Steven Fox

About Steven's Blog:

A security consultant reports from the trenches.

See Steven's Posts
Steven Fox

Bio

Steven F. Fox, CISSP is an Senior Information Security consultant. He holds a Masters in Business Information Technology from Walsh College, an NSA recognized Center of Excellence. He serves on the board of the Detroit ISSA chapter and is a columnist for the ISSA Journal. He is also the founder of SecureLexicon, a security advisory firm addressing the unique security concerns of nonprofit organizations. Listen to his podcast at www.securelexicon.com
Follow him on Twitter - http://twitter.com/securelexicon
Join his LinkedIn network - http://www.linkedin.com/pub/0/251/3a1

Latest Posts by Steven

Positioning the Security Team Through Influence Part 1

|   Last week I discussed how information security is broken at the relationship level. This was illustrated by highlighting some challenging outcomes from the dysfunctional communications between security teams and their business customers.

From Obstacle to Ally - Repositioning the Security Team Pt 1

|   Information Security is broken at the relationship level. Business professional see the security team as an obstacle on the worst of days and as a cost-center on the best of days. It's time for action! This series explores common gripes from the business and ways we can act to change things.

Designing Security with Brand in Mind

|   Brand matters when it comes to security. The lack of consistency between risk management and corporate brand can lead to a loss of not only employee endorsement of security investments but also the trust of your internal and external customers. This article discusses a case study highlighting the...

Key Sessions at CISO Executive Summit 2011

|   The EC-Council will host a gathering of public/private sector information security executives and thought-leaders at the CISO Executive Summit 2011 on December 5-6 in Las Vegas. The agenda features panel discussions addressing issues that emerge from the intersection between technology, people, and...

Securing User Credentials On Mobile Devices

|   Your mobile device is an interface into systems that can store potentially sensitive information about you, your company or your employer. Given its ease of use and portability, one would expect to find unique, strong credentials to guard against unauthorized access to these resources. This...

Securing Mobile Data at the Application Layer

|   Data Security is one of the concerns addressed in the OWASP Mobile Security Project; a project focused on the application-level risks that face mobile devices. This installment will look at some of the threats to mobile data and recommended controls to mitigate the associated risks.

Security Metrics and the Balanced Scorecard

|   If you can’t measure it, you can’t manage it. Metrics, the bane and blessing of corporate citizens, emerge from this truism. Metrics allow managers to determine the efficacy of process changes and technology implementation. However, poor metrics sometimes impose an atmosphere of...

The Dark Side of Collaboration

|   Collaboration can be toxic to an Information Security program. Assaulted by conflicting management agendas and priorities, the consensus needed for success sometimes suffers an early death. However, many organizations perpetuate the mantra that collaboration is always a good idea.

Friends, Foes and Faceless Denizens – The Real Social Network

|   The successful compromises of physical security on my social engineering engagements have been enabled by information gleaned from social networking sites. This articles discusses challenges and solution scenarios to manage social media risks appropriately.

Promoting Security Policies Using Organizational Culture

|   Most of us refer to security policies in much the same way as we refer to our car manuals – when something unexpected happens. We know these documents have useful information. However, their utility is tied to situations where answers do not present themselves readily.According to Chris Noel,...

Browse CSO Blogs

See all CSO Blogs »

Recent Comments

RESOURCE CENTER