The latest version of the NIST Cybersecurity Framework was created in April of 2018. It is comprised of 108 requirements, and one notable addition are 5 requirements to evaluate Technology Supply Chain Risk.
Read moreThe past 5 years or so have brought many Managed Security Services Provider (MSSP) offerings into the market place. Here is how to evaluate what a provider is going to do and whether it fits your needs.
Read moreThere is a common phrase that attempts to get “Everyone on Board”: “Something” is Everyone’s Job. Cybersecurity is NOT Everyone’s Job. Someone needs to own it.
Read moreI have been to many corners of the IT Security world. Operations, Audit, Penetration Tester, Risk, Enterprise, SMB, Federal. Here is why I refuse to sell with FUD.
Read moreOver the past thirty years of the modern era of IT Security many things have changed, but the basic tenets have stayed the same. One subject that tends to be overlooked is the use of a framework.
Read more