Showing posts with label Bob Covello. Show all posts
Showing posts with label Bob Covello. Show all posts

Sunday, February 25, 2018

New Report Offers Better Cybersecurity Definitions

The Council of Economic Advisers recently released a report that examines the cost of malicious cyber activity to the U.S. economy. The report cites many of the usual findings from the Verizon DBIR and Ponemon reports. Nothing new to those of us who live and breathe cybersecurity. However, the report caught my eye because it […]… Read More

The post New Report Offers Better Cybersecurity Definitions appeared first on The State of Security.

The post New Report Offers Better Cybersecurity Definitions appeared first on Security Boulevard.



from New Report Offers Better Cybersecurity Definitions

Monday, January 22, 2018

Let’s Not Be Our Own Worst Security Enemy

If you are like most infosec professionals, you probably have to evaluate the security awareness training program that will be used in your organization. These training programs are important, and more recently, they are required in many regulated organizations. Perhaps your security awareness training is “home grown,” or perhaps you use a training program offered […]… Read More

The post Let’s Not Be Our Own Worst Security Enemy appeared first on The State of Security.

The post Let’s Not Be Our Own Worst Security Enemy appeared first on Security Boulevard.



from Let’s Not Be Our Own Worst Security Enemy

Sunday, November 5, 2017

Policium Concisium: Advice on Writing a Security Policy

What do your policies look like? If your organization is like most, then your policies are probably voluminous and all-encompassing. This is a good thing – or is it? Probably one of the most painful aspects of being an infosec professional is having to author or review policies. (Audit is the other painful aspect.) When […]… Read More

The post Policium Concisium: Advice on Writing a Security Policy appeared first on The State of Security.

The post Policium Concisium: Advice on Writing a Security Policy appeared first on Security Boulevard.



from Policium Concisium: Advice on Writing a Security Policy

Friday, May 19, 2017

New NIST guidelines banish periodic password changes

New draft guidelines have been issued by NIST are recommending that users should not be forced to periodically change their passwords. Guest contributor Bob Covello reports.

from New NIST guidelines banish periodic password changes

Thursday, April 13, 2017

Graduating in Information Security: Part Two

In part one of this series, I posited that additional integrity on a resume as well as in interview situations can benefit the entire information security profession by highlighting the specific disciplines in our industry. This, in turn, could serve to stop the perception of a cyber skills-gap by driving awareness that the InfoSec field […]… Read More

The post Graduating in Information Security: Part Two appeared first on The State of Security.



from Graduating in Information Security: Part Two

Wednesday, April 5, 2017

Graduating in Information Security: Part One

There has been a lot of news recently about the cybersecurity skills shortage. While there is a lot to be concerned about with all of the news about insecure devices and unsecured networks, I am confident that the shortage alarms are more headline-grabbing sensationalism than actual fact. In this two-part article, I will explore the […]… Read More

The post Graduating in Information Security: Part One appeared first on The State of Security.



from Graduating in Information Security: Part One

Wednesday, March 1, 2017

The New York State Department of Financial Services: The Evolution of a Regulation – Part 3

In part 1 and part 2 of this series, I reviewed some of the administrative and technical evolution of the cybersecurity legislation that has been proposed for all financial entities in New York State. As I started to write this, the final regulation was adopted. The good news is that most of the changes that […]… Read More

The post The New York State Department of Financial Services: The Evolution of a Regulation – Part 3 appeared first on The State of Security.



from The New York State Department of Financial Services: The Evolution of a Regulation – Part 3

Monday, February 27, 2017

The New York State Department of Financial Services: The Evolution of a Regulation – Part 1

The New York State Department of Financial Services has proposed a cyber security regulation that is unique in its breadth. The original proposed regulation underwent a 45-day review period, after which it was changed. It is currently under another 45-day review period pending further changes and should be published in the next few weeks. The […]… Read More

The post The New York State Department of Financial Services: The Evolution of a Regulation – Part 1 appeared first on The State of Security.



from The New York State Department of Financial Services: The Evolution of a Regulation – Part 1

Monday, January 9, 2017

Now Ransomware Can Be a Breach Event

In the early days of computer viruses, there were different classifications of viruses based on their behavior. Worms had the ability to self-replicate, while polymorphic viruses had the ability to change their appearance to avoid eradication. Additionally, multipartite viruses consisted of a combination of viral techniques. There are, of course, other virus types in the […]… Read More

The post Now Ransomware Can Be a Breach Event appeared first on The State of Security.



from Now Ransomware Can Be a Breach Event

Thursday, September 1, 2016

Some Unorthodox Back-To-School Online Safety Tips For the Tech Savvy

Have you read the latest online safety back-to-school tips? Some of the advice is excellent, such as resisting the urge to click on unsolicited links in text messages, locking your phone before you put it down, and never sharing your passwords. However, to the tech-savvy among us, these bits of advice make us roll our […]… Read More

The post Some Unorthodox Back-To-School Online Safety Tips For the Tech Savvy appeared first on The State of Security.



from Some Unorthodox Back-To-School Online Safety Tips For the Tech Savvy