<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>I Told You So, Volume 1 - risk-management</title>
    <subtitle>Archive, Volume 1: conference talks and papers on security and risk, 2010 to 2018.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://blog.itys.net/vol1/tags/risk-management/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2013-06-18T00:00:00+00:00</updated>
    <id>https://blog.itys.net/vol1/tags/risk-management/atom.xml</id>
    <entry xml:lang="en">
        <title>Cloud Security</title>
        <published>2013-06-18T00:00:00+00:00</published>
        <updated>2013-06-18T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/cloudsecurity-isc2tc/"/>
        <id>https://blog.itys.net/vol1/posts/cloudsecurity-isc2tc/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/cloudsecurity-isc2tc/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The (ISC)2 Twin Cities Area Chapter presentation Cloud Security by Matthew J.
Harmon at the 2013 Annual Meeting introduces the fundamentals of virtualization
and cloud computing, emphasizing both their transformative potential and the
security considerations they entail.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;cloud-technology&quot;&gt;Cloud Technology&lt;&#x2F;h2&gt;
&lt;p&gt;First, Harmon unpacks virtualization basics like defining hypervisors (Type 1
and Type 2), guests, and core virtualization architecturesand maps these
concepts onto cloud service models such as Software-as-a-Service (SaaS),
Infrastructure-as-a-Service (IaaS), and Anything-as-a-Service. He highlights key
benefits including server consolidation, rapid provisioning and decommissioning
of resources, auto-patching and silent upgrades, reduced operational overhead,
and the ability to harvest processing power on demand. This framing positions
cloud computing as a natural extension of traditional virtualization that
delivers scale, flexibility, and cost efficiency.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;security-and-privacy-risks&quot;&gt;Security and Privacy Risks&lt;&#x2F;h2&gt;
&lt;p&gt;Second, the presentation shifts to the security and privacy risks inherent in
cloud environments. Harmon details confidentiality challenges in multi-tenant
platformswhere co-located data often lacks provider-managed encryption and
availability threats stemming from service outages, contractual lock-in, or
disputes with providers. He also addresses integrity risks due to limited
transparency into vendor operations and the potential for insider threats. To
mitigate these issues, he advocates a trust but verify approach: enforce
end-to-end encryption (in transit, processing, and at rest), conduct rigorous
vendor audits, codify security requirements in contracts, and maintain
continuous risk assessments to ensure that cloud-hosted assets remain under
organizational control and resilient against data breaches.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;56461_2013-06-18_CloudSecurity-ISC2TC.pdf&quot;&gt;Cloud Security&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Security on a Shoestring Budget</title>
        <published>2012-03-16T00:00:00+00:00</published>
        <updated>2012-03-16T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/security-on-a-shoestring-budget/"/>
        <id>https://blog.itys.net/vol1/posts/security-on-a-shoestring-budget/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/security-on-a-shoestring-budget/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The Minnesota Council for Non Profits presentation Security on a Shoestring
Budget by Matthew J. Harmon and Natascha E. Shawver delivers practical guidance
for nonprofit organizations to improve their security posture without large
investments. It frames security as a mission enabler rather than a cost center
and stresses that common-sense controls can dramatically reduce risk.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;security-concepts&quot;&gt;Security Concepts&lt;&#x2F;h2&gt;
&lt;p&gt;The presenters begin by defining core information-security concepts: impact,
risk, threats, vulnerabilities, and controlsto build a shared vocabulary. They
emphasize why nonprofits must care about security, listing potential losses
(reputation, funding, productivity, legal liability) that imperil organizational
missions. By demystifying terms and highlighting that security is more than just
computer stuff, they prepare attendees to tackle specific, budget-friendly
measures.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;actions&quot;&gt;Actions&lt;&#x2F;h2&gt;
&lt;p&gt;The heart of the talk is a prioritized bare necessities checklist of seventeen
actions tailored for resource-constrained environments. Starting with secure
password management and asset inventories, it moves through network hardening
(firewalls, patching, wireless security), malware defenses, automated backups,
and principle-of-least-privilege user controls. It rounds out with training,
policies, disaster-recovery planning, and vendor oversight. Each step is
designed to be actionable with free or low-cost tools, enabling nonprofits to
take incremental, sustainable strides toward resilience.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;56002_2012-03-16_Security_on_a_Shoestring_Budget-MNCNP.pdf&quot;&gt;Security on a Shoestring
Budget&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>ISO Focus+ Article: Plugging Security Gaps</title>
        <published>2010-04-01T00:00:00+00:00</published>
        <updated>2010-04-01T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/iso-focus-plus/"/>
        <id>https://blog.itys.net/vol1/posts/iso-focus-plus/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/iso-focus-plus/">&lt;p&gt;The attached article examines the explosive adoption of radio-frequency
identification (RFID) technology across industries and the emerging security
concerns that threaten its continued growth. As organizationsfrom the U.S.
Department of Defense to livestock ranchers and healthcare providersincreasingly
rely on RFID for tracking assets, the industry must confront vulnerabilities
that could undermine both privacy and trust in this pervasive technology.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;attacks&quot;&gt;Attacks&lt;&#x2F;h2&gt;
&lt;p&gt;In the face of demonstrated attackssuch as drive-by cloning of passport tagsRFID
systems are exposed to a spectrum of threats at multiple points: the tag itself,
the reader (interrogator), and the air interface. Common attack vectors include
mimicking (spoofing, cloning, malicious code), information gathering (skimming,
eavesdropping, data tampering), and denial-of-service tactics (reader jamming,
tag blocking or killing). Each of these can compromise confidentiality,
integrity, or availability, potentially disrupting business operations and
eroding user confidence.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;defense&quot;&gt;Defense&lt;&#x2F;h3&gt;
&lt;p&gt;To address these challenges, international standards bodies have moved to embed
security into RFID deployments. ISO&#x2F;IEC TR 24729-4 lays out guidelines for tag
data securitycovering encryption, authentication, and secure data
transmissionwhile balancing cost, storage constraints, and read-performance
requirements. The report recommends leveraging a suite of countermeasures (e.g.,
unique tag identifiers per ISO 15963, password protection, and cryptographic
controls) and employs the OWASP DREAD model to assess and prioritize risks.
Ongoing work by ISO&#x2F;IEC SC 31s WG 7 seeks to harmonize these efforts into a
coherent framework that ensures interoperability, efficiency, and privacy as
RFID becomes ever more ubiquitous.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;55287_2010-04-01_Plugging_Security_Gaps-ISOFP.pdf&quot;&gt;ISO Focus+ April
2010&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
