Advantages of Data-Focused Risk Assessments
By Danny Lieberman, Security Expert and Founder of Software Associates
The detailed reasons why people fail at DLP implementations merits a separate post – but it’s a lot like why over 50% of the content management implementation from vendors never made it to production in the 90s – the root cause was that there was no real business case for the technology. Unlike business processes – data risk cannot be outsourced.
DLP is Short for Disturbing Lack of Process?
By Danny Lieberman, Security Expert and Founder of Software Associates
The question is not lack of process but whether or not security is being used to help enforce business process in the relevant areas of product safety, customer service, employee workplace security and information protection in business-to-business relationships.
The Truth About Regulatory Compliance
By Steven Fox, Founder of SecureLexicon
Given the business impact of regulations like PCI DSS, Sarbanes Oxley, and GLBA, this is understandable. While savvy business leaders understand the limitations of these guidelines, there are among us less enlightened individuals who view these as a cure for organizational security issues.
Black Hat: Articulating the Value of Security
By Steven Fox, Founder of SecureLexicon
How do we market security? The cyber-bullies among us might still use Fear, Uncertainty, and Doubt. While this may produce short term acquiescence, that approach ultimately alienates us from the decision makers. Ultimately, security professionals must identify what is valuable to the business and then associate the need for security with those assets
Geithner Appointment Clears Landscape
By Kevin M. Nixon, Information-Security-Resources.com Security Editor
Despite the enactment of the USA PATRIOT ACT, which was to strengthen the Banking Secrecy Act and both of which were supposed to follow the Federal Information Security Management Act (FISMA), when all that helicopter dust finally settled, an audit showed that all of the puzzle pieces had been placed on the table, but none of the old guard had done anything to actually make the security really work.
Reality to Palin: Anybody In There?
Feature By Kevin M Nixon, MSA, CISSP, CISM, ♦ ISR Master Security Editor
“Now, think about the current state of the global economy. If publicly-traded Corporations use these services and do not disclose the risk in their Sarbanes-Oxley (SOX) disclosures to the Securities and Exchange Commission (SEC) they are committing a Crime and deserve the fines and deserve to serve the time in prison as stipulated by law. We hear calls for stiffer regulations, oversight and transparency, but; do we really know how much of our private information is “out walkin’ around” already?”
Wait - The Palin Story Gets Worse…
Feature By Kevin M Nixon, MSA, CISSP, CISM, ♦ ISR Master Security Editor
“Once the Governor began transmitting information in an unprotected manner via her personal web-based email account, which was outside the State of Alaska’s highly secure and well protected network, there was no way to guarantee the safety and integrity of those date floating in cyber-space. In other words, there was no way for the Governor or other state employees to know if the information which was being transmitted was being intercepted and read by someone who was not authorized under the State’s Data Security Policies and Procedures or the Federal Data Privacy Laws.”


