The InfoSec Blog

System Integrity: Without Integrity you don’t have Security

July 14th, 2010

IAM - Basics - Policy

If there’s one thing that upsets me when I see articles and posting to forums about policy, its mention of a “Password Policy”. I have to step away from the keyboard, go outside and take some deep breaths to calm down.

I get upset because policy is important and developing — and more importantly communicating — policy has been an important part of my career and the professional service I offer. Policies need to be easy to understand and follow and need to be based on business needs.

If you begin with a list of policies, you end up adapting the the reality of your business - the operations - to the list. You are creating a false sense of security. You need to address what you need to control, and that is Identity and Access.

Lets face it, passwords, as Rick Smith points out in his book “Authentication“, are not only awkward, they are passée - even Microsoft thinks so. More to the point, using passwords can be bad for your financial health.

They should be used with care and not as a default.

And they should most certainly NOT be entombed in a corporate policy statement. Read the rest of this entry »

June 29th, 2010

You don’t need a Firewall Security Policy

June 4th, 2010

Google Phasing out Windows

May 28th, 2010

“Impact” is not a Metric

May 22nd, 2010

Risk Analysis Makes No Sense … does it?

May 19th, 2010

Risk is Not a Primary Metric

May 19th, 2010

The Classical Risk Equation

March 26th, 2010

A Security Policy needs to be abstract not specific

March 22nd, 2010

More on how to win friends and influence management

March 13th, 2010

On the one hand …

March 5th, 2010

White House Cyber Czar: ‘There Is No Cyberwar’

February 28th, 2010

The FBI risk equation

February 5th, 2010

The checklist revolution works

January 25th, 2010

About Social Networking policy

January 25th, 2010

Text vs HTML: what is more secure?

January 15th, 2010

Arrogant? Who? Us?

January 6th, 2010

The Need to Understand Culture

December 27th, 2009

Throwing in the towel

December 1st, 2009

The wedge gets thicker

November 25th, 2009

Why don’t companies apply more risk analysis - Part 2