Blog Content
Articles on knowledge, tools, and strategies needed to protect you and your stakeholders against evolving cyber threats.
Read moreDoveryai, no proveryai (Trust, but verify).
Read moreWhen entrusted to process, you are obligated to safeguard.

Cybersecurity Goals of IT Support
A few months ago I was casually discussing roles of IT personnel with a law enforcement professional. This discussion was rather short as we were only briefly going over the scope of duties. However, the discussion got me thinking about how much security is integrated…
Read moreGive a man an audit and he will be secure for a day. Teach a man to audit and he will be secure for the rest of his life.

Exploring Policy Format Tips
We kicked off the exploring series by taking a look at policies. We started with recognizing policies as a major type of documentation. We moved into the importance of having policies. Then, we looked at how a policy is created and effected. To wrap up our first…
Read moreInformation security is an economics problem.

Exploring the IT Policy Creation Process
We’ve reviewed policies as a major type of documentation and why having policies is very important. Now, let’s briefly overview how a policy is created and effected. The IT policy creation process is as follows: Recognize Plan Research Draft Approve Adopt Disseminate…

Tales From Cybersecurity Leader Bios
I’m still reeling off the high from the annual Security Congress put on by ISC2 a couple of weeks ago. As I calm down, I’d like to review a few highlights from some speakers. Join me as we go through a few cybersecurity leader bios. They have a few good lessons. Since…
Read moreSecure is an adjective, so it’s subjective to owner’s risk acceptance.

Exploring the Importance of IT Policies
In last week’s post, Exploring 3 Different Types of IT Documentation, we briefly touched on policies as one of the three common types of documentation. The importance of IT policies cannot be overstated. Policies are very important as they portray an organization’s…
Read moreMany recommendations across the Net sound like this: ‘Don’t keep your information on the cloud.’ Fair enough, but it’s the same as if you asked, ‘How not to get my house burned down?’ and the answer would be, ‘Do not have a house.’ The logic is solid, but a better way to translate such advice is, ‘avoid storing sensitive information on the cloud.’ So if you have a choice you should opt for keeping your crucial information away from virtual world or use appropriate solutions.

Exploring 3 Different Types of IT Documentation
Although there are clear boundaries of document types in theory, what a type of document actually is and should be can vary depending on who you talk to. Some people add procedures with policies and standards to procedures. These types of people want to make available…
Need Additional Guidance?
Get recommended materials and more on the Resources Page.