Showing posts with label blogging. Show all posts
Showing posts with label blogging. Show all posts

Monday, February 2, 2009

Sometimes a piece of bread is just a piece of bread

I really like Andy the IT Guy but sometimes he goes overboard...

Andy the IT Guy is, of all the bloggers I read, the most practical. He isn't an analyst like the Securosis guys or a salesperson like most of the others. Or a ninja-type like the Hoff. He is a hands-on security person. Like me.

I find sometimes, I will be sitting in the traffic or walking down the street or shopping or whatever and thinking "there must be some Information Security parallel to this" and I get ready to blog about whatever it was. You can equate just about everything with Information Security. I'm sure that bloggers of all types go around thinking "...ooo..must blog about that..". There should be a support group. Maybe there is. Maybe it has a blog. I hope not.

By the way, Andy's advice about Information becoming "mixed" is really good advice and all companies should take note. I am about to start an Information Classification program and I shudder to think what it is that I will find. If everything was done right from the beginning ("pffft...") then it would be a simple thing to perform.

Andy, I totally agree with your observation, mate. But, sometimes just switch off and enjoy your breakfast. Even if it does taste slightly generic. I could use my own advice too. Maybe we should just give in to the addiction...

Now, what do fishpaste sandwiches have to do with Information Security? They smell funny but they are really good for you? Hmmmm....

Friday, December 12, 2008

Advert

Hi,

My Blog runs on Blogspot which is a free service but I am currently paying for my homepage and assorted other internet services.

These come to about R200 ($20) a month and I figured that I'd use my blog to generate some of that.

So, I have added an advert at the bottom of this Blog. I hope it is out of the way enough that it doesn't distract from the Blog message. I may add an advert along the side of the Blog too.

Hopefully these will bring in some money to make my online life a little cheaper. I hope noone feels offended and I'd love to have no advertising but it seems that I need to sell out to The Man.

Thursday, January 17, 2008

2007

I have been trying to get the motivation together to blog about my predictions for 2008 but I'm not finding it. So, I've decided to break it up into smaller pieces and hopefully that will make it easier.

So, looking back...

2007 started with me being very motivated, excited and happy. It was going to be a great year with lots of promise. It ended with me feeling very down, de-motivated and depressed. But I am still optimistic for 2008 which either means I am hard to get down or just really naive. I guess time will tell.

My first prediction for 2008 is that I will be a very different person by this time next year. And I will be sitting in a very different place. If I am not - I will have failed.

I don't like to get too much into the personal aspects of my job but a lot of the energy I put into getting security to move forward has been in vain and I am feeling that I am now wasting my time trying to move forward. I have put myself into "cruise" mode while I work behind the scenes to improve myself and then with a big bang I'll be back.

There were some some really excellent moments in 2007. I think that the most important was when I started my blog. I highly recommend blogger. I also recommend feedburner. Both companies are owned by the big G.

A big thank you goes out to Alan from Still Secure who got me motivated and introduced me to the Security Bloggers Network.

While it helps that I am a member of the network and that drives some views to my blog, it has helped me more to explore and find people on the network. I have been able to populate my RSS feed list from a number of bloggers and I hope to add more. I just need the time.

So, who is honoured to be in my RSS feed?

First up is my brother-from-another-mother - Andy the IT guy. I call him that because he has a very similar job, a wife and two daughters and he has had a very similar career path to me. More importantly, I usually see eye-to-eye with him.

Next up is "Security Mike" - Mike Rothman. The daily incite is an amazing tool to get an idea of what is happening in the security blog world. How Mike can read so much still amazes me. One day I'll have saved up enough. The new Audio is also worthwhile.

Next is (this is the order I read my blogs in - obviously I'd want to get the best first) the Mogull. One can see from his postings just how much research he has done into the security field. They are well written and very useful.

Just as wordy and usually more fun is the Hoff. The Hoff is worth reading because of how he pushes the boundaries of what security (or survivability) is all about. He does not pull his punches and is not afraid to sacrifice a few sacred cows along the way.

There are other bloggers that I respect and read too - Anton Chuvakin, Randy Armknecht, Richard Bejtlich, etc etc

I think that the best part of reading all of the above blogs is that the authors all read each others blogs too. This leads to debates, arguments but hopefully lessons learned.

2007 was also the year that I learned about the Security Catalyst Forums where more debate happens. This just proves how new our industry is and how much passion is being put into finding out the answers. This can only be a good thing.

Locally I've kept up with my visits to ISG Africa which has great presentations every month.

I completed almost 100 blog entries over the year, putting into word my thoughts about our exciting industry. My "70s" entries show where we went wrong in the 80s with our IT plans and how we are putting things right again. My 7 habits show how popular business and life philosophies can be used in InfoSec to move us in the right direction. I will hopefully finish those off shortly. (Prediction 2?)

Thank you everyone who has shared their views and hard work with me via their blogs and forums and I hope all that read this blog have learned something and will continue to follow my progress and read my thoughts.

Soon I will post my predictions for 2008.

Thursday, June 28, 2007

Its MINE and its BEAUTIFUL!


My wife used to run a little craft shop and her biggest challenge was getting adults to be creative. When she asked someone straight out to do crafts they would usually reply "but I'm not arty" or some such nonsense. Everyone is artistic. We may not all be Picasso or Rembrandt but there is a little artiste inside all of us waiting to get out.

[For both of the guys who read this column for the Information Security bits (thanks mom, dad) , its coming near the end.]

All of these people have cellphones with their own rings tones, themes, personalizations. Even little things that hang off the aerial, little cases, etc etc

The ones that work have PCs that have custom desktops. It may be a soccer team, cute kittens, a nice colour, pictures of their kids etc.

People in the workplace have, in most cases, few opportunities to express themselves creatively. But it has to come out somehow. And hence, people change their desktops and cell phone rings.
This also leads to the attraction of blogging but more to facebook and its friends.

I imagine it would be possible to fill up 8 hours a day for a month customising facebook, adding friends, adding and removing applications, putting in information, getting more applications that need information, drawing, chatting etc etc. And the whole time you are using the creative part of your brain.

How does this relate to Information Security? Well, a big deal of time is spent understanding what users do. A user is a tricky resource to understand. Companies have to accept the fact that their employees need to express their creative side, and not just the advertising guys and the script writers, but Jeff in Accounting too.

The alternative is that users will find ways to bypass measures in place that stifle their creativity. They will spend loads of time on facebook, swap joke emails, download music through p2p or even just spend time by the watercooler.

Or maybe I'm being too lenient, maybe the technological answer is correct and we should just close down undesirable sites, use "managed desktops" where everything is tightened up etc.

But facebook can be used from a cell phone...