Trust is Not Really a Control, Neither is Luck
By Gene Kim, CTO of Tripwire and co-founder of the IT Process Institute
This risk is often hidden in plain sight, poses a genuine clear and present danger to the business and information security objectives, and one that is often overlooked. This issue is change control.
Application Virtualization and IT Security
By Derek Crawford, Director of Sales Engineering at Tripwire
From an IT Operations perspective it would seem there is a pretty powerful argument to virtualize and distribute applications like this rather than have to install and maintain them on every users PC or laptop.
Audits and the Change Management Process
By Gene Kim, CTO of Tripwire and co-founder of the IT Process Institute
If the auditor observes that no one is showing up to the change management meetings, authorizations are rubber stamped without any real evaluation, unauthorized changes and unplanned outages are occurring regularly, then she will likely flag this as a potential high risk area.


