<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Disqus - Latest Comments for disc7</title><link>http://disqus.com/by/disc7/</link><description></description><atom:link href="http://disqus.com/disc7/comments.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Sat, 14 Feb 2015 19:21:19 -0000</lastBuildDate><item><title>Re: Cyber Security safeguard offers much more than just protection</title><link>http://blog.deurainfosec.com/cyber-security-safeguard-offers-much-more-than-just-protection#comment-1855961208</link><description>&lt;p&gt;Once more unto the Breach - Managing information security in an uncertain world: &lt;a href="http://affiliate.itgovernance.co.uk/idevaffiliate.php?id=7777&amp;amp;url=148" rel="nofollow noopener" target="_blank" title="http://affiliate.itgovernance.co.uk/idevaffiliate.php?id=7777&amp;amp;url=148"&gt;http://affiliate.itgovernan...&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Sat, 14 Feb 2015 19:21:19 -0000</pubDate></item><item><title>Re: DISC InfoSec FB Page</title><link>http://blog.deurainfosec.com/disc-infosec-fb-page#comment-1842833848</link><description>&lt;p&gt;Cyber Security&lt;br&gt; Books: &lt;a href="http://bit.ly/1vCx39F" rel="nofollow noopener" target="_blank" title="http://bit.ly/1vCx39F"&gt;http://bit.ly/1vCx39F&lt;/a&gt; &lt;br&gt; Satndards: &lt;a href="http://bit.ly/1DbERVN" rel="nofollow noopener" target="_blank" title="http://bit.ly/1DbERVN"&gt;http://bit.ly/1DbERVN&lt;/a&gt; &lt;br&gt; Toolkit: &lt;a href="http://bit.ly/1BelHPT" rel="nofollow noopener" target="_blank" title="http://bit.ly/1BelHPT"&gt;http://bit.ly/1BelHPT&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Sun, 08 Feb 2015 20:14:38 -0000</pubDate></item><item><title>Re: ISO 27001 is the litmus test for information security</title><link>http://blogs.computerworld.com/saas/21379/iso-27001-%E2%80%93-litmus-test-information-security#comment-772051289</link><description>&lt;p&gt;Interesting discussion about FedRAMP though.&lt;br&gt;Whatever I know about the FedRAMP so far is very interesting and intriguing.  The core of FedRAMP is based on conformity assessment (where you measure the effectiveness of the control in this case NIST 800-53) which is based on ISO 17000. I briefly saw the CONOPS document which follow pretty much the same steps as ISO 27001 requirement (scope, assets boundaries, risk acceptance, risk assessment (SAR),  document the as-is control in gap assessment, plan to implement new controls, continuous monitoring of controls (based on Deming PDCA model), the most important is 3PAO which is core of ISO 27001 certification).&lt;/p&gt;&lt;p&gt;Since both ISO 27001 and FedRAMP follow the similar steps. below is the post on project planning outline for ISO 27001 and how to select a project manager.&lt;br&gt;&lt;a href="http://blog.deurainfosec.com/project-planning-outline-for-iso-27001-isms" rel="nofollow noopener" target="_blank" title="http://blog.deurainfosec.com/project-planning-outline-for-iso-27001-isms"&gt;http://blog.deurainfosec.co...&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Fri, 18 Jan 2013 15:29:06 -0000</pubDate></item><item><title>Re: 5 Essentials changes to harden Network Infrastructure</title><link>http://blog.deurainfosec.com/5-essentials-changes-to-harden-network-infrastructure#comment-768878614</link><description>&lt;p&gt;Will it help L2 dos attck if you disable icmp?&lt;/p&gt;&lt;p&gt;ICMP is usually used for network troubleshooting at layer3, which&lt;br&gt;can be used for ddos attacks from  outside. So I will say ICMP is a&lt;br&gt;necessary evil so enable it when you need it otherwise it should remain&lt;br&gt;disable.&lt;br&gt;·        &lt;br&gt;ARP and ICMP is layer 3 - Network Layer.&lt;/p&gt;&lt;p&gt;Layer 2 is Ethernet, PPP, HDLC, DSL, Frames, Network Switching, CAM table, MAC&lt;br&gt;address ...&lt;/p&gt;&lt;p&gt;So icmp ddos attack is possible only at L3 since it is a L3 protocol. Ex of L2&lt;br&gt;ddos attacks are manipulation of wireless frame content or Cam table overflow.&lt;br&gt;Therefore I agree by disabling icmp will not help L2 dos attacks.&lt;/p&gt;&lt;p&gt;A layer2 attack is hard to achieve from&lt;br&gt;the outside world, The effect of a DOS attack on L2 takes another dimension as&lt;br&gt;the Bandwidth is considerably higher.&lt;/p&gt;&lt;p&gt;Ex: L2 use CAM table overflow attack.