<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>I Told You So, Volume 1 - low-cost-controls</title>
    <subtitle>Archive, Volume 1: conference talks and papers on security and risk, 2010 to 2018.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://blog.itys.net/vol1/tags/low-cost-controls/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2012-03-16T00:00:00+00:00</updated>
    <id>https://blog.itys.net/vol1/tags/low-cost-controls/atom.xml</id>
    <entry xml:lang="en">
        <title>Security on a Shoestring Budget</title>
        <published>2012-03-16T00:00:00+00:00</published>
        <updated>2012-03-16T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/security-on-a-shoestring-budget/"/>
        <id>https://blog.itys.net/vol1/posts/security-on-a-shoestring-budget/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/security-on-a-shoestring-budget/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The Minnesota Council for Non Profits presentation Security on a Shoestring
Budget by Matthew J. Harmon and Natascha E. Shawver delivers practical guidance
for nonprofit organizations to improve their security posture without large
investments. It frames security as a mission enabler rather than a cost center
and stresses that common-sense controls can dramatically reduce risk.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;security-concepts&quot;&gt;Security Concepts&lt;&#x2F;h2&gt;
&lt;p&gt;The presenters begin by defining core information-security concepts: impact,
risk, threats, vulnerabilities, and controlsto build a shared vocabulary. They
emphasize why nonprofits must care about security, listing potential losses
(reputation, funding, productivity, legal liability) that imperil organizational
missions. By demystifying terms and highlighting that security is more than just
computer stuff, they prepare attendees to tackle specific, budget-friendly
measures.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;actions&quot;&gt;Actions&lt;&#x2F;h2&gt;
&lt;p&gt;The heart of the talk is a prioritized bare necessities checklist of seventeen
actions tailored for resource-constrained environments. Starting with secure
password management and asset inventories, it moves through network hardening
(firewalls, patching, wireless security), malware defenses, automated backups,
and principle-of-least-privilege user controls. It rounds out with training,
policies, disaster-recovery planning, and vendor oversight. Each step is
designed to be actionable with free or low-cost tools, enabling nonprofits to
take incremental, sustainable strides toward resilience.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;56002_2012-03-16_Security_on_a_Shoestring_Budget-MNCNP.pdf&quot;&gt;Security on a Shoestring
Budget&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
