uk There is also a ENGLISH VERSION of this site


Mijn Engelstalige boek over IT infrastructuur architectuur





Links

Aanbevolen
Genootschap voor Informatie Architecten
Rene Hamberg
Eric Meijer
Bas Varkevisser
Ruth Malan
l-rs.org
Informatiekundig bekeken
Bredemeyer Consulting
Gaudi site
Hans Bot ArchITectuur Bedrijven
Security.nl
Byelex
XR Magazine
Esther Barthel's site on virtualization


Meer artikelen


01 Oct - 31 Oct 2011
01 Sep - 30 Sep 2011
01 Jul - 31 Jul 2011
01 Jun - 30 Jun 2011
01 May - 31 May 2011
01 Apr - 30 Apr 2011
01 Mar - 31 Mar 2011
01 Feb - 28 Feb 2011
01 Jan - 31 Jan 2011
01 Dec - 31 Dec 2010
01 Nov - 30 Nov 2010
01 Oct - 31 Oct 2010
01 Sep - 30 Sep 2010
01 Aug - 31 Aug 2010
01 Jul - 31 Jul 2010
01 Jun - 30 Jun 2010
01 May - 31 May 2010
01 Apr - 30 Apr 2010
01 Mar - 31 Mar 2010
01 Feb - 28 Feb 2010
01 Jan - 31 Jan 2010
01 Dec - 31 Dec 2009
01 Oct - 31 Oct 2009
01 Sep - 30 Sep 2009
01 Aug - 31 Aug 2009
01 Jun - 30 Jun 2009
01 Apr - 30 Apr 2009
01 Mar - 31 Mar 2009
01 Feb - 28 Feb 2009
01 Jan - 31 Jan 2009
01 Dec - 31 Dec 2008
01 Nov - 30 Nov 2008
01 Oct - 31 Oct 2008
01 Sep - 30 Sep 2008
01 Aug - 31 Aug 2008
01 Jul - 31 Jul 2008
01 Jun - 30 Jun 2008
01 May - 31 May 2008
01 Apr - 30 Apr 2008
01 Mar - 31 Mar 2008
01 Feb - 28 Feb 2008
01 Jan - 31 Jan 2008
01 Dec - 31 Dec 2007
01 Nov - 30 Nov 2007
01 Oct - 31 Oct 2007
01 Sep - 30 Sep 2007
01 Aug - 31 Aug 2007
01 Jul - 31 Jul 2007
01 Jun - 30 Jun 2007
01 May - 31 May 2007
01 Apr - 30 Apr 2007
01 Mar - 31 Mar 2007
01 Feb - 28 Feb 2007
01 Jan - 31 Jan 2007
01 Dec - 31 Dec 2006
01 Nov - 30 Nov 2006
01 Oct - 31 Oct 2006
01 Sep - 30 Sep 2006
01 Aug - 31 Aug 2006



Diversen

Powered by Pivot - 1.40.1: 'Dreadwind' 
XML: RSS Feed 
XML: Atom Feed 


Human factors in security

24 September 09 - 14:01
Aandachtsgebied: default - Link naar dit artikel

Lately some discussions arose on the Internet about the human factors in the security Common Body of Knowledgs (CBK) of the (ISC)².

Some of the arguments can be found here, here and here. The point is that learning the CBK (see here for a link to the CBK book ) students who want to certify for CISSP are not trained in the human factors of security.

Some say that apart from the 10 main topics in the CBK an extra topic on human factros should be added. Others state that human factors are part of almost all of the CBK topics. My opinion is that human factors are not very well addressed in the CBK. Instead of adding a extra topic to the CBK I would suggest to include human factors more explicitly in the BCK topics already available. Not only should human factors be included, but also some generic patterns should be addresses that can be used to handle the human shortcomings regarding security.

Some of these are:

  • Humans tend to be sloppy. They write passwords down or they lose USB sticks
  • Humans tend to take shortcuts to do their work more efficiently, sometimes circumvencing security policies
  • Humans are usually willing to help others, opening up to social engineering attacks

I think CISSP students can use a little help on addressing these kind of issues. Maybe an elaboration on these topics in a new version of the CBK would help.

Google outage

02 September 09 - 21:12
Aandachtsgebied: default - Link naar dit artikel

Today I read this message on the Google site. I found it quite frightening.

The Gmail service today was not reachable for about 90 minutes. Although this can happen to any service I was triggered by the phrase "worldwide outage" in some of the news articles about it. Gmail is used worldwide by an enormous amount of people. Downtime affects users around the globe. This is something new.

When infrastructures fail it is usually a local problem. Electrical power can be down, networks can fail, but it usually affects only a relatively small group of people. Even if a complete datacenter would fail (for instance because of a failure in the air conditioning system) normally only the local customers of the data center would be affected. A world wide infrastructure failure is something new and something we should be prepared for to happen more in the future. The more we get dependent on cloud services like the Google infrastructure (search, mail, office applications, etc) the more vulnerable we are. And not only we, but millions users worldwide.


Meer artikelen: Zie de linkerbalk.
Twitter LinkedIn Facebook RSS


Over Sjaak Laan

Sjaak Laan

Ik ben 46 jaar oud, getrouwd met Angelina, en we hebben 3 kinderen van 13, 8 en 6 jaar oud. Ik woon in Friesland (Drachten).

Ik werk voor Logica als Principal IT Architect. Ik heb 20 jaar IT ervaring.

Ik bezit de volgende certificaten:

ITAC Master Certified IT Architect


CISSP_logo CISSP (Certified Information Systems Security Professional)


TOGAF8_Certified_web TOGAF Certified Architect



Ik ben lid van:


Mijn zakelijke contacten onderhoud ik via Linkedin.

U kunt mij ook volgen op Twitter: twitter.com/sjaaklaan

U kunt mij bereiken via sjaak.laan [ a t ] gmail [puntje] com.

Deze site bevat mijn eigen mening, en niet noodzakelijkerwijs die van mijn werkgever of van de klanten waar ik voor werk.