Syndicated Blog

[su_panel border="1px solid #ddd" radius="3" text_align="center"]
Skeeter Spray
[/su_panel]

Getting Security Buy-in from Everybody

|
Buy-in of Information Security projects / initiatives / “we should just be doing it” is a tricky thing.   While support from senior leaders in the organization is key for resources (i.e. $$$$) ...

Getting Security Buy-in from Everybody

|
Buy-in of Information Security projects / initiatives / “we should just be doing it” is a tricky thing.   While support from senior leaders in the organization is key for resources (i.e. $$$$) ...

What Should Information Security Be Responsible For?

|
In the Enterprise environment it seems there is always a battle around who should be responsible for what in IT.  And there is always some manager or director that complains (or his ...

What Should Information Security Be Responsible For?

|
In the Enterprise environment it seems there is always a battle around who should be responsible for what in IT.  And there is always some manager or director that complains (or his ...

Is the problem local admin or change?

|
Welcome back. "...back after {an} exclusive three year tour of Europe, Scandinavia and the sub continent" (Cab Calloway in the Blues Brothers). Ok, not really, I never left the city for more ...

Is the problem local admin or change?

|
Welcome back. "...back after {an} exclusive three year tour of Europe, Scandinavia and the sub continent" (Cab Calloway in the Blues Brothers). Ok, not really, I never left the city for more ...

Threat Modeling and Security Assessments

|
Over the last several months, in creating a threat evaluation model / process and performing a security evaluation, I have come to several conclusions. In creating a threat model, you must create ...

Threat Modeling and Security Assessments

|
Over the last several months, in creating a threat evaluation model / process and performing a security evaluation, I have come to several conclusions.In creating a threat model, you must create a ...

Creating an Action Plan from a Security Review

|
After all the work of performing a security review of an organization, it is time to create an action plan.   This plan must be something the client can use, so it must ...

Threat & Vulnerability Mitigation – Asset Identification

|
No matter what you all your program (I call mine Vulnerability Management) to manage threats and vulnerabilities as they apply to your network and processing environment you must know what you have ...