&lt;br&gt;Content-Addressable Memory (CAM) (ARP)table address-learning process&lt;/p&gt;&lt;p&gt;Countermeasure: Limit amount of MAC addresses to be learned / port&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Tue, 15 Jan 2013 12:17:01 -0000</pubDate></item><item><title>Re: ISO 27001 is the litmus test for information security</title><link>http://blogs.computerworld.com/saas/21379/iso-27001-%E2%80%93-litmus-test-information-security#comment-755937930</link><description>&lt;p&gt;I concur that ISMS based on ISO 27001 is a litmus test for an organization by an independent certification body. During this process organization finds out as-is state of security, which threats may pose risk and what is their security strategy. Post below describes the six main benefits of ISMS based on ISO 27001 to clarify the point.&lt;br&gt;&lt;a href="http://blog.deurainfosec.com/six-main-benefits-of-information-security-management-system" rel="nofollow noopener" target="_blank" title="http://blog.deurainfosec.com/six-main-benefits-of-information-security-management-system"&gt;http://blog.deurainfosec.co...&lt;/a&gt; &lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Fri, 04 Jan 2013 15:08:10 -0000</pubDate></item><item><title>Re: Make October YOUR Cyber Security Month</title><link>http://blog.deurainfosec.com/make-october-your-cyber-security-month#comment-679516819</link><description>&lt;p&gt;Unfortunately, fraud is common on the web these days, it's not a matter of if but when. So awareness is the key,  which will prepare an individual or an organizatoion  for any event or an incident. I encourage the reader to share a useful link or make a comment to do their part in this security awareness month.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Thu, 11 Oct 2012 23:40:33 -0000</pubDate></item><item><title>Re: Six main benefits of Information Security Management System</title><link>http://blog.deurainfosec.com/six-main-benefits-of-information-security-management-system#comment-620304701</link><description>&lt;p&gt;&lt;br&gt;　&lt;br&gt;ISMS is a part of doing business these days, soon your management will realize the importance of ISMS or one of your most importnant customer/vendor will ask you to have one. ISMS provides better information security and compliance work practices that support business goals &amp;amp; it is an Internationally recognized good security practice period.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Wed, 15 Aug 2012 15:02:27 -0000</pubDate></item><item><title>Re: Top 10 Cyber Scams During Holiday Season</title><link>http://blog.deurainfosec.com/top-10-cyber-scams-during-holiday-season#comment-363856675</link><description>&lt;p&gt;The human link: There is an ever-widening disparity between the sophistication of a network and the people who use them. Cybercriminals often use social engineering toolkits to exploit unsuspecting employees when direct attacks on an organization's defenses fail. Educating employees on secure practices is not enough; organizations need to install the proper framework to empower and encourage employees to use these secure practices. &lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Tue, 15 Nov 2011 13:18:01 -0000</pubDate></item><item><title>Re: Cloud services breached via Google code search</title><link>http://blog.deurainfosec.com/cloud-services-breached-via-google-code-search#comment-361349070</link><description>&lt;p&gt;Thanks for an informative comment&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Fri, 11 Nov 2011 16:17:41 -0000</pubDate></item><item><title>Re: Ghost in the Wires: My Adventures as the World&amp;#8217;s Most Wanted Hacker by Kevin Mitnick</title><link>http://blog.deurainfosec.com/ghost-in-the-wires-my-adventures-as-the-worlds-most-wanted-hacker-by-kevin-mitnick#comment-355215049</link><description>&lt;p&gt;Fascinating read to overview of what really happened during Mitnick era of hacking and how he was able to wreak a havoc and get away with it for quite some time.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Thu, 03 Nov 2011 19:28:07 -0000</pubDate></item><item><title>Re: A guide to contract and commercial management for professionals</title><link>http://blog.deurainfosec.com/a-guide-to-contract-and-commercial-management-for-professionals#comment-347126733</link><description>&lt;p&gt;This authoritative guide represents the collective expertise of some the globes most experienced organizations and is specifically designed for business managers to understand the benefits that can be achieved; including:&lt;br&gt;•       A complete Reference Guide for all involved with Contract and Commercial management.