Norm Marks of the famous Marks On Governance blog has posted his 2012 wishlist. His blog limits the characters you can leave in a reply, so I thought I’d post mine here. 1. Norm Wishes for “A globally-accepted organizational governance code, encompassing both risk management and internal control” Norm, if you mean encompassing both so [...]
Filed under: best practice, Science of Risk Management by alex on Wednesday, December 21, 2011
2 Comments »
Bill Brenner started it with “Stop them before they predict again!:” My inbox has been getting hammered with 2012 vendor security predictions since Halloween. They all pretty much state the obvious: Mobile malware is gonna be a big deal Social networking will continue to be riddled with security holes Technologies A, B and C will [...]
Filed under: best practice, measurement by adam on Wednesday, December 21, 2011
1 Comment »
On Saturday, I discussed how “I bolluxed our blog theme.” “More to the point, we here at the New School talk a good game about how we need to talk about problems, rather than cover them up. So here’s our money where our mouths are. I, Adam Shostack, screwed up the blog presentation by not [...]
Filed under: disclosure by adam on Tuesday, December 20, 2011
1 Comment »
If you read this blog with a web-reader, you’ll note our (ahem) excellent new theme, and may be saying, wow, guys, “nice job” Yeah. Ooops. I upgraded to WordPress 3.3, and upgraded our theme, and in so doing, overwrote some of the CSS that Alex had tweaked. I didn’t test, and so things were wonky. [...]
Filed under: disclosure by adam on Saturday, December 17, 2011
No Comments »
Last week I did a podcast with Dennis Fisher. In it, we touched on what I might change in the book. Take a listen at: “Adam Shostack on Methods of Compromise, the New School and Learning“
Filed under: Book, disclosure, podcasts by adam on Thursday, December 15, 2011
No Comments »
I really like Gunnar Peterson’s post on “Top 5 Security Influencers:” Its December and so its the season for lists. Here is my list of Top 5 Security Influencers, this is the list with the people who have the biggest (good and/or bad) influence on your company and user’s security: My list is slightly different: [...]
Filed under: careers, data by adam on Monday, December 12, 2011
1 Comment »
From Keith Weinbaum, Director of Information Security of Quicken Loans Inc. https://www.quickenloanscareers.com/web/ApplyNow.aspx?ReqID=53545 From the job posting: WARNING: If you believe in implementing security only for the sake of security or only for the sake of checking a box, then this is not the job for you. ALSO, if your primary method of justifying security solutions [...]
Filed under: Amusements by alex on Thursday, December 8, 2011
1 Comment »
from Biostatistics Ryan Gosling Including my favorite: Thanks to my friend Bob Rudis for the headsup.
Filed under: Amusements by alex on Tuesday, December 6, 2011
No Comments »
My colleague Ross Smith has just presented an important new paper, “The Future of Work is Play” at the IEEE International Games Innovation Conference. There’s a couple of very useful lessons in this paper. One is the title, and the mega-trends driving games into the workplace. Another is Ross’s lessons of when games work: Over [...]
Filed under: Doing it Differently, Reports and Data by adam on Thursday, December 1, 2011
No Comments »