10 Years of Trustworthy Computing at Microsoft
Before joining Microsoft a little bit more than 10 years ago, I ran a team at PricewarehoureCoopers on e-Business Risk Management – classical security consulting in the Internet bubble time. When I announced that I will leave PwC and join Microsoft, I got interesting reactions (and remember, this was 2001). Mainly they were along two lines: Oh, you are joining a desktop company? ...
10 Reasons to migrate off Windows XP
I would like you to sit back, close your eyes and think about the year 2001. Think about how you used technology back then, how you used the Internet. Now, let’s take it a little bit further back in history and think of the year 2000. Just after we realized that the Year-2000-Problem was handled very well by the industry. How you used technology, how you used the Internet, the ...
Office 365 Becomes First and Only Major Cloud Productivity Service to Comply With Leading EU and U.S. Standards for Data Protection and Security
A long title but this was the title of the official press statement yesterday. Compliance is always a key question in the public cloud space. Therefore it is very important for us that we now achieved three things: Office 365 is compliant with EU Model Clauses, Data Processing Agreements and ISO 27001 among other standards. Office 365 is the first and only major ...
Cybersecurity–More than a good headline
A lot of governments all across the globe are working on starting, restarting or pushing their Cybersecurity initiative. What often concerns me is, that the last real headline has more impact on the strategy and the themes to be addressed than a structure or a plan or a strategy.
This made us thinking about what is needed to run a successful Cybersecurity Agenda within a country? What themes ought to be ...
By Roger Halbheer, on April 14th, 2011% This paper by the Geneva Centre for the Democratic Control of Armed Forces (DCAF) was just brought to my attention. A piece of work, which is definitely worth working through. It lays out the problem space and then does a deep dive into the different sections:
Governments Legislative Bodies The Armed Forces Law Enforcement Judges . . . → Read More: Cyber Security: The Road Ahead
By Roger Halbheer, on April 8th, 2011% An interesting article by ISACA: Six predictions for CIOs. Here they are:
Prediction 1: Cloud computing is here to stay and will become business as usual. Prediction 2: Virtualization will be a catalyst that drives IT modernization. Prediction 3: IT operations become service-centric and business value-focused, rather than process-driven and reactive. Prediction 4: Risk management . . . → Read More: Six predictions for CIOs
By Roger Halbheer, on March 31st, 2011% That’s really interesting:
Impressive! Kudos to MIT
Roger
By Roger Halbheer, on March 10th, 2011% FTC released their Consumer Sentinel Network Data Book for January – December 2010. The interesting and scary thing is that fraud via phone is on the raise. We get more and more complaints by customers as well, telling us that they got a call from “Microsoft” with the ask for getting access to the PC . . . → Read More: Fraud via Phone on the Raise
By Roger Halbheer, on January 28th, 2011% There are some high-level indsutry trends, which tend to be ignored by security officers. The CIO Central published an article, which I would even go further looking at the trends raised. . . . → Read More: Are You Focused On The Wrong Security Risks?
By Roger Halbheer, on January 3rd, 2011% Since quite a while, I am saying that targeted attacks are the risks, which really keep me up at night.
BBC just posted a similar article: Cyber-sabotage and espionage top 2011 security fears
I think that this is a real issue and very hard to fight!
Roger
By Roger Halbheer, on October 17th, 2010% As I am still oof, another short one: Ray Ozzie’s blog is back: http://ozzie.net/
Ray is definitely one of the driving persons behind our overall vision and architecture. So, it is worth keeping him on your RSS feed.
Roger
By Roger Halbheer, on September 19th, 2010% I was reading an interesting article: Forrester Pushes ‘Zero Trust’ Model For Security, where they mainly claim that you should not trust your internal network – something I am asking for since a long time. However, the conclusions Forrester and me are drawing are slightly different. John Kindervag – the person quoted in the article . . . → Read More: Is a “Zero-Trust” Model the Silver Bullet?
By Roger Halbheer, on July 15th, 2010% The Department of Homeland Security published a report on A Roadmap for Cybersecurity Research, I was definitely impressed!
All the themes, which are important to me are in their list :
Scalable trustworthy systems (including system architectures and requisite development methodology) Enterprise-level metrics (including measures of overall system trustworthiness) System evaluation life cycle (including approaches . . . → Read More: US Cybersecurity Research!
By Roger Halbheer, on June 26th, 2010% Probably not. However, it indefinitely is a security risk. We are talking about this since a looooooong time as such copiers are sold since 2002. I just recently heard that the criminals are looking into this heavily and now it is even discussed publically on BCS News: Copy Machines, a Security Risk?
Actually a really . . . → Read More: Is a Copy Machine Your Biggest Security Risk?
|
|
|