Thursday, March 11, 2010

Bookmark and Share

Archive for the ‘Spinach’ Category

“I say it’s spinach, and I say the hell with it!”

Back when broccoli was relatively new to many US consumers, circa 1928, EB White drew a cartoon for “The New Yorker” that showed a child turning up her nose at the new vegetable with the above tagline.

Speaking at the Gartner Conference this week Jamie Lewis commented, “enterprises should worry more about their intellectual property leaking out through employees or small-time hackers than their entire networks crashing from attacks of organized cyberterrorists.”

What do the two things have in common? That companies are still making the same mistakes with their approach to risk management that they have been for years. Focusing on the latest threat, it’s cyberterrorists today, but it was the gnarly, evil hacker back in the mid to late 90’s.

When I was doing audit work companies used to ask me, and the teams I worked with, to check their firewall for vulnerabilities while ignoring the rest of their overall security framework. Unprotected PCAnywhere access to a desktop through a phone line? Insecure connections to corporate divisions in other countries? Forget about it. It wasn’t cool and many auditees didn’t want to hear about the more difficult, and less ‘glam’ vulnerabilities to their data. “Just check the firewall.”

Broccoli isn’t spinach and a company’s greatest threat has and does come from insiders.

Bookmark and Share
“Our goal is to provide individuals the edge to succeed in their jobs, and businesses the edge against their competition.”
Blog Cloud

The Law: Fear It Administrative Cruft (16)
Analysts (31)
Apple (25)
AppSec (12)
Assessments (2)
Auditors (2)
Biometrics (4)
Blogs (13)
Breaches (21)
Buzzwords (2)
By Grabthar's Hammer!! (1)
Certifications (1)
Change Management (1)
Cheezburger Network (1)
Chupacabra (1)
Cloud Computing Security (4)
Collaborative Strategy Guild (2)
Compliance (4)
Copyright (9)
Credit Cards (3)
Crypto (11)
CXO Summit 2010 (1)
Cyberterrorism (2)
Data Protection (1)
DHS (25)
eBay (1)
Emergence (1)
End-to-End Encryption (1)
England (1)
Financial Fraud (1)
FISAP (1)
Forensics (5)
FTC Red Flad Rules (1)
FUD (12)
gnisreveR (2)
Google (2)
Holidays! (3)
Humor (16)
Identity Theft (4)
James Bond Shiz (1)
Legal Shiz (13)
Linux (3)
Malware (35)
Marketing and PR (9)
Messaging Security (1)
Microsoft (26)
Monoculture (3)
Mouth-Frothing (2)
Musings (17)
Open Source (3)
Oracle (21)
Outsourcing (4)
Paris Hilton (1)
Passwords (1)
PCI (4)
Phish-Eye (8)
Phones (5)
Planes (1)
Privacy (1)
Programming (1)
QDSP Blues (15)
Research (30)
Resources (6)
Rhesus Monkeys (2)
Risk Management (18)
RSA 2009 (1)
RSA 2010 (1)
SAML (1)
SAN (1)
SC Mag Blues (1)
SCADA (1)
Security Curve (8)
SecurityCurve Speaking (2)
SIEM and Log Management (5)
Social Networking (1)
SOX (1)
Speaking (2)
Spinach (1)
Spy Stuff (1)
Stealing Stuff (8)
Storage (1)
Symantec (7)
Tarot (1)
Teleological suspension of the ethical (3)
The Great Borack (1)
The Law: Fear It (10)
The Old Man of the Mountain (1)
The Regs (5)
Tokenization (1)
Useless Shizz (13)
Vendors (37)
Virtual Worlds (2)
Voting (2)
Vulnerabilities (40)
Walt Disney (2)
Wi-Fi (16)

WP Cumulus Flash tag cloud by Roy Tanck and Luke Morton requires Flash Player 9 or better.

Archives