Thursday | 20 November, 2008
CSO

Stories by: Mathias Thurman

  • +

    When a go-to guy takes a holiday 14/03/2007 11:47:12

    I'm sure many of you can relate when I say that a company with a single point of failure is primed for disaster. Sadly, there's one in my department.
  • +

    These rules will keep users in their place 26/04/2006 15:11:13

    As information security professionals, we tend to throw around certain terms when we talk about how information security should be implemented. Lately, when I've gone to meetings or written an e-mail that gives me a chance to evangelize about our security needs, my terms of preference have been "rule of least privilege" and "separation of duties."
  • +

    Deciphering options for laptop encryption 06/12/2005 14:15:57

    During the past two weeks, I started up a disk encryption project, one of the technology initiatives under my company's intellectual asset protection program.
  • +

    IDS pays off, even if there's no hacking 12/07/2005 10:15:28

    When I came into work after the weekend, a very interesting e-mail message was waiting for me. The message, with the subject line "Account Alert," appeared to be from our help desk. It requested that I read an attached document pertaining to my user account.
  • +

    Protecting the crown jewels 01/06/2005 12:10:32

    You would probably imagine that a company that writes and sells software would make the protection of that software paramount. That's why it's hard to believe that my company has implemented no comprehensive efforts to prevent its bread-and-butter software falling into the wrong hands.
  • +

    VPN evolution progressing to SSL 30/11/2004 14:49:51

    For several years, my company used Microsoft's Point-to-Point Tunneling Protocol (PPTP) to provide remote users with VPN access to corporate resources. This worked well, and almost all employees who had PPTP permissions were comfortable with this method. But after several security problems with PPTP were reported, we decided about a year ago to deploy virtual private network concentrators from Cisco Systems at all of our core points of presence.
  • +

    Single sign-on effort falls short 16/12/2003 09:19:30

    Just when I thought we had solved one set of IT security problems by getting the human resources department to properly train new hires, another has cropped up with our IT team and a new single sign-on system it has deployed. The system was designed without input from the IT security team and at least one other department that will be affected. Now we're dealing with the issues after the fact.
  • +

    OPINION: Merger Blows Out Security Walls 25/10/2002 11:48:14

    When recent acquisitions wreak havoc on Mathias' intrusion detection infrastructure, Tripwire serves as a backup measure.
Additional Resources
Newsletter Subscription
Sign up for our CSO Online newsletters!
RSS Feeds
ARN Polls

Is your company prepared for a cyber attack?

Yes
No
View Results
 
Sponsored Links