Skip to main content

Posts

Showing posts with the label history of infosec

Information Security - What does it mean to you? - Part 3 Y2K all the way!

So where I last left off - 2000 a time of transition for a number of things, the "red hot" internet properties of the '90's started the downward slide that became the recession of the early 2000's and many "internet millionaires" became bankrupt or lost much of their projected net worth. During this time many companies had been focused on growth and establishing an "internet" presence without really having a business plan or an approach to sustain or support the number of systems that were being deployed to the networks. Corporate malfeasance leads to regulation - Enron, WorldCom, Tyco and other companies caused public outrage due to accounting fraud of various magnitudes and the attempted cover-up and complacency of Sr. Management. The result is the Sarbanes-Oxley Act of 2002. While mostly corporate accountability legislation, this triggers a number of compliance initiatives that impact Information Security and compliance. Continued ema...

Information Security - What does it mean to you? - Part 2 new challenges

So we continue the journey with the next evolution of "information security". At this point (1999 - 2000) the motivators for implementing security were small and very little time, effort, and money was spent either on tools, technical training or in preparedness. 1999 was a banner year for malware (viruses, worms, etc.) with most environments being subject to at least one of the major outbreaks (Melissa, Sub7, etc.). Melissa was an interesting one, like many malware infestations to follow, the impact of the worm was that it spread exponentially and impacted the services running on the affected systems. For the first time (for most IT teams) there was an actual outage or impact to having Malware in the environment (other than having to spend the time, to clean it up). This got the attention of (some) execs, and they started to ask the questions like "what could we have done to prevent this?" and "how do we deal with the next virus like this?". Alas ...

Information Security - What does it mean to you? - Part 1

Sometimes the best way of trying to do something or explain what you want to do is to give it some analysis. Let's take a look at "Information Security" for a little bit today and see what that means to practitioners and companies at this point in time (2010). First lets start with a trip in the way back machine - Set the way back to 1999! 1999 - The Internet (although not officially new) is "new" to many people and businesses as corporate America and the world begins a love affair with e-mail, "the web", and all things Inter/net/web. Speed and cool whiz-bang ideas are all the rage, few people care or think to care about the risks associated with allowing everyone to see/access most everything. The only folks who are concerned are mostly government officials, people with law enforcement mentalities/backgrounds, and paranoid sysadmins who have been fighting to preserve their systems for years. In 1999 if you asked "what does Information Security...