Advantages of Data-Focused Risk Assessments

February 2, 2010 by ADMIN · Leave a Comment

By Danny Lieberman, Security Expert and Founder of Software Associates

The detailed reasons why people fail at DLP implementations merits a separate post – but it’s a lot like why over 50% of the content management implementation from vendors never made it to production in the 90s – the root cause was that there was no real business case for the technology. Unlike business processes – data risk cannot be outsourced.

DLP is Short for Disturbing Lack of Process?

November 12, 2009 by ADMIN · 1 Comment

By Danny Lieberman, Security Expert and Founder of Software Associates

The question is not lack of process but whether or not security is being used to help enforce business process in the relevant areas of product safety, customer service, employee workplace security and information protection in business-to-business relationships.

The Truth About Regulatory Compliance

October 19, 2009 by ADMIN · Leave a Comment

By Steven Fox, Founder of SecureLexicon

Given the business impact of regulations like PCI DSS, Sarbanes Oxley, and GLBA, this is understandable. While savvy business leaders understand the limitations of these guidelines, there are among us less enlightened individuals who view these as a cure for organizational security issues.

Black Hat: Articulating the Value of Security

October 12, 2009 by ADMIN · Leave a Comment

By Steven Fox, Founder of SecureLexicon

How do we market security? The cyber-bullies among us might still use Fear, Uncertainty, and Doubt. While this may produce short term acquiescence, that approach ultimately alienates us from the decision makers. Ultimately, security professionals must identify what is valuable to the business and then associate the need for security with those assets

Geithner Appointment Clears Landscape

February 10, 2009 by ADMIN · 1 Comment

By Kevin M. Nixon, Information-Security-Resources.com Security Editor

Despite the enactment of the USA PATRIOT ACT, which was to strengthen the Banking Secrecy Act and both of which were supposed to follow the Federal Information Security Management Act (FISMA), when all that helicopter dust finally settled, an audit showed that all of the puzzle pieces had been placed on the table, but none of the old guard had done anything to actually make the security really work.

Reality to Palin: Anybody In There?

November 22, 2008 by ADMIN · Leave a Comment

Feature By Kevin M Nixon, MSA, CISSP, CISM, ♦ ISR Master Security Editor

“Now, think about the current state of the global economy. If publicly-traded Corporations use these services and do not disclose the risk in their Sarbanes-Oxley (SOX) disclosures to the Securities and Exchange Commission (SEC) they are committing a Crime and deserve the fines and deserve to serve the time in prison as stipulated by law. We hear calls for stiffer regulations, oversight and transparency, but; do we really know how much of our private information is “out walkin’ around” already?”

Wait - The Palin Story Gets Worse…

November 22, 2008 by ADMIN · Leave a Comment

Feature By Kevin M Nixon, MSA, CISSP, CISM, ♦ ISR Master Security Editor

“Once the Governor began transmitting information in an unprotected manner via her personal web-based email account, which was outside the State of Alaska’s highly secure and well protected network, there was no way to guarantee the safety and integrity of those date floating in cyber-space. In other words, there was no way for the Governor or other state employees to know if the information which was being transmitted was being intercepted and read by someone who was not authorized under the State’s Data Security Policies and Procedures or the Federal Data Privacy Laws.”