CSO's desk Articles

Information sharing grows up

Mark Clancy, managing director, technology risk management, The Depository Trust & Clearing Corp. • February 01, 2012

An enhanced volume of sharing is allowing critical infrastructure operators and government agencies to better defend themselves from attacks, says Mark Clancy, The Depository Trust & Clearing Corp.
 

A resolution to measure more: Data breach consequences

Dan Srebnick, CISO, city of New York January 03, 2012

It's vital to understand how to talk about security to senior executives in order to prevent a data breach, says Dan Srebnick, CISO of the city of New York.
 

Implement cultural change in 2012

Justin Somaini, CISO, Yahoo! December 01, 2011

As we look at the reasons why security fails in organizations, it keeps coming back to people, says Justin Somaini, CISO, Yahoo!
 

Back to basics for enterprise defense

Vicki Ames, former information system security officer at a federal medical research agency • November 01, 2011

Implementing proper security practices protects against today's and tomorrow's risks, says Vicki Ames, former information system security officer at a federal medical research agency .
 

Taking stock of PCI five years on

Eduardo Perez, head of global payment system risk, Visa October 03, 2011

PCI rules have evolved to keep up with new technologies, and adoption rates are growing, says Visa's Eduardo Perez.
 

The cloud can actually make data safer

Ed Amoroso, chief security officer, AT&T September 01, 2011

We need to do a far better job of demonstrating that the infrastructure and services we are putting into the cloud are superior to what we have today.
 

Sweat the small stuff: A sound information security posture includes the old and the new

Ron Baklarz, CISO of Amtrak August 01, 2011

A sound information security posture includes the old but effective combination of security infused at the people, process and technology levels, says Ron Baklarz, CISO of Amtrak.
 

Signing on the dotted line of HIPAA

Bryan Cline, CISO and director of information security at Catholic Health East July 01, 2011

Given that a misrepresentation of the facts during attestation could result in civil and criminal penalties, what does a health care executive need to feel comfortable about before signing on the dotted line?
 

A new era for risk management

Justin Somaini, CISO, Yahoo! June 01, 2011

The ability to ascertain the risk tolerance of the business gives us a benchmark to hit as opposed to just "guessing" and then getting political pushback
 

Mobile device control: Get to yes

Vicky Ames, former information system security officer at a federal medical research agency May 02, 2011

If you aren't already trying to figure out your mobile device security strategy, you soon will be, says Vicky Ames, former information system security officer at a federal medical research agency.