d.strom, cissp, gsec, gsna on August 21st, 2009

Do yourself a favor. Go grab your wallet. I’ll wait for you to get back… . .. … Now, pull all your credit cards out. Grab your debit cards, also. Look at them closely. Can you identify where each one of them has been used? Have you ever used your debit card for on-line transactions? [...]

Continue reading about InfoSec Tip: 5 Ways to Protect Your Credit/Debit Card

d.strom, cissp, gsec, gsna on July 17th, 2009

Twitter hacked by old technique — again by AP: Yahoo! Tech This article came out yesterday. The short description is that a compromised personal email account led to a compromise at Twitter. Although the article is written with the focus on Twitter, this can just as easily happen to you and your organization. Tip: Keep [...]

Continue reading about InfoSec Tip: Keep Personal Separate From Work

d.strom, cissp, gsec, gsna on June 29th, 2009

You can learn alot by watching people. I had breakfast this morning and was stunned to overhear someone on their cell phone give the administrative login credentials for the company website to someone else. They also very carefully spelled out the entire URL to the login page. If I were not trustworthy, I could log [...]

Continue reading about No-effort Hacking

d.strom, cissp, gsec, gsna on June 17th, 2009

The final commonly held element of good Defense in Depth is Operations. I say “commonly held” because various authors make additions to the list of People, Technology and Operations. For a functioning description, consider Operations to be the tasks required to maintain a desired level of security. It is easy to get bogged down thinking [...]

Continue reading about The Operations Element

d.strom, cissp, gsec, gsna on June 10th, 2009

Any Defense In Depth strategy requires a technology component. Yes, we’ve already seen that people play an important role, but technology is used where consistency and repeatability are needed. You could have someone assigned to capture and analyze every packet that is aimed toward your your network, but they wouldn’t be able to do this [...]

Continue reading about The Technology Element