In the blogosphere there are a few bloggers who stand out. Amongst security bloggers, one of my absolute favorites are Dr. Anton Chuvakin. He is extremely knowledgeable, and he dares have his saying. He is also one of the bloggers in the security space that has the highest production rate I believe. 
Anton is also the co-author of the book Security Warrior.
Anton came to security after reading the book Maximum Security by Anonymous. It was an awakening, and Anton knew what to do in his life. He claims he still do not know who wrote the book.
For Anton, Information Security is not obvious, even if it sounds like it: A: information security is about two thing: "securing" and "information", not only fighting hackers, fixing vulns, blocking attacks, protecting networks, deploying appliance, configuring firewalls, etc.
Nowadays, information pretty much makes the world go round and the missing of security is to protect information C-I-A: confidentiality (of course, for confidential info), integrity and availability for legitimate use. Yes, there are various extensions to the CIA formula, but it does describe the picture adequately for our purposes.
On key impacts IS has on business, Anton says:
A: In short: IS protects business information.
That is why it is called IS - "information security." As far as the impact of security on business, it might be dramatic and negative or dramatic and positive or none.
What determines the above choice is how well you understand the risks you face. If you have no idea what risks you face and then you go and buy a lot of security gear and use it to block random things, you are guaranteed a negative impact.
And if you know the top risks, you invest in security wisely and thus allow the business to, well, "do business." :-)
Anton is the evangelist at LogLogic. As such, he has hands on knowledge on the challenges business meet regarding information security.
A: Regulatory challenges: more new regulations, more details on the existing regulations, more bad regulations, the whole pile :-) It will have sometimes good and sometimes bad impact on security.
Commercialized, professional hacking (this has been beaten to death, so - no more comments)
Data governance (and, especially, identity information governance): who can access data, who does, who has the data, what do they do with it, etc. This will be growing in importance for at least a few years.
You can read more about Anton at his website.
Anton has his Security Warrior blog.
He is the evangelist at LogLogic.
His book is available at Amazon!
And the book PCI Compliance is available at Amazon as well!
Recent comments
3 days 21 hours ago
4 days 6 hours ago
6 days 11 hours ago
1 week 3 days ago
1 week 3 days ago
2 weeks 18 hours ago
2 weeks 21 hours ago
3 weeks 1 day ago
4 weeks 1 day ago
4 weeks 3 days ago