Tuesday, September 30, 2014
ISMS Defined in terms of security
ISMS can be defined as the processes used by management to organize and coordinate security activities like governance, risk management, continuous improvement, internal audit, record keeping, document management, compliance management, communications, and awareness training. ISMS is defined in detail within mandatory clauses 4 - 10.
ISMS mitigates a series of common risks to information management but applying an internationally set of control objectives listed in Annex A. Annex A is an appendix of ISO 27001. Annex A control objectives are discretionary and can be risk justified in or out of scope.
There are over 140 contributing countries and thousands of information security professionals over a period of two years that rationalized and contributed to the latest version ISO 27001:2013. Since its inception in 1995 as BS7799 and then ISO 17799 there have been thousands more to establish ISO 27001 as the only internationally accepted information security management framework standard.
Monday, September 29, 2014
Is that true NSA Patents are available to buy
There's a new article on NSA's Technology Transfer Program, a 1990s-era program to license NSA patents to private industry. I was pretty dismissive about the offerings in the article, but I didn't find anything interesting in the catalog. Does anyone see something I missed?My guess is that the good stuff remains classified, and isn't "transferred" to anyone.
Quest to Open-Source Cancer Research
Sunday, September 28, 2014
Security Concern with icloud
This is a good essay on the security trade-offs with cloud backup:iCloud backups have not eliminated this problem, but they have made it far less common. This is, like almost everything in tech, a trade-off:It's true. For most people, the risk of data loss is greater than the risk of data theft.
Ideally, the companies that provide such services minimize the risk of your account being hijacked while maximizing the simplicity and ease of setting it up and using it. But clearly these two goals are in conflict. There's no way around the fact that the proper balance is somewhere in between maximal security and minimal complexity.
- Your data is far safer from irretrievable loss if it is synced/backed up, regularly, to a cloud-based service.
- Your data is more at risk of being stolen if it is synced/backed up, regularly, to a cloud-based service.
Further, I would wager heavily that there are thousands and thousands more people who have been traumatized by irretrievable data loss (who would have been saved if they'd had cloud-based backups) than those who have been victimized by having their cloud-based accounts hijacked (who would have been saved if they had only stored their data locally on their devices).
It is thus, in my opinion, terribly irresponsible to advise people to blindly not trust Apple (or Google, or Dropbox, or Microsoft, etc.) with "any of your data" without emphasizing, clearly and adamantly, that by only storing their data on-device, they greatly increase the risk of losing everything.
Shellshock Vulnerability Gone Wild
It's a big and nasty one.Invariably we're going to see articles pointing at this and at Heartbleed and claim a trend in vulnerabilities in open-source software. If anyone has any actual data other than these two instances and the natural human tendency to generalize, I'd like to see it.