posted by Scott Crawford   | November 10, 2010 | 0 Comments

HCIA

(Ed. Note: I’ve updated this post to incorporate some great feedback I’ve gotten on it already. I may well do so again to keep it fresh, as I expect to refer to this concept a lot…) In a recent post, I talked about the security value of IT management disciplines such as configuration and change...

Read More »





posted by Scott Crawford   | August 31, 2010 | 0 Comments

VisOps-l2

In my last post, I talked about getting beyond “the business of no” in security, to a more effective and thorough approach in which organizations define their objectives, actually implement them, maintain visibility into the environment for consistency with those objectives or activity that could indicate threats, and respond accordingly. This more mature approach is...

Read More »