&lt;br&gt;•       Practical guidance and checklists.&lt;br&gt;•       Aligns with the IACCM qualification and training.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Thu, 27 Oct 2011 12:14:54 -0000</pubDate></item><item><title>Re: The End of Online Privacy? Fight the Internet Snooping Bill!</title><link>http://blog.deurainfosec.com/the-end-of-online-privacy-fight-the-internet-snooping-bill#comment-285634186</link><description>&lt;p&gt;Must watch, if you care about your privacy.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Sat, 13 Aug 2011 15:51:18 -0000</pubDate></item><item><title>Re: Latest In U.S. Drone Technology</title><link>http://blog.deurainfosec.com/latest-in-u-s-drone-technology-2#comment-262648210</link><description>&lt;p&gt;Apparently a heavy investment in the drone (UAV) technology – UAV perhaps are becoming a weapon of choice and can be utilized anytime and anywhere – sounds like a technology from an outer space in which someone is pressing a button from thousands of miles away – Well UAV are used sometimes for surveillance but let’s be real they are also use to kill people who may be innocent. Remeber in US justice system you are innocent until proven guilty.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Sun, 24 Jul 2011 01:18:42 -0000</pubDate></item><item><title>Re: The TickITplus Kick Start Guide has Been Launched</title><link>http://blog.deurainfosec.com/the-tickitplus-kick-start-guide-has-been-launched#comment-252842138</link><description>&lt;p&gt;&lt;br&gt;Existing TickIT-registered organisations will need to make a transition to the new TickITplus Foundation level within the next three years. &lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Fri, 15 Jul 2011 12:51:56 -0000</pubDate></item><item><title>Re: Do US companies do enough for their cyber security?</title><link>http://blog.deurainfosec.com/do-us-companies-do-enough-for-their-cyber-security#comment-251822691</link><description>&lt;p&gt;Don't forget to download a free cyber security white paper from ITG website&lt;/p&gt;&lt;p&gt;What do you think - are US companies doing enough for their cyber security?&lt;/p&gt;&lt;p&gt;If they are not doing enough - do you think they should be held liable for the loses in case of an incident.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Thu, 14 Jul 2011 01:12:02 -0000</pubDate></item><item><title>Re: Newly released ISO/IEC 27005:2011 helps improve risk management</title><link>http://blog.deurainfosec.com/newly-released-isoiec-270052011-helps-improve-risk-management#comment-245275264</link><description>&lt;p&gt;Read a copy of newly released ISO 27005:2011 which addresses Information Security Risk&lt;br&gt;Management for ISMS certification and annex E gives a good oversight of different risk assessment approaches.&lt;/p&gt;&lt;p&gt;ISO 27005 is the name of the prime 27000 series standard covering information security risk management. The standard provides guidelines for information security risk management (ISRM) in an organization, specifically supporting the requirements of an information security management system defined by ISO 27001.&lt;/p&gt;&lt;p&gt;The ISO 27005 standard comprises 55 pages, although the main part is just 24 pages, the rest being mostly annexes with examples and further information for users and is applicable to all types of organization. It does not provide or recommend a specific methodology and the standard deliberately remains agnostic about quantitative and qualitative risk assessment. This will depend upon a number of factors, such as the actual scope of the Information Security Management System (ISMS), or perhaps the industry/commercial/private/Govt sector.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Thu, 07 Jul 2011 14:42:40 -0000</pubDate></item><item><title>Re: InfraGard Insights: Separation of Duties and&amp;#8230;</title><link>http://blog.deurainfosec.com/infragard-insights-separation-of-duties-and#comment-238401724</link><description>&lt;p&gt;I must say priciple of least privilege and separation of duties are two very high priority security principles.&lt;/p&gt;&lt;p&gt;Here are some more&lt;br&gt;-- Economy of mechanism&lt;br&gt;-- Complete Mediation&lt;br&gt;-- Open Design&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Wed, 29 Jun 2011 22:55:32 -0000</pubDate></item><item><title>Re: The weakest link in computer hacking?