Entries from August 2009

August 26, 2009

DHS IT SCC issue Baseline Risk Assessment

Need to read:
The Department of Homeland Security (DHS) and the Information Technology Sector Coordinating Council (IT SCC) today released the IT Sector Baseline Risk Assessment (ITSRA) to identify and prioritize national-level risks to critical sector-wide IT functions while outlining strategies to mitigate those risks and enhance national and economic security.
“The IT Sector Baseline Risk Assessment [...]

August 25, 2009

Unintentional Risk

Yep — the leading cause of cyber security breaches — per RSA study (tip to BBC):
The security vendor RSA revealed that the majority of breaches are actually caused unintentionally by employees.
Its survey showed that firms believed 52% of incidents were accidental and 19% were deliberate.
“Unintentional risk gets overlooked, yet it’s the most serious threat to [...]