The Guerilla CISO
 
Showing 1-10 of 39 records
 
Expand article

A Step Inside the Guerilla CISOs Mind

The Article has images
2008-07-31 15:33:34 by rybolov in The Guerilla CISO
...security model (and many other things) works Bookmark to
 
 
 
 
 
Expand article

Legacy Systems: Where the Catalog Falls Apart and LOLCATS Roam

The Article has images
2008-07-31 15:18:17 by rybolov in The Guerilla CISO
...security is a myth. Compliance in IT security with legacy systems is like a chupacabbra riding a white unicorn chasing a leprechaun while waving Excalibur. And the auditors just shake their head and wonder why you cant just comply Anyway, on to the LOLCATZ (note that Im getting all creative-stylie with haikus this week, must be something in...
 
 
 
 
 
Expand article

No, FISMA Doesnt Require That, Silly Product Pushers

2008-07-31 14:36:31 by rybolov in The Guerilla CISO
 
...security specifications set by the National Institute of Standards and Technology, and it has been reported that the federal government s Office of Management and Budget (OMB) plans to begin enforcing DNSSEC requirements through an auditing process, setting the standard for DNS best practices Yep, if you stamp FISMA on it, people will buy it,...
 
 
 
 
 
Expand article

C&A Seminar in August, Instructor-to-Coolness Ratio Goes Up!

2008-07-28 19:11:33 by rybolov in The Guerilla CISO
 
Potomac Forum is having a 2-day C&A seminar on August 6th and 7th . It will be unusually good this time because I wont be there to drag everybody downIll be on the road for some training. =) Anyway, check it out and say hi to my instructors from me Bookmark to
 
 
 
 
 
Expand article

LOLCATS Take on Catalog of Controls

The Article has images
2008-07-24 12:17:01 by rybolov in The Guerilla CISO
Guys, please remember that the controls from SP 800-53 and the test cases from SP 800-53A need to be tailored. Otherwise, theyre as useful as a watermelon in a lake is to a kitteh Bookmark to
 
 
 
 
 
Expand article

On Government Employees, Culture, and Survivability

The Article has images
2008-07-21 13:46:05 by rybolov in The Guerilla CISO
...security: its all an issue of culture. I have a friend who converted a year ago to a GS-scale employee and took a class on what motivates government employees. Some of these are obvious Pride at making a difference Helping people Supporting a cause Gaining unique experience on a global-class scope Job stability Retirement benefits And one...
 
 
 
 
 
Expand article

FISMA Reporting Guidance for 2008

2008-07-18 15:02:09 by rybolov in The Guerilla CISO
 
Its out. Check it out in the OMB Memo. Ill most likely have something pithy to say when I look at it a little bit more, but it looks like its mostly the same as last year Anyway, you can get it here, its OMB Memo 08-21 Bookmark to
 
 
 
 
 
Expand article

Friday Subversive MusicThe Dead Kennedys

The Article has embedded video
2008-07-18 13:20:22 by rybolov in The Guerilla CISO
 
Its even funnier when you know about the Frankenchrist album trial just a couple of years later Bookmark to
 
 
 
 
 
Expand article

Exhaustive Security Testing is Bad For You

The Article has images
2008-07-17 21:39:37 by rybolov in The Guerilla CISO
Hot on the heels of Security Assessments as Fraud, Waste, and Abuse comes this heartwarming lolcat Bookmark to
 
 
 
 
 
Expand article

Security Assessments as Fraud, Waste, and Abuse

The Article has images
2008-07-17 21:34:14 by rybolov in The Guerilla CISO
...information security does not scale the way that we need it to for ST&E, and we need to understand this in order to fix security in the Government What we need to be doing is Security Test and Evaluation which is focused on risk, not on compliance using a checklist of control objectives. Usually if you know enough to say Wow, your patch...