d.strom, cissp, gsec, gsna on July 30th, 2009

Security vendor McAfee spills 1,400 customer names – Network World “Dripping with irony” is how Network World magazine describes this situation. The lesson for the small business is that regardless of how advanced, or secure, your organization is, there needs to be constant vigilance. You don’t want to be the next company that has a [...]

Continue reading about Security vendor McAfee spills 1,400 customer names – Network World

d.strom, cissp, gsec, gsna on July 20th, 2009

UPDATE: I am not yet satisfied with the wording of the survey, and thus it will not be available when I had originally planned. Watch for the announcement of the survey to be coming soon on various mailing lists. If you want a personal reminder when it is available, leave me a note in the [...]

Continue reading about Religion/Faith and Information Security

d.strom, cissp, gsec, gsna on June 17th, 2009

The final commonly held element of good Defense in Depth is Operations. I say “commonly held” because various authors make additions to the list of People, Technology and Operations. For a functioning description, consider Operations to be the tasks required to maintain a desired level of security. It is easy to get bogged down thinking [...]

Continue reading about The Operations Element

d.strom, cissp, gsec, gsna on June 10th, 2009

Any Defense In Depth strategy requires a technology component. Yes, we’ve already seen that people play an important role, but technology is used where consistency and repeatability are needed. You could have someone assigned to capture and analyze every packet that is aimed toward your your network, but they wouldn’t be able to do this [...]

Continue reading about The Technology Element

d.strom, cissp, gsec, gsna on June 5th, 2009

Sorry to bring this up, but your computer is not perfect. Neither were the programmers who wrote the programs. Neither were the dude’s who designed the hardware. And of course the user is not perfect! Patches and Updates are used to correct programming errors and fix vulnerabilities in the software. It is difficult to keep [...]

Continue reading about InfoSec Tip: Patch Your Programs and OS