The InfoSec Blog
System Integrity: Context Is Everything
Navigation
  • About The Author
  • Presentations
  • System Integrity
You are here: Home › Archive for March 2012
Currently browsing

March 2012

Help on ISO-27000 SoA

31 March, 2012 | Filed under: ISO27K, Risk, Standards

This kind of question keeps coming up, many people are unclear about the Statement of Applicability on ISO-27000. The  SoA should outline the measures to be taken in order to reduce risks such as those mentioned in Annex A of the standard. These are based on ‘Controls’. But if you …

Surely compliance is binary?

24 March, 2012 | Filed under: Human Factors, ISO27K, Rants and Raves, Standards

Call me a dinosaur (that’s OK, since its the weekend and dressed down to work in the garden) but … Surely COMPLIANCE is a binary measure, not a “level of” issue. You are either in compliance or you are not. As in you are either deal or alive.

Social Engineering and sufficency of awareness training

23 March, 2012 | Filed under: 11th Domain, Failures, Human Factors, Policy, Risk, Social, Standards

Someone asked: If you have a good information security awareness amongst the employees then it should not a problem what kind of attempts are made by the social engineers and to glean information from your employees. Yes but as RSA demonstrated, it is a moving target. You need to have …

Orwell: a quarter of a century late

22 March, 2012 | Filed under: Hardware, Human Factors, Social

http://hdguru.com/is-your-new-hdtv-watching-you/7643/ well 28 years actually … So, the two-way tv sets of Orwell’s novel have arrived, over a quarter of a century late! It just goes to show. Science fiction things like the Star Trek communicator (Motorola flip phones) or the tricorder (some of the enhanced versions of the Newton) …

About ISO 27001 Risk Statement and Controls

18 March, 2012 | Filed under: ISO27K, Policy, Risk, Security

On the ISO27000 Forum list, someone asked: I’m looking for Risk statement for each ISO 27k control; meaning “what is the risk of not implementing a control”. That’s a very ingenious way of looking at it! One way of formulating the risk statement is from the control objective mentioned in …

The 19 most maddening security questions | Security – InfoWorld

7 March, 2012 | Filed under: Human Factors, Security

http://www.infoworld.com/d/security/the-19-most-maddening-security-questions-187983 An interesting list, since it covers issues of public structural security. I recall reading that the greatest contribution to the health of individuals came about from good public sanitation and clean water, that is civic changes (presumably enabled by legislation) that affected the public in a structural manner. What …

Naval War College uses Russian software for iPad course material

6 March, 2012 | Filed under: Crime, Hardware, Politics & Economics, Risk, Standards

http://www.nextgov.com/nextgov/ng_20120305_6368.php The Navy’s premier institution for developing senior strategic and operational leaders started issuing students Apple iPad tablet computers equipped with GoodReader software in August 2010, unaware that the mobile app was developed and maintained by a Russian company, Good.iWare, until Nextgov reported it in February. OK so its not …

Calendar

March 2012
M T W T F S S
« Feb   Apr »
 1234
567891011
12131415161718
19202122232425
262728293031  

Search

Archives

Tag Cloud

Access control Apple Botnet Business Business Continuity Planning Certified Information Systems Security Professional CISSP Computer security Confidence trick Consultants controls Donn Parker Editing English language FMEA fraud HP Individual Standards Information security infosec International Organization for Standardization IPad IPhone ISO/IEC 27001 Laptop laptops Law Linux Malware Management Microsoft Open source owasp Policy Risk Risk analysis Risk assessment Risk Management Security Site Management Standards statistics Technology United States Vulnerability

Meta

  • Log in
  • Entries RSS
  • Comments RSS
  • WordPress.org

Popular Pages

  • The Classical Risk Equation
  • Separation of Duties: Infosec, IT and Audit
  • “Cybercrime” is still Crime and “Cyberfraud” is still Fraud
  • Risk Analysis makes no sense … Does it?
  • Are *you* ready to give up yet?
  • Why InfoSec Positions go unfilled
  • Security
  • Risk

Categories

Advisories & Vulnerbilities

  • bugtraq @ insecure.org
  • SANS Security Alerts
  • SANS Storm Center
  • Secunia Advisories
  • Symantec Security Response – Advisories
  • Symantec Security Response – Resent Viruses

Blogroll

  • Augusto Paes de Barros
  • Bob Johnston
  • Daniel Accioly Rosa
  • Deep Litter
  • DHS Daily Report
  • Eduardo Neves
  • Emergent Properties
  • Gary Hinson
  • Hayden’s Harangues
  • Martin McKeay
  • Schneier on Security
  • The Quiet Earth
  • The Security Team
  • Watchguard Wire

Security Links

  • CERT-CC
  • E2K Security
  • focus-ids @ insecure.org
  • fulldisclosure @ insecure.org
  • Identity mangement news
  • Incidents
  • InfoWorld- Security
  • isn @ insecure.org
  • joatBlog
  • Kill-HUP.com
  • Mark O’Neill’s Radio Weblog
  • microsoft @ insecure.org
  • Microsoft TechNet – Security
  • MSDN- Security
  • Network World Fusion NetFlash
  • Network World on Privacy
  • Network World on Security
  • Network World on Wireless Security
  • nmap-hackers @ insecure.org
  • Scott Granneman- Intellectual Property
  • Scott Granneman- Privacy
  • Scott Granneman- Security
  • Scott Loftesness- Digital Identity
  • Security Blog
  • Stupid Security
  • THE Network Security Blog – Geek Troy Jessup
  • Wi-Fi Networking News
  • Wifi Security Project

© 2013 The InfoSec Blog

Powered by Esplanade Theme by One Designs and WordPress