This seems to come up quite often lately in the press. I think it was Risky Business (ITRadio.com) in a recent interview also covered it. Big Galoot raised it in a previous post.

The kiwis first and now the Aussies also are getting into it: http://www.news.com.au/story/0,23599,22403224-2,00.html

I wonder how someone can definitively state that it was this government or that. Anyone heard of spoofing IP addresses? Was it raised with China at APEC? :-)

Big Galoot sent me the following:

“Organisations that still have the mindset that the enemy they are battling against is mainly organised crime gangs. They’d better face up to the grim reality! Cyber crime is also State-sponsored, which given the resources available to an entire country for this type of activity, raises the stakes massively!”



Tell all your friends….bad things are actually happening on the Internet:

http://www.theregister.co.uk/2007/09/11/online_threat_report/



Not much more I can add; http://www.ipv6porn.com/ (Thanks to Donal for the link).

Other IPv6 posts

Posted in: WTF


There’s plenty you can but this one in regards to policing of Internet predators is well worth the investment.



I’ve added this as a direct response to questions I have received to clarify comments from previous posts. (See link below). I hope this helps but as usual, am open to suggestions, thoughts and criticisms of my take on this.

—————-
If you have already started to head down the PCI compliance path, you know it is a time consuming and costly exercise. If you’re about to, trust me, it is a time consuming and costly exercise. There’s no short cuts. While there are quite a few certified organisations to help you, and to provide required services like quarterly scanning and onsite Audits, you need to be careful when assessing who can actually do a good job. I know this will upset some of the other “certified” guys and some who previously were certified but no longer are, but; there’s a lot of guys out there who really can do you a disservice. We know, because we have seen the results of their work.

Choose Your PCI Auditors Carefully

When looking for a PCI certified organisation (QSA) to assist you, ask the questions. If you are getting quotes from a few parties, ask the question why some quotes maybe double, triple or more the cost of someone else. Understand what it is they are proposing and why – make sure you are comparing apples with apples. Alarm bells should ring if someone quotes you 5 days for an onsite Audit for your complex environment and another party quotes 30 days! Trust me, the latter may be closer to the actual time required to do the job right! The above link highlights the issues and costs you may be faced with later by trying to save a few bucks today.

Some questions to ask QSAs:
- How long have you been involved with PCI DSS work?
- How much PCI work have you done? (Not a big one but worth knowing – some guys have done much less than others but are far better at it!)
- How many experts and certified staff do you have in Australia (add you own country here)? (Many promote their global numbers but that means little here – they are overseas, not here!).
- What background and expertise do your staff have?
- What is your approach to the Audit? Do you just ask questions or do you get down and dirty and test?….and how and to what level?….. get them to explain their methodology! (Many will just interview – for an onsite Audit and to get the assurance you need from a risk perspective, this is just not good enough!)
- Get your best technical guys to pick apart some of the technical areas in the standard and throw some detailed technical questions on encryption and key management (as a couple of examples) at the QSA. You would be surprised how many will be stumped! If they can’t answer the questions, how can you expect them to help you become compliant?
- Company X proposed Y days for the work but you proposed Y/3. How can you do the work in that time and still give us the assurance that you will cover everything?
- And one for the dummy’s – what does “safe harbour” mean?

Obviously you’ll have your own questions also and this is just a start but as I said, the risks to your organisation can be huge if something happens. Don’t get me wrong, even the best guys will never get everything but the bad guys do and will miss the bleeding obvious!



From; Insurance Networking

Am not bagging the study(s) overly but studies like this rarely produce anything new – more just reporting that things on the RM side are getting better. Are they?

Seriously though, aside from individual projects (sometimes), many miss the point. All RM methodologies, practices, processes…whatever you want to call them, fail, if you fail on the first step – understanding what exactly it is you want to manage the risk on? We still haven’t gotten to grips with these basic foundation principles of Risk Management.

See previous post on this; “Risk Management – great in meetings, not so much in practice“.

Posted in: Research, governance


Two high profile cases making the news this week; Bank of India and Monster Breach.

Many more companies hacked or continue to be breached that you’ll not have heard about this week!

You got to love Bruce Schneier’s comment from the Monster article: “You’re going to see this happen again and again and again,” said security analyst Bruce Schneier, chief technologist for BT Counterpane. “I assure you, every other company didn’t say, `Wow, look what happened to Monster, we have to fix our problem.’”



Thanks wade…

We’ll back Wade’s bet and send it out to the first 20 respondees to this post or email to me also.

Clue: It isn’t IPv6.

If you just want the bag, we can organise that also without an answer….not sure how we handle bundles of less 10 but if your company wants their IT staff to look cool/hippy/geek etc….just send me through your details.

Posted in: WTF


How funny is this from MIS Magazine; “Don’t ask, do tell“. Well done to Michael Crawford and the team for writing this up!

You’ve got to love the percentage that were secure (so to speak) in their position. That’s pretty much close the figure that would know! In regards to the dudes who baulked….well we know the good majority have no idea whatsoever, so as we have asked before, why are you even in that role? Yeah, I know that sounds harsh….actually no, it’s pretty much on the ball. Prove me wrong!



Helen Coonan on Labor’s plans – from ZDNet.

You got to love it. The Government that succeeded in keeping us behind the major players in Asia and most of our major trading partners having the hide to bag someone else.

My previous thoughts on this: Who’s kidding who?

Oh, we’re all so concerned now about this aren’t we?!

The horse has bolted guys….let’s get some real discussion on how the country can keep, develop and grow out IT talent and our overall capability here. At present, it’s the old lip service and no more…..lets follow what the latest trend is and what will make us look good in the eyes of the majority of the population who don’t know the true story!



« Newer PostsOlder Posts »