Disclaimer: The opinions of the columnists are their own and not necessarily those of their employer.

Tag Archives: Engineering Safe and Secure Software Systems

FAA, GAO … Please Read My Book!

– … and my articles, columns, etc. about the dangers of connecting information systems to control systems. The GAO (US Government Accountability Office) released an April 2015 report, GAO-15-370, on the cybersecurity of air traffic control and avionics systems, with the title “Air Traffic…

Did Markey Miss the Mark on Vehicle Hacking?

– The staff of Edward J. Markey, U.S. Senator for Massachusetts, issued a report on February 10, 2015, called “Tracking & Hacking: Security & Privacy Gaps Put American Drivers at Risk,” which is available at…

Putting Application Security into Context

– For some time now, I have wondered why InfoSec practitioners are paying so little attention to context with respect to application security and why InfoSec professionals and software safety engineers do not collaborate as much as they should. Then I read a column on the Op Ed page of The New York…

Cybersecurity is Failing … per Spafford

– Eugene Spafford, who is the highly-regarded executive director of the Center for Education and Research in Information Assurance and Security (CERIAS) at Purdue University, is well known for his outspokenness. This trait again came to the fore in a June 24, 2014 article “Security Expert:…

CISOs Are Like Sheep to the Slaughter

– It took almost 10 years, but my claim that the role of the CISO is to take the blame when something goes awry, even if only marginally attributable to information security, goes awry has at last been substantially validated. Let’s scroll back to December 2004. I was a member of a panel of…