Posts Tagged ‘ compliance ’

Video & Venn Diagram of the Day – Compliance v. Security

September 9, 2011
By
Video & Venn Diagram of the Day – Compliance v. Security

I’ve talked about compliance before however @carnal0wnage recently tweeted a great link to a video explaining the difference between compliance and security. I think this video makes it much more clear than any write-up could possibly do. And no … it isn’t for those of us in the echo chamber but rather something you...
Read more »

Tags: , , , ,
Posted in Training | 6 Comments »

Outsourcing to Third-Party Security Services No Longer Taboo?

March 26, 2009
By

There was a time, not so very long ago, that outsourcing security services to third-party companies was seen as risky business. But in today’s economy, outsourcing security services has become more norm than exception, with companies asking themselves, “why didn’t we do this before?” Compliance—that’s why. In the past, many companies were so concerned...
Read more »

Tags: , , , , , , , , ,
Posted in News | No Comments »

The Way Not to Change NIST SP 800-30

June 16, 2008
By

Rybolov from The Guerilla CISO, a local infosec NoVA-based blog, has put together a great blog post about NIST’s latest effort to modernize SP 800-30: Risk Management Guide for Information Systems. In his post he stresses how NIST should not change this document into a “catalog of controls gap analysis” process to favor compliance...
Read more »

Tags: , , , , , , ,
Posted in News | No Comments »

Follow-Up: 2600 Group – Arlington Infosec Meetup Event – Friday, 4/4

April 5, 2008
By

I was finally able to make it to the Arlington 2600 group infosec meetup event last evening. There was a good turnout with about 10 people showing up. Most of the people that attended were fairly new so nobody really had a good idea of what we were suppose to do.
Read more »

Tags: , , , , , , , , , , , ,
Posted in NoVA Meetups | 2 Comments »

ShmooCon FireTalks Corner

Firetalks LogoMaster Post

CFP

Prizes

More to come...

Search

Grecs's Infosec Ramblings