Cigital’s Agile Security Manifesto

All Rights Reserved, Royalty-free license purchased through Fotolia.com

I tend to operate in accordance with the four principles of Cigital‘s recent Agile Security Manifesto.

[su_pullquote align=”right” class=””]NOTE: I cannot state whether I’ve employed Cigital professionally but I have had interaction with them in my career.[/su_pullquote]

SANS – Confusion in the Top How Many?

Enterprise Security or Secure Solution program?

While discussing the SANS Top 20 Critical Controls a couple of weeks ago I ran into some confusion with an infosec partner about the number of controls we were talking about.  He referred to the Top 25 but I know from my training and certification that there are 20 controls.

Brother Can You Spare a Protocol?

If you haven’t yet heard of the SSLv3 protocol exploit then where have you been and how can you sleep at night.  Surely someone ran past you yesterday (Tuesday 10/14/14) with his hair on fire, screaming about graceful degradation of protocols.

 

Royalty-free license purchased via Fotolia.com

How Do You Respond?