October 2009
6 posts
4 tags
new sections - "security pirate's guide" and "how...
two bits of news for tonight!
FIRST!
alright so instead of posting work that other people are doing and commenting/summarizing and otherwise butchering the quality. i’m actually gonna start to write my own stuff! well, i’ll probably also continue to repost that stuff too.
i’ll be naming the series as follows.
the security pirate’s guide to: live incident response,...
2 tags
CRTC 'rules' on internet neutrality in Canada →
Well, it’s not great, and it’s still vague but it’s a start. ISPs which employ ‘traffic management’ (see: quotas, caps, shaping and throttling) now must notify clients and use fair and reasonable process when deploying this technology.
5 tags
Report: Web Application Security Statistics... →
The always insightful WASC security statistics report for all of 2008 has just been released.
The data collected represents combined results of webapp vulnerability assessments from such market leaders as Whitehat, Cenzic, HP and Veracode. In total, 12186 individual sites were sampled.
One thing to consider, the results are gathered from organizations who already have purchased services from...
5 tags
5 tags
Report: Telus/University of Toronto - Canadian IT...
Telus and the University of Toronto have teamed up to deliver their second annual ‘Joint Study on Canadian IT Security Practices’. A few weeks ago, I was invited to the ISACA presentation in Toronto where the authors of this report reviewed the executive summary. I’m still getting through the full report, but so far it’s an incredible wealth of information. I’m really...
1 tag
Obligatory introduction
They always start this way. It’s a rule or something. As some of you may have guessed, this is a blog. Welcome! I’m Erik. I work at a Canadian IT services/hosting company managing everything security. This includes incident response, sales, engineering, compliance, audit, risk management, training and privacy matters. In my spare time I try to change the culture to accept security as...