Articles

PCI Compliance Becomes Scorecard for CSOs

Companies recertifying for the second or third year of PCI compliance are having a rough go of things as of late. A combination of the latest clarifications within the revised PCI DSS standard, along with the recent scoring matrix that compels assessors to ensure they have done a thorough job as part of the review, have caught an unfortunate number [continue]

Posted in Compliance, General Security, PCI on July 20th 2009 by Joe Bonnell

The Way Forward for Information Security

Every system has within it the limitation that it cannot exist unto itself. The big problems of Information Security will remain intractable as long as industry participants continue to focus inward.

For the past year or so, I have noticed that, at the same time that security technologies are reaching a certain degree of maturity, security projects remain [continue]

Posted in General Security, Security Operations on July 20th 2009 by Peter Schawacker

Twitter Confidential Information Compromised Via Weak Password

As noted, poor password management trumps strong security technology every time. Any bets on how long before google *requires* strong passwords? Both are victims, both share blame. A side note about this hack is that it highlights the trust relationships (and residual risk) that business partnerships impart upon each other.

Posted in General Security, Headdesk on July 16th 2009 by Joe Bonnell