Tuesday, December 17, 2013
How Hackers Made Minced Meat of Department of Energy Networks
In this case, as reported on Ars Technica, it came down to little or no patch management. How simple?
If they had bothered to apply a little common sense, and had Felicia Nicastro's book, Security Patch Management, a lot of this could have been avoided.
Wednesday, December 11, 2013
FCC in-flight call plan meets political and public opposition
Yet, as reported by Mobile World Live, FCC chairman Tom Wheeler doesn't care, and won't act to ban calls. I can think of few things worse than the agony of air travel compounded by rude, obnoxious, self-obsessed people making phone calls at 30,000 feet. As if bad music that filters out of earbuds isn't bad enough. There is legislation pending to ban calls, but because it depends on Congress acting, I'm not counting on it going anywhere. Noise cancelling headphones anyone?
Tuesday, December 10, 2013
Cross-Platform Malware: A Growing Threat for Computers
There's a new infographic from Mobistealth that uses Koobface to highlight cross-platform malware. The Koobface worm hits social networks like Facebook. According to Wired, the Koobface virus uses the private messaging systems of Facebook and other social media sites to infect computers via a shared video.
We have some new books to help you defend against attacks:
Automatic Defense against Zero-day Polymorphic Worms in Communication Networks
Android Security: Attacks and Defenses
We have some new books to help you defend against attacks:
Automatic Defense against Zero-day Polymorphic Worms in Communication Networks
Android Security: Attacks and Defenses
Thursday, November 14, 2013
GAO Says TSA Should Limit Future Funding for Behavior Detection Activities
The GAO found that "Available evidence does not support whether behavioral indicators, which are used in the Transportation Security Administration's (TSA) Screening of Passengers by Observation Techniques (SPOT) program, can be used to identify persons who may pose a risk to aviation security."
So,
TSA's Screening of Passengers by Observation Techniques (SPOT) program
is useless.
Bruce Schneier has long said that profiling is worse than
useless; it’s dangerous.
However, with DHA and TSA being laws onto themselves, they’ll continue with this security theater regardless of GAO recommends. So, here we have taxes wasted in two ways: by TSA in continuing programs that don’t work, and by GAO in conducting reviews that no one act on.
Related Books:
and even though GAO has its doubts, for those believers:
Tuesday, November 12, 2013
Wave of Connected Devices Poses Security and Privacy Challenges
ISACA says the governing the Internet of Things won't be easy.
OK. I'll buy that. But first, what's the Internet of Things?
Here are some resources to bring you up to speed on the technology so you then address the security.
Books
Cyber-Physical Systems: Integrated Computing and Engineering Design
Unit and Ubiquitous Internet of Things
The Internet of Things in the Cloud: A Middleware Perspective
Articles
The Internet of Things
Communication Middleware for the Internet of Things
Smart Grids
Thursday, November 7, 2013
Kevin Beaver will conduct a complimentary webinar "IT & BC: Filling the Gaps to Protect Your Business"
Kevin Beaver will conduct a complimentary webinar "IT & BC: Filling the Gaps to Protect Your Business" on Tuesday, Nov. 12.
Kevin is co-author, with Rebecca Herold, of The Practical Guide to HIPAA Privacy and Security Compliance.
Kevin is co-author, with Rebecca Herold, of The Practical Guide to HIPAA Privacy and Security Compliance.
Friday, November 1, 2013
The emerging turf battle between information and physical security pros
Oh, the problems with slow news days.
This is not a new issue. It's been going on for a long time. Battle of the retired government agent or cop security manager--white socks, black shoes, definitely analog--facing an increasing digital physical security world versus the IT security pro who ensures that all the digital safeguards are working. (ASIS vs ISSA.)
The books we publish on security management largely have an analog focus as well.
We first covered this in 2006. Really, nothing has changed and likely won't. There's a comfort level in hiring an ex-agent for physical security, regardless of digital competence.
This is not a new issue. It's been going on for a long time. Battle of the retired government agent or cop security manager--white socks, black shoes, definitely analog--facing an increasing digital physical security world versus the IT security pro who ensures that all the digital safeguards are working. (ASIS vs ISSA.)
The books we publish on security management largely have an analog focus as well.
We first covered this in 2006. Really, nothing has changed and likely won't. There's a comfort level in hiring an ex-agent for physical security, regardless of digital competence.
Subscribe to:
Posts (Atom)