jump to navigation

Chris Mark in July 2014 of TransactionWorld (Proximate Reality) July 1, 2014

Posted by Chris Mark in cybersecurity.
Tags: , , , , , , ,
2 comments

july coverJuly’s issue of TransactionWorld Magazine was just released.  Click here to read my latest article, “Understanding Proximate Reality to Improve Security”  Here is a preview..

“Various reports are published annually that analyze data breaches, opine on the root causes of the data theft and frequently ascribe blame to one party or another. It always invites scrutiny when a well-known security firm or analyst makes a definitive statement such as “X% of breaches could have been prevented through the implementation of basic controls, such as patching.” 

This position is not only inconsistent with accepted risk management practices, but also confuses the basic concepts of correlation and causation while ignoring the very human element of adaptation. Unfortunately, companies that subscribe to these simplistic views of the industry and threats are exposing themselves to very real dangers. As supported by the increasing number of breaches identified each year, information security is no longer a domain for amateurs and requires the application of lessons learned from domains such as intelligence, anti-terrorism, and decision science to make effective decisions.

Two important concepts borrowed from the intelligence and anti-terrorism domains can be used to help CSOs and others make relevant decisions related to their risk posture and other aspects of data security. These concepts are known as Proximate Reality and Adaptive Threats.”  Read More!

Now Open! Vets4InfoSec.com Online Community for Vets Interested in InfoSec June 30, 2014

Posted by Chris Mark in Uncategorized.
Tags: , , , , , , , , , ,
add a comment

iStock_000016696389XSmallA few weeks ago I put up a Facebook page for Veterans who may be interested learning more about Information Security.  The response was much greater than I had expected.  In response, I have setup an online community for Veterans interested in learning more about the field.  You can join at www.Vets4InfoSec.com  for FREE!…The objective of the group is to provide a forum for education, discussion, and networking for veterans and current service members who are interested in transitioning or simply wanting to learn more about information security.  If you are not a service member or veteran and want to help contribute to the body of knowledge and provide expertise, please feel free to join, as well.    A number of veterans have made the leap from military to InfoSec.  The current head of the PCI SSC is a Former Marine Grunt!…I am a former Grunt and a number of other folks have moved over… It is a great career and something that is well positioned for military members to have success.

Norse- Live Cyber Threat Intelligence (very cool!) June 24, 2014

Posted by Chris Mark in Uncategorized.
Tags: , , , , , , ,
add a comment

I have been thinking about a topic on which to write.  I recently ran across this company called Norse and was impressed by the live cyber intelligence Norse provides.  Please checkout their website…as stated: “Every second, Norse collects and analyzes live threat intelligence from darknets in hundreds of locations in over 40 countries. The attacks shown are based on a small subset of live flows against the Norse honeypot infrastructure, representing actual worldwide cyber attacks by bad actors. At a glance, one can see which countries are aggressors or targets at the moment, using which type of attacks (services-ports). “…forgive the language but this is…badass!

NORSE

%d bloggers like this: