ISO-27010 – Information Security Guidance for Information Exchange
Our Ethical Hacker Roundup last week included a blurb on stricter laws to protect patient health information (PHI) in Health Information Exchanges (HIEs). That led me to download and read the new...
View Article“Certified” Penetration Testing Company
It’s not uncommon for potential client to ask “Is your company certified to provide Penetration Testing?”. It’s a great question and one that unfortunately does not have a good answer – YET. Via a...
View ArticleISO 27001 to ISO 27003 Standards
Comparing the ISO 27001 Roadmap to the ISO 27003 Guidance for Implementation One of the most frequently asked questions Pivot Point Security gets when speaking with clients about implementing ISO 27001...
View ArticleIs The Motion Picture Industry A Model For Information Security?
I recently had reason to spend some time looking at the “Content Security Best Practices Common Guidelines” published by the Motion Picture Association of America (MPAA). The guidelines are intended to...
View ArticleISO 27001 Scope –“Bigger Isn’t Always Better”
The phrase “Small Is Beautiful” is widely credited to by British economist E. F. Schumacher. It has evolved to champion small, enabling and empowering approaches, , in contrast with phrases such as...
View ArticleRationalizing Risk Assessments – Objectivity be Damned?
Just finished my nth (non-fulfilling) conversation on our approach to Information Security Risk Assessments with our Audit Lead. It still amazes me that something so fundamentally logical/right is so...
View ArticleHITRUST vs. ISO-27001 (or is it?)
The process of “realization” is an interesting one. My first thoughts on HITRUST tended towards the negative; “Why do we need another ISO-27001 derivative information security framework?” “Why not just...
View ArticleWhat McDonald’s Can Teach Us About Information Security
I spoke this week at an event where I was discussing how globalization is impacting information security and used the McDonald’s at the Louvre in Paris as a very sad example of how we are unfortunately...
View ArticleSAS-70 is Dead, Long Live the King (ISO27001?)
This posting is intended for my fellow auditors working in the Fortune 1000 world. The Yankees are no longer winning the World Series every year, Bill Clinton lives in NY not Washington DC, and Y2K is...
View ArticleDon’t Hand Hackers Your LastPass Credentials!
I was just at the recent ShmooCon hacker convention and attended the now well-publicized talk at which security researcher Sean Cassidy unveiled a mirror-perfect phishing attack against leading...
View ArticleOn Pivot Point Security’s 15th Birthday, Sincere Thanks to Our Clients and...
Businesses and children have a lot in common. We love them most of the time, we dislike them on occasion, we are proud of their accomplishments, and we grieve for their struggles. Then we wake up one...
View ArticleGoogle + Dropbox = Simply Secure (We Hope)
Google and Dropbox, with help from the Open Technology Fund, just announced the creation of Simply Secure, an organization/project focused on making everyday security technology easier to use....
View ArticleWhy Personal Health Information is Worth More Off the Black Market than On It
What is the value of information? It can be hard to quantify. Organizations and society at large generally regard information as a commodity and an asset. One classic valuation of information is the...
View ArticleDisruptive Technology: Coming Soon to Your IT Environment
Everywhere you look, technology is changing the game in terms of how businesses have traditionally operated. Lately I’ve been doing a lot of work with organizations in the taxicab industry, which is...
View ArticleHow the Apple and FBI Battle Illustrates the Benefits of a Fully Functioning...
In the last couple of days, the Internet has been in an uproar over a court order compelling Apple computer to assist the FBI with gaining access to an iPhone that was used in the 2015 San Bernardino...
View Article3 Ways that Information Security Differs from IT Security—and Why You Should...
The terms “IT security” and “information security” are widely believed to mean the same thing, and are used synonymously across our industry. But they actually mean different things—and understanding...
View ArticleIs Low-Tech Fraud on your InfoSec Radar?
As businesses invest in more advanced security, cyber criminals are shifting to low-tech attack vectors like social engineering (especially phone fraud), phishing and skimming. Low-tech fraud is any...
View ArticleIs “Information Security” still “Information Security”
I had the opportunity to do a lunch-and-learn with a group of high-level business people who were not directly involved in information technology/information security. I was asked to “highlight the...
View ArticleThe Electricity Subsector Cybersecurity Capability Maturity Model – Is It Too...
The Department of Energy (DOE) recently published The Electricity Subsector Cybersecurity Capability Maturity Model (ES-C2M2), which allows electric utilities and grid operators to assess their cyber...
View ArticleISO-27010 – Information Security Guidance for Information Exchange
Our Ethical Hacker Roundup last week included a blurb on stricter laws to protect patient health information (PHI) in Health Information Exchanges (HIEs). That led me to download and read the new...
View Article