-
What is "responsible disclosure"?
Back in 2009 I wrote a blog post about vulnerability disclosure. It's interesting reading the post four years later, looking at things that have happened at places I've worked, vulnerabilities I've reported personally or watched others submit.
15 Feb / CSO Bloggers -
CREST Australia - why accreditation is a good thing
The security industry seems to be broadly polarised by the Attorney-General's recent announcement of the formation of CREST Australia (Council of Registered Ethical Security Testers). For those who have not kept pace with this piece of news, CREST Australia has been chartered by the AG's office to certify the competency of penetration testers within Australia. Now, I've spoken with quite a few people and I am quite surprised at the variety of responses—particularly from people I would have expected to endorse it.
22 May / CSO Bloggers -
The Erosion of Privacy
"If a nation values anything more than freedom, it will lose its freedom: and the irony of it is that if it is comfort or money that it values more, it will lose that, too." -- William Somerset Maugham
7 Mar / CSO Bloggers
-
CSO Bloggers
Coming soon....
- 1
The new IAM: nailing shut the door on the Trojan horse
- 2
Despite $1.46b furphy, 2013-14 Budget offers slim pickings for cyber security
- 3
VMWare wants software defined data centres for better security
- 4
iiNet’s Web analytics delivers real-time security bonus
- 5
Security a key factor in LogMeIn’s Internet of Things platform
-
Splunk Named a Leader in Gartner Magic Quadrant for SIEM
-
Dell Sets Sights on Cisco, Announces Game-Changing NSA Series That Introduces Powerful Next-Gen Firewall Advances for Mid-sized Businesses and Distributed Enterprises
-
Silver Peak saves Riverbed customers up to 86 per cent with software upgrade program
-
Ovum analysis ranks Orange Business Services ahead of APAC competition for service capability and strategy
-
2013 Brightcove Innovation Award Winners Announced at PLAY 2013 Global Customer Conference
- FTSnr Web Developer PHP/Magento/API integration into E-commerce sites. $100k+SuperNSW
- FTOS Web Applications DeveloperNSW
- FTTest Analyst (MS Environment) .netNSW
- FTWeb Developer- Drupal and PHP. Exciting new position- #2 in Dev team.$100k+SuperNSW
- FTSenior Python Web Applications DeveloperNSW
- FTQuality ManagerSA
- FT.NET - Sitecore Developer - Melbourne - PermNSW
- FTSenior E-Commerce PHP Developer- North Sydney- E-commerce Software $110kNSW
- FTSenior Python DeveloperNSW
- FTSenior Projects EngineerNSW
- FTTest Manager - IMMEDIATE STARTNSW
- FTLead Software EngineerSA
- FTTechnical Account Manager - MSP + CloudVIC
- FTSenior Field Engineer - MSNSW
- FTTest Analyst (MS Environment) .netNSW
- FTR&D EngineerSA
- FTSenior Python DeveloperNSW
- FTTest EngineerVIC
Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).
- Have an incident response plan.
- Pre-define your incident response team
- Define your approach: watch and learn or contain and recover.
- Pre-distribute call cards.
- Forensic and incident response data capture.
- Get your users on-side.
- Know how to report crimes and engage law enforcement.
- Practice makes perfect.
Warning: Tips for secure mobile holiday shopping
I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.










