start seeing more urgency place upon information security by the various government agencies.
As an example, last week U.S. Homeland Security Secretary Michael Chertoff spoke at the U.S. Chamber of Commerce emphasized the need for increased cooperation between industry and government to secure the nation’s computer systems.
Here’s an excerpt from one of the news reports about the speech…

(more…)

Insider Threat Example: Obama’s Campaign Folks Make Email Mistake

Wednesday, October 15th, 2008

No matter how much technology you throw at trying to prevent security incidents, the weakest link in the organization, your personnel (who could be your strongest link with effective training and ongoing awareness) can defeat that security technology.
On purpose, because of lack of knowledge, or by making a plain ol’ mistake.
And EVERYONE makes mistakes. Fewer if they are more diligently aware though.

(more…)

Commerce Department Issues New Rule For Encryption Exports

Tuesday, October 14th, 2008

Remember all the talk in the 1990’s that surrounded the legalities, and largely restrictions, surrounding how encryption could be used for data sent outside the U.S.? Or how encryption tools and algorithms could be exported? It’s been a significantly more silent issue during this new century.

(more…)

More Need Than Ever For Information Security In A Bad Economy!

Thursday, October 9th, 2008

There is no doubt that this economy is impacting all companies and most individuals. I’ve read about and heard from many organizations that, as a result, their information security and privacy budgets are being drastically reduced, or even cut completely, in an attempt to save money during these uncertain times.
Throwing out the baby with the bath water in this way is a very bad idea!

(more…)

Palin Email Hacker Indicted

Wednesday, October 8th, 2008

Around September 10 a widely-reported story broke about how Sarah Palin’s Yahoo! email account was broken into.
Contents of some of her email messages were then widely posted to various Internet websites.

(more…)

PII Encryption Required by New Massachusetts and Nevada Laws

Monday, September 29th, 2008

There is a growing trend in laws that require personally identifiable information (PII) to be encrypted.
Encryption in past laws have been directed to be considered based upon risk, but now they are more explicitly required in some laws.

(more…)

Obtaining Support and Funding from Senior Management

Thursday, September 18th, 2008

Throughout the late spring and summer months I had the great opportunity to participate in an talented workgroup sponsored and led by the European Network and Information Security Agency (ENISA) to create a new, and quite valuable, resource for information security practitioners to help them obtain funding and sponsorship for the training and awareness programs.

(more…)

A $1 Billion Access Control Mistake

Monday, September 15th, 2008

It has been widely reported and blogged about how an old United Airlines story was posted with huge stock value loss…

(more…)

Miscellaneous Cybercrime & Privacy Tidbits

Friday, September 12th, 2008

For the last day of Global Security Week (GSW) I’m providing a few items that relate to cybercrime that I find interesting…

(more…)

GSW Logo

Wednesday, September 10th, 2008

I really like the logo for this year’s GSW, and I wanted to include it here for those of you who had not see it…

(more…)