Tag Archives | Information Security
What is Your Digital Grid?

What is Your Digital Grid?

As consumers of digital technology do you not get the sense that the pace of change is increasing and impacting us with little time to sit back, watch, take things in, and try to make sense of it all.  Nowadays digital devices and digital environments tend to suddenly show up almost invisible to our awareness [...]

Read full story Comments { 0 }
No Privacy, please!

No Privacy, please!

We are in a world were our communication, information , search, entertainment, creation, and content are done with some form of digital device with access to the internet. This dynamic intricately tied to our personal and professional lives : privacy both online and offline is being transformed.  Some of this is within our control and [...]

Read full story Comments { 0 }
Trusted Data Assurance in the Cloud

Trusted Data Assurance in the Cloud

Cloud-based services are here to stay. Cloud services are even more attractive for companies who are being hit with the high cost of meeting compliance requirements – especially for small and mid-size companies that have shrinking or no information security budget. In Trusted Data Assurance in the Cloud, author and information security expert Felix Santos [...]

Read full story Comments { 0 } Download Whitepaper
Assessing Pentagon Performance On Information Security From some Ex-Hacker’s POV

Assessing Pentagon Performance On Information Security From some Ex-Hacker’s POV

Ever since there’s been data storage devices, there’s been guys trying to plant pieces of code on them to steal data or wreak havoc. Twenty-five or more years ago, we were constantly losing data because of worms, viruses and crooks and faulty or stolen floppy disks. Recently we’ve seen how SecureID’s used extensively for on [...]

Read full story Comments { 0 }

The Biggest Shortcomings of ISO 27001

If you’ve been reading my blog, you probably think I’m convinced ISO 27001 is the most perfect document ever written. Actually, that’s not true – working with my clients and teaching on the subject, usually the same weaknesses of this standard emerge. Here they are, together with my suggestions how to resolve them: Ambiguous Terms [...]

Read full story Comments { 0 }

Lessons Learned from WikiLeaks: What is Information Security Exactly?

Nowadays WikiLeaks is a hot story for a good reason – it is not very common for confidential documents of the world’s most powerful government to be published on the Internet. And some of these documents are, to put it mildly, embarrassing. Here I am not going to write about whether it was legal for [...]

Read full story Comments { 0 }

Four Key Benefits of ISO 27001 Implementation

Have you ever tried to convince your management to fund the implementation of information security? If you have, you probably know how it feels – they will ask you how much it costs, and if it sounds too expensive they will say no. Actually, you shouldn’t blame them – after all, their ultimate responsibility is [...]

Read full story Comments { 0 }

Information Security or IT Security?

One would think that these two terms are synonyms – after all, isn’t information security all about computers? Not really. The basic point is this – you might have perfect IT security measures, but only one malicious act done by, for instance, administrator can bring the whole IT system down. This risk has nothing to [...]

Read full story Comments { 0 }

Similarities and differences between ISO 27001 and BS 25999-2

At first glance, information security and business continuity don’t have much in common – some would add that the only similarity is that they are both about IT. Information security management is best defined in the International standard ISO/IEC 27001, while business continuity management is defined in the British standard BS 25999-2 – therefore, if [...]

Read full story Comments { 0 }

Overcomplicating Information Security and Risk Management

If I had to highlight a key problem area for organizations when it comes to how they approach Information Security and Risk Management overall, it would be the over-complication of their implementation(s), or lack thereof. (Sounds strange for the latter but it’s that “complication” that also results in the “lack thereof”). Technology has done little [...]

Read full story Comments { 3 }