Data Loss Prevention is one of the most hyped, and least understood, tools in the security arsenal. With at least a half-dozen different names and even more technology approaches, it can be difficult to understand the ultimate value of the tools and which products best suit which environments. This series of posts will provide the necessary background in DLP to help you understand the technology, know what to look for in a product, and find the best match for your organization. I won’t be…
Securosis, L.L.C. is a security consulting practice dedicated to thought leadership, objectivity, and transparency. Our consultants have all held executive level positions and are dedicated to providing the highest value strategic consulting available.
Mr. Rothman was concerned that Mr. Hoff may, perhaps, have a little too much spare time on his hands. I’ve seen Senior Hoff at work, and he definitely isn’t winning any Slacker of the Year awards. I personally have a theory that he’s really just the earthly expression of a multidimensional being beyond our comprehension.
Computerworld yesterday reported on a US-CERT advisory for the popular Quickbooks Online Edition.
I know it’s popular because I use it. And I’m popular. Aren’t I? Really? Oh… Don’t tell my mom, okay?
For those of you who don’t know, this is a blog with an editor. Chris Pepper is a long-time friend, UNIX wizard, web host, and tech writer himself. You can track his work at Extra Pepperoni, his somewhat-recently revamped blog.
If you read the security blogs, you may have seen that I have a stalker- Rob Newby over at IT Security, The View From Here. Rob’s a data security weenie like myself.
There’s been a lot of debate lately on quantitative vs. qualitative risk, frameworks, models, metrics, certifications, standards, and all sorts of other organizational junk we seem to burden ourselves with. Oh, I’m no better, having authored a risk management framework, data security hierarchy, and similar tools in my past.
Since most of you blog readers don’t care about how I feed myself I don’t intend on using the blog for boring corporate updates, but I’m going to indulge myself for a moment.
I had a little back and forth with rybolov in the comments on my military post, and he introduced me to something called the Business Reference Model right out of some government publications and NIST 800-60.
Back when I started this blog one of the only security blogs I knew about was Martin McKeay’s Network Security Blog. As can happen in the blogging community, Martin and I eventually got in touch and developed a friendship. Heck, anyone I’ve gone drinking with in 3 different cities in less than a year is definitely a friend.