Our brain is an amazing marvel that provides us the wisdom necessary to navigate the river of life. Until recently though, research around how humans handle risks they encounter was spotty at best. Understanding, and being able to influence, how we react to risks is key to making better decisions in life. A recent study Read more…
Leave it to the Air Force Institute of Technology to develop technology that detects patterns in email/web usage that could offer leading indicators of insider security threats. The technology is called Probabilistic Latent Semantic Indexing (try saying that a couple times fast). It sifts through email and web traffic logs to identify trends in Read more…
Data loss is a burning issue that should be on the mind of every C-level executive and board member, if it isn’t already. According to a recent Ponemon Data Loss Study, the costs associated with data breaches rose 55% in 2007. What is troubling is the scope and opportunity for such abuse and loss of Read more…
Web 2.0 applications are springing up everywhere in the enterprise. However, issues including privacy, anonymity, productivity loss, sensitive data breaches and technology vulnerabilities make these applications a security vulnerability that IT managers need to take seriously. As Andrew Jaquith wrote on SecurityMetrics.org “..the Web 2.0 architectural style makes it easier and faster to hose yourself Read more…
Tags: Web 2.0
If you had 30 seconds to gather your most valued possessions, what would you grab? In the world of security, IT security professionals need to have a plan in place to make decisions in a swift and intelligent manner when facing a crisis. Valuing assets is an important step in determining the losses an organization Read more…
Last week marked the 5th anniversary of the Sarbanes-Oxley Act of 2002. I felt it would be fitting to write a tribute to SOX for what it has provided to the security world over the last half decade. I must admit, as with all good friends in life, SOX has taught me a number of Read more…
Managed security, security “in the clouds,” whatever you call it, it’s on the rise according to a recent CompTIA survey. Companies are finding more economic methods of managing their organizations’ security, by letting others do the work for them. At the end of the day, managed security service providers (MSSP) are helping organizations make better Read more…
As if communities don’t have enough to worry about today with gangs, drugs, violence and sexual predators, they can now add identity thieves to the list. I recently read about the alpha release of a site called Fatdoor.com, which was designed to create online social communities for off-line neighbors. Profiles are overlaid onto a Microsoft Read more…
I recently had the opportunity to leave the security “bat cave” to meet with some of McAfee’s enterprise customers in Europe. We talked about how to measure and communicate enterprise risk. I was surprised by how these discussions immediately gravitated to the topic of regulatory compliance. My security colleagues pointed out that while securing the Read more…
Ok, I admit it, I’m a habitual viewer of the weekly crime drama Criminal Minds. This show follows a group of profilers from the FBI Behavioral Analysis Unit as they dissect the personalities of criminals to solve crimes. How does this relate to the day-to-day lives of us security guys? We are occasionally put in Read more…
Posts by Charles Ross