System Development Life Cycle (SDLC) Framework
The SDLC framework is a multi-step outline that describes the life cycle of an information system. The five phases of the SDLC are: Security that is integrated into this life…
Free resources for programming help
The SDLC framework is a multi-step outline that describes the life cycle of an information system. The five phases of the SDLC are: Security that is integrated into this life…
Situational awareness is one of the most difficult things to get right in doing cloud security, and hand in hand with that goes inventory awareness. To understand why, take a…
A previous article here on general Security Metrics outlined some key security controls for measurement: NOTE: each of these security controls may have several or even many metrics that can…
Connecting your information system to a cloud is an interconnection. NIST guidance on handling the security of interconnections is documented in 800-47 Rev. 1 “Managing the Security of Information Exchanges”.…
Cloud computing is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications and services) that can be…
Cloud computing may not deliver the cost savings that everybody seems to expect. The general computing community seems to take it for granted that the driving reason for moving to…
FEDRAMP (FEDeral Risk and Authorization Management Program) offers baselines of 800-53 security controls that have been tailored for cloud environments. But they do not offer a HIGH impact baseline. Presumably,…
Integrated attack strategies involve combining hacking computer systems with attack vectors such as: espionage, blackmail, medical/health attacks, asymmetric “guerrilla-style” attacks, weapons of mass destruction, and conventional kinetic military attacks. The…
Hacking computers is a mysterious and dangerous world that most of us don’t really understand. This video shows some hackers at DEFCON demonstrating their techniques on a reporter who volunteered…
Metasploit has a payload component called Meterpreter that is injected inside a running process and offers a command environment to the attacker. This avoids starting a new process and keeps…