Disclaimer: The opinions of the columnists are their own and not necessarily those of their employer.

Tag Archives: CISO

Assessing your Organization’s Network Perimeter (pt. 3)

– Welcome once again to the risk rack. This time on the risk rack we will be continuing our review of how to assess your organization’s network perimeter. As a reminder the identified steps were: Step 1: Define the functions and purposes of your network perimeter. Step 2: Assess the technology…

Business Drivers For Information Security: Who Needs Them Anyway?

– Security needs to be done to protect the information assets from all the hackers, thieves, criminals and people waiting to steal laptops and data as well as those disgruntled employees that are trying to sabotage the networks, right? Everyone knows that, we need to invest much more money to solve…

IT and Infosec Insourcing: Could You Do It If You Wanted To?

– There was an article by Timothy Aeppel on the front page of the June 13, 2008 issue of The Wall Street Journal with the title “Stung by Soaring Transport Cost, Factories Bring Jobs Home Again” (subscription required). The article is about manufacturers bringing back some of their…

In Praise of the Information Security Checklist

– This is much anger and venom spit when the subject of the information security checklist is brought up. At one point in my career I looked at the checklist in disdain figuring that only people who do not understand the true depths of a subject relied on checklists as a crutch in place of…

Being a Government Security CISO: Life in the Fishbowl

– Information Security is Information Security, Right? It shouldn’t matter if the organization needing protection is a government agency operating in the public sector or a private enterprise, should it ? Well, technically, no. Essential security practices should be delivered for whichever…