Home » Archive

Articles tagged with: security

Alerts, headline »

[8 Nov 2010 | | ]
Things are a changing at RetailInfoSec

Good morning (or whatever it is where you are)!
I’m putting up this post to let everyone know that the blog is going to be changing very shortly - I’m continuing to do a lot of work with leading retailers on information security initiatives and I’m still paying close attention to retail and payments security, but I’m discovering that some other areas of the business world are also starting to become a large part of my daily work life.
As I grow my involvement in these other areas of business (including the …

Interesting, Retailers, application security »

[3 Sep 2010 | | ]

I’ve been traveling a lot lately and, although I’ve read and had lots of commentary about a number of blog posts and news article recently relating to retail security, I haven’t had the time to write them down and post them…
So I’ve decided that I’m going to post a summary of the posts and articles that I’ve read over the last week or so that I’ve thought were interesting and relevant.  This isn’t what I’d really prefer to do - I’d much rather take the opportunity to rant about something …

Interesting, application security, featured »

[25 Aug 2010 | | ]
Some Security Metrics Education

Short post here, but things always seem to happen in groups, so I thought I’d make everyone aware of a couple of current and upcoming opportunities to dig into a very important topic (particularly during budget season) - Security Metrics.
NetSPI is putting on a webinar tomorrow (Thursday, Aug 26th) with Symantec - here’s the info/sign-up page on their website (full disclosure, if you don’t know by now I work for NetSPI):
Application Security - without metrics it doesn’t exist
And I got the August issue of The ISSA Journal yesterday and the …

PCI News, Vendors, application security, headline »

[25 Aug 2010 | | ]
VISA Provides Guidance on Secure Implementation and Management of Payment Applications

I walked into the office this morning and got this in my RSS feed aggregator:
VISA Provides Guidance on Secure Implementation and Management of Payment Applications [link]
After taking a look at the press release and looking through the actual document that VISA (and SANS apparently) produced [link] I think it’s a pretty interesting move on the part of VISA.  If you haven’t yet taken a look and you work for a retailer or a software vendor that sells to the retail space, I’d advise downloading the …

Interesting, featured »

[15 Jun 2010 | | ]
Firewall Security - a short article and comment

This morning I read the short article that I link to below.  It’s focused on firewall management and review which is a topic that I think many retail and hospitality organizations should be paying more attention to.
The study in the article was sponsored by a vendor that provides firewall management solutions (go figure), but it doesn’t mean that the message isn’t an important one - firewalls are easy to forget about once you
have them in place and (particularly in retail and hospitality) there are so many things that your network …

Alerts, Interesting, PCI News, Retailers, Vendors, featured »

[2 Jun 2010 | | ]
Additional Information About That Potential Lawsuit

After posting about the press release regarding the potential lawsuit (here) I got an email from the PR firm that had sent the release out.  He, in turn, connected me to Charles Hoff - the attorney for the retailer that is considering the suit, Brew HaHa!.  We had a very interesting conversation and, not being a lawyer, I’m not going to make any comments about the merits of any lawsuit that may or may not come from this episode, but, as I said, the conversation was interesting and this is …

PCI News, featured »

[6 Jan 2010 | | ]
So….. it’s been awhile……

I haven’t posted anything forever!!!
Bad Alex!
Well, I’m heading out to another NRF this weekend and I promise that I’ll post something either from the show or shortly thereafter.  It might have something to do with how poorly security is represented at the show (other than at least 25 ‘Instant PCI’ offerings and Trustwave throwing money around…), but we’ll see.
If anyone out there is actually going to be at NRF and is interested in connecting, please let me know - alex.crittenden@yahoo.com - and we’ll figure something out.
Thanks and Happy New Year!
Related …

Vendors, application security, featured »

[10 Nov 2009 | | ]
SharePoint and Security

Image by Wonderlane via Flickr

With the Microsoft SharePoint conference having recently taken place, I have been thinking a lot about SharePoint lately (haven’t you?) and about what a powerful and dangerous tool it can be.

Before I get into what I’ve been thinking about, here are a few things to consider:

A Microsoft employee recently told me that SharePoint has been the most rapidly adopted product in Microsoft’s history. While I haven’t been able to confirm this, it doesn’t really matter - what matters is, it’s everywhere and it …

Conferences / Webinars, PCI Philosophy / Approach, featured »

[23 Oct 2009 | | ]
Beyond the PCI Audit:  Helping Merchants and Service Providers as a Partner

OK - this is the feedback on the Community Meeting that I had mentioned although it really turned into a philosophical post about what your PCI partners should really be doing for you (hint: being a partner).
This one’s over at the NetSPI blog as well (I swear that I’m still going to be posting over here on a more regular basis, but, since NetSPI’s doing a good job with the blog, I’m going to blend my posts between the two blogs…).  Any feedback is going to have to come here, …

Conferences / Webinars, Interesting »

[9 Sep 2009 | | ]

Thanks to David Bryan for getting these up!  Here’s another video from the event - this one is the presentation on OpenSAMM - interesting and also very much geared towards development of security applications.  I think this is a great approach, but I have to admit that the practicality is something that I wonder about…

Pravir Chandra: Software Assurance Maturity Model (OpenSAMM) from David Bryan on Vimeo.