Skip to main content

Unified theory of Information Security

Lets call this a If we use the building metaphor for infosec to talk about the industry  

Vulnerabilities  vs weaknesses vs compliance findings  ( need more clear definitions) 

Consultations are going to an architect to see if an idea is solid or can be implemented better.

Threat modeling is walking and walking through a complete blue print discussing both security best practices, weaknesses in the design, and zoning/safety laws(compliance).

White box security testing  is walkthrough and inspection with some gentle use to make sure you were built up to code and no defects popped up because substandard materials got into the build.( Shit happens)

Black box security testing or black box penetration testing is asking a security company to assess you like an attacker would. 

Vulnerability management would then be regular inspections for mold or wear and tear damage. 

Incident response is an emergency repair team that can be called on for many reasons. They can implement quick fixes and catch a lot of things but sometimes they'll need to reengage the architects / assessors/ builders of the application. 


Comments

Popular posts from this blog

Log4J Resources and memes

-Informational Posts: https://www.darkreading.com/dr-tech/what-to-do-while-waiting-for-the-log4ju-updates https://www.securityweek.com/companies-respond-log4shell-vulnerability-attacks-rise https://www.itworldcanada.com/article/it-could-take-years-for-applications-using-vulnerable-version-of-java-log4j-library-to-be-patched-says-expert/468238 https://www.helpnetsecurity.com/2021/12/13/log4shell-update-cve-2021-44228/ https://research.nccgroup.com/2021/12/12/log4j-jndi-be-gone-a-simple-mitigation-for-cve-2021-44228/ https://www.splunk.com/en_us/blog/security/log4shell-detecting-log4j-vulnerability-cve-2021-44228-continued.html -Blue team resources https://gist.github.com/SwitHak/b66db3a06c2955a9cb71a8718970c592 https://github.com/cisagov/log4j-affected-db https://www.greynoise.io/blog/apache-log4j-vulnerability-CVE-2021-44228 -IP Tracking projects https://gist.github.com/gnremy/c546c7911d5f876f263309d7161a7217 https://www.greynoise.io/viz/query/?gnql=tag...

Music for working

I've always know that music influenced my productivity levels but the quarantine has given me time to dig into what each genre of music puts me in the mood for.  Separated from all other variables I can now say that punk music makes me want to write. It's a very odd realization for a 30 year old but hey there it is.