Roger A. Grimes's blog http://www.infoworld.com/blogs/roger-grimes en S/MIME gateways can create fatal security breakdowns http://www.infoworld.com/d/security-central/smime-gateways-can-create-fatal-security-breakdowns-172 <!--paging_filter--><p>Over the years, I've had several clients use S/MIME to authenticate and encrypt e-mail messages. Unfortunately, encrypting anything end-to-end has problems, including those associated with scanning incoming encrypted messages, checking for data leaks, or indexing for later retrieval. When my clients turn on S/MIME, they are pretty much turning off easy e-mail scanning and retrieval.</p><p><a href="http://www.infoworld.com/d/security-central/smime-gateways-can-create-fatal-security-breakdowns-172" target="_blank">read more</a></p> http://www.infoworld.com/d/security-central/smime-gateways-can-create-fatal-security-breakdowns-172#comments Security Central E-mail Encryption Fri, 20 Nov 2009 11:00:00 +0000 Roger A. Grimes 101172 at http://www.infoworld.com Your data is safer in the cloud than you think http://www.infoworld.com/d/security-central/your-data-safer-in-cloud-you-think-193 <!--paging_filter--><p>Nearly every week, news articles crop up shouting about <a href="http://www.infoworld.com/d/cloud-computing/microsoft-loses-sidekick-users-personal-data-427">someone's cloud data</a> or application temporarily -- or in some rare instances, permanently -- disappearing. Name a vendor and they've probably been in the news. "Ack!" and "Not ready for prime time!" go the headlines.  Cloud computing may be the future, but it isn't ready for the enterprise.</p> <p>Or is it?</p><p><a href="http://www.infoworld.com/d/security-central/your-data-safer-in-cloud-you-think-193" target="_blank">read more</a></p> http://www.infoworld.com/d/security-central/your-data-safer-in-cloud-you-think-193#comments Cloud Computing Security Central Cloud computing Data security Fri, 13 Nov 2009 11:00:00 +0000 Roger A. Grimes 100193 at http://www.infoworld.com The trouble with S/MIME e-mail encryption http://www.infoworld.com/d/security-central/trouble-smime-e-mail-encryption-220 <!--paging_filter--><p>A few times a year, I recognize the need for a product where none exists because I hear multiple customers asking for it. This is one of those times. The products that an increasing number of my clients is looking for are e-mail scanning and archiving systems that can handle S/MIME-encrypted messages.</p><p><a href="http://www.infoworld.com/d/security-central/trouble-smime-e-mail-encryption-220" target="_blank">read more</a></p> http://www.infoworld.com/d/security-central/trouble-smime-e-mail-encryption-220#comments Security Central Data security E-mail Encryption Fri, 06 Nov 2009 11:00:00 +0000 Roger A. Grimes 99220 at http://www.infoworld.com Win the security numbers game http://www.infoworld.com/d/security-central/win-security-numbers-game-203 <!--paging_filter--><p>I used to be a Certified Public Accountant (CPA) before I learned that computers and <a href="http://www.infoworld.com/d/security-central">computer security</a> were a better fit. Still, you would think that earning a college accounting degree, working at a CPA firm, and passing one of the hardest professional exams in the world would enable me to do my own taxes. But I'm too scared. The tax code is full of thousands of ever changing laws. There are exceptions to every exception. Believe me, when Congress passes a tax simplification act, CPA firms cheer.</p><p><a href="http://www.infoworld.com/d/security-central/win-security-numbers-game-203" target="_blank">read more</a></p> http://www.infoworld.com/d/security-central/win-security-numbers-game-203#comments Security Central Regulatory compliance Risk management Fri, 30 Oct 2009 10:00:00 +0000 Roger A. Grimes 98203 at http://www.infoworld.com Don't trust a public PC with your digital identity http://www.infoworld.com/d/security-central/dont-trust-public-pc-your-digital-identity-126 <!--paging_filter--><p>Contrary to popular belief, stealing someone's digital identity is a snap. It almost seems as though the more we use digital identities, the easier they are to swipe. The reason can be attributed to general carelessness or perhaps outright ignorance, but whatever the case, letting your digital identity fall into the wrong hands can expose you and your organization to a world of headaches.</p><p><a href="http://www.infoworld.com/d/security-central/dont-trust-public-pc-your-digital-identity-126" target="_blank">read more</a></p> http://www.infoworld.com/d/security-central/dont-trust-public-pc-your-digital-identity-126#comments Security Central Identity management Fri, 23 Oct 2009 10:00:00 +0000 Roger A. Grimes 97126 at http://www.infoworld.com Risk-analysis tools provide the big security picture http://www.infoworld.com/d/security-central/risk-analysis-tools-provide-big-security-picture-188 <!