Archive for the 'Regulation' Category
« Mark Curphey - SecurityBuddha.com
home page
January 30, 2008
On Sundays it’s a British tradition to wake up with a hangover, get a copy of the Sunday Times and watch the morning politics shows on the beeb. This Sunday past was traditional for me. Data breaches and privacy are hot political topics in the UK after the national fiasco overseen by Alistair Darling. I [...]
Categories: Identity, Information Security Economics, London, Privacy, Regulation, Security Bullshit, Security Industry, hacking, information security
Comments: 5 Comments
January 25, 2008
In a former life I designed and installed some two factor Authn and cyrpto systems for ING Barings (home of the first rogue trader Nick Leeson) in the 90’s. Let me tell you that no single FX or Options trader can run up 7 billion of debts without serious collusion. Watch this space! This story [...]
Categories: Compliance, Regulation
Comments: 2 Comments
January 18, 2008
Dear Idiot (Tom Harris - Labour MP for Glasgow),
The world has gone mad and I am boarding the next commercial flight on Virgin Galactic in search of a world where numnuts and numties no longer rule.
It was my birthday last Thursday and very peasant it was too. I got back from a week in [...]
Categories: Compliance, Information Security Economics, Privacy, Ramblings, Regulation, Security Bullshit, Security Industry
Comments: 6 Comments
October 25, 2007
My last blog leads me neatly onto to the good stuff. Joining a new company is like a poker game. They need to tell you enough to get you interested but not too much that if you decide not to join you could screw up their plans. I knew ACE had bits of cool stuff [...]
Categories: ACE Team, Compliance, Dashboards, Getting Things Done, Information Security Economics, Long Tail Security, Microsoft, PCI, Privacy, Regulation, Security Industry, Security Platforms, Security metrics, Software Development, Software Security, Visualization, Web Security, information security
Comments: 10 Comments
October 24, 2007
I am currently on my way back (this post was started on a plane) from a superb two weeks in Redmond meeting with my team and other folks in various parts of Microsoft. There is just so much cool stuff going on and in the plans that it’s hard to know where to start. I’ll [...]
Categories: ACE Team, Certification, Compliance, Information Security Economics, Microsoft, PCI, Platforms, Privacy, Regulation, Security Industry, Software Development, Software Security, Visualization, Web Security, Working Life, information security
Comments: Be the first to comment
October 2, 2007
When you have a choice between Reindeer steak or Beef steak on your menu you know you are in Finland! I like Finland, it’s great. Really nice people and a lovely coastal environment. At this time of year for someone who still live in the South of France it is a little cold!
I [...]
Categories: Certification, OWASP, PCI, Regulation, Security Industry, Software Security, Web Security, information security
Comments: 1 Comment
September 25, 2007
A while back I wrote a blog post called Lets call a Fig a Fig about the limitations of web application firewalls and the sheer ludicrousness of a security standard offering an alternative of choosing a code review or a web application firewall.
This morning I was reading an excellent post by Chris Eng about [...]
Categories: Certification, Compliance, Information Security Economics, PCI, Regulation, Security Industry, Software Security, Web Security, information security
Comments: 8 Comments
August 30, 2007
“Risk Management is like the navigator in a rally car; Business is the driver.”
Hoff’s comment made me chuckle. “..these navigators never stop and ask for directions”.
Categories: Compliance, Regulation, Security Industry, information security
Comments: Be the first to comment
August 5, 2007
My last post The Long Tail of Information Security (Part 1) described why I think information security exhibits Long Tail economic characteristics, outlined the three forces of long tail markets and discussed the first, democratization of tools for production. The intent is to provide an insight into what the future of information security may look [...]
Categories: Certification, Compliance, Cool Business, PCI, Ramblings, Regulation, Security Industry, Security metrics, Speaking, Visualization, information security
Comments: 4 Comments
August 4, 2007
I have just finished reading the Long Tail by Chris Anderson (editor of Wired). It is brilliant and the best book I have read in several years. Its in the same class as Freakonomics and The Tipping Point. I highly recommend anyone who reads my blog reads the Long Tail if they haven’t already done [...]
Categories: Blogonomics, Certification, Compliance, Cool Business, PCI, Ramblings, Regulation, Security Blogs, Security Industry, Security metrics, Speaking, Visualization, information security
Comments: 5 Comments
Recent Comments