SecurityRatty :: tag: organization
Featured Articles :: Poll: Who looks at logs in your organization? :: The wrong kind of empowerment reduces security and puts the organization at risk :: Another Old Presentation: What Every Organization Must Log and Monitor :: Oldham Primary Care Trust NHS loses two data sticks :: Is Risk Management a People Problem? :: Who should do your security audits? Or, how do you organize the security department? :: What can CISOs learn from the Societe Generale debacle :: Systematic Automations breach continued... :: "many of Colt's clients" affected by breach, CNET included :: Cascade Healthcare Community donors affected by malware
Here is my next poll about logs : Who looks at logs at your organization
Vote here
Also, my past polls and analysis are here
About me: http://www.chuvakin.org
Two really good examples of why you should not ingnore insider threats popped up this week in Florida (click HERE) and in France (click HERE). When an employee feels threatened by the organization or their management, you have to expect that they will at least consider using whatever leverage they have at their disposal. So, its
Finally, I decide to "liberate" this presentation as well: "What Every Organization Must Log and Monitor" circa 2004
This is still very useful and relevant; also, many people will appreciate my attempt to do the impossible i.e. give a simple answer to a very complex question (BTW, it rarely works
So
View | Upload your own
About me:...
...Organization
Oldham Primary Care Trust NHS (PCT
Contractor/Consultant/Branch
None
Victims
PCT "clients
Number Affected
148
Types of Data
The information lost related to copies of assessments about future healthcare needs held in a secure central file. It included peoples names, addresses and dates of birth
I'm not sure if this means that...
...organizations can become more effective. Weve been thinking very hard about metrics and measurement and governance and compliance and assurance and so on and so forth. And one thing hit me funny today within that context, its the mention of the axiom Security is a People Problem
In his article, What can CISOs learn from the Societe Generale...
...organization's security architecture, creates policies and procedures, and ultimately takes responsibility for stewarding the integrity of the organization's information assets. The security alignment group spends time understanding the needs and drivers of the various business units, and advocates the business units' positions in meetings...
...organization to ensure that it is implemented and gives the organization a false sense of security
Everyone is not after the money. One perpetuating myth about hackers is that they are all after financial gain. This may or may not be true. In Societe Generales case French prosecutors announced that they'll pursue four charges, including...
...Organization
Torrance Unified School District
Contractor/Consultant/Branch
Systematic Automation
This breach is related to
Theft from vendor affects Modesto City Schools employees " dated 2/12/08
L.A. Dept. of Water of Power employees exposed " dated 2/19/08, and
Clovis Unified School District employees receive notice " dated 2/21/08
...
...Organization
CNET Networks, Inc. ("CNET
Contractor/Consultant/Branch
Colt Express Outsourcing Services, Inc. ("Colt
Victims
current and former employees and their dependants
Number Affected
around 6,500
Types of Data
first names, last names, date of birth, Social Security numbers, address, employer, hire date, benefits group numbers, and...