Disclaimer: The opinions of the columnists are their own and not necessarily those of their employer.
Advertise with BlogInfoSec.com

Tag Archives: Policies and Procedures

Again, Security as a Differentiator

– SC Magazine’s January 2008 cover story this month illustrates security as a differentiator. In the past, I moved from a hard line to more neutral territory based on some marketing material from Visa. Here are some memorable quotes from SC Magazine: Businesses can use security to increase…

America Complacent: Chertoff Terrorism Interview on BBC America

– In a rare instance, I happened to catch the broadcast of the Chertoff interview that lead to this BBC story stating that Europe is the largest threat to the US. What is not written in the article is Chertoff’s remark that Americans are becoming complacent in the fight against terrorism.…

Data Tracing: Proposal for a Privacy and Data Security Law

– My recent Equifax issue (here, here) lead me to wonder about my personal data. Consumers should be able to find out the following: 1. What a given company is doing with one’s personal information (processing / data mining) 2. Which third parties are privy and have access to their…

You’d think it was a trend…

– A few weeks ago I found a badge on the streets of NYC (see here and here). The other day I found another badge that someone lost. The badge finder, instead of tracking the person down, hung the security badge on the intersection emergency call box. Below is a picture from my cell phone, which…

A Way to Think About the Difference between Compliance and Risk Assessment

– I heard this example today and I thought it was a very succinct. Compliance is binary: either one is compliant or one is not. Risk is a graded: there are different degrees of exposure. Here is the illustration: On a desk sits a piece of paper exposing a single person’s non-public…