Not too long ago I embarked on a creating a podcast series that would provide more regularity than the blog. Beyond the Perimeter has been a tremendous amount of fun and as we just posted our 50th podcast I wanted to reflect on some of the highlights and wonderful guests we have been honored to [...]
Posts Tagged ‘Risk’
50th “Beyond The Perimeter” Podcast HighLights
Posted in Security, tagged 451 group, Aaron Bawcom, Adam Shostack, Adobe Systems, Al HUger, Alex Hutton, Andy Purdy, antivirus, Arbor Networks, Ben Natan, beyond the perimeter, BigFix, Black Hat, Brad Arkin, Charles Dodd, Cisco, Concord Hospital, Conficker, Cyber Command, Dan Philpott, Dave Watson, David Mortman, Defcon, Doug Washburn, Dr. Peter Tippet, Economics, eIQ networks, EMA, EMC, Enterprise Management Associates, FAIR, FCRA, FIPS, FISMA, Forrester Research, Gartner, government security, Guardium, Hackers for Charity, HIPAA, IBM, Immunet, Information Security, ISS, Jack Daniel, Jeff Jones, Jeremiah Grossman, Johnny Long, Jose Nazario, Joshua Corman, Kaiser, Kaspersky, malware, Mark Starry, Mede Finance, Melissa Hathaway, Men in black, Michael Dahn, Michael Santarcangelo, Michael Smith, Microsoft, Mike Rothman, Nick Selby, NICOR, NIST, patch management, Patric Peterson, Paul Roberts, PCI, Peter Kuper, podcast, Project Quant, Reflex systems, Rich Mogull, Rick Wesson, Risk, RSA, Ryan Russell, Sam Curry, Scott Crawford, Scott Johnson, Sean Goings, Security b-sides, Securosis, Situational awareness, stelaing the network, Support Intelligence, TAC Americas, Technical Publishing, Timothy Mullen, Verizon Business Services, Virtualization, virtualizaton, Web Applicaiton Security, White Hat Security on September 21, 2009 | Leave a Comment »
Moving Security through Visibility to Implementing Operational Controls
Posted in Security, tagged Auditing, BigFix, cloud computing, Gartner, IDS, Intrusion detection, Intrusion prevention, IPS, McAfee, Monitoring, nCircle, network security, Risk, threats, Virtualization, vulnerabilities, Vulnerability Assessment on December 22, 2008 | 1 Comment »
Quick thought for the day. Most technologies in the security world move through a predictable cycle of adoption. First an organization implements a solution to gain visibility into the scope of the problem (VA, IDS, DLP/CMF, SIEM) then once it becomes apparent that the problem is vast and overwhelming they move to operationally implement technical [...]
5 Security Metrics That Matter
Posted in Security, tagged Metrics, Risk, Security on April 24, 2008 | 2 Comments »
Security metrics, which I have posted on in the past (here), and (here), are almost as elusive as security ROI. But unlike the mystical pink unicorn that is security ROI, security metrics are real, tangible and meaningful. Why is it then that we have so much difficulty in defining metrics that are both simple in [...]



