I'm live at the RSA Conference and here are my thoughts on the first two keynotes along with why you need to come to this show.
Tuesday, 28 February 2012
Monday, 27 February 2012
Live from #RSAC: Cloud computing's got some kinks (but you knew that)
Posted on 10:36 by Unknown
I'm attending the RSA Conference this week and just sat through a panel discussion on cross-jurisdictional issues in the cloud. It was part of the Cloud Security Alliance Summit 2012.
Here's what I heard: there are tons of considerations around the management, access and even the e-discovery personal data in the cloud...lots of variables and just as many things still up in the air. I'm convinced that being an information privacy and security savvy attorney is a solid - and likely most lucrative - career paths that IT professionals could take right now.
One of the audience members (apparently a founder of the Unified Compliance Framework) asked the panel why we needed yet another group (the Cloud Security Alliance) establishing yet another set of information security standards when 99.99% of everything that's being touted today is already part of some other regulation, standard or framework. I completely agree and didn't hear any compelling explanations...Everyone wants their piece of the pie I suppose.
Here's what I heard: there are tons of considerations around the management, access and even the e-discovery personal data in the cloud...lots of variables and just as many things still up in the air. I'm convinced that being an information privacy and security savvy attorney is a solid - and likely most lucrative - career paths that IT professionals could take right now.
One of the audience members (apparently a founder of the Unified Compliance Framework) asked the panel why we needed yet another group (the Cloud Security Alliance) establishing yet another set of information security standards when 99.99% of everything that's being touted today is already part of some other regulation, standard or framework. I completely agree and didn't hear any compelling explanations...Everyone wants their piece of the pie I suppose.
Video: Seeing the big picture in information security
Posted on 07:13 by Unknown
Little has been written about this in the context of information security but it's something you've go to consider in every decision you make:
Friday, 24 February 2012
CDW-TechTarget seminars are back this year - join me in Atlanta soon
Posted on 03:09 by Unknown
Great news - I'll be speaking at the CDW-TechTarget roadshows again this year! Our first show kicks off in Atlanta on March 13th and then we start zig-zagging across the country every few weeks until late September.
For most of the shows I'll be giving two presentations:
There will also be vendor expert sessions and a panel discussion at the end of the morning that I'll be moderating. You'll be out of there by lunchtime.
At a couple of the shows, we'll have two tracks running simultaneously so the day will be a bit longer (lunch included) and I'll be presenting an additional session titled Building Security (and Confidence) in the Cloud.
I hope you'll be able to join me. We got a lot of great feedback on these events last year and I know this year will be even better.
Check out the locations, dates and registration form here. There's no charge to attend if you're selected. See you in Atlanta in two and a half weeks!
For most of the shows I'll be giving two presentations:
Adapting Your Old-School Network Security Agenda to Today's New-School Security Challenges
...and:
Ensuring Security Controls in an Anytime, Anywhere Access Environment
There will also be vendor expert sessions and a panel discussion at the end of the morning that I'll be moderating. You'll be out of there by lunchtime.
At a couple of the shows, we'll have two tracks running simultaneously so the day will be a bit longer (lunch included) and I'll be presenting an additional session titled Building Security (and Confidence) in the Cloud.
I hope you'll be able to join me. We got a lot of great feedback on these events last year and I know this year will be even better.
Check out the locations, dates and registration form here. There's no charge to attend if you're selected. See you in Atlanta in two and a half weeks!
Sunday, 19 February 2012
Got compliance on your mind?
Posted on 13:53 by Unknown
I figured you did...it seems everyone does these days. However you look at compliance - be it a threat, a security enabler or just a pain in the rear-end - here are some new pieces I've written that may help:
Our dangerous overdependence on IT auditing
Compliance considerations when disposing old equipment
How Windows Server 8 can help with compliance
Enjoy!
Be sure to check out www.principlelogic.com/resources.html for links to all of my information security whitepapers, podcasts, webcasts, books and more.
Our dangerous overdependence on IT auditing
Compliance considerations when disposing old equipment
How Windows Server 8 can help with compliance
Enjoy!
Be sure to check out www.principlelogic.com/resources.html for links to all of my information security whitepapers, podcasts, webcasts, books and more.
Monday, 13 February 2012
Is it really possible to get users on board with security?
Posted on 17:02 by Unknown
I think so. Here's how.
I don't think that user awareness and training is THE answer to information security like many others believe. I do know that you shouldn't let another year pass without getting your users on board with what you're doing.
I don't think that user awareness and training is THE answer to information security like many others believe. I do know that you shouldn't let another year pass without getting your users on board with what you're doing.
Sunday, 12 February 2012
SQL injection cheatsheet & tips for getting management on board
Posted on 16:41 by Unknown
Here's a neat "cheatsheet" on SQL injection by NTObjectives that outlines some common attack strings, commands and so forth. Their SQL Invader SQL injection tool is worth checking out as well.
If you're having trouble selling management on the dangers of SQL injection, check out this piece I wrote about it not long ago:
SQL Injection – The Web Flaw That Keeps on Giving
Ten Ways to Sell Security to Management
Happy hacking!
If you're having trouble selling management on the dangers of SQL injection, check out this piece I wrote about it not long ago:
SQL Injection – The Web Flaw That Keeps on Giving
Ten Ways to Sell Security to Management
Happy hacking!
Subscribe to:
Posts (Atom)