Friday, July 11, 2008

Fun Reading on Security - 5

Instead of my usual "blogging frenzy" machine gun blast of short posts, I will just combine them into my new blog series "Fun Reading on Security." Here is an issue #5, dated June 11, 2008.

  1. Another fun (and horrible) laptop theft story, to be shown to those naive souls who say "ah, just stolen for hardware"
  2. Very fun dailydave thread on security future (sad, of course :-)) - here is an excerpt: "The complexity in security is not from any complexity in technology but the complexity in motivating people to truly care about security and act accordingly."
  3. Prediction markets for security? Fun idea!
  4. "Elevator pitch for explaining security risks to executives" by Lenny Zeltser @ SANS.
  5. "In Praise of the Information Security Checklist."
  6. A great WAF battle rages on (here and in many other places). PCI + June 30 + 6.6 + WAF = BOOM!
  7. How do you protect from IT admins "going bad?" Separate data and infrastructure (easier said than done, for sure). Another related one is "Staff more dangerous than hackers."
  8. Curious about PCI DSS compliance outside the US? Read this and this. Yes, it is pretty bad.
  9. "Terminating an employee with privileged access" from SANS (scroll to bottom)
  10. An interesting view on sad state of academic research in information security.
  11. Useful reminder to many people pushing silly/useless security solutions: while you are doing this, your organization is losing 6% of revenue to fraud. Today. Every day. Fraud checklist is linked there as well.
  12. Rich on "consumerization" of IT. Good stuff. You are ready for it, aren't you? More on this subject.
  13. Obviously, you are reading Mike R mid-year grades for his predictions.  One that failed in the most spectacular fashion (grade "D") is also an instructive read.
  14. Really good post on security vs risk management. Just read it.
  15. Matasano launches a GRC solution :-)
  16. After "security idiot" became "an official meme", it didn't take long for SecurityIdiot.com to launch with much fanfare! If you are still wondering how to misspell "SOX" go there... the mystery is answered.

See you next time!

Dr Anton Chuvakin