links for 2009-12-18

by swjohnson 12/18/2009 5:01:00 PM

links for 2009-08-16

by swjohnson 8/16/2009 5:02:00 PM

links for 2009-08-13

by swjohnson 8/13/2009 5:02:00 PM
  • Building a continually improving security program is an important and common topic. For many CISOs and other directors of security programs — this has been their day job since they earned their titles. There still exists huge gaps between IT/Operations, Application Development, and Information Security Management organizations and how they work together. There are gaps in communication between departments, and even within departments.
    (tags: security)

links for 2009-07-26

by swjohnson 7/26/2009 5:01:00 PM
  • It describes how to evaluate data security investments, map the potential investment to your business needs, then build a business justification case. It starts with a discussion of data security issues, then reviews alternative models (and their flaws), and finishes presents our justification methodology.
  • This report shows how to build a pragmatic web application security program that constrains costs while still providing effective security. It also focuses of the particular security needs of web applications, and then delves into details of the major security components and how to pull them together into a complete program, with examples built around typical use cases.
    (tags: Security)

links for 2009-07-19

by swjohnson 7/19/2009 5:02:00 PM

Feeds