Archive for 'Thoughts'

The (Not) NIST Great Guidance on Smart Grid Assessments

The (Not) NIST Great Guidance on Smart Grid Assessments

Not that long ago I bemoaned the fact that there was too much guidance on Smart Grid Security.

So it may seem odd that I’m about to profess admiration for some new guidance, namely the Smart Grid Interoperability Panel (SGIP) “Guide for Assessing the High-Level Security Requirements in NISTIR 7628, Guidelines for Smart Grid Cyber Security”.

The original three volumes of 7628 cover almost 700 pages and were one of the main ...

Continue Reading →

Tackling Smart Grid Security – Back to Basics

Tackling Smart Grid Security – Back to Basics

energy-information-securitySmart Grid promises to radically change the face of energy technology today; however, along the way, it creates threat vectors that can leave utility companies vulnerable to a whole new realm of attacks. Besides these new threats, utility companies are also affected by the uncertain economic times, thus investments are receiving more scrutiny from local PUCs (Public Utility Commissions), as it becomes increasingly difficult to recover ...

Continue Reading →

What About Your Third-Party Vendor’s Third-Party Vendors?

technology-information-securityRecently we were conducting an outsourced internal audit, looking at the risk associated with a third-party on behalf of our client. (Their vendor risk management program requires due diligence in the use of a third-party to process “sensitive” data on their behalf). On review, we found that the third-party data analytics/SaaS vendor we were assessing likewise outsourced a significant part of its IT operations ...

Continue Reading →

Personal Passwords Endanger Corporate Security

Personal Passwords Endanger Corporate Security

Writing this blog with egg on my face, tail between my legs, or whatever your favorite expression is for highly chagrined. The Zappos breach made me do a formal evaluation of my personal password practices … which sadly to say are not consistent with what I preach as an information security practitioner. Worse – my “personal password policy” had put my employer at risk.

password-policyContinue Reading →

Why ISO-27001 Certifying A Private Cloud Makes Sense

Why ISO-27001 Certifying A Private Cloud Makes Sense

One of our clients is a large New Jersey County which embarked on a shared services initiative several years ago at the direction of the County Freeholders to attempt to curb spiraling property taxes. In addition to centralizing services like snow removal, health services, and senior programs – the initiative included a number of implicit/explicit shared services with notable information technology/security ramifications including; shared IT Services, web hosting, law enforcement data sharing, and medical insurance ...

Continue Reading →
Page 1 of 8 12345...»