[ X ]Find out how you can benefit from the Streetwise Security Zone's resources for managers and staff by clicking here.
risk management, business management security, security awareness
You are not logged in. Access is limited. Login or see membership information. • Streetwise Security Zone Community
Site Search:
GO!

Most Active Members
To appear on this list, update your profile, read content, post comments, and post messages.
#1 ScottWright
Participation Points: 12395
#2 TechNo
Participation Points: 170
#3 mateosnake
Participation Points: 160
#4 poirijo
Participation Points: 150
#5 RobBell
Participation Points: 80

Start getting your FREE
Security Tips
Newsletter now!

What value do you get? 
Click HERE.

Concerned about privacy?
Click HERE

Name:
E-mail:

JOIN NOW and get a free personal membership with one-month free Business Level access to monthly coaching sessions and product discounts.

Help for...   »

»   Non-Technical Staff
»   Executives and Managers
»   IT and R&D Staff

MORE INFO...  about The Streetwise Security Zone

You can also contact Scott Wright
by Phone:
1-613-693-0997
or Email:
scott@streetwise-security-zone.com

 

Site Meter


Web Analytics


Streetwise Security Zone Community Calendar - Next Event
Local Time: Thu Sep 9 03:45:59 2010

What is the Streetwise Security Zone?

 

A place to learn about current security threats and news in non-technical language, and understand how your business and personal information can be impacted

A place for business managers to collaborate on security challenges and learn from each other
A place to discuss Security Awareness and Security Management concepts and approaches

 


Get a FREE copy of the "Streetwise Backup and Recovery Tips for Home Users" paper by taking our quick survey on how your organization views security awareness education.
We'll send you a copy of the survey results, and a free copy of our "Streetwise Backup and Restore Tips for Home Computer Users". This report is useful for families and for businesses who let their staff connect to the office network from home.
Click HERE to take the survey.

Streetwise training options for any business

Click HERE to learn about the following security awareness training options for your business:

  • "Live Online Webinars" for cost-effective and interactive staff education;
  • "Do-it-Yourself downloadable Instructor Packs" for in-house instructors or professional consultants; or
  • "Computer Based Training" packages for general staff, management or technical staff (IT administrators and R&D specialists)

Reasons to join
The Streetwise Security Zone

For Executives - Learn how you can "walk the talk" and protect your organization's future growth from being sabotaged by rapidly evolving information threats, or by your own "Accidental Adversaries".

For IT Staff - Learn how to communicate effectively with management and staff about security awareness, and find innovative ways to keep everybody engaged in securing the information they handle in their jobs.

For Everybody - Learn how to effectively focus on the information risks related to your job, and find ways to provide feedback to management about what you need to do your job securely and efficiently.


2wx4r-scottbustsmall.jpg

"Your presentation sheds light on subjects that related to everyone who touches a computer - I love that it is in "English" and easy to understand."

Click HERE to see more testimontials for Scott's services and events.


Featured Blogs / Podcasts / Articles

Link Hygiene - the same old risks apply to newly launched services like Ping for iTunes (ScottWright)
posted Sun September 5th 2010 @ 11:57 AM

As each major player in today's technology and Web-connected world makes a move to get a bigger piece of the social networking pie, they take on new risks they haven't seen before. But if they only looked around, they'd be able to see and learn from the mistakes of others.

This week Apple launched "Ping", a new social network that serves the iTunes community. But they don't seem to have learned much from those that have ventured into this space before them. The Ping forums are being bombarded with spam posts containing phishing links. As blogger Chester Wisniewski, from antivirus maker Sophos points out, "Did they not see this coming?" (click HERE).

While Apple should have anticipated the problems, and tried a bit harder to protect legitimate users from this unwanted content, my advice to users is the same as for any social network: Use good link hygiene.

What is Good Link Hygiene?

Read More »

If you want something important to get done, give it to somebody who's always busy [Dilbert] (ScottWright)
posted Mon June 21st 2010 @ 6:35 AM

I heard the above tip in a time management course many years ago. This may sound counter-intuitive to many people, and you have to be careful about how you use this advice. It's not necessarily the people who always complain that they are busy you need to look for, it's the ones you know are always "doing something important". So, Dilbert's assessment below about the guy who takes on the work too readily is a little narrow-minded, but there can be some truth in it. Read More »

Keep 'em separated - surfing and online banking computers (ScottWright)
posted Wed June 9th 2010 @ 7:10 AM

I've written about this before, but I sense the focus of much discussion in the next year or so will be the risks of doing banking online - both for business and personal purposes. The growth in online banking fraud is still increasing, due in large part to malicious software infections from web surfing that later capture your user names, account numbers and passwords during online banking logins. Brian Krebs has raised another good point about separating web browsing from online banking activities, and has generated a lot of comments on his blog from people who have strong opinions about what kind of computers are safest for online banking - a point that seems somewhat irrelevant to me.
Read More »

article linkImprove security efficiency through data classification (ScottWright)
posted Mon May 31st 2010 @ 10:44 AM

Management often only starts to take an interest in security when there is an incident or a scare that could have cost the organization money – or management it’s credibility. Unfortunately, by this time, it is hard to “fix” the problem in a meaningful and lasting way. By taking a pro-active approach to Data Classification – one of the earliest steps in any security program – fixing a specific security issue becomes much easier. Here’s why… Read More »

Quitfacebookday.com happens on May 31, 2010 - Should you quit, too? (ScottWright)
posted Thu May 20th 2010 @ 9:01 AM

