Trust is Not Really a Control, Neither is Luck

August 9, 2009 by ADMIN · Leave a Comment

By Gene Kim, CTO of Tripwire and co-founder of the IT Process Institute

This risk is often hidden in plain sight, poses a genuine clear and present danger to the business and information security objectives, and one that is often overlooked. This issue is change control.

Audits and the Change Management Process

June 29, 2009 by ADMIN · Leave a Comment

By Gene Kim, CTO of Tripwire and co-founder of the IT Process Institute

If the auditor observes that no one is showing up to the change management meetings, authorizations are rubber stamped without any real evaluation, unauthorized changes and unplanned outages are occurring regularly, then she will likely flag this as a potential high risk area.

(Never) Always Set Up QA Before Production

June 23, 2009 by ADMIN · Leave a Comment

By Gene Kim, CTO of Tripwire and co-founder of the IT Process Institute

And then the code is then deployed into production, which then fails spectacularly. Now the problem isn’t that the QA schedule is slipping. Now the problem is that a potentially mission-critical service is down, and we have a potential Sev 1 outage, requiring the best Ops, QA and Development people to figure out how to restore service.