You can't secure what you don't acknowledge.SM

Thursday, February 17, 2011

Are you focusing on the infosec basics where it counts?

Here's a good read from @arstechnica on the HBGary story. It's a fascinating story in and of itself. But the oversights related to information security "best practices" is amazing.

What is it going to take to get people to focus on the basics? Seriously, folks...Forget about all the fancy hack attacks and complex exploits for now and fix the low-hanging fruit. It's basic triage - stop the bleeding first. Focus on your highest payoff tasks and work your way down the list.

All things considered, by just focusing on the basics of information security controls and testing alone you can achieve top-notch security, relatively speaking, which is light years ahead of where most organizations are today.

No comments:

Post a Comment