Showing posts with label information security. Show all posts
Showing posts with label information security. Show all posts
Wednesday, December 3, 2014
Top 3 Enterprise Software and Security Trends for 2015
It's the time for prognostications for 2015. Cirius is first out of the gate. Here's what it foresees as significant trends developing in enterprise software and security.
1. Data jurisdiction and data sovereignty will impact the growth of Office 365 and Azure.
Satisfy local, grow global: Enhanced national privacy legislation introduced in Australia, Singapore, Germany, Malaysia, as well as the EU Data Protection Directive, is the sign of what is to come. In many cases opinion trumps facts and products like Office 365 and Azure need to demonstrate aggressively that they understand the privacy and security concerns of partners and resellers. Addressing domestic privacy and data jurisdiction concerns will help facilitate global growth
2."Cloud" will no longer be perceived as a security threat compared to on premise solutions.
The future of security is in the cloud: Cloud solution providers have had to deal with the perception the cloud was "unsecure" from day one. As a result cloud solution providers historically had to over deliver to be a viable alternative to on premise solutions. The reality is that security and compliance are not the core competency of most I.T. departments and they lack the internal resources to meet compliance requirements and evolving security threats.
3. Data Loss Prevention will become a hot issue for business leaders.
Who saw what when: Businesses need to know where their business critical information is at all times. Flagging content and communication before it leaves the office is a good start but it is not enough. Machine learning, pattern recognition, and "post-send" message controls are the next wave of DLP functionality that will protect employees, clients and increasingly the brand.
Tuesday, March 25, 2014
Papa John’s Offering a Free Pizza
Papa John’s is offering consumers a free pizza. By simply placing an order for $15 or more between today and April 7 using promo code STATS at www.papajohns.com, you can get a free pizza on your next order.
While we don't offer free books, you might want to check out these anyway:
How I Discovered World War II's Greatest Spy and Other Stories of Intelligence and Code by David Kahn; ISBN 978-1-4665-6199-1
Trade Secret Theft, Industrial Espionage, and the China Threat by Carl Roper; ISBN 9781439899380
Managing Risk and Security in Outsourcing IT Services: Onshore, Offshore and the Cloud by Frank Siepmann; ISBN 9781439879092
Intrusion Detection in Wireless Ad-Hoc Networks by Nabendu Chaki and Rituparna Chaki; ISBN 978-1-4665-1565-9
The State of the Art in Intrusion Prevention and Detection by Al-Sakib Khan Pathan; ISBN 978-1-4822-0351-6
Core Software Security: Security at the Source by James Ransome and Anmol Misra; ISBN 9781466560956
While we don't offer free books, you might want to check out these anyway:
How I Discovered World War II's Greatest Spy and Other Stories of Intelligence and Code by David Kahn; ISBN 978-1-4665-6199-1
Trade Secret Theft, Industrial Espionage, and the China Threat by Carl Roper; ISBN 9781439899380
Managing Risk and Security in Outsourcing IT Services: Onshore, Offshore and the Cloud by Frank Siepmann; ISBN 9781439879092
Intrusion Detection in Wireless Ad-Hoc Networks by Nabendu Chaki and Rituparna Chaki; ISBN 978-1-4665-1565-9
The State of the Art in Intrusion Prevention and Detection by Al-Sakib Khan Pathan; ISBN 978-1-4822-0351-6
Core Software Security: Security at the Source by James Ransome and Anmol Misra; ISBN 9781466560956
Wednesday, August 21, 2013
Is there anything really new happening?
I just received a flyer for another information security conference. Is there anything really new happening? I'm seeing sessions on the same old stuff, mostly at a introductory level. Sure, there are new threats and vulnerabilities popping up every day, but how different are they really? Even cloud, mobile, and big data are getting old, and we'll never solve the user problem. I mean, who doesn't know about this
I've been trying for a long time to get someone to write books on DLP, SEIM, APT, GRC, ..., but am beginning to believe that these topics have jumped the shark. Aside from, maybe, identity and access management, what's going to drive people's need for information and, one can hope, books sales?
BTW, if anyone wants to accept the challenge of writing a book identity and access management, let me know. It's a sure way to immortality (or at least as long as the Library of Congress exists).