--paging_filter--><p>All computer security defense ultimately comes down to managing risk. Security admins implement various defenses, each of which should have its own cost/benefit analysis. The cost of the defense should not outweigh the estimated damage of the attack or exploit. For example, if buying anti-malware software for a 100 PCs costs $3,900 per year, but cleaning up the damage from a malware attack would cost only $2,000 per year, implementing the anti-malware software wouldn't make sense.</p><p><a href="http://www.infoworld.com/d/security-central/risk-analysis-tools-provide-big-security-picture-188" target="_blank">read more</a></p> http://www.infoworld.com/d/security-central/risk-analysis-tools-provide-big-security-picture-188#comments Security Central Malware Security Fri, 16 Oct 2009 10:00:00 +0000 Roger A. Grimes 96188 at http://www.infoworld.com IT security admins, get to know your known unknowns http://www.infoworld.com/d/security-central/it-security-admins-get-know-your-known-unknowns-187 <!--paging_filter--><p>Say what you will about Donald Rumsfeld 's defense policies, but  the former Secretary of Defense uttered a series of seemingly conflated <a href="http://en.wikipedia.org/wiki/Unknown_unknown" target="_blank">nonsensical statements on July 12, 2002</a>, that actually made perfect sense: "There are known knowns. These are things we know that we know. There are known unknowns. That is to say, there are things that we now know we don't know. But there are also unknown unknowns. These are things we do not know we don't know."</p><p><a href="http://www.infoworld.com/d/security-central/it-security-admins-get-know-your-known-unknowns-187" target="_blank">read more</a></p> http://www.infoworld.com/d/security-central/it-security-admins-get-know-your-known-unknowns-187#comments Security Central Career advice Data security Fri, 09 Oct 2009 10:00:00 +0000 Roger A. Grimes 95187 at http://www.infoworld.com Macs' low popularity keeps them safer from hacking and malware http://www.infoworld.com/d/security-central/macs-low-popularity-keeps-them-safer-hacking-and-malware-138 <!--paging_filter--><p>For two weeks, I was having a heated discussion with some diehard Mac-only fans in a stock forum. It was one of those self-perpetuating, boring Windows-versus-Mac flame wars, where neither side ends up believing the other. Each side sincerely believes their platform is better and destined to rule the world.</p><p><a href="http://www.infoworld.com/d/security-central/macs-low-popularity-keeps-them-safer-hacking-and-malware-138" target="_blank">read more</a></p> http://www.infoworld.com/d/security-central/macs-low-popularity-keeps-them-safer-hacking-and-malware-138#comments Mac Security Central Windows Hacking Mac Fri, 02 Oct 2009 10:00:00 +0000 Roger A. Grimes 94138 at http://www.infoworld.com How to manage IT security -- without a tech background http://www.infoworld.com/d/security-central/how-manage-it-security-without-tech-background-214 <!--paging_filter--><p>A close friend of mine just got moved from financial services executive management to the CSO role within her organization. My friend is smart and has more degrees than a thermometer. She doesn't know much about IT security, however -- except that her company isn't doing it right.</p><p><a href="http://www.infoworld.com/d/security-central/how-manage-it-security-without-tech-background-214" target="_blank">read more</a></p> http://www.infoworld.com/d/security-central/how-manage-it-security-without-tech-background-214#comments Security Central Data security Fri, 25 Sep 2009 10:00:00 +0000 Roger A. Grimes 93214 at http://www.infoworld.com Learn cloud security before it's too late http://www.infoworld.com/d/security-central/learn-cloud-security-its-too-late-282 <!--paging_filter--><p>Don't believe anyone who says cloud computing is just a buzzword, doomed to become the next failed, overhyped industry former technology darling. Cloud computing is already here, and if you don't learn to secure it, you won't have much of a job to cling to in the not-too-distant future. Think of the information security version of a Cobol programmer.</p><p><a href="http://www.infoworld.com/d/security-central/learn-cloud-security-its-too-late-282" target="_blank">read more</a></p> http://www.infoworld.com/d/security-central/learn-cloud-security-its-too-late-282#comments Cloud Computing Security Central Cloud computing Security Fri, 18 Sep 2009 10:00:00 +0000 Roger A. Grimes 92282 at http://www.infoworld.com