Archive for 'Risky Business'

How To Save $1M With A Penetration Test

How To Save $1M With A Penetration Test

ethical hackingSeveral years ago we “formalized” our penetration testing approach into several distinct levels that correlated with the level of assurance the client was seeking and/or the risk associated with the particular network infrastructure under assessment. In that effort we also “formalized” the “less technical” aspects of the Reconnaissance phase of our testing and began referring to this portion of ...

Continue Reading →

The Illusion of Information Security

The Illusion of Information Security

isms illusionI love George Bernard Shaw’s quotation “The single biggest problem with communication is the illusion that it has taken place.” As imitation is the most sincere form of flattery; The single biggest problem with Information Security is the illusion that it has taken place.

There are two main ways that Information Security can be illusory;

  • Leveraging a “point-in-time” security (the PITS) model
  • Improperly implementing a “continuous” security ...
Continue Reading →

Indian Government To Mandate ISO 27001

Indian Government To Mandate ISO 27001

I’m surprised this piece of legislation has not gotten more press.

india iso 27001In February, the Ministry of Communications and Information Technology (MCIT) released the draft notification proposed to be released in respect of Section 43A of ITA 2008.

Under Sec 43A the ITA (Information Technology Act) defines what “Sensitive Personal Information” is and the “Reasonable Security Practice” that a company should follow to protect it.

The current phrasing of ...

Continue Reading →

Information Security Assessment: Comprehensive and Holistic

Information Security Assessment: Comprehensive and Holistic

Comprehensive vs. Holistic:

Not the same

locked folderA comprehensive approach to an information security assessment sounds like a good thing, correct? After all, comprehensive means “ Complete; including all or nearly all elements or aspects of something”. Having uniquely focused on conducting information security assessments for the last ten years – I have often tried to effectively communicate the difference. A recent electrical utilities project we worked on perfectly illustrates ...

Continue Reading →

eDiscovery Information Security Trends

eDiscovery Information Security Trends

word is flat

The good (& now rich!) folks at Clearwell published an interesting eDiscovery “trends” article last fall.

There were two interesting observations made;

  • eDiscovery is rapidly maturing into a global issue. “ As more countries adopt eDiscovery methodologies quicker than expected, they will be looking to the US for guidance and direction. With eDiscovery becoming more global, the legalities of data ...
Continue Reading →
Page 5 of 18 «...34567...»