Facebook is receiving bad press due to compromised consumer data by a Cambridge-based analytics firm for political purposes.
Frankly, this should not be news as social media outlets, and free online services (email, vlogs, blogs), use subscribing advertisers to generate their revenue by selling the (supposed to be anatomized) data. Said data extraction models have been the point of episodes on shows like Netflix's House of Cards.
Regardless, the sensitive data is supposed to be masked. And how obfuscated said data is, is often a matter of debate.
So, the questions is, will the US get serious about data privacy now and / or will consumers migrate from these services in droves?
TBD....
Showing posts with label Email. Show all posts
Showing posts with label Email. Show all posts
Wednesday, March 21, 2018
Monday, October 10, 2016
Data Breach Fatigue & Security Training
Apparently, there is "data breach fatigue" out there and recommendations on cutting down security education, training, & awareness (SETA) is gaining traction.
The question comes with to scale back SETA activities due to this fatigue?
The answer is based on the maturity of the information security (InfoSec) program, jurisdiction / market, industry, and the organization's culture. Frankly, a CISO / CIO / CTO should negotiate freedoms (e.g., local administrative access, open Internet / Web / email access) pursuant to SETA. Meaning, that if users have carte blanche then SETA is required, necessary, and regularly conducted.
Also, less SETA should equate to more budget for preventive / detective capabilities.
The question comes with to scale back SETA activities due to this fatigue?
The answer is based on the maturity of the information security (InfoSec) program, jurisdiction / market, industry, and the organization's culture. Frankly, a CISO / CIO / CTO should negotiate freedoms (e.g., local administrative access, open Internet / Web / email access) pursuant to SETA. Meaning, that if users have carte blanche then SETA is required, necessary, and regularly conducted.
Also, less SETA should equate to more budget for preventive / detective capabilities.
Tuesday, July 26, 2016
SPF, DMARC, or both?
Most orgs have email filtering in the way of sender policy framework (SPF: http://www.openspf.org/), though some seem to omit the use of domain-based message authentication reporting and conformance (DMARC: https://dmarc.org/).
While a belt and suspenders approach may not fit all budgets, in the wake of email-based malware, it may behoove orgs to use both...
While a belt and suspenders approach may not fit all budgets, in the wake of email-based malware, it may behoove orgs to use both...
Subscribe to:
Posts (Atom)