Clocks, Mobile Banking, and Social Media

This is a “Dan’s New Leaf” post . . . . Dan’s weekly blog of ramblings about information technology governance. This week’s post muses about our propensity to establish requirements for ourselves, and then forget to provide the basic tools to meet those requirements.

Dan Hadaway Earns CRISC Designation

Dan Hadaway, Managing Partner of Infotex, Inc., recently received the Certified in Risk and Information Systems Control certification (CRISC) certification. He earned the designation by meeting qualifying criteria required by the Information Systems Audit and Control Association (ISACA). The CRISC certification recognizes professionals for their knowledge of enterprise risk and their ability to design, implement, monitor, and maintain controls to mitigate those risks.

Beware “Tabnapping” – A New Kind Of Phishing Scam

A leading developer of Firefox has warned of a sneaky potential new form of phishing attack: Tabnapping

The so-called tabnapping attack works by using JavaScript to switch the destination page in a tab after a few seconds of inactivity. This might be done using attack script planted in an otherwise legitimate website, for example.