Archive for 'Risky Business'

ISO 27001 and Governance Requirements

ISO 27001 and Governance Requirements

Can’t protect what you don’t know about.

Had an interesting conversation this week with the CISO of a large bank. They were interested in moving towards ISO-27001 certification and we were talking about the challenges of conducting a “meaningful” risk assessment in such a large and distributed organization.

27001-bank

As we were talking about the merits of information and process centric risk assessment using ...

Continue Reading →

The (Not) NIST Great Guidance on Smart Grid Assessments

The (Not) NIST Great Guidance on Smart Grid Assessments

Not that long ago I bemoaned the fact that there was too much guidance on Smart Grid Security.

So it may seem odd that I’m about to profess admiration for some new guidance, namely the Smart Grid Interoperability Panel (SGIP) “Guide for Assessing the High-Level Security Requirements in NISTIR 7628, Guidelines for Smart Grid Cyber Security”.

The original three volumes of 7628 cover almost 700 pages and were one of the main ...

Continue Reading →

Tackling Smart Grid Security – Back to Basics

Tackling Smart Grid Security – Back to Basics

energy-information-securitySmart Grid promises to radically change the face of energy technology today; however, along the way, it creates threat vectors that can leave utility companies vulnerable to a whole new realm of attacks. Besides these new threats, utility companies are also affected by the uncertain economic times, thus investments are receiving more scrutiny from local PUCs (Public Utility Commissions), as it becomes increasingly difficult to recover ...

Continue Reading →

What About Your Third-Party Vendor’s Third-Party Vendors?

technology-information-securityRecently we were conducting an outsourced internal audit, looking at the risk associated with a third-party on behalf of our client. (Their vendor risk management program requires due diligence in the use of a third-party to process “sensitive” data on their behalf). On review, we found that the third-party data analytics/SaaS vendor we were assessing likewise outsourced a significant part of its IT operations ...

Continue Reading →

Personal Passwords Endanger Corporate Security

Personal Passwords Endanger Corporate Security

Writing this blog with egg on my face, tail between my legs, or whatever your favorite expression is for highly chagrined. The Zappos breach made me do a formal evaluation of my personal password practices … which sadly to say are not consistent with what I preach as an information security practitioner. Worse – my “personal password policy” had put my employer at risk.

password-policyContinue Reading →

Page 1 of 16 12345...»