Roger A. Grimes's blog http://www.infoworld.com/blogs/roger-grimes en The trouble with S/MIME e-mail encryption http://www.infoworld.com/d/security-central/trouble-smime-e-mail-encryption-220 <!--paging_filter--><p>A few times a year, I recognize the need for a product where none exists because I hear multiple customers asking for it. This is one of those times. The products that an increasing number of my clients is looking for are e-mail scanning and archiving systems that can handle S/MIME-encrypted messages.</p><p><a href="http://www.infoworld.com/d/security-central/trouble-smime-e-mail-encryption-220" target="_blank">read more</a></p> http://www.infoworld.com/d/security-central/trouble-smime-e-mail-encryption-220#comments Security Central Data security E-mail Encryption Fri, 06 Nov 2009 11:00:00 +0000 Roger A. Grimes 99220 at http://www.infoworld.com Win the security numbers game http://www.infoworld.com/d/security-central/win-security-numbers-game-203 <!--paging_filter--><p>I used to be a Certified Public Accountant (CPA) before I learned that computers and <a href="http://www.infoworld.com/d/security-central">computer security</a> were a better fit. Still, you would think that earning a college accounting degree, working at a CPA firm, and passing one of the hardest professional exams in the world would enable me to do my own taxes. But I'm too scared. The tax code is full of thousands of ever changing laws. There are exceptions to every exception. Believe me, when Congress passes a tax simplification act, CPA firms cheer.</p><p><a href="http://www.infoworld.com/d/security-central/win-security-numbers-game-203" target="_blank">read more</a></p> http://www.infoworld.com/d/security-central/win-security-numbers-game-203#comments Security Central Regulatory compliance Risk management Fri, 30 Oct 2009 10:00:00 +0000 Roger A. Grimes 98203 at http://www.infoworld.com Don't trust a public PC with your digital identity http://www.infoworld.com/d/security-central/dont-trust-public-pc-your-digital-identity-126 <!--paging_filter--><p>Contrary to popular belief, stealing someone's digital identity is a snap. It almost seems as though the more we use digital identities, the easier they are to swipe. The reason can be attributed to general carelessness or perhaps outright ignorance, but whatever the case, letting your digital identity fall into the wrong hands can expose you and your organization to a world of headaches.</p><p><a href="http://www.infoworld.com/d/security-central/dont-trust-public-pc-your-digital-identity-126" target="_blank">read more</a></p> http://www.infoworld.com/d/security-central/dont-trust-public-pc-your-digital-identity-126#comments Security Central Identity management Fri, 23 Oct 2009 10:00:00 +0000 Roger A. Grimes 97126 at http://www.infoworld.com Risk-analysis tools provide the big security picture http://www.infoworld.com/d/security-central/risk-analysis-tools-provide-big-security-picture-188 <!--paging_filter--><p>All computer security defense ultimately comes down to managing risk. Security admins implement various defenses, each of which should have its own cost/benefit analysis. The cost of the defense should not outweigh the estimated damage of the attack or exploit. For example, if buying anti-malware software for a 100 PCs costs $3,900 per year, but cleaning up the damage from a malware attack would cost only $2,000 per year, implementing the anti-malware software wouldn't make sense.</p><p><a href="http://www.infoworld.com/d/security-central/risk-analysis-tools-provide-big-security-picture-188" target="_blank">read more</a></p> http://www.infoworld.com/d/security-central/risk-analysis-tools-provide-big-security-picture-188#comments Security Central Malware Security Fri, 16 Oct 2009 10:00:00 +0000 Roger A. Grimes 96188 at http://www.infoworld.com IT security admins, get to know your known unknowns http://www.infoworld.com/d/security-central/it-security-admins-get-know-your-known-unknowns-187 <!--paging_filter--><p>Say what you will about Donald Rumsfeld 's defense policies, but  the former Secretary of Defense uttered a series of seemingly conflated <a href="http://en.wikipedia.org/wiki/Unknown_unknown" target="_blank">nonsensical statements on July 12, 2002</a>, that actually made perfect sense: "There are known knowns. These are things we know that we know. There are known unknowns. That is to say, there are things that we now know we don't know. But there are also unknown unknowns. These are things we do not know we don't know."