The InfoSec Blog

System Integrity: Without Integrity you don’t have Security

January 25th, 2010

About Social Networking policy

LONDON - FEBRUARY 03: (FILE PHOTO)  In this ph...

Policy development is one of my areas of practice, so when a colleague on a mailing list asked about how to phrase policy to deal with the social networks (Facebook, Twitter, Myspace, etc.) and what the “best practices” are, I came out of my shell to reply.

(We’ll skip over the oxymoron “best practices” since “Context is Everything“.)

The phrase

“Use of corporate resources …”

is a wonderful one to use to prefix just about any policy statement or justification. In one workshop on policy development that I ran someone pointed out that it applied to access to the company parking lot!

The issue here isn’t “social networking”, no matter how much the media and ZDNet would have you believe. It boils down to a few very clear and easy to enumerate issues: Read the rest of this entry »

January 25th, 2010

Text vs HTML: what is more secure?

January 15th, 2010

Arrogant? Who? Us?

December 27th, 2009

Throwing in the towel

December 1st, 2009

The wedge gets thicker

November 25th, 2009

Why don’t companies apply more risk analysis?

November 18th, 2009

How much would you give up your laptop for?

November 13th, 2009

The Cost of patching

November 6th, 2009

Speil Chequers

October 24th, 2009

How Many Deaths?

October 16th, 2009

A Ralph Nader for the 21st Century?

September 16th, 2009

The Glass Half Full

August 26th, 2009

Where do they get these numbers?

August 3rd, 2009

Significant Impact Calculation in Business Risk

July 29th, 2009

419 scammers using Dilbert.com

July 24th, 2009

One In Two Security Pros Unhappy In Their Jobs

July 23rd, 2009

The Need for Social Engineerig in InfoSec

July 2nd, 2009

Security Posture Assessment resources

June 20th, 2009

Audit Frequency

June 20th, 2009

Technology does not fix process