Skip to main content

Posts

Showing posts with the label infosec
Weekly recap and why you should be concerned about "attackers" even if you have "nothing to hide" Why you should be aware of, defend against, and prevent attackers... even at home: I often hear from future victims "well I don't have anything to hide/anything of value/why would they target me!?" It's really not about you, usually the attackers aren't looking for your data (if they get it, or have easy access to it, they may try to profit from it, but the people doing the compromising aren't usually the same folks that monetize). What the attackers want are compromised systems they can use to do what they want at scale. So if they can compromise 50 systems, they can send 50X the amount of SPAM... 100 systems, 100X, etc. Some operations get paid based on the number of emails they can send per day. Of course the email will likely not just be SPAM, but may also be malicious (ransomware, etc.). http://thehackernews.com/2017/09/linux-ma...

Information Security - What does it mean to you? - Part 3 Y2K all the way!

So where I last left off - 2000 a time of transition for a number of things, the "red hot" internet properties of the '90's started the downward slide that became the recession of the early 2000's and many "internet millionaires" became bankrupt or lost much of their projected net worth. During this time many companies had been focused on growth and establishing an "internet" presence without really having a business plan or an approach to sustain or support the number of systems that were being deployed to the networks. Corporate malfeasance leads to regulation - Enron, WorldCom, Tyco and other companies caused public outrage due to accounting fraud of various magnitudes and the attempted cover-up and complacency of Sr. Management. The result is the Sarbanes-Oxley Act of 2002. While mostly corporate accountability legislation, this triggers a number of compliance initiatives that impact Information Security and compliance. Continued ema...

Information Security - What does it mean to you? - Part 2 new challenges

So we continue the journey with the next evolution of "information security". At this point (1999 - 2000) the motivators for implementing security were small and very little time, effort, and money was spent either on tools, technical training or in preparedness. 1999 was a banner year for malware (viruses, worms, etc.) with most environments being subject to at least one of the major outbreaks (Melissa, Sub7, etc.). Melissa was an interesting one, like many malware infestations to follow, the impact of the worm was that it spread exponentially and impacted the services running on the affected systems. For the first time (for most IT teams) there was an actual outage or impact to having Malware in the environment (other than having to spend the time, to clean it up). This got the attention of (some) execs, and they started to ask the questions like "what could we have done to prevent this?" and "how do we deal with the next virus like this?". Alas ...

Information Security - What does it mean to you? - Part 1

Sometimes the best way of trying to do something or explain what you want to do is to give it some analysis. Let's take a look at "Information Security" for a little bit today and see what that means to practitioners and companies at this point in time (2010). First lets start with a trip in the way back machine - Set the way back to 1999! 1999 - The Internet (although not officially new) is "new" to many people and businesses as corporate America and the world begins a love affair with e-mail, "the web", and all things Inter/net/web. Speed and cool whiz-bang ideas are all the rage, few people care or think to care about the risks associated with allowing everyone to see/access most everything. The only folks who are concerned are mostly government officials, people with law enforcement mentalities/backgrounds, and paranoid sysadmins who have been fighting to preserve their systems for years. In 1999 if you asked "what does Information Security...

How to plan for a successful IT Security Team?

So I saw this come across one of the mail lists I watch today: "Hi All, Can anyone provide the references on the internet for best practices for forming IT and Security Team Structure?" And it stuck me as a good topic to go in to some depth on, and it's not nearly as easy to answer as you'd expect. To take a step or three back... Some questions and ideas to get your thoughts flowing. What problem are you trying to solve? What resources or support do you have? What limitations or constraints do you have? Also consider the scope of what you are trying to accomplish, and the requirements (if any) provided by your management or company for success (hopefully you can define these to more accurately match what you intend to create). Let's work on each of these questions a bit. What problem are you trying to solve? This seems simple, but to be successful you need to phrase this in a way that identifies a need (preferably a business need) and how you intend to improve th...