I've been trying for a long time to get someone to write books on DLP, SEIM, APT, GRC, ..., but am beginning to believe that these topics have jumped the shark. Aside from, maybe, identity and access management, what's going to drive people's need for information and, one can hope, books sales?
BTW, if anyone wants to accept the challenge of writing a book identity and access management, let me know. It's a sure way to immortality (or at least as long as the Library of Congress exists).
Friday, November 16, 2012
Battle for information security 'is being won'
... according to The Global State of Information Security Survey 2013 published by PwC in conjunction with CIO and CSO magazines.
Cautious optimism or delusional optimism?
Cautious optimism or delusional optimism?
Tuesday, April 24, 2012
Tech groups push for cyberthreat information-sharing bill. Great idea. It's worked real well with Federal agencies.
So, now industry wants Congress to legislate what it won't do volunarily. So far, there's as much trust between companies as there is between government agencies. They're all willing for a one-way exchange. This isn't going to change in government, and it won't in industry. Which reminds me. Didn't Congress legislate sharing between agencies? That's working real well, isn't it.
Monday, April 23, 2012
Mac trojan fallout: Apple security glory days gone?
There are cults in IT. UNIX is one; Macs is another. These cultists fervently believe their OS is superior to others, and, by extension, they're superior to everyone else.
When it comes to vulnerability to attacks, though, UNIX was always an easy target. Macs are so safe and secure. Of course, until recently there weren't many of them, and they weren't in the enterprise, and so they were not as attractive a target as, say, Windows. Now that there are more Macs, making them an attactive target, the myth is staring to explode. Still, zealots being zealots, all's right in their world. Koolaid anyone?
When it comes to vulnerability to attacks, though, UNIX was always an easy target. Macs are so safe and secure. Of course, until recently there weren't many of them, and they weren't in the enterprise, and so they were not as attractive a target as, say, Windows. Now that there are more Macs, making them an attactive target, the myth is staring to explode. Still, zealots being zealots, all's right in their world. Koolaid anyone?
Friday, April 20, 2012
"You can't patch stupid." House committees approve 2 cybersecurity bills
One of the best phrases I've heard lately is, "You can't patch stupid." This speaks to the ongoing threats to security posed by users. Now it appears that Congress again is trying to legislate what can't be fixed by legislation. I think "You can't patch stupid" is more easily applied to Congress.
Thursday, April 19, 2012
PWC Survey: "... majority of executives ... are confident in the effectiveness of their organization’s information security practices."
According to the results of the 2012 Global State of Information Security Survey®, the majority of executives across industries and markets worldwide are confident in the effectiveness of their organization’s information security practices.
Doesn't this fly in the face of fact? With reported breaches on the rise, and fears of fraud, APTs, and supply chain security, among other threats, increasing, why are these executives so confident?
Doesn't this fly in the face of fact? With reported breaches on the rise, and fears of fraud, APTs, and supply chain security, among other threats, increasing, why are these executives so confident?
Wednesday, November 23, 2011
From The Moscow Times, Recent trends in legal regulation of information security
The article claims Russia has strict regulations on privacy and security, but acknowledges problems. The problem with news from Russian media is that it's rank with propaganda, most of it not too subtle. The Cold War lives on. Is it heating up?
Thursday, October 27, 2011
Boeing sees growth in cybersecurity business despite defense cuts; the right choice?
Given the problems Boeing's having in delivering the new 787 Dreamliner, and the growing threats from goverments and orgainzed crime to information resouces, maybe Boeing's making the right choice.
Other news:
National Security Agency helps banks battle hackers
FBI going to court more often to get personal Internet-usage data
Other news:
National Security Agency helps banks battle hackers
FBI going to court more often to get personal Internet-usage data
Wednesday, September 28, 2011
Ripped from the headlines. Oh, the drama
Cybersecurity goes unchecked at most small businesses. Really? Only small businesses?
Integrated security reduces health IT data breaches. Single source vs best of breed?
When freedom's not free at the State Department. Big Brother is watching, and he's not your friend.
Integrated security reduces health IT data breaches. Single source vs best of breed?
When freedom's not free at the State Department. Big Brother is watching, and he's not your friend.