</p><p><a href="http://www.infoworld.com/d/security-central/it-security-admins-get-know-your-known-unknowns-187" target="_blank">read more</a></p> http://www.infoworld.com/d/security-central/it-security-admins-get-know-your-known-unknowns-187#comments Security Central Career advice Data security Fri, 09 Oct 2009 10:00:00 +0000 Roger A. Grimes 95187 at http://www.infoworld.com Macs' low popularity keeps them safer from hacking and malware http://www.infoworld.com/d/security-central/macs-low-popularity-keeps-them-safer-hacking-and-malware-138 <!--paging_filter--><p>For two weeks, I was having a heated discussion with some diehard Mac-only fans in a stock forum. It was one of those self-perpetuating, boring Windows-versus-Mac flame wars, where neither side ends up believing the other. Each side sincerely believes their platform is better and destined to rule the world.</p><p><a href="http://www.infoworld.com/d/security-central/macs-low-popularity-keeps-them-safer-hacking-and-malware-138" target="_blank">read more</a></p> http://www.infoworld.com/d/security-central/macs-low-popularity-keeps-them-safer-hacking-and-malware-138#comments Mac Security Central Windows Hacking Mac Fri, 02 Oct 2009 10:00:00 +0000 Roger A. Grimes 94138 at http://www.infoworld.com How to manage IT security -- without a tech background http://www.infoworld.com/d/security-central/how-manage-it-security-without-tech-background-214 <!--paging_filter--><p>A close friend of mine just got moved from financial services executive management to the CSO role within her organization. My friend is smart and has more degrees than a thermometer. She doesn't know much about IT security, however -- except that her company isn't doing it right.</p><p><a href="http://www.infoworld.com/d/security-central/how-manage-it-security-without-tech-background-214" target="_blank">read more</a></p> http://www.infoworld.com/d/security-central/how-manage-it-security-without-tech-background-214#comments Security Central Data security Fri, 25 Sep 2009 10:00:00 +0000 Roger A. Grimes 93214 at http://www.infoworld.com Learn cloud security before it's too late http://www.infoworld.com/d/security-central/learn-cloud-security-its-too-late-282 <!--paging_filter--><p>Don't believe anyone who says cloud computing is just a buzzword, doomed to become the next failed, overhyped industry former technology darling. Cloud computing is already here, and if you don't learn to secure it, you won't have much of a job to cling to in the not-too-distant future. Think of the information security version of a Cobol programmer.</p><p><a href="http://www.infoworld.com/d/security-central/learn-cloud-security-its-too-late-282" target="_blank">read more</a></p> http://www.infoworld.com/d/security-central/learn-cloud-security-its-too-late-282#comments Cloud Computing Security Central Cloud computing Security Fri, 18 Sep 2009 10:00:00 +0000 Roger A. Grimes 92282 at http://www.infoworld.com Windows autorun may autoinfect http://www.infoworld.com/d/security-central/windows-autorun-may-autoinfect-266 <!--paging_filter--><p>Nothing beats a USB port for convenience, whether you want to quickly transport a couple gigabytes of files for work, refresh the lineup on your MP3 player, or view the pictures from your recent trip to Boise. Unfortunately, USB ports also provide an overly convenient bridge for malware to creep from a portable media device onto an unsuspecting user's system. In fact, it seems nearly every client I visit these days has numerous computers carrying USB-infecting malware -- even trusted clients with otherwise stellar security histories.<p><a href="http://www.infoworld.com/d/security-central/windows-autorun-may-autoinfect-266" target="_blank">read more</a></p> http://www.infoworld.com/d/security-central/windows-autorun-may-autoinfect-266#comments Security Central Malware Windows Fri, 11 Sep 2009 10:00:00 +0000 Roger A. Grimes 91266 at http://www.infoworld.com Prepare for the next password attack http://www.infoworld.com/d/security-central/prepare-next-password-attack-521 <!--paging_filter--><p>All that often stands between a malicious hacker and access to valuable, confidential data is a few keystrokes: an end-user's or admin's password. Yet even the most carefully crafted and well-guarded password is susceptible to being stolen from an innocent victim, and crafty miscreants have numerous techniques at their disposal to do the dirty deed.</p><p><a href="http://www.infoworld.com/d/security-central/prepare-next-password-attack-521" target="_blank">read more</a></p> http://www.infoworld.com/d/security-central/prepare-next-password-attack-521#comments Security Central Hacking Fri, 04 Sep 2009 10:00:00 +0000 Roger A. Grimes 90521 at http://www.infoworld.com