Skip to main content

Posts

When education isn't enough

So first off, I think awareness and education is an important part of any comprehensive security program. BUT you can't think that just by talking about security or training people on what to do to reduce the chance they are a victim of an ID theft, phishing, or other attack that you have significantly changed the risk profile of your company! I've recently seen a couple of Senior security leaders expound on the fact that they just need to bring the knowledge to the company, and leave the rest to the operational people (Sysadmins, network admins, etc.) to actually implement any controls, etc. This fails on many levels. Without proper leadership, oversight, and guidance, the IT Operational teams won't know if they've met the requirements of the policies, best practices, etc. Someone needs to tell them to do more, do less, or they've hit the mark. This needs to be consistent and comply with all appropriate regulations, compliance requirements, etc. The basic contr...

Well this is annoying

Saw this on Slashdot http://www.washingtonpost.com/wp-dyn/content/article/2008/04/03/AR2008040304052.html Looks like some ISP's are starting to do "deep packet inspection" mostly it seems to profile customers and to see where they go, and possibly to sell that information to other companies. I thought that this type of inspection would be covered by the wiretap act? I will look up specifics regarding the laws that I'm aware of and post more during the coming week. Not a lawyer, and this isn't intended as legal advise or guidance, just interested in understanding my rights and what implications this activity by ISP's may have on privacy. ->Pierre

Cybercrime, how the laws work, or don't

Article on CNN today http://www.cnn.com/2008/TECH/03/31/cybercrime.eu.ap/index.html talking about new discussions between EU and NATO on information security issues (data protection, ID theft, "cybercrime", etc.) this is key because there are few functioning laws that are common between the members of NATO (the EU has some, but specific countries still have different laws, processes, Germany for instance). Multi-national companies have a lot of challenges with this type of thing, I imagine governments have similar challenges. Having seen the kind of activity that is originating from Europe, I do hope they start to pursue some of the attacks. Also - New version (1.0.0) of wireshark is available now, there are some security fixes. ->Pierre

Good windows tool to be aware of

Found out about this tool (version of TCPDump for windows) http://www.microolap.com/products/network/tcpdump/ Over at another Blog http://markremark.blogspot.com/ Always good to have in to event of an investigation, etc. Other tools to be aware of for incident response, let's start with Windows - HELIX - http://www.e-fense.com/helix/ Wireshark - http://www.wireshark.org/ Those are a good place to start, of course each incident is likely unique and may require specific tools to investigate. ->Pierre

Welcome to my Blog

The purpose of this blog will be for me to provide some practical information security tips and tricks to the public, other information security professionals, or anyone who is interested. I am an Information Security professional and have been working in various aspects of corporate Information Security for some time. Also looking for topic suggestions or questions. Please let me know if you have something you'd like to know more about, regarding any aspect of Information Security. ->Pierre