Monday, September 19, 2011
Another day, another hack
So, another big name site's been hacked, and names and PII allegedly taken. This time it's the Intelligence and National Security Alliance (INSA). This is news, but it's becoming old news.
Wednesday, September 14, 2011
SIEM Is Dead
So, a new survery reveals that 65% of security professionals say SIEM is dead. Evidently, relying on log file analysis isn't sufficient to keep on top of who's doing what. I'm sure it has nothing to do with the time, effort, and cost of set up and management. Still, if anyone's interested in writing a book on SIEM, let me know.
Thursday, September 1, 2011
So, how insightful is this?
CSO magainze has a little piece on a minor hacker who opines that "good liars undermine information security." Okay, so don't liars undermine just about everything?
Thursday, August 18, 2011
... the More Things Stay the Same
Earlier this year I surveyed some authors about what they considered their top 5 information security issues. While there were some surprises, such as supply chains, there was more consensus. Among the top issues are cloud security, malware and advance persistent threats, smart phones and other mobile devises, social media in the workplace, data loss, and critical infrastructure protection and cyberwarfare. As I said, no surprises.
Lately, though, we’ve been reading and hearing in the consumer press about malware, cyberwarfare, tons of data loss, and security and privacy problems with social media as well as more invasive and insidious tracking. So, there’s increasing awareness of these threats by the general population, or should be, and convergence between what they and people working in information security consider risky. Maybe.
There’s a lot of distance between being aware of something and doing something about it. People are still flocking to smart phones and social networking, sharing far too much data and information, and leaving themselves at risk to threats they really don’t appreciate. Ignorance is bliss until calamity strikes, and it will.
Lately, though, we’ve been reading and hearing in the consumer press about malware, cyberwarfare, tons of data loss, and security and privacy problems with social media as well as more invasive and insidious tracking. So, there’s increasing awareness of these threats by the general population, or should be, and convergence between what they and people working in information security consider risky. Maybe.
There’s a lot of distance between being aware of something and doing something about it. People are still flocking to smart phones and social networking, sharing far too much data and information, and leaving themselves at risk to threats they really don’t appreciate. Ignorance is bliss until calamity strikes, and it will.
Friday, August 5, 2011
Headline: Dog Bites Man
Are you getting tired of all the reports about threats and intrusions?
InformationWeek – “Banks face ongoing cyber threats”
NetworkWorld – “Advanced persistent threats force IT to rethink security priorities
This isn’t really news to us. It’s more of the same, and it hasn’t change much, if anything.
The “Man bites dog” headlines directed at the general public are different.
Calgary Herald –“Oil industry prime target for hackers …”
ABC News – “Nation’s infrastructure still vulnerable to cyber attacks”
When these types of reports make the news, whether it’s names stolen from Sony or an intrusion at RSA, someone with the ability to act may take notice. Still, I suspect that most enterprises still consider information security as insurance; a cost to be minimized. Security training likely isn’t offered through HR along with classes on how to manage conflict or drive safely while on company business.
It’s likely, too, that despite the increased noise directed at non-techies about security-related issues, whether it’s fraud, theft, espionage, terrorism, or warfare, that the threats, the risks, and the attacks will continue to increase, and security will remain an afterthought.
InformationWeek – “Banks face ongoing cyber threats”
NetworkWorld – “Advanced persistent threats force IT to rethink security priorities
This isn’t really news to us. It’s more of the same, and it hasn’t change much, if anything.
The “Man bites dog” headlines directed at the general public are different.
Calgary Herald –“Oil industry prime target for hackers …”
ABC News – “Nation’s infrastructure still vulnerable to cyber attacks”
When these types of reports make the news, whether it’s names stolen from Sony or an intrusion at RSA, someone with the ability to act may take notice. Still, I suspect that most enterprises still consider information security as insurance; a cost to be minimized. Security training likely isn’t offered through HR along with classes on how to manage conflict or drive safely while on company business.
It’s likely, too, that despite the increased noise directed at non-techies about security-related issues, whether it’s fraud, theft, espionage, terrorism, or warfare, that the threats, the risks, and the attacks will continue to increase, and security will remain an afterthought.
Subscribe to:
Posts (Atom)