risk

New kid on the block!

This post welcomes Chris Hayes to the blogosphere! Chris is a security professional, and he seems obsessed by risk!

The few posts so far is well worth a read, and I am looking forward to Chris ramblings in the future! In his words, his blog is about:

"A blog about assessing, articulating and quantifying information security risk. "

He says he is influenced by Alex & gang, and he is found of asking his peers "What is Risk?"

Welcome, Chris!

Why password security is key on any website

Many website owners and companies do not spend enough time considering security. Things is slowly getting better, but not in the speed required to counter fraud and identity theft.

Gnucitizen made a clear post regarding how password recovery works (warning - it gets quite technical towards the end). It is a great explanation of the 4 different automatic password recovery/resetting methods, including pros and cons. The second part of the post also gives the interested a step-by-step description of how to automate the testing process.

If you still do not get the message - consider this:

You are able to automate testing in order to counter hackers. It is easy, and takes very little knowledge and effort, thus it is not very expensive. You may or may not choose to do it. One thing is certain, though - hackers and ID-thieves allready do this. As they have done for years. 

Your choice is simple: either test and alter your code as required, or wait until you are loosing data. Not a hard choice, is it?  

Assessment

Assessment is the process of documenting, usually in measurable terms, knowledge, skills, attitudes and beliefs.

Contact us now to determine your assets!

Within information security, assessments tend to focus on Risk assessment, Value assessment and audits.

Assessment

Value proposition

  • Understanding the clients values and value proposition is key to succeed with Risk assessment. The Roer.com Value Assessment process pinpoints the relevant values of the client, thus focusing the effort in the right areas. This method reduces time and effort required to identify and assess relevant risks.
  • Recognizing the correct and relevant risk is key to apply security. The Roer.com Risk assessment services relates to the business process and industry of the client, reducing the time and effort required to maintain adequate security.
  • Audits are a key tool to compare the perceived risks with the landscape. Used correctly, audits reduces operation costs, and increases quality in all operations in the organization. Audits should be included in any internal control / TQM system.

 Contact us now to determine your assets!

Navigation

Recent comments

Recent blog posts


The blogger is Kai Roer, a European Information security professional.

View Kai Roer's profile on LinkedIn

Resources

Archive

Explore Security Bloggers Network (a FeedBurner Network)