</title><link>http://blog.deurainfosec.com/the-weakest-link-in-computer-hacking#comment-238219189</link><description>&lt;p&gt;"There’s no device known to mankind that will prevent people from being idiots"&lt;/p&gt;&lt;p&gt;Human factor is the weakest link most of the time but at the same time it is the job of security and privacy professional to train the masses and change their behavioral pattern. The security control applies to people, process and technology. The technology control are not the panacea for everything - it should be holistic approach which cover the policies and procedures and making sure these controls are implemented and observed.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Wed, 29 Jun 2011 17:54:44 -0000</pubDate></item><item><title>Re: Meet Stringent California Information Security Legislation with Comprehensive Toolkit</title><link>http://blog.deurainfosec.com/meet-stringent-california-information-security-legislation-with-comprehensive-toolkit#comment-234749583</link><description>&lt;p&gt;Thanks for your kind comments on my blog.  I’m passionate about ISO standards as well, particularly ISO27k.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Sat, 25 Jun 2011 12:23:17 -0000</pubDate></item><item><title>Re: How safe is your personal information on social network?</title><link>http://blog.deurainfosec.com/how-safe-is-your-personal-information-on-social-network#comment-234553995</link><description>&lt;p&gt;Think of a scial network as public place - if you don't want some thing to become a public knowledge, don't put it on the social network sites. &lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Sat, 25 Jun 2011 02:05:39 -0000</pubDate></item><item><title>Re: President lays out cyberwar guidelines, report says</title><link>http://blog.deurainfosec.com/president-lays-out-cyberwar-guidelines-report-says#comment-233920091</link><description>&lt;p&gt;The cyber war is definitely getting some traction – cyber war policy guidelines seems like a reaction to high profile incidents in last few months. In information security arena you win the race when you are proactive NOT reactive. Strategically every nation understand that cyber war is a tool which can have more wide spread effects than a daisy cutter.&lt;br&gt;Strategically every nation understand that cyber war is a tool which can have more wide spread effects than a daisy cutter.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Fri, 24 Jun 2011 00:02:38 -0000</pubDate></item><item><title>Re: LULZ Security Hacks CIA Website!</title><link>http://blog.deurainfosec.com/lulz-security-hacks-cia-website#comment-227479566</link><description>&lt;p&gt;A denial of service attack, like that which appears to have hit the CIA website, is against the law.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Thu, 16 Jun 2011 13:56:17 -0000</pubDate></item><item><title>Re: Hacker Groups Attacks US Senate WebSite</title><link>http://blog.deurainfosec.com/hacker-groups-attacks-us-senate-website#comment-226402859</link><description>&lt;p&gt;Senators may need to be transparent with public otherwise hackers may post their official records, perhaps a new form of transparent government&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Wed, 15 Jun 2011 10:10:35 -0000</pubDate></item><item><title>Re: Hacker Groups Attacks US Senate WebSite</title><link>http://blog.deurainfosec.com/hacker-groups-attacks-us-senate-website#comment-226391709</link><description>&lt;p&gt;Hack attacks are definitely on the rise these days. Below is the latest high profile list which includes&lt;br&gt;Google, Citi Bank, Lockheed Martin, Sony, FBI and US Senate&lt;br&gt;Some of these assets are critical infrastructure which is a growing threat to national security.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Wed, 15 Jun 2011 09:47:06 -0000</pubDate></item><item><title>Re: Credit card authorization process weakness</title><link>http://blog.deurainfosec.com/credit-card-authorization-process-weakness#comment-225890030</link><description>&lt;p&gt;I agree with you that credit card providers will reimburse the fraudulent charges but ultimately this cost is transfered to acquiring bank and rest of the credit card users community.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">disc7</dc:creator><pubDate>Tue, 14 Jun 2011 15:38:49 -0000</pubDate></item></channel></rss>