Controls

Former NIST Official Regrets Issuing Password Guidance

Bill Burr admits security advice actually created more vulnerable passwords. An article review. If you’ve ever angrily questioned some seemingly arbitrary rule when creating a new password, there is some vindication for you: the former government official whose passw...

Nine Years Later, NIST Agrees With Dan!

For the sake of user comfort, new draft document calls for an end to mandatory password changes, and other requirements. An article review. Long-time readers may remember Dan’s Password Manifesto, originally published in the Hoosier Banker Magazine in 2008, where he ...

Ransomware: Should You Pay or Should You Go?

Avoiding “The Clash” with Management! A Jolley | Hadaway article review. There are three things very unique about ransomware:  First, from a containment perspective, it’s a bit different than normal malware.  Second, from a response perspective, the way ...

FFIEC Issues a Revealing Cybersecurity Assessment Tool FAQ

Questions from vendor management to mitigating controls covered in the new document. An article review.   The FFIEC released a document earlier this month covering some of the most frequently asked questions surrounding the Cybersecurity Assessment Tool (CAT), and it...

Alarming Recurring Finding

“Mal-Configured Secure E-Mail . . .” A new risk arises as Secure Messaging Enters the Late-Majority Adoption Phase! Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . So we’re auditing a bank and they s...

Tactics Behind CareFirst Hack

An article review. Taking a turn at the breach steering wheel In May 2014, CareFirst BlueCross BlueShield learned that one of their information systems had been infected with malware, so they got rid of it. Or so they thought. The malware was never fully eradicated, leadi...

The Password Manifesto Revisited

Password aging should be retired, usually . . . There is never 100%, even in manifestos! Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . So several years back I became known as the auditor who had the audacity to prop...

Over Sensationalized Internet Security Marketing

An article review. Beware of buzzwords Our friend and associate Joe Cychosz sent us this article a few days ago, and we thought it was worth sharing. This brief article highlights an alarming trend within the InfoSec world, where security vendors are hyping and spinning t...

Awareness Is Not a Verb!

But “test” is an action verb! and your approach could “Turn Awareness Inward.” Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . “With all we have going on, our auditors are not letting us a...

The Adoption of Information Security

and the Advent of “Partial Compliance” . . . How do you decide where to start if you are NOT in a regulated industry? Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . I have been having more than one intere...