It seems like maybe I talk too much about Facebook security. But it's a growing issue in the news these days. As you can see from the image next to this blog post on my website, one of the most searched terms in Google is now "How do I delete my Facebook account?" (In fact, as of today, if you type "Delete" into a Google search, the top suggestion is "Facebook account") So, I'm debating quitting Facebook on May 31 with the others who are disgusted with the site's disregard for privacy and security. (See http://www.quitfacebookday.com)

My reasons include:
Read More »

article linkThink about the optics of collecting personal information [Dilbert] (ScottWright)
posted Sat May 15th 2010 @ 9:25 AM

No doubt, one of the most common situations in which you find yourself divulging personal information is when you are speaking to a customer service representative. But when you think about it, doesn't this interaction seem a bit "one-sided" in terms of who gets the value most of the time? Read More »

article linkGreed and laziness make the masses vulnerable. [Dilbert] (ScottWright)
posted Thu May 13th 2010 @ 7:22 AM

Wally has a plan, but doesn't realize Identity Thieves could take advantage of his greed and laziness to cause him more damage than reward. While this example from Dilbert takes things to the extreme for Wally, it's a good illustration of how Identity Thieves can take advantage of peoples' laziness when it comes to security, and think ahead of the masses. Read More »

Figuratively, today’s Internal Audit teams must track and herd zoo animals. Security pros can help. (ScottWright)
posted Wed May 12th 2010 @ 9:03 AM

Recently, I was reviewing the Canadian Financial Administration Act (FAA) and Federal Accountability Act (FedAA, or sometimes also called the FAA) for an initiative I've taken on.  As a result I couldn't help but notice the wide range of challenges faced by internal audit teams. It struck me that many people don’t realize the range of responsibilities and activities that are usually taken on by their internal audit team, and how this critical governance function has an important relationship to security and privacy. And like zoo keepers who track and herd different types of zoo animals, some parts of an organization are easier to work with than others; and the challenges include more than just the simple things we might expect, like counting them and feeding them. Read More »

Your software probably needs to be updated 75 times a year - are you sure yours is up to date? (ScottWright)
posted Fri May 7th 2010 @ 7:10 AM

Many of the most important risks we face today are related to computers that are not properly protected against attacks. If you run Microsoft Windows or use Adobe Reader, you really need to make sure these software programs are updating themselves automatically, even if you aren't the one who knows how to make it happen. If you aren't prepared to check for and install software updates 75 times a year, on average, you need to make sure automatic updates are turned on for all the software you use.
Read More »

A few quick but important statistics about malware (stats provided by Trend) (ScottWright)
posted Tue April 27th 2010 @ 8:01 PM

I attended an interesting event yesterday that was hosted by Trend Micro, here in Ottawa. Talks were given by Jirka Danek (Government of Canada CTO), as well as Eva Chen (one of Trend's founders) and Raimund Genes (Trend CTO). While there was some great discussion around cloud security - a key focus of Trend's business model - there were some very memorable malware statistics from Raimund and Eva that I think are important for everyone to take special notice of. Read More »

Go To Calendar » 

Streetwise Security Zone Community Calendar - Upcoming Events
Local Time: Thu Sep 9 03:45:59 2010

Simplifying security for your team to
"Work Smart and Work Secure"

Follow or message Scott Wright on Twitter as @streetsec...

Twitter / streetsec

streetsec: @lonervamp RE: link hygiene link using bitly? :) -> Absolutely! How else to reach those who are most at risk from risky clicks?

(Sun, 05 Sep 2010 21:16:27 +0000)


streetsec: From my blog: Link Hygiene - the same old risks apply to newly launched services like Ping for iTunes: As each ma... http://bit.ly/acxBuX

(Sun, 05 Sep 2010 16:28:58 +0000)


Twitter / Favorites from streetsec

dgtweets: RT @streetsec Caught before you even post. The future of monitoring employee Internet usage - a la Minority Report. http://icio.us/fxzbw5

(Thu, 08 Apr 2010 12:59:22 +0000)


Realtime Community | IT Compliance

Smart Grid Privacy: Possible Privacy Standards To Address Concerns
(Sat, 28 Nov 2009 18:42:04 -0500)

Sorry to be so tardy in getting a blog post out. As many of you know I've been working with the NIST Smart Grid Privacy Subgroup since late June. The work done for this group is through time volunteered by all involved. As a quick recap, I led the privacy impact assessment (PIA) for the consumer-to-utility portion of the planned smart grid during the late June to late August/early September time frame. On Friday, 11/20, I provided an update on our NIST groups activities during the Gridwise Alliance phone conference; perhaps some of you were on that call? Here are some links showing information about our NIST Smart Grid privacy group's work:

The Security Catalyst

Vacancy Management and Hierarchies Part 4: Cost Center Ownership
(Wed, 01 Sep 2010 14:21:48 +0000)

I once talked to a finance manager and asked her why her group couldn’t produce an accurate list of cost center owners. Her response was simple, “I would love to have an updated list, but no one ever tells me when there’s a change, so I have no way of maintaining a list.” As with [...]Related posts:Vacancy Management and Hierarchies Part 3: Data/Access OwnershipIdentity Management Series – Vacancy Management and Hierarchies Part 1: IntroductionVacancy Management and Hierarchies Part 2: Line Management Hierarchy


FREE AUDIO TRAINING GUIDE

For your free one-hour audio guide to Facebook Privacy and Security click HERE.


FREE PODCASTS

You can listen to the Streetwise Security Zone Podcast by clicking HERE or the Social Media Security Podcast by clicking HERE.


AUDIO TRAINING PROGRAMS

Learn how to protect yourself while browsing the Web with our one-hour audio guide to Safe Web Surfing. Now, only $4.99 for non-members, and $3.99 for members.