In the previous
post, I spoke about the importance of having an asset register and how
crucial asset classification is. After all, not many of us have unlimited
resources, therefore focusing investment where it matters most is the way to
go. Whilst I was thinking about this, the link between changing the CISO
traditional attitude and the necessity for risk management became even more
apparent and I would like to expand on the trinity of “Asset, Technical
Services and Business Need”...
A blog about information security, payments, risk, fraud, digital innovation and social media... Connect on LinkedIn?
Showing posts with label risk assessment. Show all posts
Showing posts with label risk assessment. Show all posts
4 March 2012
26 February 2012
MANAGE RISK BEFORE IT DAMAGES YOU: PART ONE...
Neira Jones on Google+
After my part
1 and part
2 posts on incident response and the last post on cloud
computing security, a number of you requested I talk about risk assessments.
Since it’s currently my favourite topic, I am more than happy to oblige... First,
a few facts:
- Epsilon was breached in the first quarter of 2011. At the time, they built and hosted customer databases for 2,500 well-known brands and sent more than 40 billion emails a year on their behalf.
- Not long after, the Sony breach ended up compromising personally identifiable information for more than 100 million of its customers.
Obviously, for both organisations, customer information is a
key asset...
21 February 2012
UNDERSTANDING CLOUD SECURITY: PART TWO...
Google
I
thank you for your attention on the previous
post where we had a look at security considerations for the three main
cloud service models commonly referred to as SPI (SaaS, PaaS, IaaS). As promised
here’s part two looking at other cloud implementation considerations, namely:
- Cloud deployment model: public vs. private vs community vs hybrid deployments,
- Cloud location: internal vs. external hosting or combined,
6 February 2012
INCIDENT RESPONSE & RISK MANAGEMENT GO HAND IN HAND...
Google
I was delighted with the level of interest generated by my last
post on incident response so I thought I’d continue on the same theme... My
thanks go yet again to the NIST
report previously mentioned as I will explore some aspects of
risk management and prioritisation that apply to incident response...
Subscribe to:
Posts (Atom)