People

d.strom, cissp, gsec, gsna on January 8th, 2010

I received a call this week from a friend who works in a small office. She had been out for a few days, and when she returned it became obvious that someone had been rummaging through the stuff on her desk. Then, she started telling me that when she turned her computer on there was [...]

Continue reading about Common Sense and Physical Security

d.strom, cissp, gsec, gsna on May 19th, 2009

People play a vital role in your Defense In Depth strategy. Technology, by itself, cannot provide information assurance. Likewise, great operational procedures cannot assure confidentiality, integrity and availability. Time and effort must be invested in people. I used to think that good technology and procedures could overcome almost any problem. That was before a co-worker [...]

Continue reading about The People Element

d.strom, cissp, gsec, gsna on April 16th, 2009

Can a small or medium sized business do Defense in Depth? How about the home user? The phrase “defense in depth” is tossed around in the Information Security field as if everyone knows what is being talked about. Just what is Defense in Depth? The National Security Agency has put out a short paper which [...]

Continue reading about Defense in Depth