Skip to main content

Posts

Showing posts from 2016

Did i miss to assetize Virtual Machines !

Auditee : Hi There ! Welcome, What would you like to have? Tea or Coffee? Auditor: Asset Register ! A comprehensive Asset Register is something which is quintessential for any risk management program. Everything that has to do with risk, follows from here. Information Security Risks are no different that any other type of risks. Having a few people (rarely security pro) building asset register will probably mess up any risk management at the very first stage. It has been seen that people generally miss to address technologically advanced assets (The ones they did not understand a few years ago)  to register in their asset inventory. The most obvious are the virtual machines.  Every day ,Virtual Machines (VM) are being created on the fly as per business requirement, many of them persist for years and many not so much. There are many questions  like: if that particular VM is of some value? Do I need to consider it as valuable at this point of time, whe...

To hell with "compliance", If it's not bringing Security on the table !

When the world is about to wake up on handling security consciously, The C-Suite is unable to digest the Return On Investment. Every minute of every hour, Organizations are loosing their precious security employees just because someone somewhere is incapable to use Simple Math to give some numbers to their Bosses. The management is failing to understand or at-least ignoring the fact that security is important to their businesses directly. Gone are those days when repercussions were felt later in time, In contemporary culture the impact are too high and sudden. By the time organizations wake up, They have already had a visible dent on their businesses and values.  In the last couple of years, when everyone was working to bring security solutions on the table , C-Suite people made the wrong turn and brought "compliance" ! From that day till the next major incident, we are not expecting any turn from the current pathway . No one is sharing their part of energy to push this ...