Gearing Towards Your Next Audit – Understanding the Difference Between Best Practice Frameworks and Regulatory Compliance Standards

Security configuration management (SCM) can help organizations do much more than just harden their attack surfaces against intrusions. This fundamental control also has the ability to make your audits flow more smoothly. Indeed, it allows organizations… Continue reading Gearing Towards Your Next Audit – Understanding the Difference Between Best Practice Frameworks and Regulatory Compliance Standards

Does PHP Have A Future, Or Are Twenty Five Years Enough?

In June, 1995, Rasmus Lerdorf made an announcement on a Usenet group. You can still read it.

Announcing the Personal Home Page Tools (PHP Tools) version 1.0.

These tools are a set of small tight cgi binaries written in C.

Today, twenty five years on, PHP is about as ubiquitous …read more

Continue reading Does PHP Have A Future, Or Are Twenty Five Years Enough?

Cybersecurity Frameworks in Healthcare (And How to Adopt Them)

The post Cybersecurity Frameworks in Healthcare (And How to Adopt Them) appeared first on CCSI.
The post Cybersecurity Frameworks in Healthcare (And How to Adopt Them) appeared first on Security Boulevard.
Continue reading Cybersecurity Frameworks in Healthcare (And How to Adopt Them)

2020 Update

Here we are in 2020, and there are many updates to go over.  I plan on further postings on several of these items, and need to get back into blogging here with more regularity.
Here are some of the new things that are out.
CCPA.  Privacy as a… Continue reading 2020 Update

2019 Update on frameworks, standards, and regulations for infosec

At the 2019 BSides Tampa Security conference I did a talk on 2019 Updates on frameworks, standards, and regulations for infosec.  Over the last year several new and updated frameworks and regulations have come out, as well as are being updated.
Mo… Continue reading 2019 Update on frameworks, standards, and regulations for infosec

2018 NIST Cybersecurity Risk Management Conference

Back in October I was in Baltimore for NIST’s 2018 Cybersecurity Risk Management Conference.  For those not aware, let me break this down.  NIST is the National Institute of Standards and Technology, a non-regulatory research arm of the Depar… Continue reading 2018 NIST Cybersecurity Risk Management Conference

Framework/standard updates coming

Well, it’s early 2018 and there are several information security framework/standards being updated:

NIST CSF v1.1.  The second draft was released at the end of 2017, and we just wrapped up the comment period on this.  I believe the plans ar… Continue reading Framework/standard updates coming