Not long ago I had a conversation with a colleague of mine who's also a consultant. We were discussing the topic of how, even with today's shaky economy, people still goof off on the job as if they had nothing to lose.
Are you seeing this too?
I wrote about this phenomenon over three years ago. Funny how not much changes internally given all the external forces pressing down on us.
Not being willing to do whatever it takes to become - and remain - a valuable asset to your business is a sure-fire way to get axed when big decisions are being made. Trust me, I learned this lesson the hard way working for a previous employer before I went out on my own.
I recommend continually asking yourself: What's the most valuable use of my time? I often find the answer to be something else other than what I'm currently doing. We all struggle with this. We're only human. It's the people who learn and overcome that move to the head of the pack.
Wondering what helps minimize the pain, stress and time required to run effective Web vulnerability scans? It's the things you can see in the toolbar of HP's WebInspect:
Start/Resume, Pause - because you're going to need to pause and resume your scans at some point. Rescan - because you're going to want to re-run the scan again or re-test for the flaws uncovered previously. Compare - because you're going to have a need to compare results for remediation validation testing, etc. eventually.
If you do this work enough, these types of vulnerability scanner features can have tremendous payoffs over the long haul.
I'm finally back in the swing of things after taking some time off for Spring Break. I hope you're enjoying your Spring as well.
Here are two articles I've recently written about full disk encryption...arguably the greatest missing link in any given business's information security program.
As always, be sure to check out www.principlelogic.com/resources.html for links to all of my information security whitepapers, podcasts, webcasts, books and more.
Anyone is capable of doing anything...that's what comes to mind when I think about the JetBlue captain going mad on a flight yesterday. Here's what I know...Just because someone has passed a background check, has a good references and has created a good track record for himself doesn't mean he's not capable of flying off the hook and doing bad things. This applies to pilots as in this situation and it applies to your own users when it comes to information security.
Sadly, as with doctors, law enforcement officers and the like, we typically hold pilots on pedestals without question. These are the people we look up to assuming they're well put together and always doing good things. This is not always true. We have to trust, but verify...yet still, we never really know. I'm just glad the JetBlue co-pilot and passengers executed a worthy backup plan. Great reminder we always need a Plan B...especially today if you work in JetBlue's PR department.