Syndicated Blog

[su_panel border="1px solid #ddd" radius="3" text_align="center"]
Defense Rests
Information Security without tears or apology.
[/su_panel]

Unethical Security Professional is a contradiction in terms

| | HBGary, professionalism
This is a post I never thought I would write. That I never thought I would have to write. Let me start with a quote from the CISSP Code of EthicsCode of ...

Unethical Security Professional is a contradiction in terms

| | HBGary, professionalism
This is a post I never thought I would write. That I never thought I would have to write. Let me start with a quote from the CISSP Code of EthicsCode of ...

Something different: An information security parable

|
Usually, when we write about risk management, we talk about money. Lots of risk has to do with money, so that makes sense. But there's something lost, as well. This occurred to ...

Something different: An information security parable

|
Usually, when we write about risk management, we talk about money. Lots of risk has to do with money, so that makes sense. But there's something lost, as well. This occurred to ...

PCI III: Addressing the Criticisms of the PCI DSS – Scope of Protection

In Part II of my PCI series, I listed the criticisms of the PCI DSS I’ve heard to date and asked for readers to add to the list. Nothing’s been added to ...

Governance Part 4: Standards

We’ve covered how management uses policies to govern an undertaking, whether that’s a business, a household, or one’s career. Today we’ll continue the Governance series with a look at standards and how ...

PCI II: Criticisms of the PCI DSS

|
Having given a very brief explanation of the PCI DSS standard and how the credit card industry manages it’s risk by requiring merchants who want to use credit cards adhere to it, ...

Compliance: PCI in a very small nutshell

DisclosureI am certified as a Payment Card Industry (PCI) Qualified Security Assesor (QSA). I am frequently paid to perform PCI audits, to advise people on how to fill out their Self Assessment ...

Managing Risk Through Acceptance and Assignment

Last week, we looked at risk mitigation. If you do something to reduce your vulnerability to a threat, or the impact of that threat, the risk goes down. Your personal firewall, your ...

Risk Management: Risk Mitigation

Last week, I started talking about risk management by talking about how it relates to something as mundane as forgetting your car keys. I’m going to stick with that analogy as we ...