INFOSEC MANAGEMENT

This section includes papers from a variety of sources that bear on the management of information security.

 

Courses

CV

Cyberwatch

Ethics

Security Mgmt

IYIR

Methods

NetworkWorld Archive

Opinion

Ops Mgmt

Overviews

Contact info
 

 

Video Reviews

This section include page-long summaries and evaluations of some excellent awarness and training films available on VHS and DVD.

 

Computer Security Incident Response Team Management     PDF

How to set up and run an effective CSIRT.

 

Developing Security Policies      PDF

Chapter 44 from the Computer Security Handbook, 4th Edition (CSH4) reviews methods for developing security policies in specific organizations. It was later updated to become Chapter 66 of the CSH5.

 

DISA Computer Incident Response Team Management CD-ROM      ZIP

The Defense Information Systems Agency (DISA) stopped producing the excellent training CD-ROM "Computer Incident Response Team Management" in 2007. In response to my enquiry about providing the CD-ROM to MSIA students enrolled in the CSIRTM Elective, someone from DISA with a bit of gender confusion about me caused by my name responded "Dear Ms Kabay, / Thank you for your interest! However we discontinued that product, CIRT Management, just recently. We do have a few copies may have kept on hand, if you want a copy, then you can make copies of it for your students. There is no charge for our products. . . ." THEREFORE, feel free to download the 358 MB ZIP file and install it to disk. Use the README file for instructions on installation. By the way, DISA helpfully shipped me ONE THOUSAND COPIES of the disk (a few by US government standards. . . .).

 

End of Passwords, The      PDF

Why I hate passwords as a method for authentication.

 

Facilities Security Audit Checklist     PDF

Questions to help you evaluate the security of your building.

 

Identification, Authentication and Authorization on the World Wide Web     PDF

This white paper appeared in 1997 as part of the ICSA (International Computer Security Association) [previously National Computer Security Association and later TruSecure and then CyberTrust] Web site. This version has a few updates to the identifying information (e.g., removing and old e-mail address) but is otherwise as originally written (and thus now out of date). The HTML version is not usable because of the extensive use of tables and diagrams.

 

Implementing Computer Security: If Not Now, When?      HTML    PDF

This little paper reviews key threats to information and urges managers not to wait in developing and implementing security policies.

 

Net Present Value of Information Security    HTML    PDF

Thoughts about ways of presenting information security as more than just loss-avoidance. This paper was later published with additions by colleagues Karen Worstell and Mike Gerdes of AtomicTangerine and published on the now-defunct SecurityPortal Web site. Over the years I have added to my original version with corrections and updates.

 

Personnel Management and INFOSEC     HTML    PDF

Hiring, management and firing with an eye to information assurance. Later became a chapter in the Computer Security Handbook, 4th Edition and then in the 5th edition.

 

Preparing for the Next Solar Max    PDF

Solar storms threaten the critical infrastructure. Get ready.

 

Protecting Your Reputation in Cyberspace    PDF

This paper looks at how we can use e-mail and other electronic communications responsibly and professionally. It is intended to provide useful information for corporate INFOSEC awareness programs.

 

Securing Your Business in the Age of the Internet    HTML    PDF

Five pages this time to convince your bosses to pay attention to INFOSEC.   

 

Security on a Budget
   PDF    PPT (no narration)
   MP3 (narration for lecture)

About 40 minutes of narrated lecture on the key elements of managing information security effectively. Delivered via Vermont Interactive Television to an audience in Germany at a conference sponsored by Network World Deutschland in December 2002. If you would like to hear the lecture as well as see the slides, you can download the MP3 file (~ 8MB) and move through the slideshow as you listen to the sound. The first 7.5 minutes are in German, so you can skip ahead if you want to start with the English section.

 

Social Psychology and INFOSEC: Psycho-Social Factors in the Implementation of Information Security Policy
HTML    PDF    PPT

This paper was first delivered at the 16th National Computer Security Conference in 1993, where it was accorded one of the two Best Paper awards. This version has been updated and was published as Chapter 35 of the Computer Security Handbook, 4th Edition and then updated as Chapter 50 in the 5th Edition.   

 

Stopping Chain Letters and Hoaxes on the Internet    HTML    PDF

This was originally a response to a friend who kept sending jokes, frightening rumors and virus hoaxes to everyone she knew with instructions to send the jokes, frightening rumors and virus hoaxes to everyone they knew and so on ad nauseam.  Now return to the beginning of this description and read it again.  And again.  And. . . .

 

Using E-mail Safely and Well (v2)
    HTML   PDF

Compilation of several short papers published from 1995 through 2007; updated and reformatted January 2009. 

VA Data Insecurity Saga    HTML    PDF

A collection of articles from Network World Security Strategies discussing the loss of control over personally identifiable data at Veterans Affairs.

 

Velocihackers and Tyrannosaurus superior
    HTML     PDF

A 1993 column from Network World (the paper version) that reviews the movie Jurassic Park and draws lessons for security experts from the misadventures of the heroes and villains.

 

What's Important for Information Security:  A Manager's Guide     HTML     PDF

Yet another attempt to reach managers who are not yet interested in security.    

 

Waving the Red Flag: Rules for Reducing Identity Theft     PDF

Commentary on the Notice of Proposed Rulemaking for banks and other financial institutions for Red Flag guidelines against identity theft.

 

Wireless LAN Security     ZIP (6 MB)

Training materials from the Government of Canada Communications Security Establishment (with both English and French versions). May be freely copied and distributed on condidion that there is no charge and that no data are modified in any manner.    

 


 

Copyright © 2009 M. E. Kabay.  All rights reserved.

The opinions expressed in any of the writings on this Web site represent the author’s opinions and do not necessarily represent the opinions or positions of his employers, associates, colleagues, students, relatives, friends, enemies, cats, dog or plants.

Updated 2009-09-03