Disclaimer: The opinions of the columnists are their own and not necessarily those of their employer.
Executive Women's Forum - Information Security, Risk Management and Privacy

Category Archives: Risk Analysis

PCI DSS Position on Patching May Be Unjustified

– Verizon Business recently posted an excellent article on their blog about security patching. As someone who just read The New School of Information Security (an important book that all information security professionals should read), I thought it was refreshing to see someone take an…

Assessing your Organization’s Network Perimeter (pt. 2)

– Welcome once again to the risk rack. This time on the risk rack we will be continuing our review of how to assess your organization’s network perimeter. As a reminder the identified steps were: Step 1: Define the functions and purposes of your network perimeter. Step 2: Assess the technology…

Agility and Risk Compensation: Exploring the Connection

– In my previous and inaugural column, I introduced the concept of a tradeoff between information security and agility, where agility was defined as “the capability to change with managed cost and speed.” Information security doesn’t necessarily have to be at odds with agility, but…

Assessing your Organization’s Network Perimeter (pt. 1)

– Welcome once again to the risk rack. This time on the risk rack we will be reviewing how to assess your organization’s network perimeter. The assessment of a network perimeter has six major steps: Define the functions and purposes of your network perimeter. Assess the technology used along…

Risk Assessment Gone Awry: The Costly, and Unpleasant, Consequences of Good Intentions

– We are all well aware that information security controls should be “risk-based.”  Innumerable email messages received from vendors stress this apparent truth, and conference speakers are forever reminding us that risk assessment must serve as the foundation of an effective—and…