John Pescatore

A member of the Gartner Blog Network

Archives for October, 2010


Another Dot Dot Dot Security Friday

by John Pescatore  |  October 29, 2010  |  Submit a Comment

Next week I will drive to a polling place to physically vote, pretty much the same way I did in 1978, the first time I could actually vote. My computer in 1978 was a KIM-1 6502 board – that actually made a safer online voting platform than the Windows PC I use today. We don’t [...]

Submit a Comment »

Category: Uncategorized     Tags:

Are The Most Secure Cloud Services Hosted in Denmark, New Zealand and Singapore?

by John Pescatore  |  October 28, 2010  |  1 Comment

Transparency International recently published their 2010 Corruption Index, basically ranking 178 countries against the United Nations Convention Against Corruption framework. Looking at the color coded map, what struck me is how similar it looks to the malware “heat map” that Microsoft publishes as part of their Security Intelligence Report, which color codes countries based on [...]

1 Comment »

Category: Uncategorized     Tags:

Different Security Horses for Different Security Courses

by John Pescatore  |  October 27, 2010  |  Submit a Comment

Last year I took advantage of the Cash for Clunkers program in the US and traded my 1997 pickup truck in for a new station wagon. I looked at Ford, Subaru, Toyota and many other major car manufacturers. I did not look at Bayliner, Boston Whaler, Grady White, Wellcraft or any other major boat manufacturers. [...]

Submit a Comment »

Category: Uncategorized     Tags:

Twelve Word Tuesday: Safety First – Risk, Shmisk

by John Pescatore  |  October 26, 2010  |  5 Comments

Information security is way more about safety than it is about risk.

5 Comments »

Category: Uncategorized     Tags:

Facebook Insecurity as a Microcosm of All The World’s Security Problems

by John Pescatore  |  October 25, 2010  |  Submit a Comment

I mentioned last week that the hot security topics at Gartner Symposium were (1) securely  supporting devices like the iPhone, iPad or Droid phones and (2) securely using public cloud. I don’t think I got a single question about how to securely allow use of Facebook, or securely using social network sites for business gain. Yet, [...]

Submit a Comment »

Category: Uncategorized     Tags:

Fall Symposium: Finally Friday, Fleeing Florida

by John Pescatore  |  October 22, 2010  |  1 Comment

I’ve been at Gartner a bit over 11 years and this was actually my 12th Fall Symposium. Attendance was up in a huge way this year – it actually felt like 2000 when the Dot Com boom was still happening and the downturn caused by the terrorist attacks of 2001 was still in the future. [...]

1 Comment »

Category: Security     Tags:

Twelve Word Tuesday: More Layers of Flawed Shingles Leads to Roof Collapse, Not Fewer Leaks

by John Pescatore  |  October 19, 2010  |  1 Comment

Adding levels of inneffective security: really only spending (not defense) in depth.

1 Comment »

Category: Uncategorized     Tags:

Gartner Symposium Day One: Dealing With Consumerization

by John Pescatore  |  October 18, 2010  |  1 Comment

Well, I’m down at Gartner’s Symposium in Orlando, FL – where the sun is always shining but we never get to see it. I did the Gartner Information Security Scenario presentation in the am, and then 9 client 1-1 meetings in the afternoon. Most of the conversations I had with Gartner clients were about how [...]

1 Comment »

Category: Security     Tags:

On The Road for October

by John Pescatore  |  October 15, 2010  |  Submit a Comment

I’ve been out on the West Coast with Gartner clients for most of the past three weeks and it has been unusually warm – temperatures were in the 90s and above most of the time. October has also brought a heat wave in vulnerabilities: Adobe kicked off the month releasing a whopping 23 patches. Microsoft’s [...]

Submit a Comment »

Category: Security     Tags:

FISMA: CyberScope is to Government Security as Self Service Colonoscopy is To Colon Cancer Prevention

by John Pescatore  |  October 14, 2010  |  2 Comments

Lots of coverage this week over over Government agencies lack of readiness to use a mandated FISMA reporting capability called Cyberscope. CyberScope was sold as “empowering” users and reducing their workload and increasing efficiency. In reality, at best all CyberScope could really do was reduce the OMB end of the problem it had in receiving [...]

2 Comments »

Category: Uncategorized     Tags: