Nach unserem Talk über die #BAIT endet für mich der IT-GRC Kongress 2022. Vielen Dank für die tollen Vorträge und die guten - teils auch kontrovers geführten - Diskussionen. Ich freue mich auf das nächste Jahr.
Noch 15 Minuten dann startet unser Vortrag zum #DigitalOperationalResilienceAct auf dem @ISACAGermany IT-GRC Kongress 2022. Ich freue mich schon auf die Diskussion mit der Community!
Der erste Tag des @ISACAGermany IT-GRC Kongress 2022 neigt sich dem Ende zu. Es war toll die Kolleg*innen wieder in Präsenz zu treffen und sich auszutauschen. Morgen geht es weiter und ich darf mit Kollegen zwei Vorträge zum #DigitalOperationalResilienceAct und #BAIT beitragen.
@BrianRPhillips I can talk about Information Security Governance Models for any time between 5 minutes and 3 hours without prep. If we allow for a small detour to risk management, I‘d recommend clearing the calendar for the day.
This is also very useful for #infosec practitioners, especially if writing non-quantitative risk assessments. (And a call to action for myself to review some of my older writing.)
.@bradshoemaker mentioning LinuxFromScratch on this weeks @nextlander Ramblecast was a serious blast from the past of my high school years. And now am I sitting here, wondering how lfs changed in the last twenty years and if I should set up a box with it 🤔
@Haramis @platschpittie Für Kinder: Heilsalbe, Desinfektionsmittel und Pflaster. Außerdem Fiebersaft oder -Zäpfchen, je nach Alter. Im Winter haben wir noch oft ein Nasenspray (das nur mit Salzwasser?). Alle andere haben wir immer nach Bedarf verschrieben bekommen.
Not the usual analysis (or am I kidding myself here?) I come to @RatlSecurity for, but thank you to @qjurecic for the Mountain Goats recommendation. It significantly improved my dish washing!
tfw a smarthome device (yes,i know) registers with hostname 'open-wrt' in your network and provides an unauthenticated,non-tls website for flashing its firmware while providing an obligatory 'press a button on the device before flashing' message.looking at you @nanoleaf#infosec
@madplatt Secrets and lies primed me for infosec when I read it 20 years ago (while still in high school - now I feel even older. Great.) The book has some great ideas and reading it can be really depressing because we‘re still doing not enough of it.
To summarize: Interresting paper, potentially fruitful area for research, please consider the oppurtunity for exchange with practitioners already doing similar work in a non-academic environment. 7/7
Over lunch I had the chance to read 'Security policy audits: why and how' by Arvind Narayanan and Kevin Lee (https://t.co/kAKNigPqzu).The paper opens with the introductory section titled 'Security policies matter, but you wouldn’t know it from conference proceedings'. 1/7
(I'm aware that the paper mainly considers the risk to the end user, similar to a PIA, while a risk assessment also/mainly considers the risk to the enterprise. However the point still stands.) 6/7