I went to the RSA conference once — it was really busy and hearing from my buddies at the front, it’s now busier than ever. So much for the boycott, eh? A lot of my security buddies are at RSA this week, and are broadcasting the buzz back to the rest of us here [...]
Entries Tagged as 'cloud'
by French Caldwell | February 27, 2014 | 2 Comments
by French Caldwell | October 24, 2012 | Comments Off
I’m here at Orlando Symposium talking to a good colleague, Neil McDonald, and I ask Neil, “Why don’t IT service providers, who complain so much about the intrusiveness and costs of customer inquiries, inspections and audits of their security controls, just provide their customers an IT GRC dashboard? That way customers can see for themselves [...]
by French Caldwell | October 9, 2012 | 5 Comments
Some vendors and their auditors appear to be misusing SSAE 16 the same as they did SAS 70. For example, today I saw an announcement from security vendor Prolexic with the headline, “Prolexic Completes SSAE 16 Examination for Distributed Denial of Service (DDoS) Attack Mitigation Services.” SSAE 16 (aka SOC 1) like SAS 70 before [...]